Results 1 to 7 of 7
  1. #1
    Member
    Join Date
    Oct 2017
    Posts
    4
    Points
    0

    Default Malicious inside hijackthis

    the Help2Go Detective prompted you to do because I have an issue, here in France.

    Configuration : Windows 10 on Acer desktop (see attached pic for details)


    Original Problem/issue
    1 - I can not upload pics in a mail thru Yahoo Webmail. It is SO LONG that crashes by not sending mail at all... (MAIN problem)
    2 - I got an alert from my antivirus about 'vast.bp3873834.btrll.com' inside Edge 'it is not possible to valid certificate'...bla bla bla

    Test : W10 safe mode with network, Firefox normal and no antivirus : It worked fine , we've been able to attach 3 1mo pics in Yahoo webmail and then send mail

    I post the logs in the Spyware Help Forum *all run in safe mode with network* :
    a - hijackthis
    b - SUPERAntiSpyware Scan Log - 10-10-2017 - 14-54-51
    c - AdwCleaner[S0] 2017 10 10
    d - malwarebyte

    I hope this will help you to find the problem.

    Thanks in advance

    a - hijackthis log
    Logfile of Trend Micro HijackThis v2.0.5
    Scan saved at 14:30:27, on 10/10/2017
    Platform: Unknown Windows (WinNT 6.02.1008)
    MSIE: Internet Explorer v11.0 (11.00.15063.0608)

    FIREFOX: 56.0 (x86 fr)
    Boot mode: Safe mode with network support

    Running processes:
    C:\Users\richard\Downloads\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://go.microsoft.com/fwlink/p/?L...3&ocid=UE03DHP
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: UserInit=
    O2 - BHO: ScriptInjectionPluginBrowserHelperObject - {03993315-5CE9-4F00-8790-D14A94F1D91A} - C:\Program Files (x86)\Orange\Orange Security Suite 10.10\IEExt\ie_plugin.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_144\bin\ssv.dll
    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_144\bin\jp2ssv.dll
    O2 - BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
    O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
    O3 - Toolbar: Kaspersky Protection Toolbar - {001032CB-B0AC-4F2C-A650-AD4B2B26E5DA} - C:\Program Files (x86)\Orange\Orange Security Suite 10.10\IEExt\ie_plugin.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    O4 - HKCU\..\Run: [OneDrive] "C:\Users\richard\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
    O4 - HKCU\..\Run: [Dropbox Update] "C:\Users\richard\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKCU\..\RunOnce: [Report] C:\AdwCleaner\AdwCleaner[C0].txt
    O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-21-3844302631-3143525539-2212018275-1003\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NeroMediaHomeUser.4')
    O4 - HKUS\S-1-5-21-3844302631-3143525539-2212018275-1003\..\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade (User 'NeroMediaHomeUser.4')
    O4 - HKUS\S-1-5-21-3844302631-3143525539-2212018275-501\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'Invité')
    O4 - HKUS\S-1-5-21-3844302631-3143525539-2212018275-501\..\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade (User 'Invité')
    O4 - HKUS\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User '?')
    O4 - HKUS\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\..\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade (User '?')
    O4 - Startup: Dropbox.lnk = richard\AppData\Roaming\Dropbox\bin\Dropbox.exe
    O4 - Startup: OneNote 2010 - Capture d’écran et lancement.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
    O9 - Extra button: Notes &liées OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    O9 - Extra 'Tools' menuitem: Notes &liées OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O16 - DPF: {9DF1C00D-8426-4337-972C-DC042D19A916} (FTMediaPlayer Class) - http://webtv.guidetv.orange.fr/resources/OCS_9418.cab
    O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
    O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
    O23 - Service: @%SystemRoot%\system32\AJRouter.dll,-2 (AJRouter) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
    O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30011 (AppHostSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\appidsvc.dll,-100 (AppIDSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\AppReadiness.dll,-1000 (AppReadiness) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\appxdeploymentserver.dll,-1 (AppXSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\AudioEndpointBuilder.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (Audiosrv) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: Suite de Sécurité Orange 10.10 (AVP16.0.1) - AO Kaspersky Lab - C:\Program Files (x86)\Orange\Orange Security Suite 10.10\avp.exe
    O23 - Service: @%SystemRoot%\system32\AxInstSV.dll,-103 (AxInstSV) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\bdesvc.dll,-100 (BDESVC) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%windir%\system32\bisrv.dll,-100 (BrokerInfrastructure) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\BthHFSrv.dll,-103 (BthHFSrv) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\bthserv.dll,-101 (bthserv) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\cdpsvc.dll,-100 (CDPSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\cdpusersvc.dll,-100 (CDPUserSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: Service pour utilisateur de plateforme d’appareils connectés_21359 (CDPUserSvc_21359) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\ClipSVC.dll,-103 (ClipSVC) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\coremessaging.dll,-1 (CoreMessagingRegistrar) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @combase.dll,-5012 (DcomLaunch) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\defragsvc.dll,-101 (defragsvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\das.dll,-100 (DeviceAssociationService) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (DeviceInstall) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\DevicesFlowBroker.dll,-103 (DevicesFlowUserSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: Flux d’appareils_21359 (DevicesFlowUserSvc_21359) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\DevQueryBroker.dll,-100 (DevQueryBroker) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\dhcpcore.dll,-100 (Dhcp) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\diagtrack.dll,-3001 (DiagTrack) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\Windows.Internal.Management.dll,-100 (DmEnrollmentSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\dmwappushsvc.dll,-200 (dmwappushservice) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\dosvc.dll,-100 (DoSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\DeviceSetupManager.dll,-1000 (DsmSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\dssvc.dll,-10003 (DsSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\dusmsvc.dll,-1 (DusmSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\embeddedmodesvc.dll,-201 (embeddedmode) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @EnterpriseAppMgmtSvc.dll,-1 (EntAppSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (EventLog) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\fhsvc.dll,-101 (fhsvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\FrameServer.dll,-100 (FrameServer) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\ListSvc.dll,-100 (HomeGroupListener) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\provsvc.dll,-100 (HomeGroupProvider) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\hvhostsvc.dll,-100 (HvHost) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\tetheringservice.dll,-4097 (icssvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\iphlpsvc.dll,-500 (iphlpsvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%Systemroot%\system32\ipxlatcfg.dll,-500 (IpxlatCfgSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\irmon.dll,-2000 (irmon) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
    O23 - Service: klvssbrigde64 - AO Kaspersky Lab - C:\Program Files (x86)\Orange\Orange Security Suite 10.10\x64\vssbridge64.exe
    O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\lfsvc.dll,-1 (lfsvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\licensemanagersvc.dll,-200 (LicenseManager) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%windir%\system32\lsm.dll,-1001 (LSM) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\moshost.dll,-100 (MapsBroker) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\MessagingService.dll,-100 (MessagingService) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: MessagingService_21359 - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
    O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23090 (MpsSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\WINDOWS\system32\msiexec.exe
    O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\NaturalAuth.dll,-100 (NaturalAuthentication) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\ncasvc.dll,-3009 (NcaSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\ncbservice.dll,-500 (NcbService) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\NcdAutoSetup.dll,-100 (NcdAutoSetup) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\netprofmsvc.dll,-202 (netprofm) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\NetSetupSvc.dll,-3 (NetSetupSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\NgcCtnrSvc.dll,-1 (NgcCtnrSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\APHostRes.dll,-10002 (OneSyncSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: Hôte de synchronisation_21359 (OneSyncSvc_21359) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\sysWow64\perfhost.exe,-2 (PerfHost) - Unknown owner - C:\WINDOWS\SysWow64\perfhost.exe
    O23 - Service: @%SystemRoot%\system32\PhoneserviceRes.dll,-10000 (PhoneSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\UserDataAccessRes.dll,-15001 (PimIndexMaintenanceSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: Données de contacts_21359 (PimIndexMaintenanceSvc_21359) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-200 (PlugPlay) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\pnrpauto.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\umpo.dll,-100 (Power) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll,-1 (PrintNotify) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\RDXService.dll,-256 (RetailDemo) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\RMapi.dll,-1001 (RmSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%windir%\system32\RpcEpMap.dll,-1001 (RpcEptMapper) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
    O23 - Service: @combase.dll,-5010 (RpcSs) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\ScDeviceEnum.dll,-100 (ScDeviceEnum) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\SEMgrSvc.dll,-1001 (SEMgrSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\sensorservice.dll,-1000 (SensorService) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\sensrsvc.dll,-1000 (SensrSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\ipnathlp.dll,-106 (SharedAccess) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\smphost.dll,-102 (smphost) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\SmsRouterSvc.dll,-10001 (SmsRouter) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\windows.staterepository.dll,-1 (StateRepository) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (stisvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\StorSvc.dll,-100 (StorSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\svsvc.dll,-101 (svsvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%windir%\system32\SystemEventsBrokerServer.dll,-1001 (SystemEventsBroker) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
    O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\themeservice.dll,-8192 (Themes) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\tileobjserver.dll,-1 (tiledatamodelsvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%windir%\system32\TimeBrokerServer.dll,-1001 (TimeBrokerSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\tokenbroker.dll,-100 (TokenBroker) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\WINDOWS\servicing\TrustedInstaller.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\umrdp.dll,-1000 (UmRdpService) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\UserDataAccessRes.dll,-10003 (UnistoreSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: Stockage des données utilisateur_21359 (UnistoreSvc_21359) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\UserDataAccessRes.dll,-14001 (UserDataSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: Accès aux données utilisateur_21359 (UserDataSvc_21359) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\usermgr.dll,-100 (UserManager) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\usocore.dll,-101 (UsoSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\icsvc.dll,-801 (vmicguestinterface) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\icsvc.dll,-101 (vmicheartbeat) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\icsvc.dll,-201 (vmickvpexchange) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\icsvcext.dll,-601 (vmicrdv) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\icsvc.dll,-301 (vmicshutdown) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\icsvc.dll,-401 (vmictimesync) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\icsvc.dll,-901 (vmicvmsession) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\icsvcext.dll,-501 (vmicvss) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30014 (w3logsvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30003 (W3SVC) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\WalletService.dll,-1000 (WalletService) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30001 (WAS) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbiosrvc.dll,-100 (WbioSrvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wcmsvc.dll,-4097 (Wcmsvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
    O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\wephostsvc.dll,-100 (WEPHOSTSVC) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wfdsconmgrsvc.dll,-9000 (WFDSConMgrSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wiarpc.dll,-2 (WiaRpc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\flightsettings.dll,-104 (wisvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (WlanSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wlidsvc.dll,-100 (wlidsvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\lpasvc.dll,-1000 (wlpasvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
    O23 - Service: @%systemroot%\system32\workfolderssvc.dll,-102 (workfolderssvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wpnservice.dll,-1 (WpnService) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\WpnUserService.dll,-1 (WpnUserService) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: Service utilisateur de notifications Push Windows_21359 (WpnUserService_21359) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wscsvc.dll,-200 (wscsvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
    O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\WINDOWS\system32\SearchIndexer.exe
    O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%SystemRoot%\System32\wwansvc.dll,-257 (WwanSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\xbgmsvc.dll,-100 (xbgm) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\XblAuthManager.dll,-100 (XblAuthManager) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\XblGameSave.dll,-100 (XblGameSave) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\xboxgipsvc.dll,-100 (XboxGipSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
    O23 - Service: @%systemroot%\system32\XboxNetApiSvc.dll,-100 (XboxNetApiSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe

    --
    End of file - 34221 bytes

    b - SUPERAntiSpyware

    SUPERAntiSpyware Scan Log
    SUPERAntiSpyware | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!

    Generated 10/10/2017 at 02:54 PM

    Application Version : 6.0.1248
    Database Version : 14028

    Scan type : Complete Scan
    Total Scan Time : 00:21:53

    Operating System Information
    Windows 10 Home 64-bit (Build 10.00.15063)
    UAC Off - Administrator

    Memory items scanned : 584
    Memory items detected : 0
    Registry items scanned : 86758
    Registry items detected : 0
    File items scanned : 41693
    File items detected : 685

    Adware.Tracking Cookie
    theadex.com/.axd [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\00LN4B39.TXT ]
    theadex.com/.tis [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\00LN4B39.TXT ]
    dotomi.com/.DotomiUser [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\03NQ2YT3.TXT ]
    w55c.net/.wfivefivec [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\03T0TYF6.TXT ]
    w55c.net/.matchcasale [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\03T0TYF6.TXT ]
    w55c.net/.matchgoogle [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\03T0TYF6.TXT ]
    weborama.fr/.AFFICHE_W [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\08D1NLQA.TXT ]
    weborama.fr/.wousq [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\08D1NLQA.TXT ]
    nspmotion.com/.ads [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\0NQ53E74.TXT ]
    sitescout.com/.ssi [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\0R3IPFA0.TXT ]
    sitescout.com/._ssum [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\0R3IPFA0.TXT ]
    amazon-adsystem.com/.ad-id [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\0SC49PEH.TXT ]
    amazon-adsystem.com/.ad-privacy [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\0SC49PEH.TXT ]
    tracker.databrain.com/.bmt.ta [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\1Y90ZCDH.TXT ]
    www2.adserverpub.com/.ds_0 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\13POK7MM.TXT ]
    tribalfusion.com/.ANON_ID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\147VLRT4.TXT ]
    expressroulartaanalytics.solution.weborama.fr/._wrvur [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\15BT29N2.TXT ]
    expressroulartaanalytics.solution.weborama.fr/._wrvusr [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\15BT29N2.TXT ]
    metrics.nt.vc/.fid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\18Q4T5VQ.TXT ]
    metrics.nt.vc/.admrc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\18Q4T5VQ.TXT ]
    collective-media.net/.cli [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\1DREVKZH.TXT ]
    vizu.com/.VZ_anonID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\1EAGO4E5.TXT ]
    vizu.com/.VZ_c [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\1EAGO4E5.TXT ]
    track.adform.net/.C [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\1HCQR3WA.TXT ]
    track.adform.net/.cid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\1HCQR3WA.TXT ]
    statcounter.com/.is_unique [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\1M0L02ZV.TXT ]
    mxptint.net/.mxpim [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\1QS8OAXU.TXT ]
    stat.blogorama.fr/.magicrpm-29734 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\1XJ8M1B0.TXT ]
    adsrvr.org/.TDID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\21WSEOGT.TXT ]
    adsrvr.org/.TDCPM [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\21WSEOGT.TXT ]
    audienceiq.com/.uid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\22H2TV5R.TXT ]
    chango.com/._t [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\2AYP5FZT.TXT ]
    chango.com/._vt [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\2AYP5FZT.TXT ]
    px.demdex.net/.px [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\2C1YIZNS.TXT ]
    px.demdex.net/.DexLifeCycle [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\2C1YIZNS.TXT ]
    tidaltv.com/.tidal_ttid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\2JAOCWDW.TXT ]
    adfarm1.adition.com/.UserID1 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\2NMQ4D34.TXT ]
    http://www.googleadservices.com/page...60/.Conversion [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4W8F3L7H.TXT ]
    demdex.net/.demdex [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\31KPSUA1.TXT ]
    demdex.net/.DST [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\31KPSUA1.TXT ]
    abmr.net/.01AI [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\3BEWN2DD.TXT ]
    atomex.net/.__atm_uuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\3C22K0CL.TXT ]
    lfstmedia.com/.adm_4_YFVfc6lgbj4hE36dBo-g [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\3I76QTEV.TXT ]
    adsniper.ru/.uuid3 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\3PA7QZXA.TXT ]
    adsniper.ru/.uuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\3PA7QZXA.TXT ]
    cstatic.weborama.fr/._xttrk_all [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\3S498833.TXT ]
    s372.meetrics.net/.id [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\3ZV0R72N.TXT ]
    nuggad.net/.d [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\40EA47LN.TXT ]
    nuggad.net/.ci [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\40EA47LN.TXT ]
    nuggad.net/.ut [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\40EA47LN.TXT ]
    654941032.log.optimizely.com/.end_user_id [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\410MPTYF.TXT ]
    254a.com/.tuuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\46OAKN37.TXT ]
    254a.com/.synced [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\46OAKN37.TXT ]
    254a.com/.uf [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\46OAKN37.TXT ]
    254a.com/.ipvc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\46OAKN37.TXT ]
    adgrx.com/.ADGRX_UID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4DKM68H8.TXT ]
    adgrx.com/.ADGRX_CM_CASALE_BRIDGED [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4DKM68H8.TXT ]
    adgrx.com/.ADGRX_CM_CASALE_US_BRIDGED [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4DKM68H8.TXT ]
    1040888755.log.optimizely.com/.end_user_id [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4DUEEPF2.TXT ]
    ad.360yield.com/.tuuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4P0X4WXM.TXT ]
    ad.360yield.com/.um [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4P0X4WXM.TXT ]
    ad.360yield.com/.umeh [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4P0X4WXM.TXT ]
    ad.360yield.com/.is [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4P0X4WXM.TXT ]
    ad.360yield.com/.lcai9h [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4P0X4WXM.TXT ]
    ad.360yield.com/.lcri5m [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4P0X4WXM.TXT ]
    ad.360yield.com/.pxl [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4P0X4WXM.TXT ]
    zedo.com/.FFIDA [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4QBNALLQ.TXT ]
    zedo.com/.ZEDOIDA [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4QBNALLQ.TXT ]
    zedo.com/.FFBbh [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4QBNALLQ.TXT ]
    zedo.com/.FFgb [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4QBNALLQ.TXT ]
    clubmed.d1.sc.omtrdc.net/.s_vi [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4SKKRPBD.TXT ]
    serving-sys.com/.u2 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4Z9KK1FF.TXT ]
    serving-sys.com/.A6 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4Z9KK1FF.TXT ]
    serving-sys.com/.ActivityInfo2 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\4Z9KK1FF.TXT ]
    ctnsnet.com/.opt [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\50CW17D9.TXT ]
    ctnsnet.com/.pb [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\50CW17D9.TXT ]
    ctnsnet.com/.cid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\50CW17D9.TXT ]
    wtp101.com/.tuuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\52TB3CT3.TXT ]
    wtp101.com/.cookie_born [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\52TB3CT3.TXT ]
    wtp101.com/.synced [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\52TB3CT3.TXT ]
    casalemedia.com/.CMID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\52YZSBG9.TXT ]
    casalemedia.com/.CMPS [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\52YZSBG9.TXT ]
    casalemedia.com/.CMRUM3 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\52YZSBG9.TXT ]
    casalemedia.com/.CMST [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\52YZSBG9.TXT ]
    exoclick.com/.__uvt [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\53OKI6W0.TXT ]
    alenty.com/._lnt_ui [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\5G2IM97F.TXT ]
    trafficshop.com/.u [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\5JUL2JG4.TXT ]
    criteo.com/.uid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\5LFTUKCC.TXT ]
    to-porno.com/.__atuvc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\63TQHT2D.TXT ]
    at.atwola.com/.ATTACID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\65VB4MZP.TXT ]
    trc.taboola.com/petitfute/.taboola_uppc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\6C3YZQYI.TXT ]
    trc.taboola.com/petitfute/.taboola_svrii [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\6C3YZQYI.TXT ]
    vindicosuite.com/.ug [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\6ECKBFPD.TXT ]
    http://www.googleadservices.com/page...57/.Conversion [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\6MJ8D1IK.TXT ]
    societegenerale.solution.weborama.fr/._adpc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\6UP3SVCV.TXT ]
    societegenerale.solution.weborama.fr/._adpp [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\6UP3SVCV.TXT ]
    societegenerale.solution.weborama.fr/._adpe [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\6UP3SVCV.TXT ]
    societegenerale.solution.weborama.fr/._advcrea [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\6UP3SVCV.TXT ]
    syndication1.traffichaus.com/.AVPUID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\6WWE60G9.TXT ]
    legolas-media.com/.ui [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\725E5I58.TXT ]
    legolas-media.com/.udt [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\725E5I58.TXT ]
    ads.traffichunt.com/.adx_profile_guid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\79E2EMZW.TXT ]
    ads.traffichunt.com/.tr_done [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\79E2EMZW.TXT ]
    www3.smartadserver.com/.comp [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7GOBNXFV.TXT ]
    mathtag.com/.uuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7JA08WWU.TXT ]
    mathtag.com/.uuidc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7JA08WWU.TXT ]
    mathtag.com/.mt_mop [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7JA08WWU.TXT ]
    mathtag.com/.mt_misc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7JA08WWU.TXT ]
    mathtag.com/.HRL8 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7JA08WWU.TXT ]
    marinsm.com/._msuuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7LTIIH02.TXT ]
    http://www.googleadservices.com/page...40/.Conversion [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7O038F5Q.TXT ]
    tynt.com/.uid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7S2GMPKE.TXT ]
    tradelab.fr/.uuid2 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7TI6UTA1.TXT ]
    tradelab.fr/.b0 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7TI6UTA1.TXT ]
    tradelab.fr/.uuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7TI6UTA1.TXT ]
    tradelab.fr/.iev0 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7TI6UTA1.TXT ]
    univide.com/.pdv [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7ZCYVFMR.TXT ]
    univide.com/.pids [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7ZCYVFMR.TXT ]
    univide.com/.uid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7ZCYVFMR.TXT ]
    univide.com/.pd [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7ZCYVFMR.TXT ]
    univide.com/.ext [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7ZCYVFMR.TXT ]
    univide.com/.ex [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\7ZCYVFMR.TXT ]
    revsci.net/.rts_AAAA [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\882LEJQ3.TXT ]
    revsci.net/.NETID01 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\882LEJQ3.TXT ]
    revsci.net/.rtc_AAAA [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\882LEJQ3.TXT ]
    revsci.net/.pudm_AAAA [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\882LEJQ3.TXT ]
    everesttech.net/.everest_g_v2 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\8AMFA18Q.TXT ]
    everesttech.net/.ev_t2 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\8AMFA18Q.TXT ]
    everesttech.net/.gglck [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\8AMFA18Q.TXT ]
    everesttech.net/.ev_t [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\8AMFA18Q.TXT ]
    agkn.com/.uuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\8CS3TN97.TXT ]
    agkn.com/.u [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\8CS3TN97.TXT ]
    grupoportaventura.solution.weborama.fr/._adpc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\8RCTS06X.TXT ]
    grupoportaventura.solution.weborama.fr/._adpp [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\8RCTS06X.TXT ]
    grupoportaventura.solution.weborama.fr/._adpe [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\8RCTS06X.TXT ]
    grupoportaventura.solution.weborama.fr/._advcrea [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\8RCTS06X.TXT ]
    tracking.publicidees.com/.IC [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\8TBK1SD0.TXT ]
    netseer.com/.netseer_v3_vi [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\8Y1366PM.TXT ]
    adbrn.com/.tuuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\9AI01ULB.TXT ]
    impact-ad.jp/.tuuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\9CRD41HC.TXT ]
    www.wtp101.com/.lldt [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\9FPKD8VY.TXT ]
    y.one.impact-ad.jp/.cm [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\9UHAMJXW.TXT ]
    y.one.impact-ad.jp/.cmi [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\9UHAMJXW.TXT ]
    ru4.com/.X1ID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\A9EUWQC1.TXT ]
    crwdcntrl.net/._cc_cc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ABSELE2X.TXT ]
    crwdcntrl.net/._cc_aud [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ABSELE2X.TXT ]
    crwdcntrl.net/._cc_id [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ABSELE2X.TXT ]
    crwdcntrl.net/._cc_dc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ABSELE2X.TXT ]
    engine.phn.doublepimp.com/.IUID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.IPLH [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.IPLH_Q [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.IZH [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.IZH_Q [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.IMCH [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.IMCH_Q [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.IMH [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.IMH_Q [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.ISH [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.ISH_Q [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.ISPH [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.ISPH_Q [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.CH [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.MSSH [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.MSRH [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.ILP [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.ILPLU [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.ILEALC [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.IPMPLU [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.IPMUID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.ICH [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    engine.phn.doublepimp.com/.ICH_Q [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHP6EPXH.TXT ]
    contextweb.com/.V [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHVVJ4DX.TXT ]
    contextweb.com/.pb_rtb_ev [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AHVVJ4DX.TXT ]
    bluekai.com/.bkdc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AIMNOZCZ.TXT ]
    bluekai.com/.bklc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AIMNOZCZ.TXT ]
    bluekai.com/.bku [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AIMNOZCZ.TXT ]
    247realmedia.com/.OAX [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AK9WXSX8.TXT ]
    247realmedia.com/.crit2014 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AK9WXSX8.TXT ]
    247realmedia.com/.critlmob14 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AK9WXSX8.TXT ]
    247realmedia.com/.criprem2012 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AK9WXSX8.TXT ]
    247realmedia.com/.kkcrit13 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AK9WXSX8.TXT ]
    ww691.smartadserver.com/.comp [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AMCI631J.TXT ]
    ww691.smartadserver.com/.ps72015 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AMCI631J.TXT ]
    pt.trafficjunky.net/.tj_pt [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AMHL7TEE.TXT ]
    pt.trafficjunky.net/.ad_id [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AMHL7TEE.TXT ]
    pt.trafficjunky.net/.65_pt_join [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AMHL7TEE.TXT ]
    trc.taboola.com/.taboola_upci [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\APH37QGX.TXT ]
    trc.taboola.com/.taboola_svfcd [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\APH37QGX.TXT ]
    rlcdn.com/.ck1 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AQ9ABYLH.TXT ]
    rlcdn.com/.rlas3 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AQ9ABYLH.TXT ]
    rlcdn.com/.rtn1 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AQ9ABYLH.TXT ]
    rlcdn.com/.ids [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AQ9ABYLH.TXT ]
    rlcdn.com/.dids222775866 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AQ9ABYLH.TXT ]
    clickadu.com/.OAID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AR5K43I5.TXT ]
    clickadu.com/.OACBLOCK [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AR5K43I5.TXT ]
    clickadu.com/.OACCAP [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AR5K43I5.TXT ]
    domdex.com/.PAD [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ATUGAAOW.TXT ]
    domdex.com/.PIXELpnfnyr [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ATUGAAOW.TXT ]
    ipinyou.com/.PYID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AULYR0A0.TXT ]
    ipinyou.com/.EIDBMPE [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AULYR0A0.TXT ]
    ipinyou.com/.EIDBMP [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AULYR0A0.TXT ]
    owneriq.net/.si [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AY05MKCL.TXT ]
    ads.betweendigital.com/.tuuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AZ2GE5JC.TXT ]
    ads.betweendigital.com/.um2 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\AZ2GE5JC.TXT ]
    ww14.smartadserver.com/.comp [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\B099K9Z0.TXT ]
    po.st/.post_dcm [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\BEEVD2XM.TXT ]
    po.st/.post_uuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\BEEVD2XM.TXT ]
    pixel.sitescout.com/dmp/._ssum [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\BEKZ80LO.TXT ]
    fl01.ct2.comclick.com/.UID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\BFLW1XIE.TXT ]
    fl01.ct2.comclick.com/.last [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\BFLW1XIE.TXT ]
    fl01.ct2.comclick.com/.CKTA [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\BFLW1XIE.TXT ]
    adform.net/.uid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\BIGSKIYP.TXT ]
    adxcore.com/a.phpAds_partner3 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\BJAM2P61.TXT ]
    www.smartadserver.com/.comp [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\BM8MCWQM.TXT ]
    trc.taboola.com/lexpress-styles/.taboola_wt [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\BQCJZAXH.TXT ]
    trc.taboola.com/lexpress-styles/.taboola_uppc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\BQCJZAXH.TXT ]
    trc.taboola.com/lexpress-styles/.taboola_ntrii [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\BQCJZAXH.TXT ]
    trc.taboola.com/lexpress-styles/.taboola_svrii [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\BQCJZAXH.TXT ]
    taboola.com/.t_gid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\BXQ3SSNH.TXT ]
    http://www.googleadservices.com/page...33/.Conversion [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\C2VBHFWY.TXT ]
    mediaplex.com/.svid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\C2XPXTSQ.TXT ]
    mediaplex.com/.rts [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\C2XPXTSQ.TXT ]
    mediaplex.com/.mojo3 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\C2XPXTSQ.TXT ]
    www6.smartadserver.com/.comp [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\C7Z9HE6Y.TXT ]
    us.cam4ads.com/.OAID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\EAET31GL.TXT ]
    advertising.com/.ACID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\CV5K6F2I.TXT ]
    advertising.com/.UMAP [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\CV5K6F2I.TXT ]
    rfihub.com/.u [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\D3C7CQAA.TXT ]
    rfihub.com/.eud [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\D3C7CQAA.TXT ]
    rfihub.com/.rud [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\D3C7CQAA.TXT ]
    rfihub.com/.ac [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\D3C7CQAA.TXT ]
    rfihub.com/.b [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\D3C7CQAA.TXT ]
    rfihub.com/.cmd [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\D3C7CQAA.TXT ]
    rfihub.com/.g [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\D3C7CQAA.TXT ]
    rfihub.com/.ub [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\D3C7CQAA.TXT ]
    atemda.com/.UM1 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\DUXOLFXW.TXT ]
    atemda.com/.vi [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\DUXOLFXW.TXT ]
    atemda.com/.fid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\DUXOLFXW.TXT ]
    bidswitch.net/.tuuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\DXRZU3PJ.TXT ]
    bidswitch.net/.c [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\DXRZU3PJ.TXT ]
    acuityplatform.com/.auid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\EBUVSSAP.TXT ]
    vip.adstatic.com/.as_uuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\EMQNJ2H6.TXT ]
    vip.adstatic.com/.as_pc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\EMQNJ2H6.TXT ]
    adsymptotic.com/.U [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\F0GKQIBD.TXT ]
    radiocanada.122.2o7.net/.s_vi [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\F6SLGJ2U.TXT ]
    tap2-cdn.rubiconproject.com/.pux [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FCKU13NZ.TXT ]
    addthis.com/.uid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FFDF3RC8.TXT ]
    addthis.com/.um [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FFDF3RC8.TXT ]
    addthis.com/.uvc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FFDF3RC8.TXT ]
    addthis.com/.dt [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FFDF3RC8.TXT ]
    addthis.com/.di2 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FFDF3RC8.TXT ]
    addthis.com/.bt [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FFDF3RC8.TXT ]
    addthis.com/.vc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FFDF3RC8.TXT ]
    addthis.com/.loc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FFDF3RC8.TXT ]
    addthis.com/.uit [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FFDF3RC8.TXT ]
    ads.p161.net/.tuuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FGLRHSOE.TXT ]
    datvantagevolumes.solution.weborama.fr/._wrvur [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FM8PMGI0.TXT ]
    datvantagevolumes.solution.weborama.fr/._wrvusr [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FM8PMGI0.TXT ]
    adgear.com/.AdGear_UID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FOCVU044.TXT ]
    outbrain.com/.obuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FS9XELPV.TXT ]
    outbrain.com/._lvs2 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FS9XELPV.TXT ]
    outbrain.com/._lvd2 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FS9XELPV.TXT ]
    outbrain.com/._rcc2 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FS9XELPV.TXT ]
    outbrain.com/._fcap_CAM4 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FS9XELPV.TXT ]
    outbrain.com/._ofcap_DOC1 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FS9XELPV.TXT ]
    outbrain.com/._utastes_1 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\FS9XELPV.TXT ]
    adserve.atedra.com/._adstanding_id [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\HDFD5RW5.TXT ]
    adventori.com/.tk_ui [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\G8ESR2WM.TXT ]
    ad4.adfarm1.adition.com/.fc5 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\GCNL9GVM.TXT ]
    korrelate.net/.adsuu [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\GG83R0B3.TXT ]
    openx.net/.i [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\GX71CRWA.TXT ]
    erne.co/.u [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\H0J18YYX.TXT ]
    ad.zanox.com/.zpvc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\H1PEXU8Q.TXT ]
    msnportal.112.2o7.net/.s_vi [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\HDTKPLTX.TXT ]
    go.sonobi.com/.__uin_mm [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\HNFMAKAL.TXT ]
    go.sonobi.com/.__uis [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\HNFMAKAL.TXT ]
    choicestream.com/instr/crunch.__cs_lpsppc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\HPCI92V9.TXT ]
    http://www.googleadservices.com/page...32/.Conversion [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\HUA4L2S9.TXT ]
    tradedoubler.com/.BT [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\HUSQWNAJ.TXT ]
    tradedoubler.com/.UI [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\HUSQWNAJ.TXT ]
    krxd.net/.ServedBy [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\HW9LNBGI.TXT ]
    krxd.net/._kuid_ [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\HW9LNBGI.TXT ]
    x.fidelity-media.com/.OAID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\HZOCOF53.TXT ]
    x.fidelity-media.com/.DSP_UID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\HZOCOF53.TXT ]
    http://www.googleadservices.com/page...22/.Conversion [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\I5QG1HYN.TXT ]
    http://www.googleadservices.com/page...76/.Conversion [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IAXN1Q9I.TXT ]
    cofidis2.solution.weborama.fr/._adpc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IILGU57D.TXT ]
    cofidis2.solution.weborama.fr/._adpp [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IILGU57D.TXT ]
    cofidis2.solution.weborama.fr/._adpe [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IILGU57D.TXT ]
    cofidis2.solution.weborama.fr/._advcrea [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IILGU57D.TXT ]
    sxp.smartclip.net/.uuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IJ1WLRXT.TXT ]
    sxp.smartclip.net/.psyn [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IJ1WLRXT.TXT ]
    medleyads.com/.__utma [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ILBWLPKG.TXT ]
    medleyads.com/.__utmz [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ILBWLPKG.TXT ]
    medleyads.com/.adgroups [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ILBWLPKG.TXT ]
    medleyads.com/.sg_7524 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ILBWLPKG.TXT ]
    rtbidder.net/.uid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ILMF8D7D.TXT ]
    smartadserver.com/.pid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.TestIfCookieP [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.csync [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.iab [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.pdomid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.Trk199901 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.pbw [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.partner-852b0921 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.sasd2 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.sasd [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.dyncdn [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.pbwmaj6 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.Trk157706 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.Trk196413 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.partner-bd0d1074 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.partner-7427b81c [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.TrkC234442 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.csfq [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    smartadserver.com/.partner-91d2c5d9 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IVL1YXZT.TXT ]
    eqads.com/.EQUser [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IX3MJTG6.TXT ]
    greenacrescom.solution.weborama.fr/._wrvur [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IXMOBD5V.TXT ]
    greenacrescom.solution.weborama.fr/._wrvusr [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\IXMOBD5V.TXT ]
    ads2.zeusclicks.com/.AVPUID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\JJCGGR3J.TXT ]
    dpm.demdex.net/.dpm [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\JSYQ8U6X.TXT ]
    pixel.rubiconproject.com/.rpx [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\K0X2H29V.TXT ]
    sociomantic.com/.sonar [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\KBGIRULL.TXT ]
    sociomantic.com/.sonar-expires [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\KBGIRULL.TXT ]
    sociomantic.com/.__sonar [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\KBGIRULL.TXT ]
    atdmt.com/.ATN [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\KFZIFQGD.TXT ]
    tap.rubiconproject.com/.dq [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\MJEGRLFE.TXT ]
    adsearch.adkontekst.pl/._7 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\KTUSZJ0U.TXT ]
    pswec.com/.tuuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\L0NGWW4T.TXT ]
    pubmatic.com/.KRTBCOOKIE_57 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LF0P8LXK.TXT ]
    pubmatic.com/.KRTBCOOKIE_27 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LF0P8LXK.TXT ]
    pubmatic.com/.KRTBCOOKIE_22 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LF0P8LXK.TXT ]
    pubmatic.com/.PUBMDCID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LF0P8LXK.TXT ]
    pubmatic.com/.KRTBCOOKIE_80 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LF0P8LXK.TXT ]
    pubmatic.com/.KRTBCOOKIE_257 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LF0P8LXK.TXT ]
    pubmatic.com/.KRTBCOOKIE_18 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LF0P8LXK.TXT ]
    pubmatic.com/.KRTBCOOKIE_752 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LF0P8LXK.TXT ]
    pubmatic.com/.KRTBCOOKIE_323 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LF0P8LXK.TXT ]
    pubmatic.com/.KRTBCOOKIE_255 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LF0P8LXK.TXT ]
    pubmatic.com/.KRTBCOOKIE_97 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LF0P8LXK.TXT ]
    pubmatic.com/.KRTBCOOKIE_854 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LF0P8LXK.TXT ]
    pubmatic.com/.KRTBCOOKIE_466 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LF0P8LXK.TXT ]
    pubmatic.com/.KRTBCOOKIE_379 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LF0P8LXK.TXT ]
    pubmatic.com/.KRTBCOOKIE_277 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LF0P8LXK.TXT ]
    pu.trafficshop.com/.puq [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LPGRQHTK.TXT ]
    http://www.googleadservices.com/page...25/.Conversion [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\LU0BOG2X.TXT ]
    http://www.googleadservices.com/page...20/.Conversion [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\M0M2MB5P.TXT ]
    dsp-token.aws.rubiconproject.com/.dq [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\M13NO6WO.TXT ]
    choicestream.com/._item_view.tripadvisor.hotels [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\M45X4PCA.TXT ]
    choicestream.com/.CSAnywhere [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\M45X4PCA.TXT ]
    choicestream.com/.__cs_apnxs_ta_seg [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\M45X4PCA.TXT ]
    choicestream.com/.__cs_bss_id [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\M45X4PCA.TXT ]
    choicestream.com/.__cs_apnxs_uid2 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\M45X4PCA.TXT ]
    http://www.googleadservices.com/page...72/.Conversion [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\M7Q64N8B.TXT ]
    metrigo.com/.id [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\M87GZPD4.TXT ]
    imrworldwide.com/cgi-bin.IMRID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\MELDXH30.TXT ]
    eyereturn.com/casale/.er_guid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\MIZCXQCB.TXT ]
    rs.gwallet.com/.RA1balancer [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\NOCX09B9.TXT ]
    adhigh.net/.gi_u [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\MSCQIYKJ.TXT ]
    ww370.smartadserver.com/.comp [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\MTAO405O.TXT ]
    mookie1.com/.id [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\MVYYGFID.TXT ]
    mookie1.com/.mdata [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\MVYYGFID.TXT ]
    mookie1.com/.OAX [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\MVYYGFID.TXT ]
    mookie1.com/.syncdata_VD [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\MVYYGFID.TXT ]
    mookie1.com/.fr.gookie [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\MVYYGFID.TXT ]
    sync.richmetrics.com/.id [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\NK1IJHV6.TXT ]
    tapad.com/.TapAd_TS [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\NM0HW01Y.TXT ]
    tapad.com/.TapAd_DID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\NM0HW01Y.TXT ]
    ezakus.net/.aisakosId [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\NNMRJ8B8.TXT ]
    ezakus.net/.aisakosSync [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\NNMRJ8B8.TXT ]
    ads.trafficjunky.net/.tj_123461807 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\O18GXHBC.TXT ]
    ads.trafficjunky.net/.tj_pt [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\O18GXHBC.TXT ]
    ads.trafficjunky.net/.tj_UUID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\O18GXHBC.TXT ]
    admized.com/.ads_uxid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ONQGTMIX.TXT ]
    lijit.com/.ljt_reader [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\PF19B1JQ.TXT ]
    lijit.com/.ljtrtb [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\PF19B1JQ.TXT ]
    lijit.com/.lijit_retarget [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\PF19B1JQ.TXT ]
    lijit.com/._lijit_retarget_rtb_037fcee3-8e38-4c7e-9e20-ab14e94d705f [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\PF19B1JQ.TXT ]
    lijit.com/._ljtrtb_21 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\PF19B1JQ.TXT ]
    netmng.com/.evo5 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\QY66DS00.TXT ]
    netmng.com/.u [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\QY66DS00.TXT ]
    netmng.com/.dct_oba [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\QY66DS00.TXT ]
    adtechus.com/.JEB2 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\PJ8T6OJJ.TXT ]
    gwallet.com/.ra1_sid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\PNMVBE5L.TXT ]
    gwallet.com/.ra1_uid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\PNMVBE5L.TXT ]
    gwallet.com/.ra1_pd [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\PNMVBE5L.TXT ]
    gwallet.com/.ra1_sgm [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\PNMVBE5L.TXT ]
    adscale.de/.uu [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\PTKLI3EE.TXT ]
    basebanner.com/.cicouid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\PZE8RXWY.TXT ]
    fordeu.d3.sc.omtrdc.net/.s_vi [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\QN2AXL39.TXT ]
    rubiconproject.com/.rpb [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\QQ1XUZOJ.TXT ]
    rubiconproject.com/.sput [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\QQ1XUZOJ.TXT ]
    rubiconproject.com/.khaos [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\QQ1XUZOJ.TXT ]
    rubiconproject.com/.ruid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\QQ1XUZOJ.TXT ]
    rubiconproject.com/.cd [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\QQ1XUZOJ.TXT ]
    rubiconproject.com/.au [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\QQ1XUZOJ.TXT ]
    rubiconproject.com/.lm [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\QQ1XUZOJ.TXT ]
    rubiconproject.com/.ses15 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\QQ1XUZOJ.TXT ]
    rubiconproject.com/.vis15 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\QQ1XUZOJ.TXT ]
    liverail.com/.lr_uds [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\QW9SXNCH.TXT ]
    liverail.com/.lr_uid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\QW9SXNCH.TXT ]
    bouyguestelecomfr.solution.weborama.fr/._adprofile [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\S34YB1RE.TXT ]
    skimresources.com/.skimGUID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\R2XJ7K8X.TXT ]
    fastclick.net/.pluto [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\RFWXTKCL.TXT ]
    fastclick.net/.cttutcid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\RFWXTKCL.TXT ]
    yieldlab.net/.id [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\RQPFQIKV.TXT ]
    http://www.googleadservices.com/page...45/.Conversion [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\RWSSM8JK.TXT ]
    adtech.de/.JEB2 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\RY5WCABP.TXT ]
    matures-naked.com/.__atuvc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\RYY29AVI.TXT ]
    insightexpressai.com/.DW [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\S33QRN2T.TXT ]
    insightexpressai.com/.IXAI5993 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\S33QRN2T.TXT ]
    insightexpressai.com/.DW_Time [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\S33QRN2T.TXT ]
    insightexpressai.com/.TID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\S33QRN2T.TXT ]
    insightexpressai.com/.IXAI5493 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\S33QRN2T.TXT ]
    bs.serving-sys.com/.eyeblaster [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\S83A0IHE.TXT ]
    one.cam4ads.com/.OAID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\S8L08N4E.TXT ]
    adnxs.com/.uuid2 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\SH4L5RPP.TXT ]
    adnxs.com/.anj [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\SH4L5RPP.TXT ]
    adnxs.com/.icu [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\SH4L5RPP.TXT ]
    adnxs.com/.sess [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\SH4L5RPP.TXT ]
    cdn.turn.com/.rrs [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\T2O3LB2G.TXT ]
    cdn.turn.com/.rds [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\T2O3LB2G.TXT ]
    cdn.turn.com/.rv [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\T2O3LB2G.TXT ]
    http://www.googleadservices.com/page...92/.Conversion [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\TZJ78OQL.TXT ]
    zanox.com/.zptpvc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\TD2X0TXA.TXT ]
    nexac.com/.na_tc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\TKZ4OAF5.TXT ]
    ih.adscale.de/adscale-ih/.tu [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\TRHMNT90.TXT ]
    nxtck.com/.tc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\TS9SP5IM.TXT ]
    nxtck.com/.nxtck_srv [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\TS9SP5IM.TXT ]
    nxtck.com/.uuid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\TS9SP5IM.TXT ]
    nxtck.com/.ccv2 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\TS9SP5IM.TXT ]
    de17a.com/.ss [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\W3F9HA13.TXT ]
    de17a.com/.d1 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\W3F9HA13.TXT ]
    de17a.com/.t42127251 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\W3F9HA13.TXT ]
    tubemogul.com/._tmid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\U4RMY7DK.TXT ]
    c1.adform.net/.cid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\UN1A17FP.TXT ]
    http://www.googleadservices.com/page...65/.Conversion [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\VGHXO5T5.TXT ]
    connexity.net/.COu [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\VGNIUQ6O.TXT ]
    kau.li/.d [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\W06FVX8H.TXT ]
    kau.li/.i [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\W06FVX8H.TXT ]
    xiti.com/.idrxvr [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\XET0ARHZ.TXT ]
    clubmed.solution.weborama.fr/._adp_ret_TGP [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\WBJM6GRA.TXT ]
    adadvisor.net/.ab [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\WF7839OU.TXT ]
    turn.com/.uid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\WTIY4AL3.TXT ]
    turn.com/.fc [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\WTIY4AL3.TXT ]
    turn.com/.rrs [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\WTIY4AL3.TXT ]
    turn.com/.rds [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\WTIY4AL3.TXT ]
    turn.com/.rv [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\WTIY4AL3.TXT ]
    canwestglobal.112.2o7.net/.s_vi [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\X7P21WF2.TXT ]
    semasio.net/.SEUNCY [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\X7QOSGIH.TXT ]
    delivery.swid.switchads.com/.SOC [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\X80RWKF0.TXT ]
    delivery.swid.switchads.com/.MMTH [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\X80RWKF0.TXT ]
    delivery.swid.switchads.com/.QNCS [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\X80RWKF0.TXT ]
    postmedia.demdex.net/.postmedia [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\Y22UL7GN.TXT ]
    postmedia.demdex.net/.DexLifeCycle [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\Y22UL7GN.TXT ]
    mediaforge.com/.uID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\Y6U8WW38.TXT ]
    mediaforge.com/.uid3 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\Y6U8WW38.TXT ]
    mediaforge.com/.pID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\Y6U8WW38.TXT ]
    doubleclick.net/.id [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\YCLZWBG5.TXT ]
    simpli.fi/.uid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\YF7FFWOI.TXT ]
    spotxchange.com/.partner-1435880199_91a9-0 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\YNXDGIG1.TXT ]
    estat.com/.e [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\YTIPEDDF.TXT ]
    burstnet.com/.TID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\Z3NEY66G.TXT ]
    burstnet.com/.BI77161 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\Z3NEY66G.TXT ]
    dmp.adform.net/.cid [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\Z4EV1Y2L.TXT ]
    ebz.io/.sp [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\Z6HSKAEG.TXT ]
    ebz.io/.cappingCookie [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\Z6HSKAEG.TXT ]
    bubblestat.com/.TG107 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\Z6TSUDE6.TXT ]
    bubblestat.com/.TG124 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\Z6TSUDE6.TXT ]
    bubblestat.com/.TG122 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\Z6TSUDE6.TXT ]
    bubblestat.com/.TG161 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\Z6TSUDE6.TXT ]
    bubblestat.com/.TG261 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\Z6TSUDE6.TXT ]
    m6r.eu/.id [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\Z8WPCBDC.TXT ]
    scorecardresearch.com/.UID [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ZJHKECI9.TXT ]
    scorecardresearch.com/.UIDR [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ZJHKECI9.TXT ]
    ad2.adfarm1.adition.com/.fc3 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ZU2H6Z3R.TXT ]
    uk.at.atwola.com/.c9 [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ZXXKAKMO.TXT ]
    ibeu2.mookie1.com/.ibkukiuno [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ZZOQHUIK.TXT ]
    ibeu2.mookie1.com/.ibkukinet [ C:\USERS\INVITé\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCOOKIES\LOW\ZZOQHUIK.TXT ]
    yume.com/.ymvw [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\GFG9153J.COOKIE ]
    trc.taboola.com/msn-france/.taboola_svrii [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\2A24OO4D.COOKIE ]
    trc.taboola.com/msn-france/.taboola_rii [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\2A24OO4D.COOKIE ]
    trc.taboola.com/msn-france/.taboola_svwv [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\2A24OO4D.COOKIE ]
    trc.taboola.com/msn-france/.taboola_wv [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\2A24OO4D.COOKIE ]
    trc.taboola.com/.taboola_upci [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\9EJLZB9A.COOKIE ]
    trc.taboola.com/.taboola_svfcm [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\9EJLZB9A.COOKIE ]
    trc.taboola.com/.taboola_svfcd [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\9EJLZB9A.COOKIE ]
    advertising.com/.APID [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\CRLP9L05.COOKIE ]
    advertising.com/.IDSYNC [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\CRLP9L05.COOKIE ]
    advertising.com/.ACID [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\CRLP9L05.COOKIE ]
    advertising.com/.UMAP [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\CRLP9L05.COOKIE ]
    advertising.com/.DOMSYNC [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\CRLP9L05.COOKIE ]
    advertising.com/.ADMARK [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\CRLP9L05.COOKIE ]
    advertising.com/.CS1 [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\CRLP9L05.COOKIE ]
    advertising.com/.JEB2 [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\CRLP9L05.COOKIE ]
    trc.taboola.com/leboncoin/.taboola_svrii [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\PQIT0TRY.COOKIE ]
    adnxs.com/.sess [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\GJ1ZJLLU.COOKIE ]
    adnxs.com/.uuid2 [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\GJ1ZJLLU.COOKIE ]
    adnxs.com/.anj [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\GJ1ZJLLU.COOKIE ]
    adnxs.com/.icu [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\GJ1ZJLLU.COOKIE ]
    tribalfusion.com/.ANON_ID [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\HLTFJ7K8.COOKIE ]
    outbrain.com/.obuid [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\HU44LK1R.COOKIE ]
    outbrain.com/._fcap_CAM4 [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\HU44LK1R.COOKIE ]
    outbrain.com/._ofcap_DOC1 [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\HU44LK1R.COOKIE ]
    outbrain.com/._utastes_1 [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\HU44LK1R.COOKIE ]
    outbrain.com/.apnxs [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\HU44LK1R.COOKIE ]
    outbrain.com/.rcktfl [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\HU44LK1R.COOKIE ]
    outbrain.com/.ttd [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\HU44LK1R.COOKIE ]
    outbrain.com/.muid [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\HU44LK1R.COOKIE ]
    zedo.com/.zusr [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\I2OAI2P1.COOKIE ]
    zedo.com/.ZCBC [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\I2OAI2P1.COOKIE ]
    zedo.com/.FFgip [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\I2OAI2P1.COOKIE ]
    zedo.com/.ZEDOIDA [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\I2OAI2P1.COOKIE ]
    zedo.com/.FFIDA [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\I2OAI2P1.COOKIE ]
    zedo.com/.FFcat [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\I2OAI2P1.COOKIE ]
    zedo.com/.FFad [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\I2OAI2P1.COOKIE ]
    at.atwola.com/.APID [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\MK7SXSC3.COOKIE ]
    at.atwola.com/.APIDTS [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\MK7SXSC3.COOKIE ]
    at.atwola.com/.ATTACID [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\MK7SXSC3.COOKIE ]
    at.atwola.com/.CS1 [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\MK7SXSC3.COOKIE ]
    at.atwola.com/.JEB2 [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\MK7SXSC3.COOKIE ]
    criteo.com/.uid [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\P7EC86YZ.COOKIE ]
    smartadserver.com/.pid [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\TDANL8BA.COOKIE ]
    smartadserver.com/.TestIfCookieP [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\TDANL8BA.COOKIE ]
    smartadserver.com/.csync [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\TDANL8BA.COOKIE ]
    smartadserver.com/.pdomid [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\TDANL8BA.COOKIE ]
    smartadserver.com/.pbw [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\TDANL8BA.COOKIE ]
    smartadserver.com/.__qca [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\TDANL8BA.COOKIE ]
    smartadserver.com/.Trk199901 [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\TDANL8BA.COOKIE ]
    smartadserver.com/.Trk357402 [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\TDANL8BA.COOKIE ]
    smartadserver.com/.Trk157706 [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\TDANL8BA.COOKIE ]
    smartadserver.com/.Trk0 [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\TDANL8BA.COOKIE ]
    smartadserver.com/.csfq [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\TDANL8BA.COOKIE ]
    smartadserver.com/.dyncdn [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\TDANL8BA.COOKIE ]
    smartadserver.com/.pbwmaj6 [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\TDANL8BA.COOKIE ]
    taboola.com/.t_gid [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\VC4EW5GA.COOKIE ]
    taboola.com/.taboola_usg [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\VC4EW5GA.COOKIE ]
    taboola.com/.stpt [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\VC4EW5GA.COOKIE ]
    taboola.com/.t_vpub [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\VC4EW5GA.COOKIE ]
    taboola.com/.__cfduid [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\VC4EW5GA.COOKIE ]
    taboola.com/.taboola_fp_td_user_id [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\VC4EW5GA.COOKIE ]
    taboola.com/.taboola_ucc [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\VC4EW5GA.COOKIE ]
    taboola.com/.taboola_mk [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\VC4EW5GA.COOKIE ]
    adnxs.com/pbs/v1/.uids [ C:\USERS\RICHARD\APPDATA\LOCAL\PACKAGES\MICROSOFT.MICROSOFTEDGE_8WEKYB3D8BBWE\AC\#!002\MICROSOFTEDGE\COOKIES\ZLTO9IQX.COOKIE ]
    .serving-sys.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .advertising.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .tribalfusion.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .advertising.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .atdmt.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    partners.tremorhub.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .btrll.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .ads.linkedin.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .ads.linkedin.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .ads.linkedin.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .ads.linkedin.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .casalemedia.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .casalemedia.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .casalemedia.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .casalemedia.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .casalemedia.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .casalemedia.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .connexity.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .scorecardresearch.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .doubleclick.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .dotomi.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .exelator.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .eloqua.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .eloqua.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .doubleclick.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .advertising.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .adtech.de [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .nexage.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    match.rundsp.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    match.rundsp.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    bs.serving-sys.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .adsrvr.org [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .adsrvr.org [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .tapad.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .tapad.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .tapad.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .smartadserver.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .adsymptotic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .scorecardresearch.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    ads.stickyadstv.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .advertising.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .contextweb.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .crwdcntrl.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .crwdcntrl.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .crwdcntrl.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .crwdcntrl.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .1rx.io [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .adaptv.advertising.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .adnxs.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .bluekai.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .bluekai.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .bidswitch.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .rlcdn.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .rlcdn.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .smartadserver.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .demdex.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pippio.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pippio.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .dpm.demdex.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .dotomi.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .estat.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .rfihub.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .everesttech.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .everesttech.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .adhigh.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .openx.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .ibeu2.mookie1.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .ibeu2.mookie1.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .mookie1.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .xiti.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    io.narrative.io [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .geo-um.btrll.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .mookie1.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    tracker.mrpfd.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pippio.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .contextweb.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .smartadserver.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .adhigh.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .ads.pubmatic.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pippio.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .rlcdn.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .gwallet.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .gwallet.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .connexity.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .rlcdn.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .pixel.rubiconproject.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .adaptv.advertising.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .rlcdn.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .rfihub.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .adnxs.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .rfihub.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .contextweb.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .adbrn.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .bidswitch.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .company-target.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .bidswitch.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .company-target.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .tremorhub.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .serving-sys.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .exelator.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .adform.net [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .simpli.fi [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .turn.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .spotxchange.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .mathtag.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .adnxs.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .mathtag.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]
    .gumgum.com [ C:\USERS\RICHARD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FXMNCFPB.DEFAULT-1491205843176\COOKIES.SQLITE ]

    ============
    End of Log
    ============


    c - AdwCleaner[S0] 2017 10 10
    # AdwCleaner 7.0.3.1 - Logfile created on Tue Oct 10 12:24:36 2017
    # Updated on 2017/29/09 by Malwarebytes
    # Database: 10-04-2017.1
    # Running on Windows 10 Home (X64)
    # Mode: scan
    # Support: https://www.malwarebytes.com/support

    ***** [ Services ] *****

    No malicious services found.

    ***** [ Folders ] *****

    No malicious folders found.

    ***** [ Files ] *****

    No malicious files found.

    ***** [ DLL ] *****

    No malicious DLLs found.

    ***** [ WMI ] *****

    No malicious WMI found.

    ***** [ Shortcuts ] *****

    No malicious shortcuts found.

    ***** [ Tasks ] *****

    No malicious tasks found.

    ***** [ Registry ] *****

    PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}


    ***** [ Firefox (and derivatives) ] *****

    No malicious Firefox entries.

    ***** [ Chromium (and derivatives) ] *****

    No malicious Chromium entries.

    *************************



    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########

    d - MalwareByte
    Malwarebytes Anti-Malware
    www.malwarebytes.org

    Date de l'analyse: 10/10/2017
    Heure de l'analyse: 15:07
    Fichier journal: Malwarebyte Log 2017 10 10.txt
    Administrateur: Oui

    Version: 2.2.1.1043
    Base de données de programmes malveillants: v2017.10.10.03
    Base de données de rootkits: v2017.09.13.01
    Licence: Gratuit
    Protection contre les programmes malveillants: Désactivé
    Protection contre les sites Web malveillants: Désactivé
    Autoprotection: Désactivé

    Système d'exploitation: Windows 10
    Processeur: x64
    Système de fichiers: NTFS
    Utilisateur: richard

    Type d'analyse: Analyse des menaces
    Résultat: Terminé
    Objets analysés: 456792
    Temps écoulé: 14 min, 49 s

    Mémoire: Activé
    Démarrage: Activé
    Système de fichiers: Activé
    Archives: Activé
    Rootkits: Désactivé
    Heuristique: Activé
    PUP: Avertir
    PUM: Activé

    Processus: 0
    (Aucun élément malveillant détecté)

    Modules: 0
    (Aucun élément malveillant détecté)

    Clés du Registre: 0
    (Aucun élément malveillant détecté)

    Valeurs du Registre: 0
    (Aucun élément malveillant détecté)

    Données du Registre: 0
    (Aucun élément malveillant détecté)

    Dossiers: 0
    (Aucun élément malveillant détecté)

    Fichiers: 0
    (Aucun élément malveillant détecté)

    Secteurs physiques: 0
    (Aucun élément malveillant détecté)


    (end)

  2. #2
    Member Spyware Fighter DonnaB's Avatar
    Join Date
    Apr 2009
    Location
    Illiana, Ill. USA
    Posts
    3,521
    Points
    563

    Default

    Hi B_Richard,

    Welcome to Help2Go!

    My name is Donna and I will reviewing your logs.

    Let's see what Farbar Recovery Scan Tool finds, if anything. If you need to use Safe Mode with Networking that is fine.

    Please download Farbar Recovery Scan Tool and save it to your desktop. <<< Very Important!

    Note: You will need to run the 64-bit version.

    • Make sure that FRST is on the desktop of the infected system
    • Right click and choose Run as administrator. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will produce a log called FRST.txt in the same directory the tool is run from.
    • Please copy and paste log back here.
    • The first time the tool is run it generates a second log (Addition.txt - also located in the same directory as FRST64.exe. Please also paste that along with the FRST.txt into your reply.


    Since the logs generated on Windows 10 are so long, you may need post them in separate posts. Please do so.
    If you think you might be infected with malware or have recently cleansed your computer of malware without the help of an expert, please read and follow the instructions in How to Start Removing Viruses and Spyware from your Computer. This can alleviate time consumed in trouble shooting your current computer problems.

    If your problem is solved, here's how to say thanks!

    Very proud parent of a U.S. Navy "CB"



    "People may forget what you say,
    People may forget what you did,
    but People will never forget how you made them feel!"

  3. #3
    Member
    Join Date
    Oct 2017
    Posts
    4
    Points
    0

    Default Farbar Recovery Scan Tool results in log file #1

    Quote Originally Posted by DonnaB View Post
    Hi B_Richard,

    Welcome to Help2Go!

    My name is Donna and I will reviewing your logs.

    Let's see what Farbar Recovery Scan Tool finds, if anything. If you need to use Safe Mode with Networking that is fine.

    Please download Farbar Recovery Scan Tool and save it to your desktop. <<< Very Important!

    Note: You will need to run the 64-bit version.

    • Make sure that FRST is on the desktop of the infected system
    • Right click and choose Run as administrator. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will produce a log called FRST.txt in the same directory the tool is run from.
    • Please copy and paste log back here.
    • The first time the tool is run it generates a second log (Addition.txt - also located in the same directory as FRST64.exe. Please also paste that along with the FRST.txt into your reply.


    Since the logs generated on Windows 10 are so long, you may need post them in separate posts. Please do so.
    ------------------------- log file 1 FIRST.TXT ----------------------
    Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 11-10-2017
    Exécuté par richard (administrateur) sur RICHARD-PC (13-10-2017 14:51:30)
    Exécuté depuis C:\Users\richard\Desktop
    Profils chargés: richard (Profils disponibles: richard & NeroMediaHomeUser.4 & Invité & DefaultAppPool)
    Platform: Windows 10 Home Version 1703 170317-1834 (X64) Langue: Français (France)
    Internet Explorer Version 11 (Navigateur par défaut: IE)
    Mode d'amorçage: Normal
    Tutoriel pour Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

    ==================== Processus (Avec liste blanche) =================

    (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

    (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
    (AO Kaspersky Lab) C:\Program Files (x86)\Orange\Orange Security Suite 10.10\avp.exe
    (Microsoft Corporation) C:\Windows\System32\mqsvc.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
    (McAfee, Inc.) C:\Program Files\McAfee\Real Protect\RealProtect.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
    (AO Kaspersky Lab) C:\Program Files (x86)\Orange\Orange Security Suite 10.10\avpui.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (Dropbox, Inc.) C:\Users\richard\AppData\Local\Dropbox\Update\DropboxUpdate.exe
    (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    (Dropbox, Inc.) C:\Users\richard\AppData\Roaming\Dropbox\bin\Dropbox.exe
    (Dropbox, Inc.) C:\Users\richard\AppData\Roaming\Dropbox\bin\Dropbox.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
    (Dropbox, Inc.) C:\Users\richard\AppData\Roaming\Dropbox\bin\Dropbox.exe
    (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11708.1001.30.0_x64__8wekyb3d8bbwe\WinStore.App.exe
    () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17082.14121.0_x64__8wekyb3d8bbwe\Video.UI.exe
    (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
    (Microsoft Corporation) C:\Windows\System32\smartscreen.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    (Microsoft Corporation) C:\Windows\HelpPane.exe

    ==================== Registre (Avec liste blanche) ===========================

    (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

    HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
    HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7981600 2009-07-23] (Realtek Semiconductor)
    HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
    HKLM\...\RunOnce: [RealProtect] => C:\Program Files\McAfee\Real Protect\RealProtect.exe [7108360 2017-10-07] (McAfee, Inc.)
    HKU\S-1-5-21-3844302631-3143525539-2212018275-1001\...\Run: [Dropbox Update] => C:\Users\richard\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-05] (Dropbox, Inc.)
    HKU\S-1-5-21-3844302631-3143525539-2212018275-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7964064 2017-08-17] (SUPERAntiSpyware)
    Startup: C:\Users\richard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2017-10-03]
    ShortcutTarget: Dropbox.lnk -> C:\Users\richard\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    Startup: C:\Users\richard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 - Capture d’écran et lancement.lnk [2017-03-22]
    ShortcutTarget: OneNote 2010 - Capture d’écran et lancement.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

    ==================== Internet (Avec liste blanche) ====================

    (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
    Tcpip\..\Interfaces\{49a970a7-b84d-4469-beb1-55fcb930f5da}: [DhcpNameServer] 192.168.1.1 192.168.1.1
    Tcpip\..\Interfaces\{a8d629d1-c392-4011-9b43-05e2f04ca7ef}: [DhcpNameServer] 192.168.1.1 192.168.1.1

    Internet Explorer:
    ==================
    HKU\S-1-5-21-3844302631-3143525539-2212018275-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE03&ocid=UE03DHP
    SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
    SearchScopes: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE04
    SearchScopes: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE04
    SearchScopes: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_fr___FR423
    BHO: Kaspersky Protection -> {03993315-5CE9-4F00-8790-D14A94F1D91A} -> C:\Program Files (x86)\Orange\Orange Security Suite 10.10\x64\IEExt\ie_plugin.dll [2016-12-12] (AO Kaspersky Lab)
    BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
    BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-09-22] (Eyeo GmbH)
    BHO-x32: Kaspersky Protection -> {03993315-5CE9-4F00-8790-D14A94F1D91A} -> C:\Program Files (x86)\Orange\Orange Security Suite 10.10\IEExt\ie_plugin.dll [2016-12-12] (AO Kaspersky Lab)
    BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08] (Adobe Systems Incorporated)
    BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08] (CANON INC.)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\ssv.dll [2017-10-06] (Oracle Corporation)
    BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-10-06] (Oracle Corporation)
    BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22] (Eyeo GmbH)
    Toolbar: HKLM - Kaspersky Protection Toolbar - {001032CB-B0AC-4F2C-A650-AD4B2B26E5DA} - C:\Program Files (x86)\Orange\Orange Security Suite 10.10\x64\IEExt\ie_plugin.dll [2016-12-12] (AO Kaspersky Lab)
    Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08] (CANON INC.)
    Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {001032CB-B0AC-4F2C-A650-AD4B2B26E5DA} - C:\Program Files (x86)\Orange\Orange Security Suite 10.10\IEExt\ie_plugin.dll [2016-12-12] (AO Kaspersky Lab)
    Toolbar: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001 -> Pas de nom - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Pas de fichier
    DPF: HKLM-x32 {9DF1C00D-8426-4337-972C-DC042D19A916} hxxp://webtv.guidetv.orange.fr/resources/OCS_9418.cab
    Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
    Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)

    Edge:
    ======
    Edge Extension: (AdBlock) -> EdgeExtension_BetaFishAdBlock_c1wakc4j0nefm => C:\Program Files\WindowsApps\BetaFish.AdBlock_2.3.0.0_neutral__c1wakc4j0nefm [2017-10-07]

    FireFox:
    ========
    FF ProfilePath: C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\fxmncfpb.default-1491205843176 [2017-10-13]
    FF NetworkProxy: Mozilla\Firefox\Profiles\fxmncfpb.default-1491205843176 -> type", 0
    FF Extension: (AdBlock) - C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\fxmncfpb.default-1491205843176\Extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi [2017-10-10]
    FF Extension: (Safe Browsing Version 4 (temporary add-on)) - C:\Users\richard\AppData\Roaming\Mozilla\Firefox\Profiles\fxmncfpb.default-1491205843176\Extensions\sbv4-gradual-rollout@mozilla.com.xpi [2017-10-12]
    FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
    FF Extension: (PDF Architect Converter For Firefox) - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-03-25] [non signé]
    FF HKLM-x32\...\Firefox\Extensions: [light_plugin_D772DC8D6FAF43A29B25C4EBAA5AD1DE@kaspersky.com] - C:\Program Files (x86)\Orange\Orange Security Suite 10.10\FFExt\light_plugin_firefox\addon.xpi
    FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Orange\Orange Security Suite 10.10\FFExt\light_plugin_firefox\addon.xpi [2017-09-20]
    FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_130.dll [2017-10-06] ()
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
    FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
    FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files (x86)\Virtual Earth 3D\ [] ()
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll [2017-10-06] ()
    FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2010-04-15] (CANON INC.)
    FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
    FF Plugin-x32: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-10-06] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-10-06] (Oracle Corporation)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/VirtualEarth3D,version=4.0 -> C:\Program Files (x86)\Virtual Earth 3D\ [] ()
    FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)

    Chrome:
    =======
    CHR HKLM\...\Chrome\Extension: [kgleflkdamakpmckkidkcmnmdikbbmok] - hxxps://chrome.google.com/webstore/detail/kgleflkdamakpmckkidkcmnmdikbbmok
    CHR HKLM-x32\...\Chrome\Extension: [gjmpioofjhhijdaikhaabpkcbjinfnnp] - hxxps://chrome.google.com/webstore/detail/gjmpioofjhhijdaikhaabpkcbjinfnnp
    CHR HKLM-x32\...\Chrome\Extension: [kgleflkdamakpmckkidkcmnmdikbbmok] - hxxps://chrome.google.com/webstore/detail/kgleflkdamakpmckkidkcmnmdikbbmok

    ==================== Services (Avec liste blanche) ====================

    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

    R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-31] (SUPERAntiSpyware.com)
    R2 AVP16.0.1; C:\Program Files (x86)\Orange\Orange Security Suite 10.10\avp.exe [236928 2015-12-22] (AO Kaspersky Lab)
    S3 klvssbrigde64; C:\Program Files (x86)\Orange\Orange Security Suite 10.10\x64\vssbridge64.exe [152488 2015-12-22] (AO Kaspersky Lab)
    S4 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-04-17] (Egis Technology Inc.)
    S4 NeroMediaHomeService.4; C:\Program Files (x86)\Nero\Nero MediaHome 4\NMMediaServerService.exe [259368 2009-06-23] (Nero AG)
    S4 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR)
    S4 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR)
    S4 RichVideo; C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [244904 2010-02-24] () [Fichier non signé]
    R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
    R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-07-17] (Microsoft Corporation)

    ===================== Pilotes (Avec liste blanche) ======================

    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

    R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [389816 2015-07-06] (Kaspersky Lab ZAO)
    S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
    R0 kl1; C:\WINDOWS\System32\DRIVERS\kl1.sys [478392 2015-09-11] (Kaspersky Lab ZAO)
    R0 klbackupdisk; C:\WINDOWS\System32\DRIVERS\klbackupdisk.sys [53432 2015-06-06] (Kaspersky Lab ZAO)
    R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [79752 2015-12-01] (AO Kaspersky Lab)
    R2 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [78200 2015-12-02] (AO Kaspersky Lab)
    S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [30328 2015-06-24] (Kaspersky Lab)
    R3 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [186352 2017-04-19] (AO Kaspersky Lab)
    R1 klhk; C:\WINDOWS\System32\drivers\klhk.sys [244720 2017-04-19] (AO Kaspersky Lab)
    R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1001976 2017-09-20] (AO Kaspersky Lab)
    R1 KLIM6; C:\WINDOWS\system32\DRIVERS\klim6.sys [51288 2016-07-05] (AO Kaspersky Lab)
    R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [52608 2015-11-11] (AO Kaspersky Lab)
    R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [41656 2015-06-07] (Kaspersky Lab ZAO)
    R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [45960 2015-12-07] (AO Kaspersky Lab)
    R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [87984 2016-12-12] (AO Kaspersky Lab)
    R1 Klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [116448 2017-03-15] (AO Kaspersky Lab)
    R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [194440 2015-12-03] (AO Kaspersky Lab)
    R1 MpKsl000208f1; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A50C7A84-3B89-4DCA-A06D-4DE5F88658C5}\MpKsl000208f1.sys [58120 2017-10-12] (Microsoft Corporation)
    R1 MpKsl62fc7e4a; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B47450CC-E08A-405F-880B-6F009784B05C}\MpKsl62fc7e4a.sys [58120 2017-10-13] (Microsoft Corporation)
    R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2017-03-18] (Realtek )
    R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
    S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
    S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
    R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
    R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
    U3 idsvc; pas de ImagePath
    S3 klids; \??\C:\ProgramData\Kaspersky Lab\AVP16.0.1\Bases\klids.sys [X]

    ==================== NetSvcs (Avec liste blanche) ===================

    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


    ==================== Un mois - Créés - fichiers et dossiers ========

    (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

    2017-10-13 14:51 - 2017-10-13 14:52 - 000017697 _____ C:\Users\richard\Desktop\FRST.txt
    2017-10-13 14:50 - 2017-10-13 14:51 - 000000000 ____D C:\FRST
    2017-10-13 14:50 - 2017-10-13 14:49 - 002401792 _____ (Farbar) C:\Users\richard\Desktop\FRST64.exe
    2017-10-13 14:48 - 2017-10-13 14:49 - 002401792 _____ (Farbar) C:\Users\richard\Downloads\FRST64.exe
    2017-10-11 08:59 - 2017-09-30 04:29 - 000804784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
    2017-10-11 08:59 - 2017-09-30 04:26 - 001333136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
    2017-10-11 08:59 - 2017-09-30 04:10 - 000480920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
    2017-10-11 08:59 - 2017-09-30 04:04 - 004215184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
    2017-10-11 08:59 - 2017-09-30 04:04 - 000438096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll
    2017-10-11 08:59 - 2017-09-30 04:04 - 000182680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
    2017-10-11 08:59 - 2017-09-30 04:03 - 006768288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
    2017-10-11 08:59 - 2017-09-30 04:02 - 000175512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\basecsp.dll
    2017-10-11 08:59 - 2017-09-29 09:45 - 002953216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
    2017-10-11 08:59 - 2017-09-29 09:39 - 000364032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
    2017-10-11 08:59 - 2017-09-29 09:38 - 002671616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
    2017-10-11 08:59 - 2017-09-29 09:38 - 000370688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
    2017-10-11 08:59 - 2017-09-29 09:38 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scksp.dll
    2017-10-11 08:59 - 2017-09-29 09:37 - 000306688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll
    2017-10-11 08:59 - 2017-09-29 09:36 - 000590336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPKsp.dll
    2017-10-11 08:59 - 2017-09-29 09:34 - 002859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
    2017-10-11 08:59 - 2017-09-29 09:33 - 007598080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
    2017-10-11 08:59 - 2017-09-29 09:32 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
    2017-10-11 08:59 - 2017-09-29 09:29 - 001460736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
    2017-10-11 08:59 - 2017-09-29 09:29 - 001318912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
    2017-10-11 08:59 - 2017-09-29 09:29 - 000157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpchttp.dll
    2017-10-11 08:59 - 2017-09-29 09:28 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
    2017-10-11 08:59 - 2017-09-29 09:28 - 000473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
    2017-10-11 08:59 - 2017-09-29 09:28 - 000297984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
    2017-10-11 08:59 - 2017-09-29 09:28 - 000104448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Robocopy.exe
    2017-10-11 08:59 - 2017-09-29 09:28 - 000040448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cipher.exe
    2017-10-11 08:59 - 2017-09-20 17:08 - 000640512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswstr10.dll
    2017-10-11 08:59 - 2017-09-20 17:08 - 000345088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
    2017-10-11 08:59 - 2017-09-20 17:08 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjint40.dll
    2017-10-11 08:58 - 2017-09-30 04:29 - 001408536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
    2017-10-11 08:58 - 2017-09-30 04:26 - 001292872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
    2017-10-11 08:58 - 2017-09-30 04:10 - 001839872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
    2017-10-11 08:58 - 2017-09-30 04:10 - 001150776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
    2017-10-11 08:58 - 2017-09-30 04:10 - 000606072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
    2017-10-11 08:58 - 2017-09-30 04:10 - 000508344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
    2017-10-11 08:58 - 2017-09-30 04:09 - 000787712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
    2017-10-11 08:58 - 2017-09-30 04:06 - 004471368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
    2017-10-11 08:58 - 2017-09-30 04:05 - 005827744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
    2017-10-11 08:58 - 2017-09-30 04:05 - 002603744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
    2017-10-11 08:58 - 2017-09-30 04:05 - 001266544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
    2017-10-11 08:58 - 2017-09-30 04:05 - 000750488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
    2017-10-11 08:58 - 2017-09-30 04:05 - 000559000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
    2017-10-11 08:58 - 2017-09-30 04:04 - 000612120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
    2017-10-11 08:58 - 2017-09-30 04:04 - 000347544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
    2017-10-11 08:58 - 2017-09-30 04:03 - 020373408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2017-10-11 08:58 - 2017-09-30 04:03 - 001439032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
    2017-10-11 08:58 - 2017-09-30 04:01 - 000124544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
    2017-10-11 08:58 - 2017-09-29 09:44 - 000133120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
    2017-10-11 08:58 - 2017-09-29 09:43 - 002199552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
    2017-10-11 08:58 - 2017-09-29 09:43 - 000142336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll
    2017-10-11 08:58 - 2017-09-29 09:43 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
    2017-10-11 08:58 - 2017-09-29 09:42 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mgmtapi.dll
    2017-10-11 08:58 - 2017-09-29 09:41 - 013844992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
    2017-10-11 08:58 - 2017-09-29 09:41 - 000110080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BitLockerCsp.dll
    2017-10-11 08:58 - 2017-09-29 09:40 - 006728192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
    2017-10-11 08:58 - 2017-09-29 09:40 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
    2017-10-11 08:58 - 2017-09-29 09:39 - 020511232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
    2017-10-11 08:58 - 2017-09-29 09:39 - 011888640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2017-10-11 08:58 - 2017-09-29 09:38 - 005721600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
    2017-10-11 08:58 - 2017-09-29 09:38 - 001135616 ____R (The ICU Project) C:\WINDOWS\SysWOW64\icuuc.dll
    2017-10-11 08:58 - 2017-09-29 09:38 - 000471040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
    2017-10-11 08:58 - 2017-09-29 09:38 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
    2017-10-11 08:58 - 2017-09-29 09:38 - 000308224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
    2017-10-11 08:58 - 2017-09-29 09:37 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll
    2017-10-11 08:58 - 2017-09-29 09:36 - 019337216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2017-10-11 08:58 - 2017-09-29 09:35 - 003654656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
    2017-10-11 08:58 - 2017-09-29 09:34 - 006255616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
    2017-10-11 08:58 - 2017-09-29 09:34 - 000798720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
    2017-10-11 08:58 - 2017-09-29 09:34 - 000787456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
    2017-10-11 08:58 - 2017-09-29 09:34 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
    2017-10-11 08:58 - 2017-09-29 09:33 - 004559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
    2017-10-11 08:58 - 2017-09-29 09:33 - 001506816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
    2017-10-11 08:58 - 2017-09-29 09:33 - 000658944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
    2017-10-11 08:58 - 2017-09-29 09:32 - 002782720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
    2017-10-11 08:58 - 2017-09-29 09:32 - 002340864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
    2017-10-11 08:58 - 2017-09-29 09:32 - 001244160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll
    2017-10-11 08:58 - 2017-09-29 09:31 - 003107328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
    2017-10-11 08:58 - 2017-09-29 07:40 - 000804312 _____ C:\WINDOWS\SysWOW64\locale.nls
    2017-10-11 08:58 - 2017-09-29 07:40 - 000804312 _____ C:\WINDOWS\system32\locale.nls
    2017-10-11 08:58 - 2017-09-19 00:15 - 000648704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
    2017-10-11 08:57 - 2017-09-30 04:09 - 002259760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
    2017-10-11 08:57 - 2017-09-30 04:04 - 000519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
    2017-10-11 08:57 - 2017-09-29 09:40 - 000371200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
    2017-10-11 08:57 - 2017-09-19 00:20 - 000049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tetheringclient.dll
    2017-10-11 08:51 - 2017-09-30 07:41 - 005304496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
    2017-10-11 08:51 - 2017-09-30 07:40 - 000558912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
    2017-10-11 08:51 - 2017-09-30 07:40 - 000336320 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
    2017-10-11 08:51 - 2017-09-29 09:32 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
    2017-10-11 08:51 - 2017-09-29 09:27 - 000538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
    2017-10-11 08:51 - 2017-09-29 09:24 - 003377664 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
    2017-10-11 08:51 - 2017-09-29 09:23 - 000972288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
    2017-10-11 08:50 - 2017-09-30 07:50 - 001346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
    2017-10-11 08:50 - 2017-09-30 07:50 - 001068208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
    2017-10-11 08:50 - 2017-09-30 07:49 - 001004136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
    2017-10-11 08:50 - 2017-09-30 07:42 - 000820120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
    2017-10-11 08:50 - 2017-09-30 07:41 - 000259400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
    2017-10-11 08:50 - 2017-09-30 07:38 - 007910072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
    2017-10-11 08:50 - 2017-09-29 09:34 - 003669504 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
    2017-10-11 08:50 - 2017-09-29 09:32 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
    2017-10-11 08:50 - 2017-09-29 09:32 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
    2017-10-11 08:50 - 2017-09-29 09:31 - 000306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
    2017-10-11 08:50 - 2017-09-29 09:31 - 000168448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
    2017-10-11 08:50 - 2017-09-29 09:31 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
    2017-10-11 08:50 - 2017-09-29 09:30 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
    2017-10-11 08:50 - 2017-09-29 09:29 - 000724992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
    2017-10-11 08:50 - 2017-09-29 09:29 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
    2017-10-11 08:50 - 2017-09-29 09:29 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
    2017-10-11 08:50 - 2017-09-29 09:27 - 000565760 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
    2017-10-11 08:50 - 2017-09-29 09:27 - 000412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
    2017-10-11 08:50 - 2017-09-29 09:27 - 000350720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
    2017-10-11 08:50 - 2017-09-29 09:24 - 000684032 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
    2017-10-11 08:50 - 2017-09-29 09:23 - 005557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
    2017-10-11 08:50 - 2017-09-29 09:23 - 002446336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
    2017-10-11 08:50 - 2017-09-29 09:23 - 002055680 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
    2017-10-11 08:50 - 2017-09-29 09:23 - 001398784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
    2017-10-11 08:50 - 2017-09-29 09:23 - 000986624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
    2017-10-11 08:50 - 2017-09-29 09:22 - 001438208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
    2017-10-11 08:50 - 2017-09-29 09:22 - 000407040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
    2017-10-11 08:50 - 2017-09-29 09:20 - 001811456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
    2017-10-11 08:50 - 2017-09-29 09:19 - 002088448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
    2017-10-11 08:49 - 2017-09-30 07:51 - 001458320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
    2017-10-11 08:49 - 2017-09-30 07:42 - 001506712 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
    2017-10-11 08:49 - 2017-09-30 07:41 - 000651672 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
    2017-10-11 08:49 - 2017-09-30 07:41 - 000228248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
    2017-10-11 08:49 - 2017-09-30 07:40 - 000408984 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
    2017-10-11 08:49 - 2017-09-30 07:40 - 000072944 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
    2017-10-11 08:49 - 2017-09-30 07:39 - 021351760 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2017-10-11 08:49 - 2017-09-30 07:39 - 000203672 _____ (Microsoft Corporation) C:\WINDOWS\system32\basecsp.dll
    2017-10-11 08:49 - 2017-09-30 07:36 - 002672024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
    2017-10-11 08:49 - 2017-09-29 09:32 - 000209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll
    2017-10-11 08:49 - 2017-09-29 09:32 - 000023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\mgmtapi.dll
    2017-10-11 08:49 - 2017-09-29 09:31 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
    2017-10-11 08:49 - 2017-09-29 09:30 - 007931392 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
    2017-10-11 08:49 - 2017-09-29 09:30 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
    2017-10-11 08:49 - 2017-09-29 09:28 - 000556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
    2017-10-11 08:49 - 2017-09-29 09:28 - 000527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
    2017-10-11 08:49 - 2017-09-29 09:28 - 000458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
    2017-10-11 08:49 - 2017-09-29 09:28 - 000254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\scksp.dll
    2017-10-11 08:49 - 2017-09-29 09:27 - 000409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
    2017-10-11 08:49 - 2017-09-29 09:26 - 008213504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
    2017-10-11 08:49 - 2017-09-29 09:26 - 000356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
    2017-10-11 08:49 - 2017-09-29 09:26 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll
    2017-10-11 08:49 - 2017-09-29 09:25 - 008199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
    2017-10-11 08:49 - 2017-09-29 09:25 - 004175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
    2017-10-11 08:49 - 2017-09-29 09:24 - 002503680 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
    2017-10-11 08:49 - 2017-09-29 09:24 - 001628672 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
    2017-10-11 08:49 - 2017-09-29 09:23 - 004730368 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
    2017-10-11 08:49 - 2017-09-29 09:23 - 002730496 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
    2017-10-11 08:49 - 2017-09-29 09:23 - 001052672 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
    2017-10-11 08:49 - 2017-09-29 09:23 - 000841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
    2017-10-11 08:49 - 2017-09-29 09:23 - 000756224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
    2017-10-11 08:49 - 2017-09-29 09:23 - 000512000 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
    2017-10-11 08:49 - 2017-09-29 09:21 - 003304448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
    2017-10-11 08:49 - 2017-09-29 09:21 - 000722944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
    2017-10-11 08:49 - 2017-09-29 09:21 - 000414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
    2017-10-11 08:49 - 2017-09-29 09:21 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll
    2017-10-11 08:49 - 2017-09-29 09:20 - 000804864 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
    2017-10-11 08:49 - 2017-09-29 09:20 - 000385536 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
    2017-10-11 08:49 - 2017-09-29 09:20 - 000286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
    2017-10-11 08:49 - 2017-09-29 09:19 - 000325120 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
    2017-10-11 08:49 - 2017-09-29 09:19 - 000306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
    2017-10-11 08:49 - 2017-09-29 09:19 - 000208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
    2017-10-11 08:49 - 2017-09-29 09:18 - 002438656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
    2017-10-11 08:49 - 2017-09-29 09:18 - 000215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\manage-bde.exe
    2017-10-11 08:49 - 2017-09-29 09:18 - 000141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
    2017-10-11 08:49 - 2017-09-19 01:11 - 001018272 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
    2017-10-11 08:48 - 2017-09-30 07:49 - 000777400 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
    2017-10-11 08:48 - 2017-09-30 07:48 - 008319384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2017-10-11 08:48 - 2017-09-30 07:48 - 002327448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
    2017-10-11 08:48 - 2017-09-30 07:47 - 001194792 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
    2017-10-11 08:48 - 2017-09-30 07:41 - 005477600 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
    2017-10-11 08:48 - 2017-09-29 09:29 - 000461824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
    2017-10-11 08:48 - 2017-09-29 09:25 - 002760704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll
    2017-10-11 08:48 - 2017-09-29 09:23 - 000647168 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
    2017-10-11 08:48 - 2017-09-29 09:21 - 000154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\regsvc.dll
    2017-10-11 08:48 - 2017-09-29 09:20 - 000194560 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpchttp.dll
    2017-10-11 08:48 - 2017-09-29 09:18 - 001527296 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
    2017-10-11 08:48 - 2017-09-29 09:18 - 000130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Robocopy.exe
    2017-10-11 08:47 - 2017-09-30 07:49 - 000135576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
    2017-10-11 08:47 - 2017-09-30 07:48 - 002399728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
    2017-10-11 08:47 - 2017-09-30 07:44 - 000712600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
    2017-10-11 08:47 - 2017-09-30 07:44 - 000181912 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
    2017-10-11 08:47 - 2017-09-30 07:43 - 007318888 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
    2017-10-11 08:47 - 2017-09-30 07:43 - 002442136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
    2017-10-11 08:47 - 2017-09-30 07:40 - 000642680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
    2017-10-11 08:47 - 2017-09-30 07:38 - 002239136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
    2017-10-11 08:47 - 2017-09-30 07:36 - 000057976 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe
    2017-10-11 08:47 - 2017-09-29 09:46 - 023678976 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
    2017-10-11 08:47 - 2017-09-29 09:32 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspisrv.dll
    2017-10-11 08:47 - 2017-09-29 09:30 - 023686144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2017-10-11 08:47 - 2017-09-29 09:29 - 008333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
    2017-10-11 08:47 - 2017-09-29 09:29 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
    2017-10-11 08:47 - 2017-09-29 09:29 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
    2017-10-11 08:47 - 2017-09-29 09:29 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\ServiceWorkerHost.exe
    2017-10-11 08:47 - 2017-09-29 09:27 - 012803072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2017-10-11 08:47 - 2017-09-29 09:26 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPKsp.dll
    2017-10-11 08:47 - 2017-09-29 09:24 - 003307008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2017-10-11 08:47 - 2017-09-29 09:23 - 003140096 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
    2017-10-11 08:47 - 2017-09-29 09:23 - 001460224 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
    2017-10-11 08:47 - 2017-09-29 09:22 - 001802240 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2017-10-11 08:47 - 2017-09-29 09:21 - 000476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
    2017-10-11 08:47 - 2017-09-29 09:21 - 000124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
    2017-10-11 08:47 - 2017-09-29 09:20 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsiexe.dll
    2017-10-11 08:47 - 2017-09-29 09:18 - 000347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
    2017-10-11 08:47 - 2017-09-19 00:20 - 000831488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
    2017-10-11 08:46 - 2017-09-30 07:52 - 001595152 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
    2017-10-11 08:46 - 2017-09-30 07:51 - 000661224 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
    2017-10-11 08:46 - 2017-09-30 07:47 - 002969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
    2017-10-11 08:46 - 2017-09-30 07:42 - 004848952 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
    2017-10-11 08:46 - 2017-09-30 07:41 - 000961944 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
    2017-10-11 08:46 - 2017-09-30 07:40 - 000724704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
    2017-10-11 08:46 - 2017-09-29 09:34 - 017370624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
    2017-10-11 08:46 - 2017-09-29 09:33 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
    2017-10-11 08:46 - 2017-09-29 09:32 - 002199552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
    2017-10-11 08:46 - 2017-09-29 09:31 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\efssvc.dll
    2017-10-11 08:46 - 2017-09-29 09:30 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
    2017-10-11 08:46 - 2017-09-29 09:29 - 000304640 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
    2017-10-11 08:46 - 2017-09-29 09:28 - 000699904 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
    2017-10-11 08:46 - 2017-09-29 09:28 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
    2017-10-11 08:46 - 2017-09-29 09:27 - 001321984 ____R (The ICU Project) C:\WINDOWS\system32\icuuc.dll
    2017-10-11 08:46 - 2017-09-29 09:26 - 001269760 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
    2017-10-11 08:46 - 2017-09-29 09:24 - 001307648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
    2017-10-11 08:46 - 2017-09-29 09:23 - 001887744 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
    2017-10-11 08:46 - 2017-09-29 09:23 - 001605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
    2017-10-11 08:46 - 2017-09-29 09:22 - 002829824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
    2017-10-11 08:46 - 2017-09-29 09:21 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
    2017-10-11 08:46 - 2017-09-29 09:18 - 000893440 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
    2017-10-11 08:46 - 2017-09-29 09:18 - 000603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
    2017-10-11 08:46 - 2017-09-29 09:18 - 000046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\cipher.exe
    2017-10-11 08:46 - 2017-09-19 01:20 - 001065104 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
    2017-10-11 08:46 - 2017-09-19 01:20 - 000900376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
    2017-10-11 08:46 - 2017-09-19 01:17 - 001395664 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
    2017-10-11 08:46 - 2017-09-19 01:17 - 001186464 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
    2017-10-11 08:46 - 2017-09-19 00:25 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\eShims.dll
    2017-10-11 08:45 - 2017-09-30 07:51 - 001147288 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
    2017-10-11 08:45 - 2017-09-30 07:50 - 001024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
    2017-10-11 08:45 - 2017-09-30 07:48 - 000644696 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
    2017-10-11 08:45 - 2017-09-30 07:41 - 002086808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
    2017-10-11 08:45 - 2017-09-30 07:41 - 000654976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
    2017-10-11 08:45 - 2017-09-30 07:41 - 000257432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
    2017-10-11 08:45 - 2017-09-30 07:40 - 000184728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
    2017-10-11 08:45 - 2017-09-29 09:30 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
    2017-10-11 08:45 - 2017-09-29 09:27 - 000616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
    2017-10-11 08:45 - 2017-09-29 09:27 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
    2017-10-11 08:45 - 2017-09-29 09:26 - 002809344 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
    2017-10-11 08:45 - 2017-09-29 09:26 - 001468928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
    2017-10-11 08:45 - 2017-09-29 09:25 - 000586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
    2017-10-11 08:45 - 2017-09-29 09:24 - 001886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
    2017-10-11 08:45 - 2017-09-19 01:18 - 000965024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
    2017-10-11 08:45 - 2017-09-19 01:17 - 000821664 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
    2017-10-11 08:45 - 2017-09-19 00:26 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
    2017-10-11 08:45 - 2017-09-19 00:23 - 000210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
    2017-10-11 08:44 - 2017-09-30 07:45 - 000511896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
    2017-10-11 08:44 - 2017-09-30 07:40 - 000173976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys
    2017-10-11 08:44 - 2017-09-29 09:32 - 000035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
    2017-10-11 08:44 - 2017-09-19 01:09 - 000554400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
    2017-10-10 14:41 - 2017-10-10 14:41 - 000000000 ____D C:\Users\richard\Downloads\backups
    2017-10-10 14:32 - 2017-10-10 14:32 - 000001853 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    2017-10-10 14:32 - 2017-10-10 14:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
    2017-10-10 14:24 - 2017-10-10 14:32 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
    2017-10-10 14:24 - 2017-10-10 14:24 - 000000536 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task c2139770-4bf2-4d2e-a928-129c1af2b24e.job
    2017-10-10 14:24 - 2017-10-10 14:24 - 000000536 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 63b7a601-b9d6-4e47-a703-c57b1ced9c04.job
    2017-10-10 14:24 - 2017-10-10 14:24 - 000000000 ____D C:\Users\richard\AppData\Roaming\SUPERAntiSpyware.com
    2017-10-10 14:24 - 2017-10-10 14:24 - 000000000 ____D C:\ProgramData\SUPERAntiSpyware.com
    2017-10-10 14:21 - 2017-10-10 14:26 - 000000000 ____D C:\AdwCleaner
    2017-10-10 14:20 - 2017-10-10 14:20 - 126925120 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
    2017-10-10 14:19 - 2017-10-10 15:07 - 000346318 _____ C:\WINDOWS\ntbtlog.txt
    2017-10-10 14:13 - 2017-10-10 14:13 - 000388608 _____ (Trend Micro Inc.) C:\Users\richard\Downloads\HijackThis.exe
    2017-10-10 14:05 - 2017-10-10 14:05 - 030668680 _____ (SUPERAntiSpyware) C:\Users\richard\Downloads\SUPERAntiSpyware.exe
    2017-10-10 14:04 - 2017-10-10 14:05 - 039029448 _____ (Microsoft Corporation) C:\Users\richard\Downloads\Windows-KB890830-x64-V5.53.exe
    2017-10-08 07:32 - 2017-10-08 07:32 - 000000118 ___RH C:\Users\richard\Downloads\Stinger.opt
    2017-10-07 23:34 - 2017-10-07 23:34 - 000359721 _____ C:\Users\richard\AppData\Local\census.cache
    2017-10-07 23:34 - 2017-10-07 23:34 - 000142788 _____ C:\Users\richard\AppData\Local\ars.cache
    2017-10-07 16:55 - 2017-10-07 20:40 - 000000825 _____ C:\Users\richard\Downloads\Stinger_07102017_165508.html
    2017-10-07 16:54 - 2017-10-07 16:54 - 016570584 _____ (McAfee Inc) C:\Users\richard\Downloads\stinger32.exe
    2017-10-07 16:54 - 2017-10-07 16:54 - 002405672 _____ (Trend Micro Inc.) C:\Users\richard\Downloads\HousecallLauncher64.exe
    2017-10-07 16:54 - 2017-10-07 16:54 - 000000036 _____ C:\Users\richard\AppData\Local\housecall.guid.cache
    2017-10-07 16:54 - 2017-10-07 16:54 - 000000000 ____D C:\Program Files\McAfee
    2017-10-07 16:44 - 2017-10-07 16:44 - 000040148 _____ C:\Users\richard\Documents\cc_20171007_164408.reg
    2017-10-07 16:39 - 2017-10-10 15:24 - 000000000 ____D C:\Users\richard\Desktop\ORDIZEN37
    2017-10-07 16:30 - 2017-10-07 16:32 - 000000000 ____D C:\Users\richard\AppData\Roaming\ZHP
    2017-10-07 16:28 - 2017-10-07 16:28 - 008250832 _____ (Malwarebytes) C:\Users\richard\Downloads\adwcleaner_7.0.3.1.exe
    2017-10-07 16:26 - 2017-10-08 07:32 - 000000000 ____D C:\Program Files (x86)\stinger
    2017-10-07 15:50 - 2017-10-10 14:28 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
    2017-10-06 16:08 - 2017-10-06 16:15 - 000000000 ____D C:\Users\richard\AppData\Local\Thunderbird
    2017-10-06 16:08 - 2017-10-06 16:08 - 000001286 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
    2017-10-06 16:08 - 2017-10-06 16:08 - 000001274 _____ C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
    2017-10-06 16:08 - 2017-10-06 16:08 - 000000000 ____D C:\Users\richard\AppData\Roaming\Thunderbird
    2017-10-06 16:08 - 2017-10-06 16:08 - 000000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
    2017-10-06 15:57 - 2017-10-06 15:57 - 000088594 _____ C:\Users\richard\Documents\cc_20171006_155729.reg
    2017-10-03 20:07 - 2017-10-03 20:07 - 000000000 ____D C:\Users\richard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
    2017-09-29 13:57 - 2017-09-29 13:57 - 001679200 _____ C:\Users\richard\Downloads\unspecified
    2017-09-17 22:47 - 2017-09-17 22:47 - 000000000 ____D C:\WINDOWS\PCHEALTH
    2017-09-17 22:44 - 2017-09-05 07:12 - 000627080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
    2017-09-17 22:44 - 2017-09-05 06:45 - 002476712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
    2017-09-17 22:44 - 2017-09-05 06:45 - 002166808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2017-09-17 22:44 - 2017-09-05 06:45 - 000085784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialUIBroker.exe
    2017-09-17 22:44 - 2017-09-05 06:42 - 002330520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
    2017-09-17 22:44 - 2017-09-05 06:41 - 004671832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
    2017-09-17 22:44 - 2017-09-05 06:37 - 000583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
    2017-09-17 22:44 - 2017-09-05 06:23 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
    2017-09-17 22:44 - 2017-09-05 06:22 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
    2017-09-17 22:44 - 2017-09-05 06:16 - 005961728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
    2017-09-17 22:44 - 2017-09-05 06:16 - 000357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
    2017-09-17 22:44 - 2017-09-05 06:15 - 001248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
    2017-09-17 22:44 - 2017-09-05 06:15 - 000657408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
    2017-09-17 22:44 - 2017-09-05 06:12 - 005225984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
    2017-09-17 22:44 - 2017-09-05 06:12 - 000899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
    2017-09-17 22:44 - 2017-09-05 06:11 - 003667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
    2017-09-17 22:44 - 2017-09-05 06:11 - 001355264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
    2017-09-17 22:44 - 2017-09-05 06:11 - 001060352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
    2017-09-17 22:44 - 2017-09-05 06:11 - 001019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
    2017-09-17 22:44 - 2017-09-05 06:06 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
    2017-09-17 22:44 - 2017-09-05 06:04 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RstrtMgr.dll
    2017-09-17 22:44 - 2017-09-05 06:04 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
    2017-09-17 22:43 - 2017-09-05 07:30 - 000287648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
    2017-09-17 22:43 - 2017-09-05 07:24 - 000519584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
    2017-09-17 22:43 - 2017-09-05 07:21 - 000189344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
    2017-09-17 22:43 - 2017-09-05 07:16 - 000546208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
    2017-09-17 22:43 - 2017-09-05 07:14 - 000094624 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
    2017-09-17 22:43 - 2017-09-05 07:12 - 000081176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
    2017-09-17 22:43 - 2017-09-05 06:50 - 004330920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupapi.dll
    2017-09-17 22:43 - 2017-09-05 06:44 - 000569264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
    2017-09-17 22:43 - 2017-09-05 06:43 - 000359560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
    2017-09-17 22:43 - 2017-09-05 06:43 - 000280480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
    2017-09-17 22:43 - 2017-09-05 06:43 - 000169376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
    2017-09-17 22:43 - 2017-09-05 06:43 - 000042456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbs.dll
    2017-09-17 22:43 - 2017-09-05 06:42 - 000703056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
    2017-09-17 22:43 - 2017-09-05 06:42 - 000291904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
    2017-09-17 22:43 - 2017-09-05 06:41 - 001106904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
    2017-09-17 22:43 - 2017-09-05 06:41 - 001013912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
    2017-09-17 22:43 - 2017-09-05 06:40 - 000052768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidapi.dll
    2017-09-17 22:43 - 2017-09-05 06:28 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
    2017-09-17 22:43 - 2017-09-05 06:28 - 000039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\buttonconverter.sys
    2017-09-17 22:43 - 2017-09-05 06:27 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmCx.sys
    2017-09-17 22:43 - 2017-09-05 06:26 - 000404480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
    2017-09-17 22:43 - 2017-09-05 06:26 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthpan.sys
    2017-09-17 22:43 - 2017-09-05 06:26 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidbth.sys
    2017-09-17 22:43 - 2017-09-05 06:26 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
    2017-09-17 22:43 - 2017-09-05 06:25 - 001448960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
    2017-09-17 22:43 - 2017-09-05 06:25 - 000293376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
    2017-09-17 22:43 - 2017-09-05 06:25 - 000154624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
    2017-09-17 22:43 - 2017-09-05 06:24 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcrecovery.dll
    2017-09-17 22:43 - 2017-09-05 06:24 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
    2017-09-17 22:43 - 2017-09-05 06:23 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
    2017-09-17 22:43 - 2017-09-05 06:22 - 000742912 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
    2017-09-17 22:43 - 2017-09-05 06:22 - 000640512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
    2017-09-17 22:43 - 2017-09-05 06:22 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
    2017-09-17 22:43 - 2017-09-05 06:22 - 000274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
    2017-09-17 22:43 - 2017-09-05 06:22 - 000165888 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
    2017-09-17 22:43 - 2017-09-05 06:21 - 001178624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
    2017-09-17 22:43 - 2017-09-05 06:21 - 000312320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll
    2017-09-17 22:43 - 2017-09-05 06:21 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srpapi.dll
    2017-09-17 22:43 - 2017-09-05 06:21 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
    2017-09-17 22:43 - 2017-09-05 06:21 - 000062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntprint.exe
    2017-09-17 22:43 - 2017-09-05 06:20 - 000805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
    2017-09-17 22:43 - 2017-09-05 06:20 - 000546816 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
    2017-09-17 22:43 - 2017-09-05 06:19 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntprint.dll
    2017-09-17 22:43 - 2017-09-05 06:19 - 000181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authz.dll
    2017-09-17 22:43 - 2017-09-05 06:19 - 000134656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dinput.dll
    2017-09-17 22:43 - 2017-09-05 06:19 - 000124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
    2017-09-17 22:43 - 2017-09-05 06:19 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
    2017-09-17 22:43 - 2017-09-05 06:18 - 000524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll
    2017-09-17 22:43 - 2017-09-05 06:18 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
    2017-09-17 22:43 - 2017-09-05 06:18 - 000452608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasplap.dll
    2017-09-17 22:43 - 2017-09-05 06:18 - 000266240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
    2017-09-17 22:43 - 2017-09-05 06:18 - 000175104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dinput8.dll
    2017-09-17 22:43 - 2017-09-05 06:18 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasman.dll
    2017-09-17 22:43 - 2017-09-05 06:17 - 000918528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
    2017-09-17 22:43 - 2017-09-05 06:17 - 000852480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasgcw.dll
    2017-09-17 22:43 - 2017-09-05 06:17 - 000586240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
    2017-09-17 22:43 - 2017-09-05 06:16 - 000844288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
    2017-09-17 22:43 - 2017-09-05 06:16 - 000563200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
    2017-09-17 22:43 - 2017-09-05 06:16 - 000358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
    2017-09-17 22:43 - 2017-09-05 06:16 - 000257024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Phoneutil.dll
    2017-09-17 22:43 - 2017-09-05 06:15 - 000636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
    2017-09-17 22:43 - 2017-09-05 06:15 - 000430592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
    2017-09-17 22:43 - 2017-09-05 06:15 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shdocvw.dll
    2017-09-17 22:43 - 2017-09-05 06:14 - 002516480 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
    2017-09-17 22:43 - 2017-09-05 06:14 - 001046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
    2017-09-17 22:43 - 2017-09-05 06:14 - 000754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
    2017-09-17 22:43 - 2017-09-05 06:14 - 000476160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
    2017-09-17 22:43 - 2017-09-05 06:13 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
    2017-09-17 22:43 - 2017-09-05 06:11 - 001463296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
    2017-09-17 22:43 - 2017-09-05 06:10 - 000761344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
    2017-09-17 22:43 - 2017-09-05 06:10 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthHFSrv.dll
    2017-09-17 22:43 - 2017-09-05 06:06 - 000221696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wisp.dll
    2017-09-17 22:42 - 2017-09-05 07:31 - 000750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
    2017-09-17 22:42 - 2017-09-05 07:26 - 001930840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
    2017-09-17 22:42 - 2017-09-05 07:25 - 000159648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
    2017-09-17 22:42 - 2017-09-05 07:24 - 000923040 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
    2017-09-17 22:42 - 2017-09-05 07:23 - 001242528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
    2017-09-17 22:42 - 2017-09-05 07:18 - 002972552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
    2017-09-17 22:42 - 2017-09-05 07:18 - 002647224 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2017-09-17 22:42 - 2017-09-05 07:18 - 000212384 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
    2017-09-17 22:42 - 2017-09-05 07:17 - 000316320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
    2017-09-17 22:42 - 2017-09-05 07:16 - 000715168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
    2017-09-17 22:42 - 2017-09-05 07:16 - 000410168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
    2017-09-17 22:42 - 2017-09-05 07:16 - 000182688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
    2017-09-17 22:42 - 2017-09-05 07:15 - 003116184 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
    2017-09-17 22:42 - 2017-09-05 07:14 - 004708504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
    2017-09-17 22:42 - 2017-09-05 07:14 - 001146176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
    2017-09-17 22:42 - 2017-09-05 07:14 - 000958664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
    2017-09-17 22:42 - 2017-09-05 07:14 - 000254176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
    2017-09-17 22:42 - 2017-09-05 07:11 - 000610720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
    2017-09-17 22:42 - 2017-09-05 07:11 - 000387936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
    2017-09-17 22:42 - 2017-09-05 06:53 - 001620880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
    2017-09-17 22:42 - 2017-09-05 06:30 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
    2017-09-17 22:42 - 2017-09-05 06:30 - 000093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
    2017-09-17 22:42 - 2017-09-05 06:30 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
    2017-09-17 22:42 - 2017-09-05 06:29 - 000037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SEMgrPS.dll
    2017-09-17 22:42 - 2017-09-05 06:27 - 000095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
    2017-09-17 22:42 - 2017-09-05 06:27 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\datamarketsvc.dll
    2017-09-17 22:42 - 2017-09-05 06:27 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
    2017-09-17 22:42 - 2017-09-05 06:26 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntprint.exe
    2017-09-17 22:42 - 2017-09-05 06:26 - 000022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnpinst.exe
    2017-09-17 22:42 - 2017-09-05 06:25 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nsiproxy.sys
    2017-09-17 22:42 - 2017-09-05 06:24 - 000457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
    2017-09-17 22:42 - 2017-09-05 06:24 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntprint.dll
    2017-09-17 22:42 - 2017-09-05 06:24 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
    2017-09-17 22:42 - 2017-09-05 06:23 - 000305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
    2017-09-17 22:42 - 2017-09-05 06:23 - 000140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
    2017-09-17 22:42 - 2017-09-05 06:22 - 000477696 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasplap.dll
    2017-09-17 22:42 - 2017-09-05 06:22 - 000388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
    2017-09-17 22:42 - 2017-09-05 06:22 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
    2017-09-17 22:42 - 2017-09-05 06:22 - 000173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetpp.dll
    2017-09-17 22:42 - 2017-09-05 06:21 - 001051136 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
    2017-09-17 22:42 - 2017-09-05 06:21 - 000946688 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasgcw.dll
    2017-09-17 22:42 - 2017-09-05 06:21 - 000422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
    2017-09-17 22:42 - 2017-09-05 06:20 - 007337472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
    2017-09-17 22:42 - 2017-09-05 06:20 - 001878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
    2017-09-17 22:42 - 2017-09-05 06:20 - 000412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
    2017-09-17 22:42 - 2017-09-05 06:20 - 000282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
    2017-09-17 22:42 - 2017-09-05 06:20 - 000229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
    2017-09-17 22:42 - 2017-09-05 06:19 - 001085440 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
    2017-09-17 22:42 - 2017-09-05 06:18 - 002078720 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
    2017-09-17 22:42 - 2017-09-05 06:18 - 000921600 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
    2017-09-17 22:42 - 2017-09-05 06:18 - 000874496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
    2017-09-17 22:42 - 2017-09-05 06:18 - 000864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
    2017-09-17 22:42 - 2017-09-05 06:18 - 000832000 _____ (Microsoft Corporation) C:\WINDOWS\system32\printfilterpipelinesvc.exe
    2017-09-17 22:42 - 2017-09-05 06:18 - 000803328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
    2017-09-17 22:42 - 2017-09-05 06:18 - 000752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
    2017-09-17 22:42 - 2017-09-05 06:18 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
    2017-09-17 22:42 - 2017-09-05 06:18 - 000257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
    2017-09-17 22:42 - 2017-09-05 06:18 - 000176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
    2017-09-17 22:42 - 2017-09-05 06:18 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
    2017-09-17 22:42 - 2017-09-05 06:17 - 000757760 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
    2017-09-17 22:42 - 2017-09-05 06:15 - 004396032 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
    2017-09-17 22:42 - 2017-09-05 06:15 - 003059200 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
    2017-09-17 22:42 - 2017-09-05 06:15 - 001143296 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
    2017-09-17 22:42 - 2017-09-05 06:15 - 001077248 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
    2017-09-17 22:42 - 2017-09-05 06:15 - 000706560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
    2017-09-17 22:42 - 2017-09-05 06:15 - 000664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
    2017-09-17 22:42 - 2017-09-05 06:15 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
    2017-09-17 22:42 - 2017-09-05 06:14 - 002177024 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
    2017-09-17 22:42 - 2017-09-05 06:14 - 002006528 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
    2017-09-17 22:42 - 2017-09-05 06:14 - 001657344 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
    2017-09-17 22:42 - 2017-09-05 06:14 - 001583616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
    2017-09-17 22:42 - 2017-09-05 06:14 - 000827904 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
    2017-09-17 22:42 - 2017-09-05 06:13 - 002009600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
    2017-09-17 22:42 - 2017-09-05 06:07 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\RstrtMgr.dll
    2017-09-17 22:42 - 2017-09-05 06:07 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll
    2017-09-17 22:42 - 2017-09-05 06:06 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
    2017-09-17 22:42 - 2017-09-01 07:55 - 000031932 _____ C:\WINDOWS\system32\edgehtmlpluginpolicy.bin
    2017-09-17 22:41 - 2017-09-05 07:31 - 000115792 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
    2017-09-17 22:41 - 2017-09-05 07:23 - 004462120 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupapi.dll
    2017-09-17 22:41 - 2017-09-05 07:20 - 001057824 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
    2017-09-17 22:41 - 2017-09-05 07:18 - 001668344 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
    2017-09-17 22:41 - 2017-09-05 07:18 - 000685512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
    2017-09-17 22:41 - 2017-09-05 07:16 - 001320344 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
    2017-09-17 22:41 - 2017-09-05 07:16 - 000872472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
    2017-09-17 22:41 - 2017-09-05 07:16 - 000049720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbs.dll
    2017-09-17 22:41 - 2017-09-05 07:15 - 000871448 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
    2017-09-17 22:41 - 2017-09-05 07:15 - 000381824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
    2017-09-17 22:41 - 2017-09-05 07:13 - 001619816 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
    2017-09-17 22:41 - 2017-09-05 07:13 - 000064680 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidapi.dll
    2017-09-17 22:41 - 2017-09-05 06:30 - 001639936 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
    2017-09-17 22:41 - 2017-09-05 06:30 - 001275904 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
    2017-09-17 22:41 - 2017-09-05 06:30 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
    2017-09-17 22:41 - 2017-09-05 06:30 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
    2017-09-17 22:41 - 2017-09-05 06:30 - 000447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
    2017-09-17 22:41 - 2017-09-05 06:30 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrvext.dll
    2017-09-17 22:41 - 2017-09-05 06:27 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\CfgSPCellular.dll
    2017-09-17 22:41 - 2017-09-05 06:27 - 000131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAPNCsp.dll
    2017-09-17 22:41 - 2017-09-05 06:26 - 000499712 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
    2017-09-17 22:41 - 2017-09-05 06:26 - 000156160 _____ (Microsoft Corporation) C:\WINDOWS\system32\csplte.dll
    2017-09-17 22:41 - 2017-09-05 06:26 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
    2017-09-17 22:41 - 2017-09-05 06:26 - 000124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxm.dll
    2017-09-17 22:41 - 2017-09-05 06:25 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
    2017-09-17 22:41 - 2017-09-05 06:24 - 000385536 _____ (Microsoft Corporation) C:\WINDOWS\system32\tpmvsc.dll
    2017-09-17 22:41 - 2017-09-05 06:24 - 000274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\authz.dll
    2017-09-17 22:41 - 2017-09-05 06:24 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dinput.dll
    2017-09-17 22:41 - 2017-09-05 06:24 - 000109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\dab.dll
    2017-09-17 22:41 - 2017-09-05 06:23 - 000739840 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
    2017-09-17 22:41 - 2017-09-05 06:23 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
    2017-09-17 22:41 - 2017-09-05 06:23 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
    2017-09-17 22:41 - 2017-09-05 06:23 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasman.dll
    2017-09-17 22:41 - 2017-09-05 06:22 - 000413184 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
    2017-09-17 22:41 - 2017-09-05 06:22 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\RasMediaManager.dll
    2017-09-17 22:41 - 2017-09-05 06:22 - 000213504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dinput8.dll
    2017-09-17 22:41 - 2017-09-05 06:21 - 000773120 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
    2017-09-17 22:41 - 2017-09-05 06:21 - 000691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
    2017-09-17 22:41 - 2017-09-05 06:20 - 000925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
    2017-09-17 22:41 - 2017-09-05 06:19 - 001260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
    2017-09-17 22:41 - 2017-09-05 06:19 - 001028608 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
    2017-09-17 22:41 - 2017-09-05 06:19 - 000996864 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
    2017-09-17 22:41 - 2017-09-05 06:19 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
    2017-09-17 22:41 - 2017-09-05 06:19 - 000243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll
    2017-09-17 22:41 - 2017-09-05 06:18 - 000922112 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
    2017-09-17 22:41 - 2017-09-05 06:18 - 000564736 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
    2017-09-17 22:41 - 2017-09-05 06:16 - 002680320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
    2017-09-17 22:41 - 2017-09-05 06:16 - 000440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.immersiveshell.serviceprovider.dll
    2017-09-17 22:41 - 2017-09-05 06:16 - 000397312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
    2017-09-17 22:41 - 2017-09-05 06:15 - 001736704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
    2017-09-17 22:41 - 2017-09-05 06:15 - 001293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
    2017-09-17 22:41 - 2017-09-05 06:14 - 000810496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
    2017-09-17 22:41 - 2017-09-05 06:12 - 002153984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
    2017-09-17 22:41 - 2017-09-05 06:11 - 000254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
    2017-09-17 22:41 - 2017-09-05 06:09 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wisp.dll

    ==================== Un mois - Modifiés - fichiers et dossiers ========

    (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

    2017-10-13 14:46 - 2017-07-17 23:03 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
    2017-10-13 13:02 - 2015-05-24 22:10 - 000000000 ____D C:\ProgramData\Kaspersky Lab
    2017-10-13 12:54 - 2017-07-17 23:25 - 000004172 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{C09C8021-3C2E-4E06-9463-AAC8900F95DD}
    2017-10-13 06:41 - 2017-07-17 23:25 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2017-10-13 06:40 - 2017-03-18 13:40 - 000524288 _____ C:\WINDOWS\system32\config\BBI
    2017-10-12 07:48 - 2017-03-18 23:03 - 000000000 ___HD C:\Program Files\WindowsApps
    2017-10-12 07:48 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\AppReadiness
    2017-10-12 07:45 - 2017-03-18 23:01 - 000000000 ____D C:\WINDOWS\INF
    2017-10-11 18:26 - 2016-04-27 07:50 - 000000000 __RHD C:\Users\Public\AccountPictures
    2017-10-11 17:51 - 2017-07-17 23:06 - 002989894 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2017-10-11 17:51 - 2017-03-20 07:10 - 001384304 _____ C:\WINDOWS\system32\perfh00C.dat
    2017-10-11 17:51 - 2017-03-20 07:10 - 000334738 _____ C:\WINDOWS\system32\perfc00C.dat
    2017-10-11 17:47 - 2017-07-17 23:03 - 000338896 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2017-10-11 17:44 - 2017-03-18 23:03 - 000230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
    2017-10-11 17:44 - 2017-03-18 23:03 - 000207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
    2017-10-11 17:44 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\ShellExperiences
    2017-10-11 17:44 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\Provisioning
    2017-10-11 09:32 - 2017-03-18 22:51 - 000000000 ____D C:\WINDOWS\CbsTemp
    2017-10-10 15:07 - 2014-11-14 10:46 - 000192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
    2017-10-10 14:20 - 2011-11-05 20:30 - 126925120 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2017-10-07 17:22 - 2017-03-18 13:40 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
    2017-10-07 17:16 - 2016-06-28 14:44 - 000000000 ____D C:\Users\richard\AppData\Local\Packages
    2017-10-07 17:05 - 2016-12-12 12:08 - 000000000 ____D C:\Users\richard\AppData\LocalLow\Mozilla
    2017-10-07 16:33 - 2016-07-16 13:47 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
    2017-10-07 12:47 - 2013-11-28 12:41 - 000001255 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk
    2017-10-07 12:47 - 2013-11-28 12:41 - 000001243 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk
    2017-10-07 07:20 - 2016-12-12 12:08 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2017-10-07 07:20 - 2013-03-25 11:29 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2017-10-06 16:39 - 2011-03-20 16:03 - 000544424 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
    2017-10-06 15:55 - 2017-07-15 18:51 - 000000000 ___DC C:\WINDOWS\Panther
    2017-10-06 15:55 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\LiveKernelReports
    2017-10-06 15:48 - 2014-09-14 21:39 - 000000000 ____D C:\Users\richard\AppData\Local\Adobe
    2017-10-06 15:47 - 2017-07-17 23:25 - 000004546 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
    2017-10-06 15:47 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
    2017-10-06 15:47 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\system32\Macromed
    2017-10-06 15:46 - 2015-03-11 16:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
    2017-10-06 15:46 - 2015-03-11 16:18 - 000000000 ____D C:\ProgramData\Oracle
    2017-10-06 15:46 - 2011-03-20 20:21 - 000000000 ____D C:\Program Files (x86)\Java
    2017-10-06 15:41 - 2015-03-11 16:20 - 000097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
    2017-10-03 20:07 - 2013-07-18 13:54 - 000000000 ____D C:\Users\richard\AppData\Roaming\Dropbox
    2017-09-28 21:19 - 2014-01-03 11:34 - 000000000 ____D C:\Users\richard\AppData\LocalLow\Adblock Plus for IE
    2017-09-27 20:58 - 2017-07-17 23:07 - 000000000 ____D C:\Users\richard
    2017-09-20 13:13 - 2014-12-13 18:21 - 001001976 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klif.sys
    2017-09-20 07:00 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\rescache
    2017-09-19 20:16 - 2017-07-25 18:42 - 000003372 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3844302631-3143525539-2212018275-1001
    2017-09-19 20:16 - 2016-06-28 14:49 - 000002461 _____ C:\Users\richard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2017-09-19 20:16 - 2016-06-28 14:49 - 000000000 ___RD C:\Users\richard\OneDrive
    2017-09-17 23:12 - 2017-03-20 07:10 - 000000000 ____D C:\WINDOWS\system32\fr
    2017-09-17 23:12 - 2017-03-18 23:03 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
    2017-09-17 23:12 - 2017-03-18 23:03 - 000000000 ___SD C:\WINDOWS\system32\F12
    2017-09-17 23:12 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
    2017-09-17 23:12 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
    2017-09-17 23:12 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\system32\setup
    2017-09-17 23:11 - 2017-03-18 23:03 - 000000000 ____D C:\Program Files\Windows Photo Viewer
    2017-09-17 23:11 - 2017-03-18 23:03 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
    2017-09-17 22:56 - 2013-08-15 21:40 - 000000000 ____D C:\WINDOWS\system32\MRT

    ==================== Fichiers à la racine de certains dossiers =======

    2013-02-11 18:52 - 2013-02-11 18:52 - 000000268 ___RH () C:\Users\richard\AppData\Roaming\Compressor
    2013-02-11 18:52 - 2013-02-11 18:52 - 000000268 ___RH () C:\Users\richard\AppData\Roaming\Conditionals
    2013-02-11 18:52 - 2013-02-11 18:52 - 000000268 ___RH () C:\Users\richard\AppData\Roaming\Configure Folder Actions
    2013-02-11 18:51 - 2013-02-11 18:51 - 000000268 ___RH () C:\Users\richard\AppData\Roaming\Developer Tools
    2013-10-12 19:27 - 2013-10-12 19:27 - 000006216 _____ () C:\Users\richard\AppData\Roaming\mbam.context.scan
    2017-10-07 23:34 - 2017-10-07 23:34 - 000142788 _____ () C:\Users\richard\AppData\Local\ars.cache
    2017-10-07 23:34 - 2017-10-07 23:34 - 000359721 _____ () C:\Users\richard\AppData\Local\census.cache
    2011-03-30 07:38 - 2013-05-15 10:25 - 000017408 _____ () C:\Users\richard\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2017-10-07 16:54 - 2017-10-07 16:54 - 000000036 _____ () C:\Users\richard\AppData\Local\housecall.guid.cache
    2012-10-10 18:11 - 2012-10-10 18:11 - 000001002 _____ () C:\Users\richard\AppData\Local\recently-used.xbel
    2010-09-27 04:29 - 2010-09-27 04:37 - 000014178 _____ () C:\ProgramData\ArcadeDeluxe4.log
    2013-02-11 18:52 - 2013-02-11 18:52 - 000000268 ___RH () C:\ProgramData\Contents
    2013-02-11 18:52 - 2013-02-11 18:52 - 000000268 ___RH () C:\ProgramData\Contextual Menu Items
    2013-02-11 18:52 - 2013-02-11 18:52 - 000000268 ___RH () C:\ProgramData\Core Data Application
    2013-02-11 18:51 - 2013-02-11 18:51 - 000000268 ___RH () C:\ProgramData\Digital Basic
    2010-05-22 05:44 - 2010-01-27 16:40 - 000131472 _____ () C:\ProgramData\FullRemove.exe
    2013-02-11 18:51 - 2013-02-11 18:51 - 000000020 ____H () C:\ProgramData\PKP_DLeo.DAT
    2013-02-11 18:52 - 2013-04-06 14:28 - 000000020 ____H () C:\ProgramData\PKP_DLes.DAT
    2013-02-11 18:52 - 2015-10-24 18:30 - 000000020 ____H () C:\ProgramData\PKP_DLet.DAT
    2013-02-11 18:52 - 2013-04-06 14:20 - 000000020 ____H () C:\ProgramData\PKP_DLev.DAT
    2010-09-27 04:33 - 2010-09-27 04:34 - 000000032 _____ () C:\ProgramData\PS.log

    Fichiers à déplacer ou supprimer:
    ====================
    C:\Users\richard\setup.exe


    ==================== Bamital & volsnap ======================

    (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

    C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement
    C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement
    C:\WINDOWS\explorer.exe => Le fichier est signé numériquement
    C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement
    C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement
    C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement
    C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement
    C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement
    C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement
    C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement
    C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement
    C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement
    C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement
    C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
    C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement

    LastRegBack: 2017-10-07 23:36

    ==================== Fin de FRST.txt ============================

  4. #4
    Member
    Join Date
    Oct 2017
    Posts
    4
    Points
    0

    Default

    Quote Originally Posted by DonnaB View Post
    Hi B_Richard,

    Welcome to Help2Go!

    My name is Donna and I will reviewing your logs.

    Let's see what Farbar Recovery Scan Tool finds, if anything. If you need to use Safe Mode with Networking that is fine.

    Please download Farbar Recovery Scan Tool and save it to your desktop. <<< Very Important!

    Note: You will need to run the 64-bit version.

    • Make sure that FRST is on the desktop of the infected system
    • Right click and choose Run as administrator. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will produce a log called FRST.txt in the same directory the tool is run from.
    • Please copy and paste log back here.
    • The first time the tool is run it generates a second log (Addition.txt - also located in the same directory as FRST64.exe. Please also paste that along with the FRST.txt into your reply.


    Since the logs generated on Windows 10 are so long, you may need post them in separate posts. Please do so.
    ------------------------- log file 2 Addition.TXT ----------------------
    Résultats de l'Analyse supplémentaire de Farbar Recovery Scan Tool (x64) Version: 11-10-2017
    Exécuté par richard (13-10-2017 14:53:22)
    Exécuté depuis C:\Users\richard\Desktop
    Windows 10 Home Version 1703 170317-1834 (X64) (2017-07-17 21:36:38)
    Mode d'amorçage: Normal
    ==========================================================


    ==================== Comptes: =============================

    Administrateur (S-1-5-21-3844302631-3143525539-2212018275-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-3844302631-3143525539-2212018275-503 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-3844302631-3143525539-2212018275-1002 - Limited - Enabled)
    Invité (S-1-5-21-3844302631-3143525539-2212018275-501 - Limited - Disabled) => C:\Users\Invité
    NeroMediaHomeUser.4 (S-1-5-21-3844302631-3143525539-2212018275-1003 - Limited - Enabled) => C:\Users\NeroMediaHomeUser.4
    richard (S-1-5-21-3844302631-3143525539-2212018275-1001 - Administrator - Enabled) => C:\Users\richard

    ==================== Centre de sécurité ========================

    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.)

    AV: Suite de Sécurité Orange (Disabled - Up to date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Suite de Sécurité Orange (Disabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    FW: Suite de Sécurité Orange (Disabled) {BE0DF4B4-018B-AF50-0486-D6FE7C8A8AE3}

    ==================== Programmes installés ======================

    (Seuls les logiciels publicitaires ('adware') avec la marque 'caché' ('Hidden') sont susceptibles d'être ajoutés au fichier fixlist.txt pour qu'ils ne soient plus masqués. Les programmes publicitaires devront être désinstallés manuellement.)

    Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3007 - Acer Incorporated)
    Acer GameZone Console (HKLM-x32\...\{ABEE079E-648E-488B-8301-0C3DB48C1BCE}_is1) (Version: 6.1.0.2 - Oberon Media, Inc.)
    Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0812 - Acer Incorporated)
    Acer TouchCam (HKLM-x32\...\{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.0.2624 - CyberLink Corp.) Hidden
    Acer TouchPortal (HKLM-x32\...\{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version: 4.2.7803 - CyberLink Corp.) Hidden
    Acer TouchPortal (HKLM-x32\...\{B906C11A-D193-4143-9FA7-E2EE8A5A8F21}) (Version: 9.0.6531 - CyberLink Corp.) Hidden
    Acer TouchPortal (HKLM-x32\...\{C652F86F-348A-4A65-8BE8-A3F7A6370D98}) (Version: 2.00.3003 - Acer Incorporated)
    Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
    Adblock Plus for IE (HKLM-x32\...\{fd97d1e2-368a-4cd9-af63-8eeff938044a}) (Version: 1.1 - )
    Adblock Plus pour IE (32-bits et 64-bits) (HKLM\...\{1C9A24E0-CA21-414D-8D21-22BF8981FC9F}) (Version: 1.5 - Eyeo GmbH)
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
    Adobe Flash Player 27 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 27.0.0.130 - Adobe Systems Incorporated)
    Adobe Reader 9.5.5 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
    Advertising Center (HKLM-x32\...\{B2EC4A38-B545-4A00-8214-13FE0E915E6D}) (Version: 0.0.0.2 - Nero AG) Hidden
    Assistant de connexion Windows Live (HKLM-x32\...\{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}) (Version: 5.000.818.5 - Microsoft Corporation)
    Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - )
    Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: - )
    Canon MG5100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5100_series) (Version: - )
    Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version: - )
    Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - )
    Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version: - )
    CCleaner (HKLM\...\CCleaner) (Version: 5.35 - Piriform)
    Dropbox (HKU\S-1-5-21-3844302631-3143525539-2212018275-1001\...\Dropbox) (Version: 36.4.22 - Dropbox, Inc.)
    Enregistrement utilisateur de Canon MG5100 series (HKLM-x32\...\Enregistrement utilisateur de Canon MG5100 series) (Version: - )
    Galerie de photos Windows Live (HKLM-x32\...\{B131E59D-202C-43C6-84C9-68F0C37541F1}) (Version: 14.0.8081.709 - Microsoft Corporation) Hidden
    Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
    Hotkey Utility (HKLM-x32\...\Hotkey Utility) (Version: 2.05.3003 - Acer Incorporated)
    Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3003 - Acer Incorporated)
    ImagXpress (HKLM-x32\...\{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}) (Version: 7.0.74.0 - Nero AG) Hidden
    Installation Windows Live (HKLM-x32\...\{46ABBC54-1872-4AA3-95E2-F2C063A63F31}) (Version: 14.0.8089.726 - Microsoft Corporation) Hidden
    Installation Windows Live (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
    Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
    Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2102 - Intel Corporation)
    ITECIR (HKLM-x32\...\{40580068-9B10-40B5-9548-536CE88AB23C}) (Version: 1.00.0000 - ITE)
    Java 8 Update 144 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180144F0}) (Version: 8.0.1440.1 - Oracle Corporation)
    JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.33.2 - JMicron Technology Corp.)
    Junk Mail filter update (HKLM-x32\...\{E2DFE069-083E-4631-9B6C-43C48E991DE5}) (Version: 14.0.8089.726 - Microsoft Corporation) Hidden
    Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
    MediaShow Espresso (HKLM-x32\...\{4968622A-4D3F-489E-9ACE-5FEC4CC0BDE3}) (Version: 5.5.1422_24072 - CyberLink Corp.) Hidden
    Microsoft Office Famille et Étudiant 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
    Microsoft OneDrive (HKU\S-1-5-21-3844302631-3143525539-2212018275-1001\...\OneDriveSetup.exe) (Version: 17.3.6998.0830 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Touch Pack for Windows 7 (HKLM-x32\...\{8FF90DB8-6DED-44A3-B182-244FEC09012F}) (Version: 1.0.40517.00 - Microsoft Corporation)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
    Microsoft XNA Framework Redistributable 3.0 (HKLM-x32\...\{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}) (Version: 3.0.11010.0 - Microsoft Corporation)
    Module linguistique Microsoft Visual Studio 2010 Tools pour Office Runtime (x64) - FRA (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - FRA) (Version: 10.0.50903 - Microsoft Corporation)
    Mozilla Firefox 56.0 (x86 fr) (HKLM-x32\...\Mozilla Firefox 56.0 (x86 fr)) (Version: 56.0 - Mozilla)
    Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 52.3.0 - Mozilla)
    Mozilla Thunderbird 52.3.0 (x86 fr) (HKLM-x32\...\Mozilla Thunderbird 52.3.0 (x86 fr)) (Version: 52.3.0 - Mozilla)
    MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    MyWinLocker (HKLM-x32\...\{0D7CD0D9-4A88-4A63-8F91-3F4E8F371768}) (Version: 3.1.210.0 - Egis Technology Inc.) Hidden
    MyWinLocker Suite (HKLM-x32\...\{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}) (Version: 3.1.210.0 - Egis Technology Inc.) Hidden
    MyWinLocker Suite (HKLM-x32\...\InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}) (Version: 3.1.210.0 - Egis Technology Inc.)
    Nero 9 Essentials (HKLM-x32\...\{9d48c9c1-0e14-48fe-a1ab-1e9091067835}) (Version: - Nero AG)
    Nero MediaHome 4 Essentials (HKLM-x32\...\{afac7cad-bf1d-4c56-807d-c015e32dd050}) (Version: - Nero AG)
    Nikon Message Center 2 (HKLM-x32\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon)
    Nikon Movie Editor (HKLM-x32\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.6.0 - Nikon)
    OpenOffice.org 3.4.1 (HKLM-x32\...\{7DA1C06F-C913-46C7-8A0F-DA2CBA17EA1D}) (Version: 3.41.9593 - Apache Software Foundation)
    Orange WebTV Player 1.29418 (HKLM-x32\...\Orange WebTV Player_is1) (Version: - Orange)
    Outil de téléchargement Windows Live (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
    PDF Architect (HKLM-x32\...\{80A07844-CA64-4DE4-AB61-D37DDBE8074F}) (Version: 1.0.52.8917 - pdfforge)
    PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.6.2 - pdfforge)
    Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
    Picture Control Utility x64 (HKLM\...\{11953C65-BB4E-4CA4-B0F0-2600A4B20040}) (Version: 1.4.7 - Nikon)
    Realtek 8136 8168 8169 Ethernet Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0005 - Realtek)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5901 - Realtek Semiconductor Corp.)
    Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
    Shredder (HKLM\...\{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}) (Version: 2.0.8.3 - Egis Technology Inc.) Hidden
    Shredder (HKLM-x32\...\{C2695E83-CF1D-43D1-84FE-B3BEC561012A}) (Version: 2.0.8.3 - Egis Technology Inc.) Hidden
    Skype™ 7.12 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.12.101 - Skype Technologies S.A.)
    Suite de Sécurité Orange (HKLM-x32\...\{F575F386-57EF-4943-B003-A13F13B05EEB}) (Version: 16.0.1.445 - Orange) Hidden
    Suite de Sécurité Orange (HKLM-x32\...\InstallWIX_{F575F386-57EF-4943-B003-A13F13B05EEB}) (Version: 16.0.1.445 - Orange)
    SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1248 - SUPERAntiSpyware.com)
    TeamViewer 8 (HKLM-x32\...\TeamViewer 8) (Version: 8.0.44109 - TeamViewer)
    TouchSettings (HKLM-x32\...\{75880CD4-9436-4EDD-B7E7-400EBFD60B2C}) (Version: 1.00.0005 - Acer Incorporated)
    ViewNX 2 (HKLM\...\{635BE602-BB9C-4C59-8CC5-93F9366E8A21}) (Version: 2.6.0 - Nikon)
    Virtual Earth 3D (Beta) (HKLM\...\{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}) (Version: 4.0.903.16005 - Microsoft Corporation)
    Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.)
    Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.00.3013 - Acer Incorporated)
    WIDCOMM Bluetooth Software (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.0.9600 - Broadcom Corporation)
    Windows 10 Update and Privacy Settings (HKLM\...\{4DFCD818-036A-4229-A67D-CF17DC461D92}) (Version: 1.0.14.0 - Microsoft Corporation)
    XnView 1.99.1 (HKLM-x32\...\XnView_is1) (Version: 1.99.1 - Gougelet Pierre-e)

    ==================== Personnalisé CLSID (Avec liste blanche): ==========================

    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

    CustomCLSID: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\richard\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3844302631-3143525539-2212018275-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll [2010-04-17] (Egis Technology Inc.)
    ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll [2010-04-17] (Egis Technology Inc.)
    ContextMenuHandlers1: [EDSshellExt] -> {29FF7AB0-BE34-4992-A30B-53A9D86EE239} => C:\Program Files (x86)\EgisTec MyWinLocker\x64\mwlshellext.dll [2010-04-17] (Egis Technology Inc.)
    ContextMenuHandlers1: [Kaspersky Anti-Virus 16.0.1] -> {7E2FE095-E536-4F69-AC17-997E9EAEBD4D} => C:\Program Files (x86)\Orange\Orange Security Suite 10.10\x64\shellex.dll [2015-12-22] (AO Kaspersky Lab)
    ContextMenuHandlers1-x32: [PDFArchitectExtension] -> {DBDB3433-0E01-40CE-A026-D9F54FAC3CA9} => C:\Program Files (x86)\PDF Architect\ContextMenuExt.dll [2013-01-09] (pdfforge GbR)
    ContextMenuHandlers2: [Kaspersky Anti-Virus 16.0.1] -> {7E2FE095-E536-4F69-AC17-997E9EAEBD4D} => C:\Program Files (x86)\Orange\Orange Security Suite 10.10\x64\shellex.dll [2015-12-22] (AO Kaspersky Lab)
    ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes)
    ContextMenuHandlers3: [ShredderContextMenu] -> {521065F1-DE6C-4E46-BBCB-89B0D0BE860D} => C:\Program Files (x86)\EgisTec Shredder\x64\ShredderContextMenu.dll [2010-04-02] (Egis Technology Inc.)
    ContextMenuHandlers4: [EDSshellExt] -> {29FF7AB0-BE34-4992-A30B-53A9D86EE239} => C:\Program Files (x86)\EgisTec MyWinLocker\x64\mwlshellext.dll [2010-04-17] (Egis Technology Inc.)
    ContextMenuHandlers4: [Kaspersky Anti-Virus 16.0.1] -> {7E2FE095-E536-4F69-AC17-997E9EAEBD4D} => C:\Program Files (x86)\Orange\Orange Security Suite 10.10\x64\shellex.dll [2015-12-22] (AO Kaspersky Lab)
    ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> Pas de fichier
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Pas de fichier
    ContextMenuHandlers6: [Kaspersky Anti-Virus 16.0.1] -> {7E2FE095-E536-4F69-AC17-997E9EAEBD4D} => C:\Program Files (x86)\Orange\Orange Security Suite 10.10\x64\shellex.dll [2015-12-22] (AO Kaspersky Lab)
    ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes)
    ContextMenuHandlers1_S-1-5-21-3844302631-3143525539-2212018275-1001: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
    ContextMenuHandlers4_S-1-5-21-3844302631-3143525539-2212018275-1001: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)
    ContextMenuHandlers5_S-1-5-21-3844302631-3143525539-2212018275-1001: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\richard\AppData\Roaming\Dropbox\bin\DropboxExt64.18.0.dll [2017-10-03] (Dropbox, Inc.)

    ==================== Tâches planifiées (Avec liste blanche) =============

    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

    Task: {03D09402-A4F3-4192-8DD7-36193A20BE7A} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> Pas de fichier <==== ATTENTION
    Task: {0962DB04-75D4-45B7-A46B-11B5C06402C9} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3844302631-3143525539-2212018275-1001UA1d23728bf44c518 => C:\Users\richard\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-05] (Dropbox, Inc.)
    Task: {0AFFDBBB-597C-4D5B-9EBF-2049A3648420} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
    Task: {1519DCBC-5C78-4004-9480-1B65077D10BE} - \Microsoft\Windows\Setup\gwx\rundetector -> Pas de fichier <==== ATTENTION
    Task: {15B39C35-C18E-4D63-BEA1-602C3B9C0DDE} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Pas de fichier <==== ATTENTION
    Task: {1695C6D8-BD99-415C-B061-A5E21035D46C} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> Pas de fichier <==== ATTENTION
    Task: {1748E259-C5B3-485C-B4DD-8EB48AEB96D6} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
    Task: {1FDC66FD-7960-43C5-A4F2-0E83F4C29A8C} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Pas de fichier <==== ATTENTION
    Task: {210DA9B6-7064-4178-9B52-7A692C5AA790} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3844302631-3143525539-2212018275-1001Core1d23728bf1f3444 => C:\Users\richard\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-05] (Dropbox, Inc.)
    Task: {361AFF76-377F-47B0-AF5D-E897101BE2F7} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {3838360F-59D7-4866-AA81-7A643F88291D} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
    Task: {3A0ED166-710A-4F29-94DF-DD6285C7B951} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {3FB533AC-2AD7-4DC1-BA49-BE3904FC82FF} - System32\Tasks\{C31C31E5-91A2-4BFA-86C1-EAD0EB32C54E} => C:\Windows\system32\pcalua.exe -a C:\Users\richard\Desktop\OOo_3.3.0_Win_x86_install-wJRE_fr.exe -d C:\Users\richard\Desktop
    Task: {48B0B94B-CF4E-467D-9651-E15FD4C2B43D} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Pas de fichier <==== ATTENTION
    Task: {54B5C2E7-2F19-4FCE-B1B4-5FDDC1703C59} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {59C0F2ED-175C-4260-AA2B-7370F42897A0} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {5E735301-730F-485B-9ED4-06CF1AF0F647} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {5E9F7F82-96C9-4284-9213-1E95216A3B21} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {642AEB12-5F3B-4619-8A26-ED66E192998A} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
    Task: {6D1BB6DE-DD89-46BE-B963-3AB3CA2E7F4D} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
    Task: {6D5E2338-BB65-40E5-90A3-2B3FAFED09AA} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
    Task: {73E783F7-89F6-4400-8EF6-DF0FE3F1A2B4} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {7508701D-5E0D-4EF9-A935-EA6520D683C9} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
    Task: {79711BED-85AB-43E5-8683-AA9285224310} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
    Task: {7A80456F-F26B-4782-A2B5-101E809C6828} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Pas de fichier <==== ATTENTION
    Task: {7B2ACA2E-6768-499A-89EA-9EFC756A05BF} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
    Task: {84ABA0E8-9AA6-49B0-AECF-E3441C48C8F7} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {983B8C8C-48C6-4500-B4A1-11991372B3AC} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
    Task: {9AE6A012-8659-4A41-B292-73A3705DBA97} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Pas de fichier <==== ATTENTION
    Task: {A1E12B58-3454-41A1-A3A9-B1882DC0DCE1} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Pas de fichier <==== ATTENTION
    Task: {A9CB1BDE-1912-4DA1-A8AE-5C993952F268} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> Pas de fichier <==== ATTENTION
    Task: {ABB2CF2D-593E-4C2C-A6E9-9BF76C8363DF} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
    Task: {AC7B8741-56F7-4EAE-9ABF-06CAD90DF306} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {B1D069F1-1DF4-4F94-A286-3BF470BF2E20} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Pas de fichier <==== ATTENTION
    Task: {BCFF22C6-562F-4AF8-8F66-6EA09AE58957} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-09-20] (Piriform Ltd)
    Task: {CC5DB959-E9D4-438B-B5E0-7C2B2311D44E} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> Pas de fichier <==== ATTENTION
    Task: {D0C5F8CD-5941-4A30-9B35-65C5B847A8E0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {DAA2D1F9-7A60-47E4-BDA6-99C795526D7C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Pas de fichier <==== ATTENTION
    Task: {DAE74467-ACBA-4147-A452-6500AAFB82C1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-10-06] (Adobe Systems Incorporated)
    Task: {E08534E9-6943-4DE8-BCB3-588C9AC95018} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {E08A1396-1A6C-4066-AD05-19C936AFA38F} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
    Task: {E37773E1-E25E-40EA-9E0F-29AE83075976} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Pas de fichier <==== ATTENTION
    Task: {FB0797D9-4757-445B-87B7-D8D9D5701877} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> Pas de fichier <==== ATTENTION
    Task: {FD44CA82-53EE-47AF-841F-7DC62047842B} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Pas de fichier <==== ATTENTION
    Task: {FFCB187B-48EA-4FAE-A193-5A8B310ABB3F} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe

    (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.)

    Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
    Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3844302631-3143525539-2212018275-1001Core1d23728bf1f3444.job => C:\Users\richard\AppData\Local\Dropbox\Update\DropboxUpdate.exe
    Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3844302631-3143525539-2212018275-1001UA1d23728bf44c518.job => C:\Users\richard\AppData\Local\Dropbox\Update\DropboxUpdate.exe
    Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 63b7a601-b9d6-4e47-a703-c57b1ced9c04.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task c2139770-4bf2-4d2e-a928-129c1af2b24e.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    ==================== Raccourcis & WMI ========================

    (Les éléments sont susceptibles d'être inscrits dans le fichier fixlist.txt afin d'être supprimés ou restaurés.)


    ==================== Modules chargés (Avec liste blanche) ==============

    2017-03-18 22:58 - 2017-03-18 22:58 - 000138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
    2017-03-18 22:59 - 2017-03-20 07:11 - 001731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
    2017-09-17 20:35 - 2017-09-17 20:36 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11708.1001.30.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
    2017-10-05 05:56 - 2017-10-05 05:56 - 010634752 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11708.1001.30.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll
    2017-10-05 05:56 - 2017-10-05 05:56 - 002640896 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11708.1001.30.0_x64__8wekyb3d8bbwe\MS.Entertainment.Common.Mobile.dll
    2017-09-28 14:58 - 2017-09-28 14:59 - 026118656 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17082.14121.0_x64__8wekyb3d8bbwe\Video.UI.exe
    2017-09-28 14:58 - 2017-09-28 14:59 - 009162240 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17082.14121.0_x64__8wekyb3d8bbwe\EntCommon.dll
    2017-09-17 20:25 - 2017-09-17 20:25 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17082.14121.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
    2017-09-28 14:58 - 2017-09-28 14:59 - 011470848 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17082.14121.0_x64__8wekyb3d8bbwe\EntPlat.dll
    2015-12-22 03:47 - 2015-12-22 03:47 - 000794920 _____ () C:\Program Files (x86)\Orange\Orange Security Suite 10.10\kpcengine.2.3.dll
    2017-10-03 20:07 - 2017-10-03 12:21 - 000771904 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\dropbox_watchdog.dll
    2017-10-03 20:07 - 2017-10-03 12:21 - 001804608 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\dropbox_crashpad.dll
    2016-11-12 22:08 - 2017-10-03 12:21 - 000100296 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\_ctypes.pyd
    2015-12-11 14:09 - 2017-10-03 12:21 - 000018888 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\select.pyd
    2015-12-11 14:09 - 2017-10-03 12:22 - 000020800 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd
    2016-11-12 22:08 - 2017-10-03 12:21 - 000035792 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd
    2015-12-11 14:09 - 2017-10-03 12:21 - 000694224 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\unicodedata.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000021848 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd
    2016-11-12 22:08 - 2017-10-03 12:21 - 000130512 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 001856848 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000022864 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd
    2017-10-03 20:07 - 2017-10-03 12:21 - 000145864 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\pyexpat.pyd
    2017-10-03 20:07 - 2017-10-03 12:21 - 000116688 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\pywintypes27.dll
    2015-12-11 14:09 - 2017-10-03 12:21 - 000105928 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\win32api.pyd
    2016-11-12 22:08 - 2017-10-03 12:22 - 000022864 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\winffi.crt.compiled._winffi_crt.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000062784 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd
    2015-12-11 14:09 - 2017-10-03 12:21 - 000024528 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\win32event.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000040248 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\fastpath.pyd
    2017-10-03 20:07 - 2017-10-03 12:21 - 000020936 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\mmapfile.pyd
    2016-11-12 22:08 - 2017-10-03 12:21 - 000124880 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\win32file.pyd
    2016-11-12 22:08 - 2017-10-03 12:21 - 000116176 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\win32security.pyd
    2017-10-03 20:07 - 2017-10-03 12:21 - 000392656 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\pythoncom27.dll
    2015-12-11 14:09 - 2017-10-03 12:22 - 000392512 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd
    2016-11-12 22:08 - 2017-10-03 12:22 - 000026456 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\winffi.kernel32.compiled._winffi_kernel32.pyd
    2015-12-11 14:09 - 2017-10-03 12:21 - 000024016 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\win32clipboard.pyd
    2016-11-12 22:08 - 2017-10-03 12:21 - 000175560 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\win32gui.pyd
    2016-11-12 22:08 - 2017-10-03 12:21 - 000030160 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\win32pipe.pyd
    2016-11-12 22:08 - 2017-10-03 12:21 - 000043472 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\win32process.pyd
    2017-09-22 06:44 - 2017-10-03 12:21 - 000026056 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\win32job.pyd
    2016-11-12 22:08 - 2017-10-03 12:21 - 000048592 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\win32service.pyd
    2015-12-11 14:09 - 2017-10-03 12:21 - 000057808 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\win32evtlog.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000021824 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd
    2017-09-17 20:19 - 2017-10-03 12:22 - 000023368 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\winshell.compiled._winshell.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000022856 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\crashpad.compiled._Crashpad.pyd
    2017-05-17 20:33 - 2017-10-03 12:22 - 000066392 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\winenumhandles.compiled._WinEnumHandles.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 001796920 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd
    2015-12-11 14:09 - 2017-10-03 12:21 - 000084424 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\sip.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 001956152 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 003859264 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000154440 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineWidgets.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000521024 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000045888 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineCore.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000042304 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\PyQt5.QtWebChannel.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000131384 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000218944 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000204096 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd
    2016-11-12 22:08 - 2017-10-03 12:22 - 000025432 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd
    2016-11-12 22:08 - 2017-10-03 12:21 - 000060880 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\win32print.pyd
    2017-02-28 07:16 - 2017-10-03 12:22 - 000054608 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\winrpcserver.compiled._RPCServer.pyd
    2016-11-12 22:08 - 2017-10-03 12:21 - 000024016 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\win32profile.pyd
    2017-01-24 07:37 - 2017-10-03 12:22 - 000022864 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\winffi.user32.compiled._winffi_user32.pyd
    2016-11-12 22:08 - 2017-10-03 12:22 - 000069968 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\windisplaytoast.compiled._DisplayToast.pyd
    2016-11-12 22:08 - 2017-10-03 12:21 - 000028616 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\win32ts.pyd
    2017-01-24 07:37 - 2017-10-03 12:22 - 000022360 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\winffi.iphlpapi.compiled._winffi_iphlpapi.pyd
    2017-01-24 07:37 - 2017-10-03 12:22 - 000021848 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\winffi.winerror.compiled._winffi_winerror.pyd
    2017-01-24 07:37 - 2017-10-03 12:22 - 000022360 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\winffi.wininet.compiled._winffi_wininet.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000027488 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd
    2016-11-12 22:08 - 2017-10-03 12:21 - 000349128 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\winxpgui.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000101184 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\PyQt5.QtWinExtras.pyd
    2016-11-12 22:08 - 2017-10-03 12:22 - 000023896 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000025424 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd
    2017-10-03 20:07 - 2017-10-03 12:21 - 000036296 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\librsync.dll
    2017-10-03 20:07 - 2017-10-03 12:22 - 000032600 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\enterprise_data.compiled._enterprise_data.pyd
    2017-10-03 20:07 - 2017-10-03 12:21 - 000293392 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\EnterpriseDataAdapter.dll
    2017-10-03 20:07 - 2017-10-03 12:22 - 000181056 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.DLL
    2016-11-12 22:08 - 2017-10-03 12:22 - 000030536 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\wind3d11.compiled._wind3d11.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000024368 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\libEGL.DLL
    2017-10-03 20:07 - 2017-10-03 12:22 - 001638200 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\libGLESv2.dll
    2016-11-12 22:08 - 2017-10-03 12:22 - 000026456 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\winffi.winhttp.compiled._winffi_winhttp.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000545080 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000359224 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd
    2017-10-03 20:07 - 2017-10-03 12:22 - 000038208 _____ () C:\Users\richard\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngine.pyd

    ==================== Alternate Data Streams (Avec liste blanche) =========

    (Si un élément est inclus dans le fichier fixlist.txt, seul le flux de données additionnel (ADS - Alternate Data Stream) sera supprimé.)


    ==================== Mode sans échec (Avec liste blanche) ===================

    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le "AlternateShell" sera restauré.)


    ==================== Association (Avec liste blanche) ===============

    (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé.)


    ==================== Internet Explorer sites de confiance/sensibles ===============

    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre.)


    ==================== Hosts contenu: ===============================

    (Si nécessaire, la commande Hosts: peut être incluse dans le fichier fixlist.txt afin de réinitialiser le fichier hosts.)

    2009-07-14 04:34 - 2009-06-10 23:00 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


    ==================== Autres zones ============================

    (Actuellement, il n'y a pas de correction automatique pour cette section.)

    HKU\S-1-5-21-3844302631-3143525539-2212018275-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\richard\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
    DNS Servers: 192.168.1.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
    Le Pare-feu est activé.

    ==================== MSCONFIG/TASK MANAGER éléments désactivés ==

    MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
    MSCONFIG\Services: AVP15.0.2 => 2
    MSCONFIG\Services: btwdins => 2
    MSCONFIG\Services: Greg_Service => 2
    MSCONFIG\Services: gusvc => 3
    MSCONFIG\Services: MWLService => 3
    MSCONFIG\Services: Nero BackItUp Scheduler 4.0 => 3
    MSCONFIG\Services: NeroMediaHomeService.4 => 2
    MSCONFIG\Services: PDF Architect Helper Service => 2
    MSCONFIG\Services: PDF Architect Service => 2
    MSCONFIG\Services: RichVideo => 2
    MSCONFIG\Services: SkypeUpdate => 2
    MSCONFIG\Services: TeamViewer8 => 2
    MSCONFIG\Services: Updater Service => 2
    MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\Windows\pss\Bluetooth.lnk.CommonStartup
    MSCONFIG\startupfolder: C:^Users^richard^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
    MSCONFIG\startupfolder: C:^Users^richard^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 - Capture d'écran et lancement.lnk => C:\Windows\pss\OneNote 2010 - Capture d'écran et lancement.lnk.Startup
    MSCONFIG\startupfolder: C:^Users^richard^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 - Capture d’écran et lancement.lnk => C:\Windows\pss\OneNote 2010 - Capture d’écran et lancement.lnk.Startup
    MSCONFIG\startupfolder: C:^Users^richard^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.4.1.lnk => C:\Windows\pss\OpenOffice.org 3.4.1.lnk.Startup
    MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
    MSCONFIG\startupreg: CanonSolutionMenuEx => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
    MSCONFIG\startupreg: Dropbox Update => "C:\Users\richard\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
    MSCONFIG\startupreg: EgisTecPMMUpdate => "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
    MSCONFIG\startupreg: EgisUpdate => "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
    MSCONFIG\startupreg: Hotkey Utility => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
    MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
    MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
    MSCONFIG\startupreg: MDS_Menu => "C:\Program Files (x86)\Acer\Acer TouchPortal\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer\Acer TouchPortal\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6"
    MSCONFIG\startupreg: mwlDaemon => C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
    MSCONFIG\startupreg: Nero MediaHome 4 => "C:\Program Files (x86)\Nero\Nero MediaHome 4\NeroMediaHome.exe" /AUTORUN
    MSCONFIG\startupreg: Nikon Message Center 2 => C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe -s
    MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
    MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
    MSCONFIG\startupreg: SuiteTray => "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
    MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    MSCONFIG\startupreg: TouchMovieService => "C:\Program Files (x86)\Acer\Acer TouchPortal\Acer Touch Movie\TouchMovieService.exe"
    MSCONFIG\startupreg: TouchORB => C:\Program Files (x86)\TouchSettings\TouchPortalOBR.exe
    MSCONFIG\startupreg: TouchPortal => C:\Program Files (x86)\Acer\Acer Touch Suite\TouchPortalLauncher.exe na
    MSCONFIG\startupreg: UCam_Menu => "C:\Program Files (x86)\Acer\Acer Touch Suite\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer\Acer Touch Suite\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\3.0"

    ==================== RèglesPare-feu (Avec liste blanche) ===============

    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

    FirewallRules: [{4EA82AD0-4696-4980-800B-413E585F461C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{6EBB777A-FC4A-40E0-AB6B-2714936AD5F4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{F00AE0BF-FD22-44FB-A2F2-9269FB06BA75}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
    FirewallRules: [{A772065F-F5C3-4253-8EB2-41F13DDB88D0}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
    FirewallRules: [{EA487A4B-B906-4F4A-AAD3-B4E25F6E62A2}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
    FirewallRules: [{FE030EE5-9473-42C6-9B06-EE5377A638E0}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
    FirewallRules: [{A45AC57F-B0B9-4850-B37F-F54C63AF0094}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
    FirewallRules: [{9EF06508-40FE-49E7-BF75-B97F80578DC9}] => (Allow) C:\Users\richard\AppData\Roaming\Dropbox\bin\Dropbox.exe
    FirewallRules: [{A77D2D20-9A40-4A9F-B94A-71E56E74F622}] => (Allow) C:\Users\richard\AppData\Roaming\Dropbox\bin\Dropbox.exe
    FirewallRules: [{15BAAFB0-345E-4B9B-86BE-E4468AF8FA30}] => (Allow) C:\Program Files (x86)\Nero\Nero MediaHome 4\NMMediaServerService.exe
    FirewallRules: [{32E43587-D5AD-4C96-B1DF-558A4706DF8C}] => (Allow) C:\Program Files (x86)\Nero\Nero MediaHome 4\NMMediaServerService.exe
    FirewallRules: [{07C11E56-E6A8-4B5B-A2E2-036E7FC89C55}] => (Allow) svchost.exe
    FirewallRules: [{20D1187D-ADDD-42E5-865F-E0AE3B2138F5}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
    FirewallRules: [{77C3399D-00D5-410D-9A8E-481366609FE6}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\wlcsdk.exe
    FirewallRules: [{B655CB86-6806-400B-874D-FC0EB702D9E7}] => (Allow) C:\Program Files (x86)\Acer\Acer TouchPortal\Acer Touch Movie\TouchMovieService.exe
    FirewallRules: [{92410253-2844-4C6A-9C2F-0E378D106BDA}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
    FirewallRules: [{6F64EFDA-DBD6-4811-976B-EF214840A210}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
    FirewallRules: [{18997538-4CBA-4B43-91F0-A973C106CD37}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
    FirewallRules: [{894AFEE8-1DC2-4579-8010-08EBE23F4A0B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe

    ==================== Points de restauration =========================

    26-09-2017 07:53:53 Point de contrôle planifié
    05-10-2017 06:07:43 Point de contrôle planifié
    11-10-2017 09:10:32 Windows Update

    ==================== Éléments en erreur du Gestionnaire de périphériques =============


    ==================== Erreurs du Journal des événements: =========================

    Erreurs Application:
    ==================
    Error: (10/13/2017 08:40:05 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: richard-PC)
    Description: Le package Microsoft.Windows.Photos_2017.39081.15820.0_x64__8wekyb3d8bbwe+App a été interrompu, car sa suspension a été trop longue.

    Error: (10/13/2017 07:13:30 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: richard-PC)
    Description: Échec de l’activation de l’application Microsoft.Windows.Photos_8wekyb3d8bbwe!App avec l’erreur*: -2144927142 Pour plus d’informations, voir le journal Microsoft-Windows-TWinUI/Opérationnel.

    Error: (10/13/2017 07:00:31 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: richard-PC)
    Description: Le package Microsoft.Windows.Photos_2017.39081.15820.0_x64__8wekyb3d8bbwe+App a été interrompu, car sa suspension a été trop longue.

    Error: (10/13/2017 06:50:03 AM) (Source: SideBySide) (EventID: 63) (User: )
    Description: La création du contexte d’activation a échoué pour «*c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll*». Erreur dans le fichier de manifeste ou de stratégie «*c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll*» à la ligne 3.
    La valeur «*MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR*» de l’attribut «*version*» de l’élément «*assemblyIdentity*» n’est pas valide.

    Error: (10/13/2017 06:47:18 AM) (Source: SideBySide) (EventID: 35) (User: )
    Description: La création du contexte d’activation a échoué pour «*C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.Exe*». Erreur dans le fichier de manifeste ou de stratégie «*C:\Program Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL*» à la ligne 8.
    L’identité de composant trouvé dans le manifeste ne correspond pas à celle du composant demandé.
    La référence est WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
    La définition est WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
    Utilisez sxstrace.exe pour un diagnostic détaillé.

    Error: (10/12/2017 10:40:06 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: richard-PC)
    Description: Le package Microsoft.Windows.Photos_2017.39081.15820.0_x64__8wekyb3d8bbwe+App a été interrompu, car sa suspension a été trop longue.

    Error: (10/12/2017 09:40:07 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: richard-PC)
    Description: Le package Microsoft.Windows.Photos_2017.39081.15820.0_x64__8wekyb3d8bbwe+App a été interrompu, car sa suspension a été trop longue.

    Error: (10/12/2017 08:00:26 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Nom de l’application défaillante Microsoft.Photos.exe, version : 2017.39081.15820.0, horodatage : 0x59cc392e
    Nom du module défaillant : Windows.UI.Xaml.dll, version : 10.0.15063.674, horodatage : 0xaf452875
    Code d’exception : 0xc000027b
    Décalage d’erreur : 0x00000000004aae04
    ID du processus défaillant : 0x1b60
    Heure de début de l’application défaillante : 0x01d3431f5fc7c69e
    Chemin d’accès de l’application défaillante : C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39081.15820.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
    Chemin d’accès du module défaillant: C:\Windows\System32\Windows.UI.Xaml.dll
    ID de rapport : 8c6a5def-3456-4a6a-bec2-a2c7ae6cb475
    Nom complet du package défaillant*: Microsoft.Windows.Photos_2017.39081.15820.0_x64__8wekyb3d8bbwe
    ID de l’application relative au package défaillant*: App

    Error: (10/12/2017 07:49:36 AM) (Source: SideBySide) (EventID: 63) (User: )
    Description: La création du contexte d’activation a échoué pour «*c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll*». Erreur dans le fichier de manifeste ou de stratégie «*c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll*» à la ligne 3.
    La valeur «*MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR*» de l’attribut «*version*» de l’élément «*assemblyIdentity*» n’est pas valide.

    Error: (10/12/2017 07:45:42 AM) (Source: SideBySide) (EventID: 35) (User: )
    Description: La création du contexte d’activation a échoué pour «*C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.Exe*». Erreur dans le fichier de manifeste ou de stratégie «*C:\Program Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL*» à la ligne 8.
    L’identité de composant trouvé dans le manifeste ne correspond pas à celle du composant demandé.
    La référence est WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
    La définition est WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
    Utilisez sxstrace.exe pour un diagnostic détaillé.


    Erreurs système:
    =============
    Error: (10/13/2017 06:42:02 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: Le service NetMsmqActivator n’a pas pu démarrer en raison de l’erreur*:
    Le service n’a pas répondu assez vite à la demande de lancement ou de contrôle.

    Error: (10/13/2017 06:42:02 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: Le service NetPipeActivator n’a pas pu démarrer en raison de l’erreur*:
    Le service n’a pas répondu assez vite à la demande de lancement ou de contrôle.

    Error: (10/13/2017 06:42:02 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
    Description: Le dépassement de délai (30000 millisecondes) a été atteint lors de l’attente de la connexion du service NetMsmqActivator.

    Error: (10/13/2017 06:42:02 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
    Description: Le dépassement de délai (30000 millisecondes) a été atteint lors de l’attente de la connexion du service NetPipeActivator.

    Error: (10/13/2017 06:41:39 AM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT)
    Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID
    {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
    et l’APPID
    {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
    au SID AUTORITE NT\SERVICE LOCAL de l’utilisateur (S-1-5-19) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants.

    Error: (10/13/2017 06:41:39 AM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT)
    Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID
    {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
    et l’APPID
    {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
    au SID AUTORITE NT\SERVICE LOCAL de l’utilisateur (S-1-5-19) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants.

    Error: (10/13/2017 06:41:30 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: Le service NetTcpActivator dépend du service NetTcpPortSharing qui n’a pas pu démarrer en raison de l’erreur*:
    Le service ne peut pas être démarré parce qu’il est désactivé ou qu’aucun périphérique activé ne lui est associé.

    Error: (10/13/2017 06:41:28 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: Le service CldFlt n’a pas pu démarrer en raison de l’erreur*:
    Cette demande n’est pas prise en charge.

    Error: (10/12/2017 07:40:58 AM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT)
    Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID
    {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
    et l’APPID
    {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
    au SID AUTORITE NT\SERVICE LOCAL de l’utilisateur (S-1-5-19) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants.

    Error: (10/12/2017 07:40:58 AM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT)
    Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID
    {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
    et l’APPID
    {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
    au SID AUTORITE NT\SERVICE LOCAL de l’utilisateur (S-1-5-19) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants.


    CodeIntegrity:
    ===================================
    Date: 2017-10-12 19:30:28.332
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2017-10-12 09:02:25.872
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

    Date: 2017-10-12 09:02:25.827
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

    Date: 2017-10-12 09:02:25.790
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

    Date: 2017-10-12 09:02:25.719
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

    Date: 2017-10-12 09:02:25.680
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

    Date: 2017-10-12 09:02:25.596
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

    Date: 2017-10-12 09:02:24.121
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

    Date: 2017-10-12 09:02:23.776
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

    Date: 2017-10-12 08:49:16.902
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.


    ==================== Infos Mémoire ===========================

    Processeur: Pentium(R) Dual-Core CPU E5700 @ 3.00GHz
    Pourcentage de mémoire utilisée: 47%
    Mémoire physique - RAM - totale: 4059.42 MB
    Mémoire physique - RAM - disponible: 2121.48 MB
    Mémoire virtuelle totale: 8155.42 MB
    Mémoire virtuelle disponible: 5773.5 MB

    ==================== Lecteurs ================================

    Drive c: (Acer) (Fixed) (Total:291.54 GB) (Free:233.54 GB) NTFS
    Drive d: (DATA) (Fixed) (Total:291.54 GB) (Free:241.51 GB) NTFS

    ==================== MBR & Table des partitions ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: 040B7A32)
    Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
    Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=291.5 GB) - (Type=07 NTFS)
    Partition 4: (Not Active) - (Size=291.5 GB) - (Type=07 NTFS)

    ==================== Fin de Addition.txt ============================

  5. #5
    Member Spyware Fighter DonnaB's Avatar
    Join Date
    Apr 2009
    Location
    Illiana, Ill. USA
    Posts
    3,521
    Points
    563

    Default

    Hi B_Richard,

    Thank you for the logs. I don't see anything of the malicious nature in your logs in the way of malware.

    Original Problem/issue
    1 - I can not upload pics in a mail thru Yahoo Webmail. It is SO LONG that crashes by not sending mail at all... (MAIN problem)
    2 - I got an alert from my antivirus about 'vast.bp3873834.btrll.com' inside Edge 'it is not possible to valid certificate'...bla bla bla

    Test : W10 safe mode with network, Firefox normal and no antivirus : It worked fine , we've been able to attach 3 1mo pics in Yahoo webmail and then send mail
    In regards to the problems you are experiencing above, I have a feeling this is due to your AntiVirus. When you boot to Safe Mode, only drivers required for minimal operation conditions are loaded. The drivers, processes and services for your AV do not load which is why you were able to attach pics and send through email.

    AV: Suite de Sécurité Orange (Disabled - Up to date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Suite de Sécurité Orange (Disabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    FW: Suite de Sécurité Orange (Disabled) {BE0DF4B4-018B-AF50-0486-D6FE7C8A8AE3}
    I see that you have AO Kaspersky Lab installed though it appears to be disabled as shown above. Why it does not display in your installed programs I find confusing.

    Windows Defender is the built in AV in Windows 10 and is enabled. When Kaspserky is enabled it should disable Windows Defender automatically. If both AV's are enabled at the same time you will have conflicts and this could cause what you were experiencing. Could be why you were able to attach a pic and send while in safe mode since both AV's were disabled.


    Have you tried disabling Kaspersky in normal mode and try attaching a pic to send through email? You might even need to temporarily uninstall Kaspersky to trouble shoot the problem. It could also be the root of the valid certificate problem as well. If it is the paid version, make sure to write down your license number so that you have when and if you decide to reinstall it.
    If you think you might be infected with malware or have recently cleansed your computer of malware without the help of an expert, please read and follow the instructions in How to Start Removing Viruses and Spyware from your Computer. This can alleviate time consumed in trouble shooting your current computer problems.

    If your problem is solved, here's how to say thanks!

    Very proud parent of a U.S. Navy "CB"



    "People may forget what you say,
    People may forget what you did,
    but People will never forget how you made them feel!"

  6. #6
    Member
    Join Date
    Oct 2017
    Posts
    4
    Points
    0

    Default ... Test Phase ... to be continued

    Hello

    We have removed completely Kaspersky and now Windows 10 anti-virus is only running tool to protect us

    We'll now try for around 10 days and we'll come back to you then.

    Thank you for your efforts to help us.

    Best Regards



    Quote Originally Posted by DonnaB View Post
    Hi B_Richard,

    Thank you for the logs. I don't see anything of the malicious nature in your logs in the way of malware.


    In regards to the problems you are experiencing above, I have a feeling this is due to your AntiVirus. When you boot to Safe Mode, only drivers required for minimal operation conditions are loaded. The drivers, processes and services for your AV do not load which is why you were able to attach pics and send through email.



    I see that you have AO Kaspersky Lab installed though it appears to be disabled as shown above. Why it does not display in your installed programs I find confusing.

    Windows Defender is the built in AV in Windows 10 and is enabled. When Kaspserky is enabled it should disable Windows Defender automatically. If both AV's are enabled at the same time you will have conflicts and this could cause what you were experiencing. Could be why you were able to attach a pic and send while in safe mode since both AV's were disabled.


    Have you tried disabling Kaspersky in normal mode and try attaching a pic to send through email? You might even need to temporarily uninstall Kaspersky to trouble shoot the problem. It could also be the root of the valid certificate problem as well. If it is the paid version, make sure to write down your license number so that you have when and if you decide to reinstall it.

  7. #7
    Member Spyware Fighter DonnaB's Avatar
    Join Date
    Apr 2009
    Location
    Illiana, Ill. USA
    Posts
    3,521
    Points
    563

    Default

    Yes. Please keep us informed. If you continue to have issues, especially with trying to send uploads in Yahoo mail, try sending the pics as zip files. Yahoo does have a 25mb size limit. See link > [urll=https://www.lifewire.com/attachment-message-size-limits-yahoo-1174505]Yahoo! Mail Message and Attachment Size Limits[/url]
    If you think you might be infected with malware or have recently cleansed your computer of malware without the help of an expert, please read and follow the instructions in How to Start Removing Viruses and Spyware from your Computer. This can alleviate time consumed in trouble shooting your current computer problems.

    If your problem is solved, here's how to say thanks!

    Very proud parent of a U.S. Navy "CB"



    "People may forget what you say,
    People may forget what you did,
    but People will never forget how you made them feel!"