You are on page 1of 25

Logfile of random's system information tool 1.

09 (written by random/random) Run by jplu at 2012-01-12 16:04:01 Microsoft Windows7 dition Familiale Premium Service Pack 1 System drive C: has 344 GB (73%) free of 470 GB Total RAM: 4095 MB (18% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 16:12:07, on 12/01/2012 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v9.00 (9.00.8112.16421) Boot mode: Normal Running processes: C:\Program Files (x86)\VPNTunnel\bin\VPNTunnel.exe C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe C:\Program Files (x86)\TechSmith\Jing\Jing.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files (x86)\TRENDnet\TEW-424UB\WlanCU.exe C:\Users\jplu\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Users\jplu\M-1-25-5432-6437-5685\winmgr.exe C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray .exe C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe C:\Program Files (x86)\Mindjet\MindManager 9\MmReminderService.exe C:\Program Files (x86)\Acronis\TrueImageHome\OnlineBackupStandalone\TrueImageMon itor.exe C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\VPNTunnel\bin\ConnGuardManager.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Users\jplu\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe C:\Program Files (x86)\Pidgin\pidgin.exe C:\Program Files (x86)\Adobe\Adobe Photoshop CS4\Photoshop.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\SysWOW64\rundll32.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Skype\Phone\Skype.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\jplu\AppData\Local\Temp\4953472.exe C:\Users\jplu\AppData\Roaming\30CAB\FA541.exe C:\Users\jplu\AppData\Roaming\AB27E\lvvm.exe C:\Program Files (x86)\Tweedeck\TweetDeck\TweetDeck.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files\trend micro\jplu.exe C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat.exe C:\Windows\sysWow64\SearchProtocolHost.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ho mepage.acer.com/rdr.aspx?b=ACAW&l=040c&m=aspire_x1301&r=17361209ln07973480k35bg7 412l93 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.micr osoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.goog le.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ho mepage.acer.com/rdr.aspx?b=ACAW&l=040c&m=aspire_x1301&r=17361209ln07973480k35bg7 412l93 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http:// go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.micr osoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage .acer.com/rdr.aspx?b=ACAW&l=040c&m=aspire_x1301&r=17361209ln07973480k35bg7412l93 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysW OW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServe r = http=127.0.0.1:60202 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverr ide = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F3 - REG:win.ini: load=C:\Users\jplu\AppData\Roaming\AB27E\lvvm.exe F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Progra m Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: CmjBrowserHelperObject Object - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files (x86)\Mindjet\MindManager 9\Mm8InternetExplorer.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-

4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Sha red\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Pr ogram Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE1 61910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClie nt.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program File s (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Progr am Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Fi les (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Progr am Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystem s\Acer Backup Manager\BackupManagerTray.exe" -h -k O4 - HKLM\..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\Ho tkeyUtility.exe O4 - HKLM\..\Run: [EgisTecLiveUpdate] "C:\Program Files (x86)\EgisTec Egis Softw are Update\EgisUpdate.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0 \AdobeARM.exe" O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.ex e" /min O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\A crobat 9.0\Acrobat\Acrobat_sl.exe" O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\ Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 9\MMReminderService.exe O4 - HKLM\..\Run: [SAOB Monitor] C:\Program Files (x86)\Acronis\TrueImageHome\On lineBackupStandalone\TrueImageMonitor.exe O4 - HKLM\..\Run: [TrueImageMonitor.exe] "C:\Program Files (x86)\Acronis\TrueIma geHome\TrueImageMonitor.exe" O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwareby tes' Anti-Malware\mbamgui.exe" /starttray O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malware bytes' Anti-Malware\mbamgui.exe /install /silent O4 - HKCU\..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.ex e" -silent O4 - HKCU\..\Run: [Google Update] "C:\Users\jplu\AppData\Local\Google\Update\Goo gleUpdate.exe" /c O4 - HKCU\..\Run: [Jing] C:\Program Files (x86)\TechSmith\Jing\Jing.exe O4 - HKCU\..\Run: [Microsoft Windows Manager] C:\Users\jplu\M-1-25-5432-6437-5685 \winmgr.exe O4 - HKCU\..\Run: [F16.exe] C:\Users\jplu\AppData\Roaming\Microsoft\4143\F16.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE RSEAU') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User

'SERVICE RSEAU') O4 - Startup: Dropbox.lnk = jplu\AppData\Roaming\Dropbox\bin\Dropbox.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\ Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Wireless Configuration Utility HW.14.lnk = C:\Program Files (x86)\TRENDnet\TEW-424UB\WlanCU.exe O8 - Extra context menu item: Ajouter la cible du lien un fichier PDF existant res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient .dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Ajouter un fichier PDF existant - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend .html O8 - Extra context menu item: Convertir au format Adobe PDF - res://C:\Program F iles (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture. html O8 - Extra context menu item: Convertir la cible du lien au format Adobe PDF - r es://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.d ll/AcroIECaptureSelLinks.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MIC ROS~1\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~2 \MICROS~1\Office12\EXCEL.EXE/3000 O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Pr ogram Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C34168CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\Writer BrowserExtension.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C: \PROGRA~2\MICROS~1\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0 C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll O9 - Extra button: Envoyer Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F3 54B7FF} - C:\Program Files (x86)\Mindjet\MindManager 9\Mm8InternetExplorer.dll O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B 9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935 -AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeie plugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA ~2\MICROS~1\Office12\REFIEBAR.DLL O9 - Extra button: Afficher ou masquer l'HP Smart Web Printing - {DDE87865-83C548c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Pr inting\hpswp_BHO.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O17 - HKLM\System\CCS\Services\Tcpip\..\{5B159DBA-C247-46A2-A731-21B5A9298F13}: NameServer = 8.8.8.8,8.8.4.4 O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C :\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O23 - Service: ABBYY FineReader 9.0 PE Licensing Service (ABBYY.Licensing.FineRe ader.Professional.9.0) - ABBYY (BIT Software) - C:\Program Files (x86)\Common Fi les\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe O23 - Service: Service Scheduler2 Acronis (AcrSch2Svc) - Acronis - C:\Program Fi les (x86)\Common Files\Acronis\Schedule2\schedul2.exe O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown ow ner - C:\Windows\system32\svchost.exe O23 - Service: Service Acronis Nonstop Backup (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Wi ndows\System32\alg.exe (file missing) O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira Gmb

H - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Fi les (x86)\Avira\AntiVir Desktop\avguard.exe O23 - Service: @%systemroot%\system32\appidsvc.dll,-100 (AppIDSvc) - Unknown own er - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (AudioSrv) - Unknown own er - C:\Windows\System32\svchost.exe O23 - Service: Advanced Web Ranking Scheduler (AWRScheduler) - Caphyon - C:\Prog ram Files (x86)\Caphyon\Advanced Web Ranking\Scheduler.exe O23 - Service: @%SystemRoot%\system32\AxInstSV.dll,-103 (AxInstSV) - Unknown own er - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\bdesvc.dll,-100 (BDESVC) - Unknown owner C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C: \Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\bthserv.dll,-101 (bthserv) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown o wner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown ow ner - C:\Windows\system32\svchost.exe O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\syste m32\svchost.exe O23 - Service: @%SystemRoot%\system32\defragsvc.dll,-101 (defragsvc) - Unknown o wner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\dhcpcore.dll,-100 (Dhcp) - Unknown owner C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owne r - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Wi ndows\System32\svchost.exe O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C: \Windows\System32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\ehome\ehrecvr.exe,-101 (ehRecvr) - Unknown owner C:\Windows\ehome\ehRecvr.exe O23 - Service: @%SystemRoot%\ehome\ehsched.exe,-101 (ehSched) - Unknown owner C:\Windows\ehome\ehsched.exe O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (eventlog) - Unknown owne r - C:\Windows\System32\svchost.exe O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\syst em32\svchost.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C :\Windows\system32\fxssvc.exe (file missing) O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown own er - C:\Windows\system32\svchost.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Fi

les (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService. exe O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.e xe O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown ow ner - C:\Windows\system32\svchost.exe O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svc host.exe O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe O23 - Service: Service Google Update (gupdate) (gupdate) - Unknown owner - C:\Pr ogram Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Service Google Update (gupdatem) (gupdatem) - Unknown owner - C:\ Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86) \Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\kmsvc.dll,-6 (hkmsvc) - Unknown owner - C: \Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\ListSvc.dll,-100 (HomeGroupListener) - Unk nown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\provsvc.dll,-100 (HomeGroupProvider) - Unk nown owner - C:\Windows\System32\svchost.exe O23 - Service: hpqcxs08 - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Service HP CUE DeviceDiscovery (hpqddsvc) - Unknown owner - C:\Wi ndows\system32\svchost.exe O23 - Service: HP Network Devices Support (HPSLPSVC) - Unknown owner - C:\Window s\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown o wner - C:\Windows\system32\svchost.exe O23 - Service: Service de liPod (iPod Service) - Apple Inc. - C:\Program Files\iP od\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\l sass.exe (file missing) O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\s vchost.exe O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown o wner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unkn own owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\M alwarebytes Anti-Malware\mbamservice.exe O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C :\Windows\system32\svchost.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\m sdtc.exe (file missing) O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown own er - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe

O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Prog ram Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Co mmon Files\Nero\Nero BackItUp 4\NBService.exe O23 - Service: Net Driver HPZ12 - Unknown owner - C:\Windows\System32\svchost.ex e O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown own er - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\netprofm.dll,-202 (netprofm) - Unknown own er - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C :\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C: \Windows\system32\svchost.exe O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\ NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files ( x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8004 (p2pimsvc) - Unknown own er - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C :\Windows\system32\svchost.exe O23 - Service: @%systemroot%\sysWow64\perfhost.exe,-2 (PerfHost) - Unknown owner - C:\Windows\SysWow64\perfhost.exe O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Wi ndows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown own er - C:\Windows\system32\svchost.exe O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\Windows\System32\svchost.ex e O23 - Service: @%SystemRoot%\system32\pnrpauto.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8000 (PNRPsvc) - Unknown owne r - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\umpo.dll,-100 (Power) - Unknown owner - C: \Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unkno wn owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\ Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @regsvc.dll,-1 (RemoteRegistry) - Unknown owner - C:\Windows\syst em32\svchost.exe O23 - Service: @%windir%\system32\RpcEpMap.dll,-1001 (RpcEptMapper) - Unknown ow ner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owne r - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\s vchost.exe O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C: \Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\System32\SCardSvr.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown own er - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown o wner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown ow ner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\ Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\sensrsvc.dll,-1000 (SensrSvc) - Unknown ow ner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown o wner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unk nown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppuinotify.dll,-103 (sppuinotify) - Unkno wn owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA C orporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (stisvc) - Unknown owner C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C :\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owne r - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unk nown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown own er - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C: \Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown o wner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\themeservice.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown own er - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C :\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstall er) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown o wner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\Updat erService.exe O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown own er - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\dwm.exe,-2000 (UxSms) - Unknown owner - C: \Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown ow ner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Wi ndows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\ Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown own er - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%systemroot%\system32\wbiosrvc.dll,-100 (WbioSrvc) - Unknown own er - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInServic e) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown ow ner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown own er - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown own er - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - U nknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - U nknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown o wner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknow n owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetwor kSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: @%SystemRoot%\system32\wpcsvc.dll,-100 (WPCSvc) - Unknown owner C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owne r - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owne r - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\wwansvc.dll,-257 (WwanSvc) - Unknown owner

- C:\Windows\system32\svchost.exe -End of file - 31949 bytes ======Listing Processes====== \SystemRoot\System32\smss.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,2048 0,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:User ServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDl l=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 wininit.exe %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,2048 0,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:User ServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDl l=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe winlogon.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe "C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe" "C:\Program Files (x86)\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkL icenseServer.exe" -service "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe" "C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe" "C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe" "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDevi ceService.exe" "C:\Program Files (x86)\Caphyon\Advanced Web Ranking\Scheduler.exe" C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork "C:\Program Files (x86)\Acer\Registration\GregHSRW.exe" "C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_000 00754 \??\C:\Windows\system32\conhost.exe "-522666051352006229310320981-15927490628177 37554-490055380-982570268-689655299 C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt "C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe" C:\Windows\System32\svchost.exe -k HPZ12 "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe " C:\Windows\System32\svchost.exe -k HPZ12 "C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe" C:\Windows\system32\svchost.exe -k imgsvc "C:\Program Files\Acer\Acer Updater\UpdaterService.exe" "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe" "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe" C:\Windows\system32\svchost.exe -k HPService "C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6 aa} -IoEventPortName:HostProcess-f724a556-f386-4f01-a5a0-6c2c03c0e23d -SystemEve ntPortName:HostProcess-2965d966-418f-4291-859d-08b01762ed61 -IoCancelEventPortNa me:HostProcess-65c757b3-2996-4e0a-94b4-dcbd61be9e09 -NonStateChangingEventPortNa

me:HostProcess-a47cae76-4c7d-4c6a-aaa7-55aa29b5af86 -ServiceSID:S-1-5-80-2652678 385-582572993-1835434367-1344795993-749280709 -LifetimeId:e8e3913d-5265-4fbb-8d8 5-0ae1ed9d8e89 "taskhost.exe" "C:\Windows\system32\Dwm.exe" taskeng.exe {B7868117-31D2-4D18-AC8B-5C536B118535} "C:\Program Files (x86)\VPNTunnel\bin\VPNTunnel.exe" C:\Windows\Explorer.EXE C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" "C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" "C:\Program Files (x86)\TechSmith\Jing\Jing.exe" "C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe" "C:\Program Files (x86)\TRENDnet\TEW-424UB\WlanCU.exe" "C:\Users\jplu\AppData\Roaming\Dropbox\bin\Dropbox.exe" C:\Windows\system32\SearchIndexer.exe /Embedding C:\Users\jplu\M-1-25-5432-6437-5685\winmgr.exe "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTra y.exe" -h -k "C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe" "C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe" "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe" "C:\Program Files (x86)\Mindjet\MindManager 9\MmReminderService.exe" "C:\Program Files (x86)\Acronis\TrueImageHome\OnlineBackupStandalone\TrueImageMo nitor.exe" "C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE" "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" "C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe" -CtxID "#Hewlett-Pa ckard#HP Photosmart C4700 series#1270200773" -Startup "C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe" -Embedding "C:\Program Files\Windows Media Player\wmpnetwk.exe" "C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe" -Embedding C:\Windows\System32\svchost.exe -k LocalServicePeerNet "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" "C:\Program Files (x86)\VPNTunnel\bin\ConnGuardManager.exe" \??\C:\Windows\system32\conhost.exe "7005042901348264053-679159391-1785262060-21 12178955-2077804543135339926-481047373 "C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=4972.96f 62f0.1393743596 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox .8.0.1 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 4972 "\\.\pipe \gecko-crash-server-pipe.4972" plugin "C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLic ensingService.exe" "C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=4972.2fb d8890.1373197022 "C:\Users\jplu\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll " Mozilla.Firefox.8.0.1 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja r" 4972 "\\.\pipe\gecko-crash-server-pipe.4972" plugin "C:\Users\jplu\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe" "C:\Program Files (x86)\Pidgin\pidgin.exe" "C:\Program Files (x86)\Adobe\Adobe Photoshop CS4\Photoshop.exe" "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/C onnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parall el_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant /Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/Conse rvativeAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd10/Spdy Impact/npn_with_spdy/WarmSocketImpact/last_accessed_socket/ --extension-process

--enable-print-preview --channel=2064.03C2AD80.1103816579 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/C onnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parall el_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant /Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/Conse rvativeAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd10/Spdy Impact/npn_with_spdy/WarmSocketImpact/last_accessed_socket/ --extension-process --enable-print-preview --channel=2064.03C2A000.1305151578 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/C onnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parall el_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant /Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/Conse rvativeAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd10/Spdy Impact/npn_with_spdy/WarmSocketImpact/last_accessed_socket/ --extension-process --enable-print-preview --channel=2064.03C2A180.914394265 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/C onnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parall el_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant /Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/Conse rvativeAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd10/Spdy Impact/npn_with_spdy/WarmSocketImpact/last_accessed_socket/ --extension-process --enable-print-preview --channel=2064.03C2A300.1371578874 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/C onnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parall el_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant /Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/Conse rvativeAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd10/Spdy Impact/npn_with_spdy/WarmSocketImpact/last_accessed_socket/ --extension-process --enable-print-preview --channel=2064.0583C180.315632922 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/C onnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parall el_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant /Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/Conse rvativeAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd10/Spdy Impact/npn_with_spdy/WarmSocketImpact/last_accessed_socket/ --extension-process --enable-print-preview --channel=2064.0583C300.1027921699 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/C onnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parall el_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant /Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/Conse rvativeAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd10/Spdy Impact/npn_with_spdy/WarmSocketImpact/last_accessed_socket/ --extension-process --enable-print-preview --channel=2064.0583C480.985065545 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/C onnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parall el_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant /Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/Conse rvativeAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd10/Spdy Impact/npn_with_spdy/WarmSocketImpact/last_accessed_socket/ --extension-process --enable-print-preview --channel=2064.0583C600.1231445183 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/C onnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parall

el_default/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/Instant /Inactive/Prefetch/ContentPrefetchPrerender2/PrerenderFromOmniboxHeuristic/Conse rvativeAlgorithm/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwnd10/Spdy Impact/npn_with_spdy/WarmSocketImpact/last_accessed_socket/ --extension-process --enable-print-preview --channel=2064.0583C780.386341964 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access ed_socket/ --enable-print-preview --channel=2064.067C2A80.2144298119 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access ed_socket/ --enable-print-preview --channel=2064.06B55780.1339847274 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access ed_socket/ --enable-print-preview --channel=2064.06B55900.1811462210 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access ed_socket/ --enable-print-preview --channel=2064.06B55A80.831275903 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access ed_socket/ --enable-print-preview --channel=2064.06B55C00.116479902 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access ed_socket/ --enable-print-preview --channel=2064.06B55D80.1984164425 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access

ed_socket/ --enable-print-preview --channel=2064.067C2000.1917490289 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access ed_socket/ --enable-print-preview --channel=2064.067C2180.531532783 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access ed_socket/ --enable-print-preview --channel=2064.067C2300.2132148126 /prefetch:3 C:\Windows\system32\rundll32.exe "C:\Users\jplu\AppData\Local\Google\Chrome\APPL IC~1\160912~1.75\gcswf32.dll",BrokerMain browser=chrome "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\jplu\AppData\Local\Google\Chrome\Application\16.0.912.7 5\gcswf32.dll" --lang=fr --channel=2064.069848C0.451847221 --flash-broker=5864 / prefetch:4 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\jplu\AppData\Local\Google\Chrome\User Data\Default\Exte nsions\deckhobdafgddaglbaokimbcjjdikago\3.5.3_0\npiopus.dll" --lang=fr --channel =2064.0A7988C0.487907730 /prefetch:4 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\jplu\AppData\Local\Google\Chrome\User Data\Default\Exte nsions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8153_0\npSkypeChromePlugin.dll" -lang=fr --channel=2064.0A77EA80.1740553716 /prefetch:4 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access ed_socket/ --enable-print-preview --channel=2064.067C2480.126026087 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\jplu\AppData\Local\Google\Chrome\User Data\Default\Exte nsions\deckhobdafgddaglbaokimbcjjdikago\3.5.3_0\npsi.dll" --lang=fr --channel=20 64.072B38C0.1038309207 /prefetch:4 "C:\Program Files (x86)\Skype\Phone\Skype.exe" "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access ed_socket/ --enable-print-preview --channel=2064.067C2780.20015449 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access ed_socket/ --enable-print-preview --channel=2064.067C2900.571530921 /prefetch:3

"C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access ed_socket/ --enable-print-preview --channel=2064.067C2C00.1382408233 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access ed_socket/ --enable-print-preview --channel=2064.067C2D80.1419570922 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access ed_socket/ --enable-print-preview --channel=2064.067C2600.893337691 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access ed_socket/ --enable-print-preview --channel=2064.05D53780.1487349859 /prefetch:3 "C:\Users\jplu\AppData\Local\Google\Chrome\Application\chrome.exe" --type=render er --lang=fr --force-fieldtest=CacheListSize/CacheListSize_14/ConnCountImpact/co nn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled _prefetch/DnsParallelism/parallel_default/GlobalSdch/global_enable_sdch/IdleSktT oImpact/idle_timeout_10/Instant/Inactive/Prefetch/ContentPrefetchPrerender2/Prer enderFromOmniboxHeuristic/ConservativeAlgorithm/ProxyConnectionImpact/proxy_conn ections_32/SpdyCwnd/cwnd10/SpdyImpact/npn_with_spdy/WarmSocketImpact/last_access ed_socket/ --enable-print-preview --channel=2064.05D53A80.2085412519 /prefetch:3 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe "C:\Users\jplu\AppData\Local\Temp\4953472.exe" C:\Users\jplu\AppData\Roaming\30CAB\FA541.exe C:\Users\jplu\AppData\Roaming\AB27E\lvvm.exe "C:\Program Files (x86)\Tweedeck\TweetDeck\TweetDeck.exe" "C:\Windows\system32\notepad.exe" "taskhost.exe" "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe" "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamgui.exe" /startalways C:\Windows\system32\wbem\wmiprvse.exe "C:\Users\jplu\Downloads\RSITx64.exe" "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat.exe" "C:\Users\jplu\Ap pData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\LL9Q2ZA7\ boostertRR.pdf" C:\Windows\splwow64.exe 8192 "C:\Windows\sysWow64\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1 -5-21-2378692057-4251612070-2817567377-100066_ Global\UsGthrCtrlFltPipeMssGthrPi pe_S-1-5-21-2378692057-4251612070-2817567377-100066 1 -2147483646 "Software\Micr osoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search

4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaem on" "1" "C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528 taskhost.exe $(Arg0) ======Scheduled tasks folder====== C:\Windows\tasks\GoogleUpdateTaskMachineCore.job C:\Windows\tasks\GoogleUpdateTaskMachineUA.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2378692057-4251612070-2817567377-1 000Core.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2378692057-4251612070-2817567377-1 000UA.job =========Mozilla firefox========= ProfilePath - C:\Users\jplu\AppData\Roaming\Mozilla\Firefox\Profiles\nqne2sa4.de fault prefs.js - "browser.startup.homepage" - "http://www.google.fr/" prefs.js - "extensions.enabledItems" - "{2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}: 2.1.106, firebug@software.joehewitt.com:1.6.2, {a7c6cf7f-112c-4500-a7ea-39801a32 7e5f}:1.0.10, FirePHPExtension-Build@firephp.org:0.5.0, {CAFEEFAC-0016-0000-0020 -ABCDEFFEDCBA}:6.0.20, {c2b1f3ae-5cd5-49b7-8a0c-2c3bcbbbb294}:1.1, senseo@nicost einer.de:1.5.5, {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9, {37fa1426-b82d-11d b-8314-0800200c9a66}:2.7.5, yslow@yahoo-inc.com:2.1.0, {AB2CE124-6272-4b12-94A97303C7397BD1}:4.2.0.5198, {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, {e3f6c2 cc-d8db-498c-af6c-499fb211db97}:1.10.2, toolbar@seomoz.org:0.52, wappalyzer@crun chlabz.com:1.13.0, {d47a9f51-8281-43fa-f450-f28ef8735e9a}:2.1.1, autofillForms@b lueimp.net:0.9.8.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.15" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe Flash Player 10.1 Plugin "Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,versio n=] "Description"=Module iTunes Detector "Path"= [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,versio n=1.0] "Description"= "Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin] "Description"=Oracle Next Generation Java Plug-In "Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=C:\Windows\system32\Wat\npWatWeb.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,ve rsion=1.0] "Description"=Ag Player Plugin "Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,vers ion=14.0.8117.0416]

"Description"=WLPG Install MIME type "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision] "Description"=NVIDIA stereo images plugin for Mozilla browsers "Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] "Description"=Google Update "Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin] "Description"=Oracle Next Generation Java Plug-In "Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=C:\Windows\system32\Wat\npWatWeb.dll C:\Program Files (x86)\Mozilla Firefox\extensions\ {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} {972ce4c6-7e08-4474-a285-3208198ce6fd} C:\Program Files (x86)\Mozilla Firefox\components\ binary.manifest browsercomps.dll nsIQTScriptablePlugin.xpt C:\Program Files (x86)\Mozilla Firefox\plugins\ npdeployJava1.dll nppdf32.DEU nppdf32.dll nppdf32.FRA npqtplugin.dll npqtplugin2.dll npqtplugin3.dll npqtplugin4.dll npqtplugin5.dll npqtplugin6.dll npqtplugin7.dll QuickTimePlugin.class C:\Program Files (x86)\Mozilla Firefox\searchplugins\ amazon-france.xml bing.xml cnrtl-tlfi-fr.xml eBay-france.xml google.xml wikipedia-fr.xml yahoo-france.xml C:\Users\jplu\AppData\Roaming\Mozilla\Firefox\Profiles\nqne2sa4.default\extensio ns\

staged toolbar@seomoz.org wappalyzer@crunchlabz.com {2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9} {317B5128-0B0B-49b2-B2DB-1E7560E16C74} {37fa1426-b82d-11db-8314-0800200c9a66} {44d0a1b4-9c90-4f86-ac92-8680b5d6549e} {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} {c2b1f3ae-5cd5-49b7-8a0c-2c3bcbbbb294} {c45c406e-ab73-11d8-be73-000a95be3b12} {d47a9f51-8281-43fa-f450-f28ef8735e9a} {e3f6c2cc-d8db-498c-af6c-499fb211db97} C:\Users\jplu\AppData\Roaming\Mozilla\Firefox\Profiles\nqne2sa4.default\searchpl ugins\ search.xml ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser H elper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolb ar_64.dll [2012-01-11 458352] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser H elper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [201012-29 43520] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explor er\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}] HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing \hpswp_printenhancer.dll [2009-10-22 328248] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explor er\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\Active X\AcroIEHelperShim.dll [2009-02-27 75128] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explor er\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explor er\Browser Helper Objects\{6FE6A929-59D1-4763-91AD-29B61CFFB35B}] CmjBrowserHelperObject Object - C:\Program Files (x86)\Mindjet\MindManager 9\Mm8 InternetExplorer.dll [2011-02-11 84832] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explor er\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Programme d aide de l Assistant de connexion Windows Live - C:\Program Files (x8 6)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 4 08448] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explor er\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolb ar_32.dll [2012-01-11 342128] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explor er\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]

Adobe PDF Conversion Toolbar Helper - C:\Program Files (x86)\Common Files\Adobe\ Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explor er\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\s kypeieplugin.dll [2011-08-16 3942048] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explor er\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explor er\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}] SmartSelect Class - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\Ac roIEFavClient.dll [2008-06-11 345480] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explor er\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}] HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printin g\hpswp_BHO.dll [2009-10-22 517688] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86) \Google\Google Toolbar\GoogleToolbar_64.dll [2012-01-11 458352] [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar] {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files (x86)\Comm on Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86) \Google\Google Toolbar\GoogleToolbar_32.dll [2012-01-11 342128] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-07-20 7981088] "mwlDaemon"=C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [2009 -08-06 349480] "Service Scheduler2 Acronis"=C:\Program Files (x86)\Common Files\Acronis\Schedul e2\schedhlp.exe [2011-02-01 391120] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "EA Core"=C:\Program Files (x86)\Electronic Arts\EADM\Core.exe -silent [] "Google Update"=C:\Users\jplu\AppData\Local\Google\Update\GoogleUpdate.exe [2010 -04-07 136176] "Jing"=C:\Program Files (x86)\TechSmith\Jing\Jing.exe [2010-08-19 3069192] "Microsoft Windows Manager"=C:\Users\jplu\M-1-25-5432-6437-5685\winmgr.exe [201201-04 36864] "F16.exe"=C:\Users\jplu\AppData\Roaming\Microsoft\4143\F16.exe [2012-01-12 29132 8] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "BackupManagerTray"=C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manag er\BackupManagerTray.exe [2009-08-12 261888] "Hotkey Utility"=C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [2 009-08-10 629280] "EgisTecLiveUpdate"=C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpda te.exe [2009-08-04 199464] "Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009 -09-04 935288] "avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2010-08-17 28176

8] "Adobe Acrobat Speed Launcher"=C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\ Acrobat_sl.exe [2008-06-12 37232] ""= [] "Acrobat Assistant 8.0"=C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotra y.exe [2008-06-11 640376] "AdobeCS4ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS4ServiceMan ager\CS4ServiceManager.exe [2008-08-14 611712] "MMReminderService"=C:\Program Files (x86)\Mindjet\MindManager 9\MMReminderServi ce.exe [2011-02-11 38240] "SAOB Monitor"=C:\Program Files (x86)\Acronis\TrueImageHome\OnlineBackupStandalo ne\TrueImageMonitor.exe [2010-11-16 2570080] "TrueImageMonitor.exe"=C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMon itor.exe [2011-02-01 5582392] "Malwarebytes Anti-Malware"=C:\Program Files (x86)\Malwarebytes Anti-Malware\m bamgui.exe [2011-12-24 460872] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnc e] "Malwarebytes Anti-Malware"=C:\Program Files (x86)\Malwarebytes Anti-Malware\mb amgui.exe [2011-12-24 460872] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\h pqtra08.exe Wireless Configuration Utility HW.14.lnk - C:\Program Files (x86)\TRENDnet\TEW-4 24UB\WlanCU.exe C:\Users\jplu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup Dropbox.lnk - C:\Users\jplu\AppData\Roaming\Dropbox\bin\Dropbox.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObject DelayLoad] WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService ] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1

"EnableLinkedConnections"=1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "ForceActiveDesktopOn"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\fi rewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\fi rewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "vidc.uyvy"=msyuv.dll "vidc.yuy2"=msyuv.dll "vidc.yvyu"=msyuv.dll "vidc.iyuv"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "vidc.yvu9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "wave4"=wdmaud.drv "midi4"=wdmaud.drv "mixer4"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv "wave3"=wdmaud.drv "midi3"=wdmaud.drv "mixer3"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS4\Dreamweaver.exe ","%1" ======List of files/folders created in the last 1 month====== 2012-01-12 2012-01-12 2012-01-12 2012-01-12 2012-01-11 2012-01-11 16:04:02 16:04:01 13:23:25 13:22:53 19:52:16 19:52:16 ----D-------D-------D-------D-------A-------A---C:\Program Files\trend micro C:\rsit C:\Users\jplu\AppData\Roaming\AB27E C:\Users\jplu\AppData\Roaming\30CAB C:\Windows\SYSWOW64\quartz.dll C:\Windows\SYSWOW64\qdvd.dll

2012-01-11 2012-01-11 2012-01-11 2012-01-11 2012-01-11 2012-01-11 2012-01-09 2012-01-06 2012-01-06 2012-01-06 2012-01-04 2012-01-04 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14 2011-12-14

19:52:16 19:52:16 19:49:37 19:49:37 13:58:02 13:58:02 08:49:40 17:34:50 10:22:42 10:22:42 15:30:58 15:30:53 18:44:07 18:44:06 18:44:06 18:44:06 18:44:05 18:44:05 18:44:05 18:44:05 18:44:05 18:44:05 18:44:04 18:44:03 18:44:03 18:44:02 18:44:02 18:44:02 18:44:01 18:44:01 18:44:00 18:43:59 18:43:58 18:43:58 09:29:00 09:28:59 09:28:58 09:28:57 09:28:52 09:28:52

----A---- C:\Windows\system32\quartz.dll ----A---- C:\Windows\system32\qdvd.dll ----A---- C:\Windows\SYSWOW64\ntdll.dll ----A---- C:\Windows\system32\ntdll.dll ----A---- C:\Windows\SYSWOW64\packager.dll ----A---- C:\Windows\system32\packager.dll ----AH---- C:\Users\jplu\AppData\Roaming\winstat.txt ----D---- C:\Users\jplu\AppData\Roaming\TeamViewer ----D---- C:\ProgramData\Spybot - Search & Destroy ----D---- C:\Program Files (x86)\Spybot - Search & Destroy ----AH---- C:\Users\jplu\AppData\Roaming\windrvg8.txt ----AH---- C:\Users\jplu\AppData\Roaming\windrvconfig.txt ----A---- C:\Windows\system32\mshtmled.dll ----A---- C:\Windows\SYSWOW64\mshtmled.dll ----A---- C:\Windows\SYSWOW64\iertutil.dll ----A---- C:\Windows\system32\iertutil.dll ----A---- C:\Windows\SYSWOW64\urlmon.dll ----A---- C:\Windows\SYSWOW64\url.dll ----A---- C:\Windows\SYSWOW64\ieui.dll ----A---- C:\Windows\system32\urlmon.dll ----A---- C:\Windows\system32\url.dll ----A---- C:\Windows\system32\ieui.dll ----A---- C:\Windows\system32\jsproxy.dll ----A---- C:\Windows\SYSWOW64\wininet.dll ----A---- C:\Windows\system32\wininet.dll ----A---- C:\Windows\SYSWOW64\jscript9.dll ----A---- C:\Windows\SYSWOW64\jscript.dll ----A---- C:\Windows\system32\jscript9.dll ----A---- C:\Windows\SYSWOW64\jsproxy.dll ----A---- C:\Windows\system32\jscript.dll ----A---- C:\Windows\SYSWOW64\mshtml.dll ----A---- C:\Windows\system32\mshtml.dll ----A---- C:\Windows\SYSWOW64\ieframe.dll ----A---- C:\Windows\system32\ieframe.dll ----A---- C:\Windows\system32\csrsrv.dll ----A---- C:\Windows\system32\win32k.sys ----A---- C:\Windows\system32\EncDec.dll ----A---- C:\Windows\SYSWOW64\EncDec.dll ----A---- C:\Windows\SYSWOW64\tzres.dll ----A---- C:\Windows\system32\tzres.dll

======List of files/folders modified in the last 1 month====== 2012-01-12 2012-01-12 2012-01-12 2012-01-12 2012-01-12 2012-01-12 2012-01-12 2012-01-12 2012-01-12 2012-01-12 2012-01-12 2012-01-12 2012-01-12 2012-01-12 2012-01-12 2012-01-12 2012-01-12 16:11:35 16:10:04 16:07:41 16:04:02 16:02:50 15:06:12 15:06:09 13:26:27 13:26:26 13:22:53 13:00:01 09:47:26 09:23:51 09:23:12 09:22:58 09:22:04 09:22:04 ----D---- C:\Users\jplu\AppData\Roaming\.purple ----D---- C:\Users\jplu\AppData\Roaming\Skype ----D---- C:\Windows\Prefetch ----RD---- C:\Program Files ----D---- C:\Windows\Temp ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware ----D---- C:\Windows\system32\drivers ----D---- C:\Windows\system32\drivers\etc ----D---- C:\Windows\system32\Tasks ----SD---- C:\Users\jplu\AppData\Roaming\Microsoft ----D---- C:\Windows\system32\config ----SHD---- C:\Windows\Installer ----D---- C:\Users\jplu\AppData\Roaming\Dropbox ----D---- C:\Windows\winsxs ----D---- C:\ProgramData\NVIDIA ----D---- C:\Windows\SysWOW64 ----D---- C:\Windows\System32

2012-01-12 2012-01-11 2012-01-11 2012-01-11 2012-01-11 2012-01-11 2012-01-11 2012-01-11 2012-01-10 2012-01-10 2012-01-09 2012-01-09 2012-01-06 2012-01-06 2012-01-06 2012-01-06 2012-01-06 2011-12-15 2011-12-15 2011-12-15 2011-12-15 2011-12-15 2011-12-14 2011-12-14

09:22:04 19:50:10 19:50:07 19:50:06 19:49:16 18:09:35 13:57:58 13:57:58 17:55:39 16:29:04 12:39:40 12:39:40 18:10:40 18:10:34 18:10:31 10:22:42 10:22:42 13:02:29 10:39:05 10:39:05 10:39:05 10:39:05 18:42:48 18:42:48

----D---- C:\Windows\ehome ----A---- C:\Windows\system32\MRT.exe ----HD---- C:\Config.Msi ----D---- C:\ProgramData\Microsoft Help ----SHD---- C:\System Volume Information ----D---- C:\Windows\system32\NDF ----D---- C:\Windows\system32\catroot2 ----D---- C:\Windows\system32\catroot ----RSD---- C:\Windows\Fonts ----D---- C:\Users\jplu\AppData\Roaming\Spotify ----RSD---- C:\Windows\assembly ----D---- C:\Windows\Microsoft.NET ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI ----D---- C:\Windows\inf ----A---- C:\Windows\system32\PerfStringBackup.INI ----RD---- C:\Program Files (x86) ----HD---- C:\ProgramData ----D---- C:\Windows\rescache ----D---- C:\Windows\SYSWOW64\migration ----D---- C:\Windows\system32\migration ----D---- C:\Program Files\Internet Explorer ----D---- C:\Program Files (x86)\Internet Explorer ----D---- C:\Windows\SYSWOW64\fr-FR ----D---- C:\Windows\system32\fr-FR

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2009-04-29 23913 6] R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213 888] R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys [2 011-04-22 277088] R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-12-13 834544] R0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273); C:\Windo ws\system32\DRIVERS\tdrpm273.sys [2011-04-22 1263200] R0 timounter;Acronis Backup Archive Explorer; C:\Windows\system32\DRIVERS\timntr .sys [2011-04-22 970336] R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2011-08-31 123784] R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2009 -06-02 22576] R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06 -02 20016] R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06 -02 60464] R2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [2008-06-27 88632] R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2011-08-31 88288 ] R3 afcdp;afcdp; C:\Windows\system32\DRIVERS\afcdp.sys [2011-04-22 285280] R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM. sys [2009-05-18 34152] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\d rivers\RTKVHD64.sys [2009-07-20 1831968] R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-1 2-10 23152] R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2009-05-06 1843 2] R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\dr

ivers\nvhda64v.sys [2009-11-12 84584] R3 NVNET;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\n vmf6264.sys [2009-04-30 339360] R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2009-04-24 28704] R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2009-05-06 1 6896] S3 abllpw6q;abllpw6q; C:\Windows\system32\drivers\abllpw6q.sys [] S3 catchme;catchme; \??\C:\Users\jplu\AppData\Local\Temp\catchme.sys [] S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920] S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\drivers\Dot 4Prt.sys [2010-11-20 19968] S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb .sys [2009-07-14 43008] S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIV ERS\nvm62x64.sys [2009-06-10 408960] S3 RTL8187B;Carte rseau USB2.0 Realtek RTL8187B sans fil 802.11b/g 54Mbits/s; C:\Wi ndows\system32\DRIVERS\RTL8187B.sys [2009-06-10 416768] S3 StillCam;Pilote dappareil photo numrique srie; C:\Windows\system32\DRIVERS\sersc an.sys [2009-07-14 12288] S3 tap0901;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2011-0 4-26 31232] S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\ drivers\tsusbflt.sys [2010-11-20 59392] S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2010-04-19 50688] S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009 -07-14 41984] S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand , 4=Disabled)====== R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; C:\Program Files (x86)\Common Files\ABBYY\FineReader\9.00\Licensing\PE \NetworkLicenseServer.exe [2007-12-06 660768] R2 AcrSch2Svc;Service Scheduler2 Acronis; C:\Program Files (x86)\Common Files\Ac ronis\Schedule2\schedul2.exe [2011-02-01 1112640] R2 afcdpsrv;Service Acronis Nonstop Backup; C:\Program Files (x86)\Common Files\ Acronis\CDP\afcdpsrv.exe [2011-04-22 3246040] R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files (x86)\A vira\AntiVir Desktop\sched.exe [2011-04-28 136360] R2 AntiVirService;Avira AntiVir Guard; C:\Program Files (x86)\Avira\AntiVir Desk top\avguard.exe [2011-08-31 269480] R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\ Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-06-10 144176] R2 AWRScheduler;Advanced Web Ranking Scheduler; C:\Program Files (x86)\Caphyon\A dvanced Web Ranking\Scheduler.exe [2011-04-18 115136] R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Applica tion Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin 32\nSvcAppFlt.exe [2009-04-19 625184] R2 Greg_Service;GRegService; C:\Program Files (x86)\Acer\Registration\GregHSRW.e xe [2009-06-04 1150496] R2 hpqddsvc;Service HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [200 9-07-14 27136] R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2009-07 -14 27136] R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mb amservice.exe [2011-12-24 652872] R2 MWLService;MyWinLocker Service; C:\Program Files (x86)\EgisTec\MyWinLocker 3\

x86\\MWLService.exe [2009-08-06 311592] R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-1 4 27136] R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAcces sManager\bin32\nSvcIp.exe [2009-04-19 207904] R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems \Acer Backup Manager\IScheduleSvc.exe [2009-08-12 62208] R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-1 4 27136] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\ NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-01-11 240232] R2 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterSe rvice.exe [2009-07-04 240160] R3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\C ommon Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-0 3-01 655624] R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 27136] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] S2 gupdate;Service Google Update (gupdate); C:\Program Files (x86)\Google\Update \GoogleUpdate.exe [2010-04-01 135664] S3 aspnet_state;Service d tat ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0. 30319\aspnet_state.exe [2010-03-18 44376] S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\C ommon Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011 -02-15 1038088] S3 gupdatem;Service Google Update (gupdatem); C:\Program Files (x86)\Google\Upda te\GoogleUpdate.exe [2010-04-01 135664] S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Up dater\GoogleUpdaterService.exe [2009-08-14 182768] S3 iPod Service;Service de liPod; C:\Program Files\iPod\bin\iPodService.exe [2010 -06-15 653616] S3 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files (x8 6)\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-07-28 935208] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Fi les\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Share d\Source Engine\OSE.EXE [2006-10-26 145184] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wa t\WatAdminSvc.exe [2010-05-26 1255736] S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceMod elInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost .exe [2010-03-18 124240] S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceMod elInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost .exe [2010-03-18 124240] S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceMode lInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost. exe [2010-03-18 124240] -----------------EOF-----------------

You might also like