Avast a trouvé un virus win 32 que j'ai mis en quarantaine mais depuis 3 jours j'ai des plantages à répétitions sur des logiciels, par exemple Firefox qui indique "ne répond pas " a répétition et empêche la navigation. Je vous poste ci dessous copie du rapport OTL que je viens d'effectuer .
Merci par avance de vos conseils
Code : Tout sélectionner
OTL logfile created on: 01/01/2016 16:26:51 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\sophie\Desktop\telecharg
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18124)
Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy
1,87 Gb Total Physical Memory | 0,74 Gb Available Physical Memory | 39,72% Memory free
3,75 Gb Paging File | 2,47 Gb Available in Paging File | 65,89% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 35,15 Gb Total Space | 5,01 Gb Free Space | 14,24% Space Free | Partition Type: NTFS
Drive D: | 39,36 Gb Total Space | 20,55 Gb Free Space | 52,22% Space Free | Partition Type: FAT32
Drive G: | 74,53 Gb Total Space | 28,11 Gb Free Space | 37,72% Space Free | Partition Type: NTFS
Drive Z: | 228,13 Gb Total Space | 60,32 Gb Free Space | 26,44% Space Free | Partition Type: NTFS
Computer Name: PCF | User Name: sophie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2016/01/01 16:26:29 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\sophie\Desktop\telecharg\OTL(1).exe
PRC - [2015/12/31 12:24:23 | 003,442,368 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_20_0_0_267.exe
PRC - [2015/12/30 22:17:31 | 000,392,136 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2015/12/08 22:53:17 | 000,443,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\GWX\GWX.exe
PRC - [2015/11/21 02:38:09 | 007,004,376 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2015/11/21 02:38:06 | 000,174,416 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/11/23 03:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012/01/18 05:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
PRC - [2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - [2015/12/31 12:24:22 | 017,882,304 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_20_0_0_267.dll
MOD - [2015/11/21 02:38:08 | 000,466,448 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\ffl2.dll
MOD - [2015/11/21 02:38:08 | 000,103,888 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\log.dll
MOD - [2015/11/21 02:38:06 | 000,125,512 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
MOD - [2015/11/12 03:08:28 | 000,797,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\fc0cb289aaf886978a3406099b59ac42\System.Runtime.Remoting.ni.dll
MOD - [2015/05/13 23:58:03 | 000,967,680 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\908075c4922acdf834c67ac802814c9d\System.Configuration.ni.dll
MOD - [2015/05/06 22:44:41 | 040,540,672 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2015/05/05 07:21:58 | 010,069,504 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\d18e2115a3270f89663fce831547f534\System.ni.dll
MOD - [2015/05/05 06:45:44 | 007,793,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\3d6ee4ffbd9a86ac1e7b01800b6fe9c7\System.Xml.ni.dll
MOD - [2015/05/05 06:42:19 | 017,207,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\d1265d6159ea876f9d63ea4c1361b587\mscorlib.ni.dll
[color=#E56717]========== Services (SafeList) ==========[/color]
SRV - [2015/12/31 12:24:23 | 000,269,504 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2015/11/21 02:38:06 | 000,174,416 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2015/11/10 01:03:07 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2015/07/22 18:53:34 | 000,937,984 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\diagtrack.dll -- (DiagTrack)
SRV - [2013/05/27 05:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2013/02/20 15:08:53 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2013/01/03 12:42:57 | 001,259,448 | ---- | M] (NVIDIA Corporation) [On_Demand | Stopped] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012/01/18 05:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2009/07/14 02:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\Users\sophie\AppData\Local\Temp\mbr.sys -- (mbr)
DRV - File not found [Kernel | On_Demand | Running] -- C:\Users\sophie\AppData\Local\Temp\CFcatchme.sys -- (CFcatchme)
DRV - File not found [Kernel | On_Demand | Running] -- C:\Users\sophie\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - [2016/01/01 15:07:19 | 000,040,304 | ---- | M] (Greatis Software) [Kernel | On_Demand | Unknown] -- C:\Windows\System32\drivers\Partizan.sys -- (Partizan)
DRV - [2015/12/30 22:03:43 | 000,019,984 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\EsgScanner.sys -- (EsgScanner)
DRV - [2015/11/21 02:38:15 | 000,435,464 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2015/11/21 02:38:15 | 000,209,432 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2015/11/21 02:38:15 | 000,117,200 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aswStm.sys -- (aswStm)
DRV - [2015/11/21 02:38:14 | 000,081,728 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr2.sys -- (aswRdr)
DRV - [2015/11/21 02:38:14 | 000,081,168 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2015/11/21 02:38:14 | 000,049,776 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2015/11/21 02:38:14 | 000,024,016 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aswHwid.sys -- (aswHwid)
DRV - [2015/11/21 02:37:57 | 000,794,952 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2014/09/05 13:09:00 | 000,038,984 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\aswTap.sys -- (aswTap)
DRV - [2013/07/25 16:53:46 | 000,018,944 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\netaapl.sys -- (Netaapl)
DRV - [2013/02/19 21:32:54 | 010,919,200 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2012/08/17 22:31:10 | 001,321,568 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\netr28u.sys -- (netr28u)
DRV - [2012/01/18 05:44:52 | 004,332,960 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC)
DRV - [2012/01/18 05:44:28 | 000,312,096 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvrs.sys -- (LVRS)
DRV - [2010/11/20 22:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 22:29:03 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 22:29:03 | 000,062,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dmvsc.sys -- (dmvsc)
DRV - [2010/11/20 22:29:03 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 22:29:03 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 22:29:03 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 22:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV - [2010/11/20 22:29:03 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 22:29:03 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/08/12 12:07:48 | 000,298,216 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmf6232.sys -- (NVNET)
DRV - [2010/03/31 03:13:28 | 000,379,904 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTL8187B.sys -- (RTL8187B)
DRV - [2009/07/14 01:18:07 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2009/07/14 00:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/13 23:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
DRV - [2006/10/17 14:44:00 | 000,007,680 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2005/10/11 17:07:38 | 000,393,088 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\senfilt.sys -- (SenFiltService)
DRV - [2005/06/20 09:12:00 | 000,215,040 | ---- | M] (SiS Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sis163u.sys -- (SIS163u)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Users\sophie\Desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.search.countryCode: "FR"
FF - prefs.js..browser.search.hiddenOneOffs: "Yahoo,Bing,Amazon.fr,DuckDuckGo,eBay France,Portail Lexical - CNRTL,Wikipédia (fr)"
FF - prefs.js..browser.search.region: "FR"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "https://www.google.fr/?gws_rd=ssl"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:44.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_267.dll ()
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp: C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf: C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.0: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013/02/25 09:49:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2015/11/21 20:05:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\SafePrice\FF [2015/11/21 02:38:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2015/12/30 22:17:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 28.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2015/12/30 22:17:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 44.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 44.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2015/12/30 22:17:13 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013/02/25 09:49:02 | 000,000,000 | ---D | M]
[2015/04/30 16:37:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\sophie\AppData\Roaming\mozilla\Extensions
[2015/12/31 13:36:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\sophie\AppData\Roaming\mozilla\Firefox\Profiles\owwmyve3.default-1442839411105\extensions
[2015/12/15 23:01:48 | 000,989,188 | ---- | M] () (No name found) -- C:\Users\sophie\AppData\Roaming\mozilla\firefox\profiles\owwmyve3.default-1442839411105\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2015/12/30 22:17:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2015/12/30 22:17:02 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
O1 HOSTS File: ([2016/01/01 16:01:30 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run-Disabled: Policies = "C:\Windows\system32\windir\svchost.exe"
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run-Disabled: Policies = "C:\Windows\system32\windir\svchost.exe"
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe (Hewlett-Packard)
O16 - DPF: Microsoft XML Parser for Java file:///C:/Windows/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2BCA4CB4-323F-4275-896D-B31E4806396A}: DhcpNameServer = 192.168.0.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{82594609-2D22-4E0C-9C47-5A1B86B26B42}: DhcpNameServer = 192.168.0.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{86EB4940-4DE5-485D-AC49-2FACF17578EE}: DhcpNameServer = 192.168.0.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C987F703-2EB0-42DC-AEAF-59C11CCD01E0}: DhcpNameServer = 172.20.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F0B1CE05-78F8-4FA0-9FC2-E0CC84609E14}: DhcpNameServer = 192.168.0.254
O18 - Protocol\Handler\wlmailhtml - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (Partizan)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2016/01/01 16:01:37 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2016/01/01 15:46:00 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2016/01/01 15:46:00 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2016/01/01 15:46:00 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2016/01/01 15:45:11 | 000,000,000 | ---D | C] -- C:\Qoobox
[2016/01/01 15:07:19 | 000,040,304 | ---- | C] (Greatis Software) -- C:\Windows\System32\drivers\Partizan.sys
[2016/01/01 14:58:17 | 000,000,000 | ---D | C] -- C:\ProgramData\RegRun
[2016/01/01 14:56:38 | 000,047,920 | ---- | C] (Greatis Software) -- C:\Windows\System32\partizan.exe
[2016/01/01 14:56:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reanimator
[2016/01/01 14:56:33 | 000,000,000 | ---D | C] -- C:\Program Files\Greatis
[2015/12/31 21:08:25 | 000,000,000 | R--D | C] -- C:\Users\sophie\Videos
[2015/12/31 21:08:25 | 000,000,000 | R--D | C] -- C:\Users\sophie\Pictures
[2015/12/31 21:08:25 | 000,000,000 | R--D | C] -- C:\Users\sophie\Music
[2015/12/31 19:37:16 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2015/12/31 19:34:13 | 000,000,000 | ---D | C] -- C:\Users\sophie\Desktop\telecharg
[2015/12/31 18:26:10 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
[2015/12/31 18:26:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2015/12/31 15:22:12 | 000,000,000 | ---D | C] -- C:\Program Files\DVD Maker
[2015/12/31 15:00:19 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2015/12/30 23:22:14 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2015/12/30 22:55:23 | 000,000,000 | ---D | C] -- C:\Program Files\ExploreTech
[2015/12/30 22:50:10 | 000,000,000 | R--D | C] -- C:\Users\sophie\Downloads
[2015/12/30 22:50:10 | 000,000,000 | ---D | C] -- C:\Users\sophie\AppData\Roaming\Opera Software
[2015/12/30 22:49:18 | 000,000,000 | ---D | C] -- C:\Program Files\Opera
[2015/12/30 22:17:00 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2015/12/30 22:16:51 | 000,000,000 | ---D | C] -- C:\Users\sophie\Desktop\el biar
[2015/12/30 22:04:54 | 000,000,000 | ---D | C] -- C:\Users\sophie\Start Menu
[2015/12/30 18:39:09 | 000,000,000 | ---D | C] -- C:\ProgramData\GlarySoft
[2015/12/30 18:37:43 | 000,000,000 | ---D | C] -- C:\Users\sophie\AppData\Roaming\GlarySoft
[2015/12/30 18:18:01 | 000,000,000 | ---D | C] -- C:\Users\sophie\AppData\Roaming\EasyDuplicateFinder
[2015/12/30 18:18:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Easy Duplicate Finder
[2015/12/30 17:42:22 | 000,000,000 | ---D | C] -- C:\Users\sophie\AppData\Roaming\DigitalVolcano
[2015/12/30 17:41:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Duplicate Cleaner Free
[2015/12/30 17:02:09 | 000,000,000 | R--D | C] -- C:\Users\sophie\Documents
[2015/12/29 23:40:55 | 000,000,000 | R--D | C] -- C:\Users\sophie\Searches
[2015/12/29 23:25:41 | 000,000,000 | R--D | C] -- C:\Users\sophie\Favorites
[2015/12/29 22:51:55 | 000,000,000 | ---D | C] -- C:\Users\sophie\AppData\Local\Google
[2015/12/29 22:51:49 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2015/12/29 17:54:37 | 000,000,000 | ---D | C] -- C:\Users\sophie\AppData\Roaming\iOrgSoft
[2015/12/29 13:09:45 | 000,000,000 | ---D | C] -- C:\Users\sophie\AppData\Roaming\Awesome Duplicate Photo Finder
[2015/12/29 13:04:59 | 000,000,000 | ---D | C] -- C:\Users\sophie\AppData\Roaming\FastStone
[2015/12/25 20:37:32 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2015/12/19 14:39:57 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DVDVideoSoft
[2015/12/10 23:39:24 | 000,000,000 | ---D | C] -- C:\Users\sophie\Desktop\doc verneret
[2015/12/09 14:01:19 | 002,386,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2015/12/09 14:01:19 | 001,251,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2015/12/09 14:01:10 | 000,684,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2015/12/09 14:01:10 | 000,667,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe
[2015/12/09 14:01:10 | 000,341,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2015/12/09 14:01:10 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2015/12/09 14:01:10 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollector.exe
[2015/12/09 14:01:10 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\JavaScriptCollectionAgent.dll
[2015/12/09 14:01:10 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwproxystub.dll
[2015/12/09 14:01:10 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2015/12/09 14:01:10 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2015/12/09 14:01:09 | 002,724,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2015/12/09 14:01:09 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2015/12/09 14:01:09 | 000,687,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2015/12/09 14:01:09 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9diag.dll
[2015/12/09 14:01:09 | 000,416,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2015/12/09 14:01:08 | 002,050,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2015/12/09 14:01:08 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2015/12/09 14:01:07 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2015/12/09 14:01:07 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollectorres.dll
[2015/12/09 14:01:06 | 000,279,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2015/12/09 14:01:05 | 000,476,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2015/12/09 14:01:03 | 000,341,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2015/12/09 14:01:02 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll
[2015/12/09 14:01:02 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MshtmlDac.dll
[2015/12/09 14:00:58 | 004,514,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2015/12/09 13:59:57 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2015/12/09 13:59:51 | 002,956,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2015/12/09 13:59:51 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2015/12/09 13:59:51 | 000,174,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2015/12/09 13:59:51 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2015/12/09 13:59:51 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinSetupUI.dll
[2015/12/09 13:59:51 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2015/12/09 13:59:51 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2015/12/09 13:59:51 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2015/12/09 13:59:51 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wu.upgrade.ps.dll
[2015/12/09 13:59:44 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\nlsbres.dll
[2015/12/09 13:59:44 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kbdgeoqw.dll
[2015/12/09 13:59:44 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDAZEL.DLL
[2015/12/09 13:59:44 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\KBDAZE.DLL
[2015/12/09 13:59:41 | 000,179,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\els.dll
[2015/12/09 13:59:39 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\rmcast.sys
[2015/12/09 13:59:39 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wshrm.dll
[2015/12/03 14:38:50 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AV
[2 C:\Users\sophie\Desktop\*.tmp files -> C:\Users\sophie\Desktop\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2016/01/01 16:09:57 | 000,033,632 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2016/01/01 16:09:57 | 000,033,632 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2016/01/01 16:01:30 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2016/01/01 15:59:05 | 1509,449,728 | -HS- | M] () -- C:\hiberfil.sys
[2016/01/01 15:44:00 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2016/01/01 15:18:05 | 000,761,238 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2016/01/01 15:18:05 | 000,666,890 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2016/01/01 15:18:05 | 000,156,846 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2016/01/01 15:18:05 | 000,127,856 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2016/01/01 15:07:19 | 000,040,304 | ---- | M] (Greatis Software) -- C:\Windows\System32\drivers\Partizan.sys
[2016/01/01 14:56:44 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2016/01/01 14:56:44 | 000,001,688 | ---- | M] () -- C:\Windows\System32\autoexec.nt
[2016/01/01 14:56:44 | 000,000,002 | RHS- | M] () -- C:\Windows\winstart.bat
[2016/01/01 14:56:38 | 000,001,074 | ---- | M] () -- C:\Users\sophie\Desktop\Reanimator.lnk
[2015/12/31 22:07:49 | 000,408,432 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2015/12/31 12:24:23 | 000,796,864 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2015/12/31 12:24:23 | 000,142,528 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2015/12/30 23:25:39 | 000,000,970 | ---- | M] () -- C:\Users\sophie\Desktop\Mozilla Firefox.lnk
[2015/12/30 22:03:43 | 000,019,984 | ---- | M] () -- C:\Windows\System32\drivers\EsgScanner.sys
[2015/12/30 17:59:43 | 008,622,330 | ---- | M] () -- C:\Users\sophie\Desktop\Diaporama2.exe
[2015/12/30 17:26:30 | 017,578,542 | ---- | M] () -- C:\Users\sophie\Desktop\Diaporama.exe
[2015/12/25 20:37:33 | 000,000,928 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2015/12/06 18:37:39 | 001,501,436 | ---- | M] () -- C:\Users\sophie\Desktop\fiscalite_du_vehicule.pdf
[2 C:\Users\sophie\Desktop\*.tmp files -> C:\Users\sophie\Desktop\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2016/01/01 15:46:00 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2016/01/01 15:46:00 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2016/01/01 15:46:00 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2016/01/01 15:46:00 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2016/01/01 15:46:00 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2016/01/01 14:56:44 | 000,000,002 | RHS- | C] () -- C:\Windows\winstart.bat
[2016/01/01 14:56:38 | 000,001,074 | ---- | C] () -- C:\Users\sophie\Desktop\Reanimator.lnk
[2015/12/31 22:07:32 | 000,408,432 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2015/12/30 22:03:43 | 000,019,984 | ---- | C] () -- C:\Windows\System32\drivers\EsgScanner.sys
[2015/12/30 17:59:43 | 008,622,330 | ---- | C] () -- C:\Users\sophie\Desktop\Diaporama2.exe
[2015/12/30 17:26:30 | 017,578,542 | ---- | C] () -- C:\Users\sophie\Desktop\Diaporama.exe
[2015/12/25 20:37:33 | 000,000,928 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2015/12/25 19:33:19 | 000,001,002 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015/12/06 18:37:38 | 001,501,436 | ---- | C] () -- C:\Users\sophie\Desktop\fiscalite_du_vehicule.pdf
[2015/09/09 22:46:22 | 000,000,079 | ---- | C] () -- C:\Windows\wininit.ini
[2015/01/02 20:16:18 | 000,006,550 | ---- | C] () -- C:\Windows\jautoexp.dat
[2015/01/02 19:54:39 | 000,014,848 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll
[2014/12/23 01:23:11 | 000,000,239 | ---- | C] () -- C:\Users\sophie\AppData\Roaming\prefsdb.dat
[2014/05/12 01:30:55 | 000,005,355 | ---- | C] () -- C:\Windows\hpomdl18.dat.temp
[2014/01/30 21:29:32 | 000,002,478 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[color=#E56717]========== ZeroAccess Check ==========[/color]
[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015/08/06 18:44:51 | 012,875,776 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 22:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report >