cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.7.19.96 By Nicolas Coolman (2015/07/19)
~ Run by Abokr (Administrator) (2015/07/20 06:31:32)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ State version: Version OK
~ Mode: Scan
~ Report: C:\Users\Abokr\Desktop\ZHPDiag.txt
~ Report: C:\Users\Abokr\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Deactivate
~ System startup: Normal (Normal boot)
~ Windows 7, 32-bit Service Pack 1 (Build 7601)

---\\ Internet Browsers (3) - 0s
GCIE: Google Chrome v43.0.2357.81
MFIE: Mozilla Firefox 37.0.1 (x86 ar) v37.0.1
MSIE: Internet Explorer v10.0.9200.16635

---\\ Windows Product Information (3) - 1s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Activation Technologies : OK

---\\ System protection software (1) - 1s
Malwarebytes Anti-Malware version 2.1.8.1057

---\\ System optimization software (1) - 1s
CCleaner v4.13

---\\ Surveillance software (2) - 1s
Adobe Flash Player 18 NPAPI
Adobe Reader XI

---\\ Information on the system (6) - 0s
~ Operating System: x86 Family 6 Model 23 Stepping 10, GenuineIntel
~ Operating System: 32-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 2086.392 MB (20% free)
~ System Restore: Activé (Enable)
~ System drive C: has 9 GB free of 309 GB

---\\ Connection to the system mode (3) - 0s
~ Computer Name: ABOKR-PC
~ User Name: Abokr
~ Logged in as Administrator

---\\ Enumeration of the disk units (2) - 6s
~ Drive C: has 9 GB free of 309 GB (System)
~ Drive D: has 63 GB free of 166 GB

---\\ Search Generic System Files (24) - 1s
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - ãÓÊßÔÝ Windows.) () -- C:\Windows\Explorer.exe [2616320]
[MD5.51138BEEA3E2C21EC44D0932C71762A8] - (.Microsoft Corporation - ÚãáíÉ ãÖíÝ Windows (Rundll32)ý.) () -- C:\Windows\System32\rundll32.exe [44544]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - ýýÊØÈíÞ ÈÏÁ ÊÔÛíá Windows.) () -- C:\Windows\System32\Wininit.exe [96256]
[MD5.9BF7C7654EFD098EE3A27B49492A382A] - (.Microsoft Corporation - ãáÍÞÇÊ ÇáÅäÊÑäÊ áÜ Win32.) () -- C:\Windows\System32\wininet.dll [1767936]
[MD5.6D13E1406F50C66E2A95D97F22C47560] - (.Microsoft Corporation - ÊØÈíÞ ÊÓÌíá ÏÎæá Windows.) () -- C:\Windows\System32\Winlogon.exe [286720]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - ãßÊÈÉ ÊÑÇÎíÕ ÇáÈÑÇãÌ.) () -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.129F80D7868E30DF3E3DE33A1D3132B4] - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) () -- C:\Windows\System32\fr-FR\user32.dll.mui [20480]
[MD5.9EBBBA55060F786F0FCAA3893BFA2806] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\Windows\System32\drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\Windows\System32\drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\Windows\System32\drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\Windows\System32\drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\Windows\System32\drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\Windows\System32\drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - ÈÑäÇãÌ ÊÔÛíá ãäÝÐ i8042.) () -- C:\Windows\System32\drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\Windows\System32\drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) () -- C:\Windows\System32\drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\Windows\System32\drivers\netBT.sys [187904]
[MD5.5E43D2B0EE64123D4880DFA6626DEFDE] - (.Microsoft Corporation - NT File System Driver.) () -- C:\Windows\System32\drivers\ntfs.sys [1211752]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - ÈÑäÇãÌ ÊÔÛíá ÇáãäÝÐ ÇáãÊæÇÒí.) () -- C:\Windows\System32\drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\Windows\System32\drivers\Rasl2tp.sys [78848]
[MD5.B973FCFC50DC1434E1970A146F7E3885] - (.Microsoft Corporation - Microsoft RDP Device redirector.) () -- C:\Windows\System32\drivers\rdpdr.sys [133632]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) () -- C:\Windows\System32\drivers\smb.sys [71168]
[MD5.B459575348C20E8121D6039DA063C704] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\Windows\System32\drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - ÈÑäÇãÌ ÊÔÛíá ÎÏãÉ ãáÝÇÊ ÇáÙá ÇáÇÍÊíÇØíÉ áæÍ.) () -- C:\Windows\System32\drivers\volsnap.sys [245632]

---\\ Process running (11) - 1s
[MD5.DB20F308018D4CF85FA59888B32B997D] - (...) -- C:\Program Files\Clear Database\Clear Database.exe [8016599] [PID.1740]
[MD5.10B8F89D146D0E20B1284D47BB4EC6C9] - (.Devguru Co., Ltd. - Device Error Recovery SDK(x86).) -- C:\Windows\System32\dgdersvc.exe [95568] [PID.1776]
[MD5.F96C429788350DB4BA6771C3034DFD88] - (.Teruten - FsUsbDevice.) -- C:\Windows\System32\FsUsbExService.Exe [217088] [PID.1804]
[MD5.13506EA06B46A1AF984D52DF37567AB4] - (...) -- C:\Users\Abokr\AppData\Roaming\00000000-1429418606-0000-0000-001FD01E31BC\jnsn2D56.tmp [215040] [PID.2044] =>PUP.Optional.CrossRider
[MD5.96EFEC24346A8EB1157E80523079ADDC] - (...) -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056] [PID.404]
[MD5.4ACFC5853A3F0C6C2F54E537C23EE90F] - (.TeamViewer GmbH - TeamViewer 9.) -- C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe [4799760] [PID.1152]
[MD5.051DC25FDD891EE231259227D444326E] - (...) -- C:\Users\Abokr\AppData\Roaming\00000000-1429418606-0000-0000-001FD01E31BC\nsjD374.tmp [157696] [PID.1736] =>PUP.Optional.CrossRider
[MD5.1A536B01E64D26BED151C9BFA3EDCEB2] - (.Realtek Semiconductor - ÅÏÇÑÉ ÕæÊ Realtek HD.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [11430504] [PID.4056]
[MD5.308F2EE28005510DE616409148CF077B] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896] [PID.1840]
[MD5.EF3E22DB024654232D9232CD16D37615] - (.BlueStack Systems, Inc. - BlueStacks Agent.) -- C:\Program Files\BlueStacks\HD-Agent.exe [888440] [PID.3148]
[MD5.432F4E8794A2EA8A64E4C75EA80B790E] - (.BitTorrent Inc. - µTorrent.) -- C:\Users\Abokr\AppData\Roaming\uTorrent\uTorrent.exe [1694560] [PID.3260]

---\\ Google Chrome, Start,Search,Extensions (G0,G1,G2) (17) - 0s
G0 - GCSP: Preferences [User Data\Default][HomePage] http://gamesjobstarblack.in/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.facebook.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://clients1.google.com/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://epicunitscan.info/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://fbcdn-photos-c-a.akamaihd.net/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://fbcdn-profile-a.akamaihd.net/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://fbcdn-sphotos-a-a.akamaihd.net/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://fbstatic-a.akamaihd.net/
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.com.sa/
G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc.

---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (P2,M0,M1,M2,M3) (29) - 2s
M0 - MFSP: prefs.js [Abokr - c6gs1yl5.default-1377986054771] http://www.alarabeyes.com/
M1 - SPR:Search Page Redirection - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
P2 - EXT: (.RealNetworks, Inc. - RealPlayer(tm) LiveConnect-Enabled Plug-In.) -- C:\Program Files\Mozilla Firefox\Plugins\nppl3260.dll
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\Plugins\nppl3260.xpt
P2 - EXT: (.RealPlayer - RealPlayer Download Plugin.) -- C:\Program Files\Mozilla Firefox\Plugins\nprpplugin.dll
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\Plugins\QuickTimePlugin.class
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazondotcom.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\bing.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\eBay.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-ar.xml
P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo.xml
P2 - EXT: (.Mozilla - Default.) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\NPSWF32_18_0_0_209.dll
P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (.Apple Inc..) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
P2 - FPN: [HKLM] [@java.com/DTPlugin,version=10.67.2] - (.Oracle Corporation.) -- C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=10.67.2] - (.Oracle Corporation.) -- C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@real.com/nppl3260;version=16.0.3.51] - (.RealNetworks, Inc..) -- c:\program files\Real\realplayer\Netscape6\nppl3260.dll
P2 - FPN: [HKLM] [@real.com/nprndlchromebrowserrecordext;version=1.3.3] - (.RealNetworks, Inc..) -- C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
P2 - FPN: [HKLM] [@real.com/nprndlhtml5videoshim;version=1.3.3] - (.RealNetworks, Inc..) -- C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
P2 - FPN: [HKLM] [@real.com/nprndlpepperflashvideoshim;version=1.3.3] - (.RealNetworks, Inc..) -- C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
P2 - FPN: [HKLM] [@real.com/nprpplugin;version=16.0.3.51] - (.RealPlayer.) -- c:\program files\Real\realplayer\Netscape6\nprpplugin.dll
P2 - FPN: [HKLM] [@realnetworks.com/npdlplugin;version=1] - (.RealDownloader.) -- C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
P2 - FPN: [HKLM] [@rim.com/npappworld] - (...) -- C:\Program Files\Research In Motion Limited\BlackBerry App World Browser Plugin\npappworld.dll
P2 - FPN: [HKLM] [@RIM.com/WebSLLauncher,version=1.0] - (.Research In Motion.) -- C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.0.5] - (.VideoLAN.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll
P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.1.3] - (.VideoLAN.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll
P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.1.5] - (.VideoLAN.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll

---\\ Internet Explorer Extensions, Start, Search (R4,R3,R0,R1) (16) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://www.google.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = http://google.com
R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 2

---\\ Internet Explorer, Proxy Management (R5) (3) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Line Analysis F0, F1, F2, F3 - IniFiles, Auto loading programs (3) - 0s
F2 - REG:system.ini: UserInit=C:\Windows\system32\Userinit.exe (.Microsoft Corporation.)
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.)
F2 - REG:system.ini: VMApplet=C:\Windows\System32\shell32.dll (.Microsoft Corporation.)

---\\ Hosts file redirection (O1) (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (0)

---\\ Auto loading programs from Registry and folders (O4) (14) - 0s
O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - ÅÏÇÑÉ ÕæÊ Realtek HD.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe
O4 - HKCU\..\Run: [AdobeBridge] (Orphean)
O4 - HKCU\..\Run: [uTorrent] . (.BitTorrent Inc. - µTorrent.) -- C:\Users\Abokr\AppData\Roaming\uTorrent\uTorrent.exe
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_344EAA708D3DEB3BF3D87CB9142603FE] C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe (.not file.) =>PUP.Optional.CrossBrowse
O4 - HKCU\..\Run: [VideoBox] C:\Users\Abokr\AppData\Roaming\Baidu\VideoBox\VideoBox.exe (.not file.)
O4 - HKCU\..\Run: [iCloudServices] . (.Apple Inc. - iCloud.) -- C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - HKCU\..\Run: [ApplePhotoStreams] . (.Apple Inc. - Apple Photostreams Uploader Executable.) -- C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
O4 - HKUS\S-1-5-21-1597058447-2255405293-4085650674-1000\..\Run: [AdobeBridge] (Orphean)
O4 - HKUS\S-1-5-21-1597058447-2255405293-4085650674-1000\..\Run: [uTorrent] . (.BitTorrent Inc. - µTorrent.) -- C:\Users\Abokr\AppData\Roaming\uTorrent\uTorrent.exe
O4 - HKUS\S-1-5-21-1597058447-2255405293-4085650674-1000\..\Run: [GoogleChromeAutoLaunch_344EAA708D3DEB3BF3D87CB9142603FE] C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe (.not file.) =>PUP.Optional.CrossBrowse
O4 - HKUS\S-1-5-21-1597058447-2255405293-4085650674-1000\..\Run: [VideoBox] C:\Users\Abokr\AppData\Roaming\Baidu\VideoBox\VideoBox.exe (.not file.)
O4 - HKUS\S-1-5-21-1597058447-2255405293-4085650674-1000\..\Run: [iCloudServices] . (.Apple Inc. - iCloud.) -- C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - HKUS\S-1-5-21-1597058447-2255405293-4085650674-1000\..\Run: [ApplePhotoStreams] . (.Apple Inc. - Apple Photostreams Uploader Executable.) -- C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe

---\\ Lop.com/Domain Hijackers (O17) (6) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = afaqe2e.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpDomain = afaqe2e.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpDomain = afaqe2e.com

---\\ Non Microsoft non disabled Windows XP/NT/2000 Services (O23) (15) - 1s
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) . (...) - C:\Program Files\BlueStacks\HD-LogRotatorService.exe (.not file.)
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) . (.BlueStack Systems, Inc. - BlueStacks Updater Service.) - C:\Program Files\BlueStacks\HD-UpdaterService.exe
O23 - Service: Clear Database (Clear Database) . (...) - C:\Program Files\Clear Database\Clear Database.exe
O23 - Service: Device Error Recovery Service (dgdersvc) . (.Devguru Co., Ltd. - Device Error Recovery SDK(x86).) - C:\Windows\System32\dgdersvc.exe
O23 - Service: FsUsbExService (FsUsbExService) . (.Teruten - FsUsbDevice.) - C:\Windows\System32\FsUsbExService.Exe
O23 - Service: Google Update Service (gupdate) (gupdate) . (.Google Inc. - ãËÈøöÊ Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Upgrade Record (qesowobi) . (...) - C:\Users\Abokr\AppData\Roaming\00000000-1429418606-0000-0000-001FD01E31BC\jnsn2D56.tmp =>PUP.Optional.CrossRider
O23 - Service: RealNetworks Downloader Resolver Service (RealNetworks Downloader Resolver Service) . (...) - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: TeamViewer 9 (TeamViewer9) . (.TeamViewer GmbH - TeamViewer 9.) - C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: Bulletin Board Socket (xipepebe) . (...) - C:\Users\Abokr\AppData\Roaming\00000000-1429418606-0000-0000-001FD01E31BC\nsjD374.tmp =>PUP.Optional.CrossRider

---\\ Task Planned Automatically (O39) (46) - 6s
[MD5.E3FB05F33E1404AD606B1E1FE7C323C3] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [998104]
[MD5.9B3355B29942AF67F014EA90CE1EA960] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [268976]
[MD5.00000000000000000000000000000000] [APT] [Bidaily Synchronize Task[pr]] (...) -- c:\programdata\{398c853c-48cf-f853-398c-c853c48c14f1}\6807384055752097645s.exe (.not file.) [0] =>PUP.Optional.BidailySync
[MD5.03E07421C99D99D2DB8F4E5CCB890B23] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [4524312]
[MD5.00000000000000000000000000000000] [APT] [ChordBuddy] (...) -- c:\programdata\{e72caa25-96bb-7356-e72c-caa2596ba896}\120f.exe (.not file.) [0]
[MD5.C6FF00DA1605982E616C03BE809FFE2D] [APT] [GoogleUpdateTaskMachineCore1cec5de49bddfb9] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [144200]
[MD5.C6FF00DA1605982E616C03BE809FFE2D] [APT] [GoogleUpdateTaskMachineUA1cec5de4a96ddc6] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [144200]
[MD5.C55057DED2CE2944F6C2C87739E32063] [APT] [HPCustParticipation HP Deskjet 2050 J510 series] (.Hewlett-Packard Co..) -- C:\Program Files\HP\HP Deskjet 2050 J510 series\bin\HPCustPartic.exe [2938984]
[MD5.DDBE89226D55D694F1B7B3DD0C324640] [APT] [RealDownloaderDownloaderScheduledTaskS-1-5-21-1597058447-2255405293-4085650674-1000] (.RealNetworks, Inc..) -- C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe [233048]
[MD5.675DE4EC2D88A6D68C39C662A3204596] [APT] [RealDownloaderRealUpgradeLogonTaskS-1-5-21-1597058447-2255405293-4085650674-1000] (.RealNetworks, Inc..) -- C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe [187984]
[MD5.675DE4EC2D88A6D68C39C662A3204596] [APT] [RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1597058447-2255405293-4085650674-1000] (.RealNetworks, Inc..) -- C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe [187984]
[MD5.2A356FA2650E30E139F0476979548BF6] [APT] [RealPlayerRealUpgradeLogonTaskS-1-5-21-1597058447-2255405293-4085650674-1000] (.RealNetworks, Inc..) -- C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [187984]
[MD5.2A356FA2650E30E139F0476979548BF6] [APT] [RealPlayerRealUpgradeScheduledTaskS-1-5-21-1597058447-2255405293-4085650674-1000] (.RealNetworks, Inc..) -- C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [187984]
[MD5.2A356FA2650E30E139F0476979548BF6] [APT] [RealUpgradeLogonTaskS-1-5-21-1597058447-2255405293-4085650674-1000] (.RealNetworks, Inc..) -- C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [187984]
[MD5.2A356FA2650E30E139F0476979548BF6] [APT] [RealUpgradeScheduledTaskS-1-5-21-1597058447-2255405293-4085650674-1000] (.RealNetworks, Inc..) -- C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [187984]
[MD5.7CEF49745A2AA9FEE4155446D068551C] [APT] [ScheduledScan] (...) -- C:\Users\Abokr\AppData\Roaming\Flasher\c32s.exe [78848]
[MD5.00000000000000000000000000000000] [APT] [SustainerPlus] (...) -- c:\programdata\{2ece9395-6aef-324c-2ece-e93956ae4e55}\2015289736255108263b.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [TechSmith Updater] (...) -- C:\Program Files\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe (.not file.) [0]
[MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [Apple\AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [561984]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [830]
O39 - APT: Bidaily Synchronize Task[pr] - (...) -- C:\Windows\Tasks\Bidaily Synchronize Task[pr].job [354] =>PUP.Optional.BidailySync
O39 - APT: ChordBuddy - (...) -- C:\Windows\Tasks\ChordBuddy.job [322]
O39 - APT: GoogleUpdateTaskMachineCore1cec5de49bddfb9 - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cec5de49bddfb9.job [824]
O39 - APT: GoogleUpdateTaskMachineUA1cec5de4a96ddc6 - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cec5de4a96ddc6.job [828]
O39 - APT: SustainerPlus - (...) -- C:\Windows\Tasks\SustainerPlus.job [354]
O39 - APT: Adobe Acrobat Update Task - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Acrobat Update Task [3874]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [3768]
O39 - APT: Bidaily Synchronize Task[pr] - (...) -- C:\Windows\System32\Tasks\Bidaily Synchronize Task[pr] [3266] =>PUP.Optional.BidailySync
O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\Windows\System32\Tasks\CCleanerSkipUAC [2772]
O39 - APT: ChordBuddy - (...) -- C:\Windows\System32\Tasks\ChordBuddy [3234]
O39 - APT: GoogleUpdateTaskMachineCore1cec5de49bddfb9 - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1cec5de49bddfb9 [3572]
O39 - APT: GoogleUpdateTaskMachineUA1cec5de4a96ddc6 - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1cec5de4a96ddc6 [3824]
O39 - APT: HPCustParticipation HP Deskjet 2050 J510 series - (.Hewlett-Packard Co..) -- C:\Windows\System32\Tasks\HPCustParticipation HP Deskjet 2050 J510 series [3622]
O39 - APT: RealDownloaderDownloaderScheduledTaskS-1-5-21-1597058447-2255405293-4085650674-1000 - (.RealNetworks, Inc..) -- C:\Windows\System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1597058447-2255405293-4085650674-1000 [3370]
O39 - APT: RealDownloaderRealUpgradeLogonTaskS-1-5-21-1597058447-2255405293-4085650674-1000 - (.RealNetworks, Inc..) -- C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1597058447-2255405293-4085650674-1000 [3216]
O39 - APT: RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1597058447-2255405293-4085650674-1000 - (.RealNetworks, Inc..) -- C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1597058447-2255405293-4085650674-1000 [3350]
O39 - APT: RealPlayerRealUpgradeLogonTaskS-1-5-21-1597058447-2255405293-4085650674-1000 - (.RealNetworks, Inc..) -- C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1597058447-2255405293-4085650674-1000 [3194]
O39 - APT: RealPlayerRealUpgradeScheduledTaskS-1-5-21-1597058447-2255405293-4085650674-1000 - (.RealNetworks, Inc..) -- C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1597058447-2255405293-4085650674-1000 [3328]
O39 - APT: RealUpgradeLogonTaskS-1-5-21-1597058447-2255405293-4085650674-1000 - (.RealNetworks, Inc..) -- C:\Windows\System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1597058447-2255405293-4085650674-1000 [3196]
O39 - APT: RealUpgradeScheduledTaskS-1-5-21-1597058447-2255405293-4085650674-1000 - (.RealNetworks, Inc..) -- C:\Windows\System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1597058447-2255405293-4085650674-1000 [3328]
O39 - APT: ScheduledScan - (...) -- C:\Windows\System32\Tasks\ScheduledScan [3228]
O39 - APT: ScheduledScan - (...) -- C:\Windows\System32\Tasks\SidebarExecute [3148]
O39 - APT: SustainerPlus - (...) -- C:\Windows\System32\Tasks\SustainerPlus [3266]
O39 - APT: TechSmith Updater - (...) -- C:\Windows\System32\Tasks\TechSmith Updater [3780]
O39 - APT: TechSmith Updater - (...) -- C:\Windows\System32\Tasks\{85AF91C5-AC82-42CE-A37F-CA96BB2B5AA0} [3160]
O39 - APT: TechSmith Updater - (...) -- C:\Windows\System32\Tasks\{E645FF9B-89BC-414D-B5A8-0FA98EDA614D} [3258]

---\\ Software installed (O42) (89) - 15s
O42 - Logiciel: Active@ Password Changer Professional - (...) [HKLM] -- Active@ Password Changer Professional
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- Adobe AIR
O42 - Logiciel: Adobe Flash Player 18 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 18 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI
O42 - Logiciel: Adobe Shockwave Player 11.6 - (.Adobe Systems, Inc..) [HKLM] -- Adobe Shockwave Player
O42 - Logiciel: Adobe ExtendScript Toolkit 2 - (.Adobe Systems Incorporated.) [HKLM] -- Adobe_3e054d2218e7aa282c2369d939e58ff
O42 - Logiciel: Beyluxe Messenger - (.Hichatters Srl.) [HKLM] -- Beyluxe Messenger1
O42 - Logiciel: BlackBerry Desktop Software 7.1 - (.Research In Motion Ltd..) [HKLM] -- BlackBerry_Desktop
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: Adobe Help Manager - (.Adobe Systems Incorporated.) [HKLM] -- chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
O42 - Logiciel: D-Link VGA Webcam - (...) [HKLM] -- D-Link VGA Webcam
O42 - Logiciel: DreamBoxEdit -- The one and only settings editor for your Dreambox - (...) [HKLM] -- dreamboxEDIT
O42 - Logiciel: FastStone Capture 7.1 - (.FastStone Soft.) [HKLM] -- FastStone Capture
O42 - Logiciel: FormatFactory 3.2.0.1 - (.Free Time.) [HKLM] -- FormatFactory
O42 - Logiciel: Google Chrome - (.Google Incý.ý.) [HKLM] -- Google Chrome
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- HDMI
O42 - Logiciel: HP Photo Creations - (.HP.) [HKLM] -- HP Photo Creations
O42 - Logiciel: Malwarebytes Anti-Malware version 2.1.8.1057 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes Anti-Malware_is1
O42 - Logiciel: Mozilla Firefox 37.0.1 (x86 ar) - (.Mozilla.) [HKLM] -- Mozilla Firefox 37.0.1 (x86 ar)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService
O42 - Logiciel: PDF To JPG Converter 2.0.2 - (.PDF To JPG Converter.) [HKLM] -- PDF To JPG Converter_is1
O42 - Logiciel: TeamViewer 9 - (.TeamViewer.) [HKLM] -- TeamViewer 9
O42 - Logiciel: KMPlayer (remove only) - (.PandoraTV.) [HKLM] -- The KMPlayer
O42 - Logiciel: Topaz Clean 3 - (.Topaz Labs, LLC.) [HKLM] -- Topaz Clean 3
O42 - Logiciel: Intel(R) TV Wizard - (.Intel Corporation.) [HKLM] -- TVWiz
O42 - Logiciel: UltraISO Premium V9.31 - (...) [HKLM] -- UltraISO_is1
O42 - Logiciel: UsbFix - (.El Desaparecido - www.usbfix.net - www.sosvirus.net.) [HKLM] -- Usbfix
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM] -- VLC media player
O42 - Logiciel: WinRAR archiver - (...) [HKLM] -- WinRAR archiver
O42 - Logiciel: Your Uninstaller! 2010 - (.URSoft, Inc..) [HKLM] -- YU2010_is1
O42 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
O42 - Logiciel: BlackBerry Device Software Updater - (.Research In Motion Ltd.) [HKLM] -- {06A51130-C9D1-46BF-8F57-E0EFE3DBFEDE}
O42 - Logiciel: Active@ Password Changer Professional 5.0 - (.LSoft Technologies Inc.) [HKLM] -- {06DC3F36-F3F7-408E-909B-6D861D49E2E4}_is1
O42 - Logiciel: Sound Forge Audio Studio 10.0 - (.Sony.) [HKLM] -- {0A013EA1-A1D3-11E0-8DCF-005056C00008}
O42 - Logiciel: TL-WN321G Wireless Utility - (.TP-LINK.) [HKLM] -- {1FF78023-EFA4-491F-9F5A-284DE97AA326}
O42 - Logiciel: Microsoft Server Speech Platform Runtime (x86) - (.Microsoft Corporation.) [HKLM] -- {22CB8ED7-DF57-4864-BD04-F63B9CE4B494}
O42 - Logiciel: HP Deskjet 2050 J510 series ÏÑÇÓÉ ÊÍÓíä ÇáãäÊÌ - (.Hewlett-Packard Co..) [HKLM] -- {241807D5-5A8B-4D5D-BABA-7F8E9DF1677B}
O42 - Logiciel: Skype™ 7.1 - (.Skype Technologies S.A..) [HKLM] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}
O42 - Logiciel: Adobe ExtendScript Toolkit 2 - (.Adobe Systems Incorporated.) [HKLM] -- {24D7346D-D4B4-45E8-98EA-75EC14B42DD8}
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {268278CF-FB69-4D98-B70E-BFEC1CDCA225}
O42 - Logiciel: Java(TM) 6 Update 33 - (.Oracle.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216032FF}
O42 - Logiciel: Java 7 Update 67 - (.Oracle.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83217025FF}
O42 - Logiciel: RealUpgrade 1.1 - (.RealNetworks, Inc..) [HKLM] -- {28C2DED6-325B-4CC7-983A-1777C8F7FBAB}
O42 - Logiciel: Ralink RT2870 Wireless LAN Card - (.Ralink.) [HKLM] -- {28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}
O42 - Logiciel: Adobe Illustrator CS6 - (.Adobe Systems Incorporated.) [HKLM] -- {4869414E-7AEA-4C8E-BE1C-8D40977FD517}
O42 - Logiciel: Dassault Systemes Software VC9 Prerequisites x86 - (.Dassault Systemes.) [HKLM] -- {50BFDB3B-9CA8-477E-82FE-D3CD5F58F8C4}
O42 - Logiciel: OutlookAddInNet3Setup - (.Samsung.) [HKLM] -- {5B4383F2-37EE-4E97-AD81-F5FF76F286DA}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
O42 - Logiciel: swMSM - (.Adobe Systems, Inc.) [HKLM] -- {612C34C7-5E90-47D8-9B5C-0F717DD82726}
O42 - Logiciel: Image Resizer for Windows - (.Brice Lambson.) [HKLM] -- {6285B71F-660A-478B-A876-C7E66A678E6A}
O42 - Logiciel: Image Resizer for Windows - (.Brice Lambson.) [HKLM] -- {69d72156-6582-4556-8637-06f40aa7f85b}
O42 - Logiciel: Dassault Systemes Software Prerequisites x86 - (.Dassault Systemes.) [HKLM] -- {6DE6837F-F3A3-40FF-9F5C-A0B95948E32D}
O42 - Logiciel: TP-LINK Wireless Utility - (.TP-LINK.) [HKLM] -- {6FFEF5E1-F7B0-40DD-838D-557BD7EE4301}
O42 - Logiciel: MSVCRT Redists - (.Sony Creative Software Inc..) [HKLM] -- {7032B400-11EC-11E0-A9BF-0013D3D69929}
O42 - Logiciel: MSVCRT Redists - (.Sony Creative Software Inc..) [HKLM] -- {70CB6C40-8DF1-11E1-BDCF-F04DA23A5C58}
O42 - Logiciel: Microsoft Kinect Drivers v1.0 - (.Microsoft Corporation.) [HKLM] -- {71F69E61-EC59-447B-A2E1-0154FD8D96F2}
O42 - Logiciel: Adobe Photoshop CS6 - (.Adobe Systems Incorporated.) [HKLM] -- {74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}
O42 - Logiciel: Microsoft Kinect Speech Recognition Language Pack (en-US) - (.Microsoft Corporation.) [HKLM] -- {8AAA44BB-487E-4D01-AF76-484ACB90DBFE}
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
O42 - Logiciel: BlackBerry App World Browser Plugin - (.Research In Motion Limited.) [HKLM] -- {8DE03F6E-FCD2-4497-A8FF-F6C4430618B6}
O42 - Logiciel: MSVCRT110 - (.Microsoft.) [HKLM] -- {8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}
O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM] -- {912D30CF-F39E-4B31-AD9A-123C6B794EE2}
O42 - Logiciel: 32 Bit HP CIO Components Installer - (.Hewlett-Packard.) [HKLM] -- {92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}
O42 - Logiciel: Microsoft Kinect SDK v1.0 - (.Microsoft Corporation.) [HKLM] -- {A2F1481A-6C6F-49F5-B26B-E569F270C04F}
O42 - Logiciel: 32 Bit HP CIO Components Installer - (.Hewlett-Packard.) [HKLM] -- {A80FA752-C491-4ED9-ABF0-4278563160B2}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-0804-1033-1959-001824147215}
O42 - Logiciel: Adobe Reader XI (11.0.12) - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1033-7B44-AB0000000001}
O42 - Logiciel: Adobe Help Manager - (.Adobe Systems Incorporated.) [HKLM] -- {AF37176A-78CA-545B-34EF-8B6A21514DD1}
O42 - Logiciel: Microsoft Kinect Runtime v1.0 - (.Microsoft Corporation.) [HKLM] -- {B25A1C24-3789-4A96-A311-2146573C1091}
O42 - Logiciel: Adobe Setup - (.Adobe Systems Incorporated.) [HKLM] -- {B3C02EC1-A7B0-4987-9A43-8789426AAA7D}
O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {B67BAFBA-4C9F-48FA-9496-933E3B255044}
O42 - Logiciel: MSVCRT Redists - (.Sony Creative Software Inc..) [HKLM] -- {B8D84F70-0296-11E2-8DF5-F04DA23A5C58}
O42 - Logiciel: BlackBerry Desktop Software 7.1 - (.Research In Motion Ltd..) [HKLM] -- {BE5B0450-DCCB-4FE9-93E2-3B38D88A745B}
O42 - Logiciel: MSVCRT Redists - (.Sony Creative Software Inc..) [HKLM] -- {BFA49D40-85A5-11E1-8E8E-005056C00008}
O42 - Logiciel: PDF Settings CS6 - (.Adobe Systems Incorporated.) [HKLM] -- {BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}
O42 - Logiciel: RealDownloader - (.RealNetworks, Inc..) [HKLM] -- {C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}
O42 - Logiciel: Windows 7 USB/DVD Download Tool - (.Microsoft Corporation.) [HKLM] -- {CCF298AF-9CE1-4B26-B251-486E98A34789}
O42 - Logiciel: ãÚÑÖ ÇáÕæÑ - (.Microsoft Corporation.) [HKLM] -- {CF15F988-98D4-479F-9750-85A495BF8233}
O42 - Logiciel: ISO to USB - (.isotousb.com.) [HKLM] -- {D08A30AC-A663-4EA8-8D81-B98E17F19F1C}_is1
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {E14ADE0E-75F3-4A46-87E5-26692DD626EC}
O42 - Logiciel: MSVCRT Redists - (.Sony Creative Software Inc..) [HKLM] -- {E9627240-E930-11E0-8690-F04DA23A5C58}
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
O42 - Logiciel: QPSMR Companion 2012.2.4 - (.NetMR Ltd.) [HKLM] -- {F3380B34-1ED2-4906-A6F9-00363B387102}
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- {FE23D063-934D-4829-A0D8-00634CE79B4A}
O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU] -- uTorrent

---\\ HKCU & HKLM Software Keys (225) - 15s
HKLM\SOFTWARE\"alpha_installer"/n
HKLM\SOFTWARE\"charlie_installer"/n
HKLM\SOFTWARE\"echo_installer"/n
HKLM\SOFTWARE\ABSoft
HKLM\SOFTWARE\Adobe
HKLM\SOFTWARE\AdsFix
HKLM\SOFTWARE\AdwCleaner
HKLM\SOFTWARE\AppDataLow
HKLM\SOFTWARE\Apple Computer, Inc.
HKLM\SOFTWARE\Apple Inc.
HKLM\SOFTWARE\ATI Technologies
HKLM\SOFTWARE\AviSynth
HKLM\SOFTWARE\baidu
HKLM\SOFTWARE\Baidu Security
HKLM\SOFTWARE\Big Fish Games
HKLM\SOFTWARE\BlueStacks
HKLM\SOFTWARE\BriceLambson
HKLM\SOFTWARE\bsoft
HKLM\SOFTWARE\Bunndle
HKLM\SOFTWARE\CDDB
HKLM\SOFTWARE\Client
HKLM\SOFTWARE\cybelsoft
HKLM\SOFTWARE\CyberGhost
HKLM\SOFTWARE\Cygnus Solutions
HKLM\SOFTWARE\Docudesk
HKLM\SOFTWARE\Dolby
HKLM\SOFTWARE\DTS
HKLM\SOFTWARE\EASEUS
HKLM\SOFTWARE\EasyBoot Systems
HKLM\SOFTWARE\echo_update
HKLM\SOFTWARE\Extended Systems
HKLM\SOFTWARE\Facecons
HKLM\SOFTWARE\GEAR Software
HKLM\SOFTWARE\Google
HKLM\SOFTWARE\HaaliMkx
HKLM\SOFTWARE\Hewlett-Packard
HKLM\SOFTWARE\HP
HKLM\SOFTWARE\IM Providers
HKLM\SOFTWARE\Intel
HKLM\SOFTWARE\Internet Download Manager
HKLM\SOFTWARE\InterVideo
HKLM\SOFTWARE\JavaSoft
HKLM\SOFTWARE\JreMetrics
HKLM\SOFTWARE\KMPlayer
HKLM\SOFTWARE\Knowles
HKLM\SOFTWARE\LexmarkLaser
HKLM\SOFTWARE\Licenses
HKLM\SOFTWARE\Lightworks
HKLM\SOFTWARE\LogMeInRescueCallingCard
HKLM\SOFTWARE\Macromedia
HKLM\SOFTWARE\Macrovision
HKLM\SOFTWARE\Malwarebytes' Anti-Malware
HKLM\SOFTWARE\MaxPower
HKLM\SOFTWARE\MimarSinan
HKLM\SOFTWARE\MOVAVI
HKLM\SOFTWARE\Mozilla
HKLM\SOFTWARE\mozilla.org
HKLM\SOFTWARE\MozillaPlugins
HKLM\SOFTWARE\Nalpeiron
HKLM\SOFTWARE\ODBC
HKLM\SOFTWARE\OmniVision
HKLM\SOFTWARE\Pandora.TV
HKLM\SOFTWARE\PCDataApp
HKLM\SOFTWARE\Piriform
HKLM\SOFTWARE\Ralink
HKLM\SOFTWARE\RealNetworks
HKLM\SOFTWARE\Realtek
HKLM\SOFTWARE\Realtek Semiconductor Corp.
HKLM\SOFTWARE\Reg
HKLM\SOFTWARE\RegisteredApplications
HKLM\SOFTWARE\Research In Motion
HKLM\SOFTWARE\RocketLife
HKLM\SOFTWARE\S.A.D
HKLM\SOFTWARE\Samsung
HKLM\SOFTWARE\Skype
HKLM\SOFTWARE\Sonic
HKLM\SOFTWARE\SonicFocus
HKLM\SOFTWARE\Sony Creative Software
HKLM\SOFTWARE\Sony Media Software
HKLM\SOFTWARE\SOSVirus
HKLM\SOFTWARE\SRS Labs
HKLM\SOFTWARE\SUPERAntiSpyware.com
HKLM\SOFTWARE\Symantec
HKLM\SOFTWARE\Sysinternals
HKLM\SOFTWARE\TeamViewer
HKLM\SOFTWARE\TechSmith
HKLM\SOFTWARE\Topaz Labs
HKLM\SOFTWARE\TOSHIBA
HKLM\SOFTWARE\TP-LINK
HKLM\SOFTWARE\TuneUp
HKLM\SOFTWARE\VideoLAN
HKLM\SOFTWARE\Visan
HKLM\SOFTWARE\Volatile
HKLM\SOFTWARE\VST
HKLM\SOFTWARE\Waves Audio
HKLM\SOFTWARE\WinRAR
HKLM\SOFTWARE\WinUpdat =>PUP.Optional.WinRST
HKLM\SOFTWARE\Wise Solutions
HKLM\SOFTWARE\Wondershare
HKLM\SOFTWARE\Xing Technology Corp.
HKCU\SOFTWARE\2f66344d0d42634967c02eb2813fb628 =>PUP.Optional.CrossRider
HKCU\SOFTWARE\4shared
HKCU\SOFTWARE\8cc5db40eb97299bd658a6eaa7488f79 =>PUP.Optional.CrossRider
HKCU\SOFTWARE\ABSoft
HKCU\SOFTWARE\AC3filter
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\AdsFix
HKCU\SOFTWARE\Akeo Consulting
HKCU\SOFTWARE\AlterGeo
HKCU\SOFTWARE\AnchorFree
HKCU\SOFTWARE\AOL
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\Apple Computer, Inc.
HKCU\SOFTWARE\Apple Inc.
HKCU\SOFTWARE\Applications WinDev
HKCU\SOFTWARE\Baidu Security
HKCU\SOFTWARE\Beyluxe Messenger
HKCU\SOFTWARE\BitCtrl Systems GmbH
HKCU\SOFTWARE\BitTorrent
HKCU\SOFTWARE\Borland
HKCU\SOFTWARE\BriceLambson
HKCU\SOFTWARE\BugSplat
HKCU\SOFTWARE\CDDB
HKCU\SOFTWARE\ched
HKCU\SOFTWARE\Chromium
HKCU\SOFTWARE\CodeGear
HKCU\SOFTWARE\CompSoft
HKCU\SOFTWARE\Cygnus Solutions
HKCU\SOFTWARE\DirectShow
HKCU\SOFTWARE\DownloadAstro
HKCU\SOFTWARE\DownloadCenter
HKCU\SOFTWARE\dreamboxEDIT
HKCU\SOFTWARE\DreamMultimedia
HKCU\SOFTWARE\DXTransform
HKCU\SOFTWARE\EasyBits
HKCU\SOFTWARE\EasyBoot Systems
HKCU\SOFTWARE\Elecard
HKCU\SOFTWARE\Extended Systems
HKCU\SOFTWARE\Facecons
HKCU\SOFTWARE\FastStone
HKCU\SOFTWARE\FileOpen
HKCU\SOFTWARE\FreeTime
HKCU\SOFTWARE\Gabest
HKCU\SOFTWARE\Ge-Force-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\Haali
HKCU\SOFTWARE\Hewlett-Packard
HKCU\SOFTWARE\Host Process for Windows Services
HKCU\SOFTWARE\HP
HKCU\SOFTWARE\HubTech
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\INTEL
HKCU\SOFTWARE\JavaSoft
HKCU\SOFTWARE\KasperskyLab
HKCU\SOFTWARE\kde.org
HKCU\SOFTWARE\KMPlayer
HKCU\SOFTWARE\Licenses
HKCU\SOFTWARE\Lightworks
HKCU\SOFTWARE\LlamaWare
HKCU\SOFTWARE\Local AppWizard-Generated Applications
HKCU\SOFTWARE\LogMeInRescueCallingCard
HKCU\SOFTWARE\LSoft Technologies
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\MainConcept
HKCU\SOFTWARE\MainConcept (Consumer)
HKCU\SOFTWARE\Malwarebytes' Anti-Malware
HKCU\SOFTWARE\MBC
HKCU\SOFTWARE\Mediachance
HKCU\SOFTWARE\MGinstall
HKCU\SOFTWARE\Modern UI Test
HKCU\SOFTWARE\MOVAVI
HKCU\SOFTWARE\Mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\Netscape
HKCU\SOFTWARE\Nico Mak Computing
HKCU\SOFTWARE\NITRO
HKCU\SOFTWARE\OB
HKCU\SOFTWARE\ODBC
HKCU\SOFTWARE\OJOsoft Corporation
HKCU\SOFTWARE\PC SOFT
HKCU\SOFTWARE\PCDataApp
HKCU\SOFTWARE\Piriform
HKCU\SOFTWARE\pth264
HKCU\SOFTWARE\RealNetworks
HKCU\SOFTWARE\Realtek
HKCU\SOFTWARE\Redemption
HKCU\SOFTWARE\Reg
HKCU\SOFTWARE\Research In Motion
HKCU\SOFTWARE\S.A.D
HKCU\SOFTWARE\Samsung
HKCU\SOFTWARE\Sense-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\ShortCutInfection
HKCU\SOFTWARE\SimpleTV by SergeyVS#3
HKCU\SOFTWARE\Skype
HKCU\SOFTWARE\SnapFiles.com
HKCU\SOFTWARE\Sony Creative Software
HKCU\SOFTWARE\STOIK Imaging
HKCU\SOFTWARE\SUPERAntiSpyware.com
HKCU\SOFTWARE\Symantec
HKCU\SOFTWARE\Sysinternals
HKCU\SOFTWARE\TeamViewer
HKCU\SOFTWARE\TechSmith
HKCU\SOFTWARE\Topaz Labs
HKCU\SOFTWARE\TopazLabs
HKCU\SOFTWARE\Trolltech
HKCU\SOFTWARE\TuneUp
HKCU\SOFTWARE\URSoft
HKCU\SOFTWARE\UsbFix
HKCU\SOFTWARE\VB and VBA Program Settings
HKCU\SOFTWARE\Visan
HKCU\SOFTWARE\WebApp
HKCU\SOFTWARE\WinRAR
HKCU\SOFTWARE\WinRAR SFX
HKCU\SOFTWARE\Wondershare
HKCU\SOFTWARE\Xerox
HKCU\SOFTWARE\yahooinstall
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\AppDataLow\RealNetworks
HKCU\SOFTWARE\AppDataLow\Software
HKCU\SOFTWARE\AppDataLow\Software\Adobe
HKCU\SOFTWARE\AppDataLow\Software\JavaSoft
HKCU\SOFTWARE\AppDataLow\Software\Macromedia
HKCU\SOFTWARE\AppDataLow\Software\Mail.Ru
HKCU\SOFTWARE\AppDataLow\Software\MarkAny
HKCU\SOFTWARE\AppDataLow\Software\RealNetworks

---\\ Contents of the Common Files folders (O43) (414) - 16s
O43 - CFD: 2012/01/13 03:04:53 - [] HD -- C:\Program Files\3aLab
O43 - CFD: 2013/09/22 05:06:06 - [0] HD -- C:\Program Files\7-Zip
O43 - CFD: 2013/05/06 05:41:45 - [] HD -- C:\Program Files\Active Data Recovery Software
O43 - CFD: 2015/02/09 02:44:28 - [] HD -- C:\Program Files\Adobe
O43 - CFD: 2014/06/10 16:42:33 - [] HD -- C:\Program Files\AL-Software
O43 - CFD: 2015/06/16 20:11:11 - [0] D -- C:\Program Files\Alarm
O43 - CFD: 2012/03/30 14:13:06 - [] HD -- C:\Program Files\Apple Software Update
O43 - CFD: 2015/02/07 20:53:43 - [] HD -- C:\Program Files\Ashampoo
O43 - CFD: 2015/03/14 08:52:50 - [] HD -- C:\Program Files\Baidu Security
O43 - CFD: 2014/06/10 06:28:02 - [] HD -- C:\Program Files\Beyluxe Messenger
O43 - CFD: 2015/07/19 23:35:32 - [] D -- C:\Program Files\BlueStacks
O43 - CFD: 2014/09/14 09:14:09 - [0] HD -- C:\Program Files\Bonjour
O43 - CFD: 2015/02/07 06:44:12 - [] HD -- C:\Program Files\CCleaner
O43 - CFD: 2013/07/11 10:24:48 - [] HD -- C:\Program Files\Cisco
O43 - CFD: 2015/07/07 22:15:17 - [] D -- C:\Program Files\Clear Database
O43 - CFD: 2015/05/23 12:34:15 - [] HD -- C:\Program Files\Common Files
O43 - CFD: 2015/07/19 23:24:54 - [0] D -- C:\Program Files\CutterEdit
O43 - CFD: 2015/07/19 23:14:22 - [0] D -- C:\Program Files\CutterMaker
O43 - CFD: 2015/06/16 20:08:38 - [0] HD -- C:\Program Files\CyberGhost 5
O43 - CFD: 2015/04/30 04:37:04 - [0] HD -- C:\Program Files\CyberGhost VPN
O43 - CFD: 2015/04/19 20:03:26 - [0] HD -- C:\Program Files\Diablo III Server Status
O43 - CFD: 2014/06/19 00:01:19 - [] HD -- C:\Program Files\Docudesk
O43 - CFD: 2013/09/25 07:02:02 - [] HD -- C:\Program Files\Dr.Fone_Temp
O43 - CFD: 2015/03/07 18:57:20 - [] HD -- C:\Program Files\dreamboxEDIT
O43 - CFD: 2012/09/09 08:41:18 - [] HD -- C:\Program Files\DVD Maker
O43 - CFD: 2014/09/04 12:09:16 - [0] HD -- C:\Program Files\EaseUS
O43 - CFD: 2014/04/18 08:43:09 - [] HD -- C:\Program Files\Easeware
O43 - CFD: 2015/07/19 23:19:43 - [0] D -- C:\Program Files\ExtensionBB Launcher Plus
O43 - CFD: 2014/04/18 08:23:41 - [] HD -- C:\Program Files\EyetoyOnComputer Project
O43 - CFD: 2015/04/19 21:08:24 - [0] HD -- C:\Program Files\Facebook Colors
O43 - CFD: 2015/05/12 06:20:50 - [0] HD -- C:\Program Files\Facebook Invite Them All
O43 - CFD: 2014/08/18 21:33:14 - [] HD -- C:\Program Files\FastStone Capture
O43 - CFD: 2014/12/01 07:49:39 - [] HD -- C:\Program Files\Felis Faber
O43 - CFD: 2015/07/19 23:16:22 - [0] D -- C:\Program Files\FREE MP3 Search
O43 - CFD: 2011/10/14 03:07:06 - [] HD -- C:\Program Files\FreeTime
O43 - CFD: 2012/07/26 22:39:58 - [] HD -- C:\Program Files\GlobalSCAPE
O43 - CFD: 2015/04/19 21:59:53 - [] HD -- C:\Program Files\Google
O43 - CFD: 2012/09/09 06:47:23 - [] HD -- C:\Program Files\HDD Regenerator
O43 - CFD: 2013/09/25 16:35:40 - [0] HD -- C:\Program Files\Hodo iPhone Data Recovery (iPhone 4S)
O43 - CFD: 2014/12/03 10:16:58 - [] HD -- C:\Program Files\HP
O43 - CFD: 2014/12/03 10:16:20 - [] HD -- C:\Program Files\HP Photo Creations
O43 - CFD: 2013/06/30 08:48:44 - [0] HD -- C:\Program Files\iAidsoft Windows Password Recovery
O43 - CFD: 2015/04/14 13:00:22 - [] HD -- C:\Program Files\IE Tab Seamless
O43 - CFD: 2013/09/23 01:52:46 - [] HD -- C:\Program Files\Image Resizer for Windows
O43 - CFD: 2015/06/08 03:41:48 - [0] D -- C:\Program Files\IncrementModule
O43 - CFD: 2015/05/20 09:22:25 - [0] HD -- C:\Program Files\IndepthFoobar
O43 - CFD: 2014/03/03 01:32:52 - [] HD -- C:\Program Files\InstallShield Installation Information
O43 - CFD: 2011/05/12 12:31:43 - [] HD -- C:\Program Files\Intel
O43 - CFD: 2015/04/19 16:19:34 - [] HD -- C:\Program Files\Internet Explorer
O43 - CFD: 2013/04/29 15:43:32 - [] HD -- C:\Program Files\iPod
O43 - CFD: 2012/04/29 02:52:38 - [] HD -- C:\Program Files\ISO to USB
O43 - CFD: 2013/04/29 15:43:55 - [] HD -- C:\Program Files\iTunes
O43 - CFD: 2014/09/21 22:03:25 - [] HD -- C:\Program Files\Java
O43 - CFD: 2013/11/08 18:19:06 - [] HD -- C:\Program Files\Lexmark
O43 - CFD: 2014/03/03 09:11:16 - [] HD -- C:\Program Files\Longman
O43 - CFD: 2013/04/26 13:58:04 - [] HD -- C:\Program Files\LSoft Technologies
O43 - CFD: 2014/11/27 06:16:53 - [0] HD -- C:\Program Files\ma-config.com
O43 - CFD: 2015/07/20 00:11:39 - [] HD -- C:\Program Files\Malwarebytes Anti-Malware
O43 - CFD: 2011/05/24 09:59:04 - [] HD -- C:\Program Files\MarkAny
O43 - CFD: 2014/07/31 03:32:34 - [0] HD -- C:\Program Files\Microsoft
O43 - CFD: 2014/12/19 03:47:50 - [] HD -- C:\Program Files\Microsoft Analysis Services
O43 - CFD: 2009/07/14 10:50:24 - [] HD -- C:\Program Files\Microsoft Games
O43 - CFD: 2013/07/11 10:28:05 - [0] HD -- C:\Program Files\Microsoft Kinect
O43 - CFD: 2014/12/19 03:49:18 - [] HD -- C:\Program Files\Microsoft Office
O43 - CFD: 2013/07/11 10:28:04 - [0] HD -- C:\Program Files\Microsoft SDKs
O43 - CFD: 2013/07/06 10:46:24 - [0] HD -- C:\Program Files\Microsoft Silverlight
O43 - CFD: 2015/05/23 11:37:32 - [] HD -- C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 2014/12/19 03:49:18 - [] HD -- C:\Program Files\Microsoft Sync Framework
O43 - CFD: 2014/12/19 03:49:49 - [] HD -- C:\Program Files\Microsoft Synchronization Services
O43 - CFD: 2013/07/11 10:28:13 - [] HD -- C:\Program Files\Microsoft Visual Studio
O43 - CFD: 2013/07/11 10:28:13 - [] HD -- C:\Program Files\Microsoft Visual Studio 8
O43 - CFD: 2013/07/11 10:28:13 - [] HD -- C:\Program Files\Microsoft Works
O43 - CFD: 2013/07/11 10:28:13 - [] HD -- C:\Program Files\Microsoft.NET
O43 - CFD: 2015/02/25 06:55:40 - [0] HD -- C:\Program Files\Movavi Video Editor 10
O43 - CFD: 2015/07/19 23:58:07 - [] HD -- C:\Program Files\Mozilla Firefox
O43 - CFD: 2015/04/13 17:22:53 - [] HD -- C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 2014/12/19 03:50:21 - [] HD -- C:\Program Files\MSBuild
O43 - CFD: 2013/07/06 10:04:55 - [0] HD -- C:\Program Files\MSN Toolbar Installer
O43 - CFD: 2015/04/22 03:11:00 - [0] HD -- C:\Program Files\My IMDb
O43 - CFD: 2014/02/25 05:35:00 - [0] HD -- C:\Program Files\MyPCDrivers
O43 - CFD: 2015/07/19 23:43:51 - [0] HD -- C:\Program Files\Neat Video for Sony Vegas
O43 - CFD: 2012/04/29 00:12:11 - [] HD -- C:\Program Files\nLite
O43 - CFD: 2011/10/19 07:04:44 - [0] HD -- C:\Program Files\OpenSubtitlesPlayer
O43 - CFD: 2012/05/04 03:15:13 - [] HD -- C:\Program Files\OpoSoft
O43 - CFD: 2015/05/12 06:18:23 - [0] HD -- C:\Program Files\PathEdit
O43 - CFD: 2011/05/24 10:00:53 - [] HD -- C:\Program Files\PC Connectivity Solution
O43 - CFD: 2014/11/27 06:24:35 - [] HD -- C:\Program Files\PCData
O43 - CFD: 2015/07/08 06:16:08 - [] D -- C:\Program Files\PHP Console
O43 - CFD: 2014/11/27 06:27:28 - [0] HD -- C:\Program Files\PlatinumHideIP
O43 - CFD: 2015/04/22 03:08:41 - [0] HD -- C:\Program Files\ProcessFoobar
O43 - CFD: 2014/11/27 06:36:45 - [0] HD -- C:\Program Files\ProgDVB
O43 - CFD: 2013/09/25 17:38:53 - [] HD -- C:\Program Files\QuickTime
O43 - CFD: 2013/10/21 06:41:50 - [] HD -- C:\Program Files\Real
O43 - CFD: 2013/10/21 06:41:55 - [] HD -- C:\Program Files\RealNetworks
O43 - CFD: 2011/11/16 13:30:46 - [] HD -- C:\Program Files\Realtek
O43 - CFD: 2009/07/14 07:52:30 - [] HD -- C:\Program Files\Reference Assemblies
O43 - CFD: 2011/08/02 15:59:08 - [] HD -- C:\Program Files\Research In Motion
O43 - CFD: 2011/07/31 20:05:42 - [] HD -- C:\Program Files\Research In Motion Limited
O43 - CFD: 2015/01/17 16:21:05 - [0] HD -- C:\Program Files\RoboSizer
O43 - CFD: 2011/05/24 10:01:57 - [] HD -- C:\Program Files\Samsung
O43 - CFD: 2015/03/14 08:59:12 - [] HD -- C:\Program Files\SecurityXploded
O43 - CFD: 2015/02/25 19:57:40 - [] HD -- C:\Program Files\Skype
O43 - CFD: 2015/07/20 02:12:46 - [] HD -- C:\Program Files\Sony
O43 - CFD: 2015/03/14 12:19:42 - [0] HD -- C:\Program Files\Steel Cut =>PUP.Optional.SteelCut
O43 - CFD: 2013/09/23 02:04:42 - [] HD -- C:\Program Files\STOIK Technology
O43 - CFD: 2012/09/09 08:15:45 - [] HD -- C:\Program Files\SUPERAntiSpyware
O43 - CFD: 2015/05/01 06:18:33 - [0] HD -- C:\Program Files\SystemExtend
O43 - CFD: 2015/04/23 09:07:56 - [0] HD -- C:\Program Files\SystemImprove
O43 - CFD: 2015/07/19 23:14:48 - [] D -- C:\Program Files\SystemMaintain
O43 - CFD: 2015/04/19 16:39:34 - [0] HD -- C:\Program Files\TampaFoobar
O43 - CFD: 2015/07/19 23:25:13 - [] D -- C:\Program Files\TampaInit
O43 - CFD: 2015/05/23 12:00:47 - [0] HD -- C:\Program Files\TampEditor
O43 - CFD: 2015/06/16 19:58:06 - [0] D -- C:\Program Files\TAP-Windows
O43 - CFD: 2014/11/19 01:14:02 - [] HD -- C:\Program Files\TeamViewer
O43 - CFD: 2015/05/23 11:19:11 - [] HD -- C:\Program Files\TechSmith
O43 - CFD: 2013/09/25 16:30:21 - [] HD -- C:\Program Files\Temp
O43 - CFD: 2013/09/25 16:31:07 - [0] HD -- C:\Program Files\Tenorshare iPhone 4 Data Recovery
O43 - CFD: 2014/11/27 06:43:03 - [0] HD -- C:\Program Files\The KMPlayer
O43 - CFD: 2015/05/09 08:21:50 - [0] HD -- C:\Program Files\ToolPro
O43 - CFD: 2011/05/25 06:21:40 - [] HD -- C:\Program Files\Topaz Labs
O43 - CFD: 2013/07/11 10:28:14 - [] HD -- C:\Program Files\TP-LINK
O43 - CFD: 2012/04/28 20:43:39 - [] HD -- C:\Program Files\UltraISO
O43 - CFD: 2009/07/14 07:53:23 - [0] HD -- C:\Program Files\Uninstall Information
O43 - CFD: 2015/06/16 19:55:26 - [0] D -- C:\Program Files\Unofficial Gimme Bar Extension
O43 - CFD: 2013/03/25 18:06:11 - [] HD -- C:\Program Files\URUSoft
O43 - CFD: 2012/03/15 12:55:28 - [] HD -- C:\Program Files\USB Disk Security
O43 - CFD: 2013/08/23 14:43:03 - [0] HD -- C:\Program Files\Veetle
O43 - CFD: 2011/10/20 01:44:12 - [] HD -- C:\Program Files\VideoLAN
O43 - CFD: 2014/06/03 16:51:14 - [0] HD -- C:\Program Files\Visual CertExam Suite
O43 - CFD: 2015/07/05 21:14:36 - [] HD -- C:\Program Files\Windows Defender
O43 - CFD: 2013/07/11 04:53:23 - [] HD -- C:\Program Files\Windows Journal
O43 - CFD: 2015/05/23 11:37:28 - [] HD -- C:\Program Files\Windows Live
O43 - CFD: 2012/09/09 08:41:18 - [] HD -- C:\Program Files\Windows Mail
O43 - CFD: 2012/09/09 08:41:17 - [] HD -- C:\Program Files\Windows Media Player
O43 - CFD: 2009/07/14 07:52:30 - [] HD -- C:\Program Files\Windows NT
O43 - CFD: 2013/06/30 08:44:32 - [] HD -- C:\Program Files\Windows Password Unlocker Enterprise 2012 v6.0.1 Full
O43 - CFD: 2012/09/09 08:41:17 - [] HD -- C:\Program Files\Windows Photo Viewer
O43 - CFD: 2012/09/09 08:41:17 - [] HD -- C:\Program Files\Windows Portable Devices
O43 - CFD: 2012/09/09 08:41:18 - [] HD -- C:\Program Files\Windows Sidebar
O43 - CFD: 2015/01/17 01:19:44 - [] HD -- C:\Program Files\WinRAR
O43 - CFD: 2013/09/25 08:26:14 - [] HD -- C:\Program Files\Wondershare
O43 - CFD: 2014/11/27 06:21:41 - [0] HD -- C:\Program Files\XBMC
O43 - CFD: 2012/06/24 18:15:27 - [] HD -- C:\Program Files\Your Uninstaller 2010
O43 - CFD: 2015/05/18 08:59:31 - [] HD -- C:\Program Files\ZHPDiag
O43 - CFD: 2011/05/12 00:28:02 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2013/05/06 05:41:46 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Active@ Password Changer
O43 - CFD: 2011/07/13 16:55:13 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AD Popup Killer
O43 - CFD: 2011/05/12 00:28:06 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2014/05/16 20:30:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baidu PC App Store
O43 - CFD: 2013/06/12 13:52:31 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlackBerry
O43 - CFD: 2015/06/24 23:38:39 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
O43 - CFD: 2012/05/19 23:34:37 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Genius Professional Edition
O43 - CFD: 2014/08/18 21:33:14 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastStone Capture
O43 - CFD: 2012/04/30 07:54:18 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 2015/04/23 08:36:32 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 2014/07/30 13:25:39 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hao123-Saudi
O43 - CFD: 2014/12/03 10:16:20 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
O43 - CFD: 2013/09/25 17:46:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
O43 - CFD: 2013/09/23 01:52:46 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Resizer for Windows
O43 - CFD: 2012/04/29 02:52:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ISO to USB
O43 - CFD: 2013/04/29 15:44:04 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
O43 - CFD: 2014/09/21 22:02:31 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
O43 - CFD: 2015/05/20 08:50:43 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightworks
O43 - CFD: 2014/11/06 21:40:54 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ma-config.com
O43 - CFD: 2009/07/14 07:42:30 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2014/12/19 03:51:09 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
O43 - CFD: 2012/04/28 23:29:49 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\nLite
O43 - CFD: 2012/09/04 11:20:02 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pakeysoft Windows Password Recovery Standard Trial
O43 - CFD: 2013/07/31 04:37:04 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF To JPG Converter
O43 - CFD: 2013/09/25 17:38:50 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
O43 - CFD: 2013/10/21 06:41:56 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
O43 - CFD: 2015/01/11 19:34:20 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoboSizer
O43 - CFD: 2014/12/19 03:51:08 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
O43 - CFD: 2015/02/25 19:57:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
O43 - CFD: 2015/07/19 23:38:55 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
O43 - CFD: 2015/05/23 12:34:10 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 2009/07/14 10:48:45 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 2012/04/28 20:43:56 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO
O43 - CFD: 2013/03/25 18:06:11 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\URUSoft
O43 - CFD: 2014/04/05 15:56:56 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
O43 - CFD: 2013/06/30 08:44:30 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Password Unlocker Enterprise 2012 v6.0.1 Full
O43 - CFD: 2011/05/11 16:04:42 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 2013/09/25 16:30:04 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
O43 - CFD: 2012/06/24 18:14:47 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Your Uninstaller 2010
O43 - CFD: 2015/05/18 08:51:20 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
O43 - CFD: 2013/04/29 15:43:55 - [] D -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
O43 - CFD: 2015/04/21 11:03:28 - [0] D -- C:\ProgramData\8baacc200002a1f
O43 - CFD: 2015/04/23 04:55:30 - [0] D -- C:\ProgramData\a676ae20000604a
O43 - CFD: 2014/08/03 20:51:29 - [] D -- C:\ProgramData\Adobe
O43 - CFD: 2011/10/19 07:04:43 - [] D -- C:\ProgramData\ALLPlayer
O43 - CFD: 2014/07/31 03:48:58 - [0] D -- C:\ProgramData\ALM
O43 - CFD: 2011/05/21 00:45:00 - [] D -- C:\ProgramData\Apple
O43 - CFD: 2011/05/21 00:46:08 - [] D -- C:\ProgramData\Apple Computer
O43 - CFD: 2009/07/14 07:53:55 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 2015/02/07 20:53:45 - [] D -- C:\ProgramData\ashampoo
O43 - CFD: 2015/04/20 15:24:08 - [] D -- C:\ProgramData\Baidu
O43 - CFD: 2014/05/14 22:22:23 - [] D -- C:\ProgramData\Baidu Security
O43 - CFD: 2015/06/24 23:38:44 - [] D -- C:\ProgramData\BlueStacks
O43 - CFD: 2015/06/25 00:11:32 - [] D -- C:\ProgramData\BlueStacksSetup
O43 - CFD: 2012/07/16 15:35:21 - [] D -- C:\ProgramData\DassaultSystemes
O43 - CFD: 2009/07/14 07:53:55 - [0] SHD -- C:\ProgramData\Desktop
O43 - CFD: 2015/02/04 22:41:24 - [] D -- C:\ProgramData\Doctor Web
O43 - CFD: 2009/07/14 07:53:55 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 2015/04/24 08:09:50 - [0] D -- C:\ProgramData\Drv
O43 - CFD: 2009/07/14 07:53:55 - [0] SHD -- C:\ProgramData\Favorites
O43 - CFD: 2013/05/14 01:53:00 - [] D -- C:\ProgramData\FileOpen
O43 - CFD: 2014/03/14 00:57:04 - [] D -- C:\ProgramData\FLEXnet
O43 - CFD: 2015/05/20 08:50:32 - [] D -- C:\ProgramData\Geevs
O43 - CFD: 2011/10/14 13:05:57 - [] D -- C:\ProgramData\Google
O43 - CFD: 2015/04/23 21:41:15 - [] D -- C:\ProgramData\Hi
O43 - CFD: 2014/06/21 21:47:38 - [] D -- C:\ProgramData\HP
O43 - CFD: 2014/12/03 10:16:20 - [] D -- C:\ProgramData\HP Photo Creations
O43 - CFD: 2013/07/06 07:18:35 - [] D -- C:\ProgramData\HPSSUPPLY
O43 - CFD: 2013/09/23 18:12:55 - [0] D -- C:\ProgramData\IDM
O43 - CFD: 2014/05/11 19:56:38 - [] D -- C:\ProgramData\ItsMyApp
O43 - CFD: 2015/04/24 08:09:58 - [] D -- C:\ProgramData\Kirin
O43 - CFD: 2014/04/18 12:55:34 - [] D -- C:\ProgramData\Log
O43 - CFD: 2014/11/06 21:40:48 - [] D -- C:\ProgramData\ma-config.com
O43 - CFD: 2015/02/05 02:33:00 - [] D -- C:\ProgramData\Malwarebytes
O43 - CFD: 2015/07/05 21:14:43 - [] SD -- C:\ProgramData\Microsoft
O43 - CFD: 2014/12/19 03:58:02 - [] D -- C:\ProgramData\Microsoft Help
O43 - CFD: 2015/02/25 06:55:42 - [0] D -- C:\ProgramData\Movavi
O43 - CFD: 2012/04/25 16:23:51 - [] D -- C:\ProgramData\Mozilla
O43 - CFD: 2013/05/14 01:51:25 - [] D -- C:\ProgramData\Nitro
O43 - CFD: 2011/12/17 10:45:00 - [] D -- C:\ProgramData\Norton
O43 - CFD: 2011/11/15 22:02:16 - [] D -- C:\ProgramData\NortonInstaller
O43 - CFD: 2014/09/21 22:04:10 - [0] D -- C:\ProgramData\Oracle
O43 - CFD: 2015/04/19 07:46:27 - [] D -- C:\ProgramData\Package Cache
O43 - CFD: 2015/02/09 03:47:32 - [0] D -- C:\ProgramData\PC Cleaners
O43 - CFD: 2015/02/09 03:47:32 - [] D -- C:\ProgramData\PC1Data
O43 - CFD: 2013/11/12 10:11:52 - [] D -- C:\ProgramData\PlatinumHideIP
O43 - CFD: 2014/11/27 06:35:46 - [0] D -- C:\ProgramData\ProgDVB
O43 - CFD: 2013/07/12 11:18:43 - [] D -- C:\ProgramData\Ralink Driver
O43 - CFD: 2015/04/07 03:28:40 - [] D -- C:\ProgramData\Real
O43 - CFD: 2013/10/21 06:41:53 - [] D -- C:\ProgramData\RealNetworks
O43 - CFD: 2013/10/11 18:38:43 - [] D -- C:\ProgramData\regid.1986-12.com.adobe
O43 - CFD: 2011/08/02 15:59:21 - [] D -- C:\ProgramData\Research In Motion
O43 - CFD: 2015/02/05 03:30:50 - [] D -- C:\ProgramData\RogueKiller
O43 - CFD: 2014/11/27 06:39:30 - [] D -- C:\ProgramData\Samsung
O43 - CFD: 2015/02/25 19:57:46 - [] D -- C:\ProgramData\Skype
O43 - CFD: 2011/06/19 14:33:47 - [] D -- C:\ProgramData\Skype Extras
O43 - CFD: 2015/04/25 03:54:19 - [] D -- C:\ProgramData\Sony
O43 - CFD: 2009/07/14 07:53:55 - [0] SHD -- C:\ProgramData\Start Menu
O43 - CFD: 2013/09/23 02:04:47 - [] D -- C:\ProgramData\STOIK
O43 - CFD: 2011/06/09 15:24:15 - [] D -- C:\ProgramData\Sun
O43 - CFD: 2012/05/17 08:38:12 - [] D -- C:\ProgramData\SUPERAntiSpyware.com
O43 - CFD: 2011/10/11 08:49:38 - [] D -- C:\ProgramData\Symantec
O43 - CFD: 2015/05/23 12:34:15 - [] D -- C:\ProgramData\TechSmith
O43 - CFD: 2015/07/19 23:09:36 - [0] AD -- C:\ProgramData\TEMP
O43 - CFD: 2009/07/14 07:53:55 - [0] SHD -- C:\ProgramData\Templates
O43 - CFD: 2013/09/25 08:50:38 - [] D -- C:\ProgramData\TenorShare
O43 - CFD: 2015/05/09 06:09:47 - [] D -- C:\ProgramData\TheAdBlock =>PUP.Optional.TheAdBlock
O43 - CFD: 2013/07/11 10:25:29 - [] D -- C:\ProgramData\TP-LINK Driver
O43 - CFD: 2013/01/26 22:32:02 - [] D -- C:\ProgramData\TuneUp Software
O43 - CFD: 2013/07/11 10:28:14 - [] D -- C:\ProgramData\Visan
O43 - CFD: 2012/05/07 06:11:02 - [] D -- C:\ProgramData\Windows Genuine Advantage
O43 - CFD: 2013/09/25 07:02:00 - [] D -- C:\ProgramData\Wondershare
O43 - CFD: 2013/07/06 03:15:37 - [] D -- C:\ProgramData\Xerox
O43 - CFD: 2012/03/03 16:25:52 - [0] D -- C:\ProgramData\Zbshareware Lab
O43 - CFD: 2011/05/21 00:46:24 - [] D -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
O43 - CFD: 2013/09/28 06:55:54 - [] HDC -- C:\ProgramData\{AB404F93-CDCE-40D9-8D4E-8606C84D368C}
O43 - CFD: 2014/07/31 03:47:07 - [] D -- C:\Program Files\Common Files\Adobe
O43 - CFD: 2014/07/31 03:47:54 - [] D -- C:\Program Files\Common Files\Adobe AIR
O43 - CFD: 2013/04/29 15:43:32 - [] D -- C:\Program Files\Common Files\Apple
O43 - CFD: 2014/12/19 03:50:32 - [] D -- C:\Program Files\Common Files\DESIGNER
O43 - CFD: 2012/04/28 20:43:38 - [] D -- C:\Program Files\Common Files\EZB Systems
O43 - CFD: 2013/07/11 10:28:06 - [] D -- C:\Program Files\Common Files\Hewlett-Packard
O43 - CFD: 2012/09/04 11:59:30 - [] D -- C:\Program Files\Common Files\InstallShield
O43 - CFD: 2014/09/21 22:03:39 - [] D -- C:\Program Files\Common Files\Java
O43 - CFD: 2014/03/04 09:14:28 - [] D -- C:\Program Files\Common Files\Macrovision Shared
O43 - CFD: 2015/05/23 11:36:10 - [] D -- C:\Program Files\Common Files\microsoft shared
O43 - CFD: 2013/06/12 14:26:40 - [] D -- C:\Program Files\Common Files\Research In Motion
O43 - CFD: 2011/05/24 09:59:15 - [] D -- C:\Program Files\Common Files\Samsung
O43 - CFD: 2009/07/14 05:37:05 - [] D -- C:\Program Files\Common Files\Services
O43 - CFD: 2015/02/25 19:57:40 - [] D -- C:\Program Files\Common Files\Skype
O43 - CFD: 2009/07/14 05:37:05 - [] D -- C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 2015/07/19 23:58:07 - [] D -- C:\Program Files\Common Files\System
O43 - CFD: 2014/05/20 21:31:13 - [] D -- C:\Program Files\Common Files\Topaz Labs
O43 - CFD: 2011/05/12 12:06:08 - [] D -- C:\Program Files\Common Files\Windows Live
O43 - CFD: 2014/09/14 02:54:27 - [] D -- C:\Program Files\Common Files\Wise Installation Wizard
O43 - CFD: 2013/06/12 13:52:22 - [] D -- C:\Program Files\Common Files\XCPCSync.OEM
O43 - CFD: 2013/10/21 06:41:47 - [] D -- C:\Program Files\Common Files\xing shared
O43 - CFD: 2015/04/20 04:46:06 - [] D -- C:\Users\Abokr\AppData\Roaming\00000000-1429418606-0000-0000-001FD01E31BC
O43 - CFD: 2014/07/31 03:48:59 - [] D -- C:\Users\Abokr\AppData\Roaming\Adobe
O43 - CFD: 2015/05/24 19:38:04 - [] D -- C:\Users\Abokr\AppData\Roaming\Apple Computer
O43 - CFD: 2015/02/07 20:55:01 - [] D -- C:\Users\Abokr\AppData\Roaming\Ashampoo
O43 - CFD: 2015/04/23 21:38:04 - [] D -- C:\Users\Abokr\AppData\Roaming\Baidu
O43 - CFD: 2014/06/10 06:35:00 - [] D -- C:\Users\Abokr\AppData\Roaming\Beyluxe
O43 - CFD: 2015/04/24 00:49:07 - [] D -- C:\Users\Abokr\AppData\Roaming\Craft
O43 - CFD: 2015/04/23 21:35:08 - [] D -- C:\Users\Abokr\AppData\Roaming\Crown
O43 - CFD: 2012/07/16 15:35:05 - [] D -- C:\Users\Abokr\AppData\Roaming\DassaultSystemes
O43 - CFD: 2014/07/04 04:17:53 - [] D -- C:\Users\Abokr\AppData\Roaming\deskPDF
O43 - CFD: 2014/06/19 00:10:20 - [] D -- C:\Users\Abokr\AppData\Roaming\deskPDF Editor
O43 - CFD: 2015/07/19 23:41:56 - [0] D -- C:\Users\Abokr\AppData\Roaming\DMCache
O43 - CFD: 2013/05/14 01:49:06 - [] D -- C:\Users\Abokr\AppData\Roaming\Downloaded Installations
O43 - CFD: 2012/04/27 06:18:26 - [0] D -- C:\Users\Abokr\AppData\Roaming\DRPSu
O43 - CFD: 2012/08/26 03:54:22 - [] D -- C:\Users\Abokr\AppData\Roaming\dvdcss
O43 - CFD: 2011/05/12 21:58:44 - [] D -- C:\Users\Abokr\AppData\Roaming\Easeware
O43 - CFD: 2014/08/19 01:55:44 - [] D -- C:\Users\Abokr\AppData\Roaming\FastStone
O43 - CFD: 2013/05/14 01:53:00 - [] D -- C:\Users\Abokr\AppData\Roaming\FileOpen
O43 - CFD: 2011/06/28 13:28:08 - [] D -- C:\Users\Abokr\AppData\Roaming\Firestorm
O43 - CFD: 2015/04/23 21:34:58 - [] D -- C:\Users\Abokr\AppData\Roaming\Fixs
O43 - CFD: 2015/04/24 00:49:37 - [] D -- C:\Users\Abokr\AppData\Roaming\Flasher
O43 - CFD: 2012/07/26 22:40:13 - [] D -- C:\Users\Abokr\AppData\Roaming\GlobalSCAPE
O43 - CFD: 2011/06/04 00:55:52 - [] D -- C:\Users\Abokr\AppData\Roaming\Google
O43 - CFD: 2011/05/12 21:47:49 - [] D -- C:\Users\Abokr\AppData\Roaming\HP
O43 - CFD: 2014/12/10 08:39:22 - [] D -- C:\Users\Abokr\AppData\Roaming\HpUpdate
O43 - CFD: 2015/04/23 21:34:58 - [] D -- C:\Users\Abokr\AppData\Roaming\htcon
O43 - CFD: 2011/05/11 14:32:26 - [] D -- C:\Users\Abokr\AppData\Roaming\Identities
O43 - CFD: 2014/03/03 09:12:41 - [] D -- C:\Users\Abokr\AppData\Roaming\ldoce5
O43 - CFD: 2011/05/11 16:38:17 - [] D -- C:\Users\Abokr\AppData\Roaming\Macromedia
O43 - CFD: 2015/02/05 02:33:00 - [0] D -- C:\Users\Abokr\AppData\Roaming\Malwarebytes
O43 - CFD: 2009/07/14 10:48:45 - [0] D -- C:\Users\Abokr\AppData\Roaming\Media Center Programs
O43 - CFD: 2015/04/19 16:01:23 - [] D -- C:\Users\Abokr\AppData\Roaming\mgy2y2jxzwsybtb
O43 - CFD: 2013/08/11 20:43:38 - [] SD -- C:\Users\Abokr\AppData\Roaming\Microsoft
O43 - CFD: 2015/02/24 06:56:36 - [] D -- C:\Users\Abokr\AppData\Roaming\Movavi
O43 - CFD: 2011/10/22 01:02:39 - [] D -- C:\Users\Abokr\AppData\Roaming\Mozilla
O43 - CFD: 2012/04/20 19:32:12 - [] D -- C:\Users\Abokr\AppData\Roaming\mypcdrivers
O43 - CFD: 2015/05/02 03:08:32 - [] D -- C:\Users\Abokr\AppData\Roaming\NeatVideo SV 32
O43 - CFD: 2013/05/14 02:16:00 - [] D -- C:\Users\Abokr\AppData\Roaming\Nitro
O43 - CFD: 2013/08/15 07:14:54 - [] D -- C:\Users\Abokr\AppData\Roaming\PDAppFlex
O43 - CFD: 2013/11/12 10:08:40 - [] D -- C:\Users\Abokr\AppData\Roaming\PlatinumHideIP
O43 - CFD: 2012/03/24 16:12:41 - [0] D -- C:\Users\Abokr\AppData\Roaming\Publish Providers
O43 - CFD: 2013/12/24 01:14:37 - [] D -- C:\Users\Abokr\AppData\Roaming\Real
O43 - CFD: 2013/10/21 06:42:12 - [] D -- C:\Users\Abokr\AppData\Roaming\RealNetworks
O43 - CFD: 2012/05/22 07:13:58 - [0] D -- C:\Users\Abokr\AppData\Roaming\redsn0w
O43 - CFD: 2011/08/02 16:40:44 - [] D -- C:\Users\Abokr\AppData\Roaming\Research In Motion
O43 - CFD: 2015/01/17 16:19:46 - [] D -- C:\Users\Abokr\AppData\Roaming\RoboSizer
O43 - CFD: 2014/11/27 06:39:42 - [] D -- C:\Users\Abokr\AppData\Roaming\Samsung
O43 - CFD: 2011/06/22 09:13:49 - [] D -- C:\Users\Abokr\AppData\Roaming\SecondLife
O43 - CFD: 2015/02/25 20:13:26 - [] D -- C:\Users\Abokr\AppData\Roaming\Skype
O43 - CFD: 2011/06/19 16:03:47 - [] D -- C:\Users\Abokr\AppData\Roaming\skypePM
O43 - CFD: 2015/05/12 08:03:00 - [] D -- C:\Users\Abokr\AppData\Roaming\Sony
O43 - CFD: 2015/04/25 03:54:08 - [] D -- C:\Users\Abokr\AppData\Roaming\Sony Creative Software Inc
O43 - CFD: 2013/08/15 08:25:18 - [] D -- C:\Users\Abokr\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
O43 - CFD: 2012/05/17 08:38:43 - [] D -- C:\Users\Abokr\AppData\Roaming\SUPERAntiSpyware.com
O43 - CFD: 2014/12/19 02:13:22 - [0] D -- C:\Users\Abokr\AppData\Roaming\support
O43 - CFD: 2015/07/20 02:15:26 - [0] D -- C:\Users\Abokr\AppData\Roaming\System32
O43 - CFD: 2014/11/26 01:08:46 - [] D -- C:\Users\Abokr\AppData\Roaming\TeamViewer
O43 - CFD: 2015/05/23 11:40:48 - [] D -- C:\Users\Abokr\AppData\Roaming\TechSmith
O43 - CFD: 2013/01/26 22:32:00 - [] D -- C:\Users\Abokr\AppData\Roaming\TuneUp Software
O43 - CFD: 2012/06/24 18:14:49 - [] D -- C:\Users\Abokr\AppData\Roaming\URSoft
O43 - CFD: 2015/07/20 06:31:13 - [] D -- C:\Users\Abokr\AppData\Roaming\uTorrent
O43 - CFD: 2013/07/06 02:58:37 - [] D -- C:\Users\Abokr\AppData\Roaming\Visan
O43 - CFD: 2014/12/09 07:24:18 - [] D -- C:\Users\Abokr\AppData\Roaming\vlc
O43 - CFD: 2014/11/11 02:44:49 - [] D -- C:\Users\Abokr\AppData\Roaming\WinBatch
O43 - CFD: 2011/05/11 16:04:51 - [] D -- C:\Users\Abokr\AppData\Roaming\WinRAR
O43 - CFD: 2012/08/28 18:44:07 - [] D -- C:\Users\Abokr\AppData\Roaming\WinZip
O43 - CFD: 2013/07/31 04:37:54 - [] D -- C:\Users\Abokr\AppData\Roaming\YCanPDF
O43 - CFD: 2012/03/03 16:25:52 - [] D -- C:\Users\Abokr\AppData\Roaming\Zbshareware Lab
O43 - CFD: 2015/07/20 06:31:49 - [] D -- C:\Users\Abokr\AppData\Roaming\ZHP
O43 - CFD: 2014/04/14 19:50:20 - [] D -- C:\Users\Abokr\AppData\Local\Adobe
O43 - CFD: 2011/05/21 00:45:05 - [] D -- C:\Users\Abokr\AppData\Local\Apple
O43 - CFD: 2015/05/24 19:25:10 - [] D -- C:\Users\Abokr\AppData\Local\Apple Computer
O43 - CFD: 2011/05/11 14:32:18 - [0] SHD -- C:\Users\Abokr\AppData\Local\Application Data
O43 - CFD: 2015/02/07 20:55:03 - [] D -- C:\Users\Abokr\AppData\Local\ashampoo
O43 - CFD: 2012/10/02 13:54:52 - [] D -- C:\Users\Abokr\AppData\Local\assembly
O43 - CFD: 2013/09/25 08:42:25 - [] D -- C:\Users\Abokr\AppData\Local\avgchrome
O43 - CFD: 2014/11/27 01:07:36 - [] D -- C:\Users\Abokr\AppData\Local\Bluestacks
O43 - CFD: 2013/09/23 02:34:01 - [] D -- C:\Users\Abokr\AppData\Local\Brice_Lambson
O43 - CFD: 2014/03/31 02:22:54 - [] D -- C:\Users\Abokr\AppData\Local\cache
O43 - CFD: 2014/09/03 09:41:25 - [] D -- C:\Users\Abokr\AppData\Local\Comodo
O43 - CFD: 2015/05/12 05:26:00 - [] D -- C:\Users\Abokr\AppData\Local\CrashDumps
O43 - CFD: 2012/07/16 15:35:05 - [0] D -- C:\Users\Abokr\AppData\Local\DassaultSystemes
O43 - CFD: 2012/09/09 06:46:26 - [0] D -- C:\Users\Abokr\AppData\Local\Deployment
O43 - CFD: 2015/02/24 06:57:04 - [0] D -- C:\Users\Abokr\AppData\Local\Deshaker
O43 - CFD: 2015/04/13 02:22:19 - [0] D -- C:\Users\Abokr\AppData\Local\Diagnostics
O43 - CFD: 2014/03/20 08:02:51 - [] D -- C:\Users\Abokr\AppData\Local\Downloaded Installations
O43 - CFD: 2015/07/01 18:56:48 - [0] D -- C:\Users\Abokr\AppData\Local\ElevatedDiagnostics
O43 - CFD: 2014/08/19 01:55:44 - [] D -- C:\Users\Abokr\AppData\Local\FastStone
O43 - CFD: 2012/07/26 22:40:14 - [] D -- C:\Users\Abokr\AppData\Local\GlobalSCAPE
O43 - CFD: 2014/09/03 09:41:26 - [] D -- C:\Users\Abokr\AppData\Local\Google
O43 - CFD: 2011/05/11 14:32:18 - [0] SHD -- C:\Users\Abokr\AppData\Local\History
O43 - CFD: 2014/06/21 21:49:05 - [] D -- C:\Users\Abokr\AppData\Local\HP
O43 - CFD: 2014/03/23 00:01:03 - [0] D -- C:\Users\Abokr\AppData\Local\iexplorer
O43 - CFD: 2014/03/03 09:12:34 - [] D -- C:\Users\Abokr\AppData\Local\ldoce5
O43 - CFD: 2013/09/25 07:00:35 - [] D -- C:\Users\Abokr\AppData\Local\libimobiledevice
O43 - CFD: 2012/06/24 00:39:11 - [] D -- C:\Users\Abokr\AppData\Local\Macromedia
O43 - CFD: 2015/05/24 18:57:25 - [] D -- C:\Users\Abokr\AppData\Local\Microsoft
O43 - CFD: 2015/04/17 16:53:24 - [] D -- C:\Users\Abokr\AppData\Local\Microsoft Games
O43 - CFD: 2015/03/14 09:14:00 - [] D -- C:\Users\Abokr\AppData\Local\Microsoft Help
O43 - CFD: 2015/02/24 06:56:33 - [] D -- C:\Users\Abokr\AppData\Local\Movavi
O43 - CFD: 2013/09/23 18:02:44 - [] D -- C:\Users\Abokr\AppData\Local\Mozilla
O43 - CFD: 2013/02/14 04:01:21 - [] D -- C:\Users\Abokr\AppData\Local\Programs
O43 - CFD: 2013/06/12 14:11:45 - [] D -- C:\Users\Abokr\AppData\Local\Research In Motion
O43 - CFD: 2014/11/27 06:39:42 - [0] D -- C:\Users\Abokr\AppData\Local\Samsung
O43 - CFD: 2015/04/24 07:51:04 - [] D -- C:\Users\Abokr\AppData\Local\SecondLife
O43 - CFD: 2015/02/25 19:57:56 - [] D -- C:\Users\Abokr\AppData\Local\Skype
O43 - CFD: 2015/04/25 03:52:28 - [] D -- C:\Users\Abokr\AppData\Local\Sony
O43 - CFD: 2015/05/23 11:19:11 - [] D -- C:\Users\Abokr\AppData\Local\TechSmith
O43 - CFD: 2015/07/20 06:31:25 - [] D -- C:\Users\Abokr\AppData\Local\temp
O43 - CFD: 2011/05/11 14:32:18 - [0] SHD -- C:\Users\Abokr\AppData\Local\Temporary Internet Files
O43 - CFD: 2015/02/24 06:56:30 - [] D -- C:\Users\Abokr\AppData\Local\videoeditor
O43 - CFD: 2013/01/26 22:46:51 - [] D -- C:\Users\Abokr\AppData\Local\VirtualStore
O43 - CFD: 2015/05/24 18:56:55 - [] D -- C:\Users\Abokr\AppData\Local\Windows Live
O43 - CFD: 2013/05/01 21:11:04 - [] D -- C:\Users\Abokr\AppData\Local\Wondershare
O43 - CFD: 2009/07/14 07:42:04 - [] RD -- C:\Users\Abokr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2013/05/06 05:41:46 - [0] D -- C:\Users\Abokr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Active@ Password Changer
O43 - CFD: 2013/07/11 01:20:50 - [] RD -- C:\Users\Abokr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2014/06/15 17:26:10 - [] D -- C:\Users\Abokr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Baidu PC App Store
O43 - CFD: 2014/06/15 17:26:10 - [] D -- C:\Users\Abokr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Beyluxe Messenger
O43 - CFD: 2015/04/24 07:34:42 - [] D -- C:\Users\Abokr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Disabled Startup
O43 - CFD: 2015/03/07 18:57:20 - [] D -- C:\Users\Abokr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\dreamboxEDIT
O43 - CFD: 2014/01/26 18:10:39 - [] D -- C:\Users\Abokr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
O43 - CFD: 2013/10/10 19:35:44 - [0] D -- C:\Users\Abokr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 2009/07/14 07:37:42 - [] RD -- C:\Users\Abokr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2012/04/28 23:29:49 - [0] D -- C:\Users\Abokr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\nLite
O43 - CFD: 2011/11/17 09:06:06 - [] D -- C:\Users\Abokr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
O43 - CFD: 2015/07/20 02:15:22 - [] RD -- C:\Users\Abokr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 2015/02/08 03:30:07 - [] D -- C:\Users\Abokr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
O43 - CFD: 2012/05/20 10:05:44 - [] D -- C:\Users\Abokr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
O43 - CFD: 2011/05/11 16:04:42 - [] D -- C:\Users\Abokr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 2011/12/08 19:27:34 - [] RD -- C:\Windows\System32\Config\systemprofile\Start Menu\Programs\Administrative Tools
O43 - CFD: 2011/12/08 19:27:34 - [] RD -- C:\Windows\System32\Config\systemprofile\Start Menu\Programs\Startup

---\\ ShareTools MSconfig StartupReg (SMSR) (O53) (6) - 0s
O53 - SMSR:HKLM\...\startupreg\AdobeAAMUpdater-1.0 [Key] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
O53 - SMSR:HKLM\...\startupreg\AdobeCS6ServiceManager [Key] . (.Adobe Systems Incorporated - Adobe CS6 Service Manager.) -- C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe
O53 - SMSR:HKLM\...\startupreg\APSDaemon [Key] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
O53 - SMSR:HKLM\...\startupreg\HP Software Update [Key] . (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O53 - SMSR:HKLM\...\startupreg\iTunesHelper [Key] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
O53 - SMSR:HKLM\...\startupreg\QuickTime Task [Key] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe

---\\ System Drivers List (SDL) (O58) (80) - 13s
O58 - SDL:2009/07/14 04:26:15 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [422976]
O58 - SDL:2009/07/14 04:26:17 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [297552]
O58 - SDL:2009/07/14 04:26:15 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\drivers\adpu320.sys [146512]
O58 - SDL:2009/07/14 04:26:15 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [14400]
O58 - SDL:2011/03/11 08:38:37 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [80256]
O58 - SDL:2009/07/14 04:26:15 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [159312]
O58 - SDL:2011/03/11 08:38:37 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [22400]
O58 - SDL:2009/07/14 04:26:15 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [76368]
O58 - SDL:2009/07/14 04:26:15 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [86608]
O58 - SDL:2009/07/14 01:02:49 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60x.sys [229888]
O58 - SDL:2009/07/14 01:53:28 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [13568]
O58 - SDL:2009/07/14 01:53:28 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [5248]
O58 - SDL:2009/07/14 03:57:25 A . (.Brother Industries Ltd. - ÈÑäÇãÌ ÊÔÛíá I/F ÇáÊÓáÓáí áÜ Brotehr (WDM)ý.) -- C:\Windows\System32\drivers\BrSerId.sys [272128]
O58 - SDL:2009/07/14 01:53:32 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [62336]
O58 - SDL:2009/07/14 01:53:33 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [12160]
O58 - SDL:2009/07/14 01:53:33 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [11904]
O58 - SDL:2009/07/14 01:02:48 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbdx.sys [430080]
O58 - SDL:2009/07/14 04:26:21 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [15952]
O58 - SDL:2010/09/13 13:31:54 A . (.Devguru Co., Ltd - Device Error Recovery SDK(x86).) -- C:\Windows\System32\drivers\dgderdrv.sys [18120]
O58 - SDL:2009/07/14 04:20:28 A . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\drivers\djsvs.sys [70720]
O58 - SDL:2009/07/14 04:20:28 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [453712]
O58 - SDL:2009/07/14 01:02:48 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbdx.sys [3100160]
O58 - SDL:2012/08/21 13:01:22 A . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\System32\drivers\GEARAspiWDM.sys [26840]
O58 - SDL:2009/07/14 01:54:14 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [26624]
O58 - SDL:2009/07/14 04:20:28 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [67152]
O58 - SDL:2011/03/11 08:38:51 A . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\drivers\iaStorV.sys [332160]
O58 - SDL:2009/09/23 19:18:14 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd32.sys [4808192]
O58 - SDL:2009/07/14 04:20:36 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [41040]
O58 - SDL:2009/07/14 04:20:36 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [95824]
O58 - SDL:2009/07/14 04:20:37 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [89168]
O58 - SDL:2009/07/14 04:20:36 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [54864]
O58 - SDL:2009/07/14 04:20:36 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [96848]
O58 - SDL:2015/06/18 08:41:36 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\mbam.sys [23256]
O58 - SDL:2015/06/18 08:41:42 A . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\drivers\mbamchameleon.sys [94936]
O58 - SDL:2015/07/20 03:20:08 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys [98520]
O58 - SDL:2009/07/14 04:20:36 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [30800]
O58 - SDL:2009/07/14 04:20:36 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [235584]
O58 - SDL:2015/06/18 08:41:54 A . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\drivers\mwac.sys [51928]
O58 - SDL:2012/04/17 10:31:10 A . (.Ralink Technology Corp. - Ralink 802.11n Wireless Adapter Driver.) -- C:\Windows\System32\drivers\netr28u.sys [1317952]
O58 - SDL:2009/07/14 01:02:53 A . (.Ralink Technology, Corp. - Ralink 802.11 USB Wireless Adapter Driver.) -- C:\Windows\System32\drivers\netr73.sys [545792]
O58 - SDL:2009/07/14 04:20:44 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [44624]
O58 - SDL:2011/03/11 08:39:00 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [117120]
O58 - SDL:2011/03/11 08:39:00 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [143744]
O58 - SDL:2015/02/05 02:51:29 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\nwsoboxn.sys [52440]
O58 - SDL:2003/10/15 17:52:48 A . (.OmniVision Technologies Inc. - Dual Mode USB Camera 519 Universal Serial.) -- C:\Windows\System32\drivers\ov519cmd.sys [25211]
O58 - SDL:2003/10/15 17:52:50 A . (.OmniVision Technologies, Inc. - Dual Mode USB Camera 519 Stream Class Mini.) -- C:\Windows\System32\drivers\ov519vid.sys [174530]
O58 - SDL:2009/07/14 04:19:04 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1383488]
O58 - SDL:2009/07/14 04:19:04 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [106064]
O58 - SDL:2012/12/10 15:48:12 A . (.Research in Motion Ltd - RIM Virtual Serial Driver.) -- C:\Windows\System32\drivers\RimSerial.sys [35840]
O58 - SDL:2013/06/27 10:35:32 A . (.Research In Motion Limited - BlackBerry Device Driver.) -- C:\Windows\System32\drivers\RimUsb.sys [68096]
O58 - SDL:2009/07/14 01:02:52 A . (.Realtek Corporation - Realtek 8101E/8168/8169 NDIS 6.20 32-bit Dr.) -- C:\Windows\System32\drivers\Rt86win7.sys [139776]
O58 - SDL:2011/10/18 19:53:14 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RTKVHDA.sys [3546664]
O58 - SDL:2009/07/14 01:02:53 A . (.Realtek Semiconductor Corporation - Realtek RTL8187B NDIS Driver.) -- C:\Windows\System32\drivers\RTL8187B.sys [347136]
O58 - SDL:2009/07/13 23:50:20 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [20480]
O58 - SDL:2009/07/14 04:19:04 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [40016]
O58 - SDL:2009/07/14 04:19:04 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [77888]
O58 - SDL:2014/01/23 06:20:56 A . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\Windows\System32\drivers\ssadcm.sys [15560]
O58 - SDL:2014/01/23 06:20:56 A . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\Windows\System32\drivers\ssadwh.sys [15304]
O58 - SDL:2009/07/14 04:19:04 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [21072]
O58 - SDL:2013/08/22 15:40:22 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver.) -- C:\Windows\System32\drivers\tap0901.sys [35288]
O58 - SDL:2015/02/05 03:30:55 A . (...) -- C:\Windows\System32\drivers\TrueSight.sys [35064]
O58 - SDL:2012/12/13 13:50:38 A . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\drivers\usbaapl.sys [45056]
O58 - SDL:2009/07/14 04:19:10 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [16976]
O58 - SDL:2009/07/14 04:19:11 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [141904]
O58 - SDL:2009/07/14 00:40:41 A . (...) -- C:\Windows\System32\ANSI.SYS [9029]
O58 - SDL:2009/07/14 00:40:44 A . (...) -- C:\Windows\System32\country.sys [27097]
O58 - SDL:2010/09/13 13:28:48 A . (...) -- C:\Windows\System32\FsUsbExDisk.Sys [36640]
O58 - SDL:2009/07/14 00:40:40 A . (...) -- C:\Windows\System32\HIMEM.SYS [4768]
O58 - SDL:2009/07/14 00:40:43 A . (...) -- C:\Windows\System32\KEY01.SYS [42809]
O58 - SDL:2009/07/14 00:40:43 A . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537]
O58 - SDL:2009/07/14 00:40:23 A . (...) -- C:\Windows\System32\NTDOS.SYS [27866]
O58 - SDL:2009/07/14 00:40:31 A . (...) -- C:\Windows\System32\NTDOS404.SYS [29146]
O58 - SDL:2009/07/14 00:40:35 A . (...) -- C:\Windows\System32\NTDOS411.SYS [29370]
O58 - SDL:2009/07/14 00:40:39 A . (...) -- C:\Windows\System32\NTDOS412.SYS [29274]
O58 - SDL:2009/07/14 00:40:27 A . (...) -- C:\Windows\System32\NTDOS804.SYS [29146]
O58 - SDL:2009/07/14 00:40:11 A . (...) -- C:\Windows\System32\NTIO.SYS [33952]
O58 - SDL:2009/07/14 00:40:15 A . (...) -- C:\Windows\System32\NTIO404.SYS [34672]
O58 - SDL:2009/07/14 00:40:17 A . (...) -- C:\Windows\System32\NTIO411.SYS [35776]
O58 - SDL:2009/07/14 00:40:19 A . (...) -- C:\Windows\System32\NTIO412.SYS [35536]
O58 - SDL:2009/07/14 00:40:13 A . (...) -- C:\Windows\System32\NTIO804.SYS [34672]

---\\ Last modified or created user files (O61) (5) - 217s
O61 - LFC: 2015/07/18 04:19:26 A . (..) -- C:\Users\Abokr\Autoexec.bat [426]
O61 - LFC: 2015/07/19 23:02:40 A . (.Bleeping Computer, LLC.) -- C:\Users\Abokr\Desktop\ap.exe.com [1943800]
O61 - LFC: 2015/07/18 00:10:57 A . (..) -- C:\Users\Abokr\AppData\Roaming\appdataFr25.bin [24]
O61 - LFC: 2015/07/18 09:40:12 A . (..) -- C:\Users\Abokr\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [1113849]
O61 - LFC: 2015/07/13 10:14:22 A . (..) -- C:\Users\Abokr\AppData\Local\Google\Chrome\User Data\PepperFlash\18.0.0.209\pepflashplayer.dll [16307888]

---\\ File Associations Shell Spawning (O67) (9) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - ýýãÍÑÑ ÇáÊÓÌíá.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe

---\\ Start Menu Internet (SMI) (O68) (8) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe

---\\ Search Browser Infection (SBI) (O69) (11) - 12s
O69 - SBI: prefs.js [Abokr - c6gs1yl5.default-1377986054771] user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine"); =>PUP.Optional.SearchEngine
O69 - SBI: prefs.js [Abokr - c6gs1yl5.default-1377986054771] user_pref("browser.search.searchengine.ptid", "wpc"); =>PUP.Optional.SearchEngine
O69 - SBI: prefs.js [Abokr - c6gs1yl5.default-1377986054771] user_pref("browser.search.searchengine.uid", "WDCXWD5000AAKX-001CA0_WD-WCAYUK77405474054"); =>PUP.Optional.SearchEngine
O69 - SBI: prefs.js [Abokr - c6gs1yl5.default-1377986054771] user_pref("extensions.Surftastic.asul", "1396311976835"); =>PUP.Optional.Surftastic
O69 - SBI: prefs.js [Abokr - c6gs1yl5.default-1377986054771] user_pref("extensions.Surftastic.aul", "1396311469931"); =>PUP.Optional.Surftastic
O69 - SBI: prefs.js [Abokr - c6gs1yl5.default-1377986054771] user_pref("extensions.Surftastic.irl", true); =>PUP.Optional.Surftastic
O69 - SBI: prefs.js [Abokr - c6gs1yl5.default-1377986054771] user_pref("extensions.Surftastic.is", "amp17lmsa"); =>PUP.Optional.Surftastic
O69 - SBI: prefs.js [Abokr - c6gs1yl5.default-1377986054771] user_pref("extensions.Surftastic.ug", "A52364DA-0F76-4062-9918-95DEEDD3E9BE"); =>PUP.Optional.Surftastic
O69 - SBI: prefs.js [Abokr - c6gs1yl5.default-1377986054771] user_pref("keyword.URL", "http://www.arabyonline.com/search.php?src=1000&q={searchTerms}"); =>Trojan.Vonteera
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/
O69 - SBI: SearchScopes [HKCU] {6ACB8679-C193-46AF-A8F5-B0F7045AE5B4} - (google.com) - http://www.google.com/

---\\ Search Svchost Services (SSS) (O83) (33) - 1s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - ÎÏãÉ äÔÑ ÔåÇÏÉ ÇáÈØÇÞÉ ÇáÐßíÉ áÜ Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - ÎÏãÉ äÔÑ ÔåÇÏÉ ÇáÈØÇÞÉ ÇáÐßíÉ áÜ Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - ãßÊÈÉ ÇáÇÑÊÈÇØ ÇáÏíäÇãíßí áÎÏãÉ ÇáÎÇÏã.) -- C:\Windows\System32\srvsvc.dll [168960]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Úãíá äåÌ ÇáãÌãæÚÉ.) -- C:\Windows\System32\gpsvc.dll [593408]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\IKEEXT.DLL [674304]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - ÎÏãÉ ÕæÊ Windows.) -- C:\Windows\System32\audiosrv.dll [473600]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - ÅÏÇÑÉ ÇáØáÈ ÇáÊáÞÇÆí ááæÕæá Úä ÈõÚÏ.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [286208]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - ÎÏãÉ ÇáÅÚáÇã ÈÃÍÏÇË ÇáäÙÇã (SENS).) -- C:\Windows\System32\Sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [242176]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remote Desktop Session Host Server Remote C.) -- C:\Windows\System32\termsrv.dll [521216]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - ÚÇãá Windows Update.) -- C:\Windows\System32\wuaueng.dll [1933848]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - ÎÏãÉ ÇáäÞá ÇáÐßí Ýí ÇáÎáÝíÉ.) -- C:\Windows\System32\qmgr.dll [585728]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - ãßÊÈÉ ÇáÇÑÊÈÇØ ÇáÏíäÇãíßí áÎÏãÇÊ Windows Sh.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [499712]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - ãßÊÈÉ ÇáÇÑÊÈÇØ ÇáÏíäÇãíßí ÇáÎÇÕÉ ÈÎÏãÉ ÊÓÌí.) -- C:\Windows\System32\seclogon.dll [21504]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - ÎÏãÉ ãÚáæãÇÊ ÇáÊØÈíÞÇÊ.) -- C:\Windows\System32\appinfo.dll [47104]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - ÎÏãÉ ÇßÊÔÇÝ iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - ÎÏãÉ ÌÏæáÉ ÝÆÇÊ ÊÚÏÏ ÇáæÓÇÆØ.) -- C:\Windows\System32\mmcss.dll [49664]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - ÊÞÇÑíÑ ÇáãÔÇßá æÍáæáåÇ.) -- C:\Windows\System32\wercplsupport.dll [61440]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [98304]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164352]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - ÎÏãÉ ÌÏæáÉ ÇáãåÇã.) -- C:\Windows\System32\schedsvc.dll [750592]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\Windows\System32\KMSVC.DLL [71168]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - ÎÏãÉ Êßæíä ÓØÍ ÇáãßÊÈ ÇáÈÚíÏ.) -- C:\Windows\System32\SessEnv.dll [113664]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - ãßÊÈÉ ÇáÇÑÊÈÇØ ÇáÏíäÇãíßí áÎÏãÉ ãÓÊÚÑÖ Çáßã.) -- C:\Windows\System32\browser.dll [102912]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - ãßÊÈÉ ÇáÇÑÊÈÇØ ÇáÏíäÇãíßí áÎÏãÇÊ äõÓÞ Windo.) -- C:\Windows\System32\themeservice.dll [37376]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - ÎÏãÉ BDE.) -- C:\Windows\System32\bdesvc.dll [76800]
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - ÎÏãÉ ÊËÈÊ ÇáÈÑÇãÌ.) -- C:\Windows\System32\appmgmts.dll [149504]

---\\ Firewall Active Exception List (FirewallRules) (O87) (24) - 2s
O87 - FAEL: "TCP Query User{78FE472E-85E4-4372-8579-773A76A2AE36}C:\program files\java\jre6\bin\java.exe" [In-None-P6-TRUE] .(.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\program files\java\jre6\bin\java.exe
O87 - FAEL: "UDP Query User{4BB6E6BA-82B6-4A86-9C4C-ADCB9AFB30E0}C:\program files\java\jre6\bin\java.exe" [In-None-P17-TRUE] .(.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\program files\java\jre6\bin\java.exe
O87 - FAEL: "TCP Query User{AC9D3360-9354-48B5-94AD-81D876E2929B}C:\program files\real\realplayer\realplay.exe" [In-None-P6-TRUE] .(.RealNetworks, Inc. - RealPlayer.) -- C:\program files\real\realplayer\realplay.exe
O87 - FAEL: "UDP Query User{1BCBBC95-7A53-47A4-A52A-4329ACF0CAB2}C:\program files\real\realplayer\realplay.exe" [In-None-P17-TRUE] .(.RealNetworks, Inc. - RealPlayer.) -- C:\program files\real\realplayer\realplay.exe
O87 - FAEL: "{D38999AE-80CF-4681-8FD4-DB3A1CC80D6E}" [In-None-P6-TRUE] .(.Research In Motion - BlackBerry Desktop Software.) -- C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe
O87 - FAEL: "{2A8E5D52-B001-4EE6-9404-8727FA98ABA8}" [In-None-P17-TRUE] .(.Research In Motion - BlackBerry Desktop Software.) -- C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe
O87 - FAEL: "{9455A21B-D37B-4312-9861-8B926DAD27FB}" [In-None-P6-TRUE] .(.Musiccity Co.Ltd. - MUZAoDApp Module.) -- C:\Windows\System32\muzapp.exe
O87 - FAEL: "{C7256024-1ABC-4C5B-B0FC-34E2918EF05E}" [In-None-P17-TRUE] .(.Musiccity Co.Ltd. - MUZAoDApp Module.) -- C:\Windows\System32\muzapp.exe
O87 - FAEL: "TCP Query User{733D675A-F8E6-4865-8BE7-8704F2873A57}C:\users\abokr\documents\downloads\compressed\dreambox control center dcc 2.95\dcc.exe" [In-None-P6-TRUE] .(.BernyR - Dreambox Control Center.) -- C:\users\abokr\documents\downloads\compressed\dreambox control center dcc 2.95\dcc.exe
O87 - FAEL: "UDP Query User{D2FB0A88-5080-4CE9-9916-73790ACA7900}C:\users\abokr\documents\downloads\compressed\dreambox control center dcc 2.95\dcc.exe" [In-None-P17-TRUE] .(.BernyR - Dreambox Control Center.) -- C:\users\abokr\documents\downloads\compressed\dreambox control center dcc 2.95\dcc.exe
O87 - FAEL: "TCP Query User{BC62EE65-0D86-4B6F-A614-022BDEEDD44E}C:\program files\videolan\vlc\vlc.exe" [In-None-P6-TRUE] .(.VideoLAN - VLC media player 2.1.5.) -- C:\program files\videolan\vlc\vlc.exe
O87 - FAEL: "UDP Query User{FFFFC968-9A7B-4C39-B329-16EAF4623A1D}C:\program files\videolan\vlc\vlc.exe" [In-None-P17-TRUE] .(.VideoLAN - VLC media player 2.1.5.) -- C:\program files\videolan\vlc\vlc.exe
O87 - FAEL: "{2EAF42FF-4DA1-4F09-8D8D-BB4BA48AEF02}" [In-None-P17-TRUE] .(.VideoLAN - VLC media player 2.1.5.) -- C:\program files\videolan\vlc\vlc.exe
O87 - FAEL: "{36880AD0-E790-4C2D-88D5-6D566CAA97B2}" [In-None-P6-TRUE] .(.VideoLAN - VLC media player 2.1.5.) -- C:\program files\videolan\vlc\vlc.exe
O87 - FAEL: "{138BE1C9-50FA-4F5A-BD89-FCD9F6B34B77}" [In-None-P6-TRUE] .(.TeamViewer GmbH - TeamViewer 9.) -- C:\Program Files\TeamViewer\Version9\TeamViewer.exe
O87 - FAEL: "{50FC09D8-DCE8-4D80-9DF0-B6731A5BD92C}" [In-None-P17-TRUE] .(.TeamViewer GmbH - TeamViewer 9.) -- C:\Program Files\TeamViewer\Version9\TeamViewer.exe
O87 - FAEL: "{6B789769-7487-42DF-AEC3-53472A44405B}" [In-None-P6-TRUE] .(.TeamViewer GmbH - TeamViewer 9.) -- C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
O87 - FAEL: "{08CE46A9-FAF2-499C-BABB-8BB0637FA534}" [In-None-P17-TRUE] .(.TeamViewer GmbH - TeamViewer 9.) -- C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
O87 - FAEL: "TCP Query User{322D6360-3B46-4100-A1C8-F76EFEF395ED}C:\users\abokr\appdata\roaming\utorrent\utorrent.exe" [In-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\users\abokr\appdata\roaming\utorrent\utorrent.exe
O87 - FAEL: "UDP Query User{83368106-4407-4599-AC11-34A7338CAE48}C:\users\abokr\appdata\roaming\utorrent\utorrent.exe" [In-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\users\abokr\appdata\roaming\utorrent\utorrent.exe
O87 - FAEL: "TCP Query User{62428EDD-30D3-41EB-B14E-B5AC84EBDBB8}C:\users\abokr\appdata\roaming\utorrent\utorrent.exe" [In-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\users\abokr\appdata\roaming\utorrent\utorrent.exe
O87 - FAEL: "UDP Query User{98A59E3E-66F3-4585-944E-CBA6912AC60E}C:\users\abokr\appdata\roaming\utorrent\utorrent.exe" [In-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\users\abokr\appdata\roaming\utorrent\utorrent.exe
O87 - FAEL: "{6EC4569F-EA29-4284-9765-641C692FC764}" [In-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Abokr\AppData\Roaming\uTorrent\uTorrent.exe
O87 - FAEL: "{950B4ADC-C580-40A5-8E7A-6EF531DE1A5D}" [In-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Abokr\AppData\Roaming\uTorrent\uTorrent.exe

---\\ Additional Scan (O88) (11) - 0s
C:\Users\Abokr\AppData\Roaming\00000000-1429418606-0000-0000-001FD01E31BC\jnsn2D56.tmp =>PUP.Optional.CrossRider
C:\Users\Abokr\AppData\Roaming\00000000-1429418606-0000-0000-001FD01E31BC\nsjD374.tmp =>PUP.Optional.CrossRider
HKLM\SYSTEM\CurrentControlSet\Services\qesowobi =>PUP.Optional.CrossRider
HKLM\SYSTEM\CurrentControlSet\Services\xipepebe =>PUP.Optional.CrossRider
C:\Windows\Tasks\Bidaily Synchronize Task[pr].job =>PUP.Optional.BidailySync
C:\Windows\System32\Tasks\Bidaily Synchronize Task[pr] =>PUP.Optional.BidailySync
HKLM\SOFTWARE\WinUpdat =>PUP.Optional.WinRST
HKCU\SOFTWARE\Ge-Force-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\Sense-nv-ie =>PUP.Optional.CrossRider
C:\Program Files\Steel Cut =>PUP.Optional.SteelCut
C:\ProgramData\TheAdBlock =>PUP.Optional.TheAdBlock

---\\ Summary of the elements found on your workstation (9) - 0s
http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider
http://www.nicolascoolman.fr/blog =>PUP.Optional.CrossBrowse
http://www.nicolascoolman.fr/blog =>PUP.Optional.BidailySync
http://www.nicolascoolman.fr/blog =>PUP.Optional.WinRST
http://www.nicolascoolman.fr/pup-steelcut/ =>PUP.Optional.SteelCut
http://www.nicolascoolman.fr/blog =>PUP.Optional.TheAdBlock
http://www.nicolascoolman.fr/blog =>PUP.Optional.SearchEngine
http://www.nicolascoolman.fr/pup-surftastic/ =>PUP.Optional.Surftastic
http://www.nicolascoolman.fr/trojan-vonteera/ =>Trojan.Vonteera

~ End of the scan, 28864 items in 328 seconds (1163)(0)()

Publicité


Signaler le contenu de ce document

Publicité