cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.10.30.158 By Nicolas Coolman (2015/10/29)
~ Run by Hasona (Administrator) (2015/10/31 22:33:26)
~ Web: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ State version: Version OK
~ Mode: Scan
~ Report: C:\Users\Hasona\Desktop\ZHPDiag.txt
~ Report: C:\Users\Hasona\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ System startup: Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 10240)

---\\ Internet Browsers (3) - 0s
GCIE: Google Chrome v46.0.2490.80
MFIE: Mozilla Firefox 41.0.2 (x86 ar) v41.0.2
MSIE: Internet Explorer v11.0.10240.16431

---\\ Windows Product Information (3) - 6s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK

---\\ System protection software (2) - 2s
Kaspersky Total Security v16.0.0.614
Windows Defender (Deactivate)

---\\ System optimization software (1) - 3s
CCleaner v5.08

---\\ Surveillance software (2) - 3s
Adobe Flash Player 19 NPAPI
Adobe Reader X

---\\ Information on the system (6) - 0s
~ Operating System: Intel64 Family 6 Model 30 Stepping 5, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 8383.988 MB (69% free)
~ System Restore: Activé (Enable)
~ System drive C: has 85 GB free of 199 GB

---\\ Connection to the system mode (3) - 0s
~ Computer Name: HASONA-PC
~ User Name: Hasona
~ Logged in as Administrator

---\\ Enumeration of the disk units (3) - 6s
~ Drive C: has 85 GB free of 199 GB (System)
~ Drive D: has 199 GB free of 200 GB
~ Drive E: has 553 GB free of 553 GB

---\\ State of the Windows Security Center (8) - 0s
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableTaskMgr: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Search Generic System Files (24) - 27s
[MD5.F1CBCB7FA6F3B309639AA2D4EF74469C] - 11/08/2015 - (.Microsoft Corporation - مستكشف Windows.) -- C:\WINDOWS\Explorer.exe [4532304] ©
[MD5.5DED2A3F11AE916C8F2724947E736261] - 10/07/2015 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\WINDOWS\System32\rundll32.exe [59392] ©
[MD5.7718A2A9B2BFB2C8E2BAEB03310CA3FD] - 18/07/2015 - (.Microsoft Corporation - ‎‎تطبيق بدء تشغيل Windows.) -- C:\WINDOWS\System32\Wininit.exe [290312] ©
[MD5.E5D86250453B33900666D92ED1A92ABE] - 17/09/2015 - (.Microsoft Corporation - ملحقات الإنترنت لـ Win32.) -- C:\WINDOWS\System32\wininet.dll [2740224] ©
[MD5.C527C9231D39BF69611F5F8C80C36140] - 21/10/2015 - (.Microsoft Corporation - تطبيق تسجيل دخول Windows.) -- C:\WINDOWS\System32\Winlogon.exe [579072] ©
[MD5.ECB1943967424DFB96E03F6A098434EF] - 19/07/2015 - (.Microsoft Corporation - مكتبة تراخيص البرامج.) -- C:\WINDOWS\System32\sppcomapi.dll [430592] ©
[MD5.C287D0E32771E3222A444DC527A29477] - 10/07/2015 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\WINDOWS\System32\dnsapi.dll [680256] ©
[MD5.BB5BBD0E4D04047585E4ED0F07AA51E7] - 10/07/2015 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\WINDOWS\Syswow64\dnsapi.dll [534064] ©
[MD5.6C12C7E01A4F64E0AA9C88AF66955CC9] - 10/07/2015 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\WINDOWS\System32\drivers\AFD.sys [577888] ©
[MD5.8921DF6060DB5C7700AA48CB12E9EA08] - 10/07/2015 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [28512] ©
[MD5.F2829DC6D292DCAC5029893BB2E9FEE3] - 10/07/2015 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [92672] ©
[MD5.CA160E02F35A61C6F5C681FB4669C519] - 10/07/2015 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [174080] ©
[MD5.25435407D97419627F4B10653433BF2B] - 10/07/2015 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\DfsC.sys [138240] ©
[MD5.C277A49F8A8295840DEBC9240B75A282] - 10/07/2015 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [80896] ©
[MD5.D4CDEE4A62BDFFF6E8558A9552148EA7] - 10/07/2015 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [114688] ©
[MD5.5D3744E6FDEC1A6FB3FA9B1DD4AF0694] - 10/07/2015 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [143360] ©
[MD5.1DF2C5FD2710A13B07E663A12F0E0EEA] - 10/07/2015 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [415232] ©
[MD5.F0D791348AD254360CC3C3E501CCB745] - 10/07/2015 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [273408] ©
[MD5.466EC5659C02ED53DBD47DC1BC2B8086] - 30/07/2015 - (.Microsoft Corporation - NT File System Driver.) -- C:\WINDOWS\System32\drivers\ntfs.sys [2116448] ©
[MD5.38F1AE32339731F6E5A7281AE8042545] - 10/07/2015 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\WINDOWS\System32\drivers\Parport.sys [96768] ©
[MD5.CA60F6C03611AF1710BC903ED9F566FB] - 10/07/2015 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [104960] ©
[MD5.A32AED8C644734B283A7C9D08D76064D] - 10/07/2015 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [176128] ©
[MD5.28E1E63A1AC65E17B3194238FA2CF3BF] - 10/07/2015 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [116576] ©
[MD5.823A237D871CD652C6BFD47BECB6810A] - 10/07/2015 - (.Microsoft Corporation - Volume Shadow Copy Driver.) -- C:\WINDOWS\System32\drivers\volsnap.sys [378720] ©

---\\ Process running (26) - 0s
[MD5.5FECE663E1DE63053D52E6CECA2AFDF8] - (.NVIDIA Corporation - Stereo Vision Control Panel API Server.) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [417400] [PID.1208] ©
[MD5.D19C4EE2AC7C47B8F5F84FFF1A789D8A] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [63960] [PID.2176] ©
[MD5.B17D0BDBDDF4BD4709D6CA3147D409C0] - (.NVIDIA Corporation - NVIDIA GeForce ExperienceService.) -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156384] [PID.2260] ©
[MD5.50C3C62FFE6337E6E4F2F01CB07DF63C] - (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 16.0.0\avp.exe [194000] [PID.2368] ©
[MD5.C2909BD26906E1D05D77B1D48B48E94A] - (.NVIDIA Corporation - NVIDIA Network Service.) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1873696] [PID.2532] ©
[MD5.ED5F5504A99E92211B753E1815A34CBC] - (...) -- C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [32880] [PID.2684]
[MD5.AF610CC6600953A3C236FDF41D322893] - (.RealNetworks, Inc. - RealTimes Desktop Service.) -- c:\program files (x86)\Real\realplayer\RPDS\Bin\rpdsvc.exe [1115736] [PID.2916] ©
[MD5.932A21CF0DA4E951C7C4A62D27E6D8FB] - (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 16.0.0\avpui.exe [211712] [PID.3988] ©
[MD5.65E8545F1297CD83534C354A7BED1848] - (.Realtek Semiconductor - إدارة صوت Realtek HD.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696] [PID.2496] ©
[MD5.6BE70A935DFD72F47C29757305B50B1E] - (.NVIDIA Corporation - NVIDIA Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2655520] [PID.5336] ©
[MD5.3DDC1784EA5963EFBDF5D528D53820B4] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3911248] [PID.5664] ©
[MD5.9D51EA92A612B37E76E5E4621650C50A] - (.Renesas Electronics Corporation - USB 3.0 Monitor.) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288] [PID.5184] ©
[MD5.FBD407FFA18B89CAED9A196E2267B6DA] - (.RealNetworks, Inc. - RealTimes Service UI.) -- C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpsystray.exe [1133656] [PID.3760] ©
[MD5.2EB0316230509066579851D237173679] - (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [286784] [PID.1596] ©
[MD5.FCEC6F664FA7E5FE323165FBC9314470] - (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040] [PID.4116] ©
[MD5.E9C6EF9437ECB30911488F9313AD821A] - (.Tonec Inc. - Internet Download Manager agent for click m.) -- C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe [269848] [PID.4748] ©
[MD5.12C2DF35CCE47376933A3FA0D57D59A5] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 358.5.) -- C:\Windows\System32\nvvsvc.exe [938800] [PID.4684] ©
[MD5.68B1D7C5A6EE6CB585E4F39B65766E42] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe [1253168] [PID.6068] ©
[MD5.12C2DF35CCE47376933A3FA0D57D59A5] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 358.5.) -- C:\Windows\System32\nvvsvc.exe [938800] [PID.4764] ©
[MD5.87438B0C7DF32411CDC6E7D96B275B19] - (.RealNetworks, Inc. - RealDownloader.) -- C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [343640] [PID.5804] ©
[MD5.87438B0C7DF32411CDC6E7D96B275B19] - (.RealNetworks, Inc. - RealDownloader.) -- C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [343640] [PID.5624] ©
[MD5.59499B4B9127191704FAAF58E220F85D] - (.Internet Download Manager, Tonec Inc. - Broker for reading of IDM settings.) -- C:\Program Files (x86)\Internet Download Manager\idmBroker.exe [69144] [PID.2500] ©
[MD5.1767250F71798F94A26D635B8DCA9ED9] - (.NVIDIA Corporation - NVIDIA Settings.) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe [2448176] [PID.5328] ©
[MD5.1767250F71798F94A26D635B8DCA9ED9] - (.NVIDIA Corporation - NVIDIA Settings.) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe [2448176] [PID.4948] ©
[MD5.BD2E3D5008F1EAB96379CEA2C0FABBBD] - (.Adobe Systems Incorporated - Adobe® Flash® Player Utility.) -- C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe [882680] [PID.4080] ©
[MD5.0C9ED96644A1A39C420DE030F447DDF0] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Hasona\Downloads\Programs\ZHPDiag3.exe [1961984] [PID.5952] ©

---\\ Google Chrome, Start,Search,Extensions (25) - 22s
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.com.sa
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://accounts.google.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://chrome.google.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://clients4.google.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.gstatic.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.googleapis.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.gstatic.com
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.google.com
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [ejbdobdndcjhdmljipngpeoekdinlohe] Norton Home Page for Chrome
G2 - GCE: Preference [User Data\Default] [hbcennhacfaagdopikcegfcobcadeocj] eBay Shopping Assistant
G2 - GCE: Preference [User Data\Default] [icdlfehblmklkikfigmjhbmmpmkmpooj] Domain Error Assistant
G2 - GCE: Preference [User Data\Default] [iikflkcanblccfahdhdonehdalibjnif] Norton Identity Safe
G2 - GCE: Preference [User Data\Default] [kaebhgioafceeldhgjmendlfhbfjefmo] EagleGet Free Downloader
G2 - GCE: Preference [User Data\Default] [lifbcibllhkdhoafpjfnlhfpfgnpldfl] Skype Click to Call
G2 - GCE: Preference [User Data\Default] [mhkaekfpcppmmioggniknbnbdbcigpkk] Slick Savings
G2 - GCE: Preference [User Data\Default] [ngpampappnmepgilojfohadhhmbhlaek] IDM Integration Module
G2 - GCE: Preference [User Data\Default] [nmgcfemagnogdodbambjhdcmfcpicngl] Norton Safe
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pfndaklgolladniicklehhancnlgocpp] Amazon Shopping Assistant by Spigot
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc.

---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (11) - 55s
M1 - SPR:Search Page Redirection - C:\Program Files (x86)\Mozilla Firefox\extensions\afurladvisor@anchorfree.com
P2 - EXT: (. - NPAPI Extension for Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\nppluginrichmediaplayer.dll
P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\WMP Firefox Plugin License.rtf
P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\WMP Firefox Plugin RelNotes.txt
P2 - EXT FILE: (...) -- C:\Users\Hasona\AppData\Roaming\Mozilla\Firefox\Profiles\7yaf5eqd.default\extensions\eagleget_ffext@eagleget.com.xpi
P2 - EXT FILE: (...) -- C:\Users\Hasona\AppData\Roaming\Mozilla\Firefox\Profiles\7yaf5eqd.default\extensions\firefox@zenmate.com.xpi
P2 - EXT FILE: (...) -- C:\Users\Hasona\AppData\Roaming\Mozilla\Firefox\Profiles\7yaf5eqd.default\searchplugins\babylon.xml =>PUP.Optional.Babylon
P2 - EXT FILE: (...) -- C:\Users\Hasona\AppData\Roaming\Mozilla\Firefox\Profiles\7yaf5eqd.default\searchplugins\delta.xml
P2 - EXT: (.Mozilla - Default.) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ©
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll ©
P2 - FPN: [HKLM] [@real.com/nprpplugin;version=18.0.2.59] - (.RealTimes.) -- c:\program files (x86)\Real\realplayer\Netscape6\nprpplugin.dll

---\\ Internet Explorer Extensions, Start, Search (18) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: (no name) - {1429281c-75a8-469c-86c1-a812ca17c452} Orphean
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1
R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1

---\\ Internet Explorer, Proxy Management (5) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
F2 - REG:system.ini: UserInit=
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) ©
F2 - REG:system.ini: VMApplet=

---\\ Hosts file redirection (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)

---\\ Browser Helper Object (BHO) (11) - 2s
O2 - BHO: IDM Helper [64Bits] - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll ©
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer [64Bits] - {3049C3E9-B461-4BC5-8870-4C09146192CA} . (.RealDownloader - RealTimes Video Downloader.) -- C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll ©
O2 - BHO: Skype for Business Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} . (.Microsoft Corporation - Skype for Business.) -- C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll ©
O2 - BHO: Norton Identity Protection [64Bits] - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} (Orphean)
O2 - BHO: Groove GFS Browser Helper [64Bits] - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL ©
O2 - BHO: Norton Identity Protection [64Bits] - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} . (.Symantec Corporation - coIEPlugIn.) -- C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\CoIEPlg.dll ©
O2 - BHO: SkypeIEPluginBHO [64Bits] - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll ©
O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL ©
O2 - BHO: ScriptInjectionPluginBrowserHelperObject [64Bits] - {C66D064F-82FE-4E1A-B06A-B2490BA48B18} . (.AO Kaspersky Lab - Kaspersky Protection plugins.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 16.0.0\IEExt\ie_plugin.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} . (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL ©
O2 - BHO: (no name) [64Bits] - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} (Orphean)

---\\ Internet Explorer Toolbars (3) - 0s
O3 - Toolbar: arab_media Toolbar - [HKLM]{1429281c-75a8-469c-86c1-a812ca17c452} . (...) -- (.not file.)
O3 - Toolbar: Norton Toolbar - [HKLM]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} . (...) -- (.not file.)
O3 - Toolbar: (no name) - [HKLM]{3507FA00-ADA2-4A02-99B9-51AD26CA9120} (Orphean)

---\\ Auto loading programs from Registry and folders (20) - 1s
O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - إدارة صوت Realtek HD.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe ©
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe ©
O4 - HKLM\..\Run: [BCSSync] . (.Microsoft Corporation - Microsoft Office 2010 component.) -- C:\Program Files\Microsoft Office\Office14\BCSSync.exe ©
O4 - HKLM\..\Run: [NvBackend] . (.NVIDIA Corporation - NVIDIA Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe ©
O4 - HKLM\..\Run: [ShadowPlay] . (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe ©
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (.not file.)
O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe ©
O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe ©
O4 - HKLM\..\Wow6432Node\Run: [NUSB3MON] . (.Renesas Electronics Corporation - USB 3.0 Monitor.) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe ©
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe ©
O4 - HKLM\..\Wow6432Node\Run: [AdobeCEPServiceManager] . (.Adobe Systems Incorporated - Adobe CEP Service Manager.) -- C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe ©
O4 - HKLM\..\Wow6432Node\Run: [HDD Regenerator] C:\Program Files (x86)\HDD Regenerator\Shell.exe (.not file.)
O4 - HKLM\..\Wow6432Node\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- c:\program files (x86)\Real\realplayer\Update\realsched.exe ©
O4 - HKLM\..\Wow6432Node\Run: [RealDownloader] . (.Copyright © RealNetworks, Inc. 1995-2012 - RealDownloader.) -- C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ©
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe ©
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe ©
O4 - HKUS\S-1-5-21-3877646012-4086668814-2580275828-1000\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (.not file.)
O4 - HKUS\S-1-5-21-3877646012-4086668814-2580275828-1000\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe ©
O4 - HKUS\S-1-5-21-3877646012-4086668814-2580275828-1000\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe ©

---\\ Winsock hijacker (Layered Service Provider) (7) - 0s
O10 - WLSP:\Catalog_Entries\000000000001\Winsock LSP File . (...) -- C:\Windows\System32\networkdlllsp.dll (Not File) =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries\000000000002\Winsock LSP File . (...) -- C:\Windows\System32\networkdlllsp.dll (Not File) =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries\000000000003\Winsock LSP File . (...) -- C:\Windows\System32\networkdlllsp.dll (Not File) =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries\000000000004\Winsock LSP File . (...) -- C:\Windows\System32\networkdlllsp.dll (Not File) =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries\000000000005\Winsock LSP File . (...) -- C:\Windows\System32\networkdlllsp.dll (Not File) =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries\000000000006\Winsock LSP File . (...) -- C:\Windows\System32\networkdlllsp.dll (Not File) =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries\000000000007\Winsock LSP File . (...) -- C:\Windows\System32\networkdlllsp.dll (Not File) =>Hijacker.Winsock

---\\ Lop.com/Domain Hijackers (6) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.4.4 =>.Google Public DNS
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = lan
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.4.4 =>.Google Public DNS
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpDomain = lan

---\\ Extra protocols (26) - 15s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - عارض Microsoft (R) HTML.) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - ملحقات OLE32 لـ Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll ©
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - ملحقات OLE32 لـ Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - ملحقات OLE32 لـ Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - ملحقات OLE32 لـ Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - ملحقات OLE32 لـ Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll ©
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - عارض Microsoft (R) HTML.) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - ملحقات OLE32 لـ Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - عارض Microsoft (R) HTML.) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\SysWOW64\inetcomm.dll ©
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - ملحقات OLE32 لـ Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll ©
O18 - Handler: osf [64Bits] - {D924BDC6-C83A-4BD5-90D0-095128A113D1} . (.Microsoft Corporation - Microsoft Office 2013 component.) -- C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL ©
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - عارض Microsoft (R) HTML.) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: skype4com [64Bits] - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} . (.Skype Technologies - Skype4COM.) -- C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll ©
O18 - Handler: skypec2c [64Bits] - {91774881-D725-4E58-B298-07617B9B86A8} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll ©
O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\SysWOW64\tbauth.dll ©
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll ©
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - عارض Microsoft (R) HTML.) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Photo Gallery Album Download Protocol Handl.) -- C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll ©
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll ©
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll ©
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll ©
O18 - Filter: text/xml [64Bits] - {807583E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL ©

---\\ Non Microsoft non disabled Windows Services (14) - 1s
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe ©
O23 - Service: Kaspersky Anti-Virus Service 16.0.0 (AVP16.0.0) . (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 16.0.0\avp.exe ©
O23 - Service: egGetSvc (egGetSvc) . (.Copyright (C) EagleGet 2014~2015 - EGMonitor.) - C:\Program Files (x86)\EagleGet\EGMonitor.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) . (.NVIDIA Corporation - NVIDIA GeForce ExperienceService.) - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe ©
O23 - Service: خدمة Google Update (gupdate) (gupdate) . (.Google Inc. - مثبِّت Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ©
O23 - Service: Hotspot Shield Monitoring Service (HssWd) . (...) - C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe (.not file.)
O23 - Service: Norton Identity Safe (NCO) . (.Symantec Corporation - Norton Identity Safe.) - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\NST.exe ©
O23 - Service: NVIDIA Network Service (NvNetworkService) . (.NVIDIA Corporation - NVIDIA Network Service.) - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe ©
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) . (.NVIDIA Corporation - NVIDIA Streamer Service.) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe ©
O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 358.5.) - C:\Windows\System32\nvvsvc.exe ©
O23 - Service: RealPlayer Update Service (RealPlayerUpdateSvc) . (...) - C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
O23 - Service: RealTimes Desktop Service (RealTimes Desktop Service) . (.RealNetworks, Inc. - RealTimes Desktop Service.) - c:\program files (x86)\Real\realplayer\RPDS\Bin\rpdsvc.exe ©
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe ©
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) . (.NVIDIA Corporation - Stereo Vision Control Panel API Server.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe ©

---\\ Task Planned Automatically (24) - 29s
[MD5.8C194A201698B4B4F77D974549819D1F] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [269000] ©
[MD5.00000000000000000000000000000000] [APT] [AutoPico Daily Restart] (...) -- C:\Program Files\KMSpico\AutoPico.exe (.not file.) [0] =>HackTool.KMSpico
[MD5.3D01BD151A423F6B7D89970E42E31E46] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6453528] ©
[MD5.00000000000000000000000000000000] [APT] [GoforFilesUpdate] (...) -- C:\Program Files (x86)\GoforFiles\GFFUpdater.exe (.not file.) [0] =>PUP.Optional.YourFileDownloader
[MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] ©
[MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] ©
[MD5.A3C70B18A44741DB0393750880AA73F1] [APT] [RealDownloader Update Check] (.Copyright © RealNetworks, Inc. 1995-2012.) -- C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [614464]
[MD5.0F6A28DD356843E2C42044195F1A113F] [APT] [RealDownloaderRealUpgradeLogonTaskS-1-5-21-3877646012-4086668814-2580275828-1000] (.RealNetworks, Inc..) -- C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [143424] ©
[MD5.0F6A28DD356843E2C42044195F1A113F] [APT] [RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3877646012-4086668814-2580275828-1000] (.RealNetworks, Inc..) -- C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [143424] ©
[MD5.9EC72B7CE86BCFD675DF4FEBAD15DBCA] [APT] [Volaro Update] (.Volaro.) -- C:\Program Files (x86)\Volaro\Updater\Updater.exe [280400] =>Trojan.Vonteera
[MD5.00000000000000000000000000000000] [APT] [YourFile DownloaderUpdate] (...) -- C:\Program Files (x86)\YourFileDownloader Updater\YourFileUpdater.exe (.not file.) [0] =>PUP.Optional.YourFileDownloader
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job [830] ©
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job [866] ©
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job [870] ©
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater [3804] ©
O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\WINDOWS\System32\Tasks\CCleanerSkipUAC [2904] ©
O39 - APT: GoforFilesUpdate - (...) -- C:\WINDOWS\System32\Tasks\GoforFilesUpdate [3188] =>PUP.Optional.YourFileDownloader
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore [3696] ©
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA [3928] ©
O39 - APT: RealDownloader Update Check - (.Copyright © RealNetworks, Inc. 1995-2012.) -- C:\WINDOWS\System32\Tasks\RealDownloader Update Check [3560]
O39 - APT: RealDownloaderRealUpgradeLogonTaskS-1-5-21-3877646012-4086668814-2580275828-1000 - (.RealNetworks, Inc..) -- C:\WINDOWS\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3877646012-4086668814-2580275828-1000 [3552] ©
O39 - APT: RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3877646012-4086668814-2580275828-1000 - (.RealNetworks, Inc..) -- C:\WINDOWS\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3877646012-4086668814-2580275828-1000 [3612] ©
O39 - APT: Volaro Update - (.Volaro.) -- C:\WINDOWS\System32\Tasks\Volaro Update [3530] =>Trojan.Vonteera
O39 - APT: YourFile DownloaderUpdate - (...) -- C:\WINDOWS\System32\Tasks\YourFile DownloaderUpdate [3246] =>PUP.Optional.YourFileDownloader

---\\ Software installed (81) - 9s
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner ©
O42 - Logiciel: KMSpico v9.3.1 - (...) [HKLM][64Bits] -- KMSpico_is1 =>HackTool.KMSpico
O42 - Logiciel: Speccy - (.Piriform.) [HKLM][64Bits] -- Speccy ©
O42 - Logiciel: TeamSpeak 3 Client - (.TeamSpeak Systems GmbH.) [HKLM][64Bits] -- TeamSpeak 3 Client ©
O42 - Logiciel: WinRAR 4.20 (64-بت) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver ©
O42 - Logiciel: MotioninJoy Gamepad tool 0.7.1001 - (.www.motioninjoy.com.) [HKLM][64Bits] -- {330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1 ©
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} ©
O42 - Logiciel: AMD Wireless Display v3.0 - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {8E4821DB-6F10-E1B8-ED65-6756ADFC54EF} ©
O42 - Logiciel: Microsoft Access MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0015-0401-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Excel MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0016-0401-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft PowerPoint MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0018-0401-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Publisher MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0019-0401-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Outlook MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001A-0401-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Word MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001B-0401-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft InfoPath MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0044-0401-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft DCF MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0090-0401-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft OneNote MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00A1-0401-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Groove MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00BA-0401-1000-0000000FF1CE} ©
O42 - Logiciel: Update for Skype for Business 2015 (KB3085581) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{6BCC80EE-3B68-4110-8D47-23E04FB6D08D} ©
O42 - Logiciel: Microsoft Lync MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-012B-0401-1000-0000000FF1CE} ©
O42 - Logiciel: Update for Skype for Business 2015 (KB2889853) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90150000-012B-0401-1000-0000000FF1CE}_Office15.PROPLUSR_{4B154642-070A-4391-A5A6-E41FDC0FF38B} ©
O42 - Logiciel: Update for Skype for Business 2015 (KB3085581) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90150000-012B-0401-1000-0000000FF1CE}_Office15.PROPLUSR_{6BCC80EE-3B68-4110-8D47-23E04FB6D08D} ©
O42 - Logiciel: Update for Skype for Business 2015 (KB3085581) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {91150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{6BCC80EE-3B68-4110-8D47-23E04FB6D08D} ©
O42 - Logiciel: Microsoft DVD App Installation for Microsoft.WindowsDVDPlayer_2019.6.11761. - (.Microsoft Corporation.) [HKLM][64Bits] -- {986E003C-E56D-5A47-110E-D3C81F0E8535} ©
O42 - Logiciel: NVIDIA برامج تشغيل ‎3D Vision 358.50 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision ©
O42 - Logiciel: NVIDIA برنامج تشغيل الرسومات 358.50 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver ©
O42 - Logiciel: NVIDIA GeForce Experience 2.5.15.54 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience ©
O42 - Logiciel: NVIDIA برنامج تشغيل مراقب ‎3D Vision 352.65 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB ©
O42 - Logiciel: NVIDIA برنامج نظام PhysX 9.15.0428 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX ©
O42 - Logiciel: NVIDIA برنامج تشغيل صوت HD 1.3.34.3 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver ©
O42 - Logiciel: AMD Wireless Display v3.0 - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {C3ECDE27-BD89-71E3-254D-DF32AF7C389D} ©
O42 - Logiciel: MSVCRT110_amd64 - (.Microsoft.) [HKLM][64Bits] -- {E9FA781F-3E80-4399-825A-AD3E11C28C77} ©
O42 - Logiciel: Adobe Flash Player 19 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI ©
O42 - Logiciel: Audacity 2.0.6 - (.Audacity Team.) [HKLM][64Bits] -- Audacity_is1 ©
O42 - Logiciel: AviSynth 2.5 - (...) [HKLM][64Bits] -- AviSynth
O42 - Logiciel: Bundled software uninstaller - (...) [HKLM][64Bits] -- bi_uninstaller
O42 - Logiciel: CABAL2 (US) - (.ESTsoft Corp..) [HKLM][64Bits] -- CABAL2US ©
O42 - Logiciel: Google Chrome - (.Google Inc‎.‎.) [HKLM][64Bits] -- Google Chrome ©
O42 - Logiciel: Renesas Electronics USB 3.0 Host Controller Driver - (.Renesas Electronics Corporation.) [HKLM][64Bits] -- InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996} ©
O42 - Logiciel: GIGABYTE OC_GURU II - (.GIGABYTE Technology Co.,Ltd..) [HKLM][64Bits] -- InstallShield_{EA298EC1-2B8F-4DA9-8C5B-BC1FCBBAD72F}
O42 - Logiciel: Kaspersky Total Security - (.Kaspersky Lab.) [HKLM][64Bits] -- InstallWIX_{77E7AE5C-181C-4CAF-ADBF-946F11C1CE26} ©
O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM][64Bits] -- Internet Download Manager ©
O42 - Logiciel: K-Lite Codec Pack 4.7.5 (Full) - (...) [HKLM][64Bits] -- KLiteCodecPack_is1
O42 - Logiciel: LAME v3.99.3 (for Windows) - (...) [HKLM][64Bits] -- LAME_is1
O42 - Logiciel: Action! - (.Mirillis.) [HKLM][64Bits] -- Mirillis Action! ©
O42 - Logiciel: MKVToolNix 6.5.0 - (.Moritz Bunkus.) [HKLM][64Bits] -- MKVToolNix ©
O42 - Logiciel: Mozilla Firefox 41.0.2 (x86 ar) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 41.0.2 (x86 ar) ©
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService ©
O42 - Logiciel: NVIDIA Stereoscopic 3D Driver - (.NVIDIA Corporation.) [HKLM][64Bits] -- NVIDIAStereo ©
O42 - Logiciel: RealTimes (RealPlayer) - (.RealNetworks.) [HKLM][64Bits] -- RealPlayer 18.0 ©
O42 - Logiciel: UltraISO Premium V8.61 - (...) [HKLM][64Bits] -- UltraISO_is1
O42 - Logiciel: VobSub v2.23 (Remove Only) - (...) [HKLM][64Bits] -- VobSub
O42 - Logiciel: Volaro Updater - (.Volaro.) [HKLM][64Bits] -- Volaro Updater =>Trojan.Vonteera
O42 - Logiciel: PDF Settings CC - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {1FBAE18D-4DE4-47AA-83EC-D1B046F262DC} ©
O42 - Logiciel: Java 8 Update 65 - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83218065F0} ©
O42 - Logiciel: Aion RainMeter version 2.1 - (.Rainy.ws.) [HKLM][64Bits] -- {284CFEE9-720C-43C6-A276-1945CA4F6DDF}_is1 ©
O42 - Logiciel: RealUpgrade 1.1 - (.RealNetworks, Inc..) [HKLM][64Bits] -- {28C2DED6-325B-4CC7-983A-1777C8F7FBAB} ©
O42 - Logiciel: Adobe Photoshop CC - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {2D99B50E-431D-4AA8-85C1-172A6F8BCF09} ©
O42 - Logiciel: Snagit 11 - (.TechSmith Corporation.) [HKLM][64Bits] -- {44BD21C2-9132-48DB-B65B-23817E4C6F4B} ©
O42 - Logiciel: Renesas Electronics USB 3.0 Host Controller Driver - (.Renesas Electronics Corporation.) [HKLM][64Bits] -- {5442DAB8-7177-49E1-8B22-09A049EA5996} ©
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} ©
O42 - Logiciel: RealDownloader - (.RealNetworks.) [HKLM][64Bits] -- {66fed0a4-7536-40b2-b830-382e37c0c32c} ©
O42 - Logiciel: Windows Media Player Firefox Plugin - (.Microsoft Corp.) [HKLM][64Bits] -- {69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4} ©
O42 - Logiciel: Skype™ 7.13 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {6A0549A9-1B96-498C-ACBC-3943001FEB19} ©
O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM][64Bits] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701} ©
O42 - Logiciel: معرض الصور - (.Microsoft Corporation.) [HKLM][64Bits] -- {6F77C156-7660-4CEC-8793-97D80D5BFEC0} ©
O42 - Logiciel: Kaspersky Total Security - (.Kaspersky Lab.) [HKLM][64Bits] -- {77E7AE5C-181C-4CAF-ADBF-946F11C1CE26} ©
O42 - Logiciel: AION Free-to-Play version 1.0 - (.Gameforge.) [HKLM][64Bits] -- {82E73E8D-E1E7-45A4-A311-6D31492AA913}_is1 ©
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} ©
O42 - Logiciel: MSVCRT110 - (.Microsoft.) [HKLM][64Bits] -- {8E14DDC8-EA60-4E18-B3E3-1937104D5BDA} ©
O42 - Logiciel: Gameforge Live 2.0.8 - (.Gameforge.) [HKLM][64Bits] -- {9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1 ©
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} ©
O42 - Logiciel: Adobe Reader X (10.1.4) - Arabic - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1025-7B44-AA1000000001} ©
O42 - Logiciel: RealDownloader - (.RealNetworks, Inc..) [HKLM][64Bits] -- {B0235718-21E0-4A90-A42F-9C64C1B531CD} ©
O42 - Logiciel: Win10Pcap - (.Daiyuu Nobori, University of Tsukuba, Japan.) [HKLM][64Bits] -- {B5B58F8A-1984-4F3E-B400-235A6E005001}
O42 - Logiciel: BattlePing - (.BattlePing.) [HKLM][64Bits] -- {DB480AC3-1578-B8DC-3F8F-786A2A4E3BC7}
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF} ©
O42 - Logiciel: UpdateService - (.RealNetworks, Inc..) [HKLM][64Bits] -- {E3AE96D6-E196-45B4-AF62-2B41998B9E37} ©
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} ©
O42 - Logiciel: EagleGet version 2.0.4.6 - (.EagleGet.) [HKLM][64Bits] -- {F6D8142A-B30B-454B-9EE0-08A7B997DFE4}_is1 ©
O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU][64Bits] -- uTorrent

---\\ HKCU & HKLM Software Keys (158) - 9s
HKLM\SOFTWARE\Wow6432Node\Adobe
HKLM\SOFTWARE\Wow6432Node\AGEIA Technologies
HKLM\SOFTWARE\Wow6432Node\AMD
HKLM\SOFTWARE\Wow6432Node\AppDataLow
HKLM\SOFTWARE\Wow6432Node\Apple Computer, Inc.
HKLM\SOFTWARE\Wow6432Node\arab_media
HKLM\SOFTWARE\Wow6432Node\ATI Technologies
HKLM\SOFTWARE\Wow6432Node\AviSynth
HKLM\SOFTWARE\Wow6432Node\Baidu Security
HKLM\SOFTWARE\Wow6432Node\CDDB
HKLM\SOFTWARE\Wow6432Node\Codec Tweak Tool
HKLM\SOFTWARE\Wow6432Node\DataMngr =>PUP.Optional.Datamngr
HKLM\SOFTWARE\Wow6432Node\Delta =>Toolbar.DeltaSearch
HKLM\SOFTWARE\Wow6432Node\DivXNetworks
HKLM\SOFTWARE\Wow6432Node\Dxtory Software
HKLM\SOFTWARE\Wow6432Node\EagleGet
HKLM\SOFTWARE\Wow6432Node\EasyBoot Systems
HKLM\SOFTWARE\Wow6432Node\Gameforge
HKLM\SOFTWARE\Wow6432Node\Gameforge4d
HKLM\SOFTWARE\Wow6432Node\GNU
HKLM\SOFTWARE\Wow6432Node\GoforFiles
HKLM\SOFTWARE\Wow6432Node\Google
HKLM\SOFTWARE\Wow6432Node\HaaliMkx
HKLM\SOFTWARE\Wow6432Node\IM Providers
HKLM\SOFTWARE\Wow6432Node\InstallShield
HKLM\SOFTWARE\Wow6432Node\Intel
HKLM\SOFTWARE\Wow6432Node\Internet Download Manager
HKLM\SOFTWARE\Wow6432Node\IObit
HKLM\SOFTWARE\Wow6432Node\JavaSoft
HKLM\SOFTWARE\Wow6432Node\JreMetrics
HKLM\SOFTWARE\Wow6432Node\KasperskyLab
HKLM\SOFTWARE\Wow6432Node\Khronos
HKLM\SOFTWARE\Wow6432Node\KLCodecPack
HKLM\SOFTWARE\Wow6432Node\Lame For Audacity
HKLM\SOFTWARE\Wow6432Node\Licenses
HKLM\SOFTWARE\Wow6432Node\LogMeInRescueCallingCard
HKLM\SOFTWARE\Wow6432Node\Macromedia
HKLM\SOFTWARE\Wow6432Node\Metin2_EN
HKLM\SOFTWARE\Wow6432Node\Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\Norton
HKLM\SOFTWARE\Wow6432Node\Nostale_UK
HKLM\SOFTWARE\Wow6432Node\Nuance
HKLM\SOFTWARE\Wow6432Node\NVIDIA Corporation
HKLM\SOFTWARE\Wow6432Node\ODBC
HKLM\SOFTWARE\Wow6432Node\Overwolf
HKLM\SOFTWARE\Wow6432Node\PlayNC
HKLM\SOFTWARE\Wow6432Node\PowerPivot
HKLM\SOFTWARE\Wow6432Node\RealNetworks
HKLM\SOFTWARE\Wow6432Node\Runes of Magic
HKLM\SOFTWARE\Wow6432Node\S3R521
HKLM\SOFTWARE\Wow6432Node\Skype
HKLM\SOFTWARE\Wow6432Node\Symantec
HKLM\SOFTWARE\Wow6432Node\Systweak =>PUP.Optional.Systweak
HKLM\SOFTWARE\Wow6432Node\TechSmith
HKLM\SOFTWARE\Wow6432Node\TERA
HKLM\SOFTWARE\Wow6432Node\Tqdigital
HKLM\SOFTWARE\Wow6432Node\TuneUp
HKLM\SOFTWARE\Wow6432Node\Uniblue =>.Superfluous.Uniblue
HKLM\SOFTWARE\Wow6432Node\VobSub
HKLM\SOFTWARE\Wow6432Node\Volaro Updater =>Trojan.Vonteera
HKLM\SOFTWARE\Wow6432Node\Volatile
HKLM\SOFTWARE\Wow6432Node\Xing Technology Corp.
HKLM\SOFTWARE\Wow6432Node\YourFileDownloader =>PUP.Optional.YourFileDownloader
HKLM\SOFTWARE\Wow6432Node\Zemi Interactive
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications
HKCU\SOFTWARE\014ef4f712d39e082790d249eb634c4e =>PUP.Optional.CrossRider
HKCU\SOFTWARE\4shared
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\AhnLab
HKCU\SOFTWARE\Aion
HKCU\SOFTWARE\AMD
HKCU\SOFTWARE\AMD Driver Downloader
HKCU\SOFTWARE\AnchorFree
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\ATI
HKCU\SOFTWARE\Audacity
HKCU\SOFTWARE\Baidu
HKCU\SOFTWARE\Baidu Security
HKCU\SOFTWARE\BI =>PUP.Optional.MegaSearch
HKCU\SOFTWARE\BitTorrent
HKCU\SOFTWARE\Conduit =>PUP.Optional.Conduit
HKCU\SOFTWARE\CoreVorbis
HKCU\SOFTWARE\DataMngr =>PUP.Optional.Datamngr
HKCU\SOFTWARE\Delta =>Toolbar.DeltaSearch
HKCU\SOFTWARE\DivXNetworks
HKCU\SOFTWARE\DownloadManager
HKCU\SOFTWARE\Dreambelievers
HKCU\SOFTWARE\Drivers
HKCU\SOFTWARE\DSP-worx
HKCU\SOFTWARE\EagleGet
HKCU\SOFTWARE\EasyBoot Systems
HKCU\SOFTWARE\epsxe
HKCU\SOFTWARE\ESTsoft
HKCU\SOFTWARE\Gabest
HKCU\SOFTWARE\Gameforge4d
HKCU\SOFTWARE\GNU
HKCU\SOFTWARE\GoforFiles
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\Haali
HKCU\SOFTWARE\IKARIAM 2012
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\JavaSoft
HKCU\SOFTWARE\KasperskyLab
HKCU\SOFTWARE\Licenses
HKCU\SOFTWARE\LogMeInRescueCallingCard
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\madFlac
HKCU\SOFTWARE\MainConcept
HKCU\SOFTWARE\MediaInfo
HKCU\SOFTWARE\Mine
HKCU\SOFTWARE\Mirillis
HKCU\SOFTWARE\mkvmergeGUI
HKCU\SOFTWARE\MONOGRAM
HKCU\SOFTWARE\Mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\Netscape
HKCU\SOFTWARE\NetworkTunnel
HKCU\SOFTWARE\Norton
HKCU\SOFTWARE\NVIDIA Corporation
HKCU\SOFTWARE\ODBC
HKCU\SOFTWARE\Piriform
HKCU\SOFTWARE\plaync
HKCU\SOFTWARE\QtProject
HKCU\SOFTWARE\Raptr
HKCU\SOFTWARE\RealNetworks
HKCU\SOFTWARE\Realtek
HKCU\SOFTWARE\RegisteredApplications
HKCU\SOFTWARE\Renesas Electronics
HKCU\SOFTWARE\RLZer
HKCU\SOFTWARE\SimonTatham
HKCU\SOFTWARE\Skype
HKCU\SOFTWARE\Softonic =>PUP.Optional.Softonic
HKCU\SOFTWARE\Sysinternals
HKCU\SOFTWARE\System32
HKCU\SOFTWARE\TeamSpeak 3 Client
HKCU\SOFTWARE\TechSmith
HKCU\SOFTWARE\Trolltech
HKCU\SOFTWARE\TuneUp
HKCU\SOFTWARE\VB and VBA Program Settings
HKCU\SOFTWARE\Vision Thing
HKCU\SOFTWARE\Volaro =>Trojan.Vonteera
HKCU\SOFTWARE\WASEL Pro VPN Service
HKCU\SOFTWARE\Win
HKCU\SOFTWARE\WinRAR
HKCU\SOFTWARE\WinRAR SFX
HKCU\SOFTWARE\Wow6432Node
HKCU\SOFTWARE\YourFileDownloader =>PUP.Optional.YourFileDownloader
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\AppDataLow\Software
HKCU\SOFTWARE\AppDataLow\Software\arab_media
HKCU\SOFTWARE\AppDataLow\Software\Conduit =>PUP.Optional.Conduit
HKCU\SOFTWARE\AppDataLow\Software\JavaSoft
HKCU\SOFTWARE\AppDataLow\Software\LyricsTube
HKCU\SOFTWARE\AppDataLow\Software\Norton
HKCU\SOFTWARE\AppDataLow\Software\RealNetworks
HKCU\SOFTWARE\AppDataLow\Software\Search Settings =>PUP.Optional.SearchSettings

---\\ Contents of the Common Files folders (274) - 7s
O43 - CFD: 25/12/2013 - [] D -- C:\Program Files (x86)\Adobe
O43 - CFD: 29/10/2015 - [] D -- C:\Program Files (x86)\Aion RainMeter
O43 - CFD: 26/11/2014 - [] D -- C:\Program Files (x86)\Audacity
O43 - CFD: 18/05/2013 - [] D -- C:\Program Files (x86)\AviSynth 2.5
O43 - CFD: 31/10/2015 - [] D -- C:\Program Files (x86)\BattlePing
O43 - CFD: 14/10/2015 - [] D -- C:\Program Files (x86)\CABAL2 (US)
O43 - CFD: 21/10/2015 - [] D -- C:\Program Files (x86)\Common Files
O43 - CFD: 15/11/2013 - [] D -- C:\Program Files (x86)\Company
O43 - CFD: 20/10/2013 - [] D -- C:\Program Files (x86)\Dxtory Software
O43 - CFD: 30/10/2015 - [] D -- C:\Program Files (x86)\EagleGet
O43 - CFD: 14/11/2013 - [] D -- C:\Program Files (x86)\Gabest
O43 - CFD: 05/08/2015 - [] D -- C:\Program Files (x86)\GameforgeLive
O43 - CFD: 04/08/2015 - [] D -- C:\Program Files (x86)\GIGABYTE
O43 - CFD: 03/06/2015 - [] D -- C:\Program Files (x86)\Google
O43 - CFD: 04/08/2015 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 21/10/2015 - [] D -- C:\Program Files (x86)\Internet Download Manager
O43 - CFD: 12/08/2015 - [] D -- C:\Program Files (x86)\Internet Explorer
O43 - CFD: 21/10/2015 - [] D -- C:\Program Files (x86)\Java
O43 - CFD: 07/05/2013 - [] D -- C:\Program Files (x86)\K-Lite Codec Pack
O43 - CFD: 31/10/2015 - [] D -- C:\Program Files (x86)\Kaspersky Lab
O43 - CFD: 26/11/2014 - [] D -- C:\Program Files (x86)\Lame For Audacity
O43 - CFD: 29/11/2014 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services
O43 - CFD: 05/08/2015 - [] D -- C:\Program Files (x86)\Microsoft ASP.NET
O43 - CFD: 10/10/2015 - [] D -- C:\Program Files (x86)\Microsoft Office
O43 - CFD: 12/08/2015 - [] D -- C:\Program Files (x86)\Microsoft Silverlight
O43 - CFD: 10/10/2015 - [] D -- C:\Program Files (x86)\Microsoft SQL Server
O43 - CFD: 21/10/2013 - [] D -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
O43 - CFD: 10/10/2015 - [] D -- C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 16/10/2015 - [] D -- C:\Program Files (x86)\Mirillis
O43 - CFD: 20/11/2013 - [] D -- C:\Program Files (x86)\MKVToolNix
O43 - CFD: 16/10/2015 - [] D -- C:\Program Files (x86)\mozilla firefox
O43 - CFD: 19/10/2015 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service
O43 - CFD: 10/10/2015 - [] D -- C:\Program Files (x86)\MSBuild
O43 - CFD: 08/04/2015 - [] D -- C:\Program Files (x86)\Norton Identity Safe
O43 - CFD: 04/08/2015 - [] D -- C:\Program Files (x86)\NVIDIA Corporation
O43 - CFD: 14/09/2015 - [] D -- C:\Program Files (x86)\Real
O43 - CFD: 14/09/2015 - [] D -- C:\Program Files (x86)\RealNetworks
O43 - CFD: 17/06/2015 - [] D -- C:\Program Files (x86)\Realtek
O43 - CFD: 05/08/2015 - [] D -- C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 28/03/2013 - [] D -- C:\Program Files (x86)\Renesas Electronics
O43 - CFD: 15/10/2015 - [] RD -- C:\Program Files (x86)\Skype
O43 - CFD: 18/11/2013 - [] D -- C:\Program Files (x86)\TechSmith
O43 - CFD: 05/06/2013 - [] D -- C:\Program Files (x86)\UltraISO
O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files (x86)\Uninstall Information
O43 - CFD: 22/06/2013 - [] D -- C:\Program Files (x86)\Volaro =>Trojan.Vonteera
O43 - CFD: 14/09/2015 - [] D -- C:\Program Files (x86)\WASEL Pro VPN Service
O43 - CFD: 24/09/2015 - [] D -- C:\Program Files (x86)\Win10Pcap
O43 - CFD: 05/08/2015 - [] D -- C:\Program Files (x86)\Windows Defender
O43 - CFD: 21/10/2013 - [] D -- C:\Program Files (x86)\Windows Live
O43 - CFD: 04/08/2015 - [] D -- C:\Program Files (x86)\Windows Mail
O43 - CFD: 05/08/2015 - [] D -- C:\Program Files (x86)\Windows Media Player
O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform
O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Windows NT
O43 - CFD: 05/08/2015 - [] D -- C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 04/08/2015 - [] SHD -- C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 10/07/2015 - [] SD -- C:\Program Files (x86)\WindowsPowerShell
O43 - CFD: 02/06/2013 - [] D -- C:\Program Files (x86)\WinRAR
O43 - CFD: 03/10/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 04/08/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 10/07/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aion RainMeter
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5
O43 - CFD: 31/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BattlePing
O43 - CFD: 04/08/2015 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
O43 - CFD: 30/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EagleGet
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live
O43 - CFD: 24/02/2013 - [0] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGABYTE
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 21/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
O43 - CFD: 21/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
O43 - CFD: 31/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Total Security
O43 - CFD: 10/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico =>HackTool.KMSpico
O43 - CFD: 10/07/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 10/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
O43 - CFD: 15/10/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
O43 - CFD: 12/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mirillis
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy
O43 - CFD: 24/05/2014 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCWest
O43 - CFD: 04/08/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Identity Safe
O43 - CFD: 10/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
O43 - CFD: 14/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Renesas Electronics
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
O43 - CFD: 26/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
O43 - CFD: 04/08/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
O43 - CFD: 10/07/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 10/07/2015 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VobSub
O43 - CFD: 14/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WASEL Pro VPN Service
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 23/12/2013 - [] D -- C:\ProgramData\Adobe
O43 - CFD: 04/08/2015 - [0] D -- C:\ProgramData\AMD
O43 - CFD: 23/01/2015 - [] D -- C:\ProgramData\APN =>Toolbar.Ask
O43 - CFD: 10/07/2015 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 05/05/2013 - [0] D -- C:\ProgramData\Babylon =>PUP.Optional.Babylon
O43 - CFD: 30/10/2015 - [] D -- C:\ProgramData\Baidu
O43 - CFD: 30/10/2015 - [] D -- C:\ProgramData\Baidu Security
O43 - CFD: 03/01/2014 - [] D -- C:\ProgramData\BlueStacksSetup
O43 - CFD: 14/05/2013 - [] HD -- C:\ProgramData\Common Files
O43 - CFD: 10/07/2015 - [0] D -- C:\ProgramData\Comms
O43 - CFD: 10/07/2015 - [0] SHD -- C:\ProgramData\Desktop
O43 - CFD: 10/07/2015 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 23/11/2013 - [] D -- C:\ProgramData\EagleGet
O43 - CFD: 04/08/2015 - [0] SHD -- C:\ProgramData\Favorites
O43 - CFD: 22/10/2014 - [] D -- C:\ProgramData\Glyph
O43 - CFD: 02/03/2013 - [0] D -- C:\ProgramData\IDM
O43 - CFD: 02/06/2013 - [] D -- C:\ProgramData\IObit
O43 - CFD: 31/10/2015 - [] D -- C:\ProgramData\Kaspersky Lab
O43 - CFD: 15/11/2013 - [] D -- C:\ProgramData\MaskMyIP
O43 - CFD: 28/02/2013 - [] D -- C:\ProgramData\McAfee
O43 - CFD: 10/10/2015 - [] SD -- C:\ProgramData\Microsoft
O43 - CFD: 15/10/2015 - [] D -- C:\ProgramData\Microsoft Help
O43 - CFD: 04/08/2015 - [] D -- C:\ProgramData\Microsoft OneDrive
O43 - CFD: 29/09/2014 - [] D -- C:\ProgramData\Mirillis
O43 - CFD: 24/02/2013 - [] D -- C:\ProgramData\Mozilla
O43 - CFD: 17/06/2015 - [] D -- C:\ProgramData\Norton
O43 - CFD: 02/06/2013 - [] D -- C:\ProgramData\NortonInstaller
O43 - CFD: 31/10/2015 - [] D -- C:\ProgramData\NVIDIA
O43 - CFD: 10/10/2015 - [] D -- C:\ProgramData\NVIDIA Corporation
O43 - CFD: 21/10/2015 - [] D -- C:\ProgramData\Oracle
O43 - CFD: 14/09/2015 - [] D -- C:\ProgramData\Package Cache
O43 - CFD: 08/04/2015 - [0] D -- C:\ProgramData\PCSettings
O43 - CFD: 14/09/2015 - [] D -- C:\ProgramData\Real
O43 - CFD: 14/09/2015 - [] D -- C:\ProgramData\RealNetworks
O43 - CFD: 20/12/2013 - [] D -- C:\ProgramData\regid.1986-12.com.adobe
O43 - CFD: 10/10/2015 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft
O43 - CFD: 30/10/2015 - [] D -- C:\ProgramData\Skype
O43 - CFD: 10/07/2015 - [0] D -- C:\ProgramData\SoftwareDistribution
O43 - CFD: 10/07/2015 - [0] SHD -- C:\ProgramData\Start Menu
O43 - CFD: 12/11/2013 - [] D -- C:\ProgramData\Sun
O43 - CFD: 06/02/2015 - [0] D -- C:\ProgramData\Systweak =>PUP.Optional.Systweak
O43 - CFD: 10/11/2013 - [] D -- C:\ProgramData\Tarma Installer =>PUP.Optional.Tarma
O43 - CFD: 18/11/2013 - [] D -- C:\ProgramData\TechSmith
O43 - CFD: 06/11/2014 - [0] AD -- C:\ProgramData\TEMP
O43 - CFD: 10/07/2015 - [0] SHD -- C:\ProgramData\Templates
O43 - CFD: 14/05/2013 - [] D -- C:\ProgramData\TuneUp Software
O43 - CFD: 10/07/2015 - [] D -- C:\ProgramData\USOPrivate
O43 - CFD: 10/07/2015 - [] D -- C:\ProgramData\USOShared
O43 - CFD: 14/05/2013 - [] SHD -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
O43 - CFD: 02/06/2013 - [0] D -- C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
O43 - CFD: 24/12/2013 - [] D -- C:\Program Files (x86)\Common Files\Adobe
O43 - CFD: 30/10/2015 - [] D -- C:\Program Files (x86)\Common Files\EagleGet
O43 - CFD: 05/06/2013 - [] D -- C:\Program Files (x86)\Common Files\EZB Systems
O43 - CFD: 04/08/2015 - [] D -- C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 21/10/2015 - [] D -- C:\Program Files (x86)\Common Files\Java
O43 - CFD: 10/10/2015 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared
O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Common Files\Services
O43 - CFD: 26/08/2015 - [] D -- C:\Program Files (x86)\Common Files\Skype
O43 - CFD: 04/08/2015 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines
O43 - CFD: 02/06/2013 - [] D -- C:\Program Files (x86)\Common Files\Spigot =>PUP.Optional.Dealio
O43 - CFD: 08/04/2015 - [0] D -- C:\Program Files (x86)\Common Files\Symantec Shared
O43 - CFD: 04/08/2015 - [] D -- C:\Program Files (x86)\Common Files\System
O43 - CFD: 21/10/2013 - [] D -- C:\Program Files (x86)\Common Files\Windows Live
O43 - CFD: 20/12/2013 - [] D -- C:\Program Files (x86)\Common Files\xing shared
O43 - CFD: 25/12/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\Adobe
O43 - CFD: 31/10/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\Aion RainMeter
O43 - CFD: 02/06/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\Apple Computer
O43 - CFD: 24/02/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\ATI
O43 - CFD: 10/01/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\Audacity
O43 - CFD: 05/05/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\Babylon =>PUP.Optional.Babylon
O43 - CFD: 31/10/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\baidu
O43 - CFD: 05/06/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\Baidu Security
O43 - CFD: 30/10/2015 - [0] D -- C:\Users\Hasona\AppData\Roaming\BavMini
O43 - CFD: 31/10/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\DMCache
O43 - CFD: 08/03/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\EagleGet
O43 - CFD: 24/12/2013 - [0] D -- C:\Users\Hasona\AppData\Roaming\fltk.org
O43 - CFD: 05/05/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\GoforFiles =>PUP.Optional.YourFileDownloader
O43 - CFD: 03/01/2014 - [] D -- C:\Users\Hasona\AppData\Roaming\gtk-2.0
O43 - CFD: 24/02/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\Identities
O43 - CFD: 21/10/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\IDM
O43 - CFD: 02/06/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\IObit
O43 - CFD: 12/07/2014 - [] D -- C:\Users\Hasona\AppData\Roaming\library_dir
O43 - CFD: 24/02/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\Macromedia
O43 - CFD: 15/11/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\MaskMyIP
O43 - CFD: 14/07/2009 - [0] D -- C:\Users\Hasona\AppData\Roaming\Media Center Programs
O43 - CFD: 05/08/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\Media Player Classic
O43 - CFD: 10/10/2015 - [] SD -- C:\Users\Hasona\AppData\Roaming\Microsoft
O43 - CFD: 29/09/2014 - [] D -- C:\Users\Hasona\AppData\Roaming\Mirillis
O43 - CFD: 20/11/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\mkvtoolnix
O43 - CFD: 05/06/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\MotioninJoy
O43 - CFD: 24/02/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\Mozilla
O43 - CFD: 25/06/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\NetworkTunnel
O43 - CFD: 14/05/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\OpenCandy =>PUP.Optional.OpenCandy
O43 - CFD: 18/04/2014 - [] D -- C:\Users\Hasona\AppData\Roaming\Oracle
O43 - CFD: 14/09/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\Real
O43 - CFD: 14/09/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\RealNetworks
O43 - CFD: 08/04/2015 - [0] D -- C:\Users\Hasona\AppData\Roaming\rmc
O43 - CFD: 12/07/2014 - [] D -- C:\Users\Hasona\AppData\Roaming\rmi
O43 - CFD: 28/11/2014 - [] D -- C:\Users\Hasona\AppData\Roaming\shamela
O43 - CFD: 31/10/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\Skype
O43 - CFD: 30/08/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\Sun
O43 - CFD: 10/09/2014 - [] D -- C:\Users\Hasona\AppData\Roaming\TERA
O43 - CFD: 12/12/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\Thinstall
O43 - CFD: 30/10/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\TS3Client
O43 - CFD: 14/05/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\TuneUp Software
O43 - CFD: 30/10/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\uTorrent
O43 - CFD: 14/05/2013 - [0] D -- C:\Users\Hasona\AppData\Roaming\Winlogon
O43 - CFD: 24/02/2013 - [] D -- C:\Users\Hasona\AppData\Roaming\WinRAR
O43 - CFD: 12/02/2015 - [] SHD -- C:\Users\Hasona\AppData\Roaming\wyUpdate AU
O43 - CFD: 08/08/2013 - [0] D -- C:\Users\Hasona\AppData\Roaming\YourFileDownloader =>PUP.Optional.YourFileDownloader
O43 - CFD: 31/10/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\ZHP
O43 - CFD: 27/05/2015 - [] D -- C:\Users\Hasona\AppData\Local\Adobe
O43 - CFD: 02/02/2014 - [] D -- C:\Users\Hasona\AppData\Local\AionLogAnalyzer
O43 - CFD: 04/08/2015 - [0] SHD -- C:\Users\Hasona\AppData\Local\Application Data
O43 - CFD: 23/11/2013 - [] D -- C:\Users\Hasona\AppData\Local\Apps
O43 - CFD: 24/02/2013 - [] D -- C:\Users\Hasona\AppData\Local\ATI
O43 - CFD: 12/02/2015 - [] D -- C:\Users\Hasona\AppData\Local\BattlePing
O43 - CFD: 17/05/2013 - [] D -- C:\Users\Hasona\AppData\Local\Bundled software uninstaller =>PUP.Optional.MegaSearch
O43 - CFD: 24/02/2013 - [] D -- C:\Users\Hasona\AppData\Local\Chromium
O43 - CFD: 03/09/2015 - [] D -- C:\Users\Hasona\AppData\Local\Comms
O43 - CFD: 04/08/2015 - [0] D -- C:\Users\Hasona\AppData\Local\CrashDumps
O43 - CFD: 14/09/2015 - [] D -- C:\Users\Hasona\AppData\Local\CrashRpt =>.Superfluous.CrashReports
O43 - CFD: 04/07/2015 - [0] D -- C:\Users\Hasona\AppData\Local\Diagnostics
O43 - CFD: 07/07/2014 - [] D -- C:\Users\Hasona\AppData\Local\Downloaded Installations
O43 - CFD: 27/08/2013 - [] D -- C:\Users\Hasona\AppData\Local\Dreambelievers
O43 - CFD: 08/04/2015 - [0] D -- C:\Users\Hasona\AppData\Local\Dxtory Software
O43 - CFD: 11/06/2015 - [0] SHD -- C:\Users\Hasona\AppData\Local\EmieBrowserModeList
O43 - CFD: 11/06/2015 - [0] SHD -- C:\Users\Hasona\AppData\Local\EmieSiteList
O43 - CFD: 11/06/2015 - [0] SHD -- C:\Users\Hasona\AppData\Local\EmieUserList
O43 - CFD: 24/02/2013 - [] D -- C:\Users\Hasona\AppData\Local\Gameforge4d
O43 - CFD: 08/04/2015 - [] D -- C:\Users\Hasona\AppData\Local\Glyph
O43 - CFD: 27/05/2015 - [] D -- C:\Users\Hasona\AppData\Local\Google
O43 - CFD: 01/06/2015 - [] D -- C:\Users\Hasona\AppData\Local\GWX
O43 - CFD: 04/08/2015 - [0] SHD -- C:\Users\Hasona\AppData\Local\History
O43 - CFD: 12/02/2015 - [] SHD -- C:\Users\Hasona\AppData\Local\icsxml
O43 - CFD: 05/07/2013 - [] D -- C:\Users\Hasona\AppData\Local\Lowerping
O43 - CFD: 28/02/2013 - [] D -- C:\Users\Hasona\AppData\Local\Macromedia
O43 - CFD: 10/10/2015 - [] D -- C:\Users\Hasona\AppData\Local\Microsoft
O43 - CFD: 29/11/2014 - [0] D -- C:\Users\Hasona\AppData\Local\Microsoft Help
O43 - CFD: 04/08/2015 - [] D -- C:\Users\Hasona\AppData\Local\MicrosoftEdge
O43 - CFD: 29/09/2014 - [] D -- C:\Users\Hasona\AppData\Local\Mirillis
O43 - CFD: 16/10/2013 - [] D -- C:\Users\Hasona\AppData\Local\Mozilla
O43 - CFD: 12/02/2015 - [] SHD -- C:\Users\Hasona\AppData\Local\ms-drivers
O43 - CFD: 04/02/2014 - [] D -- C:\Users\Hasona\AppData\Local\Not_Aion_Launcher
O43 - CFD: 20/12/2013 - [] D -- C:\Users\Hasona\AppData\Local\NPE
O43 - CFD: 10/10/2015 - [] D -- C:\Users\Hasona\AppData\Local\NVIDIA
O43 - CFD: 04/08/2015 - [] D -- C:\Users\Hasona\AppData\Local\NVIDIA Corporation
O43 - CFD: 16/09/2015 - [] D -- C:\Users\Hasona\AppData\Local\Packages
O43 - CFD: 04/08/2015 - [0] D -- C:\Users\Hasona\AppData\Local\PeerDistRepub
O43 - CFD: 24/02/2013 - [] D -- C:\Users\Hasona\AppData\Local\Programs
O43 - CFD: 04/08/2015 - [] D -- C:\Users\Hasona\AppData\Local\Publishers
O43 - CFD: 25/06/2015 - [] D -- C:\Users\Hasona\AppData\Local\Real
O43 - CFD: 10/03/2014 - [] D -- C:\Users\Hasona\AppData\Local\Skype
O43 - CFD: 12/03/2013 - [] D -- C:\Users\Hasona\AppData\Local\TechSmith
O43 - CFD: 31/10/2015 - [] D -- C:\Users\Hasona\AppData\Local\Temp
O43 - CFD: 04/08/2015 - [0] SHD -- C:\Users\Hasona\AppData\Local\Temporary Internet Files
O43 - CFD: 12/12/2013 - [] D -- C:\Users\Hasona\AppData\Local\Thinstall
O43 - CFD: 04/08/2015 - [] D -- C:\Users\Hasona\AppData\Local\TileDataLayer
O43 - CFD: 24/12/2013 - [] D -- C:\Users\Hasona\AppData\Local\VirtualStore
O43 - CFD: 08/06/2014 - [] D -- C:\Users\Hasona\AppData\Local\Windows Live
O43 - CFD: 10/07/2015 - [] RD -- C:\Users\Hasona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 04/08/2015 - [] RD -- C:\Users\Hasona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 19/10/2015 - [] RD -- C:\Users\Hasona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 14/05/2013 - [0] D -- C:\Users\Hasona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5
O43 - CFD: 04/08/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CABAL2 (US)
O43 - CFD: 04/08/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 21/10/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
O43 - CFD: 04/08/2015 - [0] D -- C:\Users\Hasona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lowerping
O43 - CFD: 10/07/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 04/08/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
O43 - CFD: 19/10/2015 - [] RD -- C:\Users\Hasona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 10/07/2015 - [] RD -- C:\Users\Hasona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 14/11/2013 - [0] D -- C:\Users\Hasona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VobSub
O43 - CFD: 10/07/2015 - [] RSD -- C:\Users\Hasona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
O43 - CFD: 04/08/2015 - [] D -- C:\Users\Hasona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR

---\\ Latest files created in Prefetcher (2) - 9s
O45 - LFCP:[MD5.243F04D42DC01D6A38BA37F9CF65756B] 10/10/2015 A -- C:\WINDOWS\Prefetch\KMSPICO.TMP-7305DE6E.pf =>HackTool.KMSpico
O45 - LFCP:[MD5.7F259C32C397BC431F1C48894F61F62E] 10/10/2015 A -- C:\WINDOWS\Prefetch\KMSPICO.TMP-D626255E.pf =>HackTool.KMSpico

---\\ ShellIconOverlayIdentifiers (SIOI) (13) - 0s
O106 - SIOI: ErrorOverlayHandler Class [ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Hasona\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll ©
O106 - SIOI: SharedOverlayHandler Class [ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Hasona\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll ©
O106 - SIOI: SharedSyncingOverlayHandler Class [ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Hasona\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll ©
O106 - SIOI: UpToDateOverlayHandler Class [ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Hasona\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll ©
O106 - SIOI: SyncingOverlayHandler Class [ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Hasona\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll ©
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) [ SkyDrivePro1 (ErrorConflict)] - {8BA85C75-763B-4103-94EB-9470F12FE0F7}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL ©
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) [ SkyDrivePro2 (SyncInProgress)] - {CD55129A-B1A1-438E-A425-CEBC7DC684EE}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL ©
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 3 (InSync) [ SkyDrivePro3 (InSync)] - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL ©
O106 - SIOI: Groove Explorer Icon Overlay 1 (GFS Unread Stub) [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] - {99FD978C-D287-4F50-827F-B2C658EDA8E7}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL ©
O106 - SIOI: Groove Explorer Icon Overlay 2 (GFS Stub) [Groove Explorer Icon Overlay 2 (GFS Stub)] - {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL ©
O106 - SIOI: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] - {920E6DB1-9907-4370-B3A0-BAFC03D81399}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL ©
O106 - SIOI: Groove Explorer Icon Overlay 3 (GFS Folder) [Groove Explorer Icon Overlay 3 (GFS Folder)] - {16F3DD56-1AF5-4347-846D-7C10C4192619}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL ©
O106 - SIOI: Groove Explorer Icon Overlay 4 (GFS Unread Mark) [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] - {2916C86E-86A6-43FE-8112-43ABE6BF8DCC}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL ©

---\\ System Drivers List (72) - 25s
O58 - SDL:2015/07/10 13:59:38 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107360] ©
O58 - SDL:2015/07/10 13:59:38 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135456] ©
O58 - SDL:2014/10/28 02:46:12 A . (.Advanced Micro Devices, Inc. - AMD PCI Root Bus Lower Filter.) -- C:\WINDOWS\System32\drivers\amdkmpfd.sys [62152] ©
O58 - SDL:2015/07/10 13:59:38 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [83296] ©
O58 - SDL:2015/07/10 13:59:38 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259424] ©
O58 - SDL:2015/07/10 13:59:38 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [26976] ©
O58 - SDL:2015/07/10 13:59:38 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [131936] ©
O58 - SDL:2014/12/21 06:37:40 A . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) -- C:\WINDOWS\System32\drivers\AtihdW76.sys [94720] ©
O58 - SDL:2015/07/10 13:59:38 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [17624] ©
O58 - SDL:2015/07/10 13:59:38 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [531296] ©
O58 - SDL:2015/07/06 00:10:20 A . (.Kaspersky Lab ZAO - Cryptographic Module Driver x64 (Weak).) -- C:\WINDOWS\System32\drivers\cm_km.sys [389816] ©
O58 - SDL:2015/08/01 20:55:52 A . (.eagleGet - eagleGet Network Filter.) -- C:\WINDOWS\System32\drivers\eagleGet.sys [77624] ©
O58 - SDL:2015/07/10 13:59:38 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3436896] ©
O58 - SDL:2015/07/10 13:59:38 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64352] ©
O58 - SDL:2013/10/16 04:42:02 A . (.AnchorFree Inc. - Hotspot Shield Routing Driver.) -- C:\WINDOWS\System32\drivers\hssdrv6.sys [44744] ©
O58 - SDL:2015/07/10 13:59:36 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] ©
O58 - SDL:2015/07/10 13:59:36 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [122608] ©
O58 - SDL:2015/07/10 13:59:38 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [673120] ©
O58 - SDL:2015/07/10 13:59:38 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412000] ©
O58 - SDL:2015/07/10 13:59:39 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [424800] ©
O58 - SDL:2015/06/12 05:00:58 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\WINDOWS\System32\drivers\idmwfp.sys [197616] ©
O58 - SDL:2015/06/22 20:40:04 A . (.Kaspersky Lab ZAO - Kaspersky Unified Driver.) -- C:\WINDOWS\System32\drivers\kl1.sys [478392] ©
O58 - SDL:2015/06/06 08:48:24 A . (.Kaspersky Lab ZAO - Backup Disk Filter [fre_wnet_x64].) -- C:\WINDOWS\System32\drivers\klbackupdisk.sys [53432] ©
O58 - SDL:2015/06/27 01:30:00 A . (.Kaspersky Lab ZAO - Backup File Filter [fre_win8_x64].) -- C:\WINDOWS\System32\drivers\klbackupflt.sys [70512] ©
O58 - SDL:2015/06/06 08:51:00 A . (.Kaspersky Lab ZAO - Virtual Disk [fre_wnet_x64].) -- C:\WINDOWS\System32\drivers\kldisk.sys [68280] ©
O58 - SDL:2015/06/24 01:28:32 A . (.Kaspersky Lab - Klelam Mini-Filter [fre_win8_x64].) -- C:\WINDOWS\System32\drivers\klelam.sys [30328] ©
O58 - SDL:2015/10/31 21:53:49 A . (.AO Kaspersky Lab - Filter Core [fre_win8_x64].) -- C:\WINDOWS\System32\drivers\klflt.sys [181640]
O58 - SDL:2015/10/31 21:05:09 A . (.AO Kaspersky Lab - klhk [fre_win8_x64].) -- C:\WINDOWS\System32\drivers\klhk.sys [227512]
O58 - SDL:2015/10/31 21:53:50 A . (.AO Kaspersky Lab - Core System Interceptors [fre_win8_x64].) -- C:\WINDOWS\System32\drivers\klif.sys [925064]
O58 - SDL:2015/06/11 19:35:38 A . (.Kaspersky Lab ZAO - Kaspersky Lab Intermediate Network Driver [.) -- C:\WINDOWS\System32\drivers\klim6.sys [39608] ©
O58 - SDL:2015/06/06 08:31:42 A . (.Kaspersky Lab ZAO - Keyboard Device Filter [fre_win8_x64].) -- C:\WINDOWS\System32\drivers\klkbdflt.sys [41656] ©
O58 - SDL:2015/06/07 01:52:56 A . (.Kaspersky Lab ZAO - Mouse Device Filter [fre_win8_x64].) -- C:\WINDOWS\System32\drivers\klmouflt.sys [41656] ©
O58 - SDL:2015/10/31 21:53:50 A . (.AO Kaspersky Lab - Format Recognizer [fre_wnet_x64].) -- C:\WINDOWS\System32\drivers\klpd.sys [41352]
O58 - SDL:2015/10/31 21:53:50 A . (.Kaspersky Lab ZAO - Network filtering component [fre_win8_x64].) -- C:\WINDOWS\System32\drivers\klwfp.sys [87944] ©
O58 - SDL:2015/06/16 21:56:32 A . (.Kaspersky Lab ZAO - WFP Network Connection Filter Driver [fre_w.) -- C:\WINDOWS\System32\drivers\klwtp.sys [102584] ©
O58 - SDL:2015/06/23 18:30:50 A . (.Kaspersky Lab ZAO - Network Processor [fre_wnet_x64].) -- C:\WINDOWS\System32\drivers\kneps.sys [187056] ©
O58 - SDL:2015/07/10 13:59:38 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [108896] ©
O58 - SDL:2015/07/10 13:59:38 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [104800] ©
O58 - SDL:2015/07/10 13:59:38 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [99168] ©
O58 - SDL:2015/07/10 13:59:38 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82784] ©
O58 - SDL:2015/07/10 13:59:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59744] ©
O58 - SDL:2015/07/10 13:59:39 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575840] ©
O58 - SDL:2015/07/10 13:59:39 A . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [705376] ©
O58 - SDL:2015/07/10 13:59:39 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63840] ©
O58 - SDL:2015/07/10 13:59:39 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [76128] ©
O58 - SDL:2013/03/01 04:49:12 A . (.Riverbed Technology, Inc. - npf.sys (NT5/6 AMD64) Kernel Driver.) -- C:\WINDOWS\System32\drivers\npf.sys [36600] ©
O58 - SDL:2015/07/25 03:14:14 A . (.NVIDIA Corporation - NVIDIA HDMI Audio Driver.) -- C:\WINDOWS\System32\drivers\nvhda64v.sys [204648] ©
O58 - SDL:2015/10/06 21:45:58 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\WINDOWS\System32\drivers\nvlddmkm.sys [11210056] ©
O58 - SDL:2015/07/10 13:59:39 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150368] ©
O58 - SDL:2015/07/10 13:59:39 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [166240] ©
O58 - SDL:2015/08/11 07:52:30 A . (.NVIDIA Corporation - NVIDIA Virtual Audio Driver.) -- C:\WINDOWS\System32\drivers\nvvad64v.sys [50472] ©
O58 - SDL:2015/07/10 13:59:39 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [58208] ©
O58 - SDL:2015/07/10 13:59:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [58720] ©
O58 - SDL:2015/07/10 13:59:39 A . (.Realtek - Realtek 8136/8168/8169 NDIS 6.40 64-bit Dri.) -- C:\WINDOWS\System32\drivers\rt640x64.sys [587264] ©
O58 - SDL:2015/06/24 22:57:00 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\WINDOWS\System32\drivers\RTKVHD64.sys [4504320] ©
O58 - SDL:2015/07/10 13:59:39 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44896] ©
O58 - SDL:2015/07/10 13:59:39 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81760] ©
O58 - SDL:2010/11/26 18:02:18 A . (...) -- C:\WINDOWS\System32\drivers\SmartDefragDriver.sys [17720]
O58 - SDL:2014/01/22 08:52:10 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ve.) -- C:\WINDOWS\System32\drivers\ssudbus.sys [108800] ©
O58 - SDL:2014/01/22 08:52:10 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ve.) -- C:\WINDOWS\System32\drivers\ssudmdm.sys [206080] ©
O58 - SDL:2015/07/10 13:59:39 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31072] ©
O58 - SDL:2015/07/31 13:23:59 A . (.Symantec Corporation - Symantec Event Library.) -- C:\WINDOWS\System32\drivers\SYMEVENT64x86.SYS [111344] ©
O58 - SDL:2012/06/28 10:49:50 A . (.The OpenVPN Project - TAP-Win32 Virtual Network Driver.) -- C:\WINDOWS\System32\drivers\tap0901.sys [31232] ©
O58 - SDL:2012/03/16 00:26:18 A . (.AnchorFree Inc - TAP-Win32 Virtual Network Driver.) -- C:\WINDOWS\System32\drivers\taphss.sys [37888]
O58 - SDL:2014/05/17 03:42:38 A . (.Anchorfree Inc. - Anchorfree HSS VPN Adapter.) -- C:\WINDOWS\System32\drivers\taphss6.sys [42184] ©
O58 - SDL:2015/07/10 13:59:48 A . (...) -- C:\WINDOWS\System32\drivers\Udecx.sys [44032]
O58 - SDL:2015/07/10 13:59:39 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166752] ©
O58 - SDL:2015/07/10 13:59:39 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305504] ©
O58 - SDL:2015/06/10 12:06:18 A . (.Daiyuu Nobori, University of Tsukuba, Japan - Win10Pcap.sys.) -- C:\WINDOWS\System32\drivers\Win10Pcap.sys [50264]
O58 - SDL:2015/07/10 13:59:39 A . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [26976] ©
O58 - SDL:2015/07/10 13:59:39 A . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [59232] ©
O58 - SDL:2014/05/22 18:22:36 A . (...) -- C:\WINDOWS\System32\drivers\{587cb346-a3d8-4884-b39b-f0ed918b6f96}Gw64.sys [9264] =>PUP.Optional.LinkiDoo

---\\ Last modified or created user files (7) - 17s
O61 - LFC: 2015/10/31 21:32:11 A . (.BattlePing.) -- C:\Users\Hasona\Desktop\BattlePing1.3.6.7.exe [5384166]
O61 - LFC: 2015/10/30 18:24:58 A . (..) -- C:\Users\Hasona\AppData\Roaming\Mirillis\Action\back.bin [20]
O61 - LFC: 2015/10/29 18:51:14 A . (..) -- C:\Users\Hasona\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\UrlBlock\urlblock_635816371674991374.bin [47292]
O61 - LFC: 2015/10/28 07:01:44 A . (..) -- C:\Users\Hasona\AppData\Local\NVIDIA\NvBackend\UMDShim\nvcoproc.bin [6027430]
O61 - LFC: 2015/10/29 21:03:11 A . (..) -- C:\Users\Hasona\AppData\Local\NVIDIA\NvBackend\Packages\000081f1\DAO.20116488.exe [6729440]
O61 - LFC: 2015/10/28 21:01:47 A . (..) -- C:\Users\Hasona\AppData\Local\NVIDIA\NvBackend\Packages\000081d0\CoProc update.20110886.exe [592800]
O61 - LFC: 2015/10/31 20:28:15 A . (..) -- C:\Users\Hasona\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [1113849]

---\\ File Associations Shell Spawning (11) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe ©
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe ©
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ©
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe ©
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe ©
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\program files (x86)\mozilla firefox\firefox.exe ©

---\\ Start Menu Internet (12) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\program files (x86)\mozilla firefox\firefox.exe ©
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\program files (x86)\mozilla firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - ‎‎الأداة المساعدة للتهيئة لكل مستخدم لـ IE.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\program files (x86)\mozilla firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - ‎‎الأداة المساعدة للتهيئة لكل مستخدم لـ IE.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\program files (x86)\mozilla firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - ‎‎الأداة المساعدة للتهيئة لكل مستخدم لـ IE.) -- C:\Windows\System32\ie4uinit.exe ©

---\\ Search Browser Infection (27) - 4s
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.admin", false); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.aflt", "babsst"); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.autoRvrt", "false"); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.dfltLng", "ar"); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.excTlbr", false); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.ffxUnstlRst", true); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.id", "7461b8b500000000000000ff4d58fe31"); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.instlDay", "15924"); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.instlRef", "sst"); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.newTab", false); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.prdct", "delta"); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.prtnrId", "delta"); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.rvrt", "false"); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.smplGrp", "none"); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.tlbrId", "base"); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.tlbrSrchUrl", ""); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.vrsn", "1.8.22.0"); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.vrsnTs", "1.8.22.01:28:33"); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta.vrsni", "1.8.22.0"); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta_i.babExt", ""); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta_i.babTrack", "affID=120007&tsp=4967"); =>Toolbar.DeltaSearch
O69 - SBI: prefs.js [Hasona - 7yaf5eqd.default] user_pref("extensions.delta_i.srcExt", "ss"); =>Toolbar.DeltaSearch
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com/
O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} - (Delta Search) - http://www1.delta-search.com/ =>Toolbar.DeltaSearch
O69 - SBI: SearchScopes [HKCU] {756D1D40-E491-4E1D-9BC6-5B37CEDE646E} - (VenteeRo) - http://www.arabyonline.com/ =>Trojan.Vonteera
O69 - SBI: SearchScopes [HKCU] {77645FE3-1D94-4552-BA3A-086A37D89379} [DefaultScope] - (Yahoo! Search) - http://search.yahoo.com/

---\\ Search Svchost Services (42) - 1s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - خدمة نشر شهادة البطاقة الذكية لـ Microsoft.) -- C:\WINDOWS\System32\certprop.dll [192000] ©
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - خدمة نشر شهادة البطاقة الذكية لـ Microsoft.) -- C:\Windows\System32\certprop.dll [192000] ©
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\Windows\System32\srvsvc.dll [283136] ©
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - عميل نهج المجموعة.) -- C:\Windows\System32\gpsvc.dll [1335296] ©
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\IKEEXT.DLL [954368] ©
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [954880] ©
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي الخاصة بخدمة تسجي.) -- C:\Windows\System32\seclogon.dll [31232] ©
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\Windows\System32\appinfo.dll [93696] ©
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\Windows\System32\iscsiexe.dll [151040] ©
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [106496] ©
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - خدمة جدولة المهام.) -- C:\Windows\System32\schedsvc.dll [1008640] ©
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [226304] ©
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\Windows\System32\browser.dll [133120] ©
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [324608] ©
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [371200] ©
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - تقارير المشاكل وحلولها.) -- C:\Windows\System32\wercplsupport.dll [95744] ©
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Microsoft® Account Service.) -- C:\Windows\System32\wlidsvc.dll [2093056] ©
O83 - Search Svchost Services: DcpSvc (DcpSvc) . (.Microsoft Corporation - dcpsvc Task.) -- C:\Windows\System32\dcpsvc.dll [196096] ©
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Microsoft Network Connectivity Assistant Se.) -- C:\Windows\System32\NcaSvc.dll [167424] ©
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Network Setup Service.) -- C:\Windows\System32\NetSetupSvc.dll [187392] ©
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\Windows\System32\rasauto.dll [106496] ©
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [679936] ©
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [497152] ©
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\Windows\System32\Sens.dll [72192] ©
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [452608] ©
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [311808] ©
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - عامل Windows Update.) -- C:\Windows\System32\wuaueng.dll [2236416] ©
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\Windows\System32\qmgr.dll [1168896] ©
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمات Windows Sh.) -- C:\Windows\System32\shsvcs.dll [593920] ©
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\Windows\System32\dmwappushsvc.dll [63488] ©
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\Windows\System32\XblGameSave.dll [1149440] ©
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\Windows\System32\XboxNetApiSvc.dll [1019392] ©
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Update Session Orchestrator Core.) -- C:\Windows\System32\usocore.dll [343040] ©
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\Windows\System32\usermgr.dll [713216] ©
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Geolocation Service.) -- C:\Windows\System32\lfsvc.dll [27136] ©
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - Windows Managent Service DLL.) -- C:\Windows\System32\Windows.Internal.Management.dll [267776] ©
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\Windows\System32\XblAuthManager.dll [918016] ©
O83 - Search Svchost Services: RetailDemo (RetailDemo) . (.Microsoft Corporation - RDXService.) -- C:\Windows\System32\RDXService.dll [1010176] ©
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\Windows\System32\bdesvc.dll [359936] ©
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Device Setup Manager.) -- C:\Windows\System32\DeviceSetupManager.dll [237568] ©
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\Windows\System32\themeservice.dll [58368] ©
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - خدمة تثبت البرامج.) -- C:\Windows\System32\appmgmts.dll [200192] ©

---\\ Firewall Active Exception List (15) - 6s
O87 - FAEL: "{62D3A316-0A21-40F0-87AD-7712936158C1}" [In-None-P6-TRUE] .(...) -- E:\GameforgeLive\gfl_client.exe
O87 - FAEL: "{548DA363-8A43-4571-8269-AED08264BC10}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE (.not file.)
O87 - FAEL: "{3369DA56-D724-4D8F-9C9E-EF7F4A5D389D}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE (.not file.)
O87 - FAEL: "{BB64CE4F-ABD1-4429-99B7-5A90770F7BC3}" [In-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Hasona\AppData\Roaming\uTorrent\uTorrent.exe
O87 - FAEL: "{E8992157-4784-468A-AAB2-0548A7A25812}" [In-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Hasona\AppData\Roaming\uTorrent\uTorrent.exe
O87 - FAEL: "UDP Query User{55CF05F1-BCA3-41BE-B499-8D1CD2FEB58E}C:\program files (x86)\eagleget\eagleget.exe" [In-None-P17-TRUE] .(.EagleGet.com - EagleGet Free Downloader.) -- C:\program files (x86)\eagleget\eagleget.exe
O87 - FAEL: "TCP Query User{6DB89257-4670-4250-9592-FB2C6EC8CC9A}C:\program files (x86)\eagleget\eagleget.exe" [In-None-P6-TRUE] .(.EagleGet.com - EagleGet Free Downloader.) -- C:\program files (x86)\eagleget\eagleget.exe
O87 - FAEL: "UDP Query User{79971CFA-4C6B-4992-B056-FB13A2CBEFD9}C:\program files (x86)\gameforgelive\games\gbr_eng\aion\nclauncher.exe" [In-None-P17-TRUE] .(.NCSOFT Corporation - NCLauncher Module.) -- C:\program files (x86)\gameforgelive\games\gbr_eng\aion\nclauncher.exe
O87 - FAEL: "TCP Query User{2F90135B-8AC8-4004-A642-C78648475604}C:\program files (x86)\gameforgelive\games\gbr_eng\aion\nclauncher.exe" [In-None-P6-TRUE] .(.NCSOFT Corporation - NCLauncher Module.) -- C:\program files (x86)\gameforgelive\games\gbr_eng\aion\nclauncher.exe
O87 - FAEL: "{D696389C-406C-4630-AABE-6C7EA2343D76}" [In-None-P6-TRUE] .(.@ByELDI - KMS GUI ELDI.) -- C:\Program Files\KMSpico\KMSELDI.exe =>HackTool.KMSpico
O87 - FAEL: "{24FF6B93-AF59-48CE-A8F6-9974180A4748}" [In-None-P17-TRUE] .(.@ByELDI - KMS GUI ELDI.) -- C:\Program Files\KMSpico\KMSELDI.exe =>HackTool.KMSpico
O87 - FAEL: "{B02AC806-1E09-4B30-B6A6-4F3DCBA6C58C}" [In-None-P6-TRUE] .(...) -- C:\Program Files\KMSpico\AutoPico.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{2C04F117-ECB2-4608-8B42-082961A65C63}" [In-None-P17-TRUE] .(...) -- C:\Program Files\KMSpico\AutoPico.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{D140B3F4-DED2-4A6A-A78D-75C72039E02A}" [In-None-P6-TRUE] .(...) -- C:\Program Files\KMSpico\Service_KMS.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{292CC3C6-77A3-48CA-A023-F0AA459B1393}" [In-None-P17-TRUE] .(...) -- C:\Program Files\KMSpico\Service_KMS.exe (.not file.) =>HackTool.KMSpico

---\\ Services not Microsoft (SR=Run, SS=Stop) (19) - 30s

SR - Auto [14/08/2012] [ 63960] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe ©
SS - Demand [17/10/2015] [ 269000] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ©
SR - Auto [31/10/2015] [ 194000] Kaspersky Anti-Virus Service 16.0.0 (AVP16.0.0) . (.Kaspersky Lab ZAO.) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 16.0.0\avp.exe ©
SS - Auto [24/10/2015] [ 236544] egGetSvc (egGetSvc) . (.Copyright (C) EagleGet 2014~2015.) - C:\Program Files (x86)\EagleGet\EGMonitor.exe
SR - Auto [12/10/2015] [ 1156384] NVIDIA GeForce Experience Service (GfExperienceService) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe ©
SS - Auto [29/08/2015] [ 144200] خدمة Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ©
SS - Demand [29/08/2015] [ 144200] خدمة Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ©
SS - Demand [14/11/2005] [ 69632] InstallDriver Table Manager (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe ©
SS - Demand [16/10/2015] [ 147624] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe ©
SS - Auto [05/03/2015] [ 131144] Norton Identity Safe (NCO) . (.Symantec Corporation.) - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\NST.exe ©
SR - Auto [12/10/2015] [ 1873696] NVIDIA Network Service (NvNetworkService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe ©
SS - Auto [12/10/2015] [ 5568288] NVIDIA Streamer Service (NvStreamSvc) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe ©
SR - Auto [03/10/2015] [ 938800] NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\System32\nvvsvc.exe ©
SR - Auto [27/07/2015] [ 32880] RealPlayer Update Service (RealPlayerUpdateSvc) . (...) - C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
SR - Auto [14/09/2015] [ 1115736] RealTimes Desktop Service (RealTimes Desktop Service) . (.RealNetworks, Inc..) - c:\program files (x86)\Real\realplayer\RPDS\Bin\rpdsvc.exe ©
SS - Auto [09/07/2015] [ 327296] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe ©
SR - Auto [03/10/2015] [ 417400] NVIDIA Stereoscopic 3D Driver Service (Stereo Service) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe ©
SS - Demand [09/07/2015] [ 144640] vssbrigde64 (vssbrigde64) . (.AO Kaspersky Lab.) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 16.0.0\x64\vssbridge64.exe

---\\ Additional Scan (O88) (40) - 0s
C:\Users\Hasona\AppData\Roaming\Mozilla\Firefox\Profiles\7yaf5eqd.default\searchplugins\babylon.xml =>PUP.Optional.Babylon
C:\Program Files (x86)\Volaro\Updater\Updater.exe =>Trojan.Vonteera
C:\WINDOWS\System32\Tasks\GoforFilesUpdate =>PUP.Optional.YourFileDownloader
C:\WINDOWS\System32\Tasks\Volaro Update =>Trojan.Vonteera
C:\WINDOWS\System32\Tasks\YourFile DownloaderUpdate =>PUP.Optional.YourFileDownloader
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KMSpico_is1 =>HackTool.KMSpico
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Volaro Updater =>Trojan.Vonteera
HKLM\SOFTWARE\Wow6432Node\DataMngr =>PUP.Optional.Datamngr
HKLM\SOFTWARE\Wow6432Node\Delta =>Toolbar.DeltaSearch
HKLM\SOFTWARE\Wow6432Node\Systweak =>PUP.Optional.Systweak
HKLM\SOFTWARE\Wow6432Node\Uniblue =>.Superfluous.Uniblue
HKLM\SOFTWARE\Wow6432Node\Volaro Updater =>Trojan.Vonteera
HKLM\SOFTWARE\Wow6432Node\YourFileDownloader =>PUP.Optional.YourFileDownloader
HKCU\SOFTWARE\014ef4f712d39e082790d249eb634c4e =>PUP.Optional.CrossRider
HKCU\SOFTWARE\BI =>PUP.Optional.MegaSearch
HKCU\SOFTWARE\Conduit =>PUP.Optional.Conduit
HKCU\SOFTWARE\DataMngr =>PUP.Optional.Datamngr
HKCU\SOFTWARE\Delta =>Toolbar.DeltaSearch
HKCU\SOFTWARE\Softonic =>PUP.Optional.Softonic
HKCU\SOFTWARE\Volaro =>Trojan.Vonteera
HKCU\SOFTWARE\YourFileDownloader =>PUP.Optional.YourFileDownloader
HKCU\SOFTWARE\AppDataLow\Software\Conduit =>PUP.Optional.Conduit
HKCU\SOFTWARE\AppDataLow\Software\Search Settings =>PUP.Optional.SearchSettings
C:\Program Files (x86)\Volaro =>Trojan.Vonteera
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico =>HackTool.KMSpico
C:\ProgramData\APN =>Toolbar.Ask
C:\ProgramData\Babylon =>PUP.Optional.Babylon
C:\ProgramData\Systweak =>PUP.Optional.Systweak
C:\ProgramData\Tarma Installer =>PUP.Optional.Tarma
C:\Program Files (x86)\Common Files\Spigot =>PUP.Optional.Dealio
C:\Users\Hasona\AppData\Roaming\Babylon =>PUP.Optional.Babylon
C:\Users\Hasona\AppData\Roaming\GoforFiles =>PUP.Optional.YourFileDownloader
C:\Users\Hasona\AppData\Roaming\OpenCandy =>PUP.Optional.OpenCandy
C:\Users\Hasona\AppData\Roaming\YourFileDownloader =>PUP.Optional.YourFileDownloader
C:\Users\Hasona\AppData\Local\Bundled software uninstaller =>PUP.Optional.MegaSearch
C:\Users\Hasona\AppData\Local\CrashRpt =>.Superfluous.CrashReports
C:\WINDOWS\Prefetch\KMSPICO.TMP-7305DE6E.pf =>HackTool.KMSpico
C:\WINDOWS\Prefetch\KMSPICO.TMP-D626255E.pf =>HackTool.KMSpico
C:\WINDOWS\System32\drivers\{587cb346-a3d8-4884-b39b-f0ed918b6f96}Gw64.sys =>PUP.Optional.LinkiDoo
C:\Program Files\KMSpico\KMSELDI.exe =>HackTool.KMSpico

---\\ Summary of the elements found (20) - 0s
http://www.nicolascoolman.fr/pup-babylon/ =>PUP.Optional.Babylon
http://www.nicolascoolman.fr/pup-kmspico/ =>HackTool.KMSpico
http://www.nicolascoolman.fr/pup-yourfiledownloader/ =>PUP.Optional.YourFileDownloader
http://www.nicolascoolman.fr/trojan-vonteera/ =>Trojan.Vonteera
http://www.nicolascoolman.fr/blog =>PUP.Optional.AdvancedFileOptimizer
http://www.nicolascoolman.fr/pup-datamngr/ =>PUP.Optional.Datamngr
http://www.nicolascoolman.fr/toolbar-deltasearch/ =>Toolbar.DeltaSearch
http://www.nicolascoolman.fr/pup-systweak/ =>PUP.Optional.Systweak
http://www.nicolascoolman.fr/blog =>.Superfluous.Uniblue
http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider
http://www.nicolascoolman.fr/adware-megasearch/ =>PUP.Optional.MegaSearch
http://www.nicolascoolman.fr/toolbar-conduit/ =>PUP.Optional.Conduit
http://www.nicolascoolman.fr/blog =>PUP.Optional.Softonic
http://www.nicolascoolman.fr/adware-searchsettings/ =>PUP.Optional.SearchSettings
http://www.nicolascoolman.fr/toolbar-ask/ =>Toolbar.Ask
http://www.nicolascoolman.fr/pup-tarma/ =>PUP.Optional.Tarma
http://www.nicolascoolman.fr/pup-dealio/ =>PUP.Optional.Dealio
http://www.nicolascoolman.fr/adware-opencandy/ =>PUP.Optional.OpenCandy
http://www.nicolascoolman.fr/blog =>.Superfluous.CrashReports
http://www.nicolascoolman.fr/pup-linkidoo/ =>PUP.Optional.LinkiDoo

~ End of the scan, 69135 items in 2146 seconds (1088)(0)

Publicité


Signaler le contenu de ce document

Publicité