cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2016.6.14.104 By Nicolas Coolman (2016/06/10)
~ Run by salamouna2 (Administrator) (2016/06/29 16:18:35)
~ Web: http://www.nicolascoolman.com
~ Facebook: https://www.facebook.com/nicolascoolman1
~ State version:
~ Mode: Scan
~ Report: C:\Users\salamouna2\Desktop\ZHPDiag.txt
~ Report: C:\Users\salamouna2\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ System startup: Normal (Normal boot)
Windows 10 Home, 64-bit (Build 10586)

---\\ Internet Browsers (3) - 0s
GCIE: Google Chrome v53.0.2774.3
MFIE: Mozilla Firefox 47.0 (x86 en-US)
MSIE: Internet Explorer v11.212.10586.0

---\\ Windows Product Information (3) - 3s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : KO

---\\ System protection software (2) - 3s
Malwarebytes Anti-Malware version 2.2.1.1043
Windows Defender (Deactivate)

---\\ Sharing software PeerToPeer (1) - 3s
µTorrent v3.2.2.28500

---\\ Information on the system (6) - 0s
~ Operating System: Intel64 Family 6 Model 61 Stepping 4, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 8285.544 MB (79% free)
System Restore: Activé (Enable)
System drive C: has 188 GB () free of 353 GB

---\\ Connection to the system mode (3) - 0s
~ Computer Name: SALAMOUNA
~ User Name: salamouna2
~ Logged in as Administrator

---\\ Enumeration of the disk units (3) - 0s
~ Drive C: has 188 GB free of 353 GB (System)
~ Drive E: has 396 GB free of 599 GB
~ Drive F: has 30 GB free of 30 GB

---\\ State of the Windows Security Center (7) - 0s
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Search Generic System Files (24) - 2s
[MD5.95D730526EF81792CD6848D8D10FAA1C] - 29/01/2016 - (.Microsoft Corporation - Windows Explorer.) -- C:\WINDOWS\Explorer.exe [4502352] =>.Microsoft Windows®
[MD5.0DCB89B1F3689BC6262FF30BBD603171] - 30/10/2015 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\WINDOWS\System32\rundll32.exe [59392] =>.Microsoft Corporation
[MD5.CAD491DD9EC00BB841EA407D9C498C4A] - 30/10/2015 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\WINDOWS\System32\Wininit.exe [290856] =>.Microsoft Windows Publisher®
[MD5.AE6A68A065D4C26AF4BEFAA53623B266] - 29/03/2016 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\WINDOWS\System32\wininet.dll [2755584] =>.Microsoft Corporation
[MD5.7B24B823404D53DA4748F21AD2BF04C9] - 05/01/2016 - (.Microsoft Corporation - Windows Logon Application.) -- C:\WINDOWS\System32\Winlogon.exe [584704] =>.Microsoft Corporation
[MD5.9EEAA1B69DC3FD620AE576CC8F4147DC] - 30/10/2015 - (.Microsoft Corporation - Software Licensing Library.) -- C:\WINDOWS\System32\sppcomapi.dll [430592] =>.Microsoft Corporation
[MD5.9A3E17CDB177913C2A111C80F3D0DBB4] - 29/03/2016 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\WINDOWS\System32\dnsapi.dll [686976] =>.Microsoft Windows®
[MD5.6A7ACABAE92C837F5C1330188EAE36AE] - 29/03/2016 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\WINDOWS\Syswow64\dnsapi.dll [535080] =>.Microsoft Windows®
[MD5.70148EFA9A562E7185B75BBE7D376BF7] - 05/11/2015 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\WINDOWS\System32\drivers\AFD.sys [578912] =>.Microsoft Windows®
[MD5.492B99D2E3D5D7BFD5F0AE1BE7BD37DD] - 30/10/2015 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [28512] =>.Microsoft Windows®
[MD5.7F9C7226D743B232907ED2537B8A574F] - 30/10/2015 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [92672] =>.Microsoft Corporation
[MD5.82D97776BF982AA143BDC7DFB5054EA8] - 30/10/2015 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [173568] =>.Microsoft Corporation
[MD5.935823F79CBEDB91637B63D37E3A5A36] - 29/03/2016 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\DfsC.sys [148480] =>.Microsoft Corporation
[MD5.84BC034B6BB763733C1949B7B9BAF976] - 30/10/2015 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [79872] =>.Microsoft Corporation
[MD5.53FDD9E69189E546DE4740F8C4D8AB2F] - 30/10/2015 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [114688] =>.Microsoft Corporation
[MD5.9E5E8F2A1996F23B7E9687846AA81B01] - 30/10/2015 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [143360] =>.Microsoft Corporation
[MD5.0B3B0C1D86050355676640488FA897D3] - 23/02/2016 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [430944] =>.Microsoft Windows®
[MD5.F51C02D992A8D6BC5EC4D990F227D4C7] - 30/10/2015 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [279552] =>.Microsoft Corporation
[MD5.19BD8A88AAC580592668B070AC0727D9] - 29/03/2016 - (.Microsoft Corporation - NT File System Driver.) -- C:\WINDOWS\System32\drivers\ntfs.sys [2152280] =>.Microsoft Windows®
[MD5.7D0FC96264C0F8F2C1321E33E8EB646C] - 30/10/2015 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\WINDOWS\System32\drivers\Parport.sys [96768] =>.Microsoft Corporation
[MD5.E3C82823B22463BC38AA4F8ADA852624] - 23/02/2016 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [104960] =>.Microsoft Corporation
[MD5.1DC2CC74B51E4DC4CD5A20C1021E4010] - 30/10/2015 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [173056] =>.Microsoft Corporation
[MD5.91D3F2A6253EF83EFBD7903028F58C4D] - 05/11/2015 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [118624] =>.Microsoft Windows®
[MD5.E1F91A727A04C9F8199D04FF3BBBF63C] - 30/10/2015 - (.Microsoft Corporation - Volume Shadow Copy Driver.) -- C:\WINDOWS\System32\drivers\volsnap.sys [414560] =>.Microsoft Windows®

---\\ Non Microsoft non disabled Windows Services (24) - 5s
O23 - Service: ASLDR Service (ASLDRService) . (.ASUSTek Computer Inc. - ASLDR Service.) - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe =>.ASUSTeK Computer Inc.®
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) . (.ASUS - GFNEXSrv.) - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe =>.ASUSTeK Computer Inc.®
O23 - Service: AVG Service (avgsvc) . (.AVG Technologies CZ, s.r.o. - AVG Service Process.) - C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe =>.AVG Technologies CZ, s.r.o.®
O23 - Service: ESET Service (ekrn) . (.ESET - ESET Service.) - C:\Program Files\ESET\ESET Smart Security\ekrn.exe =>.ESET, spol. s r.o.®
O23 - Service: ESIF Upper Framework Service (esifsvc) . (.Intel Corporation - Intel(R) Dynamic Platform and Thermal Frame.) - C:\Windows\SysWOW64\esif_uf.exe =>.Intel(R) Software®
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
O23 - Service: HWDeviceService64.exe (HWDeviceService64.exe) . (.Copyright (C) 2008 - DCSHOST.) - C:\ProgramData\DatacardService\HWDeviceService64.exe =>.HUAWEI Technologies Co., Ltd.®
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) . (.Intel Corporation - igfxCUIService Module.) - C:\Windows\System32\igfxCUIService.exe =>.Intel Corporation - pGFX®
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe =>.Intel Corporation - Embedded Subsystems and IP Blocks Group®
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Intel(R) Local Management Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation - Embedded Subsystems and IP Blocks Group®
O23 - Service: Mobile Broadband HL Service (Mobile Broadband HL Service) . (.Copyright (C) 2014 - .) - C:\ProgramData\MobileBrServ\mbbservice.exe =>.Huawei Technologies Co., Ltd.®
O23 - Service: Mobile Partner. OUC (Mobile Partner. RunOuc) . (...) - C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) . (.NVIDIA Corporation - NVIDIA Network Service.) - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe =>.NVIDIA Corporation®
O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 353.5.) - C:\Windows\System32\nvvsvc.exe =>.NVIDIA Corporation®
O23 - Service: Service KMSELDI (Service KMSELDI) . (. - Service_KMS.) - C:\Program Files\KMSpico\Service_KMS.exe =>HackTool.KMSpico
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl®
O23 - Service: Splashtop Software Updater Service (SSUService) . (.Splashtop Inc. - Splashtop Software Updater Service.) - C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe =>.Splashtop Inc.®
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) . (.AVG Technologies CZ, s.r.o. - AVG PC TuneUp Service.) - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe =>.AVG Technologies CZ, s.r.o.®
O23 - Service: VMware Authorization Service (VMAuthdService) . (.VMware, Inc. - VMware Authorization Service.) - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe =>.VMware, Inc.®
O23 - Service: VMware DHCP Service (VMnetDHCP) . (.VMware, Inc. - VMware VMnet DHCP service.) - C:\Windows\SysWOW64\VMNETDHCP.EXE =>.VMware, Inc.®
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) . (.VMware, Inc. - VMware USB Arbitration Service.) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe =>.VMware, Inc.®
O23 - Service: VMware NAT Service (VMware NAT Service) . (.VMware, Inc. - VMware NAT Service.) - C:\Windows\SysWOW64\vmnat.exe =>.VMware, Inc.®
O23 - Service: VMware Workstation Server (VMwareHostd) . (...) - C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe =>.VMware, Inc.®
O23 - Service: ZAtheros Bt and Wlan Coex Agent (ZAtheros Bt and Wlan Coex Agent) . (.Atheros - Atheros Coex Service Application.) - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe =>.Atheros

---\\ Services not Microsoft (SR=Run, SS=Stop) (34) - 57s

SR - Auto [26/03/2014] [ 115512] ASLDR Service (ASLDRService) . (.ASUSTek Computer Inc..) - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe =>.ASUSTeK Computer Inc.®
SR - Auto [21/11/2011] [ 96896] ATKGFNEX Service (ATKGFNEXSrv) . (.ASUS.) - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe =>.ASUSTeK Computer Inc.®
SR - Auto [21/06/2016] [ 1080080] AVG Service (avgsvc) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe =>.AVG Technologies CZ, s.r.o.®
SS - Demand [07/01/2016] [ 433688] BlueStacks Android Service (BstHdAndroidSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-Service.exe =>.BlueStack Systems, Inc.®
SS - Demand [07/01/2016] [ 413208] BlueStacks Log Rotator Service (BstHdLogRotatorSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe =>.BlueStack Systems, Inc.®
SS - Demand [07/01/2016] [ 859672] BlueStacks Updater Service (BstHdUpdaterSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe =>.BlueStack Systems, Inc.®
SS - Demand [19/12/2015] [ 300968] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe =>.Intel Corporation - pGFX®
SR - Auto [23/05/2016] [ 2519904] ESET Service (ekrn) . (.ESET.) - C:\Program Files\ESET\ESET Smart Security\ekrn.exe =>.ESET, spol. s r.o.®
SR - Auto [18/09/2014] [ 1037568] ESIF Upper Framework Service (esifsvc) . (.Intel Corporation.) - C:\Windows\SysWOW64\esif_uf.exe =>.Intel(R) Software®
SS - Auto [28/11/2015] [ 144200] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [28/11/2015] [ 144200] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SR - Auto [14/03/2011] [ 346976] HWDeviceService64.exe (HWDeviceService64.exe) . (.Copyright (C) 2008.) - C:\ProgramData\DatacardService\HWDeviceService64.exe =>.HUAWEI Technologies Co., Ltd.®
SS - Demand [24/04/2012] [ 169752] Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe =>.Intel Corporation®
SR - Auto [19/12/2015] [ 373160] Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) . (.Intel Corporation.) - C:\Windows\System32\igfxCUIService.exe =>.Intel Corporation
SS - Demand [03/10/2014] [ 881152] Intel(R) Capability Licensing Service TCP IP Interface (Intel(R) Capability Licensing Service TCP IP Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe =>.Intel® Trusted Connect Service®
SR - Auto [25/02/2015] [ 156960] Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe =>.Intel Corporation - Embedded Subsystems and IP Blocks Group®
SR - Auto [25/02/2015] [ 409376] Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation - Embedded Subsystems and IP Blocks Group®
SR - Auto [20/08/2014] [ 242256] Mobile Broadband HL Service (Mobile Broadband HL Service) . (.Copyright (C) 2014.) - C:\ProgramData\MobileBrServ\mbbservice.exe =>.Huawei Technologies Co., Ltd.®
SS - Auto [01/03/2013] [ 650240] Mobile Partner. OUC (Mobile Partner. RunOuc) . (...) - C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe
SS - Demand [08/06/2016] [ 146888] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation®
SR - Auto [13/12/2014] [ 1701520] NVIDIA Network Service (NvNetworkService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe =>.NVIDIA Corporation®
SR - Auto [13/07/2015] [ 937616] NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation.) - C:\WINDOWS\system32\nvvsvc.exe =>.NVIDIA Corporation
SS - Demand [16/12/2015] [ 38200] OpenVPN Service (OpenVPNService) . (.The OpenVPN Project.) - C:\Program Files\OpenVPN\bin\openvpnserv.exe =>.OpenVPN Technologies, Inc.®
SS - Auto [25/11/2013] [ 800536] Service KMSELDI (Service KMSELDI) . (...) - C:\Program Files\KMSpico\Service_KMS.exe =>HackTool.KMSpico
SS - Auto [23/03/2016] [ 327808] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl®
SR - Auto [09/10/2013] [ 609056] Splashtop Software Updater Service (SSUService) . (.Splashtop Inc..) - C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe =>.Splashtop Inc.®
SR - Auto [01/06/2016] [ 4803344] AVG PC TuneUp Service (TuneUp.UtilitiesSvc) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe =>.AVG Technologies CZ, s.r.o.®
SR - Auto [14/04/2014] [ 86744] VMware Authorization Service (VMAuthdService) . (.VMware, Inc..) - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe =>.VMware, Inc.®
SR - Auto [14/04/2014] [ 359128] VMware DHCP Service (VMnetDHCP) . (.VMware, Inc..) - C:\Windows\SysWOW64\VMNETDHCP.EXE =>.VMware, Inc.®
SR - Auto [27/02/2014] [ 906432] VMware USB Arbitration Service (VMUSBArbService) . (.VMware, Inc..) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe =>.VMware, Inc.®
SR - Auto [14/04/2014] [ 437976] VMware NAT Service (VMware NAT Service) . (.VMware, Inc..) - C:\Windows\SysWOW64\vmnat.exe =>.VMware, Inc.®
SR - Auto [14/04/2014] [14407384] VMware Workstation Server (VMwareHostd) . (...) - C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe =>.VMware, Inc.®
SR - Auto [28/09/2014] [ 323584] ZAtheros Bt and Wlan Coex Agent (ZAtheros Bt and Wlan Coex Agent) . (.Atheros.) - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe =>.Atheros

---\\ Task Planned Automatically (40) - 8s
[MD5.00000000000000000000000000000000] [APT] [TaskName] (...) -- Task To Run (.not file.) [0] (.Activate.) =>.Superfluous.Empty
[MD5.8BDF98213169A0E2AAFEC4A646458369] [APT] [ASUS Smart Gesture Launcher] (.AsusTek.) -- C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [18416] (.Activate.) =>.ASUSTeK Computer Inc.®
[MD5.61205A84623464E7B3574E31FE3D5AE8] [APT] [ASUS USB Charger Plus] (.ASUSTek Computer Inc..) -- C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [19853392] (.Activate.) =>.ASUSTeK Computer Inc.®
[MD5.95BF2536652AC4116CD54F8D2CB2E055] [APT] [ATK Package 36D18D69AFC3] (.ASUSTek Computer Inc..) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [120632] (.Activate.) =>.ASUSTeK Computer Inc.®
[MD5.CA189CB28ED318B44A2A89F0B35B1831] [APT] [AutoPico Daily Restart] (...) -- C:\Program Files\KMSpico\AutoPico.exe [801048] (.Activate.) =>HackTool.KMSpico
[MD5.E0256050F4208EE3DC149F155003D707] [APT] [AVGPCTuneUp_Task_BkGndMaintenance] (.AVG Technologies CZ, s.r.o..) -- C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe [2263824] (.Activate.) =>.AVG Technologies CZ, s.r.o.®
[MD5.750446ED76A5D13E902174DDDDA1A62B] [APT] [Google Update] (.Google Inc..) -- C:\Users\salamouna2\AppData\Local\Google\Update\GoogleUpdate.exe [154440] (.Activate.) =>.Google Inc®
[MD5.053EEEE1ABAE53F044F1E386E22AE525] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] (.Activate.) =>.Google Inc®
[MD5.053EEEE1ABAE53F044F1E386E22AE525] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] (.Activate.) =>.Google Inc®
[MD5.750446ED76A5D13E902174DDDDA1A62B] [APT] [GoogleUpdateTaskUserS-1-5-21-1498194768-3071915256-2736199516-1001Core] (.Google Inc..) -- C:\Users\salamouna2\AppData\Local\Google\Update\GoogleUpdate.exe [154440] (.Activate.) =>.Google Inc®
[MD5.750446ED76A5D13E902174DDDDA1A62B] [APT] [GoogleUpdateTaskUserS-1-5-21-1498194768-3071915256-2736199516-1001UA] (.Google Inc..) -- C:\Users\salamouna2\AppData\Local\Google\Update\GoogleUpdate.exe [154440] (.Activate.) =>.Google Inc®
[MD5.79CD14A75D06BA52712E45BEA1070FBA] [APT] [hfdccd] (.AutoIt Team.) -- C:\Users\salamouna2\hfdccd\zvbvhivw.exe [931840] (.Activate.) =>.AutoIt Team
[MD5.6513807FEE68E6C32E67437EE3FFB6C8] [APT] [Java Platform SE Auto Updater] (.Oracle Corporation.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504] (.Activate.) =>.Oracle America, Inc.®
[MD5.8A3A1B1D58C43A45517321BC8C650752] [APT] [klcp_update] (...) -- C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1175040] (.Activate.)
[MD5.7986E339CA3B9E73AD05C9701E880D62] [APT] [RTKCPL] (.Realtek Semiconductor.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13872856] (.Activate.) =>.Realtek Semiconductor Corp®
[MD5.70D6EA378844CC762C57FA4B8AC63764] [APT] [update-S-1-5-21-1498194768-3071915256-2736199516-1001] (.Copyright 2009.) -- C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [105728] (.Activate.) =>PUP.Optional.Skillbrains
[MD5.70D6EA378844CC762C57FA4B8AC63764] [APT] [update-sys] (.Copyright 2009.) -- C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [105728] (.Activate.) =>PUP.Optional.Skillbrains
[MD5.E5FC0EBDE5E76F6A65D6657C18CFCE30] [APT] [{6DDF7C85-E9A4-482B-8905-8345726CEC8A}] (.Google Inc..) -- c:\program files (x86)\Google\Chrome\application\chrome.exe [1134920] (.Activate.) =>.Google Inc®
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job [1092] =>.Google Inc®
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job [1096] =>.Google Inc®
O39 - APT: GoogleUpdateTaskUserS-1-5-21-1498194768-3071915256-2736199516-1001Core - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1498194768-3071915256-2736199516-1001Core.job [1066] =>.Google Inc®
O39 - APT: GoogleUpdateTaskUserS-1-5-21-1498194768-3071915256-2736199516-1001UA - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1498194768-3071915256-2736199516-1001UA.job [1118] =>.Google Inc®
O39 - APT: update-S-1-5-21-1498194768-3071915256-2736199516-1001 - (.Copyright 2009.) -- C:\WINDOWS\Tasks\update-S-1-5-21-1498194768-3071915256-2736199516-1001.job [418] =>PUP.Optional.Skillbrains
O39 - APT: update-sys - (.Copyright 2009.) -- C:\WINDOWS\Tasks\update-sys.job [418] =>PUP.Optional.Skillbrains
O39 - APT: ASUS Smart Gesture Launcher - (.AsusTek.) -- C:\WINDOWS\System32\Tasks\ASUS Smart Gesture Launcher [3628] =>.ASUSTeK Computer Inc.®
O39 - APT: ASUS USB Charger Plus - (.ASUSTek Computer Inc..) -- C:\WINDOWS\System32\Tasks\ASUS USB Charger Plus [2188] =>.ASUSTeK Computer Inc.®
O39 - APT: ATK Package 36D18D69AFC3 - (.ASUSTek Computer Inc..) -- C:\WINDOWS\System32\Tasks\ATK Package 36D18D69AFC3 [2782] =>.ASUSTeK Computer Inc.®
O39 - APT: AutoPico Daily Restart - (...) -- C:\WINDOWS\System32\Tasks\AutoPico Daily Restart [3814] =>HackTool.KMSpico
O39 - APT: AVGPCTuneUp_Task_BkGndMaintenance - (.AVG Technologies CZ, s.r.o..) -- C:\WINDOWS\System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance [2904] =>.AVG Technologies CZ, s.r.o.®
O39 - APT: Google Update - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\Google Update [3928] =>.Google Inc®
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore [3922] =>.Google Inc®
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA [4154] =>.Google Inc®
O39 - APT: GoogleUpdateTaskUserS-1-5-21-1498194768-3071915256-2736199516-1001Core - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1498194768-3071915256-2736199516-1001Core [3870] =>.Google Inc®
O39 - APT: GoogleUpdateTaskUserS-1-5-21-1498194768-3071915256-2736199516-1001UA - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1498194768-3071915256-2736199516-1001UA [4246] =>.Google Inc®
O39 - APT: hfdccd - (.AutoIt Team.) -- C:\WINDOWS\System32\Tasks\hfdccd [3680] =>.AutoIt Team
O39 - APT: Java Platform SE Auto Updater - (.Oracle Corporation.) -- C:\WINDOWS\System32\Tasks\Java Platform SE Auto Updater [3798] =>.Oracle America, Inc.®
O39 - APT: klcp_update - (...) -- C:\WINDOWS\System32\Tasks\klcp_update [3222]
O39 - APT: RTKCPL - (.Realtek Semiconductor.) -- C:\WINDOWS\System32\Tasks\RTKCPL [2174] =>.Realtek Semiconductor Corp®
O39 - APT: update-S-1-5-21-1498194768-3071915256-2736199516-1001 - (.Copyright 2009.) -- C:\WINDOWS\System32\Tasks\update-S-1-5-21-1498194768-3071915256-2736199516-1001 [2854] =>PUP.Optional.Skillbrains
O39 - APT: update-sys - (.Copyright 2009.) -- C:\WINDOWS\System32\Tasks\update-sys [2684] =>PUP.Optional.Skillbrains

---\\ Process running (43) - 5s
[MD5.287D7C125CCCBA0D2111181F44BE2C2A] - (.ESET - ESET Service.) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2519904] [PID.1196] =>.ESET, spol. s r.o.®
[MD5.1B44B5244EAF26BEC315AE84B0AFFC66] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 353.5.) -- C:\Windows\System32\nvvsvc.exe [937616] [PID.1332] =>.NVIDIA Corporation®
[MD5.078DE1A9D9DB0BB617D4DCF1EF925928] - (.Intel Corporation - igfxCUIService Module.) -- C:\Windows\System32\igfxCUIService.exe [373160] [PID.1404] =>.Intel Corporation - pGFX®
[MD5.DB1EC96C28212D0EAE597317EEFF6D67] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe [1253008] [PID.1516] =>.NVIDIA Corporation®
[MD5.1B44B5244EAF26BEC315AE84B0AFFC66] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 353.5.) -- C:\Windows\System32\nvvsvc.exe [937616] [PID.1524] =>.NVIDIA Corporation®
[MD5.564CB886D1A968B9798C1AB03F4EB54F] - (.ASUSTek Computer Inc. - ASLDR Service.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe [115512] [PID.2044] =>.ASUSTeK Computer Inc.®
[MD5.DBC598E47E7A382E60E2A4745D41FEF9] - (.ASUS - GFNEXSrv.) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896] [PID.1368] =>.ASUSTeK Computer Inc.®
[MD5.A994548B7F442CE9653D1569BB91CD17] - (.AVG Technologies CZ, s.r.o. - AVG Service Process.) -- C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1080080] [PID.2316] =>.AVG Technologies CZ, s.r.o.®
[MD5.127C81F616E8CB699CFC16B0A2AF412C] - (.Intel Corporation - Intel(R) Dynamic Platform and Thermal Frame.) -- C:\Windows\SysWOW64\esif_uf.exe [1037568] [PID.2408] =>.Intel(R) Software®
[MD5.064DDEC72C818AB8881B607A3836E265] - (.NVIDIA Corporation - NVIDIA Network Service.) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520] [PID.2452] =>.NVIDIA Corporation®
[MD5.533AA4A69EE91B1C53910EF57E314DEF] - (.Copyright (C) 2014 - .) -- C:\ProgramData\MobileBrServ\mbbservice.exe [242256] [PID.2468] =>.Huawei Technologies Co., Ltd.®
[MD5.E90DA42B87D684DEBFB73B38A718A006] - (.Copyright (C) 2008 - DCSHOST.) -- C:\ProgramData\DatacardService\HWDeviceService64.exe [346976] [PID.2476] =>.HUAWEI Technologies Co., Ltd.®
[MD5.41FAE6618768DC93D98DDAF3F8282D3E] - (.VMware, Inc. - VMware USB Arbitration Service.) -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [906432] [PID.2536] =>.VMware, Inc.®
[MD5.08E2C72275EEB2E74575D8176CC08EA6] - (.VMware, Inc. - VMware NAT Service.) -- C:\Windows\SysWOW64\vmnat.exe [437976] [PID.2644] =>.VMware, Inc.®
[MD5.C04DA837FBC636DC88A2ACAEDB4E95F6] - (.VMware, Inc. - VMware VMnet DHCP service.) -- C:\Windows\SysWOW64\VMNETDHCP.EXE [359128] [PID.2668] =>.VMware, Inc.®
[MD5.D07589E4434BD14E192ACED6C398B0CB] - (.VMware, Inc. - VMware Authorization Service.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe [86744] [PID.2728] =>.VMware, Inc.®
[MD5.86B8B1F5C1189D68B07666784BE882FE] - (.Atheros - Atheros Coex Service Application.) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584] [PID.2760] =>.Atheros
[MD5.F2A8DDF60FBC63B0E9545363F316D4EB] - (.AVG Technologies CZ, s.r.o. - AVG PC TuneUp Service.) -- C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [4803344] [PID.2784] =>.AVG Technologies CZ, s.r.o.®
[MD5.504C33FE3B4E2AF11FE5875DDCA8EBEA] - (.Splashtop Inc. - Splashtop Software Updater Service.) -- C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe [609056] [PID.2808] =>.Splashtop Inc.®
[MD5.81BC96818A1A718342B5A03BA34AED2A] - (...) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [14407384] [PID.1060] =>.VMware, Inc.®
[MD5.1C3EF75B521DB60E951711440648B0D5] - (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [156960] [PID.1668] =>.Intel Corporation - Embedded Subsystems and IP Blocks Group®
[MD5.56FE3C885B0901601549E23E7A435984] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler.exe [250008] [PID.2420] =>.Google Inc®
[MD5.A425CDCEB9D26E9A5ABAFA259799D447] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler64.exe [312472] [PID.2520] =>.Google Inc®
[MD5.631ABC3E8FF50F9B70B9A52568B1F5F6] - (.Intel Corporation - Intel(R) Local Management Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [409376] [PID.2548] =>.Intel Corporation - Embedded Subsystems and IP Blocks Group®
[MD5.6A80F5C61899D79B755BC41E0C48E793] - (.ASUSTek Computer Inc. - HControl.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe [303928] [PID.5036] =>.ASUSTeK Computer Inc.®
[MD5.26793BC0B998B3595F1FA5D7A0C16923] - (.Intel Corporation - Intel(R) Dynamic Platform and Thermal Frame.) -- C:\Windows\Temp\DPTF\esif_assist.exe [183816] [PID.5104] =>.Intel(R) Software®
[MD5.B03B66ACBEE88E4DF0D5CD6F4EF69DF7] - (.AVG Technologies CZ, s.r.o. - AVG PC TuneUp.) -- C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe [4430608] [PID.868] =>.AVG Technologies CZ, s.r.o.®
[MD5.1E019BCBFAED4BE128CAEFDE11B79B3E] - (.ESET - ESET Main GUI.) -- C:\Program Files\ESET\ESET Smart Security\egui.exe [5565088] [PID.2800] =>.ESET, spol. s r.o.®
[MD5.61205A84623464E7B3574E31FE3D5AE8] - (.ASUSTek Computer Inc. - ASUS USB Charger Plus.) -- C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [19853392] [PID.2008] =>.ASUSTeK Computer Inc.®
[MD5.CFAC0D3B76F75709B03360FDF910CF21] - (.ASUSTek Computer Inc. - ATKOSD2.) -- C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [406328] [PID.2884] =>.ASUSTeK Computer Inc.®
[MD5.E72C2F7797A6B7E0445D789FD6EF87B5] - (.ASUSTek Computer Inc. - ATK Media.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [209720] [PID.4292] =>.ASUSTeK Computer Inc.®
[MD5.349AB4F70E2AC44970894E7F03E1576E] - (.Huawei Technologies Co., Ltd. - DataCardMonitor MFC Application.) -- C:\ProgramData\DatacardService\DCSHelper.exe [236384] [PID.4956] =>.HUAWEI Technologies Co., Ltd.®
[MD5.D61AEC9A148F08A82487938E4EA5DADC] - (.Intel Corporation - igfxEM Module.) -- C:\Windows\System32\igfxEM.exe [354216] [PID.2564] =>.Intel Corporation - pGFX®
[MD5.3A19FD28BF891CB67FD89A94BEC88C3F] - (...) -- C:\Windows\System32\igfxTray.exe [402344] [PID.600] =>.Intel Corporation - pGFX®
[MD5.904CA475F6ADD4080B0EA5144D23FDF1] - (...) -- C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe [144384] [PID.3204]
[MD5.E515A22A8DB5350A94248FBCF09F089D] - (.NVIDIA Corporation - NVIDIA GeForce Experience Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472] [PID.3320] =>.NVIDIA Corporation®
[MD5.3244E954707B649F16ECB3D94CE56600] - (.NVIDIA Corporation - NVIDIA Settings.) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe [2447688] [PID.3328] =>.NVIDIA Corporation®
[MD5.7986E339CA3B9E73AD05C9701E880D62] - (.Realtek Semiconductor - Realtek HD Audio Manager.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13872856] [PID.6124] =>.Realtek Semiconductor Corp®
[MD5.82193D2E6389E944EF9868E61C648ED4] - (.AsusTek - ASUS Smart Gesture Loader.) -- C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe [366064] [PID.4996] =>.ASUSTeK Computer Inc.®
[MD5.0B42873501A576FF6CDE35EA69EE930A] - (.Skillbrains - Lightshot.) -- C:\Program Files (x86)\Skillbrains\lightshot\5.3.0.0\Lightshot.exe [477184] [PID.5012] =>PUP.Optional.Skillbrains
[MD5.5A2CC093AB11C4B2708A039981611053] - (.AsusTek - ASUS Smart Gesture Center.) -- C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe [311792] [PID.6956] =>.ASUSTeK Computer Inc.®
[MD5.BFB751CDB142AEFFDAF54EDE93032643] - (.AsusTek - ASUS Smart Gesture Helper.) -- C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe [179696] [PID.6036] =>.ASUSTeK Computer Inc.®
[MD5.4FA12350B04AAECF0D3893ADFB65101C] - (.Nicolas Coolman - ZHPDiag.) -- F:\ZHPDiag3.exe [2216960] [PID.4760] =>.Nicolas Coolman

---\\ Google Chrome, Start,Search,Extensions (24) - 1s
G0 - GCSP: Preferences [User Data\Default][HomePage] http://cdn.datatables.net
G0 - GCSP: Preferences [User Data\Default][HomePage] http://sms-activate.ru
G0 - GCSP: Preferences [User Data\Default][HomePage] http://d.joinhoney.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://emails.abine.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://ext-cdn.joinhoney.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://license.abine.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://push.abine.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://s.joinhoney.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.gstatic.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.tn
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://search.conduit.com/ =>.Superfluous.Conduit
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://home.eazel.com
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [bmnlcjabgnpnenekpadlanbbkooimhnj] Honey
G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [ejidjjhkpiempkbhmpbfngldlkglhimk] __MSG_WEBSTORE_PRONGHORN_PRODUCT_NAME__
G2 - GCE: Preference [User Data\Default] [epanfjkfahimkgomnigadpkobaefekcd] Blur
G2 - GCE: Preference [User Data\Default] [hflfdfjhemennkeeolpjdbdfbfonodbg] FB UID Scraper Lite
G2 - GCE: Preference [User Data\Default] [lfpjkncokllnfokkgpkobnkbkmelfefj] Linkclump
G2 - GCE: Preference [User Data\Default] [ngpampappnmepgilojfohadhhmbhlaek] IDM Integration Module
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router

---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (8) - 3s
M0 - MFSP: prefs.js [salamouna2 - e18oh439.default] http://www.google.fr/
P2 - EXT: (.Microsoft Corporation - The plugin allows you to have a better expe.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npMeetingJoinPluginOC.dll =>.Microsoft Corporation®
P2 - EXT FILE: (...) -- C:\Users\salamouna2\AppData\Roaming\Mozilla\Firefox\Profiles\e18oh439.default\extensions\jid1-BYcQOfYfmBMd9A@jetpack.xpi
P2 - EXT FILE: (...) -- C:\Users\salamouna2\AppData\Roaming\Mozilla\Firefox\Profiles\e18oh439.default\extensions\toolbar@seomoz.org.xpi
P2 - EXT FILE: (...) -- C:\Users\salamouna2\AppData\Roaming\Mozilla\Firefox\Profiles\e18oh439.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
P2 - EXT: (.Hemant Pawar - Buy Proxies.) -- C:\Users\salamouna2\AppData\Roaming\Mozilla\Firefox\Profiles\e18oh439.default\extensions\firefox@buyproxies.org
P2 - EXT: (.LastPass Dev Team - LastPass.) -- C:\Users\salamouna2\AppData\Roaming\Mozilla\Firefox\Profiles\e18oh439.default\extensions\support@lastpass.com =>.LastPass Dev Team
P2 - EXT: (.iMacros, an Ipswitch Product - iMacros for Firefox.) -- C:\Users\salamouna2\AppData\Roaming\Mozilla\Firefox\Profiles\e18oh439.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}

---\\ Internet Explorer Extensions, Start, Search (17) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphan =>.Microsoft Internet Explorer
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1
R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1

---\\ Internet Explorer, Proxy Management (4) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
F2 - REG:system.ini: UserInit=
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=

---\\ Hosts file redirection (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)

---\\ Browser Helper Object (BHO) (4) - 1s
O2 - BHO: IDM Helper [64Bits] - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll =>.Tonec Inc.®
O2 - BHO: Lync Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} (Orphean)
O2 - BHO: iMacros Browser Helper Object [64Bits] - {34D5A80A-992D-4F07-9509-66E9E133BAAF} . (...) -- C:\Program Files (x86)\Ipswitch\iMacros\iMacrosBHO.dll {036F562E1D233FA28EFB3F83CA4897A1}
O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL =>.Microsoft Corporation®

---\\ Auto loading programs from Registry and folders (28) - 3s
O4 - HKLM\..\Run: [NvBackend] . (.NVIDIA Corporation - NVIDIA GeForce Experience Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe =>.NVIDIA Corporation®
O4 - HKLM\..\Run: [XboxStat] . (.Microsoft Corporation - XBoxStat.exe.) -- C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe =>.Microsoft Corporation®
O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc.
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Software Sarl®
O4 - HKCU\..\Run: [uTorrent] . (.BitTorrent, Inc. - µTorrent.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Google Installer.) -- C:\Users\salamouna2\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc®
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64 (.not file.)
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64] C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64 (.not file.)
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64] C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64 (.not file.)
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64] C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64 (.not file.)
O4 - HKLM\..\Wow6432Node\Run: [vmware-tray.exe] . (.VMware, Inc. - VMware Tray Process.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe =>.VMware, Inc.®
O4 - HKLM\..\Wow6432Node\Run: [Lightshot] . (.Copyright 2009 - Starter Module.) -- C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe =>PUP.Optional.Skillbrains
O4 - HKLM\..\Wow6432Node\Run: [BlueStacks Agent] . (.BlueStack Systems, Inc. - BlueStacks Agent.) -- C:\Program Files (x86)\BlueStacks\HD-Agent.exe =>.BlueStack Systems, Inc.®
O4 - HKLM\..\Wow6432Node\Run: [AvgUi] . (.AVG Technologies CZ, s.r.o. - AVG Ui (Re)Starter.) -- C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe =>.AVG Technologies CZ, s.r.o.®
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle America, Inc.®
O4 - HKLM\..\policies\Explorer\Run: [BtvStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (.not file.)
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Corporation®
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Corporation®
O4 - HKUS\S-1-5-21-1498194768-3071915256-2736199516-1001\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc.
O4 - HKUS\S-1-5-21-1498194768-3071915256-2736199516-1001\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Software Sarl®
O4 - HKUS\S-1-5-21-1498194768-3071915256-2736199516-1001\..\Run: [uTorrent] . (.BitTorrent, Inc. - µTorrent.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - HKUS\S-1-5-21-1498194768-3071915256-2736199516-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - HKUS\S-1-5-21-1498194768-3071915256-2736199516-1001\..\Run: [Google Update] . (.Google Inc. - Google Installer.) -- C:\Users\salamouna2\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc®
O4 - HKUS\S-1-5-21-1498194768-3071915256-2736199516-1001\..\RunOnce: [Uninstall C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64 (.not file.)
O4 - HKUS\S-1-5-21-1498194768-3071915256-2736199516-1001\..\RunOnce: [Uninstall C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64] C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64 (.not file.)
O4 - HKUS\S-1-5-21-1498194768-3071915256-2736199516-1001\..\RunOnce: [Uninstall C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64] C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64 (.not file.)
O4 - HKUS\S-1-5-21-1498194768-3071915256-2736199516-1001\..\RunOnce: [Uninstall C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64] C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64 (.not file.)

---\\ Global shortcuts Startup (71) - 17s
O4 - GS\Desktop [Administrator]: Grand Theft Auto V.lnk . (.Rockstar Games - Grand Theft Auto V Launcher.) E:\Grand Theft Auto V\GTAVLauncher.exe =>.Take-Two Interactive Software, Inc.®
O4 - GS\Desktop [Administrator]: HTTrack Website Copier.lnk . (.HTTrack - WinHTTrack Website Copier, Copy Websites to.) C:\Program Files\WinHTTrack\WinHTTrack.exe =>.Open Source Developer, httrack.com®
O4 - GS\Desktop [Administrator]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc.
O4 - GS\Desktop [Administrator]: Multi-Drive.lnk . (...) C:\Users\salamouna2\AppData\Roaming\Nox\bin\MultiPlayerManager.exe {3D3A32026D6FFDF4D9631F40D0ABB5A8}
O4 - GS\Desktop [Administrator]: Nox.lnk . (.Duodian Technology Co. Ltd. - Nox App Player.) C:\Users\salamouna2\AppData\Roaming\Nox\bin\Nox.exe {3D3A32026D6FFDF4D9631F40D0ABB5A8} =>.Duodian Technology Co. Ltd.
O4 - GS\Desktop [Administrator]: Telegram.lnk . (.Telegram Messenger LLP - .) C:\Users\salamouna2\AppData\Roaming\Telegram Desktop\Telegram.exe {4098401CAB91A429} =>.Telegram Messenger LLP
O4 - GS\Desktop [Administrator]: UsbFix.lnk . (...) C:\UsbFix\UsbFix.exe
O4 - GS\Desktop [Administrator]: Your Unin-staller!.lnk . (.URSoft,Inc - Your Uninstaller! - New way to uninstall pr.) C:\Program Files (x86)\Your Uninstaller! 7\urmain.exe
O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\salamouna2\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Administrator]: Rental Management.lnk . (.Jsoft.fr - .) C:\Users\salamouna2\AppData\Roaming\Jsoft.fr\Gestion locative\gestion-locative.exe {050D2F4FDB31B8FF2E283E21178BF9DB} =>.Jsoft.fr
O4 - GS\Quicklaunch [Administrator]: VMware Workstation.lnk . (.VMware, Inc. - VMware Workstation.) C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe =>.VMware, Inc.®
O4 - GS\Quicklaunch [Administrator]: µTorrent.lnk . (.BitTorrent, Inc. - µTorrent.) C:\Program Files (x86)\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [Administrator]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Software Sarl®
O4 - GS\sendTo [Administrator]: WinSCP (for upload).lnk . (.Martin Prikryl - WinSCP: SFTP, FTP and SCP client.) C:\Program Files (x86)\WinSCP\WinSCP.exe =>.Martin Prikryl®
O4 - GS\TaskBar [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Desktop [Guest]: Grand Theft Auto V.lnk . (.Rockstar Games - Grand Theft Auto V Launcher.) E:\Grand Theft Auto V\GTAVLauncher.exe =>.Take-Two Interactive Software, Inc.®
O4 - GS\Desktop [Guest]: HTTrack Website Copier.lnk . (.HTTrack - WinHTTrack Website Copier, Copy Websites to.) C:\Program Files\WinHTTrack\WinHTTrack.exe =>.Open Source Developer, httrack.com®
O4 - GS\Desktop [Guest]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc.
O4 - GS\Desktop [Guest]: Multi-Drive.lnk . (...) C:\Users\salamouna2\AppData\Roaming\Nox\bin\MultiPlayerManager.exe {3D3A32026D6FFDF4D9631F40D0ABB5A8}
O4 - GS\Desktop [Guest]: Nox.lnk . (.Duodian Technology Co. Ltd. - Nox App Player.) C:\Users\salamouna2\AppData\Roaming\Nox\bin\Nox.exe {3D3A32026D6FFDF4D9631F40D0ABB5A8} =>.Duodian Technology Co. Ltd.
O4 - GS\Desktop [Guest]: Telegram.lnk . (.Telegram Messenger LLP - .) C:\Users\salamouna2\AppData\Roaming\Telegram Desktop\Telegram.exe {4098401CAB91A429} =>.Telegram Messenger LLP
O4 - GS\Desktop [Guest]: UsbFix.lnk . (...) C:\UsbFix\UsbFix.exe
O4 - GS\Desktop [Guest]: Your Unin-staller!.lnk . (.URSoft,Inc - Your Uninstaller! - New way to uninstall pr.) C:\Program Files (x86)\Your Uninstaller! 7\urmain.exe
O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\salamouna2\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Guest]: Rental Management.lnk . (.Jsoft.fr - .) C:\Users\salamouna2\AppData\Roaming\Jsoft.fr\Gestion locative\gestion-locative.exe {050D2F4FDB31B8FF2E283E21178BF9DB} =>.Jsoft.fr
O4 - GS\Quicklaunch [Guest]: VMware Workstation.lnk . (.VMware, Inc. - VMware Workstation.) C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe =>.VMware, Inc.®
O4 - GS\Quicklaunch [Guest]: µTorrent.lnk . (.BitTorrent, Inc. - µTorrent.) C:\Program Files (x86)\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [Guest]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Software Sarl®
O4 - GS\sendTo [Guest]: WinSCP (for upload).lnk . (.Martin Prikryl - WinSCP: SFTP, FTP and SCP client.) C:\Program Files (x86)\WinSCP\WinSCP.exe =>.Martin Prikryl®
O4 - GS\TaskBar [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Desktop [salamouna2]: Grand Theft Auto V.lnk . (.Rockstar Games - Grand Theft Auto V Launcher.) E:\Grand Theft Auto V\GTAVLauncher.exe =>.Take-Two Interactive Software, Inc.®
O4 - GS\Desktop [salamouna2]: HTTrack Website Copier.lnk . (.HTTrack - WinHTTrack Website Copier, Copy Websites to.) C:\Program Files\WinHTTrack\WinHTTrack.exe =>.Open Source Developer, httrack.com®
O4 - GS\Desktop [salamouna2]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc.
O4 - GS\Desktop [salamouna2]: Multi-Drive.lnk . (...) C:\Users\salamouna2\AppData\Roaming\Nox\bin\MultiPlayerManager.exe {3D3A32026D6FFDF4D9631F40D0ABB5A8}
O4 - GS\Desktop [salamouna2]: Nox.lnk . (.Duodian Technology Co. Ltd. - Nox App Player.) C:\Users\salamouna2\AppData\Roaming\Nox\bin\Nox.exe {3D3A32026D6FFDF4D9631F40D0ABB5A8} =>.Duodian Technology Co. Ltd.
O4 - GS\Desktop [salamouna2]: Telegram.lnk . (.Telegram Messenger LLP - .) C:\Users\salamouna2\AppData\Roaming\Telegram Desktop\Telegram.exe {4098401CAB91A429} =>.Telegram Messenger LLP
O4 - GS\Desktop [salamouna2]: UsbFix.lnk . (...) C:\UsbFix\UsbFix.exe
O4 - GS\Desktop [salamouna2]: Your Unin-staller!.lnk . (.URSoft,Inc - Your Uninstaller! - New way to uninstall pr.) C:\Program Files (x86)\Your Uninstaller! 7\urmain.exe
O4 - GS\Desktop [salamouna2]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\salamouna2\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [salamouna2]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [salamouna2]: Rental Management.lnk . (.Jsoft.fr - .) C:\Users\salamouna2\AppData\Roaming\Jsoft.fr\Gestion locative\gestion-locative.exe {050D2F4FDB31B8FF2E283E21178BF9DB} =>.Jsoft.fr
O4 - GS\Quicklaunch [salamouna2]: VMware Workstation.lnk . (.VMware, Inc. - VMware Workstation.) C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe =>.VMware, Inc.®
O4 - GS\Quicklaunch [salamouna2]: µTorrent.lnk . (.BitTorrent, Inc. - µTorrent.) C:\Program Files (x86)\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [salamouna2]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Software Sarl®
O4 - GS\sendTo [salamouna2]: WinSCP (for upload).lnk . (.Martin Prikryl - WinSCP: SFTP, FTP and SCP client.) C:\Program Files (x86)\WinSCP\WinSCP.exe =>.Martin Prikryl®
O4 - GS\TaskBar [salamouna2]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\CommonDesktop [Public]: Apps.lnk . (...) C:\Users\Public\Libraries\Apps.library-ms
O4 - GS\CommonDesktop [Public]: AudioWizard.lnk . (.Flexera Software LLC - InstallShield.) C:\Windows\Installer\{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}\NewShortcut21_88CE7B52F926451CAD0B30AC2FF26CC7.exe =>.ICEpower a/s®
O4 - GS\CommonDesktop [Public]: AVG PC TuneUp.lnk . (.AVG Technologies CZ, s.r.o. - AVG User Interface.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe =>.AVG Technologies CZ, s.r.o.®
O4 - GS\CommonDesktop [Public]: Camtasia Studio 8.lnk . (.TechSmith Corporation - Camtasia Studio.) C:\Program Files (x86)\TechSmith\Camtasia Studio 8\CamtasiaStudio.exe {0405D56C46C5C7254AC1464FC2CF4A1F} =>.TechSmith Corporation
O4 - GS\CommonDesktop [Public]: DriversCloud.com - Start the detection.lnk . (.CybelSoft - .) C:\Program Files (x86)\DriversCloud.com\MCDetection.exe =>.CybelSoft
O4 - GS\CommonDesktop [Public]: eManual.Lnk . (.ASUSTek Computer Inc. - EManual Application.) C:\eSupport\Manual\eManual.exe =>.ASUSTeK Computer Inc.®
O4 - GS\CommonDesktop [Public]: ESET Banking & Payment protection.lnk . (.ESET - .) C:\Program Files (x86)\ESET\ESET Smart Security\ecmd.exe =>.ESET
O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\CommonDesktop [Public]: Hex Workshop Hex Editor (64 bit).lnk . (.BreakPoint Software, Inc. - .) C:\Program Files (x86)\BreakPoint Software\Hex Workshop v6.8\HWorks64.exe
O4 - GS\CommonDesktop [Public]: Intel(R) HD Graphics Control Panel.lnk . (.Intel Corporation - GFXUIEX Module.) C:\Windows\system32\GfxUIEx.exe =>.Intel Corporation - pGFX®
O4 - GS\CommonDesktop [Public]: Malwarebytes Anti-Malware.lnk . (.Malwarebytes - Malwarebytes Anti-Malware.) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe =>.Malwarebytes Corporation®
O4 - GS\CommonDesktop [Public]: Mobile Partner.lnk . (...) C:\Program Files (x86)\Mobile Partner\Mobile Partner.exe
O4 - GS\CommonDesktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\CommonDesktop [Public]: OpenVPN GUI.lnk . (...) C:\Program Files\OpenVPN\bin\openvpn-gui.exe =>.OpenVPN Technologies, Inc.®
O4 - GS\CommonDesktop [Public]: Rental Management.lnk . (.Jsoft.fr - .) C:\Users\salamouna2\AppData\Roaming\Jsoft.fr\Gestion locative\gestion-locative.exe {050D2F4FDB31B8FF2E283E21178BF9DB} =>.Jsoft.fr
O4 - GS\CommonDesktop [Public]: Skype.lnk . (...) C:\Windows\Installer\{FC965A47-4839-40CA-B618-18F486F042C6}\SkypeIcon.exe
O4 - GS\CommonDesktop [Public]: Splashtop Personal.lnk . (.Splashtop Inc. - Splashtop Personal - Remote Desktop for Win.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Client for STP\clientoobe.exe {7A70012DFCB7B3BC1770BAB83A4DCA7D} =>.Splashtop Inc.
O4 - GS\CommonDesktop [Public]: Start BlueStacks.lnk . (.BlueStack Systems, Inc. - BlueStacks StartLauncher.) C:\Program Files (x86)\BlueStacks\HD-StartLauncher.exe =>.BlueStack Systems, Inc.®
O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe =>.VideoLAN®
O4 - GS\CommonDesktop [Public]: VMware Workstation.lnk . (.VMware, Inc. - VMware Workstation.) C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe =>.VMware, Inc.®
O4 - GS\CommonDesktop [Public]: WinSCP.lnk . (.Martin Prikryl - WinSCP: SFTP, FTP and SCP client.) C:\Program Files (x86)\WinSCP\WinSCP.exe =>.Martin Prikryl®
O4 - GS\CommonDesktop [Public]: YouWave Android.lnk . (...) C:\Program Files (x86)\YouWave Android\YouWave Android.exe {11210F780EC071E5979A5FE0332993A7E82B}
O4 - GS\CommonDesktop [Public]: µTorrent.lnk . (.BitTorrent, Inc. - µTorrent.) C:\Program Files (x86)\uTorrent\uTorrent.exe =>.BitTorrent Inc®

---\\ Lop.com/Domain Hijackers (9) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\..\{5c468d7b-e32f-4de6-b744-1b84a36aa35c}: NameServer = 8.8.8.8,8.8.4.4 =>.Google Public DNS
O17 - HKLM\System\CCS\Services\Tcpip\..\{0b080915-1272-4b57-824f-e8cb7911534c}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{2c45ff53-a249-4050-be86-22c608ea313f}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{5c468d7b-e32f-4de6-b744-1b84a36aa35c}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{7b5a4e37-ad08-486c-8e85-6d6e76e01bfb}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{ce6e713e-5f0d-4972-be99-275c4fd01ec0}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{0b080915-1272-4b57-824f-e8cb7911534c}: DhcpDomain = wifimodem.orange
O17 - HKLM\System\CCS\Services\Tcpip\..\{5c468d7b-e32f-4de6-b744-1b84a36aa35c}: DhcpDomain = wifimodem.orange
O17 - HKLM\System\CCS\Services\Tcpip\..\{7b5a4e37-ad08-486c-8e85-6d6e76e01bfb}: DhcpDomain = wifimodem.orange

---\\ Extra protocols (24) - 1s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\SysWOW64\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation
O18 - Handler: osf [64Bits] - {D924BDC6-C83A-4BD5-90D0-095128A113D1} . (.Microsoft Corporation - Microsoft Office 2013 component.) -- C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL =>.Microsoft Corporation®
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\SysWOW64\tbauth.dll =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: windows.tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\SysWOW64\tbauth.dll =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: text/xml [64Bits] - {807583E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL =>.Microsoft Corporation®

---\\ Software installed (104) - 32s
O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKLM][64Bits] -- uTorrent =>.BitTorrent Inc®
O42 - Logiciel: ASUS Smart Gesture - (.ASUS.) [HKLM][64Bits] -- {4D3286A6-F6AB-498A-82A4-E4F040529F3D} =>.ASUS
O42 - Logiciel: ASUS USB Charger Plus - (.ASUS.) [HKLM][64Bits] -- {A859E3E5-C62F-4BFA-AF1D-2B95E03166AF} =>.ASUS
O42 - Logiciel: ATK Package - (.ASUS.) [HKLM][64Bits] -- {AB5C933E-5C7D-4D30-B314-9C83A49B94BE} =>.ASUS
O42 - Logiciel: AudioWizard - (.ICEpower a/s.) [HKLM][64Bits] -- {57E770A2-2BAF-4CAA-BAA3-BD896E2254D3} =>.ICEpower a/s
O42 - Logiciel: AVG PC TuneUp - (.AVG Technologies.) [HKLM][64Bits] -- {B73C71A6-550D-436C-AB2E-E677B7BA010E} =>.AVG Technologies
O42 - Logiciel: AVG PC TuneUp - (.AVG Technologies.) [HKLM][64Bits] -- AVG PC TuneUp =>.AVG Technologies CZ, s.r.o.®
O42 - Logiciel: BlueStacks App Player - (.BlueStack Systems, Inc..) [HKLM][64Bits] -- {4047E0FE-CBD8-4915-BBB1-45F6CBF417AC} =>.BlueStack Systems, Inc.
O42 - Logiciel: Camtasia Studio 8 - (.TechSmith Corporation.) [HKLM][64Bits] -- {AF33D0D2-2627-4AC8-8473-FDBB7892129C} =>.TechSmith Corporation
O42 - Logiciel: DriversCloud.com (64 bits) - (.Cybelsoft.) [HKLM][64Bits] -- {B3F21810-C58E-4AE1-BFBA-8327721C9F8A} =>.CybelSoft
O42 - Logiciel: ESET Smart Security - (.ESET, spol. s r.o..) [HKLM][64Bits] -- {11994064-51F2-45DF-A83E-539B4BFE3F5A} =>.ESET, spol. s r.o.
O42 - Logiciel: FileZilla Client 3.18.0 - (.Tim Kosse.) [HKLM][64Bits] -- FileZilla Client =>.Tim Kosse
O42 - Logiciel: FMW 1 - (.AVG Technologies.) [HKLM][64Bits] -- {69851B81-35BF-4B1B-AE90-3B1D67DD8857} =>.AVG Technologies
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome =>.Google Inc®
O42 - Logiciel: Google Earth - (.Google.) [HKLM][64Bits] -- {817750FA-EC6A-485D-9901-0683AE6FFDF1} =>.Google
O42 - Logiciel: Google Earth Pro - (.Google.) [HKLM][64Bits] -- {35DAA04C-1720-4BE3-A920-A03731EC6A1D} =>.Google
O42 - Logiciel: Google Talk Plugin - (.Google.) [HKLM][64Bits] -- {F9B579C2-D854-300A-BE62-A09EB9D722E4} =>.Google
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: Grand Theft Auto V version v.1.0.350.1 - (.GMT-MAX.ORG.) [HKLM][64Bits] -- Grand Theft Auto V_is1
O42 - Logiciel: Hex Workshop v6.8 - (.BreakPoint Software.) [HKLM][64Bits] -- {A36AC685-4435-4C16-861F-221231DE165D}
O42 - Logiciel: HxD Hex Editor version 1.7.7.0 - (.Maël Hِrz.) [HKLM][64Bits] -- HxD Hex Editor_is1
O42 - Logiciel: iMacros Version 10.0.2.2823 (x64) - (.Ipswitch, Inc.) [HKLM][64Bits] -- {9C5118F7-E26D-4fc0-B7F4-4A067A0808FA}_is1
O42 - Logiciel: Intel Collaborative Processor Performance Control - (.Intel Corporation.) [HKLM][64Bits] -- 0E7DAF70-FB54-4B91-B192-7E771C25AEEB =>.Intel Corporation
O42 - Logiciel: Intel(R) Chipset Device Software - (.Intel Corporation.) [HKLM][64Bits] -- {BD667C75-0EDD-4073-A406-A6DD9C3016EB} =>.Intel Corporation
O42 - Logiciel: Intel(R) Chipset Device Software - (.Intel(R) Corporation.) [HKLM][64Bits] -- {f5d71765-7cd1-4e68-998f-5b379e725da3} =>.Intel Corporation - Software and Firmware Products®
O42 - Logiciel: Intel(R) Control Center - (.Intel Corporation.) [HKLM][64Bits] -- {F8A9085D-4C7A-41a9-8A77-C8998A96C421} =>.Intel Corporation - pGFX®
O42 - Logiciel: Intel(R) Dynamic Platform and Thermal Framework - (.Intel Corporation.) [HKLM][64Bits] -- {654EE65D-FAA4-4EA6-8C07-DC94E6A304D4} =>.Intel Corporation
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {1CEAC85D-2590-4760-800F-8DE5E91F3700} =>.Intel Corporation
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {69AAE674-929D-4A17-B108-623E8FDD6EE7} =>.Intel Corporation
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {6C9B8590-9D31-4802-92A2-0DDFE9708C4C} =>.Intel Corporation
O42 - Logiciel: Intel(R) ME UninstallLegacy - (.Intel Corporation.) [HKLM][64Bits] -- {013FAB2E-017D-4330-8179-B5FE02E7F81C} =>.Intel Corporation
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} =>.Intel Corporation - pGFX®
O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {5EA6BC70-0CFC-413D-8465-8506B6F46EE0} =>.Intel Corporation
O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM][64Bits] -- Internet Download Manager =>.Tonec Inc.®
O42 - Logiciel: Java 8 Update 91 - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83218091F0} =>.Oracle Corporation
O42 - Logiciel: Java Auto Updater - (.Oracle Corporation.) [HKLM][64Bits] -- {4A03706F-666A-4037-7777-5F2748764D10} =>.Oracle Corporation
O42 - Logiciel: K-Lite Codec Pack 11.7.5 Full - (...) [HKLM][64Bits] -- KLiteCodecPack_is1
O42 - Logiciel: KMSpico v9.1.0.20131125 (Beta) - (...) [HKLM][64Bits] -- KMSpico_is1 =>HackTool.KMSpico
O42 - Logiciel: Lightshot-5.3.0.0 - (.Skillbrains.) [HKLM][64Bits] -- {30A5B3C9-2084-4063-A32A-628A98DE512B}_is1 =>PUP.Optional.Skillbrains
O42 - Logiciel: Malwarebytes Anti-Malware version 2.2.1.1043 - (.Malwarebytes.) [HKLM][64Bits] -- Malwarebytes Anti-Malware_is1 =>.Malwarebytes
O42 - Logiciel: Microsoft Access MUI (English) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0015-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Access Setup Metadata MUI (English) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0117-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft DCF MUI (English) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0090-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Excel MUI (English) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0016-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Groove MUI (English) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00BA-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft InfoPath MUI (English) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0044-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Lync MUI (English) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-012B-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft OneNote MUI (English) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00A1-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Outlook MUI (English) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001A-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft PowerPoint MUI (English) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0018-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Publisher MUI (English) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0019-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Word MUI (English) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001B-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Xbox 360 Accessories 1.2 - (.Microsoft.) [HKLM][64Bits] -- {D9C50188-12D5-4D3E-8F00-682346C2AA5F} =>.Microsoft
O42 - Logiciel: Mobile Broadband HL Service - (.Huawei Technologies Co.,Ltd.) [HKLM][64Bits] -- Mobile Broadband HL Service =>.Huawei Technologies Co., Ltd.®
O42 - Logiciel: Mobile Partner - (.Huawei Technologies Co.,Ltd.) [HKLM][64Bits] -- Mobile Partner =>.Huawei Technologies Co.,Ltd
O42 - Logiciel: MouseRecorder v1.0.47 - (.Bartels Media GmbH.) [HKLM][64Bits] -- MouseRecorder_is1
O42 - Logiciel: Mozilla Firefox 47.0 (x86 en-US) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 47.0 (x86 en-US) =>.Mozilla Corporation®
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService =>.Mozilla
O42 - Logiciel: Notepad++ - (.Notepad++ Team.) [HKLM][64Bits] -- Notepad++ =>.Notepad++ Team
O42 - Logiciel: Nox APP Player - (.Duodian Technology Co. Ltd..) [HKLM][64Bits] -- Nox =>.Duodian Online Technology Co. Ltd.®
O42 - Logiciel: NVIDIA Control Panel 353.54 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Graphics Driver 345.05 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Install Application - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Network Service - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Optimus Update 16.18.9 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA PhysX - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B455E95A-B804-439F-B533-336B1635AE97} =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA PhysX System Software 9.14.0702 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Update Core - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core =>.NVIDIA Corporation
O42 - Logiciel: OpenVPN 2.3.9-I601 - (...) [HKLM][64Bits] -- OpenVPN
O42 - Logiciel: Qualcomm Atheros Bluetooth Suite (64) - (.Qualcomm Atheros Communications.) [HKLM][64Bits] -- {A84A4FB1-D703-48DB-89E0-68B6499D2801} =>.Qualcomm Atheros Communications
O42 - Logiciel: Qualcomm Atheros Client Installation Program - (.Qualcomm Atheros.) [HKLM][64Bits] -- {28006915-2739-4EBE-B5E8-49B25D32EB33} =>.Qualcomm Atheros
O42 - Logiciel: Realtek Card Reader - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {5BC2B5AB-80DE-4E83-B8CF-426902051D0A} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Rental Management - (.Jsoft.fr.) [HKLM][64Bits] -- {4F040BE0-2E11-4CED-8AE3-047C0DA352D4}_is1 {050D2F4FDB31B8FF2E283E21178BF9DB} =>.Jsoft.fr
O42 - Logiciel: Rockstar Games Social Club - (.Rockstar Games.) [HKLM][64Bits] -- Rockstar Games Social Club =>.Take-Two Interactive Software, Inc.®
O42 - Logiciel: Skype™ 7.24 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {FC965A47-4839-40CA-B618-18F486F042C6} =>.Skype Technologies S.A.
O42 - Logiciel: Splashtop Personal - (.Splashtop Inc..) [HKLM][64Bits] -- {E7CF0F14-8C1D-41F3-85ED-579C108262C7} =>.Splashtop Inc.
O42 - Logiciel: Splashtop Software Updater - (.Splashtop Inc..) [HKLM][64Bits] -- Splashtop Software Updater =>.Splashtop Inc.
O42 - Logiciel: TAP-Windows 9.21.1 - (...) [HKLM][64Bits] -- TAP-Windows
O42 - Logiciel: Telegram Desktop version 0.9.51 - (.Telegram Messenger LLP.) [HKCU][64Bits] -- {53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1 =>.Telegram Messenger LLP
O42 - Logiciel: Terminals - (.Robert Chartier.) [HKLM][64Bits] -- {9CA99653-709D-493E-BB16-C32125D94138}
O42 - Logiciel: tools-freebsd - (.VMware, Inc..) [HKLM][64Bits] -- {003BFBBD-6C67-419E-A24D-0DCAFC3A5249} =>.VMware, Inc.
O42 - Logiciel: tools-linux - (.VMware, Inc..) [HKLM][64Bits] -- {D102611A-6466-4101-A51D-51069303AC65} =>.VMware, Inc.
O42 - Logiciel: tools-netware - (.VMware, Inc..) [HKLM][64Bits] -- {197597A7-AD33-4898-9D8E-73066818B464} =>.VMware, Inc.
O42 - Logiciel: tools-solaris - (.VMware, Inc..) [HKLM][64Bits] -- {AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4} =>.VMware, Inc.
O42 - Logiciel: tools-windows - (.VMware, Inc..) [HKLM][64Bits] -- {FFD9383C-01D5-4897-A954-43AF599AED30} =>.VMware, Inc.
O42 - Logiciel: tools-winPre2k - (.VMware, Inc..) [HKLM][64Bits] -- {AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D} =>.VMware, Inc.
O42 - Logiciel: Update for Skype for Business 2015 (KB2889853) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{40930C8E-A677-414C-A72F-DFDEB10738FB} =>.Microsoft Corporation®
O42 - Logiciel: UsbFix - (.El Desaparecido - www.usb-antivirus.com - www.sosvirus.net.) [HKLM][64Bits] -- Usbfix =>.El Desaparecido - www.usb-antivirus.com - www.sosvirus.net
O42 - Logiciel: Visual Studio 2012 x64 Redistributables - (.AVG Technologies.) [HKLM][64Bits] -- {8C775E70-A791-4DA8-BCC3-6AB7136F4484} =>.AVG Technologies
O42 - Logiciel: Visual Studio 2012 x86 Redistributables - (.AVG Technologies CZ, s.r.o..) [HKLM][64Bits] -- {98EFF19A-30AB-4E4B-B943-F06B1C63EBF8} =>.AVG Technologies CZ, s.r.o.
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
O42 - Logiciel: VMware Workstation - (.VMware, Inc.) [HKLM][64Bits] -- VMware_Workstation =>.VMware, Inc
O42 - Logiciel: VMware Workstation - (.VMware, Inc..) [HKLM][64Bits] -- {0D94F75A-0EA6-4951-B3AF-B145FA9E05C6} =>.VMware, Inc.
O42 - Logiciel: Windows Driver Package - ASUS (ATP) Mouse (11/11/2015 1.0.0.262) - (.ASUS.) [HKLM][64Bits] -- A044C5901003C24E6891688653ABA1068D04A1A0 =>.ASUSTeK Computer Inc.®
O42 - Logiciel: Windows Driver Package - BigNox Corporation (VBoxUSB) USB (09/16/2015 4.3. - (.BigNox Corporation.) [HKLM][64Bits] -- 76B144D15273552931249392EDB13C0BBD52C84E =>.Duodian Online Technology Co. Ltd.®
O42 - Logiciel: Windows Driver Package - BigNox Corporation VBoxUSBMon System (09/16/2015 - (.BigNox Corporation.) [HKLM][64Bits] -- 39F54A37125643D2E1E90FA7D81F36ACC9441510 =>.Duodian Online Technology Co. Ltd.®
O42 - Logiciel: Windows Driver Package - BigNox Corporation XQHDrv System (09/16/2015 4.3. - (.BigNox Corporation.) [HKLM][64Bits] -- 0147813640F7AF69F569581EE672B6BE1E71798E =>.Duodian Online Technology Co. Ltd.®
O42 - Logiciel: WinHTTrack Website Copier 3.48-21 (x64) - (.HTTrack.) [HKLM][64Bits] -- WinHTTrack Website Copier_is1 =>.Open Source Developer, httrack.com®
O42 - Logiciel: WinRAR 5.30 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver =>.win.rar GmbH®
O42 - Logiciel: WinSCP 5.7.6 - (.Martin Prikryl.) [HKLM][64Bits] -- winscp3_is1 =>.Martin Prikryl®
O42 - Logiciel: Your Uninstaller! 7 - (.URSoft, Inc..) [HKLM][64Bits] -- YU2010_is1
O42 - Logiciel: YouWave for Android - (.YouWave Inc..) [HKLM][64Bits] -- YouWave

---\\ HKCU & HKLM Software Keys (119) - 32s
HKLM\SOFTWARE\Wow6432Node\Adobe
HKLM\SOFTWARE\Wow6432Node\AGEIA Technologies
HKLM\SOFTWARE\Wow6432Node\Apple Inc.
HKLM\SOFTWARE\Wow6432Node\ASIO
HKLM\SOFTWARE\Wow6432Node\AsLdr
HKLM\SOFTWARE\Wow6432Node\ASUS
HKLM\SOFTWARE\Wow6432Node\Atheros
HKLM\SOFTWARE\Wow6432Node\AVG
HKLM\SOFTWARE\Wow6432Node\BigNox
HKLM\SOFTWARE\Wow6432Node\BlueStacks
HKLM\SOFTWARE\Wow6432Node\BlueStacksGameManager
HKLM\SOFTWARE\Wow6432Node\DuoDianOnline
HKLM\SOFTWARE\Wow6432Node\ESET
HKLM\SOFTWARE\Wow6432Node\FileZilla 3
HKLM\SOFTWARE\Wow6432Node\FileZilla Client
HKLM\SOFTWARE\Wow6432Node\Google
HKLM\SOFTWARE\Wow6432Node\HaaliMkx
HKLM\SOFTWARE\Wow6432Node\Huawei technologies
HKLM\SOFTWARE\Wow6432Node\Icaros
HKLM\SOFTWARE\Wow6432Node\IM Providers
HKLM\SOFTWARE\Wow6432Node\Intel
HKLM\SOFTWARE\Wow6432Node\Internet Download Manager
HKLM\SOFTWARE\Wow6432Node\iOpus
HKLM\SOFTWARE\Wow6432Node\Ipswitch
HKLM\SOFTWARE\Wow6432Node\JavaSoft
HKLM\SOFTWARE\Wow6432Node\JreMetrics
HKLM\SOFTWARE\Wow6432Node\Khronos
HKLM\SOFTWARE\Wow6432Node\KLCodecPack
HKLM\SOFTWARE\Wow6432Node\LAV
HKLM\SOFTWARE\Wow6432Node\Licenses
HKLM\SOFTWARE\Wow6432Node\Macromedia
HKLM\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware
HKLM\SOFTWARE\Wow6432Node\Martin Prikryl
HKLM\SOFTWARE\Wow6432Node\Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\Notepad++
HKLM\SOFTWARE\Wow6432Node\Nuance
HKLM\SOFTWARE\Wow6432Node\NVIDIA Corporation
HKLM\SOFTWARE\Wow6432Node\ODBC
HKLM\SOFTWARE\Wow6432Node\PowerPivot
HKLM\SOFTWARE\Wow6432Node\Qualcomm Atheros
HKLM\SOFTWARE\Wow6432Node\Realtek
HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\Rockstar Games
HKLM\SOFTWARE\Wow6432Node\RSystem64
HKLM\SOFTWARE\Wow6432Node\Skillbrains =>PUP.Optional.Skillbrains
HKLM\SOFTWARE\Wow6432Node\Skype
HKLM\SOFTWARE\Wow6432Node\SOSVirus
HKLM\SOFTWARE\Wow6432Node\Splashtop Inc.
HKLM\SOFTWARE\Wow6432Node\SRS Labs
HKLM\SOFTWARE\Wow6432Node\SuppHelpDir
HKLM\SOFTWARE\Wow6432Node\TeamViewer
HKLM\SOFTWARE\Wow6432Node\TechSmith
HKLM\SOFTWARE\Wow6432Node\ThinPrint
HKLM\SOFTWARE\Wow6432Node\TuneUp
HKLM\SOFTWARE\Wow6432Node\TVInstallTemp
HKLM\SOFTWARE\Wow6432Node\VideoLAN
HKLM\SOFTWARE\Wow6432Node\VMware, Inc.
HKLM\SOFTWARE\Wow6432Node\Volatile
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\ASUS
HKCU\SOFTWARE\Atheros
HKCU\SOFTWARE\AVG
HKCU\SOFTWARE\BitTorrent
HKCU\SOFTWARE\BreakPoint
HKCU\SOFTWARE\BreakPoint License Manager
HKCU\SOFTWARE\CHEMINAIS
HKCU\SOFTWARE\Corner Stone Research
HKCU\SOFTWARE\DownloadManager
HKCU\SOFTWARE\ESET
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\Haali
HKCU\SOFTWARE\Icaros
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\iMacros
HKCU\SOFTWARE\Intel
HKCU\SOFTWARE\Ipswitch
HKCU\SOFTWARE\JavaSoft
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\madshi
HKCU\SOFTWARE\MainConcept
HKCU\SOFTWARE\Martin Prikryl
HKCU\SOFTWARE\MediaInfo
HKCU\SOFTWARE\Mine
HKCU\SOFTWARE\Mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\MPC-HC
HKCU\SOFTWARE\Netscape
HKCU\SOFTWARE\Nilings
HKCU\SOFTWARE\NVIDIA Corporation
HKCU\SOFTWARE\ODBC
HKCU\SOFTWARE\QtProject
HKCU\SOFTWARE\Realtek
HKCU\SOFTWARE\RegisteredApplications
HKCU\SOFTWARE\Robert Chartier
HKCU\SOFTWARE\RSystem64
HKCU\SOFTWARE\SimonTatham
HKCU\SOFTWARE\SkillBrains =>PUP.Optional.Skillbrains
HKCU\SOFTWARE\Skype
HKCU\SOFTWARE\Splashtop Inc.
HKCU\SOFTWARE\SyncEngines
HKCU\SOFTWARE\TeamViewer
HKCU\SOFTWARE\TechSmith
HKCU\SOFTWARE\Trolltech
HKCU\SOFTWARE\URSoft
HKCU\SOFTWARE\UsbFix
HKCU\SOFTWARE\VMware, Inc.
HKCU\SOFTWARE\WinHTTrack Website Copier
HKCU\SOFTWARE\WinRAR
HKCU\SOFTWARE\WinRAR SFX
HKCU\SOFTWARE\Wow6432Node
HKCU\SOFTWARE\YouWave Android
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\AppDataLow\Software
HKCU\SOFTWARE\AppDataLow\Software\JavaSoft
HKCU\SOFTWARE\AppDataLow\Software\ThinPrint

---\\ Contents of the Common Files folders (279) - 63s
O43 - CFD: 22/05/2016 - [] D -- C:\Program Files\Bignox
O43 - CFD: 11/03/2016 - [] D -- C:\Program Files\BreakPoint Software {0AC3CF34686D1BFF5FC6519BD737B0C5}
O43 - CFD: 14/02/2016 - [] D -- C:\Program Files\Common Files
O43 - CFD: 22/05/2016 - [] D -- C:\Program Files\DIFX =>.Duodian Online Technology Co. Ltd.®
O43 - CFD: 17/06/2016 - [] D -- C:\Program Files\DriversCloud.com =>.CYBELSOFT®
O43 - CFD: 29/11/2015 - [] D -- C:\Program Files\ESET =>.ESET, spol. s r.o.®
O43 - CFD: 14/02/2016 - [] D -- C:\Program Files\Intel =>.Intel® Trusted Connect Service®
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files\Internet Explorer
O43 - CFD: 20/12/2015 - [] D -- C:\Program Files\Ipswitch {036F562E1D233FA28EFB3F83CA4897A1}
O43 - CFD: 26/03/2016 - [] AD -- C:\Program Files\KMSpico =>HackTool.KMSpico
O43 - CFD: 29/11/2015 - [] D -- C:\Program Files\Microsoft Analysis Services =>.Microsoft Corporation®
O43 - CFD: 29/11/2015 - [] AD -- C:\Program Files\Microsoft Office =>.Microsoft Corporation®
O43 - CFD: 29/11/2015 - [] D -- C:\Program Files\Microsoft SQL Server
O43 - CFD: 17/06/2016 - [] D -- C:\Program Files\Microsoft Xbox 360 Accessories =>.Microsoft Corporation®
O43 - CFD: 14/02/2016 - [] D -- C:\Program Files\Microsoft.NET
O43 - CFD: 15/02/2016 - [] D -- C:\Program Files\MSBuild
O43 - CFD: 14/02/2016 - [] D -- C:\Program Files\NVIDIA Corporation =>.NVIDIA Corporation®
O43 - CFD: 12/01/2016 - [] D -- C:\Program Files\OpenVPN
O43 - CFD: 14/02/2016 - [] D -- C:\Program Files\Realtek =>.Andrea Electronics®
O43 - CFD: 15/02/2016 - [] D -- C:\Program Files\Reference Assemblies
O43 - CFD: 27/03/2016 - [] D -- C:\Program Files\Rockstar Games =>.Take-Two Interactive Software, Inc.®
O43 - CFD: 12/01/2016 - [] D -- C:\Program Files\TAP-Windows
O43 - CFD: 22/08/2013 - [0] HD -- C:\Program Files\Uninstall Information
O43 - CFD: 30/10/2015 - [] D -- C:\Program Files\Windows Defender
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files\Windows Journal
O43 - CFD: 30/10/2015 - [] D -- C:\Program Files\Windows Mail
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files\Windows Media Player
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files\Windows Multimedia Platform
O43 - CFD: 30/10/2015 - [] D -- C:\Program Files\Windows NT
O43 - CFD: 30/10/2015 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation®
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files\Windows Portable Devices
O43 - CFD: 30/10/2015 - [] SHD -- C:\Program Files\Windows Sidebar
O43 - CFD: 16/04/2016 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation®
O43 - CFD: 30/10/2015 - [] SD -- C:\Program Files\WindowsPowerShell
O43 - CFD: 25/01/2016 - [] AD -- C:\Program Files\WinHTTrack
O43 - CFD: 28/11/2015 - [] AD -- C:\Program Files\WinRAR =>.win.rar GmbH®
O43 - CFD: 27/11/2015 - [0] D -- C:\Program Files (x86)\AGEIA Technologies
O43 - CFD: 21/02/2016 - [] D -- C:\Program Files (x86)\ASUS =>.ASUSTeK Computer Inc.®
O43 - CFD: 12/04/2016 - [] D -- C:\Program Files (x86)\AVG =>.AVG Technologies CZ, s.r.o.®
O43 - CFD: 09/02/2016 - [] AD -- C:\Program Files (x86)\BlueStacks
O43 - CFD: 14/02/2016 - [] AD -- C:\Program Files (x86)\Bluetooth Suite
O43 - CFD: 03/05/2016 - [] D -- C:\Program Files (x86)\Common Files
O43 - CFD: 24/06/2016 - [] AD -- C:\Program Files (x86)\FileZilla FTP Client =>.Tim Kosse®
O43 - CFD: 04/05/2016 - [] D -- C:\Program Files (x86)\Google =>.Google Inc®
O43 - CFD: 11/03/2016 - [] AD -- C:\Program Files (x86)\HxD
O43 - CFD: 27/11/2015 - [] D -- C:\Program Files (x86)\ICEpower =>.ICEpower a/s®
O43 - CFD: 27/11/2015 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.Realtek Semiconductor Corp®
O43 - CFD: 27/11/2015 - [] D -- C:\Program Files (x86)\Intel =>.Intel Corporation - pGFX®
O43 - CFD: 02/06/2016 - [] D -- C:\Program Files (x86)\Internet Download Manager
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files (x86)\Internet Explorer
O43 - CFD: 20/12/2015 - [] D -- C:\Program Files (x86)\Ipswitch {036F562E1D233FA28EFB3F83CA4897A1}
O43 - CFD: 25/04/2016 - [] D -- C:\Program Files (x86)\Java =>.Oracle America, Inc.®
O43 - CFD: 01/12/2015 - [] AD -- C:\Program Files (x86)\K-Lite Codec Pack
O43 - CFD: 26/03/2016 - [] AD -- C:\Program Files (x86)\Malwarebytes Anti-Malware =>.Malwarebytes Corporation®
O43 - CFD: 29/11/2015 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services =>.Microsoft Corporation®
O43 - CFD: 29/11/2015 - [] D -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation®
O43 - CFD: 29/11/2015 - [] D -- C:\Program Files (x86)\Microsoft SQL Server
O43 - CFD: 14/02/2016 - [] AD -- C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 18/02/2016 - [] D -- C:\Program Files (x86)\Mobile Partner =>.HUAWEI Technologies Co., Ltd.®
O43 - CFD: 09/02/2016 - [] AD -- C:\Program Files (x86)\MouseRecorder {11211BB60A8D3623516581689603FB6C9880}
O43 - CFD: 13/06/2016 - [] D -- C:\Program Files (x86)\Mozilla Firefox =>.Mozilla Corporation®
O43 - CFD: 13/06/2016 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service =>.Mozilla Corporation®
O43 - CFD: 15/02/2016 - [] D -- C:\Program Files (x86)\MSBuild
O43 - CFD: 01/12/2015 - [] D -- C:\Program Files (x86)\Notepad++
O43 - CFD: 27/11/2015 - [] D -- C:\Program Files (x86)\NVIDIA Corporation =>.NVIDIA Corporation®
O43 - CFD: 27/11/2015 - [] AD -- C:\Program Files (x86)\Qualcomm Atheros
O43 - CFD: 03/05/2016 - [] D -- C:\Program Files (x86)\QuickTime =>Riskware.QuickTime
O43 - CFD: 27/11/2015 - [] D -- C:\Program Files (x86)\Realtek =>.Realtek Semiconductor Corp®
O43 - CFD: 15/02/2016 - [] D -- C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 27/03/2016 - [] D -- C:\Program Files (x86)\Rockstar Games =>.Take-Two Interactive Software, Inc.®
O43 - CFD: 22/01/2016 - [] D -- C:\Program Files (x86)\Skillbrains =>PUP.Optional.Skillbrains
O43 - CFD: 02/06/2016 - [] RD -- C:\Program Files (x86)\Skype =>.Skype Software Sarl®
O43 - CFD: 05/06/2016 - [] D -- C:\Program Files (x86)\Splashtop =>.Splashtop Inc.®
O43 - CFD: 04/06/2016 - [] AD -- C:\Program Files (x86)\TeamViewer
O43 - CFD: 03/05/2016 - [] D -- C:\Program Files (x86)\TechSmith {0405D56C46C5C7254AC1464FC2CF4A1F}
O43 - CFD: 27/11/2015 - [0] HD -- C:\Program Files (x86)\Temp
O43 - CFD: 02/12/2015 - [] AD -- C:\Program Files (x86)\Terminals
O43 - CFD: 14/02/2016 - [0] HD -- C:\Program Files (x86)\Uninstall Information
O43 - CFD: 10/01/2016 - [] AD -- C:\Program Files (x86)\uTorrent =>.BitTorrent Inc®
O43 - CFD: 26/04/2016 - [] D -- C:\Program Files (x86)\VideoLAN
O43 - CFD: 28/11/2015 - [] AD -- C:\Program Files (x86)\VMware =>.VMware, Inc.®
O43 - CFD: 30/10/2015 - [] D -- C:\Program Files (x86)\Windows Defender
O43 - CFD: 30/10/2015 - [] D -- C:\Program Files (x86)\Windows Mail
O43 - CFD: 30/10/2015 - [] D -- C:\Program Files (x86)\Windows Media Player
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform
O43 - CFD: 30/10/2015 - [] D -- C:\Program Files (x86)\Windows NT
O43 - CFD: 30/10/2015 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation®
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 30/10/2015 - [] SHD -- C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 30/10/2015 - [] SD -- C:\Program Files (x86)\WindowsPowerShell
O43 - CFD: 01/12/2015 - [] AD -- C:\Program Files (x86)\WinSCP =>.Martin Prikryl®
O43 - CFD: 09/02/2016 - [] AD -- C:\Program Files (x86)\Your Uninstaller! 7
O43 - CFD: 09/02/2016 - [] D -- C:\Program Files (x86)\YouWave Android
O43 - CFD: 30/10/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 30/10/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 30/10/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
O43 - CFD: 17/06/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriversCloud.com
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
O43 - CFD: 19/06/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
O43 - CFD: 27/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GMT-MAX.ORG
O43 - CFD: 11/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hex Workshop v6.8
O43 - CFD: 11/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICEpower
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iMacros
O43 - CFD: 14/02/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
O43 - CFD: 25/04/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
O43 - CFD: 26/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico =>HackTool.KMSpico
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
O43 - CFD: 30/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 26/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
O43 - CFD: 17/06/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Xbox 360 Accessories
O43 - CFD: 18/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mobile Partner
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MouseRecorder
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
O43 - CFD: 27/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rental Management
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
O43 - CFD: 05/06/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Splashtop Remote
O43 - CFD: 30/10/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
O43 - CFD: 30/10/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 30/10/2015 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TAP-Windows
O43 - CFD: 03/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Terminals
O43 - CFD: 26/04/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinHTTrack
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Your Uninstaller! 7
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouWave Android
O43 - CFD: 14/02/2016 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 29/06/2016 - [] D -- C:\ProgramData\ASUS Smart Gesture
O43 - CFD: 27/11/2015 - [] D -- C:\ProgramData\Atheros
O43 - CFD: 12/04/2016 - [] AD -- C:\ProgramData\Avg
O43 - CFD: 09/02/2016 - [] AD -- C:\ProgramData\BlueStacks
O43 - CFD: 09/02/2016 - [] D -- C:\ProgramData\BlueStacksGameManager
O43 - CFD: 13/06/2016 - [] D -- C:\ProgramData\BlueStacksSetup
O43 - CFD: 29/06/2016 - [0] D -- C:\ProgramData\Client
O43 - CFD: 12/04/2016 - [] HD -- C:\ProgramData\Common Files
O43 - CFD: 30/10/2015 - [0] D -- C:\ProgramData\Comms
O43 - CFD: 01/05/2016 - [] D -- C:\ProgramData\DataCardService
O43 - CFD: 14/02/2016 - [0] SHD -- C:\ProgramData\Desktop
O43 - CFD: 14/02/2016 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 17/06/2016 - [] D -- C:\ProgramData\DriversCloud.com
O43 - CFD: 29/11/2015 - [] D -- C:\ProgramData\ESET
O43 - CFD: 28/11/2015 - [0] D -- C:\ProgramData\IDM
O43 - CFD: 27/11/2015 - [] D -- C:\ProgramData\Intel
O43 - CFD: 27/05/2016 - [] D -- C:\ProgramData\Jsoft.fr
O43 - CFD: 29/11/2015 - [] D -- C:\ProgramData\Malwarebytes
O43 - CFD: 14/02/2016 - [] SD -- C:\ProgramData\Microsoft
O43 - CFD: 30/11/2015 - [] D -- C:\ProgramData\Microsoft Help
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\Microsoft OneDrive
O43 - CFD: 12/01/2016 - [] D -- C:\ProgramData\Mobile Partner =>Toolbar.YahooPartner
O43 - CFD: 28/11/2015 - [] D -- C:\ProgramData\MobileBrServ
O43 - CFD: 09/02/2016 - [0] D -- C:\ProgramData\MouseRecorder
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\NVIDIA
O43 - CFD: 14/02/2016 - [] D -- C:\ProgramData\NVIDIA Corporation
O43 - CFD: 25/04/2016 - [] D -- C:\ProgramData\Oracle
O43 - CFD: 27/03/2016 - [] D -- C:\ProgramData\Package Cache
O43 - CFD: 27/11/2015 - [] D -- C:\ProgramData\Qualcomm Atheros
O43 - CFD: 14/02/2016 - [] AD -- C:\ProgramData\regid.1991-06.com.microsoft
O43 - CFD: 03/05/2016 - [] AD -- C:\ProgramData\regid.1995-08.com.techsmith
O43 - CFD: 21/02/2016 - [] D -- C:\ProgramData\SetupTPDriver
O43 - CFD: 02/06/2016 - [] D -- C:\ProgramData\Skype
O43 - CFD: 27/03/2016 - [] D -- C:\ProgramData\Socialclub
O43 - CFD: 18/02/2016 - [] D -- C:\ProgramData\SoftwareDistribution
O43 - CFD: 05/06/2016 - [] D -- C:\ProgramData\Splashtop
O43 - CFD: 14/02/2016 - [0] SHD -- C:\ProgramData\Start Menu
O43 - CFD: 27/03/2016 - [] D -- C:\ProgramData\Steam
O43 - CFD: 03/05/2016 - [] AD -- C:\ProgramData\TechSmith
O43 - CFD: 09/02/2016 - [0] AD -- C:\ProgramData\TEMP
O43 - CFD: 14/02/2016 - [0] SHD -- C:\ProgramData\Templates
O43 - CFD: 27/11/2015 - [] D -- C:\ProgramData\USBChargerPlus
O43 - CFD: 15/02/2016 - [] D -- C:\ProgramData\USOPrivate
O43 - CFD: 15/02/2016 - [] D -- C:\ProgramData\USOShared
O43 - CFD: 29/06/2016 - [] AD -- C:\ProgramData\VMware
O43 - CFD: 16/03/2016 - [] D -- C:\Program Files (x86)\Common Files\Adobe
O43 - CFD: 27/11/2015 - [] D -- C:\Program Files (x86)\Common Files\Atheros
O43 - CFD: 14/02/2016 - [] D -- C:\Program Files (x86)\Common Files\Intel
O43 - CFD: 25/04/2016 - [] D -- C:\Program Files (x86)\Common Files\Java
O43 - CFD: 14/02/2016 - [] AD -- C:\Program Files (x86)\Common Files\Microsoft Shared
O43 - CFD: 27/11/2015 - [] D -- C:\Program Files (x86)\Common Files\PostureAgent
O43 - CFD: 30/10/2015 - [] D -- C:\Program Files (x86)\Common Files\Services
O43 - CFD: 12/03/2016 - [] AD -- C:\Program Files (x86)\Common Files\Skype
O43 - CFD: 30/10/2015 - [] D -- C:\Program Files (x86)\Common Files\System
O43 - CFD: 03/05/2016 - [] D -- C:\Program Files (x86)\Common Files\TechSmith Shared
O43 - CFD: 28/11/2015 - [] D -- C:\Program Files (x86)\Common Files\VMware
O43 - CFD: 19/05/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\Adobe
O43 - CFD: 27/11/2015 - [] D -- C:\Users\salamouna2\AppData\Roaming\Atheros
O43 - CFD: 28/03/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\Audacity
O43 - CFD: 14/04/2016 - [0] D -- C:\Users\salamouna2\AppData\Roaming\AVG
O43 - CFD: 29/06/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\DMCache
O43 - CFD: 29/06/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\FileZilla
O43 - CFD: 09/02/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\gtk-2.0
O43 - CFD: 14/06/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\IDM
O43 - CFD: 27/05/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\Jsoft.fr
O43 - CFD: 08/05/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\KompoZer
O43 - CFD: 20/12/2015 - [] D -- C:\Users\salamouna2\AppData\Roaming\Macromedia
O43 - CFD: 11/03/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\Mael
O43 - CFD: 28/05/2016 - [] SD -- C:\Users\salamouna2\AppData\Roaming\Microsoft
O43 - CFD: 29/06/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\Monitor
O43 - CFD: 09/02/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\Mouse Recorder
O43 - CFD: 11/03/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\Mozilla
O43 - CFD: 01/12/2015 - [] D -- C:\Users\salamouna2\AppData\Roaming\MPC-HC
O43 - CFD: 01/12/2015 - [] D -- C:\Users\salamouna2\AppData\Roaming\Notepad++
O43 - CFD: 22/05/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\Nox
O43 - CFD: 29/06/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\Skype
O43 - CFD: 19/02/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\Sun
O43 - CFD: 04/06/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\TeamViewer
O43 - CFD: 03/01/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\TechSmith
O43 - CFD: 27/06/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\Telegram Desktop
O43 - CFD: 28/01/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\U3
O43 - CFD: 09/02/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\URSoft
O43 - CFD: 30/05/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\uTorrent
O43 - CFD: 28/05/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\vlc
O43 - CFD: 14/05/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\VMware
O43 - CFD: 28/11/2015 - [] D -- C:\Users\salamouna2\AppData\Roaming\WinRAR
O43 - CFD: 29/06/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\ZHP
O43 - CFD: 14/02/2016 - [0] D -- C:\Users\salamouna2\AppData\Local\ActiveSync
O43 - CFD: 10/05/2016 - [] D -- C:\Users\salamouna2\AppData\Local\Adobe
O43 - CFD: 14/02/2016 - [0] SHD -- C:\Users\salamouna2\AppData\Local\Application Data
O43 - CFD: 28/03/2016 - [] D -- C:\Users\salamouna2\AppData\Local\Audacity
O43 - CFD: 12/04/2016 - [] D -- C:\Users\salamouna2\AppData\Local\Avg
O43 - CFD: 12/04/2016 - [] D -- C:\Users\salamouna2\AppData\Local\AvgSetupLog
O43 - CFD: 27/11/2015 - [] D -- C:\Users\salamouna2\AppData\Local\BMExplorer
O43 - CFD: 14/02/2016 - [] D -- C:\Users\salamouna2\AppData\Local\Comms
O43 - CFD: 29/06/2016 - [] D -- C:\Users\salamouna2\AppData\Local\CrashDumps
O43 - CFD: 23/06/2016 - [] D -- C:\Users\salamouna2\AppData\Local\Diagnostics
O43 - CFD: 27/11/2015 - [] D -- C:\Users\salamouna2\AppData\Local\Downloaded Installations
O43 - CFD: 27/12/2015 - [0] SHD -- C:\Users\salamouna2\AppData\Local\EmieBrowserModeList
O43 - CFD: 27/12/2015 - [0] SHD -- C:\Users\salamouna2\AppData\Local\EmieSiteList
O43 - CFD: 27/12/2015 - [0] SHD -- C:\Users\salamouna2\AppData\Local\EmieUserList
O43 - CFD: 29/11/2015 - [] D -- C:\Users\salamouna2\AppData\Local\ESET
O43 - CFD: 11/03/2016 - [] D -- C:\Users\salamouna2\AppData\Local\Google
O43 - CFD: 01/12/2015 - [] D -- C:\Users\salamouna2\AppData\Local\GWX
O43 - CFD: 14/02/2016 - [0] SHD -- C:\Users\salamouna2\AppData\Local\History
O43 - CFD: 04/03/2016 - [] D -- C:\Users\salamouna2\AppData\Local\Microsoft
O43 - CFD: 13/06/2016 - [] D -- C:\Users\salamouna2\AppData\Local\Microsoft Help
O43 - CFD: 15/02/2016 - [] D -- C:\Users\salamouna2\AppData\Local\MicrosoftEdge
O43 - CFD: 28/11/2015 - [] D -- C:\Users\salamouna2\AppData\Local\Mozilla
O43 - CFD: 14/02/2016 - [0] D -- C:\Users\salamouna2\AppData\Local\NetworkTiles
O43 - CFD: 13/06/2016 - [] D -- C:\Users\salamouna2\AppData\Local\Nox
O43 - CFD: 27/11/2015 - [] D -- C:\Users\salamouna2\AppData\Local\NVIDIA
O43 - CFD: 22/06/2016 - [] D -- C:\Users\salamouna2\AppData\Local\Packages
O43 - CFD: 29/11/2015 - [] D -- C:\Users\salamouna2\AppData\Local\Programs
O43 - CFD: 14/02/2016 - [] D -- C:\Users\salamouna2\AppData\Local\Publishers
O43 - CFD: 03/12/2015 - [] D -- C:\Users\salamouna2\AppData\Local\Robert_Chartier
O43 - CFD: 27/03/2016 - [] D -- C:\Users\salamouna2\AppData\Local\Rockstar Games
O43 - CFD: 29/12/2015 - [0] D -- C:\Users\salamouna2\AppData\Local\Skype
O43 - CFD: 03/01/2016 - [] D -- C:\Users\salamouna2\AppData\Local\TechSmith
O43 - CFD: 29/06/2016 - [] D -- C:\Users\salamouna2\AppData\Local\Temp
O43 - CFD: 14/02/2016 - [0] SHD -- C:\Users\salamouna2\AppData\Local\Temporary Internet Files
O43 - CFD: 14/02/2016 - [] D -- C:\Users\salamouna2\AppData\Local\TileDataLayer
O43 - CFD: 27/11/2015 - [0] D -- C:\Users\salamouna2\AppData\Local\VirtualStore
O43 - CFD: 14/05/2016 - [] D -- C:\Users\salamouna2\AppData\Local\VMware
O43 - CFD: 29/11/2015 - [0] D -- C:\Users\salamouna2\AppData\Local\Programs\Common
O43 - CFD: 30/10/2015 - [] RD -- C:\Users\salamouna2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 14/02/2016 - [] RD -- C:\Users\salamouna2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 16/03/2016 - [] RD -- C:\Users\salamouna2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 14/02/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
O43 - CFD: 30/10/2015 - [] D -- C:\Users\salamouna2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 01/12/2015 - [0] D -- C:\Users\salamouna2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
O43 - CFD: 16/03/2016 - [] RD -- C:\Users\salamouna2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 30/10/2015 - [] RD -- C:\Users\salamouna2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 22/06/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop
O43 - CFD: 30/10/2015 - [] RSD -- C:\Users\salamouna2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
O43 - CFD: 14/02/2016 - [] D -- C:\Users\salamouna2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 12/04/2016 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Avg
O43 - CFD: 0 - [0] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\CrashDumps
O43 - CFD: 0 - [0] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\DataSharing
O43 - CFD: 0 - [0] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\ESET
O43 - CFD: 15/02/2016 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Microsoft
O43 - CFD: 0 - [0] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Packages

---\\ ShellIconOverlayIdentifiers (SIOI) (8) - 1s
O106 - SIOI: ErrorOverlayHandler Class [ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SharedOverlayHandler Class [ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SharedSyncingOverlayHandler Class [ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: UpToDateOverlayHandler Class [ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SyncingOverlayHandler Class [ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\salamouna2\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) [ SkyDrivePro1 (ErrorConflict)] - {8BA85C75-763B-4103-94EB-9470F12FE0F7}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) [ SkyDrivePro2 (SyncInProgress)] - {CD55129A-B1A1-438E-A425-CEBC7DC684EE}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 3 (InSync) [ SkyDrivePro3 (InSync)] - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL =>.Microsoft Corporation®

---\\ System Drivers List (96) - 20s
O58 - SDL:2015/10/30 08:17:22 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107360] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:22 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135456] =>.Microsoft Windows®
O58 - SDL:2014/09/11 16:48:20 A . (.ASUSTek Computer Inc. - ASUS Charger driver.) -- C:\WINDOWS\System32\drivers\AiCharger.sys [17152] =>.ASUSTeK Computer Inc.®
O58 - SDL:2015/10/30 08:17:22 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [83296] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:22 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259424] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:22 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [26976] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:22 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [131936] =>.Microsoft Windows®
O58 - SDL:2015/05/13 05:44:24 A . (.ASUS - HID driver for ASUS Wireless Radio Control.) -- C:\WINDOWS\System32\drivers\AsHIDSwitch64.sys [19976] =>.Microsoft Windows Hardware Compatibility Publisher®
O58 - SDL:2015/12/14 14:45:00 A . (.ASUS Corporation - Asus TP Filter Driver(X64).) -- C:\WINDOWS\System32\drivers\AsusTP.sys [101368] =>.ASUSTeK Computer Inc.®
O58 - SDL:2015/06/26 17:23:54 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\drivers\athw10x.sys [4325544] =>.WDKTestCert qcaswbld,130129545209614653®
O58 - SDL:2015/10/30 08:17:22 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn.sys [9728] =>.Windows (R) Win 7 DDK provider
O58 - SDL:2015/10/30 08:17:22 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [9728] =>.Windows (R) Win 7 DDK provider
O58 - SDL:2014/09/28 21:59:20 A . (.Qualcomm Atheros - Qualcomm Atheros BUS driver.) -- C:\WINDOWS\System32\drivers\btath_bus.sys [35016] =>.Qualcomm Atheros®
O58 - SDL:2015/06/29 11:22:38 A . (.Qualcomm Atheros - Qualcomm Atheros BtFilter Driver.) -- C:\WINDOWS\System32\drivers\btfilter.sys [609992] =>.Qualcomm Atheros®
O58 - SDL:2015/10/30 08:17:22 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [531296] =>.Microsoft Windows®
O58 - SDL:2014/09/18 19:36:14 A . (.Intel Corporation - DPTF ACPI Device (32-Bit).) -- C:\WINDOWS\System32\drivers\dptf_cpu.sys [38720] =>.Intel(R) Software®
O58 - SDL:2014/09/18 19:36:14 A . (.Intel Corporation - DPTF ACPI Device (64-Bit).) -- C:\WINDOWS\System32\drivers\dptf_pch.sys [38208] =>.Intel(R) Software®
O58 - SDL:2016/03/19 14:10:01 A . (.ESET - Amon monitor.) -- C:\WINDOWS\System32\drivers\eamonm.sys [264552] =>.ESET, spol. s r.o.®
O58 - SDL:2015/07/30 12:41:36 A . (.ESET - ESET ELAM driver.) -- C:\WINDOWS\System32\drivers\eelam.sys [14976] =>.Microsoft Windows Early Launch Anti-malware Publisher®
O58 - SDL:2016/02/02 14:04:50 A . (.ESET - ESET Helper driver.) -- C:\WINDOWS\System32\drivers\ehdrv.sys [186784] =>.ESET, spol. s r.o.®
O58 - SDL:2016/02/02 14:04:50 A . (.ESET - ESET OPP Keyboard Filter.) -- C:\WINDOWS\System32\drivers\ekbdflt.sys [142976] =>.ESET, spol. s r.o.®
O58 - SDL:2016/03/19 14:10:01 A . (.ESET - ESET Personal Firewall driver.) -- C:\WINDOWS\System32\drivers\epfw.sys [198096] =>.ESET, spol. s r.o.®
O58 - SDL:2016/03/19 14:10:01 A . (.ESET - Epfw NDIS LightWeight Filter.) -- C:\WINDOWS\System32\drivers\epfwlwf.sys [53384] =>.ESET, spol. s r.o.®
O58 - SDL:2016/03/19 14:10:01 A . (.ESET - ESET Personal Firewall driver.) -- C:\WINDOWS\System32\drivers\epfwwfp.sys [84800] =>.ESET, spol. s r.o.®
O58 - SDL:2014/09/18 19:36:20 A . (.Intel Corporation - DPTF ACPI Device (64-Bit).) -- C:\WINDOWS\System32\drivers\esif_lf.sys [216360] =>.Intel(R) Software®
O58 - SDL:2015/10/30 08:17:22 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3436896] =>.Microsoft Windows®
O58 - SDL:2010/10/08 09:59:40 A . (.Huawei Tech. Co., Ltd. - HUAWEI USB Smart Card Driver.) -- C:\WINDOWS\System32\drivers\ewdcsc.sys [32768] =>.Huawei Tech. Co., Ltd.
O58 - SDL:2011/12/31 02:20:58 A . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\WINDOWS\System32\drivers\ewusbmdm.sys [225920] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2012/12/03 11:40:56 A . (.Huawei Technologies Co., Ltd. - USB NDIS Miniport Driver.) -- C:\WINDOWS\System32\drivers\ewusbwwan.sys [452608] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2010/09/26 11:09:28 A . (.Huawei Technologies Co., Ltd. - ew_hwupgrade Driver.) -- C:\WINDOWS\System32\drivers\ew_hwupgrade.sys [22016] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2010/07/27 02:52:16 A . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\WINDOWS\System32\drivers\ew_hwusbdev.sys [117248] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2012/08/20 01:55:56 A . (.Huawei Technologies Co., Ltd. - ew_jubusenum Driver.) -- C:\WINDOWS\System32\drivers\ew_jubusenum.sys [90112] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2012/08/20 01:55:56 A . (.Huawei Technologies Co., Ltd. - ew_jucdcacm Driver.) -- C:\WINDOWS\System32\drivers\ew_jucdcacm.sys [104960] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2012/10/29 12:44:32 A . (.Huawei Technologies Co., Ltd. - ew_jucdcndis Driver.) -- C:\WINDOWS\System32\drivers\ew_jucdcecm.sys [76800] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2012/08/20 01:55:56 A . (.Huawei Technologies Co., Ltd. - ew_juextctrl Driver.) -- C:\WINDOWS\System32\drivers\ew_juextctrl.sys [30720] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2012/12/03 12:22:48 A . (.Huawei Technologies Co., Ltd. - ew_jucdcndis Driver.) -- C:\WINDOWS\System32\drivers\ew_juwwanecm.sys [241152] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2012/10/30 05:42:28 A . (.Huawei Technologies Co., Ltd. - Filter Driver.) -- C:\WINDOWS\System32\drivers\ew_usbenumfilter.sys [14336] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2016/01/12 15:13:32 A . (.Flash Card. - Flash Card USB Device Driver.) -- C:\WINDOWS\System32\drivers\FcSerial.sys [221568]
O58 - SDL:2014/02/27 18:40:32 A . (.VMware, Inc. - VMware USB monitor.) -- C:\WINDOWS\System32\drivers\hcmon.sys [54464] =>.VMware, Inc.®
O58 - SDL:2015/10/30 08:17:22 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64352] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:18 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) -- C:\WINDOWS\System32\drivers\iai2c.sys [81408] =>.Intel(R) Corporation
O58 - SDL:2015/10/30 08:17:18 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [165888] =>.Intel Corporation
O58 - SDL:2015/10/30 08:17:18 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] =>.Intel Corporation - Client Components Group®
O58 - SDL:2015/10/30 08:17:18 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [113152] =>.Intel Corporation
O58 - SDL:2015/02/09 08:06:00 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver -.) -- C:\WINDOWS\System32\drivers\iaStorA.sys [1399536] =>.Intel Corporation - Rapid Storage Technology®
O58 - SDL:2015/10/30 08:17:22 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [673120] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:22 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412000] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:23 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [424800] =>.Microsoft Windows®
O58 - SDL:2016/05/24 15:29:12 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\WINDOWS\System32\drivers\idmwfp.sys [207928] =>.Tonec Inc.®
O58 - SDL:2015/12/19 01:08:22 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\igdkmd64.sys [7858088] =>.Intel Corporation - pGFX®
O58 - SDL:2014/12/22 03:36:22 N . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\WINDOWS\System32\drivers\IntcDAud.sys [455440] =>.Intel Corporation - Client Components Group®
O58 - SDL:2014/12/11 01:13:50 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\intelaud.sys [42288] =>.Intel(R) Wireless Display®
O58 - SDL:2014/08/26 10:07:28 A . (.Intel Corporation - Intel Collaborative Processor Performance C.) -- C:\WINDOWS\System32\drivers\IntelPcc.sys [79016] =>.Intel(R) Software®
O58 - SDL:2015/10/30 08:17:23 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [108888] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:23 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [104800] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:23 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [99168] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:23 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82784] =>.Microsoft Windows®
O58 - SDL:2016/03/10 14:08:54 A . (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\WINDOWS\System32\drivers\mbam.sys [27008] =>.Malwarebytes Corporation®
O58 - SDL:2016/03/10 14:08:58 A . (.Malwarebytes - Malwarebytes Chameleon Protection Driver.) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys [140672] =>.Malwarebytes Corporation®
O58 - SDL:2016/06/29 01:39:27 A . (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [192216] =>.Malwarebytes Corporation®
O58 - SDL:2015/10/30 08:17:23 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59744] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:23 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575840] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:23 A . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [705376] =>.Microsoft Windows®
O58 - SDL:2010/08/06 00:43:20 A . (.DiBcom SA - DiBcom AVSTREAM BDA driver.) -- C:\WINDOWS\System32\drivers\mod7700.sys [1001472] =>.DiBcom SA
O58 - SDL:2015/10/30 08:17:23 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63840] =>.Microsoft Windows®
O58 - SDL:2016/03/10 14:09:10 A . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\WINDOWS\System32\drivers\mwac.sys [65408] =>.Malwarebytes Corporation®
O58 - SDL:2015/10/30 08:17:23 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [76128] =>.Microsoft Windows®
O58 - SDL:2015/07/13 20:45:08 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\WINDOWS\System32\drivers\nvlddmkm.sys [11139216] =>.NVIDIA Corporation®
O58 - SDL:2015/10/30 08:17:23 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150368] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:23 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [166240] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:23 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [58208] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:23 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [58720] =>.Microsoft Windows®
O58 - SDL:2015/07/07 23:25:38 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.40 64-bit Dr.) -- C:\WINDOWS\System32\drivers\rt640x64.sys [895256] =>.Realtek Semiconductor Corp®
O58 - SDL:2014/12/26 10:04:12 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\WINDOWS\System32\drivers\RTKVHD64.sys [4363864] =>.Realtek Semiconductor Corp®
O58 - SDL:2013/07/09 07:35:38 A . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/V.) -- C:\WINDOWS\System32\drivers\RtsUVStor.sys [329944] =>.Realtek Semiconductor Corp®
O58 - SDL:2015/10/30 08:17:23 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44896] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:23 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81760] =>.Microsoft Windows®
O58 - SDL:2014/01/22 08:52:10 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ve.) -- C:\WINDOWS\System32\drivers\ssudbus.sys [108800] =>.DEVGURU CO LTD®
O58 - SDL:2014/01/22 08:52:10 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ve.) -- C:\WINDOWS\System32\drivers\ssudmdm.sys [206080] =>.DEVGURU CO LTD®
O58 - SDL:2015/10/30 08:17:23 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31072] =>.Microsoft Windows®
O58 - SDL:2014/11/05 14:16:32 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\WINDOWS\System32\drivers\tap0901.sys [27136] =>.The OpenVPN Project
O58 - SDL:2015/02/25 14:15:40 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\TeeDriverx64.sys [129312] =>.Intel Corporation - Embedded Subsystems and IP Blocks Group®
O58 - SDL:2015/09/16 07:07:12 A . (.BigNox Corporation - VirtualBox USB Monitor Driver.) -- C:\WINDOWS\System32\drivers\VBoxUSBMon.sys [127432] =>.Duodian Online Technology Co. Ltd.®
O58 - SDL:2013/10/08 18:21:06 A . (.VMware, Inc. - VMware PCI VMCI Bus Device.) -- C:\WINDOWS\System32\drivers\vmci.sys [85584] =>.VMware, Inc.®
O58 - SDL:2014/04/14 16:40:42 A . (.VMware, Inc. - VMware virtual network driver (64-bit).) -- C:\WINDOWS\System32\drivers\vmnet.sys [24656] =>.VMware, Inc.®
O58 - SDL:2014/04/14 16:40:42 A . (.VMware, Inc. - VMware virtual network adapter driver (64-b.) -- C:\WINDOWS\System32\drivers\vmnetadapter.sys [20560] =>.VMware, Inc.®
O58 - SDL:2014/04/14 16:40:42 A . (.VMware, Inc. - VMware bridge driver (64-bit).) -- C:\WINDOWS\System32\drivers\vmnetbridge.sys [46160] =>.VMware, Inc.®
O58 - SDL:2014/04/14 16:41:38 A . (.VMware, Inc. - VMware network application interface driver.) -- C:\WINDOWS\System32\drivers\vmnetuserif.sys [31448] =>.VMware, Inc.®
O58 - SDL:2014/04/14 16:41:22 A . (.VMware, Inc. - VMware kernel driver.) -- C:\WINDOWS\System32\drivers\vmx86.sys [64728] =>.VMware, Inc.®
O58 - SDL:2015/10/30 08:17:23 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166752] =>.Microsoft Windows®
O58 - SDL:2013/10/08 18:21:10 A . (.VMware, Inc. - VMware vSockets Service.) -- C:\WINDOWS\System32\drivers\vsock.sys [73296] =>.VMware, Inc.®
O58 - SDL:2015/10/30 08:17:23 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305504] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:23 A . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [26976] =>.Microsoft Windows®
O58 - SDL:2015/10/30 08:17:23 A . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [59232] =>.Microsoft Windows®
O58 - SDL:2015/09/16 04:29:46 A . (.BigNox Corporation - VirtualBox Support Driver.) -- C:\WINDOWS\System32\drivers\XQHDrv.sys [253384] =>.Duodian Online Technology Co. Ltd.®
O58 - SDL:2014/09/09 00:39:24 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\athwbx.sys [4221952] =>.Qualcomm Atheros Communications, Inc.

---\\ Last modified or created user files (10) - 79s
O61 - LFC: 2016/06/28 16:46:39 A . (.xs-Sol.) -- C:\Users\salamouna2\Downloads\Programs\Cetagram_Activate_46f8ac1049396aee9.exe [679672]
O61 - LFC: 2016/06/24 18:46:05 A . (..) -- C:\Users\salamouna2\Desktop\test.bat [160]
O61 - LFC: 2016/06/22 15:32:32 A . (..) -- C:\Users\salamouna2\AppData\Roaming\Telegram Desktop\unins000.exe [1561801]
O61 - LFC: 2016/06/29 16:02:30 A . (..) -- C:\Users\salamouna2\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\speech_onecorereg.bin [8192]
O61 - LFC: 2016/06/28 16:54:33 A . (..) -- C:\Users\salamouna2\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\UrlBlock\urlblock_636027211354776436.bin [112425]
O61 - LFC: 2016/06/22 13:30:06 A . (..) -- C:\Users\salamouna2\AppData\Local\NVIDIA\NvBackend\UMDShim\nvcoproc.bin [7208075]
O61 - LFC: 2016/06/29 16:00:38 A . (..) -- C:\Users\salamouna2\AppData\Local\Microsoft\Windows\UPPS\UPPS.bin [16148]
O61 - LFC: 2016/06/29 01:45:40 A . (..) -- C:\Users\salamouna2\AppData\Local\Microsoft\Terminal Server Client\Cache\Cache0000.bin [104591640]
O61 - LFC: 2016/06/29 01:44:49 A . (..) -- C:\Users\salamouna2\AppData\Local\Microsoft\Terminal Server Client\Cache\Cache0001.bin [104612072]
O61 - LFC: 2016/06/29 01:45:07 A . (..) -- C:\Users\salamouna2\AppData\Local\Microsoft\Terminal Server Client\Cache\Cache0002.bin [104571208]

---\\ File Associations Shell Spawning (10) - 1s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S

---\\ Start Menu Internet (12) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

---\\ Search Browser Infection (2) - 20s
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/
O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/

---\\ Search Svchost Services (41) - 2s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\WINDOWS\System32\certprop.dll [192000] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\WINDOWS\System32\certprop.dll [192000] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\WINDOWS\system32\srvsvc.dll [283136] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\WINDOWS\System32\gpsvc.dll [1338368] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\WINDOWS\System32\ikeext.dll [957952] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\WINDOWS\System32\iphlpsvc.dll [958464] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\WINDOWS\system32\seclogon.dll [31232] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\WINDOWS\System32\appinfo.dll [94720] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\WINDOWS\system32\iscsiexe.dll [151040] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\WINDOWS\System32\eapsvc.dll [112640] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\WINDOWS\system32\schedsvc.dll [997376] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [225280] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\WINDOWS\System32\browser.dll [134656] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\WINDOWS\system32\profsvc.dll [328192] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [372736] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\WINDOWS\System32\wercplsupport.dll [96256] =>.Microsoft Corporation
O83 - Search Svchost Services: DcpSvc (DcpSvc) . (.Microsoft Corporation - dcpsvc Task.) -- C:\WINDOWS\system32\dcpsvc.dll [186880] =>.Microsoft Corporation
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Microsoft® Account Service.) -- C:\WINDOWS\system32\wlidsvc.dll [2057216] =>.Microsoft Corporation
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Microsoft Network Connectivity Assistant Se.) -- C:\WINDOWS\System32\ncasvc.dll [168960] =>.Microsoft Corporation
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Network Setup Service.) -- C:\WINDOWS\System32\NetSetupSvc.dll [207360] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\WINDOWS\system32\themeservice.dll [59392] =>.Microsoft Corporation
O83 - Search Svchost Services: RetailDemo (RetailDemo) . (.Microsoft Corporation - RDXService.) -- C:\WINDOWS\system32\RDXService.dll [1090048] =>.Microsoft Corporation
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Geolocation Service.) -- C:\Windows\System32\lfsvc.dll [27136] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\WINDOWS\System32\rasauto.dll [106496] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINDOWS\System32\rasmans.dll [696320] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [507904] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\WINDOWS\System32\sens.dll [73216] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\WINDOWS\System32\ipnathlp.dll [456704] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [311808] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\WINDOWS\system32\wuaueng.dll [2275328] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\WINDOWS\System32\qmgr.dll [1144320] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [608768] =>.Microsoft Corporation
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\WINDOWS\system32\dmwappushsvc.dll [57856] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\WINDOWS\System32\bdesvc.dll [361472] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\WINDOWS\system32\XboxNetApiSvc.dll [1035776] =>.Microsoft Corporation
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Update Session Orchestrator Core.) -- C:\WINDOWS\system32\usocore.dll [360960] =>.Microsoft Corporation
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\WINDOWS\System32\XblGameSave.dll [1139712] =>.Microsoft Corporation
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - Windows Managent Service DLL.) -- C:\Windows\System32\Windows.Internal.Management.dll [278016] =>.Microsoft Corporation
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Device Setup Manager.) -- C:\WINDOWS\System32\DeviceSetupManager.dll [205824] =>.Microsoft Corporation
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\WINDOWS\System32\usermgr.dll [912384] =>.Microsoft Corporation
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\WINDOWS\System32\XblAuthManager.dll [948736] =>.Microsoft Corporation

---\\ Firewall Active Exception List (10) - 7s
O87 - FAEL: "{8A22401A-6FCD-4C90-A459-5AC6B94CD68A}" [In-None-P6-TRUE] .(.Bartels Media GmbH - Mouse Recorder.) -- C:\Program Files (x86)\MouseRecorder\MouseRecorder.exe {11211BB60A8D3623516581689603FB6C9880}
O87 - FAEL: "{D5EA07D1-DC9A-431B-97A3-96660993BBD2}" [In-None-P6-TRUE] .(...) -- C:\Program Files\KMSpico\KMSELDI.exe =>HackTool.KMSpico
O87 - FAEL: "{D1338576-47D2-4D56-8699-0592D6B0C593}" [In-None-P17-TRUE] .(...) -- C:\Program Files\KMSpico\KMSELDI.exe =>HackTool.KMSpico
O87 - FAEL: "{3E7CEB8A-8DF3-4F24-8FDF-5FFB799B47C4}" [In-None-P6-TRUE] .(...) -- C:\Program Files\KMSpico\AutoPico.exe =>HackTool.KMSpico
O87 - FAEL: "{4AE22350-3470-4495-B916-294DFD2DCAAC}" [In-None-P17-TRUE] .(...) -- C:\Program Files\KMSpico\AutoPico.exe =>HackTool.KMSpico
O87 - FAEL: "{9DC84334-9973-47ED-8058-BA2F9191EAFD}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Bignox\BigNoxVM\RTNoxVMHandle.exe (.not file.)
O87 - FAEL: "TCP Query User{BEDB0855-4D46-4752-853F-2E82CC21E8CD}C:\program files (x86)\youwave android\vb\vboxsdl.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\youwave android\vb\vboxsdl.exe {1121F46A4923EAE1C5CA24D3C6CF87F1D5A3}
O87 - FAEL: "UDP Query User{9117BCA3-B01A-4217-8A9C-6181562CBB8F}C:\program files (x86)\youwave android\vb\vboxsdl.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\youwave android\vb\vboxsdl.exe {1121F46A4923EAE1C5CA24D3C6CF87F1D5A3}
O87 - FAEL: "{4CF11F6A-606E-4AD3-8DF3-A6542F47F997}" [In-None-P6-TRUE] .(...) -- C:\Program Files\KMSpico\Service_KMS.exe =>HackTool.KMSpico
O87 - FAEL: "{259F7BED-4114-4E36-B714-887831A4A913}" [In-None-P17-TRUE] .(...) -- C:\Program Files\KMSpico\Service_KMS.exe =>HackTool.KMSpico

---\\ Additional Scan (O88) (13) - 0s
HKLM\SYSTEM\CurrentControlSet\Services\Service KMSELDI =>HackTool.KMSpico
C:\Program Files\KMSpico\Service_KMS.exe =>HackTool.KMSpico
C:\Program Files\KMSpico\AutoPico.exe =>HackTool.KMSpico
C:\WINDOWS\System32\Tasks\AutoPico Daily Restart =>HackTool.KMSpico
C:\Program Files (x86)\Skillbrains\lightshot\5.3.0.0\Lightshot.exe =>PUP.Optional.Skillbrains
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KMSpico_is1 =>HackTool.KMSpico
HKLM\SOFTWARE\Wow6432Node\Skillbrains =>PUP.Optional.Skillbrains
HKCU\SOFTWARE\SkillBrains =>PUP.Optional.Skillbrains
C:\Program Files\KMSpico =>HackTool.KMSpico
C:\Program Files (x86)\QuickTime =>Riskware.QuickTime
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico =>HackTool.KMSpico
C:\ProgramData\Mobile Partner =>Toolbar.YahooPartner
C:\Program Files\KMSpico\KMSELDI.exe =>HackTool.KMSpico

---\\ Summary of the elements found (5) - 0s
http://www.nicolascoolman.fr/?p=989 =>HackTool.KMSpico
https://www.nicolascoolman.info/2016/04/30/pup-optional-skillbrains/ =>PUP.Optional.Skillbrains
http://www.nicolascoolman.fr/?p=210 =>.Superfluous.Conduit
https://www.nicolascoolman.info/2016/04/21/riskware-quicktime/ =>Riskware.QuickTime
http://www.nicolascoolman.fr/?p=5143 =>Toolbar.YahooPartner

~ End of the scan, 23905 items in 00h08mn30s (1132)(0)

Publicité


Signaler le contenu de ce document

Publicité