~ Report of ZHPDiag v2015.5.31.53 - Nicolas Coolman (5/31/2015) ~ Launched by libya (6/3/2015 6:34:16 AM) ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ Web forum address : http://forum.nicolascoolman.fr ~ Translated by ~ Version State : Updated version. ~ White List : Deactivate by user ~ Elevation of privilege : OK ~ User Account Control : Deactivate by program ---\\ Internet browsers MSIE: Internet Explorer v11.0.9600.17801 GCIE: Google Chrome v42.0.2311.135 OPIE: Opera Stable v29.0.1795.60 ---\\ Windows product information ~ Langage: Anglais Windows Server License Manager Script : OK ~ Windows Operating System - Windows(R) 7, OEM_SLP channel System Locked Preinstallation (OEM_SLP) : OK Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK Windows 7 Ultimate, 32-bit Service Pack 1 (Build 7601) ---\\ System protection software Malwarebytes Anti-Malware ÇáäÓÎÉ 2.1.6.1022 Windows Defender W7 (Activate) ---\\ System optimization software ---\\ Sharing software PeerToPeer ---\\ Surveillance software Adobe Flash Player 17 NPAPI ---\\ Information on the system ~ Processor: x86 Family 6 Model 23 Stepping 6, GenuineIntel ~ Operating System: 32 Bits Boot mode: Normal (Normal boot) Total RAM: 2047.1 MB (35% free) System Restore: Activé (Enable) System drive C: has 6 GB (12%) free of 47 GB ---\\ Connection to the system mode ~ Computer Name: LIBYA-PC ~ User Name: libya ~ All Users Names: libya, Guest, Administrator, ~ Unselected Option: None Logged in as Administrator ---\\ Environment variables ~ System Unit : C:\ ~ %AppZHP% : C:\Users\libya\AppData\Roaming\ZHP\ ~ %AppData% : C:\Users\libya\AppData\Roaming\ ~ %Desktop% : C:\Users\libya\Desktop\ ~ %Favorites% : C:\Users\libya\Favorites\ ~ %LocalAppData% : C:\Users\libya\AppData\Local\ ~ %StartMenu% : C:\Users\libya\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ Enumeration of the disk units C: Hard drive, Flash drive, Thumb drive (Free 6 Go of 47 Go) D: Hard drive, Flash drive, Thumb drive (Free 27 Go of 54 Go) E: Hard drive, Flash drive, Thumb drive (Free 8 Go of 48 Go) G: Floppy drive, Flash card reader, USB Key (Not Inserted) ---\\ State of the Windows Security Center [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ~ Security Center: 38 Scanned in 00mn AMs ---\\ Search Generic System Files [MD5.40D777B7A95E00593EB1568C68514493] - (.Microsoft Corporation - مستكشف Windows.) (.11/20/2010 - 2:17:09 PM.) -- C:\Windows\Explorer.exe [2616320] [MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - ‎‎تطبيق بدء تشغيل Windows.) (.7/14/2009 - 3:14:45 AM.) -- C:\Windows\System32\Wininit.exe [96256] [MD5.CB5F450D21B9D76B7F01D006E4AEDB40] - (.Microsoft Corporation - ملحقات الإنترنت لـ Win32.) (.5/26/2015 - 7:57:40 PM.) -- C:\Windows\System32\wininet.dll [1882112] [MD5.52449FD429D6053B78AE564DEF303870] - (.Microsoft Corporation - تطبيق تسجيل دخول Windows.) (.7/17/2014 - 3:39:27 AM.) -- C:\Windows\System32\Winlogon.exe [304128] [MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - مكتبة تراخيص البرامج.) (.11/20/2010 - 2:21:24 PM.) -- C:\Windows\System32\sppcomapi.dll [193536] [MD5.D0B388DA1D111A34366E04EB4A5DD156] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.5/30/2014 - 8:36:07 AM.) -- C:\Windows\system32\Drivers\AFD.sys [338944] [MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.7/14/2009 - 3:26:15 AM.) -- C:\Windows\system32\Drivers\atapi.sys [21584] [MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.7/14/2009 - 1:11:15 AM.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656] [MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.11/20/2010 - 10:38:10 AM.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544] [MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.11/20/2010 - 10:42:32 AM.) -- C:\Windows\system32\Drivers\DfsC.sys [78336] [MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.11/20/2010 - 11:59:29 AM.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544] [MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - برنامج تشغيل منفذ i8042.) (.7/14/2009 - 1:11:24 AM.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896] [MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.7/14/2009 - 1:54:29 AM.) -- C:\Windows\system32\Drivers\IpNat.sys [101888] [MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.4/27/2011 - 4:17:22 AM.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904] [MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.11/20/2010 - 10:39:44 AM.) -- C:\Windows\system32\Drivers\netBT.sys [187904] [MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - (.Microsoft Corporation - NT File System Driver.) (.1/24/2014 - 4:18:22 AM.) -- C:\Windows\system32\Drivers\ntfs.sys [1212352] [MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - برنامج تشغيل المنفذ المتوازي.) (.7/14/2009 - 1:45:35 AM.) -- C:\Windows\system32\Drivers\Parport.sys [79360] [MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.7/14/2009 - 1:54:34 AM.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848] [MD5.B973FCFC50DC1434E1970A146F7E3885] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.11/20/2010 - 12:24:46 PM.) -- C:\Windows\system32\Drivers\rdpdr.sys [133632] [MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.7/14/2009 - 1:53:41 AM.) -- C:\Windows\system32\Drivers\smb.sys [71168] [MD5.B459575348C20E8121D6039DA063C704] - (.Microsoft Corporation - TDI Translation Driver.) (.11/20/2010 - 10:39:17 AM.) -- C:\Windows\system32\Drivers\tdx.sys [74752] [MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - برنامج تشغيل خدمة ملفات الظل الاحتياطية لوحدة التخزين.) (.11/20/2010 - 2:30:16 PM.) -- C:\Windows\system32\Drivers\volsnap.sys [245632] ~ Generic Processes: Scanned in 04mn AMs ---\\ Hidden files state (Hidden/Total) ~ Mes Favoris (My Favorites) : 1/22 ~ Mes Documents (My Documents) : 1/15 ~ Mon Bureau (My Desktop) : 1/10 ~ Menu demarrer (Programs) : 1/33 ~ Hidden Files: Scanned in 00mn AMs ---\\ Process running [MD5.177E1AEA245EC7853BF93B433BD352DF] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe [3882576] [PID.2172] [MD5.77C01F1850E55373280A1B865D824F58] - (.© 2015 Microsoft Corporation - Microsoft Bing Service.) -- C:\Users\libya\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008] [PID.2184] [MD5.468CD52A5E41726E2970C4B2FECF6BA8] - (...) -- C:\Program Files\Nimbuzz\Nimbuzz.exe [8934400] [PID.2272] [MD5.BD95E822E7A958BBCA842D078426A151] - (.Tonec Inc. - Internet Download Manager agent for click m.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe [269848] [PID.3412] [MD5.9F8CC0B84798CE0737A9061F4F5A6C76] - (.Crossbrowse - Crossbrowse.) -- C:\Program Files\Crossbrowse\Crossbrowse\Application\Crossbrowse.exe [770048] [PID.9540] =>PUP.CrossBrowser [MD5.F48EFC6DE03D9D7F136BA08D65CB6155] - (.Mozilla Corporation - Firefox.) -- D:\Program Files\Mozilla Firefox\firefox.exe [376944] [PID.568] [MD5.D1FFBC0A73CEB5E1501223D6FA0E3D34] - (.Mozilla Corporation - Plugin Container for Firefox.) -- D:\Program Files\Mozilla Firefox\plugin-container.exe [270960] [PID.9868] [MD5.411837D66846190BDEA7077046EA9038] - (.Adobe Systems, Inc. - Adobe Flash Player 17.0 r0.) -- C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe [1894064] [PID.4932] [MD5.4A143FD710F4CB9D609AEC89D8E56C7D] - (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\29.0.1795.60\opera.exe [56025208] [PID.3140] [MD5.F5049158094CB12DF71FF54748A60B34] - (...) -- C:\Program Files\Opera\29.0.1795.60\opera_crashreporter.exe [479352] [PID.2808] [MD5.F3198BA5BA8CC86D3F2DEA8C2ACA7385] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8212992] [PID.3008] ~ Processes Running: Scanned in 36mn AMs ---\\ Google Chrome, Start,Search,Extensions (G0,G1,G2) C:\Users\libya\AppData\Local\Google\Chrome\User Data\Default\Preferences ---\\ Google Chrome Extension Folder G2 - EXT: C:\Users\libya\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [__MSG_appName__] G2 - EXT: C:\Users\libya\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [Docs] G2 - EXT: C:\Users\libya\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [__MSG_appName__] G2 - EXT: C:\Users\libya\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [__MSG_appName__] G2 - EXT: C:\Users\libya\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [__MSG_appName__] G2 - EXT: C:\Users\libya\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd [__MSG_ExtnName__] G2 - EXT: C:\Users\libya\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [__MSG_appName__] G2 - EXT: C:\Users\libya\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn [IDM Integration Module] G2 - EXT: C:\Users\libya\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [__MSG_appName__] ~ Google Lines Browser: 18 Scanned in 00mn AMs ---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (P2,M0,M1,M2,M3) C:\Users\libya\AppData\Roaming\Mozilla\Firefox\Profiles\his2fla6.default\prefs.js C:\Users\libya\AppData\Roaming\Mozilla\Firefox\Profiles\his2fla6.default\user.js M3 - MFPP: Plugins - [libya] -- C:\Users\libya\AppData\Roaming\Mozilla\Firefox\Profiles\his2fla6.default\searchplugins\bingp.xml M3 - MFPP: Plugins - [libya] -- C:\Users\libya\AppData\Roaming\Mozilla\Firefox\Profiles\his2fla6.default\searchplugins\trovi.xml M2 - MFEP: Extension [libya - his2fla6.default] jid1-KWFaW5zc0EbtBQ@jetpack.xpi P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll P2 - FPN: [HKLM] [@staging.google.com/globalUpdate Update;version=10] - (.globalUpdate - globalUpdate Update.) -- C:\Program Files\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll =>PUP.GlobalUpdate P2 - FPN: [HKLM] [@staging.google.com/globalUpdate Update;version=4] - (.globalUpdate - globalUpdate Update.) -- C:\Program Files\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll =>PUP.GlobalUpdate P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.2.1] - (.VideoLAN - VLC media player Web Plugin.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll =>.VideoLAN ~ Firefox Browser: 7 Scanned in 00mn AMs ---\\ Internet Explorer Extensions, Start, Search (R4,R3,R0,R1) R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.trovi.com =>Hijacker.TroviCom R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.VideoLAN - VLC media player Web Plugin.) (No version) -- (.not file.) =>.VideoLAN R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 0 ~ IE Browser: 10 Scanned in 00mn AMs ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn AMs ---\\ Line Analysis F0, F1, F2, F3 - IniFiles, Auto loading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn AMs ---\\ Hosts file redirection (O1) ~ Le fichier hôte est sain (The hosts file is clean) (21) ~ Hosts File: Scanned in 00mn AMs ---\\ Browser Helper Objects (O2) O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files\Internet Download Manager\IDMIECC.dll ~ BHO: 2 Scanned in 00mn AMs ---\\ Other User Links (O4) O4 - GS\Desktop [Public]: Crossbrowse.lnk . (.Crossbrowse - Crossbrowse.) -- C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe =>PUP.CrossBrowser O4 - GS\Desktop [Public]: Pro PC Cleaner.lnk . (.Rainmaker Software Group LLC. - Pro PC Cleaner.) -- C:\Program Files\Pro PC Cleaner\ProPCCleaner.exe =>PUP.DoctorPC O4 - GS\Desktop [Public]: Resume Reimage Repair Installation.lnk . (.Reimage® - Reimage Downloader.) -- C:\Users\libya\Downloads\Programs\ReimageRepair.exe =>Rogue.ReimageRepair O4 - GS\QuickLaunch [libya]: Crossbrowse.lnk . (.Crossbrowse - Crossbrowse.) -- C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe =>PUP.CrossBrowser ~ Global Startup: 5 Scanned in 04mn AMs ---\\ Auto loading programs from Registry and folders (O4) O4 - GS\Startup [libya]: crossbrowse.lnk . (.Crossbrowse - Crossbrowse.) -- C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe =>PUP.CrossBrowser O4 - HKLM\..\Run: [gmsd_gb_398] . (...) -- C:\Program Files\gmsd_gb_398\gmsd_gb_398.exe O4 - HKLM\..\RunOnce: [upgmsd_gb_398.exe] . (...) -- C:\Users\libya\AppData\Local\gmsd_gb_398\upgmsd_gb_398.exe O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe O4 - HKCU\..\Run: [BingSvc] . (.© 2015 Microsoft Corporation - Microsoft Bing Service.) -- C:\Users\libya\AppData\Local\Microsoft\BingSvc\BingSvc.exe O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- D:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd O4 - HKCU\..\Run: [Nimbuzz] . (...) -- C:\Program Files\Nimbuzz\Nimbuzz.exe O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_F869A474B56DEC3386C30B8DA5B84F81] . (.Crossbrowse - Crossbrowse.) -- C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe =>PUP.CrossBrowser O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-2686101908-3917168696-217693980-1000\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe O4 - HKUS\S-1-5-21-2686101908-3917168696-217693980-1000\..\Run: [BingSvc] . (.© 2015 Microsoft Corporation - Microsoft Bing Service.) -- C:\Users\libya\AppData\Local\Microsoft\BingSvc\BingSvc.exe O4 - HKUS\S-1-5-21-2686101908-3917168696-217693980-1000\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- D:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd O4 - HKUS\S-1-5-21-2686101908-3917168696-217693980-1000\..\Run: [Nimbuzz] . (...) -- C:\Program Files\Nimbuzz\Nimbuzz.exe O4 - HKUS\S-1-5-21-2686101908-3917168696-217693980-1000\..\Run: [GoogleChromeAutoLaunch_F869A474B56DEC3386C30B8DA5B84F81] . (.Crossbrowse - Crossbrowse.) -- C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe =>PUP.CrossBrowser ~ Application: Scanned in 00mn AMs ---\\ IE Options icon not visible in Control Panel (O5) O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no ~ IE Control Panel: 1 Scanned in 00mn AMs ---\\ Winsock hijacker (Layered Service Provider) (O10) O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - موفر Shim لتسمية البريد الإلكتروني.) -- C:\Windows\system32\napinsp.dll O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - PNRP Name Space Provider.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - PNRP Name Space Provider.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - Microsoft Windows Sockets 2.0 Service Provider.) -- C:\Windows\system32\mswsock.dll O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll ~ Winsock: 7 Scanned in 00mn AMs ---\\ Lop.com/Domain Hijackers (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{484FE1C7-41F3-442F-819D-188838391F84}: DhcpNameServer = 10.0.0.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{484FE1C7-41F3-442F-819D-188838391F84}: DhcpNameServer = 10.0.0.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{484FE1C7-41F3-442F-819D-188838391F84}: DhcpNameServer = 10.0.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1 ~ Domain: Scanned in 00mn AMs ---\\ Extra protocols (O18) O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - عارض Microsoft (R) HTML.) -- C:\Windows\System32\mshtml.dll O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation ~ Protocole Additionnel: Scanned in 00mn AMs ---\\ AppInit_DLLs Registry value Autorun (O20) O20 - AppInit_DLLs: . (.Client Connect LTD - Search Protect.) - C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll =>PUP.SearchProtect ~ AppInit DLL: Scanned in 00mn AMs ---\\ ShellServiceObjectDelayLoad (O21) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. ~ SSODL: 1 Scanned in 00mn AMs ---\\ Non Microsoft non disabled Windows XP/NT/2000 Services (O23) O23 - Service: Search Protect Service (CltMngSvc) . (.Client Connect LTD - Search Protect.) - C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe =>PUP.SearchProtect O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) . (.globalUpdate - globalUpdate Update.) - C:\Program Files\globalUpdate\Update\globalupdate.exe =>PUP.GlobalUpdate O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: UpdateDust (UpdateDustTool) . (.VIS without Co - Downloader.Service.) - C:\Windows\Provider\UpdaterToolService.exe O23 - Service: Util Edu App (Util Edu App) . (...) - C:\Program Files\Edu App\bin\utilEduApp.exe (.not file.) =>PUP.Optional ~ Services: 5 Scanned in 10mn AMs ---\\ Windows Active Desktop & MHTML Editor (O24) O24 - Default MHTML Editor: Last - .(...) - (.not file.) ~ Desktop Component: 4 Scanned in 00mn AMs ---\\ BootExecute (BEX) (O34) O34 - HKLM BootExecute: (autocheck autochk *) - File not found ~ BEX: 1 Scanned in 00mn AMs ---\\ Task Planned Automatically (039) [MD5.00000000000000000000000000000000] [APT] [APSnotifierPP1] (...) -- C:\Program Files\AnyProtectEx\AnyProtect.exe (.not file.) [0] =>PUP.AnyProtect [MD5.00000000000000000000000000000000] [APT] [APSnotifierPP2] (...) -- C:\Program Files\AnyProtectEx\AnyProtect.exe (.not file.) [0] =>PUP.AnyProtect [MD5.00000000000000000000000000000000] [APT] [APSnotifierPP3] (...) -- C:\Program Files\AnyProtectEx\AnyProtect.exe (.not file.) [0] =>PUP.AnyProtect [MD5.F5126CC817A0638A77F1EF3DDFE22F8E] [APT] [avabvbxvh] (...) -- C:\Users\libya\AppData\Local\avabvbxvh\avabvbxvh.exe [2135552] [MD5.947835240308F523C9D980C89D35E76D] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- D:\Program Files\CCleaner\CCleaner.exe [4825880] [MD5.4243DC9B601DFDE56F1EDAE8F25CBD2E] [APT] [Crossbrowse] (...) -- C:\Program Files\Crossbrowse\Crossbrowse\Application\utility.exe [1957976] =>PUP.CrossBrowser [MD5.E04384BFAF66E3EC9F3643488CD0EDE8] [APT] [Format Factory] (.Free Time.) -- C:\Users\libya\AppData\Local\Temp\is-5VGJQ.tmp\prsetup.exe [1289835] [MD5.00000000000000000000000000000000] [APT] [MaxComputerCleaner_Start] (...) -- C:\Program Files\Max Computer Cleaner\MaxComputerCleaner.exe (.not file.) [0] =>PUP.MaxComputerCleaner [MD5.9765C6373A259BFE07BF281FE70EA66C] [APT] [Opera scheduled Autoupdate 1433113948] (.Opera Software.) -- C:\Program Files\Opera\launcher.exe [888440] [MD5.39CBC89CDBA3DBD19A6F945938970FF5] [APT] [ProPCCleaner_Popup] (...) -- C:\Program Files\Pro PC Cleaner\Splash.exe [271128] =>PUP.DoctorPC [MD5.251C33DA217DD8590D844A4CCD3FEC5B] [APT] [ProPCCleaner_Start] (.Rainmaker Software Group LLC..) -- C:\Program Files\Pro PC Cleaner\ProPCCleaner.exe [5984536] =>PUP.DoctorPC [MD5.00000000000000000000000000000000] [APT] [SmartWeb Upgrade Trigger Task] (...) -- C:\Users\libya\AppData\Local\SmartWeb\SmartWebHelper.exe (.not file.) [0] =>PUP.SmartWeb O39 - APT: APSnotifierPP1 - (...) -- C:\Windows\Tasks\APSnotifierPP1.job [366] =>PUP.AnyProtect O39 - APT: APSnotifierPP1 - (...) -- C:\Windows\System32\Tasks\APSnotifierPP1 [366] =>PUP.AnyProtect O39 - APT: APSnotifierPP2 - (...) -- C:\Windows\Tasks\APSnotifierPP2.job [364] =>PUP.AnyProtect O39 - APT: APSnotifierPP2 - (...) -- C:\Windows\System32\Tasks\APSnotifierPP2 [364] =>PUP.AnyProtect O39 - APT: APSnotifierPP3 - (...) -- C:\Windows\Tasks\APSnotifierPP3.job [364] =>PUP.AnyProtect O39 - APT: APSnotifierPP3 - (...) -- C:\Windows\System32\Tasks\APSnotifierPP3 [364] =>PUP.AnyProtect O39 - APT: Crossbrowse - (...) -- C:\Windows\Tasks\Crossbrowse.job [1044] =>PUP.CrossBrowser O39 - APT: Crossbrowse - (...) -- C:\Windows\System32\Tasks\Crossbrowse [1044] =>PUP.CrossBrowser O39 - APT: - (..) -- C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job [952] =>PUP.GlobalUpdate O39 - APT: - (..) -- C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job [956] =>PUP.GlobalUpdate ~ Scheduled Task: 20 Scanned in 14mn AMs ---\\ ActiveSetup Installed Components (O40) O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - ‎‎موارد Windows Media Player.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API لنُسق Windows.) -- C:\Windows\System32\themeui.dll O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - ‎‎بريد Windows.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - امتداد Shell الخاص بمجلد Microsoft Internet Explorer FTP.) -- C:\Windows\System32\msieftp.dll O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - ‎‎موارد Windows Media Player.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation O40 - ASIC: Disable SSL3 - {7D715857-A67C-4C2F-A929-038448584D63} . (.Microsoft Corporation - ‎‎الأداة المساعدة للتهيئة لكل مستخدم لـ IE.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لـ Windows Shell.) -- C:\Windows\System32\shell32.dll O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - ‎‎الأداة المساعدة للتهيئة لكل مستخدم لـ IE.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll ~ Active Setup: 10 Scanned in 00mn AMs ---\\ Drivers launched at startup (O41) O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\drivers\cdrom.sys O41 - Driver: C:\Windows\System32\cscsvc.dll (CSC) . (.Microsoft Corporation - Windows Client Side Caching Driver.) - C:\Windows\System32\drivers\csc.sys O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys O41 - Driver: (innfd_1_10_0_14) . (. - .) - C:\Windows\System32\drivers\innfd_1_10_0_14.sys (.not file.) O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - QoS Packet Scheduler.) - C:\Windows\System32\DRIVERS\pacer.sys O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - برنامج تشغيل النظام الفرعي لتخزين القرص الم.) - C:\Windows\System32\DRIVERS\rdbss.sys O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys O41 - Driver: (Serial) . (.Microsoft Corporation - Serial Device Driver.) - C:\Windows\System32\DRIVERS\serial.sys O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys ~ Drivers: 68 Scanned in 00mn AMs ---\\ Software installed (O42) O42 - Logiciel: Adobe Flash Player 17 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI O42 - Logiciel: Crossbrowse - (.The Crossbrowse Authors.) [HKLM] -- Crossbrowse =>PUP.CrossBrowser O42 - Logiciel: GamesDesktop 013.398 - (.GAMESDESKTOP.) [HKLM] -- gmsd_gb_398_is1 =>Adware.GamesDesktop O42 - Logiciel: Google Chrome - (.Google Inc‎.‎.) [HKCU] -- Google Chrome O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM] -- Internet Download Manager O42 - Logiciel: Malwarebytes Anti-Malware ÇáäÓÎÉ 2.1.6.1022 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes Anti-Malware_is1 O42 - Logiciel: Nimbuzz 2.9.4 - (.Nimbuzz B.V..) [HKLM] -- Nimbuzz O42 - Logiciel: Opera Stable 29.0.1795.60 - (.Opera Software ASA.) [HKLM] -- Opera 29.0.1795.60 O42 - Logiciel: Pro PC Cleaner - (.Rainmaker Software Group LLC..) [HKLM] -- {715DCA23-8423-4269-B35A-08C113631B0A} =>PUP.DoctorPC O42 - Logiciel: Search Protect - (.Client Connect LTD.) [HKLM] -- SearchProtect =>PUP.SearchProtect O42 - Logiciel: UpdaterService version 1.5 - (.Updater Service.) [HKLM] -- {DC866C1E-B796-4BD2-93B8-B5706AC5B5CC}_is1 =>Adware.IncrediBar O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM] -- VLC media player =>.VideoLAN ~ Logic: 28 Scanned in 00mn AMs ---\\ HKCU & HKLM Software Keys [HKCU\Software\AnyProtect] =>PUP.AnyProtect [HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider [HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}] [HKCU\Software\AppDataLow] [HKCU\Software\Chromium] [HKCU\Software\Classes] [HKCU\Software\Clients] [HKCU\Software\CrossBrowser] =>PUP.CrossBrowser [HKCU\Software\Crossbrowse] =>PUP.CrossBrowser [HKCU\Software\DownloadManager] [HKCU\Software\Format Factory] [HKCU\Software\Google] [HKCU\Software\IM Providers] [HKCU\Software\IM] [HKCU\Software\MCAFEE] [HKCU\Software\Macromedia] [HKCU\Software\MaxComputerCleanerConfig] =>PUP.MaxComputerCleaner [HKCU\Software\MaxComputerCleanerLanguage] =>PUP.MaxComputerCleaner [HKCU\Software\MozillaPlugins] [HKCU\Software\Mozilla] [HKCU\Software\Nimbuzz] [HKCU\Software\Opera Software] [HKCU\Software\Optimizer Pro] =>PUP.OptimizerPro [HKCU\Software\Piriform] [HKCU\Software\Policies] [HKCU\Software\Popcornew] =>PUP.Popcornew [HKCU\Software\ProPCCleanerLanguage] =>PUP.DoctorPC [HKCU\Software\Rainmaker Software Group LLC.] [HKCU\Software\SWiSHzone.com] [HKCU\Software\Shop and Save Up-nv-ie] =>PUP.CrossRider [HKCU\Software\Skype] [HKCU\Software\SwiftMediaConverterApp] [HKCU\Software\Trolltech] [HKCU\Software\TutoTag] =>PUP.AgenceExclusive [HKCU\Software\Tutorials] =>PUP.AgenceExclusive [HKCU\Software\WebApp] [HKCU\Software\WinRAR] [HKCU\Software\ZebHelpProcess Helper] [HKCU\Software\globalUpdate] =>PUP.GlobalUpdate [HKCU\Software\tvp] [HKLM\Software\ASUS] [HKLM\Software\ATI Technologies] [HKLM\Software\AppDataLow] [HKLM\Software\Classes] [HKLM\Software\Clients] [HKLM\Software\GAMESDESKTOP] =>Adware.GamesDesktop [HKLM\Software\GlobalUpdate] =>PUP.GlobalUpdate [HKLM\Software\Google] [HKLM\Software\Infonaut_1.10.0.14] =>PUP.Infonaut [HKLM\Software\Intel] [HKLM\Software\Macromedia] [HKLM\Software\Malwarebytes' Anti-Malware] [HKLM\Software\MozillaPlugins] [HKLM\Software\Mozilla] [HKLM\Software\ODBC] [HKLM\Software\Opera Software] [HKLM\Software\Policies] [HKLM\Software\Popcornew] =>PUP.Popcornew [HKLM\Software\Rainmaker Software Group LLC.] [HKLM\Software\RegisteredApplications] [HKLM\Software\Reimage] =>Rogue.ReimageRepair [HKLM\Software\SPPDCOM] =>Rogue.PCSpeedUp [HKLM\Software\Skype] [HKLM\Software\Sonic] [HKLM\Software\Tutorials] =>PUP.AgenceExclusive [HKLM\Software\VideoLAN] [HKLM\Software\Volatile] [HKLM\Software\cbbb007f-6750-459d-bda5-ffce74fc3cac] =>PUP.CrossRider [HKLM\Software\mozilla.org] ~ Key Software: 114 Scanned in 00mn AMs ---\\ Contents of the Common Files folders (O43) O43 - CFD: 6/3/2015 - 6:22:09 AM - [] ----D C:\Program Files\Bin O43 - CFD: 5/23/2015 - 3:53:42 AM - [] ----D C:\Program Files\Common Files O43 - CFD: 6/3/2015 - 5:04:53 AM - [] ----D C:\Program Files\Crossbrowse =>PUP.CrossBrowser O43 - CFD: 5/25/2015 - 3:44:36 AM - [] ----D C:\Program Files\DVD Maker O43 - CFD: 6/3/2015 - 5:41:09 AM - [] ----D C:\Program Files\globalUpdate =>PUP.GlobalUpdate O43 - CFD: 6/3/2015 - 5:26:53 AM - [] ----D C:\Program Files\gmsd_gb_398 O43 - CFD: 5/19/2015 - 2:25:48 AM - [] ----D C:\Program Files\Google O43 - CFD: 5/19/2015 - 7:38:59 AM - [] ----D C:\Program Files\Internet Download Manager O43 - CFD: 5/27/2015 - 12:26:38 AM - [] ----D C:\Program Files\Internet Explorer O43 - CFD: 5/23/2015 - 3:58:55 AM - [] ----D C:\Program Files\Malwarebytes Anti-Malware O43 - CFD: 7/14/2009 - 10:50:24 AM - [] ----D C:\Program Files\Microsoft Games O43 - CFD: 5/25/2015 - 8:05:28 PM - [] ----D C:\Program Files\Microsoft.NET O43 - CFD: 7/14/2009 - 7:52:30 AM - [] ----D C:\Program Files\MSBuild O43 - CFD: 5/29/2015 - 3:10:50 AM - [] ----D C:\Program Files\Nimbuzz O43 - CFD: 6/1/2015 - 8:23:04 PM - [] ----D C:\Program Files\Opera O43 - CFD: 6/3/2015 - 5:11:38 AM - [0] ----D C:\Program Files\Optimizer Pro 3.95 =>PUP.OptimizerPro O43 - CFD: 6/3/2015 - 5:43:24 AM - [] ----D C:\Program Files\Popcornew =>PUP.Popcornew O43 - CFD: 6/3/2015 - 5:16:00 AM - [0] ----D C:\Program Files\predm =>Adware.Downware O43 - CFD: 5/23/2015 - 5:28:13 AM - [] ----D C:\Program Files\PriceeMinus =>PriceMinus O43 - CFD: 6/3/2015 - 5:32:37 AM - [] ----D C:\Program Files\Pro PC Cleaner =>PUP.DoctorPC O43 - CFD: 7/14/2009 - 7:52:30 AM - [] ----D C:\Program Files\Reference Assemblies O43 - CFD: 5/23/2015 - 4:36:34 AM - [] ----D C:\Program Files\Reimage =>Rogue.ReimageRepair O43 - CFD: 6/3/2015 - 5:26:31 AM - [] ----D C:\Program Files\SearchProtect =>PUP.SearchProtect O43 - CFD: 7/14/2009 - 7:53:23 AM - [0] --H-D C:\Program Files\Uninstall Information O43 - CFD: 6/3/2015 - 5:26:44 AM - [] ----D C:\Program Files\UpdaterService O43 - CFD: 5/20/2015 - 3:37:33 AM - [] ----D C:\Program Files\VideoLAN O43 - CFD: 5/27/2015 - 12:26:38 AM - [] ----D C:\Program Files\Windows Defender O43 - CFD: 5/27/2015 - 12:26:43 AM - [] ----D C:\Program Files\Windows Journal O43 - CFD: 5/25/2015 - 3:44:37 AM - [] ----D C:\Program Files\Windows Mail =>.Microsoft Corporation O43 - CFD: 5/26/2015 - 6:34:23 PM - [] ----D C:\Program Files\Windows Media Player =>.Microsoft Corporation O43 - CFD: 7/14/2009 - 7:52:30 AM - [] ----D C:\Program Files\Windows NT O43 - CFD: 5/25/2015 - 3:44:35 AM - [] ----D C:\Program Files\Windows Photo Viewer O43 - CFD: 5/25/2015 - 3:44:36 AM - [] ----D C:\Program Files\Windows Portable Devices O43 - CFD: 5/25/2015 - 3:44:37 AM - [] ----D C:\Program Files\Windows Sidebar O43 - CFD: 6/3/2015 - 6:23:26 AM - [] ----D C:\Program Files\ZHPDiag =>.Nicolas Coolman O43 - CFD: 7/14/2009 - 7:56:49 AM - [] ----D C:\Program Files\Common Files\microsoft shared O43 - CFD: 7/14/2009 - 5:37:05 AM - [] ----D C:\Program Files\Common Files\Services O43 - CFD: 7/14/2009 - 5:37:05 AM - [] ----D C:\Program Files\Common Files\SpeechEngines O43 - CFD: 5/18/2015 - 7:27:47 PM - [] ----D C:\Program Files\Common Files\System O43 - CFD: 6/3/2015 - 4:47:38 AM - [] ----D C:\ProgramData\28341ff220e0446c9fff27c4493d622e O43 - CFD: 5/21/2015 - 6:36:18 AM - [] ----D C:\ProgramData\6214062358534923216 O43 - CFD: 7/14/2009 - 7:53:55 AM - [] -SH-D C:\ProgramData\Application Data O43 - CFD: 6/3/2015 - 5:11:30 AM - [] ----D C:\ProgramData\bb075863000015fa O43 - CFD: 7/14/2009 - 7:53:55 AM - [] -SH-D C:\ProgramData\Desktop O43 - CFD: 7/14/2009 - 7:53:55 AM - [] -SH-D C:\ProgramData\Documents O43 - CFD: 7/14/2009 - 7:53:55 AM - [] -SH-D C:\ProgramData\Favorites O43 - CFD: 6/3/2015 - 5:24:21 AM - [] ----D C:\ProgramData\FlashBeat =>PUP.FlashBeat O43 - CFD: 5/18/2015 - 7:10:39 PM - [0] ----D C:\ProgramData\IDM O43 - CFD: 5/23/2015 - 1:47:33 AM - [] ----D C:\ProgramData\Malwarebytes O43 - CFD: 5/19/2015 - 3:43:58 AM - [] ----D C:\ProgramData\McAfee O43 - CFD: 5/30/2015 - 9:08:11 AM - [] -S--D C:\ProgramData\Microsoft O43 - CFD: 5/19/2015 - 1:28:24 AM - [] ----D C:\ProgramData\Mozilla O43 - CFD: 5/23/2015 - 4:40:04 AM - [] ----D C:\ProgramData\Reimage Protector =>Rogue.ReimageRepair O43 - CFD: 5/23/2015 - 3:53:46 AM - [] ----D C:\ProgramData\Skype O43 - CFD: 7/14/2009 - 7:53:55 AM - [] -SH-D C:\ProgramData\Start Menu O43 - CFD: 7/14/2009 - 7:53:55 AM - [] -SH-D C:\ProgramData\Templates O43 - CFD: 5/22/2015 - 6:33:01 AM - [] ----D C:\ProgramData\{6027ee47-4bdd-be51-6027-7ee474bdb91d} O43 - CFD: 1/3/2002 - 4:37:06 AM - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 1/3/2002 - 4:37:21 AM - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 6/3/2015 - 5:05:33 AM - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crossbrowse =>PUP.CrossBrowser O43 - CFD: 1/3/2002 - 4:37:05 AM - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 6/3/2015 - 5:26:53 AM - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP =>Adware.GamesDesktop O43 - CFD: 5/18/2015 - 7:10:36 PM - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager O43 - CFD: 7/14/2009 - 7:42:30 AM - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 5/23/2015 - 3:58:57 AM - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware O43 - CFD: 5/29/2015 - 3:10:50 AM - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nimbuzz O43 - CFD: 6/3/2015 - 5:32:37 AM - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro PC Cleaner =>PUP.DoctorPC O43 - CFD: 5/23/2015 - 4:40:03 AM - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair =>Rogue.ReimageRepair O43 - CFD: 5/23/2015 - 2:56:43 AM - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 7/14/2009 - 10:48:45 AM - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 6/3/2015 - 5:26:44 AM - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UpdaterService O43 - CFD: 5/20/2015 - 3:37:42 AM - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN O43 - CFD: 5/18/2015 - 7:09:49 PM - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 6/3/2015 - 6:23:27 AM - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP =>.Nicolas Coolman O43 - CFD: 5/19/2015 - 3:44:11 AM - [] ----D C:\Users\libya\AppData\Roaming\Adobe O43 - CFD: 6/3/2015 - 5:24:06 AM - [] -SH-D C:\Users\libya\AppData\Roaming\AnyProtectEx =>PUP.AnyProtect O43 - CFD: 6/3/2015 - 5:29:59 AM - [] ----D C:\Users\libya\AppData\Roaming\ASPackage =>PUP.ASPackage O43 - CFD: 6/3/2015 - 6:32:50 AM - [] ----D C:\Users\libya\AppData\Roaming\DMCache O43 - CFD: 5/18/2015 - 6:51:21 PM - [] ----D C:\Users\libya\AppData\Roaming\Identities O43 - CFD: 6/3/2015 - 6:33:23 AM - [] ----D C:\Users\libya\AppData\Roaming\IDM O43 - CFD: 5/19/2015 - 3:44:11 AM - [] ----D C:\Users\libya\AppData\Roaming\Macromedia O43 - CFD: 7/14/2009 - 10:48:45 AM - [0] ----D C:\Users\libya\AppData\Roaming\Media Center Programs O43 - CFD: 5/27/2015 - 8:41:56 AM - [] -S--D C:\Users\libya\AppData\Roaming\Microsoft O43 - CFD: 5/18/2015 - 6:58:15 PM - [] ----D C:\Users\libya\AppData\Roaming\Mozilla O43 - CFD: 6/1/2015 - 2:12:46 AM - [] ----D C:\Users\libya\AppData\Roaming\Opera Software O43 - CFD: 6/3/2015 - 5:32:11 AM - [] ----D C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC O43 - CFD: 5/23/2015 - 3:35:39 AM - [] ----D C:\Users\libya\AppData\Roaming\Skype O43 - CFD: 6/3/2015 - 5:06:43 AM - [] ----D C:\Users\libya\AppData\Roaming\vlc O43 - CFD: 5/18/2015 - 7:09:37 PM - [0] ----D C:\Users\libya\AppData\Roaming\WinRAR O43 - CFD: 6/3/2015 - 6:35:34 AM - [] ----D C:\Users\libya\AppData\Roaming\ZHP =>.Nicolas Coolman O43 - CFD: 5/19/2015 - 3:47:33 AM - [0] ----D C:\Users\libya\AppData\Local\Adobe O43 - CFD: 5/18/2015 - 6:50:46 PM - [] -SH-D C:\Users\libya\AppData\Local\Application Data O43 - CFD: 6/3/2015 - 5:27:24 AM - [] ----D C:\Users\libya\AppData\Local\avabvbxvh O43 - CFD: 6/3/2015 - 5:06:31 AM - [] ----D C:\Users\libya\AppData\Local\Crossbrowse =>PUP.CrossBrowser O43 - CFD: 5/22/2015 - 8:04:26 PM - [] ----D C:\Users\libya\AppData\Local\Diagnostics O43 - CFD: 5/29/2015 - 9:10:46 PM - [] -SH-D C:\Users\libya\AppData\Local\EmieBrowserModeList O43 - CFD: 5/29/2015 - 9:10:46 PM - [] -SH-D C:\Users\libya\AppData\Local\EmieSiteList O43 - CFD: 5/29/2015 - 9:10:46 PM - [] -SH-D C:\Users\libya\AppData\Local\EmieUserList O43 - CFD: 6/3/2015 - 5:41:09 AM - [] ----D C:\Users\libya\AppData\Local\globalUpdate =>PUP.GlobalUpdate O43 - CFD: 6/3/2015 - 5:30:08 AM - [] ----D C:\Users\libya\AppData\Local\gmsd_gb_398 O43 - CFD: 5/19/2015 - 1:27:06 AM - [] ----D C:\Users\libya\AppData\Local\Google O43 - CFD: 5/18/2015 - 6:50:46 PM - [] -SH-D C:\Users\libya\AppData\Local\History O43 - CFD: 5/19/2015 - 3:44:11 AM - [] ----D C:\Users\libya\AppData\Local\Macromedia O43 - CFD: 6/3/2015 - 4:58:48 AM - [] ----D C:\Users\libya\AppData\Local\Max_Computer_Cleaner O43 - CFD: 5/30/2015 - 9:08:10 AM - [] ----D C:\Users\libya\AppData\Local\Microsoft O43 - CFD: 5/31/2015 - 4:58:51 AM - [] ----D C:\Users\libya\AppData\Local\Microsoft Games O43 - CFD: 5/18/2015 - 7:32:25 PM - [] ----D C:\Users\libya\AppData\Local\Mozilla O43 - CFD: 6/3/2015 - 3:53:59 AM - [] ----D C:\Users\libya\AppData\Local\nimbuzz O43 - CFD: 6/1/2015 - 2:12:46 AM - [] ----D C:\Users\libya\AppData\Local\Opera Software O43 - CFD: 6/3/2015 - 4:59:35 AM - [] ----D C:\Users\libya\AppData\Local\Popcornew =>PUP.Popcornew O43 - CFD: 5/23/2015 - 1:47:22 AM - [] ----D C:\Users\libya\AppData\Local\Programs O43 - CFD: 6/3/2015 - 5:39:00 AM - [] ----D C:\Users\libya\AppData\Local\Rainmaker_Software_Group_ =>PUP.DoctorPC O43 - CFD: 6/3/2015 - 5:27:03 AM - [] ----D C:\Users\libya\AppData\Local\SearchProtect =>PUP.SearchProtect O43 - CFD: 5/20/2015 - 5:49:21 AM - [] ----D C:\Users\libya\AppData\Local\Skype O43 - CFD: 6/3/2015 - 5:27:01 AM - [] ----D C:\Users\libya\AppData\Local\SmartWeb =>PUP.SmartWeb O43 - CFD: 6/3/2015 - 6:34:01 AM - [] ----D C:\Users\libya\AppData\Local\Temp O43 - CFD: 5/18/2015 - 6:50:46 PM - [] -SH-D C:\Users\libya\AppData\Local\Temporary Internet Files O43 - CFD: 6/3/2015 - 4:01:49 AM - [] ----D C:\Users\libya\AppData\Local\VirtualStore O43 - CFD: 7/14/2009 - 7:42:04 AM - [] R---D C:\Users\libya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 5/27/2015 - 12:32:17 AM - [] R---D C:\Users\libya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 5/19/2015 - 1:27:16 AM - [] ----D C:\Users\libya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome O43 - CFD: 5/18/2015 - 7:10:36 PM - [] ----D C:\Users\libya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager O43 - CFD: 7/14/2009 - 7:37:42 AM - [] R---D C:\Users\libya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 6/3/2015 - 5:27:01 AM - [] R---D C:\Users\libya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 5/18/2015 - 7:09:49 PM - [] ----D C:\Users\libya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR ~ Program Folder: 125 Scanned in 00mn AMs ---\\ Last modified or created files under Windows and System32 (O44) O44 - LFC:[MD5.F4BF196240FA7D6E39F0FD446E1A9FC2] - 5/23/2015 - 2:00:40 AM ---A- . (.Microsoft Corporation - أداة إزالة البرامج الضارة لـ Microsoft Wind.) -- C:\Windows\System32\MRT.exe [137310008] O44 - LFC:[MD5.3C21F7E95FFCA33EF1A83AA33D9663CF] - 5/23/2015 - 2:58:50 AM ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [23256] O44 - LFC:[MD5.155BF99B2B87E0C298CAC3B4B8136D83] - 5/23/2015 - 2:58:50 AM ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [92888] O44 - LFC:[MD5.167BCE00050B19DA25065335645A3C7A] - 5/23/2015 - 2:58:50 AM ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [51928] O44 - LFC:[MD5.C89781A2A37DBB385C656CE44345BEBF] - 5/23/2015 - 3:56:28 AM ---A- . (...) -- C:\Windows\Reimage.ini [99] =>Rogue.ReimageRepair O44 - LFC:[MD5.9E0403FADA024E5F5F0D80C8363C8098] - 5/24/2015 - 10:01:39 PM ---A- . (.Microsoft Corporation - Compatibility Appraiser.) -- C:\Windows\System32\appraiser.dll [860160] O44 - LFC:[MD5.AC4B4920CDCA5CD5BF0C906FE1DB1E16] - 5/24/2015 - 10:01:39 PM ---A- . (.Microsoft Corporation - Compatibility Upgrade Migration Host.) -- C:\Windows\System32\acmigration.dll [26112] O44 - LFC:[MD5.470F4975DEC5770E8F9B4782295C3827] - 5/24/2015 - 10:01:39 PM ---A- . (.Microsoft Corporation - Device Inventory Library.) -- C:\Windows\System32\devinv.dll [331264] O44 - LFC:[MD5.5F35948A3CEA196E2C0ED695020913A6] - 5/24/2015 - 10:01:39 PM ---A- . (.Microsoft Corporation - Inventory Agent.) -- C:\Windows\System32\invagent.dll [630784] O44 - LFC:[MD5.F57E1D225AE5C2C8F475A99BFDF018F4] - 5/24/2015 - 10:01:40 PM ---A- . (.Microsoft Corporation - Application Impact Telemetry Static Analyze.) -- C:\Windows\System32\aitstatic.exe [1167520] O44 - LFC:[MD5.A8019D0CAAC186C4461DAEAFB1DE6304] - 5/24/2015 - 10:01:40 PM ---A- . (.Microsoft Corporation - General Telemetry.) -- C:\Windows\System32\generaltel.dll [576000] O44 - LFC:[MD5.DC81EECB36A1D19B428C73EE85B0BC91] - 5/24/2015 - 9:42:08 PM ----- . (.Microsoft Corporation - Microsoft Malware Protection Signature Upda.) -- C:\Windows\System32\MpSigStub.exe [246920] O44 - LFC:[MD5.704314FD398C81D5F342CAA5DF7B7F21] - 5/25/2015 - 1:37:01 AM ---A- . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbemcomn.dll [363008] O44 - LFC:[MD5.A399514D3B28C9A3453A486BBAAFF1C7] - 5/25/2015 - 1:37:22 AM ---A- . (.Microsoft Corporation - Panther Engine Module.) -- C:\Windows\System32\wdscore.dll [189952] O44 - LFC:[MD5.C236A8735A48B165A2A7724357DBE332] - 5/25/2015 - 1:37:34 AM ---A- . (...) -- C:\Windows\System32\RacRules.xml [105559] O44 - LFC:[MD5.C42D1CE706C54875A6A4BBAD0429288C] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Bashkir Keyboard Layout.) -- C:\Windows\System32\KBDBASH.DLL [6144] O44 - LFC:[MD5.BD5B1737FDE2FF7AD036FADE1CAC4D0D] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Belarusian Keyboard Layout.) -- C:\Windows\System32\KBDBLR.DLL [6144] O44 - LFC:[MD5.D3BFA17457E5EAB5B7DABEDA21961183] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Bengali Keyboard Layout.) -- C:\Windows\System32\KBDINBEN.DLL [6656] O44 - LFC:[MD5.E2F6200309179812F1EC40245F988C15] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Bulgarian Keyboard Layout.) -- C:\Windows\System32\KBDBULG.DLL [6144] O44 - LFC:[MD5.DD3524C9B0EC264BF74B4C5A84891D76] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Czech_101 Keyboard Layout.) -- C:\Windows\System32\KBDCZ1.DLL [7168] O44 - LFC:[MD5.8711853E43B65F5CA1CCD48980BC6A22] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - DEC LK411-AJ Keyboard Layout.) -- C:\Windows\System32\kbdlk41a.dll [7168] O44 - LFC:[MD5.0CCB0C66DCD24A742CFBC06CD49EBD0D] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Georgian Keyboard Layout.) -- C:\Windows\System32\KBDGEO.DLL [5632] O44 - LFC:[MD5.93132CE66FC74818B4FD32E13C24C4BB] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - German_IBM Keyboard Layout.) -- C:\Windows\System32\KBDGR1.DLL [6656] O44 - LFC:[MD5.86EA2C61BCEC344195AE33B995CAB9C3] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Greek_Latin Keyboard Layout.) -- C:\Windows\System32\KBDGKL.DLL [6656] O44 - LFC:[MD5.E615582BCA38987368E5598BD114A6BC] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Hindi Keyboard Layout.) -- C:\Windows\System32\KBDINHIN.DLL [6144] O44 - LFC:[MD5.911DA311FF63B6F91D2BD05EFED9756A] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Kannada Keyboard Layout.) -- C:\Windows\System32\KBDINKAN.DLL [6144] O44 - LFC:[MD5.0DEDC0314F3EB8C0253A88D72A73E019] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Lithuanian Keyboard Layout.) -- C:\Windows\System32\KBDLT1.DLL [6144] O44 - LFC:[MD5.3174AA5D2A5BCDF4DB378FC0C24B08A9] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Maori Keyboard Layout.) -- C:\Windows\System32\KBDMAORI.DLL [6144] O44 - LFC:[MD5.A92149941A0D6A0A14AC116245E1E08F] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Marathi Keyboard Layout.) -- C:\Windows\System32\KBDINMAR.DLL [6144] O44 - LFC:[MD5.D667E487B72FEB7FFEAD869ECC0467CF] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Microsoft DirectPlay8 Address.) -- C:\Windows\System32\dpnaddr.dll [2560] O44 - LFC:[MD5.7FA7F2E249A5DCBB7970630E15E1F482] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Microsoft S3 Emulated Device Cap Driver.) -- C:\Windows\System32\Drivers\vms3cap.sys [5632] O44 - LFC:[MD5.48DC9C2926AAE98D9E3FE14570180246] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Mongolian Keyboard Layout.) -- C:\Windows\System32\KBDMON.DLL [6144] O44 - LFC:[MD5.D35F4DFF5D7B3D6503CF9888B833C801] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - NLSBuild resource DLL.) -- C:\Windows\System32\nlsbres.dll [69120] O44 - LFC:[MD5.B566E8F3EB5953722E11D113285E0ACB] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Nepali Keyboard Layout.) -- C:\Windows\System32\KBDNEPR.DLL [6656] O44 - LFC:[MD5.F533E1EA22FB9B1426010D285BFDD7D4] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Oriya Keyboard Layout.) -- C:\Windows\System32\KBDINORI.DLL [6144] O44 - LFC:[MD5.A02691FF3AA0763CF4E312DF56A7AC50] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Portuguese Keyboard Layout.) -- C:\Windows\System32\KBDPO.DLL [6656] O44 - LFC:[MD5.9CA1705E2EBFE63F2E92628415934960] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Swiss French Keyboard Layout.) -- C:\Windows\System32\KBDSF.DLL [6656] O44 - LFC:[MD5.CDD67E0C0E3205CD00F5CD56E4DC9104] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Swiss German Keyboard Layout.) -- C:\Windows\System32\KBDSG.DLL [7168] O44 - LFC:[MD5.566925A00B8F439D6155F023E9494DEB] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Tajik Keyboard Layout.) -- C:\Windows\System32\KBDTAJIK.DLL [6144] O44 - LFC:[MD5.05477A526F6EAF10952DC63FFCED6609] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Tamil Keyboard Layout.) -- C:\Windows\System32\KBDINTAM.DLL [6144] O44 - LFC:[MD5.11DB22E2FBAC2854DAA7541B16E11F41] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Telugu Keyboard Layout.) -- C:\Windows\System32\KBDINTEL.DLL [6144] O44 - LFC:[MD5.E097726A556E584EE8CEF98FCD848033] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Turkish F Keyboard Layout.) -- C:\Windows\System32\KBDTUF.DLL [6656] O44 - LFC:[MD5.F7BAA05246D68845641DF85D2D4B77AA] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Turkish Q Keyboard Layout.) -- C:\Windows\System32\KBDTUQ.DLL [6656] O44 - LFC:[MD5.BDEB4A838DA1E2D9C9631298FA3D58C5] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Turkmen Keyboard Layout.) -- C:\Windows\System32\KBDTURME.DLL [6144] O44 - LFC:[MD5.357B990A4249D7F7485B230C0CC8825A] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - United States Keyboard Layout.) -- C:\Windows\System32\KBDUS.DLL [6144] O44 - LFC:[MD5.86B58589C695702E05395D4E34D9D39D] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Uyghur Keyboard Layout.) -- C:\Windows\System32\KBDUGHR1.DLL [6144] O44 - LFC:[MD5.E56C4703D0D9B476EF6195AD22C2ACC0] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - Windows NT PIF Manager Icon Resources Libra.) -- C:\Windows\System32\pifmgr.dll [35328] O44 - LFC:[MD5.3F0BB313E64983FF701D43C930530AC7] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - موارد إطار عمل معالج الإعداد.) -- C:\Windows\System32\spwizres.dll [7680] O44 - LFC:[MD5.B243C97C4F5292CADB71E850DA7FEB1D] - 5/25/2015 - 1:37:35 AM ---A- . (.Microsoft Corporation - ناشر Blb.) -- C:\Windows\System32\BlbEvents.dll [52736] O44 - LFC:[MD5.9036377B8A6C15DC2EEC53E489D159B5] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\Drivers\hdaudbus.sys [108544] O44 - LFC:[MD5.A5EF29D5315111C80A5C1ABAD14C8972] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - High Definition Audio Function Driver.) -- C:\Windows\System32\Drivers\HdAudio.sys [304128] O44 - LFC:[MD5.B373C8ACBB78D7B31AD4FAC8BD4F2102] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - Hyper-V Integration Components Coinstaller.) -- C:\Windows\System32\IcCoinstall.dll [113664] O44 - LFC:[MD5.993ABFB6DFD197927C3B24A36C966039] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - Hyper-V Integration Components Coinstaller.) -- C:\Windows\System32\VmdCoinstall.dll [113664] O44 - LFC:[MD5.FFD0CF7A58905B8D05CDA6F8554A346D] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - Hyper-V VMBUS Coinstaller.) -- C:\Windows\System32\VmbusCoinstaller.dll [116224] O44 - LFC:[MD5.035074DAEB2333A248FD9C6B88AD16CD] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - ISCII Code Page Translation DLL.) -- C:\Windows\System32\C_ISCII.DLL [11264] O44 - LFC:[MD5.3C3C78515F5AB448B022BDF5B8FFDD2E] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) -- C:\Windows\System32\Drivers\wanarp.sys [63488] O44 - LFC:[MD5.46A8664B446B5ED10DBDEF8B6DE7F648] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - Microsoft RDP Reflector Display Driver.) -- C:\Windows\System32\RDPREFDD.dll [26624] O44 - LFC:[MD5.1CB91B2BD8F6DD367DFC2EF26FD751B2] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - Named Pipe Transport Driver.) -- C:\Windows\System32\Drivers\tdpipe.sys [18432] O44 - LFC:[MD5.23DAE03F29D253AE74C44F99E515F9A1] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - RDP Miniport.) -- C:\Windows\System32\Drivers\RDPCDD.sys [6656] O44 - LFC:[MD5.F977BE7B8C5462087374364EAFB3C15B] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - Shell Browser UI Library.) -- C:\Windows\System32\browseui.dll [10752] O44 - LFC:[MD5.6D4CCAEDC018F1CF52866BBBAA235982] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - Small Form Factor SD Protocol Driver.) -- C:\Windows\System32\Drivers\sffp_sd.sys [12800] O44 - LFC:[MD5.FD82D2B38C465A55C527E339BA1201B1] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) -- C:\Windows\System32\Drivers\USBCAMD.sys [25856] O44 - LFC:[MD5.E071E5BE621FEC4590117C488A78AE32] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) -- C:\Windows\System32\Drivers\USBCAMD2.sys [25856] O44 - LFC:[MD5.D295BED4B898F0FD999FCFA9B32B071B] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - User-Mode Bus Enumerator.) -- C:\Windows\System32\Drivers\umbus.sys [39936] O44 - LFC:[MD5.B1462F0C851B0B0F3FBC4ADBB09CDF5E] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - Virtual Machine Integration Component Time.) -- C:\Windows\System32\vmictimeprovider.dll [47616] O44 - LFC:[MD5.CF9E55F8D1E527FE19153604EADC918C] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - VmBus User Mode Pipe DLL.) -- C:\Windows\System32\vmbuspipe.dll [14336] O44 - LFC:[MD5.0A8E209F3C1D1FB6889465D1019CC5BF] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - Windows Shell Obsolete APIs.) -- C:\Windows\System32\shunimpl.dll [10752] O44 - LFC:[MD5.0693B5EC673E34DC147E195779A4DCF6] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - برنامج تشغيل عامل تصفية قارئ البطاقة الذكية.) -- C:\Windows\System32\Drivers\scfilter.sys [26624] O44 - LFC:[MD5.9E3CED91863E6EE98C24794D05E27A71] - 5/25/2015 - 1:37:36 AM ---A- . (.Microsoft Corporation - برنامج تشغيل عامل تصفية لوحة المفاتيح HID.) -- C:\Windows\System32\Drivers\kbdhid.sys [28160] O44 - LFC:[MD5.21CE1E98A17FD46BE371719DFD046958] - 5/25/2015 - 1:37:37 AM ---A- . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\System32\wshirda.dll [11264] O44 - LFC:[MD5.4BD7134618C1D2A27466A099062547BF] - 5/25/2015 - 1:37:37 AM ---A- . (.Microsoft Corporation - برنامج تشغيل WMI IPMI.) -- C:\Windows\System32\Drivers\IPMIDrv.sys [65536] O44 - LFC:[MD5.1EFBC664ABFF416D1D07DB115DCB264F] - 5/25/2015 - 1:37:38 AM ---A- . (.Microsoft Corporation - ACPI Power Metering Driver.) -- C:\Windows\System32\Drivers\acpipmi.sys [10240] O44 - LFC:[MD5.38FBE267E7E6983311179230FACB1017] - 5/25/2015 - 1:37:38 AM ---A- . (.Microsoft Corporation - MS PPP Framing Driver (Strong Encryption).) -- C:\Windows\System32\Drivers\ndiswan.sys [118784] O44 - LFC:[MD5.D4D77455211E204F370D08F4963063CE] - 5/25/2015 - 1:37:38 AM ---A- . (.Microsoft Corporation - Microsoft VMBus HID Miniport.) -- C:\Windows\System32\Drivers\VMBusHID.sys [17920] O44 - LFC:[MD5.41EE23F636C6E9BDE5E8C09454CBEEFD] - 5/25/2015 - 1:37:38 AM ---A- . (.Microsoft Corporation - Microsoft® Korean IME.) -- C:\Windows\System32\imkr80.ime [430080] O44 - LFC:[MD5.03A88560EF6B5F746A9AC5BA1C0A36C7] - 5/25/2015 - 1:37:38 AM ---A- . (.Microsoft Corporation - Remote Desktop Session Host Server Connecti.) -- C:\Windows\System32\rdpcfgex.dll [8704] O44 - LFC:[MD5.10C19F8290891AF023EAEC0832E1EB4D] - 5/25/2015 - 1:37:38 AM ---A- . (.Microsoft Corporation - USB Miniport Driver for Input Devices.) -- C:\Windows\System32\Drivers\hidusb.sys [24064] O44 - LFC:[MD5.AAF7BEB63E2CC499834B608A85A55E4E] - 5/25/2015 - 1:37:38 AM ---A- . (.Microsoft Corporation - WSD Challenge Component.) -- C:\Windows\System32\wsdchngr.dll [21504] O44 - LFC:[MD5.CFD8B8537036CF35F6254192997A4D8E] - 5/25/2015 - 1:37:38 AM ---A- . (.Microsoft Corporation - Windows Shell User Logon.) -- C:\Windows\System32\shgina.dll [20992] O44 - LFC:[MD5.B5506B451BFE7148ECA7056BDA2970BD] - 5/25/2015 - 1:37:38 AM ---A- . (.Microsoft Corporation - Wrapper Dll for Richedit 1.0.) -- C:\Windows\System32\riched32.dll [8704] O44 - LFC:[MD5.89E783711AF91AF09E1EF30EF3107446] - 5/25/2015 - 1:37:38 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي الأساسية الخاصة ب.) -- C:\Windows\System32\sscore.dll [9728] O44 - LFC:[MD5.5C18CD22BE4628865FCB63337A6E5EF6] - 5/25/2015 - 1:37:39 AM ---A- . (...) -- C:\Windows\System32\ScavengeSpace.xml [10429] O44 - LFC:[MD5.F024449C97EC1E464AAFFDA18593DB88] - 5/25/2015 - 1:37:39 AM ---A- . (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\Drivers\dfsc.sys [78336] O44 - LFC:[MD5.6D666983C638F5E507C4A11AED1291CC] - 5/25/2015 - 1:37:39 AM ---A- . (.Microsoft Corporation - DS Authorization for Services.) -- C:\Windows\System32\dsauth.dll [30208] O44 - LFC:[MD5.7B3FD36359DE5D2EE49D213CCAD13427] - 5/25/2015 - 1:37:39 AM ---A- . (.Microsoft Corporation - ELS Transliteration Service.) -- C:\Windows\System32\elsTrans.dll [22528] O44 - LFC:[MD5.126F8331BD023178C7F0EF2F5EDE16B3] - 5/25/2015 - 1:37:39 AM ---A- . (.Microsoft Corporation - Microsoft Fax Print Monitor.) -- C:\Windows\System32\FXSMON.dll [39424] O44 - LFC:[MD5.543324F86787BFA31AABBAA7A91D08D0] - 5/25/2015 - 1:37:39 AM ---A- . (.Microsoft Corporation - Microsoft Narrator Text Renderer.) -- C:\Windows\System32\TRAPI.dll [21504] O44 - LFC:[MD5.9E122E5CD1BB79CF8F0BCEAC947B81C0] - 5/25/2015 - 1:37:39 AM ---A- . (.Microsoft Corporation - NAP GPEdit Extension.) -- C:\Windows\System32\napdsnap.dll [68096] O44 - LFC:[MD5.57A51217581614DE07F30E34D6BB4993] - 5/25/2015 - 1:37:39 AM ---A- . (.Microsoft Corporation - Offline Files Temporary Shim.) -- C:\Windows\System32\cscdll.dll [23040] O44 - LFC:[MD5.0552A8684BF7566F744D5B19FF6AEC6B] - 5/25/2015 - 1:37:39 AM ---A- . (.Microsoft Corporation - Perfmon Counter Access.) -- C:\Windows\System32\bitsperf.dll [19456] O44 - LFC:[MD5.0435045377BF76438CE5BF385995C699] - 5/25/2015 - 1:37:39 AM ---A- . (.Microsoft Corporation - RDP Encoder Mirror Driver.) -- C:\Windows\System32\RDPENCDD.dll [121856] O44 - LFC:[MD5.A42E7748BE906434C5FD17161D168C20] - 5/25/2015 - 1:37:39 AM ---A- . (.Microsoft Corporation - Scheduler Service Client DLL.) -- C:\Windows\System32\schedcli.dll [17408] O44 - LFC:[MD5.3EF0D8AB08385AAB5802E773511A2E6A] - 5/25/2015 - 1:37:39 AM ---A- . (.Microsoft Corporation - Windows Logon User Interface Host.) -- C:\Windows\System32\LogonUI.exe [10752] O44 - LFC:[MD5.AC122407B29378FF9646F03404AC7C54] - 5/25/2015 - 1:37:39 AM ---A- . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\System32\wshbth.dll [36352] O44 - LFC:[MD5.B2FA25D9B17A68BB93D58B0556E8C90D] - 5/25/2015 - 1:37:39 AM ---A- . (.Microsoft Corporation - برنامج تشغيل واجهة النفق لـ Microsoft.) -- C:\Windows\System32\Drivers\tunnel.sys [108544] O44 - LFC:[MD5.457C561BA80E02F1230DD0B87DA770A9] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - BitLocker Drive Encryption: Configuration T.) -- C:\Windows\System32\manage-bde.exe [61952] O44 - LFC:[MD5.CA1870CDB1052F33B05E338F2B326A3D] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - BitLocker Drive Encryption: Repair Tool.) -- C:\Windows\System32\repair-bde.exe [57344] O44 - LFC:[MD5.326A5BDD4F299EA8B4843BB78F06A6B8] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - DLL Interface to TermDD Device Driver.) -- C:\Windows\System32\icaapi.dll [15872] O44 - LFC:[MD5.7069AAB8536F29ED7323140973A2894B] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - DMO Runtime.) -- C:\Windows\System32\msdmo.dll [30720] O44 - LFC:[MD5.E84735F79C272FCEC320A6BED2861475] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - Intel G711 CODEC.) -- C:\Windows\System32\g711codc.ax [45568] O44 - LFC:[MD5.BF7DDBE14FA4B68AAB6A3C78EF5C96B8] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - Microsoft MIB-II subagent.) -- C:\Windows\System32\inetmib1.dll [52736] O44 - LFC:[MD5.CBE8C58A8579CFE5FCCF809E6F114E89] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - Multi-Transport Composite Bus Enumerator.) -- C:\Windows\System32\Drivers\CompositeBus.sys [31232] O44 - LFC:[MD5.F88E4A26A7C8112FD1809CAF0F512D27] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - MultiUser Query Utility.) -- C:\Windows\System32\query.exe [14848] O44 - LFC:[MD5.6E2C504C11A2D0B3820EDAF66E6DF06B] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - ODBC Driver Configuration Program.) -- C:\Windows\System32\odbcconf.dll [40960] O44 - LFC:[MD5.6C796F88B7D9BF52A45757E2C837185A] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - Reflector Driver API.) -- C:\Windows\System32\rdprefdrvapi.dll [21504] O44 - LFC:[MD5.2B53A92F4BB168B893C4722F56C2201E] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - Remote Desktop Services Change Utility.) -- C:\Windows\System32\change.exe [15360] O44 - LFC:[MD5.595B73359FD9B724E7981B0989FC274C] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - Remote Desktop Services Reset Utility.) -- C:\Windows\System32\reset.exe [15360] O44 - LFC:[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\Drivers\cdrom.sys [108544] O44 - LFC:[MD5.2C098921217204301D76BF3BD5D953BB] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - Unload PerfMon Counters.) -- C:\Windows\System32\unlodctr.exe [34304] O44 - LFC:[MD5.5831FC32006FB68B4014B16837CE4A95] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - User Profile WMI Provider.) -- C:\Windows\System32\profprov.dll [28672] O44 - LFC:[MD5.373A87DBFD387DDC54375F547834FBBD] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - VBI Surface Allocator Filter.) -- C:\Windows\System32\vbisurf.ax [33792] O44 - LFC:[MD5.6FD5074B8CD05450F3F040993C6C2F1D] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - Virtual Machine Bus Resource DLL.) -- C:\Windows\System32\vmbusres.dll [44544] O44 - LFC:[MD5.C0AB322DAE9E26F13C4B6BBBABCFA148] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - Virtual Machine Integration Component Servi.) -- C:\Windows\System32\vmicres.dll [53760] O44 - LFC:[MD5.B0AC902EFD7E46708014625ECEB25741] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - Virtual Machine Storage Filter Resource DLL.) -- C:\Windows\System32\vmstorfltres.dll [38400] O44 - LFC:[MD5.71C39495C1BC7C3979B4CFAF59B1265B] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - WinPE network installer.) -- C:\Windows\System32\netcfg.exe [25600] O44 - LFC:[MD5.FB1BA42D1A1440E99C6B8667E141CFB1] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - Windows Remote Desktop Services Performance.) -- C:\Windows\System32\perfts.dll [17408] O44 - LFC:[MD5.86B9E27CDB040DE1C981BEC2A56326A7] - 5/25/2015 - 1:37:40 AM ---A- . (.Microsoft Corporation - Windows Ribbon Framework Resources.) -- C:\Windows\System32\UIRibbonRes.dll [1164800] O44 - LFC:[MD5.03783D0840B2C54D7665248425C74417] - 5/25/2015 - 1:37:41 AM ---A- . (...) -- C:\Windows\System32\dosx.exe [53600] O44 - LFC:[MD5.F0016853FA3F38F55FD868FF74C0359B] - 5/25/2015 - 1:37:41 AM ---A- . (.Microsoft Corporation - Adaptive SQM WDI Plugin.) -- C:\Windows\System32\wdiasqmmodule.dll [31744] O44 - LFC:[MD5.C2DF5544931944AE00C59A0B3080EBFE] - 5/25/2015 - 1:37:41 AM ---A- . (.Microsoft Corporation - Lua manifest install.) -- C:\Windows\System32\luainstall.dll [41984] O44 - LFC:[MD5.5F8B3561CD7024C0F488A2E43434AE22] - 5/25/2015 - 1:37:41 AM ---A- . (.Microsoft Corporation - MUI Callback for font registry settings.) -- C:\Windows\System32\muifontsetup.dll [13312] O44 - LFC:[MD5.2883942DF154A6CEBDB75B42C0093CF3] - 5/25/2015 - 1:37:41 AM ---A- . (.Microsoft Corporation - Microsoft Network Provider for MPEG2 based.) -- C:\Windows\System32\MSDvbNP.ax [59904] O44 - LFC:[MD5.7319102526BD11B45FD66335CF90CA12] - 5/25/2015 - 1:37:41 AM ---A- . (.Microsoft Corporation - Microsoft Windows HotStart User Agent.) -- C:\Windows\System32\HotStartUserAgent.dll [22528] O44 - LFC:[MD5.7A6986DD659B96398A11AF5173892715] - 5/25/2015 - 1:37:41 AM ---A- . (.Microsoft Corporation - Microsoft® Cabinet File API.) -- C:\Windows\System32\cabinet.dll [73216] O44 - LFC:[MD5.3C519BC7767F41F1C88DB0395F31A817] - 5/25/2015 - 1:37:41 AM ---A- . (.Microsoft Corporation - OPK Sysprep Plugin.) -- C:\Windows\System32\spopk.dll [19968] O44 - LFC:[MD5.E81591FCC19409E11F9A913728746391] - 5/25/2015 - 1:37:41 AM ---A- . (.Microsoft Corporation - Preview Handler Surrogate Host.) -- C:\Windows\System32\prevhost.exe [31232] O44 - LFC:[MD5.2F885864D5BC8A16C86BEE595969A48A] - 5/25/2015 - 1:37:41 AM ---A- . (.Microsoft Corporation - TDI Wrapper.) -- C:\Windows\System32\Drivers\tdi.sys [21504] O44 - LFC:[MD5.1A078C3FE1C1F9C8561CD600C69AD300] - 5/25/2015 - 1:37:41 AM ---A- . (.Microsoft Corporation - إدارة نهج إعادة توجيه USB لـ Windows.) -- C:\Windows\System32\Drivers\usbrpm.sys [26112] O44 - LFC:[MD5.8E4B58E12B3FA65ED1462846906E0B59] - 5/25/2015 - 1:37:41 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي الخاصة بعميل ترخي.) -- C:\Windows\System32\sppc.dll [121344] O44 - LFC:[MD5.FAA05DD44E5DF264AEBE3F03BA4211BB] - 5/25/2015 - 1:37:41 AM ---A- . (.Microsoft Corporation - ‎‎عارض معرض الصور.) -- C:\Windows\System32\shimgvw.dll [35840] O44 - LFC:[MD5.1DE21EC4A2232FF4F5298ADCAE7B3690] - 5/25/2015 - 1:37:41 AM ---A- . (.Radius Inc. - Cinepak® Codec.) -- C:\Windows\System32\iccvid.dll [82944] O44 - LFC:[MD5.AD61F7AFE913B2642650504DF283AA63] - 5/25/2015 - 1:37:42 AM ---A- . (.Microsoft Corporation - DNSCache Unattend Generic Command.) -- C:\Windows\System32\dnscacheugc.exe [28672] O44 - LFC:[MD5.6DB7ECBA34165ACB99A1A3C7F739E757] - 5/25/2015 - 1:37:42 AM ---A- . (.Microsoft Corporation - EAP Generic UI.) -- C:\Windows\System32\eappgnui.dll [94208] O44 - LFC:[MD5.18F02C555FBC9885DF9DB77754D6BB9B] - 5/25/2015 - 1:37:42 AM ---A- . (.Microsoft Corporation - Find String (QGREP) Utility.) -- C:\Windows\System32\findstr.exe [62976] O44 - LFC:[MD5.CCA67BD391CFC9F036323B2522887A6A] - 5/25/2015 - 1:37:42 AM ---A- . (.Microsoft Corporation - Microsoft Sync Center.) -- C:\Windows\System32\mobsync.exe [101376] O44 - LFC:[MD5.2BF84985DE59544A0460BB33F804DA3A] - 5/25/2015 - 1:37:42 AM ---A- . (.Microsoft Corporation - Microsoft Windows Recovery Agent.) -- C:\Windows\System32\ReAgentc.exe [22016] O44 - LFC:[MD5.E460AFD3A201408919ADB05977095E8D] - 5/25/2015 - 1:37:42 AM ---A- . (.Microsoft Corporation - Microsoft® Remote Desktop Services Cryptogr.) -- C:\Windows\System32\tlscsp.dll [69632] O44 - LFC:[MD5.20B3934DB73EABA2B49B7177873CB81F] - 5/25/2015 - 1:37:42 AM ---A- . (.Microsoft Corporation - Net Win32 API Helpers DLL.) -- C:\Windows\System32\netutils.dll [22528] O44 - LFC:[MD5.337CC9E8EA6F7BE53EB1B200365CE918] - 5/25/2015 - 1:37:42 AM ---A- . (.Microsoft Corporation - Remote Desktop Services End Process Utility.) -- C:\Windows\System32\tskill.exe [22528] O44 - LFC:[MD5.1CAD25B4E90A2648FDD25F4F00BE3C37] - 5/25/2015 - 1:37:42 AM ---A- . (.Microsoft Corporation - Reset Session Utility.) -- C:\Windows\System32\rwinsta.exe [20992] O44 - LFC:[MD5.CCC607182821134A38D7A400AE063F73] - 5/25/2015 - 1:37:42 AM ---A- . (.Microsoft Corporation - Session Connection Utility.) -- C:\Windows\System32\tscon.exe [21504] O44 - LFC:[MD5.D9A93A44116C4FDED67F1F83BC8AE88E] - 5/25/2015 - 1:37:42 AM ---A- . (.Microsoft Corporation - Session Disconnection Utility.) -- C:\Windows\System32\tsdiscon.exe [22016] O44 - LFC:[MD5.7BF2B91D4F9B26409974A93E63E5E895] - 5/25/2015 - 1:37:42 AM ---A- . (.Microsoft Corporation - Session Logoff Utility.) -- C:\Windows\System32\logoff.exe [21504] O44 - LFC:[MD5.37E31A84967F6E5135FF0CFD10BFE487] - 5/25/2015 - 1:37:42 AM ---A- . (.Microsoft Corporation - Session Remote Control Utility.) -- C:\Windows\System32\shadow.exe [20992] O44 - LFC:[MD5.4DAD175C07B982A1518FE64FDBB7071A] - 5/25/2015 - 1:37:42 AM ---A- . (.Microsoft Corporation - Windows Fault Reporting.) -- C:\Windows\System32\WerFaultSecure.exe [28672] O44 - LFC:[MD5.E2D56AE1D40E3725084054CD8E9CFBB1] - 5/25/2015 - 1:37:42 AM ---A- . (.Microsoft Corporation - Windows Image Acquisition RPC client DLL.) -- C:\Windows\System32\wiarpc.dll [33280] O44 - LFC:[MD5.AA5F3F417DF0F470D67A7862451EA8E1] - 5/25/2015 - 1:37:42 AM ---A- . (.Microsoft Corporation - برنامج تشغيل DirectShow MCI.) -- C:\Windows\System32\mciqtz32.dll [36352] O44 - LFC:[MD5.EB6C16CE0163AD282E95FCE5EE9BA518] - 5/25/2015 - 1:37:42 AM ---A- . (.No owner - ‎‎تطبيق PrintBrm.) -- C:\Windows\System32\PrintBrmUi.exe [66048] O44 - LFC:[MD5.BC080CEA43CB990F28B049742706581F] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - BCD Sysprep Plugin.) -- C:\Windows\System32\spbcd.dll [61952] O44 - LFC:[MD5.CE61B59CE4FC335A46A7D016C3AB2F59] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - BitLocker Drive Encryption: Drive Preparati.) -- C:\Windows\System32\BdeHdCfg.exe [126464] O44 - LFC:[MD5.445B0083337705538690841766921AD1] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - Change INI File Mapping Utility.) -- C:\Windows\System32\chgusr.exe [20992] O44 - LFC:[MD5.310AD32D483D4E16A62CDFD52B1C5D7E] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - Change port Utility.) -- C:\Windows\System32\chgport.exe [22528] O44 - LFC:[MD5.382BDDDE3438F9A65935ABC6B3F76D1B] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - DirectShow Runtime..) -- C:\Windows\System32\amstream.dll [70656] O44 - LFC:[MD5.2C60338287CB0AEC009D0B48CEA864D2] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - DiskPart.) -- C:\Windows\System32\diskpart.exe [133632] O44 - LFC:[MD5.6468512559971A92A66E2AA08AC8BA61] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - Microsoft Fax TIFF library.) -- C:\Windows\System32\FXSTIFF.dll [430080] O44 - LFC:[MD5.2AF094C822BD6094F14A8E85FB51D52A] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - Microsoft Cluster Resource Utility DLL.) -- C:\Windows\System32\resutils.dll [71168] O44 - LFC:[MD5.AC32AF909111561893E42E8EC89C5532] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - Microsoft IME Old Style.) -- C:\Windows\System32\IMJP10.IME [1027584] O44 - LFC:[MD5.100733DAEA508929EDDF1A3A3B7324CE] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - Microsoft® InfoTech IR Local DLL.) -- C:\Windows\System32\itircl.dll [158720] O44 - LFC:[MD5.D2A937964199F647B1C3BC435712E5D9] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - Name Resolution Proxy (NRP) RPC interface.) -- C:\Windows\System32\nrpsrv.dll [11776] O44 - LFC:[MD5.795582E10CA3DCF596C01B58FFE3AC28] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - Query Remote Desktop Session Host Server Ut.) -- C:\Windows\System32\qappsrv.exe [21504] O44 - LFC:[MD5.4C640D37A9FFD4B92320059951887441] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - Query User Utility.) -- C:\Windows\System32\quser.exe [23040] O44 - LFC:[MD5.B2E1E4A16EDD02396F451F915FA3CBFA] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - Remote Access TAPI Compliance Layer.) -- C:\Windows\System32\rastapi.dll [69632] O44 - LFC:[MD5.3D97D200A1449F3995E88BEA8F7D0C81] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - WDM Streaming Crossbar.) -- C:\Windows\System32\ksxbar.ax [48640] O44 - LFC:[MD5.3F2B83695E5BF11930C16AF50E991F96] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - Windows Media Player Proxy Stub Dll.) -- C:\Windows\System32\wmpps.dll [144384] O44 - LFC:[MD5.56D80B7E622338AF0F93B25A85D97188] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - Windows NT System Setup.) -- C:\Windows\System32\syssetup.dll [14848] O44 - LFC:[MD5.3379984F13BDC0F26783E3E0C678ED5C] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - Windows Sound Recorder.) -- C:\Windows\System32\WavDest.dll [46592] O44 - LFC:[MD5.E5A4A1326A02F8E7B59E6C3270CE7202] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - Workstation Service Client DLL.) -- C:\Windows\System32\wkscli.dll [47104] O44 - LFC:[MD5.4542DED3177F52CF075565987885EB0D] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - iSCSI Discovery tool.) -- C:\Windows\System32\iscsicli.exe [144896] O44 - LFC:[MD5.B0180B20B065D89232A78A40FE56EAA6] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - خدمة إعلامات SPP.) -- C:\Windows\System32\sppuinotify.dll [53760] O44 - LFC:[MD5.44F5C1CF70AC8F7239F3B3667E58697A] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - مشغل نهج الشهادة.) -- C:\Windows\System32\CertPolEng.dll [65024] O44 - LFC:[MD5.50BB4FBC720D23497EEB5C9DAC497405] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - واجهة مستخدم مجلد المستندات.) -- C:\Windows\System32\mydocs.dll [136192] O44 - LFC:[MD5.02C25A63D58FC12DEA8FA4ECDB832CC0] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - ‎‎الأمر العام غير المراقب لـ NetBT.) -- C:\Windows\System32\netbtugc.exe [24064] O44 - LFC:[MD5.D4496F4DC6B90F6915CEB1DB20B44C07] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - ‎‎الأمر العام غير المراقب لـ Netio.) -- C:\Windows\System32\netiougc.exe [25600] O44 - LFC:[MD5.C2EF686098DDABD5851E6BCA2F8620C2] - 5/25/2015 - 1:37:43 AM ---A- . (.Microsoft Corporation - ‎‎جهاز التقاط رقمي ‎‎لمراقبة أداة التعيين.) -- C:\Windows\System32\MultiDigiMon.exe [53248] O44 - LFC:[MD5.CC0C2CF2EBD58234C45C5D0C046ABB79] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - AzMan Sql Audit Extended Stored Procedures.) -- C:\Windows\System32\AzSqlExt.dll [28160] O44 - LFC:[MD5.3FBBE458FB60D5F38EF5E19F53772088] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - CCA DirectShow Filter..) -- C:\Windows\System32\cca.dll [66560] O44 - LFC:[MD5.588901BE6987933B6EA6B35C8B2AFCEB] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - Change Logon Utility.) -- C:\Windows\System32\chglogon.exe [22016] O44 - LFC:[MD5.7BD10646253ED4F6FD361279181362E7] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - MUI unattend action.) -- C:\Windows\System32\MuiUnattend.exe [70656] O44 - LFC:[MD5.835982D4DB80A9CC114E34E34E90E2A0] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - Message Utility.) -- C:\Windows\System32\msg.exe [24576] O44 - LFC:[MD5.6357E2B68753A1F5CF4A68A25C4FD14A] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - Microsoft WinSNMP v2.0 Manager API.) -- C:\Windows\System32\wsnmp32.dll [51712] O44 - LFC:[MD5.4EA584FCC419E66E9ADCEEAE0B0A7301] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - NPS XML Datastore Access.) -- C:\Windows\System32\iasrecst.dll [122880] O44 - LFC:[MD5.0AEE06C1CB1123AE2C9873908DB59BAF] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - ODBC Driver for Oracle.) -- C:\Windows\System32\msorcl32.dll [176128] O44 - LFC:[MD5.79C626237AD93981BDF72606DD543CEE] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - Performance Relogging Utility.) -- C:\Windows\System32\relog.exe [37888] O44 - LFC:[MD5.03CF941D031F30272D3063E5A4D686F5] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - Print Sandbox COM Proxy Stub.) -- C:\Windows\System32\PrintIsolationProxy.dll [32768] O44 - LFC:[MD5.32A5CC033236E6CC8AAE00B580986C4D] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - Query Process Utility.) -- C:\Windows\System32\qprocess.exe [25088] O44 - LFC:[MD5.5AA02AB0623B57332A7AF6CB73A9011C] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - Query Session Utility.) -- C:\Windows\System32\qwinsta.exe [26624] O44 - LFC:[MD5.665AAD05AEE9E37A7A9BAEDCAC775989] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - Toshiba Video Codec.) -- C:\Windows\System32\tsbyuv.dll [12288] O44 - LFC:[MD5.E98A08E70C15D6371AFEEB802227228D] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - Unattend Library.) -- C:\Windows\System32\unattend.dll [202240] O44 - LFC:[MD5.D33E95C0A2754061233B58DC41F8094C] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - User Mode Bus Driver Interface Dll.) -- C:\Windows\System32\umb.dll [50688] O44 - LFC:[MD5.87095E9BA2A172685897F1D4AFE35E91] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - Windows Diagnosis and Recovery.) -- C:\Windows\System32\RelPost.exe [182784] O44 - LFC:[MD5.65B76F79BA94CF8837D556D4C9067773] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - Windows Media Audio Voice Decoder.) -- C:\Windows\System32\WMSPDMOD.DLL [739328] O44 - LFC:[MD5.DAB748AE0439955ED2FA22357533DDDB] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - Windows NT BASE API Server DLL.) -- C:\Windows\System32\basesrv.dll [44032] O44 - LFC:[MD5.079D12BFED9E3E03D02A44BAF8FFA3A9] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - إعدادات سطح المكتب في لوحة التحكم.) -- C:\Windows\System32\desk.cpl [128000] O44 - LFC:[MD5.D8A65DAFB3EB41CBB622745676FCD072] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - برنامج تشغيل I/O لوضع المستخدم NDIS.) -- C:\Windows\System32\Drivers\ndisuio.sys [46080] O44 - LFC:[MD5.24498D084FAA7A459C91066EC241E1CE] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - برنامج تشغيل VfW MM الخاص بأجهزة التقاط فيد.) -- C:\Windows\System32\vfwwdm32.dll [56832] O44 - LFC:[MD5.195C41CC67E9E1CEDD960CCB74925920] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - برنامج تشغيل ناقل Bluetooth.) -- C:\Windows\System32\Drivers\bthport.sys [393216] O44 - LFC:[MD5.3F5A4F3A11EAA28DCD5C85C06C09D853] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - تنظيف ملفات الإعداد.) -- C:\Windows\System32\setupcln.dll [115712] O44 - LFC:[MD5.7B47059ADEA2983C073562DD40F3FD73] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - واجهة مستخدم Pdh.) -- C:\Windows\System32\pdhui.dll [46592] O44 - LFC:[MD5.00263CA2071DC9A6EE577EB356B0D1D9] - 5/25/2015 - 1:37:44 AM ---A- . (.Microsoft Corporation - ‎‎مثبت ملف تعريف إدارة الاتصال لـ Microsoft.) -- C:\Windows\System32\cmstp.exe [84992] O44 - LFC:[MD5.8126CB6DEA909054E4ECA1F0D55B7579] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - Filtering Platform Helper Class.) -- C:\Windows\System32\fphc.dll [98304] O44 - LFC:[MD5.04FAE971A77E76B3F4EF44053AEE0905] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - Microsoft RLE Compressor.) -- C:\Windows\System32\msrle32.dll [13312] O44 - LFC:[MD5.71EAF975B87917ADCB26886482F6FB5B] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - Microsoft Transport Information Filter for.) -- C:\Windows\System32\psisrndr.ax [75776] O44 - LFC:[MD5.D30117DB43F48C4DBA9B41C08156A339] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - Microsoft UYVY Video Decompressor.) -- C:\Windows\System32\msyuv.dll [22528] O44 - LFC:[MD5.4D6262D5CFFA7D932126D2B85C373F87] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - Microsoft VBI Codec.) -- C:\Windows\System32\VBICodec.ax [153600] O44 - LFC:[MD5.925AE681543B4E666E172B5BD7E45B32] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - Quarantine Client WMI Provider.) -- C:\Windows\System32\QCLIPROV.DLL [71680] O44 - LFC:[MD5.B292EBE345B14B66E17E5F36CEF7209C] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - Remote Desktop USB Redirection GP Extension.) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe [7680] O44 - LFC:[MD5.5A220C5CFC74AB3C2517D1F1B670D5D3] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - SPP CMI Installer Plug-in DLL.) -- C:\Windows\System32\sppinst.dll [100864] O44 - LFC:[MD5.CE292C4C10B8DB6070F262EA2733F0DC] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - SQM Client.) -- C:\Windows\System32\sqmapi.dll [189952] O44 - LFC:[MD5.8007508CEF6A5B10C24F7971DAF00F09] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - Takes ownership of a file.) -- C:\Windows\System32\takeown.exe [51200] O44 - LFC:[MD5.AF2E7640E72F005DDB86158E1F8BA1FC] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - WIA Video.) -- C:\Windows\System32\wiavideo.dll [109568] O44 - LFC:[MD5.41A2EEB3FC7C4677787C612478DBD69A] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - Windows Media DRM for Network Devices DLL.) -- C:\Windows\System32\wmdrmnet.dll [436736] O44 - LFC:[MD5.9E44D3D2D1D2DA5ED565D471E350F1CD] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - Windows Media Screen Decoder.) -- C:\Windows\System32\WMVSDECD.DLL [541184] O44 - LFC:[MD5.630A31F277349109299E590856A4B004] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - التقاط فيديو دفق WDM.) -- C:\Windows\System32\Kswdmcap.ax [107008] O44 - LFC:[MD5.0CE0812F2BDFED908FB1066AD4B868C7] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - الوحدة النمطية الخاصة بوسائط 802.3.) -- C:\Windows\System32\dot3msm.dll [115200] O44 - LFC:[MD5.55663BED58AEDDE8ADE37A582CD8380C] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - برنامج ترميز الفيديو YUV لـ Intel Indeo(R).) -- C:\Windows\System32\iyuv_32.dll [50176] O44 - LFC:[MD5.DCEABBA22E12CC44C2E7785C0EB9C6E3] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - مكتبة دعم ملفات Microsoft AVI.) -- C:\Windows\System32\avifil32.dll [91648] O44 - LFC:[MD5.1060D60CCA69A8136A87DBE3C8F4A467] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - واجهة برمجة تطبيق التخزين المحسّن من Window.) -- C:\Windows\System32\EhStorAPI.dll [128512] O44 - LFC:[MD5.92DF43A9CDD39C67F2B2D2F98799E086] - 5/25/2015 - 1:37:45 AM ---A- . (.Microsoft Corporation - وقت تشغيل DirectShow..) -- C:\Windows\System32\qdv.dll [283136] O44 - LFC:[MD5.1893ACD253854AC385042DB594FA23FF] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - DirectX Graphics MMS.) -- C:\Windows\System32\Drivers\dxgmms1.sys [211968] O44 - LFC:[MD5.8BC9DB92C4B2F3BE89185BEAB2AFC1F6] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Extended MAPI 1.0 الخاصة بـ Windows NT.) -- C:\Windows\System32\mapi32.dll [76800] O44 - LFC:[MD5.8BC9DB92C4B2F3BE89185BEAB2AFC1F6] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Extended MAPI 1.0 الخاصة بـ Windows NT.) -- C:\Windows\System32\mapistub.dll [76800] O44 - LFC:[MD5.8C74DBDF501E081CC56BFE41FA8B17AE] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - MUI Language pack cleanup.) -- C:\Windows\System32\lpremove.exe [61952] O44 - LFC:[MD5.E9AEF26AEEBFAAB901FAB3D93677DF98] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Microsoft MPEG-2 Section and Table Acquisit.) -- C:\Windows\System32\Mpeg2Data.ax [72704] O44 - LFC:[MD5.B21B85E60DA18D7D338599D95D4CB211] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Microsoft OLE for Windows.) -- C:\Windows\System32\olethk32.dll [77824] O44 - LFC:[MD5.13CDD3FF0961A2EC6D9829A1640DD6DC] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Microsoft SQL Mobile.) -- C:\Windows\System32\sqlcese30.dll [309760] O44 - LFC:[MD5.F7CF764F8155492EB50E4505A6DA8D87] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Microsoft Windows Portable Device Status Pr.) -- C:\Windows\System32\PortableDeviceStatus.dll [427520] O44 - LFC:[MD5.37485CC09B7E6E70093A4DF62B3CC744] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Native Code OPC Services Library.) -- C:\Windows\System32\OpcServices.dll [1160192] O44 - LFC:[MD5.465BEA35F7ED4A4A57686DEA7EA10F47] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Offline Files Win32 API.) -- C:\Windows\System32\cscapi.dll [34816] O44 - LFC:[MD5.2F3FD95C12AAED396EB1FFE4AF919BFF] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Performance Log Utility.) -- C:\Windows\System32\logman.exe [82944] O44 - LFC:[MD5.F65D14471F76F9C91315352932408939] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Quarantine Server Management.) -- C:\Windows\System32\QSVRMGMT.DLL [99328] O44 - LFC:[MD5.D0C94D78DC8652153F020F5B6ACED36F] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - RDP Direct3D Remoting DLL.) -- C:\Windows\System32\rdpd3d.dll [52224] O44 - LFC:[MD5.5CCDCD40E732D54E0F7451AC66AC1C87] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Server Service Client DLL.) -- C:\Windows\System32\srvcli.dll [90112] O44 - LFC:[MD5.97BAF1DE66F886D8292AED040B8CC281] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Unattend Action Queue Generator / Executor.) -- C:\Windows\System32\ActionQueue.dll [179200] O44 - LFC:[MD5.F9724B48380FE80D75A3C16280A5D78F] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Unattended Setup Generic Command For Domain.) -- C:\Windows\System32\djoin.exe [59904] O44 - LFC:[MD5.53CA6BF58658815FCB472205291DD953] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Unimodem Service Provider AT Mini Driver.) -- C:\Windows\System32\unimdmat.dll [59392] O44 - LFC:[MD5.7DF45A1E1A4AAFDEEFF2CA8F8200F37B] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - WMDM Service Provider for Windows Portable.) -- C:\Windows\System32\WPDSp.dll [350720] O44 - LFC:[MD5.D25958B2A71EF488959272878EF934BE] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - WinStation utility support DLL.) -- C:\Windows\System32\utildll.dll [31744] O44 - LFC:[MD5.FF3C5379DE4FD18498C255D096FED3F5] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Windows Media Audio Decoder.) -- C:\Windows\System32\WMADMOD.DLL [902656] O44 - LFC:[MD5.D4191EFAB91E00FC09257AA5EBAF503B] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Windows NT MP Router Administration DLL.) -- C:\Windows\System32\mprapi.dll [158720] O44 - LFC:[MD5.487F44B08EFEAF5AD087878357B9403D] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - Windows Performance Data Helper DLL.) -- C:\Windows\System32\pdh.dll [236544] O44 - LFC:[MD5.98F657555DD1C1A30362927DF8FBB266] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - iSCSI Discovery api.) -- C:\Windows\System32\iscsium.dll [28672] O44 - LFC:[MD5.8F64E5E1CE1F7E0F76D66BB0C7E2221F] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - أداة ترحيل الملفات غير المتصلة لـ Microsoft.) -- C:\Windows\System32\CscMig.dll [109568] O44 - LFC:[MD5.D8868258E3F26B40ECB8E945C2DA8BD9] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - التطبيق الصغير للوحة تحكم تكوين إدارة الطاق.) -- C:\Windows\System32\powercfg.cpl [142336] O44 - LFC:[MD5.775C41C2F2EF3DD150A7444B95E631D0] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - شاشة التوقف الفقاقيع.) -- C:\Windows\System32\Bubbles.scr [878592] O44 - LFC:[MD5.D15880276D208AF03521B8F922C1F3B5] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - شاشة التوقف.) -- C:\Windows\System32\Mystify.scr [221184] O44 - LFC:[MD5.831319977C168FFCF4E9ABB83A992F80] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - شاشة توقف "الأشرطة".) -- C:\Windows\System32\Ribbons.scr [220672] O44 - LFC:[MD5.E783DE1447EC0EED7B768BB69705D8E3] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - موالف تلفزيون دفق WDM.) -- C:\Windows\System32\kstvtune.ax [84480] O44 - LFC:[MD5.9D67B55896F679CD6C0FC7EAD0F4BDEA] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - موفر الجهاز المحمول لـ Microsoft Windows..) -- C:\Windows\System32\PortableDeviceSyncProvider.dll [183296] O44 - LFC:[MD5.4D05BDE56A7116B744B04192173A0122] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - ‎‎أداة تشخيص الذاكرة الفعلية لـ Windows.) -- C:\Windows\System32\MdSched.exe [132608] O44 - LFC:[MD5.44D647692BEFABB34EA46B34048C0F03] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - ‎‎أداة معايرة جهاز الالتقاط الرقمي.) -- C:\Windows\System32\tabcal.exe [74240] O44 - LFC:[MD5.33CDDA42E768A997827CC480EC13DAD5] - 5/25/2015 - 1:37:46 AM ---A- . (.Microsoft Corporation - ‎‎مكتبة واجهة مستخدم حماية مفتاح تشفير Wind.) -- C:\Windows\System32\ncryptui.dll [60928] O44 - LFC:[MD5.0920B14AA67A8B04ACF48FFE7C6F0927] - 5/25/2015 - 1:37:47 AM ---A- . (.Microsoft Corporation - BITS administration utility.) -- C:\Windows\System32\bitsadmin.exe [186368] O44 - LFC:[MD5.A29E036A5A3B37C7530F3EA1CF385129] - 5/25/2015 - 1:37:47 AM ---A- . (.Microsoft Corporation - LSM interfaces proxy Dll.) -- C:\Windows\System32\lsmproxy.dll [21504] O44 - LFC:[MD5.A557563260FD041F6CFA5C296918104E] - 5/25/2015 - 1:37:47 AM ---A- . (.Microsoft Corporation - PnP unattend action.) -- C:\Windows\System32\PnPUnattend.exe [61440] O44 - LFC:[MD5.F14A9B1778376D0B1788E402AC1F831A] - 5/25/2015 - 1:37:47 AM ---A- . (.Microsoft Corporation - Shell Accounts Classes.) -- C:\Windows\System32\shacct.dll [108032] O44 - LFC:[MD5.5CF15474FFDB5005E54958DF6EDD97AB] - 5/25/2015 - 1:37:47 AM ---A- . (.Microsoft Corporation - Windows Media DRM for Network Devices Regis.) -- C:\Windows\System32\wmdrmdev.dll [507392] O44 - LFC:[MD5.E9C7D94D71857409BF741F1B7561D0E6] - 5/25/2015 - 1:37:47 AM ---A- . (.Microsoft Corporation - مشغل Windows Media Player.) -- C:\Windows\System32\wmpshell.dll [105472] O44 - LFC:[MD5.DBD14D0DB0382DFE96D7B5007DDD5ABE] - 5/25/2015 - 1:37:48 AM ---A- . (.Microsoft Corporation - Boot File Servicing Utility.) -- C:\Windows\bfsvc.exe [65024] O44 - LFC:[MD5.BFB9EE8EE977EFE85D1A3105ABEF6DD1] - 5/25/2015 - 1:37:48 AM ---A- . (.Microsoft Corporation - Media Center Extender Service.) -- C:\Windows\System32\Mcx2Svc.dll [68096] O44 - LFC:[MD5.9204A9C716B7B4AA451010DEDB0BB5BE] - 5/25/2015 - 1:37:48 AM ---A- . (.Microsoft Corporation - Media Foundation Playback API DLL.) -- C:\Windows\System32\MFPlay.dll [176128] O44 - LFC:[MD5.9B9EF57993ECC02CE7469F3F3AC3CE10] - 5/25/2015 - 1:37:48 AM ---A- . (.Microsoft Corporation - Microsoft ThirdPartyEapDispatcher.) -- C:\Windows\System32\eapp3hst.dll [242176] O44 - LFC:[MD5.E178A1BD78441E08ACA10F6AF4B88F6E] - 5/25/2015 - 1:37:48 AM ---A- . (.Microsoft Corporation - Microsoft® Logon Server Test Utility.) -- C:\Windows\System32\nltest.exe [327168] O44 - LFC:[MD5.906DCFC5EBF4EC0433F8D4FFFB0BA334] - 5/25/2015 - 1:37:48 AM ---A- . (.Microsoft Corporation - Reliable Multicast Transport.) -- C:\Windows\System32\Drivers\rmcast.sys [117760] O44 - LFC:[MD5.EA7D55E6964AA852BC7AE6F1C3349A55] - 5/25/2015 - 1:37:48 AM ---A- . (.Microsoft Corporation - Windows Media Player Logagent.) -- C:\Windows\System32\logagent.exe [95232] O44 - LFC:[MD5.EEE470F2A771FC0B543BDEEF74FCECA0] - 5/25/2015 - 1:37:48 AM ---A- . (.Microsoft Corporation - Windows® installer.) -- C:\Windows\System32\msiexec.exe [73216] O44 - LFC:[MD5.00F48A9D03F672F7EBE601FFA9BB6F28] - 5/25/2015 - 1:37:48 AM ---A- . (.Microsoft Corporation - iTV Data Filters..) -- C:\Windows\System32\iTVData.dll [219648] O44 - LFC:[MD5.69C85737F4CA5634E7A19B818579D176] - 5/25/2015 - 1:37:48 AM ---A- . (.Microsoft Corporation - أداة تشخيص Microsoft DirectX.) -- C:\Windows\System32\dxdiagn.dll [210432] O44 - LFC:[MD5.45DC6C69CE5759666EC758BAD657B040] - 5/25/2015 - 1:37:48 AM ---A- . (.Microsoft Corporation - أداة ضغط Microsoft Video 1.) -- C:\Windows\System32\msvidc32.dll [31744] O44 - LFC:[MD5.CF3CD3F466D84C9E2F66490D9578A563] - 5/25/2015 - 1:37:48 AM ---A- . (.Microsoft Corporation - الموفر الأساسي لخدمة الأقراص الظاهرية.) -- C:\Windows\System32\vdsbas.dll [160256] O44 - LFC:[MD5.CA63BC9F834A42DAA8375FAC76B5CE83] - 5/25/2015 - 1:37:48 AM ---A- . (.Microsoft Corporation - معالج WCN الخاص بالأجهزة المحمولة لـ Window.) -- C:\Windows\System32\wpdwcn.dll [198144] O44 - LFC:[MD5.A77E0E5B15E6956C19E7269566ABE6C7] - 5/25/2015 - 1:37:48 AM ---A- . (.Microsoft Corporation - مكتبة واجهة المستخدم للعميل IEEE 802.1X.) -- C:\Windows\System32\onexui.dll [1111552] O44 - LFC:[MD5.D44741F65A1D71F65814A12CF6E2400A] - 5/25/2015 - 1:37:48 AM ---A- . (.Microsoft Corporation - ‎‎التشغيل مرة واحدة لأداة الالتفاف.) -- C:\Windows\System32\runonce.exe [50688] O44 - LFC:[MD5.9B9A0802B4E34CC4D9DB04AB6ABFA8AE] - 5/25/2015 - 1:37:49 AM ---A- . (.Microsoft Corporation - InputSetting DLL.) -- C:\Windows\System32\input.dll [202240] O44 - LFC:[MD5.08236C4BCE5EDD0A0318A438AF28E0F7] - 5/25/2015 - 1:37:49 AM ---A- . (.Microsoft Corporation - Microsoft® Windows Backup Service.) -- C:\Windows\System32\sdrsvc.dll [125952] O44 - LFC:[MD5.93C4029DABC19166076BE347283AB969] - 5/25/2015 - 1:37:49 AM ---A- . (.Microsoft Corporation - NAP Cryptographic API helper.) -- C:\Windows\System32\NAPCRYPT.DLL [46080] O44 - LFC:[MD5.703FFD301AB900B047337C5D40FD6F96] - 5/25/2015 - 1:37:49 AM ---A- . (.Microsoft Corporation - No Comment.) -- C:\Windows\System32\olepro32.dll [90112] O44 - LFC:[MD5.207CF171B1C6B8AE50C1FBF87363EEBC] - 5/25/2015 - 1:37:49 AM ---A- . (.Microsoft Corporation - PPP CHAP للوصول عن بُعد.) -- C:\Windows\System32\raschap.dll [318976] O44 - LFC:[MD5.BD626EF05967D14C772B8096292731A3] - 5/25/2015 - 1:37:49 AM ---A- . (.Microsoft Corporation - Quarantine Utilities.) -- C:\Windows\System32\QUTIL.DLL [80896] O44 - LFC:[MD5.9D30A820EAB9C146BB59557CA0236875] - 5/25/2015 - 1:37:49 AM ---A- . (.Microsoft Corporation - RDPSRAPI COM Objects.) -- C:\Windows\System32\rdpencom.dll [186368] O44 - LFC:[MD5.5845B1C54380FB980F68024B3A8B1E66] - 5/25/2015 - 1:37:49 AM ---A- . (.Microsoft Corporation - VPN IKE API's.) -- C:\Windows\System32\vpnikeapi.dll [25600] O44 - LFC:[MD5.F645EF77ED0735B927E9804E28855E17] - 5/25/2015 - 1:37:49 AM ---A- . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll [299520] O44 - LFC:[MD5.1274A7FD37E2DA781282CEE1D2131374] - 5/25/2015 - 1:37:49 AM ---A- . (.Microsoft Corporation - Windows Optional Component Setup API.) -- C:\Windows\System32\ocsetapi.dll [174592] O44 - LFC:[MD5.ACA1F50844E08F3F5178E8FF3F21FBC2] - 5/25/2015 - 1:37:49 AM ---A- . (.Microsoft Corporation - إعدادات التحكم في حساب المستخدم.) -- C:\Windows\System32\UserAccountControlSettings.dll [78848] O44 - LFC:[MD5.3D57FFBAD3ED16B63DE3879BAB0FB56F] - 5/25/2015 - 1:37:49 AM ---A- . (.Microsoft Corporation - مستكشف الشبكة.) -- C:\Windows\System32\networkexplorer.dll [1661440] O44 - LFC:[MD5.B57053CD59114D36952461EE638D3784] - 5/25/2015 - 1:37:49 AM ---A- . (.Microsoft Corporation - مكتبة ملحق Shell لعلامة تبويب التوافق.) -- C:\Windows\System32\acppage.dll [45568] O44 - LFC:[MD5.292F2FA57EB9B773DA1C15AFCC4A4F90] - 5/25/2015 - 1:37:49 AM ---A- . (.Microsoft Corporation - ملحق CPL لجلسات العمل البعيدة.) -- C:\Windows\System32\remotepg.dll [146944] O44 - LFC:[MD5.DC661CF87F2501A8B8D9628C006AA3BD] - 5/25/2015 - 1:37:49 AM ---A- . (.Microsoft Corporation - ‎‎مراقبة الأداء والموارد.) -- C:\Windows\System32\perfmon.exe [157184] O44 - LFC:[MD5.1C20F53017D9ADBE40B6826FE81FF47C] - 5/25/2015 - 1:37:49 AM ---A- . (.Microsoft Corporation - ‎‎نتائج Windows Anytime Upgrade.) -- C:\Windows\System32\WindowsAnytimeUpgradeResults.exe [292864] O44 - LFC:[MD5.BF1EAD0561F37CEA65F76DD276F90E04] - 5/25/2015 - 1:37:50 AM ---A- . (.Microsoft Corporation - DiskRAID.) -- C:\Windows\System32\diskraid.exe [276480] O44 - LFC:[MD5.E2864DF592832883151A8D5500A7EAAA] - 5/25/2015 - 1:37:50 AM ---A- . (.Microsoft Corporation - Microsoft® Windows System Protection Config.) -- C:\Windows\System32\srrstr.dll [257024] O44 - LFC:[MD5.4A8E2F20809CC161107FAA94F6CF2685] - 5/25/2015 - 1:37:50 AM ---A- . (.Microsoft Corporation - Multi-User Windows IMM32 API Client DLL.) -- C:\Windows\System32\imm32.dll [118272] O44 - LFC:[MD5.FD4C4F9EC7D6D23E282F9375B4029AE5] - 5/25/2015 - 1:37:50 AM ---A- . (.Microsoft Corporation - Setup Wizard Framework.) -- C:\Windows\System32\uxlib.dll [118784] O44 - LFC:[MD5.19F75D71E4256F5113D64CE2BB66B838] - 5/25/2015 - 1:37:50 AM ---A- . (.Microsoft Corporation - Software Licensing WGA API.) -- C:\Windows\System32\slwga.dll [14336] O44 - LFC:[MD5.F6FD7F8147A591317E57D9008C8C7541] - 5/25/2015 - 1:37:50 AM ---A- . (.Microsoft Corporation - Wimfltr v2 extractor.) -- C:\Windows\System32\wimserv.exe [327680] O44 - LFC:[MD5.735263DA17BF5BAF9CCD483843BF9D5A] - 5/25/2015 - 1:37:50 AM ---A- . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\Windows\System32\WPDShServiceObj.dll [105984] O44 - LFC:[MD5.5E3830EE3282A53920E00784FEC44CFD] - 5/25/2015 - 1:37:50 AM ---A- . (.Microsoft Corporation - nslookup.) -- C:\Windows\System32\nslookup.exe [98304] O44 - LFC:[MD5.AD6DB3F85D329ABA90EAF7B2D8A2EEA9] - 5/25/2015 - 1:37:50 AM ---A- . (.Microsoft Corporation - شاشة توقف نصية ثلاثية الأبعاد.) -- C:\Windows\System32\ssText3d.scr [293888] O44 - LFC:[MD5.8A31F7A5A29EA3564493BC5EF8E78032] - 5/25/2015 - 1:37:50 AM ---A- . (.Microsoft Corporation - عمليات دفق اتصال WAN اللاسلكية.) -- C:\Windows\System32\wwanconn.dll [196608] O44 - LFC:[MD5.451E47CF063A37D105A1D2111FD4C4E5] - 5/25/2015 - 1:37:50 AM ---A- . (.Microsoft Corporation - فيديو لبرنامج تشغيل Windows MCI.) -- C:\Windows\System32\mciavi32.dll [84480] O44 - LFC:[MD5.5DC6DBFC22911C58FD2C9208A9756021] - 5/25/2015 - 1:37:50 AM ---A- . (.Microsoft Corporation - مجلد ازدواج الأجهزة.) -- C:\Windows\System32\DevicePairingFolder.dll [211456] O44 - LFC:[MD5.C335EC1182AC10B188705554E0BC1186] - 5/25/2015 - 1:37:50 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لـ Microsoft Vide.) -- C:\Windows\System32\msvfw32.dll [120320] O44 - LFC:[MD5.AE9898D5600A232CD8AE3298692162E5] - 5/25/2015 - 1:37:50 AM ---A- . (.Microsoft Corporation - مكتبة واجهة برمجة التطبيقات (API) لنظام الم.) -- C:\Windows\System32\clusapi.dll [230912] O44 - LFC:[MD5.4634B0EE4098F0F2B972BDAC19A802E7] - 5/25/2015 - 1:37:50 AM ---A- . (.Microsoft Corporation - ملحق Shell الخاص بأجهزة الوسائط المحمولة.) -- C:\Windows\System32\audiodev.dll [243712] O44 - LFC:[MD5.604409A90F3962C1CC05276ADBFE233C] - 5/25/2015 - 1:37:50 AM ---A- . (.Microsoft Corporation - ‎‎عميل توافق العرض التقديمي للكمبيوتر المحم.) -- C:\Windows\System32\PresentationSettings.exe [170496] O44 - LFC:[MD5.A54E92AE753D4BC63FE71F010F76EF04] - 5/25/2015 - 1:37:51 AM ---A- . (.Microsoft Corporation - DirectShow ASF Support.) -- C:\Windows\System32\qasf.dll [206848] O44 - LFC:[MD5.377F0C1DDBFA6A43CB7E7568BC0ECED0] - 5/25/2015 - 1:37:51 AM ---A- . (.Microsoft Corporation - Unimodem 5 Service Provider.) -- C:\Windows\System32\unimdm.tsp [281088] O44 - LFC:[MD5.39C3CDE5BFA5D95661712258EDFE5F17] - 5/25/2015 - 1:37:51 AM ---A- . (.Microsoft Corporation - WMI Configuration Core.) -- C:\Windows\System32\SmiEngine.dll [697344] O44 - LFC:[MD5.C06A8EB439D3451DF15828FF1CB7D0F8] - 5/25/2015 - 1:37:51 AM ---A- . (.Microsoft Corporation - Windows Package Manager.) -- C:\Windows\System32\PkgMgr.exe [209920] O44 - LFC:[MD5.319C6B309773D063541D01DF8AC6F55F] - 5/25/2015 - 1:37:51 AM ---A- . (.Microsoft Corporation - خدمة نشر شهادة البطاقة الذكية لـ Microsoft.) -- C:\Windows\System32\certprop.dll [67584] O44 - LFC:[MD5.C9708C9F3DBA3DBFB1D2FEE1E9DABAD0] - 5/25/2015 - 1:37:51 AM ---A- . (.Microsoft Corporation - صفحة خصائص الإصدارات السابقة.) -- C:\Windows\System32\twext.dll [146432] O44 - LFC:[MD5.C5A99A4C0DC9F0F5A95BA0C83D30A549] - 5/25/2015 - 1:37:51 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لواجهة مجدول المه.) -- C:\Windows\System32\mstask.dll [209920] O44 - LFC:[MD5.CC5BF60E9D3F181C0B62AC91AD8634B8] - 5/25/2015 - 1:37:51 AM ---A- . (.Microsoft Corporation - وقت تشغيل DirectShow..) -- C:\Windows\System32\qcap.dll [190976] O44 - LFC:[MD5.824E84AC88AC9F82D772960657E094D1] - 5/25/2015 - 1:37:51 AM ---A- . (.Microsoft Corporation - ‎‎معالج الأوامر العام غير المراقب للإعداد.) -- C:\Windows\System32\setupugc.exe [113152] O44 - LFC:[MD5.163A95975E1D8819E653AA3E961371CA] - 5/25/2015 - 1:37:51 AM ---A- . (.Twain Working Group - Twain_32 Source Manager (Image Acquisition.) -- C:\Windows\twain_32.dll [51200] O44 - LFC:[MD5.2097D9A13CDB88213612E3E8479185F5] - 5/25/2015 - 1:37:52 AM ---A- . (.Microsoft Corporation - Microsoft Wave MSP.) -- C:\Windows\System32\wavemsp.dll [222208] O44 - LFC:[MD5.3CC04CB09FAFAD87942437FDDEE11EE3] - 5/25/2015 - 1:37:52 AM ---A- . (.Microsoft Corporation - Microsoft Windows Recovery Agent DLL.) -- C:\Windows\System32\ReAgent.dll [247808] O44 - LFC:[MD5.A4BDC541E69674FBFF1A8FF00BE913F2] - 5/25/2015 - 1:37:52 AM ---A- . (.Microsoft Corporation - NDIS Proxy.) -- C:\Windows\System32\Drivers\ndproxy.sys [48640] O44 - LFC:[MD5.B4D3BDF863B81BF84658396666CF7200] - 5/25/2015 - 1:37:52 AM ---A- . (.Microsoft Corporation - Windows Optional Component Setup.) -- C:\Windows\System32\ocsetup.exe [197632] O44 - LFC:[MD5.6A6B2EE4565A178035BE2A4FF6F2C968] - 5/25/2015 - 1:37:52 AM ---A- . (.Microsoft Corporation - Windows Remote Desktop Session Host Server.) -- C:\Windows\System32\wtsapi32.dll [40448] O44 - LFC:[MD5.8DDD47810EE260744BEAA82EFA2DB9BB] - 5/25/2015 - 1:37:52 AM ---A- . (.Microsoft Corporation - Windows Time Zone Utility.) -- C:\Windows\System32\tzutil.exe [47616] O44 - LFC:[MD5.0BD483CECD8DAC86E04347589ADC71EE] - 5/25/2015 - 1:37:52 AM ---A- . (.Microsoft Corporation - Windows Visual Components.) -- C:\Windows\System32\wvc.dll [444928] O44 - LFC:[MD5.3C9035085141162416A0DD34DBF3F3C1] - 5/25/2015 - 1:37:52 AM ---A- . (.Microsoft Corporation - Windows Wireless LAN 802.11 MSM DLL.) -- C:\Windows\System32\wlanmsm.dll [428032] O44 - LFC:[MD5.DBC02D918FFF1CAD628ACBE0C0EAA8E8] - 5/25/2015 - 1:37:52 AM ---A- . (.Microsoft Corporation - مجموعة المشاركة المنزلية في Windows.) -- C:\Windows\System32\provsvc.dll [165376] O44 - LFC:[MD5.861A80C7DCA93A95327463D7F8C9CE64] - 5/25/2015 - 1:37:52 AM ---A- . (.Microsoft Corporation - مكتبة Windows Imaging.) -- C:\Windows\System32\wimgapi.dll [406528] O44 - LFC:[MD5.73869A8A7AF77801387A36CF9B9B5886] - 5/25/2015 - 1:37:52 AM ---A- . (.Microsoft Corporation - مكتبة مثبت فئات النظام.) -- C:\Windows\System32\sysclass.dll [198144] O44 - LFC:[MD5.5862A867BB6228D427CB784F610662F7] - 5/25/2015 - 1:37:52 AM ---A- . (.Microsoft Corporation - ملحق القوالب الإدارية.) -- C:\Windows\System32\AdmTmpl.dll [438272] O44 - LFC:[MD5.918379B6C94AA59F567E06FB4E0E5E1B] - 5/25/2015 - 1:37:52 AM ---A- . (.Microsoft Corporation - واجهة المستخدم العامة لخدمة Active Director.) -- C:\Windows\System32\dsuiext.dll [685056] O44 - LFC:[MD5.8FBE98499ADC541C63BB10B722DA00D4] - 5/25/2015 - 1:37:52 AM ---A- . (.Microsoft Corporation - واجهة المستخدم المتقدمة 802.3.) -- C:\Windows\System32\dot3ui.dll [333824] O44 - LFC:[MD5.FB036244DBD2FADC225AD8650886B641] - 5/25/2015 - 1:37:52 AM ---A- . (.Microsoft Corporation - ‎‎Microsoft® Disk Defragmenter.) -- C:\Windows\System32\dfrgui.exe [586752] O44 - LFC:[MD5.3A16EA01FCFAAB40882DB5BFEE632322] - 5/25/2015 - 1:37:54 AM ---A- . (.Microsoft Corporation - Rich Text Edit Control, v4.1.) -- C:\Windows\System32\msftedit.dll [592384] O44 - LFC:[MD5.3FE9A20ECA67745948FD536F8A9E00D9] - 5/25/2015 - 1:37:54 AM ---A- . (.Microsoft Corporation - ‎‎أداة نسخ صورة القرص لـ Windows.) -- C:\Windows\System32\isoburn.exe [86528] O44 - LFC:[MD5.8CD1DEE212E52B9C22E66DBA44991D32] - 5/25/2015 - 1:37:55 AM ---A- . (.Microsoft Corporation - HTTP Protocol Stack API.) -- C:\Windows\System32\httpapi.dll [34816] O44 - LFC:[MD5.404B123E9460395E3A7338B12C681B92] - 5/25/2015 - 1:37:55 AM ---A- . (.Microsoft Corporation - Net Shell IP Security helper DLL.) -- C:\Windows\System32\nshipsec.dll [346112] O44 - LFC:[MD5.088CF5B6380FB9002F2A4246F812225D] - 5/25/2015 - 1:37:55 AM ---A- . (.Microsoft Corporation - No Comment.) -- C:\Windows\System32\asycfilt.dll [67584] O44 - LFC:[MD5.22DE9DFF5565B00F230EAC0C635DAEB7] - 5/25/2015 - 1:37:55 AM ---A- . (.Microsoft Corporation - Windows SQM Consolidator.) -- C:\Windows\System32\wsqmcons.exe [254976] O44 - LFC:[MD5.1A1C4782E9C4110BDD0DBD5052D91383] - 5/25/2015 - 1:37:55 AM ---A- . (.Microsoft Corporation - خدمات Microsoft Windows SideShow.) -- C:\Windows\System32\AuxiliaryDisplayServices.dll [112128] O44 - LFC:[MD5.366BA8FB4B7BB7435E3B9EACB3843F67] - 5/25/2015 - 1:37:55 AM ---A- . (.Microsoft Corporation - خدمة التكوين التلقائي السلكية.) -- C:\Windows\System32\dot3svc.dll [214016] O44 - LFC:[MD5.E62AA52713617C1F402829EBF79653AB] - 5/25/2015 - 1:37:56 AM ---A- . (.Microsoft Corporation - Map Network Drives/Network Places Wizard.) -- C:\Windows\System32\netplwiz.dll [175616] O44 - LFC:[MD5.0C0DF0F05BAEA320FA301F34E256E08B] - 5/25/2015 - 1:37:56 AM ---A- . (.Microsoft Corporation - Microsoft(R) Delta Package Expander.) -- C:\Windows\System32\dpx.dll [257024] O44 - LFC:[MD5.6EC16BBD14906A59EA8A9A3F71B7F9AD] - 5/25/2015 - 1:37:56 AM ---A- . (.Microsoft Corporation - Migration System Isolation Layer.) -- C:\Windows\System32\migisol.dll [101888] O44 - LFC:[MD5.E9CFC1884D1E579E82073103827FA62B] - 5/25/2015 - 1:37:56 AM ---A- . (.Microsoft Corporation - NAP client config API helper.) -- C:\Windows\System32\NAPHLPR.DLL [107008] O44 - LFC:[MD5.B86FB49A715157C49E2C7205E1817012] - 5/25/2015 - 1:37:56 AM ---A- . (.Microsoft Corporation - WMPSrcWp Module.) -- C:\Windows\System32\wmpsrcwp.dll [182272] O44 - LFC:[MD5.D205C24A9D069049FE2DF2A1B38726A7] - 5/25/2015 - 1:37:56 AM ---A- . (.Microsoft Corporation - برنامج تشغيل نظام صوت Winmm.) -- C:\Windows\System32\wdmaud.drv [172032] O44 - LFC:[MD5.521B748A7F9923302CA18B7E6AA2EEAE] - 5/25/2015 - 1:37:56 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لطبقة موجه ADs.) -- C:\Windows\System32\activeds.dll [202752] O44 - LFC:[MD5.737AFC772243C75E6AD17A7A8E8E23F9] - 5/25/2015 - 1:37:56 AM ---A- . (.Windows (R) Codename Longhorn DDK provider - خدمات إدارة الخطوط.) -- C:\Windows\System32\fms.dll [93696] O44 - LFC:[MD5.102CF6879887BBE846A00C459E6D4ABC] - 5/25/2015 - 1:37:57 AM ---A- . (.Microsoft Corporation - Rich Text Edit Control, v3.1.) -- C:\Windows\System32\riched20.dll [473600] O44 - LFC:[MD5.B459575348C20E8121D6039DA063C704] - 5/25/2015 - 1:37:57 AM ---A- . (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\Drivers\tdx.sys [74752] O44 - LFC:[MD5.C140F86932B5B61F54A4D836E2D34AB2] - 5/25/2015 - 1:37:57 AM ---A- . (.Microsoft Corporation - WDM Streaming ActiveMovie Proxy.) -- C:\Windows\System32\ksproxy.ax [193536] O44 - LFC:[MD5.6E30D02AAC9CAC84F421622E3A2F6178] - 5/25/2015 - 1:37:57 AM ---A- . (.Microsoft Corporation - خدمة مثبت ActiveX.) -- C:\Windows\System32\AxInstSv.dll [88064] O44 - LFC:[MD5.D65645E5E9858EB60C3CF06848DD328D] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - Bcdboot utility.) -- C:\Windows\System32\bcdboot.exe [146944] O44 - LFC:[MD5.9473C7BDD77A204C0BB70B467740D326] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - Boot Configuration Data Editor.) -- C:\Windows\System32\bcdedit.exe [295424] O44 - LFC:[MD5.4AC64014668BB2B4834A66B73406AB63] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - CPL الخاص بالنظام.) -- C:\Windows\System32\systemcpl.dll [410624] O44 - LFC:[MD5.A912933C92B9C4C70E9039C0B597AE4E] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - Microsoft Teletext Server.) -- C:\Windows\System32\WSTPager.ax [68608] O44 - LFC:[MD5.D7B7159BC8374E87D8C45A30377A3440] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - Microsoft® Lan Manager.) -- C:\Windows\System32\ntlanman.dll [69120] O44 - LFC:[MD5.368A5F0D5FD18CDBF25E98FB1BDF6DBB] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - No Comment.) -- C:\Windows\System32\fsquirt.exe [219648] O44 - LFC:[MD5.967C44F54703EE9E16EA288AA42F14C6] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - Remote Desktop Session Host Server Sign Too.) -- C:\Windows\System32\rdpsign.exe [57344] O44 - LFC:[MD5.0915C4DB6DBC3BB9E11B7ECBBE4B7159] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - Routing Utilities.) -- C:\Windows\System32\rtutils.dll [37376] O44 - LFC:[MD5.89F5770AD1E9D9CEF93D00303135EC33] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - Spooler Setup DLL.) -- C:\Windows\System32\ntprint.dll [297472] O44 - LFC:[MD5.7B97346CE563B74BBCC120FC83E5A6D9] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - WMPMDE DLL.) -- C:\Windows\System32\wmpmde.dll [738816] O44 - LFC:[MD5.468D6989581E6AEA75DE74D4B3722CC3] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - الشروع في العمل.) -- C:\Windows\System32\OobeFldr.dll [859648] O44 - LFC:[MD5.20A20A911CD79A6F6839167149A05668] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - حقيبة ملفات Windows.) -- C:\Windows\System32\syncui.dll [159232] O44 - LFC:[MD5.E24BB41C4EFC309A14709FC127A3B847] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - لوحة تحكم "النسخ الاحتياطي والاستعادة لـ Wi.) -- C:\Windows\System32\sdcpl.dll [750080] O44 - LFC:[MD5.2DAF758E7C15886DD2424F77F488759A] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - لوحة تحكم الاسترداد.) -- C:\Windows\System32\recovery.dll [135680] O44 - LFC:[MD5.DFA05B91BA331F7407F5F50EEAA9E2B2] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - لوحة تحكم التشغيل التلقائي.) -- C:\Windows\System32\autoplay.dll [146944] O44 - LFC:[MD5.D304A5C08E733D694455DC770B86E069] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - لوحة تحكم الكمبيوتر اللوحي.) -- C:\Windows\System32\TabletPC.cpl [600576] O44 - LFC:[MD5.EB1A79442F10C6768E5B92D5868CF81B] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - لوحة تحكم تشفير المحركات باستخدام BitLocker.) -- C:\Windows\System32\fvecpl.dll [175104] O44 - LFC:[MD5.2A39F32E0067CBF221611FE1FA8C6D8F] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - مركز الأجهزة.) -- C:\Windows\System32\DeviceCenter.dll [484864] O44 - LFC:[MD5.54DEFF61C4E6AF1581DA2F236154BA4C] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - مركز الصيانة في لوحة التحكم.) -- C:\Windows\System32\ActionCenterCPL.dll [537600] O44 - LFC:[MD5.33BEE4A0B2DC34F4A6D01210F7507508] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - مكتبة الأدوات المساعدة لخدمة الأقراص الظاهر.) -- C:\Windows\System32\vdsutil.dll [151040] O44 - LFC:[MD5.97D7CC94EEA6EBB6B928EA3DD91A2A0C] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لواجهة مستخدم الح.) -- C:\Windows\System32\dskquoui.dll [196608] O44 - LFC:[MD5.05BF975CA428E04B462FB90841B37C95] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - موفر بيانات اعتماد البطاقة الذكية لـ Window.) -- C:\Windows\System32\SmartcardCredentialProvider.dll [152064] O44 - LFC:[MD5.55CDE81B9FD8E234C4E00E4EEE919406] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - وحدة PnP لـ SysPrep.) -- C:\Windows\System32\sppnp.dll [115712] O44 - LFC:[MD5.7635B6502882E4B1713F049FD8FD2EA4] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - ‎‎Microsoft® Windows Repair Disc.) -- C:\Windows\System32\recdisc.exe [210432] O44 - LFC:[MD5.8C545F6F1BA83C15B8B02EE4AA62FF11] - 5/25/2015 - 1:37:58 AM ---A- . (.Microsoft Corporation - ‎‎مفاتيح الاختصار الخاصة بالوصول.) -- C:\Windows\System32\sethc.exe [270336] O44 - LFC:[MD5.B06B2FEC249F48C4E7F628B689859AC7] - 5/25/2015 - 1:37:59 AM ---A- . (.Microsoft Corporation - 802.3 Netsh Helper.) -- C:\Windows\System32\dot3cfg.dll [82432] O44 - LFC:[MD5.0FE24BD8E67F3A6757A5D193A7A9B287] - 5/25/2015 - 1:37:59 AM ---A- . (.Microsoft Corporation - DLL الخاص بلوحة التحكم.) -- C:\Windows\System32\intl.cpl [345088] O44 - LFC:[MD5.3F6D9269E7B3A754B1C2F8533DC7F318] - 5/25/2015 - 1:37:59 AM ---A- . (.Microsoft Corporation - EFS Core Library.) -- C:\Windows\System32\efscore.dll [205312] O44 - LFC:[MD5.9996103F8A650BDB3586C9AAE1101912] - 5/25/2015 - 1:37:59 AM ---A- . (.Microsoft Corporation - File Transfer Program.) -- C:\Windows\System32\ftp.exe [42496] O44 - LFC:[MD5.0A2DFF70EB5210C4F7D4954A317E9B04] - 5/25/2015 - 1:37:59 AM ---A- . (.Microsoft Corporation - Hardware Abstraction Layer DLL.) -- C:\Windows\System32\halacpi.dll [137088] O44 - LFC:[MD5.931A1DF1520ABC6E84BA4A75E6957025] - 5/25/2015 - 1:37:59 AM ---A- . (.Microsoft Corporation - Hid Class Library.) -- C:\Windows\System32\Drivers\hidclass.sys [55808] O44 - LFC:[MD5.82A9C6ADDCC4D392293AF15C09192DEC] - 5/25/2015 - 1:37:59 AM ---A- . (.Microsoft Corporation - IFS Utility DLL.) -- C:\Windows\System32\ifsutil.dll [148992] O44 - LFC:[MD5.D8B2F66671C13C4C2F22FE3A588945F8] - 5/25/2015 - 1:37:59 AM ---A- . (.Microsoft Corporation - IP Router Manager.) -- C:\Windows\System32\iprtrmgr.dll [271360] O44 - LFC:[MD5.F44CCA639625EC735667BD8B8E523A33] - 5/25/2015 - 1:37:59 AM ---A- . (.Microsoft Corporation - Single-Instance Store Backup Support Functi.) -- C:\Windows\System32\sisbkup.dll [19456] O44 - LFC:[MD5.E82CEFE0D2F98651D556E2437163486B] - 5/25/2015 - 1:37:59 AM ---A- . (.Microsoft Corporation - التحكم في مراقبة النظام.) -- C:\Windows\System32\sysmon.ocx [389632] O44 - LFC:[MD5.E9B7D9BBD3E78E7DD053A5108B7649AC] - 5/25/2015 - 1:37:59 AM ---A- . (.Microsoft Corporation - خدمات ويب الخاصة بـ Windows Shell.) -- C:\Windows\System32\shwebsvc.dll [428544] O44 - LFC:[MD5.73CB55D2E8099D24FD077C990FFE3DDB] - 5/25/2015 - 1:37:59 AM ---A- . (.Microsoft Corporation - لوحة تحكم الموقع الافتراضي.) -- C:\Windows\System32\defaultlocationcpl.dll [220672] O44 - LFC:[MD5.297848A1D7D03A5735CEDF91F82ACFAB] - 5/25/2015 - 1:37:59 AM ---A- . (.Microsoft Corporation - مثبت فئة إعداد برنامج التشغيل الخاص بالأجهز.) -- C:\Windows\System32\wpd_ci.dll [577024] O44 - LFC:[MD5.186147C89867B66CB02667D4037C7550] - 5/25/2015 - 1:37:59 AM ---A- . (.Microsoft Corporation - مكون بروتوكول RADIUS لـ NPS.) -- C:\Windows\System32\iasrad.dll [172032] O44 - LFC:[MD5.E3D5E244807AD655787FCD25477CC1BC] - 5/25/2015 - 1:37:59 AM ---A- . (.Microsoft Corporation - ‎‎Bluetooth Control Panel Applet.) -- C:\Windows\System32\bthprops.cpl [692736] O44 - LFC:[MD5.3E709F7BFA217CD3B6FC338780465E20] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - ADs LDAP Provider DLL.) -- C:\Windows\System32\adsldp.dll [186880] O44 - LFC:[MD5.3FFAEA12666E565FF51BF2FCA674F543] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - Configuration Manager DLL.) -- C:\Windows\System32\cfgmgr32.dll [145920] O44 - LFC:[MD5.E343CABBD8D600ABAF3F11625D33B3D0] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - Domain Join DLL.) -- C:\Windows\System32\netjoin.dll [161792] O44 - LFC:[MD5.3206ADC4D06BB764C9A4936C8E22708C] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - Media Metadata Handler.) -- C:\Windows\System32\MediaMetadataHandler.dll [266752] O44 - LFC:[MD5.EAC4B0A0900CB391BBD48FC0A0E58C7F] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - Microsoft Protected Broadcast Digital Archi.) -- C:\Windows\System32\mspbda.dll [414208] O44 - LFC:[MD5.F1E9A22C1D4F5D3AC7BA555D4E95329C] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - SUD في لوحة التحكم.) -- C:\Windows\System32\sud.dll [755200] O44 - LFC:[MD5.1E8D06AAE74FED674C1156B3FEA911C2] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - Windows User Mode Crash Reporting DLL.) -- C:\Windows\System32\Faultrep.dll [320512] O44 - LFC:[MD5.477B711EBF491226FA40301290F66BAC] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - Windows® Media Center WMDRM-ND Receiver Bri.) -- C:\Windows\System32\MCEWMDRMNDBootstrap.dll [312168] O44 - LFC:[MD5.C8333F1F77A1B2E25F2202E892CAF634] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - prnfldr dll.) -- C:\Windows\System32\prnfldr.dll [395264] O44 - LFC:[MD5.BA2B249CD7C8CE15E1A8D69ECAEE5FA3] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - التطبيقات الصغيرة للماوس ولوحة المفاتيح في.) -- C:\Windows\System32\main.cpl [516096] O44 - LFC:[MD5.067ADF4DFA75CE40ADE163A5933E8953] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - امتداد Shell الخاص بمجلد Microsoft Internet.) -- C:\Windows\System32\msieftp.dll [301568] O44 - LFC:[MD5.EA72CAE0FFA2D86522888320ADE6B33E] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - خريطة الشبكة.) -- C:\Windows\System32\networkmap.dll [2130944] O44 - LFC:[MD5.7717A57C01812C3714BA25B96C36BF39] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - شريط المهام في لوحة التحكم.) -- C:\Windows\System32\taskbarcpl.dll [233472] O44 - LFC:[MD5.4A6554C141450D2B6AA6DE17A298AEDA] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - لوحة تحكم الهويات على إنترنت.) -- C:\Windows\System32\OnLineIDCpl.dll [218112] O44 - LFC:[MD5.9A39A2A5F443A756C568C6ED5748AFE4] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - مركز الصيانة.) -- C:\Windows\System32\ActionCenter.dll [744448] O44 - LFC:[MD5.59079D4288FF7175758E838A489DD992] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - معالج طباعة الصور.) -- C:\Windows\System32\photowiz.dll [295424] O44 - LFC:[MD5.8CBD6FDACDCC0ED48BAF607226D6D0C9] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - ‎‎المثبّت المستقل لـ Windows Update.) -- C:\Windows\System32\wusa.exe [314880] O44 - LFC:[MD5.D861EB4D6719D6738270E6A376B87F18] - 5/25/2015 - 1:38:00 AM ---A- . (.Microsoft Corporation - ‎‎عميل تنشيط Windows.) -- C:\Windows\System32\slui.exe [325632] O44 - LFC:[MD5.5DCEF0C32BE0F33277326586FA503689] - 5/25/2015 - 1:38:01 AM ---A- . (.Microsoft Corporation - Kernel CSA Library.) -- C:\Windows\System32\Drivers\ks.sys [190976] O44 - LFC:[MD5.DC190EB70C5C15BB087F893D6E77E5C6] - 5/25/2015 - 1:38:01 AM ---A- . (.Microsoft Corporation - Microsoft AC-3 Encoder.) -- C:\Windows\System32\MSAC3ENC.DLL [226304] O44 - LFC:[MD5.1EB40CEBF58C2983497A77442B99B2D0] - 5/25/2015 - 1:38:01 AM ---A- . (.Microsoft Corporation - Setup Wizard Framework.) -- C:\Windows\System32\spwizeng.dll [352768] O44 - LFC:[MD5.6FE596F2DC97F7E1CA292F376C33D3CB] - 5/25/2015 - 1:38:01 AM ---A- . (.Microsoft Corporation - WorkspaceRuntime.) -- C:\Windows\System32\wksprt.exe [223232] O44 - LFC:[MD5.5BAC1C3853E2D1F3F65CBB578228A268] - 5/25/2015 - 1:38:01 AM ---A- . (.Microsoft Corporation - إدارة التخويل.) -- C:\Windows\System32\azroleui.dll [314368] O44 - LFC:[MD5.BEFF01C9F044BA2AD7F5FB837972FC90] - 5/25/2015 - 1:38:01 AM ---A- . (.Microsoft Corporation - التطبيق الصغير للنظام الخاص بلوحة التحكم.) -- C:\Windows\System32\sysdm.cpl [326656] O44 - LFC:[MD5.45C0DF404182850C21749AF7763C095F] - 5/25/2015 - 1:38:01 AM ---A- . (.Microsoft Corporation - سهولة الوصول إلى لوحة التحكم.) -- C:\Windows\System32\accessibilitycpl.dll [3727872] O44 - LFC:[MD5.AA53356D60AF47EACC85BC617A4F3F66] - 5/25/2015 - 1:38:01 AM ---A- . (.Microsoft Corporation - عداد الجهاز المحمول.) -- C:\Windows\System32\wpdbusenum.dll [85504] O44 - LFC:[MD5.A2F0B6A45EF5B68173AAA2A39690904E] - 5/25/2015 - 1:38:01 AM ---A- . (.Microsoft Corporation - مجلدات مضغوطة.) -- C:\Windows\System32\zipfldr.dll [327680] O44 - LFC:[MD5.6F241D9C35D157A376003CDEF2E26CAE] - 5/25/2015 - 1:38:01 AM ---A- . (.Microsoft Corporation - ملحق نهج المجموعة الخاص بإعادة توجيه المجلد.) -- C:\Windows\System32\fdeploy.dll [59904] O44 - LFC:[MD5.67C1B58706B47EEBA4E117AC197289E6] - 5/25/2015 - 1:38:02 AM ---A- . (.Microsoft Corporation - DLL الخاص بمساعد مقياس البطارية.) -- C:\Windows\System32\batmeter.dll [740864] O44 - LFC:[MD5.0FC7E6C8DFB1052F121638485A675761] - 5/25/2015 - 1:38:02 AM ---A- . (.Microsoft Corporation - Print Ticket Services Module.) -- C:\Windows\System32\prntvpt.dll [120320] O44 - LFC:[MD5.96FE583424174CF7926250ED16C4EA01] - 5/25/2015 - 1:38:02 AM ---A- . (.Microsoft Corporation - Windows Time Service Diagnostic Tool.) -- C:\Windows\System32\w32tm.exe [66048] O44 - LFC:[MD5.370349F79315D4DB86CD992CACEFEE61] - 5/25/2015 - 1:38:02 AM ---A- . (.Microsoft Corporation - عرض الشبكات المتوفرة.) -- C:\Windows\System32\VAN.dll [638976] O44 - LFC:[MD5.5ABBEF3B5984C29BD9D7CB1C7F35B323] - 5/25/2015 - 1:38:02 AM ---A- . (.Microsoft Corporation - لوحة تحكم مركز الشبكة.) -- C:\Windows\System32\netcenter.dll [1644032] O44 - LFC:[MD5.013CB5286ABB32259349AD858087068C] - 5/25/2015 - 1:38:02 AM ---A- . (.Microsoft Corporation - مركز الأداء.) -- C:\Windows\System32\PerfCenterCPL.dll [600576] O44 - LFC:[MD5.A882CD13F68656CFD657E6639D3D3E17] - 5/25/2015 - 1:38:02 AM ---A- . (.Microsoft Corporation - واجهة مستخدم كلف التعريف اللاسلكي.) -- C:\Windows\System32\wlanui.dll [410112] O44 - LFC:[MD5.2305BFF2966D73694972FD7531BC5BAA] - 5/25/2015 - 1:38:02 AM ---A- . (.Microsoft Corporation - ‎‎خالط مستوى الصوت.) -- C:\Windows\System32\SndVol.exe [314368] O44 - LFC:[MD5.B5FFA9977015ED3E1B2C3FF266A1BEB9] - 5/25/2015 - 1:38:02 AM ---A- . (.Microsoft Corporation - ‎‎‫مركز إعدادات الكمبيوتر المحمول لـ Window.) -- C:\Windows\System32\mblctr.exe [941568] O44 - LFC:[MD5.6ED76824354C47C0B227ED38DEC89800] - 5/25/2015 - 1:38:03 AM ---A- . (.Microsoft Corporation - Boot Configuration Data COM Server.) -- C:\Windows\System32\bcdsrv.dll [133632] O44 - LFC:[MD5.196B4E3F4CCCC24AF836CE58FACBB699] - 5/25/2015 - 1:38:03 AM ---A- . (.Microsoft Corporation - Key Management Service.) -- C:\Windows\System32\KMSVC.DLL [71168] O44 - LFC:[MD5.D83841B6EE406B58461ACE8A6308AA2D] - 5/25/2015 - 1:38:03 AM ---A- . (.Microsoft Corporation - لوحة تحكم المستخدم.) -- C:\Windows\System32\usercpl.dll [600064] O44 - LFC:[MD5.58405E4F68BA8E4057C6E914F326ABA2] - 5/25/2015 - 1:38:03 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمة محطة العمل.) -- C:\Windows\System32\wkssvc.dll [84480] O44 - LFC:[MD5.D56D2F498713BD66F50763D5285F4F38] - 5/25/2015 - 1:38:04 AM ---A- . (.Microsoft Corporation - Demand Dial Manager Supervisor.) -- C:\Windows\System32\mprddm.dll [268800] O44 - LFC:[MD5.613BF4820361543956909043A265C6AC] - 5/25/2015 - 1:38:04 AM ---A- . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [242176] O44 - LFC:[MD5.573EF199073CE66169B4A8166EB8581B] - 5/25/2015 - 1:38:04 AM ---A- . (.Microsoft Corporation - أداة MMC الإضافية "المستخدمين المحليين والم.) -- C:\Windows\System32\localsec.dll [429056] O44 - LFC:[MD5.0BA4982FE2C21D3D4A68B81FB25474D7] - 5/25/2015 - 1:38:04 AM ---A- . (.Microsoft Corporation - شاشة التوقف المستخدم فيها الصور.) -- C:\Windows\System32\PhotoScreensaver.scr [413696] O44 - LFC:[MD5.69C81451DCE63069A036FBF646A86996] - 5/25/2015 - 1:38:04 AM ---A- . (.Microsoft Corporation - مجلد خطوط Windows.) -- C:\Windows\System32\fontext.dll [828928] O44 - LFC:[MD5.C7952D0A4C43A965A1741916BB134751] - 5/25/2015 - 1:38:04 AM ---A- . (.Microsoft Corporation - مجموعة المشاركة المنزلية في لوحة التحكم.) -- C:\Windows\System32\hgcpl.dll [312832] O44 - LFC:[MD5.2CFA4569350B7F84F815E9EC34E85766] - 5/25/2015 - 1:38:04 AM ---A- . (.Microsoft Corporation - مستوى صوت SCA.) -- C:\Windows\System32\SndVolSSO.dll [220160] O44 - LFC:[MD5.8124944EC89D6A1815E4E53F5B96AAF4] - 5/25/2015 - 1:38:04 AM ---A- . (.Microsoft Corporation - مشغل عميل محرر تكوين أمان Windows.) -- C:\Windows\System32\scecli.dll [175616] O44 - LFC:[MD5.7F8678C59F188528D60104E697C2361E] - 5/25/2015 - 1:38:04 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لنظام مطابقة الأل.) -- C:\Windows\System32\mscms.dll [481792] O44 - LFC:[MD5.EB9B8B2C75FFC489F57E16794FD41215] - 5/25/2015 - 1:38:04 AM ---A- . (.Microsoft Corporation - موفر تسجيل حسابات NPS.) -- C:\Windows\System32\iasacct.dll [78848] O44 - LFC:[MD5.64B628C5258625129288F2D0C75268DA] - 5/25/2015 - 1:38:05 AM ---A- . (.Microsoft Corporation - CPL لإضفاء الطابع الشخصي.) -- C:\Windows\System32\themecpl.dll [2157568] O44 - LFC:[MD5.7DC1FABD139B6AE5743C5DF75EEC5958] - 5/25/2015 - 1:38:05 AM ---A- . (.Microsoft Corporation - DNS Client MMC Snap-in DLL.) -- C:\Windows\System32\dnscmmc.dll [109056] O44 - LFC:[MD5.518395321DC96FE2C9F0E96AC743B656] - 5/25/2015 - 1:38:05 AM ---A- . (.Microsoft Corporation - ReadyBoost Driver.) -- C:\Windows\System32\Drivers\rdyboost.sys [173440] O44 - LFC:[MD5.43B3206DD654E783AA7E4EAD340A43B8] - 5/25/2015 - 1:38:05 AM ---A- . (.Microsoft Corporation - برنامج تشغيل المنفذ المصغر لـ Bluetooth.) -- C:\Windows\System32\Drivers\BTHUSB.SYS [60416] O44 - LFC:[MD5.E8CB091A918C1C687B087389D9A66B39] - 5/25/2015 - 1:38:05 AM ---A- . (.Microsoft Corporation - فتح منطقة الدعم لأدوات الاستشعار.) -- C:\Windows\System32\SensorsCpl.dll [2202624] O44 - LFC:[MD5.BFDC1FE9B277779E3263B0B2A9DC3E0D] - 5/25/2015 - 1:38:05 AM ---A- . (.Microsoft Corporation - لوحة تحكم المراقبة الأبوية.) -- C:\Windows\System32\wpccpl.dll [766464] O44 - LFC:[MD5.A3CAE5D281DB4CFF7CFF8233507EE5AD] - 5/25/2015 - 1:38:06 AM ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\Drivers\iaStorV.sys [332160] O44 - LFC:[MD5.41E215F560028DBAA897DEAEF8390A7A] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - Cabinet File Viewer Shell Extension.) -- C:\Windows\System32\cabview.dll [132608] O44 - LFC:[MD5.C43580971DE309516BAFC30DE736C147] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - Microsoft Distributed Transaction Coordinat.) -- C:\Windows\System32\msdtctm.dll [1066496] O44 - LFC:[MD5.9FC4D46F7BCAD9EE8517171195917776] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - Microsoft TAPI3 Terminal Manager.) -- C:\Windows\System32\termmgr.dll [352768] O44 - LFC:[MD5.8EA53101FF2B15BDFF934B62A8FB326D] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - Net Logon Client DLL.) -- C:\Windows\System32\logoncli.dll [127488] O44 - LFC:[MD5.67F9B5C7E215B48F9256757E9CC09A7B] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - Remote Access PPP.) -- C:\Windows\System32\rasppp.dll [176640] O44 - LFC:[MD5.099972E1FAF4950D3994FBAB9DD21253] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - SCSI Port Driver.) -- C:\Windows\System32\Drivers\scsiport.sys [140160] O44 - LFC:[MD5.5E6E37DC2EFE39EC146271E22A16844F] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - Shell setup helper.) -- C:\Windows\System32\shsetup.dll [111104] O44 - LFC:[MD5.DCAFFD62259E0BDB433DD67B5BB37619] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - Storage VSC Driver.) -- C:\Windows\System32\Drivers\storvsc.sys [28032] O44 - LFC:[MD5.472AF0311073DCECEAA8FA18BA2BDF89] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - Virtual Storage Filter Driver.) -- C:\Windows\System32\Drivers\vmstorfl.sys [40704] O44 - LFC:[MD5.62BA4FDCA65BDB69695E0D1157C57717] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - Windows Hypervisor Interface Driver.) -- C:\Windows\System32\Drivers\winhv.sys [43392] O44 - LFC:[MD5.8EC00CCCBB3436D534FC8DA85FF943BF] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - إدارة تطبيقات Shell.) -- C:\Windows\System32\appwiz.cpl [649216] O44 - LFC:[MD5.3E158EB9DC295CA3EF8D1F1EF57ABEDD] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - استكشاف أخطاء "لوحة التحكم" وإصلاحها.) -- C:\Windows\System32\DiagCpl.dll [1188864] O44 - LFC:[MD5.E4343C7233EF714435231A85F11677D7] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - لوحة تحكم المقاييس الحيوية.) -- C:\Windows\System32\biocpl.dll [428032] O44 - LFC:[MD5.84897874906481E0B3F4045DAD90D69F] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - لوحة تحكم جدار حماية Windows.) -- C:\Windows\System32\FirewallControlPanel.dll [856576] O44 - LFC:[MD5.E3AE23569749DE12D45BA3B489A036AE] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - مكتبة تراخيص البرامج.) -- C:\Windows\System32\sppcomapi.dll [193536] O44 - LFC:[MD5.4D7B1415719FFCC700118318D86FD7EC] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - واجهة المستخدم الافتراضية للماسح الضوئي لـ.) -- C:\Windows\System32\wiadefui.dll [416768] O44 - LFC:[MD5.A00075951E38A73FE2F9D8384311710A] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - ‎‎أداة تكوين النظام المساعدة.) -- C:\Windows\System32\msconfig.exe [233984] O44 - LFC:[MD5.050A774CF85E04EE4387515994B8455D] - 5/25/2015 - 1:38:06 AM ---A- . (.Microsoft Corporation - ‎‎محرر الأحرف الخاصة.) -- C:\Windows\System32\eudcedit.exe [288256] O44 - LFC:[MD5.909C11946AC04EA54A98C97792DC3C18] - 5/25/2015 - 1:38:07 AM ---A- . (.Microsoft Corporation - DLL الخاص بكائنات PrintUI.) -- C:\Windows\System32\puiobj.dll [324608] O44 - LFC:[MD5.26EF8C37B8D58E98EE49F0DA81E77283] - 5/25/2015 - 1:38:07 AM ---A- . (.Microsoft Corporation - Microsoft Digital Receiver Interface Class.) -- C:\Windows\System32\msdri.dll [417792] O44 - LFC:[MD5.8483DD8F87DBE86AAB55BBF95C207061] - 5/25/2015 - 1:38:07 AM ---A- . (.Microsoft Corporation - Microsoft Distributed Transaction Coordinat.) -- C:\Windows\System32\mtxclu.dll [320512] O44 - LFC:[MD5.8A244E6F8004A421359812C3FC55AE1B] - 5/25/2015 - 1:38:07 AM ---A- . (.Microsoft Corporation - XPS Rasterization Service Component.) -- C:\Windows\System32\XpsRasterService.dll [135168] O44 - LFC:[MD5.14558D849EC14160AC3DACD8AC36E10A] - 5/25/2015 - 1:38:07 AM ---A- . (.Microsoft Corporation - العرض في لوحة التحكم.) -- C:\Windows\System32\Display.dll [1040384] O44 - LFC:[MD5.2D699FB6E89CE0D8DA14ECC03B3EDFE0] - 5/25/2015 - 1:38:07 AM ---A- . (.Microsoft Corporation - برنامج تشغيل ناقل دعم MultiPath.) -- C:\Windows\System32\Drivers\mpio.sys [130432] O44 - LFC:[MD5.B7A7EFA6DBB68401CFAB1C4252FD3257] - 5/25/2015 - 1:38:07 AM ---A- . (.Microsoft Corporation - لوحة التحكم لمشاركة الوسائط.) -- C:\Windows\System32\sharemediacpl.dll [316416] O44 - LFC:[MD5.3EC541C196DE18ED9A0D0AC82A694D4C] - 5/25/2015 - 1:38:07 AM ---A- . (.Microsoft Corporation - واجهة مستخدم ذاكرة التخزين المؤقت من جانب ا.) -- C:\Windows\System32\cscui.dll [418816] O44 - LFC:[MD5.61AC3EFDFACFDD3F0F11DD4FD4044223] - 5/25/2015 - 1:38:07 AM ---A- . (.Microsoft Corporation - ‎‎تطبيق تسجيل دخول Userinit.) -- C:\Windows\System32\userinit.exe [26624] O44 - LFC:[MD5.39B9273CA01364E115B464416CFB729B] - 5/25/2015 - 1:38:08 AM ---A- . (.Microsoft - robocopy.) -- C:\Windows\System32\Robocopy.exe [98816] O44 - LFC:[MD5.ABA2AAA6F31EE934A76C87B537515EC6] - 5/25/2015 - 1:38:08 AM ---A- . (.Microsoft Corporation - مزامنة Microsoft Windows DXP..) -- C:\Windows\System32\DxpTaskSync.dll [1400320] O44 - LFC:[MD5.545BF7EAA24A9E062857D0742EC0B28A] - 5/25/2015 - 1:38:08 AM ---A- . (.Microsoft Corporation - ‎‎إدارة مهام Windows.) -- C:\Windows\System32\taskmgr.exe [227328] O44 - LFC:[MD5.45D9F6CD2469CDB6A640DD4BD2B01471] - 5/25/2015 - 1:38:09 AM ---A- . (.Microsoft Corporation - CoInstaller: NET.) -- C:\Windows\System32\nci.dll [78848] O44 - LFC:[MD5.5997D769CDB108390DCFAEBF442BF816] - 5/25/2015 - 1:38:09 AM ---A- . (.Microsoft Corporation - Remote RPC Extension.) -- C:\Windows\System32\RpcRtRemote.dll [46080] O44 - LFC:[MD5.6658F4404DE03D75FE3BA09F7ABA6A30] - 5/25/2015 - 1:38:09 AM ---A- . (.Microsoft Corporation - Windows HomeGroup.) -- C:\Windows\System32\ListSvc.dll [194560] O44 - LFC:[MD5.12C1BBE5B01F554DC2FA3225131E2D2B] - 5/25/2015 - 1:38:09 AM ---A- . (.Microsoft Corporation - Windows Media Network Plugin Manager DLL.) -- C:\Windows\System32\WMNetMgr.dll [1003008] O44 - LFC:[MD5.CC88EF08712C08C5F5FE74A395BA25AC] - 5/25/2015 - 1:38:09 AM ---A- . (.Microsoft Corporation - الشبكات اللاسلكية المفضلة.) -- C:\Windows\System32\wlanpref.dll [1326592] O44 - LFC:[MD5.669E18322F05A14356E8F6DA16D15DA0] - 5/25/2015 - 1:38:09 AM ---A- . (.Microsoft Corporation - لوحة التحكم مخزن Windows.) -- C:\Windows\System32\Vault.dll [933376] O44 - LFC:[MD5.5EFDBEAECD69E250E5BA4A2950203CD4] - 5/25/2015 - 1:38:09 AM ---A- . (.Microsoft Corporation - ‎‎Microsoft® Windows Backup.) -- C:\Windows\System32\sdclt.exe [1131008] O44 - LFC:[MD5.CF87A1DE791347E75B98885214CED2B8] - 5/25/2015 - 1:38:09 AM ---A- . (.Microsoft Corporation - ‎‎خدمة النظام الأساسي لحماية البرامج لـ Mic.) -- C:\Windows\System32\sppsvc.exe [3179520] O44 - LFC:[MD5.D2958325C1AE1AE37A83334C6229E3BC] - 5/25/2015 - 1:38:10 AM ---A- . (.Microsoft Corporation - ActiveX Interface Marshaling Library.) -- C:\Windows\System32\actxprxy.dll [309760] O44 - LFC:[MD5.280122DDCF04B378EDD1AD54D71C1E54] - 5/25/2015 - 1:38:10 AM ---A- . (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\Drivers\netbt.sys [187904] O44 - LFC:[MD5.6E79D0D90AB03DC45AFACA52A6699963] - 5/25/2015 - 1:38:10 AM ---A- . (.Microsoft Corporation - Microsoft Network Provider for MPEG2 based.) -- C:\Windows\System32\MSNP.ax [204288] O44 - LFC:[MD5.82E7ECE9096EEACB2EAC5644FE19A6F2] - 5/25/2015 - 1:38:10 AM ---A- . (.Microsoft Corporation - NTFS Utility DLL.) -- C:\Windows\System32\untfs.dll [346624] O44 - LFC:[MD5.02530B0B7E048DD5AC8D52DAEACAEB2B] - 5/25/2015 - 1:38:10 AM ---A- . (.Microsoft Corporation - Quarantine Agent Proxy.) -- C:\Windows\System32\QAGENT.DLL [171520] O44 - LFC:[MD5.CDBE627E16CC9E98F343D73F8E81D258] - 5/25/2015 - 1:38:10 AM ---A- . (.Microsoft Corporation - Server Network driver.) -- C:\Windows\System32\Drivers\srvnet.sys [114176] O44 - LFC:[MD5.6A1E8DEB746912DF47CF651E138401D7] - 5/25/2015 - 1:38:10 AM ---A- . (.Microsoft Corporation - Structured Query.) -- C:\Windows\System32\StructuredQuery.dll [363520] O44 - LFC:[MD5.67BCB4490E9C7307E39C150CC09BEF9A] - 5/25/2015 - 1:38:10 AM ---A- . (.Microsoft Corporation - System Control Panel Applet; Network ID Pag.) -- C:\Windows\System32\netid.dll [117248] O44 - LFC:[MD5.BF63EBFC6979FEFB2BC03DF7989A0C1A] - 5/25/2015 - 1:38:10 AM ---A- . (.Microsoft Corporation - USB Mass Storage Class Driver.) -- C:\Windows\System32\Drivers\USBSTOR.SYS [76288] O44 - LFC:[MD5.F87D30E72E03D579A5199CCB3831D6EA] - 5/25/2015 - 1:38:10 AM ---A- . (.Microsoft Corporation - User-mode Power Service.) -- C:\Windows\System32\umpo.dll [119808] O44 - LFC:[MD5.4C63E00F2F4B5F86AB48A58CD990F212] - 5/25/2015 - 1:38:10 AM ---A- . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys [53120] O44 - LFC:[MD5.83C9840CF87A0CA55526327801716D27] - 5/25/2015 - 1:38:10 AM ---A- . (.Microsoft Corporation - التطبيقات الصغيرة للوقت والتاريخ في لوحة ال.) -- C:\Windows\System32\timedate.cpl [478720] O44 - LFC:[MD5.FCA71F6230075CD687189AC29AB06945] - 5/25/2015 - 1:38:10 AM ---A- . (.Microsoft Corporation - لوحة التحكم لـ Microsoft Windows SideShow.) -- C:\Windows\System32\AuxiliaryDisplayCpl.dll [665600] O44 - LFC:[MD5.53E054880ADBB856ECE6EB10EDBB8A32] - 5/25/2015 - 1:38:10 AM ---A- . (.Microsoft Corporation - لوحة تحكم الصوت.) -- C:\Windows\System32\mmsys.cpl [905216] O44 - LFC:[MD5.8BCF1DCE05F4494C8891F33EEA450D0A] - 5/25/2015 - 1:38:10 AM ---A- . (.Microsoft Corporation - مراقبة الأداء.) -- C:\Windows\System32\wdc.dll [1227776] O44 - LFC:[MD5.ADDB05C93272A62606599B24730BD645] - 5/25/2015 - 1:38:10 AM ---A- . (.Microsoft Corporation - ملحق Shell لـ Device Stage.) -- C:\Windows\System32\DXP.dll [399872] O44 - LFC:[MD5.B1603F0A972B94927B8EF5F04DF11855] - 5/25/2015 - 1:38:11 AM ---A- . (.Microsoft Corporation - IP Security Monitor Snap-in.) -- C:\Windows\System32\ipsmsnap.dll [400896] O44 - LFC:[MD5.2003E9B15E1C502B146DAD2E383AC1E3] - 5/25/2015 - 1:38:11 AM ---A- . (.Microsoft Corporation - Manages scheduled tasks.) -- C:\Windows\System32\schtasks.exe [179712] O44 - LFC:[MD5.9A892B3439884C62B04718F0303A49E9] - 5/25/2015 - 1:38:11 AM ---A- . (.Microsoft Corporation - Microsoft EAPHost Peer service.) -- C:\Windows\System32\eapphost.dll [222208] O44 - LFC:[MD5.E362FAA5E232D9A326F42D8F78AEA2D8] - 5/25/2015 - 1:38:11 AM ---A- . (.Microsoft Corporation - WMI SDK Provider Framework.) -- C:\Windows\System32\framedyn.dll [202752] O44 - LFC:[MD5.34EEE0DFAADB4F691D6D5308A51315DC] - 5/25/2015 - 1:38:11 AM ---A- . (.Microsoft Corporation - Windows Connect Now - Config Registrar Serv.) -- C:\Windows\System32\wcncsvc.dll [276992] O44 - LFC:[MD5.3925944734DFC5D2253F3DC5923F797D] - 5/25/2015 - 1:38:11 AM ---A- . (.Microsoft Corporation - خيارات الطاقة في لوحة التحكم.) -- C:\Windows\System32\powercpl.dll [441856] O44 - LFC:[MD5.674B0C0F6A448EB185CAAB9C51D44032] - 5/25/2015 - 1:38:11 AM ---A- . (.Microsoft Corporation - خيارات الفهرسة.) -- C:\Windows\System32\srchadmin.dll [301568] O44 - LFC:[MD5.B81E879AE660F9D244FC20EC8A26783E] - 5/25/2015 - 1:38:11 AM ---A- . (.Microsoft Corporation - عامل تصفية MIME.) -- C:\Windows\System32\mimefilt.dll [42496] O44 - LFC:[MD5.CAFC0B884E5590B5E80D84F592388B3D] - 5/25/2015 - 1:38:11 AM ---A- . (.Microsoft Corporation - كائنات تكوين الشبكة.) -- C:\Windows\System32\tcpipcfg.dll [181760] O44 - LFC:[MD5.F88A52EB62019D6A62FDD9E08034DBD8] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - Auto Check Utility.) -- C:\Windows\System32\autochk.exe [668160] O44 - LFC:[MD5.09D786401F6CA6AEB16B2811B169F944] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - Auto File System Conversion Utility.) -- C:\Windows\System32\autoconv.exe [679424] O44 - LFC:[MD5.A475B7BB0CCCFD848AA26075E81D7888] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - Auto File System Format Utility.) -- C:\Windows\System32\autofmt.exe [658944] O44 - LFC:[MD5.CF13841F9F2B231F0DF974425888B89A] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - Boot Resource Library.) -- C:\Windows\System32\bootres.dll [2217856] O44 - LFC:[MD5.56CEED370508F69A1BA04939BD1BADDA] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - DLL لخادم MSUTB.) -- C:\Windows\System32\msutb.dll [167936] O44 - LFC:[MD5.CFE599FA85D52F82327FA8C549AD9296] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - HBA API data interface dll for HBA_API_Rev_.) -- C:\Windows\System32\hbaapi.dll [66560] O44 - LFC:[MD5.1BF0D4727FDB437D513CFF8A9359C050] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - Hardware Abstraction Layer DLL.) -- C:\Windows\System32\hal.dll [194432] O44 - LFC:[MD5.1BF0D4727FDB437D513CFF8A9359C050] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - Hardware Abstraction Layer DLL.) -- C:\Windows\System32\halmacpi.dll [194432] O44 - LFC:[MD5.A90DC9ABD65DB1A8902F361103029952] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - IP Helper API.) -- C:\Windows\System32\IPHLPAPI.DLL [103936] O44 - LFC:[MD5.95DE3CF54E0A360EED766DBDDF152F0D] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - Narrator.) -- C:\Windows\System32\Narrator.exe [1077248] O44 - LFC:[MD5.38CACBEB75E3F85CBF7E65522DFDA1B0] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - Netio Helper DLL.) -- C:\Windows\System32\netiohlp.dll [166400] O44 - LFC:[MD5.2607A85B6466C0110EA8ABB9D8CC83FC] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - Registry Configuration APIs.) -- C:\Windows\System32\regapi.dll [72192] O44 - LFC:[MD5.CB9E04DC05EACF5B9A36CA276D475006] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [286208] O44 - LFC:[MD5.68ECCA523ED760AAFC03C5D587569859] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - Security Accounts Manager Client DLL.) -- C:\Windows\System32\samcli.dll [51200] O44 - LFC:[MD5.EE43346C7E4B5E63E54F927BABBB32FF] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - UDF File System Driver.) -- C:\Windows\System32\Drivers\udfs.sys [246784] O44 - LFC:[MD5.CEA80C80BED809AA0DA6FEBC04733349] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - برنامج تشغيل ACPI الخاص بـ NT.) -- C:\Windows\System32\Drivers\acpi.sys [274304] O44 - LFC:[MD5.6FEC7B9A76B41D9AC67615A3040017F5] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - خدمة إدارة بيانات الاعتماد.) -- C:\Windows\System32\vaultsvc.dll [196096] O44 - LFC:[MD5.763FECDC3D30C815FE72DD57936C6CD1] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - خدمة إدخال الكمبيوتر اللوحي لـ Microsoft.) -- C:\Windows\System32\TabSvc.dll [73216] O44 - LFC:[MD5.672D7C5080ACB003343006405DA2E621] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - ذاكرة التخزين المؤقت للصور المصغرة لـ Micro.) -- C:\Windows\System32\thumbcache.dll [82944] O44 - LFC:[MD5.D5AEFAD57C08349A4393D987DF7C715D] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي الخاصة بـ MCI API.) -- C:\Windows\System32\winmm.dll [194048] O44 - LFC:[MD5.414DA952A35BF5D50192E28263B40577] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمات Windows Sh.) -- C:\Windows\System32\shsvcs.dll [328192] O44 - LFC:[MD5.2E77BAB79F078654782F83F0A0AEFE31] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - ‎‎ProQuota.) -- C:\Windows\System32\proquota.exe [28672] O44 - LFC:[MD5.5F2122888583347C9B81724CF169EFC6] - 5/25/2015 - 1:38:12 AM ---A- . (.Microsoft Corporation - ‎‎معلومات النظام.) -- C:\Windows\System32\msinfo32.exe [303104] O44 - LFC:[MD5.F748F53FE09D21D8ECBB6421E6792024] - 5/25/2015 - 1:38:13 AM ---A- . (.Microsoft Corporation - IEEE 802.1X supplicant library.) -- C:\Windows\System32\onex.dll [199168] O44 - LFC:[MD5.754AFC50022C95DA7C86B7020DB78136] - 5/25/2015 - 1:38:13 AM ---A- . (.Microsoft Corporation - Microsoft Desktop Window Manager Redirectio.) -- C:\Windows\System32\dwmredir.dll [97280] O44 - LFC:[MD5.80C5342074711F098A00F71FFF262B3B] - 5/25/2015 - 1:38:13 AM ---A- . (.Microsoft Corporation - Windows Media Player Encoding Module.) -- C:\Windows\System32\WMPEncEn.dll [1624064] O44 - LFC:[MD5.C262B132CF3790405A9AC8C5B18847A1] - 5/25/2015 - 1:38:14 AM ---A- . (.Microsoft Corporation - Application Experience Program Inventory Co.) -- C:\Windows\System32\aeinv.dll [302592] O44 - LFC:[MD5.2D11BC8B460957E62E4420373A0D8BDA] - 5/25/2015 - 1:38:14 AM ---A- . (.Microsoft Corporation - Image Mastering API v2.) -- C:\Windows\System32\imapi2.dll [392192] O44 - LFC:[MD5.012C5F4E9349E711E11E0F19A8589F0A] - 5/25/2015 - 1:38:14 AM ---A- . (.Microsoft Corporation - MS AHCI 1.0 Standard Driver.) -- C:\Windows\System32\Drivers\msahci.sys [28032] O44 - LFC:[MD5.1BE1A0487946F64AF5D2946AD1ECD596] - 5/25/2015 - 1:38:14 AM ---A- . (.Microsoft Corporation - System Clone Tool.) -- C:\Windows\System32\setupcl.exe [103936] O44 - LFC:[MD5.E1FB3706030FB4578A0D72C2FC3689E4] - 5/25/2015 - 1:38:14 AM ---A- . (.Microsoft Corporation - خدمة أجهزة الصور الثابتة.) -- C:\Windows\System32\wiaservc.dll [463360] O44 - LFC:[MD5.1078F4A06BE5DACDC8429215ADAE8104] - 5/25/2015 - 1:38:14 AM ---A- . (.Microsoft Corporation - محرر نغمات الرنين لـ Microsoft.) -- C:\Windows\System32\DXPTaskRingtone.dll [630784] O44 - LFC:[MD5.938F39B50BAFE13D6F58C7790682C010] - 5/25/2015 - 1:38:15 AM ---A- . (.Microsoft Corporation - ASN.1 Runtime APIs.) -- C:\Windows\System32\msasn1.dll [34304] O44 - LFC:[MD5.0B5FED26EA8686163591F2609DEF5C89] - 5/25/2015 - 1:38:15 AM ---A- . (.Microsoft Corporation - MCMDE DLL.) -- C:\Windows\System32\mcmde.dll [727040] O44 - LFC:[MD5.33B0A618BA5F44E67757C561D0A935C1] - 5/25/2015 - 1:38:15 AM ---A- . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) -- C:\Windows\System32\WFS.exe [802304] O44 - LFC:[MD5.5461686CCA2FDA57B024547733AB42E3] - 5/25/2015 - 1:38:15 AM ---A- . (.Microsoft Corporation - VHD Miniport Driver.) -- C:\Windows\System32\Drivers\vhdmp.sys [160128] O44 - LFC:[MD5.CBBD4D79EEC3EF5A4ADAE9697944C6B9] - 5/25/2015 - 1:38:15 AM ---A- . (.Microsoft Corporation - أداة ترميز Microsoft MPEG-2.) -- C:\Windows\System32\MSMPEG2ENC.DLL [830464] O44 - LFC:[MD5.9E4B0E7472B4CEBA9E17F440B8CB0AB8] - 5/25/2015 - 1:38:15 AM ---A- . (.Microsoft Corporation - برنامج تشعيل Windows Spooler.) -- C:\Windows\System32\winspool.drv [320000] O44 - LFC:[MD5.414BBA67A3DED1D28437EB66AEB8A720] - 5/25/2015 - 1:38:15 AM ---A- . (.Microsoft Corporation - تنبيهات وسجلات الأداء.) -- C:\Windows\System32\pla.dll [1508864] O44 - LFC:[MD5.CF4274CEEA9F7791FB7FC40A066BC2C7] - 5/25/2015 - 1:38:15 AM ---A- . (.Microsoft Corporation - كائن In-proc COM المستخدم من قبل عملاء CSC.) -- C:\Windows\System32\cscobj.dll [139264] O44 - LFC:[MD5.9419ABF3163B6F0E3AD3DD2B381C879F] - 5/25/2015 - 1:38:15 AM ---A- . (.Microsoft Corporation - واجهة برمجة تطبيقات البطاقة الذكية لـ Micro.) -- C:\Windows\System32\WinSCard.dll [134656] O44 - LFC:[MD5.F74737E0EF87295E82EBD0A4B040539A] - 5/25/2015 - 1:38:15 AM ---A- . (.Microsoft Corporation - ‎‎مكون الإدخال بالقلم واللمس لـ Microsoft.) -- C:\Windows\System32\wisptis.exe [334336] O44 - LFC:[MD5.146459D2B08BFDCBFA856D9947043C81] - 5/25/2015 - 1:38:16 AM ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [22400] O44 - LFC:[MD5.B973FCFC50DC1434E1970A146F7E3885] - 5/25/2015 - 1:38:16 AM ---A- . (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\Drivers\rdpdr.sys [133632] O44 - LFC:[MD5.6B140B1382F1FE04BA57B196AEB19725] - 5/25/2015 - 1:38:16 AM ---A- . (.Microsoft Corporation - Microsoft T2Embed Font Embedding.) -- C:\Windows\System32\t2embed.dll [109056] O44 - LFC:[MD5.3B28814B74E898750A139FA4CBDFDCF7] - 5/25/2015 - 1:38:16 AM ---A- . (.Microsoft Corporation - Microsoft® Windows Backup Engine.) -- C:\Windows\System32\sdengin2.dll [907776] O44 - LFC:[MD5.C6FA3CBF5C6BD7B9BCB63441C6D67EA7] - 5/25/2015 - 1:38:16 AM ---A- . (.Microsoft Corporation - Network Diagnostic Framework.) -- C:\Windows\System32\netdiagfx.dll [225792] O44 - LFC:[MD5.04DBF4B01EA4BF25A9A3E84AFFAC9B20] - 5/25/2015 - 1:38:16 AM ---A- . (.Microsoft Corporation - Remote Desktop Server Driver.) -- C:\Windows\System32\Drivers\termdd.sys [53120] O44 - LFC:[MD5.86472B217C2E96640297B3F719BD7CBF] - 5/25/2015 - 1:38:16 AM ---A- . (.Microsoft Corporation - Remote Desktop Session Host Server Configur.) -- C:\Windows\System32\tscfgwmi.dll [154624] O44 - LFC:[MD5.05D860DA1040F111503AC416CCEF2BCA] - 5/25/2015 - 1:38:16 AM ---A- . (.Microsoft Corporation - SBP-2 Protocol Driver.) -- C:\Windows\System32\Drivers\sbp2port.sys [85376] O44 - LFC:[MD5.774D0EB71920648ACC79642341CA56C7] - 5/25/2015 - 1:38:16 AM ---A- . (.Microsoft Corporation - Virtual Machine Integration Component Servi.) -- C:\Windows\System32\vmicsvc.exe [215552] O44 - LFC:[MD5.A8CDF3768604FF95B54669E20053D569] - 5/25/2015 - 1:38:16 AM ---A- . (.Microsoft Corporation - Windows Security Center API.) -- C:\Windows\System32\wscapi.dll [51712] O44 - LFC:[MD5.1D3198205747685AAC2EED0B3BCD38C3] - 5/25/2015 - 1:38:16 AM ---A- . (.Microsoft Corporation - المثبت المشترك لبرنامج تشغيل USB العام الخا.) -- C:\Windows\System32\TsUsbGDCoInstaller.dll [33280] O44 - LFC:[MD5.2DDEA2C345DA5BC589EFD398F220DB0E] - 5/25/2015 - 1:38:16 AM ---A- . (.Microsoft Corporation - مركز مزامنة Microsoft.) -- C:\Windows\System32\SyncCenter.dll [2146304] O44 - LFC:[MD5.342E7165807B7C0BC9E810F3A9E2527E] - 5/25/2015 - 1:38:16 AM ---A- . (.Microsoft Corporation - ملحق Script Adm.) -- C:\Windows\System32\scrptadm.dll [464896] O44 - LFC:[MD5.181F69BC9C406B7FB5C0ADE8031630AC] - 5/25/2015 - 1:38:16 AM ---A- . (.Microsoft Corporation - ملحق Shell الخاص بالأجهزة المحمولة.) -- C:\Windows\System32\wpdshext.dll [2311168] O44 - LFC:[MD5.B70B2E022318E7EF942EEAC7126E6972] - 5/25/2015 - 1:38:16 AM ---A- . (.Microsoft Corporation - ملحق الأداة الإضافية الخاص بإعادة توجيه الم.) -- C:\Windows\System32\fde.dll [124416] O44 - LFC:[MD5.DB846EECA70EE9D2E2FF31147C57B0F4] - 5/25/2015 - 1:38:16 AM ---A- . (.Microsoft Corporation - وقت تشغيل خدمات ويب في Windows.) -- C:\Windows\System32\webservices.dll [782336] O44 - LFC:[MD5.53946B69BA0836BD95B03759530C81EC] - 5/25/2015 - 1:38:17 AM ---A- . (.Microsoft Corporation - DLL الخاصة بخادم Windows IPsec SPD.) -- C:\Windows\System32\IPSECSVC.DLL [350208] O44 - LFC:[MD5.34391196FE00480C9ADBFBE215B6B28C] - 5/25/2015 - 1:38:17 AM ---A- . (.Microsoft Corporation - Quarantine SHV Host.) -- C:\Windows\System32\QSHVHOST.DLL [167936] O44 - LFC:[MD5.F99A4D145C862CBAD61B409C0AB0CD65] - 5/25/2015 - 1:38:17 AM ---A- . (.Microsoft Corporation - Wireless Network Policy Management Snap-in.) -- C:\Windows\System32\wlangpui.dll [411648] O44 - LFC:[MD5.3D6F22551D422F97AACB0BB927E4C846] - 5/25/2015 - 1:38:17 AM ---A- . (.Microsoft Corporation - رمز نظام الشبكة.) -- C:\Windows\System32\pnidui.dll [1750528] O44 - LFC:[MD5.CAEF9CD6C10B1017E2C298D849CD31DB] - 5/25/2015 - 1:38:18 AM ---A- . (.Microsoft Corporation - Canonical Display Driver.) -- C:\Windows\System32\cdd.dll [107520] O44 - LFC:[MD5.967EA5B213E9984CBE270205DF37755B] - 5/25/2015 - 1:38:18 AM ---A- . (.Microsoft Corporation - Fax Service.) -- C:\Windows\System32\FXSSVC.exe [523264] O44 - LFC:[MD5.243974EC02F7AE49E4179C54624143AB] - 5/25/2015 - 1:38:18 AM ---A- . (.Microsoft Corporation - MMDevice API.) -- C:\Windows\System32\MMDevAPI.dll [213504] O44 - LFC:[MD5.3E63222185341DCB8EEEDB8E2761EE6F] - 5/25/2015 - 1:38:18 AM ---A- . (.Microsoft Corporation - Microsoft® Windows(TM) ScanSettings Profile.) -- C:\Windows\System32\scansetting.dll [246272] O44 - LFC:[MD5.2041012726EF7C95ED51C15C56545A7F] - 5/25/2015 - 1:38:18 AM ---A- . (.Microsoft Corporation - Net Command.) -- C:\Windows\System32\net1.exe [142336] O44 - LFC:[MD5.A2718532AFF3B0F9C73D3034A1511F50] - 5/25/2015 - 1:38:18 AM ---A- . (.Microsoft Corporation - RPC HTTP DLL.) -- C:\Windows\System32\rpchttp.dll [139264] O44 - LFC:[MD5.C2F2911156FDC7817C52829C86DA494E] - 5/25/2015 - 1:38:18 AM ---A- . (.Microsoft Corporation - Virtual Machine Bus.) -- C:\Windows\System32\Drivers\vmbus.sys [175360] O44 - LFC:[MD5.0F416E23DD2EB4DEBE70608020CFD283] - 5/25/2015 - 1:38:18 AM ---A- . (.Microsoft Corporation - Windows Media Playback/Authoring DLL.) -- C:\Windows\System32\WMVCORE.DLL [2504192] O44 - LFC:[MD5.3B91EA6DC3AE6088C880AB9073A833C2] - 5/25/2015 - 1:38:18 AM ---A- . (.Microsoft Corporation - Windows Media Player Effects.) -- C:\Windows\System32\wmpeffects.dll [352256] O44 - LFC:[MD5.73F6C5223F7E9B5780DD4A6C30FCF569] - 5/25/2015 - 1:38:18 AM ---A- . (.Microsoft Corporation - خدمات ويب لـ DLL الخاصة بواجهة برمجة تطبيقا.) -- C:\Windows\System32\WSDApi.dll [458752] O44 - LFC:[MD5.2FE30D71919C51131405797620E0A714] - 5/25/2015 - 1:38:18 AM ---A- . (.Microsoft Corporation - خدمة محلل التخزين المؤقت لـ DNS.) -- C:\Windows\System32\dnsrslvr.dll [132608] O44 - LFC:[MD5.673E55C3498EB970088E812EA820AA8F] - 5/25/2015 - 1:38:18 AM ---A- . (.Microsoft Corporation - عدّاد PCI الخاص بـ "التوصيل والتشغيل لـ NT".) -- C:\Windows\System32\Drivers\pci.sys [153984] O44 - LFC:[MD5.27A81A5FEB2ACF01D406EFE153E95D4C] - 5/25/2015 - 1:38:18 AM ---A- . (.Microsoft Corporation - محدِّث بيانات توافق البرامج.) -- C:\Windows\System32\aepdu.dll [321536] O44 - LFC:[MD5.C3CD30495687C2A2F66A65CA6FD89BE9] - 5/25/2015 - 1:38:18 AM ---A- . (.Microsoft Corporation - ‎‎خدمة الأقراص الظاهرية.) -- C:\Windows\System32\vds.exe [453632] O44 - LFC:[MD5.2A3557DD3913F8D7CC5A5703083424D8] - 5/25/2015 - 1:38:18 AM ---A- . (.Microsoft Corporation - ‎‎عامل تتبع التأثير على التطبيقات.) -- C:\Windows\System32\aitagent.exe [119808] O44 - LFC:[MD5.50AF423CC8915B0010F0A96BF78672E9] - 5/25/2015 - 1:38:19 AM ---A- . (.Microsoft Corporation - Print UI Cache.) -- C:\Windows\System32\prncache.dll [116736] O44 - LFC:[MD5.8EC04CA86F1D68DA9E11952EB85973D6] - 5/25/2015 - 1:38:19 AM ---A- . (.Microsoft Corporation - خدمة نهج تشخيص WDI.) -- C:\Windows\System32\dps.dll [144384] O44 - LFC:[MD5.D27DDE7E0444C7F1819F958469EB7D93] - 5/25/2015 - 1:38:19 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي الخاصة بموفر الطب.) -- C:\Windows\System32\inetpp.dll [126464] O44 - LFC:[MD5.9DF9B31EAC1669F244C02B61F10D123A] - 5/25/2015 - 1:38:19 AM ---A- . (.Microsoft Corporation - واجهة مستخدم إعدادات الطباعة.) -- C:\Windows\System32\printui.dll [932352] O44 - LFC:[MD5.8A73E79089B282100B9393B644CB853B] - 5/25/2015 - 1:38:20 AM ---A- . (.Microsoft Corporation - BitLocker Drive Encryption Driver.) -- C:\Windows\System32\Drivers\fvevol.sys [194800] O44 - LFC:[MD5.919001D2BB17DF06CA3F8AC16AD039F6] - 5/25/2015 - 1:38:20 AM ---A- . (.Microsoft Corporation - Fusion 2.5.) -- C:\Windows\System32\sxs.dll [380416] O44 - LFC:[MD5.F059EB4C9C256F62F196EAA439E28F74] - 5/25/2015 - 1:38:20 AM ---A- . (.Microsoft Corporation - HomeGroup Printing Support.) -- C:\Windows\System32\hgprint.dll [155136] O44 - LFC:[MD5.8D5AAE3F6AEF417EF4DFDB8A3031B877] - 5/25/2015 - 1:38:20 AM ---A- . (.Microsoft Corporation - Remote Desktop Programs WMI provider.) -- C:\Windows\System32\tspubwmi.dll [133632] O44 - LFC:[MD5.EAB975DB4C2805927FE5BD047D05C9AA] - 5/25/2015 - 1:38:20 AM ---A- . (.Microsoft Corporation - Shell الخاص باتصالات الشبكة.) -- C:\Windows\System32\netshell.dll [2494464] O44 - LFC:[MD5.7FF15A4F092CD4A96055BA69F903E3E9] - 5/25/2015 - 1:38:20 AM ---A- . (.Microsoft Corporation - Windows Socket 2.0 32-Bit DLL.) -- C:\Windows\System32\ws2_32.dll [206848] O44 - LFC:[MD5.55055F8AD8BE27A64C831322A780A228] - 5/25/2015 - 1:38:20 AM ---A- . (.Microsoft Corporation - الوحدة النمطية المحددة للجهاز لـ Microsoft.) -- C:\Windows\System32\Drivers\msdsm.sys [116096] O44 - LFC:[MD5.D528BC58A489409BA40334EBF96A311B] - 5/25/2015 - 1:38:20 AM ---A- . (.Microsoft Corporation - برنامج تشغيل النظام الفرعي لتخزين القرص الم.) -- C:\Windows\System32\Drivers\rdbss.sys [242688] O44 - LFC:[MD5.912649A1B3F9E6ACB3899FBDABA2ED5F] - 5/25/2015 - 1:38:20 AM ---A- . (.Microsoft Corporation - كائن خدمة Systray shell.) -- C:\Windows\System32\stobject.dll [228352] O44 - LFC:[MD5.BDAC1AA64495D0F7E1FF810EBBF1F018] - 5/25/2015 - 1:38:20 AM ---A- . (.Microsoft Corporation - مكتبة عناصر التحكم لخبرات المستخدم.) -- C:\Windows\System32\comctl32.dll [530432] O44 - LFC:[MD5.80B562B5B59ED850C328DD75F964F3D8] - 5/25/2015 - 1:38:21 AM ---A- . (.Microsoft Corporation - VPNIKE Protocol Engine - Test dll.) -- C:\Windows\System32\vpnike.dll [242176] O44 - LFC:[MD5.E6D90DC604F407B3B5E0FD285E46B2A0] - 5/25/2015 - 1:38:21 AM ---A- . (.Microsoft Corporation - Windows BitLocker Drive Encryption API.) -- C:\Windows\System32\fveapi.dll [271664] O44 - LFC:[MD5.B85B0267A743607052263447E6091E8C] - 5/25/2015 - 1:38:21 AM ---A- . (.Microsoft Corporation - إطار شريط Windows.) -- C:\Windows\System32\UIRibbon.dll [2983424] O44 - LFC:[MD5.D64AF876D53ECA3668BB97B51B4E70AB] - 5/25/2015 - 1:38:21 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمة الخادم.) -- C:\Windows\System32\srvsvc.dll [168960] O44 - LFC:[MD5.A3901CD2E276484003C2944F78BEB80E] - 5/25/2015 - 1:38:21 AM ---A- . (.Microsoft Corporation - ‎‎مثبت حزمة اللغة.) -- C:\Windows\System32\lpksetup.exe [477696] O44 - LFC:[MD5.E7F4D42D8076EC60E21715CD11743A0D] - 5/25/2015 - 1:38:22 AM ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [80256] O44 - LFC:[MD5.1B133875B8AA8AC48969BD3458AFE9F5] - 5/25/2015 - 1:38:22 AM ---A- . (.Microsoft Corporation - 1394 OpenHCI Driver.) -- C:\Windows\System32\Drivers\1394ohci.sys [164864] O44 - LFC:[MD5.81C0FA250EF6DC1C6B3FA2BCE81D6C2E] - 5/25/2015 - 1:38:22 AM ---A- . (.Microsoft Corporation - API لأداة تعيين نظام Windows.) -- C:\Windows\System32\WinSATAPI.dll [335872] O44 - LFC:[MD5.BFEBB6F76A0988A38260870C61A6D1B7] - 5/25/2015 - 1:38:22 AM ---A- . (.Microsoft Corporation - Media Foundation ReadWrite DLL.) -- C:\Windows\System32\mfreadwrite.dll [196608] O44 - LFC:[MD5.8B57A1AD493653BB57F281FE75DD175B] - 5/25/2015 - 1:38:22 AM ---A- . (.Microsoft Corporation - Natural Language Development Platform 6.) -- C:\Windows\System32\NaturalLanguage6.dll [801280] O44 - LFC:[MD5.61D57A5D7C6D9AFE10E77DAE6E1B445E] - 5/25/2015 - 1:38:22 AM ---A- . (.Microsoft Corporation - Quarantine Agent Service Run-Time.) -- C:\Windows\System32\QAGENTRT.DLL [330240] O44 - LFC:[MD5.4470B0943469C4AF5B114E420DCB1AEF] - 5/25/2015 - 1:38:22 AM ---A- . (.Microsoft Corporation - SQL Server ODBC Driver.) -- C:\Windows\System32\sqlsrv32.dll [778240] O44 - LFC:[MD5.866A43013535DC8587C258E43579C764] - 5/25/2015 - 1:38:22 AM ---A- . (.Microsoft Corporation - Spooler SubSystem App.) -- C:\Windows\System32\spoolsv.exe [317440] O44 - LFC:[MD5.53223B673A3FA2F9A4D1C31C8D3F6CD8] - 5/25/2015 - 1:38:22 AM ---A- . (.Microsoft Corporation - Windows Image Helper.) -- C:\Windows\System32\dbghelp.dll [854016] O44 - LFC:[MD5.1C3E8371377E988B683797A132EFFE1B] - 5/25/2015 - 1:38:22 AM ---A- . (.Microsoft Corporation - المكون الإضافي لجدولة مهام توافق الإصدارات.) -- C:\Windows\System32\taskcomp.dll [305152] O44 - LFC:[MD5.B47CD1B9551DA3DE9166D6DD17E6FD82] - 5/25/2015 - 1:38:22 AM ---A- . (.Microsoft Corporation - موفر تشفير البطاقة الذكية الأساسية لـ Micro.) -- C:\Windows\System32\basecsp.dll [144768] O44 - LFC:[MD5.A4EDDE0895B8595D5D1F4C9C40E7BB3A] - 5/25/2015 - 1:38:22 AM ---A- . (.Microsoft Corporation - ‎‎تطبيقات تسجيل الدخول إلى RemoteApp.) -- C:\Windows\System32\rdpinit.exe [161280] O44 - LFC:[MD5.60B7C0FEAD45F2066E5B805A91F4F0FC] - 5/25/2015 - 1:38:22 AM ---A- . (.Microsoft Corporation - ‎‎حاسبة Windows.) -- C:\Windows\System32\calc.exe [776192] O44 - LFC:[MD5.E9E01EB683C132F7FA27CD607B8A2B63] - 5/25/2015 - 1:38:23 AM ---A- . (.Microsoft Corporation - خدمة عميل DHCP.) -- C:\Windows\System32\dhcpcore.dll [254464] O44 - LFC:[MD5.971A36C4827AD1AE2A54E6407478921A] - 5/25/2015 - 1:38:23 AM ---A- . (.Microsoft Corporation - مكتبة نقاط الحماية المشتركة لـ Microsoft® W.) -- C:\Windows\System32\spp.dll [172544] O44 - LFC:[MD5.4F2659160AFCCA990305816946F69407] - 5/25/2015 - 1:38:23 AM ---A- . (.Microsoft Corporation - ‎‎مشغل خدمة جدولة المهام.) -- C:\Windows\System32\taskeng.exe [192000] O44 - LFC:[MD5.108C2CFA5527458C096A699929ECBD80] - 5/25/2015 - 1:38:24 AM ---A- . (.Microsoft Corporation - واجهة المستخدم الخاصة بإدارة بيانات الاعتما.) -- C:\Windows\System32\credui.dll [168960] O44 - LFC:[MD5.5992A9DF57FD5E6960FDCC2DB69867F7] - 5/25/2015 - 1:38:25 AM ---A- . (.Microsoft Corporation - API لنُسق Windows.) -- C:\Windows\System32\themeui.dll [2755072] O44 - LFC:[MD5.1869BD251211FB6275067372A45682D6] - 5/25/2015 - 1:38:25 AM ---A- . (.Microsoft Corporation - PRS CPL.) -- C:\Windows\System32\werconcpl.dll [1063936] O44 - LFC:[MD5.2F6C94BA73C976FAF939358D84E653E9] - 5/25/2015 - 1:38:25 AM ---A- . (.Microsoft Corporation - azroles Module.) -- C:\Windows\System32\azroles.dll [762880] O44 - LFC:[MD5.F68878CF6A7EA29EACEAD49A268FC447] - 5/25/2015 - 1:38:25 AM ---A- . (.Microsoft Corporation - ملحق الأداة الإضافية لتثبيت البرامج.) -- C:\Windows\System32\appmgr.dll [339968] O44 - LFC:[MD5.1E2BAC209D184BB851E1A187D8A29136] - 5/25/2015 - 1:38:26 AM ---A- . (.Microsoft Corporation - Base Filtering Engine.) -- C:\Windows\System32\BFE.DLL [494592] O44 - LFC:[MD5.71D5EBEFC617B84E1136F3F0E07A88F5] - 5/25/2015 - 1:38:26 AM ---A- . (.Microsoft Corporation - Media Foundation Direct Show wrapper DLL.) -- C:\Windows\System32\mfds.dll [296448] O44 - LFC:[MD5.B85B7368F6EC16CE2DF2A87E7EE20F0B] - 5/25/2015 - 1:38:26 AM ---A- . (.Microsoft Corporation - RDP Audio Endpoint.) -- C:\Windows\System32\rdpendp.dll [140800] O44 - LFC:[MD5.6ADA78F0E4BE07CF7C5500778DE8FB7D] - 5/25/2015 - 1:38:26 AM ---A- . (.Microsoft Corporation - WMI CMI Plugin.) -- C:\Windows\System32\wmicmiplugin.dll [351232] O44 - LFC:[MD5.D0481FB85BEEDD30A0884BE327880F80] - 5/25/2015 - 1:38:26 AM ---A- . (.Microsoft Corporation - WMI SDK Provider Framework.) -- C:\Windows\System32\framedynos.dll [206336] O44 - LFC:[MD5.E7C54812A2AAF43316EB6930C1FFA108] - 5/25/2015 - 1:38:26 AM ---A- . (.Microsoft Corporation - برنامج التشغيل NDIS 6.20.) -- C:\Windows\System32\Drivers\ndis.sys [712576] O44 - LFC:[MD5.F497F67932C6FA693D7DE2780631CFE7] - 5/25/2015 - 1:38:26 AM ---A- . (.Microsoft Corporation - برنامج تشغيل خدمة ملفات الظل الاحتياطية لوح.) -- C:\Windows\System32\Drivers\volsnap.sys [245632] O44 - LFC:[MD5.245F4691314F42D4D1BC06442F0B2086] - 5/25/2015 - 1:38:26 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخادم SAM.) -- C:\Windows\System32\samsrv.dll [551424] O44 - LFC:[MD5.15F93B37F6801943360D9EB42485D5D3] - 5/25/2015 - 1:38:26 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمة CSC.) -- C:\Windows\System32\cscsvc.dll [546304] O44 - LFC:[MD5.A8BB45F9ECAD993461E0FEF8E2A99152] - 5/25/2015 - 1:38:26 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لواجهة برمجة تطبي.) -- C:\Windows\System32\Wldap32.dll [269824] O44 - LFC:[MD5.59DF156711A76BCB993253EC6C9BBF41] - 5/25/2015 - 1:38:26 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لواجهة برمجة تطبي.) -- C:\Windows\System32\dnsapi.dll [270336] O44 - LFC:[MD5.12C45E3CB6D65F73209549E2D02ECA7A] - 5/25/2015 - 1:38:26 AM ---A- . (.Microsoft Corporation - نظام خصائص Microsoft.) -- C:\Windows\System32\propsys.dll [988160] O44 - LFC:[MD5.5505592313B74F2E2C8727837750F66D] - 5/25/2015 - 1:38:26 AM ---A- . (.Microsoft Corporation - ‎‎جهاز عرض قصاصات RDP.) -- C:\Windows\System32\rdpclip.exe [173568] O44 - LFC:[MD5.7660F01D3B38ACA1747E397D21D790AF] - 5/25/2015 - 1:38:27 AM ---A- . (.Microsoft Corporation - Distributed COM Services.) -- C:\Windows\System32\rpcss.dll [376832] O44 - LFC:[MD5.AD7B9C14083B52BC532FBA5948342B98] - 5/25/2015 - 1:38:27 AM ---A- . (.Microsoft Corporation - Windows Command Processor.) -- C:\Windows\System32\cmd.exe [302592] O44 - LFC:[MD5.3A11396EAC2414012155AB14E5C1E332] - 5/25/2015 - 1:38:29 AM ---A- . (.Microsoft Corporation - Software Protection Platform Windows Plugin.) -- C:\Windows\System32\sppwinob.dll [412160] O44 - LFC:[MD5.D1DE1EAFDE97BE41CF6585027FF3E732] - 5/25/2015 - 1:38:30 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لمربعات الحوار ال.) -- C:\Windows\System32\comdlg32.dll [485888] O44 - LFC:[MD5.ED04627EF998D04182C00ECD211FACBD] - 5/25/2015 - 1:38:31 AM ---A- . (.Microsoft Corporation - Driver Store API.) -- C:\Windows\System32\drvstore.dll [323072] O44 - LFC:[MD5.D15618A0FF8DBC2C5BF3726BACC75A0B] - 5/25/2015 - 1:38:31 AM ---A- . (.Microsoft Corporation - Userenv.) -- C:\Windows\System32\userenv.dll [81920] O44 - LFC:[MD5.9C8E9CAAF237E8CD8BEBDE700AAFF9E0] - 5/25/2015 - 1:38:31 AM ---A- . (.Microsoft Corporation - Xps Object Model in memory creation and des.) -- C:\Windows\System32\xpsservices.dll [1712640] O44 - LFC:[MD5.5232D090B7540F90E9BF6DDC2EBB5CA2] - 5/25/2015 - 1:38:32 AM ---A- . (.Microsoft Corporation - Resource cache builder tool.) -- C:\Windows\System32\mcbuilder.exe [220672] O44 - LFC:[MD5.421D9645B72CD341ECDBB0FCE06C97DE] - 5/25/2015 - 1:38:32 AM ---A- . (.Microsoft Corporation - Software Protection Platform Plugins.) -- C:\Windows\System32\sppobjs.dll [974336] O44 - LFC:[MD5.34BEF0783E17E760BE6DBEFB888A94B8] - 5/25/2015 - 1:38:32 AM ---A- . (.Microsoft Corporation - الأداة الإضافية 'الشهادات'.) -- C:\Windows\System32\certmgr.dll [1555456] O44 - LFC:[MD5.4AE380F39A0032EAB7DD953030B26D28] - 5/25/2015 - 1:38:32 AM ---A- . (.Microsoft Corporation - خدمة تكوين سطح المكتب البعيد.) -- C:\Windows\System32\SessEnv.dll [113664] O44 - LFC:[MD5.8CC3C111D653E96F3EA1590891491D71] - 5/25/2015 - 1:38:32 AM ---A- . (.Microsoft Corporation - مكتبة الأدوات المساعدة الخفيفة لـ Shell.) -- C:\Windows\System32\shlwapi.dll [350208] O44 - LFC:[MD5.E98278865E8DABA21CFE5FE4BE34210A] - 5/25/2015 - 1:38:32 AM ---A- . (.Microsoft Corporation - مكونات API للجهاز المحمول لـ Windows.) -- C:\Windows\System32\PortableDeviceApi.dll [547840] O44 - LFC:[MD5.C02F50BBC064689FE3FCD89348C884EB] - 5/25/2015 - 1:38:33 AM ---A- . (.Microsoft Corporation - Extensible Performance Counter Shim.) -- C:\Windows\System32\netfxperf.dll [49488] O44 - LFC:[MD5.7A82634C75F5CD12EFCF43897A2E28CE] - 5/25/2015 - 1:38:33 AM ---A- . (.Microsoft Corporation - Image Mastering File System Imaging API v2.) -- C:\Windows\System32\imapi2fs.dll [732160] O44 - LFC:[MD5.E5DD784A4EE5EBC72A86C677C988FCDB] - 5/25/2015 - 1:38:33 AM ---A- . (.Microsoft Corporation - Smb 2.0 Server driver.) -- C:\Windows\System32\Drivers\srv2.sys [309248] O44 - LFC:[MD5.3C2177A897B4CA2788C6FB0C3FD81D4B] - 5/25/2015 - 1:38:33 AM ---A- . (.Microsoft Corporation - Windows Client Side Caching Driver.) -- C:\Windows\System32\Drivers\csc.sys [388096] O44 - LFC:[MD5.653CF8E759C4B13C5507B70BD383F158] - 5/25/2015 - 1:38:33 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكية لإدارة العقد لـ.) -- C:\Windows\System32\mmcndmgr.dll [2151936] O44 - LFC:[MD5.8AEA9A37C1A3565A204D37C5E72AB791] - 5/25/2015 - 1:38:33 AM ---A- . (.Microsoft Corporation - ‎‎خدمة إدارة جلسات العمل المحلية.) -- C:\Windows\System32\lsm.exe [267776] O44 - LFC:[MD5.C9FB8C3D650EF8BD76865EC20A19A5BC] - 5/25/2015 - 1:38:34 AM ---A- . (.Microsoft - عامل تصفية جهاز عرض RDP (معيد التوجيه).) -- C:\Windows\System32\DShowRdpFilter.dll [252928] O44 - LFC:[MD5.954EA9B34F155C844B11F4047A8F6F89] - 5/25/2015 - 1:38:34 AM ---A- . (.Microsoft Corporation - UPnP نقطة تحكم ل API.) -- C:\Windows\System32\upnp.dll [206848] O44 - LFC:[MD5.AF2EEC9580C1D32FB7EAF105D9784061] - 5/25/2015 - 1:38:34 AM ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [117120] O44 - LFC:[MD5.63B282FB2550893724647A359BA2323F] - 5/25/2015 - 1:38:35 AM ---A- . (.Microsoft Corporation - Content Index Utility DLL.) -- C:\Windows\System32\Query.dll [1363456] O44 - LFC:[MD5.112127C3B2E64D7680CC39CD0A39DD7E] - 5/25/2015 - 1:38:35 AM ---A- . (.Microsoft Corporation - Server driver.) -- C:\Windows\System32\Drivers\srv.sys [311296] O44 - LFC:[MD5.1ECF8CD26AF7D9555C5B09CC2BDF51EF] - 5/25/2015 - 1:38:35 AM ---A- . (.Microsoft Corporation - عميل التفضيل لنهج المجموعة.) -- C:\Windows\System32\gpprefcl.dll [584192] O44 - LFC:[MD5.F1DD3ACAEE5E6B4BBC69BC6DF75CEF66] - 5/25/2015 - 1:38:36 AM ---A- . (.Microsoft Corporation - DLL لعميل Windows USER API متعدد المستخدمين.) -- C:\Windows\System32\user32.dll [811520] O44 - LFC:[MD5.1FF7E4F548C7C372C804938F0D5B36AE] - 5/25/2015 - 1:38:36 AM ---A- . (.Microsoft Corporation - كائنات تكوين الشبكة.) -- C:\Windows\System32\netcfgx.dll [406528] O44 - LFC:[MD5.209A3B1901B83AEB8527ED211CCE9E4C] - 5/25/2015 - 1:38:37 AM ---A- . (.Microsoft Corporation - Microsoft® Volume Shadow Copy Service.) -- C:\Windows\System32\VSSVC.exe [1025536] O44 - LFC:[MD5.8E8C92DD50F6B34907813AFDC0C8F7DD] - 5/25/2015 - 1:38:37 AM ---A- . (.Microsoft Corporation - Windows Symbolic Debugger Engine.) -- C:\Windows\System32\dbgeng.dll [2522624] O44 - LFC:[MD5.59D16C3D5CC0D573256A01783ED5CCB4] - 5/25/2015 - 1:38:37 AM ---A- . (.Microsoft Corporation - عنصر تحكم ActiveX للفيديو المتدفق.) -- C:\Windows\System32\MSVidCtl.dll [2291712] O44 - LFC:[MD5.C1809B9907ADEDAF16F50C894100883B] - 5/25/2015 - 1:38:37 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمات تسجيل الدخ.) -- C:\Windows\System32\netlogon.dll [563712] O44 - LFC:[MD5.BAF28D456E418DC1013F9F38E0EFE8F3] - 5/25/2015 - 1:38:37 AM ---A- . (.Microsoft Corporation - ‎‎RemoteApp Shell.) -- C:\Windows\System32\rdpshell.exe [260608] O44 - LFC:[MD5.04B88428A872390D235BE52D38A9D4EF] - 5/25/2015 - 1:38:38 AM ---A- . (.Microsoft Corporation - 802.3 Autoconfiguration API.) -- C:\Windows\System32\dot3api.dll [91136] O44 - LFC:[MD5.10FB16B50AFFDA6D44588F3C445DC273] - 5/25/2015 - 1:38:38 AM ---A- . (.Microsoft Corporation - API الخاص بإعداد Windows.) -- C:\Windows\System32\setupapi.dll [1667584] O44 - LFC:[MD5.886B0EAA3B0FE76B3204E687C8DA6F66] - 5/25/2015 - 1:38:38 AM ---A- . (.Microsoft Corporation - Windows System Assessment Tool.) -- C:\Windows\System32\WinSAT.exe [3367424] O44 - LFC:[MD5.8DCB990113DEF9255445B17D7F6DA64A] - 5/25/2015 - 1:38:38 AM ---A- . (.Microsoft Corporation - الأداة الإضافية RDP MF.) -- C:\Windows\System32\tsmf.dll [270848] O44 - LFC:[MD5.CA9F7888B524D8100B977C81F44C3234] - 5/25/2015 - 1:38:38 AM ---A- . (.Microsoft Corporation - خدمات Windows HTTP.) -- C:\Windows\System32\winhttp.dll [351232] O44 - LFC:[MD5.409994A8EACEEE4E328749C0353527A0] - 5/25/2015 - 1:38:38 AM ---A- . (.Microsoft Corporation - خدمة مُعيد توجيه جهاز خدمات سطح المكتب البع.) -- C:\Windows\System32\umrdp.dll [171008] O44 - LFC:[MD5.9283C58EBAA2618F93482EB5DABCEC82] - 5/25/2015 - 1:38:38 AM ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [143744] O44 - LFC:[MD5.23F5D28378A160352BA8F817BD8C71CB] - 5/25/2015 - 1:38:39 AM ---A- . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\Windows\System32\Drivers\dxgkrnl.sys [728448] O44 - LFC:[MD5.7D34AF98A706230CC2DEDFE0CABF87AB] - 5/25/2015 - 1:38:39 AM ---A- . (.Microsoft Corporation - ODBC Driver Manager.) -- C:\Windows\System32\odbc32.dll [573440] O44 - LFC:[MD5.ECF036299AA554B5E0455262857B39D0] - 5/25/2015 - 1:38:39 AM ---A- . (.Microsoft Corporation - تشخيص الأداء لـ Microsoft.) -- C:\Windows\System32\diagperf.dll [863744] O44 - LFC:[MD5.9835584E999D25004E1EE8E5F3E3B881] - 5/25/2015 - 1:38:39 AM ---A- . (.Microsoft Corporation - خدمة حماية Microsoft.) -- C:\Windows\System32\MPSSVC.dll [566272] O44 - LFC:[MD5.691E3285E53DCA558E1A84667F13E15A] - 5/25/2015 - 1:38:39 AM ---A- . (.Microsoft Corporation - ‎‎Microsoft® Block Level Backup Engine Serv.) -- C:\Windows\System32\wbengine.exe [1203200] O44 - LFC:[MD5.269D867585CDA04D3972A39F3694E7DF] - 5/25/2015 - 1:38:40 AM ---A- . (.Microsoft Corporation - MSXML 6.0 SP3.) -- C:\Windows\System32\msxml6.dll [1390080] O44 - LFC:[MD5.497E59D9F01C6F247E72222A61835119] - 5/25/2015 - 1:38:40 AM ---A- . (.Microsoft Corporation - Microsoft DWM Core Library.) -- C:\Windows\System32\dwmcore.dll [1371136] O44 - LFC:[MD5.23E9DCEE1D2BBA23EA5B50F76F633A0A] - 5/25/2015 - 1:38:40 AM ---A- . (.Microsoft Corporation - SP Installer.) -- C:\Windows\System32\spinstall.exe [456192] O44 - LFC:[MD5.D0804290B30C58652724344365C89D12] - 5/25/2015 - 1:38:40 AM ---A- . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\spreview.exe [280576] O44 - LFC:[MD5.E897EAF5ED6BA41E081060C9B447A673] - 5/25/2015 - 1:38:40 AM ---A- . (.Microsoft Corporation - عميل نهج المجموعة.) -- C:\Windows\System32\gpsvc.dll [593408] O44 - LFC:[MD5.6400774E903729ADD0A62A24A334EE56] - 5/25/2015 - 1:38:40 AM ---A- . (.Microsoft Corporation - وقت تشغيل استدعاء إجراء بعيد.) -- C:\Windows\System32\rpcrt4.dll [653312] O44 - LFC:[MD5.D683E64BB0D3AE0FDEB5BCC4EC04FACE] - 5/25/2015 - 1:38:41 AM ---A- . (.Microsoft Corporation - PushPrinterConnection application.) -- C:\Windows\System32\PushPrinterConnections.exe [51200] O44 - LFC:[MD5.6EF5F3F18413C367195F06E503AB86A6] - 5/25/2015 - 1:38:42 AM ---A- . (.Microsoft Corporation - Direct3D 9 Runtime.) -- C:\Windows\System32\d3d9.dll [1828352] O44 - LFC:[MD5.13337A3FB17F2242487FD45488ED0485] - 5/25/2015 - 1:38:42 AM ---A- . (.Microsoft Corporation - Microsoft® Volume Shadow Copy Requestor/Wri.) -- C:\Windows\System32\vssapi.dll [1128448] O44 - LFC:[MD5.544EFF88AC6C85DF5A4D6F18DFE08CFC] - 5/25/2015 - 1:38:42 AM ---A- . (.Microsoft Corporation - Task Scheduler COM API.) -- C:\Windows\System32\taskschd.dll [505856] O44 - LFC:[MD5.6581B52E133CC6D00661C58968C7E212] - 5/25/2015 - 1:38:42 AM ---A- . (.Microsoft Corporation - مجلد البحث.) -- C:\Windows\System32\SearchFolder.dll [646144] O44 - LFC:[MD5.40D777B7A95E00593EB1568C68514493] - 5/25/2015 - 1:38:42 AM ---A- . (.Microsoft Corporation - مستكشف Windows.) -- C:\Windows\explorer.exe [2616320] O44 - LFC:[MD5.928CF7268086631F54C3D8E17238C6DD] - 5/25/2015 - 1:38:43 AM ---A- . (.Microsoft Corporation - Microsoft OLE لـ Windows.) -- C:\Windows\System32\ole32.dll [1414144] O44 - LFC:[MD5.241E015DD809CFB23242F890B1FC575B] - 5/25/2015 - 1:38:43 AM ---A- . (.Microsoft Corporation - خدمة تسجيل الأحداث.) -- C:\Windows\System32\wevtsvc.dll [1086976] O44 - LFC:[MD5.E2A17BCC08D92F42E08AF6BA2F93ABA7] - 5/25/2015 - 1:38:44 AM ---A- . (.Microsoft Corporation - ExplorerFrame.) -- C:\Windows\System32\ExplorerFrame.dll [1493504] O44 - LFC:[MD5.B8CBB46B42570D373C9933FBDF25EBCE] - 5/25/2015 - 1:38:45 AM ---A- . (...) -- C:\Windows\System32\systemsf.ebd [146852] O44 - LFC:[MD5.8371F19E329B6CD650A6A9E9BF41EB2D] - 5/25/2015 - 1:38:45 AM ---A- . (.Microsoft Corporation - RDP Display Driver.) -- C:\Windows\System32\rdpdd.dll [213504] O44 - LFC:[MD5.E585445D5021971FAE10393F0F1C3961] - 5/25/2015 - 1:38:45 AM ---A- . (.Microsoft Corporation - خدمة النقل الذكي في الخلفية.) -- C:\Windows\System32\qmgr.dll [585728] O44 - LFC:[MD5.13A1F9A72F81509658F3E0B6AC2AD994] - 5/25/2015 - 1:38:46 AM ---A- . (.Microsoft Corporation - Microsoft.WindowsFirewall.SnapIn.) -- C:\Windows\System32\AuthFWSnapin.dll [5066752] O44 - LFC:[MD5.198366199A9F342EF87978D79308B49F] - 5/25/2015 - 1:38:46 AM ---A- . (.Microsoft Corporation - مشغل حساب قياسات تحليل ثبات النظام.) -- C:\Windows\System32\RacEngn.dll [1115136] O44 - LFC:[MD5.A04BB13F8A72F8B6E8B4071723E4E336] - 5/25/2015 - 1:38:47 AM ---A- . (.Microsoft Corporation - خدمة جدولة المهام.) -- C:\Windows\System32\schedsvc.dll [750592] O44 - LFC:[MD5.256503028879103E9741A276FA24D65D] - 5/25/2015 - 1:38:48 AM ---A- . (.Microsoft Corporation - Extensible Storage Engine for Microsoft(R).) -- C:\Windows\System32\esent.dll [1698816] O44 - LFC:[MD5.0C4E035C7F105F1299258C90886C64C5] - 5/25/2015 - 1:38:48 AM ---A- . (.Microsoft Corporation - Hardware Policy Driver.) -- C:\Windows\System32\Drivers\hwpolicy.sys [14208] O44 - LFC:[MD5.A2AEEAB451AD341070F9B8F8E1A2EC28] - 5/25/2015 - 1:38:48 AM ---A- . (.Microsoft Corporation - Windows Presentation Foundation Host Proxy.) -- C:\Windows\System32\PresentationHostProxy.dll [99176] O44 - LFC:[MD5.6A08F1C87BBF6197F5DAD95CF41E5175] - 5/25/2015 - 1:38:48 AM ---A- . (.Microsoft Corporation - مضيف Windows Presentation Foundation.) -- C:\Windows\System32\PresentationHost.exe [295264] O44 - LFC:[MD5.82FA3C4C5752C7F630FA39005B2FC8C8] - 5/25/2015 - 1:38:50 AM ---A- . (.Microsoft Corporation - Intel Microcode Update Library.) -- C:\Windows\System32\mcupdate_GenuineIntel.dll [520064] O44 - LFC:[MD5.29BC473072568C072EC8B176498DE996] - 5/25/2015 - 1:38:50 AM ---A- . (.Microsoft Corporation - عميل تسجيل خدمات شهادات Microsoft® Active D.) -- C:\Windows\System32\CertEnroll.dll [1334272] O44 - LFC:[MD5.D83947A58613E9091B4C9CC0F1546A8D] - 5/25/2015 - 1:38:51 AM ---A- . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll [297808] O44 - LFC:[MD5.283E4E276D023DC20E7C9F8DFB4A3204] - 5/25/2015 - 1:38:51 AM ---A- . (.Microsoft Corporation - واجهة المستخدم لمعالج ‎‎SPC.) -- C:\Windows\System32\spwizui.dll [253952] O44 - LFC:[MD5.36650D618CA34C9D357DFD3D89B2C56F] - 5/25/2015 - 1:38:55 AM ---A- . (.Microsoft Corporation - مضيف خدمة الإحضار المسبق.) -- C:\Windows\System32\sysmain.dll [1159168] O44 - LFC:[MD5.F8BD7CBFBFE95CFC8205707A05E0C666] - 5/25/2015 - 1:38:56 AM ---A- . (.Microsoft Corporation - RD Server Licensing Policy Module.) -- C:\Windows\System32\tssrvlic.dll [120320] O44 - LFC:[MD5.2A6C1373D88B6D5933383B9F5C034CB9] - 5/25/2015 - 1:38:56 AM ---A- . (.Microsoft Corporation - مكتبة MFCDLL مشتركة - إصدار التجزئة.) -- C:\Windows\System32\mfc40.dll [954752] O44 - LFC:[MD5.AB9EB3745B03AE67AB241A82338DEA7B] - 5/25/2015 - 1:38:56 AM ---A- . (.Microsoft Corporation - مكتبة MFCDLL مشتركة - إصدار التجزئة.) -- C:\Windows\System32\mfc40u.dll [954288] O44 - LFC:[MD5.A04C06A2142226D79DDA75920A496243] - 5/25/2015 - 1:38:56 AM ---A- . (.No owner - RemoteFX Helper.) -- C:\Windows\System32\RDVGHelper.exe [80896] O44 - LFC:[MD5.1EAEA5605AEB7F5EDA1AA73AE8DBB233] - 5/25/2015 - 1:38:59 AM ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Virtual Graphics S.) -- C:\Windows\System32\LSCSHostPolicy.dll [53760] O44 - LFC:[MD5.FD1D6C73E6333BE727CBCC6054247654] - 5/25/2015 - 1:38:59 AM ---A- . (.Microsoft Corporation - برنامج تشغيل عامل تصفية موزع USB الخاص بسطح.) -- C:\Windows\System32\Drivers\TsUsbFlt.sys [52224] O44 - LFC:[MD5.B78AF77C0F1627969DAB04E17870618C] - 5/25/2015 - 1:38:59 AM ---A- . (.Microsoft Corporation - ملحق GP لإعادة توجيه USB الخاص بسطح المكتب.) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll [11776] O44 - LFC:[MD5.C04E8D0509505AB8D8C5623E94458831] - 5/25/2015 - 2:40:32 AM ---A- . (.Microsoft Corporation - Microsoft Class Mini-driver.) -- C:\Windows\System32\msclmd.dll [152576] O44 - LFC:[MD5.C576D922C2C461CBA33CDBC5A876576D] - 5/26/2015 - 11:36:32 PM ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1984208] O44 - LFC:[MD5.9B6BBECA0A6F3382C0692A0AC0547E77] - 5/26/2015 - 11:36:32 PM ---A- . (...) -- C:\Windows\System32\perfc001.dat [78912] O44 - LFC:[MD5.1B4F5F25D22EDD15787CC927B96295D7] - 5/26/2015 - 11:36:32 PM ---A- . (...) -- C:\Windows\System32\perfc009.dat [106316] O44 - LFC:[MD5.EFB4EDF323B3B541042A57C696440F90] - 5/26/2015 - 11:36:32 PM ---A- . (...) -- C:\Windows\System32\perfc00C.dat [110720] O44 - LFC:[MD5.83DDF406DB41A91F5E2B2C738692893B] - 5/26/2015 - 11:36:32 PM ---A- . (...) -- C:\Windows\System32\perfh001.dat [442418] O44 - LFC:[MD5.D6E2464399982473F0032C77968AF285] - 5/26/2015 - 11:36:32 PM ---A- . (...) -- C:\Windows\System32\perfh009.dat [623940] O44 - LFC:[MD5.6AF80DA68BD88EAD4FA58558D9F6A440] - 5/26/2015 - 11:36:32 PM ---A- . (...) -- C:\Windows\System32\perfh00C.dat [647270] O44 - LFC:[MD5.86F34E7288DA428E38E2D8C7E806A871] - 5/26/2015 - 2:35:56 AM ---A- . (.Microsoft Corporation - RDP Core DLL.) -- C:\Windows\System32\rdpcore.dll [826880] O44 - LFC:[MD5.2C2C5AFE7EE4F620D69C23C0617651A8] - 5/26/2015 - 2:35:56 AM ---A- . (.Microsoft Corporation - TCP Transport Driver.) -- C:\Windows\System32\Drivers\tdtcp.sys [24576] O44 - LFC:[MD5.5D9A1A3E5824CECE65871C60E5A08A1A] - 5/26/2015 - 2:40:29 AM ---A- . (.Microsoft Corporation - WSMAN Automation.) -- C:\Windows\System32\WsmAuto.dll [145920] O44 - LFC:[MD5.B6AC69FFBAA159DD5CEED814245A286D] - 5/26/2015 - 2:40:29 AM ---A- . (.Microsoft Corporation - WSMAN WMI Provider.) -- C:\Windows\System32\WsmWmiPl.dll [214016] O44 - LFC:[MD5.B975C202F590BBC5AA63225FBD148791] - 5/26/2015 - 2:40:29 AM ---A- . (.Microsoft Corporation - WSMan HTTP Configuration File.) -- C:\Windows\System32\WSManHTTPConfig.exe [198656] O44 - LFC:[MD5.2C28FEC61C4AC68480A99CB7AA197FA9] - 5/26/2015 - 2:40:29 AM ---A- . (.Microsoft Corporation - WinRM Migration Plugin.) -- C:\Windows\System32\WSManMigrationPlugin.dll [248832] O44 - LFC:[MD5.1DE9BD23AFA36150586C732D876D9B74] - 5/26/2015 - 2:40:29 AM ---A- . (.Microsoft Corporation - خدمة WSMan.) -- C:\Windows\System32\WsmSvc.dll [1177088] O44 - LFC:[MD5.DA5B856A037872BE089CA6967C7050C5] - 5/26/2015 - 2:40:50 AM ---A- . (.Microsoft Corporation - MSXML 3.0 SP11.) -- C:\Windows\System32\msxml3.dll [1237504] O44 - LFC:[MD5.78492CF3C3697FB5AF4EAABB2BAF8595] - 5/26/2015 - 2:40:50 AM ---A- . (.Microsoft Corporation - XML Resources.) -- C:\Windows\System32\msxml3r.dll [2048] O44 - LFC:[MD5.EACFDF31921F51C097629F1F3C9129B4] - 5/26/2015 - 2:57:23 AM ---A- . (.Microsoft Corporation - خدمة معلومات التطبيقات.) -- C:\Windows\System32\appinfo.dll [47104] O44 - LFC:[MD5.FCFD4F50419B4BC72E80066DA10D2E54] - 5/26/2015 - 3:47:51 AM ---A- . (.Microsoft Corporation - Remote Desktop Session Host Server Remote C.) -- C:\Windows\System32\termsrv.dll [523776] O44 - LFC:[MD5.B3BC38B886CA53C92D52EF724A9F0D45] - 5/26/2015 - 3:48:21 AM ---A- . (.Microsoft Corporation - مشغل محرر تكوين أمان ‎‎Windows.) -- C:\Windows\System32\scesrv.dll [308224] O44 - LFC:[MD5.D3916F83AC8F2314262387A2E16C6578] - 5/26/2015 - 3:51:15 AM ---A- . (.Microsoft Corporation - Microsoft Windows Media Component Removal F.) -- C:\Windows\System32\dxmasf.dll [4096] O44 - LFC:[MD5.D3916F83AC8F2314262387A2E16C6578] - 5/26/2015 - 3:51:15 AM ---A- . (.Microsoft Corporation - Microsoft Windows Media Component Removal F.) -- C:\Windows\System32\msdxm.ocx [4096] O44 - LFC:[MD5.8B07DBA0D77346545C6359AC67DCB980] - 5/26/2015 - 3:51:15 AM ---A- . (.Microsoft Corporation - Windows Media Player System Preparation DLL.) -- C:\Windows\System32\spwmp.dll [8192] O44 - LFC:[MD5.2F3CE58D8C276570EEB69C99CFBAFD58] - 5/26/2015 - 3:51:15 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي الخاصة بأخطاء Med.) -- C:\Windows\System32\mferror.dll [2048] O44 - LFC:[MD5.F0C8038C9336EE6C3244CF431AB362BE] - 5/26/2015 - 3:51:15 AM ---A- . (.Microsoft Corporation - موارد الأحداث المساعدة لتوافق البرامج.) -- C:\Windows\System32\pcaevts.dll [8704] O44 - LFC:[MD5.7C1CADCA0E674212412559B0EAD0919A] - 5/26/2015 - 3:51:15 AM ---A- . (.Microsoft Corporation - ‎‎موارد Windows Media Player.) -- C:\Windows\System32\wmploc.DLL [12625408] O44 - LFC:[MD5.69B4CE000298A9253EB206C3AC1360F5] - 5/26/2015 - 3:51:16 AM ---A- . (.Microsoft Corporation - AppID Certificate Store Verification Task.) -- C:\Windows\System32\appidcertstorecheck.exe [16896] O44 - LFC:[MD5.81F97D8F8B3FB94A451CC6F7CF8B2965] - 5/26/2015 - 3:51:16 AM ---A- . (.Microsoft Corporation - AppID Driver.) -- C:\Windows\System32\Drivers\appid.sys [50176] O44 - LFC:[MD5.3245B3D9A1F36C8A80900003B22F9FA4] - 5/26/2015 - 3:51:16 AM ---A- . (.Microsoft Corporation - AppID Policy Converter Task.) -- C:\Windows\System32\appidpolicyconverter.exe [96768] O44 - LFC:[MD5.70E96EBE87A38857619671FCB9C8EC7B] - 5/26/2015 - 3:51:16 AM ---A- . (.Microsoft Corporation - DRM ActiveX Network Object.) -- C:\Windows\System32\msnetobj.dll [265216] O44 - LFC:[MD5.6C620B9DDB9EB0F0D92E9607D76B3D3D] - 5/26/2015 - 3:51:16 AM ---A- . (.Microsoft Corporation - MUI Callback for Bcd.) -- C:\Windows\System32\setbcdlocale.dll [50176] O44 - LFC:[MD5.49F4EE8DF752CFA159B99046CD1FDD2B] - 5/26/2015 - 3:51:16 AM ---A- . (.Microsoft Corporation - Media Foundation Protected Pipeline EXE.) -- C:\Windows\System32\mfpmp.exe [23040] O44 - LFC:[MD5.AF47EAA4ADDA9AA221FB7647EE22BF53] - 5/26/2015 - 3:51:16 AM ---A- . (.Microsoft Corporation - Media Foundation Proxy DLL.) -- C:\Windows\System32\mfps.dll [103424] O44 - LFC:[MD5.6B1EB62B8DD3F439F972BE14D7A34FC8] - 5/26/2015 - 3:51:16 AM ---A- . (.Microsoft Corporation - Mount Point Manger Sysprep Utility Library.) -- C:\Windows\System32\msmmsp.dll [10752] O44 - LFC:[MD5.C45E651DD6C0D7C1D92B338CE9331EF3] - 5/26/2015 - 3:51:16 AM ---A- . (.Microsoft Corporation - Program Compatibility Assistant Diagnostic.) -- C:\Windows\System32\pcadm.dll [28160] O44 - LFC:[MD5.10495B2681F3E271CB93608D853A0CF0] - 5/26/2015 - 3:51:16 AM ---A- . (.Microsoft Corporation - Program Compatibility Assistant Helper.) -- C:\Windows\System32\pcawrk.exe [9728] O44 - LFC:[MD5.08FF727297A97907AADED4BA86CF44E9] - 5/26/2015 - 3:51:16 AM ---A- . (.Microsoft Corporation - R&R installer.) -- C:\Windows\System32\rrinstaller.exe [50176] O44 - LFC:[MD5.F5090F8FA6757C58E17BAEAA86093636] - 5/26/2015 - 3:51:16 AM ---A- . (.Microsoft Corporation - خدمة هوية التطبيق.) -- C:\Windows\System32\appidsvc.dll [27648] O44 - LFC:[MD5.A6AEADE370FFE3F37554D8AAA3E4B873] - 5/26/2015 - 3:51:16 AM ---A- . (.Microsoft Corporation - ‎‎مساعد توافق البرامج.) -- C:\Windows\System32\pcalua.exe [8192] O44 - LFC:[MD5.E0AB9CA912398BE1AAD14FF7AD75C397] - 5/26/2015 - 3:51:17 AM ---A- . (.Microsoft Corporation - APIs Dll لهوية التطبيق.) -- C:\Windows\System32\appidapi.dll [50688] O44 - LFC:[MD5.CFE8B425822E478B530A590896ECF091] - 5/26/2015 - 3:51:17 AM ---A- . (.Microsoft Corporation - Windows Audio Device Graph Isolation.) -- C:\Windows\System32\audiodg.exe [100864] O44 - LFC:[MD5.320A8699369C43CF53B2DB4538D17C52] - 5/26/2015 - 3:51:17 AM ---A- . (.Microsoft Corporation - Windows Media Secure Content Provider.) -- C:\Windows\System32\msscp.dll [504320] O44 - LFC:[MD5.50B8937A81360D16A5C772302BD32CFE] - 5/26/2015 - 3:51:18 AM ---A- . (.Microsoft Corporation - جلسة عمل صوتية.) -- C:\Windows\System32\AudioSes.dll [195584] O44 - LFC:[MD5.2D21189858856316D55EAD55DF4964C2] - 5/26/2015 - 3:51:19 AM ---A- . (.Microsoft Corporation - Audio Engine.) -- C:\Windows\System32\AudioEng.dll [374784] O44 - LFC:[MD5.3BAA4BAE71460C5CEB40D5E9339A61BC] - 5/26/2015 - 3:51:19 AM ---A- . (.Microsoft Corporation - Crypto Network Related API.) -- C:\Windows\System32\cryptnet.dll [103936] O44 - LFC:[MD5.B54FD1991E659FD61EF1D34EC27AAECD] - 5/26/2015 - 3:51:19 AM ---A- . (.Microsoft Corporation - Cryptographic Service Provider API.) -- C:\Windows\System32\cryptsp.dll [81408] O44 - LFC:[MD5.3051724F223EA48968B19567DE2A81F4] - 5/26/2015 - 3:51:19 AM ---A- . (.Microsoft Corporation - Kernel Cryptography, Next Generation.) -- C:\Windows\System32\Drivers\cng.sys [370488] O44 - LFC:[MD5.6EBC44F464A00EF4E4F0DBBB6BD3FF14] - 5/26/2015 - 3:51:19 AM ---A- . (.Microsoft Corporation - Media Foundation Crash Dump Encryption DLL.) -- C:\Windows\System32\EncDump.dll [275968] O44 - LFC:[MD5.C5667EE72D7364BE81516C0707FEF724] - 5/26/2015 - 3:51:19 AM ---A- . (.Microsoft Corporation - Media Foundation Platform DLL.) -- C:\Windows\System32\mfplat.dll [354816] O44 - LFC:[MD5.644905A19D0F37F2233DFCE53BC4BC19] - 5/26/2015 - 3:51:19 AM ---A- . (.Microsoft Corporation - إدارة نقطة التحميل.) -- C:\Windows\System32\Drivers\mountmgr.sys [78784] O44 - LFC:[MD5.98C1191C862B44567FCF3C18BAEE859E] - 5/26/2015 - 3:51:19 AM ---A- . (.Microsoft Corporation - تشغيل أقراص DVD لـ DirectShow في وقت التشغي.) -- C:\Windows\System32\qdvd.dll [519680] O44 - LFC:[MD5.52954BE460EC6C54C0ACB2B3B126FFC6] - 5/26/2015 - 3:51:19 AM ---A- . (.Microsoft Corporation - خدمة مساعد توافق البرامج.) -- C:\Windows\System32\pcasvc.dll [157184] O44 - LFC:[MD5.B7D2BB84C590F0AE9DA51DBB065A780E] - 5/26/2015 - 3:51:19 AM ---A- . (.Microsoft Corporation - موفر واجهة مستخدم الثقة لـ Microsoft.) -- C:\Windows\System32\cryptui.dll [1005056] O44 - LFC:[MD5.2D4814D567E5A85C473228BA772A7AFB] - 5/26/2015 - 3:51:20 AM ---A- . (.Microsoft Corporation - DLL لجهاز تقديم الفيديو المحسّن.) -- C:\Windows\System32\evr.dll [489984] O44 - LFC:[MD5.18F1BBB37F1BC76332B5C1B5FA5ED310] - 5/26/2015 - 3:51:20 AM ---A- . (.Microsoft Corporation - Resume From Hibernate boot application.) -- C:\Windows\System32\winresume.exe [455752] O44 - LFC:[MD5.49474B3E37969AF4B5C076F42B623AFF] - 5/26/2015 - 3:51:20 AM ---A- . (.Microsoft Corporation - خدمات تشفيرية.) -- C:\Windows\System32\cryptsvc.dll [143872] O44 - LFC:[MD5.C1619A13B10CAC5038BF7129F57D8DE3] - 5/26/2015 - 3:51:20 AM ---A- . (.Microsoft Corporation - خدمة صوت Windows.) -- C:\Windows\System32\audiosrv.dll [475136] O44 - LFC:[MD5.96DB6A923DEDB58FC7CBBF5CFF73314D] - 5/26/2015 - 3:51:20 AM ---A- . (.Microsoft Corporation - وقت تشغيل DirectShow..) -- C:\Windows\System32\quartz.dll [1329664] O44 - LFC:[MD5.A56F4029FDCF4F817E78953CDA953E28] - 5/26/2015 - 3:51:21 AM ---A- . (.Microsoft Corporation - Audio Ks Endpoint.) -- C:\Windows\System32\AUDIOKSE.dll [442880] O44 - LFC:[MD5.D31FB78F37F075FA9605D7ED9B2070D2] - 5/26/2015 - 3:51:21 AM ---A- . (.Microsoft Corporation - Code Integrity Module.) -- C:\Windows\System32\ci.dll [409272] O44 - LFC:[MD5.74264B7F57A16D25CB581C07964D324A] - 5/26/2015 - 3:51:21 AM ---A- . (.Microsoft Corporation - Crypto API32.) -- C:\Windows\System32\crypt32.dll [1174528] O44 - LFC:[MD5.D5EC42139D6A6158CF188975C50B6A60] - 5/26/2015 - 3:51:21 AM ---A- . (.Microsoft Corporation - Microsoft Trust Verification APIs.) -- C:\Windows\System32\wintrust.dll [179200] O44 - LFC:[MD5.7DD3B3971D45197FA059C7CF55387BE8] - 5/26/2015 - 3:51:21 AM ---A- . (.Microsoft Corporation - OS Loader.) -- C:\Windows\System32\winload.exe [521384] O44 - LFC:[MD5.AEBC369F7DC72AB3F5B9BDF34FA0D43F] - 5/26/2015 - 3:51:21 AM ---A- . (.Microsoft Corporation - Protected Environment Authentication and Au.) -- C:\Windows\System32\Drivers\PEAuth.sys [593920] O44 - LFC:[MD5.BB73C907D1BD437B6C30F2C23BB089FC] - 5/26/2015 - 3:51:22 AM ---A- . (.Microsoft Corporation - DRM Migration DLL.) -- C:\Windows\System32\drmmgrtn.dll [406016] O44 - LFC:[MD5.B378B6A865C28CE5C1E23C35760A1199] - 5/26/2015 - 3:51:24 AM ---A- . (.Microsoft Corporation - Windows Media Player.) -- C:\Windows\System32\wmp.dll [11411968] O44 - LFC:[MD5.DCC148408770F2D55B201F8FC26438A1] - 5/26/2015 - 3:51:25 AM ---A- . (.Microsoft Corporation - DRMv2 Client DLL.) -- C:\Windows\System32\drmv2clt.dll [988160] O44 - LFC:[MD5.5B0C6247027FCF5A2E2F150E298D2FFA] - 5/26/2015 - 3:51:25 AM ---A- . (.Microsoft Corporation - Media Foundation DLL.) -- C:\Windows\System32\mf.dll [3209728] O44 - LFC:[MD5.833FCABCB5D95B1911BA6E62FC82AC04] - 5/26/2015 - 3:51:25 AM ---A- . (.Microsoft Corporation - Windows Media DRM SDK DLL.) -- C:\Windows\System32\wmdrmsdk.dll [617984] O44 - LFC:[MD5.003C51B9FE38287BA4E0E58D3AE080BD] - 5/26/2015 - 3:51:26 AM ---A- . (.Microsoft Corporation - BlackBox DLL.) -- C:\Windows\System32\blackbox.dll [744960] O44 - LFC:[MD5.EDF2DF71C4F1E13A6AC75F5224DE655A] - 5/26/2015 - 3:51:42 AM ---A- . (.Microsoft Corporation - Default Hub Driver for USB.) -- C:\Windows\System32\Drivers\usbhub.sys [258560] O44 - LFC:[MD5.D40855F89B69305140BBD7E9A3BA2DA6] - 5/26/2015 - 3:51:42 AM ---A- . (.Microsoft Corporation - EHCI eUSB Miniport Driver.) -- C:\Windows\System32\Drivers\usbehci.sys [43520] O44 - LFC:[MD5.9828C8D14CC2676421778F0DE638CF97] - 5/26/2015 - 3:51:42 AM ---A- . (.Microsoft Corporation - OHCI USB Miniport Driver.) -- C:\Windows\System32\Drivers\usbohci.sys [20480] O44 - LFC:[MD5.800AABFD625EEFF899F7E5496BDE37AB] - 5/26/2015 - 3:51:42 AM ---A- . (.Microsoft Corporation - UHCI USB Miniport Driver.) -- C:\Windows\System32\Drivers\usbuhci.sys [24064] O44 - LFC:[MD5.0803FBA9FE829D61AE26EC0BCC910C46] - 5/26/2015 - 3:51:42 AM ---A- . (.Microsoft Corporation - USB Common Class Generic Parent Driver.) -- C:\Windows\System32\Drivers\usbccgp.sys [76288] O44 - LFC:[MD5.74F805AB12EB0E3E49E469F19FF02640] - 5/26/2015 - 3:51:42 AM ---A- . (.Microsoft Corporation - Universal Serial Bus Driver.) -- C:\Windows\System32\Drivers\usbd.sys [6016] O44 - LFC:[MD5.EC2C5AF37B76D7B58C642CB74423DB7A] - 5/26/2015 - 3:51:42 AM ---A- . (.Microsoft Corporation - برنامج تشغيل منفذ USB 1.1 و 2.0.) -- C:\Windows\System32\Drivers\usbport.sys [284672] O44 - LFC:[MD5.03F899F521D2AAED1C55008F734DF252] - 5/26/2015 - 3:51:46 AM ---A- . (.Microsoft Corporation - Windows NT WebDav Minirdr.) -- C:\Windows\System32\Drivers\mrxdav.sys [116224] O44 - LFC:[MD5.933222B19FF3E7EA5F65517EA1F7D57E] - 5/26/2015 - 3:51:53 AM ---A- . (...) -- C:\Windows\System32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf [3] O44 - LFC:[MD5.48704647CD2E9DAA2EB81BDE6D029EDB] - 5/26/2015 - 3:51:53 AM ---A- . (.Microsoft Corporation - Kernel Mode Driver Framework Loader.) -- C:\Windows\System32\Drivers\WdfLdr.sys [47720] O44 - LFC:[MD5.2F0BC1FC6142DCB31C7D9804962A7011] - 5/26/2015 - 3:51:53 AM ---A- . (.Microsoft Corporation - Kernel Mode Driver Framework Resource.) -- C:\Windows\System32\Wdfres.dll [9728] O44 - LFC:[MD5.25944D2CC49E0A6C581D02A74B7D6645] - 5/26/2015 - 3:51:53 AM ---A- . (.Microsoft Corporation - Kernel Mode Driver Framework Runtime.) -- C:\Windows\System32\Drivers\Wdf01000.sys [527064] O44 - LFC:[MD5.A5F833506BF6A1B5D693E1499DEE2444] - 5/26/2015 - 3:51:56 AM ---A- . (.Microsoft Corporation - Uniscribe Unicode script processor.) -- C:\Windows\System32\usp10.dll [626688] O44 - LFC:[MD5.EC7BC28D207DA09E79B3E9FAF8B232CA] - 5/26/2015 - 3:52:02 AM ---A- . (.Microsoft Corporation - خدمة 'التوصيل والتشغيل' لوضع المستخدم.) -- C:\Windows\System32\umpnpmgr.dll [293376] O44 - LFC:[MD5.A6CD6B3F71E13E2E45B727FB8A47EA87] - 5/26/2015 - 3:52:11 AM ---A- . (.Microsoft Corporation - Microsoft Windows Search Filter Host.) -- C:\Windows\System32\SearchFilterHost.exe [86528] O44 - LFC:[MD5.2DC6285EC4F902BE08E7C5FA6D3FD017] - 5/26/2015 - 3:52:11 AM ---A- . (.Microsoft Corporation - msscntrs.dll.) -- C:\Windows\System32\msscntrs.dll [59392] O44 - LFC:[MD5.987323F0247D023AD1AE52195540ECE0] - 5/26/2015 - 3:52:11 AM ---A- . (.Microsoft Corporation - النظام الأساسي لـ MSSearch Vista.) -- C:\Windows\System32\mssvp.dll [666624] O44 - LFC:[MD5.5BDF8B0B9A3EADE3A2A6F2ED8D44E36D] - 5/26/2015 - 3:52:11 AM ---A- . (.Microsoft Corporation - موصل Outlook MSSearch.) -- C:\Windows\System32\mssphtb.dll [197120] O44 - LFC:[MD5.DB67C7C62038BDE813CB6486581A7611] - 5/26/2015 - 3:52:12 AM ---A- . (.Microsoft Corporation - Microsoft Search Protocol Handler.) -- C:\Windows\System32\mssph.dll [337408] O44 - LFC:[MD5.236F286E103FD44BD85FDD93097FD5DD] - 5/26/2015 - 3:52:12 AM ---A- . (.Microsoft Corporation - Microsoft Windows Search Indexer.) -- C:\Windows\System32\SearchIndexer.exe [427520] O44 - LFC:[MD5.E1AC89F6C5252057E6062843E36A6701] - 5/26/2015 - 3:52:12 AM ---A- . (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) -- C:\Windows\System32\SearchProtocolHost.exe [164352] O44 - LFC:[MD5.0241CB16136B9A4939CA0395768AE286] - 5/26/2015 - 3:52:12 AM ---A- . (.Microsoft Corporation - mssrch.dll.) -- C:\Windows\System32\mssrch.dll [1401344] O44 - LFC:[MD5.465DBF63A5049E4DB4BC5C12FFE781CB] - 5/26/2015 - 3:52:12 AM ---A- . (.Microsoft Corporation - tquery.dll.) -- C:\Windows\System32\tquery.dll [1549312] O44 - LFC:[MD5.03F3B770DFBED6131653CEDA8CA780F0] - 5/26/2015 - 3:52:20 AM ---A- . (.Microsoft Corporation - امتداد Shell الخاص بالمشاركة.) -- C:\Windows\System32\ntshrui.dll [442880] O44 - LFC:[MD5.813845D5C5D8325CA5E8B1F547016378] - 5/26/2015 - 3:52:34 AM ---A- . (.Microsoft Corporation - عوامل تصفية XDSCodec & Encypter/Decrypter.) -- C:\Windows\System32\EncDec.dll [534528] O44 - LFC:[MD5.9DC80A8AAAAAC397BDAB3C67165A824E] - 5/26/2015 - 3:52:44 AM ---A- . (.Microsoft Corporation - Windows NT CRT DLL.) -- C:\Windows\System32\msvcrt.dll [690688] O44 - LFC:[MD5.8E01332CC4B68BC6B5B7EFFE374442AA] - 5/26/2015 - 3:52:50 AM ---A- . (.Microsoft Corporation - Active Accessibility Core Component.) -- C:\Windows\System32\oleacc.dll [233472] O44 - LFC:[MD5.534BF06B2DEE965A1389A9312545AE03] - 5/26/2015 - 3:52:55 AM ---A- . (.Microsoft Corporation - ODBC Cursor Library.) -- C:\Windows\System32\odbccr32.dll [81920] O44 - LFC:[MD5.E2D83DAA6A229CFDAF129189A9245889] - 5/26/2015 - 3:52:55 AM ---A- . (.Microsoft Corporation - ODBC Cursor Library.) -- C:\Windows\System32\odbccu32.dll [86016] O44 - LFC:[MD5.EF37EDC20412A01DDD9A42E8D939A5A3] - 5/26/2015 - 3:52:55 AM ---A- . (.Microsoft Corporation - ODBC Driver Manager Trace.) -- C:\Windows\System32\odbctrac.dll [163840] O44 - LFC:[MD5.66ABBF38123D3113BB55EBAFCF37AB92] - 5/26/2015 - 3:52:55 AM ---A- . (.Microsoft Corporation - ODBC Installer.) -- C:\Windows\System32\odbccp32.dll [122880] O44 - LFC:[MD5.3FDB77D0BBEEB36AE35077ABC0BF80EC] - 5/26/2015 - 3:52:56 AM ---A- . (.Microsoft Corporation - Microsoft ODBC Desktop Driver Pack 3.5.) -- C:\Windows\System32\odbcjt32.dll [319488] O44 - LFC:[MD5.8F2DA3028D5FCBD1A060A3DE64CD6506] - 5/26/2015 - 3:53:40 AM ---A- . (.Microsoft Corporation - NT Lan Manager Datagram Receiver Driver.) -- C:\Windows\System32\Drivers\bowser.sys [69632] O44 - LFC:[MD5.C245EBD6B1A5FB6E6BBE2A635032490F] - 5/26/2015 - 3:53:43 AM ---A- . (.Microsoft Corporation - Microsoft Fax Cover Page Editor.) -- C:\Windows\System32\FXSCOVER.exe [191488] O44 - LFC:[MD5.DC6612A9EE015A36BA2A27BC9CC12537] - 5/26/2015 - 3:53:47 AM ---A- . (.Microsoft Corporation - مكتبة MFCDLL مشتركة - إصدار التجزئة.) -- C:\Windows\System32\mfc42.dll [1137664] O44 - LFC:[MD5.24CAEDCD73B5B0E22226283B7B2468C7] - 5/26/2015 - 3:53:47 AM ---A- . (.Microsoft Corporation - مكتبة MFCDLL مشتركة - إصدار التجزئة.) -- C:\Windows\System32\mfc42u.dll [1164288] O44 - LFC:[MD5.74AF6AA2E8B3180AADAE5FE8813CB1CD] - 5/26/2015 - 3:54:13 AM ---A- . (.Microsoft Corporation - Local Spooler DLL.) -- C:\Windows\System32\localspl.dll [769024] O44 - LFC:[MD5.92FB57D9D865019D26346EB13E15CD75] - 5/26/2015 - 3:54:28 AM ---A- . (.Microsoft Corporation - PTFilter & Encypter/Decrypter Tagger Filte.) -- C:\Windows\System32\CPFilters.dll [642048] O44 - LFC:[MD5.246560C5B7995489F25BF9175F2B6380] - 5/26/2015 - 3:54:28 AM ---A- . (.Microsoft Corporation - DirectShow MPEG-2 Splitter..) -- C:\Windows\System32\mpg2splt.ax [199680] O44 - LFC:[MD5.4D05D7A79E970398D8C687712E65A9B0] - 5/26/2015 - 3:54:28 AM ---A- . (.Microsoft Corporation - DirectShow Stream Buffer Filter..) -- C:\Windows\System32\sbe.dll [850944] O44 - LFC:[MD5.ED27D1D75BF5E683AD3EDD9E3123520A] - 5/26/2015 - 3:54:45 AM ---A- . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll [741376] O44 - LFC:[MD5.B81F204D146000BE76651A50670A5E9E] - 5/26/2015 - 3:54:49 AM ---A- . (.Microsoft Corporation - Longhorn SMB 2.0 Redirector.) -- C:\Windows\System32\Drivers\mrxsmb20.sys [96768] O44 - LFC:[MD5.6D17A4791ACA19328C685D256349FEFC] - 5/26/2015 - 3:54:49 AM ---A- . (.Microsoft Corporation - Longhorn SMB Downlevel SubRdr.) -- C:\Windows\System32\Drivers\mrxsmb10.sys [223744] O44 - LFC:[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - 5/26/2015 - 3:54:49 AM ---A- . (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\Drivers\mrxsmb.sys [123904] O44 - LFC:[MD5.4F8CCD3E7D9F17A7C60FA0AE2466CACF] - 5/26/2015 - 3:56:16 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لإعداد تقرير بالأ.) -- C:\Windows\System32\wer.dll [381440] O44 - LFC:[MD5.2A6BFDEDF2C57923E78F970BB15D7E7D] - 5/26/2015 - 3:56:46 AM ---A- . (.Microsoft Corporation - RD Gateway QEC.) -- C:\Windows\System32\tsgqec.dll [36864] O44 - LFC:[MD5.954AAF2028CD907B7F7ED40FFFD9D27F] - 5/26/2015 - 3:56:46 AM ---A- . (.Microsoft Corporation - RDP Extension DLL.) -- C:\Windows\System32\rdpwsx.dll [58880] O44 - LFC:[MD5.CD9214A6AE17D188D17C3CF8CB9CC693] - 5/26/2015 - 3:56:46 AM ---A- . (.Microsoft Corporation - RDP Terminal Stack Driver.) -- C:\Windows\System32\Drivers\rdpwd.sys [184320] O44 - LFC:[MD5.6C5139E4283249518F7743D7043775B3] - 5/26/2015 - 3:56:46 AM ---A- . (.Microsoft Corporation - TS Security Filter Driver.) -- C:\Windows\System32\Drivers\tssecsrv.sys [31232] O44 - LFC:[MD5.A5661C9330E5FCFCDD53EB03D5F04822] - 5/26/2015 - 3:56:47 AM ---A- . (.Microsoft Corporation - RDP Listeners Correction Tool.) -- C:\Windows\System32\rdrmemptylst.exe [8192] O44 - LFC:[MD5.B4203FC65D4C0D7A0B7A02AFD13472BB] - 5/26/2015 - 3:56:47 AM ---A- . (.Microsoft Corporation - TS (KM) RDPCore DLL.) -- C:\Windows\System32\rdpcorekmts.dll [130048] O44 - LFC:[MD5.FD67683FBA9B2C4BB551780BD8846F64] - 5/26/2015 - 3:56:47 AM ---A- . (.Microsoft Corporation - Winstation Library.) -- C:\Windows\System32\winsta.dll [157696] O44 - LFC:[MD5.52449FD429D6053B78AE564DEF303870] - 5/26/2015 - 3:56:47 AM ---A- . (.Microsoft Corporation - تطبيق تسجيل دخول Windows.) -- C:\Windows\System32\winlogon.exe [304128] O44 - LFC:[MD5.0DBD0B4D4766CADEB8C30242A0611395] - 5/26/2015 - 3:56:47 AM ---A- . (.Microsoft Corporation - ‎‎الاتصال بسطح المكتب البعيد.) -- C:\Windows\System32\mstsc.exe [1051136] O44 - LFC:[MD5.3F34A1B4C5F6475F320C275E63AFCE9B] - 5/26/2015 - 3:57:10 AM ---A- . (.Microsoft Corporation - Partition Management Driver.) -- C:\Windows\System32\Drivers\partmgr.sys [56176] O44 - LFC:[MD5.FB19FC5951A88F3C523E35C2C98D23C0] - 5/26/2015 - 3:57:13 AM ---A- . (.Microsoft Corporation - API الخاص ببروتوكولات النقل عبر ويب.) -- C:\Windows\System32\webio.dll [314880] O44 - LFC:[MD5.A8DDB7ACB122FC36FF0D7C9B3099A380] - 5/26/2015 - 3:57:30 AM ---A- . (.Microsoft Corporation - مكون اتصال سطح المكتب و RemoteApp.) -- C:\Windows\System32\TSWorkspace.dll [793600] O44 - LFC:[MD5.3B7C1A53047FF6ACEFD9BA6E281DEBB7] - 5/26/2015 - 3:57:54 AM ---A- . (.Microsoft Corporation - Microsoft CDO for Windows Library.) -- C:\Windows\System32\cdosys.dll [805376] O44 - LFC:[MD5.37C395C075E6FA66623C82DE50A8FAED] - 5/26/2015 - 3:58:04 AM ---A- . (.Microsoft Corporation - PPP EAP-TLS للوصول عن بُعد.) -- C:\Windows\System32\rastls.dll [372736] O44 - LFC:[MD5.F5142E9A99F44F9CC19A8AF31761F7F9] - 5/26/2015 - 3:58:15 AM ---A- . (.Microsoft Corporation - عميل ActiveX لخدمات سطح المكتب البعيد.) -- C:\Windows\System32\mstscax.dll [3221504] O44 - LFC:[MD5.B3AC14EA18DD0EE517703A86963AED18] - 5/26/2015 - 3:58:15 AM ---A- . (.Microsoft Corporation - عميل الوصول لأي موقع.) -- C:\Windows\System32\aaclient.dll [131584] O44 - LFC:[MD5.B9C54120F46392100478F58F374E5709] - 5/26/2015 - 3:58:34 AM ---A- . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\IKEEXT.DLL [679424] O44 - LFC:[MD5.CE2A48CD0D2B39FB77FA4797C6434E71] - 5/26/2015 - 3:58:34 AM ---A- . (.Microsoft Corporation - Windows Filtering Platform Netsh Helper.) -- C:\Windows\System32\nshwfp.dll [656896] O44 - LFC:[MD5.F0D0E883EBBDC7615DC9EDEA0FFB2817] - 5/26/2015 - 3:58:34 AM ---A- . (.Microsoft Corporation - واجهة برمجة التطبيقات (API) لوضع المستخدم ل.) -- C:\Windows\System32\FWPUCLNT.DLL [216576] O44 - LFC:[MD5.DDCE686D76C2B4DB435A3AF5BD0E691D] - 5/26/2015 - 3:58:38 AM ---A- . (.Microsoft Corporation - ATAPI Driver Extension.) -- C:\Windows\System32\Drivers\ataport.sys [133056] O44 - LFC:[MD5.306EB846F88E58C7E763946DE95952E3] - 5/26/2015 - 3:58:56 AM ---A- . (.Microsoft Corporation - Microsoft Remote Desktop Services Web Proxy.) -- C:\Windows\System32\TSWbPrxy.exe [46592] O44 - LFC:[MD5.280B8EA3F529A8A41AE3BF98B5272E1B] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - Audit Policy Program.) -- C:\Windows\System32\auditpol.exe [50176] O44 - LFC:[MD5.590AF89D7836C7C019A4410BC778063C] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll [17408] O44 - LFC:[MD5.A5B076011C853B4CAFD6296217A6E345] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecdd.sys [67512] O44 - LFC:[MD5.FD6A70D5D5B5BDF36AD265A232DAFB9A] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecpkg.sys [137656] O44 - LFC:[MD5.03A7667367CE73CA2C23371022E319E8] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - LSA SSPI RPC interface DLL.) -- C:\Windows\System32\sspisrv.dll [15872] O44 - LFC:[MD5.618BA9298726844DA4E9E53C7C8D4015] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - Local Security Authority Process.) -- C:\Windows\System32\lsass.exe [22528] O44 - LFC:[MD5.2F47A9303208E8812660A3396EE31477] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll [259584] O44 - LFC:[MD5.6954B10C2CF2D99E3F138FB9BDF32547] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll [172032] O44 - LFC:[MD5.D7DDFF16973763EDAA28C824E0EFDDF7] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - Security Support Provider Interface.) -- C:\Windows\System32\secur32.dll [22016] O44 - LFC:[MD5.D9CC31860C7A188EFB691E00C6DE123B] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - Security Support Provider Interface.) -- C:\Windows\System32\sspicli.dll [100352] O44 - LFC:[MD5.2665A3D34D1C62DF303723422215B001] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll [248832] O44 - LFC:[MD5.4279AF72FD8493586422C60BFCA08E07] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\TSpkg.dll [65536] O44 - LFC:[MD5.A8822401C68B6080FB0C82FD667CF956] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - أسماء تدقيق كائنات النظام.) -- C:\Windows\System32\msobjs.dll [60416] O44 - LFC:[MD5.D8D4D751AC82BF3DDB28452878267DA5] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - حزمة أمان Kerberos.) -- C:\Windows\System32\kerberos.dll [550912] O44 - LFC:[MD5.D0CA74BE380498A0111A73EB9C76CF8F] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - عميل خدمات شهادات Microsoft® Active Directo.) -- C:\Windows\System32\certcli.dll [342016] O44 - LFC:[MD5.986E8181921B351C7D395DCFA1767DDC] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لأحداث تدقيق الأم.) -- C:\Windows\System32\msaudite.dll [146432] O44 - LFC:[MD5.E6569C796B54DEA4E21231BA3211976B] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخادم LSA.) -- C:\Windows\System32\lsasrv.dll [1061376] O44 - LFC:[MD5.F91A59FB95541E209971CCBB7F3D6AE5] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لمخطط تدقيق الأما.) -- C:\Windows\System32\adtschema.dll [686080] O44 - LFC:[MD5.86E23CD282F2AE7A95CB8F48A70C3188] - 5/26/2015 - 3:59:14 AM ---A- . (.Microsoft Corporation - مكتبة تشفير Windows.) -- C:\Windows\System32\ncrypt.dll [221184] O44 - LFC:[MD5.0805487A6036A9F9C4E7AF7FEF835529] - 5/26/2015 - 3:59:25 AM ---A- . (.Microsoft Corporation - Windows Media Video Decoder.) -- C:\Windows\System32\WMVDECOD.DLL [1620992] O44 - LFC:[MD5.50C73E54062BA252350F3F29580E28DA] - 5/26/2015 - 3:59:40 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لمناطق الأوقات.) -- C:\Windows\System32\tzres.dll [2048] O44 - LFC:[MD5.23FC8068953C9BE2D63AE4EF1129112A] - 5/26/2015 - 4:00:21 AM ---A- . (.Microsoft Corporation - Net Event Handler.) -- C:\Windows\System32\netevent.dll [18944] O44 - LFC:[MD5.3EEBD3BD93DA46A26E89893C7AB2FF3B] - 5/26/2015 - 4:00:21 AM ---A- . (.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) -- C:\Windows\System32\Drivers\tcpipreg.sys [35328] O44 - LFC:[MD5.5078492B9CAC9CB721698DB51F039035] - 5/26/2015 - 4:00:21 AM ---A- . (.Microsoft Corporation - فئات مساعد تشخيص عمليات الشبكة الداخلية.) -- C:\Windows\System32\netcorehc.dll [175104] O44 - LFC:[MD5.58F67245D041FBE7AF88F4EAF79DF0FA] - 5/26/2015 - 4:00:22 AM ---A- . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [499712] O44 - LFC:[MD5.B53BBEB3A90030ADCD8FCEC26AB0E65B] - 5/26/2015 - 4:01:13 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll [3072] O44 - LFC:[MD5.2DE16A63F71D10B42ACE01E759078600] - 5/26/2015 - 4:01:14 AM ---A- . (.Microsoft Corporation - Console Window Host.) -- C:\Windows\System32\conhost.exe [271360] O44 - LFC:[MD5.51BB04243DF6196C06E125898127E397] - 5/26/2015 - 4:01:14 AM ---A- . (.Microsoft Corporation - DLL لخادم Windows متعدد المستخدمين.) -- C:\Windows\System32\winsrv.dll [169984] O44 - LFC:[MD5.1E65CF7B26D02750544EFDD73C8118FA] - 5/26/2015 - 4:01:14 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لعميل API الأساسي.) -- C:\Windows\System32\KernelBase.dll [293376] O44 - LFC:[MD5.F74FFA7654702F81884BDB41EB80DAC2] - 5/26/2015 - 4:01:14 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لعميل API الأساسي.) -- C:\Windows\System32\kernel32.dll [868352] O44 - LFC:[MD5.CFCD9EDB4B54653B767EBDF722BA8309] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll [3072] O44 - LFC:[MD5.4810BDB223ADBEF09C6A96153F7B9987] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll [3072] O44 - LFC:[MD5.05635E9F41C3ED112E48B06A039C0B3D] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll [3072] O44 - LFC:[MD5.CA9BF20C89804DDF90B77186E9C4053D] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll [3072] O44 - LFC:[MD5.6AB46CEEBD62287B3CAC9CABF35C0B31] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll [3072] O44 - LFC:[MD5.C1B384335B462D49D44A36EEF3D84458] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll [5120] O44 - LFC:[MD5.9BB5788E5403ADB0FBEC56C12FDF01F6] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll [3072] O44 - LFC:[MD5.E1364901E2DB1D50069B3C7D3167D788] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll [3584] O44 - LFC:[MD5.C204A714C587E5935D93818357C5F2F1] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll [3584] O44 - LFC:[MD5.AB19DC0B708CFDA06567B1428D5EBE16] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll [3072] O44 - LFC:[MD5.4D338A4961C16CE062725508A43392AD] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll [3584] O44 - LFC:[MD5.1F89EE12D56D833D0BF4B8070D213A27] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll [4096] O44 - LFC:[MD5.F8664C3B4A7365773312EAE6593E7525] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll [4096] O44 - LFC:[MD5.6F482E6BA305AB471D0BAF728BC75310] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll [3584] O44 - LFC:[MD5.541F08D2A39AFFBD938C76137407D286] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll [4096] O44 - LFC:[MD5.9CEBA869447B1E338631DB05493C21CE] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll [3584] O44 - LFC:[MD5.C74DF35F56CA85075060ED2A715D776A] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll [3584] O44 - LFC:[MD5.5EA6870FE09F75D92E26A2614A756659] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll [4608] O44 - LFC:[MD5.B28490AC5CAABF0BF796A49946300F67] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll [3072] O44 - LFC:[MD5.65E14C022A7E3A70C7FD2627EF75B4D6] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll [3072] O44 - LFC:[MD5.C7280F39F0E4ED5DDB97630B59C1A804] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll [3072] O44 - LFC:[MD5.E515B51CAA7CE378CA9419EE9B07CD2F] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll [4096] O44 - LFC:[MD5.232E3A49A5897AFDA0881F3D2A1AD98A] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll [4096] O44 - LFC:[MD5.46237F5C64CA4638024E341BE2AD1D19] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll [4608] O44 - LFC:[MD5.CCBA7F264A5259DF5F6915CBEFC453C9] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll [3072] O44 - LFC:[MD5.C3566123385C8FF53BFFE4D7413F6290] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll [3584] O44 - LFC:[MD5.FF41CF91302C9C12BC2ABD41989DDEB5] - 5/26/2015 - 4:01:14 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll [6144] O44 - LFC:[MD5.9EA3783672D21817B9DF1061B54C3B3C] - 5/26/2015 - 4:01:53 AM ---A- . (.Microsoft Corporation - ‎‎مخطط توزيع الأحرف.) -- C:\Windows\System32\charmap.exe [155136] O44 - LFC:[MD5.A208DAC2932649CFF82A6A684D8BB1F6] - 5/26/2015 - 4:01:56 AM ---A- . (.Microsoft Corporation - No Comment.) -- C:\Windows\System32\oleaut32.dll [571904] O44 - LFC:[MD5.5FB4F271032B6435F3B2252F577A4815] - 5/26/2015 - 4:03:04 AM ---A- . (.Microsoft Corporation - Crash Dump Disk Driver.) -- C:\Windows\System32\Drivers\Diskdump.sys [27072] O44 - LFC:[MD5.F1A449D762657230629D8BFC107ABC14] - 5/26/2015 - 4:03:04 AM ---A- . (.Microsoft Corporation - Microsoft Storage Port Driver.) -- C:\Windows\System32\Drivers\storport.sys [149440] O44 - LFC:[MD5.EB34CE31FABD4DC4343FD2AD16D2CAF9] - 5/26/2015 - 4:03:04 AM ---A- . (.Microsoft Corporation - Microsoft iSCSI Initiator Driver.) -- C:\Windows\System32\Drivers\msiscsi.sys [234432] O44 - LFC:[MD5.8229618C90801E957BADC332CE32A6C5] - 5/26/2015 - 4:03:04 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لتسجيل الإدخال/ال.) -- C:\Windows\System32\iologmsg.dll [2048] O44 - LFC:[MD5.83EE20D7160484C9172FDF0ACBDC8929] - 5/26/2015 - 4:03:22 AM ---A- . (.Microsoft Corporation - Microsoft RDP Video Miniport driver.) -- C:\Windows\System32\Drivers\rdpvideominiport.sys [15872] O44 - LFC:[MD5.B36B3488D81E64D6026E838B8F087BAC] - 5/26/2015 - 4:03:23 AM ---A- . (.Microsoft Corporation - TS RDPCore DLL.) -- C:\Windows\System32\rdpcorets.dll [919552] O44 - LFC:[MD5.81D2D712EBB8CBB73AECB85D8835A168] - 5/26/2015 - 4:03:23 AM ---A- . (.Microsoft Corporation - UMRDP Display Driver.) -- C:\Windows\System32\rdpudd.dll [134656] O44 - LFC:[MD5.E2ED66FAF894F545EB083AC5F5763854] - 5/26/2015 - 4:03:34 AM ---A- . (.Microsoft Corporation - تنظيف حزمة التحديث.) -- C:\Windows\System32\scavengeui.dll [434688] O44 - LFC:[MD5.33A60554882FDF59CDA3E1806370BBA1] - 5/26/2015 - 4:03:38 AM ---A- . (.Microsoft Corporation - Common Log File System Driver.) -- C:\Windows\System32\clfs.sys [249784] O44 - LFC:[MD5.D824C1C235349B67E652A5CA70D1AA49] - 5/26/2015 - 4:03:38 AM ---A- . (.Microsoft Corporation - Common Log Marshalling Win32 DLL.) -- C:\Windows\System32\clfsw32.dll [58880] O44 - LFC:[MD5.55273844B66D77A2F1A2213C17A9EA4A] - 5/26/2015 - 4:05:09 AM ---A- . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\System32\atmlib.dll [34304] O44 - LFC:[MD5.965D6A2B30A95A9F7EF13653988D3D9F] - 5/26/2015 - 4:05:09 AM ---A- . (.Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver.) -- C:\Windows\System32\atmfd.dll [299008] O44 - LFC:[MD5.274F0540FD4C88FC845C94CA1569688A] - 5/26/2015 - 4:05:09 AM ---A- . (.Microsoft Corporation - DCI Manager.) -- C:\Windows\System32\dciman32.dll [10240] O44 - LFC:[MD5.ABB358777FDF4AF51B2FE26137D2B8D4] - 5/26/2015 - 4:05:09 AM ---A- . (.Microsoft Corporation - Font Subsetting DLL.) -- C:\Windows\System32\fontsub.dll [70656] O44 - LFC:[MD5.DD16C06B79DA2FBD422E87923C6C0C9D] - 5/26/2015 - 4:05:09 AM ---A- . (.Microsoft Corporation - Language Pack.) -- C:\Windows\System32\lpk.dll [26624] O44 - LFC:[MD5.B804EAA9E037580F96C22537C2ECB62A] - 5/26/2015 - 4:05:12 AM ---A- . (.Microsoft Corporation - DLL الخاصة بإدارة عمليات الخلفية الموحدة.) -- C:\Windows\System32\ubpm.dll [171520] O44 - LFC:[MD5.72035C97983745E742D71E9A8EF70BBB] - 5/26/2015 - 4:05:57 AM ---A- . (.Microsoft - PEGI Finland Ratings System.) -- C:\Windows\System32\pegi-fi.rs [20480] O44 - LFC:[MD5.7752619457598CF057C4CC02A0867029] - 5/26/2015 - 4:05:57 AM ---A- . (.Microsoft - نظام تصنيفات CERO.) -- C:\Windows\System32\cero.rs [55296] O44 - LFC:[MD5.DDD1C4AB9A9DAE6D4092C4C95E714650] - 5/26/2015 - 4:05:57 AM ---A- . (.Microsoft - نظام تصنيفات ESRB.) -- C:\Windows\System32\esrb.rs [51712] O44 - LFC:[MD5.CBC69A055EF410CBD65593E4808B6DB4] - 5/26/2015 - 4:05:57 AM ---A- . (.Microsoft - نظام تصنيفات OFLC.) -- C:\Windows\System32\oflc.rs [23552] O44 - LFC:[MD5.6EC618588447B82EA8D88719EE46F725] - 5/26/2015 - 4:05:58 AM ---A- . (.Microsoft - CSRR Ratings System.) -- C:\Windows\System32\csrr.rs [43520] O44 - LFC:[MD5.4F5C56DBF076D5BBB1D22B37BF281396] - 5/26/2015 - 4:05:58 AM ---A- . (.Microsoft - PEGI Portugal Ratings System.) -- C:\Windows\System32\pegi-pt.rs [20480] O44 - LFC:[MD5.41CE7975CAD7BCF92538D2C452239523] - 5/26/2015 - 4:05:58 AM ---A- . (.Microsoft - نظام تصنيفات COB-AU.) -- C:\Windows\System32\cob-au.rs [40960] O44 - LFC:[MD5.27828AAA24AA46F11036954ADE355C1C] - 5/26/2015 - 4:05:58 AM ---A- . (.Microsoft - نظام تصنيفات DJCTQ.) -- C:\Windows\System32\djctq.rs [15360] O44 - LFC:[MD5.A704E750245D5D4EE4A23E99A00F27D5] - 5/26/2015 - 4:05:58 AM ---A- . (.Microsoft - نظام تصنيفات FPB.) -- C:\Windows\System32\fpb.rs [46592] O44 - LFC:[MD5.A067A19A91C2AA0198F9BD01A5CEF5C6] - 5/26/2015 - 4:05:58 AM ---A- . (.Microsoft - نظام تصنيفات GRB.) -- C:\Windows\System32\grb.rs [21504] O44 - LFC:[MD5.ED59143843560B5EDB543C2A48CB9E4B] - 5/26/2015 - 4:05:58 AM ---A- . (.Microsoft - نظام تصنيفات OFLC-NZ.) -- C:\Windows\System32\oflc-nz.rs [45568] O44 - LFC:[MD5.5109C45498BC709C8A7E016D5FFCCAC2] - 5/26/2015 - 4:05:58 AM ---A- . (.Microsoft - نظام تصنيفات PEGI.) -- C:\Windows\System32\pegi.rs [20480] O44 - LFC:[MD5.9B7D7F4D1F79E8B7D727BE94B1630D59] - 5/26/2015 - 4:05:58 AM ---A- . (.Microsoft - نظام تصنيفات PEGI/BBFC.) -- C:\Windows\System32\pegibbfc.rs [44544] O44 - LFC:[MD5.9EDCFA23CC081E38C86CA309D0F7E3DC] - 5/26/2015 - 4:05:58 AM ---A- . (.Microsoft - نظام تصنيفات USK.) -- C:\Windows\System32\usk.rs [30720] O44 - LFC:[MD5.64E211E0FDFCE4D186DF58BB7D0503BC] - 5/26/2015 - 4:05:58 AM ---A- . (.Microsoft Corporation - مستكشف الألعاب.) -- C:\Windows\System32\gameux.dll [2576384] O44 - LFC:[MD5.43C9CF6825CEA58F1815B7C3DBBB385C] - 5/26/2015 - 4:05:58 AM ---A- . (.Microsoft Corporation - مكتبة إعدادات WPC.) -- C:\Windows\System32\Wpc.dll [308736] O44 - LFC:[MD5.8580484193CE0A0788830FBAB97CF13B] - 5/26/2015 - 4:06:08 AM ---A- . (.Microsoft Corporation - ClickOnce Application Deployment Support Li.) -- C:\Windows\System32\dfshim.dll [1131664] O44 - LFC:[MD5.D5D5BBF6AA45D820BAA0BD1303B8AAF6] - 5/26/2015 - 4:06:08 AM ---A- . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll [81560] O44 - LFC:[MD5.A139A5E6B34F136405B030EA04595A20] - 5/26/2015 - 4:06:08 AM ---A- . (.Microsoft Corporation - موارد Microsoft .NET Runtime IE.) -- C:\Windows\System32\mscorier.dll [156824] O44 - LFC:[MD5.DEE7EDA5AAA96C4C68A1F098F5145799] - 5/26/2015 - 4:06:44 AM ---A- . (.Microsoft Corporation - FWP/IPsec Kernel-Mode API.) -- C:\Windows\System32\Drivers\FWPKCLNT.SYS [187840] O44 - LFC:[MD5.5DBD4F73E2A52FEED61DBAB3752E329C] - 5/26/2015 - 4:06:44 AM ---A- . (.Microsoft Corporation - Network I/O Subsystem.) -- C:\Windows\System32\Drivers\netio.sys [240576] O44 - LFC:[MD5.5579DD18546999F5D0EC39D018726C6B] - 5/26/2015 - 4:06:44 AM ---A- . (.Microsoft Corporation - ‏‏برنامج تشغيل TCP/IP.) -- C:\Windows\System32\Drivers\tcpip.sys [1294272] O44 - LFC:[MD5.492FF9C530EC0352B3C904CE9898269D] - 5/26/2015 - 4:06:46 AM ---A- . (.Microsoft Corporation - تحرير DirectShow..) -- C:\Windows\System32\qedit.dll [509440] O44 - LFC:[MD5.9DA1CCDBBF8136AC2383C2624CA8CD14] - 5/26/2015 - 4:07:00 AM ---A- . (.Microsoft Corporation - Windows® installer.) -- C:\Windows\System32\msihnd.dll [337408] O44 - LFC:[MD5.CADC4CFE957C24984FFA718AB7E4EF3C] - 5/26/2015 - 4:07:00 AM ---A- . (.Microsoft Corporation - ‎‎واجهة مستخدم الموافقة للتطبيقات الإدارية.) -- C:\Windows\System32\consent.exe [101824] O44 - LFC:[MD5.C212A43AA83A717AD38505F23ACDCB33] - 5/26/2015 - 4:07:01 AM ---A- . (.Microsoft Corporation - Windows Installer.) -- C:\Windows\System32\msi.dll [2363392] O44 - LFC:[MD5.43CD23B65CBF04D6F8ACA984B0EF93FE] - 5/26/2015 - 4:07:01 AM ---A- . (.Microsoft Corporation - واجهة المستخدم لمصادقة Windows.) -- C:\Windows\System32\authui.dll [1805824] O44 - LFC:[MD5.0780A42DBD7D9969F9BF4A19AA4285B5] - 5/26/2015 - 4:07:10 AM ---A- . (.Microsoft Corporation - Services and Controller app.) -- C:\Windows\System32\services.exe [259072] O44 - LFC:[MD5.9842041E2F5ACE1E2F5FB4EF02053DC8] - 5/26/2015 - 4:07:13 AM ---A- . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\Windows\System32\Drivers\drmk.sys [81408] O44 - LFC:[MD5.EB6137D696A9B4E9718AC6F8641CB4C9] - 5/26/2015 - 4:07:13 AM ---A- . (.Microsoft Corporation - Port Class (Class Driver for Port/Miniport.) -- C:\Windows\System32\Drivers\portcls.sys [177152] O44 - LFC:[MD5.C6A991D7DF17EBD8DE4739CD1F283133] - 5/26/2015 - 4:08:24 AM ---A- . (.Microsoft Corporation - ‎‎الوصول إلى لوحة المفاتيح على الشاشة.) -- C:\Windows\System32\osk.exe [646144] O44 - LFC:[MD5.2A58DBC1BADEA2F496099F8CB068E698] - 5/26/2015 - 4:08:25 AM ---A- . (.Microsoft Corporation - برنامج تشغيل Win32 متعدد المستخدمين.) -- C:\Windows\System32\win32k.sys [2350080] O44 - LFC:[MD5.84B460BB65567ED42DD605FA044DB370] - 5/26/2015 - 4:08:27 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخادم MSCTF.) -- C:\Windows\System32\msctf.dll [828928] O44 - LFC:[MD5.FC415B303B1ECF80B5F130A1F7203D02] - 5/26/2015 - 4:08:32 AM ---A- . (.Microsoft Corporation - موفر طباعة العرض الجانبي للعميل.) -- C:\Windows\System32\win32spl.dll [492544] O44 - LFC:[MD5.45FBAFFA68CBC29AC2563985CEE72B9C] - 5/26/2015 - 4:09:37 AM ---A- . (.Microsoft Corporation - مربعات حوار الشهادات العامة لـ Microsoft.) -- C:\Windows\System32\cryptdlg.dll [24576] O44 - LFC:[MD5.50E0DD0A5B8D8BC353578F2F73926697] - 5/26/2015 - 4:11:57 AM ---A- . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\System32\nlaapi.dll [52224] O44 - LFC:[MD5.F115C5CD29E512F18BD7138A094B77E5] - 5/26/2015 - 4:11:57 AM ---A- . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\System32\nlasvc.dll [242688] O44 - LFC:[MD5.140D9F911182357626165EA0BEB98C4F] - 5/26/2015 - 4:11:57 AM ---A- . (.Microsoft Corporation - مؤشر حالة اتصال الشبكة.) -- C:\Windows\System32\ncsi.dll [156672] O44 - LFC:[MD5.715C060150D969B0DE5DD5B365A712AF] - 5/26/2015 - 4:12:07 AM ---A- . (.Microsoft Corporation - Application Compatibility Database Installe.) -- C:\Windows\System32\sdbinst.exe [20992] O44 - LFC:[MD5.12E6A172D72AFC626727B8635DD17E39] - 5/26/2015 - 4:12:07 AM ---A- . (.Microsoft Corporation - Application Experience Service.) -- C:\Windows\System32\aelupsvc.dll [62464] O44 - LFC:[MD5.DCA2C6E7990771209CDD8E9DA90ED0E2] - 5/26/2015 - 4:12:07 AM ---A- . (.Microsoft Corporation - Shim Engine DLL.) -- C:\Windows\System32\shimeng.dll [5120] O44 - LFC:[MD5.D3E8C7FADB758E5D222C639CC65790AD] - 5/26/2015 - 4:12:07 AM ---A- . (.Microsoft Corporation - مكتبة عميل توافق التطبيقات.) -- C:\Windows\System32\apphelp.dll [295936] O44 - LFC:[MD5.FD9692A3D31E021207D3C2A9DDDC2BE3] - 5/26/2015 - 4:12:10 AM ---A- . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164864] O44 - LFC:[MD5.72910F1DEB838E6E08A9017BFB7D4F0B] - 5/26/2015 - 4:13:24 AM ---A- . (.Microsoft Corporation - Browser Service Client DLL.) -- C:\Windows\System32\browcli.dll [41984] O44 - LFC:[MD5.2FCA0D2C59A855C54BAFA22AA329DF0F] - 5/26/2015 - 4:13:24 AM ---A- . (.Microsoft Corporation - Net Win32 API DLL.) -- C:\Windows\System32\netapi32.dll [57344] O44 - LFC:[MD5.3DAA727B5B0A45039B0E1C9A211B8400] - 5/26/2015 - 4:13:24 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمة مستعرض الكم.) -- C:\Windows\System32\browser.dll [102912] O44 - LFC:[MD5.C557EB6CD735B4EE5076EA289B02CEAC] - 5/26/2015 - 4:14:07 AM ---A- . (.Microsoft Corporation - ApiSet Schema DLL.) -- C:\Windows\System32\apisetschema.dll [6656] O44 - LFC:[MD5.A169307F0105183092F2AEDA9A8BD15D] - 5/26/2015 - 4:14:07 AM ---A- . (.Microsoft Corporation - Microsoft® Windows System Restore Client Li.) -- C:\Windows\System32\srclient.dll [43008] O44 - LFC:[MD5.485436C2A90318218777401FB973558C] - 5/26/2015 - 4:14:07 AM ---A- . (.Microsoft Corporation - Windows Session Manager.) -- C:\Windows\System32\smss.exe [69632] O44 - LFC:[MD5.B68B44D003D3FF5E245F6B3761496082] - 5/26/2015 - 4:14:07 AM ---A- . (.Microsoft Corporation - عملية وقت التشغيل للخادم العميل.) -- C:\Windows\System32\csrsrv.dll [38912] O44 - LFC:[MD5.0C01746013943D7E7EE86B920ADFB50D] - 5/26/2015 - 4:14:07 AM ---A- . (.Microsoft Corporation - ‎‎Microsoft® Windows System Restore.) -- C:\Windows\System32\rstrui.exe [262656] O44 - LFC:[MD5.4611A40E1A94E6EBE9885EA609F3D13E] - 5/26/2015 - 4:14:08 AM ---A- . (.Microsoft Corporation - Microsoft® Windows System Restore Core Libr.) -- C:\Windows\System32\srcore.dll [400896] O44 - LFC:[MD5.2E5F8CB2EDB36F404D0111471D934B70] - 5/26/2015 - 4:14:08 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لطبقة NT.) -- C:\Windows\System32\ntdll.dll [1306112] O44 - LFC:[MD5.11896E75E1A118ABFAD126BEB650A189] - 5/26/2015 - 4:14:09 AM ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntoskrnl.exe [3920824] O44 - LFC:[MD5.A6A644BFAE31F111F35F8C3C7BA2A8A0] - 5/26/2015 - 4:14:10 AM ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntkrnlpa.exe [3976632] O44 - LFC:[MD5.124FD729FB2B621EB32E9B34B8D49A34] - 5/26/2015 - 4:16:17 AM ---A- . (.Microsoft Corporation - Windows Setup UI.) -- C:\Windows\System32\WinSetupUI.dll [50176] O44 - LFC:[MD5.7E5C454A3F986FEBAD075DB8D915917E] - 5/26/2015 - 4:16:17 AM ---A- . (.Microsoft Corporation - عامل Windows Update.) -- C:\Windows\System32\wuaueng.dll [2020864] O44 - LFC:[MD5.9D68CE45935C439D5082ECB56902124D] - 5/26/2015 - 4:16:17 AM ---A- . (.Microsoft Corporation - واجهة برمجة تطبيقات عميل Windows Update API.) -- C:\Windows\System32\wuapi.dll [566784] O44 - LFC:[MD5.751C4859FD46A1461B3FB57252F541D8] - 5/26/2015 - 4:16:18 AM ---A- . (.Microsoft Corporation - Windows Update Application Launcher.) -- C:\Windows\System32\wuapp.exe [33792] O44 - LFC:[MD5.031C03C9639CE0D294695968C68A5775] - 5/26/2015 - 4:16:18 AM ---A- . (.Microsoft Corporation - Windows Update Vista Web Control.) -- C:\Windows\System32\wuwebv.dll [173056] O44 - LFC:[MD5.E981C27FA6C2F45C135DB4AF78D6FE1F] - 5/26/2015 - 4:16:18 AM ---A- . (.Microsoft Corporation - Windows Update WUDriver Stub.) -- C:\Windows\System32\wudriver.dll [92672] O44 - LFC:[MD5.0430D8CE2C251BAD25CF809CEA3D2153] - 5/26/2015 - 4:16:18 AM ---A- . (.Microsoft Corporation - Windows Update client proxy stub 2.) -- C:\Windows\System32\wups2.dll [35328] O44 - LFC:[MD5.131BDD454DD1AA5BF732886DA6A3B0FA] - 5/26/2015 - 4:16:18 AM ---A- . (.Microsoft Corporation - Windows Update client proxy stub for intern.) -- C:\Windows\System32\wu.upgrade.ps.dll [11776] O44 - LFC:[MD5.C7E498E41D92CF8C2EAED9995781A7F7] - 5/26/2015 - 4:16:18 AM ---A- . (.Microsoft Corporation - Windows Update client proxy stub.) -- C:\Windows\System32\wups.dll [29696] O44 - LFC:[MD5.CFF96E0CE6F81F5968A6D61786642855] - 5/26/2015 - 4:16:18 AM ---A- . (.Microsoft Corporation - Windows Update.) -- C:\Windows\System32\wuauclt.exe [131584] O44 - LFC:[MD5.3096CA2455ECDEF83A90F2384BD305D3] - 5/26/2015 - 4:16:18 AM ---A- . (.Microsoft Corporation - خبرة مستخدم عميل Windows Update.) -- C:\Windows\System32\wucltux.dll [3088384] O44 - LFC:[MD5.2352AB5F9F8F097BF9D41D5A4718A041] - 5/26/2015 - 4:18:57 AM ---A- . (.Microsoft Corporation - USB Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\usbcir.sys [86016] O44 - LFC:[MD5.487569E5DA56A5A432FF8AF6D3599CF9] - 5/26/2015 - 4:19:00 AM ---A- . (.Microsoft Corporation - HTTP Protocol Stack.) -- C:\Windows\System32\Drivers\http.sys [514560] O44 - LFC:[MD5.C489D8B4D8C64F20CC75A93F541F7D91] - 5/26/2015 - 4:19:02 AM ---A- . (.Microsoft Corporation - Primitive Operations Queue Executor.) -- C:\Windows\System32\poqexec.exe [123904] O44 - LFC:[MD5.0F39AC3274312EFFD03928291E8BA7CA] - 5/26/2015 - 4:19:06 AM ---A- . (.Microsoft Corporation - Object Packager2.) -- C:\Windows\System32\packager.dll [67584] O44 - LFC:[MD5.58712A48D31B40EBCB35B47205F87771] - 5/26/2015 - 4:21:34 AM ---A- . (.Microsoft Corporation - Windows Rights Management Services Server S.) -- C:\Windows\System32\secproc_ssp.dll [87040] O44 - LFC:[MD5.9158DBE2F8483434FC72F320690C9DB8] - 5/26/2015 - 4:21:34 AM ---A- . (.Microsoft Corporation - Windows Rights Management Services Server S.) -- C:\Windows\System32\secproc_ssp_isv.dll [87040] O44 - LFC:[MD5.12A9F24DC9F465DA79AC2272D829A81E] - 5/26/2015 - 4:21:35 AM ---A- . (.Microsoft Corporation - Windows Rights Management Desktop Security.) -- C:\Windows\System32\secproc.dll [428032] O44 - LFC:[MD5.BBCE3E9E74C7CEA47FA4115B360AC2C6] - 5/26/2015 - 4:21:35 AM ---A- . (.Microsoft Corporation - Windows Rights Management Desktop Security.) -- C:\Windows\System32\secproc_isv.dll [423936] O44 - LFC:[MD5.08D323750350A8A29611D1004C0CF319] - 5/26/2015 - 4:21:35 AM ---A- . (.Microsoft Corporation - Windows Rights Management Services Activati.) -- C:\Windows\System32\RMActivate_ssp.exe [510976] O44 - LFC:[MD5.7FA485555BF802FE3DB5598004DBDFAC] - 5/26/2015 - 4:21:35 AM ---A- . (.Microsoft Corporation - عميل إدارة حقوق Windows.) -- C:\Windows\System32\msdrm.dll [390144] O44 - LFC:[MD5.6142C5540C8D2764D59CBC11AF4A5900] - 5/26/2015 - 4:21:36 AM ---A- . (.Microsoft Corporation - Windows Rights Management Services Activati.) -- C:\Windows\System32\RMActivate.exe [572416] O44 - LFC:[MD5.E01D2AC63453534DB8AD1EA97DEE9C3A] - 5/26/2015 - 4:21:36 AM ---A- . (.Microsoft Corporation - Windows Rights Management Services Activati.) -- C:\Windows\System32\RMActivate_isv.exe [594944] O44 - LFC:[MD5.0F5FEF37588AF457E02125674F171A4F] - 5/26/2015 - 4:21:36 AM ---A- . (.Microsoft Corporation - Windows Rights Management Services Activati.) -- C:\Windows\System32\RMActivate_ssp_isv.exe [508928] O44 - LFC:[MD5.2C4A87CA8C00E98EFDCFA2E8EC9A3503] - 5/26/2015 - 4:25:09 AM ---A- . (.Microsoft Corporation - كائن مستند Shell ومكتبة عناصر التحكم الخاصة.) -- C:\Windows\System32\shdocvw.dll [180224] O44 - LFC:[MD5.340EECB781E6C06A6171B3068DA208AD] - 5/26/2015 - 4:25:25 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لـ Windows Shell.) -- C:\Windows\System32\shell32.dll [12875264] O44 - LFC:[MD5.81F6C1AE23B1C493D9E996C3103915D7] - 5/26/2015 - 4:26:42 AM ---A- . (.Microsoft Corporation - DHCPv6 Client.) -- C:\Windows\System32\dhcpcsvc6.dll [44032] O44 - LFC:[MD5.EF71BA5DF59034962B0C62314A71351A] - 5/26/2015 - 4:26:42 AM ---A- . (.Microsoft Corporation - عميل DHCPv6.) -- C:\Windows\System32\dhcpcore6.dll [193536] O44 - LFC:[MD5.EAF4712B706936C0B10D3B5319B37E81] - 5/26/2015 - 4:26:45 AM ---A- . (.Microsoft Corporation - Web DAV Client DLL.) -- C:\Windows\System32\davclnt.dll [81920] O44 - LFC:[MD5.75E8EBD7040CE238684333F97014762A] - 5/26/2015 - 4:26:45 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمة Web DAV.) -- C:\Windows\System32\WebClnt.dll [205824] O44 - LFC:[MD5.DA8AAF7E56F698608A89542131F74818] - 5/26/2015 - 4:26:49 AM ---A- . (.Microsoft Corporation - WWAN Device Interface Module.) -- C:\Windows\System32\wwanprotdim.dll [40960] O44 - LFC:[MD5.7CC38741B8F68F1E0D5D79DA6123666A] - 5/26/2015 - 4:26:49 AM ---A- . (.Microsoft Corporation - خدمة التكوين التلقائي لـ WWAN.) -- C:\Windows\System32\wwansvc.dll [185344] O44 - LFC:[MD5.418AEC0CE89A13200F2820079B9CDFD9] - 5/26/2015 - 4:26:51 AM ---A- . (.Microsoft Corporation - Microsoft Tablet PC InkEdit Control.) -- C:\Windows\System32\InkEd.dll [216064] O44 - LFC:[MD5.955200436F29C751FEB30F139F0664B1] - 5/26/2015 - 4:26:51 AM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لمراقبة منفذ دفتر.) -- C:\Windows\System32\jnwmon.dll [19968] O44 - LFC:[MD5.D0B388DA1D111A34366E04EB4A5DD156] - 5/26/2015 - 4:26:59 AM ---A- . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\Drivers\afd.sys [338944] O44 - LFC:[MD5.1153AC6E133AA849853DFD407B086B80] - 5/26/2015 - 4:27:19 AM ---A- . (...) -- C:\Windows\System32\locale.nls [420064] O44 - LFC:[MD5.CC917AC4D3F8756FF13174980B474791] - 5/26/2015 - 4:27:37 AM ---A- . (.Microsoft Corporation - Active Directory Certificate Services Encod.) -- C:\Windows\System32\certenc.dll [43008] O44 - LFC:[MD5.0D52559AEF4AA5EAC82F530617032283] - 5/26/2015 - 4:27:37 AM ---A- . (.Microsoft Corporation - CertUtil.exe.) -- C:\Windows\System32\certutil.exe [903168] O44 - LFC:[MD5.D23E615E0969AECC1134E372B0B295D1] - 5/26/2015 - 4:27:50 AM ---A- . (.Microsoft Corporation - Windows Briefcase Engine.) -- C:\Windows\System32\synceng.dll [78336] O44 - LFC:[MD5.172D2960EF38795D2819A35268672F3D] - 5/26/2015 - 4:27:51 AM ---A- . (.Microsoft Corporation - GDI Client DLL.) -- C:\Windows\System32\gdi32.dll [305152] O44 - LFC:[MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - 5/26/2015 - 4:28:07 AM ---A- . (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\Drivers\ntfs.sys [1212352] O44 - LFC:[MD5.72E953215CADE1A726C04AAFDF6B463D] - 5/26/2015 - 7:56:09 PM ---A- . (.Microsoft Corporation - Host Process for Windows Tasks.) -- C:\Windows\System32\taskhost.exe [49152] O44 - LFC:[MD5.E94C583CDE2348950155F2AF2876F34D] - 5/26/2015 - 7:56:17 PM ---A- . (.Microsoft Corporation - Microsoft Windows Sockets 2.0 Service Provi.) -- C:\Windows\System32\mswsock.dll [231424] O44 - LFC:[MD5.401D25136E26B237D77DA1BF1198B3BD] - 5/26/2015 - 7:56:27 PM ---A- . (.Microsoft Corporation - مكتبة مساعد تعقب الأحداث.) -- C:\Windows\System32\tdh.dll [619520] O44 - LFC:[MD5.D67472125471784DE7147946EDA25FEB] - 5/26/2015 - 7:56:27 PM ---A- . (.Microsoft Corporation - واجهة برمجة تطبيقات أساسية متقدمة لـ Window.) -- C:\Windows\System32\advapi32.dll [640512] O44 - LFC:[MD5.2CBD6D22499EB13A2666F62EF33D00E2] - 5/26/2015 - 7:57:40 PM ---A- . (...) -- C:\Windows\System32\ieuinit.inf [16303] O44 - LFC:[MD5.F7B6E341F4B1947BEC0E14EEBE3C627E] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - ADVPACK.) -- C:\Windows\System32\IEAdvpack.dll [111616] O44 - LFC:[MD5.8C00AB01B1BC1E2F69765776BBC5A5D1] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - DAC for Trident DOM.) -- C:\Windows\System32\MshtmlDac.dll [64000] O44 - LFC:[MD5.AD27563BC16AB1EAACAE3033E99C2F78] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - ELS Hyphenation Service.) -- C:\Windows\System32\elshyph.dll [194048] O44 - LFC:[MD5.9025CA7BCD6B7956366FC90B3D6E3933] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - IE ETW Collector Proxy Stub Resources.) -- C:\Windows\System32\ieetwproxystub.dll [47616] O44 - LFC:[MD5.9EA5751205B65A11CC4C3F9FE353B5F3] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - IE ETW Collector Service Resources.) -- C:\Windows\System32\ieetwcollectorres.dll [4096] O44 - LFC:[MD5.FE8453CD0ABE1F1D42A545CCDEBEB044] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - IE ETW Collector Service.) -- C:\Windows\System32\ieetwcollector.exe [102912] O44 - LFC:[MD5.4BCC7EB5F20840DA67943BD86AE95735] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - IE PNG plugin image decoder.) -- C:\Windows\System32\pngfilt.dll [56832] O44 - LFC:[MD5.83F49FD1BC0A999B006D564C540C7258] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - IE Sysprep Provider.) -- C:\Windows\System32\iesysprep.dll [86016] O44 - LFC:[MD5.6EB0B7301E00F717BD68A742D1391FAF] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - IE plugin image decoder support DLL.) -- C:\Windows\System32\imgutil.dll [36352] O44 - LFC:[MD5.CFCE4EFF1D6D909EE2EA3AFCB8F1E677] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Internet Shortcut Shell Extension DLL.) -- C:\Windows\System32\url.dll [233472] O44 - LFC:[MD5.3CE5DE0730C22A54FE783DB8A989E8BD] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - JScript Proxy Auto-Configuration.) -- C:\Windows\System32\jsproxy.dll [47104] O44 - LFC:[MD5.746BBC86351D07859D8B40056447F7B2] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - JavaScript Performance Collection Agent.) -- C:\Windows\System32\JavaScriptCollectionAgent.dll [60416] O44 - LFC:[MD5.1C5C5B5EF9CFDFC897D4549A2385DB3A] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft (R) HTML Media DLL.) -- C:\Windows\System32\mshtmlmedia.dll [1155072] O44 - LFC:[MD5.55969AADF0210A614700F89B48976F68] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft Feeds Background Sync.) -- C:\Windows\System32\msfeedsbs.dll [43008] O44 - LFC:[MD5.C2EB0AA5570CF8BC881B36EE55A59337] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft Feeds Manager.) -- C:\Windows\System32\msfeeds.dll [688640] O44 - LFC:[MD5.53FC62C51CB18C9100A7DFAF2D2A6C47] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft Feeds Synchronization.) -- C:\Windows\System32\msfeedssync.exe [12800] O44 - LFC:[MD5.4F032F1FDEFEA5EC8EEA3562643B5EE8] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft Information Card IE Helper.) -- C:\Windows\System32\icardie.dll [69120] O44 - LFC:[MD5.298FDE634538B62CEEEC266D8773B21A] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft Line Services library file.) -- C:\Windows\System32\msls31.dll [182272] O44 - LFC:[MD5.C17139EAF939964142C7A1AEEE02DC81] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft SmartScreen Filter Data File.) -- C:\Windows\System32\ieapfltr.dat [616104] O44 - LFC:[MD5.63A2E3E9C771B1D4D7D84942D6FCB661] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft SmartScreen Filter.) -- C:\Windows\System32\ieapfltr.dll [710144] O44 - LFC:[MD5.C611C6ED5ECFE4608BA79472DFE3D49C] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft Spell Checking Facility.) -- C:\Windows\System32\MsSpellCheckingFacility.exe [646144] O44 - LFC:[MD5.CC4974FCF9387F32A0FF87BCE093A5AD] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft ® JScript Diagnostics.) -- C:\Windows\System32\jscript9diag.dll [620032] O44 - LFC:[MD5.F2DB87F164BC13AB8EF90FBF5D866B65] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft ® JScript.) -- C:\Windows\System32\jscript.dll [664576] O44 - LFC:[MD5.6E2B4875B968324E5844F35A37A79260] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft ® JScript.) -- C:\Windows\System32\jscript9.dll [4305920] O44 - LFC:[MD5.C1A32612710492D0C3339E46EC15E333] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft ® VBScript.) -- C:\Windows\System32\vbscript.dll [504320] O44 - LFC:[MD5.AE6A2C5ECD3E96556E22F12816842F60] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft® HTML Editing Component's Resourc.) -- C:\Windows\System32\mshtmler.dll [48640] O44 - LFC:[MD5.CFCB89C0FE8EF502A7934C0D20E5DBD6] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft® HTML Editing Component.) -- C:\Windows\System32\mshtmled.dll [76288] O44 - LFC:[MD5.AB3B2CA52AFB695AFCDD2620A21E5B21] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft® License Manager DLL.) -- C:\Windows\System32\licmgr10.dll [24576] O44 - LFC:[MD5.28313FF0DE83EAD8F5EF1B963D9078C3] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Microsoft® MSHTML Typelib.) -- C:\Windows\System32\mshtml.tlb [2724864] O44 - LFC:[MD5.C1A6E565B2782C09BC40AD749B46D9ED] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Registers custom PKEYs for IE.) -- C:\Windows\System32\RegisterIEPKEYs.exe [71680] O44 - LFC:[MD5.C525258A00ECFB4CE089F54C163268C3] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Run time utility for Internet Explorer.) -- C:\Windows\System32\iertutil.dll [2278400] O44 - LFC:[MD5.887055A3C8DD6C87D200D11EAFDBD45B] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Sets the date that IE was installed.) -- C:\Windows\System32\SetIEInstalledDate.exe [74240] O44 - LFC:[MD5.9E170B0AF156B478BD2B1FD6A2250C9E] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - TDC ActiveX Control.) -- C:\Windows\System32\tdc.ocx [62464] O44 - LFC:[MD5.9B8701A380CEE1B05D651B4ED4048C8F] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Windows Globalization.) -- C:\Windows\System32\jsIntl.dll [645120] O44 - LFC:[MD5.9A33FDDD687A836A1FD478B43C5A95FD] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - Wizard.) -- C:\Windows\System32\iexpress.exe [151552] O44 - LFC:[MD5.6388FC82897DDDA607BBE3580D75AE15] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - إدراج علامة تجارية لـ IEAK.) -- C:\Windows\System32\iedkcs32.dll [342736] O44 - LFC:[MD5.136687227F11CE928CB05F4FD90319AC] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - الإنترنت في لوحة التحكم.) -- C:\Windows\System32\inetcpl.cpl [2052608] O44 - LFC:[MD5.EC7038154490E50ACD405A022F51B204] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - تثبيت مشغل.) -- C:\Windows\System32\inseng.dll [83456] O44 - LFC:[MD5.03B3541AE6986602CF9CB5B3AD169C33] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - جهاز عرض موقع ويب.) -- C:\Windows\System32\webcheck.dll [208384] O44 - LFC:[MD5.D74445161E58644309F858342F5E265C] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - عارض Microsoft (R) HTML.) -- C:\Windows\System32\mshtml.dll [19691008] O44 - LFC:[MD5.1200D9C7DB0ADC1B8143A0A9921BF7DA] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - عارض عنصر تحكم الكائن.) -- C:\Windows\System32\occache.dll [127488] O44 - LFC:[MD5.1AFBAA54BDF637F69B8E02A5578286B0] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - كائنات النظير لـ Internet Explorer.) -- C:\Windows\System32\iepeers.dll [116736] O44 - LFC:[MD5.07E82A31808C8BC053D1DE547082C58F] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - محول Microsoft HTML.) -- C:\Windows\System32\html.iec [341504] O44 - LFC:[MD5.E993B5E929F46A52E9F4EB68A7855CDF] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - مخطط إصدار IOD.) -- C:\Windows\System32\iesetup.dll [62464] O44 - LFC:[MD5.0E22CD36FC3292CB812CC46CBCFD8444] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - مستعرض الإنترنت.) -- C:\Windows\System32\ieframe.dll [12828672] O44 - LFC:[MD5.BCFA71A878903B5F92A7AFEFCCC5CA97] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - مشغل واجهة مستخدم Internet Explorer.) -- C:\Windows\System32\ieui.dll [478208] O44 - LFC:[MD5.C3120D99E6DA7878A1DD2D88138AC60A] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - معالجة RunOnce الموسعة مع واجهة المستخدم.) -- C:\Windows\System32\iernonce.dll [30720] O44 - LFC:[MD5.37625FC1DAF886F1980E2D8F315B93AC] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لتصنيفات الإنترنت.) -- C:\Windows\System32\msrating.dll [168960] O44 - LFC:[MD5.AA2F2D55DEF98007839D0189D721D70B] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - ملحقات OLE32 لـ Win32.) -- C:\Windows\System32\urlmon.dll [1310208] O44 - LFC:[MD5.CB5F450D21B9D76B7F01D006E4AEDB40] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - ملحقات الإنترنت لـ Win32.) -- C:\Windows\System32\wininet.dll [1882112] O44 - LFC:[MD5.1BBC9CFD29A62D80FB77BB69BFF7513C] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - ‎‎أداة التثبيت المساعدة غير المراقبة لـ IE.) -- C:\Windows\System32\ieUnatt.exe [115712] O44 - LFC:[MD5.D5EFD1C5F5BB4F7D52D1F77FBBD2342E] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - ‎‎الأداة المساعدة للتهيئة لكل مستخدم لـ IE.) -- C:\Windows\System32\ie4uinit.exe [685568] O44 - LFC:[MD5.6A92CEC8532056791C6832B2725D170D] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - ‎‎الاستخراج الذاتي لملف خزانة Win32.) -- C:\Windows\System32\wextract.exe [139264] O44 - LFC:[MD5.ABDFC692D9FE43E2BA8FE6CB5A8CB95A] - 5/26/2015 - 7:57:40 PM ---A- . (.Microsoft Corporation - ‎‎مضيف تطبيق Microsoft (R) HTML.) -- C:\Windows\System32\mshta.exe [13312] O44 - LFC:[MD5.7DAE5EBCC80E45D3253F4923DC424D05] - 5/26/2015 - 8:31:14 PM ---A- . (.Microsoft Corporation - File System Recognizer Driver.) -- C:\Windows\System32\Drivers\fs_rec.sys [19824] O44 - LFC:[MD5.907281ED4AD35D41B29FFDC211EBAD80] - 5/26/2015 - 8:31:14 PM ---A- . (.Microsoft Corporation - WMI DC and DP functionality.) -- C:\Windows\System32\wmi.dll [5120] O44 - LFC:[MD5.B2DB6ABA2E292235749B80A9C3DFA867] - 5/26/2015 - 8:31:14 PM ---A- . (.Microsoft Corporation - Windows NT Image Helper.) -- C:\Windows\System32\imagehlp.dll [159232] O44 - LFC:[MD5.28A8B99DE70F376B18709E6B07D6A352] - 5/26/2015 - 8:32:05 PM ---A- . (.Microsoft Corporation - Windows Presentation Foundation Terminal Se.) -- C:\Windows\System32\TsWpfWrp.exe [35480] O44 - LFC:[MD5.8D466B36076BCD7997838C0DDB69764C] - 5/26/2015 - 8:32:08 PM ---A- . (.Microsoft Corporation - Windows CardSpace User Interface Agent.) -- C:\Windows\System32\icardagt.exe [619672] O44 - LFC:[MD5.370FC4421ADE62FC89AC93B345570388] - 5/26/2015 - 8:32:18 PM ---A- . (.Microsoft Corporation - ‎‎Windows CardSpace.) -- C:\Windows\System32\icardres.dll [8856] O44 - LFC:[MD5.AF6655214DEBB2C8446DE843A02AAEBA] - 5/26/2015 - 8:32:19 PM ---A- . (.Microsoft Corporation - Microsoft InfoCards.) -- C:\Windows\System32\infocardapi.dll [99480] O44 - LFC:[MD5.933222B19FF3E7EA5F65517EA1F7D57E] - 5/26/2015 - 8:33:43 PM ---A- . (...) -- C:\Windows\System32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf [3] O44 - LFC:[MD5.A36F7A256E65D858A7039DB00ADEEBDD] - 5/26/2015 - 8:33:43 PM ---A- . (.Microsoft Corporation - WDF:UMDF Framework Library.) -- C:\Windows\System32\WUDFx.dll [613888] O44 - LFC:[MD5.980B6A5F92B8DB235C4A26728C2BE732] - 5/26/2015 - 8:33:43 PM ---A- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\WUDFHost.exe [196608] O44 - LFC:[MD5.D689B2C2E69156D954C24810F4081C1E] - 5/26/2015 - 8:33:43 PM ---A- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Platf.) -- C:\Windows\System32\WUDFCoinstaller.dll [38912] O44 - LFC:[MD5.06E6F32C8D0A3F66D956F57B43A2E070] - 5/26/2015 - 8:33:44 PM ---A- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\Drivers\WUDFPf.sys [66560] O44 - LFC:[MD5.867C301E8B790040AE9CF6486E8041DF] - 5/26/2015 - 8:33:44 PM ---A- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\Drivers\WUDFRd.sys [155136] O44 - LFC:[MD5.FE47B7BC8EA320C2D9B5E5BF6E303765] - 5/26/2015 - 8:33:44 PM ---A- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\WUDFSvc.dll [73216] O44 - LFC:[MD5.D5CF1536137026ACDED95BF6CBF849F6] - 5/26/2015 - 8:33:44 PM ---A- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Platf.) -- C:\Windows\System32\WUDFPlatform.dll [172032] O44 - LFC:[MD5.6DE66FE7C526637E74CD066461C7C871] - 5/26/2015 - 9:12:38 AM ---A- . (.Microsoft Corporation - Direct3D 11 Runtime.) -- C:\Windows\System32\d3d11.dll [1505280] O44 - LFC:[MD5.B3170CCC779B682C3341873EA60CF084] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - Direct3D 10 Rasterizer.) -- C:\Windows\System32\d3d10warp.dll [1988096] O44 - LFC:[MD5.8504944851DF6175CC489A8F3328459E] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - Direct3D 10 Runtime.) -- C:\Windows\System32\d3d10.dll [1080832] O44 - LFC:[MD5.FB3F036EF6A467F7AF46C821FF5D198D] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - Direct3D 10 Runtime.) -- C:\Windows\System32\d3d10core.dll [220160] O44 - LFC:[MD5.4FF3EC04CD47DD62181894B71B004E40] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - Direct3D 10 to Direct3D9 Translation Runtim.) -- C:\Windows\System32\d3d10level9.dll [604160] O44 - LFC:[MD5.3C1936A12C62254F914A01BBC6A8DC69] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - Direct3D 10.1 Runtime.) -- C:\Windows\System32\d3d10_1.dll [161792] O44 - LFC:[MD5.D4212AB475A3B25EC4DF574536C3EDC5] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - Direct3D 10.1 Runtime.) -- C:\Windows\System32\d3d10_1core.dll [249856] O44 - LFC:[MD5.D4F264FE23F8953D840904418220C15E] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - DirectX Graphics Infrastructure.) -- C:\Windows\System32\dxgi.dll [293376] O44 - LFC:[MD5.9FF8F684BACF326082E5562F7C104A79] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - Microsoft D2D Library.) -- C:\Windows\System32\d2d1.dll [3419136] O44 - LFC:[MD5.600A65F922CCDCBB2D11467914241556] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - Microsoft DTV-DVD Video Decoder.) -- C:\Windows\System32\msmpeg2vdec.dll [2284544] O44 - LFC:[MD5.4277F5164DE9B7C665BB928B9145BEE0] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - Microsoft DirectX Typography Services.) -- C:\Windows\System32\DWrite.dll [1247744] O44 - LFC:[MD5.62A6EB5771580CAE445804389F3F7432] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - Microsoft Windows Codecs Extended Library.) -- C:\Windows\System32\WindowsCodecsExt.dll [207872] O44 - LFC:[MD5.3BCECD87AB4E6743BFB45B352AD1A529] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - Microsoft Windows Codecs Library.) -- C:\Windows\System32\WindowsCodecs.dll [1230336] O44 - LFC:[MD5.8B285BDAB7735FDFB18E6F7122923B77] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - Windows Animation Manager.) -- C:\Windows\System32\UIAnimation.dll [187392] O44 - LFC:[MD5.E12C4928B32ACE04610259647F072635] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - Windows Font Cache Service.) -- C:\Windows\System32\FntCache.dll [906240] O44 - LFC:[MD5.545F1BAAADD0BF1F4FE4586293FCA07D] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - Windows Media Photo Codec.) -- C:\Windows\System32\WMPhoto.dll [417792] O44 - LFC:[MD5.6A7B5A3EFCCDB53DA41CF6838056990F] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - XPS Printing DLL.) -- C:\Windows\System32\XpsPrint.dll [1158144] O44 - LFC:[MD5.C7A730AFB80B11F93EFC81B1D6F920D7] - 5/26/2015 - 9:15:52 AM ---A- . (.Microsoft Corporation - XPS to GDI Converter.) -- C:\Windows\System32\XpsGdiConverter.dll [364544] O44 - LFC:[MD5.6A13B4F3B3F575F1E24B877B9359AABA] - 5/26/2015 - 9:15:52 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll [10752] O44 - LFC:[MD5.49ACA548B2423F1C67898E6AC719A9A6] - 5/26/2015 - 9:15:52 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll [3584] O44 - LFC:[MD5.2E33DFD10F28F86C3FC40EE123CC3904] - 5/26/2015 - 9:15:52 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll [2560] O44 - LFC:[MD5.1C60E09CA1C3A045BC4D367F67C915B7] - 5/26/2015 - 9:15:52 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll [5632] O44 - LFC:[MD5.60F4AEFA103D421EA4A40E31409B4756] - 5/26/2015 - 9:15:52 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll [3072] O44 - LFC:[MD5.6951562DC4625EEFC6EACD52AD165866] - 5/26/2015 - 9:15:52 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll [9728] O44 - LFC:[MD5.007863E45F25AA47A4C30D0930BBFD85] - 5/26/2015 - 9:15:52 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll [5632] O44 - LFC:[MD5.589CBC4989F750E1DA35625AB481CF43] - 5/26/2015 - 9:15:52 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll [4096] O44 - LFC:[MD5.3BE0D923AA45A4DBE091C2D84F0B4FE7] - 5/26/2015 - 9:15:52 AM --HA- . (.Microsoft Corporation - ApiSet Stub DLL.) -- C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll [3072] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 5/29/2015 - 11:50:47 PM ---A- . (...) -- C:\Windows\setuperr.log [0] O44 - LFC:[MD5.CA3FEF90F81D29D7AC50C30EECB5934E] - 6/2/2015 - 5:17:08 PM ---A- . (...) -- C:\Windows\Provider20150603062629AM.dll [145408] O44 - LFC:[MD5.A9157AC353E7F4B2FE99D381E31EED41] - 6/2/2015 - 6:18:21 PM ---A- . (...) -- C:\Windows\PFRO.log [4356] O44 - LFC:[MD5.8F8759368A7884B4BE9415B6E60B4F08] - 6/3/2015 - 2:57:32 AM ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [269536] O44 - LFC:[MD5.3424A62C3946F5C5041D26692BC21381] - 6/3/2015 - 2:57:33 AM -S-A- . (...) -- C:\Windows\bootstat.dat [67584] O44 - LFC:[MD5.F35695256E326493AAF877F2EDF19514] - 6/3/2015 - 2:57:35 AM ---A- . (...) -- C:\Windows\setupact.log [616] O44 - LFC:[MD5.04B309A1A653177994630C2773E659F1] - 6/3/2015 - 2:58:22 AM ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [119512] O44 - LFC:[MD5.479735F6AE05D10E7BBC3209EE81EAB2] - 6/3/2015 - 3:00:47 AM ---A- . (...) -- C:\Windows\WindowsUpdate.log [1840249] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 6/3/2015 - 3:33:39 AM ---A- . (...) -- C:\Windows\System32\track [0] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 6/3/2015 - 3:52:25 AM ---A- . (...) -- C:\Windows\System32\Number of results [0] O44 - LFC:[MD5.1B48FC74A2B36F4A5DF1ECC6D94816B5] - 6/3/2015 - 4:02:49 AM ---A- . (...) -- C:\Windows\System32\errorlog.xml [89263] O44 - LFC:[MD5.43D9CF0C3E6769513DBADE0C41056353] - 6/3/2015 - 4:23:11 AM ---A- . (...) -- C:\END [8] O44 - LFC:[MD5.CA3FEF90F81D29D7AC50C30EECB5934E] - 6/3/2015 - 5:26:46 AM ---A- . (...) -- C:\Windows\Provider.dll [145408] ~ Files: 1144 Scanned in 13mn AMs ---\\ Local Security Authority-LSA Deny (O48) O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - مشغل عميل محرر تكوين أمان Windows.) -- C:\Windows\System32\scecli.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - حزمة أمان Kerberos.) -- C:\Windows\System32\kerberos.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll ~ LSA: 8 Scanned in 00mn AMs ---\\ Safe Boot Control (O49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - برنامج تشغيل عامل تصفية الماوس التسلسلي.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - برنامج تشغيل ملحق إدارة وحدة التخزين.) -- C:\Windows\System32\Drivers\volmgrx.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - برنامج تشغيل عامل تصفية الماوس التسلسلي.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - برنامج تشغيل ملحق إدارة وحدة التخزين.) -- C:\Windows\System32\Drivers\volmgrx.sys ~ CSB: 13 Scanned in 00mn AMs ---\\ MountPoints2 Shell Key (MPSK) (O51) O51 - MPSK:{6b0286ff-ffe9-11d5-a02e-806e6f6e6963}\AutoRun\command. (...) -- F:\setup.exe (.not file.) ~ Keys: Scanned in 00mn AMs ---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52) O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Cinepak® Codec.) -- C:\Windows\System32\iccvid.dll O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm ~ TDSD: 3 Scanned in 00mn AMs ---\\ Microsoft Control Security Providers (MCSP) (O54) O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll ~ MSCP: 2 Scanned in 00mn AMs ---\\ Microsoft Windows Policies System (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5 O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3 O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1 O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0 O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0 O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ MWPS: 16 Scanned in 00mn AMs ---\\ System Drivers List (SDL) (O58) O58 - SDL:7/14/2009 - 3:26:15 AM ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976] O58 - SDL:7/14/2009 - 3:26:17 AM ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [297552] O58 - SDL:7/14/2009 - 3:26:15 AM ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\Drivers\adpu320.sys [146512] O58 - SDL:7/14/2009 - 3:26:15 AM ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [14400] O58 - SDL:11/20/2010 - 2:29:13 PM ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [80256] O58 - SDL:7/14/2009 - 3:26:15 AM ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows fa.) -- C:\Windows\System32\Drivers\amdsbs.sys [159312] O58 - SDL:11/20/2010 - 2:29:15 PM ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [22400] O58 - SDL:7/14/2009 - 3:26:15 AM ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [76368] O58 - SDL:7/14/2009 - 3:26:15 AM ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [86608] O58 - SDL:8/13/2004 - 8:56:20 AM ---A- . (.No owner - ATK0110 ACPI Utility.) -- C:\Windows\System32\Drivers\ASACPI.sys [5810] O58 - SDL:7/14/2009 - 12:02:46 AM ---A- . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driver.) -- C:\Windows\System32\Drivers\athr.sys [1096704] O58 - SDL:7/14/2009 - 12:02:49 AM ---A- . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver..) -- C:\Windows\System32\Drivers\b57nd60x.sys [229888] O58 - SDL:7/14/2009 - 12:53:28 AM ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [13568] O58 - SDL:7/14/2009 - 12:53:28 AM ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [5248] O58 - SDL:7/14/2009 - 2:57:25 AM ---A- . (.Brother Industries Ltd. - برنامج تشغيل I/F التسلسلي لـ Brotehr (WDM)‎.) -- C:\Windows\System32\Drivers\BrSerId.sys [272128] O58 - SDL:7/14/2009 - 12:53:32 AM ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [62336] O58 - SDL:7/14/2009 - 12:53:33 AM ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [12160] O58 - SDL:7/14/2009 - 12:53:33 AM ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [11904] O58 - SDL:7/14/2009 - 12:02:48 AM ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbdx.sys [430080] O58 - SDL:7/14/2009 - 3:26:21 AM ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [15952] O58 - SDL:7/14/2009 - 3:20:28 AM ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\Drivers\djsvs.sys [70720] O58 - SDL:7/14/2009 - 3:20:28 AM ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712] O58 - SDL:7/14/2009 - 12:02:48 AM ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbdx.sys [3100160] O58 - SDL:7/14/2009 - 12:54:14 AM ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [26624] O58 - SDL:7/14/2009 - 3:20:28 AM ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [67152] O58 - SDL:11/20/2010 - 2:29:54 PM ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\Drivers\iaStorV.sys [332160] O58 - SDL:10/1/2014 - 6:19:10 AM ---A- . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\Drivers\idmwfp.sys [115240] O58 - SDL:7/14/2009 - 3:20:36 AM ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [41040] O58 - SDL:7/14/2009 - 12:02:47 AM ---A- . (.Atheros Communications, Inc. - Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20.) -- C:\Windows\System32\Drivers\L1E62x86.sys [47104] O58 - SDL:7/14/2009 - 3:20:36 AM ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [95824] O58 - SDL:7/14/2009 - 3:20:37 AM ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [89168] O58 - SDL:7/14/2009 - 3:20:36 AM ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [54864] O58 - SDL:7/14/2009 - 3:20:36 AM ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [96848] O58 - SDL:4/14/2015 - 8:37:42 AM ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [23256] O58 - SDL:4/14/2015 - 8:37:44 AM ---A- . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\Drivers\mbamchameleon.sys [92888] O58 - SDL:6/3/2015 - 2:58:22 AM ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\MBAMSwissArmy.sys [119512] O58 - SDL:7/14/2009 - 3:20:36 AM ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7 for x86.) -- C:\Windows\System32\Drivers\megasas.sys [30800] O58 - SDL:7/14/2009 - 3:20:36 AM ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [235584] O58 - SDL:4/14/2015 - 8:37:54 AM ---A- . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\Drivers\mwac.sys [51928] O58 - SDL:7/14/2009 - 3:20:44 AM ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [44624] O58 - SDL:6/10/2009 - 11:19:48 PM ---A- . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version 185.93.) -- C:\Windows\System32\Drivers\nvlddmkm.sys [9853248] O58 - SDL:11/20/2010 - 2:30:06 PM ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [117120] O58 - SDL:11/20/2010 - 2:30:06 PM ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [143744] O58 - SDL:7/14/2009 - 3:19:04 AM ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1383488] O58 - SDL:7/14/2009 - 3:19:04 AM ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [106064] O58 - SDL:7/13/2009 - 10:50:20 PM ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [20480] O58 - SDL:7/14/2009 - 3:19:04 AM ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [40016] O58 - SDL:7/14/2009 - 3:19:04 AM ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [77888] O58 - SDL:7/14/2009 - 3:19:04 AM ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [21072] O58 - SDL:7/14/2009 - 3:19:10 AM ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [16976] O58 - SDL:7/14/2009 - 3:19:11 AM ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [141904] O58 - SDL:7/13/2009 - 11:40:41 PM ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029] O58 - SDL:7/13/2009 - 11:40:44 PM ---A- . (...) -- C:\Windows\System32\country.sys [27097] O58 - SDL:7/13/2009 - 11:40:40 PM ---A- . (...) -- C:\Windows\System32\HIMEM.SYS [4768] O58 - SDL:7/13/2009 - 11:40:43 PM ---A- . (...) -- C:\Windows\System32\KEY01.SYS [42809] O58 - SDL:7/13/2009 - 11:40:43 PM ---A- . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537] O58 - SDL:7/13/2009 - 11:40:23 PM ---A- . (...) -- C:\Windows\System32\NTDOS.SYS [27866] O58 - SDL:7/13/2009 - 11:40:31 PM ---A- . (...) -- C:\Windows\System32\NTDOS404.SYS [29146] O58 - SDL:7/13/2009 - 11:40:35 PM ---A- . (...) -- C:\Windows\System32\NTDOS411.SYS [29370] O58 - SDL:7/13/2009 - 11:40:39 PM ---A- . (...) -- C:\Windows\System32\NTDOS412.SYS [29274] O58 - SDL:7/13/2009 - 11:40:27 PM ---A- . (...) -- C:\Windows\System32\NTDOS804.SYS [29146] O58 - SDL:7/13/2009 - 11:40:11 PM ---A- . (...) -- C:\Windows\System32\NTIO.SYS [33952] O58 - SDL:7/13/2009 - 11:40:15 PM ---A- . (...) -- C:\Windows\System32\NTIO404.SYS [34672] O58 - SDL:7/13/2009 - 11:40:17 PM ---A- . (...) -- C:\Windows\System32\NTIO411.SYS [35776] O58 - SDL:7/13/2009 - 11:40:19 PM ---A- . (...) -- C:\Windows\System32\NTIO412.SYS [35536] O58 - SDL:7/13/2009 - 11:40:13 PM ---A- . (...) -- C:\Windows\System32\NTIO804.SYS [34672] ~ Drivers: 66 Scanned in 04mn AMs ---\\ Last modified or created user files (O61) O61 - LFC: 5/28/2015 - 6:37:16 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Microsoft\Windows\1025\StructuredQuerySchema.bin [328875] O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\InstAct.exe [29976] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\Interop.IWshRuntimeLibrary.dll [49152] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\Interop.Shell32.dll [49152] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\Setup.dll [79872] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\Splash.exe [271128] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\Uninst000.CA.dll [1045293] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\Uninst000.dll [163328] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\ar\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\ar\Uninst000.resources.dll [7168] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\bs-Cyrl-BA\Splash.resources.dll [6144] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\bs-Cyrl-BA\Uninst000.resources.dll [7168] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\bs-Latn-BA\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\bs-Latn-BA\Uninst000.resources.dll [7168] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\da\Splash.resources.dll [5120] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\da\Uninst000.resources.dll [7168] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\de\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\de\Uninst000.resources.dll [7680] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\es\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\es\Uninst000.resources.dll [7680] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\fil-PH\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\fil-PH\Uninst000.resources.dll [7168] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\fr\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\fr\Uninst000.resources.dll [7680] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\he\Splash.resources.dll [5120] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\he\Uninst000.resources.dll [7168] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\hr-HR\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\hr-HR\Uninst000.resources.dll [7680] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\it\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\it\Uninst000.resources.dll [7168] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\ja\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\ja\Uninst000.resources.dll [7168] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\nl\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\nl\Uninst000.resources.dll [7680] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\no\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\no\Uninst000.resources.dll [7168] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\pt\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\pt\Uninst000.resources.dll [7168] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\ru\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\ru\Uninst000.resources.dll [8192] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\se-FI\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\se-FI\Uninst000.resources.dll [7680] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\sr-Cyrl-RS\Splash.resources.dll [6144] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\sr-Cyrl-RS\Uninst000.resources.dll [7168] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\sr-Latn-RS\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\sr-Latn-RS\Uninst000.resources.dll [7168] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\sv\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\sv\Uninst000.resources.dll [7680] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\th-TH\Splash.resources.dll [6144] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\th-TH\Uninst000.resources.dll [7168] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\tr-TR\Splash.resources.dll [5632] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\tr-TR\Uninst000.resources.dll [7168] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\ProPCCleaner.exe [5984536] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\ar\ProPCCleaner.resources.dll [70656] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\bs-Cyrl-BA\ProPCCleaner.resources.dll [74240] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\bs-Latn-BA\ProPCCleaner.resources.dll [65024] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\da\ProPCCleaner.resources.dll [64000] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\de\ProPCCleaner.resources.dll [66560] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\es\ProPCCleaner.resources.dll [66560] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\fil-PH\ProPCCleaner.resources.dll [66048] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\fr\ProPCCleaner.resources.dll [67072] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\he\ProPCCleaner.resources.dll [63488] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\hr-HR\ProPCCleaner.resources.dll [65024] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\it\ProPCCleaner.resources.dll [66048] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\ja\ProPCCleaner.resources.dll [69120] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\nl\ProPCCleaner.resources.dll [65024] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\no\ProPCCleaner.resources.dll [64512] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\pt\ProPCCleaner.resources.dll [65024] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\ru\ProPCCleaner.resources.dll [75776] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\se-FI\ProPCCleaner.resources.dll [65024] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\sr-Cyrl-RS\ProPCCleaner.resources.dll [74240] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\sr-Latn-RS\ProPCCleaner.resources.dll [64512] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\sv\ProPCCleaner.resources.dll [65024] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\th-TH\ProPCCleaner.resources.dll [84992] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\tr-TR\ProPCCleaner.resources.dll [65536] =>PUP.DoctorPC O61 - LFC: 5/29/2015 - 6:37:44 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Roaming\Rainmaker Software Group LLC\Pro PC Cleaner 2.7.1\install\3631B0A\updater.exe [407320] =>PUP.DoctorPC O61 - LFC: 5/30/2015 - 6:37:15 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Microsoft\Internet Explorer\UrlBlockManager\urlblocklist.bin [0] O61 - LFC: 5/30/2015 - 6:37:44 AM ---A- . (.Adobe Systems Inc.) -- C:\Users\libya\AppData\Roaming\Mozilla\Firefox\Profiles\his2fla6.default\gmp-eme-adobe\10\eme-adobe.dll [5915888] O61 - LFC: 5/31/2015 - 6:37:15 AM ---A- . (...) -- C:\Users\libya\AppData\Local\gmsd_gb_398\upgmsd_gb_398.exe [3318728] O61 - LFC: 6/1/2015 - 6:37:45 AM ---A- . (.Opera Software.) -- C:\Users\libya\Downloads\Programs\Opera_NI_stable.exe [684200] O61 - LFC: 6/2/2015 - 6:37:45 AM ---A- . (...) -- C:\Users\libya\Downloads\Programs\Firefox Setup Stub 38.0.1.exe [243544] O61 - LFC: 6/3/2015 - 6:37:37 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\6988.exe [1957976] O61 - LFC: 6/3/2015 - 6:37:37 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\bitool.dll [59904] O61 - LFC: 6/3/2015 - 6:37:37 AM ---A- . (.Conduit.) -- C:\Users\libya\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\Extracted\adv_35.exe [66368] O61 - LFC: 6/3/2015 - 6:37:37 AM ---A- . (.SoftBrain Technologies Ltd..) -- C:\Users\libya\AppData\Local\SmartWeb\__u.exe [172673] =>PUP.SmartWeb O61 - LFC: 6/3/2015 - 6:37:37 AM ---A- . (.globalUpdate.) -- C:\Users\libya\AppData\Local\Temp\comh.177218\globalupdate.exe [68608] =>PUP.GlobalUpdate O61 - LFC: 6/3/2015 - 6:37:37 AM ---A- . (.globalUpdate.) -- C:\Users\libya\AppData\Local\Temp\comh.177218\globalupdateBroker.exe [46080] =>PUP.GlobalUpdate O61 - LFC: 6/3/2015 - 6:37:37 AM ---A- . (.globalUpdate.) -- C:\Users\libya\AppData\Local\Temp\comh.177218\globalupdateCrashHandler.exe [68608] =>PUP.GlobalUpdate O61 - LFC: 6/3/2015 - 6:37:37 AM ---A- . (.globalUpdate.) -- C:\Users\libya\AppData\Local\Temp\comh.177218\globalupdateOnDemand.exe [46080] =>PUP.GlobalUpdate O61 - LFC: 6/3/2015 - 6:37:37 AM ---A- . (.globalUpdate.) -- C:\Users\libya\AppData\Local\Temp\comh.177218\goopdate.dll [761856] =>PUP.GlobalUpdate O61 - LFC: 6/3/2015 - 6:37:37 AM ---A- . (.globalUpdate.) -- C:\Users\libya\AppData\Local\Temp\comh.177218\goopdateres_en.dll [22528] =>PUP.GlobalUpdate O61 - LFC: 6/3/2015 - 6:37:37 AM ---A- . (.globalUpdate.) -- C:\Users\libya\AppData\Local\Temp\comh.177218\npglobalupdateUpdate4.dll [220672] =>PUP.GlobalUpdate O61 - LFC: 6/3/2015 - 6:37:37 AM ---A- . (.globalUpdate.) -- C:\Users\libya\AppData\Local\Temp\comh.177218\psmachine.dll [155648] =>PUP.GlobalUpdate O61 - LFC: 6/3/2015 - 6:37:37 AM ---A- . (.globalUpdate.) -- C:\Users\libya\AppData\Local\Temp\comh.177218\psuser.dll [155648] =>PUP.GlobalUpdate O61 - LFC: 6/3/2015 - 6:37:38 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\is-BJTR6.tmp\prsetup.exe [4203632] O61 - LFC: 6/3/2015 - 6:37:38 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\is-BJTR6.tmp\temporal_setup.exe [229114] O61 - LFC: 6/3/2015 - 6:37:38 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\is-BJTR6.tmp\temporal_setup2.exe [0] O61 - LFC: 6/3/2015 - 6:37:38 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\mVO1C48.exe [305152] O61 - LFC: 6/3/2015 - 6:37:38 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\mVO3A03.exe [305152] O61 - LFC: 6/3/2015 - 6:37:38 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\mVOD0E5.exe [305152] O61 - LFC: 6/3/2015 - 6:37:38 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsaE1A9.tmp\registry.dll [25088] O61 - LFC: 6/3/2015 - 6:37:38 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nscFD15.tmp\Registry.dll [25088] O61 - LFC: 6/3/2015 - 6:37:38 AM ---A- . (.Microsoft Corporation.) -- C:\Users\libya\AppData\Local\Temp\is-4H7N3.tmp\_isetup\_shfoldr.dll [23312] O61 - LFC: 6/3/2015 - 6:37:38 AM ---A- . (.Microsoft Corporation.) -- C:\Users\libya\AppData\Local\Temp\is-5VGJQ.tmp\_isetup\_shfoldr.dll [23312] O61 - LFC: 6/3/2015 - 6:37:38 AM ---A- . (.Microsoft Corporation.) -- C:\Users\libya\AppData\Local\Temp\is-BJTR6.tmp\_isetup\_shfoldr.dll [23312] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsdBE22.tmp\GetVersion.dll [6656] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsdBE22.tmp\Math.dll [67584] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsdBE22.tmp\System.dll [11264] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsdBE22.tmp\UserInfo.dll [4096] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsdBE22.tmp\WindeskWinsearch_silent_s3.exe [1022320] =>PUP.WindeskWinsearch O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsdBE22.tmp\blowfish.dll [22528] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsdBE22.tmp\manlib.dll [26112] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsdBE22.tmp\nsCBHTML5.dll [58368] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsdBE22.tmp\nsDialogs.dll [9728] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsdBE22.tmp\nsisunz.dll [40960] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsdBE22.tmp\registry.dll [25088] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsdBE22.tmp\serlib.dll [16384] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nshE5EF.tmp\ProcessKiller.dll [42496] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nskEDD9.tmp\IpConfig.dll [117248] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nskEDD9.tmp\NSISEncrypt.dll [132608] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nskEDD9.tmp\System.dll [11264] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nskEDD9.tmp\UserInfo.dll [4096] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nskEDD9.tmp\WmiInspector.dll [95232] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nskEDD9.tmp\inetc.dll [20992] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsl92DF.tmp\Registry.dll [25088] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nslD26D.tmp\Registry.dll [25088] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsm8D81.tmp\xml.dll [121344] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsm9C90.tmp\inetc.dll [20992] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (.Client Connect LTD.) -- C:\Users\libya\AppData\Local\Temp\nsn653B.tmp\SPtool.dll [3044624] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (.InstallMonetizer.) -- C:\Users\libya\AppData\Local\Temp\nsdBE22.tmp\setup.exe [10246680] O61 - LFC: 6/3/2015 - 6:37:39 AM ---A- . (.Rainmaker Software Group LLC..) -- C:\Users\libya\AppData\Local\Temp\nsdBE22.tmp\ProPCCleaner.exe [6644880] =>PUP.DoctorPC O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsn843F.tmp\Registry.dll [25088] O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nso1372.tmp\inetc.dll [20992] O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsoC13E.tmp\Registry.dll [25088] O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsp4174.tmp\Registry.dll [25088] O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsq24B1.tmp\Registry.dll [25088] O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsrA131.tmp\ProcessKiller.dll [42496] O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsrA131.tmp\nsis-progressbar.dll [97280] O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsrDE40.tmp\nsProcess.dll [4608] O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nst5A23.tmp\NSISList.dll [99840] O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nst7EE.tmp\nsProcess.dll [4096] O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsu2F3C.tmp\Registry.dll [25088] O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsu35D1.tmp\registry.dll [25088] O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsv7DF6.tmp\registry.dll [25088] O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsxCFEE.tmp\UserInfo.dll [4096] O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (.Client Connect LTD.) -- C:\Users\libya\AppData\Local\Temp\nstBE71.tmp\SPtool.dll [3044624] O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (.Client Connect LTD.) -- C:\Users\libya\AppData\Local\Temp\nsvC1DB.tmp\SPtool.dll [3044624] O61 - LFC: 6/3/2015 - 6:37:40 AM ---A- . (.FlashBeat.) -- C:\Users\libya\AppData\Local\Temp\nsxCFEE.tmp\NSISHelper.dll [539136] =>PUP.FlashBeat O61 - LFC: 6/3/2015 - 6:37:41 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\Uninstall.exe [61981] O61 - LFC: 6/3/2015 - 6:37:41 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\UninstallModule.exe [92816] O61 - LFC: 6/3/2015 - 6:37:41 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsy82A9.tmp\xml.dll [121344] O61 - LFC: 6/3/2015 - 6:37:41 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\nsyEF01.tmp\UserInfo.dll [4096] O61 - LFC: 6/3/2015 - 6:37:41 AM ---A- . (...) -- C:\Users\libya\AppData\Local\Temp\setup_648.exe [276048] O61 - LFC: 6/3/2015 - 6:37:41 AM ---A- . (.FlashBeat.) -- C:\Users\libya\AppData\Local\Temp\nsyEF01.tmp\NSISHelper.dll [539136] =>PUP.FlashBeat O61 - LFC: 6/3/2015 - 6:37:41 AM ---A- . (.InstallMonetizer.) -- C:\Users\libya\AppData\Local\Temp\~nsu.tmp\Au_.exe [1860767] O61 - LFC: 6/3/2015 - 6:37:42 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\ASPackage\ASPackage.exe [259622] =>PUP.ASPackage O61 - LFC: 6/3/2015 - 6:37:42 AM ---A- . (...) -- C:\Users\libya\AppData\Roaming\ASPackage\ASSrv.exe [93696] =>PUP.ASPackage O61 - LFC: 6/3/2015 - 6:37:45 AM ---A- . (.Nicolas Coolman.) -- C:\Users\libya\Downloads\Programs\ZHPDiag2.exe [6880236] =>.Nicolas Coolman ~ 223 Fichiers temporaires (Temporary files) ~ 18 Fichiers cookies (Cookies files) ~ Files: 158 Scanned in 31mn AMs ---\\ List all tools cleaner (LATC) (O63) O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman ~ ADS: Scanned in 00mn AMs ---\\ List all legacy services(LALS) (O64) O64 - Services: CurCS - 10/1/2014 - C:\Windows\System32\DRIVERS\idmwfp.sys (IDMWFP) .(.Tonec Inc. - Internet Download Manager WFP Driver.) - LEGACY_IDMWFP O64 - Services: CurCS - 2/21/1746 - C:\Windows\System32\drivers\innfd_1_10_0_14.sys (innfd_1_10_0_14) .(...) - LEGACY_INNFD_1_10_0_14 O64 - Services: CurCS - 4/14/2015 - C:\Windows\system32\drivers\mbam.sys (MBAMProtector) .(.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - LEGACY_MBAMPROTECTOR O64 - Services: CurCS - 6/3/2015 - C:\Windows\system32\drivers\MBAMSwissArmy.sys (MBAMSwissArmy) .(.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - LEGACY_MBAMSWISSARMY O64 - Services: CurCS - 4/14/2015 - C:\Windows\system32\drivers\mwac.sys (MBAMWebAccessControl) .(.Malwarebytes Corporation - Malwarebytes Web Access Control.) - LEGACY_MBAMWEBACCESSCONTROL O64 - Services: CurCS - 7/13/2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV O64 - Services: CurCS - 2/21/1746 - C:\Windows\system32\drivers\SPPD.sys (SPPD) .(...) - LEGACY_SPPD =>Rogue.PCSpeedUp ~ Legacy: 113 Scanned in 00mn AMs ---\\ File Associations Shell Spawning (O67) O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - ‎‎مشغل الأداة الإضافية لعارض الأحداث.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Crossbrowse - Crossbrowse.) -- C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe =>PUP.CrossBrowser O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - ‎‎محرر التسجيل.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Not Key.) ~ FASS Keys: 11 Scanned in 00mn AMs ---\\ Start Menu Internet (SMI) (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Crossbrowse - Crossbrowse.) -- C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe =>PUP.CrossBrowser O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\libya\AppData\Local\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\Launcher.exe ~ Keys: Scanned in 00mn AMs ---\\ Search Browser Infection (SBI) (O69) O69 - SBI: SearchScopes [HKCU] {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} [DefaultScope] - (Trovi) - http://www.trovi.com =>Hijacker.TroviCom O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com ~ Keys: Scanned in 00mn AMs ---\\ Search Svchost Services (SSS) (O83) O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\Windows\System32\aelupsvc.dll [62464] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - خدمة نشر شهادة البطاقة الذكية لـ Microsoft.) -- C:\Windows\System32\certprop.dll [67584] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - خدمة نشر شهادة البطاقة الذكية لـ Microsoft.) -- C:\Windows\System32\certprop.dll [67584] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمة الخادم.) -- C:\Windows\System32\srvsvc.dll [168960] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - عميل نهج المجموعة.) -- C:\Windows\System32\gpsvc.dll [593408] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\ikeext.dll [679424] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - خدمة صوت Windows.) -- C:\Windows\System32\Audiosrv.dll [475136] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - إدارة الطلب التلقائي للوصول عن بُعد.) -- C:\Windows\System32\rasauto.dll [90624] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [286208] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [75264] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - خدمة الإعلام بأحداث النظام (SENS).) -- C:\Windows\System32\sens.dll [49664] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [300544] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [242176] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remote Desktop Session Host Server Remote Connections Manager.) -- C:\Windows\System32\termsrv.dll [523776] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - عامل Windows Update.) -- C:\Windows\System32\wuaueng.dll [2020864] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - خدمة النقل الذكي في الخلفية.) -- C:\Windows\System32\qmgr.dll [585728] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمات Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over an IPv4 network..) -- C:\Windows\System32\iphlpsvc.dll [499712] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي الخاصة بخدمة تسجيل الدخول الثانوي.) -- C:\Windows\system32\seclogon.dll [21504] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - خدمة معلومات التطبيقات.) -- C:\Windows\System32\appinfo.dll [47104] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - خدمة اكتشاف iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - خدمة جدولة فئات تعدد الوسائط.) -- C:\Windows\System32\mmcss.dll [49664] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - تقارير المشاكل وحلولها.) -- C:\Windows\System32\wercplsupport.dll [61440] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [98304] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164864] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - خدمة جدولة المهام.) -- C:\Windows\System32\schedsvc.dll [750592] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\Windows\System32\kmsvc.dll [71168] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - خدمة تكوين سطح المكتب البعيد.) -- C:\Windows\System32\sessenv.dll [113664] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمة مستعرض الكمبيوتر.) -- C:\Windows\System32\browser.dll [102912] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمات نُسق Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376] O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - خدمة BDE.) -- C:\Windows\System32\bdesvc.dll [76800] O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - خدمة تثبت البرامج.) -- C:\Windows\System32\appmgmts.dll [149504] ~ Services: 33 Scanned in 01mn AMs ---\\ Search Rogue Infection (SRI) (O86) O43 - CFD: 6/3/2015 - 4:47:38 AM - [] ----D C:\ProgramData\28341ff220e0446c9fff27c4493d622e ~ Files: Scanned in 00mn AMs ---\\ Firewall Active Exception List (FirewallRules) (O87) O87 - FAEL: "{82E80028-B3FC-4034-B7A0-108E72F5A5B5}" | In - None - P17 - TRUE | .(.Crossbrowse - Crossbrowse.) -- C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe =>PUP.CrossBrowser ~ Firewall: 1 Scanned in 03mn AMs ---\\ Product Upgrade Codes (PUC) (O90) O90 - PUC: "32ACD517324896243BA5801C3136B1A0" . (.Pro PC Cleaner.) -- C:\Windows\Installer\{715DCA23-8423-4269-B35A-08C113631B0A}\Pro_PC_Cleaner_Icon.exe =>PUP.DoctorPC ~ Update Products: 1 Scanned in 00mn AMs ---\\ Random Export Key (REK) (O91) [HKLM\Software\cbbb007f-6750-459d-bda5-ffce74fc3cac] => Clé orpheline => Clé orpheline => Clé orpheline => Clé orpheline ~ Export Key Software: Scanned in 00mn AMs ---\\ Windows Installer Scan (WIS) (O93) (NTFS) [MD5.2902CE9A4CED9222A21CB62622EE4B07] [WIS][5/29/2015] (.Rainmaker Software Group LLC. - Pro PC Cleaner.) -- C:\Windows\Installer\5718c5.msi [1207296] =>PUP.DoctorPC ~ WIS: 1 Scanned in 04mn AMs ---\\ Search Tracing Registry Key (O100) HKLM\SOFTWARE\Microsoft\Tracing\MaxComputerCleaner_Maintenance_RASAPI32 =>PUP.MaxComputerCleaner HKLM\SOFTWARE\Microsoft\Tracing\MaxComputerCleaner_Maintenance_RASMANCS =>PUP.MaxComputerCleaner HKLM\SOFTWARE\Microsoft\Tracing\MaxComputerCleaner_RASAPI32 =>PUP.MaxComputerCleaner HKLM\SOFTWARE\Microsoft\Tracing\MaxComputerCleaner_RASMANCS =>PUP.MaxComputerCleaner HKLM\SOFTWARE\Microsoft\Tracing\ReimageRepair_RASAPI32 =>Rogue.ReimageRepair HKLM\SOFTWARE\Microsoft\Tracing\ReimageRepair_RASMANCS =>Rogue.ReimageRepair ~ BTK: 70 Scanned in 00mn AMs ---\\ Search CLSID Registry Key (O101) [HKCR\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}] (globalUpdate Update Plugin) =>PUP.GlobalUpdate [HKCR\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}] (globalUpdate.OneClickProcessLauncher) =>PUP.GlobalUpdate [HKCR\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}] (globalUpdate Update Plugin) =>PUP.GlobalUpdate ~ BCK: 4305 Scanned in 22mn AMs ---\\ Scan Additionnel (O88) Database Version : 13008 - (5/31/2015) Clés trouvées (Keys found) : 11 Valeurs trouvées (Values found) : 6 Dossiers trouvés (Folders found) : 22 Fichiers trouvés (Files found) : 38 [HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc] =>PUP.SearchProtect^ [HKLM\SYSTEM\CurrentControlSet\Services\globalUpdate) (globalUpdate] =>PUP.GlobalUpdate^ [HKLM\SYSTEM\CurrentControlSet\Services\Util Edu App] =>PUP.Optional^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Crossbrowse] =>PUP.CrossBrowser^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\gmsd_gb_398_is1] =>Adware.GamesDesktop^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{715DCA23-8423-4269-B35A-08C113631B0A}] =>PUP.DoctorPC^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect] =>PUP.SearchProtect^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{DC866C1E-B796-4BD2-93B8-B5706AC5B5CC}_is1] =>Adware.IncrediBar^ [HKCU\Software\Tutorials] =>Spyware.AgenceExclusive [HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider [HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:GoogleChromeAutoLaunch_F869A474B56DEC3386C30B8DA5B84F81 =>PUP.CrossBrowser^ C:\Program Files\Crossbrowse =>PUP.CrossBrowser^ C:\Program Files\globalUpdate =>PUP.GlobalUpdate^ C:\Program Files\Optimizer Pro 3.95 =>PUP.OptimizerPro^ C:\Program Files\Popcornew =>PUP.Popcornew^ C:\Program Files\predm =>Adware.Downware^ C:\Program Files\Pro PC Cleaner =>PUP.DoctorPC^ C:\Program Files\Reimage =>Rogue.ReimageRepair^ C:\Program Files\SearchProtect =>PUP.SearchProtect^ C:\ProgramData\FlashBeat =>PUP.FlashBeat^ C:\ProgramData\Reimage Protector =>Rogue.ReimageRepair^ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crossbrowse =>PUP.CrossBrowser^ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP =>Adware.GamesDesktop^ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro PC Cleaner =>PUP.DoctorPC^ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair =>Rogue.ReimageRepair^ C:\Users\libya\AppData\Roaming\AnyProtectEx =>PUP.AnyProtect^ C:\Users\libya\AppData\Roaming\ASPackage =>PUP.ASPackage^ C:\Users\libya\AppData\Local\Crossbrowse =>PUP.CrossBrowser^ C:\Users\libya\AppData\Local\globalUpdate =>PUP.GlobalUpdate^ C:\Users\libya\AppData\Local\Popcornew =>PUP.Popcornew^ C:\Users\libya\AppData\Local\Rainmaker_Software_Group_ =>PUP.DoctorPC^ C:\Users\libya\AppData\Local\SearchProtect =>PUP.SearchProtect^ C:\Users\libya\AppData\Local\SmartWeb =>PUP.SmartWeb^ C:\Program Files\Crossbrowse\Crossbrowse\Application\Crossbrowse.exe =>PUP.CrossBrowser^ C:\Program Files\Crossbrowse\Crossbrowse\Application\utility.exe =>PUP.CrossBrowser^ C:\Program Files\Pro PC Cleaner\Splash.exe =>PUP.DoctorPC^ C:\Program Files\Pro PC Cleaner\ProPCCleaner.exe =>PUP.DoctorPC^ C:\Windows\Tasks\APSnotifierPP1.job =>PUP.AnyProtect^ C:\Windows\System32\Tasks\APSnotifierPP1 =>PUP.AnyProtect^ C:\Windows\Tasks\APSnotifierPP2.job =>PUP.AnyProtect^ C:\Windows\System32\Tasks\APSnotifierPP2 =>PUP.AnyProtect^ C:\Windows\Tasks\APSnotifierPP3.job =>PUP.AnyProtect^ C:\Windows\System32\Tasks\APSnotifierPP3 =>PUP.AnyProtect^ C:\Windows\Tasks\Crossbrowse.job =>PUP.CrossBrowser^ C:\Windows\System32\Tasks\Crossbrowse =>PUP.CrossBrowser^ C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job =>PUP.GlobalUpdate^ C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job =>PUP.GlobalUpdate^ [HKCU\Software\AnyProtect] =>PUP.AnyProtect^ [HKCU\Software\CrossBrowser] =>PUP.CrossBrowser^ [HKCU\Software\Crossbrowse] =>PUP.CrossBrowser^ [HKCU\Software\MaxComputerCleanerConfig] =>PUP.MaxComputerCleaner^ [HKCU\Software\MaxComputerCleanerLanguage] =>PUP.MaxComputerCleaner^ [HKCU\Software\Optimizer Pro] =>PUP.OptimizerPro^ [HKCU\Software\Popcornew] =>PUP.Popcornew^ [HKCU\Software\ProPCCleanerLanguage] =>PUP.DoctorPC^ [HKCU\Software\Shop and Save Up-nv-ie] =>PUP.CrossRider^ [HKCU\Software\TutoTag] =>PUP.AgenceExclusive^ [HKCU\Software\globalUpdate] =>PUP.GlobalUpdate^ [HKLM\Software\GAMESDESKTOP] =>Adware.GamesDesktop^ [HKLM\Software\GlobalUpdate] =>PUP.GlobalUpdate^ [HKLM\Software\Infonaut_1.10.0.14] =>PUP.Infonaut^ [HKLM\Software\Popcornew] =>PUP.Popcornew^ [HKLM\Software\Reimage] =>Rogue.ReimageRepair^ [HKLM\Software\SPPDCOM] =>Rogue.PCSpeedUp^ [HKLM\Software\Tutorials] =>PUP.AgenceExclusive^ [HKLM\Software\cbbb007f-6750-459d-bda5-ffce74fc3cac] =>PUP.CrossRider^ C:\Windows\Installer\5718c5.msi =>PUP.DoctorPC^ [HKCR\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}] (globalUpdate Update Plugin) =>PUP.GlobalUpdate^ [HKCR\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}] (globalUpdate.OneClickProcessLauncher) =>PUP.GlobalUpdate^ [HKCR\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}] (globalUpdate Update Plugin) =>PUP.GlobalUpdate^ C:\Windows\Reimage.ini =>Rogue.ReimageRepair ~ Additionnel Scan: 129882 Items scanned in 23mn AMs ---\\ Additional information about modules ~ http://nicolascoolman.fr/g2-google-chrome-extensions/ =>.Google Chrome, Start,Search,Extensions (G0,G1,G2) ~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5) ~ http://nicolascoolman.fr/o2-browser-helper-objects-de-navigateur/ =>.Browser Helper Objects (O2) ~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Auto loading programs from Registry and folders (O4) ~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.MountPoints2 Shell Key (MPSK) (O51) ~ AMI: 5 Scanned in 00mn AMs ---\\ Summary of the detections found on your workstation http://www.nicolascoolman.fr/blog/ =>PUP.CrossBrowser http://nicolascoolman.fr/pup-globalupdate =>PUP.GlobalUpdate http://nicolascoolman.fr/hijacker-trovicom =>Hijacker.TroviCom http://www.nicolascoolman.fr/blog/ =>PUP.DoctorPC http://nicolascoolman.fr/rogue-reimagerepair =>Rogue.ReimageRepair http://nicolascoolman.fr/pup-searchprotect =>PUP.SearchProtect http://www.nicolascoolman.fr/blog/ =>PUP.Optional http://nicolascoolman.fr/pup-anyprotect =>PUP.AnyProtect http://www.nicolascoolman.fr/blog/ =>PUP.MaxComputerCleaner http://nicolascoolman.fr/pup-smartwebsearch =>PUP.SmartWeb http://www.nicolascoolman.fr/blog/ =>Adware.GamesDesktop http://nicolascoolman.fr/adware-incredibar =>Adware.IncrediBar http://nicolascoolman.fr/pup-crossrider =>PUP.CrossRider http://nicolascoolman.fr/pup-optimizerpro =>PUP.OptimizerPro http://www.nicolascoolman.fr/blog/ =>PUP.Popcornew http://nicolascoolman.fr/spyware-agenceexclusive =>PUP.AgenceExclusive http://www.nicolascoolman.fr/blog/ =>PUP.Infonaut http://nicolascoolman.fr/rogue-pcspeedup =>Rogue.PCSpeedUp http://nicolascoolman.fr/adware-downware =>Adware.Downware http://www.nicolascoolman.fr/blog/ =>PriceMinus http://www.nicolascoolman.fr/blog/ =>PUP.FlashBeat http://www.nicolascoolman.fr/blog/ =>PUP.ASPackage http://www.nicolascoolman.fr/blog/ =>PUP.WindeskWinsearch Clé orpheline => Clé orpheline => Clé orpheline => Clé orpheline http://www.nicolascoolman.fr/blog/ =>Spyware.AgenceExclusive ~ MSI: 25 link(s) detected in 00mn AMs End of the scan (2320 lines in 24mn AMs)(0.8)