~ ZHPDiag v2015.7.10.86 By Nicolas Coolman (2015/07/10) ~ Run by user (Administrator) (2015/07/10 15:16:31) ~ Site: http://www.nicolascoolman.fr ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ State version: Version OK ~ Mode: Scan ~ Report: C:\Users\user\Desktop\ZHPDiag.txt ~ Report: C:\Users\user\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ System startup: Normal (Normal boot) ~ Windows 7, 32-bit (Build 7600) ---\\ Windows Product Information (3) - 1s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Activation Technologies : OK ---\\ Surveillance software (2) - 0s Adobe Flash Player 11 ActiveX & Plugin Adobe Reader X ---\\ Information on the system (6) - 0s ~ Operating System: x86 Family 6 Model 30 Stepping 5, GenuineIntel ~ Operating System: 32-bit ~ Boot mode: Normal (Normal boot) ~ Total physical RAM (KB): 3078000 ~ System Restore: Activé (Enable) ~ System drive C: has 117 GB free of 150 GB ---\\ Connection to the system mode (3) - 0s ~ Computer Name: USER-PC ~ User Name: user ~ Logged in as Administrator ---\\ Enumeration of the disk units (2) - 0s ~ Drive C: has 117 GB free of 150 GB (System) ~ Drive D: has 107 GB free of 154 GB ---\\ Search Generic System Files (23) - 1s [MD5.15BC38A7492BEFE831966ADB477CF76F] - (.Microsoft Corporation - Windows Explorer.) () -- C:\Windows\Explorer.exe [2613248] [MD5.51138BEEA3E2C21EC44D0932C71762A8] - (.Microsoft Corporation - Windows host process (Rundll32).) () -- C:\Windows\System32\rundll32.exe [44544] [MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Windows Start-Up Application.) () -- C:\Windows\System32\Wininit.exe [96256] [MD5.0D874F3BC751CC2198AF2E6783FB8B35] - (.Microsoft Corporation - Internet Extensions for Win32.) () -- C:\Windows\System32\wininet.dll [977920] [MD5.8EC6A4AB12B8F3759E21F8E3A388F2CF] - (.Microsoft Corporation - Windows Logon Application.) () -- C:\Windows\System32\Winlogon.exe [285696] [MD5.58C94EAE54BF0C5E2B80B2E5E7744D4C] - (.Microsoft Corporation - Software Licensing Library.) () -- C:\Windows\System32\sppcomapi.dll [193024] [MD5.DDC040FDB01EF1712A6B13E52AFB104C] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\Windows\System32\drivers\AFD.sys [338944] [MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\Windows\System32\drivers\atapi.sys [21584] [MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\Windows\System32\drivers\Cdfs.sys [70656] [MD5.BA6E70AA0E6091BC39DE29477D866A77] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\Windows\System32\drivers\Cdrom.sys [108544] [MD5.8E09E52EE2E3CEB199EF3DD99CF9E3FB] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\Windows\System32\drivers\DfsC.sys [78336] [MD5.717A2207FD6F13AD3E664C7D5A43C7BF] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\Windows\System32\drivers\HDAudBus.sys [108544] [MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - i8042 Port Driver.) () -- C:\Windows\System32\drivers\i8042prt.sys [80896] [MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\Windows\System32\drivers\IpNat.sys [101888] [MD5.F4A054BE78AF7F410129C4B64B07DC9B] - (.Microsoft Corporation - Windows NT SMB Minirdr.) () -- C:\Windows\System32\drivers\MRxSmb.sys [123392] [MD5.DD52A733BF4CA5AF84562A5E2F963B91] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\Windows\System32\drivers\netBT.sys [187904] [MD5.3795DCD21F740EE799FB7223234215AF] - (.Microsoft Corporation - NT File System Driver.) () -- C:\Windows\System32\drivers\ntfs.sys [1210432] [MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Parallel Port Driver.) () -- C:\Windows\System32\drivers\Parport.sys [79360] [MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\Windows\System32\drivers\Rasl2tp.sys [78848] [MD5.C5FF95883FFEF704D50C40D21CFB3AB5] - (.Microsoft Corporation - Microsoft RDP Device redirector.) () -- C:\Windows\System32\drivers\rdpdr.sys [133120] [MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) () -- C:\Windows\System32\drivers\smb.sys [71168] [MD5.CB39E896A2A83702D1737BFD402B3542] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\Windows\System32\drivers\tdx.sys [74240] [MD5.58DF9D2481A56EDDE167E51B334D44FD] - (.Microsoft Corporation - Volume Shadow Copy Driver.) () -- C:\Windows\System32\drivers\volsnap.sys [245328] ---\\ Process running (19) - 2s [MD5.44A3CA21C5E7A1A93697B2AAEAD2CA75] - (.AMD - AMD External Events Service Module.) -- C:\Windows\System32\atiesrxx.exe [208896] [PID.880] [MD5.059112C65E1C6A9D8023A9123A78081E] - (.AMD - AMD External Events Client Module.) -- C:\Windows\System32\atieclxx.exe [513536] [PID.1304] [MD5.FF966760FBAE211F585DEC2247D777EB] - (.Webby - iWebar exe.) -- C:\Program Files\iWebar\50e2eba1-c248-41fe-b755-1c97d900606c-6.exe [1324544] [PID.2012] =>PUP.Optional.CrossRider [MD5.7729B0F4675F627F8B44F4AB8D492BA1] - (.Webby - iWebar exe.) -- C:\Program Files\iWebar\50e2eba1-c248-41fe-b755-1c97d900606c-1-6.exe [1408512] [PID.1948] =>PUP.Optional.CrossRider [MD5.34CE117AEF7791333D5704014BE4B49B] - (.Sense+ - SensePlus exe.) -- C:\Program Files\SensePlus\7061973a-9457-4c07-abc3-36fc40507147-6.exe [1324544] [PID.828] =>PUP.Optional.CrossRider [MD5.3ABCD08D9A496A85A685238E9FC5201D] - (.Sense+ - SensePlus exe.) -- C:\Program Files\SensePlus\7061973a-9457-4c07-abc3-36fc40507147-1-6.exe [1408512] [PID.2088] =>PUP.Optional.CrossRider [MD5.5A78BB029FD8414381FF1315F1E46947] - (.Copyright (C) 2012 - .) -- C:\ProgramData\MobileBrServ\mbbservice.exe [232288] [PID.2148] [MD5.BD659838F5CBE8462D56ECD1559AEDD2] - (.ShopperPro - ShopperPro Update Service.) -- C:\Program Files\Common Files\ShopperPro\spbiu.exe [1813504] [PID.2192] =>PUP.Optional.ShopperPro [MD5.3398509A82AD7279204ABF66FAAE67AF] - (...) -- C:\Program Files\Swift Record\bin\utilSwiftRecord.exe [474352] [PID.2636] =>PUP.Optional.SwiftRecord [MD5.EB7711A785E5B12F153C715CC91BC76F] - (.Copyright © 2010. All rights reserved. - CDA Server.) -- C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [350072] [PID.3736] [MD5.308F2EE28005510DE616409148CF077B] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896] [PID.3820] [MD5.F7593C18BE0493DF2BE3B3245545EB9C] - (.Advanced Micro Devices Inc. - Catalyst Control Center: Monitoring program.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe [299520] [PID.3848] [MD5.06DCDE310630A7E8BAB528168C29C7AF] - (.ATI Technologies Inc. - Catalyst Control Center: Host application.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [299520] [PID.3952] [MD5.146B1CE7F7F7556264026789CD9BAA90] - (.Copyright (C) 2014 - JsDriver.) -- C:\Program Files\ShopperPro\JSDriver\1.42.1.2069\jsdrv.exe [3225088] [PID.2516] =>PUP.Optional.ShopperPro [MD5.3398509A82AD7279204ABF66FAAE67AF] - (...) -- C:\Program Files\Swift Record\updateSwiftRecord.exe [474352] [PID.5172] =>PUP.Optional.SwiftRecord [MD5.1F0BFA676197376640E4BBED972692AE] - (...) -- C:\Program Files\Swift Record\bin\SwiftRecord.BrowserAdapter.exe [108784] [PID.5800] =>PUP.Optional.SwiftRecord [MD5.57E25B7A80C70111F41D9E1A5CAD1986] - (...) -- C:\Program Files\Swift Record\bin\SwiftRecord.expext.exe [114928] [PID.5988] =>PUP.Optional.SwiftRecord [MD5.259964F40372D62FA0878752B2785D04] - (...) -- C:\Program Files\Swift Record\bin\SwiftRecord.PurBrowse.exe [296688] [PID.6092] =>PUP.Optional.SwiftRecord [MD5.A9CA1AAD4E4890826D3C2E2F74CDF8E1] - (.Oracle Corporation - Java(TM) Update Checker.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe [511872] [PID.3284] ---\\ Google Chrome, Start,Search,Extensions (G0,G1,G2) (14) - 1s G2 - GCE: Extension [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc. G2 - GCE: Extension [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc. G2 - GCE: Extension [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc. G2 - GCE: Extension [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc. G2 - GCE: Extension [User Data\Default] [dhdgffkkebhmkfjojejmpbldmpobfkfo] Tampermonkey G2 - GCE: Extension [User Data\Default] [gighmmpiobklfepjocnamgkkbiglidom] AdBlock G2 - GCE: Extension [User Data\Default] [hppdcdfhpfelinnjbddccbgplfdapmbi] Swift Record =>PUP.Optional.SwiftRecord G2 - GCE: Extension [User Data\Default] [lccekmodgklaepjeofjdjpbminllajkg] Chrome Hotword Shared Module G2 - GCE: Extension [User Data\Default] [mihcahmgecmbnbcchbopgniflfhgnkff] mihcahmgecmbnbcchbopgniflfhgnkff G2 - GCE: Extension [User Data\Default] [mppnoffgpafgpgbaigljliadgbnhljfl] Ask Search G2 - GCE: Extension [User Data\Default] [nafaimnnclfjfedmmabolbppcngeolgf] iLivid =>PUP.Optional.Bandoo G2 - GCE: Extension [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. G2 - GCE: Extension [User Data\Default] [offledjhohfjkfefaaljadpjjmnjcncp] safewwEb =>PUP.Optional.Multiplug G2 - GCE: Extension [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc. ---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (P2,M0,M1,M2,M3) (12) - 1s M1 - SPR:Search Page Redirection - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} P2 - EXT: (.mozilla.org - Default Plug-in.) -- C:\Program Files\Mozilla Firefox\Plugins\npnul32.dll P2 - EXT: (.RealNetworks, Inc. - RealJukebox Netscape Plugin.) -- C:\Program Files\Mozilla Firefox\Plugins\nprjplug.dll P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\NPSWF32_11_6_602_180.dll P2 - FPN: [HKLM] [@java.com/DTPlugin,version=10.67.2] - (.Oracle Corporation.) -- C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=10.67.2] - (.Oracle Corporation.) -- C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll P2 - FPN: [HKLM] [@real.com/nppl3260;version=12.0.1.609] - (.RealNetworks, Inc..) -- C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll P2 - FPN: [HKLM] [@real.com/nprjplug;version=12.0.1.609] - (.RealNetworks, Inc..) -- C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll P2 - FPN: [HKLM] [@real.com/nprphtml5videoshim;version=12.0.1.609] - (.RealNetworks.) -- C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll P2 - FPN: [HKLM] [@real.com/nprpjplug;version=12.0.1.609] - (.RealNetworks, Inc..) -- C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll P2 - FPN: [HKLM] [@staging.google.com/globalUpdate Update;version=10] - (.globalUpdate.) -- C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll =>PUP.Optional.GlobalUpdate P2 - FPN: [HKLM] [@staging.google.com/globalUpdate Update;version=4] - (.globalUpdate.) -- C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll =>PUP.Optional.GlobalUpdate ---\\ Internet Explorer Extensions, Start, Search (R4,R3,R0,R1) (10) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer ---\\ Internet Explorer, Proxy Management (R5) (3) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Line Analysis F0, F1, F2, F3 - IniFiles, Auto loading programs (3) - 0s F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.) F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) F2 - REG:system.ini: VMApplet=C:\Windows\system32\SystemPropertiesPerformance.exe (.Microsoft Corporation.) ---\\ Hosts file redirection (O1) (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (21) ---\\ Browser Helper Object (BHO) (O2) (5) - 1s O2 - BHO: Swift Record 1.0.0.7 - {0759d61f-3673-416f-85d2-58b847e78ddf} . (.Swift Record - Swift Record.) -- C:\Program Files\Swift Record\SwiftRecordbho.dll =>PUP.Optional.SwiftRecord O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} . (...) -- C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (.not file.) O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre7\bin\ssv.dll O2 - BHO: ShopperProBHO - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} . (.Goobzo Ltd. - ShopperPro Extension.) -- C:\ProgramData\ShopperPro\ShopperPro.dll =>PUP.Optional.ShopperPro O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre7\bin\jp2ssv.dll ---\\ Auto loading programs from Registry and folders (O4) (13) - 0s O4 - HKLM\..\Run: [GrooveMonitor] . (.Microsoft Corporation - GrooveMonitor Utility.) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe O4 - HKLM\..\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe O4 - HKLM\..\Run: [CDAServer] . (.Copyright © 2010. All rights reserved. - CDA Server.) -- C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe O4 - HKLM\..\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe O4 - HKLM\..\Run: [HP Software Update] . (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe O4 - HKCU\..\Run: [SPDriver] . (.Copyright (C) 2014 - JsDriver.) -- C:\Program Files\ShopperPro\JSDriver\1.42.1.2069\jsdrv.exe =>PUP.Optional.ShopperPro O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe O4 - HKUS\S-1-5-21-688127040-1277483408-1112017465-1000\..\Run: [SPDriver] . (.Copyright (C) 2014 - JsDriver.) -- C:\Program Files\ShopperPro\JSDriver\1.42.1.2069\jsdrv.exe =>PUP.Optional.ShopperPro ---\\ Lop.com/Domain Hijackers (O17) (6) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.15.1 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.15.1 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpNameServer = 192.168.15.1 ---\\ Non Microsoft non disabled Windows XP/NT/2000 Services (O23) (10) - 1s O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\System32\atiesrxx.exe O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) . (.globalUpdate - globalUpdate Update.) - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe =>PUP.Optional.GlobalUpdate O23 - Service: ÎÏãÉ Google Update (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: HP Service (hpsrv) . (.Hewlett-Packard Company - HpService.) - C:\Windows\System32\Hpservice.exe O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) . (.Hewlett-Packard Company - SolutionsFrameworkService.) - C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe O23 - Service: Mobile Broadband HL Service (Mobile Broadband HL Service) . (.Copyright (C) 2012 - .) - C:\ProgramData\MobileBrServ\mbbservice.exe O23 - Service: ShopperPro Update (SPBIUpd) . (.ShopperPro - ShopperPro Update Service.) - C:\Program Files\Common Files\ShopperPro\spbiu.exe =>PUP.Optional.ShopperPro O23 - Service: Update Swift Record (Update Swift Record) . (...) - C:\Program Files\Swift Record\updateSwiftRecord.exe =>PUP.Optional.SwiftRecord O23 - Service: Util Swift Record (Util Swift Record) . (...) - C:\Program Files\Swift Record\bin\utilSwiftRecord.exe =>PUP.Optional.SwiftRecord ---\\ Task Planned Automatically (O39) (58) - 5s [MD5.7729B0F4675F627F8B44F4AB8D492BA1] [APT] [50e2eba1-c248-41fe-b755-1c97d900606c-1-6] (.Webby.) -- C:\Program Files\iWebar\50e2eba1-c248-41fe-b755-1c97d900606c-1-6.exe [1408512] =>PUP.Optional.CrossRider [MD5.499DE5793BAD300B56D9CE76560496CF] [APT] [50e2eba1-c248-41fe-b755-1c97d900606c-4] (.Webby.) -- C:\Program Files\iWebar\50e2eba1-c248-41fe-b755-1c97d900606c-4.exe [1372160] =>PUP.Optional.CrossRider [MD5.C3E4E0B3F23355FCFBDB5A269A47FAA9] [APT] [50e2eba1-c248-41fe-b755-1c97d900606c-5] (.Webby.) -- C:\Program Files\iWebar\50e2eba1-c248-41fe-b755-1c97d900606c-5.exe [1061376] =>PUP.Optional.CrossRider [MD5.C3E4E0B3F23355FCFBDB5A269A47FAA9] [APT] [50e2eba1-c248-41fe-b755-1c97d900606c-5_user] (.Webby.) -- C:\Program Files\iWebar\50e2eba1-c248-41fe-b755-1c97d900606c-5.exe [1061376] =>PUP.Optional.CrossRider [MD5.FF966760FBAE211F585DEC2247D777EB] [APT] [50e2eba1-c248-41fe-b755-1c97d900606c-6] (.Webby.) -- C:\Program Files\iWebar\50e2eba1-c248-41fe-b755-1c97d900606c-6.exe [1324544] =>PUP.Optional.CrossRider [MD5.3ABCD08D9A496A85A685238E9FC5201D] [APT] [7061973a-9457-4c07-abc3-36fc40507147-1-6] (.Sense+.) -- C:\Program Files\SensePlus\7061973a-9457-4c07-abc3-36fc40507147-1-6.exe [1408512] =>PUP.Optional.CrossRider [MD5.D0D11E17DD29B5D5ED8BC120D2C1C238] [APT] [7061973a-9457-4c07-abc3-36fc40507147-4] (.Sense+.) -- C:\Program Files\SensePlus\7061973a-9457-4c07-abc3-36fc40507147-4.exe [1372160] =>PUP.Optional.CrossRider [MD5.ADB45A6AF360E278D045725AEF981B3C] [APT] [7061973a-9457-4c07-abc3-36fc40507147-5] (.Sense+.) -- C:\Program Files\SensePlus\7061973a-9457-4c07-abc3-36fc40507147-5.exe [1061376] =>PUP.Optional.CrossRider [MD5.ADB45A6AF360E278D045725AEF981B3C] [APT] [7061973a-9457-4c07-abc3-36fc40507147-5_user] (.Sense+.) -- C:\Program Files\SensePlus\7061973a-9457-4c07-abc3-36fc40507147-5.exe [1061376] =>PUP.Optional.CrossRider [MD5.34CE117AEF7791333D5704014BE4B49B] [APT] [7061973a-9457-4c07-abc3-36fc40507147-6] (.Sense+.) -- C:\Program Files\SensePlus\7061973a-9457-4c07-abc3-36fc40507147-6.exe [1324544] =>PUP.Optional.CrossRider [MD5.D858BA2EE718B1DB1CED20646E641D08] [APT] [globalUpdateUpdateTaskMachineCore] (.globalUpdate.) -- C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608] =>PUP.Optional.GlobalUpdate [MD5.D858BA2EE718B1DB1CED20646E641D08] [APT] [globalUpdateUpdateTaskMachineUA] (.globalUpdate.) -- C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608] =>PUP.Optional.GlobalUpdate [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [116648] [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [116648] [MD5.F59DDAB9119C9BB26E2887351BF2FC09] [APT] [HPCustParticipation HP Deskjet 1510 series] (.Hewlett-Packard Co..) -- C:\Program Files\Hp\HP Deskjet 1510 series\Bin\HPCustPartic.exe [3906592] [MD5.EA0CA98847DC1A403FFEC3BE116E8B2F] [APT] [Inst_Rep] (.Copyright (C) 2014.) -- C:\Users\user\AppData\Local\Installer\Install_26811\DCytaiesmt_smtyc_setup.exe [1222640] [MD5.BDEE1AEE61C63AB26A8A4F6B760B7388] [APT] [RealUpgradeLogonTaskS-1-5-21-688127040-1277483408-1112017465-1000] (.RealNetworks, Inc..) -- C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [169640] [MD5.BDEE1AEE61C63AB26A8A4F6B760B7388] [APT] [RealUpgradeScheduledTaskS-1-5-21-688127040-1277483408-1112017465-1000] (.RealNetworks, Inc..) -- C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [169640] [MD5.5836E93798A77EAF3F6AC13C70FA8C3A] [APT] [ShopperPro] (.Goobzo LTD.) -- C:\Program Files\ShopperPro\ShopperPro.exe [1111472] =>PUP.Optional.ShopperPro [MD5.14AE6E649130842485E0B15A1CAA5591] [APT] [ShopperProJSUpd] (.Goobzo.) -- C:\Program Files\ShopperPro\Updater.exe [764336] =>PUP.Optional.ShopperPro [MD5.146B1CE7F7F7556264026789CD9BAA90] [APT] [SPDriver] (.Copyright (C) 2014.) -- C:\Program Files\ShopperPro\JSDriver\1.42.1.2069\jsdrv.exe [3225088] =>PUP.Optional.ShopperPro [MD5.146B1CE7F7F7556264026789CD9BAA90] [APT] [UNELEVATE_20865] (.Copyright (C) 2014.) -- C:\Program Files\ShopperPro\JSDriver\1.42.1.2069\jsdrv.exe [3225088] =>PUP.Optional.ShopperPro O39 - APT: 50e2eba1-c248-41fe-b755-1c97d900606c-1-6 - (.Webby.) -- C:\Windows\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-1-6.job [3430] =>PUP.Optional.CrossRider O39 - APT:Automatic Planified Task - (...) -- C:\Windows\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-1-7.job [3430] =>PUP.Optional.CrossRider O39 - APT: 50e2eba1-c248-41fe-b755-1c97d900606c-4 - (.Webby.) -- C:\Windows\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-4.job [4450] =>PUP.Optional.CrossRider O39 - APT: 50e2eba1-c248-41fe-b755-1c97d900606c-5 - (.Webby.) -- C:\Windows\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-5.job [2746] =>PUP.Optional.CrossRider O39 - APT: 50e2eba1-c248-41fe-b755-1c97d900606c-5_user - (.Webby.) -- C:\Windows\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-5_user.job [2746] =>PUP.Optional.CrossRider O39 - APT: 50e2eba1-c248-41fe-b755-1c97d900606c-6 - (.Webby.) -- C:\Windows\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-6.job [5818] =>PUP.Optional.CrossRider O39 - APT:Automatic Planified Task - (...) -- C:\Windows\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-7.job [5474] =>PUP.Optional.CrossRider O39 - APT: 7061973a-9457-4c07-abc3-36fc40507147-1-6 - (.Sense+.) -- C:\Windows\Tasks\7061973a-9457-4c07-abc3-36fc40507147-1-6.job [3100] =>PUP.Optional.CrossRider O39 - APT:Automatic Planified Task - (...) -- C:\Windows\Tasks\7061973a-9457-4c07-abc3-36fc40507147-1-7.job [3436] =>PUP.Optional.CrossRider O39 - APT: 7061973a-9457-4c07-abc3-36fc40507147-4 - (.Sense+.) -- C:\Windows\Tasks\7061973a-9457-4c07-abc3-36fc40507147-4.job [4456] =>PUP.Optional.CrossRider O39 - APT: 7061973a-9457-4c07-abc3-36fc40507147-5 - (.Sense+.) -- C:\Windows\Tasks\7061973a-9457-4c07-abc3-36fc40507147-5.job [2752] =>PUP.Optional.CrossRider O39 - APT: 7061973a-9457-4c07-abc3-36fc40507147-5_user - (.Sense+.) -- C:\Windows\Tasks\7061973a-9457-4c07-abc3-36fc40507147-5_user.job [2752] =>PUP.Optional.CrossRider O39 - APT: 7061973a-9457-4c07-abc3-36fc40507147-6 - (.Sense+.) -- C:\Windows\Tasks\7061973a-9457-4c07-abc3-36fc40507147-6.job [5480] =>PUP.Optional.CrossRider O39 - APT:Automatic Planified Task - (...) -- C:\Windows\Tasks\7061973a-9457-4c07-abc3-36fc40507147-7.job [5480] =>PUP.Optional.CrossRider O39 - APT: globalUpdateUpdateTaskMachineCore - (.globalUpdate.) -- C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job [884] =>PUP.Optional.GlobalUpdate O39 - APT: globalUpdateUpdateTaskMachineUA - (.globalUpdate.) -- C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job [888] =>PUP.Optional.GlobalUpdate O39 - APT: 50e2eba1-c248-41fe-b755-1c97d900606c-1-6 - (.Webby.) -- C:\Windows\System32\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-1-6 [6458] =>PUP.Optional.CrossRider O39 - APT: 50e2eba1-c248-41fe-b755-1c97d900606c-4 - (.Webby.) -- C:\Windows\System32\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-4 [7480] =>PUP.Optional.CrossRider O39 - APT: 50e2eba1-c248-41fe-b755-1c97d900606c-5 - (.Webby.) -- C:\Windows\System32\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-5 [5776] =>PUP.Optional.CrossRider O39 - APT: 50e2eba1-c248-41fe-b755-1c97d900606c-5_user - (.Webby.) -- C:\Windows\System32\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-5_user [5768] =>PUP.Optional.CrossRider O39 - APT: 50e2eba1-c248-41fe-b755-1c97d900606c-6 - (.Webby.) -- C:\Windows\System32\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-6 [8846] =>PUP.Optional.CrossRider O39 - APT: 7061973a-9457-4c07-abc3-36fc40507147-1-6 - (.Sense+.) -- C:\Windows\System32\Tasks\7061973a-9457-4c07-abc3-36fc40507147-1-6 [6128] =>PUP.Optional.CrossRider O39 - APT: 7061973a-9457-4c07-abc3-36fc40507147-4 - (.Sense+.) -- C:\Windows\System32\Tasks\7061973a-9457-4c07-abc3-36fc40507147-4 [7486] =>PUP.Optional.CrossRider O39 - APT: 7061973a-9457-4c07-abc3-36fc40507147-5 - (.Sense+.) -- C:\Windows\System32\Tasks\7061973a-9457-4c07-abc3-36fc40507147-5 [5782] =>PUP.Optional.CrossRider O39 - APT: 7061973a-9457-4c07-abc3-36fc40507147-5_user - (.Sense+.) -- C:\Windows\System32\Tasks\7061973a-9457-4c07-abc3-36fc40507147-5_user [5774] =>PUP.Optional.CrossRider O39 - APT: 7061973a-9457-4c07-abc3-36fc40507147-6 - (.Sense+.) -- C:\Windows\System32\Tasks\7061973a-9457-4c07-abc3-36fc40507147-6 [8508] =>PUP.Optional.CrossRider O39 - APT: globalUpdateUpdateTaskMachineCore - (.globalUpdate.) -- C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore [3632] =>PUP.Optional.GlobalUpdate O39 - APT: globalUpdateUpdateTaskMachineUA - (.globalUpdate.) -- C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA [3886] =>PUP.Optional.GlobalUpdate O39 - APT: Inst_Rep - (.Copyright (C) 2014.) -- C:\Windows\System32\Tasks\Inst_Rep [3504] O39 - APT: RealUpgradeLogonTaskS-1-5-21-688127040-1277483408-1112017465-1000 - (.RealNetworks, Inc..) -- C:\Windows\System32\Tasks\RealUpgradeLogonTaskS-1-5-21-688127040-1277483408-1112017465-1000 [3188] O39 - APT: RealUpgradeScheduledTaskS-1-5-21-688127040-1277483408-1112017465-1000 - (.RealNetworks, Inc..) -- C:\Windows\System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-688127040-1277483408-1112017465-1000 [3324] O39 - APT: ShopperPro - (.Goobzo LTD.) -- C:\Windows\System32\Tasks\ShopperPro [4182] =>PUP.Optional.ShopperPro O39 - APT: ShopperProJSUpd - (.Goobzo.) -- C:\Windows\System32\Tasks\ShopperProJSUpd [3552] =>PUP.Optional.ShopperPro O39 - APT:Automatic Planified Task - (...) -- C:\Windows\System32\Tasks\SPBIW_UpdateTask_Time_343036393034333837362d3223572a23456c4155572a32 [4228] O39 - APT: SPDriver - (.Copyright (C) 2014.) -- C:\Windows\System32\Tasks\SPDriver [3478] O39 - APT: UNELEVATE_20865 - (.Copyright (C) 2014.) -- C:\Windows\System32\Tasks\UNELEVATE_20865 [3146] ---\\ Software installed (O42) (47) - 8s O42 - Logiciel: Adobe Flash Player 11 ActiveX & Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX O42 - Logiciel: Audio Recorder Titanium v7.1.2 - (.ART Inc..) [HKLM] -- Audio Recorder Titanium_is1 O42 - Logiciel: Samsung Easy Wireless Setup - (.Samsung Electronics Co., Ltd..) [HKLM] -- Easy Wireless Setup O42 - Logiciel: Google Chrome - (.Google Incý.ý.) [HKLM] -- Google Chrome O42 - Logiciel: HP Photo Creations - (.HP.) [HKLM] -- HP Photo Creations O42 - Logiciel: iWebar - (.Webby.) [HKLM] -- iWebar =>PUP.Optional.CrossRider O42 - Logiciel: Mobile Broadband HL Service - (.Huawei Technologies Co.,Ltd.) [HKLM] -- Mobile Broadband HL Service O42 - Logiciel: Mozilla Firefox (3.0.3) - (.Mozilla.) [HKLM] -- Mozilla Firefox (3.0.3) O42 - Logiciel: photoFXlab - (.Topaz Labs.) [HKLM] -- photoFXlab O42 - Logiciel: RealPlayer - (.RealNetworks.) [HKLM] -- RealPlayer 12.0 O42 - Logiciel: Samsung Easy Printer Manager - (.Samsung Electronics Co., Ltd..) [HKLM] -- Samsung Easy Printer Manager O42 - Logiciel: Samsung M2020 Series - (.Samsung Electronics Co., Ltd..) [HKLM] -- Samsung M2020 Series O42 - Logiciel: Samsung Printer Live Update - (.Samsung Electronics Co., Ltd..) [HKLM] -- Samsung Printer Live Update O42 - Logiciel: SensePlus - (.Sense+.) [HKLM] -- SensePlus =>PUP.Optional.CrossRider O42 - Logiciel: Shopper-Pro - (...) [HKLM] -- ShopperPro =>PUP.Optional.ShopperPro O42 - Logiciel: SPlayer - (...) [HKLM] -- SPlayer O42 - Logiciel: Swift Record - (.Swift Record.) [HKLM] -- Swift Record =>PUP.Optional.SwiftRecord O42 - Logiciel: Topaz Adjust 5 - (.Topaz Labs, LLC.) [HKLM] -- Topaz Adjust 5 O42 - Logiciel: Topaz B&W Effects - (.Topaz Labs, LLC.) [HKLM] -- Topaz BW Effects 2 O42 - Logiciel: Topaz Clarity - (.Topaz Labs, LLC.) [HKLM] -- Topaz Clarity O42 - Logiciel: Topaz Clean 3 - (.Topaz Labs, LLC.) [HKLM] -- Topaz Clean 3 O42 - Logiciel: Topaz Fusion Express 2 - (.Topaz Labs.) [HKLM] -- Topaz Fusion Express 2 O42 - Logiciel: Topaz Star Effects - (.Topaz Labs, LLC.) [HKLM] -- Topaz Star Effects O42 - Logiciel: UsbFix - (.El Desaparecido - www.usbfix.net - www.sosvirus.net.) [HKLM] -- Usbfix O42 - Logiciel: VLC media player 1.1.11 - (.VideoLAN.) [HKLM] -- VLC media player O42 - Logiciel: WinRAR archiver - (...) [HKLM] -- WinRAR archiver O42 - Logiciel: AMD Drag and Drop Transcoding - (.Advanced Micro Devices, Inc..) [HKLM] -- {00A876BC-8B69-864D-7F0B-33751D01FE73} O42 - Logiciel: Common Desktop Agent - (.OEM.) [HKLM] -- {031A0E14-0413-4C97-9772-2639B782F46F} O42 - Logiciel: Catalyst Control Center - Branding - (.Advanced Micro Devices, Inc..) [HKLM] -- {25A3B953-1423-3F15-640E-B620DD0F419A} O42 - Logiciel: Java 7 Update 67 - (.Oracle.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83217051FF} O42 - Logiciel: RealUpgrade 1.1 - (.RealNetworks, Inc..) [HKLM] -- {28C2DED6-325B-4CC7-983A-1777C8F7FBAB} O42 - Logiciel: HP Deskjet 1510 series Help - (.Hewlett Packard.) [HKLM] -- {2E25FCEB-EFCB-4696-AA01-D3CBAC721831} O42 - Logiciel: AMD Catalyst Install Manager - (.Advanced Micro Devices, Inc..) [HKLM] -- {319271B3-E2AA-F623-928E-245C9EBF16F7} O42 - Logiciel: Product Improvement Study for HP Deskjet 1510 series - (.Hewlett-Packard Co..) [HKLM] -- {40147F4F-B73E-4C87-A3D3-8BD36F7C77F0} O42 - Logiciel: safeweb - (.safeeWeb.) [HKLM] -- {497C131E-2032-051B-B32A-C69A960FBB13} =>PUP.Optional.Multiplug O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} O42 - Logiciel: AMD Wireless Display v3.0 - (.Advanced Micro Devices, Inc..) [HKLM] -- {7941CEA2-7F1E-89F6-EA85-D885D44371F3} O42 - Logiciel: HP Support Solutions Framework - (.Hewlett-Packard Company.) [HKLM] -- {86FD8326-909D-45F5-BB61-0619D0D31293} O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM] -- {912D30CF-F39E-4B31-AD9A-123C6B794EE2} O42 - Logiciel: AMD Accelerated Video Transcoding - (.Advanced Micro Devices, Inc..) [HKLM] -- {91C62FCC-B36B-78F9-8A46-F6F9C97913A5} O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} O42 - Logiciel: Adobe Reader X (10.1.4) - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1033-7B44-AA1000000001} O42 - Logiciel: COWON Media Center - jetAudio Plus VX - (.COWON.) [HKLM] -- {DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A} O42 - Logiciel: Vegas Pro 11.0 - (.Sony.) [HKLM] -- {E6F012B0-E930-11E0-A67A-F04DA23A5C58} O42 - Logiciel: MSVCRT Redists - (.Sony Creative Software Inc..) [HKLM] -- {E9627240-E930-11E0-8690-F04DA23A5C58} O42 - Logiciel: Light Image Resizer 4.6.3.0 - (.ObviousIdea.) [HKLM] -- {EBE030DD-D404-4D92-85E9-8C3624820808}_is1 O42 - Logiciel: 12.0.0.0 - (.Adobe Photoshop CS5 ME by Magic-M.) [HKLM] -- {FECB3E96-76A8-45A9-B73C-D7304DE02190}_is1 ---\\ HKCU & HKLM Software Keys (105) - 9s HKLM\SOFTWARE\8eb85197-5de5-48f5-a843-5a492e36c4ed =>PUP.Optional.CrossRider HKLM\SOFTWARE\a8c06f18-1b7f-4e5a-a840-77837eb0ea77 =>PUP.Optional.CrossRider HKLM\SOFTWARE\Adobe HKLM\SOFTWARE\AMD HKLM\SOFTWARE\AppDataLow HKLM\SOFTWARE\ATI HKLM\SOFTWARE\ATI Technologies HKLM\SOFTWARE\CDDB HKLM\SOFTWARE\Common Desktop Agent HKLM\SOFTWARE\COWON HKLM\SOFTWARE\GlobalUpdate =>PUP.Optional.GlobalUpdate HKLM\SOFTWARE\Goobzo =>PUP.Optional.Goobzo HKLM\SOFTWARE\Google HKLM\SOFTWARE\Hewlett-Packard HKLM\SOFTWARE\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions HKLM\SOFTWARE\Intel HKLM\SOFTWARE\iWebar =>PUP.Optional.CrossRider HKLM\SOFTWARE\iWebar-nv =>PUP.Optional.CrossRider HKLM\SOFTWARE\iWebar-nv-ie =>PUP.Optional.CrossRider HKLM\SOFTWARE\JavaSoft HKLM\SOFTWARE\JreMetrics HKLM\SOFTWARE\Khronos HKLM\SOFTWARE\Licenses HKLM\SOFTWARE\Macromedia HKLM\SOFTWARE\MimarSinan HKLM\SOFTWARE\Mozilla HKLM\SOFTWARE\mozilla.org HKLM\SOFTWARE\MozillaPlugins HKLM\SOFTWARE\ObviousIdea HKLM\SOFTWARE\ODBC HKLM\SOFTWARE\RealNetworks HKLM\SOFTWARE\RegisteredApplications HKLM\SOFTWARE\RocketLife HKLM\SOFTWARE\Samsung HKLM\SOFTWARE\SensePlus =>PUP.Optional.CrossRider HKLM\SOFTWARE\SensePlus-nv =>PUP.Optional.CrossRider HKLM\SOFTWARE\SensePlus-nv-ie =>PUP.Optional.CrossRider HKLM\SOFTWARE\ShopperPro =>PUP.Optional.ShopperPro HKLM\SOFTWARE\Sonic HKLM\SOFTWARE\Sony Creative Software HKLM\SOFTWARE\SPlayer HKLM\SOFTWARE\SSPrint HKLM\SOFTWARE\Swift Record =>PUP.Optional.SwiftRecord HKLM\SOFTWARE\Topaz Labs HKLM\SOFTWARE\VideoLAN HKLM\SOFTWARE\Visan HKLM\SOFTWARE\Volatile HKLM\SOFTWARE\VST HKLM\SOFTWARE\WinRAR HKLM\SOFTWARE\Xing Technology Corp. HKCU\SOFTWARE\Adobe HKCU\SOFTWARE\AMD HKCU\SOFTWARE\AMD Driver Downloader HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\ATI HKCU\SOFTWARE\Audio Recorder Titanium HKCU\SOFTWARE\CDDB HKCU\SOFTWARE\COWON HKCU\SOFTWARE\DirectShow HKCU\SOFTWARE\Dropbox HKCU\SOFTWARE\DropboxUpdate HKCU\SOFTWARE\drpsu HKCU\SOFTWARE\DSP-worx HKCU\SOFTWARE\globalUpdate =>PUP.Optional.GlobalUpdate HKCU\SOFTWARE\Goobzo =>PUP.Optional.Goobzo HKCU\SOFTWARE\Google HKCU\SOFTWARE\Hewlett-Packard HKCU\SOFTWARE\HP HKCU\SOFTWARE\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions HKCU\SOFTWARE\Intel HKCU\SOFTWARE\iWebar-nv =>PUP.Optional.CrossRider HKCU\SOFTWARE\iWebar-nv-ie =>PUP.Optional.CrossRider HKCU\SOFTWARE\JavaSoft HKCU\SOFTWARE\Joshua F. Madison HKCU\SOFTWARE\KasperskyLab HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\Magicbit HKCU\SOFTWARE\ManiacTools HKCU\SOFTWARE\Mozilla HKCU\SOFTWARE\MozillaPlugins HKCU\SOFTWARE\MultimediaTools HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\ObviousIdea HKCU\SOFTWARE\ODBC HKCU\SOFTWARE\PowerPack HKCU\SOFTWARE\RealNetworks HKCU\SOFTWARE\RegisteredApplicationsEx =>PUP.Optional.SfKpCouponApp HKCU\SOFTWARE\Samsung HKCU\SOFTWARE\SensePlus-nv =>PUP.Optional.CrossRider HKCU\SOFTWARE\SensePlus-nv-ie =>PUP.Optional.CrossRider HKCU\SOFTWARE\ShopperPro =>PUP.Optional.ShopperPro HKCU\SOFTWARE\Sony Creative Software HKCU\SOFTWARE\SSPrint HKCU\SOFTWARE\Swift Record =>PUP.Optional.SwiftRecord HKCU\SOFTWARE\Topaz Labs HKCU\SOFTWARE\TopazLabs HKCU\SOFTWARE\Trolltech HKCU\SOFTWARE\Usbfix HKCU\SOFTWARE\Visan HKCU\SOFTWARE\WinRAR HKCU\SOFTWARE\WinRAR SFX HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Software HKCU\SOFTWARE\AppDataLow\Software\Crossrider =>PUP.Optional.CrossRider HKCU\SOFTWARE\AppDataLow\Software\JavaSoft ---\\ Contents of the Common Files folders (O43) (175) - 9s O43 - CFD: 2015/04/09 12:57:02 - [] D -- C:\Program Files\a88cfe55-f36e-48cc-8323-e1eaf55de942 =>PUP.Optional.CrossRider O43 - CFD: 2014/09/27 17:55:46 - [] D -- C:\Program Files\Adobe O43 - CFD: 2015/04/09 12:57:02 - [] D -- C:\Program Files\AMD O43 - CFD: 2014/09/30 15:23:11 - [] D -- C:\Program Files\AMD AVT O43 - CFD: 2014/03/08 19:29:28 - [] D -- C:\Program Files\ATI O43 - CFD: 2014/09/30 15:21:53 - [] D -- C:\Program Files\ATI Technologies O43 - CFD: 2015/07/06 12:30:49 - [] D -- C:\Program Files\Audio Recorder Titanium O43 - CFD: 2015/04/09 12:55:37 - [] D -- C:\Program Files\Common Files O43 - CFD: 2009/07/14 10:20:43 - [] D -- C:\Program Files\DVD Maker O43 - CFD: 2015/04/09 12:56:52 - [] D -- C:\Program Files\f06584f3-5617-4dd8-bda3-593c20507d55 =>PUP.Optional.CrossRider O43 - CFD: 2015/04/09 12:56:38 - [] D -- C:\Program Files\globalUpdate =>PUP.Optional.GlobalUpdate O43 - CFD: 2014/03/11 19:07:31 - [] D -- C:\Program Files\Google O43 - CFD: 2015/03/22 09:42:07 - [] D -- C:\Program Files\Hewlett-Packard O43 - CFD: 2015/03/22 09:41:50 - [] D -- C:\Program Files\Hp O43 - CFD: 2015/05/23 11:07:42 - [] D -- C:\Program Files\HP Photo Creations O43 - CFD: 2014/03/08 08:05:28 - [] HD -- C:\Program Files\InstallShield Installation Information O43 - CFD: 2009/07/14 07:56:49 - [] D -- C:\Program Files\Internet Explorer O43 - CFD: 2015/05/04 11:49:23 - [] D -- C:\Program Files\iWebar =>PUP.Optional.CrossRider O43 - CFD: 2014/09/30 14:40:32 - [] D -- C:\Program Files\Java O43 - CFD: 2014/05/14 19:35:45 - [] D -- C:\Program Files\JetAudio O43 - CFD: 2014/03/08 08:03:45 - [] D -- C:\Program Files\Microsoft Office O43 - CFD: 2014/03/08 08:03:39 - [] D -- C:\Program Files\Microsoft Visual Studio O43 - CFD: 2014/03/08 08:00:42 - [] D -- C:\Program Files\Microsoft Visual Studio 8 O43 - CFD: 2014/03/08 08:04:05 - [] D -- C:\Program Files\Microsoft Works O43 - CFD: 2014/03/23 17:50:56 - [] D -- C:\Program Files\Microsoft.NET O43 - CFD: 2015/04/21 02:00:03 - [] D -- C:\Program Files\Mozilla Firefox O43 - CFD: 2014/03/08 08:03:52 - [] D -- C:\Program Files\MSBuild O43 - CFD: 2014/07/03 14:45:06 - [] D -- C:\Program Files\ObviousIdea O43 - CFD: 2014/03/08 08:07:37 - [] D -- C:\Program Files\Real O43 - CFD: 2009/07/14 07:52:30 - [] D -- C:\Program Files\Reference Assemblies O43 - CFD: 2015/05/04 21:48:27 - [] D -- C:\Program Files\safeweb =>PUP.Optional.SafeWeb O43 - CFD: 2014/09/07 14:55:12 - [] D -- C:\Program Files\Samsung O43 - CFD: 2014/09/07 15:00:17 - [] D -- C:\Program Files\SamsungPrinterLiveUpdate O43 - CFD: 2014/09/07 14:59:57 - [] D -- C:\Program Files\SamsungPrinterLiveUpdateInstaller O43 - CFD: 2015/05/03 14:41:50 - [] D -- C:\Program Files\SensePlus =>PUP.Optional.CrossRider O43 - CFD: 2015/07/05 00:30:56 - [] D -- C:\Program Files\ShopperPro =>PUP.Optional.ShopperPro O43 - CFD: 2014/03/11 18:25:33 - [] D -- C:\Program Files\Sony O43 - CFD: 2014/09/09 00:40:32 - [] D -- C:\Program Files\SPlayer O43 - CFD: 2015/07/10 14:33:50 - [] D -- C:\Program Files\Swift Record =>PUP.Optional.SwiftRecord O43 - CFD: 2014/09/30 14:19:50 - [] D -- C:\Program Files\Topaz Labs O43 - CFD: 2009/07/14 07:53:23 - [0] HD -- C:\Program Files\Uninstall Information O43 - CFD: 2014/03/08 07:59:57 - [] D -- C:\Program Files\VideoLAN O43 - CFD: 2009/07/14 07:56:49 - [] D -- C:\Program Files\Windows Defender O43 - CFD: 2009/07/14 10:20:39 - [] D -- C:\Program Files\Windows Journal O43 - CFD: 2009/07/14 07:56:49 - [] D -- C:\Program Files\Windows Mail O43 - CFD: 2009/07/14 07:56:49 - [] D -- C:\Program Files\Windows Media Player O43 - CFD: 2009/07/14 07:52:30 - [] D -- C:\Program Files\Windows NT O43 - CFD: 2009/07/14 07:56:49 - [] D -- C:\Program Files\Windows Photo Viewer O43 - CFD: 2009/07/14 07:52:32 - [] D -- C:\Program Files\Windows Portable Devices O43 - CFD: 2009/07/14 07:56:49 - [] D -- C:\Program Files\Windows Sidebar O43 - CFD: 2014/03/08 08:08:29 - [] D -- C:\Program Files\WinRAR O43 - CFD: 2014/03/08 06:47:23 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2014/03/08 08:06:07 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2014/09/27 17:56:17 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5 ME O43 - CFD: 2014/09/30 15:22:40 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center O43 - CFD: 2014/03/08 08:05:33 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COWON Media Center - jetAudio O43 - CFD: 2009/07/14 10:20:51 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 2015/07/05 00:22:22 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome O43 - CFD: 2015/05/23 11:07:44 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP O43 - CFD: 2014/09/30 14:40:32 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java O43 - CFD: 2009/07/14 07:42:30 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2014/03/08 08:06:07 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office O43 - CFD: 2014/03/08 08:00:42 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2005 O43 - CFD: 2014/03/08 08:04:34 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox O43 - CFD: 2014/07/03 14:45:08 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ObviousIdea O43 - CFD: 2014/03/08 08:07:40 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real O43 - CFD: 2014/09/07 14:55:14 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers O43 - CFD: 2014/03/11 18:25:56 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony O43 - CFD: 2014/03/08 08:08:02 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SPlayer O43 - CFD: 2009/07/14 07:41:57 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 2009/07/14 10:20:18 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 2014/09/30 14:21:18 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Topaz Labs O43 - CFD: 2014/03/08 08:00:12 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN O43 - CFD: 2014/03/08 08:08:29 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 2014/03/15 01:22:26 - [] D -- C:\ProgramData\a08d45172cfc7814 O43 - CFD: 2014/09/27 18:01:33 - [] D -- C:\ProgramData\Adobe O43 - CFD: 2014/09/30 15:23:12 - [] D -- C:\ProgramData\AMD O43 - CFD: 2009/07/14 07:53:55 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 2014/09/30 15:27:11 - [] D -- C:\ProgramData\ATI O43 - CFD: 2009/07/14 07:53:55 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 2009/07/14 07:53:55 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 2015/07/05 00:31:17 - [] D -- C:\ProgramData\Dropbox O43 - CFD: 2009/07/14 07:53:55 - [0] SHD -- C:\ProgramData\Favorites O43 - CFD: 2015/05/10 16:34:06 - [] D -- C:\ProgramData\HP O43 - CFD: 2015/05/23 11:07:44 - [] D -- C:\ProgramData\HP Photo Creations O43 - CFD: 2014/03/15 01:20:13 - [] D -- C:\ProgramData\InstallMate O43 - CFD: 2014/03/13 23:37:55 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 2014/03/08 08:06:11 - [] D -- C:\ProgramData\Microsoft Help O43 - CFD: 2014/03/08 08:13:35 - [] D -- C:\ProgramData\MobileBrServ O43 - CFD: 2014/09/30 14:44:56 - [] D -- C:\ProgramData\NVIDIA O43 - CFD: 2014/09/30 14:41:07 - [0] D -- C:\ProgramData\Oracle O43 - CFD: 2014/09/30 15:16:23 - [] D -- C:\ProgramData\Package Cache O43 - CFD: 2015/07/10 14:31:57 - [] D -- C:\ProgramData\Real O43 - CFD: 2014/09/27 18:01:35 - [] D -- C:\ProgramData\regid.1986-12.com.adobe O43 - CFD: 2015/05/04 11:49:28 - [] D -- C:\ProgramData\safeweb =>PUP.Optional.SafeWeb O43 - CFD: 2014/09/07 14:54:24 - [] D -- C:\ProgramData\Samsung O43 - CFD: 2015/07/05 00:22:22 - [] D -- C:\ProgramData\ShopperPro =>PUP.Optional.ShopperPro O43 - CFD: 2014/03/11 18:37:41 - [] D -- C:\ProgramData\Sony O43 - CFD: 2009/07/14 07:53:55 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 2014/03/11 16:28:51 - [] D -- C:\ProgramData\Sun O43 - CFD: 2015/04/25 23:22:38 - [0] AD -- C:\ProgramData\TEMP O43 - CFD: 2009/07/14 07:53:55 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 2015/03/22 09:42:05 - [] D -- C:\ProgramData\Visan O43 - CFD: 2014/09/30 14:15:08 - [] HDC -- C:\ProgramData\{7E8842F4-ECF1-457B-9B22-AA8299B810D9} O43 - CFD: 2014/09/27 18:01:33 - [] D -- C:\Program Files\Common Files\Adobe O43 - CFD: 2014/09/30 15:21:04 - [] D -- C:\Program Files\Common Files\ATI Technologies O43 - CFD: 2014/09/07 14:54:23 - [] D -- C:\Program Files\Common Files\Common Desktop Agent O43 - CFD: 2014/03/08 08:05:34 - [] D -- C:\Program Files\Common Files\COWON O43 - CFD: 2014/03/08 08:03:39 - [] D -- C:\Program Files\Common Files\DESIGNER O43 - CFD: 2014/03/08 08:04:58 - [] D -- C:\Program Files\Common Files\InstallShield O43 - CFD: 2014/09/30 14:40:42 - [] D -- C:\Program Files\Common Files\Java O43 - CFD: 2014/03/08 08:04:02 - [] D -- C:\Program Files\Common Files\microsoft shared O43 - CFD: 2009/07/14 05:37:05 - [] D -- C:\Program Files\Common Files\Services O43 - CFD: 2015/07/05 00:31:12 - [] D -- C:\Program Files\Common Files\ShopperPro =>PUP.Optional.ShopperPro O43 - CFD: 2009/07/14 05:37:05 - [] D -- C:\Program Files\Common Files\SpeechEngines O43 - CFD: 2014/03/08 08:00:21 - [] D -- C:\Program Files\Common Files\System O43 - CFD: 2014/09/30 14:19:31 - [] D -- C:\Program Files\Common Files\Topaz Labs O43 - CFD: 2014/03/08 08:07:34 - [] D -- C:\Program Files\Common Files\xing shared O43 - CFD: 2014/09/30 15:35:00 - [] D -- C:\Users\user\AppData\Roaming\Adobe O43 - CFD: 2015/04/09 12:56:34 - [] D -- C:\Users\user\AppData\Roaming\AdvertismentImages O43 - CFD: 2014/09/30 15:28:50 - [] D -- C:\Users\user\AppData\Roaming\AMD O43 - CFD: 2014/09/30 15:27:11 - [] D -- C:\Users\user\AppData\Roaming\ATI O43 - CFD: 2015/07/06 12:34:25 - [] D -- C:\Users\user\AppData\Roaming\Audio Recorder Titanium O43 - CFD: 2014/09/09 11:28:00 - [0] D -- C:\Users\user\AppData\Roaming\BitTorrent O43 - CFD: 2014/03/11 17:53:36 - [] D -- C:\Users\user\AppData\Roaming\COWON O43 - CFD: 2015/07/10 14:23:24 - [] D -- C:\Users\user\AppData\Roaming\Dropbox O43 - CFD: 2015/03/29 12:57:35 - [] D -- C:\Users\user\AppData\Roaming\HpUpdate O43 - CFD: 2014/03/08 07:43:03 - [] D -- C:\Users\user\AppData\Roaming\Identities O43 - CFD: 2014/03/14 01:10:00 - [] D -- C:\Users\user\AppData\Roaming\Macromedia O43 - CFD: 2009/07/14 10:20:18 - [0] D -- C:\Users\user\AppData\Roaming\Media Center Programs O43 - CFD: 2014/03/14 01:08:46 - [] D -- C:\Users\user\AppData\Roaming\Media Player Classic O43 - CFD: 2015/03/13 16:27:54 - [] SD -- C:\Users\user\AppData\Roaming\Microsoft O43 - CFD: 2014/03/08 19:01:01 - [] D -- C:\Users\user\AppData\Roaming\Mozilla O43 - CFD: 2014/09/28 14:03:31 - [] D -- C:\Users\user\AppData\Roaming\ObviousIdea O43 - CFD: 2014/09/09 00:38:18 - [] D -- C:\Users\user\AppData\Roaming\OpenCandy =>PUP.Optional.OpenCandy O43 - CFD: 2014/03/11 16:29:40 - [] D -- C:\Users\user\AppData\Roaming\Oracle O43 - CFD: 2014/03/11 18:37:39 - [0] D -- C:\Users\user\AppData\Roaming\Publish Providers O43 - CFD: 2015/07/10 14:32:08 - [] D -- C:\Users\user\AppData\Roaming\Real O43 - CFD: 2014/09/07 14:54:25 - [] D -- C:\Users\user\AppData\Roaming\Samsung O43 - CFD: 2014/03/11 21:28:18 - [] D -- C:\Users\user\AppData\Roaming\Sony O43 - CFD: 2014/03/14 02:02:14 - [] D -- C:\Users\user\AppData\Roaming\Sony Creative Software Inc O43 - CFD: 2014/09/09 00:40:32 - [] D -- C:\Users\user\AppData\Roaming\SPlayer O43 - CFD: 2014/07/30 01:58:46 - [] D -- C:\Users\user\AppData\Roaming\vlc O43 - CFD: 2014/03/11 18:23:37 - [] D -- C:\Users\user\AppData\Roaming\WinRAR O43 - CFD: 2015/07/10 15:16:37 - [] D -- C:\Users\user\AppData\Roaming\ZHP O43 - CFD: 2014/09/27 18:51:40 - [] D -- C:\Users\user\AppData\Local\Adobe O43 - CFD: 2014/03/08 07:42:41 - [0] SHD -- C:\Users\user\AppData\Local\Application Data O43 - CFD: 2014/09/30 15:27:11 - [] D -- C:\Users\user\AppData\Local\ATI O43 - CFD: 2014/03/15 01:21:44 - [] D -- C:\Users\user\AppData\Local\Comodo O43 - CFD: 2015/04/09 12:53:41 - [] D -- C:\Users\user\AppData\Local\CrashRpt =>SUP.CrashReports O43 - CFD: 2014/05/12 21:24:11 - [0] D -- C:\Users\user\AppData\Local\Diagnostics O43 - CFD: 2015/07/10 14:37:29 - [] D -- C:\Users\user\AppData\Local\Dropbox O43 - CFD: 2015/07/05 00:54:25 - [0] D -- C:\Users\user\AppData\Local\ElevatedDiagnostics O43 - CFD: 2015/04/09 12:56:37 - [] D -- C:\Users\user\AppData\Local\globalUpdate =>PUP.Optional.GlobalUpdate O43 - CFD: 2014/03/15 01:21:44 - [] D -- C:\Users\user\AppData\Local\Google O43 - CFD: 2014/03/08 07:42:41 - [0] SHD -- C:\Users\user\AppData\Local\History O43 - CFD: 2015/03/22 09:42:48 - [] D -- C:\Users\user\AppData\Local\HP O43 - CFD: 2015/04/09 12:53:44 - [] D -- C:\Users\user\AppData\Local\Installer O43 - CFD: 2015/05/23 11:07:29 - [] D -- C:\Users\user\AppData\Local\Microsoft O43 - CFD: 2015/03/13 16:27:53 - [] D -- C:\Users\user\AppData\Local\Microsoft Help O43 - CFD: 2014/03/08 19:00:59 - [] D -- C:\Users\user\AppData\Local\Mozilla O43 - CFD: 2014/09/30 14:15:07 - [0] D -- C:\Users\user\AppData\Local\PackageAware =>PUP.Optional.BearShare O43 - CFD: 2015/02/10 23:47:51 - [] D -- C:\Users\user\AppData\Local\Programs O43 - CFD: 2014/03/11 18:37:29 - [] D -- C:\Users\user\AppData\Local\Sony O43 - CFD: 2015/07/10 15:15:22 - [] D -- C:\Users\user\AppData\Local\Temp O43 - CFD: 2014/03/08 07:42:41 - [0] SHD -- C:\Users\user\AppData\Local\Temporary Internet Files O43 - CFD: 2014/09/30 15:28:48 - [] D -- C:\Users\user\AppData\Local\Topaz Labs O43 - CFD: 2014/03/15 01:21:44 - [] D -- C:\Users\user\AppData\Local\Torch =>PUP.Optional.Torch O43 - CFD: 2014/12/24 18:27:56 - [] D -- C:\Users\user\AppData\Local\VirtualStore O43 - CFD: 2009/07/14 07:42:04 - [] RD -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2014/03/08 07:43:12 - [] RD -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2009/07/14 07:37:42 - [] RD -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2015/07/10 14:22:50 - [] RD -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 2014/09/30 14:21:18 - [] D -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Topaz Labs O43 - CFD: 2014/03/08 08:08:29 - [] D -- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR ---\\ System Drivers List (SDL) (O58) (81) - 6s O58 - SDL:2011/05/13 19:57:20 A . (.Hewlett-Packard Company - HP Accelerometer.) -- C:\Windows\System32\drivers\Accelerometer.sys [35896] O58 - SDL:2009/07/14 04:26:15 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [422976] O58 - SDL:2009/07/14 04:26:17 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [297552] O58 - SDL:2009/07/14 04:26:15 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\drivers\adpu320.sys [146512] O58 - SDL:2009/07/14 04:26:15 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [14400] O58 - SDL:2014/09/16 01:29:02 A . (.Advanced Micro Devices - AMD ACP Kernel Service Driver.) -- C:\Windows\System32\drivers\amdacpksd.sys [264928] O58 - SDL:2009/07/14 04:26:15 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [79952] O58 - SDL:2009/07/14 04:26:15 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [159312] O58 - SDL:2009/07/14 04:26:15 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [23616] O58 - SDL:2009/07/14 04:26:15 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [76368] O58 - SDL:2009/07/14 04:26:15 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [86608] O58 - SDL:2012/06/20 10:43:02 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\Windows\System32\drivers\athr.sys [2957312] O58 - SDL:2010/05/06 05:21:42 A . (.ATI Technologies, Inc. - ATI High Definition Audio Function Driver.) -- C:\Windows\System32\drivers\AtiHdmi.sys [108560] O58 - SDL:2014/06/21 20:00:20 A . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) -- C:\Windows\System32\drivers\AtihdW73.sys [77824] O58 - SDL:2014/09/16 01:25:30 A . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\System32\drivers\atikmdag.sys [14798336] O58 - SDL:2014/09/16 00:59:00 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\Windows\System32\drivers\atikmpag.sys [463360] O58 - SDL:2009/07/14 01:02:49 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60x.sys [229888] O58 - SDL:2009/07/14 01:53:28 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [13568] O58 - SDL:2009/07/14 01:53:28 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [5248] O58 - SDL:2009/07/14 03:57:25 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [272128] O58 - SDL:2009/07/14 01:53:32 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [62336] O58 - SDL:2009/07/14 01:53:33 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [12160] O58 - SDL:2009/07/14 01:53:33 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [11904] O58 - SDL:2009/07/14 01:02:48 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbdx.sys [430080] O58 - SDL:2009/07/14 04:26:21 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [15952] O58 - SDL:2009/07/14 04:20:28 A . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\drivers\djsvs.sys [70720] O58 - SDL:2009/07/14 04:20:28 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [453712] O58 - SDL:2009/07/14 01:02:48 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbdx.sys [3100160] O58 - SDL:2009/07/14 01:54:14 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [26624] O58 - SDL:2009/09/17 20:54:14 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\drivers\HECI.sys [41088] O58 - SDL:2011/05/13 19:57:42 A . (.Hewlett-Packard Company - HP Disk Filter - SATA/RAID.) -- C:\Windows\System32\drivers\hpdskflt.sys [25656] O58 - SDL:2009/07/14 04:20:28 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [67152] O58 - SDL:2009/07/14 04:20:36 A . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\drivers\iaStorV.sys [332352] O58 - SDL:2009/07/14 04:20:36 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [41040] O58 - SDL:2009/07/14 04:20:36 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [95824] O58 - SDL:2009/07/14 04:20:37 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [89168] O58 - SDL:2009/07/14 04:20:36 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [54864] O58 - SDL:2009/07/14 04:20:36 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [96848] O58 - SDL:2009/07/14 04:20:36 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [30800] O58 - SDL:2009/07/14 04:20:36 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [235584] O58 - SDL:2009/07/14 04:20:44 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [44624] O58 - SDL:2009/07/14 04:20:44 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [117312] O58 - SDL:2009/07/14 04:20:44 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [142416] O58 - SDL:2009/07/14 04:19:04 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1383488] O58 - SDL:2009/07/14 04:19:04 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [106064] O58 - SDL:2011/06/10 07:34:52 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.20 32-bit Dr.) -- C:\Windows\System32\drivers\Rt86win7.sys [394856] O58 - SDL:2009/07/13 23:50:20 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [20480] O58 - SDL:2009/07/14 04:19:04 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [40016] O58 - SDL:2009/07/14 04:19:04 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [77888] O58 - SDL:2013/04/10 12:38:16 A . (.Samsung Electronics - 32bit Port Contention Driver.) -- C:\Windows\System32\drivers\SSPORT.SYS [5120] O58 - SDL:2009/07/14 04:19:04 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [21072] O58 - SDL:2009/07/14 04:19:10 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [16976] O58 - SDL:2009/07/14 04:19:11 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [141904] O58 - SDL:2015/04/26 23:05:38 A . (.StdLib - StdLib.) -- C:\Windows\System32\drivers\{033a8c6f-862d-4347-b28e-fa9ff3a16aca}Gw.sys [43152] =>PUP.Optional.LinkiDoo O58 - SDL:2015/04/20 11:05:56 A . (.StdLib - StdLib.) -- C:\Windows\System32\drivers\{2c5699ec-85f1-4ae8-892b-4feb9efc1813}Gw.sys [43152] =>PUP.Optional.LinkiDoo O58 - SDL:2015/05/06 04:06:18 A . (.StdLib - StdLib.) -- C:\Windows\System32\drivers\{361bdfbd-a59f-41fc-9013-7d7dfdba60ef}Gw.sys [43152] =>PUP.Optional.LinkiDoo O58 - SDL:2015/04/25 08:06:28 A . (.StdLib - StdLib.) -- C:\Windows\System32\drivers\{575b3a04-506c-436e-a31c-1cf303fdf32b}Gw.sys [43152] =>PUP.Optional.LinkiDoo O58 - SDL:2015/07/04 12:47:04 A . (.StdLib - StdLib.) -- C:\Windows\System32\drivers\{64b5be32-7185-4edd-8c8b-6f2cd5600942}w.sys [43152] =>PUP.Optional.LinkiDoo O58 - SDL:2015/05/09 22:41:08 A . (.StdLib - StdLib.) -- C:\Windows\System32\drivers\{6df2f73e-17d8-40e2-a697-ff95eaa0ed40}Gw.sys [43152] =>PUP.Optional.LinkiDoo O58 - SDL:2015/07/06 03:58:00 A . (.StdLib - StdLib.) -- C:\Windows\System32\drivers\{842cb8d9-206d-4bdf-809e-de5abc49f58c}w.sys [43152] =>PUP.Optional.LinkiDoo O58 - SDL:2015/04/17 18:05:08 A . (.StdLib - StdLib.) -- C:\Windows\System32\drivers\{86495074-1e01-4c57-b1c7-869ad9007a9b}Gw.sys [43152] =>PUP.Optional.LinkiDoo O58 - SDL:2015/04/29 16:07:34 A . (.StdLib - StdLib.) -- C:\Windows\System32\drivers\{a39d17ac-a52f-4ea6-9251-3e4afb5f49e5}Gw.sys [43152] =>PUP.Optional.LinkiDoo O58 - SDL:2015/04/09 02:28:32 A . (.StdLib - StdLib.) -- C:\Windows\System32\drivers\{d2987c5a-d6d8-46af-82d2-c3c2c88502d8}Gw.sys [43152] =>PUP.Optional.LinkiDoo O58 - SDL:2015/07/10 03:12:28 A . (.StdLib - StdLib.) -- C:\Windows\System32\drivers\{e619bb08-669f-48b4-9f56-5b7bf92c838a}w.sys [43152] =>PUP.Optional.LinkiDoo O58 - SDL:2015/05/02 22:03:08 A . (.StdLib - StdLib.) -- C:\Windows\System32\drivers\{e8f0b08d-0e23-4874-b486-b0090bc03fe5}Gw.sys [43152] =>PUP.Optional.LinkiDoo O58 - SDL:2015/04/12 21:13:58 A . (.StdLib - StdLib.) -- C:\Windows\System32\drivers\{ebea2f01-162e-499b-ad18-028f0259de6f}Gw.sys [43152] =>PUP.Optional.LinkiDoo O58 - SDL:2009/07/14 00:40:41 A . (...) -- C:\Windows\System32\ANSI.SYS [9029] O58 - SDL:2009/07/14 00:40:44 A . (...) -- C:\Windows\System32\country.sys [27097] O58 - SDL:2009/07/14 00:40:40 A . (...) -- C:\Windows\System32\HIMEM.SYS [4768] O58 - SDL:2009/07/14 00:40:43 A . (...) -- C:\Windows\System32\KEY01.SYS [42809] O58 - SDL:2009/07/14 00:40:43 A . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537] O58 - SDL:2009/07/14 00:40:23 A . (...) -- C:\Windows\System32\NTDOS.SYS [27866] O58 - SDL:2009/07/14 00:40:31 A . (...) -- C:\Windows\System32\NTDOS404.SYS [29146] O58 - SDL:2009/07/14 00:40:35 A . (...) -- C:\Windows\System32\NTDOS411.SYS [29370] O58 - SDL:2009/07/14 00:40:39 A . (...) -- C:\Windows\System32\NTDOS412.SYS [29274] O58 - SDL:2009/07/14 00:40:27 A . (...) -- C:\Windows\System32\NTDOS804.SYS [29146] O58 - SDL:2009/07/14 00:40:11 A . (...) -- C:\Windows\System32\NTIO.SYS [33952] O58 - SDL:2009/07/14 00:40:15 A . (...) -- C:\Windows\System32\NTIO404.SYS [34672] O58 - SDL:2009/07/14 00:40:17 A . (...) -- C:\Windows\System32\NTIO411.SYS [35776] O58 - SDL:2009/07/14 00:40:19 A . (...) -- C:\Windows\System32\NTIO412.SYS [35536] O58 - SDL:2009/07/14 00:40:13 A . (...) -- C:\Windows\System32\NTIO804.SYS [34672] ---\\ Last modified or created user files (O61) (10) - 39s O61 - LFC: 2015/07/06 19:46:38 A . (..) -- C:\Users\user\AppData\Local\Sony\Vegas Pro\11.0\OCL 46ffaa7c-2c510734.bin [208556] O61 - LFC: 2015/07/06 19:46:32 A . (..) -- C:\Users\user\AppData\Local\Sony\Vegas Pro\11.0\OCL 46ffaa7c-6b8263d9.bin [24996] O61 - LFC: 2015/07/06 19:46:30 A . (..) -- C:\Users\user\AppData\Local\Sony\Vegas Pro\11.0\OCL 46ffaa7c-8e537d5e.bin [148724] O61 - LFC: 2015/07/06 19:46:58 A . (..) -- C:\Users\user\AppData\Local\Sony\Vegas Pro\11.0\OCL 46ffaa7c-a1aad1e0.bin [27348] O61 - LFC: 2015/07/06 19:46:28 A . (..) -- C:\Users\user\AppData\Local\Sony\Vegas Pro\11.0\OCL 46ffaa7c-a3b0af79.bin [15216] O61 - LFC: 2015/07/06 19:46:41 A . (..) -- C:\Users\user\AppData\Local\Sony\Vegas Pro\11.0\OCL 46ffaa7c-dffdca54.bin [23436] O61 - LFC: 2015/07/06 19:46:44 A . (..) -- C:\Users\user\AppData\Local\Sony\Vegas Pro\11.0\OCL 46ffaa7c-e7a700ba.bin [28588] O61 - LFC: 2015/07/06 13:31:28 A . (..) -- C:\Users\user\AppData\Local\Sony\Vegas Pro\11.0\svfx_plugin_cache.bin [17498] O61 - LFC: 2015/07/10 14:35:26 A . (..) -- C:\Users\user\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [1113849] O61 - LFC: 2015/07/10 14:32:13 A . (..) -- C:\Users\user\AppData\Local\ATI\ACE\Manifest.Bin [30042] ---\\ File Associations Shell Spawning (O67) (9) - 1s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S ---\\ Start Menu Internet (SMI) (O68) (12) - 0s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe ---\\ Search Browser Infection (SBI) (O69) (1) - 2s O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ ---\\ Search Svchost Services (SSS) (O83) (33) - 2s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\Windows\System32\aelupsvc.dll [62464] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [67584] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [67584] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\Windows\System32\srvsvc.dll [168448] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\Windows\System32\gpsvc.dll [591360] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\IKEEXT.DLL [667136] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\Windows\System32\audiosrv.dll [473088] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\Windows\System32\rasauto.dll [90624] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [285184] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [75264] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\Windows\System32\Sens.dll [49664] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [300544] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [241664] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remote Desktop Session Host Server Remote C.) -- C:\Windows\System32\termsrv.dll [543232] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\System32\wuaueng.dll [1933848] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\Windows\System32\qmgr.dll [589312] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [328192] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [497152] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\Windows\System32\seclogon.dll [21504] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\Windows\System32\appinfo.dll [46592] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\Windows\System32\iscsiexe.dll [114688] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) -- C:\Windows\System32\mmcss.dll [49664] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\Windows\System32\wercplsupport.dll [61440] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [98304] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [162816] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\Windows\System32\schedsvc.dll [743424] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\Windows\System32\KMSVC.DLL [71168] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [99328] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\Windows\System32\browser.dll [102400] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\Windows\System32\themeservice.dll [37376] O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\Windows\System32\bdesvc.dll [76800] O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Software installation Service.) -- C:\Windows\System32\appmgmts.dll [149504] ---\\ General States of Services not Microsoft (EGS) (SR=Running, SS=Stopped) (12) - 25s SR - Auto [2012/07/27 23:51:26] [ 63960] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe SR - Auto [2014/09/16 01:03:16] [ 208896] (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe SS - Auto [2015/04/09 12:56:37] [ 68608] globalUpdate Update Service (globalUpdate) (globalUpdate) . (.globalUpdate.) - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe SS - Demand [2015/04/09 12:56:37] [ 68608] globalUpdate Update Service (globalUpdatem) (globalUpdatem) . (.globalUpdate.) - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe SS - Auto [2014/03/08 19:02:22] [ 116648] ÎÏãÉ Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe SS - Demand [2014/03/08 19:02:22] [ 116648] ÎÏãÉ Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe SR - Auto [2011/05/13 19:57:36] [ 26168] HP Service (hpsrv) . (.Hewlett-Packard Company.) - C:\Windows\System32\Hpservice.exe SR - Auto [2014/02/05 15:39:00] [ 47416] HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) . (.Hewlett-Packard Company.) - C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe SR - Auto [2012/03/12 12:05:33] [ 232288] Mobile Broadband HL Service (Mobile Broadband HL Service) . (.Copyright (C) 2012.) - C:\ProgramData\MobileBrServ\mbbservice.exe SR - Auto [2015/07/02 08:08:58] [ 1813504] ShopperPro Update (SPBIUpd) . (.ShopperPro.) - C:\Program Files\Common Files\ShopperPro\spbiu.exe SR - Auto [2015/07/10 14:33:32] [ 474352] Update Swift Record (Update Swift Record) . (...) - C:\Program Files\Swift Record\updateSwiftRecord.exe SR - Auto [2015/07/10 13:52:01] [ 474352] Util Swift Record (Util Swift Record) . (...) - C:\Program Files\Swift Record\bin\utilSwiftRecord.exe ---\\ Search Tracing Registry Key (O100) (8) - 5s HKLM\SOFTWARE\Microsoft\Tracing\RegistryReviver_RASAPI32 =>PUP.Optional.RegistryReviver HKLM\SOFTWARE\Microsoft\Tracing\RegistryReviver_RASMANCS =>PUP.Optional.RegistryReviver HKLM\SOFTWARE\Microsoft\Tracing\ShopperPro_RASAPI32 =>PUP.Optional.ShopperPro HKLM\SOFTWARE\Microsoft\Tracing\ShopperPro_RASMANCS =>PUP.Optional.ShopperPro HKLM\SOFTWARE\Microsoft\Tracing\SwiftRecord_RASAPI32 =>PUP.Optional.SwiftRecord HKLM\SOFTWARE\Microsoft\Tracing\SwiftRecord_RASMANCS =>PUP.Optional.SwiftRecord HKLM\SOFTWARE\Microsoft\Tracing\SwiftRecord_Setup_RASAPI32 =>PUP.Optional.SwiftRecord HKLM\SOFTWARE\Microsoft\Tracing\SwiftRecord_Setup_RASMANCS =>PUP.Optional.SwiftRecord ---\\ Additional Scan (O88) (125) - 0s C:\Program Files\iWebar\50e2eba1-c248-41fe-b755-1c97d900606c-6.exe =>PUP.Optional.CrossRider C:\Program Files\iWebar\50e2eba1-c248-41fe-b755-1c97d900606c-1-6.exe =>PUP.Optional.CrossRider C:\Program Files\SensePlus\7061973a-9457-4c07-abc3-36fc40507147-6.exe =>PUP.Optional.CrossRider C:\Program Files\SensePlus\7061973a-9457-4c07-abc3-36fc40507147-1-6.exe =>PUP.Optional.CrossRider C:\Program Files\Common Files\ShopperPro\spbiu.exe =>PUP.Optional.ShopperPro C:\Program Files\Swift Record\bin\utilSwiftRecord.exe =>PUP.Optional.SwiftRecord C:\Program Files\ShopperPro\JSDriver\1.42.1.2069\jsdrv.exe =>PUP.Optional.ShopperPro C:\Program Files\Swift Record\updateSwiftRecord.exe =>PUP.Optional.SwiftRecord C:\Program Files\Swift Record\bin\SwiftRecord.BrowserAdapter.exe =>PUP.Optional.SwiftRecord C:\Program Files\Swift Record\bin\SwiftRecord.expext.exe =>PUP.Optional.SwiftRecord C:\Program Files\Swift Record\bin\SwiftRecord.PurBrowse.exe =>PUP.Optional.SwiftRecord C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\hppdcdfhpfelinnjbddccbgplfdapmbi C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\offledjhohfjkfefaaljadpjjmnjcncp C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll =>PUP.Optional.GlobalUpdate C:\Program Files\Swift Record\SwiftRecordbho.dll =>PUP.Optional.SwiftRecord HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0759d61f-3673-416f-85d2-58b847e78ddf} =>PUP.Optional.SwiftRecord C:\ProgramData\ShopperPro\ShopperPro.dll =>PUP.Optional.ShopperPro HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} =>PUP.Optional.ShopperPro HKLM\SYSTEM\CurrentControlSet\Services\globalUpdate =>PUP.Optional.GlobalUpdate C:\Program Files\globalUpdate\Update\GoogleUpdate.exe =>PUP.Optional.GlobalUpdate HKLM\SYSTEM\CurrentControlSet\Services\SPBIUpd =>PUP.Optional.ShopperPro HKLM\SYSTEM\CurrentControlSet\Services\Update Swift Record =>PUP.Optional.SwiftRecord HKLM\SYSTEM\CurrentControlSet\Services\Util Swift Record =>PUP.Optional.SwiftRecord C:\Program Files\iWebar\50e2eba1-c248-41fe-b755-1c97d900606c-4.exe =>PUP.Optional.CrossRider C:\Program Files\iWebar\50e2eba1-c248-41fe-b755-1c97d900606c-5.exe =>PUP.Optional.CrossRider C:\Program Files\SensePlus\7061973a-9457-4c07-abc3-36fc40507147-4.exe =>PUP.Optional.CrossRider C:\Program Files\SensePlus\7061973a-9457-4c07-abc3-36fc40507147-5.exe =>PUP.Optional.CrossRider C:\Program Files\ShopperPro\ShopperPro.exe =>PUP.Optional.ShopperPro C:\Program Files\ShopperPro\Updater.exe =>PUP.Optional.ShopperPro C:\Windows\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-1-6.job =>PUP.Optional.CrossRider C:\Windows\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-1-7.job =>PUP.Optional.CrossRider C:\Windows\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-4.job =>PUP.Optional.CrossRider C:\Windows\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-5.job =>PUP.Optional.CrossRider C:\Windows\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-5_user.job =>PUP.Optional.CrossRider C:\Windows\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-6.job =>PUP.Optional.CrossRider C:\Windows\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-7.job =>PUP.Optional.CrossRider C:\Windows\Tasks\7061973a-9457-4c07-abc3-36fc40507147-1-6.job =>PUP.Optional.CrossRider C:\Windows\Tasks\7061973a-9457-4c07-abc3-36fc40507147-1-7.job =>PUP.Optional.CrossRider C:\Windows\Tasks\7061973a-9457-4c07-abc3-36fc40507147-4.job =>PUP.Optional.CrossRider C:\Windows\Tasks\7061973a-9457-4c07-abc3-36fc40507147-5.job =>PUP.Optional.CrossRider C:\Windows\Tasks\7061973a-9457-4c07-abc3-36fc40507147-5_user.job =>PUP.Optional.CrossRider C:\Windows\Tasks\7061973a-9457-4c07-abc3-36fc40507147-6.job =>PUP.Optional.CrossRider C:\Windows\Tasks\7061973a-9457-4c07-abc3-36fc40507147-7.job =>PUP.Optional.CrossRider C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job =>PUP.Optional.GlobalUpdate C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job =>PUP.Optional.GlobalUpdate C:\Windows\System32\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-1-6 =>PUP.Optional.CrossRider C:\Windows\System32\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-4 =>PUP.Optional.CrossRider C:\Windows\System32\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-5 =>PUP.Optional.CrossRider C:\Windows\System32\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-5_user =>PUP.Optional.CrossRider C:\Windows\System32\Tasks\50e2eba1-c248-41fe-b755-1c97d900606c-6 =>PUP.Optional.CrossRider C:\Windows\System32\Tasks\7061973a-9457-4c07-abc3-36fc40507147-1-6 =>PUP.Optional.CrossRider C:\Windows\System32\Tasks\7061973a-9457-4c07-abc3-36fc40507147-4 =>PUP.Optional.CrossRider C:\Windows\System32\Tasks\7061973a-9457-4c07-abc3-36fc40507147-5 =>PUP.Optional.CrossRider C:\Windows\System32\Tasks\7061973a-9457-4c07-abc3-36fc40507147-5_user =>PUP.Optional.CrossRider C:\Windows\System32\Tasks\7061973a-9457-4c07-abc3-36fc40507147-6 =>PUP.Optional.CrossRider C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore =>PUP.Optional.GlobalUpdate C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA =>PUP.Optional.GlobalUpdate C:\Windows\System32\Tasks\ShopperPro =>PUP.Optional.ShopperPro C:\Windows\System32\Tasks\ShopperProJSUpd =>PUP.Optional.ShopperPro HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iWebar =>PUP.Optional.CrossRider HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SensePlus =>PUP.Optional.CrossRider HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopperPro =>PUP.Optional.ShopperPro HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Swift Record =>PUP.Optional.SwiftRecord HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{497C131E-2032-051B-B32A-C69A960FBB13} =>PUP.Optional.Multiplug HKLM\SOFTWARE\GlobalUpdate =>PUP.Optional.GlobalUpdate HKLM\SOFTWARE\Goobzo =>PUP.Optional.Goobzo HKLM\SOFTWARE\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions HKLM\SOFTWARE\iWebar =>PUP.Optional.CrossRider HKLM\SOFTWARE\iWebar-nv =>PUP.Optional.CrossRider HKLM\SOFTWARE\iWebar-nv-ie =>PUP.Optional.CrossRider HKLM\SOFTWARE\SensePlus =>PUP.Optional.CrossRider HKLM\SOFTWARE\SensePlus-nv =>PUP.Optional.CrossRider HKLM\SOFTWARE\SensePlus-nv-ie =>PUP.Optional.CrossRider HKLM\SOFTWARE\ShopperPro =>PUP.Optional.ShopperPro HKLM\SOFTWARE\Swift Record =>PUP.Optional.SwiftRecord HKCU\SOFTWARE\globalUpdate =>PUP.Optional.GlobalUpdate HKCU\SOFTWARE\Goobzo =>PUP.Optional.Goobzo HKCU\SOFTWARE\InstalledBrowserExtensions =>PUP.Optional.BrowserExtensions HKCU\SOFTWARE\iWebar-nv =>PUP.Optional.CrossRider HKCU\SOFTWARE\iWebar-nv-ie =>PUP.Optional.CrossRider HKCU\SOFTWARE\RegisteredApplicationsEx =>PUP.Optional.SfKpCouponApp HKCU\SOFTWARE\SensePlus-nv =>PUP.Optional.CrossRider HKCU\SOFTWARE\SensePlus-nv-ie =>PUP.Optional.CrossRider HKCU\SOFTWARE\ShopperPro =>PUP.Optional.ShopperPro HKCU\SOFTWARE\Swift Record =>PUP.Optional.SwiftRecord HKCU\SOFTWARE\AppDataLow\Software\Crossrider =>PUP.Optional.CrossRider =>PUP.Optional.CrossRider C:\Program Files\a88cfe55-f36e-48cc-8323-e1eaf55de942 =>PUP.Optional.CrossRider C:\Program Files\f06584f3-5617-4dd8-bda3-593c20507d55 =>PUP.Optional.CrossRider C:\Program Files\globalUpdate =>PUP.Optional.GlobalUpdate C:\Program Files\iWebar =>PUP.Optional.CrossRider C:\Program Files\safeweb =>PUP.Optional.SafeWeb C:\Program Files\SensePlus =>PUP.Optional.CrossRider C:\Program Files\ShopperPro =>PUP.Optional.ShopperPro C:\Program Files\Swift Record =>PUP.Optional.SwiftRecord C:\ProgramData\safeweb =>PUP.Optional.SafeWeb C:\ProgramData\ShopperPro =>PUP.Optional.ShopperPro C:\Program Files\Common Files\ShopperPro =>PUP.Optional.ShopperPro C:\Users\user\AppData\Roaming\OpenCandy =>PUP.Optional.OpenCandy C:\Users\user\AppData\Local\CrashRpt =>SUP.CrashReports C:\Users\user\AppData\Local\globalUpdate =>PUP.Optional.GlobalUpdate C:\Users\user\AppData\Local\PackageAware =>PUP.Optional.BearShare C:\Users\user\AppData\Local\Torch =>PUP.Optional.Torch C:\Windows\System32\drivers\{033a8c6f-862d-4347-b28e-fa9ff3a16aca}Gw.sys =>PUP.Optional.LinkiDoo C:\Windows\System32\drivers\{2c5699ec-85f1-4ae8-892b-4feb9efc1813}Gw.sys =>PUP.Optional.LinkiDoo C:\Windows\System32\drivers\{361bdfbd-a59f-41fc-9013-7d7dfdba60ef}Gw.sys =>PUP.Optional.LinkiDoo C:\Windows\System32\drivers\{575b3a04-506c-436e-a31c-1cf303fdf32b}Gw.sys =>PUP.Optional.LinkiDoo C:\Windows\System32\drivers\{64b5be32-7185-4edd-8c8b-6f2cd5600942}w.sys =>PUP.Optional.LinkiDoo C:\Windows\System32\drivers\{6df2f73e-17d8-40e2-a697-ff95eaa0ed40}Gw.sys =>PUP.Optional.LinkiDoo C:\Windows\System32\drivers\{842cb8d9-206d-4bdf-809e-de5abc49f58c}w.sys =>PUP.Optional.LinkiDoo C:\Windows\System32\drivers\{86495074-1e01-4c57-b1c7-869ad9007a9b}Gw.sys =>PUP.Optional.LinkiDoo C:\Windows\System32\drivers\{a39d17ac-a52f-4ea6-9251-3e4afb5f49e5}Gw.sys =>PUP.Optional.LinkiDoo C:\Windows\System32\drivers\{d2987c5a-d6d8-46af-82d2-c3c2c88502d8}Gw.sys =>PUP.Optional.LinkiDoo C:\Windows\System32\drivers\{e619bb08-669f-48b4-9f56-5b7bf92c838a}w.sys =>PUP.Optional.LinkiDoo C:\Windows\System32\drivers\{e8f0b08d-0e23-4874-b486-b0090bc03fe5}Gw.sys =>PUP.Optional.LinkiDoo C:\Windows\System32\drivers\{ebea2f01-162e-499b-ad18-028f0259de6f}Gw.sys =>PUP.Optional.LinkiDoo HKLM\SYSTEM\CurrentControlSet\Services\globalUpdatem =>PUP.Optional.GlobalUpdate HKLM\SOFTWARE\Microsoft\Tracing\RegistryReviver_RASAPI32 =>PUP.Optional.RegistryReviver HKLM\SOFTWARE\Microsoft\Tracing\RegistryReviver_RASMANCS =>PUP.Optional.RegistryReviver HKLM\SOFTWARE\Microsoft\Tracing\ShopperPro_RASAPI32 =>PUP.Optional.ShopperPro HKLM\SOFTWARE\Microsoft\Tracing\ShopperPro_RASMANCS =>PUP.Optional.ShopperPro HKLM\SOFTWARE\Microsoft\Tracing\SwiftRecord_RASAPI32 =>PUP.Optional.SwiftRecord HKLM\SOFTWARE\Microsoft\Tracing\SwiftRecord_RASMANCS =>PUP.Optional.SwiftRecord HKLM\SOFTWARE\Microsoft\Tracing\SwiftRecord_Setup_RASAPI32 =>PUP.Optional.SwiftRecord HKLM\SOFTWARE\Microsoft\Tracing\SwiftRecord_Setup_RASMANCS =>PUP.Optional.SwiftRecord ---\\ Summary of the detections found on your workstation (16) - 0s http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider http://www.nicolascoolman.fr/pup-shopperpro/ =>PUP.Optional.ShopperPro http://www.nicolascoolman.fr/blog =>PUP.Optional.SwiftRecord http://www.nicolascoolman.fr/adware-bandoo/ =>PUP.Optional.Bandoo http://www.nicolascoolman.fr/pup-mutiplug/ =>PUP.Optional.Multiplug http://www.nicolascoolman.fr/pup-globalupdate/ =>PUP.Optional.GlobalUpdate http://www.nicolascoolman.fr/pup-goobzo/ =>PUP.Optional.Goobzo http://www.nicolascoolman.fr/blog =>PUP.Optional.BrowserExtensions http://www.nicolascoolman.fr/blog =>PUP.Optional.SfKpCouponApp http://www.nicolascoolman.fr/pup-safeweb/ =>PUP.Optional.SafeWeb http://www.nicolascoolman.fr/adware-opencandy/ =>PUP.Optional.OpenCandy http://www.nicolascoolman.fr/blog =>SUP.CrashReports http://www.nicolascoolman.fr/pup-bearshare/ =>PUP.Optional.BearShare http://www.nicolascoolman.fr/blog =>PUP.Optional.Torch http://www.nicolascoolman.fr/pup-linkidoo/ =>PUP.Optional.LinkiDoo http://www.nicolascoolman.fr/blog =>PUP.Optional.RegistryReviver ~ End of the scan, 25148 items in 121 seconds (858)(0)()