~ ZHPDiag v2015.8.31.131 By Nicolas Coolman (2015/08/31) ~ Run by donotdisturb (Administrator) (2015/09/01 17:16:26) ~ Web: http://www.nicolascoolman.fr ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ State version: Version OK ~ Mode: Scan ~ Report: C:\Users\donotdisturb\Desktop\ZHPDiag.txt ~ Report: C:\Users\donotdisturb\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ System startup: Normal (Normal boot) Windows 8.1, 64-bit (Build 9600) ---\\ Internet Browsers (1) - 0s MSIE: Internet Explorer v11.0.9600.17937 ---\\ Windows Product Information (4) - 6s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK (Demand) Windows Activation Technologies : OK ---\\ System protection software (3) - 1s Computer Security 14.139.100.0 Malwarebytes Anti-Malware version 2.1.8.1057 Windows Defender (Deactivate) ---\\ System protection software (Superfluous) (1) - 1s SUPERAntiSpyware v6.0.1204 ---\\ System optimization software (1) - 1s CCleaner v5.07 ---\\ Surveillance software (1) - 1s Adobe Reader XI ---\\ Information on the system (6) - 0s ~ Operating System: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel ~ Operating System: 64-bit ~ Boot mode: Normal (Normal boot) Total RAM: 7495.248 MB (76% free) ~ System Restore: Activé (Enable) ~ System drive C: has 805 GB free of 849 GB ---\\ Connection to the system mode (3) - 0s ~ Computer Name: DINAUSUREZZZZZ ~ User Name: donotdisturb ~ Logged in as Administrator ---\\ Enumeration of the disk units (2) - 0s ~ Drive C: has 805 GB free of 849 GB (System) ~ Drive D: has 78 GB free of 81 GB ---\\ State of the Windows Security Center (11) - 0s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ---\\ Search Generic System Files (22) - 1s [MD5.C10A66189DC8C090E7C84873EDCEBC88] - (.Microsoft Corporation - Utforskaren.) () -- C:\WINDOWS\Explorer.exe [2501368] © [MD5.6C308D32AFA41D26CE2A0EA8F7B79565] - (.Microsoft Corporation - Windows-värdprocess (Rundll32).) () -- C:\WINDOWS\System32\rundll32.exe [54784] © [MD5.A570A64292214C43E0BA50E6A72A6380] - (.Microsoft Corporation - Startprogrammet i Windows.) () -- C:\WINDOWS\System32\Wininit.exe [145920] © [MD5.C555B5C8142844DED9E3BD94E6313000] - (.Microsoft Corporation - Internettillbehör för Win32.) () -- C:\WINDOWS\System32\wininet.dll [2427904] © [MD5.EC498BAE1F0D3E0E401C963F8D76C437] - (.Microsoft Corporation - Inloggningsprogram för Windows.) () -- C:\WINDOWS\System32\Winlogon.exe [572416] © [MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - (.Microsoft Corporation - Bibliotek för programvarulicensiering.) () -- C:\WINDOWS\System32\sppcomapi.dll [447488] © [MD5.374E27295F0A9DCAA8FC96370F9BEEA5] - (.Microsoft Corporation - Ancillary Function Driver för WinSock.) () -- C:\WINDOWS\System32\drivers\AFD.sys [563200] © [MD5.74B14192CF79A72F7536B27CB8814FBD] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\WINDOWS\System32\drivers\atapi.sys [26464] © [MD5.2FA6510E33F7DEFEC03658B74101A9B9] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\WINDOWS\System32\drivers\Cdfs.sys [88576] © [MD5.C6796EA22B513E3457514D92DCDB1A3D] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\WINDOWS\System32\drivers\Cdrom.sys [164352] © [MD5.A03F362C5557E238CBFA914689C77248] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\WINDOWS\System32\drivers\DfsC.sys [134144] © [MD5.D4B7ED39C7900384D9E5C1283F1E7926] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\WINDOWS\System32\drivers\HDAudBus.sys [76800] © [MD5.49EE0AE9E5B64FFBBD06D55C4984B598] - (.Microsoft Corporation - Drivrutin för i8042 Port.) () -- C:\WINDOWS\System32\drivers\i8042prt.sys [108544] © [MD5.B7342B3C58E91107F6E946A93D9D4EFD] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\WINDOWS\System32\drivers\IpNat.sys [142848] © [MD5.6FBDF2B1B025A8E6E069234362FFFFB7] - (.Microsoft Corporation - Windows NT SMB Minirdr.) () -- C:\WINDOWS\System32\drivers\MRxSmb.sys [401408] © [MD5.0217532E19A748F0E5D569307363D5FD] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\WINDOWS\System32\drivers\netBT.sys [282624] © [MD5.7F68063A5A0461E02BC860CE0E6BFDDC] - (.Microsoft Corporation - NTFS-drivrutin.) () -- C:\WINDOWS\System32\drivers\ntfs.sys [2025792] © [MD5.764B1121867B2D9B31C491668AC72B2B] - (.Microsoft Corporation - Drivrutin för parallellport.) () -- C:\WINDOWS\System32\drivers\Parport.sys [94208] © [MD5.1BD3022FD6E450B00DE560265638FD2A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [112640] © [MD5.680C1DAE268B6FB67FA21B389A8B79EF] - (.Microsoft Corporation - Microsoft RDP Device redirector.) () -- C:\WINDOWS\System32\drivers\rdpdr.sys [195584] © [MD5.FFF28F9F6823EB1756C60F1649560BBF] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\WINDOWS\System32\drivers\tdx.sys [107520] © [MD5.64CA2B4A49A8EAF495E435623ECCE7DB] - (.Microsoft Corporation - Drivrutin för skuggkopior av volymer.) () -- C:\WINDOWS\System32\drivers\volsnap.sys [310080] © ---\\ Process running (45) - 1s [MD5.FB50E60564ED30DDC855F0CE435C8467] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 327.0.) -- C:\WINDOWS\system32\nvvsvc.exe [920864] [PID.312] © [MD5.970C70F6B2953ED43822D3797855D84C] - (.SUPERAntiSpyware.com - Core Service.) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344] [PID.1736] [MD5.ADDA5E1951B90D3D23C56D3CF0622ADC] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65640] [PID.1752] © [MD5.8CA064F79E25CE0B63B1552912042667] - (.Windows (R) Win 7 DDK provider - Windows Setup API.) -- C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [323152] [PID.1772] © [MD5.E8A3102296B412EBE14801733474816B] - (.Samsung Electronics CO., LTD. - EasyLauncher.) -- C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593152] [PID.1840] © [MD5.F26292A81EC48523B905C31FF7BEA486] - (.F-Secure Corporation - F-Secure Host Process.) -- C:\Program Files (x86)\F-Secure\Internet Security\fshoster32.exe [193064] [PID.1888] © [MD5.277A41EB7D2DAA7105DF85BFC2F1C9AD] - (.F-Secure Corporation - F-Secure ORSP Service.) -- C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Reputation\fsorsp.exe [60456] [PID.1992] © [MD5.DAE6C3099D291EED8922A65C29ABCF52] - (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520] [PID.2020] © [MD5.21B359789D9B6A493C202541FE2A097D] - (.F-Secure Corporation - F-Secure Gatekeeper Handler 32-bit.) -- C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Anti-Virus\fsgk32.exe [865832] [PID.2044] © [MD5.52069AEB42D3D0F97CBCA1085EBF55E6] - (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432] [PID.1300] © [MD5.B2E0C6FD6CA1B5EBC4E8DB8C674A661B] - (.Malwarebytes Corporation - Malwarebytes Anti-Exploit Service.) -- C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [713016] [PID.1488] © [MD5.E1768C436DF49E0A0F8CB9DC57BDA73B] - (.Malwarebytes Corporation - Malwarebytes Anti-Exploit 64bit tasks.) -- C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe [359736] [PID.1712] © [MD5.93A92C6B05B52E736E6194F045A422E7] - (.Samsung Electronics CO., LTD. - Samsung Update Agent.) -- C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3025248] [PID.2096] © [MD5.B7D05B7F5AA886EDC3D70D5EE128A528] - (.VoodooSoft, LLC - VoodooShield.) -- C:\Program Files\VoodooShield\VoodooShieldService.exe [79384] [PID.2136] [MD5.BEC3EFB8834FDA3F4F6C63555F7A0741] - (.Atheros - Atheros Coex Service Application.) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [327296] [PID.2344] © [MD5.2572C691F268DE23E978981A9DDA91E2] - (.F-Secure Corporation - F-Secure Management Agent.) -- C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Common\FSMA32.EXE [216104] [PID.2652] © [MD5.5C66373475C2308CDC15A2781BBFD2CC] - (.F-Secure Corporation - F-Secure DLL Hosting Plugin.) -- C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Common\FSHDLL64.EXE [106536] [PID.2724] © [MD5.379BB69436EB2BC02B0D9C416FBDF574] - (.F-Secure Corporation - F-Secure Scanner Manager 32-bit.) -- C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Anti-Virus\fssm32.exe [1273384] [PID.3052] © [MD5.844B780F7EB43C4FB5D7BE0EAFA52F6A] - (.Adobe Systems Incorporated - Adobe Photoshop Elements 11.0 (component).) -- C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [172104] [PID.3092] © [MD5.20E83F4632E15A5E9E716FF2E8AC7FAE] - (.Intel Corporation - IAStorDataSvc.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720] [PID.3336] © [MD5.83FF82FE209E7997067B375DAD6CF23D] - (.Intel Corporation - Intel(R) Integrated Clock Controller Servic.) -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [169752] [PID.4172] © [MD5.3DE66F47365AA8CEB18B1EE272F4FEBA] - (.Intel Corporation - Intel(R) Local Management Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [390616] [PID.2588] © [MD5.F73AE30945F674DF57D2CBFD6397C85F] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe [1171744] [PID.3932] © [MD5.FB50E60564ED30DDC855F0CE435C8467] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 327.0.) -- C:\WINDOWS\system32\nvvsvc.exe [920864] [PID.304] © [MD5.E040801AE77E34266A98918E0E18C546] - (...) -- C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe [84800] [PID.3820] [MD5.968292958A5A507856B0E7025A73857D] - (.IvoSoft - Classic Start Menu.) -- C:\Program Files\Classic Shell\ClassicStartMenu.exe [164112] [PID.3156] © [MD5.31DD175A34396F163508A2C6E963FD95] - (.Samsung Electronics CO., LTD. - Settings.) -- C:\Program Files (x86)\Samsung\Settings\sSettings.exe [2623296] [PID.5708] © [MD5.880597F46CEF7A807F14E20EAC5705E4] - (.Intel Corporation - igfxext Module.) -- C:\WINDOWS\system32\igfxext.exe [397784] [PID.5656] © [MD5.BB8609D796C1D93561DBFBB11A920168] - (.NVIDIA Corporation - NVIDIA Settings.) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe [2450208] [PID.4596] © [MD5.4C985C3361B23B7D3063F370637F3E74] - (.Intel Corporation - igfxsrvc Module.) -- C:\WINDOWS\system32\igfxsrvc.exe [845272] [PID.3356] © [MD5.F7A438281667B1489CC64DE9B0423D6A] - (.Atheros Communications - Stackserver för Bluetooth.) -- C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [134736] [PID.3212] © [MD5.77AF6B1BCA863AE4782985D332986DF9] - (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe [770008] [PID.5912] © [MD5.CEB56B723922508FBAD03E38D1EA6094] - (.VoodooSoft, LLC - VoodooShield.) -- C:\Program Files\VoodooShield\VoodooShield.exe [1729472] [PID.3672] [MD5.2BFBD5FB7B6EFFF59AD79BB8A8796926] - (.Realtek Semiconductor - HD Audio Background Process.) -- C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1353432] [PID.5200] © [MD5.F99A480B86098CA30EB8FDB7495ADCD7] - (.Realtek Semiconductor - Realtek HD-ljudkonfiguration.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13654744] [PID.3560] © [MD5.F26292A81EC48523B905C31FF7BEA486] - (.F-Secure Corporation - F-Secure Host Process.) -- C:\Program Files (x86)\F-Secure\Internet Security\fshoster32.exe [193064] [PID.3460] © [MD5.857B9F46501D76DDAA8F57709AEAAA54] - (.F-Secure Corporation - F-Secure Settings and Statistics.) -- C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Common\FSM32.EXE [306216] [PID.1332] © [MD5.90F08C914B0492762B6A8A99703FFA2E] - (.Malwarebytes Corporation - Malwarebytes Anti-Exploit.) -- C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2620728] [PID.4332] © [MD5.F2527F0DE9A89B4FA980ECC7EFEF0EF5] - (...) -- C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe [12880] [PID.2536] [MD5.586AA08862F28053188811A06673F0CC] - (.Samsung Electronics CO., LTD. - S Agent.) -- C:\Program Files\Samsung\S Agent\CommonAgent.exe [2981712] [PID.3836] © [MD5.B234DEE2DDC56EB52341CAE6619908BF] - (.Eyeo GmbH - Adblock Plus Engine for Internet Explorer.) -- C:\Program Files\Adblock Plus for IE\AdblockPlusEngine.exe [5384968] [PID.5800] © [MD5.3D45AD2B246B90DBD3E6F213E7AEBF64] - (.Intel Corporation - IAStorIcon.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592] [PID.1412] © [MD5.CE63F25AE041877635695FCDC241CF11] - (.Adobe Systems Incorporated - Adobe® Flash® Player Utility.) -- C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe [862696] [PID.4328] © [MD5.2E6CBC165C40A0560AF83DAFB5BD3122] - (.Samsung Electronics CO., LTD. - Support Center Agent.) -- C:\Program Files\Samsung\Support Center\GuaranaAgent.exe [4241760] [PID.5320] © [MD5.FE4DD1A2E417A772052A142AEAFE5EDD] - (.Nicolas Coolman - ZHPDiag.) -- D:\ZHPDiag3.exe [1915392] [PID.5112] © ---\\ Internet Explorer Extensions, Start, Search (18) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.f-secure.com/ R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://samsung13.msn.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 ---\\ Internet Explorer, Proxy Management (5) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 ---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) F2 - REG:system.ini: VMApplet=C:\WINDOWS\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) ---\\ Hosts file redirection (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (21) ---\\ Browser Helper Object (BHO) (5) - 0s O2 - BHO: ExplorerBHO Class [64Bits] - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} . (.IvoSoft - Adds classic Windows Explorer features.) -- C:\Program Files\Classic Shell\ClassicExplorer64.dll © O2 - BHO: Browsing Protection [64Bits] - {45BBE08D-81C5-4A67-AF20-B2A077C67747} . (.F-Secure Corporation - Enhanced HTTPS support for IE.) -- C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https64.dll © O2 - BHO: SafeSearchBHO [64Bits] - {690EF1CF-5775-4CB3-A5B8-85A63FD0262B} . (.F-Secure Corporation - Safe Search IE Extension.) -- C:\Program Files (x86)\F-Secure\Internet Security\apps\SafeSearch\IE\FSSafeSearch64.dll © O2 - BHO: ClassicIEBHO Class [64Bits] - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} . (.IvoSoft - Customizations for the title bar and status.) -- C:\Program Files\Classic Shell\ClassicIEDLL_64.dll © O2 - BHO: Adblock Plus for IE Browser Helper Object [64Bits] - {FFCB3198-32F3-4E8B-9539-4324694ED664} . (.Eyeo GmbH - Adblock Plus BHO for Internet Explorer.) -- C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll © ---\\ Auto loading programs from Registry and folders (18) - 0s O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\WINDOWS\system32\igfxtray.exe © O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\WINDOWS\system32\hkcmd.exe © O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\WINDOWS\system32\igfxpers.exe © O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe © O4 - HKLM\..\Run: [Classic Start Menu] . (.IvoSoft - Classic Start Menu.) -- C:\Program Files\Classic Shell\ClassicStartMenu.exe © O4 - HKLM\..\Run: [IAStorIcon] . (.Intel Corporation - Delayed launcher.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe © O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.) O4 - HKLM\..\Run: [VoodooShield] . (.VoodooSoft, LLC - VoodooShield.) -- C:\Program Files\VoodooShield\VoodooShield.exe O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe © O4 - HKCU\..\Run: [SUPERAntiSpyware] . (.SUPERAntiSpyware - SUPERAntiSpyware Application.) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe © O4 - HKLM\..\Wow6432Node\Run: [F-Secure Hoster (666)] . (.F-Secure Corporation - F-Secure Host Process.) -- C:\Program Files (x86)\F-Secure\Internet Security\fshoster32.exe © O4 - HKLM\..\Wow6432Node\Run: [F-Secure Manager] . (.F-Secure Corporation - F-Secure Settings and Statistics.) -- C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Common\FSM32.EXE © O4 - HKLM\..\Wow6432Node\Run: [Athan] . (.www.IslamicFinder.org - Automatic Athan (Azan) five times a day f.) -- C:\Program Files (x86)\Athan\Athan.exe O4 - HKLM\..\Wow6432Node\Run: [Malwarebytes Anti-Exploit] . (.Malwarebytes Corporation - Malwarebytes Anti-Exploit.) -- C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe © O4 - HKLM\..\policies\Explorer\Run: [BtvStack] . (.Atheros Communications - Stackserver för Bluetooth.) -- C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe © O4 - HKUS\S-1-5-21-3047659432-1251398356-2651448383-1002\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe © O4 - HKUS\S-1-5-21-3047659432-1251398356-2651448383-1002\..\Run: [SUPERAntiSpyware] . (.SUPERAntiSpyware - SUPERAntiSpyware Application.) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ---\\ Lop.com/Domain Hijackers (2) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 ---\\ Extra protocols (20) - 0s O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) Visningsprogram för HTML.) -- C:\Windows\System32\mshtml.dll © O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32-tillägg för Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX-kontroll för direktuppspelad video.) -- C:\Windows\System32\MSVidCtl.dll © O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32-tillägg för Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32-tillägg för Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32-tillägg för Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32-tillägg för Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll © O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) Visningsprogram för HTML.) -- C:\Windows\System32\mshtml.dll © O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32-tillägg för Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) Visningsprogram för HTML.) -- C:\Windows\System32\mshtml.dll © O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll © O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32-tillägg för Win32.) -- C:\Windows\System32\urlmon.dll © O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll © O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) Visningsprogram för HTML.) -- C:\Windows\System32\mshtml.dll © O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX-kontroll för direktuppspelad video.) -- C:\Windows\System32\MSVidCtl.dll © O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) Visningsprogram för HTML.) -- C:\Windows\System32\mshtml.dll © O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll © O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll © O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll © ---\\ AppInit_DLLs Registry value Autorun (1) - 0s O20 - AppInit_DLLs: . (.NVIDIA Corporation - NVIDIA shim initialization dll, Version 327.) - C:\windows\system32\nvinitx.dll ---\\ Non Microsoft non disabled Windows Services (18) - 1s O23 - Service: SAS Core Service (!SASCORE) . (.SUPERAntiSpyware.com - Core Service.) - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE O23 - Service: Adobe Active File Monitor V11 (AdobeActiveFileMonitor11.0) . (.Adobe Systems Incorporated - Adobe Photoshop Elements 11.0 (component).) - C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe © O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe © O23 - Service: AtherosSvc (AtherosSvc) . (.Windows (R) Win 7 DDK provider - Windows Setup API.) - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe © O23 - Service: (Easy Launcher) . (.Samsung Electronics CO., LTD. - EasyLauncher.) - C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe © O23 - Service: F-Secure Dll Hoster (fshoster) . (.F-Secure Corporation - F-Secure Host Process.) - C:\Program Files (x86)\F-Secure\Internet Security\fshoster32.exe © O23 - Service: F-Secure ORSP Client (FSORSPClient) . (.F-Secure Corporation - F-Secure ORSP Service.) - C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Reputation\fsorsp.exe © O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation - IAStorDataSvc.) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe © O23 - Service: Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe © O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe © O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Intel(R) Local Management Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe © O23 - Service: Malwarebytes Anti-Exploit Service (MbaeSvc) . (.Malwarebytes Corporation - Malwarebytes Anti-Exploit Service.) - C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe © O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe © O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 327.0.) - C:\WINDOWS\system32\nvvsvc.exe © O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) . (.NVIDIA Corporation - NVIDIA Settings Update Manager.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe © O23 - Service: SW Update Service (SWUpdateService) . (.Samsung Electronics CO., LTD. - Samsung Update Agent.) - C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe © O23 - Service: VoodooShieldService (VoodooShieldService) . (.VoodooSoft, LLC - VoodooShield.) - C:\Program Files\VoodooShield\VoodooShieldService.exe O23 - Service: ZAtheros Bt and Wlan Coex Agent (ZAtheros Bt and Wlan Coex Agent) . (.Atheros - Atheros Coex Service Application.) - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe © ---\\ Task Planned Automatically (23) - 3s [MD5.744B3186BD09222D43E395E9ACC4487E] [APT] [advRecovery] (.SEC.) -- C:\Program Files\Samsung\Recovery\WCScheduler.exe [868728] © [MD5.00000000000000000000000000000000] [APT] [ASC8_PerformanceMonitor] (...) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [ASC8_SkipUac_donotdisturb] (...) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe (.not file.) [0] [MD5.6313BA5D7F348576758CE789AF7E548A] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6405912] © [MD5.2BFBD5FB7B6EFFF59AD79BB8A8796926] [APT] [RtHDVBg] (.Realtek Semiconductor.) -- C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1353432] © [MD5.F99A480B86098CA30EB8FDB7495ADCD7] [APT] [RTKCPL] (.Realtek Semiconductor.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13654744] © [MD5.00000000000000000000000000000000] [APT] [SAgent] (...) -- C:\Program Files (x86)\Samsung\S Agent\CommonAgent.exe (.not file.) [0] [MD5.CD94CE676FE1A3F5956AF07EDDE58733] [APT] [Scheduled scanning task] (.F-Secure Corporation.) -- C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Anti-Virus\fsav.exe [228392] © [MD5.31DD175A34396F163508A2C6E963FD95] [APT] [Settings] (.Samsung Electronics CO., LTD..) -- C:\Program Files (x86)\Samsung\Settings\sSettings.exe [2623296] © [MD5.00000000000000000000000000000000] [APT] [Uninstaller_SkipUac_donotdisturb] (...) -- C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe (.not file.) [0] O39 - APT: ASC8_SkipUac_donotdisturb - (...) -- C:\WINDOWS\Tasks\ASC8_SkipUac_donotdisturb.job [286] O39 - APT: Scheduled scanning task - (.F-Secure Corporation.) -- C:\WINDOWS\Tasks\Scheduled scanning task.job [716] © O39 - APT: Uninstaller_SkipUac_donotdisturb - (...) -- C:\WINDOWS\Tasks\Uninstaller_SkipUac_donotdisturb.job [322] O39 - APT: advRecovery - (.SEC.) -- C:\WINDOWS\System32\Tasks\advRecovery [3126] © O39 - APT: ASC8_PerformanceMonitor - (...) -- C:\WINDOWS\System32\Tasks\ASC8_PerformanceMonitor [3210] O39 - APT: ASC8_SkipUac_donotdisturb - (...) -- C:\WINDOWS\System32\Tasks\ASC8_SkipUac_donotdisturb [2400] O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\WINDOWS\System32\Tasks\CCleanerSkipUAC [2816] © O39 - APT: RtHDVBg - (.Realtek Semiconductor.) -- C:\WINDOWS\System32\Tasks\RtHDVBg [3150] © O39 - APT: RTKCPL - (.Realtek Semiconductor.) -- C:\WINDOWS\System32\Tasks\RTKCPL [3132] © O39 - APT: SAgent - (...) -- C:\WINDOWS\System32\Tasks\SAgent [3038] O39 - APT: Scheduled scanning task - (.F-Secure Corporation.) -- C:\WINDOWS\System32\Tasks\Scheduled scanning task [3454] © O39 - APT: Settings - (.Samsung Electronics CO., LTD..) -- C:\WINDOWS\System32\Tasks\Settings [3434] © O39 - APT: Uninstaller_SkipUac_donotdisturb - (...) -- C:\WINDOWS\System32\Tasks\Uninstaller_SkipUac_donotdisturb [2436] ---\\ Software installed (60) - 3s O42 - Logiciel: Windows-drivrutinspaket - Samsung Electronics Co. Ltd. (RadioHIDMini) HIDCl - (.Samsung Electronics Co. Ltd..) [HKLM][64Bits] -- 26BFE384C802803107F583AE1A739E4FEB56134B O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner © O42 - Logiciel: Malwarebytes Anti-Exploit version 1.07.1.1015 - (.Malwarebytes.) [HKLM][64Bits] -- Malwarebytes Anti-Exploit_is1 © O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey © O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {409CB30E-E457-4008-9B1A-ED1B9EA21140} © O42 - Logiciel: Revo Uninstaller Pro 3.1.4 - (.VS Revo Group, Ltd..) [HKLM][64Bits] -- {67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1 O42 - Logiciel: Support Center - (.Samsung Electronics CO., LTD..) [HKLM][64Bits] -- {711DE117-767F-48A8-9864-66C525B9539F} © O42 - Logiciel: Adblock Plus för IE (32-bitars och 64-bitars) - (.Eyeo GmbH.) [HKLM][64Bits] -- {789FA9EC-180F-44C6-97AC-E99A8997A6E7} © O42 - Logiciel: Classic Shell - (.IvoSoft.) [HKLM][64Bits] -- {7C129CF8-199F-4269-AAEE-60B5D8D716E2} © O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {93F692D4-0C4D-4EED-9BFE-657C1D5959FE} © O42 - Logiciel: Qualcomm Atheros Bluetooth Suite (64) - (.Qualcomm Atheros Communications.) [HKLM][64Bits] -- {A84A4FB1-D703-48DB-89E0-68B6499D2801} O42 - Logiciel: VoodooShield version 2.75 - (.VoodooSoft, LLC.) [HKLM][64Bits] -- {A8644328-A66F-490E-B8FA-901FF649189D}_is1 O42 - Logiciel: Help Desk - (.Samsung Electronics CO., LTD..) [HKLM][64Bits] -- {AEC9D273-E162-4614-83F1-722B8C74B185} © O42 - Logiciel: NVIDIA Grafikdrivrutin 327.02 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver © O42 - Logiciel: NVIDIA PhysX System Software 9.12.1031 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX © O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {B5E06417-A4AC-4225-B36E-7E34C91616E7} © O42 - Logiciel: SUPERAntiSpyware - (.SUPERAntiSpyware.com.) [HKLM][64Bits] -- {CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA} O42 - Logiciel: SAMSUNG USB Driver for Mobile Phones - (.SAMSUNG Electronics Co., Ltd..) [HKLM][64Bits] -- {D0795B21-0CDA-4a92-AB9E-6E92D8111E44} © O42 - Logiciel: MSVCRT110_amd64 - (.Microsoft.) [HKLM][64Bits] -- {E9FA781F-3E80-4399-825A-AD3E11C28C77} © O42 - Logiciel: S Agent - (.Samsung Electronics CO., LTD..) [HKLM][64Bits] -- {F49C89E7-14AC-4796-9C6A-49FA97890857} © O42 - Logiciel: 7-Zip 15.06 beta - (.Igor Pavlov.) [HKLM][64Bits] -- 7-Zip © O42 - Logiciel: Adobe Photoshop Elements 11 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Photoshop Elements 11 © O42 - Logiciel: Athan Basic 4.5 - (...) [HKLM][64Bits] -- Athan O42 - Logiciel: F-Secure - (.F-Secure Corporation.) [HKLM][64Bits] -- F-Secure ServiceEnabler 666 © O42 - Logiciel: Samsung Kies - (.Samsung Electronics Co., Ltd..) [HKLM][64Bits] -- InstallShield_{758C8301-2696-4855-AF45-534B1200980A} © O42 - Logiciel: Malwarebytes Anti-Malware version 2.1.8.1057 - (.Malwarebytes Corporation.) [HKLM][64Bits] -- Malwarebytes Anti-Malware_is1 © O42 - Logiciel: Plants vs. Zombies - (.PopCap Games.) [HKLM][64Bits] -- Plants vs. Zombies © O42 - Logiciel: Wise Registry Cleaner 8.71 - (.WiseCleaner.com, Inc..) [HKLM][64Bits] -- Wise Registry Cleaner_is1 O42 - Logiciel: F-Secure CCF Reputation - (.F-Secure.) [HKLM][64Bits] -- {00000000-2778-5BED-8199-52EB14D8D22F} © O42 - Logiciel: Samsung Update - (.Samsung Electronics CO., LTD..) [HKLM][64Bits] -- {00ABE05F-DB49-4421-AA35-833DD9A9A94D} © O42 - Logiciel: Recovery - (.Samsung Electronics CO., LTD..) [HKLM][64Bits] -- {145DE957-0679-4A2A-BB5C-1D3E9808FAB2} © O42 - Logiciel: Qualcomm Atheros Client Installation Program - (.Qualcomm Atheros.) [HKLM][64Bits] -- {28006915-2739-4EBE-B5E8-49B25D32EB33} © O42 - Logiciel: F-Secure Network CCF 1.03.139 - (.F-Secure Corporation.) [HKLM][64Bits] -- {51E7E1F9-CFDF-4DBE-B826-50B7C9571EA2} © O42 - Logiciel: SideSync - (.Samsung Electronics CO., LTD..) [HKLM][64Bits] -- {59687468-8CE9-4ABF-9C6A-5C31F0E09F8B} © O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A} © O42 - Logiciel: Computer Security 14.139.100.0 (release) - (.F-Secure Corporation.) [HKLM][64Bits] -- {658FDBCA-B7A1-43E4-A849-9F0812473331} © O42 - Logiciel: Support Center FAQ - (.Samsung Electronics CO., LTD..) [HKLM][64Bits] -- {661544AE-C07F-4EAD-B187-7A217E69A426} © O42 - Logiciel: User Guide - (.Samsung Electronics CO., LTD..) [HKLM][64Bits] -- {7536A888-2F1E-4B3B-AEF1-BC08C822C5F1} © O42 - Logiciel: Samsung Kies - (.Samsung Electronics Co., Ltd..) [HKLM][64Bits] -- {758C8301-2696-4855-AF45-534B1200980A} © O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} © O42 - Logiciel: NVIDIA PhysX - (.NVIDIA Corporation.) [HKLM][64Bits] -- {8B922CF8-8A6C-41CE-A858-F1755D7F5D29} © O42 - Logiciel: Settings - (.Samsung Electronics CO., LTD..) [HKLM][64Bits] -- {8CB5C357-12E5-41B1-A024-D57D4E6F32D9} © O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} © O42 - Logiciel: MSVCRT110 - (.Microsoft.) [HKLM][64Bits] -- {8E14DDC8-EA60-4E18-B3E3-1937104D5BDA} © O42 - Logiciel: PSE11 STI Installer - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {98CE8819-87AA-4814-8167-ADDDD513485F} © O42 - Logiciel: Fotogalleriet - (.Microsoft Corporation.) [HKLM][64Bits] -- {9F470E17-4FC3-4091-A508-D5347A16A2B9} © O42 - Logiciel: F-Secure - (.F-Secure Corporation.) [HKLM][64Bits] -- {A251F01E-DF36-49CB-BC10-0634905B9C72} © O42 - Logiciel: Easy File Share - (.Samsung Electronics CO.,LTD..) [HKLM][64Bits] -- {A7C37D4B-F37A-42E8-9B6A-B28C18AD4C12} O42 - Logiciel: Adobe Reader XI (11.0.03) MUI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-FFFF-7B44-AB0000000001} © O42 - Logiciel: Valokuvavalikoima - (.Microsoft Corporation.) [HKLM][64Bits] -- {C32F4F5A-C9FB-427C-9F6F-9DB157611FFF} © O42 - Logiciel: Online Safety 2.139.3446.2391 - (.F-Secure Corporation.) [HKLM][64Bits] -- {CA381D6D-DDD7-4612-BCC1-F07C7CB591F1} © O42 - Logiciel: F-Secure SafeSearch 1.05.143.0 (release) - (.F-Secure Corporation.) [HKLM][64Bits] -- {D459612C-3563-4426-BBBE-A4AF348BD4FB} © O42 - Logiciel: Phone Screen Sharing - (.RSUPPORT.) [HKLM][64Bits] -- {DF02C515-40B5-45AC-A601-5DC69D03885C} O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF} © O42 - Logiciel: Fotogalleri - (.Microsoft Corporation.) [HKLM][64Bits] -- {E354D495-5DA4-4CCF-AB39-080F6A4141BE} © O42 - Logiciel: F-Secure CCF Scanning 1.66.103.568 (release) - (.F-Secure Corporation.) [HKLM][64Bits] -- {E8CD6036-C044-4FDF-9494-846DF851B704} © O42 - Logiciel: E-POP - (.Samsung Electronics CO., LTD..) [HKLM][64Bits] -- {F06DD8D9-9DC8-430C-835C-C9BF21E05CC1} © O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} © O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} © O42 - Logiciel: Intel(R) SDK for OpenCL - CPU Only Runtime Package - (.Intel Corporation.) [HKLM][64Bits] -- {FCB3772C-B7D0-4933-B1A9-3707EBACC573} © ---\\ HKCU & HKLM Software Keys (54) - 3s HKLM\SOFTWARE\Wow6432Node\7-Zip HKLM\SOFTWARE\Wow6432Node\Adobe HKLM\SOFTWARE\Wow6432Node\AdwCleaner HKLM\SOFTWARE\Wow6432Node\AGEIA Technologies HKLM\SOFTWARE\Wow6432Node\Ashampoo HKLM\SOFTWARE\Wow6432Node\Atheros HKLM\SOFTWARE\Wow6432Node\Data Fellows HKLM\SOFTWARE\Wow6432Node\Dell HKLM\SOFTWARE\Wow6432Node\F-Secure HKLM\SOFTWARE\Wow6432Node\Google HKLM\SOFTWARE\Wow6432Node\Intel HKLM\SOFTWARE\Wow6432Node\Khronos HKLM\SOFTWARE\Wow6432Node\Macromedia HKLM\SOFTWARE\Wow6432Node\Malwarebytes Anti-Exploit HKLM\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware HKLM\SOFTWARE\Wow6432Node\Mozilla HKLM\SOFTWARE\Wow6432Node\MozillaPlugins HKLM\SOFTWARE\Wow6432Node\Nuance HKLM\SOFTWARE\Wow6432Node\NVIDIA Corporation HKLM\SOFTWARE\Wow6432Node\ODBC HKLM\SOFTWARE\Wow6432Node\PopCap HKLM\SOFTWARE\Wow6432Node\Qualcomm Atheros HKLM\SOFTWARE\Wow6432Node\Realtek HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp. HKLM\SOFTWARE\Wow6432Node\Samsung HKLM\SOFTWARE\Wow6432Node\Samsung Electronics CO., LTD. HKLM\SOFTWARE\Wow6432Node\Sonic HKLM\SOFTWARE\Wow6432Node\SuppHelpDir HKLM\SOFTWARE\Wow6432Node\Symantec HKLM\SOFTWARE\Wow6432Node\Volatile HKLM\SOFTWARE\Wow6432Node\WiseCleaner HKLM\SOFTWARE\Wow6432Node\RegisteredApplications HKCU\SOFTWARE\7-Zip HKCU\SOFTWARE\AdblockPlus HKCU\SOFTWARE\Adobe HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\Atheros HKCU\SOFTWARE\F-Secure HKCU\SOFTWARE\F-Secure Antibot HKCU\SOFTWARE\Intel HKCU\SOFTWARE\IvoSoft HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\Mirage HKCU\SOFTWARE\NVIDIA Corporation HKCU\SOFTWARE\Piriform HKCU\SOFTWARE\Realtek HKCU\SOFTWARE\RegisteredApplications HKCU\SOFTWARE\Samsung HKCU\SOFTWARE\SUPERAntiSpyware.com HKCU\SOFTWARE\Synaptics HKCU\SOFTWARE\VS Revo Group HKCU\SOFTWARE\Wow6432Node HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Software ---\\ Contents of the Common Files folders (145) - 3s O43 - CFD: 2015/08/25 14:30:41 - [] D -- C:\Program Files (x86)\7-Zip O43 - CFD: 2013/07/30 14:23:45 - [] D -- C:\Program Files (x86)\Adobe O43 - CFD: 2013/07/30 14:01:43 - [0] D -- C:\Program Files (x86)\AGEIA Technologies O43 - CFD: 2015/08/25 14:49:06 - [] D -- C:\Program Files (x86)\Athan O43 - CFD: 2015/08/31 00:00:42 - [] D -- C:\Program Files (x86)\Bluetooth Suite O43 - CFD: 2015/08/30 23:58:32 - [] D -- C:\Program Files (x86)\Common Files O43 - CFD: 2015/08/24 13:54:53 - [] D -- C:\Program Files (x86)\F-Secure O43 - CFD: 2015/08/30 23:55:09 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information O43 - CFD: 2015/08/31 00:05:33 - [] D -- C:\Program Files (x86)\Intel O43 - CFD: 2015/08/30 20:29:21 - [] D -- C:\Program Files (x86)\Internet Explorer O43 - CFD: 2015/08/30 22:07:16 - [] D -- C:\Program Files (x86)\Malwarebytes Anti-Exploit O43 - CFD: 2015/08/27 10:00:56 - [] D -- C:\Program Files (x86)\Malwarebytes Anti-Malware O43 - CFD: 2013/07/30 14:26:59 - [] D -- C:\Program Files (x86)\Microsoft Office O43 - CFD: 2013/07/30 14:17:34 - [] D -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition O43 - CFD: 2013/08/22 17:36:30 - [] D -- C:\Program Files (x86)\Microsoft.NET O43 - CFD: 2015/08/25 12:57:05 - [] D -- C:\Program Files (x86)\MSBuild O43 - CFD: 2015/08/25 13:30:21 - [] D -- C:\Program Files (x86)\NVIDIA Corporation O43 - CFD: 2013/07/30 14:15:49 - [] D -- C:\Program Files (x86)\PopCap Games O43 - CFD: 2015/08/30 23:46:20 - [] D -- C:\Program Files (x86)\Qualcomm Atheros O43 - CFD: 2015/08/30 23:46:37 - [] D -- C:\Program Files (x86)\Realtek O43 - CFD: 2015/08/25 12:57:05 - [] D -- C:\Program Files (x86)\Reference Assemblies O43 - CFD: 2015/08/31 00:03:07 - [] D -- C:\Program Files (x86)\Samsung O43 - CFD: 2013/07/30 14:29:59 - [] D -- C:\Program Files (x86)\SymSilent O43 - CFD: 2015/08/30 23:49:28 - [0] HD -- C:\Program Files (x86)\Temp O43 - CFD: 2015/08/24 13:33:12 - [0] HD -- C:\Program Files (x86)\Uninstall Information O43 - CFD: 2015/08/30 20:29:21 - [] D -- C:\Program Files (x86)\Windows Defender O43 - CFD: 2013/07/30 14:17:32 - [] D -- C:\Program Files (x86)\Windows Live O43 - CFD: 2015/08/30 20:29:21 - [] D -- C:\Program Files (x86)\Windows Mail O43 - CFD: 2015/08/30 20:29:21 - [] D -- C:\Program Files (x86)\Windows Media Player O43 - CFD: 2014/11/21 18:33:38 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform O43 - CFD: 2013/08/22 17:36:30 - [] D -- C:\Program Files (x86)\Windows NT O43 - CFD: 2015/08/30 20:29:21 - [] D -- C:\Program Files (x86)\Windows Photo Viewer O43 - CFD: 2014/11/21 18:33:38 - [] D -- C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 2015/08/25 13:30:25 - [] SHD -- C:\Program Files (x86)\Windows Sidebar O43 - CFD: 2013/08/22 17:36:30 - [] D -- C:\Program Files (x86)\WindowsPowerShell O43 - CFD: 2015/08/25 15:10:45 - [] D -- C:\Program Files (x86)\Wise O43 - CFD: 2015/08/25 14:30:42 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip O43 - CFD: 2014/11/21 18:34:18 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 2015/08/25 13:06:11 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2015/08/27 11:37:54 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2015/08/25 14:49:04 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Athan O43 - CFD: 2015/08/31 00:00:41 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BT Program O43 - CFD: 2015/08/25 14:32:54 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner O43 - CFD: 2015/08/25 14:26:20 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell O43 - CFD: 2015/08/25 13:33:19 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\F-Secure O43 - CFD: 2015/08/31 00:03:25 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel O43 - CFD: 2013/08/22 17:36:33 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2015/08/30 22:07:20 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit O43 - CFD: 2015/08/27 10:00:59 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware O43 - CFD: 2015/08/25 13:30:26 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PopCap Games O43 - CFD: 2015/08/25 14:56:44 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro O43 - CFD: 2015/08/31 00:10:24 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung O43 - CFD: 2015/08/25 14:34:05 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp O43 - CFD: 2015/08/27 09:24:39 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware O43 - CFD: 2014/11/21 18:34:18 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 2014/11/21 10:26:42 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 2015/09/01 13:59:47 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VoodooShield O43 - CFD: 2015/08/25 15:10:47 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Registry Cleaner O43 - CFD: 2013/07/30 14:23:45 - [] D -- C:\ProgramData\Adobe O43 - CFD: 2013/08/22 16:45:52 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 2015/08/31 00:08:51 - [] D -- C:\ProgramData\Atheros O43 - CFD: 2015/08/25 14:47:22 - [] D -- C:\ProgramData\ClassicShell O43 - CFD: 2013/07/30 12:03:38 - [] D -- C:\ProgramData\ColorMode O43 - CFD: 2013/08/22 16:45:52 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 2013/08/22 16:45:52 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 2015/08/25 13:54:13 - [0] SHD -- C:\ProgramData\Dokument O43 - CFD: 2015/08/24 14:07:00 - [] D -- C:\ProgramData\F-Secure O43 - CFD: 2015/08/31 00:03:29 - [] D -- C:\ProgramData\Intel O43 - CFD: 2015/08/25 13:54:13 - [0] SHD -- C:\ProgramData\Mallar O43 - CFD: 2015/08/27 10:00:48 - [] D -- C:\ProgramData\Malwarebytes O43 - CFD: 2015/08/30 22:08:33 - [] D -- C:\ProgramData\Malwarebytes Anti-Exploit O43 - CFD: 2015/08/30 21:33:30 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 2015/08/24 14:03:59 - [] D -- C:\ProgramData\Norton O43 - CFD: 2015/08/24 14:01:14 - [] D -- C:\ProgramData\NortonInstaller O43 - CFD: 2013/07/30 14:01:54 - [] D -- C:\ProgramData\NVIDIA O43 - CFD: 2015/08/25 13:11:50 - [] D -- C:\ProgramData\NVIDIA Corporation O43 - CFD: 2013/07/30 14:15:49 - [] D -- C:\ProgramData\PopCap Games O43 - CFD: 2015/08/25 13:30:27 - [] D -- C:\ProgramData\PRICache O43 - CFD: 2015/08/30 17:23:46 - [] D -- C:\ProgramData\ProductData O43 - CFD: 2015/08/25 13:54:13 - [0] SHD -- C:\ProgramData\Programdata O43 - CFD: 2013/07/30 11:40:35 - [] D -- C:\ProgramData\Qualcomm Atheros O43 - CFD: 2015/08/25 13:33:19 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft O43 - CFD: 2015/08/30 23:38:19 - [] D -- C:\ProgramData\Samsung O43 - CFD: 2015/08/25 13:54:13 - [0] SHD -- C:\ProgramData\Skrivbord O43 - CFD: 2013/08/22 16:45:52 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 2015/08/25 13:54:13 - [0] SHD -- C:\ProgramData\Start-meny O43 - CFD: 2015/08/27 09:24:37 - [] D -- C:\ProgramData\SUPERAntiSpyware.com O43 - CFD: 2013/08/22 16:45:52 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 2015/09/01 17:16:38 - [] D -- C:\ProgramData\VoodooShield O43 - CFD: 2015/08/25 14:56:43 - [] D -- C:\ProgramData\VS Revo Group O43 - CFD: 2015/09/01 16:41:55 - [] D -- C:\ProgramData\WinClon O43 - CFD: 2015/08/30 23:59:35 - [] D -- C:\ProgramData\{41A350B0-C533-4604-B09D-EB21FC05B6BB} O43 - CFD: 2015/08/30 17:23:17 - [0] D -- C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0} O43 - CFD: 2013/07/30 14:26:35 - [] D -- C:\Program Files (x86)\Common Files\Adobe O43 - CFD: 2013/07/30 14:03:28 - [] D -- C:\Program Files (x86)\Common Files\Atheros O43 - CFD: 2013/07/30 11:38:08 - [] D -- C:\Program Files (x86)\Common Files\InstallShield O43 - CFD: 2015/08/25 13:10:50 - [] D -- C:\Program Files (x86)\Common Files\Intel O43 - CFD: 2015/08/30 23:45:36 - [] D -- C:\Program Files (x86)\Common Files\Intel Corporation O43 - CFD: 2015/08/30 17:23:11 - [] D -- C:\Program Files (x86)\Common Files\IObit O43 - CFD: 2015/08/25 13:30:20 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared O43 - CFD: 2013/07/30 11:37:12 - [] D -- C:\Program Files (x86)\Common Files\postureAgent O43 - CFD: 2013/07/30 14:22:13 - [] D -- C:\Program Files (x86)\Common Files\PX Storage Engine O43 - CFD: 2013/08/22 17:36:33 - [] D -- C:\Program Files (x86)\Common Files\Services O43 - CFD: 2013/07/30 14:22:13 - [] D -- C:\Program Files (x86)\Common Files\Sonic Shared O43 - CFD: 2015/08/30 20:29:21 - [] D -- C:\Program Files (x86)\Common Files\System O43 - CFD: 2013/07/30 14:16:25 - [] D -- C:\Program Files (x86)\Common Files\Windows Live O43 - CFD: 2015/08/24 13:59:48 - [] D -- C:\Users\donotdisturb\AppData\Roaming\Adobe O43 - CFD: 2015/08/30 17:23:25 - [] D -- C:\Users\donotdisturb\AppData\Roaming\Apple Computer O43 - CFD: 2015/08/31 00:08:23 - [] D -- C:\Users\donotdisturb\AppData\Roaming\Atheros O43 - CFD: 2015/08/25 15:13:14 - [] D -- C:\Users\donotdisturb\AppData\Roaming\ClassicShell O43 - CFD: 2015/08/25 13:57:47 - [] D -- C:\Users\donotdisturb\AppData\Roaming\Identities O43 - CFD: 2015/08/30 23:44:40 - [] D -- C:\Users\donotdisturb\AppData\Roaming\Intel Corporation O43 - CFD: 2015/08/25 14:28:28 - [] D -- C:\Users\donotdisturb\AppData\Roaming\Macromedia O43 - CFD: 2015/08/30 21:33:28 - [] SD -- C:\Users\donotdisturb\AppData\Roaming\Microsoft O43 - CFD: 2015/08/30 18:20:43 - [] D -- C:\Users\donotdisturb\AppData\Roaming\ProductData O43 - CFD: 2015/08/31 00:03:16 - [] D -- C:\Users\donotdisturb\AppData\Roaming\Samsung O43 - CFD: 2015/08/27 09:25:24 - [] D -- C:\Users\donotdisturb\AppData\Roaming\SUPERAntiSpyware.com O43 - CFD: 2015/08/24 14:05:50 - [] D -- C:\Users\donotdisturb\AppData\Roaming\Synaptics O43 - CFD: 2015/08/27 08:55:07 - [] D -- C:\Users\donotdisturb\AppData\Roaming\Wise Registry Cleaner O43 - CFD: 2015/09/01 17:16:37 - [] D -- C:\Users\donotdisturb\AppData\Roaming\ZHP O43 - CFD: 2015/08/24 13:59:48 - [] D -- C:\Users\donotdisturb\AppData\Local\Adobe O43 - CFD: 2015/08/24 13:37:38 - [] D -- C:\Users\donotdisturb\AppData\Local\BMExplorer O43 - CFD: 2015/09/01 15:49:14 - [] D -- C:\Users\donotdisturb\AppData\Local\ClassicShell O43 - CFD: 2015/09/01 07:40:17 - [] D -- C:\Users\donotdisturb\AppData\Local\CrashDumps O43 - CFD: 2015/08/30 21:32:42 - [] D -- C:\Users\donotdisturb\AppData\Local\Diagnostics O43 - CFD: 2015/08/24 14:26:14 - [] D -- C:\Users\donotdisturb\AppData\Local\ElevatedDiagnostics O43 - CFD: 2015/08/30 22:44:16 - [] D -- C:\Users\donotdisturb\AppData\Local\F-Secure O43 - CFD: 2015/08/28 17:07:51 - [] D -- C:\Users\donotdisturb\AppData\Local\GWX O43 - CFD: 2015/08/30 21:33:30 - [] D -- C:\Users\donotdisturb\AppData\Local\Microsoft O43 - CFD: 2015/08/25 14:02:58 - [] D -- C:\Users\donotdisturb\AppData\Local\Packages O43 - CFD: 2015/08/25 13:27:27 - [0] SHD -- C:\Users\donotdisturb\AppData\Local\Programdata O43 - CFD: 2015/08/25 14:44:35 - [] D -- C:\Users\donotdisturb\AppData\Local\Programs O43 - CFD: 2015/08/24 13:33:52 - [] D -- C:\Users\donotdisturb\AppData\Local\Samsung O43 - CFD: 2015/09/01 17:16:41 - [] D -- C:\Users\donotdisturb\AppData\Local\Temp O43 - CFD: 2015/08/25 13:27:27 - [0] SHD -- C:\Users\donotdisturb\AppData\Local\Temporary Internet Files O43 - CFD: 2015/08/25 13:27:27 - [0] SHD -- C:\Users\donotdisturb\AppData\Local\Tidigare O43 - CFD: 2015/08/25 23:22:30 - [] D -- C:\Users\donotdisturb\AppData\Local\VirtualStore O43 - CFD: 2015/08/25 14:56:48 - [] D -- C:\Users\donotdisturb\AppData\Local\VS Revo Group O43 - CFD: 2015/08/25 13:28:10 - [] RD -- C:\Users\donotdisturb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 2015/08/25 13:48:15 - [] RD -- C:\Users\donotdisturb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2015/08/25 13:58:28 - [] RD -- C:\Users\donotdisturb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2015/09/01 16:40:01 - [] RD -- C:\Users\donotdisturb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices O43 - CFD: 2013/08/22 17:36:32 - [] D -- C:\Users\donotdisturb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2015/08/25 13:58:28 - [] RD -- C:\Users\donotdisturb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 2015/08/25 13:28:10 - [] RD -- C:\Users\donotdisturb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools ---\\ System Drivers List (64) - 1s O58 - SDL:2013/08/22 14:43:41 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [108896] © O58 - SDL:2013/08/22 14:43:41 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [782176] © O58 - SDL:2013/08/22 14:43:41 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [79200] © O58 - SDL:2013/08/22 14:43:41 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259424] © O58 - SDL:2013/08/22 14:43:40 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [25952] © O58 - SDL:2013/08/22 14:43:41 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [114016] © O58 - SDL:2013/04/15 20:55:42 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\drivers\athw8x.sys [3786752] © O58 - SDL:2013/08/15 20:13:30 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\drivers\athwbx.sys [3859968] © O58 - SDL:2013/08/13 01:25:46 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [17624] © O58 - SDL:2015/06/01 20:31:42 A . (.Qualcomm Atheros - Qualcomm Atheros A2DP driver.) -- C:\WINDOWS\System32\drivers\btath_a2dp.sys [338072] © O58 - SDL:2015/06/01 20:31:42 A . (.Qualcomm Atheros - Qualcomm Atheros Bluetooth AVDT driver.) -- C:\WINDOWS\System32\drivers\btath_avdt.sys [119448] © O58 - SDL:2015/06/01 20:31:42 A . (.Qualcomm Atheros - Qualcomm Atheros BUS driver.) -- C:\WINDOWS\System32\drivers\btath_bus.sys [35016] © O58 - SDL:2015/06/01 20:31:42 A . (.Qualcomm Atheros - Qualcomm Atheros FILTER driver.) -- C:\WINDOWS\System32\drivers\btath_flt.sys [89800] © O58 - SDL:2015/06/01 20:31:42 A . (.Qualcomm Atheros - Qualcomm Atheros HCRP driver.) -- C:\WINDOWS\System32\drivers\btath_hcrp.sys [179432] © O58 - SDL:2015/06/01 20:31:42 A . (.Qualcomm Atheros - Qualcomm Atheros FILTER driver.) -- C:\WINDOWS\System32\drivers\btath_lwflt.sys [77464] © O58 - SDL:2015/06/01 20:31:42 A . (.Qualcomm Atheros - Qualcomm Atheros AVRCP driver.) -- C:\WINDOWS\System32\drivers\btath_rcp.sys [137928] © O58 - SDL:2015/06/01 20:31:42 A . (.Qualcomm Atheros - Qualcomm Atheros BtFilter Driver.) -- C:\WINDOWS\System32\drivers\btfilter.sys [601240] © O58 - SDL:2013/08/22 14:43:41 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [531296] © O58 - SDL:2012/04/23 20:01:00 A . (.Corel Corporation - CDR4 64-bit CD and DVD Place Holder Driver.) -- C:\WINDOWS\System32\drivers\cdr4_xp.sys [10864] © O58 - SDL:2012/04/23 20:01:00 A . (.Corel Corporation - CDRAL 64-bit Place Holder Driver (see PxHel.) -- C:\WINDOWS\System32\drivers\cdralw2k.sys [11376] © O58 - SDL:2013/08/22 14:43:45 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3357024] © O58 - SDL:2015/08/24 14:22:10 A . (...) -- C:\WINDOWS\System32\drivers\fsbts.sys [55336] O58 - SDL:2012/07/13 04:56:32 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\HECIx64.sys [62784] © O58 - SDL:2013/08/22 14:43:45 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64352] © O58 - SDL:2013/07/30 20:47:35 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [24568] © O58 - SDL:2013/07/25 21:05:39 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [99320] © O58 - SDL:2013/08/07 14:23:46 A . (.Intel Corporation - Intel Rapid Storage Technology driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorA.sys [644968] © O58 - SDL:2013/08/10 02:39:30 A . (.Intel Corporation - Intel Rapid Storage Technology driver (inbo.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [651248] © O58 - SDL:2013/08/22 14:43:45 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412000] © O58 - SDL:2014/03/20 07:53:14 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\igdkmd64.sys [4209152] © O58 - SDL:2013/05/28 07:07:30 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\WINDOWS\System32\drivers\IntcDAud.sys [342528] © O58 - SDL:2013/10/29 03:08:35 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\intelaud.sys [39320] © O58 - SDL:2013/10/29 03:08:35 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\iwdbus.sys [27032] © O58 - SDL:2013/08/22 14:43:44 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [109408] © O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2.sys [93536] © O58 - SDL:2013/08/22 14:43:44 A . (.LSI Corporation - LSI SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3.sys [81760] © O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82784] © O58 - SDL:2015/06/18 08:41:40 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\WINDOWS\System32\drivers\mbam.sys [25816] © O58 - SDL:2015/06/18 08:41:44 A . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys [109272] © O58 - SDL:2015/08/30 21:52:35 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [113880] © O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [56672] © O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575840] © O58 - SDL:2013/08/22 14:43:49 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63840] © O58 - SDL:2015/06/18 08:42:02 A . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\WINDOWS\System32\drivers\mwac.sys [64216] © O58 - SDL:2013/09/05 02:36:46 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\WINDOWS\System32\drivers\nvlddmkm.sys [11273504] © O58 - SDL:2013/09/05 02:37:00 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\WINDOWS\System32\drivers\nvpciflt.sys [30496] © O58 - SDL:2013/08/22 14:43:31 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150368] © O58 - SDL:2013/08/22 14:43:32 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [168288] © O58 - SDL:2012/08/09 20:01:00 A . (.Corel Corporation - Px Engine Device Driver for 64-bit (x86-64).) -- C:\WINDOWS\System32\drivers\PxHlpa64.sys [56336] © O58 - SDL:2012/07/27 14:00:03 A . (.Windows (R) Win 7 DDK provider - HID Radio Switch mini driver for USB Fx2 De.) -- C:\WINDOWS\System32\drivers\RadioHIDMini.sys [23408] © O58 - SDL:2009/12/30 11:21:26 A . (.VS Revo Group - Revo Uninstaller Minifilter.) -- C:\WINDOWS\System32\drivers\revoflt.sys [31800] © O58 - SDL:2013/07/26 15:07:30 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.30 64-bit Dr.) -- C:\WINDOWS\System32\drivers\Rt630x64.sys [827096] © O58 - SDL:2013/10/02 21:37:02 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\WINDOWS\System32\drivers\RTKVHD64.sys [3678680] © O58 - SDL:2013/08/22 17:35:09 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\WINDOWS\System32\drivers\secdrv.sys [23040] © O58 - SDL:2013/08/22 14:43:31 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44896] © O58 - SDL:2013/08/22 14:43:32 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81760] © O58 - SDL:2013/08/22 14:43:32 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31072] © O58 - SDL:2013/11/29 04:32:30 A . (.Synaptics Incorporated - Synaptics Touchpad 64-bit Driver.) -- C:\WINDOWS\System32\drivers\SynTP.sys [541424] © O58 - SDL:2013/09/16 12:20:12 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\TeeDriverx64.sys [99288] © O58 - SDL:2013/08/22 14:43:34 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\WINDOWS\System32\drivers\viaide.sys [19808] © O58 - SDL:2013/08/22 14:43:34 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [168800] © O58 - SDL:2013/08/22 14:43:34 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305504] © O58 - SDL:2013/04/15 20:55:42 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\athw8x.sys [3786752] © O58 - SDL:2013/08/15 20:13:30 N . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\athwbx.sys [3859968] © ---\\ Last modified or created user files (18) - 4s O61 - LFC: 2015/08/31 11:39:22 A . (.Copyright © 2014.) -- C:\Users\donotdisturb\AppData\Local\Packages\Microsoft.BingMaps_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Utilities\5a49d0861bf47760979cb8a1656664d5\Utilities.ni.dll [450560] O61 - LFC: 2015/08/31 11:39:26 A . (.Copyright © 2014.) -- C:\Users\donotdisturb\AppData\Local\Packages\Microsoft.BingMaps_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Search\0e98fea516d0ee108ff43edbb31eeb23\Search.ni.dll [67584] O61 - LFC: 2015/08/31 11:39:26 A . (.Copyright © 2014.) -- C:\Users\donotdisturb\AppData\Local\Packages\Microsoft.BingMaps_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Requests\76c5ef118925356c7b8053239370716c\Requests.ni.dll [607744] O61 - LFC: 2015/08/31 11:39:25 A . (.Copyright © 2013.) -- C:\Users\donotdisturb\AppData\Local\Packages\Microsoft.BingMaps_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Microsoft.Bc95a2f00#\a7d4a611001c5d93e8804c46643b291c\Microsoft.Bing.Platform.Logging.ClientWinRT.ni.dll [1130496] O61 - LFC: 2015/08/31 11:39:28 A . (..) -- C:\Users\donotdisturb\AppData\Local\Packages\Microsoft.BingMaps_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Microsoft.B2384b708#\0e5e3fce9ca6c1503dacf1cbe03f1483\Microsoft.Bing.Client.Graph.ni.dll [496640] O61 - LFC: 2015/08/31 11:39:28 A . (.Copyright © 2014.) -- C:\Users\donotdisturb\AppData\Local\Packages\Microsoft.BingMaps_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\MapClientGraph\e082b2141a606af7c074988978ced778\MapClientGraph.ni.dll [276992] O61 - LFC: 2015/08/31 11:39:20 A . (.Copyright © 2014.) -- C:\Users\donotdisturb\AppData\Local\Packages\Microsoft.BingMaps_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Map\387d2e36d51adfefa8dbb703e3e8dcf1\Map.ni.exe [7814656] O61 - LFC: 2015/08/31 11:39:22 A . (.Copyright © 2014.) -- C:\Users\donotdisturb\AppData\Local\Packages\Microsoft.BingMaps_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\DataTypes\9d63c8b599271a31fa1fab26f7ccf721\DataTypes.ni.dll [1160192] O61 - LFC: 2015/08/31 11:39:26 A . (.Copyright © 2014.) -- C:\Users\donotdisturb\AppData\Local\Packages\Microsoft.BingMaps_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\ConfigModels\8a3a9ca673cc8e583a8889875061de60\ConfigModels.ni.dll [78336] O61 - LFC: 2015/08/31 11:39:26 A . (.Copyright © 2014.) -- C:\Users\donotdisturb\AppData\Local\Packages\Microsoft.BingMaps_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\ConfigManager\87c06095499b46ee90b11cefc6db700e\ConfigManager.ni.dll [208896] O61 - LFC: 2015/08/31 11:39:23 A . (..) -- C:\Users\donotdisturb\AppData\Local\Packages\Microsoft.BingMaps_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Bing.Maps\3e1ed29e88993063e5c80b7d3756029f\Bing.Maps.ni.dll [1336320] O61 - LFC: 2015/08/31 11:39:27 A . (.Copyright © 2014.) -- C:\Users\donotdisturb\AppData\Local\Packages\Microsoft.BingMaps_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Autosuggest\5e39ce89cbcf431243c0fb875f24b4b2\Autosuggest.ni.dll [197120] O61 - LFC: 2015/08/31 11:39:27 A . (.Copyright © 2014.) -- C:\Users\donotdisturb\AppData\Local\Packages\Microsoft.BingMaps_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0\NativeImages\Authentication\73ce4cecfb198a84d364f24ee466a59b\Authentication.ni.dll [244736] O61 - LFC: 2015/08/25 11:09:38 A . (..) -- C:\Users\donotdisturb\AppData\Local\Microsoft\Windows\appsFolderLayout.bin [1423] O61 - LFC: 2015/08/25 13:13:47 A . (..) -- C:\Users\donotdisturb\AppData\Local\Microsoft\Windows\INetCache\Virtualized\C\ProgramData\NVIDIA Corporation\Drs\nvdrssel.bin [1] O61 - LFC: 2015/09/01 13:38:04 A . (..) -- C:\Users\donotdisturb\AppData\Local\Microsoft\Windows\INetCache\IE\P2LUL421\urlblockindex[1].bin [16] O61 - LFC: 2015/08/25 14:00:15 A . (..) -- C:\Users\donotdisturb\AppData\Local\Microsoft\Windows\1053\StructuredQuerySchema.bin [374277] O61 - LFC: 2015/08/25 14:28:14 A . (..) -- C:\Users\donotdisturb\AppData\Local\Microsoft\Internet Explorer\UrlBlockManager\urlblocklist.bin [0] ---\\ File Associations Shell Spawning (10) - 0s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe © O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Startprogram för snapin-modulen Loggboken.) -- C:\Windows\System32\eventvwr.exe © O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe © O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe © O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registereditorn.) -- C:\Windows\regedit.exe © O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S ---\\ Start Menu Internet (4) - 0s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Användarspecifikt initieringstillbehör för.) -- C:\Windows\System32\ie4uinit.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Användarspecifikt initieringstillbehör för.) -- C:\Windows\System32\ie4uinit.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Användarspecifikt initieringstillbehör för.) -- C:\Windows\System32\ie4uinit.exe © ---\\ Search Browser Infection (1) - 0s O69 - SBI: SearchScopes [HKCU] {3F941D5A-8FD9-4dc4-94E5-F6C2C7CF6571} - (F-Secure Search) - http://search.f-secure.com/ ---\\ Search Svchost Services (34) - 0s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Tjänsten Application Experience.) -- C:\WINDOWS\System32\aelupsvc.dll [214528] © O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsofts spridningstjänst för smartkortsc.) -- C:\WINDOWS\System32\certprop.dll [156160] © O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsofts spridningstjänst för smartkortsc.) -- C:\WINDOWS\System32\certprop.dll [156160] © O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL för tjänsten Server.) -- C:\WINDOWS\system32\srvsvc.dll [329216] © O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Gruppricipklient.) -- C:\WINDOWS\System32\gpsvc.dll [1360896] © O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE-tillägg.) -- C:\WINDOWS\System32\ikeext.dll [1084416] © O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Tjänst som erbjuder IPv6-anslutning över et.) -- C:\WINDOWS\System32\iphlpsvc.dll [926208] © O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL-fil för tjänsten Secondary Logon.) -- C:\WINDOWS\system32\seclogon.dll [31744] © O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\WINDOWS\System32\appinfo.dll [110080] © O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Tjänsten iSCSI-identifiering.) -- C:\WINDOWS\system32\iscsiexe.dll [151040] © O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost-tjänst.) -- C:\WINDOWS\System32\eapsvc.dll [110592] © O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Schemaläggartjänsten.) -- C:\WINDOWS\system32\schedsvc.dll [1265152] © O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [230400] © O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Tjänsten Multimedia Class Scheduler.) -- C:\WINDOWS\system32\mmcss.dll [71168] © O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL-fil för tjänsten Computer Browser.) -- C:\WINDOWS\System32\browser.dll [135168] © O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\WINDOWS\system32\profsvc.dll [228864] © O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Tjänsten Konfiguration av fjärrskrivbord.) -- C:\Windows\System32\SessEnv.dll [339968] © O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problemrapporter och -lösningar.) -- C:\WINDOWS\System32\wercplsupport.dll [84992] © O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\WINDOWS\system32\kmsvc.dll [101376] © O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE-tjänsten.) -- C:\WINDOWS\System32\bdesvc.dll [348672] © O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Windows platsramverkstjänst.) -- C:\Windows\System32\GeofenceMonitorService.dll [522240] © O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Microsoft®-kontotjänst.) -- C:\WINDOWS\system32\wlidsvc.dll [1639424] © O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL-fil för Windows Shell-tematjänsten.) -- C:\WINDOWS\system32\themeservice.dll [59392] © O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Enhetskonfigurationshanteraren.) -- C:\WINDOWS\System32\DeviceSetupManager.dll [206848] © O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Tjänsten Microsoft Network Connectivity Ass.) -- C:\WINDOWS\System32\ncasvc.dll [166400] © O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Hanteraren för automatisk uppringning vid f.) -- C:\WINDOWS\System32\rasauto.dll [102912] © O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINDOWS\System32\rasmans.dll [542208] © O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamisk gränssnittshanterare.) -- C:\Windows\System32\mprdim.dll [226816] © O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Tjänsten System Event Notification Service.) -- C:\WINDOWS\System32\sens.dll [73728] © O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Komponenter för Microsoft NAT Helper.) -- C:\WINDOWS\System32\ipnathlp.dll [452608] © O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM)-telefoniserver.) -- C:\Windows\System32\tapisrv.dll [313344] © O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update-agenten.) -- C:\WINDOWS\system32\wuaueng.dll [3704320] © O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\WINDOWS\System32\qmgr.dll [933376] © O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - DLL-fil för Windows Shell-tjänster.) -- C:\Windows\System32\shsvcs.dll [640000] © ---\\ Services not Microsoft (SR=Run, SS=Stop) (23) - 10s SR - Auto [2014/07/23 01:31:23] [ 172344] SAS Core Service (!SASCORE) . (.SUPERAntiSpyware.com.) - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE SR - Auto [2013/01/26 22:12:12] [ 172104] Adobe Active File Monitor V11 (AdobeActiveFileMonitor11.0) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe © SR - Auto [2013/05/11 12:37:26] [ 65640] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe © SR - Auto [2015/06/01 20:58:00] [ 323152] AtherosSvc (AtherosSvc) . (.Windows (R) Win 7 DDK provider.) - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe © SS - Demand [2014/03/20 07:53:24] [ 279000] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe © SR - Auto [2014/01/29 13:20:52] [ 1593152] (Easy Launcher) . (.Samsung Electronics CO., LTD..) - C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe © SR - Auto [2015/08/17 14:01:12] [ 193064] F-Secure Dll Hoster (fshoster) . (.F-Secure Corporation.) - C:\Program Files (x86)\F-Secure\Internet Security\fshoster32.exe © SR - Demand [2015/05/26 16:47:44] [ 216104] F-Secure Management Agent (FSMA) . (.F-Secure Corporation.) - C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Common\FSMA32.EXE © SR - Auto [2015/08/24 14:06:43] [ 60456] F-Secure ORSP Client (FSORSPClient) . (.F-Secure Corporation.) - C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Reputation\fsorsp.exe © SR - Auto [2013/08/07 14:24:00] [ 15720] Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe © SR - Demand [2012/04/24 07:37:56] [ 169752] Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe © SR - Auto [2013/08/27 14:32:14] [ 747520] Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe © SS - Demand [2013/08/27 14:32:30] [ 828376] Intel(R) Capability Licensing Service TCP IP Interface (Intel(R) Capability Licensing Service TCP IP Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe © SR - Auto [2013/09/16 12:20:10] [ 169432] Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe © SR - Auto [2013/09/16 12:20:16] [ 390616] Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe © SR - Auto [2015/07/22 07:26:44] [ 713016] Malwarebytes Anti-Exploit Service (MbaeSvc) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe © SS - Auto [2015/06/18 08:39:50] [ 1133880] (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe © SR - Auto [2013/08/30 00:43:18] [ 920864] NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation.) - C:\WINDOWS\system32\nvvsvc.exe © SS - Auto [2013/09/05 02:35:24] [ 1364256] NVIDIA Update Service Daemon (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe © SR - Auto [2015/07/07 21:30:42] [ 3025248] SW Update Service (SWUpdateService) . (.Samsung Electronics CO., LTD..) - C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe © SR - Auto [2015/06/27 23:12:00] [ 79384] VoodooShieldService (VoodooShieldService) . (.VoodooSoft, LLC.) - C:\Program Files\VoodooShield\VoodooShieldService.exe SR - Auto [2015/06/01 20:30:34] [ 327296] ZAtheros Bt and Wlan Coex Agent (ZAtheros Bt and Wlan Coex Agent) . (.Atheros.) - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe © ---\\ Additional Scan (O88) (1) - 0s ~ No malicious or unnecessary items found. ---\\ Summary of the elements found (1) - 0s ~ No malicious or unnecessary items found. ~ End of the scan, 18138 items in 40 seconds (664)(0)()