~ ZHPDiag v2016.3.30.79 By Nicolas Coolman (2016/03/30) ~ Run by IbraTaa (Administrator) (2016/03/30 17:17:58) ~ Web: http://www.nicolascoolman.com ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ State version: Version OK ~ Mode: Scan ~ Report: C:\Users\Ibrahim\Desktop\ZHPDiag.txt ~ Report: C:\Users\Ibrahim\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ System startup: Normal (Normal boot) Windows 8.1 Pro, 64-bit (Build 9600) ---\\ Internet Browsers (3) - 0s GCIE: Google Chrome v49.0.2623.87 MFIE: Mozilla Firefox 45.0.1 (x86 fr) MSIE: Internet Explorer v11.0.9600.16518 ---\\ Windows Product Information (3) - 0s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK ---\\ System protection software (1) - 1s Windows Defender (Activate) ---\\ Information on the system (6) - 0s ~ Operating System: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel ~ Operating System: 64-bit ~ Boot mode: Normal (Normal boot) Total RAM: 1778.364 MB (26% free) System Restore: Activé (Enable) System drive C: has 151 GB () free of 205 GB ---\\ Connection to the system mode (3) - 0s ~ Computer Name: IBRAHIM ~ User Name: IbraTaa ~ Logged in as Administrator ---\\ Enumeration of the disk units (2) - 0s ~ Drive C: has 151 GB free of 205 GB (System) ~ Drive D: has 23 GB free of 99 GB ---\\ State of the Windows Security Center (11) - 0s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ---\\ Search Generic System Files (24) - 2s [MD5.63DC38C3E4564B2405D562855643ABA2] - 19/11/2013 - (.Microsoft Corporation - Windows Explorer.) -- C:\Windows\Explorer.exe [2328872] =>.Microsoft Windows® [MD5.6E0BDFBEEED65B017F2E4C2C910B0520] - 22/08/2013 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe [52736] =>.Microsoft Corporation [MD5.48CFA7BE561A7BE144C29BB912055016] - 22/08/2013 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\Windows\System32\Wininit.exe [144384] =>.Microsoft Corporation [MD5.263B6E451526A90FF8B1CEC759F22956] - 06/02/2014 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\Windows\System32\wininet.dll [2334208] =>.Microsoft Corporation [MD5.7C94FDA3809015B8F2208D2E1C221F17] - 22/08/2013 - (.Microsoft Corporation - Windows Logon Application.) -- C:\Windows\System32\Winlogon.exe [564736] =>.Microsoft Corporation [MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - 21/12/2013 - (.Microsoft Corporation - Software Licensing Library.) -- C:\Windows\System32\sppcomapi.dll [447488] =>.Microsoft Corporation [MD5.5A2020DDCCBB0ED08BAC2355A075F303] - 19/11/2013 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\System32\dnsapi.dll [656384] =>.Microsoft Corporation [MD5.2B9EED6835D269F35B310DC03D0F5768] - 19/11/2013 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\Syswow64\dnsapi.dll [492544] =>.Microsoft Corporation [MD5.239268BAB58EAE9A3FF4E08334C00451] - 22/08/2013 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [567296] =>.Microsoft Corporation [MD5.74B14192CF79A72F7536B27CB8814FBD] - 22/08/2013 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [26464] =>.Microsoft Windows® [MD5.2FA6510E33F7DEFEC03658B74101A9B9] - 22/08/2013 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [88576] =>.Microsoft Corporation [MD5.C6796EA22B513E3457514D92DCDB1A3D] - 22/08/2013 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [164352] =>.Microsoft Corporation [MD5.5DB26D7E0216D0BF364A81D3829AD7B9] - 22/08/2013 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [134656] =>.Microsoft Corporation [MD5.03909BDBFF0DCACCABF2B2D4ADEE44DC] - 22/08/2013 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [78336] =>.Microsoft Corporation [MD5.84CFC5EFA97D0C965EDE1D56F116A541] - 22/08/2013 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\Windows\System32\drivers\i8042prt.sys [107520] =>.Microsoft Corporation [MD5.E23D32BAF152FBE35F18C6A2AB8EF271] - 19/11/2013 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [141824] =>.Microsoft Corporation [MD5.6129EDB793A4255B1E2FB41773AC9D9A] - 19/11/2013 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [404992] =>.Microsoft Corporation [MD5.0217532E19A748F0E5D569307363D5FD] - 22/08/2013 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [282624] =>.Microsoft Corporation [MD5.725EF69B2DBEB7B33280019A556201BC] - 10/03/2014 - (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\drivers\ntfs.sys [2008408] =>.Microsoft Windows® [MD5.764B1121867B2D9B31C491668AC72B2B] - 22/08/2013 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\Windows\System32\drivers\Parport.sys [94208] =>.Microsoft Corporation [MD5.BBB6272B7F46C4640A8CDB8A70C3450F] - 22/08/2013 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [120832] =>.Microsoft Corporation [MD5.680C1DAE268B6FB67FA21B389A8B79EF] - 22/08/2013 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [195584] =>.Microsoft Corporation [MD5.FFF28F9F6823EB1756C60F1649560BBF] - 22/08/2013 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [107520] =>.Microsoft Corporation [MD5.C85C075DE5B6D0FE116043054DE8EE02] - 31/01/2014 - (.Microsoft Corporation - Volume Shadow Copy Driver.) -- C:\Windows\System32\drivers\volsnap.sys [311640] =>.Microsoft Windows® ---\\ Non Microsoft non disabled Windows Services (7) - 3s O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated® O23 - Service: afoir (afoir) . (...) - C:\ProgramData\afoir\afoir.exe (.not file.) =>PUP.Optional.Salus O23 - Service: ggbugreport (ggbugreport) . (...) - C:\Program Files (x86)\SearchesToYesbnd\bugreport.exe (.not file.) =>.Superfluous.ZoekyuTechnology O23 - Service: Google Update Service (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc® O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation - igfxCUIService Module.) - C:\Windows\System32\igfxCUIService.exe =>.Intel Corporation - pGFX® O23 - Service: LockHunter Delete On Restart Service (LHDeleteOnRestartSvc) . (...) - C:\Users\Ibrahim\Desktop\LHService.exe (.not file.) O23 - Service: Winsere (Winsere) . (...) - C:\Program Files (x86)\Winsere\Winsere\Winsere.exe {56ED9E7C28D4E65DF6EF0253265ACB11} =>PUP.Optional.YesSearches ---\\ Services not Microsoft (SR=Run, SS=Stop) (9) - 14s SR - Auto [14/12/2015] [ 82128] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated® SS - Demand [16/03/2016] [ 269504] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated® SS - Demand [02/10/2014] [ 281488] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe =>.Intel Corporation - pGFX® SS - Auto [08/03/2016] [ 154440] Google Update Service (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc® SS - Demand [08/03/2016] [ 154440] Google Update Service (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc® SR - Auto [02/10/2014] [ 319376] Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation.) - C:\Windows\System32\igfxCUIService.exe =>.Intel Corporation SS - Demand [26/05/2015] [ 148080] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation® SS - Auto [24/03/2016] [ 318520] Winsere (Winsere) . (...) - C:\Program Files (x86)\Winsere\Winsere\Winsere.exe {56ED9E7C28D4E65DF6EF0253265ACB11} =>PUP.Optional.YesSearches ---\\ Task Planned Automatically (28) - 5s [MD5.4EAF6F8F0B3BE33A0E3877EB7FFD48D4] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656] (.Activate.) =>.Adobe Systems, Incorporated® [MD5.99B993BD0F4C033D832B50D5E83BEBEC] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [269504] (.Activate.) =>.Adobe Systems Incorporated® [MD5.C856B04ABD5A57CA688EF6CC2964DFBD] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6638296] (.Activate.) =>.Piriform Ltd® [MD5.362EF26C8F6811F14F31CF70AF08F9D1] [APT] [Game_Booster_AutoUpdate] (.Copyright(c) 2005-2013.) -- C:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe [801304] (.Activate.) =>.IObit Information Technology® [MD5.750446ED76A5D13E902174DDDDA1A62B] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440] (.Activate.) =>.Google Inc® [MD5.750446ED76A5D13E902174DDDDA1A62B] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440] (.Activate.) =>.Google Inc® [MD5.00000000000000000000000000000000] [APT] [psv_Physlux] (...) -- C:\ProgramData\Airtostrong\Injob.reg & del C:\ProgramData\Airtostrong\Injob.reg & SCHTASKS /Delete /TN psv_Physlux /F (.not file.) [0] (.Activate.) =>PUP.Optional.Salus [MD5.00000000000000000000000000000000] [APT] [psv_Yearlab] (...) -- C:\ProgramData\serfev\In-Tex.reg & del C:\ProgramData\serfev\In-Tex.reg & SCHTASKS /Delete /TN psv_Yearlab /F (.not file.) [0] (.Activate.) =>.Superfluous.Empty [MD5.00000000000000000000000000000000] [APT] [snf] (...) -- C:\ProgramData\Airtostrong\Airtostrong.exe (.not file.) [0] (.Activate.) =>PUP.Optional.Salus [MD5.00000000000000000000000000000000] [APT] [snp] (...) -- C:\ProgramData\Airtostrong\Airtostrong.exe (.not file.) [0] (.Activate.) =>PUP.Optional.Salus [MD5.29B81898034EF7692A242E49310E0411] [APT] [Trigger KMS Activation] (.Copyright © 2013.) -- C:\Program Files\KMSnano\TriggerKMS.exe [54784] (.Activate.) =>HackTool.AutoKMS [MD5.00000000000000000000000000000000] [APT] [uroduce] (...) -- C:\Windows\system32\config\systemprofile\AppData\Local\Alpha Jaydom /t 2369 6517 (.not file.) [0] (.Activate.) =>.Superfluous.Empty [MD5.00000000000000000000000000000000] [APT] [AVAST Software\] (...) -- C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe (.not file.) [0] (.Activate.) =>.Superfluous.Empty O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [830] =>.Adobe Systems Incorporated® O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1082] =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1086] =>.Google Inc® O39 - APT: Adobe Acrobat Update Task - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Acrobat Update Task [3886] =>.Adobe Systems, Incorporated® O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [3720] =>.Adobe Systems Incorporated® O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\Windows\System32\Tasks\CCleanerSkipUAC [2792] =>.Piriform Ltd® O39 - APT: Game_Booster_AutoUpdate - (.Copyright(c) 2005-2013.) -- C:\Windows\System32\Tasks\Game_Booster_AutoUpdate [3164] =>.IObit Information Technology® O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [3822] =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [4058] =>.Google Inc® O39 - APT: psv_Physlux - (...) -- C:\Windows\System32\Tasks\psv_Physlux [3268] (.Orphean.) =>PUP.Optional.Salus O39 - APT: psv_Yearlab - (...) -- C:\Windows\System32\Tasks\psv_Yearlab [3252] (.Orphean.) =>.Superfluous.Orphean O39 - APT: snf - (...) -- C:\Windows\System32\Tasks\snf [3260] (.Orphean.) =>PUP.Optional.Salus O39 - APT: snp - (...) -- C:\Windows\System32\Tasks\snp [3638] (.Orphean.) =>PUP.Optional.Salus O39 - APT: Trigger KMS Activation - (.Copyright © 2013.) -- C:\Windows\System32\Tasks\Trigger KMS Activation [3492] =>HackTool.AutoKMS O39 - APT: uroduce - (...) -- C:\Windows\System32\Tasks\uroduce [3246] (.Orphean.) =>.Superfluous.Orphean ---\\ Process running (18) - 1s [MD5.C814D4A0B7B91E936B2DC0828C69ACAB] - (.Intel Corporation - igfxCUIService Module.) -- C:\Windows\System32\igfxCUIService.exe [319376] [PID.972] =>.Intel Corporation - pGFX® [MD5.F2CEEE9ABBCEF207ACB103215AC28BC2] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [82128] [PID.1204] =>.Adobe Systems, Incorporated® [MD5.F736D121FF053AF9E860B91912E4D6F1] - (.Intel Corporation - igfxEM Module.) -- C:\Windows\System32\igfxEM.exe [504208] [PID.2184] =>.Intel Corporation - pGFX® [MD5.A923F9AA853AFB3E1C779C6696E344D2] - (.Intel Corporation - igfxHK Module.) -- C:\Windows\System32\igfxHK.exe [246672] [PID.2320] =>.Intel Corporation - pGFX® [MD5.C8A299BB91912D446F19EA4BD4D135C7] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874136] [PID.1688] =>.Google Inc® [MD5.C8A299BB91912D446F19EA4BD4D135C7] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874136] [PID.2068] =>.Google Inc® [MD5.C8A299BB91912D446F19EA4BD4D135C7] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874136] [PID.1692] =>.Google Inc® [MD5.C8A299BB91912D446F19EA4BD4D135C7] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874136] [PID.896] =>.Google Inc® [MD5.C8A299BB91912D446F19EA4BD4D135C7] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874136] [PID.2768] =>.Google Inc® [MD5.C8A299BB91912D446F19EA4BD4D135C7] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874136] [PID.2040] =>.Google Inc® [MD5.C8A299BB91912D446F19EA4BD4D135C7] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874136] [PID.2744] =>.Google Inc® [MD5.1731DAF3C0A9F1004043BF7D05F74B84] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3825232] [PID.3900] =>.Tonec Inc. [MD5.E9C6EF9437ECB30911488F9313AD821A] - (.Tonec Inc. - Internet Download Manager agent for click m.) -- C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe [269848] [PID.3784] =>.Tonec Inc.® [MD5.65C182E329C7F71BAC6B5F7704043072] - (.AVAST Software - avast! Antivirus Installer.) -- C:\Users\Ibrahim\Downloads\Programs\avast_premier_antivirus_setup_online.exe [5178000] [PID.3028] =>.AVAST Software a.s.® [MD5.4A2722C449C35F54A44B13048E6AD831] - (.AVAST Software - avast! Antivirus Installer.) -- C:\Users\Ibrahim\AppData\Local\Temp\_av_iup.tm~a00376\instup.exe [777992] [PID.3220] =>.AVAST Software a.s.® [MD5.4A2722C449C35F54A44B13048E6AD831] - (.AVAST Software - avast! Antivirus Installer.) -- C:\Users\Ibrahim\AppData\Local\Temp\_av_iup.tm~a00376\New_b0108cd\instup.exe [777992] [PID.3636] =>.AVAST Software a.s.® [MD5.C8A299BB91912D446F19EA4BD4D135C7] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874136] [PID.328] =>.Google Inc® [MD5.4B58AB56B9368E6C8B6E1D17D2F54FF2] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Ibrahim\AppData\Roaming\ZHP\ZHPDiag3.exe [2168832] [PID.2672] =>.Nicolas Coolman ---\\ Google Chrome, Start,Search,Extensions (5) - 1s G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.hohosearch.com/?mode=nnnb&ptid=amz&uid=B6243A430AB41921E1B0A6A9A535A19D&v=20160323&ts=AHEpCH0mA34tAk.. =>.Superfluous.Hohosearch G2 - GCE: Preference [User Data\Default] [gighmmpiobklfepjocnamgkkbiglidom] AdBlock G2 - GCE: Preference [User Data\Default] [ngpampappnmepgilojfohadhhmbhlaek] IDM Integration Module G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [nonjdcjchghhkdoolnlbekcfllmednbl] Hover Zoom ---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (11) - 0s M0 - MFSP: prefs.js [IbraTaa - 41A66E7E5EE1] http://www.hohosearch.com/?ts=AHEpCH0mA34tAk..&v=20160323&uid=B6243A430AB41921E1B0A6A9A535A19D&ptid=amz&mode=ffseng =>.Superfluous.Hohosearch P2 - EXT FILE: (...) -- C:\Users\Ibrahim\AppData\Roaming\Mozilla\Firefox\Profiles\uc9cpnvm.default\searchplugins\findit.xml =>PUP.Optional.SmartBar P2 - EXT FILE: (...) -- C:\Users\Ibrahim\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi =>PUP.Optional.YesSearches P2 - EXT FILE: (...) -- C:\Users\Ibrahim\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\DD1B66D4.xml P2 - EXT FILE: (...) -- C:\Users\Ibrahim\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\findit.xml =>PUP.Optional.SmartBar P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\findit.xml =>PUP.Optional.SmartBar P2 - EXT: (.iMacros Team, iOpus Software GmbH - iMacros for Firefox.) -- C:\Users\Ibrahim\AppData\Roaming\Mozilla\Firefox\Profiles\uc9cpnvm.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} =>.iMacros Team, iOpus Software GmbH P2 - EXT: (.iMacros Team, iOpus Software GmbH - iMacros for Firefox.) -- C:\Users\Ibrahim\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} =>.iMacros Team, iOpus Software GmbH P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_182.dll =>.Adobe Systems Incorporated P2 - FPN: [HKLM] [@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp] - (...) -- C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll P2 - FPN: [HKLM] [@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf] - (...) -- C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll ---\\ Internet Explorer Extensions, Start, Search (21) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_ByuMcS4zqTgWbU8-ytuJWNspkFaDaBoQeR3UDVAzmmNZGM7N1sInc4jJWRqv5B9qycPc6n_sIRnExAzuj3EzFTo6s1Jv4rPRp67FuCTpNGs8EWvcDE-Jyt6rDbiKALiktTWT91s_hfQ2DfZDRoGxUoLczeQdF8NnQt8pBe8aD =>PUP.Optional.Linkury R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutxkij9_byumcs4zqtgwbu8-ytujwnspkfadaboqer3udvazmmnzgm7n1sinc4jjwrqv5b9qycpc6n_sirnexazcuc8wq0bsds-g96hitav-7qletqrnltpvrk4dnivazbuidsv-yoqm5zzqw0skucnfuuvcgoyfa6eculipp261jc4nc&q={searchterms} =>PUP.Optional.Linkury R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutxkij9_byumcs4zqtgwbu8-ytujwnspkfadaboqer3udvazmmnzgm7n1sinc4jjwrqv5b9qycpc6n_sirnexazcuc8wq0bsds-g96hitav-7qletqrnltpvrk4dnivazbuidsv-yoqm5zzqw0skucnfuuvcgoyfa6eculipp261jc4nc&q={searchterms} =>PUP.Optional.Linkury R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?linkid=54896 R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?linkid=255141 R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?linkid=54896 R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutxkij9_byumcs4zqtgwbu8-ytujwnspkfadaboqer3udvazmmnzgm7n1sinc4jjwrqv5b9qycpc6n_sirnexazcuc8wq0bsds-g96hitav-7qletqrnltpvrk4dnivazbuidsv-yoqm5zzqw0skucnfuuvcgoyfa6eculipp261jc4nc&q={searchterms} =>PUP.Optional.Linkury R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutxkij9_byumcs4zqtgwbu8-ytujwnspkfadaboqer3udvazmmnzgm7n1sinc4jjwrqv5b9qycpc6n_sirnexazcuc8wq0bsds-g96hitav-7qletqrnltpvrk4dnivazbuidsv-yoqm5zzqw0skucnfuuvcgoyfa6eculipp261jc4nc&q={searchterms} =>PUP.Optional.Linkury R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?linkid=54896 R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?linkid=255141 R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?linkid=54896 R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKEY_USERS\S-1-5-21-3912457198-2960490732-2523777487-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutxkij9_byumcs4zqtgwbu8-ytujwnspkfadaboqer3udvazmmnzgm7n1sinc4jjwrqv5b9qycpc6n_sirnexazcuc8wq0bsds-g96hitav-7qletqrnltpvrk4dnivazbuidsv-yoqm5zzqw0skucnfuuvcgoyfa6eculipp261jc4nc&q={searchterms} =>PUP.Optional.Linkury R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 ---\\ Internet Explorer, Proxy Management (4) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Line Analysis, IniFiles, Auto loading programs (3) - 1s F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation ---\\ Hosts file redirection (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (21) ---\\ Browser Helper Object (BHO) (3) - 0s O2 - BHO: IDM Helper [64Bits] - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll =>.Tonec Inc.® O2 - BHO: Groove GFS Browser Helper [64Bits] - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL =>.Microsoft Corporation® ---\\ Auto loading programs from Registry and folders (7) - 0s O4 - HKLM\..\Run: [BCSSync] . (.Microsoft Corporation - Microsoft Office 2010 component.) -- C:\Program Files\Microsoft Office\Office14\BCSSync.exe =>.Microsoft Corporation® O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd® O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc. O4 - HKLM\..\Wow6432Node\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe (.not file.) O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle America, Inc.® O4 - HKUS\S-1-5-21-3912457198-2960490732-2523777487-1001\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd® O4 - HKUS\S-1-5-21-3912457198-2960490732-2523777487-1001\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc. ---\\ Global shortcuts Startup (32) - 6s O4 - GS\Desktop [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Desktop [Administrator]: IbraTaa.lnk . (...) C:\Users\Ibrahim O4 - GS\Desktop [Administrator]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc. O4 - GS\Desktop [Administrator]: MEmu.lnk . (...) D:\Program Files\Microvirt\MEmu\MEmuConsole.exe {5528D5543296BFE427D43B8DDC0A20C7} O4 - GS\Desktop [Administrator]: Microsoft Word 2010.lnk . (...) C:\Windows\Installer\{91140000-0011-0000-1000-0000000FF1CE}\wordicon.exe =>.Microsoft Corporation® O4 - GS\Desktop [Administrator]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Ibrahim\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Administrator]: Lanceur d'applications Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\sendTo [Administrator]: Format Factory.lnk . (.Free Time - FormatFactory.) C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe =>.chen jun hao® O4 - GS\Desktop [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Desktop [Guest]: IbraTaa.lnk . (...) C:\Users\Ibrahim O4 - GS\Desktop [Guest]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc. O4 - GS\Desktop [Guest]: MEmu.lnk . (...) D:\Program Files\Microvirt\MEmu\MEmuConsole.exe {5528D5543296BFE427D43B8DDC0A20C7} O4 - GS\Desktop [Guest]: Microsoft Word 2010.lnk . (...) C:\Windows\Installer\{91140000-0011-0000-1000-0000000FF1CE}\wordicon.exe =>.Microsoft Corporation® O4 - GS\Desktop [Guest]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Ibrahim\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Guest]: Lanceur d'applications Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\sendTo [Guest]: Format Factory.lnk . (.Free Time - FormatFactory.) C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe =>.chen jun hao® O4 - GS\Desktop [IbraTaa]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Desktop [IbraTaa]: IbraTaa.lnk . (...) C:\Users\Ibrahim O4 - GS\Desktop [IbraTaa]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc. O4 - GS\Desktop [IbraTaa]: MEmu.lnk . (...) D:\Program Files\Microvirt\MEmu\MEmuConsole.exe {5528D5543296BFE427D43B8DDC0A20C7} O4 - GS\Desktop [IbraTaa]: Microsoft Word 2010.lnk . (...) C:\Windows\Installer\{91140000-0011-0000-1000-0000000FF1CE}\wordicon.exe =>.Microsoft Corporation® O4 - GS\Desktop [IbraTaa]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\Desktop [IbraTaa]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Ibrahim\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [IbraTaa]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [IbraTaa]: Lanceur d'applications Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\sendTo [IbraTaa]: Format Factory.lnk . (.Free Time - FormatFactory.) C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe =>.chen jun hao® O4 - GS\CommonDesktop [Public]: Acrobat Reader DC.lnk . (.Adobe Systems Incorporated - Adobe Acrobat Reader DC.) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe =>.Adobe Systems, Incorporated® O4 - GS\Programs [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® ---\\ Lop.com/Domain Hijackers (3) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{56D6CD41-C061-4714-BDF7-3514806442C2}: NameServer = 4.4.2.2,8.8.8.8 O17 - HKLM\System\CCS\Services\Tcpip\..\{56D6CD41-C061-4714-BDF7-3514806442C2}: DhcpNameServer = 192.168.1.1 ---\\ Extra protocols (21) - 0s O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\SysWOW64\inetcomm.dll =>.Microsoft Corporation O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation O18 - Filter: text/xml [64Bits] - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL =>.Microsoft Corporation® ---\\ AppInit_DLLs Registry value Autorun (1) - 0s O20 - AppInit_DLLs: . (...) - C:\ProgramData\Airtostrong\MathLa.dll =>PUP.Optional.Salus ---\\ Software installed (22) - 7s O42 - Logiciel: Adobe Acrobat Reader DC - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1033-7B44-AC0F074E4100} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Flash Player 21 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated® O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>.Piriform Ltd® O42 - Logiciel: Cheat Engine 6.4 - (.Cheat Engine.) [HKLM][64Bits] -- Cheat Engine 6.4_is1 =>.Cheat Engine® O42 - Logiciel: FormatFactory 3.3.4.0 - (.Format Factory.) [HKLM][64Bits] -- FormatFactory =>.Format Factory O42 - Logiciel: Game Booster 3 - (.IObit.) [HKLM][64Bits] -- Game Booster_is1 =>.IObit Information Technology® O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome =>.Google Inc® O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc. O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM][64Bits] -- Internet Download Manager =>.Tonec Inc.® O42 - Logiciel: Java 8 Update 74 - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83218074F0} =>.Oracle Corporation O42 - Logiciel: Java Auto Updater - (.Oracle Corporation.) [HKLM][64Bits] -- {4A03706F-666A-4037-7777-5F2748764D10} =>.Oracle Corporation O42 - Logiciel: KMSnano 24 - (...) [HKLM][64Bits] -- KMSnano 24_is1 =>HackTool.AutoKMS O42 - Logiciel: LockHunter 3.1, 32/64 bit - (.Crystal Rich Ltd.) [HKLM][64Bits] -- LockHunter_is1 =>.Crystal Rich Ltd O42 - Logiciel: MEmu - (.Microvirt.) [HKLM][64Bits] -- MEmu O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation O42 - Logiciel: Mozilla Firefox 45.0.1 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 45.0.1 (x86 fr) =>.Mozilla Corporation® O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService =>.Mozilla O42 - Logiciel: MSVCRT Redists - (.Sony Creative Software Inc..) [HKLM][64Bits] -- {33C19CDE-E935-11E0-A0DA-F04DA23A5C58} =>.Sony Creative Software Inc. O42 - Logiciel: Pro Evolution Soccer 2013 - (.KONAMI.) [HKLM][64Bits] -- {C2523AE6-F335-4D0B-BC15-1C07E4ACE629} =>.Konami O42 - Logiciel: StartIsBack+ - (.startisback.com.) [HKCU][64Bits] -- StartIsBack {109C} =>.startisback.com O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN O42 - Logiciel: WinRAR 5.31 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver =>.win.rar GmbH® ---\\ HKCU & HKLM Software Keys (93) - 7s HKLM\SOFTWARE\Wow6432Node\Adobe HKLM\SOFTWARE\Wow6432Node\AVAST Software HKLM\SOFTWARE\Wow6432Node\AVG HKLM\SOFTWARE\Wow6432Node\AviSynth HKLM\SOFTWARE\Wow6432Node\Baidu HKLM\SOFTWARE\Wow6432Node\Baidu Security HKLM\SOFTWARE\Wow6432Node\Baidu_Drp_pos HKLM\SOFTWARE\Wow6432Node\CDDB HKLM\SOFTWARE\Wow6432Node\CLSID HKLM\SOFTWARE\Wow6432Node\Foxit Software HKLM\SOFTWARE\Wow6432Node\GNU HKLM\SOFTWARE\Wow6432Node\Google HKLM\SOFTWARE\Wow6432Node\GTASAMODHotCoffee HKLM\SOFTWARE\Wow6432Node\HaaliMkx HKLM\SOFTWARE\Wow6432Node\hohosearchSoftware =>.Superfluous.Hohosearch HKLM\SOFTWARE\Wow6432Node\Intel HKLM\SOFTWARE\Wow6432Node\Internet Download Manager HKLM\SOFTWARE\Wow6432Node\IObit HKLM\SOFTWARE\Wow6432Node\JavaSoft HKLM\SOFTWARE\Wow6432Node\JreMetrics HKLM\SOFTWARE\Wow6432Node\KasperskyLab HKLM\SOFTWARE\Wow6432Node\Khronos HKLM\SOFTWARE\Wow6432Node\KONAMI HKLM\SOFTWARE\Wow6432Node\Macromedia HKLM\SOFTWARE\Wow6432Node\Mozilla HKLM\SOFTWARE\Wow6432Node\mozilla.org HKLM\SOFTWARE\Wow6432Node\MozillaPlugins HKLM\SOFTWARE\Wow6432Node\mtafoir =>PUP.Optional.Salus HKLM\SOFTWARE\Wow6432Node\mtAirtostrong =>PUP.Optional.Salus HKLM\SOFTWARE\Wow6432Node\mtRonzap =>PUP.Optional.Salus HKLM\SOFTWARE\Wow6432Node\mtserfev HKLM\SOFTWARE\Wow6432Node\ODBC HKLM\SOFTWARE\Wow6432Node\Opera Software HKLM\SOFTWARE\Wow6432Node\Rtp HKLM\SOFTWARE\Wow6432Node\Sega HKLM\SOFTWARE\Wow6432Node\Sony Creative Software HKLM\SOFTWARE\Wow6432Node\SourceTec HKLM\SOFTWARE\Wow6432Node\Valve HKLM\SOFTWARE\Wow6432Node\VideoLAN HKLM\SOFTWARE\Wow6432Node\RegisteredApplications HKCU\SOFTWARE\Adobe HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\Avg HKCU\SOFTWARE\Baidu Security HKCU\SOFTWARE\Cheat Engine HKCU\SOFTWARE\DirectShow HKCU\SOFTWARE\Disc Soft HKCU\SOFTWARE\DownloadManager HKCU\SOFTWARE\ej-technologies HKCU\SOFTWARE\Foxit Software HKCU\SOFTWARE\FreeTime HKCU\SOFTWARE\Gabest HKCU\SOFTWARE\GNU HKCU\SOFTWARE\Google HKCU\SOFTWARE\Haali HKCU\SOFTWARE\iMacros HKCU\SOFTWARE\Intel HKCU\SOFTWARE\JavaSoft HKCU\SOFTWARE\Licenses HKCU\SOFTWARE\LockHunter HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\Mine HKCU\SOFTWARE\Mozilla HKCU\SOFTWARE\MozillaPlugins HKCU\SOFTWARE\mtafoir =>PUP.Optional.Salus HKCU\SOFTWARE\mtAirtostrong =>PUP.Optional.Salus HKCU\SOFTWARE\mtRonzap =>PUP.Optional.Salus HKCU\SOFTWARE\mtserfev HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\Octoshape HKCU\SOFTWARE\ODBC HKCU\SOFTWARE\Opera Software HKCU\SOFTWARE\Piriform HKCU\SOFTWARE\Pokki HKCU\SOFTWARE\ProtectedData HKCU\SOFTWARE\QtProject HKCU\SOFTWARE\RegisteredApplications HKCU\SOFTWARE\Rtp HKCU\SOFTWARE\SimpleTV by SergeyVS#3 HKCU\SOFTWARE\Sony Creative Software HKCU\SOFTWARE\SourceTec HKCU\SOFTWARE\StartIsBack HKCU\SOFTWARE\The Silicon Realms Toolworks HKCU\SOFTWARE\Trolltech HKCU\SOFTWARE\Unity HKCU\SOFTWARE\Valve HKCU\SOFTWARE\WinRAR HKCU\SOFTWARE\WinRAR SFX HKCU\SOFTWARE\Wow6432Node HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Software HKCU\SOFTWARE\AppDataLow\Software\JavaSoft HKCU\SOFTWARE\AppDataLow\Software\Unity ---\\ Contents of the Common Files folders (178) - 11s O43 - CFD: 30/03/2016 - [] D -- C:\Program Files\AVAST Software O43 - CFD: 07/01/2016 - [] D -- C:\Program Files\CCleaner =>.Piriform Ltd® O43 - CFD: 30/03/2016 - [] D -- C:\Program Files\Common Files O43 - CFD: 19/03/2016 - [] D -- C:\Program Files\DIFX {5EB707539E398E4A4DBB8E8E267E8753} O43 - CFD: 17/06/2015 - [] D -- C:\Program Files\Intel O43 - CFD: 18/06/2015 - [] D -- C:\Program Files\Internet Explorer O43 - CFD: 09/03/2016 - [] D -- C:\Program Files\KMSnano =>HackTool.AutoKMS O43 - CFD: 18/06/2015 - [] D -- C:\Program Files\LockHunter {1A3971F7D5A04EBA878183D0A57E1EC1} O43 - CFD: 01/01/2016 - [] D -- C:\Program Files\Microsoft Analysis Services O43 - CFD: 01/01/2016 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation® O43 - CFD: 25/12/2015 - [] D -- C:\Program Files\Microsoft Silverlight =>.Microsoft Corporation® O43 - CFD: 01/01/2016 - [] D -- C:\Program Files\Microsoft SQL Server Compact Edition O43 - CFD: 01/01/2016 - [] D -- C:\Program Files\Microsoft Sync Framework O43 - CFD: 01/01/2016 - [] D -- C:\Program Files\Microsoft Synchronization Services O43 - CFD: 28/06/2015 - [] D -- C:\Program Files\MSBuild O43 - CFD: 28/06/2015 - [] D -- C:\Program Files\Reference Assemblies O43 - CFD: 22/08/2013 - [0] HD -- C:\Program Files\Uninstall Information O43 - CFD: 18/06/2015 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation® O43 - CFD: 22/08/2013 - [] D -- C:\Program Files\Windows Journal O43 - CFD: 22/08/2013 - [] D -- C:\Program Files\Windows Mail O43 - CFD: 22/08/2013 - [] D -- C:\Program Files\Windows Media Player O43 - CFD: 22/08/2013 - [] D -- C:\Program Files\Windows Multimedia Platform O43 - CFD: 22/08/2013 - [] D -- C:\Program Files\Windows NT O43 - CFD: 22/08/2013 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation® O43 - CFD: 22/08/2013 - [] D -- C:\Program Files\Windows Portable Devices O43 - CFD: 22/08/2013 - [] SHD -- C:\Program Files\Windows Sidebar O43 - CFD: 09/03/2016 - [] HD -- C:\Program Files\WindowsApps O43 - CFD: 22/08/2013 - [] D -- C:\Program Files\WindowsPowerShell O43 - CFD: 16/03/2016 - [] D -- C:\Program Files\WinRAR =>.win.rar GmbH® O43 - CFD: 30/03/2016 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Systems, Incorporated® O43 - CFD: 28/12/2015 - [] D -- C:\Program Files (x86)\Cheat Engine 6.4 =>.Cheat Engine® O43 - CFD: 30/03/2016 - [] D -- C:\Program Files (x86)\Common Files O43 - CFD: 12/07/2015 - [] D -- C:\Program Files (x86)\FreeTime =>.chen jun hao® O43 - CFD: 08/03/2016 - [] D -- C:\Program Files (x86)\Google =>.Google Inc® O43 - CFD: 29/06/2015 - [] D -- C:\Program Files (x86)\Internet Download Manager O43 - CFD: 18/06/2015 - [] D -- C:\Program Files (x86)\Internet Explorer O43 - CFD: 03/09/2015 - [] D -- C:\Program Files (x86)\IObit =>.IObit Information Technology® O43 - CFD: 25/03/2016 - [] D -- C:\Program Files (x86)\Java =>.Oracle America, Inc.® O43 - CFD: 28/06/2015 - [] D -- C:\Program Files (x86)\KONAMI {5E5F5605339057A565AE5D1373927F29} O43 - CFD: 01/01/2016 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services O43 - CFD: 01/01/2016 - [] D -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation® O43 - CFD: 25/12/2015 - [] D -- C:\Program Files (x86)\Microsoft Silverlight =>.Microsoft Corporation® O43 - CFD: 01/01/2016 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio 8 O43 - CFD: 01/01/2016 - [] D -- C:\Program Files (x86)\Microsoft.NET O43 - CFD: 19/03/2016 - [] D -- C:\Program Files (x86)\Mozilla Firefox =>.Mozilla Corporation® O43 - CFD: 18/06/2015 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service =>.Mozilla Corporation® O43 - CFD: 01/01/2016 - [] D -- C:\Program Files (x86)\MSBuild O43 - CFD: 28/06/2015 - [] D -- C:\Program Files (x86)\Reference Assemblies O43 - CFD: 30/03/2016 - [] D -- C:\Program Files (x86)\SearchesToYesbnd =>.Superfluous.ZoekyuTechnology O43 - CFD: 24/03/2016 - [] D -- C:\Program Files (x86)\VideoLAN O43 - CFD: 18/06/2015 - [] D -- C:\Program Files (x86)\Windows Defender O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Windows Mail O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Windows Media Player O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Windows NT O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation® O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 22/08/2013 - [] SHD -- C:\Program Files (x86)\Windows Sidebar O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\WindowsPowerShell O43 - CFD: 26/03/2016 - [] D -- C:\Program Files (x86)\Winsere {56ED9E7C28D4E65DF6EF0253265ACB11} =>PUP.Optional.YesSearches O43 - CFD: 26/03/2016 - [] D -- C:\Program Files (x86)\WinTaske {56ED9E7C28D4E65DF6EF0253265ACB11} =>PUP.Optional.YesSearches O43 - CFD: 22/08/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 22/08/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 19/11/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 18/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon LBP3000 O43 - CFD: 16/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Printer Uninstaller O43 - CFD: 17/06/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner O43 - CFD: 28/12/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4 O43 - CFD: 18/06/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Booster 3 O43 - CFD: 18/06/2015 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 29/06/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager O43 - CFD: 25/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java O43 - CFD: 09/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSnano =>HackTool.AutoKMS O43 - CFD: 18/06/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LockHunter O43 - CFD: 22/08/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 23/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MEmu O43 - CFD: 01/01/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office O43 - CFD: 25/12/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight O43 - CFD: 28/06/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PESEdit.com 2013 Patch O43 - CFD: 01/01/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint O43 - CFD: 30/03/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp O43 - CFD: 22/08/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 22/08/2013 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 25/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN O43 - CFD: 16/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 30/03/2016 - [] D -- C:\ProgramData\Adobe O43 - CFD: 16/03/2016 - [] D -- C:\ProgramData\Airtostrong =>PUP.Optional.Salus O43 - CFD: 14/03/2016 - [] D -- C:\ProgramData\Airtostrongs =>PUP.Optional.Salus O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 30/03/2016 - [] D -- C:\ProgramData\AVAST Software O43 - CFD: 22/07/2015 - [0] D -- C:\ProgramData\BCloudScan_exe O43 - CFD: 20/03/2016 - [] HD -- C:\ProgramData\Common Files O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 18/06/2015 - [0] D -- C:\ProgramData\IDM O43 - CFD: 17/03/2016 - [] D -- C:\ProgramData\IObit O43 - CFD: 17/03/2016 - [] D -- C:\ProgramData\KONAMI O43 - CFD: 19/06/2015 - [] D -- C:\ProgramData\LHService O43 - CFD: 19/06/2015 - [] D -- C:\ProgramData\LockHunter O43 - CFD: 21/06/2015 - [] D -- C:\ProgramData\Logs O43 - CFD: 20/03/2016 - [] D -- C:\ProgramData\MFAData O43 - CFD: 01/01/2016 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 01/01/2016 - [] D -- C:\ProgramData\Microsoft Help O43 - CFD: 18/06/2015 - [] D -- C:\ProgramData\Mozilla O43 - CFD: 24/06/2015 - [] D -- C:\ProgramData\Oracle O43 - CFD: 04/09/2015 - [] D -- C:\ProgramData\Package Cache O43 - CFD: 22/08/2013 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft O43 - CFD: 16/03/2016 - [] D -- C:\ProgramData\serfev O43 - CFD: 15/03/2016 - [] D -- C:\ProgramData\serfevs O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 24/06/2015 - [] D -- C:\ProgramData\Sun O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 28/02/2016 - [] D -- C:\ProgramData\Thunder Network O43 - CFD: 30/03/2016 - [] D -- C:\Program Files (x86)\Common Files\Adobe O43 - CFD: 17/06/2015 - [] D -- C:\Program Files (x86)\Common Files\Intel O43 - CFD: 19/03/2016 - [] D -- C:\Program Files (x86)\Common Files\Java O43 - CFD: 01/01/2016 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Common Files\Services O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Common Files\System O43 - CFD: 30/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Roaming\Adobe O43 - CFD: 29/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Roaming\DMCache O43 - CFD: 25/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Roaming\Elex-tech =>PUP.Optional.Elex O43 - CFD: 25/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Roaming\Foxit Software O43 - CFD: 01/01/2016 - [] D -- C:\Users\Ibrahim\AppData\Roaming\Identities O43 - CFD: 30/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Roaming\IDM O43 - CFD: 18/06/2015 - [] D -- C:\Users\Ibrahim\AppData\Roaming\LockHunter O43 - CFD: 17/06/2015 - [] D -- C:\Users\Ibrahim\AppData\Roaming\Macromedia O43 - CFD: 13/03/2016 - [] SD -- C:\Users\Ibrahim\AppData\Roaming\Microsoft O43 - CFD: 24/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Roaming\Mozilla O43 - CFD: 29/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Roaming\Notepad++ O43 - CFD: 23/03/2016 - [0] D -- C:\Users\Ibrahim\AppData\Roaming\Nox O43 - CFD: 25/03/2016 - [0] D -- C:\Users\Ibrahim\AppData\Roaming\Octoshape O43 - CFD: 28/02/2016 - [] D -- C:\Users\Ibrahim\AppData\Roaming\OpenCandy =>PUP.Optional.OpenCandy O43 - CFD: 04/12/2015 - [0] D -- C:\Users\Ibrahim\AppData\Roaming\Opera Software O43 - CFD: 27/03/2016 - [0] D -- C:\Users\Ibrahim\AppData\Roaming\Publish Providers O43 - CFD: 29/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Roaming\Sony O43 - CFD: 19/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Roaming\Sun O43 - CFD: 30/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Roaming\vlc O43 - CFD: 17/06/2015 - [] D -- C:\Users\Ibrahim\AppData\Roaming\WinRAR O43 - CFD: 30/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Roaming\ZHP O43 - CFD: 29/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108 O43 - CFD: 30/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Local\Adobe O43 - CFD: 17/06/2015 - [0] SHD -- C:\Users\Ibrahim\AppData\Local\Application Data O43 - CFD: 20/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Local\Avg O43 - CFD: 21/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Local\AvgSetupLog O43 - CFD: 30/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Local\CEF O43 - CFD: 03/07/2015 - [] D -- C:\Users\Ibrahim\AppData\Local\Daring_Development_Inc O43 - CFD: 25/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Local\Diagnostics O43 - CFD: 03/07/2015 - [] D -- C:\Users\Ibrahim\AppData\Local\Disc_Soft_Ltd O43 - CFD: 23/02/2016 - [0] D -- C:\Users\Ibrahim\AppData\Local\ElevatedDiagnostics O43 - CFD: 24/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Local\Geckofx O43 - CFD: 09/10/2015 - [] D -- C:\Users\Ibrahim\AppData\Local\Google O43 - CFD: 17/06/2015 - [0] SHD -- C:\Users\Ibrahim\AppData\Local\History O43 - CFD: 23/12/2015 - [] D -- C:\Users\Ibrahim\AppData\Local\HomeDev O43 - CFD: 08/08/2015 - [] D -- C:\Users\Ibrahim\AppData\Local\Macromedia O43 - CFD: 20/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Local\MFAData O43 - CFD: 29/02/2016 - [] D -- C:\Users\Ibrahim\AppData\Local\Microsoft O43 - CFD: 01/01/2016 - [] D -- C:\Users\Ibrahim\AppData\Local\Microsoft Help O43 - CFD: 18/06/2015 - [] D -- C:\Users\Ibrahim\AppData\Local\Mozilla O43 - CFD: 23/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Local\Nox O43 - CFD: 04/12/2015 - [0] D -- C:\Users\Ibrahim\AppData\Local\Opera Software O43 - CFD: 08/08/2015 - [] D -- C:\Users\Ibrahim\AppData\Local\Packages O43 - CFD: 18/06/2015 - [] D -- C:\Users\Ibrahim\AppData\Local\Programs O43 - CFD: 29/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Local\Sony O43 - CFD: 04/12/2015 - [] D -- C:\Users\Ibrahim\AppData\Local\StartIsBack O43 - CFD: 30/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Local\Temp O43 - CFD: 17/06/2015 - [0] SHD -- C:\Users\Ibrahim\AppData\Local\Temporary Internet Files O43 - CFD: 12/09/2015 - [0] D -- C:\Users\Ibrahim\AppData\Local\Unity O43 - CFD: 29/06/2015 - [] D -- C:\Users\Ibrahim\AppData\Local\VirtualStore O43 - CFD: 22/08/2013 - [] RD -- C:\Users\Ibrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 22/08/2013 - [] RD -- C:\Users\Ibrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 18/06/2015 - [] RD -- C:\Users\Ibrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 12/07/2015 - [] D -- C:\Users\Ibrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory O43 - CFD: 14/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome O43 - CFD: 29/06/2015 - [] D -- C:\Users\Ibrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager O43 - CFD: 22/08/2013 - [] D -- C:\Users\Ibrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 22/08/2013 - [] RD -- C:\Users\Ibrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 16/03/2016 - [] D -- C:\Users\Ibrahim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR ---\\ ShellIconOverlayIdentifiers (SIOI) (7) - 2s O106 - SIOI: Groove Explorer Icon Overlay 1 (GFS Unread Stub) [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] - {99FD978C-D287-4F50-827F-B2C658EDA8E7}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O106 - SIOI: Groove Explorer Icon Overlay 2 (GFS Stub) [Groove Explorer Icon Overlay 2 (GFS Stub)] - {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O106 - SIOI: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] - {920E6DB1-9907-4370-B3A0-BAFC03D81399}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O106 - SIOI: Groove Explorer Icon Overlay 3 (GFS Folder) [Groove Explorer Icon Overlay 3 (GFS Folder)] - {16F3DD56-1AF5-4347-846D-7C10C4192619}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O106 - SIOI: Groove Explorer Icon Overlay 4 (GFS Unread Mark) [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] - {2916C86E-86A6-43FE-8112-43ABE6BF8DCC}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O106 - SIOI: Sync root make available online verb [StorageProviderError] - {0CA2640D-5B9C-4c59-A5FB-2DA61A7437CF}. (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\SysWOW64\shell32.dll =>.Microsoft Windows® O106 - SIOI: Sync root make available online verb [StorageProviderSyncing] - {0A30F902-8398-4ee8-86F7-4CFB589F04D1}. (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\SysWOW64\shell32.dll =>.Microsoft Windows® ---\\ System Drivers List (43) - 10s O58 - SDL:2013/08/22 13:43:41 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\drivers\3ware.sys [108896] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:41 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\Windows\System32\drivers\adp80xx.sys [782176] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:41 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [79200] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:41 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [259424] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:40 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [25952] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:41 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [114016] =>.Microsoft Windows® O58 - SDL:2013/08/13 00:25:46 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\drivers\bcmfn2.sys [17624] =>.Broadcom Corporation® O58 - SDL:2013/08/22 13:43:41 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [531296] =>.Microsoft Windows® O58 - SDL:2015/07/03 07:25:30 A . (.Disc Soft Ltd - DAEMON Tools Lite Virtual SCSI Bus Driver.) -- C:\Windows\System32\drivers\dtlitescsibus.sys [30264] =>.Disc Soft Ltd® O58 - SDL:2013/08/22 13:43:45 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3357024] =>.Microsoft Windows® O58 - SDL:2010/10/20 07:34:26 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\drivers\HECIx64.sys [56344] =>.Intel Corporation® O58 - SDL:2013/08/22 13:43:45 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [64352] =>.Microsoft Windows® O58 - SDL:2013/07/30 19:47:35 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568] =>.Intel Corporation - Software and Firmware Products® O58 - SDL:2013/07/25 20:05:39 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320] =>.Intel Corporation - Software and Firmware Products® O58 - SDL:2013/08/10 01:39:30 A . (.Intel Corporation - Intel Rapid Storage Technology driver (inbo.) -- C:\Windows\System32\drivers\iaStorAV.sys [651248] =>.Intel Corporation - Intel® Rapid Storage Technology® O58 - SDL:2013/08/22 13:43:45 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [412000] =>.Microsoft Windows® O58 - SDL:2015/05/20 13:55:54 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\drivers\idmwfp.sys [197616] =>.Tonec Inc.® O58 - SDL:2014/10/02 03:54:16 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd64.sys [3828152] =>.Intel Corporation - pGFX® O58 - SDL:2014/08/01 21:18:33 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\Windows\System32\drivers\intelaud.sys [38296] =>.Intel Wireless Display® O58 - SDL:2014/08/01 21:18:33 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\Windows\System32\drivers\iwdbus.sys [27032] =>.Intel Wireless Display® O58 - SDL:2013/08/22 13:43:44 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [109408] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:45 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [93536] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:44 A . (.LSI Corporation - LSI SAS Gen3 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas3.sys [81760] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:45 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sss.sys [82784] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:45 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [56672] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:45 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\megasr.sys [575840] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:49 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\Windows\System32\drivers\mvumis.sys [63840] =>.Microsoft Windows® O58 - SDL:2009/10/20 19:19:54 A . (.CACE Technologies, Inc. - npf.sys (NT5/6 AMD64) Kernel Driver.) -- C:\Windows\System32\drivers\npf.sys [47632] =>.CACE Technologies, Inc.® O58 - SDL:2013/08/22 13:43:31 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [150368] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:32 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [168288] =>.Microsoft Windows® O58 - SDL:2013/06/18 15:46:17 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.30 64-bit Dr.) -- C:\Windows\System32\drivers\Rt630x64.sys [591360] =>.Realtek O58 - SDL:2013/08/22 16:35:09 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] =>.Macrovision Corporation, Macrovision Europe Limited, O58 - SDL:2013/08/22 13:43:31 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [44896] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:32 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [81760] =>.Microsoft Windows® O58 - SDL:2014/01/22 08:52:10 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ve.) -- C:\Windows\System32\drivers\ssudbus.sys [108800] =>.DEVGURU CO LTD® O58 - SDL:2013/08/22 13:43:32 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\Windows\System32\drivers\stexstor.sys [31072] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:40:24 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver.) -- C:\Windows\System32\drivers\tap0901.sys [40664] =>.OpenVPN Technologies, Inc.® O58 - SDL:2014/05/16 14:04:46 A . (.Oracle Corporation - VirtualBox Support Driver.) -- C:\Windows\System32\drivers\VBoxDrv.sys [254240] =>.Oracle Corporation® O58 - SDL:2015/09/16 07:07:12 A . (.BigNox Corporation - VirtualBox USB Monitor Driver.) -- C:\Windows\System32\drivers\VBoxUSBMon.sys [127432] {5EB707539E398E4A4DBB8E8E267E8753} O58 - SDL:2013/08/22 13:43:34 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [19808] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:34 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [168800] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:34 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\Windows\System32\drivers\VSTXRAID.SYS [305504] =>.Microsoft Windows® O58 - SDL:2015/09/16 04:29:46 A . (.BigNox Corporation - VirtualBox Support Driver.) -- C:\Windows\System32\drivers\XQHDrv.sys [253384] {5EB707539E398E4A4DBB8E8E267E8753} ---\\ Last modified or created user files (11) - 28s O61 - LFC: 2016/03/23 12:48:07 A . (.Microvirt.) -- C:\Users\Ibrahim\Downloads\Programs\Memu-Setup.exe [288262056] {5528D5543296BFE427D43B8DDC0A20C7} O61 - LFC: 2016/03/30 12:26:44 A . (..) -- C:\Users\Ibrahim\Documents\KONAMI\Pro Evolution Soccer 2013\save\ML01.bin [8985744] O61 - LFC: 2016/03/30 12:26:46 A . (..) -- C:\Users\Ibrahim\Documents\KONAMI\Pro Evolution Soccer 2013\save\OPTION.bin [402008] O61 - LFC: 2016/03/29 21:59:51 A . (..) -- C:\Users\Ibrahim\AppData\Local\Sony\Vegas Pro\11.0\OCL 5526c9eb-10c4fd9a.bin [80201] O61 - LFC: 2016/03/29 21:59:50 A . (..) -- C:\Users\Ibrahim\AppData\Local\Sony\Vegas Pro\11.0\OCL 5526c9eb-5e70dfb3.bin [84698] O61 - LFC: 2016/03/29 21:59:51 A . (..) -- C:\Users\Ibrahim\AppData\Local\Sony\Vegas Pro\11.0\OCL 5526c9eb-7ee57f8e.bin [203363] O61 - LFC: 2016/03/29 21:59:51 A . (..) -- C:\Users\Ibrahim\AppData\Local\Sony\Vegas Pro\11.0\OCL 5526c9eb-a5b9ed64.bin [66436] O61 - LFC: 2016/03/29 21:59:53 A . (..) -- C:\Users\Ibrahim\AppData\Local\Sony\Vegas Pro\11.0\OCL 5526c9eb-d5f436b8.bin [136239] O61 - LFC: 2016/03/29 21:59:51 A . (..) -- C:\Users\Ibrahim\AppData\Local\Sony\Vegas Pro\11.0\OCL 5526c9eb-dc7ab1ce.bin [33469] O61 - LFC: 2016/03/29 21:59:51 A . (..) -- C:\Users\Ibrahim\AppData\Local\Sony\Vegas Pro\11.0\svfx_plugin_cache.bin [17442] O61 - LFC: 2016/03/30 12:45:59 A . (..) -- C:\Users\Ibrahim\AppData\Local\Adobe\Acrobat\DC\UserCache.bin [89655] ---\\ File Associations Shell Spawning (10) - 0s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe =>.Microsoft Corporation O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S ---\\ Start Menu Internet (12) - 1s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation ---\\ Search Browser Infection (13) - 6s O69 - SBI: prefs.js [IbraTaa - 41A66E7E5EE1] user_pref("browser.newtab.url", "http://www.hohosearch.com/?ts=AHEpCH0mA34tAk..&v=20160323&uid=B6243A430AB41921E1B0A6A9A535A19D&pt[...] =>.Superfluous.Hohosearch O69 - SBI: prefs.js [IbraTaa - 41A66E7E5EE1] user_pref("browser.search.defaultenginename", "hohosearch"); =>.Superfluous.Hohosearch O69 - SBI: prefs.js [IbraTaa - 41A66E7E5EE1] user_pref("browser.search.searchengine.hp", "http://www.hohosearch.com/?ts=AHEpCH0mA34tAk..&v=20160323&uid=B6243A430AB41921E1B0A6A[...] =>.Superfluous.Hohosearch O69 - SBI: prefs.js [IbraTaa - 41A66E7E5EE1] user_pref("browser.search.searchengine.sp", "http://www.hohosearch.com/chrome.php?mode=ffsengext&ptid=amz&q={searchTerms}&ts=AHEpC[...] =>.Superfluous.Hohosearch O69 - SBI: prefs.js [IbraTaa - 41A66E7E5EE1] user_pref("browser.search.searchengine.url", "http://www.hohosearch.com/chrome.php?mode=ffsengext&ptid=amz&q={searchTerms}&ts=AHEp[...] =>.Superfluous.Hohosearch O69 - SBI: prefs.js [IbraTaa - 41A66E7E5EE1] user_pref("browser.search.selectedEngine", "hohosearch"); =>.Superfluous.Hohosearch O69 - SBI: prefs.js [IbraTaa - 41A66E7E5EE1] user_pref("browser.startup.homepage", "http://www.hohosearch.com/?ts=AHEpCH0mA34tAk..&v=20160323&uid=B6243A430AB41921E1B0A6A9A535A[...] =>.Superfluous.Hohosearch O69 - SBI: prefs.js [IbraTaa - 41A66E7E5EE1] user_pref("extensions.bootstrappedAddons", "{\"@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924\":{\"version\":\"1.08.8.66\",\"type\":\"exten[...] =>PUP.Optional.YesSearches O69 - SBI: prefs.js [IbraTaa - 41A66E7E5EE1] user_pref("extensions.xpiState", "{\"app-profile\":{\"@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924\":{\"d\":\"C:\\\\Users\\\\Ibrahim\\\\A[...] =>PUP.Optional.YesSearches O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 O69 - SBI: SearchScopes [HKCU] {ielnksrch} [DefaultScope] - (Search the web) - http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_ByuMcS4zqTgWbU8-ytuJWNspkFaDaBoQeR3UDVAzmmNZGM7N1sInc4jJWRqv5B9qycPc6n_sIRnExAzcuC8wQ0BSDS-G96HiTaV-7QlETQRnltpvrk4dNIVaZBUidsV-yoqm5zZqw0SkuCNfUUVcgoyfA6ECUlipP261jc4nC&q={searchTerms} =>PUP.Optional.Linkury O69 - SBI: SearchScopes [HKLM] ielnksrch - (Search the web) - http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_ByuMcS4zqTgWbU8-ytuJWNspkFaDaBoQeR3UDVAzmmNZGM7N1sInc4jJWRqv5B9qycPc6n_sIRnExAzcuC8wQ0BSDS-G96HiTaV-7QlETQRnltpvrk4dNIVaZBUidsV-yoqm5zZqw0SkuCNfUUVcgoyfA6ECUlipP261jc4nC&q={searchTerms} =>PUP.Optional.Linkury O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (@ieframe.dll,-12512) - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC ---\\ Search Svchost Services (36) - 2s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\Windows\System32\aelupsvc.dll [207360] =>.Microsoft Corporation O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [155136] =>.Microsoft Corporation O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [155136] =>.Microsoft Corporation O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\Windows\system32\srvsvc.dll [324608] =>.Microsoft Corporation O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\Windows\System32\gpsvc.dll [1311744] =>.Microsoft Corporation O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\ikeext.dll [1104384] =>.Microsoft Corporation O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [903168] =>.Microsoft Corporation O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\Windows\system32\seclogon.dll [30720] =>.Microsoft Corporation O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\Windows\System32\appinfo.dll [109568] =>.Microsoft Corporation O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\Windows\system32\iscsiexe.dll [150528] =>.Microsoft Corporation O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [107008] =>.Microsoft Corporation O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\Windows\system32\schedsvc.dll [1214976] =>.Microsoft Corporation O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [220672] =>.Microsoft Corporation O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) -- C:\Windows\system32\mmcss.dll [70656] =>.Microsoft Corporation O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\Windows\System32\browser.dll [134144] =>.Microsoft Corporation O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [221184] =>.Microsoft Corporation O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [326656] =>.Microsoft Corporation O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\Windows\System32\wercplsupport.dll [81408] =>.Microsoft Corporation O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\Windows\system32\kmsvc.dll [97792] =>.Microsoft Corporation O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\Windows\System32\bdesvc.dll [336896] =>.Microsoft Corporation O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Windows Location Framework Service.) -- C:\Windows\System32\GeofenceMonitorService.dll [491520] =>.Microsoft Corporation O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Microsoft® Account Service.) -- C:\Windows\system32\wlidsvc.dll [1555456] =>.Microsoft Corporation O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\Windows\system32\themeservice.dll [50688] =>.Microsoft Corporation O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Device Setup Manager.) -- C:\Windows\System32\DeviceSetupManager.dll [201728] =>.Microsoft Corporation O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Microsoft Network Connectivity Assistant Se.) -- C:\Windows\System32\ncasvc.dll [164352] =>.Microsoft Corporation O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\Windows\System32\rasauto.dll [101376] =>.Microsoft Corporation O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [534016] =>.Microsoft Corporation O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [223744] =>.Microsoft Corporation O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\Windows\System32\sens.dll [71680] =>.Microsoft Corporation O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [433664] =>.Microsoft Corporation O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [306688] =>.Microsoft Corporation O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\system32\wuaueng.dll [3532288] =>.Microsoft Corporation O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\Windows\System32\qmgr.dll [1017856] =>.Microsoft Corporation O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [629760] =>.Microsoft Corporation O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Software installation Service.) -- C:\Windows\System32\appmgmts.dll [183296] =>.Microsoft Corporation O83 - Search Svchost Services: MsKeyboardFilter (MsKeyboardFilter) . (.Microsoft Corporation - SvcHost Service for Microsoft Keyboard Filt.) -- C:\Windows\System32\KeyboardFilterSvc.dll [90464] =>.Microsoft Windows® ---\\ Firewall Active Exception List (41) - 5s O87 - FAEL: "{3F4A7304-014F-4697-9621-B2BEA4AA751C}" [In-None-P6-TRUE] .(...) -- C:\Users\Ibrahim\AppData\Roaming\uTorrent\uTorrent.exe (.not file.) O87 - FAEL: "{246DBDA1-D6C0-4F81-876C-E7D6C888941C}" [In-None-P17-TRUE] .(...) -- C:\Users\Ibrahim\AppData\Roaming\uTorrent\uTorrent.exe (.not file.) O87 - FAEL: "TCP Query User{DB26099F-A4CE-41E5-9B06-4043956E2971}C:\program files (x86)\pro evolution soccer 2015\pes2015.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\pro evolution soccer 2015\pes2015.exe (.not file.) O87 - FAEL: "UDP Query User{8B276428-B04E-46F2-8E83-D22C0E640470}C:\program files (x86)\pro evolution soccer 2015\pes2015.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\pro evolution soccer 2015\pes2015.exe (.not file.) O87 - FAEL: "TCP Query User{607E945E-1DB3-4780-8E0D-39C67EDDAAE7}C:\program files (x86)\top tv\rtmpgw.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\top tv\rtmpgw.exe (.not file.) O87 - FAEL: "UDP Query User{10A1734A-FD26-413B-929C-7B894807264A}C:\program files (x86)\top tv\rtmpgw.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\top tv\rtmpgw.exe (.not file.) O87 - FAEL: "TCP Query User{63FE560F-4B25-4F78-8480-F0FB11C930BC}C:\users\ibrahim\appdata\roaming\utorrent\updates\3.4.5_41372.exe" [In-None-P6-TRUE] .(...) -- C:\users\ibrahim\appdata\roaming\utorrent\updates\3.4.5_41372.exe (.not file.) O87 - FAEL: "UDP Query User{F69702A8-A0DB-457F-A1B2-31502740EEDE}C:\users\ibrahim\appdata\roaming\utorrent\updates\3.4.5_41372.exe" [In-None-P17-TRUE] .(...) -- C:\users\ibrahim\appdata\roaming\utorrent\updates\3.4.5_41372.exe (.not file.) O87 - FAEL: "TCP Query User{4BA65C95-D735-48A6-920B-918D13F37410}C:\program files (x86)\youwave android\vb\vboxsdl.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\youwave android\vb\vboxsdl.exe (.not file.) O87 - FAEL: "UDP Query User{63A6CF81-7DE1-4794-B6EA-74887B174AB1}C:\program files (x86)\youwave android\vb\vboxsdl.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\youwave android\vb\vboxsdl.exe (.not file.) O87 - FAEL: "TCP Query User{7D1CC1E4-4454-4462-A91C-AC9C0A649A17}C:\users\ibrahim\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe" [In-None-P6-TRUE] .(...) -- C:\users\ibrahim\appdata\roaming\haiyuinst\plugins\download\minithunderplatform.exe (.not file.) O87 - FAEL: "{DF686954-0E06-4741-871D-8EB2C140233C}" [In-None-P6-TRUE] .(.http://www.qemu.org/ - QEMU machine emulators and tools.) -- C:\Program Files\KMSnano\qemu-system-i386.exe =>HackTool.AutoKMS O87 - FAEL: "{6AD1C161-B2D7-4A75-9717-1506B7BC87AD}" [In-None-P17-TRUE] .(.http://www.qemu.org/ - QEMU machine emulators and tools.) -- C:\Program Files\KMSnano\qemu-system-i386.exe =>HackTool.AutoKMS O87 - FAEL: "{4C74D2C8-436B-46F9-AC3F-AD840DD7F289}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Droid4X\Droid4X.exe (.not file.) O87 - FAEL: "{9B46016D-410E-4550-93ED-06B22BED4209}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe (.not file.) O87 - FAEL: "{64E85B72-FECF-4E1B-936D-A3EE76C97276}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe (.not file.) O87 - FAEL: "{F3962104-948D-4776-BB7A-4B94AC5EDA9A}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Oracle\VirtualBox\vboxheadless.exe (.not file.) O87 - FAEL: "{8FEBFB87-43D0-4FD1-A0DD-4942625C9620}" [In-None-P17-TRUE] .(...) -- C:\Users\Ibrahim\AppData\Roaming\Nox\bin\Nox.exe (.not file.) O87 - FAEL: "{74E4E25C-014F-4DF0-BBC2-15918FA795B3}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Bignox\BigNoxVM\RTNoxVMHandle.exe (.not file.) O87 - FAEL: "TCP Query User{2E1EE994-E547-4115-9768-51E3A9DB7A89}C:\users\ibrahim\appdata\local\temp\rar$exa0.108\embrastreamer.exe" [In-None-P6-TRUE] .(...) -- C:\users\ibrahim\appdata\local\temp\rar$exa0.108\embrastreamer.exe (.not file.) O87 - FAEL: "UDP Query User{9AD7D641-5F30-4485-B98A-77D680273084}C:\users\ibrahim\appdata\local\temp\rar$exa0.108\embrastreamer.exe" [In-None-P17-TRUE] .(...) -- C:\users\ibrahim\appdata\local\temp\rar$exa0.108\embrastreamer.exe (.not file.) O87 - FAEL: "TCP Query User{E95E2AE2-CB5F-4615-B789-0B7129DAE4E4}C:\users\ibrahim\desktop\new folder\embrastreamer.exe" [In-None-P6-TRUE] .(...) -- C:\users\ibrahim\desktop\new folder\embrastreamer.exe (.not file.) O87 - FAEL: "UDP Query User{853B76A9-FFB2-4FA0-A89A-E149C1691616}C:\users\ibrahim\desktop\new folder\embrastreamer.exe" [In-None-P17-TRUE] .(...) -- C:\users\ibrahim\desktop\new folder\embrastreamer.exe (.not file.) O87 - FAEL: "TCP Query User{897C491A-BE5A-492D-AC52-8254B418D44E}C:\users\ibrahim\desktop\embratoriag2_beta\es.exe" [In-None-P6-TRUE] .(...) -- C:\users\ibrahim\desktop\embratoriag2_beta\es.exe (.not file.) O87 - FAEL: "UDP Query User{44CB2A95-B332-4A6F-A307-E7BDC50CB151}C:\users\ibrahim\desktop\embratoriag2_beta\es.exe" [In-None-P17-TRUE] .(...) -- C:\users\ibrahim\desktop\embratoriag2_beta\es.exe (.not file.) O87 - FAEL: "TCP Query User{AB33021A-A002-4503-AFFF-5692D75917B9}C:\users\ibrahim\appdata\local\temp\rar$exa0.462\embrastreamer.exe" [In-None-P6-TRUE] .(...) -- C:\users\ibrahim\appdata\local\temp\rar$exa0.462\embrastreamer.exe (.not file.) O87 - FAEL: "UDP Query User{D307E192-1782-4119-8B68-EA9D4E59778B}C:\users\ibrahim\appdata\local\temp\rar$exa0.462\embrastreamer.exe" [In-None-P17-TRUE] .(...) -- C:\users\ibrahim\appdata\local\temp\rar$exa0.462\embrastreamer.exe (.not file.) O87 - FAEL: "TCP Query User{B5533699-4530-4D53-8EFA-B5827AF9555D}C:\users\ibrahim\desktop\new folder\embratoriag2_beta\es.exe" [In-None-P6-TRUE] .(...) -- C:\users\ibrahim\desktop\new folder\embratoriag2_beta\es.exe (.not file.) O87 - FAEL: "UDP Query User{B430B24F-C13F-481C-B5E9-43D4A814FCA8}C:\users\ibrahim\desktop\new folder\embratoriag2_beta\es.exe" [In-None-P17-TRUE] .(...) -- C:\users\ibrahim\desktop\new folder\embratoriag2_beta\es.exe (.not file.) O87 - FAEL: "{AB68B41D-EB37-4EA4-A6A4-6FF0F9E2FF09}" [In-None-P17-TRUE] .(...) -- D:\Program Files\Microvirt\MEmu\MEmu.exe {5528D5543296BFE427D43B8DDC0A20C7} O87 - FAEL: "{6A916887-AA46-47B2-A9E1-FBDCC2EB33E0}" [Out-None-P17-TRUE] .(...) -- D:\Program Files\Microvirt\MEmu\MEmu.exe {5528D5543296BFE427D43B8DDC0A20C7} O87 - FAEL: "TCP Query User{F31E71A1-CC47-47EA-9F23-0947E78CAA3C}C:\users\ibrahim\downloads\compressed\embratoriag2_beta\es.exe" [In-None-P6-TRUE] .(...) -- C:\users\ibrahim\downloads\compressed\embratoriag2_beta\es.exe (.not file.) O87 - FAEL: "UDP Query User{FE287C10-2CDC-48ED-B77E-63AECD4C77DB}C:\users\ibrahim\downloads\compressed\embratoriag2_beta\es.exe" [In-None-P17-TRUE] .(...) -- C:\users\ibrahim\downloads\compressed\embratoriag2_beta\es.exe (.not file.) O87 - FAEL: "TCP Query User{A775F437-64EB-4674-8628-91586351747C}C:\users\ibrahim\desktop\new folder (3)\embrastreamer.exe" [In-None-P6-TRUE] .(...) -- C:\users\ibrahim\desktop\new folder (3)\embrastreamer.exe (.not file.) O87 - FAEL: "UDP Query User{E51C7089-E7C0-4374-BD5F-335B705678E1}C:\users\ibrahim\desktop\new folder (3)\embrastreamer.exe" [In-None-P17-TRUE] .(...) -- C:\users\ibrahim\desktop\new folder (3)\embrastreamer.exe (.not file.) O87 - FAEL: "TCP Query User{470ACFD9-7093-4950-9F2A-2DA94194EE6B}C:\users\ibrahim\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" [In-None-P6-TRUE] .(...) -- C:\users\ibrahim\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe (.not file.) O87 - FAEL: "UDP Query User{2E3E0BD2-E8B8-42DF-8F1B-2E181E530FA4}C:\users\ibrahim\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" [In-None-P17-TRUE] .(...) -- C:\users\ibrahim\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe (.not file.) O87 - FAEL: "TCP Query User{FCCFC508-88BE-4F7F-8B21-CBF4313FF4C6}C:\users\ibrahim\desktop\new folder (3)\es.exe" [In-None-P6-TRUE] .(...) -- C:\users\ibrahim\desktop\new folder (3)\es.exe (.not file.) O87 - FAEL: "UDP Query User{A82FC076-70B6-4BC7-AF16-7781EDEB28CB}C:\users\ibrahim\desktop\new folder (3)\es.exe" [In-None-P17-TRUE] .(...) -- C:\users\ibrahim\desktop\new folder (3)\es.exe (.not file.) O87 - FAEL: "TCP Query User{9B0C382D-C531-424C-ADD4-83C94C9737CA}C:\users\ibrahim\desktop\imbrotor\es.exe" [In-None-P6-TRUE] .(...) -- C:\users\ibrahim\desktop\imbrotor\es.exe (.not file.) O87 - FAEL: "UDP Query User{36967E55-4181-446E-B2DD-C83A3A6A7899}C:\users\ibrahim\desktop\imbrotor\es.exe" [In-None-P17-TRUE] .(...) -- C:\users\ibrahim\desktop\imbrotor\es.exe (.not file.) ---\\ Search Tracing Registry Key (2) - 1s HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\afoir_RASAPI32 =>PUP.Optional.Salus HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\afoir_RASMANCS =>PUP.Optional.Salus ---\\ Additional Scan (O88) (36) - 0s HKLM\SYSTEM\CurrentControlSet\Services\afoir =>PUP.Optional.Salus HKLM\SYSTEM\CurrentControlSet\Services\ggbugreport =>.Superfluous.ZoekyuTechnology HKLM\SYSTEM\CurrentControlSet\Services\Winsere =>PUP.Optional.YesSearches C:\Program Files (x86)\Winsere\Winsere\Winsere.exe =>PUP.Optional.YesSearches C:\Program Files\KMSnano\TriggerKMS.exe =>HackTool.AutoKMS C:\Windows\System32\Tasks\psv_Physlux =>PUP.Optional.Salus C:\Windows\System32\Tasks\snf =>PUP.Optional.Salus C:\Windows\System32\Tasks\snp =>PUP.Optional.Salus C:\Windows\System32\Tasks\Trigger KMS Activation =>HackTool.AutoKMS C:\Users\Ibrahim\AppData\Roaming\Mozilla\Firefox\Profiles\uc9cpnvm.default\searchplugins\findit.xml =>PUP.Optional.SmartBar C:\Users\Ibrahim\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi =>PUP.Optional.YesSearches C:\Users\Ibrahim\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\findit.xml =>PUP.Optional.SmartBar C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\findit.xml =>PUP.Optional.SmartBar C:\ProgramData\Airtostrong\MathLa.dll =>PUP.Optional.Salus HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KMSnano 24_is1 =>HackTool.AutoKMS HKLM\SOFTWARE\Wow6432Node\hohosearchSoftware =>.Superfluous.Hohosearch HKLM\SOFTWARE\Wow6432Node\mtafoir =>PUP.Optional.Salus HKLM\SOFTWARE\Wow6432Node\mtAirtostrong =>PUP.Optional.Salus HKLM\SOFTWARE\Wow6432Node\mtRonzap =>PUP.Optional.Salus HKCU\SOFTWARE\mtafoir =>PUP.Optional.Salus HKCU\SOFTWARE\mtAirtostrong =>PUP.Optional.Salus HKCU\SOFTWARE\mtRonzap =>PUP.Optional.Salus C:\Program Files\KMSnano =>HackTool.AutoKMS C:\Program Files (x86)\SearchesToYesbnd =>.Superfluous.ZoekyuTechnology C:\Program Files (x86)\Winsere =>PUP.Optional.YesSearches C:\Program Files (x86)\WinTaske =>PUP.Optional.YesSearches C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSnano =>HackTool.AutoKMS C:\ProgramData\Airtostrong =>PUP.Optional.Salus C:\ProgramData\Airtostrongs =>PUP.Optional.Salus C:\Users\Ibrahim\AppData\Roaming\Elex-tech =>PUP.Optional.Elex C:\Users\Ibrahim\AppData\Roaming\OpenCandy =>PUP.Optional.OpenCandy HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{ielnksrch} =>PUP.Optional.Linkury HKLM\Software\Microsoft\Internet Explorer\SearchScopes\ielnksrch =>PUP.Optional.Linkury C:\Program Files\KMSnano\qemu-system-i386.exe =>HackTool.AutoKMS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\afoir_RASAPI32 =>PUP.Optional.Salus HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\afoir_RASMANCS =>PUP.Optional.Salus ---\\ Summary of the elements found (9) - 0s http://www.nicolascoolman.fr/pup-salus/ =>PUP.Optional.Salus http://www.nicolascoolman.fr/?p=5145 =>.Superfluous.ZoekyuTechnology http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.YesSearches http://www.nicolascoolman.fr/?p=1804 =>HackTool.AutoKMS http://www.nicolascoolman.fr/?p=5145 =>.Superfluous.Hohosearch http://www.nicolascoolman.fr/?p=308 =>PUP.Optional.SmartBar http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.Linkury http://www.nicolascoolman.fr/?p=996 =>PUP.Optional.Elex http://www.nicolascoolman.fr/?p=197 =>PUP.Optional.OpenCandy ~ End of the scan, 4906 items in 00h01mn54s (778)(0)