~ ZHPDiag v2016.3.8.67 By Nicolas Coolman (2016/03/08) ~ Run by Admin (Administrator) (2016/03/10 15:47:32) ~ Web: http://www.nicolascoolman.com ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ State version: Version KO ~ Mode: Scan ~ Report: C:\Users\Admin\Desktop\ZHPDiag.txt ~ Report: C:\Users\Admin\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ System startup: Normal (Normal boot) Windows 8.1, 64-bit (Build 9600) ---\\ Internet Browsers (3) - 0s GCIE: Google Chrome v48.0.2564.116 MFIE: Mozilla Firefox 45.0 (x86 en-US) MSIE: Internet Explorer v11.0.9600.18231 ---\\ Windows Product Information (3) - 0s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK ---\\ System protection software (2) - 1s McAfee Internet Security Suite v14.0.7080 Windows Defender (Deactivate) ---\\ System protection software (Superfluous) (1) - 1s McAfee Security Scan Plus v3.11.292.3 ---\\ Surveillance software (2) - 1s Adobe Flash Player 20 NPAPI Adobe Acrobat Reader DC ---\\ Information on the system (6) - 0s ~ Operating System: Intel64 Family 6 Model 60 Stepping 3, GenuineIntel ~ Operating System: 64-bit ~ Boot mode: Normal (Normal boot) Total RAM: 33312.856 MB (89% free) System Restore: Activé (Enable) System drive C: has 45 GB () free of 230 GB ---\\ Connection to the system mode (3) - 0s ~ Computer Name: X70 ~ User Name: Admin ~ Logged in as Administrator ---\\ Enumeration of the disk units (5) - 0s ~ Drive C: has 45 GB free of 230 GB (System) ~ Drive D: has 63 GB free of 471 GB ~ Drive E: has 47 GB free of 476 GB ~ Drive F: has 74 GB free of 481 GB ~ Drive G: has 81 GB free of 476 GB ---\\ State of the Windows Security Center (11) - 0s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ---\\ Search Generic System Files (24) - 0s [MD5.C10A66189DC8C090E7C84873EDCEBC88] - 28/01/2015 - (.Microsoft Corporation - Windows Explorer.) -- C:\WINDOWS\Explorer.exe [2501368] =>.Microsoft Windows® [MD5.6C308D32AFA41D26CE2A0EA8F7B79565] - 29/10/2014 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\WINDOWS\System32\rundll32.exe [54784] =>.Microsoft Corporation [MD5.EC302D06155F8E3C383750993FCB6B27] - 05/10/2015 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\WINDOWS\System32\Wininit.exe [146432] =>.Microsoft Corporation [MD5.C15649DEABA6B45562009663673E23D1] - 08/02/2016 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\WINDOWS\System32\wininet.dll [2597376] =>.Microsoft Corporation [MD5.B1102BBDDD9C87B3D609D6C08F7A3DBD] - 05/01/2016 - (.Microsoft Corporation - Windows Logon Application.) -- C:\WINDOWS\System32\Winlogon.exe [570880] =>.Microsoft Corporation [MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - 21/12/2013 - (.Microsoft Corporation - Software Licensing Library.) -- C:\WINDOWS\System32\sppcomapi.dll [447488] =>.Microsoft Corporation [MD5.0B082D6D7A53D91678E7409DD145E89C] - 05/11/2014 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\WINDOWS\System32\dnsapi.dll [657920] =>.Microsoft Corporation [MD5.205BDB00F4C032AF45A6BFD18EA7886C] - 05/11/2014 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\WINDOWS\Syswow64\dnsapi.dll [498688] =>.Microsoft Corporation [MD5.A460C3AF3755A2A79A3C8EFE72E147B5] - 13/10/2015 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\WINDOWS\System32\drivers\AFD.sys [559616] =>.Microsoft Corporation [MD5.74B14192CF79A72F7536B27CB8814FBD] - 22/08/2013 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [26464] =>.Microsoft Windows® [MD5.2FA6510E33F7DEFEC03658B74101A9B9] - 22/08/2013 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [88576] =>.Microsoft Corporation [MD5.C6796EA22B513E3457514D92DCDB1A3D] - 22/08/2013 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [164352] =>.Microsoft Corporation [MD5.A03F362C5557E238CBFA914689C77248] - 06/03/2014 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\DfsC.sys [134144] =>.Microsoft Corporation [MD5.D4B7ED39C7900384D9E5C1283F1E7926] - 24/07/2014 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [76800] =>.Microsoft Corporation [MD5.49EE0AE9E5B64FFBBD06D55C4984B598] - 04/11/2014 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [108544] =>.Microsoft Corporation [MD5.B7342B3C58E91107F6E946A93D9D4EFD] - 27/11/2013 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [142848] =>.Microsoft Corporation [MD5.61000E7155E92342D0D5338CE05D102A] - 10/01/2016 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [401920] =>.Microsoft Corporation [MD5.0217532E19A748F0E5D569307363D5FD] - 22/08/2013 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [282624] =>.Microsoft Corporation [MD5.9980B262DBE439AE6BDC91AA985F19EE] - 30/12/2015 - (.Microsoft Corporation - NT File System Driver.) -- C:\WINDOWS\System32\drivers\ntfs.sys [2017624] =>.Microsoft Windows® [MD5.764B1121867B2D9B31C491668AC72B2B] - 22/08/2013 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\WINDOWS\System32\drivers\Parport.sys [94208] =>.Microsoft Corporation [MD5.1BD3022FD6E450B00DE560265638FD2A] - 08/11/2014 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [112640] =>.Microsoft Corporation [MD5.680C1DAE268B6FB67FA21B389A8B79EF] - 14/11/2013 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [195584] =>.Microsoft Corporation [MD5.E0BD2D83875464FEEEB242CBA8B7E073] - 13/10/2015 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [108032] =>.Microsoft Corporation [MD5.64CA2B4A49A8EAF495E435623ECCE7DB] - 19/06/2014 - (.Microsoft Corporation - Volume Shadow Copy Driver.) -- C:\WINDOWS\System32\drivers\volsnap.sys [310080] =>.Microsoft Windows® ---\\ Non Microsoft non disabled Windows Services (43) - 2s O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated® O23 - Service: (AdobeUpdateService) . (.Adobe Systems Incorporated - Adobe Update Service.) - C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe =>.Adobe Systems Incorporated® O23 - Service: Adobe Genuine Software Integrity Service (AGSService) . (.Adobe Systems, Incorporated - AGS Service.) - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe =>.Adobe Systems Incorporated® O23 - Service: C:\WINDOWS\system32\CxAudMsg64.exe,-100 (CxAudMsg) . (.Conexant Systems Inc. - Conexant Audio Message Service.) - C:\Windows\System32\CxAudMsg64.exe =>.Conexant Systems, Inc.® O23 - Service: DTS APO Service (dts_apo_service) . (.Copyright © 2012 - dts_apo_service.) - C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe =>.DTS, Inc.® O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) . (.Intel(R) Corporation - Intel(R) PROSet/Wireless Event Log Service.) - C:\Program Files\Intel\WiFi\bin\EvtEng.exe =>.Intel Corporation-Mobile Wireless Group® O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) . (.NVIDIA Corporation - NVIDIA GeForce ExperienceService.) - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe =>.NVIDIA Corporation® O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc® O23 - Service: McAfee Home Network (HomeNetSvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.® O23 - Service: IconMan_R (IconMan_R) . (.Realsil Microelectronics Inc. - Realtek Card Reader Patch Tool..) - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe =>.Realtek Semiconductor Corp® O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation - igfxCUIService Module.) - C:\Windows\System32\igfxCUIService.exe =>.Intel Corporation - pGFX® O23 - Service: Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe =>.Intel(R) Corporation O23 - Service: Intel(R) ME Service (Intel(R) ME Service) . (.Intel Corporation - Intel(R) ME Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe =>.Intel Corporation® O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe =>.Intel Corporation® O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Intel(R) Local Management Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation® O23 - Service: McAfee SiteAdvisor Service (McAfee SiteAdvisor Service) . (.McAfee, Inc. - McAfee WebAdvisor.) - C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe =>.McAfee, Inc.® O23 - Service: McAfee AP Service (McAPExe) . (.McAfee, Inc. - McAfee Access Protection.) - C:\Program Files\mcafee\MSC\McAPExe.exe =>.McAfee, Inc.® O23 - Service: McAfee Boot Delay Start Service (McBootDelayStartSvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.® O23 - Service: McAfee CSP Service (mccspsvc) . (.McAfee, Inc. - McAfee CSP Service Host.) - C:\Program Files\Common Files\mcafee\CSP\1.8.267.0\McCSPServiceHost.exe =>.McAfee, Inc.® O23 - Service: McAfee Personal Firewall Service (McMPFSvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.® O23 - Service: McAfee VirusScan Announcer (McNaiAnn) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.® O23 - Service: McAfee Platform Services (mcpltsvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.® O23 - Service: McAfee Proxy Service (McProxy) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.® O23 - Service: McAfee Service Controller (mfemms) . (.McAfee, Inc. - McAfee Management Service.) - C:\Program Files\Common Files\mcafee\SystemCore\mfemms.exe =>.McAfee, Inc.® O23 - Service: McAfee Validation Trust Protection Service (mfevtp) . (.McAfee, Inc. - McAfee Process Validation Service.) - C:\Windows\System32\mfevtps.exe =>.McAfee, Inc.® O23 - Service: McAfee Anti-Spam Service (MSK80Service) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.® O23 - Service: NVIDIA Network Service (NvNetworkService) . (.NVIDIA Corporation - NVIDIA Network Service.) - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe =>.NVIDIA Corporation® O23 - Service: NVIDIA Streamer Service (NvStreamSvc) . (.NVIDIA Corporation - NVIDIA Streamer Service.) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe =>.NVIDIA Corporation® O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 361.9.) - C:\Windows\System32\nvvsvc.exe =>.NVIDIA Corporation® O23 - Service: Intel Security PEF Service (PEFService) . (.Intel Security, Inc. - Intel Security PEF Service.) - C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe =>.McAfee, Inc.® O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) . (.Intel(R) Corporation - Intel(R) PROSet/Wireless Registry Service.) - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe =>.Intel Corporation-Mobile Wireless Group® O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl® O23 - Service: SMITS (SMITS) . (...) - C:\Windows\SysWOW64\SMITSC.exe O23 - Service: TOSHIBA HDD Protection (Thpsrv) . (.TOSHIBA Corporation - TOSHIBA HDD Protection Service.) - C:\Windows\System32\ThpSrv.exe =>.TOSHIBA CORPORATION® O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) . (.TOSHIBA Corporation - TDCSrv Application.) - C:\Windows\System32\TODDSrv.exe =>.TOSHIBA CORPORATION® O23 - Service: TOSHIBA eco Utility Service (TOSHIBA eco Utility Service) . (.Toshiba Corporation - TOSHIBA eco Utility Service.) - C:\Program Files\Toshiba\Teco\TecoService.exe =>.TOSHIBA CORPORATION® O23 - Service: VMware Authorization Service (VMAuthdService) . (.VMware, Inc. - VMware Authorization Service.) - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe =>.VMware, Inc.® O23 - Service: VMware DHCP Service (VMnetDHCP) . (.VMware, Inc. - VMware VMnet DHCP service.) - C:\Windows\SysWOW64\vmnetdhcp.exe =>.VMware, Inc.® O23 - Service: VMware USB Arbitration Service (VMUSBArbService) . (.VMware, Inc. - VMware USB Arbitration Service.) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe =>.VMware, Inc.® O23 - Service: VMware NAT Service (VMware NAT Service) . (.VMware, Inc. - VMware NAT Service.) - C:\Windows\SysWOW64\vmnat.exe =>.VMware, Inc.® O23 - Service: VMware Workstation Server (VMwareHostd) . (...) - C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe =>.VMware, Inc.® O23 - Service: Wacom Professional Service (WTabletServicePro) . (.Wacom Technology, Corp. - Tablet Service.) - C:\Program Files\Tablet\Wacom\WTabletServicePro.exe =>.Wacom Technology Corp.® O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) . (.Intel® Corporation - Intel® PROSet/Wireless Zero Configure Servi.) - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe =>.Intel Corporation-Mobile Wireless Group® ---\\ Services not Microsoft (SR=Run, SS=Stop) (59) - 17s SR - Auto [13/12/2015] [ 82128] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated® SS - Demand [09/02/2016] [ 269504] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated® SR - Auto [28/01/2016] [ 693440] (AdobeUpdateService) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe =>.Adobe Systems Incorporated® SR - Auto [09/02/2016] [ 2020056] Adobe Genuine Software Integrity Service (AGSService) . (.Adobe Systems, Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe =>.Adobe Systems Incorporated® SS - Demand [31/12/2014] [ 281488] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe =>.Intel Corporation - pGFX® SR - Auto [12/12/2012] [ 205560] C:\WINDOWS\system32\CxAudMsg64.exe,-100 (CxAudMsg) . (.Conexant Systems Inc..) - C:\Windows\System32\CxAudMsg64.exe =>.Conexant Systems Inc. SR - Auto [10/09/2013] [ 19792] DTS APO Service (dts_apo_service) . (.Copyright © 2012.) - C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe =>.DTS, Inc.® SR - Auto [08/01/2014] [ 631024] Intel(R) PROSet/Wireless Event Log (EvtEng) . (.Intel(R) Corporation.) - C:\Program Files\Intel\WiFi\bin\EvtEng.exe =>.Intel Corporation-Mobile Wireless Group® SR - Auto [12/01/2016] [ 1163200] NVIDIA GeForce Experience Service (GfExperienceService) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe =>.NVIDIA Corporation® SS - Auto [28/08/2015] [ 144200] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc® SS - Demand [28/08/2015] [ 144200] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc® SR - Auto [03/01/2016] [ 453520] McAfee Home Network (HomeNetSvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.® SR - Auto [15/11/2012] [ 2468496] IconMan_R (IconMan_R) . (.Realsil Microelectronics Inc..) - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe =>.Realtek Semiconductor Corp® SS - Demand [03/04/2005] [ 69632] InstallDriver Table Manager (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe =>.Macrovision Corporation SR - Auto [31/12/2014] [ 319888] Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation.) - C:\Windows\System32\igfxCUIService.exe =>.Intel Corporation SR - Auto [10/12/2012] [ 732160] Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe =>.Intel(R) Corporation SS - Demand [10/12/2012] [ 803872] Intel(R) Capability Licensing Service TCP IP Interface (Intel(R) Capability Licensing Service TCP IP Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe =>.Intel® Trusted Connect Service® SR - Auto [22/02/2013] [ 129848] Intel(R) ME Service (Intel(R) ME Service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe =>.Intel Corporation® SS - Demand [25/09/2015] [ 178312] Intel(R) Update Manager (iumsvc) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe =>.Intel(R) Update Manager® SR - Auto [22/02/2013] [ 167736] Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe =>.Intel Corporation® SR - Auto [22/02/2013] [ 364856] Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation® SR - Auto [25/02/2016] [ 163592] McAfee SiteAdvisor Service (McAfee SiteAdvisor Service) . (.McAfee, Inc..) - C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe =>.McAfee, Inc.® SR - Auto [08/01/2016] [ 863448] McAfee AP Service (McAPExe) . (.McAfee, Inc..) - C:\Program Files\mcafee\MSC\McAPExe.exe =>.McAfee, Inc.® SR - Auto [03/01/2016] [ 453520] McAfee Boot Delay Start Service (McBootDelayStartSvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.® SS - Demand [05/02/2016] [ 293128] McAfee Security Scan Component Host Service (McComponentHostService) . (.McAfee, Inc..) - C:\Program Files\McAfee Security Scan\3.11.292\McCHSvc.exe =>.McAfee, Inc.® SR - Auto [23/02/2016] [ 1696712] McAfee CSP Service (mccspsvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\CSP\1.8.267.0\McCSPServiceHost.exe =>.McAfee, Inc.® SR - Auto [03/01/2016] [ 453520] McAfee Personal Firewall Service (McMPFSvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.® SR - Auto [03/01/2016] [ 453520] McAfee VirusScan Announcer (McNaiAnn) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.® SS - Demand [08/01/2016] [ 681680] McAfee Scanner (McODS) . (.McAfee, Inc..) - C:\Program Files\mcafee\VirusScan\mcods.exe =>.McAfee, Inc.® SR - Auto [03/01/2016] [ 453520] McAfee Platform Services (mcpltsvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.® SR - Auto [03/01/2016] [ 453520] McAfee Proxy Service (McProxy) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.® SR - Demand [18/11/2015] [ 234192] McAfee Firewall Core Service (mfefire) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\SystemCore\mfefire.exe =>.McAfee, Inc.® SR - Auto [21/01/2016] [ 380896] McAfee Service Controller (mfemms) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\SystemCore\mfemms.exe =>.McAfee, Inc.® SR - Auto [18/11/2015] [ 275368] McAfee Validation Trust Protection Service (mfevtp) . (.McAfee, Inc..) - C:\windows\system32\mfevtps.exe =>.McAfee, Inc. SS - Demand [09/03/2016] [ 146888] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation® SR - Auto [03/01/2016] [ 453520] McAfee Anti-Spam Service (MSK80Service) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.® SS - Demand [08/01/2014] [ 284912] Wireless PAN DHCP Server (MyWiFiDHCPDNS) . (.Copyright (C) 2005-2010 by Achal Dhir.) - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe =>.Intel Corporation-Mobile Wireless Group® SR - Auto [12/01/2016] [ 1879488] NVIDIA Network Service (NvNetworkService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe =>.NVIDIA Corporation® SR - Demand [12/01/2016] [ 6308288] NVIDIA Streamer Network Service (NvStreamNetworkSvc) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe =>.NVIDIA Corporation® SR - Auto [12/01/2016] [ 4812736] NVIDIA Streamer Service (NvStreamSvc) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe =>.NVIDIA Corporation® SR - Auto [09/02/2016] [ 1264696] NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation.) - C:\windows\system32\nvvsvc.exe =>.NVIDIA Corporation SR - Auto [14/12/2015] [ 902112] Intel Security PEF Service (PEFService) . (.Intel Security, Inc..) - C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe =>.McAfee, Inc.® SR - Auto [08/01/2014] [ 154864] Intel(R) PROSet/Wireless Registry Service (RegSrvc) . (.Intel(R) Corporation.) - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe =>.Intel Corporation-Mobile Wireless Group® SS - Auto [09/07/2015] [ 327296] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl® SR - Auto [08/01/2015] [ 13312] SMITS (SMITS) . (...) - C:\Windows\SysWOW64\SMITSC.exe SR - Demand [17/11/2015] [ 120392] TEMPRO Service (TemproMonitoringService) . (.Toshiba Europe GmbH.) - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe =>.Toshiba Europe Gmbh® SR - Auto [26/06/2013] [ 567136] TOSHIBA HDD Protection (Thpsrv) . (.TOSHIBA Corporation.) - C:\Windows\System32\ThpSrv.exe =>.Toshiba Corporation SR - Demand [31/07/2013] [ 53864] TMachInfo (TMachInfo) . (.TOSHIBA Corporation.) - C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe =>.TOSHIBA CORPORATION® SR - Auto [28/07/2009] [ 140632] TOSHIBA Optical Disc Drive Service (TODDSrv) . (.TOSHIBA Corporation.) - C:\Windows\system32\TODDSrv.exe =>.Toshiba Corporation SR - Auto [09/08/2013] [ 328544] TOSHIBA eco Utility Service (TOSHIBA eco Utility Service) . (.Toshiba Corporation.) - C:\Program Files\Toshiba\Teco\TecoService.exe =>.TOSHIBA CORPORATION® SR - Demand [04/09/2013] [ 466504] TPCH Service (TPCHSrv) . (.TOSHIBA Corporation.) - C:\Program Files\Toshiba\TPHM\TPCHSrv.exe =>.TOSHIBA CORPORATION® SR - Auto [31/05/2015] [ 87744] VMware Authorization Service (VMAuthdService) . (.VMware, Inc..) - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe =>.VMware, Inc.® SR - Auto [31/05/2015] [ 359104] VMware DHCP Service (VMnetDHCP) . (.VMware, Inc..) - C:\Windows\SysWOW64\vmnetdhcp.exe =>.VMware, Inc.® SR - Auto [22/05/2015] [ 916672] VMware USB Arbitration Service (VMUSBArbService) . (.VMware, Inc..) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe =>.VMware, Inc.® SR - Auto [31/05/2015] [ 438464] VMware NAT Service (VMware NAT Service) . (.VMware, Inc..) - C:\Windows\SysWOW64\vmnat.exe =>.VMware, Inc.® SR - Auto [31/05/2015] [12732608] VMware Workstation Server (VMwareHostd) . (...) - C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe =>.VMware, Inc.® SR - Auto [21/05/2013] [ 598840] Wacom Professional Service (WTabletServicePro) . (.Wacom Technology, Corp..) - C:\Program Files\Tablet\Wacom\WTabletServicePro.exe =>.Wacom Technology Corp.® SR - Auto [08/01/2014] [ 3674864] Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) . (.Intel® Corporation.) - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe =>.Intel Corporation-Mobile Wireless Group® ---\\ Task Planned Automatically (67) - 3s [MD5.4EAF6F8F0B3BE33A0E3877EB7FFD48D4] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656] =>.Adobe Systems, Incorporated® [MD5.785FD0E36CA75D90DD50042E2594BC63] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [269504] =>.Adobe Systems Incorporated® [MD5.20C08CA080F650B730B1E3FDEA9AD532] [APT] [AdobeAAMUpdater-1.0-X70-Admin] (.Adobe Systems Incorporated.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128] =>.Adobe Systems Incorporated® [MD5.64400218D3FFFDC14397B5C19E3D0A92] [APT] [G2MUpdateTask-S-1-5-21-1056618793-1677908267-3770283503-1002] (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\g2mupdate.exe [41536] {44AD220DBF367E6C4D2E480E121853D7} [MD5.64400218D3FFFDC14397B5C19E3D0A92] [APT] [G2MUploadTask-S-1-5-21-1056618793-1677908267-3770283503-1002] (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\g2mupload.exe [41536] {44AD220DBF367E6C4D2E480E121853D7} [MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc® [MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskMachineCore1d08ed7734a89e5] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc® [MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskMachineCore1d0bf4ca73bd517] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc® [MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskMachineCore1d12f3f2cc06e9e] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc® [MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc® [MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskMachineUA1d040d9e671eb] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc® [MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1cf48d2e98b56a3] (.Google Inc..) -- C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc® [MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1cf8df1f59d0058] (.Google Inc..) -- C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc® [MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1cfebd9510a899b] (.Google Inc..) -- C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc® [MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1d0017dba9e37af] (.Google Inc..) -- C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc® [MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1d0901e1f7c0029] (.Google Inc..) -- C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc® [MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002UA1cef29bb539fe3c] (.Google Inc..) -- C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc® [MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002UA1d0901e1f93e169] (.Google Inc..) -- C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc® [MD5.A3753D0D8EFFABB1F9DC7D29FDCBCAF6] [APT] [Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse] (.McAfee, Inc..) -- C:\Program Files\Common Files\mcafee\AMContent\scanners\x86_64\datrep\54.0\mcdatrep.exe [1779568] =>.McAfee, Inc.® [MD5.A3753D0D8EFFABB1F9DC7D29FDCBCAF6] [APT] [Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse] (.McAfee, Inc..) -- C:\Program Files\Common Files\mcafee\AMContent\scanners\x86_64\datrep\54.0\mcdatrep.exe [1779568] =>.McAfee, Inc.® [MD5.16B5B394028D8ED80A569123A38DC4F7] [APT] [IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473] (.Intel Corporation.) -- C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312] =>.Intel(R) Update Manager® [MD5.16B5B394028D8ED80A569123A38DC4F7] [APT] [IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon] (.Intel Corporation.) -- C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312] =>.Intel(R) Update Manager® [MD5.F0FEBD893AD40C20534F0AC1D58C304B] [APT] [McAfee Remediation (Prepare)] (.McAfee, Inc..) -- C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [3271576] =>.McAfee, Inc.® [MD5.9BE843A086D13A7B7B575DDEB8ED1B9A] [APT] [McAfeeLogon] (.McAfee, Inc..) -- C:\Program Files\Common Files\mcafee\Platform\McUICnt.exe [791360] =>.McAfee, Inc.® [MD5.8DFA7EC54AD2D293AE1D6F7CEE558C26] [APT] [Synaptics TouchPad Enhancements] (.Synaptics Incorporated.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2774256] =>.Synaptics Incorporated® [MD5.7A5DEBDF20787D389731C4FF08CCE0DA] [APT] [Toshiba\] (.Toshiba Europe GmbH.) -- C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe [475720] =>.Toshiba Europe Gmbh® [MD5.2B2C2D74BC62E22248787530A7AFC87F] [APT] [Toshiba\] (.TOSHIBA Corporation.) -- C:\Program Files\Toshiba\Toshiba Service Station\ToshibaServiceStation.exe [655464] =>.TOSHIBA CORPORATION® O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job [830] =>.Adobe Systems Incorporated® O39 - APT: G2MUpdateTask-S-1-5-21-1056618793-1677908267-3770283503-1002 - (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-1056618793-1677908267-3770283503-1002.job [570] {44AD220DBF367E6C4D2E480E121853D7} O39 - APT: G2MUploadTask-S-1-5-21-1056618793-1677908267-3770283503-1002 - (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-1056618793-1677908267-3770283503-1002.job [666] {44AD220DBF367E6C4D2E480E121853D7} O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job [910] =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineCore1d08ed7734a89e5 - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d08ed7734a89e5.job [910] =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineCore1d0bf4ca73bd517 - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0bf4ca73bd517.job [910] =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineCore1d12f3f2cc06e9e - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d12f3f2cc06e9e.job [910] =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job [914] =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineUA1d040d9e671eb - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d040d9e671eb.job [914] =>.Google Inc® O39 - APT: GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1cf8df1f59d0058 - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1cf8df1f59d0058.job [1034] =>.Google Inc® O39 - APT: GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1cfebd9510a899b - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1cfebd9510a899b.job [1034] =>.Google Inc® O39 - APT: GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1d0017dba9e37af - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1d0017dba9e37af.job [1034] =>.Google Inc® O39 - APT: GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1d0901e1f7c0029 - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1d0901e1f7c0029.job [1034] =>.Google Inc® O39 - APT: GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002UA1cef29bb539fe3c - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002UA1cef29bb539fe3c.job [1086] =>.Google Inc® O39 - APT: GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002UA1d0901e1f93e169 - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002UA1d0901e1f93e169.job [1086] =>.Google Inc® O39 - APT: Adobe Acrobat Update Task - (.Adobe Systems Incorporated.) -- C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task [3886] =>.Adobe Systems, Incorporated® O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater [3718] =>.Adobe Systems Incorporated® O39 - APT: AdobeAAMUpdater-1.0-X70-Admin - (.Adobe Systems Incorporated.) -- C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-X70-Admin [3492] =>.Adobe Systems Incorporated® O39 - APT: G2MUpdateTask-S-1-5-21-1056618793-1677908267-3770283503-1002 - (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-1056618793-1677908267-3770283503-1002 [3560] {44AD220DBF367E6C4D2E480E121853D7} O39 - APT: G2MUploadTask-S-1-5-21-1056618793-1677908267-3770283503-1002 - (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\WINDOWS\System32\Tasks\G2MUploadTask-S-1-5-21-1056618793-1677908267-3770283503-1002 [3656] {44AD220DBF367E6C4D2E480E121853D7} O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore [3650] =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineCore1d08ed7734a89e5 - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d08ed7734a89e5 [3650] =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineCore1d0bf4ca73bd517 - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d0bf4ca73bd517 [3650] =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineCore1d12f3f2cc06e9e - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d12f3f2cc06e9e [3650] =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA [3886] =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineUA1d040d9e671eb - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d040d9e671eb [3886] =>.Google Inc® O39 - APT: GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1cf48d2e98b56a3 - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1cf48d2e98b56a3 [3652] =>.Google Inc® O39 - APT: GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1cf8df1f59d0058 - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1cf8df1f59d0058 [3652] =>.Google Inc® O39 - APT: GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1cfebd9510a899b - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1cfebd9510a899b [3652] =>.Google Inc® O39 - APT: GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1d0017dba9e37af - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1d0017dba9e37af [3652] =>.Google Inc® O39 - APT: GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1d0901e1f7c0029 - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002Core1d0901e1f7c0029 [3652] =>.Google Inc® O39 - APT: GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002UA1cef29bb539fe3c - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002UA1cef29bb539fe3c [4032] =>.Google Inc® O39 - APT: GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002UA1d0901e1f93e169 - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1056618793-1677908267-3770283503-1002UA1d0901e1f93e169 [4032] =>.Google Inc® O39 - APT: Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse - (.McAfee, Inc..) -- C:\WINDOWS\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse [3846] =>.McAfee, Inc.® O39 - APT: Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse - (.McAfee, Inc..) -- C:\WINDOWS\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse [4020] =>.McAfee, Inc.® O39 - APT: IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 - (.Intel Corporation.) -- C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 [3722] =>.Intel(R) Update Manager® O39 - APT: IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon - (.Intel Corporation.) -- C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon [3476] =>.Intel(R) Update Manager® O39 - APT: McAfee Remediation (Prepare) - (.McAfee, Inc..) -- C:\WINDOWS\System32\Tasks\McAfee Remediation (Prepare) [3348] =>.McAfee, Inc.® O39 - APT: McAfeeLogon - (.McAfee, Inc..) -- C:\WINDOWS\System32\Tasks\McAfeeLogon [3064] =>.McAfee, Inc.® O39 - APT: Synaptics TouchPad Enhancements - (.Synaptics Incorporated.) -- C:\WINDOWS\System32\Tasks\Synaptics TouchPad Enhancements [2990] =>.Synaptics Incorporated® ---\\ Process running (99) - 3s [MD5.9139EEA14D2386543AFCC8F494A349C1] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 361.9.) -- C:\Windows\System32\nvvsvc.exe [1264696] [PID.396] =>.NVIDIA Corporation® [MD5.79320846F95AA3E2160609AEF394B77F] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe [1263160] [PID.616] =>.NVIDIA Corporation® [MD5.9139EEA14D2386543AFCC8F494A349C1] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 361.9.) -- C:\Windows\System32\nvvsvc.exe [1264696] [PID.424] =>.NVIDIA Corporation® [MD5.361529DF1EBD05E0B15E1026DCCC1885] - (.Intel Corporation - igfxCUIService Module.) -- C:\Windows\System32\igfxCUIService.exe [319888] [PID.1076] =>.Intel Corporation - pGFX® [MD5.772473A9ADE89E21331AF0B24928C0A6] - (.Wacom Technology, Corp. - Tablet Service.) -- C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [598840] [PID.1228] =>.Wacom Technology Corp.® [MD5.F2CEEE9ABBCEF207ACB103215AC28BC2] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [82128] [PID.1976] =>.Adobe Systems, Incorporated® [MD5.6A90FF6FFDB8DB97F7E0F730A3582794] - (.Adobe Systems Incorporated - Adobe Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [693440] [PID.1992] =>.Adobe Systems Incorporated® [MD5.8BA0756C7B80D039212F9BB957D84727] - (.Adobe Systems, Incorporated - AGS Service.) -- C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2020056] [PID.2012] =>.Adobe Systems Incorporated® [MD5.426B2624A1669D233BAB6C4AC5E9432E] - (.Conexant Systems Inc. - Conexant Audio Message Service.) -- C:\Windows\System32\CxAudMsg64.exe [205560] [PID.1284] =>.Conexant Systems, Inc.® [MD5.40CFC6671B2442D32E149FF1683212D1] - (.Copyright © 2012 - dts_apo_service.) -- C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe [19792] [PID.1720] =>.DTS, Inc.® [MD5.C8559336BB21FF701CBEF14527D7660F] - (.Intel(R) Corporation - Intel(R) PROSet/Wireless Event Log Service.) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe [631024] [PID.2092] =>.Intel Corporation-Mobile Wireless Group® [MD5.061CC5C12C39899D7398CFEBFD19F69F] - (.NVIDIA Corporation - NVIDIA GeForce ExperienceService.) -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200] [PID.2132] =>.NVIDIA Corporation® [MD5.DEA2F976E7327716AA0038EBF550003A] - (.Realsil Microelectronics Inc. - Realtek Card Reader Patch Tool..) -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2468496] [PID.2192] =>.Realtek Semiconductor Corp® [MD5.C6128F2E3DC6156C6F8828F9F1B96010] - (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160] [PID.2228] =>.Intel(R) Corporation [MD5.F47F31A8C537075A72A231D7E9B40173] - (.McAfee, Inc. - McAfee Management Service.) -- C:\Program Files\Common Files\mcafee\SystemCore\mfemms.exe [380896] [PID.2300] =>.McAfee, Inc.® [MD5.CCBD7980E8617C364B9A1AE022FF4603] - (.McAfee, Inc. - McAfee Process Validation Service.) -- C:\Windows\System32\mfevtps.exe [275368] [PID.2384] =>.McAfee, Inc.® [MD5.CCBD7980E8617C364B9A1AE022FF4603] - (.McAfee, Inc. - McAfee Process Validation Service.) -- C:\Windows\System32\mfevtps.exe [275368] [PID.2456] =>.McAfee, Inc.® [MD5.1E3277F1C9F62F90488D02869A9522B7] - (.NVIDIA Corporation - NVIDIA Network Service.) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488] [PID.2476] =>.NVIDIA Corporation® [MD5.266512CCC3B2E195CDE3A7A2C98A353A] - (.NVIDIA Corporation - NVIDIA Streamer Service.) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4812736] [PID.2548] =>.NVIDIA Corporation® [MD5.C034A645D8A75FEA04F0A4FF3EF1253D] - (.Intel Security, Inc. - Intel Security PEF Service.) -- C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [902112] [PID.2596] =>.McAfee, Inc.® [MD5.7256A19A9397E71FADC46E23E11B1609] - (.Intel(R) Corporation - Intel(R) PROSet/Wireless Registry Service.) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [154864] [PID.2652] =>.Intel Corporation-Mobile Wireless Group® [MD5.5B2244BBDE70D5E0EE7822C6E81C0A91] - (...) -- C:\Windows\SysWOW64\SMITSC.exe [13312] [PID.2712] [MD5.D35234AC71FDB240F9BC586E55F797F1] - (.TOSHIBA Corporation - TOSHIBA HDD Protection Service.) -- C:\Windows\System32\ThpSrv.exe [567136] [PID.2768] =>.TOSHIBA CORPORATION® [MD5.ED32035BDFECED1AD66D459FD9CC1140] - (.TOSHIBA Corporation - TDCSrv Application.) -- C:\Windows\System32\TODDSrv.exe [140632] [PID.2820] =>.TOSHIBA CORPORATION® [MD5.0769FDF4C15D9EDD3CAAC148A8EDC2E5] - (.VMware, Inc. - VMware NAT Service.) -- C:\Windows\SysWOW64\vmnat.exe [438464] [PID.2864] =>.VMware, Inc.® [MD5.19137CA32DA7AA6F4936514721AA53BA] - (.Intel® Corporation - Intel® PROSet/Wireless Zero Configure Servi.) -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3674864] [PID.2892] =>.Intel Corporation-Mobile Wireless Group® [MD5.380192EE4C9FA50A083C14522E6240C8] - (.Toshiba Corporation - TOSHIBA eco Utility Service.) -- C:\Program Files\Toshiba\Teco\TecoService.exe [328544] [PID.2936] =>.TOSHIBA CORPORATION® [MD5.376838F824FD863753D397BAE2937657] - (.McAfee, Inc. - McAfee Core Firewall Service.) -- C:\Program Files\Common Files\mcafee\SystemCore\mfefire.exe [234192] [PID.2944] =>.McAfee, Inc.® [MD5.225E1E03B2AABE2D493FCDB459303701] - (.VMware, Inc. - VMware Authorization Service.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe [87744] [PID.3260] =>.VMware, Inc.® [MD5.98E73D79FCD3D48E31EE999B5DF1B0ED] - (.VMware, Inc. - VMware VMnet DHCP service.) -- C:\Windows\SysWOW64\vmnetdhcp.exe [359104] [PID.3284] =>.VMware, Inc.® [MD5.15D702F235BD1077007A180EEFB9DBB8] - (.VMware, Inc. - VMware USB Arbitration Service.) -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [916672] [PID.3300] =>.VMware, Inc.® [MD5.15E0B18784B5655D4E0666BEC840EEFF] - (.McAfee, Inc. - McAfee Service Host.) -- C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [453520] [PID.3328] =>.McAfee, Inc.® [MD5.3EEEA5B5EDB54E2969CE2B8599D45983] - (...) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [12732608] [PID.3416] =>.VMware, Inc.® [MD5.9B4B3747C6756F49B986398A46EC1FE0] - (.NVIDIA Corporation - NVIDIA Network Stream Service.) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6308288] [PID.4476] =>.NVIDIA Corporation® [MD5.6818ABE67E1EF0B1B5A75C1090D1AF2F] - (.NVIDIA Corporation - NVIDIA Streamer User Agent.) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe [20069312] [PID.4948] =>.NVIDIA Corporation® [MD5.8DFA7EC54AD2D293AE1D6F7CEE558C26] - (.Synaptics Incorporated - Synaptics TouchPad 64-bit Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2774256] [PID.1064] =>.Synaptics Incorporated® [MD5.ABF64234F3462571E66527828040219B] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe [252232] [PID.1660] =>.Google Inc® [MD5.6B74802C4077347F6A26DC70CC551843] - (.Intel Corporation - igfxEM Module.) -- C:\Windows\System32\igfxEM.exe [530832] [PID.5220] =>.Intel Corporation - pGFX® [MD5.3E841814EF6311B15545BE723BBE1D23] - (.Intel Corporation - igfxHK Module.) -- C:\Windows\System32\igfxHK.exe [247696] [PID.5228] =>.Intel Corporation - pGFX® [MD5.66F330C1217FFD2D393BC8DDBF5F4758] - (.Intel Corporation - igfxTray Module.) -- C:\Windows\System32\igfxTray.exe [384912] [PID.5236] =>.Intel Corporation - pGFX® [MD5.E445C0DB7E5E89C657FC89C0C4CCEDE5] - (.NVIDIA Corporation - NVIDIA Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2787264] [PID.5616] =>.NVIDIA Corporation® [MD5.9160175E96CB8A638EFDF5F583FDF305] - (.Wacom Technology, Corp. - Tablet user module for professional driver.) -- C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe [1952568] [PID.5868] =>.Wacom Technology Corp.® [MD5.19E0B5B6202CE85796EA6C0EBB7334DF] - (.Wacom Technology - Wacom Load Agent.) -- C:\Program Files\Tablet\Wacom\WacomHost.exe [39808] [PID.5884] =>.Wacom Technology Corp.® [MD5.2E6215108125A42160A1EC17208A50F0] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe [313672] [PID.5892] =>.Google Inc® [MD5.CA7422B74F5917AE599936507691CE6C] - (.Wacom Technology, Corp. - Tablet Service for professional driver.) -- C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe [8963384] [PID.6000] =>.Wacom Technology Corp.® [MD5.2464F1EED56D8030E5E76EA75B67AA73] - (.NVIDIA Corporation - NVIDIA Settings.) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe [2456632] [PID.6120] =>.NVIDIA Corporation® [MD5.376838F824FD863753D397BAE2937657] - (.McAfee, Inc. - McAfee Core Firewall Service.) -- C:\Program Files\Common Files\mcafee\SystemCore\mfefire.exe [234192] [PID.3924] =>.McAfee, Inc.® [MD5.964FFB2A3126C4D200BB776777C68EA2] - (.Wacom Technology, Corp. - Touch User Mode Driver.) -- C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe [5100856] [PID.4704] =>.Wacom Technology Corp.® [MD5.FDFAFD06F78C40F1A61897777D76A512] - (.McAfee, Inc. - McAfee WebAdvisor.) -- C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [163592] [PID.5280] =>.McAfee, Inc.® [MD5.DE8FDA27A8A935D4A7E16BBCC68FCDFF] - (.McAfee, Inc. - McAfee Access Protection.) -- C:\Program Files\mcafee\MSC\McAPExe.exe [863448] [PID.4436] =>.McAfee, Inc.® [MD5.26C3F924E7154CA0716C3A52466FDFED] - (.McAfee, Inc. - McAfee Scanner service.) -- C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe [1047344] [PID.1100] =>.McAfee, Inc.® [MD5.484E6AA96E535E675D999CFF0AE72571] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\PROGRAM FILES\SYNAPTICS\SynTP\SYNTPHELPER.EXE [182000] [PID.4424] =>.Synaptics Incorporated® [MD5.788D0DE4CF3FEAE0782437CC2CF6E23A] - (.TOSHIBA Corporation - Resident module of eco Utility.) -- C:\Program Files\Toshiba\Teco\TecoResident.exe [178016] [PID.7072] =>.TOSHIBA CORPORATION® [MD5.D35234AC71FDB240F9BC586E55F797F1] - (.TOSHIBA Corporation - TOSHIBA HDD Protection Service.) -- C:\Windows\System32\ThpSrv.exe [567136] [PID.3076] =>.TOSHIBA CORPORATION® [MD5.ACA0A7CF75AAD65FBF2EB88C47012D7E] - (.TOSHIBA Corporation - Sleep and Charge Service.) -- C:\Program Files (x86)\TOSHIBA\System Setting\TSleepSrv.exe [1549392] [PID.7180] =>.TOSHIBA CORPORATION® [MD5.6EF487A46FB615DF717F85D7458BD2CD] - (.Copyright (C) 2012 TOSHIBA Corporation. All rights r - TOSHIBA System Settings Service.) -- C:\Program Files (x86)\TOSHIBA\System Setting\TODDMain.exe [213136] [PID.7188] =>.TOSHIBA CORPORATION® [MD5.0B22EBE04901FA3E30CCBA995FABC231] - (.Conexant Systems, Inc. - Conexant High Definition Audio Filter Agent.) -- C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe [894048] [PID.7228] =>.Conexant Systems, Inc.® [MD5.919C80271F41A85B28D218CED3E26A16] - (.TOSHIBA Corporation - TOSHIBA Function Key Main Module.) -- C:\Program Files\Toshiba\Hotkey\TCrdMain_Win8.exe [2556768] [PID.7252] =>.TOSHIBA CORPORATION® [MD5.1239B108AB608BD4EA5A619B3B3900C1] - (.Copyright (C) 2012-2013 TOSHIBA Corporation. All righ - TCrdKBB Application.) -- C:\Program Files\Toshiba\Hotkey\Hotkey\TCrdKBB.exe [438112] [PID.7300] =>.TOSHIBA CORPORATION® [MD5.D967D4C44505B7BF3F6B1FEC299ABE11] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe [50605696] [PID.7440] =>.Skype Software Sarl® [MD5.63740680B14C2EEE08B11ADADFA98DA1] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [746648] [PID.2276] =>.Google Inc® [MD5.63740680B14C2EEE08B11ADADFA98DA1] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [746648] [PID.6612] =>.Google Inc® [MD5.63740680B14C2EEE08B11ADADFA98DA1] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [746648] [PID.7312] =>.Google Inc® [MD5.63740680B14C2EEE08B11ADADFA98DA1] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [746648] [PID.6040] =>.Google Inc® [MD5.63740680B14C2EEE08B11ADADFA98DA1] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [746648] [PID.7652] =>.Google Inc® [MD5.63740680B14C2EEE08B11ADADFA98DA1] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [746648] [PID.7664] =>.Google Inc® [MD5.63740680B14C2EEE08B11ADADFA98DA1] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [746648] [PID.7668] =>.Google Inc® [MD5.63740680B14C2EEE08B11ADADFA98DA1] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [746648] [PID.7804] =>.Google Inc® [MD5.5AD04128FC183D7001BF092CA849F70D] - (.McAfee, Inc. - SiteAdvisor.) -- C:\Program Files (x86)\McAfee\SiteAdvisor\McChHost.exe [397064] [PID.7452] =>.McAfee, Inc.® [MD5.D425C962A27E01583084CA6AB175E552] - (.McAfee, Inc. - McAfee Security Scanner Scheduler.) -- C:\Program Files\McAfee Security Scan\3.11.292\SSScheduler.exe [334088] [PID.8208] =>.McAfee, Inc.® [MD5.49CD8D25D932C5BF867EBFF00D432B75] - (.Intel Corporation - Intel Services Manager.) -- C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [156000] [PID.8228] =>.Intel® Services Manager® [MD5.FDF0BF19E9360E437B02323B9FF81B18] - (. - SpyderUtility 1.2.3.) -- C:\Program Files (x86)\Datacolor\Spyder4Pro\Utility\SpyderUtility.exe [8241767] [PID.8436] [MD5.50E68F8313263B1A12A767341A25663B] - (.Adobe Systems Incorporated - Adobe Creative Cloud.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2312896] [PID.8900] =>.Adobe Systems Incorporated® [MD5.E4D0FBF9A39FD29519344919885E0D3F] - (.Adobe Systems Incorporated - Adobe IPC Broker.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe [1029792] [PID.8940] =>.Adobe Systems Incorporated® [MD5.191210884CB10B17DA4D627EB2DE9270] - (.VMware, Inc. - VMware Tray Process.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [114368] [PID.8976] =>.VMware, Inc.® [MD5.5EE9595568218E6AA0FE0F6065B65EC7] - (.MyHeritage - MyHeritage Family Tree Builder check for up.) -- C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe [2477056] [PID.9080] =>.MyHeritage [MD5.E774B4C8C885C26A864DE4BDB0584380] - (.Adobe Systems Incorporated - Adobe CEF Helper.) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe [168640] [PID.9184] =>.Adobe Systems Incorporated® [MD5.46E91D8F23069D12CB990FE8A9B05CAA] - (.CANON INC. - Canon IJ Network Scan Utility.) -- C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [206240] [PID.8236] =>.Canon Inc.® [MD5.E774B4C8C885C26A864DE4BDB0584380] - (.Adobe Systems Incorporated - Adobe CEF Helper.) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe [168640] [PID.8352] =>.Adobe Systems Incorporated® [MD5.3BAF0EDDD6412B063B6005B33A0A20F0] - (.Adobe Systems Incorporated - Creative Cloud.) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe [2278592] [PID.8788] =>.Adobe Systems Incorporated® [MD5.B600694D81D6B35F4E36FE3660A0BEBA] - (.Narrative - NarrativeUploader.) -- C:\Program Files (x86)\Narrative\Narrative Uploader\NarrativeUploader.exe [466432] [PID.9308] [MD5.B9B26821425B717CDE880EC43A18AE4F] - (.Copyright © 2013-2015, Adobe Systems Incorporated. Al - Core Sync.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe [31420080] [PID.9544] {3A478D8A8FBE0B32B9F5D0FE6051EE44} [MD5.FFC08513ADF66132EC506B8685882A06] - (.Adobe Systems Incorporated - CCXProcess.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe [154816] [PID.9552] =>.Adobe Systems Incorporated® [MD5.6D5DBA957D94E902F5A2C649A361D4CE] - (.Joyent, Inc - Evented I/O for V8 JavaScript.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe [5529472] [PID.9560] =>.Joyent, Inc® [MD5.A3A704BCB009DF39A2A3BE3714F4933B] - (.Adobe Systems Incorporated - CCLibraries.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe [154816] [PID.10208] =>.Adobe Systems Incorporated® [MD5.6D5DBA957D94E902F5A2C649A361D4CE] - (.Joyent, Inc - Evented I/O for V8 JavaScript.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe [5529472] [PID.10200] =>.Joyent, Inc® [MD5.9BE843A086D13A7B7B575DDEB8ED1B9A] - (.McAfee, Inc. - McAfee.) -- C:\Program Files\Common Files\mcafee\Platform\McUICnt.exe [791360] [PID.11228] =>.McAfee, Inc.® [MD5.63740680B14C2EEE08B11ADADFA98DA1] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [746648] [PID.3928] =>.Google Inc® [MD5.6D37299FC92A009D841A10AF60B751C0] - (.Intel Corporation - Intel(R) ME Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129848] [PID.11140] =>.Intel Corporation® [MD5.7B207A14735265EDED1BAE4792CB525D] - (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [167736] [PID.8364] =>.Intel Corporation® [MD5.A31FE15F4556AA5BA516E5C408E952CF] - (.Intel Corporation - Intel(R) Local Management Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [364856] [PID.11172] =>.Intel Corporation® [MD5.5660057DD2849F798434123891F612F2] - (.McAfee, Inc. - McAfee CSP Service Host.) -- C:\Program Files\Common Files\mcafee\CSP\1.8.267.0\McCSPServiceHost.exe [1696712] [PID.11196] =>.McAfee, Inc.® [MD5.2B2C2D74BC62E22248787530A7AFC87F] - (.TOSHIBA Corporation - TOSHIBA Service Station.) -- C:\Program Files\Toshiba\Toshiba Service Station\ToshibaServiceStation.exe [655464] [PID.3796] =>.TOSHIBA CORPORATION® [MD5.6C4F5CD42074DB52AE88FC4BAB2C54F7] - (.TOSHIBA Corporation - TSS TMachInfo Service.) -- C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe [53864] [PID.10772] =>.TOSHIBA CORPORATION® [MD5.67F2A8FCD91A06E445C374C9E6BB0DD3] - (.TOSHIBA Corporation - TOSHIBA PC Health Monitor.) -- C:\Program Files\Toshiba\TPHM\TPCHSrv.exe [466504] [PID.10080] =>.TOSHIBA CORPORATION® [MD5.3D06451CC0EA519FE768C87A1DFE96DF] - (.TOSHIBA Corporation - TOSHIBA PC Health Monitor.) -- C:\Program Files\Toshiba\TPHM\TPCHWMsg.exe [540240] [PID.3744] =>.TOSHIBA CORPORATION® [MD5.7A5DEBDF20787D389731C4FF08CCE0DA] - (.Toshiba Europe GmbH - Toshiba TEMPRO.) -- C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe [475720] [PID.10948] =>.Toshiba Europe Gmbh® [MD5.D8420B070D035C30CC890981E3C4B567] - (.Toshiba Europe GmbH - Toshiba TEMPRO.) -- C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [120392] [PID.7068] =>.Toshiba Europe Gmbh® [MD5.A5A9C15C851F41E985E7C67FE7938E44] - (.Nicolas Coolman - ZHPDiag.) -- F:\Downloads\ZHPDiag3.exe [2148352] [PID.10108] =>.Nicolas Coolman ---\\ Google Chrome, Start,Search,Extensions (19) - 1s G2 - GCE: Preference [User Data\Default] [aapbdbdomjkkjkaonfhkkikfgjllcleb] __MSG_8969005060131950570__ G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [ehloahmpmbpgpkkdnlnidpokncaaomak] Embedder for Google Business View™ G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [fheoggkfdfchfphceeifdbepaooicaho] SiteAdvisor G2 - GCE: Preference [User Data\Default] [gbkeegbaiigmenfmjfclcdgdpimamgkj] __MSG_extension_name__ G2 - GCE: Preference [User Data\Default] [ggmfokbjchlhboclfngkneflhkopebbh] Pano fetch G2 - GCE: Preference [User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [hcglmfcclpfgljeaiahehebeoaiicbko] Google Photos G2 - GCE: Preference [User Data\Default] [iepnhnepnlihldakjkioihjbhjdgcmde] New On Centre G2 - GCE: Preference [User Data\Default] [nckgahadagoaajjgafhacjanaoiihapd] __MSG_CHROME_HANGOUTS_SHORT_NAME__ G2 - GCE: Preference [User Data\Default] [nmjcnnimilkllghnhhkbciekmdopljcm] GoThru Constellation G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [oiaejidbmkiecgbjeifoejpgmdaleoha] Stylebot G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc. ---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (17) - 1s M1 - SPR:Search Page Redirection - C:\Program Files (x86)\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be P2 - EXT FILE: (...) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8060ccjj.default\extensions\belgiumeid@eid.belgium.be.xpi P2 - EXT FILE: (...) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8060ccjj.default\extensions\cccc5f0d-b9d0-4314-88b5-7e27551f9e84@jetpack.xpi P2 - EXT FILE: (...) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8060ccjj.default\extensions\firefox@mega.co.nz.xpi P2 - EXT FILE: (...) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8060ccjj.default\extensions\jid1-kps5PrGBNtzSLQ@jetpack.xpi P2 - EXT FILE: (...) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8060ccjj.default\extensions\langpack-fr@firefox.mozilla.org.xpi P2 - EXT FILE: (...) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8060ccjj.default\extensions\{71328583-3CA7-4809-B4BA-570A85818FBB}.xpi P2 - EXT FILE: (...) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8060ccjj.default\searchplugins\McSiteAdvisor.xml P2 - EXT FILE: (...) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8060ccjj.default\searchplugins\youtube-video-search.xml P2 - EXT: (.Olivier R. - Dictionnaires français.) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8060ccjj.default\extensions\fr-dicollecte@dictionaries.addons.mozilla.org =>.Olivier R. P2 - EXT: (.Mozilla - Valence.) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8060ccjj.default\extensions\fxdevtools-adapters@mozilla.org =>.Mozilla P2 - EXT: (.HySpell - HySpell Հայերէնի ուղղագրութեան ենթակիր.) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8060ccjj.default\extensions\hy-firefox-ro@hyspell.com P2 - EXT: (.HySpell - HySpell Հայերէնի ուղղագրութեան ենթակիր.) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8060ccjj.default\extensions\hy-firefox@hyspell.com P2 - EXT: (.Tom Mutdosch - HttpRequester.) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\8060ccjj.default\extensions\{ea4637dc-e014-4c17-9c2c-879322d23268} P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll =>.Adobe Systems Incorporated P2 - FPN: [HKLM] [@mcafee.com/MSC,version=10] - (.McAfee Total Protection MIME Plugin.) -- c:\Program Files (x86)\McAfee\MSC\npMcSnFFPl.dll =>.McAfee Total Protection MIME Plugin P2 - FPN: [HKLM] [@vmware.com/vmrc,version=2.5.0.00000] - (.VMware Inc.) -- C:\Program Files (x86)\Common Files\VMware\VMware VMRC Plug-in\Firefox\np-vmware-vmrc.dll ---\\ Internet Explorer Extensions, Start, Search (18) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba13.msn.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 ---\\ Internet Explorer, Proxy Management (4) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: VMApplet=C:\WINDOWS\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation ---\\ Hosts file redirection (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (30) ---\\ Browser Helper Object (BHO) (2) - 0s O2 - BHO: Skype for Business Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} (Orphean) O2 - BHO: Microsoft SkyDrive Pro Browser Helper [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} (Orphean) ---\\ Auto loading programs from Registry and folders (32) - 1s O4 - HKLM\..\Run: [TosWaitSrv] . (.TOSHIBA Corporation - .) -- C:\Program Files\Toshiba\TPHM\TosWaitSrv.exe =>.TOSHIBA CORPORATION® O4 - HKLM\..\Run: [TecoResident] . (.TOSHIBA Corporation - Resident module of eco Utility.) -- C:\Program Files\Toshiba\Teco\TecoResident.exe =>.TOSHIBA CORPORATION® O4 - HKLM\..\Run: [ThpSrv] C:\windows\system32\thpsrv /logon (.not file.) O4 - HKLM\..\Run: [TSleepSrv] . (.TOSHIBA Corporation - Sleep and Charge Service.) -- C:\Program Files (x86)\TOSHIBA\System Setting\TSleepSrv.exe =>.TOSHIBA CORPORATION® O4 - HKLM\..\Run: [TODDMain] . (.Copyright (C) 2012 TOSHIBA Corporation. All rights r - TOSHIBA System Settings Service.) -- C:\Program Files (x86)\TOSHIBA\System Setting\TODDMain.exe =>.TOSHIBA CORPORATION® O4 - HKLM\..\Run: [Nvtmru] C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (.not file.) O4 - HKLM\..\Run: [NvBackend] . (.NVIDIA Corporation - NVIDIA Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe =>.NVIDIA Corporation® O4 - HKLM\..\Run: [ShadowPlay] . (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe =>.Microsoft Corporation O4 - HKLM\..\Run: [cAudioFilterAgent] . (.Conexant Systems, Inc. - Conexant High Definition Audio Filter Agent.) -- C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe =>.Conexant Systems, Inc.® O4 - HKLM\..\Run: [SmartAudio] . (.Conexant Systems, Inc. - SmartAudio CPL (32bit).) -- C:\Program Files\CONEXANT\SAII\SACpl.exe =>.Conexant Systems, Inc. O4 - HKLM\..\Run: [TCrdMain] . (.TOSHIBA Corporation - TOSHIBA Function Key Main Module.) -- C:\Program Files\Toshiba\Hotkey\TCrdMain_Win8.exe =>.TOSHIBA CORPORATION® O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe =>.Adobe Systems Incorporated® O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Google Installer.) -- C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc® O4 - HKCU\..\Run: [Viber] C:\Users\Admin\AppData\Local\Viber\Viber.exe (.not file.) O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] . (.Microsoft Corporation - Sticky Notes.) -- C:\Windows\System32\StikyNot.exe =>.Microsoft Corporation O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - HKCU\..\Run: [Load] . (.AutoIt Team - AutoIt v3 Script.) -- C:\Users\Admin\AppData\Local\Javaxa\Firewall.exe =>.AutoIt Team O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_A5B343D047FD8BD2F268B0EA0F8DBD7C] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - HKLM\..\Wow6432Node\Run: [Intel AppUp(R) center] . (.Intel Corporation - Intel Services Manager.) -- C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe =>.Intel® Services Manager® O4 - HKLM\..\Wow6432Node\Run: [TSVU] . (.TOSHIBA - TOSHIBA Display Setup Launcher.) -- c:\Program Files\Toshiba\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe =>.TOSHIBA CORPORATION® O4 - HKLM\..\Wow6432Node\Run: [Adobe Creative Cloud] . (.Adobe Systems Incorporated - Adobe Creative Cloud.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe =>.Adobe Systems Incorporated® O4 - HKLM\..\Wow6432Node\Run: [beid] C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe (.not file.) O4 - HKLM\..\Wow6432Node\Run: [vmware-tray.exe] . (.VMware, Inc. - VMware Tray Process.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe =>.VMware, Inc.® O4 - HKLM\..\Wow6432Node\Run: [Family Tree Builder Update] . (.MyHeritage - MyHeritage Family Tree Builder check for up.) -- C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe =>.MyHeritage O4 - HKLM\..\Wow6432Node\Run: [IJNetworkScanUtility] . (.CANON INC. - Canon IJ Network Scan Utility.) -- C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe =>.Canon Inc.® O4 - HKLM\..\Wow6432Node\Run: [NarrativeUploader] . (.Narrative - NarrativeUploader.) -- C:\Program Files (x86)\Narrative\Narrative Uploader\NarrativeUploader.exe O4 - HKUS\S-1-5-21-1056618793-1677908267-3770283503-1002\..\Run: [Google Update] . (.Google Inc. - Google Installer.) -- C:\Users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc® O4 - HKUS\S-1-5-21-1056618793-1677908267-3770283503-1002\..\Run: [Viber] C:\Users\Admin\AppData\Local\Viber\Viber.exe (.not file.) O4 - HKUS\S-1-5-21-1056618793-1677908267-3770283503-1002\..\Run: [RESTART_STICKY_NOTES] . (.Microsoft Corporation - Sticky Notes.) -- C:\Windows\System32\StikyNot.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-1056618793-1677908267-3770283503-1002\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - HKUS\S-1-5-21-1056618793-1677908267-3770283503-1002\..\Run: [Load] . (.AutoIt Team - AutoIt v3 Script.) -- C:\Users\Admin\AppData\Local\Javaxa\Firewall.exe =>.AutoIt Team O4 - HKUS\S-1-5-21-1056618793-1677908267-3770283503-1002\..\Run: [GoogleChromeAutoLaunch_A5B343D047FD8BD2F268B0EA0F8DBD7C] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® ---\\ Global shortcuts Startup (143) - 5s O4 - GS\Desktop [Admin]: GMBV-Leads.ods - Shortcut.lnk . (...) D:\My Documents\Google MBV\GMBV-Leads.ods O4 - GS\Desktop [Admin]: GoToMeeting Quick Connect.lnk . (.Citrix Online, a division of Citrix Systems, Inc. - GoToMeeting.) C:\Program Files (x86)\Citrix\GoToMeeting\1172\g2mstart.exe {5C5F2BA5C9994BE5EF254FFE511288E1} O4 - GS\Desktop [Admin]: Kolor Autopano Giga 4.0.lnk . (.Kolor - .) C:\Program Files (x86)\Kolor\Autopano Giga 4.0\AutopanoGiga_x64.exe =>.Kolor O4 - GS\Desktop [Admin]: Kolor Panotour Pro 2.5.lnk . (.Kolor - .) C:\Program Files (x86)\Kolor\Panotour Pro 2.5\PanotourPro_x64.exe =>.Kolor O4 - GS\Desktop [Admin]: Kolor Panotour Viewer 1.0.lnk . (.Kolor - Panotour Viewer.) C:\Program Files (x86)\Kolor\Panotour Viewer 1.0\PanotourViewer_win32.exe {04E6993F8B7C7F94E04A7E01DCBB1E6B} =>.Kolor O4 - GS\Desktop [Admin]: Lightroom 6.0.lnk . (.Adobe Systems - .) C:\Program Files (x86)\Adobe\Adobe Lightroom\lightroom.exe =>.Adobe Systems O4 - GS\Desktop [Admin]: MediaInfo.lnk . (.MediaArea.net - .) C:\Program Files (x86)\MediaInfo\MediaInfo.exe =>.MediaArea.net O4 - GS\Desktop [Admin]: MKVExtract.lnk . (...) C:\Program Files (x86)\MKVToolNix\MKVExtractGUI2.exe O4 - GS\Desktop [Admin]: mRemoteNG.lnk . (.Copyright © 2007-2009 Felix Deimel, 2010-2013 Riley M - mRemoteNG.) C:\Program Files (x86)\mRemoteNG\mRemoteNG.exe =>.Astrospark Technologies, LLC® O4 - GS\Desktop [Admin]: MyHeritage Family Tree Builder.lnk . (.MyHeritage - MyHeritage Family Tree Builder Genealogy So.) C:\Program Files (x86)\MyHeritage\Bin\MyHeritage.exe =>.MyHeritage Ltd.® O4 - GS\Desktop [Admin]: Panini 0.71.lnk . (...) C:\Program Files (x86)\Panini\panini-0.71.104B-win32\Panini.exe O4 - GS\Desktop [Admin]: PeaZip.lnk . (.Giorgio Tani - .) C:\Program Files (x86)\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\Desktop [Admin]: Photoshop CC (2015).lnk . (.Adobe Systems, Incorporated - .) C:\Program Files (x86)\Adobe\Adobe Photoshop CC 2015\Photoshop.exe =>.Adobe Systems, Incorporated O4 - GS\Desktop [Admin]: Spyder4Pro 4.5.4.lnk . (...) C:\Program Files (x86)\Datacolor\Spyder4Pro\Spyder4Pro.exe O4 - GS\Desktop [Admin]: SubtitleEdit.lnk . (.Nikse - Subtitle Edit.) C:\Program Files (x86)\Subtitle Edit\SubtitleEdit.exe =>.Nikse O4 - GS\Desktop [Admin]: Transmission Remote GUI.lnk . (.Yury Sidorov - Transmission Remote GUI.) C:\Program Files (x86)\Transmission Remote GUI\transgui.exe =>.Yury Sidorov O4 - GS\Desktop [Admin]: ZHPCleaner.lnk . (...) C:\Users\Admin\AppData\Roaming\ZHP\ZHPCleaner.exe O4 - GS\Desktop [Admin]: ZHPDiag.lnk . (...) C:\Users\Admin\ZHPDiag3.exe O4 - GS\Quicklaunch [Admin]: DVDFab 9.lnk . (.Fengtao Software Inc. - DVDFab 9 is the all-in-one software to copy.) C:\Program Files (x86)\DVDFab 9\DVDFab.exe =>.Fengtao Software Inc.® O4 - GS\Quicklaunch [Admin]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Admin]: Kolor Autopano Giga 4.0.lnk . (.Kolor - Autopano Giga (Build 01/06/2015).) C:\Program Files\Kolor\Autopano Giga 4.0\AutopanoGiga_x64.exe =>.Kolor O4 - GS\Quicklaunch [Admin]: Kolor Autopano Giga 4.2.lnk . (.Kolor - Autopano Giga (Build 01/12/2015).) C:\Program Files\Kolor\Autopano Giga 4.2\AutopanoGiga_x64.exe =>.Kolor O4 - GS\Quicklaunch [Admin]: Kolor Panotour Pro 2.3.lnk . (.Kolor - Panotour Pro.) C:\Program Files\Kolor\Panotour Pro 2.3\PanotourPro_x64.exe {04E6993F8B7C7F94E04A7E01DCBB1E6B} =>.Kolor O4 - GS\Quicklaunch [Admin]: Kolor Panotour Viewer 1.0.lnk . (.Kolor - Panotour Viewer.) C:\Program Files (x86)\Kolor\Panotour Viewer 1.0\PanotourViewer_win32.exe {04E6993F8B7C7F94E04A7E01DCBB1E6B} =>.Kolor O4 - GS\Quicklaunch [Admin]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe =>.Mozilla Corporation® O4 - GS\Quicklaunch [Admin]: VMware Workstation.lnk . (.VMware, Inc. - VMware Workstation.) C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe =>.VMware, Inc.® O4 - GS\sendTo [Admin]: Add to archive.lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Admin]: Browse path with PeaZip.lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Admin]: Extract here (in new folder).lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Admin]: Extract here.lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Admin]: Extract....lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Admin]: Open as archive.lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Admin]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - GS\sendTo [Admin]: Test archive(s).lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\TaskBar [Admin]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [Admin]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\TaskBar [Admin]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe =>.Mozilla Corporation® O4 - GS\Startup [Admin]: SystemCC.lnk . (.AutoIt Team - AutoIt v3 Script.) C:\Users\Admin\AppData\Local\Javaxa\Firewall.exe =>.AutoIt Team O4 - GS\Desktop [Administrator]: GMBV-Leads.ods - Shortcut.lnk . (...) D:\My Documents\Google MBV\GMBV-Leads.ods O4 - GS\Desktop [Administrator]: GoToMeeting Quick Connect.lnk . (.Citrix Online, a division of Citrix Systems, Inc. - GoToMeeting.) C:\Program Files (x86)\Citrix\GoToMeeting\1172\g2mstart.exe {5C5F2BA5C9994BE5EF254FFE511288E1} O4 - GS\Desktop [Administrator]: Kolor Autopano Giga 4.0.lnk . (.Kolor - .) C:\Program Files (x86)\Kolor\Autopano Giga 4.0\AutopanoGiga_x64.exe =>.Kolor O4 - GS\Desktop [Administrator]: Kolor Panotour Pro 2.5.lnk . (.Kolor - .) C:\Program Files (x86)\Kolor\Panotour Pro 2.5\PanotourPro_x64.exe =>.Kolor O4 - GS\Desktop [Administrator]: Kolor Panotour Viewer 1.0.lnk . (.Kolor - Panotour Viewer.) C:\Program Files (x86)\Kolor\Panotour Viewer 1.0\PanotourViewer_win32.exe {04E6993F8B7C7F94E04A7E01DCBB1E6B} =>.Kolor O4 - GS\Desktop [Administrator]: Lightroom 6.0.lnk . (.Adobe Systems - .) C:\Program Files (x86)\Adobe\Adobe Lightroom\lightroom.exe =>.Adobe Systems O4 - GS\Desktop [Administrator]: MediaInfo.lnk . (.MediaArea.net - .) C:\Program Files (x86)\MediaInfo\MediaInfo.exe =>.MediaArea.net O4 - GS\Desktop [Administrator]: MKVExtract.lnk . (...) C:\Program Files (x86)\MKVToolNix\MKVExtractGUI2.exe O4 - GS\Desktop [Administrator]: mRemoteNG.lnk . (.Copyright © 2007-2009 Felix Deimel, 2010-2013 Riley M - mRemoteNG.) C:\Program Files (x86)\mRemoteNG\mRemoteNG.exe =>.Astrospark Technologies, LLC® O4 - GS\Desktop [Administrator]: MyHeritage Family Tree Builder.lnk . (.MyHeritage - MyHeritage Family Tree Builder Genealogy So.) C:\Program Files (x86)\MyHeritage\Bin\MyHeritage.exe =>.MyHeritage Ltd.® O4 - GS\Desktop [Administrator]: Panini 0.71.lnk . (...) C:\Program Files (x86)\Panini\panini-0.71.104B-win32\Panini.exe O4 - GS\Desktop [Administrator]: PeaZip.lnk . (.Giorgio Tani - .) C:\Program Files (x86)\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\Desktop [Administrator]: Photoshop CC (2015).lnk . (.Adobe Systems, Incorporated - .) C:\Program Files (x86)\Adobe\Adobe Photoshop CC 2015\Photoshop.exe =>.Adobe Systems, Incorporated O4 - GS\Desktop [Administrator]: Spyder4Pro 4.5.4.lnk . (...) C:\Program Files (x86)\Datacolor\Spyder4Pro\Spyder4Pro.exe O4 - GS\Desktop [Administrator]: SubtitleEdit.lnk . (.Nikse - Subtitle Edit.) C:\Program Files (x86)\Subtitle Edit\SubtitleEdit.exe =>.Nikse O4 - GS\Desktop [Administrator]: Transmission Remote GUI.lnk . (.Yury Sidorov - Transmission Remote GUI.) C:\Program Files (x86)\Transmission Remote GUI\transgui.exe =>.Yury Sidorov O4 - GS\Desktop [Administrator]: ZHPCleaner.lnk . (...) C:\Users\Admin\AppData\Roaming\ZHP\ZHPCleaner.exe O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (...) C:\Users\Admin\ZHPDiag3.exe O4 - GS\Quicklaunch [Administrator]: DVDFab 9.lnk . (.Fengtao Software Inc. - DVDFab 9 is the all-in-one software to copy.) C:\Program Files (x86)\DVDFab 9\DVDFab.exe =>.Fengtao Software Inc.® O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Administrator]: Kolor Autopano Giga 4.0.lnk . (.Kolor - Autopano Giga (Build 01/06/2015).) C:\Program Files\Kolor\Autopano Giga 4.0\AutopanoGiga_x64.exe =>.Kolor O4 - GS\Quicklaunch [Administrator]: Kolor Autopano Giga 4.2.lnk . (.Kolor - Autopano Giga (Build 01/12/2015).) C:\Program Files\Kolor\Autopano Giga 4.2\AutopanoGiga_x64.exe =>.Kolor O4 - GS\Quicklaunch [Administrator]: Kolor Panotour Pro 2.3.lnk . (.Kolor - Panotour Pro.) C:\Program Files\Kolor\Panotour Pro 2.3\PanotourPro_x64.exe {04E6993F8B7C7F94E04A7E01DCBB1E6B} =>.Kolor O4 - GS\Quicklaunch [Administrator]: Kolor Panotour Viewer 1.0.lnk . (.Kolor - Panotour Viewer.) C:\Program Files (x86)\Kolor\Panotour Viewer 1.0\PanotourViewer_win32.exe {04E6993F8B7C7F94E04A7E01DCBB1E6B} =>.Kolor O4 - GS\Quicklaunch [Administrator]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe =>.Mozilla Corporation® O4 - GS\Quicklaunch [Administrator]: VMware Workstation.lnk . (.VMware, Inc. - VMware Workstation.) C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe =>.VMware, Inc.® O4 - GS\sendTo [Administrator]: Add to archive.lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Administrator]: Browse path with PeaZip.lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Administrator]: Extract here (in new folder).lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Administrator]: Extract here.lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Administrator]: Extract....lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Administrator]: Open as archive.lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Administrator]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - GS\sendTo [Administrator]: Test archive(s).lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\TaskBar [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [Administrator]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\TaskBar [Administrator]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe =>.Mozilla Corporation® O4 - GS\Startup [Administrator]: SystemCC.lnk . (.AutoIt Team - AutoIt v3 Script.) C:\Users\Admin\AppData\Local\Javaxa\Firewall.exe =>.AutoIt Team O4 - GS\Desktop [Guest]: GMBV-Leads.ods - Shortcut.lnk . (...) D:\My Documents\Google MBV\GMBV-Leads.ods O4 - GS\Desktop [Guest]: GoToMeeting Quick Connect.lnk . (.Citrix Online, a division of Citrix Systems, Inc. - GoToMeeting.) C:\Program Files (x86)\Citrix\GoToMeeting\1172\g2mstart.exe {5C5F2BA5C9994BE5EF254FFE511288E1} O4 - GS\Desktop [Guest]: Kolor Autopano Giga 4.0.lnk . (.Kolor - .) C:\Program Files (x86)\Kolor\Autopano Giga 4.0\AutopanoGiga_x64.exe =>.Kolor O4 - GS\Desktop [Guest]: Kolor Panotour Pro 2.5.lnk . (.Kolor - .) C:\Program Files (x86)\Kolor\Panotour Pro 2.5\PanotourPro_x64.exe =>.Kolor O4 - GS\Desktop [Guest]: Kolor Panotour Viewer 1.0.lnk . (.Kolor - Panotour Viewer.) C:\Program Files (x86)\Kolor\Panotour Viewer 1.0\PanotourViewer_win32.exe {04E6993F8B7C7F94E04A7E01DCBB1E6B} =>.Kolor O4 - GS\Desktop [Guest]: Lightroom 6.0.lnk . (.Adobe Systems - .) C:\Program Files (x86)\Adobe\Adobe Lightroom\lightroom.exe =>.Adobe Systems O4 - GS\Desktop [Guest]: MediaInfo.lnk . (.MediaArea.net - .) C:\Program Files (x86)\MediaInfo\MediaInfo.exe =>.MediaArea.net O4 - GS\Desktop [Guest]: MKVExtract.lnk . (...) C:\Program Files (x86)\MKVToolNix\MKVExtractGUI2.exe O4 - GS\Desktop [Guest]: mRemoteNG.lnk . (.Copyright © 2007-2009 Felix Deimel, 2010-2013 Riley M - mRemoteNG.) C:\Program Files (x86)\mRemoteNG\mRemoteNG.exe =>.Astrospark Technologies, LLC® O4 - GS\Desktop [Guest]: MyHeritage Family Tree Builder.lnk . (.MyHeritage - MyHeritage Family Tree Builder Genealogy So.) C:\Program Files (x86)\MyHeritage\Bin\MyHeritage.exe =>.MyHeritage Ltd.® O4 - GS\Desktop [Guest]: Panini 0.71.lnk . (...) C:\Program Files (x86)\Panini\panini-0.71.104B-win32\Panini.exe O4 - GS\Desktop [Guest]: PeaZip.lnk . (.Giorgio Tani - .) C:\Program Files (x86)\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\Desktop [Guest]: Photoshop CC (2015).lnk . (.Adobe Systems, Incorporated - .) C:\Program Files (x86)\Adobe\Adobe Photoshop CC 2015\Photoshop.exe =>.Adobe Systems, Incorporated O4 - GS\Desktop [Guest]: Spyder4Pro 4.5.4.lnk . (...) C:\Program Files (x86)\Datacolor\Spyder4Pro\Spyder4Pro.exe O4 - GS\Desktop [Guest]: SubtitleEdit.lnk . (.Nikse - Subtitle Edit.) C:\Program Files (x86)\Subtitle Edit\SubtitleEdit.exe =>.Nikse O4 - GS\Desktop [Guest]: Transmission Remote GUI.lnk . (.Yury Sidorov - Transmission Remote GUI.) C:\Program Files (x86)\Transmission Remote GUI\transgui.exe =>.Yury Sidorov O4 - GS\Desktop [Guest]: ZHPCleaner.lnk . (...) C:\Users\Admin\AppData\Roaming\ZHP\ZHPCleaner.exe O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (...) C:\Users\Admin\ZHPDiag3.exe O4 - GS\Quicklaunch [Guest]: DVDFab 9.lnk . (.Fengtao Software Inc. - DVDFab 9 is the all-in-one software to copy.) C:\Program Files (x86)\DVDFab 9\DVDFab.exe =>.Fengtao Software Inc.® O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Guest]: Kolor Autopano Giga 4.0.lnk . (.Kolor - Autopano Giga (Build 01/06/2015).) C:\Program Files\Kolor\Autopano Giga 4.0\AutopanoGiga_x64.exe =>.Kolor O4 - GS\Quicklaunch [Guest]: Kolor Autopano Giga 4.2.lnk . (.Kolor - Autopano Giga (Build 01/12/2015).) C:\Program Files\Kolor\Autopano Giga 4.2\AutopanoGiga_x64.exe =>.Kolor O4 - GS\Quicklaunch [Guest]: Kolor Panotour Pro 2.3.lnk . (.Kolor - Panotour Pro.) C:\Program Files\Kolor\Panotour Pro 2.3\PanotourPro_x64.exe {04E6993F8B7C7F94E04A7E01DCBB1E6B} =>.Kolor O4 - GS\Quicklaunch [Guest]: Kolor Panotour Viewer 1.0.lnk . (.Kolor - Panotour Viewer.) C:\Program Files (x86)\Kolor\Panotour Viewer 1.0\PanotourViewer_win32.exe {04E6993F8B7C7F94E04A7E01DCBB1E6B} =>.Kolor O4 - GS\Quicklaunch [Guest]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe =>.Mozilla Corporation® O4 - GS\Quicklaunch [Guest]: VMware Workstation.lnk . (.VMware, Inc. - VMware Workstation.) C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe =>.VMware, Inc.® O4 - GS\sendTo [Guest]: Add to archive.lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Guest]: Browse path with PeaZip.lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Guest]: Extract here (in new folder).lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Guest]: Extract here.lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Guest]: Extract....lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Guest]: Open as archive.lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\sendTo [Guest]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - GS\sendTo [Guest]: Test archive(s).lnk . (.Giorgio Tani - PeaZip, file and archive manager.) C:\Program Files\PeaZip\peazip.exe =>.Giorgio Tani O4 - GS\TaskBar [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [Guest]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\TaskBar [Guest]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe =>.Mozilla Corporation® O4 - GS\Startup [Guest]: SystemCC.lnk . (.AutoIt Team - AutoIt v3 Script.) C:\Users\Admin\AppData\Local\Javaxa\Firewall.exe =>.AutoIt Team O4 - GS\CommonDesktop [Public]: Acrobat Reader DC.lnk . (.Adobe Systems Incorporated - Adobe Acrobat Reader DC.) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe =>.Adobe Systems, Incorporated® O4 - GS\CommonDesktop [Public]: Adobe Creative Cloud.lnk . (.Adobe Systems Incorporated - Adobe Creative Cloud.) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe =>.Adobe Systems Incorporated® O4 - GS\CommonDesktop [Public]: Audacity.lnk . (.The Audacity Team - Audacity®, the Free, Cross-Platform Sound E.) C:\Program Files (x86)\Audacity\audacity.exe O4 - GS\CommonDesktop [Public]: Calibre.lnk . (...) C:\Program Files (x86)\Calibre2\calibre.exe O4 - GS\CommonDesktop [Public]: Camtasia Studio 8.lnk . (.TechSmith Corporation - Camtasia Studio.) C:\Program Files (x86)\TechSmith\Camtasia Studio 8\CamtasiaStudio.exe =>.TechSmith Corporation® O4 - GS\CommonDesktop [Public]: Canon IJ Network Tool.lnk . (.CANON INC. - Canon IJ Network Tool.) C:\Program Files (x86)\Canon\Canon IJ Network Tool\CNMNPUT.EXE =>.Canon Inc.® O4 - GS\CommonDesktop [Public]: Desktop Assist.lnk . (.TOSHIBA - .) C:\Program Files (x86)\Toshiba\TOSHIBA Desktop Assist\TosDesktopAssist.exe =>.TOSHIBA O4 - GS\CommonDesktop [Public]: DVDFab 9.lnk . (.Fengtao Software Inc. - DVDFab 9 is the all-in-one software to copy.) C:\Program Files (x86)\DVDFab 9\DVDFab.exe =>.Fengtao Software Inc.® O4 - GS\CommonDesktop [Public]: eID Viewer.lnk . (.FedICT - Viewer for Belgian eID Cards.) C:\Program Files (x86)\Belgium Identity Card\EidViewer\eID Viewer.exe =>.Fedict O4 - GS\CommonDesktop [Public]: FileZilla Client.lnk . (.FileZilla Project - FileZilla FTP Client.) C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe =>.Tim Kosse® O4 - GS\CommonDesktop [Public]: GeForce Experience.lnk . (.NVIDIA Corporation - NVIDIA GeForce Experience Launcher Applicat.) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\LaunchGFExperience.exe =>.NVIDIA Corporation® O4 - GS\CommonDesktop [Public]: Kolor Autopano Giga 4.2.lnk . (.Kolor - Autopano Giga (Build 01/12/2015).) C:\Program Files\Kolor\Autopano Giga 4.2\AutopanoGiga_x64.exe =>.Kolor O4 - GS\CommonDesktop [Public]: Manual.lnk . (.TOSHIBA - Toshiba Regensburg EXternal file Launcher.) C:\Program Files (x86)\TOSHIBA\Manuals\TREXLauncher.exe =>.TOSHIBA CORPORATION® O4 - GS\CommonDesktop [Public]: McAfee Internet Security Suite.lnk . (.McAfee, Inc. - McAfee.) C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe =>.McAfee, Inc.® O4 - GS\CommonDesktop [Public]: McAfee Security Scan Plus.lnk . (.McAfee, Inc. - McAfee.) C:\Program Files\McAfee Security Scan\3.11.292\McUICnt.exe =>.McAfee, Inc.® O4 - GS\CommonDesktop [Public]: Microsoft Office.lnk . (...) C:\ProgramData\Toshiba\OfficeLink.cmd O4 - GS\CommonDesktop [Public]: mkvmerge.lnk . (...) C:\Program Files (x86)\MKVToolNix\mmg.exe O4 - GS\CommonDesktop [Public]: Network Recording Player.lnk . (.Cisco WebEx LLC - NBR Player Execute Module.) C:\ProgramData\WebEx\WebEx\500\nbrplay.exe {3C92413AD422E2E64910FB8B9C3DAA45} =>.Cisco WebEx LLC O4 - GS\CommonDesktop [Public]: OpenOffice 4.1.1.lnk . (.Apache Software Foundation - OpenOffice 4.1.1.) C:\Program Files (x86)\OpenOffice 4\program\soffice.exe =>.Apache Software Foundation O4 - GS\CommonDesktop [Public]: Recovery Media Creator.lnk . (.Toshiba Information Equipment(Hangzhou)Co.,LTD - TOSHIBA Recovery Media Creator Launcher.) C:\Program Files\Toshiba\TOSHIBA Recovery Media Creator\TRMCLcher.exe =>.TOSHIBA CORPORATION® O4 - GS\CommonDesktop [Public]: Skype.lnk . (...) C:\WINDOWS\Installer\{FC965A47-4839-40CA-B618-18F486F042C6}\SkypeIcon.exe O4 - GS\CommonDesktop [Public]: Toshiba Tempro.lnk . (.Toshiba Europe GmbH - Toshiba TEMPRO.) C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe =>.Toshiba Europe Gmbh® O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe =>.VideoLAN® O4 - GS\CommonDesktop [Public]: VMware vSphere Client.lnk . (.VMware, Inc. - VpxClient.) C:\Program Files (x86)\VMware\Infrastructure\Virtual Infrastructure Client\Launcher\VpxClient.exe =>.VMware, Inc.® O4 - GS\CommonDesktop [Public]: VMware Workstation.lnk . (.VMware, Inc. - VMware Workstation.) C:\Program Files (x86)\VMware\VMware Workstation\vmware.exe =>.VMware, Inc.® O4 - GS\CommonDesktop [Public]: XMedia Recode.lnk . (.XMedia Recode - XMedia Recode.) C:\Program Files (x86)\XMedia Recode\XMedia Recode.exe O4 - GS\Startup [Public]: McAfee Security Scan Plus.lnk . (.McAfee, Inc. - McAfee Security Scanner Scheduler.) C:\Program Files\McAfee Security Scan\3.11.292\SSScheduler.exe =>.McAfee, Inc.® O4 - GS\Startup [Public]: SpyderUtility.lnk . (...) C:\Program Files (x86)\Datacolor\Spyder4Pro\Utility\SpyderUtility.exe O4 - GS\Programs [Public]: MediaInfo.lnk . (.MediaArea.net - All about your audio and video files.) C:\Program Files\MediaInfo\MediaInfo.exe =>.MediaArea.net ---\\ Lop.com/Domain Hijackers (3) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.4.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3E8400C7-B8C8-4CFA-BEF2-067D7C7A35F7}: DhcpNameServer = 192.168.4.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5254CC44-21F7-4907-87B9-8430390551D0}: DhcpNameServer = 192.168.4.1 ---\\ Extra protocols (25) - 0s O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: dssrequest [64Bits] - {5513F07E-936B-4E52-9B00-067394E91CC5} . (.McAfee, Inc. - WebAdvisor.) -- c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll =>.McAfee, Inc.® O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\SysWOW64\inetcomm.dll =>.Microsoft Corporation O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation O18 - Handler: osf [64Bits] - {D924BDC6-C83A-4BD5-90D0-095128A113D1} . (.Microsoft Corporation - Microsoft Office 2013 component.) -- C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL =>.Microsoft Corporation® O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: sacore [64Bits] - {5513F07E-936B-4E52-9B00-067394E91CC5} . (.McAfee, Inc. - WebAdvisor.) -- c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll =>.McAfee, Inc.® O18 - Handler: skype4com [64Bits] - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} . (.Skype Technologies - Skype4COM.) -- C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll =>.Skype Software Sarl® O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation O18 - Filter: application/x-mfe-ipt [64Bits] - {3EF5086B-5478-4598-A054-786C45D75692} . (.McAfee, Inc. - McAfee MSC IE plugin DLL.) -- c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll =>.McAfee, Inc.® O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation ---\\ AppInit_DLLs Registry value Autorun (1) - 0s O20 - AppInit_DLLs: . (.NVIDIA Corporation - NVIDIA shim initialization dll, Version 361.) - C:\Windows\System32\nvinitx.dll ---\\ Software installed (134) - 10s O42 - Logiciel: Adobe Acrobat Reader DC - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1033-7B44-AC0F074E4100} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Creative Cloud - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Creative Cloud =>.Adobe Systems Incorporated® O42 - Logiciel: Adobe Flash Player 20 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated® O42 - Logiciel: Adobe Lightroom - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {8048A5DF-8A70-5BE1-954B-E0FDE1BD0D0D} =>.Adobe Systems Incorporated® O42 - Logiciel: Adobe Photoshop CC 2015 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {793C2BF7-A4FE-4608-91C9-9282C5801C21} =>.Adobe Systems Incorporated® O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-0804-1033-1959-001824166751} =>.Adobe Systems Incorporated O42 - Logiciel: Audacity 2.0.5 - (.Audacity Team.) [HKLM][64Bits] -- Audacity_is1 =>.Audacity Team O42 - Logiciel: Belgium e-ID middleware 4.0.7 (build 7453) - (.Belgian Government.) [HKLM][64Bits] -- {824563DE-75AD-4166-9DC0-B6482F207453} =>.Belgian Government O42 - Logiciel: calibre 64bit - (.Kovid Goyal.) [HKLM][64Bits] -- {C569C9D1-CE3A-454C-9642-37FDFC6B628D} =>.Kovid Goyal O42 - Logiciel: Camtasia Studio 8 - (.TechSmith Corporation.) [HKLM][64Bits] -- {904AC0F0-F69E-467E-A719-B083940F608A} =>.TechSmith Corporation O42 - Logiciel: Canon IJ Network Scan Utility - (...) [HKLM][64Bits] -- Canon_IJ_Network_Scan_UTILITY =>.Canon Inc.® O42 - Logiciel: Canon IJ Network Tool - (.Canon Inc..) [HKLM][64Bits] -- Canon_IJ_Network_UTILITY =>.Canon Inc.® O42 - Logiciel: Canon MG6100 series MP Drivers - (.Canon Inc..) [HKLM][64Bits] -- {1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6100_series =>.Canon Inc.® O42 - Logiciel: Canon My Printer - (.Canon Inc..) [HKLM][64Bits] -- CanonMyPrinter =>.Canon Inc.® O42 - Logiciel: Cisco WebEx Meetings - (.Cisco WebEx LLC.) [HKCU][64Bits] -- ActiveTouchMeetingClient {3C92413AD422E2E64910FB8B9C3DAA45} =>.Cisco WebEx LLC O42 - Logiciel: Citrix Online Launcher - (.Citrix.) [HKLM][64Bits] -- {6740FE60-43C1-4D15-8C4A-001624134B14} =>.Citrix O42 - Logiciel: Conexant HD Audio - (.Conexant.) [HKLM][64Bits] -- CNXT_AUDIO_HDA =>.Conexant Systems, Inc.® O42 - Logiciel: DTS Studio Sound - (.DTS, Inc..) [HKLM][64Bits] -- {2DFA9084-CEB3-4A48-B9F7-9038FEF1B8F4} =>.DTS, Inc. O42 - Logiciel: DVDFab 9.1.2.8 (19/02/2014) - (.Fengtao Software Inc..) [HKLM][64Bits] -- DVDFab 9_is1 =>.Fengtao Software Inc.® O42 - Logiciel: FFmpeg v0.6.2 for Audacity - (...) [HKLM][64Bits] -- FFmpeg for Audacity_is1 O42 - Logiciel: FileZilla Client 3.16.0 - (.Tim Kosse.) [HKLM][64Bits] -- FileZilla Client =>.Tim Kosse O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome =>.Google Inc® O42 - Logiciel: Google Earth Plug-in - (.Google.) [HKLM][64Bits] -- {4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E} =>.Google O42 - Logiciel: Google Talk Plugin - (.Google.) [HKLM][64Bits] -- {F9B579C2-D854-300A-BE62-A09EB9D722E4} =>.Google O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc. O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>.Google Inc. O42 - Logiciel: GoToMeeting 7.13.0.4542 - (.CitrixOnline.) [HKCU][64Bits] -- GoToMeeting {44AD220DBF367E6C4D2E480E121853D7} =>.CitrixOnline O42 - Logiciel: Intel AppUp(R) center - (.Intel.) [HKLM][64Bits] -- Intel AppUp(R) center 41663 =>.Intel AppUp(R) center® O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A} =>.Intel Corporation® O42 - Logiciel: Intel(R) PRO/Wireless Driver - (.Intel Corporation.) [HKLM][64Bits] -- {12f53c5a-08b1-4534-a370-49c076e2656d} =>.Intel Corporation O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} =>.Intel Corporation - pGFX® O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {409CB30E-E457-4008-9B1A-ED1B9EA21140} =>.Intel Corporation O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {96714280-14E6-4DF7-BACD-F797C0F17C3D} =>.Intel Corporation O42 - Logiciel: Intel(R) SDK for OpenCL - CPU Only Runtime Package - (.Intel Corporation.) [HKLM][64Bits] -- {FCB3772C-B7D0-4933-B1A9-3707EBACC573} =>.Intel Corporation O42 - Logiciel: Intel(R) Update Manager - (.Intel Corporation.) [HKLM][64Bits] -- {B991A1BC-DE0F-41B3-9037-B2F948F706EC} =>.Intel Corporation O42 - Logiciel: Intel(R) WiDi - (.Intel Corporation.) [HKLM][64Bits] -- {62E7C369-64FF-452C-8F46-6BE9B77FF097} =>.Intel Corporation O42 - Logiciel: Intel® PROSet/Wireless Software - (.Intel Corporation.) [HKLM][64Bits] -- {8e41467d-297e-496d-8b0f-e771b6c87c06} =>.Intel Corporation-Mobile Wireless Group® O42 - Logiciel: Intel® PROSet/Wireless WiFi Software - (.Intel Corporation.) [HKLM][64Bits] -- {1C03A416-D8D5-42F6-87CE-4874A383EBEB} =>.Intel Corporation O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {FA00A3CC-7440-4938-A271-F186F50DD40D} =>.Intel Corporation O42 - Logiciel: Java 7 Update 71 - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F03217071FF} =>.Oracle O42 - Logiciel: Java 8 Update 25 - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83218025F0} =>.Oracle Corporation O42 - Logiciel: Java Auto Updater - (.Oracle Corporation.) [HKLM][64Bits] -- {4A03706F-666A-4037-7777-5F2748764D10} =>.Oracle Corporation O42 - Logiciel: Kolor Autopano Giga 4.0 - (.Kolor.) [HKLM][64Bits] -- AutopanoGiga4.0 {04E6993F8B7C7F94E04A7E01DCBB1E6B} =>.Kolor O42 - Logiciel: Kolor Autopano Giga 4.2 - (.Kolor.) [HKLM][64Bits] -- AutopanoGiga4.2 {082916A1B615D1545742E9ED6F84C79C} =>.Kolor O42 - Logiciel: Kolor Panotour Pro 2.3 - (.Kolor.) [HKLM][64Bits] -- Panotour Pro 2.3 {04E6993F8B7C7F94E04A7E01DCBB1E6B} =>.Kolor O42 - Logiciel: Kolor Panotour Pro 2.5 - (.Kolor.) [HKLM][64Bits] -- Panotour Pro 2.5 {082916A1B615D1545742E9ED6F84C79C} =>.Kolor O42 - Logiciel: Kolor Panotour Viewer 1.0 - (.Kolor.) [HKLM][64Bits] -- Panotour Viewer 1.0 {04E6993F8B7C7F94E04A7E01DCBB1E6B} =>.Kolor O42 - Logiciel: McAfee Internet Security Suite - (.McAfee, Inc..) [HKLM][64Bits] -- MSC =>.McAfee, Inc.® O42 - Logiciel: McAfee Security Scan Plus - (.McAfee, Inc..) [HKLM][64Bits] -- McAfee Security Scan =>.McAfee, Inc.® O42 - Logiciel: McAfee WebAdvisor - (.McAfee, Inc..) [HKLM][64Bits] -- {35ED3F83-4BDC-4c44-8EC6-6A8301C7413A} =>.McAfee, Inc.® O42 - Logiciel: MediaInfo 0.7.68 - (.MediaArea.net.) [HKLM][64Bits] -- MediaInfo =>.MediaArea.net O42 - Logiciel: Microsoft OneDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- OneDriveSetup.exe =>.Microsoft Corporation® O42 - Logiciel: Microsoft OneNote 2013 - en-us - (.Microsoft Corporation.) [HKLM][64Bits] -- OneNoteFreeRetail - en-us =>.Microsoft Corporation® O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation O42 - Logiciel: MKVToolNix 7.6.0 (64bit) - (.Moritz Bunkus.) [HKLM][64Bits] -- MKVToolNix =>.Moritz Bunkus O42 - Logiciel: Mozilla Firefox 45.0 (x86 en-US) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 45.0 (x86 en-US) =>.Mozilla Corporation® O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService =>.Mozilla O42 - Logiciel: Mozilla Thunderbird 38.6.0 (x86 en-US) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Thunderbird 38.6.0 (x86 en-US) =>.Mozilla Corporation® O42 - Logiciel: mRemoteNG - (.Next Generation Software.) [HKLM][64Bits] -- mRemoteNG O42 - Logiciel: MyHeritage Family Tree Builder - (.MyHeritage.com.) [HKLM][64Bits] -- Family Tree Builder =>.MyHeritage.com O42 - Logiciel: Narrative Clip 2 Driver x64 - (.Narrative.) [HKLM][64Bits] -- {B6810DA9-73C0-47DA-B294-7AF295EB3441} O42 - Logiciel: Narrative Uploader - (.Narrative.) [HKLM][64Bits] -- {6054FDA3-E4E7-4C03-93C9-B5562C549A50} O42 - Logiciel: Narrative Uploader Software - (.Narrative.) [HKLM][64Bits] -- {32b3f463-1d8f-4672-aa33-dca52ec0ad83} {00C8E7A3CDD263EB1DEB513CE1AE392B07} O42 - Logiciel: Network Recording Player - (.Cisco WebEx LLC.) [HKLM][64Bits] -- {CC5BDE4C-A0D2-4DE0-ACB9-1D5CB019C9CF} =>.Cisco WebEx LLC O42 - Logiciel: Node.js - (.Node.js Foundation.) [HKLM][64Bits] -- {401959C6-C385-4BAF-9565-FF2B75B45D8C} O42 - Logiciel: NVIDIA Control Panel 361.91 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel =>.NVIDIA Corporation O42 - Logiciel: NVIDIA GeForce Experience 2.9.1.22 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience =>.NVIDIA Corporation O42 - Logiciel: NVIDIA GeForce Experience Service - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GfExperienceService =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Graphics Driver 361.91 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Install Application - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer =>.NVIDIA Corporation O42 - Logiciel: NVIDIA LED Visualizer 1.0 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Network Service - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Optimus Update 2.9.1.22 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus =>.NVIDIA Corporation O42 - Logiciel: NVIDIA PhysX System Software 9.15.0428 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX =>.NVIDIA Corporation O42 - Logiciel: NVIDIA ShadowPlay 2.9.1.22 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Update 2.9.1.22 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Update Core - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Virtual Audio 1.2.34 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver =>.NVIDIA Corporation O42 - Logiciel: Office 15 Click-to-Run Extensibility Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008C-0000-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Office 15 Click-to-Run Licensing Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008F-0000-1000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Office 15 Click-to-Run Localization Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008C-0409-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: OpenOffice 4.1.1 - (.Apache Software Foundation.) [HKLM][64Bits] -- {9395F41D-0F80-432E-9A59-B8E477E7E163} =>.Apache Software Foundation O42 - Logiciel: PeaZip 5.0.1 (WIN64) - (.Giorgio Tani.) [HKLM][64Bits] -- {5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1 =>.Giorgio Tani O42 - Logiciel: PeaZip configuration (WIN64) - (.Giorgio Tani.) [HKLM][64Bits] -- {4F8D60A8-C53D-47BD-AE5C-31AE6566D638}_is1 =>.Giorgio Tani O42 - Logiciel: Qualcomm Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Dr - (.Qualcomm Atheros Communications Inc..) [HKLM][64Bits] -- {3108C217-BE83-42E4-AE9E-A56A2A92E549} =>.Qualcomm Atheros Communications Inc. O42 - Logiciel: Realtek PCIE Card Reader - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {0D61A55C-3ADC-409F-BF5B-A1766D1F5944} =>.Realtek Semiconductor Corp® O42 - Logiciel: Recuva - (.Piriform.) [HKLM][64Bits] -- Recuva =>.Piriform Ltd® O42 - Logiciel: Shared C Run-time for x64 - (.McAfee.) [HKLM][64Bits] -- {EF79C448-6946-4D71-8134-03407888C054} =>.McAfee O42 - Logiciel: SHIELD Streaming - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv =>.NVIDIA Corporation O42 - Logiciel: SHIELD Wireless Controller Driver - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController =>.NVIDIA Corporation O42 - Logiciel: Skype™ 7.18 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {FC965A47-4839-40CA-B618-18F486F042C6} =>.Skype Technologies S.A. O42 - Logiciel: Spotify - (.Spotify AB.) [HKLM][64Bits] -- Spotify =>.Spotify AB® O42 - Logiciel: Spyder4Pro - (...) [HKLM][64Bits] -- Spyder4Pro O42 - Logiciel: Sublime Text 2.0.2 - (...) [HKLM][64Bits] -- Sublime Text 2_is1 O42 - Logiciel: Subtitle Edit 3.3.9 - (.Nikse.) [HKLM][64Bits] -- SubtitleEdit_is1 =>.Nikse O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey =>.Synaptics Incorporated O42 - Logiciel: tools-freebsd - (.VMware, Inc..) [HKLM][64Bits] -- {003BFBBD-6C67-419E-A24D-0DCAFC3A5249} =>.VMware, Inc. O42 - Logiciel: tools-linux - (.VMware, Inc..) [HKLM][64Bits] -- {D102611A-6466-4101-A51D-51069303AC65} =>.VMware, Inc. O42 - Logiciel: tools-netware - (.VMware, Inc..) [HKLM][64Bits] -- {197597A7-AD33-4898-9D8E-73066818B464} =>.VMware, Inc. O42 - Logiciel: tools-solaris - (.VMware, Inc..) [HKLM][64Bits] -- {AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4} =>.VMware, Inc. O42 - Logiciel: tools-windows - (.VMware, Inc..) [HKLM][64Bits] -- {FFD9383C-01D5-4897-A954-43AF599AED30} =>.VMware, Inc. O42 - Logiciel: tools-winPre2k - (.VMware, Inc..) [HKLM][64Bits] -- {AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D} =>.VMware, Inc. O42 - Logiciel: Topaz ReMask 4 - (.Topaz Labs, LLC.) [HKLM][64Bits] -- Topaz ReMask 4 =>.Topaz Labs, LLC O42 - Logiciel: TOSHIBA Blu-ray Disc Player - (.Toshiba Corporation.) [HKLM][64Bits] -- {FF07604E-C860-40E9-A230-E37FA41F103A} =>.Toshiba Corporation O42 - Logiciel: TOSHIBA Desktop Assist - (.Toshiba Corporation.) [HKLM][64Bits] -- {95CCACF0-010D-45F0-82BF-858643D8BC02} =>.Toshiba Corporation O42 - Logiciel: TOSHIBA Display Utility - (.Toshiba Corporation.) [HKLM][64Bits] -- {4BBF3F6A-D3B6-48E3-85E1-5C38D3A98034} =>.Toshiba Corporation O42 - Logiciel: TOSHIBA eco Utility - (.Toshiba Corporation.) [HKLM][64Bits] -- {5944B9D4-3C2A-48DE-931E-26B31714A2F7} =>.Toshiba Corporation O42 - Logiciel: TOSHIBA Function Key - (.Toshiba Corporation.) [HKLM][64Bits] -- {16562A90-71BC-41A0-B890-D91B0C267120} =>.Toshiba Corporation O42 - Logiciel: TOSHIBA HDD Protection - (.Toshiba Corporation.) [HKLM][64Bits] -- {94A90C69-71C1-470A-88F5-AA47ECC96B40} =>.Toshiba Corporation O42 - Logiciel: TOSHIBA Manuals - (.TOSHIBA.) [HKLM][64Bits] -- {90FF4432-21B7-4AF6-BA6E-FB8C1FED9173} =>.TOSHIBA CORPORATION® O42 - Logiciel: TOSHIBA Password Utility - (.Toshiba Corporation.) [HKLM][64Bits] -- {26BB68BB-CF93-4A12-BC6D-A3B6F53AC8D9} =>.Toshiba Corporation O42 - Logiciel: TOSHIBA Password Utility - (.Toshiba Corporation.) [HKLM][64Bits] -- InstallShield_{26BB68BB-CF93-4A12-BC6D-A3B6F53AC8D9} =>.Toshiba Corporation O42 - Logiciel: TOSHIBA PC Health Monitor - (.Toshiba Corporation.) [HKLM][64Bits] -- {9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4} =>.Toshiba Corporation O42 - Logiciel: TOSHIBA Recovery Media Creator - (.Toshiba Corporation.) [HKLM][64Bits] -- {B65BBB06-1F8E-48F5-8A54-B024A9E15FDF} =>.TOSHIBA CORPORATION® O42 - Logiciel: TOSHIBA Resolution+ Plug-in for Windows Media Player - (.Toshiba Corporation.) [HKLM][64Bits] -- {6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94} =>.Toshiba Corporation O42 - Logiciel: TOSHIBA Service Station - (.Toshiba Corporation.) [HKLM][64Bits] -- {F0F79CFB-A65C-4B7B-A1FB-38F7D1DB7D9A} =>.Toshiba Corporation O42 - Logiciel: TOSHIBA System Driver - (.Toshiba Corporation.) [HKLM][64Bits] -- {1E6A96A1-2BAB-43EF-8087-30437593C66C} =>.Toshiba Corporation O42 - Logiciel: TOSHIBA System Settings - (.Toshiba Corporation.) [HKLM][64Bits] -- {05A55927-DB9B-4E26-BA44-828EBFF829F0} =>.Toshiba Corporation O42 - Logiciel: Toshiba TEMPRO - (.Toshiba Europe GmbH.) [HKLM][64Bits] -- {E4C7D9D7-19D4-4623-AF0C-EA313C466411} =>.Toshiba Europe GmbH O42 - Logiciel: Transmission Remote GUI 5.0.1 - (.Yury Sidorov.) [HKLM][64Bits] -- transgui_is1 =>.Yury Sidorov O42 - Logiciel: VASCO Card Reader Plug-In (64-Bit) - (.VASCO Data Security.) [HKLM][64Bits] -- {47659F12-27AE-6400-9B8A-2BD803020304} =>.VASCO Data Security O42 - Logiciel: VASCO Smart Card Reader Plug-In (User) - (.VASCO Data Security.) [HKCU][64Bits] -- {c77cb28d-ddd3-46f7-b51a-14a599127ba7} =>.Vasco Data Security International GmbH® O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN O42 - Logiciel: VMware vSphere Client 5.1 - (.VMware, Inc..) [HKLM][64Bits] -- {09DC364B-A77A-49A0-972B-E43F0DACC5E3} =>.VMware, Inc. O42 - Logiciel: VMware vSphere Client 5.5 - (.VMware, Inc..) [HKLM][64Bits] -- {4CFB0494-2E96-4631-8364-538E2AA91324} =>.VMware, Inc. O42 - Logiciel: VMware Workstation - (.VMware, Inc.) [HKLM][64Bits] -- VMware_Workstation =>.VMware, Inc O42 - Logiciel: VMware Workstation - (.VMware, Inc..) [HKLM][64Bits] -- {0D94F75A-0EA6-4951-B3AF-B145FA9E05C6} =>.VMware, Inc. O42 - Logiciel: Wacom Tablet - (.Wacom Technology Corp..) [HKLM][64Bits] -- Wacom Tablet Driver =>.Wacom Technology Corp.® O42 - Logiciel: WebTablet FB Plugin 32 bit - (.Wacom Technology Corp..) [HKLM][64Bits] -- Wacom WebTabletPlugin for Internet Explorer and Netscape =>.Wacom Technology Corp. O42 - Logiciel: WebTablet FB Plugin 64 bit - (.Wacom Technology Corp..) [HKLM][64Bits] -- Wacom WebTabletPlugin for Internet Explorer and Netscape =>.Wacom Technology Corp. O42 - Logiciel: Windows Driver Package - Fedict SmartCard (03/25/2014 4.0.7.4) - (.Fedict.) [HKLM][64Bits] -- B02255EDA75F867B4D85C5A5D23E13D9EF71E8AE =>.Microsoft Windows® O42 - Logiciel: Windows Driver Package - Narrative (WinUSB) WinUSB devices (10/30/2013 1.0 - (.Narrative.) [HKLM][64Bits] -- 7AF547DF92C3050F6825B4FA179F9C5D6F863343 =>.Microsoft Windows® O42 - Logiciel: WinMerge 2.14.0 - (.Thingamahoochie Software.) [HKLM][64Bits] -- WinMerge_is1 =>.Thingamahoochie Software O42 - Logiciel: XMedia Recode version 3.2.9.0 - (.XMedia Recode.) [HKLM][64Bits] -- {DDA3C325-47B2-4730-9672-BF3771C08799}_is1 ---\\ HKCU & HKLM Software Keys (121) - 10s HKLM\SOFTWARE\Wow6432Node\Adobe HKLM\SOFTWARE\Wow6432Node\AGEIA Technologies HKLM\SOFTWARE\Wow6432Node\BEID HKLM\SOFTWARE\Wow6432Node\Canon HKLM\SOFTWARE\Wow6432Node\Citrix HKLM\SOFTWARE\Wow6432Node\DivXNetworks HKLM\SOFTWARE\Wow6432Node\DTS HKLM\SOFTWARE\Wow6432Node\DTS, Inc. HKLM\SOFTWARE\Wow6432Node\FFmpeg for Audacity HKLM\SOFTWARE\Wow6432Node\FileZilla 3 HKLM\SOFTWARE\Wow6432Node\FileZilla Client HKLM\SOFTWARE\Wow6432Node\Google HKLM\SOFTWARE\Wow6432Node\IM Providers HKLM\SOFTWARE\Wow6432Node\InstallShield HKLM\SOFTWARE\Wow6432Node\Intel HKLM\SOFTWARE\Wow6432Node\JavaSoft HKLM\SOFTWARE\Wow6432Node\JreMetrics HKLM\SOFTWARE\Wow6432Node\Khronos HKLM\SOFTWARE\Wow6432Node\Macromedia HKLM\SOFTWARE\Wow6432Node\McAfee HKLM\SOFTWARE\Wow6432Node\McAfee.com HKLM\SOFTWARE\Wow6432Node\McAfeeInstaller HKLM\SOFTWARE\Wow6432Node\mcafeeupdater HKLM\SOFTWARE\Wow6432Node\Mozilla HKLM\SOFTWARE\Wow6432Node\mozilla.org HKLM\SOFTWARE\Wow6432Node\MozillaPlugins HKLM\SOFTWARE\Wow6432Node\mRemoteNG HKLM\SOFTWARE\Wow6432Node\MyHeritage.com HKLM\SOFTWARE\Wow6432Node\NCH Software HKLM\SOFTWARE\Wow6432Node\NCH Swift Sound HKLM\SOFTWARE\Wow6432Node\Network Associates HKLM\SOFTWARE\Wow6432Node\NVIDIA Corporation HKLM\SOFTWARE\Wow6432Node\ODBC HKLM\SOFTWARE\Wow6432Node\OldTimer Tools HKLM\SOFTWARE\Wow6432Node\OpenOffice HKLM\SOFTWARE\Wow6432Node\Qualcomm Atheros Communications Inc. HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp. HKLM\SOFTWARE\Wow6432Node\SiteAdvisor HKLM\SOFTWARE\Wow6432Node\Skype HKLM\SOFTWARE\Wow6432Node\sMedio HKLM\SOFTWARE\Wow6432Node\SRS Labs HKLM\SOFTWARE\Wow6432Node\TeamViewer HKLM\SOFTWARE\Wow6432Node\TechSmith HKLM\SOFTWARE\Wow6432Node\Thingamahoochie HKLM\SOFTWARE\Wow6432Node\ThinPrint HKLM\SOFTWARE\Wow6432Node\Topaz Labs HKLM\SOFTWARE\Wow6432Node\TOSHIBA HKLM\SOFTWARE\Wow6432Node\Toshiba Corporation HKLM\SOFTWARE\Wow6432Node\VideoLAN HKLM\SOFTWARE\Wow6432Node\VMware, Inc. HKLM\SOFTWARE\Wow6432Node\Volatile HKLM\SOFTWARE\Wow6432Node\Wacom HKLM\SOFTWARE\Wow6432Node\WebEx HKLM\SOFTWARE\Wow6432Node\WildTangent HKLM\SOFTWARE\Wow6432Node\RegisteredApplications HKCU\SOFTWARE\9bis.com HKCU\SOFTWARE\Adobe HKCU\SOFTWARE\Adobe Lightroom HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\AppleWin HKCU\SOFTWARE\Audacity HKCU\SOFTWARE\BEID HKCU\SOFTWARE\calibre HKCU\SOFTWARE\Canon HKCU\SOFTWARE\Citrix HKCU\SOFTWARE\Conexant HKCU\SOFTWARE\Digimarc HKCU\SOFTWARE\DVDFab HKCU\SOFTWARE\Google HKCU\SOFTWARE\IM Providers HKCU\SOFTWARE\Intel HKCU\SOFTWARE\JavaSoft HKCU\SOFTWARE\Kolor HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\MainConcept HKCU\SOFTWARE\MCAFEE HKCU\SOFTWARE\Mine HKCU\SOFTWARE\mkvmergeGUI HKCU\SOFTWARE\Mozilla HKCU\SOFTWARE\MozillaPlugins HKCU\SOFTWARE\MyHeritage.com HKCU\SOFTWARE\Narrative HKCU\SOFTWARE\NCH Software HKCU\SOFTWARE\NCH Swift Sound HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\Node.js HKCU\SOFTWARE\NVIDIA Corporation HKCU\SOFTWARE\ODBC HKCU\SOFTWARE\OpenOffice HKCU\SOFTWARE\PaniniPerspective HKCU\SOFTWARE\Piriform HKCU\SOFTWARE\QtProject HKCU\SOFTWARE\RegisteredApplications HKCU\SOFTWARE\SimonTatham HKCU\SOFTWARE\Skype HKCU\SOFTWARE\SubSystems HKCU\SOFTWARE\SupRip HKCU\SOFTWARE\Synaptics HKCU\SOFTWARE\Sysinternals HKCU\SOFTWARE\TeamViewer HKCU\SOFTWARE\TechSmith HKCU\SOFTWARE\The Complete Genealogy Reporter HKCU\SOFTWARE\Thingamahoochie HKCU\SOFTWARE\Thunderbird HKCU\SOFTWARE\TopazLabs HKCU\SOFTWARE\Toshiba HKCU\SOFTWARE\TransmissionRemote HKCU\SOFTWARE\Trolltech HKCU\SOFTWARE\VASCO HKCU\SOFTWARE\Viber HKCU\SOFTWARE\VideoLAN HKCU\SOFTWARE\VidSoft HKCU\SOFTWARE\VMware HKCU\SOFTWARE\VMware, Inc. HKCU\SOFTWARE\WebEx HKCU\SOFTWARE\Wow6432Node HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Software HKCU\SOFTWARE\AppDataLow\Software\Adobe HKCU\SOFTWARE\AppDataLow\Software\JavaSoft HKCU\SOFTWARE\AppDataLow\Software\ThinPrint ---\\ Contents of the Common Files folders (265) - 10s O43 - CFD: 13/02/2016 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Systems Incorporated® O43 - CFD: 08/03/2014 - [] D -- C:\Program Files (x86)\Audacity O43 - CFD: 31/07/2014 - [] D -- C:\Program Files (x86)\Belgium Identity Card O43 - CFD: 31/07/2015 - [] D -- C:\Program Files (x86)\Canon =>.Canon Inc.® O43 - CFD: 15/08/2014 - [] D -- C:\Program Files (x86)\Cisco O43 - CFD: 01/08/2013 - [] D -- C:\Program Files (x86)\Citrix {5C5F2BA5C9994BE5EF254FFE511288E1} O43 - CFD: 18/12/2015 - [] D -- C:\Program Files (x86)\Common Files O43 - CFD: 03/07/2014 - [] D -- C:\Program Files (x86)\Datacolor O43 - CFD: 13/11/2014 - [] D -- C:\Program Files (x86)\directx O43 - CFD: 30/12/2013 - [] D -- C:\Program Files (x86)\DTS, Inc =>.DTS, Inc.® O43 - CFD: 03/03/2014 - [] D -- C:\Program Files (x86)\DVDFab 9 =>.Fengtao Software Inc.® O43 - CFD: 05/05/2013 - [] D -- C:\Program Files (x86)\eBay O43 - CFD: 08/03/2014 - [] D -- C:\Program Files (x86)\Ffmpeg For Audacity O43 - CFD: 01/03/2016 - [] D -- C:\Program Files (x86)\FileZilla FTP Client =>.Tim Kosse® O43 - CFD: 17/05/2015 - [] D -- C:\Program Files (x86)\Google =>.Google Inc® O43 - CFD: 19/04/2015 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.TOSHIBA CORPORATION® O43 - CFD: 15/08/2014 - [] D -- C:\Program Files (x86)\Intel O43 - CFD: 10/03/2016 - [] D -- C:\Program Files (x86)\Internet Explorer O43 - CFD: 12/01/2015 - [] D -- C:\Program Files (x86)\Java =>.Oracle America, Inc.® O43 - CFD: 27/10/2014 - [] D -- C:\Program Files (x86)\Kolor {04E6993F8B7C7F94E04A7E01DCBB1E6B} O43 - CFD: 10/03/2016 - [] D -- C:\Program Files (x86)\McAfee =>.McAfee, Inc.® O43 - CFD: 26/08/2013 - [] D -- C:\Program Files (x86)\McAfee.com =>.McAfee, Inc.® O43 - CFD: 17/10/2014 - [] D -- C:\Program Files (x86)\Microsoft ASP.NET O43 - CFD: 04/12/2015 - [] D -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation® O43 - CFD: 17/01/2016 - [] D -- C:\Program Files (x86)\Microsoft Silverlight =>.Microsoft Corporation® O43 - CFD: 08/08/2015 - [] D -- C:\Program Files (x86)\Microsoft.NET O43 - CFD: 19/11/2014 - [] D -- C:\Program Files (x86)\MKVToolNix O43 - CFD: 10/03/2016 - [] D -- C:\Program Files (x86)\Mozilla Firefox =>.Mozilla Corporation® O43 - CFD: 10/03/2016 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service =>.Mozilla Corporation® O43 - CFD: 23/02/2016 - [] D -- C:\Program Files (x86)\Mozilla Thunderbird =>.Mozilla Corporation® O43 - CFD: 07/12/2013 - [] D -- C:\Program Files (x86)\mRemoteNG O43 - CFD: 25/12/2013 - [] D -- C:\Program Files (x86)\MSBuild O43 - CFD: 27/06/2015 - [] D -- C:\Program Files (x86)\MyHeritage =>.MyHeritage Ltd.® O43 - CFD: 10/03/2016 - [] D -- C:\Program Files (x86)\Narrative O43 - CFD: 20/02/2015 - [] D -- C:\Program Files (x86)\NCH Software O43 - CFD: 13/11/2014 - [] D -- C:\Program Files (x86)\NVIDIA Corporation =>.NVIDIA Corporation® O43 - CFD: 23/02/2015 - [] D -- C:\Program Files (x86)\OpenOffice 4 O43 - CFD: 02/07/2015 - [] D -- C:\Program Files (x86)\Panini O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\QuickTime O43 - CFD: 10/06/2013 - [] D -- C:\Program Files (x86)\Realtek =>.Realtek Semiconductor Corp® O43 - CFD: 25/12/2013 - [] D -- C:\Program Files (x86)\Reference Assemblies O43 - CFD: 18/12/2015 - [] RD -- C:\Program Files (x86)\Skype =>.Skype Software Sarl® O43 - CFD: 05/05/2013 - [] D -- C:\Program Files (x86)\Spotify =>.Spotify AB® O43 - CFD: 19/02/2014 - [] D -- C:\Program Files (x86)\Subtitle Edit O43 - CFD: 15/06/2014 - [] D -- C:\Program Files (x86)\TabletPlugins O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\TechSmith =>.TechSmith Corporation® O43 - CFD: 27/07/2014 - [] D -- C:\Program Files (x86)\Topaz Labs O43 - CFD: 19/04/2015 - [] D -- C:\Program Files (x86)\TOSHIBA O43 - CFD: 10/06/2013 - [] D -- C:\Program Files (x86)\TOSHIBA Corporation O43 - CFD: 18/11/2013 - [] D -- C:\Program Files (x86)\TOSHIBA Games =>.WildTangent Inc® O43 - CFD: 13/01/2016 - [] D -- C:\Program Files (x86)\Toshiba TEMPRO =>.Toshiba Europe Gmbh® O43 - CFD: 08/09/2015 - [] D -- C:\Program Files (x86)\Transmission Remote GUI O43 - CFD: 28/07/2013 - [] D -- C:\Program Files (x86)\VideoLAN O43 - CFD: 24/06/2015 - [] D -- C:\Program Files (x86)\VMware =>.VMware, Inc.® O43 - CFD: 13/08/2015 - [] D -- C:\Program Files (x86)\Windows Defender O43 - CFD: 19/11/2014 - [] D -- C:\Program Files (x86)\Windows Mail O43 - CFD: 19/11/2014 - [] D -- C:\Program Files (x86)\Windows Media Player O43 - CFD: 19/11/2014 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Windows NT O43 - CFD: 19/11/2014 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation® O43 - CFD: 19/11/2014 - [] D -- C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 25/12/2013 - [] SHD -- C:\Program Files (x86)\Windows Sidebar O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\WindowsPowerShell O43 - CFD: 25/04/2014 - [] D -- C:\Program Files (x86)\WinMerge O43 - CFD: 16/02/2016 - [] D -- C:\Program Files (x86)\XMedia Recode O43 - CFD: 19/11/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 11/03/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 19/11/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 31/07/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belgium - eID O43 - CFD: 16/01/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management O43 - CFD: 31/07/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon IJ Network Utilities O43 - CFD: 31/07/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG6100 series O43 - CFD: 31/07/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities O43 - CFD: 03/07/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Datacolor O43 - CFD: 30/12/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DTS, Inc O43 - CFD: 03/03/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 9 O43 - CFD: 01/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client O43 - CFD: 25/12/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 07/02/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth O43 - CFD: 27/09/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel O43 - CFD: 25/12/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel AppUp(R) center O43 - CFD: 25/12/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Corporation O43 - CFD: 15/08/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless O43 - CFD: 16/10/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java O43 - CFD: 22/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kolor Autopano Giga 4.2 O43 - CFD: 22/08/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 21/01/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee O43 - CFD: 18/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus O43 - CFD: 08/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 O43 - CFD: 17/01/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight O43 - CFD: 19/11/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix O43 - CFD: 25/12/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mRemoteNG O43 - CFD: 10/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Narrative O43 - CFD: 19/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Node.js O43 - CFD: 30/12/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation O43 - CFD: 23/02/2015 - [] SD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1 O43 - CFD: 25/12/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeaZip O43 - CFD: 17/05/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3 O43 - CFD: 25/12/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva O43 - CFD: 18/12/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype O43 - CFD: 18/02/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp O43 - CFD: 19/02/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Subtitle Edit O43 - CFD: 19/11/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 14/11/2013 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 10/07/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith O43 - CFD: 25/12/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TOSHIBA O43 - CFD: 08/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Transmission Remote GUI O43 - CFD: 25/12/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN O43 - CFD: 30/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware O43 - CFD: 15/06/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Tablet O43 - CFD: 08/05/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebEx O43 - CFD: 16/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XMedia Recode O43 - CFD: 01/11/2015 - [] D -- C:\ProgramData\Adobe O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 16/11/2015 - [] D -- C:\ProgramData\boost_interprocess O43 - CFD: 31/07/2015 - [0] D -- C:\ProgramData\Canon IJ Network Tool O43 - CFD: 31/07/2015 - [] HD -- C:\ProgramData\CanonBJ O43 - CFD: 25/12/2013 - [] D -- C:\ProgramData\Conexant O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 27/09/2014 - [] D -- C:\ProgramData\Intel O43 - CFD: 12/02/2016 - [] D -- C:\ProgramData\Intel Security O43 - CFD: 10/06/2013 - [] D -- C:\ProgramData\Intel(R) Update Manager O43 - CFD: 01/08/2013 - [] D -- C:\ProgramData\IsolatedStorage O43 - CFD: 12/02/2016 - [] D -- C:\ProgramData\Malwarebytes O43 - CFD: 08/02/2016 - [] D -- C:\ProgramData\McAfee O43 - CFD: 07/08/2015 - [] D -- C:\ProgramData\McAfee Security Scan O43 - CFD: 08/08/2015 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 08/08/2015 - [] D -- C:\ProgramData\Microsoft OneDrive O43 - CFD: 27/07/2013 - [] D -- C:\ProgramData\Mozilla O43 - CFD: 27/06/2015 - [] D -- C:\ProgramData\MyHeritage O43 - CFD: 12/02/2015 - [] D -- C:\ProgramData\NCH Software O43 - CFD: 15/02/2016 - [] D -- C:\ProgramData\NVIDIA O43 - CFD: 26/12/2015 - [] D -- C:\ProgramData\NVIDIA Corporation O43 - CFD: 17/10/2014 - [] D -- C:\ProgramData\Oracle O43 - CFD: 10/03/2016 - [] D -- C:\ProgramData\Package Cache O43 - CFD: 25/12/2013 - [] D -- C:\ProgramData\PRICache O43 - CFD: 01/02/2016 - [] D -- C:\ProgramData\regid.1986-12.com.adobe O43 - CFD: 23/02/2016 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft O43 - CFD: 10/07/2015 - [] D -- C:\ProgramData\regid.1995-08.com.techsmith O43 - CFD: 10/06/2013 - [] D -- C:\ProgramData\Roaming O43 - CFD: 17/02/2016 - [] D -- C:\ProgramData\Skype O43 - CFD: 30/12/2013 - [] D -- C:\ProgramData\SRS Labs O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 22/08/2013 - [] D -- C:\ProgramData\Sun O43 - CFD: 31/07/2013 - [] D -- C:\ProgramData\Synaptics O43 - CFD: 10/07/2015 - [] D -- C:\ProgramData\TechSmith O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 27/07/2013 - [] D -- C:\ProgramData\Toshiba O43 - CFD: 01/08/2013 - [] D -- C:\ProgramData\TOSHIBA Tempro O43 - CFD: 27/07/2013 - [] D -- C:\ProgramData\ToshibaEurope O43 - CFD: 10/03/2016 - [] D -- C:\ProgramData\VMware O43 - CFD: 26/04/2014 - [] D -- C:\ProgramData\vsosdk O43 - CFD: 08/05/2014 - [] D -- C:\ProgramData\WebEx O43 - CFD: 18/11/2013 - [] D -- C:\ProgramData\WildTangent O43 - CFD: 13/02/2016 - [] D -- C:\Program Files (x86)\Common Files\Adobe O43 - CFD: 08/08/2015 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER O43 - CFD: 13/11/2014 - [] D -- C:\Program Files (x86)\Common Files\InstallShield O43 - CFD: 25/12/2013 - [] D -- C:\Program Files (x86)\Common Files\Intel O43 - CFD: 17/10/2014 - [] D -- C:\Program Files (x86)\Common Files\Java O43 - CFD: 26/08/2013 - [] D -- C:\Program Files (x86)\Common Files\mcafee O43 - CFD: 08/08/2015 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared O43 - CFD: 10/06/2013 - [] D -- C:\Program Files (x86)\Common Files\postureAgent O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Common Files\Services O43 - CFD: 18/12/2015 - [] D -- C:\Program Files (x86)\Common Files\Skype O43 - CFD: 19/11/2014 - [] D -- C:\Program Files (x86)\Common Files\System O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Common Files\TechSmith Shared O43 - CFD: 27/07/2014 - [] D -- C:\Program Files (x86)\Common Files\Topaz Labs O43 - CFD: 19/04/2015 - [] D -- C:\Program Files (x86)\Common Files\Toshiba Shared O43 - CFD: 30/11/2015 - [] D -- C:\Program Files (x86)\Common Files\VMware O43 - CFD: 22/02/2016 - [0] D -- C:\Users\Admin\AppData\Roaming\6967 O43 - CFD: 10/02/2016 - [] D -- C:\Users\Admin\AppData\Roaming\Adobe O43 - CFD: 08/03/2014 - [] D -- C:\Users\Admin\AppData\Roaming\Audacity O43 - CFD: 30/08/2014 - [] D -- C:\Users\Admin\AppData\Roaming\calibre O43 - CFD: 04/03/2014 - [] D -- C:\Users\Admin\AppData\Roaming\dvdcss O43 - CFD: 03/03/2014 - [] D -- C:\Users\Admin\AppData\Roaming\DVDFab9 O43 - CFD: 01/03/2016 - [] D -- C:\Users\Admin\AppData\Roaming\FileZilla O43 - CFD: 25/12/2013 - [] D -- C:\Users\Admin\AppData\Roaming\Identities O43 - CFD: 27/07/2013 - [] D -- C:\Users\Admin\AppData\Roaming\Intel O43 - CFD: 10/08/2013 - [] D -- C:\Users\Admin\AppData\Roaming\KiTTY O43 - CFD: 10/03/2016 - [] D -- C:\Users\Admin\AppData\Roaming\Logx O43 - CFD: 27/07/2013 - [] D -- C:\Users\Admin\AppData\Roaming\Macromedia O43 - CFD: 08/08/2015 - [] SD -- C:\Users\Admin\AppData\Roaming\Microsoft O43 - CFD: 28/07/2013 - [] D -- C:\Users\Admin\AppData\Roaming\mkvtoolnix O43 - CFD: 30/04/2014 - [] D -- C:\Users\Admin\AppData\Roaming\Mozilla O43 - CFD: 07/03/2016 - [] D -- C:\Users\Admin\AppData\Roaming\mRemoteNG O43 - CFD: 27/06/2015 - [] D -- C:\Users\Admin\AppData\Roaming\MyHeritage O43 - CFD: 20/02/2015 - [] D -- C:\Users\Admin\AppData\Roaming\NCH Software O43 - CFD: 20/05/2015 - [] D -- C:\Users\Admin\AppData\Roaming\npm O43 - CFD: 20/10/2015 - [] D -- C:\Users\Admin\AppData\Roaming\npm-cache O43 - CFD: 29/01/2014 - [] D -- C:\Users\Admin\AppData\Roaming\NVIDIA O43 - CFD: 28/03/2014 - [] D -- C:\Users\Admin\AppData\Roaming\OpenOffice O43 - CFD: 16/07/2014 - [] D -- C:\Users\Admin\AppData\Roaming\Oracle O43 - CFD: 29/01/2014 - [] D -- C:\Users\Admin\AppData\Roaming\PDAppFlex O43 - CFD: 15/07/2014 - [] D -- C:\Users\Admin\AppData\Roaming\PeaZip O43 - CFD: 10/03/2016 - [] D -- C:\Users\Admin\AppData\Roaming\Skype O43 - CFD: 27/07/2013 - [] D -- C:\Users\Admin\AppData\Roaming\sMedio O43 - CFD: 27/07/2013 - [] D -- C:\Users\Admin\AppData\Roaming\Sublime Text 2 O43 - CFD: 19/02/2014 - [] D -- C:\Users\Admin\AppData\Roaming\Subtitle Edit O43 - CFD: 05/08/2013 - [] D -- C:\Users\Admin\AppData\Roaming\SupRip O43 - CFD: 01/04/2015 - [] D -- C:\Users\Admin\AppData\Roaming\TeamViewer O43 - CFD: 10/07/2015 - [] D -- C:\Users\Admin\AppData\Roaming\TechSmith O43 - CFD: 27/06/2015 - [0] D -- C:\Users\Admin\AppData\Roaming\The Complete Genealogy Reporter - FTB O43 - CFD: 12/08/2013 - [] D -- C:\Users\Admin\AppData\Roaming\Thunderbird O43 - CFD: 05/12/2015 - [] D -- C:\Users\Admin\AppData\Roaming\U3 O43 - CFD: 09/01/2015 - [] D -- C:\Users\Admin\AppData\Roaming\VASCO O43 - CFD: 04/03/2016 - [] D -- C:\Users\Admin\AppData\Roaming\vlc O43 - CFD: 08/03/2016 - [] D -- C:\Users\Admin\AppData\Roaming\VMware O43 - CFD: 06/05/2014 - [0] D -- C:\Users\Admin\AppData\Roaming\webex O43 - CFD: 01/08/2013 - [] D -- C:\Users\Admin\AppData\Roaming\WildTangent O43 - CFD: 30/12/2013 - [] D -- C:\Users\Admin\AppData\Roaming\WinBatch O43 - CFD: 15/06/2014 - [] D -- C:\Users\Admin\AppData\Roaming\WTablet O43 - CFD: 02/04/2014 - [] D -- C:\Users\Admin\AppData\Roaming\XMedia Recode O43 - CFD: 10/03/2016 - [] D -- C:\Users\Admin\AppData\Roaming\ZHP O43 - CFD: 10/03/2016 - [] D -- C:\Users\Admin\AppData\Local\Adobe O43 - CFD: 25/12/2013 - [0] SHD -- C:\Users\Admin\AppData\Local\Application Data O43 - CFD: 31/08/2014 - [] D -- C:\Users\Admin\AppData\Local\calibre-cache O43 - CFD: 14/07/2015 - [] D -- C:\Users\Admin\AppData\Local\CEF O43 - CFD: 07/05/2015 - [] D -- C:\Users\Admin\AppData\Local\Citrix O43 - CFD: 06/03/2016 - [] D -- C:\Users\Admin\AppData\Local\CrashDumps O43 - CFD: 03/07/2014 - [] D -- C:\Users\Admin\AppData\Local\Datacolor O43 - CFD: 09/02/2016 - [0] D -- C:\Users\Admin\AppData\Local\Diagnostics O43 - CFD: 25/02/2016 - [] D -- C:\Users\Admin\AppData\Local\Downloaded Installations O43 - CFD: 21/10/2015 - [0] D -- C:\Users\Admin\AppData\Local\ElevatedDiagnostics O43 - CFD: 07/07/2015 - [0] SHD -- C:\Users\Admin\AppData\Local\EmieBrowserModeList O43 - CFD: 07/07/2015 - [0] SHD -- C:\Users\Admin\AppData\Local\EmieSiteList O43 - CFD: 07/07/2015 - [0] SHD -- C:\Users\Admin\AppData\Local\EmieUserList O43 - CFD: 17/09/2015 - [] D -- C:\Users\Admin\AppData\Local\Google O43 - CFD: 03/06/2015 - [] D -- C:\Users\Admin\AppData\Local\GWX O43 - CFD: 25/12/2013 - [0] SHD -- C:\Users\Admin\AppData\Local\History O43 - CFD: 16/02/2014 - [] D -- C:\Users\Admin\AppData\Local\Intel_Corporation O43 - CFD: 25/01/2016 - [] D -- C:\Users\Admin\AppData\Local\Javaxa O43 - CFD: 29/02/2016 - [] D -- C:\Users\Admin\AppData\Local\Kolor O43 - CFD: 28/07/2013 - [] D -- C:\Users\Admin\AppData\Local\Macromedia O43 - CFD: 08/08/2015 - [] D -- C:\Users\Admin\AppData\Local\Microsoft O43 - CFD: 28/07/2013 - [] D -- C:\Users\Admin\AppData\Local\Microsoft_Corporation O43 - CFD: 01/10/2013 - [] D -- C:\Users\Admin\AppData\Local\Mozilla O43 - CFD: 11/08/2013 - [] D -- C:\Users\Admin\AppData\Local\mRemoteNG O43 - CFD: 10/03/2016 - [] D -- C:\Users\Admin\AppData\Local\Narrative O43 - CFD: 17/01/2016 - [] D -- C:\Users\Admin\AppData\Local\NVIDIA O43 - CFD: 31/07/2014 - [] D -- C:\Users\Admin\AppData\Local\NVIDIA Corporation O43 - CFD: 09/01/2015 - [] D -- C:\Users\Admin\AppData\Local\Package Cache O43 - CFD: 31/07/2015 - [] D -- C:\Users\Admin\AppData\Local\Packages O43 - CFD: 12/10/2015 - [] D -- C:\Users\Admin\AppData\Local\paginaEpubChecker O43 - CFD: 26/01/2015 - [] D -- C:\Users\Admin\AppData\Local\Programs O43 - CFD: 18/12/2015 - [0] D -- C:\Users\Admin\AppData\Local\Skype O43 - CFD: 10/07/2015 - [] D -- C:\Users\Admin\AppData\Local\TechSmith O43 - CFD: 10/03/2016 - [] D -- C:\Users\Admin\AppData\Local\Temp O43 - CFD: 25/12/2013 - [0] SHD -- C:\Users\Admin\AppData\Local\Temporary Internet Files O43 - CFD: 15/11/2014 - [] D -- C:\Users\Admin\AppData\Local\Thunderbird O43 - CFD: 02/08/2013 - [] D -- C:\Users\Admin\AppData\Local\Toshiba O43 - CFD: 14/02/2016 - [] D -- C:\Users\Admin\AppData\Local\Transmission Remote GUI O43 - CFD: 30/11/2015 - [] D -- C:\Users\Admin\AppData\Local\VirtualStore O43 - CFD: 08/03/2016 - [] D -- C:\Users\Admin\AppData\Local\VMware O43 - CFD: 22/08/2013 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 22/08/2013 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 11/02/2016 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 24/06/2015 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kolor Autopano Giga 4.0 O43 - CFD: 11/05/2015 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kolor Panotour Pro 2.3 O43 - CFD: 15/02/2016 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kolor Panotour Pro 2.5 O43 - CFD: 27/10/2014 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kolor Panotour Viewer 1.0 O43 - CFD: 22/08/2013 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 27/06/2015 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyHeritage.com O43 - CFD: 11/02/2016 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 25/12/2013 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools ---\\ System Drivers List (83) - 6s O58 - SDL:2013/08/22 13:43:41 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [108896] =>.Microsoft Windows® O58 - SDL:2014/08/21 01:51:38 A . (.Advanced Card Systems Ltd. - PCSC/CCID IFD Handler.) -- C:\WINDOWS\System32\drivers\a38ccid.sys [62848] =>.Advanced Card Systems Ltd. O58 - SDL:2013/08/22 13:43:41 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [782176] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:41 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [79200] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:41 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259424] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:40 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [25952] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:41 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [114016] =>.Microsoft Windows® O58 - SDL:2013/08/13 00:25:46 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [17624] =>.Broadcom Corporation® O58 - SDL:2013/08/22 13:43:41 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [531296] =>.Microsoft Windows® O58 - SDL:2015/11/25 07:29:36 A . (.McAfee, Inc. - McAfee Personal Firewall IDS Plugin.) -- C:\WINDOWS\System32\drivers\cfwids.sys [79248] =>.McAfee, Inc.® O58 - SDL:2013/07/18 16:16:38 A . (.Conexant Systems Inc. - 64-bit High Definition Audio Function Drive.) -- C:\WINDOWS\System32\drivers\CHDRT64.sys [1387712] =>.Conexant Systems, Inc.® O58 - SDL:2011/06/02 14:56:52 A . (.Datacolor - Colorimeter USB Driver 1.0-1.) -- C:\WINDOWS\System32\drivers\dccmtr.sys [15360] O58 - SDL:2013/08/22 13:43:45 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3357024] =>.Microsoft Windows® O58 - SDL:2015/01/07 07:02:54 A . (.VMware, Inc. - VMware USB monitor.) -- C:\WINDOWS\System32\drivers\hcmon.sys [55488] =>.VMware, Inc.® O58 - SDL:2013/02/15 15:17:02 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\HECIx64.sys [64624] =>.Intel Corporation - Intel® Management Engine Firmware® O58 - SDL:2013/04/30 18:18:10 A . (.Windows (R) Win 7 DDK provider - Filter Driver for HID-KMDF Interface.) -- C:\WINDOWS\System32\drivers\hidkmdf.sys [14136] =>.Wacom Technology Corp.® O58 - SDL:2015/05/19 13:59:02 A . (.McAfee, Inc. - McAfee HIP IPS Driver.) -- C:\WINDOWS\System32\drivers\HipShieldK.sys [207208] =>.McAfee, Inc.® O58 - SDL:2013/08/22 13:43:45 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64352] =>.Microsoft Windows® O58 - SDL:2013/07/30 19:47:35 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [24568] =>.Intel Corporation - Software and Firmware Products® O58 - SDL:2013/07/25 20:05:39 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [99320] =>.Intel Corporation - Software and Firmware Products® O58 - SDL:2013/08/30 21:18:02 A . (.Intel Corporation - Intel Rapid Storage Technology driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorA.sys [644968] =>.Intel Corporation - Intel® Rapid Storage Technology® O58 - SDL:2013/08/10 01:39:30 A . (.Intel Corporation - Intel Rapid Storage Technology driver (inbo.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [651248] =>.Intel Corporation - Intel® Rapid Storage Technology® O58 - SDL:2013/08/22 13:43:45 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412000] =>.Microsoft Windows® O58 - SDL:2014/12/31 22:40:52 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\igdkmd64.sys [3775928] =>.Intel Corporation - pGFX® O58 - SDL:2013/04/11 14:32:32 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\WINDOWS\System32\drivers\IntcDAud.sys [442368] =>.Intel(R) Corporation O58 - SDL:2014/11/04 18:58:28 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\intelaud.sys [38296] =>.Intel Wireless Display® O58 - SDL:2014/11/04 18:58:28 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\iwdbus.sys [27032] =>.Intel Wireless Display® O58 - SDL:2013/06/18 15:44:59 A . (.Qualcomm Atheros Co., Ltd. - Qualcomm Atheros Ar81xx series PCI-E Gigabi.) -- C:\WINDOWS\System32\drivers\L1C63x64.sys [129224] =>.Qualcomm Atheros® O58 - SDL:2013/08/22 13:43:44 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [109408] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:45 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2.sys [93536] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:44 A . (.LSI Corporation - LSI SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3.sys [81760] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:45 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82784] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:45 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [56672] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:45 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575840] =>.Microsoft Windows® O58 - SDL:2015/11/25 07:29:36 A . (.McAfee, Inc. - McAfee Arbitrary Access Control Driver.) -- C:\WINDOWS\System32\drivers\mfeaack.sys [419624] =>.McAfee, Inc.® O58 - SDL:2015/11/25 07:29:36 A . (.McAfee, Inc. - Anti-Virus File System Filter Driver.) -- C:\WINDOWS\System32\drivers\mfeavfk.sys [351144] =>.McAfee, Inc.® O58 - SDL:2015/11/20 06:18:34 A . (.McAfee, Inc. - McAfee Driver Cleaning Driver.) -- C:\WINDOWS\System32\drivers\mfeclnrk.sys [20480] =>.McAfee, Inc.® O58 - SDL:2015/11/25 07:29:36 A . (.McAfee, Inc. - McAfee ELAM Driver.) -- C:\WINDOWS\System32\drivers\mfeelamk.sys [83096] =>.Microsoft Windows Early Launch Anti-malware Publisher® O58 - SDL:2015/11/25 07:29:36 A . (.McAfee, Inc. - McAfee Core Firewall Engine Driver.) -- C:\WINDOWS\System32\drivers\mfefirek.sys [496368] =>.McAfee, Inc.® O58 - SDL:2015/11/25 07:29:36 A . (.McAfee, Inc. - McAfee Link Driver.) -- C:\WINDOWS\System32\drivers\mfehidk.sys [846080] =>.McAfee, Inc.® O58 - SDL:2015/11/20 06:18:34 A . (.McAfee, Inc. - Event Driver.) -- C:\WINDOWS\System32\drivers\mfencbdc.sys [539496] =>.McAfee, Inc.® O58 - SDL:2015/11/20 06:18:34 A . (.McAfee, Inc. - Detection driver.) -- C:\WINDOWS\System32\drivers\mfencrk.sys [109480] =>.McAfee, Inc.® O58 - SDL:2015/11/25 07:29:36 A . (.McAfee, Inc. - Anti-Virus Mini-Firewall Driver.) -- C:\WINDOWS\System32\drivers\mfewfpk.sys [245096] =>.McAfee, Inc.® O58 - SDL:2013/08/22 13:43:49 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63840] =>.Microsoft Windows® O58 - SDL:2014/04/17 22:03:44 A . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\WINDOWS\System32\drivers\NETwew00.sys [3349984] =>.Intel Corporation-Mobile Wireless Group® O58 - SDL:2016/02/09 09:39:50 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\WINDOWS\System32\drivers\nvlddmkm.sys [12383288] =>.NVIDIA Corporation® O58 - SDL:2016/02/09 09:39:50 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\WINDOWS\System32\drivers\nvpciflt.sys [38336] =>.NVIDIA Corporation® O58 - SDL:2013/08/22 13:43:31 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150368] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:32 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [168288] =>.Microsoft Windows® O58 - SDL:2015/12/18 07:11:06 A . (.NVIDIA Corporation - NVIDIA Virtual Audio Driver.) -- C:\WINDOWS\System32\drivers\nvvad64v.sys [47760] =>.NVIDIA Corporation® O58 - SDL:2013/08/22 14:32:10 A . (.TOSHIBA - Generic IO & Memory Access.) -- C:\WINDOWS\System32\drivers\QIOMem.sys [14000] =>.TOSHIBA O58 - SDL:2013/07/08 04:32:16 A . (.Realtek Semiconductor Corp. - Realtek Pcie CardReader Driver for 2K/XP/Vi.) -- C:\WINDOWS\System32\drivers\RtsP2Stor.sys [290008] =>.Realtek Semiconductor Corp® O58 - SDL:2013/08/22 16:35:09 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\WINDOWS\System32\drivers\secdrv.sys [23040] =>.Macrovision Corporation, Macrovision Europe Limited, O58 - SDL:2013/08/22 13:43:31 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44896] =>.Microsoft Windows® O58 - SDL:2013/08/22 13:43:32 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81760] =>.Microsoft Windows® O58 - SDL:2013/08/28 05:32:16 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [34544] =>.Synaptics Incorporated® O58 - SDL:2013/08/22 13:43:32 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31072] =>.Microsoft Windows® O58 - SDL:2013/08/28 05:32:28 A . (.Synaptics Incorporated - Synaptics Touchpad 64-bit Driver.) -- C:\WINDOWS\System32\drivers\SynTP.sys [524528] =>.Synaptics Incorporated® O58 - SDL:2012/07/25 00:54:00 A . (.TOSHIBA Corporation. - TOSHIBA ODD Writing Driver for x64..) -- C:\WINDOWS\System32\drivers\tdcmdpst.sys [31184] =>.TOSHIBA CORPORATION® O58 - SDL:2013/08/19 12:32:10 A . (.Windows (R) Win 7 DDK provider - Toshiba Hotkey Driver.) -- C:\WINDOWS\System32\drivers\Thotkey.sys [32624] =>.TOSHIBA CORPORATION® O58 - SDL:2013/02/26 13:43:48 A . (.TOSHIBA Corporation - TOSHIBA HDD Protection Driver.) -- C:\WINDOWS\System32\drivers\thpdrv.sys [48440] =>.TOSHIBA CORPORATION® O58 - SDL:2012/06/25 22:59:58 A . (.TOSHIBA Corporation - TOSHIBA HDD Protection - Shock Sensor Drive.) -- C:\WINDOWS\System32\drivers\Thpevm.sys [18304] =>.TOSHIBA CORPORATION® O58 - SDL:2013/11/01 03:22:28 A . (.TOSHIBA Corporation - TOSHIBA Bluetooth EC Driver.) -- C:\WINDOWS\System32\drivers\tosrfec.sys [27032] =>.TOSHIBA CORPORATION® O58 - SDL:2012/06/18 18:30:56 A . (.TOSHIBA Corporation - tos_sps64.) -- C:\WINDOWS\System32\drivers\tos_sps64.sys [499096] =>.TOSHIBA CORPORATION® O58 - SDL:2012/07/21 23:59:02 A . (.TOSHIBA Corporation - TOSHIBA TVALZ Filter Driver.) -- C:\WINDOWS\System32\drivers\TVALZFL.sys [16768] =>.TOSHIBA CORPORATION® O58 - SDL:2013/08/15 01:13:32 A . (.TOSHIBA Corporation - TOSHIBA ACPI-Based Value Added Logical and.) -- C:\WINDOWS\System32\drivers\TVALZ_O.SYS [32832] =>.TOSHIBA CORPORATION® O58 - SDL:2013/01/29 01:48:14 A . (.Windows (R) Win 7 DDK provider - usb3hub.sys.) -- C:\WINDOWS\System32\drivers\usb3Hub.sys [48024] =>.Intel Wireless Display® O58 - SDL:2013/08/22 13:43:34 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\WINDOWS\System32\drivers\viaide.sys [19808] =>.Microsoft Windows® O58 - SDL:2015/05/21 16:35:56 A . (.VMware, Inc. - VMware PCI VMCI Bus Device.) -- C:\WINDOWS\System32\drivers\vmci.sys [85584] =>.VMware, Inc.® O58 - SDL:2015/05/31 06:58:40 A . (.VMware, Inc. - VMware keyboard filter driver (64-bit).) -- C:\WINDOWS\System32\drivers\VMkbd.sys [33472] =>.VMware, Inc.® O58 - SDL:2015/05/31 06:58:42 A . (.VMware, Inc. - VMware virtual network driver (64-bit).) -- C:\WINDOWS\System32\drivers\vmnet.sys [27328] =>.VMware, Inc.® O58 - SDL:2015/05/31 06:58:42 A . (.VMware, Inc. - VMware virtual network adapter driver (64-b.) -- C:\WINDOWS\System32\drivers\vmnetadapter.sys [28864] =>.VMware, Inc.® O58 - SDL:2015/05/31 06:58:42 A . (.VMware, Inc. - VMware bridge driver (64-bit).) -- C:\WINDOWS\System32\drivers\vmnetbridge.sys [48832] =>.VMware, Inc.® O58 - SDL:2015/05/31 06:59:06 A . (.VMware, Inc. - VMware network application interface driver.) -- C:\WINDOWS\System32\drivers\vmnetuserif.sys [26816] =>.VMware, Inc.® O58 - SDL:2015/05/22 07:03:42 A . (.VMware, Inc. - VMware USB driver.) -- C:\WINDOWS\System32\drivers\vmusb.sys [58048] =>.VMware, Inc.® O58 - SDL:2015/05/31 06:59:08 A . (.VMware, Inc. - VMware kernel driver.) -- C:\WINDOWS\System32\drivers\vmx86.sys [66752] =>.VMware, Inc.® O58 - SDL:2013/08/22 13:43:34 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [168800] =>.Microsoft Windows® O58 - SDL:2015/05/21 16:36:00 A . (.VMware, Inc. - VMware vSockets Service.) -- C:\WINDOWS\System32\drivers\vsock.sys [76480] =>.VMware, Inc.® O58 - SDL:2013/08/22 13:43:34 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305504] =>.Microsoft Windows® O58 - SDL:2013/04/30 18:18:10 A . (.Wacom Technology - Wacom HID Router.) -- C:\WINDOWS\System32\drivers\wachidrouter.sys [85304] =>.Wacom Technology Corp.® O58 - SDL:2012/12/20 23:20:06 A . (.Wacom Technology - Wacom Router Filter Driver.) -- C:\WINDOWS\System32\drivers\wacomrouterfilter.sys [15344] =>.Wacom Technology Corp.® O58 - SDL:2015/11/12 22:50:10 A . (.Western Digital Technologies, Inc. - Western Digital SCSI Architecture Model (SA.) -- C:\WINDOWS\System32\drivers\wdcsam64.sys [26880] =>.WDKTestCert wdclab,130885612892544312® O58 - SDL:2013/01/29 01:48:14 A . (.Windows (R) Win 7 DDK provider - xHCIport.sys.) -- C:\WINDOWS\System32\drivers\xHCIPort.sys [194456] =>.Intel Wireless Display® ---\\ Last modified or created user files (30) - 15s O61 - LFC: 2016/03/10 15:44:47 A . (..) -- C:\Users\Admin\ZHPDiag3.exe [288797] O61 - LFC: 2016/03/03 19:18:52 A . (..) -- C:\Users\Admin\AppData\Roaming\sMedio\SMIPlayer\WaterMark\elstate_exg.bin [88] O61 - LFC: 2016/03/08 10:27:39 A . (..) -- C:\Users\Admin\AppData\Roaming\NVIDIA\GLCache\3639c4a435c44b72d9af738e00f23127\8ffc5a0897f4f36a\143940d7b869002d.bin [207997] O61 - LFC: 2016/03/08 11:00:18 A . (..) -- C:\Users\Admin\AppData\Local\NVIDIA\NvBackend\UMDShim\nvcoproc.bin [6214715] O61 - LFC: 2016/03/07 14:45:05 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\G2M.dll [30093360] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:05 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\G2MAudioStreamingDSP64.dll [363608] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:05 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\g2mcomm.exe [42048] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:05 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\G2MIMessenger.dll [144456] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:06 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\G2MInstaller.exe [41536] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:06 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\G2MInstHigh.exe [42048] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:06 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\g2mlauncher.exe [41536] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:06 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\G2MOutlookAddin.dll [168520] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:06 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\G2MOutlookAddin64.dll [191568] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:06 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\G2MResource_de.dll [3178568] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:06 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\G2MResource_en.dll [3160136] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:06 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\G2MResource_es.dll [3162696] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:06 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\G2MResource_fr.dll [3180104] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:06 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\G2MResource_it.dll [3154504] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:06 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\G2MResource_zh.dll [3005512] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:06 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\g2mstart.exe [41536] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:08 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\g2mtranscoder.exe [8478784] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:08 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\g2mui.exe [41536] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:06 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\G2MUninstall.exe [42048] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:06 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\g2mupdate.exe [41536] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:06 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\g2mupload.exe [41536] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:06 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\g2mvideoconference.exe [41536] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:08 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\G2MVideoStreamingDSP64.dll [362072] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:08 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\G2MWmpPlugin64.dll [356936] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:08 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\ImmersiveWindowsFinderDllWin8.dll [111672] {44AD220DBF367E6C4D2E480E121853D7} O61 - LFC: 2016/03/07 14:45:08 A . (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\Admin\AppData\Local\Citrix\GoToMeeting\4542\uninshlp.dll [12344] {44AD220DBF367E6C4D2E480E121853D7} ---\\ File Associations Shell Spawning (11) - 0s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe =>.Microsoft Corporation O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® ---\\ Start Menu Internet (12) - 1s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation ---\\ Search Browser Infection (3) - 11s O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (@ieframe.dll,-12512) - http://www.bing.com/ O69 - SBI: SearchScopes [HKLM] {5F4E43BE-D089-41A9-83DE-B0C174A3CB1C} [DefaultScope] - (Bing) - http://www.bing.com/ ---\\ Search Svchost Services (34) - 0s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\Windows\System32\aelupsvc.dll [214528] =>.Microsoft Corporation O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\WINDOWS\System32\certprop.dll [156160] =>.Microsoft Corporation O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\WINDOWS\System32\certprop.dll [156160] =>.Microsoft Corporation O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\WINDOWS\system32\srvsvc.dll [329216] =>.Microsoft Corporation O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\WINDOWS\System32\gpsvc.dll [1360896] =>.Microsoft Corporation O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\WINDOWS\System32\ikeext.dll [1083904] =>.Microsoft Corporation O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\WINDOWS\System32\iphlpsvc.dll [926208] =>.Microsoft Corporation O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\WINDOWS\system32\seclogon.dll [31744] =>.Microsoft Corporation O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\WINDOWS\System32\appinfo.dll [110080] =>.Microsoft Corporation O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\WINDOWS\system32\iscsiexe.dll [151040] =>.Microsoft Corporation O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\WINDOWS\System32\eapsvc.dll [110592] =>.Microsoft Corporation O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\WINDOWS\system32\schedsvc.dll [1265152] =>.Microsoft Corporation O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [230400] =>.Microsoft Corporation O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) -- C:\WINDOWS\system32\mmcss.dll [71168] =>.Microsoft Corporation O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\WINDOWS\System32\browser.dll [135168] =>.Microsoft Corporation O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\WINDOWS\system32\profsvc.dll [228864] =>.Microsoft Corporation O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [339968] =>.Microsoft Corporation O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\WINDOWS\System32\wercplsupport.dll [84992] =>.Microsoft Corporation O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\WINDOWS\system32\kmsvc.dll [101376] =>.Microsoft Corporation O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\WINDOWS\System32\bdesvc.dll [348672] =>.Microsoft Corporation O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Windows Location Framework Service.) -- C:\Windows\System32\GeofenceMonitorService.dll [522240] =>.Microsoft Corporation O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Microsoft® Account Service.) -- C:\WINDOWS\system32\wlidsvc.dll [1639424] =>.Microsoft Corporation O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\WINDOWS\system32\themeservice.dll [59392] =>.Microsoft Corporation O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Device Setup Manager.) -- C:\WINDOWS\System32\DeviceSetupManager.dll [206848] =>.Microsoft Corporation O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Microsoft Network Connectivity Assistant Se.) -- C:\WINDOWS\System32\ncasvc.dll [166400] =>.Microsoft Corporation O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\WINDOWS\System32\rasauto.dll [102912] =>.Microsoft Corporation O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINDOWS\System32\rasmans.dll [542208] =>.Microsoft Corporation O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [226816] =>.Microsoft Corporation O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\WINDOWS\System32\sens.dll [73728] =>.Microsoft Corporation O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\WINDOWS\System32\ipnathlp.dll [452608] =>.Microsoft Corporation O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [313344] =>.Microsoft Corporation O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\WINDOWS\system32\wuaueng.dll [3708416] =>.Microsoft Corporation O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\WINDOWS\System32\qmgr.dll [933376] =>.Microsoft Corporation O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [640000] =>.Microsoft Corporation ---\\ Additional Scan (O88) (1) - 0s ~ No malicious or unnecessary items found. ---\\ Summary of the elements found (1) - 0s ~ No malicious or unnecessary items found. ~ End of the scan, 35618 items in 00h01mn36s (1328)(0)