~ ZHPDiag v2016.5.9.95 By Nicolas Coolman (2016/05/09) ~ Run by ROS (Administrator) (2016/05/09 19:30:55) ~ Web: http://www.nicolascoolman.com ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ State version: Version OK ~ Mode: Scan ~ Report: C:\Users\ROS\Desktop\ZHPDiag.txt ~ Report: C:\Users\ROS\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ System startup: Normal (Normal boot) Windows 7 Home Basic, 64-bit Service Pack 1 (Build 7601) ---\\ Internet Browsers (2) - 0s GCIE: Google Chrome v50.0.2661.94 MSIE: Internet Explorer v11.0.9600.16428 ---\\ Windows Product Information (4) - 4s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK Windows Activation Technologies : KO ---\\ System protection software (1) - 2s Kaspersky Internet Security v15.0.0.463 ---\\ Surveillance software (2) - 2s Adobe Flash Player 10 ActiveX Adobe Reader X ---\\ Information on the system (6) - 0s ~ Operating System: Intel64 Family 6 Model 42 Stepping 7, GenuineIntel ~ Operating System: 64-bit ~ Boot mode: Normal (Normal boot) Total RAM: 4140.912 MB (48% free) System Restore: Activé (Enable) System drive C: has 406 GB () free of 451 GB ---\\ Connection to the system mode (3) - 0s ~ Computer Name: ROS-HP ~ User Name: ROS ~ Logged in as Administrator ---\\ Enumeration of the disk units (3) - 0s ~ Drive C: has 406 GB free of 451 GB (System) ~ Drive D: has 0 GB free of 21 GB ~ Drive E: has 0 GB free of 4 GB ---\\ State of the Windows Security Center (10) - 0s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK ---\\ Search Generic System Files (25) - 7s [MD5.332FEAB1435662FC6C672E25BEB37BE3] - 22/10/2011 - (.Microsoft Corporation - Windows Explorer.) -- C:\Windows\Explorer.exe [2871808] =>.Microsoft Corporation [MD5.DD81D91FF3B0763C392422865C9AC12E] - 14/07/2009 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe [45568] =>.Microsoft Corporation [MD5.94355C28C1970635A31B3FE52EB7CEBA] - 14/07/2009 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\Windows\System32\Wininit.exe [129024] =>.Microsoft Corporation [MD5.E6CB36B85BE59095337427E853A5B65A] - 07/05/2016 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\Windows\System32\wininet.dll [2332160] =>.Microsoft Corporation [MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - 21/11/2010 - (.Microsoft Corporation - Windows Logon Application.) -- C:\Windows\System32\Winlogon.exe [390656] =>.Microsoft Corporation [MD5.067FA52BFB59A56110A12312EF9AF243] - 21/11/2010 - (.Microsoft Corporation - Software Licensing Library.) -- C:\Windows\System32\sppcomapi.dll [232448] =>.Microsoft Corporation [MD5.492D07D79E7024CA310867B526D9636D] - 22/10/2011 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\System32\dnsapi.dll [357888] =>.Microsoft Corporation [MD5.B40420876B9288E0A1C8CCA8A84E5DC9] - 22/10/2011 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\Syswow64\dnsapi.dll [270336] =>.Microsoft Corporation [MD5.0D57D091E06BB1E58E72E5D08479FDDF] - 22/10/2011 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [20480] =>.Microsoft Corporation [MD5.314C17917AC8523EC77A710215012A65] - 07/05/2016 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [497152] =>.Microsoft Corporation [MD5.02062C0B390B7729EDC9E69C680A6F3C] - 14/07/2009 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [24128] =>.Microsoft Windows® [MD5.B8BD2BB284668C84865658C77574381A] - 14/07/2009 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [92160] =>.Microsoft Corporation [MD5.F036CE71586E93D94DAB220D7BDF4416] - 21/11/2010 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [147456] =>.Microsoft Corporation [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - 21/11/2010 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [102400] =>.Microsoft Corporation [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - 21/11/2010 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [122368] =>.Microsoft Corporation [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - 14/07/2009 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\Windows\System32\drivers\i8042prt.sys [105472] =>.Microsoft Corporation [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - 14/07/2009 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [116224] =>.Microsoft Corporation [MD5.A5D9106A73DC88564C825D317CAC68AC] - 22/10/2011 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [158208] =>.Microsoft Corporation [MD5.09594D1089C523423B32A4229263F068] - 21/11/2010 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [261632] =>.Microsoft Corporation [MD5.A2F74975097F52A00745F9637451FDD8] - 22/10/2011 - (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\drivers\ntfs.sys [1659776] =>.Microsoft Windows® [MD5.0086431C29C35BE1DBC43F52CC273887] - 14/07/2009 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\Windows\System32\drivers\Parport.sys [97280] =>.Microsoft Corporation [MD5.471815800AE33E6F1C32FB1B97C490CA] - 21/11/2010 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [129536] =>.Microsoft Corporation [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - 14/07/2009 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [93184] =>.Microsoft Corporation [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - 21/11/2010 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [119296] =>.Microsoft Corporation [MD5.DF8126BD41180351A093A3AD2FC8903B] - 22/10/2011 - (.Microsoft Corporation - Volume Shadow Copy Driver.) -- C:\Windows\System32\drivers\volsnap.sys [296320] =>.Microsoft Windows® ---\\ Non Microsoft non disabled Windows Services (16) - 4s O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated® O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\System32\atiesrxx.exe =>.AMD O23 - Service: Kaspersky Anti-Virus Service 15.0.0 (AVP15.0.0) . (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe =>.Kaspersky Lab® O23 - Service: Bluetooth Service (btwdins) . (.Broadcom Corporation. - Bluetooth Support Server.) - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe =>.Broadcom Corporation® O23 - Service: TrueSuiteService (FPLService) . (.HP - HP Service.) - C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe =>.AuthenTec, Inc.® O23 - Service: خدمة Google Update (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc® O23 - Service: HP Support Assistant Service (HP Support Assistant Service) . (.Hewlett-Packard Company - HP Support Assistant Service.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe =>.Hewlett-Packard Company® O23 - Service: HP Auto (HPAuto) . (.Hewlett-Packard - HP Usage Improvement Tracking.) - C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe =>.Hewlett-Packard Company® O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) . (.Hewlett-Packard Company - HP Quick Synchronization Service.) - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe =>.Hewlett-Packard Company® O23 - Service: HPWMISVC (HPWMISVC) . (.Hewlett-Packard Development Company, L.P. - HP Quick Launch WMI Service.) - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe =>.Hewlett-Packard Company® O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation - IAStorDataSvc.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe =>.Intel Corporation® O23 - Service: IconMan_R (IconMan_R) . (.Realsil Microelectronics Inc. - Realtek Card Reader Icon Tool..) - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe =>.Realtek Semiconductor Corp® O23 - Service: Intel(R) Identity Protection Technology Host Interface Serv (jhi_service) . (.Intel Corporation - Intel IPT Host Interface Service.) - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe =>.Intel® Identity Protection Technology Software® O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation® O23 - Service: @C:\Windows\system32\stlang64.dll (STacSV) . (.IDT, Inc. - IDT PC Audio.) - C:\Program Files\IDT\WDM\stacsv64.exe =>.IDT, Inc. O23 - Service: Intel(R) Management and Security Application User Notificat (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe =>.Intel Corporation® ---\\ Services not Microsoft (SR=Run, SS=Stop) (20) - 26s SR - Auto [06/06/2011] [ 64952] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated® SR - Auto [18/08/2011] [ 204288] (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe =>.AMD SR - Auto [20/04/2014] [ 233552] Kaspersky Anti-Virus Service 15.0.0 (AVP15.0.0) . (.Kaspersky Lab ZAO.) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe =>.Kaspersky Lab® SR - Auto [20/09/2011] [ 1085216] Bluetooth Service (btwdins) . (.Broadcom Corporation..) - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe =>.Broadcom Corporation® SR - Auto [19/08/2011] [ 260424] TrueSuiteService (FPLService) . (.HP.) - C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe =>.AuthenTec, Inc.® SS - Demand [12/10/2010] [ 206072] GamesAppService (GamesAppService) . (.WildTangent, Inc..) - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe =>.WildTangent Inc® SS - Auto [08/05/2016] [ 154440] خدمة Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc® SS - Demand [08/05/2016] [ 154440] خدمة Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc® SR - Auto [10/09/2011] [ 86072] HP Support Assistant Service (HP Support Assistant Service) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe =>.Hewlett-Packard Company® SR - Auto [17/02/2011] [ 682040] HP Auto (HPAuto) . (.Hewlett-Packard.) - C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe =>.Hewlett-Packard Company® SR - Auto [06/09/2012] [ 197536] HP Quick Synchronization Service (HPDrvMntSvc.exe) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe =>.Hewlett-Packard Company® SR - Demand [06/09/2012] [ 1001376] HP Software Framework Service (hpqwmiex) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe =>.Hewlett-Packard Company® SR - Auto [05/03/2012] [ 35200] HPWMISVC (HPWMISVC) . (.Hewlett-Packard Development Company, L.P..) - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe =>.Hewlett-Packard Company® SR - Auto [30/04/2011] [ 13592] Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe =>.Intel Corporation® SS - Auto [01/09/2011] [ 2425960] IconMan_R (IconMan_R) . (.Realsil Microelectronics Inc..) - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe =>.Realtek Semiconductor Corp® SR - Auto [24/02/2011] [ 212944] Intel(R) Identity Protection Technology Host Interface Serv (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe =>.Intel® Identity Protection Technology Software® SR - Auto [02/02/2011] [ 326168] Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation® SR - Auto [08/09/2011] [ 305152] @C:\Windows\system32\stlang64.dll (STacSV) . (.IDT, Inc..) - C:\Program Files\IDT\WDM\stacsv64.exe =>.IDT, Inc. SR - Auto [02/02/2011] [ 2656280] Intel(R) Management and Security Application User Notificat (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe =>.Intel Corporation® ---\\ Task Planned Automatically (15) - 4s [MD5.00000000000000000000000000000000] [APT] [TaskName] (...) -- Task To Run (.not file.) [0] (.Activate.) =>.Superfluous.Empty [MD5.750446ED76A5D13E902174DDDDA1A62B] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440] (.Activate.) =>.Google Inc® [MD5.750446ED76A5D13E902174DDDDA1A62B] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440] (.Activate.) =>.Google Inc® [MD5.8AA3B22B716A04AC8DD13318A40D708D] [APT] [HPCeeScheduleForROS] (.Hewlett-Packard.) -- C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [95800] (.Activate.) =>.Hewlett-Packard Company® [MD5.AF714B804D3C605CFEE19713EB8190E0] [APT] [Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}] (.AO Kaspersky Lab.) -- C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [501416] (.Activate.) =>.Kaspersky Lab® [MD5.B7F55E2AE978D3D34F7876EE5D689AAE] [APT] [MirageAgent] (.CyberLink.) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488] (.Activate.) =>.CyberLink® [MD5.197A6007351ABF62372DCD9FA3E066F6] [APT] [Registration] (.Copyright © 2006.) -- C:\Program Files (x86)\Hewlett-Packard\HP Setup\Dependencies\RemEngine.exe [38456] (.Activate.) =>.Hewlett-Packard Company® O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [838] =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [842] =>.Google Inc® O39 - APT: HPCeeScheduleForROS - (.Hewlett-Packard.) -- C:\Windows\Tasks\HPCeeScheduleForROS.job [324] =>.Hewlett-Packard Company® O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [3586] =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [3838] =>.Google Inc® O39 - APT: HPCeeScheduleForROS - (.Hewlett-Packard.) -- C:\Windows\System32\Tasks\HPCeeScheduleForROS [3170] =>.Hewlett-Packard Company® O39 - APT: MirageAgent - (.CyberLink.) -- C:\Windows\System32\Tasks\MirageAgent [3148] =>.CyberLink® O39 - APT: Registration - (.Copyright © 2006.) -- C:\Windows\System32\Tasks\Registration [3560] =>.Hewlett-Packard Company® ---\\ Process running (38) - 5s [MD5.EC3949088F617ACC056FC1AB54A6A13B] - (.HP - HP Service.) -- C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe [260424] [PID.452] =>.AuthenTec, Inc.® [MD5.6807D94E8148771263308521E8CADE5E] - (.AMD - AMD External Events Service Module.) -- C:\Windows\System32\atiesrxx.exe [204288] [PID.664] =>.AMD [MD5.7BF818B11C1FEDC3E76D233124470A30] - (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\stacsv64.exe [305152] [PID.1064] =>.IDT, Inc. [MD5.382EFFE93413F2683A4FFED3CF8C8AB4] - (.AMD - AMD External Events Client Module.) -- C:\Windows\System32\atieclxx.exe [485376] [PID.1572] =>.AMD [MD5.11A52CF7B265631DEEB24C6149309EFF] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [64952] [PID.1824] =>.Adobe Systems, Incorporated® [MD5.058734C95991F6BEBF3D3075B8776234] - (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe [233552] [PID.1932] =>.Kaspersky Lab® [MD5.1249EDE2280F9A1564C946AFDDCD59D5] - (.Broadcom Corporation. - Bluetooth Support Server.) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [1085216] [PID.1984] =>.Broadcom Corporation® [MD5.CA793DCC1D5F619021EF1D37CC7A831E] - (.EasyBits Software AS - Shared EasyBits services for Windows.) -- C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232] [PID.1028] =>.EasyBits Software AS [MD5.9BFDA0BC109EB6D16F2CB862BB85E28C] - (.Hewlett-Packard Company - HP Quick Synchronization Service.) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [197536] [PID.1408] =>.Hewlett-Packard Company® [MD5.2BEC76BDCD1BC080210325E7B5094834] - (.Hewlett-Packard Development Company, L.P. - HP Quick Launch WMI Service.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [35200] [PID.1520] =>.Hewlett-Packard Company® [MD5.6C85719A21B3F62C2C76280F4BD36C7B] - (.Intel Corporation - Intel IPT Host Interface Service.) -- C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [212944] [PID.1900] =>.Intel® Identity Protection Technology Software® [MD5.2BACD71123F42CEA603F4E205E1AE337] - (.Microsoft Corp. - Microsoft® Windows Live ID Service.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2292096] [PID.1360] =>.Microsoft Corporation® [MD5.7B8C1B09C11E8DB7C4480ABD7D17E821] - (.Hewlett-Packard - HP Usage Improvement Tracking.) -- C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [682040] [PID.1924] =>.Hewlett-Packard Company® [MD5.2A46FFE841EC43001D5A293A54DB34DE] - (.Microsoft Corp. - Microsoft® Windows Live ID Service Monitor.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE [223104] [PID.2568] =>.Microsoft Corporation® [MD5.39AC970429FB9E56A29655FA8B959E90] - (.Intel Corporation - hkcmd Module.) -- C:\Windows\System32\hkcmd.exe [392472] [PID.3540] =>.Intel Corporation® [MD5.7CA105C4CCDFCA407859B2DF3D05A645] - (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe [416024] [PID.3564] =>.Intel Corporation® [MD5.67BB817D8D76963E9E4281E9823ADEAF] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2799912] [PID.3592] =>.Synaptics Incorporated® [MD5.A2199C8FBBE252614815E5AD62350B17] - (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray64.exe [1424896] [PID.3644] =>.IDT, Inc. [MD5.A446F3898F1CE9989ACB3F6E758E179B] - (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avpui.exe [192160] [PID.3972] =>.Kaspersky Lab® [MD5.33B25AFE2D6658E7681D929BC8B23858] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [121640] [PID.4092] =>.Synaptics Incorporated® [MD5.4C988ECE4DB6D5B262329B30E7962D91] - (.Hewlett-Packard Development Company, L.P. - HP Taskbar Process TP.) -- C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe [707896] [PID.3856] =>.Hewlett-Packard Company® [MD5.514455F6586473791C5C6B25BA4E1BAB] - (.Hewlett-Packard Company - HP Software Framework WMI Service.) -- C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [1001376] [PID.4904] =>.Hewlett-Packard Company® [MD5.13BB1114451C63BFB41BA7DAA4D70A29] - (.Hewlett-Packard Company - HP Support Assistant Service.) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [86072] [PID.3024] =>.Hewlett-Packard Company® [MD5.E79A8E33BD136D14BAE1FA20EB2EF124] - (.Intel Corporation - IAStorDataSvc.) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [13592] [PID.5224] =>.Intel Corporation® [MD5.D75C4B4A8FE6D7FD74A7EECDBAEC729F] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [326168] [PID.5944] =>.Intel Corporation® [MD5.758C2CE427C343F780A205E28555C98D] - (.Intel Corporation - User Notification Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2656280] [PID.4268] =>.Intel Corporation® [MD5.ABF64234F3462571E66527828040219B] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe [252232] [PID.8772] =>.Google Inc® [MD5.2E6215108125A42160A1EC17208A50F0] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe [313672] [PID.1168] =>.Google Inc® [MD5.17B0ED32D0FD1DAF7839DFD06E80F956] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [881304] [PID.9736] =>.Google Inc® [MD5.17B0ED32D0FD1DAF7839DFD06E80F956] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [881304] [PID.9788] =>.Google Inc® [MD5.17B0ED32D0FD1DAF7839DFD06E80F956] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [881304] [PID.9828] =>.Google Inc® [MD5.17B0ED32D0FD1DAF7839DFD06E80F956] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [881304] [PID.9940] =>.Google Inc® [MD5.17B0ED32D0FD1DAF7839DFD06E80F956] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [881304] [PID.10188] =>.Google Inc® [MD5.346453400873F07F6CDCDE2E3CBD1DF3] - (.Kaspersky Lab ZAO - Kaspersky Native Messaging Server for plugi.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\plugin-nm-server.exe [808744] [PID.5404] =>.Kaspersky Lab® [MD5.A6B060B72FD17BFE6458114CF3417DF0] - (.HP - TouchControl.) -- C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe [653128] [PID.6468] =>.AuthenTec, Inc.® [MD5.17B0ED32D0FD1DAF7839DFD06E80F956] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [881304] [PID.12180] =>.Google Inc® [MD5.17B0ED32D0FD1DAF7839DFD06E80F956] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [881304] [PID.9392] =>.Google Inc® [MD5.4CB9134ADBB2CF83BF8BDDB10775B5F1] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\ROS\Downloads\ZHPDiag3.exe [2204160] [PID.1548] =>.Nicolas Coolman ---\\ Google Chrome, Start,Search,Extensions (10) - 1s G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [bfmogjcijkfeahcajecmmegieipfbdcc] Website Logon G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] __MSG_ExtensionName__ G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc. ---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (4) - 1s P2 - FPN: [HKLM] [@kaspersky.com/content_blocker] - (.kaspersky.com.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com =>.kaspersky.com P2 - FPN: [HKLM] [@kaspersky.com/online_banking] - (.kaspersky.com.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com =>.kaspersky.com P2 - FPN: [HKLM] [@kaspersky.com/virtual_keyboard] - (.kaspersky.com.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com =>.kaspersky.com P2 - FPN: [HKLM] [@WildTangent.com/GamesAppPresenceDetector,Version=1.0] - (.WildTangent.) -- C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll =>.WildTangent ---\\ Internet Explorer Extensions, Start, Search (16) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer ---\\ Internet Explorer, Proxy Management (4) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Line Analysis, IniFiles, Auto loading programs (3) - 1s F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation ---\\ Hosts file redirection (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (1) ---\\ Browser Helper Object (BHO) (6) - 1s O2 - BHO: ContentBlockerBrowserHelperObject [64Bits] - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} . (.Kaspersky Lab ZAO - Content Blocker Plugin.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll =>.Kaspersky Lab® O2 - BHO: VirtualKeyboardBrowserHelperObject [64Bits] - {73455575-E40C-433C-9784-C78DC7761455} . (.Kaspersky Lab ZAO - Virtual Keyboard Plugin.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll =>.Kaspersky Lab® O2 - BHO: TSBHO Class [64Bits] - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} . (.HP - Website Log On.) -- C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll =>.AuthenTec, Inc.® O2 - BHO: Windows Live ID Sign-in Helper [64Bits] - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll =>.Microsoft Corporation® O2 - BHO: Safe Money Plugin [64Bits] - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} . (.Kaspersky Lab ZAO - Safe Money Plugin.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\OnlineBanking\online_banking_bho.dll =>.Kaspersky Lab® O2 - BHO: link filter bho [64Bits] - {E33CF602-D945-461A-83F0-819F76A199F8} . (.Kaspersky Lab ZAO - URL Advisor Plugin.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll =>.Kaspersky Lab® ---\\ Auto loading programs from Registry and folders (18) - 2s O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\System32\igfxtray.exe =>.Intel Corporation® O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\System32\hkcmd.exe =>.Intel Corporation® O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe =>.Intel Corporation® O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe =>.Synaptics Incorporated® O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray64.exe =>.IDT, Inc. O4 - HKLM\..\Run: [SetDefault] . (.Hewlett-Packard Development Company, L.P. - SetDefault.) -- C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe =>.Hewlett-Packard Company® O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe =>.Advanced Micro Devices, Inc.® O4 - HKLM\..\Wow6432Node\Run: [HPQuickWebProxy] . (.Hewlett-Packard Company - HP QuickWeb Utilities.) -- C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe =>.Hewlett-Packard Company® O4 - HKLM\..\Wow6432Node\Run: [RemoteControl10] . (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe =>.CyberLink® O4 - HKLM\..\Wow6432Node\Run: [HPOSD] . (.Hewlett-Packard Development Company, L.P. - HP On Screen Display.) -- C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe =>.Hewlett-Packard Company® O4 - HKLM\..\Wow6432Node\Run: [Easybits Recovery] . (.EasyBits Software AS - .) -- C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe =>.EasyBits Software AS O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems, Incorporated® O4 - HKLM\..\Wow6432Node\Run: [Magic Desktop for HP notification] . (.Easybits - Software update notification.) -- C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe =>.Easybits AS® O4 - HKLM\..\Wow6432Node\Run: [HP Quick Launch] . (.Hewlett-Packard Development Company, L.P. - HP Message Service.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe =>.Hewlett-Packard Company® O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Desktop Gadgets.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Desktop Gadgets.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation ---\\ Global shortcuts Startup (36) - 13s O4 - GS\Desktop [Administrator]: FRST64 - Shortcut.lnk . (.Farbar - Farbar Recovery Scan Tool.) C:\Users\ROS\Downloads\FRST64.exe =>.Farbar O4 - GS\Desktop [Administrator]: procexp - Shortcut.lnk . (.Sysinternals - www.sysinternals.com - Sysinternals Process Explorer.) C:\Users\ROS\Downloads\ProcessExplorer\procexp.exe =>.Microsoft Corporation® O4 - GS\Desktop [Administrator]: RogueKiller - Shortcut.lnk . (...) C:\Users\ROS\Downloads\RogueKiller.exe =>.Adlice® O4 - GS\Desktop [Administrator]: Safe Money.lnk . (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avpui.exe =>.Kaspersky Lab® O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\ROS\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [Administrator]: HP Recommended.LNK . (...) C:\Program Files (x86)\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe O4 - GS\TaskBar [Administrator]: Windows Live.LNK . (.Hewlett-Packard Development Company, L.P. - .) C:\Program Files (x86)\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe =>.Hewlett-Packard Development Company, L.P. O4 - GS\Desktop [Guest]: FRST64 - Shortcut.lnk . (.Farbar - Farbar Recovery Scan Tool.) C:\Users\ROS\Downloads\FRST64.exe =>.Farbar O4 - GS\Desktop [Guest]: procexp - Shortcut.lnk . (.Sysinternals - www.sysinternals.com - Sysinternals Process Explorer.) C:\Users\ROS\Downloads\ProcessExplorer\procexp.exe =>.Microsoft Corporation® O4 - GS\Desktop [Guest]: RogueKiller - Shortcut.lnk . (...) C:\Users\ROS\Downloads\RogueKiller.exe =>.Adlice® O4 - GS\Desktop [Guest]: Safe Money.lnk . (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avpui.exe =>.Kaspersky Lab® O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\ROS\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [Guest]: HP Recommended.LNK . (...) C:\Program Files (x86)\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe O4 - GS\TaskBar [Guest]: Windows Live.LNK . (.Hewlett-Packard Development Company, L.P. - .) C:\Program Files (x86)\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe =>.Hewlett-Packard Development Company, L.P. O4 - GS\Desktop [ROS]: FRST64 - Shortcut.lnk . (.Farbar - Farbar Recovery Scan Tool.) C:\Users\ROS\Downloads\FRST64.exe =>.Farbar O4 - GS\Desktop [ROS]: procexp - Shortcut.lnk . (.Sysinternals - www.sysinternals.com - Sysinternals Process Explorer.) C:\Users\ROS\Downloads\ProcessExplorer\procexp.exe =>.Microsoft Corporation® O4 - GS\Desktop [ROS]: RogueKiller - Shortcut.lnk . (...) C:\Users\ROS\Downloads\RogueKiller.exe =>.Adlice® O4 - GS\Desktop [ROS]: Safe Money.lnk . (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avpui.exe =>.Kaspersky Lab® O4 - GS\Desktop [ROS]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\ROS\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [ROS]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [ROS]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [ROS]: HP Recommended.LNK . (...) C:\Program Files (x86)\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe O4 - GS\TaskBar [ROS]: Windows Live.LNK . (.Hewlett-Packard Development Company, L.P. - .) C:\Program Files (x86)\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe =>.Hewlett-Packard Development Company, L.P. O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\CommonDesktop [Public]: HP Support Assistant.lnk . (.Hewlett-Packard Company - HP Support Assistant.) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe =>.Hewlett-Packard Company® O4 - GS\CommonDesktop [Public]: Kaspersky Internet Security.lnk . (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avpui.exe =>.Kaspersky Lab® O4 - GS\CommonDesktop [Public]: Magic Desktop.lnk . (.EasyBits Software AS - EasyBits Security Shield.) C:\Program Files (x86)\EasyBits For Kids\ezSecShield.exe =>.EasyBits Software AS® O4 - GS\CommonDesktop [Public]: Microsoft Office 2010.lnk . (.Hewlett-Packard Company - OfficeDesktopIconThread.) C:\SYSTEM.SAV\util\OfficeDesktopIconThread.exe =>.Hewlett-Packard Company® O4 - GS\CommonDesktop [Public]: Skype.lnk . (.Microsoft - launcher.) C:\Program Files (x86)\Online Services\Skype\SkypeLauncher.exe =>.Skype Technologies SA® O4 - GS\CommonDesktop [Public]: WildTangent Games App - hp.lnk . (...) C:\Program Files (x86)\HP Games\onplay\onplay.exe =>.WildTangent Inc® O4 - GS\Startup [Public]: Bluetooth.lnk . (.Broadcom Corporation. - .) C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe =>.Broadcom Corporation. O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) C:\Windows\system32\taskschd.msc ---\\ Lop.com/Domain Hijackers (2) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.5.5 O17 - HKLM\System\CCS\Services\Tcpip\..\{1BDDD790-8282-4538-B344-D1C0F06D4B12}: DhcpNameServer = 192.168.5.5 ---\\ Extra protocols (24) - 2s O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: livecall [64Bits] - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll =>.Microsoft Corporation® O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation O18 - Handler: msnim [64Bits] - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll =>.Microsoft Corporation® O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: wlmailhtml [64Bits] - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (.Microsoft Corporation - Windows Live Mail.) -- C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll =>.Microsoft Corporation® O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll =>.Microsoft Corporation® O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation® ---\\ Software installed (83) - 22s O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX =>.Adobe Systems Incorporated® O42 - Logiciel: Adobe Reader X (10.1.0) - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1033-7B44-AA1000000001} =>.Adobe Systems Incorporated O42 - Logiciel: AMD APP SDK Runtime - (.Advanced Micro Devices Inc..) [HKLM][64Bits] -- {503F672D-6C84-448A-8F8F-4BC35AC83441} =>.Advanced Micro Devices Inc. O42 - Logiciel: AuthenTec TrueAPI - (.AuthenTec, Inc..) [HKLM][64Bits] -- {054EF02F-95D8-48F4-9EEB-2F9CE3072ED8} =>.AuthenTec, Inc. O42 - Logiciel: Bejeweled 3 - (.WildTangent.) [HKLM][64Bits] -- WTA-95582ef0-2f3c-4132-83f6-ac5879bc2f07 =>.WildTangent Inc® O42 - Logiciel: Blackhawk Striker 2 - (.WildTangent.) [HKLM][64Bits] -- WTA-40d35b02-e278-42bd-943e-8538356103b3 =>.WildTangent Inc® O42 - Logiciel: Broadcom 802.11 Wireless LAN Adapter - (.Broadcom Corporation.) [HKLM][64Bits] -- Broadcom 802.11 Wireless LAN Adapter =>.Broadcom Corporation O42 - Logiciel: Broadcom Bluetooth Software - (.Broadcom Corporation.) [HKLM][64Bits] -- {6E7F4CA3-B2DE-413C-A7A1-43AA5BE19EA1} =>.Broadcom Corporation O42 - Logiciel: Broadcom InConcert Maestro - (.Broadcom Corporation.) [HKLM][64Bits] -- {57DD35E9-D9BB-4089-BB05-EF933C586CB3} =>.Broadcom Corporation O42 - Logiciel: Chuzzle Deluxe - (.WildTangent.) [HKLM][64Bits] -- WTA-a4bb04f9-199c-45a6-8bc0-3e2c8cf7621d =>.WildTangent Inc® O42 - Logiciel: Cradle of Rome 2 - (.WildTangent.) [HKLM][64Bits] -- WTA-4f713b23-a6a9-4677-9269-3c08b4904f26 =>.WildTangent Inc® O42 - Logiciel: CyberLink PowerDVD - (.CyberLink Corp..) [HKLM][64Bits] -- {DEC235ED-58A4-4517-A278-C41E8DAEAB3B} =>.CyberLink® O42 - Logiciel: CyberLink PowerDVD - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B} =>.CyberLink® O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM][64Bits] -- {01FB4998-33C4-4431-85ED-079E3EEFE75D} =>.CyberLink® O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D} =>.CyberLink® O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF} =>.Microsoft O42 - Logiciel: Dora's World Adventure - (.WildTangent.) [HKLM][64Bits] -- WTA-52106f68-369c-4ceb-a86b-93ec2a0de3eb =>.WildTangent Inc® O42 - Logiciel: ESU for Microsoft Windows 7 SP1 - (.Hewlett-Packard.) [HKLM][64Bits] -- {E96CAA2A-0244-4A2A-8403-0C3C9534778B} =>.Hewlett-Packard O42 - Logiciel: Evernote v. 4.2.3 - (.Evernote Corp..) [HKLM][64Bits] -- {F761359C-9CED-45AE-9A51-9D6605CD55C4} =>.Evernote Corp. O42 - Logiciel: Farm Frenzy - (.WildTangent.) [HKLM][64Bits] -- WTA-c8417fa9-a0ae-40bf-869e-7b75241046c7 =>.WildTangent Inc® O42 - Logiciel: Farmscapes - (.WildTangent.) [HKLM][64Bits] -- WTA-78266176-e5ed-4610-bfa5-c1bde82cb3b4 =>.WildTangent Inc® O42 - Logiciel: FATE - (.WildTangent.) [HKLM][64Bits] -- WTA-54bd2bca-76dc-4065-8f56-b7ca17c1a731 =>.WildTangent Inc® O42 - Logiciel: Final Drive Fury - (.WildTangent.) [HKLM][64Bits] -- WTA-8272968d-fbe6-4397-ba6f-5e6c25d7487c =>.WildTangent Inc® O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome =>.Google Inc® O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc. O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>Heuristic.Suspect O42 - Logiciel: Hewlett-Packard ACLM.NET v1.1.2.0 - (.Hewlett-Packard.) [HKLM][64Bits] -- {6F340107-F9AA-47C6-B54C-C3A19F11553F} =>.Hewlett-Packard O42 - Logiciel: Hoyle Card Games - (.WildTangent.) [HKLM][64Bits] -- WTA-140434d0-40a9-4840-b7d4-55905a5228cb =>.WildTangent Inc® O42 - Logiciel: HP Auto - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {CC4D56B7-6F18-470B-8734-ABCD75BCF4F1} =>.Hewlett-Packard Company O42 - Logiciel: HP Customer Experience Enhancements - (.Hewlett-Packard.) [HKLM][64Bits] -- {07FA4960-B038-49EB-891B-9F95930AA544} =>.Hewlett-Packard O42 - Logiciel: HP Documentation - (.Hewlett-Packard.) [HKLM][64Bits] -- {3D5C7E0E-AEC0-40EB-99D3-C40469738040} =>.Hewlett-Packard O42 - Logiciel: HP Games - (.WildTangent.) [HKLM][64Bits] -- WildTangent hp Master Uninstall =>.WildTangent Inc O42 - Logiciel: HP Launch Box - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {BF1E75D0-E7AF-4BEA-9FBC-567F0C54BDF9} =>.Hewlett-Packard Company O42 - Logiciel: HP On Screen Display - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {ED1BD69A-07E3-418C-91F1-D856582581BF} =>.Hewlett-Packard Company O42 - Logiciel: HP Power Manager - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {7E799992-5DA0-4A1A-9443-B1836B063FEC} =>.Hewlett-Packard Company O42 - Logiciel: HP Quick Launch - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {53B17A98-5BF0-40BC-AAFF-850A357975AC} =>.Hewlett-Packard Company O42 - Logiciel: HP QuickWeb - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {BB4FC2AD-DF12-4EE1-8AA7-2C0A26B5E2FB} =>.Hewlett-Packard Company O42 - Logiciel: HP Recovery Manager - (.Hewlett-Packard.) [HKLM][64Bits] -- {DBCD5E64-7379-4648-9444-8A6558DCB614} =>.Hewlett-Packard O42 - Logiciel: HP Security Assistant - (.Hewlett-Packard.) [HKLM][64Bits] -- {562608FE-2051-4488-BF22-8CE4C03046AC} =>.Hewlett-Packard O42 - Logiciel: HP Setup - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} =>.Hewlett-Packard Company O42 - Logiciel: HP SimplePass PE 2011 - (.Hewlett-Packard.) [HKLM][64Bits] -- {4741965C-AFD0-4D00-81D1-1039F96D4DC3} =>.Hewlett-Packard O42 - Logiciel: HP Software Framework - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {675D093B-815D-47FD-AB2C-192EC751E8E2} =>.Hewlett-Packard Company O42 - Logiciel: HP Support Assistant - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {6F44AF95-3CDE-4513-AD3F-6D45F17BF324} =>.Hewlett-Packard Company O42 - Logiciel: IDT Audio - (.IDT.) [HKLM][64Bits] -- {E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001} =>.IDT O42 - Logiciel: Intel(R) Control Center - (.Intel Corporation.) [HKLM][64Bits] -- {F8A9085D-4C7A-41a9-8A77-C8998A96C421} =>.Intel Corporation® O42 - Logiciel: Intel(R) Display Audio Driver - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} =>.Intel Corporation® O42 - Logiciel: Intel(R) Identity Protection Technology 1.1.2.0 - (.Intel Corporation.) [HKLM][64Bits] -- {C01A86F5-56E7-101F-9BC9-E3F1025EB779} =>.Intel Corporation O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A} =>.Intel Corporation® O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {3E29EE6C-963A-4aae-86C1-DC237C4A49FC} =>.Intel Corporation® O42 - Logiciel: Jewel Match 3 - (.WildTangent.) [HKLM][64Bits] -- WTA-7802e6a7-b178-4eb9-8375-e9eb43fcba88 =>.WildTangent Inc® O42 - Logiciel: Jewel Quest Mysteries: The Seventh Gate Collector's Edition - (.WildTangent.) [HKLM][64Bits] -- WTA-b5d3d66a-7dea-4a1a-9527-07a39add0aab =>.WildTangent Inc® O42 - Logiciel: John Deere Drive Green - (.WildTangent.) [HKLM][64Bits] -- WTA-6df2fdb0-04c1-45e3-a9d8-5ab48bdf9925 =>.WildTangent Inc® O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM][64Bits] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4} =>.Microsoft Corporation O42 - Logiciel: Kaspersky Internet Security - (.Kaspersky Lab.) [HKLM][64Bits] -- {653C1B5A-3287-47B1-8613-0745D4E771C4} =>.Kaspersky Lab O42 - Logiciel: Kaspersky Internet Security - (.Kaspersky Lab.) [HKLM][64Bits] -- InstallWIX_{653C1B5A-3287-47B1-8613-0745D4E771C4} =>.Kaspersky Lab O42 - Logiciel: Letters from Nowhere 2 - (.WildTangent.) [HKLM][64Bits] -- WTA-1cbdafef-e041-4019-9c06-d8f862675353 =>.WildTangent Inc® O42 - Logiciel: Luxor HD - (.WildTangent.) [HKLM][64Bits] -- WTA-cad942ab-d609-4175-a908-b02ac99aaeaf =>.WildTangent Inc® O42 - Logiciel: Magic Desktop - (.EasyBits Software AS.) [HKLM][64Bits] -- EasyBits Magic Desktop =>.EasyBits Software AS O42 - Logiciel: Mah Jong Medley - (.WildTangent.) [HKLM][64Bits] -- WTA-282c65d9-55a8-4553-9b89-1fe64c43fab5 =>.WildTangent Inc® O42 - Logiciel: Mesh Runtime - (.Microsoft Corporation.) [HKLM][64Bits] -- {8C6D6116-B724-4810-8F2D-D047E6B7D68E} =>.Microsoft Corporation O42 - Logiciel: Microsoft Application Error Reporting - (.Microsoft Corporation.) [HKLM][64Bits] -- {95120000-00B9-0409-1000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} =>.Microsoft O42 - Logiciel: MSVCRT_amd64 - (.Microsoft.) [HKLM][64Bits] -- {D0B44725-3666-492D-BEF6-587A14BD9BD9} =>.Microsoft O42 - Logiciel: opensource - (.Your Company Name.) [HKLM][64Bits] -- {3677D4D8-E5E0-49FC-B86E-06541CF00BBE} =>.Your Company Name O42 - Logiciel: Penguins! - (.WildTangent.) [HKLM][64Bits] -- WTA-676bdb4e-e617-469f-b8f9-5f8d37f53eed =>.WildTangent Inc® O42 - Logiciel: Plants vs. Zombies - Game of the Year - (.WildTangent.) [HKLM][64Bits] -- WTA-5461c740-be54-42e9-a6c4-a609085b8020 =>.WildTangent Inc® O42 - Logiciel: Poker Superstars III - (.WildTangent.) [HKLM][64Bits] -- WTA-cb0cea43-2fe5-4c39-adab-97f10d2d8699 =>.WildTangent Inc® O42 - Logiciel: Polar Bowler - (.WildTangent.) [HKLM][64Bits] -- WTA-41630d36-9f8d-4fd3-8756-c7aa9291ae69 =>.WildTangent Inc® O42 - Logiciel: Polar Golfer - (.WildTangent.) [HKLM][64Bits] -- WTA-cd6abf9c-0b06-40ed-ab00-dbabcb1069c8 =>.WildTangent Inc® O42 - Logiciel: PX Profile Update - (.AMD.) [HKLM][64Bits] -- {422CB2BA-2A49-B156-D96C-5B1971DBFF2C} =>.AMD O42 - Logiciel: Realtek PCIE Card Reader - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {C1594429-8296-4652-BF54-9DBE4932A44C} =>.Realtek Semiconductor Corp® O42 - Logiciel: RollerCoaster Tycoon 3: Platinum - (.WildTangent.) [HKLM][64Bits] -- WTA-ad74d562-e82a-40ea-a99f-22eba2f25aa4 =>.WildTangent Inc® O42 - Logiciel: Skype™ 5.5 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {AA59DDE4-B672-4621-A016-4C248204957A} =>.Skype Technologies S.A. O42 - Logiciel: swMSM - (.Adobe Systems, Inc.) [HKLM][64Bits] -- {612C34C7-5E90-47D8-9B5C-0F717DD82726} =>.Adobe Systems, Inc O42 - Logiciel: Synaptics TouchPad Driver - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey =>.Synaptics Incorporated O42 - Logiciel: The Treasures of Mystery Island: The Ghost Ship - (.WildTangent.) [HKLM][64Bits] -- WTA-ba3ec129-8a69-448f-877f-a9f23886e95e =>.WildTangent Inc® O42 - Logiciel: Torchlight - (.WildTangent.) [HKLM][64Bits] -- WTA-7f1332d4-4faa-45a5-abe8-2c2a2673be61 =>.WildTangent Inc® O42 - Logiciel: Update Installer for WildTangent Games App - (.WildTangent.) [HKLM][64Bits] -- {2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App =>.WildTangent Inc O42 - Logiciel: VIP Access SDK (1.0.1.2) - (.Symantec Inc..) [HKLM][64Bits] -- VIP Access SDK =>.Symantec Inc. O42 - Logiciel: Virtual Villagers 4 - The Tree of Life - (.WildTangent.) [HKLM][64Bits] -- WTA-aae08ac7-1168-4b29-ae5c-928b0c717129 =>.WildTangent Inc® O42 - Logiciel: WildTangent Games App (HP Games) - (.WildTangent.) [HKLM][64Bits] -- {70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp =>.WildTangent Inc O42 - Logiciel: Zuma's Revenge - (.WildTangent.) [HKLM][64Bits] -- WTA-b2155436-85c3-4a56-a2d2-bf461c2fc369 =>.WildTangent Inc® ---\\ HKCU & HKLM Software Keys (57) - 22s HKLM\SOFTWARE\Wow6432Node\Adobe HKLM\SOFTWARE\Wow6432Node\AdwCleaner HKLM\SOFTWARE\Wow6432Node\AppDataLow HKLM\SOFTWARE\Wow6432Node\ATI HKLM\SOFTWARE\Wow6432Node\ATI Technologies HKLM\SOFTWARE\Wow6432Node\AuthenTec HKLM\SOFTWARE\Wow6432Node\Caphyon HKLM\SOFTWARE\Wow6432Node\CyberLink HKLM\SOFTWARE\Wow6432Node\EasyBits HKLM\SOFTWARE\Wow6432Node\Evernote HKLM\SOFTWARE\Wow6432Node\Google HKLM\SOFTWARE\Wow6432Node\Hewlett-Packard HKLM\SOFTWARE\Wow6432Node\IDT HKLM\SOFTWARE\Wow6432Node\InstallShield HKLM\SOFTWARE\Wow6432Node\Insyde HKLM\SOFTWARE\Wow6432Node\Intel HKLM\SOFTWARE\Wow6432Node\KasperskyLab HKLM\SOFTWARE\Wow6432Node\Khronos HKLM\SOFTWARE\Wow6432Node\Lake HKLM\SOFTWARE\Wow6432Node\Macromedia HKLM\SOFTWARE\Wow6432Node\Mozilla HKLM\SOFTWARE\Wow6432Node\MozillaPlugins HKLM\SOFTWARE\Wow6432Node\ODBC HKLM\SOFTWARE\Wow6432Node\Realtek HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp. HKLM\SOFTWARE\Wow6432Node\Skype HKLM\SOFTWARE\Wow6432Node\Symantec HKLM\SOFTWARE\Wow6432Node\TGUID HKLM\SOFTWARE\Wow6432Node\Westwood HKLM\SOFTWARE\Wow6432Node\WhlProvider HKLM\SOFTWARE\Wow6432Node\WildTangent HKLM\SOFTWARE\Wow6432Node\Win32 Services HKLM\SOFTWARE\Wow6432Node\RegisteredApplications HKCU\SOFTWARE\Adobe HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\ATI HKCU\SOFTWARE\AuthenTec HKCU\SOFTWARE\Bitdefender HKCU\SOFTWARE\CyberLink HKCU\SOFTWARE\Google HKCU\SOFTWARE\Hewlett-Packard HKCU\SOFTWARE\Intel HKCU\SOFTWARE\KasperskyLab HKCU\SOFTWARE\Lake HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\MozillaPlugins HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\Northcode Inc HKCU\SOFTWARE\Symantec HKCU\SOFTWARE\Synaptics HKCU\SOFTWARE\Sysinternals HKCU\SOFTWARE\Trolltech HKCU\SOFTWARE\Widcomm HKCU\SOFTWARE\Wow6432Node HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Software HKCU\SOFTWARE\AppDataLow\Software\Adobe ---\\ Contents of the Common Files folders (155) - 32s O43 - CFD: 30/10/2011 - [] D -- C:\Program Files\ATI =>.Advanced Micro Devices, Inc.® O43 - CFD: 05/05/2016 - [] D -- C:\Program Files\Bitdefender O43 - CFD: 30/10/2011 - [] D -- C:\Program Files\Broadcom =>.Broadcom Corporation® O43 - CFD: 06/05/2016 - [] D -- C:\Program Files\Common Files O43 - CFD: 22/10/2011 - [] D -- C:\Program Files\DVD Maker O43 - CFD: 23/10/2011 - [] D -- C:\Program Files\Hewlett-Packard O43 - CFD: 30/10/2011 - [] D -- C:\Program Files\IDT O43 - CFD: 07/05/2016 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation® O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Microsoft Games O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\MSBuild O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Reference Assemblies O43 - CFD: 30/10/2011 - [] D -- C:\Program Files\Symantec O43 - CFD: 30/10/2011 - [] D -- C:\Program Files\Synaptics =>.Synaptics Incorporated® O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files\Uninstall Information O43 - CFD: 30/10/2011 - [] D -- C:\Program Files\WIDCOMM =>.Broadcom Corporation® O43 - CFD: 22/10/2011 - [] D -- C:\Program Files\Windows Defender O43 - CFD: 23/10/2011 - [] D -- C:\Program Files\Windows Live =>.Microsoft Corporation® O43 - CFD: 22/10/2011 - [] D -- C:\Program Files\Windows Mail O43 - CFD: 22/10/2011 - [] D -- C:\Program Files\Windows Media Player O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Windows NT O43 - CFD: 22/10/2011 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation® O43 - CFD: 21/11/2010 - [] D -- C:\Program Files\Windows Portable Devices O43 - CFD: 05/05/2016 - [] D -- C:\Program Files\Windows Sidebar O43 - CFD: 05/05/2016 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Systems, Incorporated® O43 - CFD: 30/10/2011 - [] D -- C:\Program Files (x86)\AMD APP O43 - CFD: 30/10/2011 - [] D -- C:\Program Files (x86)\ATI Technologies O43 - CFD: 05/05/2016 - [] D -- C:\Program Files (x86)\Common Files O43 - CFD: 30/10/2011 - [] D -- C:\Program Files (x86)\CyberLink =>.CyberLink® O43 - CFD: 23/10/2011 - [] D -- C:\Program Files (x86)\EasyBits For Kids =>.EasyBits Software AS® O43 - CFD: 22/10/2011 - [] D -- C:\Program Files (x86)\Evernote O43 - CFD: 08/05/2016 - [] D -- C:\Program Files (x86)\Google =>.Google Inc® O43 - CFD: 07/05/2016 - [] D -- C:\Program Files (x86)\Hewlett-Packard =>.Hewlett-Packard Company® O43 - CFD: 22/10/2011 - [] D -- C:\Program Files (x86)\HP Games O43 - CFD: 30/10/2011 - [] D -- C:\Program Files (x86)\HP SimplePass 2011 =>.AuthenTec, Inc.® O43 - CFD: 30/10/2011 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information O43 - CFD: 30/10/2011 - [] D -- C:\Program Files (x86)\Intel =>.Intel® Identity Protection Technology Software® O43 - CFD: 07/05/2016 - [] D -- C:\Program Files (x86)\Internet Explorer O43 - CFD: 05/05/2016 - [] D -- C:\Program Files (x86)\Kaspersky Lab =>.Kaspersky Lab® O43 - CFD: 06/05/2016 - [0] D -- C:\Program Files (x86)\Microsoft O43 - CFD: 23/10/2011 - [] D -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation® O43 - CFD: 23/10/2011 - [] D -- C:\Program Files (x86)\Microsoft Silverlight =>.Microsoft Corporation® O43 - CFD: 23/10/2011 - [] D -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition O43 - CFD: 05/05/2016 - [] D -- C:\Program Files (x86)\Microsoft.NET O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\MSBuild O43 - CFD: 05/05/2016 - [] RD -- C:\Program Files (x86)\Online Services =>.Skype Technologies SA® O43 - CFD: 05/05/2016 - [] D -- C:\Program Files (x86)\Realtek =>.Realtek Semiconductor Corp® O43 - CFD: 07/05/2016 - [] D -- C:\Program Files (x86)\Red Alert 2 O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Reference Assemblies O43 - CFD: 23/10/2011 - [] RD -- C:\Program Files (x86)\Skype =>.Skype Technologies SA® O43 - CFD: 30/10/2011 - [] D -- C:\Program Files (x86)\SymSilent =>.Symantec Corporation® O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files (x86)\Uninstall Information O43 - CFD: 22/10/2011 - [] D -- C:\Program Files (x86)\WildTangent Games =>.WildTangent Inc® O43 - CFD: 22/10/2011 - [] D -- C:\Program Files (x86)\Windows Defender O43 - CFD: 23/10/2011 - [] D -- C:\Program Files (x86)\Windows Live =>.Microsoft Corporation® O43 - CFD: 22/10/2011 - [] D -- C:\Program Files (x86)\Windows Mail O43 - CFD: 22/10/2011 - [] D -- C:\Program Files (x86)\Windows Media Player O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Windows NT O43 - CFD: 22/10/2011 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation® O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 05/05/2016 - [] D -- C:\Program Files (x86)\Windows Sidebar O43 - CFD: 08/05/2016 - [] D -- C:\Program Files (x86)\XCC O43 - CFD: 30/10/2011 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 05/05/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Communication and Chat O43 - CFD: 23/10/2011 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 05/05/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support O43 - CFD: 30/10/2011 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel O43 - CFD: 05/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 23/10/2011 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight O43 - CFD: 05/05/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos O43 - CFD: 05/05/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools O43 - CFD: 05/05/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection O43 - CFD: 30/10/2011 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 23/10/2011 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live O43 - CFD: 05/05/2016 - [] D -- C:\ProgramData\Adobe O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 30/10/2011 - [] D -- C:\ProgramData\ATI O43 - CFD: 05/05/2016 - [] D -- C:\ProgramData\Bitdefender O43 - CFD: 30/10/2011 - [] D -- C:\ProgramData\CyberLink O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 30/10/2011 - [] D -- C:\ProgramData\Downloaded Installations O43 - CFD: 05/05/2016 - [] D -- C:\ProgramData\Easybits Magic Desktop for HP O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Favorites O43 - CFD: 07/05/2016 - [] D -- C:\ProgramData\Hewlett-Packard O43 - CFD: 30/10/2011 - [] D -- C:\ProgramData\Intel O43 - CFD: 09/05/2016 - [] D -- C:\ProgramData\Kaspersky Lab O43 - CFD: 06/05/2016 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 05/05/2016 - [] D -- C:\ProgramData\Norton O43 - CFD: 30/10/2011 - [] D -- C:\ProgramData\NortonInstaller O43 - CFD: 07/05/2016 - [] D -- C:\ProgramData\RogueKiller O43 - CFD: 23/10/2011 - [] D -- C:\ProgramData\Skype O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 30/10/2011 - [] D -- C:\ProgramData\Synaptics O43 - CFD: 30/10/2011 - [] D -- C:\ProgramData\Temp O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 22/10/2011 - [] D -- C:\ProgramData\WildTangent O43 - CFD: 23/10/2011 - [] D -- C:\ProgramData\{A8DA1505-E615-42BB-BB77-74D5CC91FE7E} O43 - CFD: 05/05/2016 - [] D -- C:\Program Files (x86)\Common Files\Adobe O43 - CFD: 30/10/2011 - [] D -- C:\Program Files (x86)\Common Files\AuthenTec O43 - CFD: 30/10/2011 - [] D -- C:\Program Files (x86)\Common Files\Intel O43 - CFD: 30/10/2011 - [] D -- C:\Program Files (x86)\Common Files\Intel Corporation O43 - CFD: 30/10/2011 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared O43 - CFD: 30/10/2011 - [] D -- C:\Program Files (x86)\Common Files\postureAgent O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Common Files\Services O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines O43 - CFD: 05/05/2016 - [0] D -- C:\Program Files (x86)\Common Files\Symantec Shared O43 - CFD: 22/10/2011 - [] D -- C:\Program Files (x86)\Common Files\System O43 - CFD: 23/10/2011 - [] D -- C:\Program Files (x86)\Common Files\Windows Live O43 - CFD: 05/05/2016 - [] D -- C:\Users\ROS\AppData\Roaming\Adobe O43 - CFD: 05/05/2016 - [] D -- C:\Users\ROS\AppData\Roaming\ATI O43 - CFD: 06/05/2016 - [] D -- C:\Users\ROS\AppData\Roaming\Hewlett-Packard O43 - CFD: 07/05/2016 - [] D -- C:\Users\ROS\AppData\Roaming\hpqlog O43 - CFD: 05/05/2016 - [] D -- C:\Users\ROS\AppData\Roaming\Identities O43 - CFD: 05/05/2016 - [] D -- C:\Users\ROS\AppData\Roaming\Macromedia O43 - CFD: 08/05/2016 - [] SD -- C:\Users\ROS\AppData\Roaming\Microsoft O43 - CFD: 05/05/2016 - [0] D -- C:\Users\ROS\AppData\Roaming\QuickScan O43 - CFD: 05/05/2016 - [] D -- C:\Users\ROS\AppData\Roaming\Symantec O43 - CFD: 05/05/2016 - [] D -- C:\Users\ROS\AppData\Roaming\Synaptics O43 - CFD: 09/05/2016 - [] D -- C:\Users\ROS\AppData\Roaming\ZHP O43 - CFD: 05/05/2016 - [0] SHD -- C:\Users\ROS\AppData\Local\Application Data O43 - CFD: 05/05/2016 - [] D -- C:\Users\ROS\AppData\Local\ATI O43 - CFD: 05/05/2016 - [] D -- C:\Users\ROS\AppData\Local\AuthenTec O43 - CFD: 05/05/2016 - [] D -- C:\Users\ROS\AppData\Local\Broadcom O43 - CFD: 08/05/2016 - [] D -- C:\Users\ROS\AppData\Local\Diagnostics O43 - CFD: 08/05/2016 - [] D -- C:\Users\ROS\AppData\Local\Google O43 - CFD: 06/05/2016 - [] D -- C:\Users\ROS\AppData\Local\Hewlett-Packard O43 - CFD: 05/05/2016 - [] D -- C:\Users\ROS\AppData\Local\Hewlett-Packard_Company O43 - CFD: 05/05/2016 - [0] SHD -- C:\Users\ROS\AppData\Local\History O43 - CFD: 08/05/2016 - [] D -- C:\Users\ROS\AppData\Local\Microsoft O43 - CFD: 05/05/2016 - [] D -- C:\Users\ROS\AppData\Local\RemEngine O43 - CFD: 09/05/2016 - [] D -- C:\Users\ROS\AppData\Local\Temp O43 - CFD: 05/05/2016 - [0] SHD -- C:\Users\ROS\AppData\Local\Temporary Internet Files O43 - CFD: 05/05/2016 - [0] D -- C:\Users\ROS\AppData\Local\VirtualStore O43 - CFD: 09/05/2016 - [] D -- C:\Users\ROS\AppData\Local\Windows Live O43 - CFD: 08/05/2016 - [0] D -- C:\Users\ROS\AppData\Local\{0E77F685-334A-46BA-96F3-B8A306272896} =>.Superfluous.Empty O43 - CFD: 08/05/2016 - [0] D -- C:\Users\ROS\AppData\Local\{196F80C2-ABCF-43D8-BDAE-CBF420F96A71} =>.Superfluous.Empty O43 - CFD: 09/05/2016 - [0] D -- C:\Users\ROS\AppData\Local\{2FEDB381-6872-408E-9546-2CEB710D98E0} =>.Superfluous.Empty O43 - CFD: 07/05/2016 - [0] D -- C:\Users\ROS\AppData\Local\{3420563B-CD77-4732-8C4F-368863E7B161} =>.Superfluous.Empty O43 - CFD: 09/05/2016 - [0] D -- C:\Users\ROS\AppData\Local\{40E6A10F-306A-4B88-B5F8-36C46B0E5834} =>.Superfluous.Empty O43 - CFD: 09/05/2016 - [0] D -- C:\Users\ROS\AppData\Local\{7A236DE1-1650-422C-9F5B-21421AFBBC16} =>.Superfluous.Empty O43 - CFD: 08/05/2016 - [0] D -- C:\Users\ROS\AppData\Local\{85361488-0314-44DA-A76A-972D6E5BAB20} =>.Superfluous.Empty O43 - CFD: 09/05/2016 - [0] D -- C:\Users\ROS\AppData\Local\{87F355B7-8E7E-4EE7-8DC6-56ABC74518F2} =>.Superfluous.Empty O43 - CFD: 08/05/2016 - [0] D -- C:\Users\ROS\AppData\Local\{A081B574-CD03-42E2-BDB4-D8C4B1BC16CD} =>.Superfluous.Empty O43 - CFD: 08/05/2016 - [0] D -- C:\Users\ROS\AppData\Local\{A3029161-49FF-4DDF-8114-5368B9ADF85E} =>.Superfluous.Empty O43 - CFD: 09/05/2016 - [0] D -- C:\Users\ROS\AppData\Local\{B4C86D5B-ABC0-4603-8DB5-6BAEC1124527} =>.Superfluous.Empty O43 - CFD: 06/05/2016 - [0] D -- C:\Users\ROS\AppData\Local\{CD17107B-883A-4995-823F-F84EE1E28ED2} =>.Superfluous.Empty O43 - CFD: 09/05/2016 - [0] D -- C:\Users\ROS\AppData\Local\{D5277FC1-2F86-4F83-BF00-A82894F065C3} =>.Superfluous.Empty O43 - CFD: 09/05/2016 - [0] D -- C:\Users\ROS\AppData\Local\{E64F0F74-CDE9-4566-AD58-DC1BE1387951} =>.Superfluous.Empty O43 - CFD: 09/05/2016 - [0] D -- C:\Users\ROS\AppData\Local\{F9F7FCEC-DA04-43DE-B7FB-3CA2A8729935} =>.Superfluous.Empty O43 - CFD: 14/07/2009 - [] RD -- C:\Users\ROS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 05/05/2016 - [] RD -- C:\Users\ROS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 14/07/2009 - [] RD -- C:\Users\ROS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 05/05/2016 - [] RD -- C:\Users\ROS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup ---\\ ShellIconOverlayIdentifiers (SIOI) (2) - 0s O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation ---\\ System Drivers List (76) - 23s O58 - SDL:2009/07/14 04:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [491088] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [339536] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\drivers\adpu320.sys [182864] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [15440] =>.Microsoft Windows® O58 - SDL:2011/10/22 23:27:55 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [107904] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [194128] =>.Microsoft Windows® O58 - SDL:2011/10/22 23:27:55 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [27008] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [87632] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [97856] =>.Microsoft Windows® O58 - SDL:2011/08/18 12:40:56 A . (.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\System32\drivers\atikmdag.sys [9981952] =>.ATI Technologies Inc. O58 - SDL:2011/08/18 08:34:48 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\Windows\System32\drivers\atikmpag.sys [310272] =>.Advanced Micro Devices, Inc. O58 - SDL:2009/06/10 23:34:23 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60a.sys [270848] =>.Broadcom Corporation O58 - SDL:2011/09/21 04:36:50 A . (.Broadcom Corporation. - Broadcom Bluetooth Firmware Download Filter.) -- C:\Windows\System32\drivers\bcbtums.sys [133672] =>.Broadcom Corporation® O58 - SDL:2011/10/30 11:38:43 A . (.Broadcom Corporation - Broadcom 802.11 Network Adapter wireless dr.) -- C:\Windows\System32\drivers\BCMWL664.SYS [4729408] =>.Broadcom Corporation® O58 - SDL:2009/06/10 23:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [18432] =>.Brother Industries, Ltd. O58 - SDL:2009/06/10 23:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [8704] =>.Brother Industries, Ltd. O58 - SDL:2009/07/14 04:19:07 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [286720] =>.Brother Industries Ltd. O58 - SDL:2009/06/10 23:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [47104] =>.Brother Industries Ltd. O58 - SDL:2009/06/10 23:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [14976] =>.Brother Industries Ltd. O58 - SDL:2009/06/10 23:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [14720] =>.Brother Industries Ltd. O58 - SDL:2011/09/21 04:36:50 A . (.Broadcom Corporation. - Broadcom Bluetooth USB AMP Filter for Windo.) -- C:\Windows\System32\drivers\btwampfl.sys [620584] =>.Broadcom Corporation® O58 - SDL:2011/09/21 04:36:44 A . (.Broadcom Corporation. - Bluetooth Audio Device.) -- C:\Windows\System32\drivers\btwaudio.sys [167976] =>.Broadcom Corporation® O58 - SDL:2011/09/21 04:36:44 A . (.Broadcom Corporation. - Broadcom Bluetooth AVDT Service.) -- C:\Windows\System32\drivers\btwavdt.sys [178728] =>.Broadcom Corporation® O58 - SDL:2011/09/21 04:36:50 A . (.Broadcom Corporation. - Bluetooth LAN Access Server Driver.) -- C:\Windows\System32\drivers\btwdpan.sys [89640] =>.Broadcom Corporation® O58 - SDL:2011/09/21 04:36:44 A . (.Broadcom Corporation. - Broadcom Bluetooth L2CAP Service.) -- C:\Windows\System32\drivers\btwl2cap.sys [39976] =>.Broadcom Corporation® O58 - SDL:2011/09/21 04:36:44 A . (.Broadcom Corporation. - Bluetooth Remote Control HID Minidriver.) -- C:\Windows\System32\drivers\btwrchid.sys [21544] =>.Broadcom Corporation® O58 - SDL:2009/06/10 23:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [468480] =>.Broadcom Corporation O58 - SDL:2010/07/28 19:13:50 A . (.CyberLink Corporation - CyberLink WebCam Virtual Driver.) -- C:\Windows\System32\drivers\clwvd.sys [31088] =>.CyberLink® O58 - SDL:2009/07/14 04:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [17488] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [530496] =>.Microsoft Windows® O58 - SDL:2009/06/10 23:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3286016] =>.Broadcom Corporation O58 - SDL:2009/06/10 23:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [31232] =>.Hauppauge Computer Works, Inc. O58 - SDL:2010/10/20 03:34:26 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\drivers\HECIx64.sys [56344] =>.Intel Corporation® O58 - SDL:2010/11/21 06:23:47 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [78720] =>.Microsoft Windows® O58 - SDL:2011/04/26 21:07:36 A . (.Intel Corporation - Intel Rapid Storage Technology driver - x64.) -- C:\Windows\System32\drivers\iaStor.sys [557848] =>.Intel Corporation® O58 - SDL:2011/10/22 23:27:55 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [410496] =>.Microsoft Windows® O58 - SDL:2011/08/09 19:32:02 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd64.sys [12289472] =>.Intel Corporation O58 - SDL:2011/08/09 19:32:02 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdpmd64.sys [12289472] =>.Intel Corporation O58 - SDL:2009/07/14 04:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [44112] =>.Microsoft Windows® O58 - SDL:2010/10/15 12:28:16 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\Windows\System32\drivers\IntcDAud.sys [317440] =>.Intel(R) Corporation O58 - SDL:2014/02/20 12:59:04 A . (.Kaspersky Lab ZAO - Kaspersky Unified Driver.) -- C:\Windows\System32\drivers\kl1.sys [457824] =>.Kaspersky Lab® O58 - SDL:2016/05/06 12:16:17 A . (.Kaspersky Lab ZAO - Filter Core [fre_wlh_x64].) -- C:\Windows\System32\drivers\klflt.sys [141320] =>.Kaspersky Lab® O58 - SDL:2014/04/10 17:25:34 A . (.Kaspersky Lab ZAO - KLHK [fre_wlh_x64].) -- C:\Windows\System32\drivers\klhk.sys [243808] =>.Kaspersky Lab® O58 - SDL:2016/05/06 12:16:17 A . (.Kaspersky Lab ZAO - Klif Mini-Filter [fre_wlh_x64].) -- C:\Windows\System32\drivers\klif.sys [793800] =>.Kaspersky Lab® O58 - SDL:2014/02/25 13:09:02 A . (.Kaspersky Lab ZAO - Kaspersky Lab Intermediate Network Driver.) -- C:\Windows\System32\drivers\klim6.sys [30304] =>.Kaspersky Lab® O58 - SDL:2014/03/28 17:51:04 A . (.Kaspersky Lab ZAO - KLKBDFLT Keyboard Device Filter [fre_wlh_x6.) -- C:\Windows\System32\drivers\klkbdflt.sys [28768] =>.Kaspersky Lab® O58 - SDL:2013/08/08 17:11:00 A . (.Kaspersky Lab ZAO - KLMOUFLT Mouse Device Filter [fre_wlh_x64].) -- C:\Windows\System32\drivers\klmouflt.sys [29280] =>.Kaspersky Lab® O58 - SDL:2013/04/12 15:34:48 A . (.Kaspersky Lab ZAO - KLPD [fre_wnet_x64].) -- C:\Windows\System32\drivers\klpd.sys [15456] =>.Kaspersky Lab® O58 - SDL:2014/03/25 16:26:04 A . (.Kaspersky Lab ZAO - Network filtering component [fre_wnet_amd64.) -- C:\Windows\System32\drivers\kltdi.sys [55904] =>.Kaspersky Lab® O58 - SDL:2014/03/26 17:05:28 A . (.Kaspersky Lab ZAO - KNEPS Power [fre_wnet_amd64].) -- C:\Windows\System32\drivers\kneps.sys [179296] =>.Kaspersky Lab® O58 - SDL:2009/07/14 04:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [114752] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [106560] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [65600] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [115776] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [35392] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [284736] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [51264] =>.Microsoft Windows® O58 - SDL:2009/06/10 23:35:35 A . (.NVIDIA Corporation - NVIDIA MCP Networking Function Driver..) -- C:\Windows\System32\drivers\nvm62x64.sys [408960] =>.NVIDIA Corporation O58 - SDL:2011/10/22 23:27:55 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [148352] =>.Microsoft Windows® O58 - SDL:2011/10/22 23:27:55 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [166272] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1524816] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [128592] =>.Microsoft Windows® O58 - SDL:2011/08/24 08:57:24 A . (.Realtek - Realtek 8136/8168/8169 NDIS 6.20 64-bit Dri.) -- C:\Windows\System32\drivers\Rt64win7.sys [565352] =>.Realtek Semiconductor Corp® O58 - SDL:2011/09/02 22:46:00 A . (.Realtek Semiconductor Corp. - Realtek Pcie CardReader Driver for 2K/XP/Vi.) -- C:\Windows\System32\drivers\RtsPStor.sys [339048] =>.Realtek Semiconductor Corp® O58 - SDL:2009/06/10 23:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] =>.Macrovision Corporation, Macrovision Europe Limited, O58 - SDL:2009/07/14 04:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [43584] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [80464] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [24656] =>.Microsoft Windows® O58 - SDL:2011/09/08 16:42:28 A . (.IDT, Inc. - IDT PC Audio.) -- C:\Windows\System32\drivers\stwrt64.sys [535040] =>.IDT, Inc. O58 - SDL:2011/06/10 05:19:54 A . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\Windows\System32\drivers\SynTP.sys [1451056] =>.Synaptics Incorporated® O58 - SDL:2016/05/07 19:33:30 A . (...) -- C:\Windows\System32\drivers\TrueSight.sys [24688] =>.Adlice® O58 - SDL:2009/07/14 04:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [17488] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [161872] =>.Microsoft Windows® O58 - SDL:2009/06/11 00:01:11 A . (.Conexant Systems, Inc. - HSF_HWAZL WDM driver.) -- C:\Windows\System32\drivers\VSTAZL6.SYS [292864] =>.Conexant Systems, Inc. O58 - SDL:2009/06/11 00:01:11 A . (.Conexant Systems, Inc. - HSF_CNXT driver.) -- C:\Windows\System32\drivers\VSTCNXT6.SYS [740864] =>.Conexant Systems, Inc. O58 - SDL:2009/06/11 00:01:11 A . (.Conexant Systems, Inc. - HSF_DP driver.) -- C:\Windows\System32\drivers\VSTDPV6.SYS [1485312] =>.Conexant Systems, Inc. ---\\ Last modified or created user files (2) - 29s O61 - LFC: 2016/05/08 09:06:31 A . (..) -- C:\Users\ROS\AppData\Local\Microsoft\Windows\1033\StructuredQuerySchema.bin [297531] O61 - LFC: 2016/05/08 08:00:34 A . (..) -- C:\Users\ROS\AppData\Local\ATI\ACE\Manifest.Bin [29689] ---\\ File Associations Shell Spawning (10) - 2s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe =>.Microsoft Corporation O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S ---\\ Start Menu Internet (8) - 0s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation ---\\ Search Browser Infection (1) - 0s O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ ---\\ Search Svchost Services (32) - 4s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\Windows\System32\aelupsvc.dll [72192] =>.Microsoft Corporation O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [80384] =>.Microsoft Corporation O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [80384] =>.Microsoft Corporation O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\Windows\system32\srvsvc.dll [236032] =>.Microsoft Corporation O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\Windows\System32\gpsvc.dll [777728] =>.Microsoft Corporation O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\ikeext.dll [853504] =>.Microsoft Corporation O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\Windows\System32\Audiosrv.dll [679424] =>.Microsoft Corporation O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\Windows\System32\rasauto.dll [99328] =>.Microsoft Corporation O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [344064] =>.Microsoft Corporation O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [97792] =>.Microsoft Corporation O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\Windows\System32\Sens.dll [64512] =>.Microsoft Corporation O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [359424] =>.Microsoft Corporation O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [316928] =>.Microsoft Corporation O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remote Desktop Session Host Server Remote C.) -- C:\Windows\System32\termsrv.dll [680960] =>.Microsoft Corporation O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\system32\wuaueng.dll [2477536] =>.Microsoft Windows Component Publisher® O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\Windows\System32\qmgr.dll [849920] =>.Microsoft Corporation O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [370688] =>.Microsoft Corporation O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [569344] =>.Microsoft Corporation O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\Windows\system32\seclogon.dll [30720] =>.Microsoft Corporation O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\Windows\System32\appinfo.dll [70656] =>.Microsoft Corporation O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\Windows\system32\iscsiexe.dll [156672] =>.Microsoft Corporation O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) -- C:\Windows\system32\mmcss.dll [67584] =>.Microsoft Corporation O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [242688] =>.Microsoft Corporation O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [121856] =>.Microsoft Corporation O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\Windows\System32\browser.dll [136192] =>.Microsoft Corporation O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [111104] =>.Microsoft Corporation O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\Windows\system32\schedsvc.dll [1110016] =>.Microsoft Corporation O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\Windows\system32\kmsvc.dll [90624] =>.Microsoft Corporation O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\Windows\System32\wercplsupport.dll [84480] =>.Microsoft Corporation O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [209920] =>.Microsoft Corporation O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\Windows\system32\themeservice.dll [44544] =>.Microsoft Corporation O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\Windows\System32\bdesvc.dll [100864] =>.Microsoft Corporation ---\\ Additional Scan (O88) (2) - 0s HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>Heuristic.Suspect HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>Heuristic.Suspect ---\\ Summary of the elements found (1) - 0s http://www.nicolascoolman.info/2016/04/22/heuristic-suspect/ =>Heuristic.Suspect ~ End of the scan, 48251 items in 00h03mn48s (734)(0)