cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2016.10.19.194 By Nicolas Coolman (2016/10/19)
~ Run by YaSs (Administrator) (2016/10/20 06:33:28)
~ Web: https://www.nicolascoolman.com
~ Blog: https://www.anti-malware.top
~ Facebook: https://www.facebook.com/nicolascoolman1
~ State version: Version OK
~ Mode: Scan
~ Report: C:\Users\YaSs\Desktop\ZHPDiag.txt
~ Report: C:\Users\YaSs\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ System startup: Normal (Normal boot)
Windows 10 Pro, 32-bit (Build 14393) =>.Microsoft Corporation

---\\ Internet Browsers (4) - 0s
~ GCIE: Google Chrome v53.0.2785.143
~ MFIE: Mozilla Firefox 47.0.1 (x86 en-US)
~ OPIE: Opera 40.0.2308.81
~ MSIE: Internet Explorer v11.321.14393.0

---\\ Windows Product Information (3) - 3s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK

---\\ System protection software (2) - 7s
Avast Antivirus Gratuit v12.3.2280 => Software.Protection
Windows Defender (Deactivate) => Software.Protection

---\\ Information on the system (6) - 0s
~ Operating System: x86 Family 15 Model 4 Stepping 9, GenuineIntel
~ Operating System: 32-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 3135.924 MB (48% free)
System Restore: Activé (Enable)
System drive C: has 247 GB () free of 304 GB

---\\ Connection to the system mode (3) - 0s
~ Computer Name: DESKTOP-NQ98D5R
~ User Name: YaSs
~ Logged in as Administrator

---\\ Enumeration of the disk units (1) - 0s
~ Drive C: has 247 GB free of 304 GB (System)

---\\ State of the Windows Security Center (7) - 0s
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Search Generic System Files (23) - 1s
[MD5.97EFD2087A51AD739A8DED87D4DA86A1] - 15/09/2016 - (.Microsoft Corporation - Windows Explorer.) -- C:\WINDOWS\Explorer.exe [4311736] =>.Microsoft Windows®
[MD5.111474C61232202B5B588D2B512CBB25] - 16/07/2016 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\WINDOWS\System32\rundll32.exe [61952] =>.Microsoft Corporation
[MD5.B315D888C2AC5007D0F87880CE92102A] - 16/07/2016 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\WINDOWS\System32\Wininit.exe [205112] =>.Microsoft Windows Publisher®
[MD5.1B95B6FE7406C76BEE2ED550BBB9E20D] - 05/10/2016 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\WINDOWS\System32\wininet.dll [2254336] =>.Microsoft Corporation
[MD5.955304A906F7A5A7FDCF8180C7E6CF88] - 15/09/2016 - (.Microsoft Corporation - Windows Logon Application.) -- C:\WINDOWS\System32\Winlogon.exe [580096] =>.Microsoft Corporation
[MD5.7C880AA65587F2B274D2633E69CB19C8] - 16/07/2016 - (.Microsoft Corporation - Software Licensing Library.) -- C:\WINDOWS\System32\sppcomapi.dll [390144] =>.Microsoft Corporation
[MD5.227CFE3EDA82029AAC1C088A16297CD7] - 15/09/2016 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\WINDOWS\System32\dnsapi.dll [496872] =>.Microsoft Windows®
[MD5.5D96D7747DB82ECD15E8112E7B921290] - 16/07/2016 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\WINDOWS\System32\drivers\AFD.sys [483168] =>.Microsoft Windows®
[MD5.1D8B6976EC75698485A195A06B2DEBAC] - 16/07/2016 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [23392] =>.Microsoft Windows®
[MD5.9577B2171AD8DBC6A8BAAD75232CBF38] - 16/07/2016 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [74752] =>.Microsoft Corporation
[MD5.67B188419B7018D7956A38C89EFCC70A] - 16/07/2016 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [130560] =>.Microsoft Corporation
[MD5.9C24695688530F014821E30FC8FFD3C9] - 05/10/2016 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\DfsC.sys [113152] =>.Microsoft Corporation
[MD5.E67AAF24F03D9D1B7616C0F5663556CA] - 16/07/2016 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [67072] =>.Microsoft Corporation
[MD5.7D889F2D2464940C2DA8A218F5282F21] - 16/07/2016 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [90624] =>.Microsoft Corporation
[MD5.3FDB0E7AC49A78D21B470863CDA5E342] - 16/07/2016 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [188416] =>.Microsoft Corporation
[MD5.9549298C64834EF719F81C272ED03CD3] - 30/09/2016 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [399712] =>.Microsoft Windows®
[MD5.19B3776EE853B95924BAEDEF14702135] - 16/07/2016 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [217088] =>.Microsoft Corporation
[MD5.ACEE1857335D411CE6765AE681A6F8FB] - 30/09/2016 - (.Microsoft Corporation - NT File System Driver.) -- C:\WINDOWS\System32\drivers\ntfs.sys [1957216] =>.Microsoft Windows®
[MD5.102319D1AB9C8AE57ABF4542C15E46E5] - 16/07/2016 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\WINDOWS\System32\drivers\Parport.sys [81920] =>.Microsoft Corporation
[MD5.26F09741A8FF5EE03C66B33EB5C2A7D2] - 16/07/2016 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [80896] =>.Microsoft Corporation
[MD5.F064A9E33658E8A73280AE8AA5723C59] - 16/07/2016 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [131072] =>.Microsoft Corporation
[MD5.E8DC8115AE2C912694ACB51BD48D417D] - 16/07/2016 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [95072] =>.Microsoft Windows®
[MD5.8FC38A2B3D7A58A69065F43479E848FA] - 16/07/2016 - (.Microsoft Corporation - Volume Shadow Copy driver.) -- C:\WINDOWS\System32\drivers\volsnap.sys [353120] =>.Microsoft Windows®

---\\ Non Microsoft non disabled Windows Services (5) - 4s
O23 - Service: Avast Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe =>.AVAST Software a.s.®
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc®
O23 - Service: Sandboxie Service (SbieSvc) . (.Sandboxie Holdings, LLC - Sandboxie Service.) - C:\Program Files\Sandboxie\SbieSvc.exe =>.Invincea, Inc.®
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe =>.Skype Software Sarl®
O23 - Service: Biometric data protection service (wbiosrvp) . (...) - C:\Windows\System32\wbiosrvp.dll

---\\ Services not Microsoft (SR=Run, SS=Stop) (9) - 70s

SR - Auto [06/09/2016] [ 197128] Avast Antivirus (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe =>.AVAST Software a.s.®
SS - Auto [07/01/2016] [ 144200] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [07/01/2016] [ 144200] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [12/04/2016] [ 146888] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation®
SS - Demand [01/03/2013] [ 118520] Remote Packet Capture Protocol v.0 (experimental) (rpcapd) . (.Riverbed Technology, Inc..) - C:\Program Files\WinPcap\rpcapd.exe =>.Riverbed Technology, Inc.®
SR - Auto [15/06/2016] [ 154256] Sandboxie Service (SbieSvc) . (.Sandboxie Holdings, LLC.) - C:\Program Files\Sandboxie\SbieSvc.exe =>.Invincea, Inc.®
SS - Auto [20/09/2016] [ 324224] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe =>.Skype Software Sarl®
SR - Auto [16/07/2016] [ 345088] Biometric data protection service (wbiosrvp) . (...) - C:\Windows\System32\wbiosrvp.dll

---\\ Task Planned Automatically (14) - 13s
[MD5.A35AE98D2D85B9504789A12860BBB5EC] [APT] [\avast! Emergency Update] (.AVAST Software.) -- C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [1656456] (.Activate.) =>.AVAST Software a.s.®
[MD5.88FBBB1C601A6BC42054E57C2897FA45] [APT] [\GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [144200] (.Activate.) =>.Google Inc®
[MD5.88FBBB1C601A6BC42054E57C2897FA45] [APT] [\GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [144200] (.Activate.) =>.Google Inc®
[MD5.35B3E3E8AB090DB701C1766704DD624D] [APT] [\InternetSD] (.Google Inc..) -- C:\Program Files\Google\Chrome\Application\chrome.exe [966760] (.Activate.) =>.Google Inc®
[MD5.3DD5624F37EEC20B7534514794E98FC9] [APT] [\Opera scheduled Autoupdate 1460640151] (.Opera Software.) -- C:\Program Files\Opera\launcher.exe [896280] (.Activate.) =>.Opera Software ASA®
[MD5.BD4ED9F9E637297417B855B13810D83F] [APT] [\SafeZone scheduled Autoupdate 1461093570] (.Avast Software.) -- C:\Program Files\AVAST Software\SZBrowser\launcher.exe [783320] (.Activate.) =>.AVAST Software s.r.o.®
O39 - APT: \GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job [1092] =>.Google Inc®
O39 - APT: \GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job [1096] =>.Google Inc®
O39 - APT: \avast! Emergency Update - (.AVAST Software.) -- C:\WINDOWS\System32\Tasks\avast! Emergency Update [3158] =>.AVAST Software a.s.®
O39 - APT: \GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore [3384] =>.Google Inc®
O39 - APT: \GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA [3608] =>.Google Inc®
O39 - APT: \InternetSD - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\InternetSD [3718] =>.Google Inc®
O39 - APT: \Opera scheduled Autoupdate 1460640151 - (.Opera Software.) -- C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1460640151 [3958] =>.Opera Software ASA®
O39 - APT: \SafeZone scheduled Autoupdate 1461093570 - (.Avast Software.) -- C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1461093570 [3368] =>.AVAST Software s.r.o.®

---\\ Process running (16) - 3s
[MD5.E2DFD354631E4846E1590D6AF6A8CB4E] - (.Sandboxie Holdings, LLC - Sandboxie Service.) -- C:\Program Files\Sandboxie\SbieSvc.exe [154256] [PID.1896] =>.Invincea, Inc.®
[MD5.F4E0580B5789474385E7ACB189C4AF2C] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128] [PID.468] =>.AVAST Software a.s.®
[MD5.B70BCC55743C5A5BD7C7C6D6A02BB6F9] - (.Realtek Semiconductor Corp. - Realtek Sound Manager.) -- C:\Windows\SOUNDMAN.EXE [604704] [PID.3652] =>.Realtek Semiconductor Corp®
[MD5.CC84336ECBD7A97CEE502360AF5CE915] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastui.exe [9083840] [PID.7716] =>.AVAST Software s.r.o.®
[MD5.6EACC43D0542EF88226FB34B0B12EDB0] - (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe [598552] [PID.5400] =>.Oracle America, Inc.®
[MD5.56B39017734E0ABA996167FEEDD50665] - (.Oracle Corporation - Java Update Checker.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe [935448] [PID.6620] =>.Oracle America, Inc.®
[MD5.35B3E3E8AB090DB701C1766704DD624D] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [966760] [PID.420] =>.Google Inc®
[MD5.35B3E3E8AB090DB701C1766704DD624D] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [966760] [PID.4508] =>.Google Inc®
[MD5.35B3E3E8AB090DB701C1766704DD624D] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [966760] [PID.3608] =>.Google Inc®
[MD5.35B3E3E8AB090DB701C1766704DD624D] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [966760] [PID.8168] =>.Google Inc®
[MD5.35B3E3E8AB090DB701C1766704DD624D] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [966760] [PID.3420] =>.Google Inc®
[MD5.35B3E3E8AB090DB701C1766704DD624D] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [966760] [PID.780] =>.Google Inc®
[MD5.35B3E3E8AB090DB701C1766704DD624D] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [966760] [PID.5272] =>.Google Inc®
[MD5.10CD04CD1BFA69265772090B03185001] - (...) -- C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.8.197.0_x86__kzf8qxf38zg5c\SkypeHost.exe [62464] [PID.2708]
[MD5.35B3E3E8AB090DB701C1766704DD624D] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [966760] [PID.1964] =>.Google Inc®
[MD5.FCB97EB5D8DBA6E5A1A1D7625F134F7D] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\YaSs\Downloads\ZHPDiag3.exe [2418176] [PID.7612] =>.Nicolas Coolman

---\\ Google Chrome, Start,Search,Extensions (22) - 1s
G0 - GCSP: Preferences [User Data\Default][HomePage] http://b2.ijquery11.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://hnwl2nmrbjfqjwe.ru
G0 - GCSP: Preferences [User Data\Default][HomePage] http://latest-423154.aptexof.ru
G0 - GCSP: Preferences [User Data\Default][HomePage] http://puklisi.ru
G0 - GCSP: Preferences [User Data\Default][HomePage] http://ui.ff.avast.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.google-analytics.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://uib.ff.avast.com
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.google.fr
G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [cfhdojbkjhnklbpkdaibdccddilifddb] __MSG_name__ =>.AdblocPlus Plugin
G2 - GCE: Preference [User Data\Default] [cknebhggccemgcnbidipinkifmmegdel]
G2 - GCE: Preference [User Data\Default] [eofcbnmajmjmplflapaojjnihcjkigck] Avast SafePrice
G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [gighmmpiobklfepjocnamgkkbiglidom] __MSG_name__
G2 - GCE: Preference [User Data\Default] [gomekmidlodglbbmalcneegieacbdmki] Avast Online Security
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.

---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (4) - 3s
P2 - EXT FILE: (.striphits surf - a Traffic Exchange System.) -- C:\Users\YaSs\AppData\Roaming\Mozilla\Firefox\Profiles\b4kfvpni.default\extensions\@surfow-WOfRushZT_lqhGzM1aiEdXVOewmxerX7wL97wBljTuZlZXnk6WZS63kaOvJ2TWWmzHX7UGQHV04UjeHZG4G4zN2qtrENmw.xpi
P2 - EXT FILE: (.Alexa Traffic Rank - The Official Alexa Traffic Rank Extens.) -- C:\Users\YaSs\AppData\Roaming\Mozilla\Firefox\Profiles\b4kfvpni.default\extensions\alx-ffdeveloper@amazon.com.xpi
P2 - EXT FILE: (.Firefox Hotfix - Firefox Hotfix: avoid updates that wou.) -- C:\Users\YaSs\AppData\Roaming\Mozilla\Firefox\Profiles\b4kfvpni.default\extensions\firefox-hotfix@mozilla.org.xpi =>.Firefox Hotfix
P2 - EXT: (.iMacros, an Ipswitch Product - iMacros for Firefox.) -- C:\Users\YaSs\AppData\Roaming\Mozilla\Firefox\Profiles\b4kfvpni.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}

---\\ Opera, Plugins,Start,Search (3) - 0s
B2 - EXT: [Facebook Social Toolkit Cracked By Hamoody Mark & ] C:\Users\YaSs\AppData\Roaming\Opera Software\Opera Stable\Extensions\aaclohilgippmpempifigciphemnajkj
B2 - EXT: [Tampermonkey] C:\Users\YaSs\AppData\Roaming\Opera Software\Opera Stable\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo
B2 - EXT: [SearchWay] C:\Users\YaSs\AppData\Roaming\Opera Software\Opera Stable\Extensions\fgldnknlljnfcfgchdijbjmmkdkmnabn

---\\ Internet Explorer Extensions, Start, Search (4) - 0s
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/ =>.Microsoft Corporation
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphan =>.Microsoft Internet Explorer
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 0

---\\ Internet Explorer, Proxy Management (2) - 1s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1

---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=C:\WINDOWS\system32\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation

---\\ Hosts file redirection (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (33)

---\\ Browser Helper Object (BHO) (3) - 0s
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_101\bin\ssv.dll =>.Oracle America, Inc.®
O2 - BHO: LeapFTP Internet Explorer Hook - {A5479DA1-7843-43A7-B5C0-BE342C77B629} . (.LeapWare - LeapFTP IE Plugin.) -- C:\Program Files\LeapFTP 3.0\lftpie.dll {455993C98FC05C4AB5EE223BDA01A07E}
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_101\bin\jp2ssv.dll =>.Oracle America, Inc.®

---\\ Auto loading programs from Registry and folders (20) - 2s
O4 - HKLM\..\Run: [SoundMan] . (.Realtek Semiconductor Corp. - Realtek Sound Manager.) -- C:\WINDOWS\SOUNDMAN.EXE =>.Realtek Semiconductor Corp®
O4 - HKLM\..\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastui.exe =>.AVAST Software s.r.o.®
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe =>.Adobe Systems Incorporated®
O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe =>.Oracle America, Inc.®
O4 - HKCU\..\Run: [C] C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol >nul)&(@copy/b/y C:\WINDOWS\system32\GroupPolicy\Machine\R C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol >nul)&(@attrib +R C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol >nul)&(@start/b gpupdate.exe (.not file.)
O4 - HKCU\..\Run: [EPSON SX218 Series] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGDE.EXE =>.Seiko Epson Corporation
O4 - HKCU\..\Run: [Epson Stylus SX218] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGDE.EXE =>.Seiko Epson Corporation
O4 - HKCU\..\Run: [IDM trial reset] . (...) -- C:\IDMan Trial Reset\IDMan Trial Reset by Chamsoo.exe
O4 - HKCU\..\Run: [EPSON SX218 Series (Copy 1)] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGDE.EXE =>.Seiko Epson Corporation
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Software Sarl®
O4 - HKCU\..\Run: [SandboxieControl] . (.Sandboxie Holdings, LLC - Sandboxie Control.) -- C:\Program Files\Sandboxie\SbieCtrl.exe =>.Invincea, Inc.®
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\System32\OneDriveSetup.exe =>.Microsoft Corporation®
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\System32\OneDriveSetup.exe =>.Microsoft Corporation®
O4 - HKUS\S-1-5-21-2973495360-1647675497-93279711-1001\..\Run: [C] C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol >nul)&(@copy/b/y C:\WINDOWS\system32\GroupPolicy\Machine\R C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol >nul)&(@attrib +R C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol >nul)&(@start/b gpupdate.exe (.not file.)
O4 - HKUS\S-1-5-21-2973495360-1647675497-93279711-1001\..\Run: [EPSON SX218 Series] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGDE.EXE =>.Seiko Epson Corporation
O4 - HKUS\S-1-5-21-2973495360-1647675497-93279711-1001\..\Run: [Epson Stylus SX218] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGDE.EXE =>.Seiko Epson Corporation
O4 - HKUS\S-1-5-21-2973495360-1647675497-93279711-1001\..\Run: [IDM trial reset] . (...) -- C:\IDMan Trial Reset\IDMan Trial Reset by Chamsoo.exe
O4 - HKUS\S-1-5-21-2973495360-1647675497-93279711-1001\..\Run: [EPSON SX218 Series (Copy 1)] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\System32\spool\drivers\w32x86\3\E_FATIGDE.EXE =>.Seiko Epson Corporation
O4 - HKUS\S-1-5-21-2973495360-1647675497-93279711-1001\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Software Sarl®
O4 - HKUS\S-1-5-21-2973495360-1647675497-93279711-1001\..\Run: [SandboxieControl] . (.Sandboxie Holdings, LLC - Sandboxie Control.) -- C:\Program Files\Sandboxie\SbieCtrl.exe =>.Invincea, Inc.®

---\\ Global shortcuts Startup (125) - 19s
O4 - GS\Desktop [Administrator]: 10KHits Exchanger.lnk . (...) C:\Users\YaSs\AppData\Roaming\Microsoft\Installer\{FA26585E-4315-4AF9-9DD1-5AC8CC9152DD}\_F79BA4EADFE7E24CA106C0.exe
O4 - GS\Desktop [Administrator]: Cheat Engine.lnk . (...) C:\Program Files\Cheat Engine 6.5.1\Cheat Engine.exe =>.Cheat Engine®
O4 - GS\Desktop [Administrator]: GSA SEO Indexer.lnk . (.GSA - GSA SEO Indexer.) C:\Program Files\GSA SEO Indexer\SEO_Indexer.exe {00A6B4ABF7E1C8A9231AAA5D6FB711ADF0}
O4 - GS\Desktop [Administrator]: HitLeap Viewer.lnk . (...) C:\Users\YaSs\AppData\Roaming\Microsoft\Installer\{31B12C11-AE4E-479F-8D6D-242DC265368D}\HitLeap_Viewer.exe
O4 - GS\Desktop [Administrator]: LeapFTP.lnk . (.LeapWare - Secure File Transfer Client.) C:\Program Files\LeapFTP 3.0\LeapFTP.exe {455993C98FC05C4AB5EE223BDA01A07E}
O4 - GS\Desktop [Administrator]: Proxy Zone - Shortcut.lnk . (.Copyright © 2016 - Proxy Zone v1.2.) C:\Users\YaSs\Desktop\Proxy Zone v1.2.0.1\Proxy Zone\Proxy Zone.exe
O4 - GS\Desktop [Administrator]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) C:\Users\YaSs\Desktop\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Desktop [Administrator]: Telegram.lnk . (.Telegram Messenger LLP - .) C:\Users\YaSs\AppData\Roaming\Telegram Desktop\Telegram.exe {0084CF3F73EDB10D86} =>.Telegram Messenger LLP
O4 - GS\Desktop [Administrator]: TrafficBot - Shortcut.lnk . (.Diabolic Labs - Traffic Bot.) C:\Users\YaSs\Desktop\TrafficBot\TrafficBot.exe
O4 - GS\Desktop [Administrator]: WYSIWYG Web Builder 11.lnk . (.Pablo Software Solutions - WYSIWYG Web Builder.) C:\Program Files\WYSIWYG Web Builder 11\WebBuilder.exe =>.Pablo Software Solutions
O4 - GS\Desktop [Administrator]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleane.) C:\Users\YaSs\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\YaSs\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Administrator]: GSA SEO Indexer.lnk . (.GSA - GSA SEO Indexer.) C:\Program Files\GSA SEO Indexer\SEO_Indexer.exe {00A6B4ABF7E1C8A9231AAA5D6FB711ADF0}
O4 - GS\Quicklaunch [Administrator]: LeapFTP.lnk . (.LeapWare - Secure File Transfer Client.) C:\Program Files\LeapFTP 3.0\LeapFTP.exe {455993C98FC05C4AB5EE223BDA01A07E}
O4 - GS\sendTo [Administrator]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\sendTo [Administrator]: Sandboxie - DefaultBox.lnk . (.Sandboxie Holdings, LLC - Sandboxie Start.) C:\Program Files\Sandboxie\Start.exe /box:DefaultBox =>.Invincea, Inc.®
O4 - GS\sendTo [Administrator]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\TaskBar [Administrator]: Adobe Photoshop CC 2015 (32 Bit).lnk . (.Adobe Systems, Incorporated - Adobe Photoshop CC 2015.) C:\Program Files\Adobe\Adobe Photoshop CC 2015 (32 Bit)\Photoshop.exe =>.Adobe Systems Incorporated®
O4 - GS\TaskBar [Administrator]: Blend for Visual Studio 2015.lnk . (.Microsoft Corporation - Blend for Visual Studio.) C:\Program Files\Microsoft Visual Studio 14.0\Common7\IDE\Blend.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Administrator]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Administrator]: Opera.lnk . (.Opera Software - Opera Internet Browser.) C:\Program Files\Opera\launcher.exe =>.Opera Software ASA®
O4 - GS\TaskBar [Administrator]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\WINDOWS\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\WINDOWS\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Programs [Administrator]: 10KHits Exchanger.lnk . (...) C:\Users\YaSs\AppData\Roaming\Microsoft\Installer\{FA26585E-4315-4AF9-9DD1-5AC8CC9152DD}\_2EE35FA0677B8A0533BC14.exe
O4 - GS\Programs [Administrator]: HitLeap Viewer.lnk . (...) C:\Users\YaSs\AppData\Roaming\Microsoft\Installer\{31B12C11-AE4E-479F-8D6D-242DC265368D}\favicon.exe
O4 - GS\Programs [Administrator]: LeapFTP.lnk . (.LeapWare - Secure File Transfer Client.) C:\Program Files\LeapFTP 3.0\LeapFTP.exe {455993C98FC05C4AB5EE223BDA01A07E}
O4 - GS\Programs [Administrator]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\YaSs\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\Programs [Administrator]: Optional Features.lnk . (.Microsoft Corporation - Features On Demand Helper.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Programs [Administrator]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) C:\Users\YaSs\Desktop\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Desktop [Guest]: 10KHits Exchanger.lnk . (...) C:\Users\YaSs\AppData\Roaming\Microsoft\Installer\{FA26585E-4315-4AF9-9DD1-5AC8CC9152DD}\_F79BA4EADFE7E24CA106C0.exe
O4 - GS\Desktop [Guest]: Cheat Engine.lnk . (...) C:\Program Files\Cheat Engine 6.5.1\Cheat Engine.exe =>.Cheat Engine®
O4 - GS\Desktop [Guest]: GSA SEO Indexer.lnk . (.GSA - GSA SEO Indexer.) C:\Program Files\GSA SEO Indexer\SEO_Indexer.exe {00A6B4ABF7E1C8A9231AAA5D6FB711ADF0}
O4 - GS\Desktop [Guest]: HitLeap Viewer.lnk . (...) C:\Users\YaSs\AppData\Roaming\Microsoft\Installer\{31B12C11-AE4E-479F-8D6D-242DC265368D}\HitLeap_Viewer.exe
O4 - GS\Desktop [Guest]: LeapFTP.lnk . (.LeapWare - Secure File Transfer Client.) C:\Program Files\LeapFTP 3.0\LeapFTP.exe {455993C98FC05C4AB5EE223BDA01A07E}
O4 - GS\Desktop [Guest]: Proxy Zone - Shortcut.lnk . (.Copyright © 2016 - Proxy Zone v1.2.) C:\Users\YaSs\Desktop\Proxy Zone v1.2.0.1\Proxy Zone\Proxy Zone.exe
O4 - GS\Desktop [Guest]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) C:\Users\YaSs\Desktop\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Desktop [Guest]: Telegram.lnk . (.Telegram Messenger LLP - .) C:\Users\YaSs\AppData\Roaming\Telegram Desktop\Telegram.exe {0084CF3F73EDB10D86} =>.Telegram Messenger LLP
O4 - GS\Desktop [Guest]: TrafficBot - Shortcut.lnk . (.Diabolic Labs - Traffic Bot.) C:\Users\YaSs\Desktop\TrafficBot\TrafficBot.exe
O4 - GS\Desktop [Guest]: WYSIWYG Web Builder 11.lnk . (.Pablo Software Solutions - WYSIWYG Web Builder.) C:\Program Files\WYSIWYG Web Builder 11\WebBuilder.exe =>.Pablo Software Solutions
O4 - GS\Desktop [Guest]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleane.) C:\Users\YaSs\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\YaSs\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Guest]: GSA SEO Indexer.lnk . (.GSA - GSA SEO Indexer.) C:\Program Files\GSA SEO Indexer\SEO_Indexer.exe {00A6B4ABF7E1C8A9231AAA5D6FB711ADF0}
O4 - GS\Quicklaunch [Guest]: LeapFTP.lnk . (.LeapWare - Secure File Transfer Client.) C:\Program Files\LeapFTP 3.0\LeapFTP.exe {455993C98FC05C4AB5EE223BDA01A07E}
O4 - GS\sendTo [Guest]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\sendTo [Guest]: Sandboxie - DefaultBox.lnk . (.Sandboxie Holdings, LLC - Sandboxie Start.) C:\Program Files\Sandboxie\Start.exe /box:DefaultBox =>.Invincea, Inc.®
O4 - GS\sendTo [Guest]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\TaskBar [Guest]: Adobe Photoshop CC 2015 (32 Bit).lnk . (.Adobe Systems, Incorporated - Adobe Photoshop CC 2015.) C:\Program Files\Adobe\Adobe Photoshop CC 2015 (32 Bit)\Photoshop.exe =>.Adobe Systems Incorporated®
O4 - GS\TaskBar [Guest]: Blend for Visual Studio 2015.lnk . (.Microsoft Corporation - Blend for Visual Studio.) C:\Program Files\Microsoft Visual Studio 14.0\Common7\IDE\Blend.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Guest]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Guest]: Opera.lnk . (.Opera Software - Opera Internet Browser.) C:\Program Files\Opera\launcher.exe =>.Opera Software ASA®
O4 - GS\TaskBar [Guest]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\WINDOWS\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\WINDOWS\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Programs [Guest]: 10KHits Exchanger.lnk . (...) C:\Users\YaSs\AppData\Roaming\Microsoft\Installer\{FA26585E-4315-4AF9-9DD1-5AC8CC9152DD}\_2EE35FA0677B8A0533BC14.exe
O4 - GS\Programs [Guest]: HitLeap Viewer.lnk . (...) C:\Users\YaSs\AppData\Roaming\Microsoft\Installer\{31B12C11-AE4E-479F-8D6D-242DC265368D}\favicon.exe
O4 - GS\Programs [Guest]: LeapFTP.lnk . (.LeapWare - Secure File Transfer Client.) C:\Program Files\LeapFTP 3.0\LeapFTP.exe {455993C98FC05C4AB5EE223BDA01A07E}
O4 - GS\Programs [Guest]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\YaSs\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\Programs [Guest]: Optional Features.lnk . (.Microsoft Corporation - Features On Demand Helper.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Programs [Guest]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) C:\Users\YaSs\Desktop\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Desktop [YaSs]: 10KHits Exchanger.lnk . (...) C:\Users\YaSs\AppData\Roaming\Microsoft\Installer\{FA26585E-4315-4AF9-9DD1-5AC8CC9152DD}\_F79BA4EADFE7E24CA106C0.exe
O4 - GS\Desktop [YaSs]: Cheat Engine.lnk . (...) C:\Program Files\Cheat Engine 6.5.1\Cheat Engine.exe =>.Cheat Engine®
O4 - GS\Desktop [YaSs]: GSA SEO Indexer.lnk . (.GSA - GSA SEO Indexer.) C:\Program Files\GSA SEO Indexer\SEO_Indexer.exe {00A6B4ABF7E1C8A9231AAA5D6FB711ADF0}
O4 - GS\Desktop [YaSs]: HitLeap Viewer.lnk . (...) C:\Users\YaSs\AppData\Roaming\Microsoft\Installer\{31B12C11-AE4E-479F-8D6D-242DC265368D}\HitLeap_Viewer.exe
O4 - GS\Desktop [YaSs]: LeapFTP.lnk . (.LeapWare - Secure File Transfer Client.) C:\Program Files\LeapFTP 3.0\LeapFTP.exe {455993C98FC05C4AB5EE223BDA01A07E}
O4 - GS\Desktop [YaSs]: Proxy Zone - Shortcut.lnk . (.Copyright © 2016 - Proxy Zone v1.2.) C:\Users\YaSs\Desktop\Proxy Zone v1.2.0.1\Proxy Zone\Proxy Zone.exe
O4 - GS\Desktop [YaSs]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) C:\Users\YaSs\Desktop\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Desktop [YaSs]: Telegram.lnk . (.Telegram Messenger LLP - .) C:\Users\YaSs\AppData\Roaming\Telegram Desktop\Telegram.exe {0084CF3F73EDB10D86} =>.Telegram Messenger LLP
O4 - GS\Desktop [YaSs]: TrafficBot - Shortcut.lnk . (.Diabolic Labs - Traffic Bot.) C:\Users\YaSs\Desktop\TrafficBot\TrafficBot.exe
O4 - GS\Desktop [YaSs]: WYSIWYG Web Builder 11.lnk . (.Pablo Software Solutions - WYSIWYG Web Builder.) C:\Program Files\WYSIWYG Web Builder 11\WebBuilder.exe =>.Pablo Software Solutions
O4 - GS\Desktop [YaSs]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleane.) C:\Users\YaSs\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
O4 - GS\Desktop [YaSs]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\YaSs\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [YaSs]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [YaSs]: GSA SEO Indexer.lnk . (.GSA - GSA SEO Indexer.) C:\Program Files\GSA SEO Indexer\SEO_Indexer.exe {00A6B4ABF7E1C8A9231AAA5D6FB711ADF0}
O4 - GS\Quicklaunch [YaSs]: LeapFTP.lnk . (.LeapWare - Secure File Transfer Client.) C:\Program Files\LeapFTP 3.0\LeapFTP.exe {455993C98FC05C4AB5EE223BDA01A07E}
O4 - GS\sendTo [YaSs]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\sendTo [YaSs]: Sandboxie - DefaultBox.lnk . (.Sandboxie Holdings, LLC - Sandboxie Start.) C:\Program Files\Sandboxie\Start.exe /box:DefaultBox =>.Invincea, Inc.®
O4 - GS\sendTo [YaSs]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\TaskBar [YaSs]: Adobe Photoshop CC 2015 (32 Bit).lnk . (.Adobe Systems, Incorporated - Adobe Photoshop CC 2015.) C:\Program Files\Adobe\Adobe Photoshop CC 2015 (32 Bit)\Photoshop.exe =>.Adobe Systems Incorporated®
O4 - GS\TaskBar [YaSs]: Blend for Visual Studio 2015.lnk . (.Microsoft Corporation - Blend for Visual Studio.) C:\Program Files\Microsoft Visual Studio 14.0\Common7\IDE\Blend.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [YaSs]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [YaSs]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [YaSs]: Opera.lnk . (.Opera Software - Opera Internet Browser.) C:\Program Files\Opera\launcher.exe =>.Opera Software ASA®
O4 - GS\TaskBar [YaSs]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\WINDOWS\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\TaskBar [YaSs]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\WINDOWS\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Programs [YaSs]: 10KHits Exchanger.lnk . (...) C:\Users\YaSs\AppData\Roaming\Microsoft\Installer\{FA26585E-4315-4AF9-9DD1-5AC8CC9152DD}\_2EE35FA0677B8A0533BC14.exe
O4 - GS\Programs [YaSs]: HitLeap Viewer.lnk . (...) C:\Users\YaSs\AppData\Roaming\Microsoft\Installer\{31B12C11-AE4E-479F-8D6D-242DC265368D}\favicon.exe
O4 - GS\Programs [YaSs]: LeapFTP.lnk . (.LeapWare - Secure File Transfer Client.) C:\Program Files\LeapFTP 3.0\LeapFTP.exe {455993C98FC05C4AB5EE223BDA01A07E}
O4 - GS\Programs [YaSs]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\YaSs\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\Programs [YaSs]: Optional Features.lnk . (.Microsoft Corporation - Features On Demand Helper.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Programs [YaSs]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) C:\Users\YaSs\Desktop\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\CommonDesktop [Public]: Adobe Application Manager.lnk . (.Adobe Systems Incorporated - Adobe Application Manager.) C:\Program Files\Common Files\Adobe\OOBE\PDApp\core\PDapp.exe --appletID=CCM_UI --appletVersion=1.0 --workflow=CCM_workflow_launch =>.Adobe Systems Incorporated®
O4 - GS\CommonDesktop [Public]: Avast Antivirus Gratuit.lnk . (.AVAST Software - avast! Antivirus.) C:\Program Files\AVAST Software\Avast\AvastUI.exe =>.AVAST Software s.r.o.®
O4 - GS\CommonDesktop [Public]: Avast SafeZone Browser.lnk . (.Avast Software - Avast SafeZone Browser.) C:\Program Files\AVAST Software\SZBrowser\launcher.exe =>.AVAST Software s.r.o.®
O4 - GS\CommonDesktop [Public]: Camtasia Studio 8.lnk . (.TechSmith Corporation - Camtasia Studio.) C:\Program Files\TechSmith\Camtasia Studio 8\CamtasiaStudio.exe =>.TechSmith Corporation®
O4 - GS\CommonDesktop [Public]: Elite Proxy Switcher.lnk . (.my-proxy.com - Elite Proxy Switcher.) C:\Program Files\Didsoft\Elite Proxy Switcher\EPS.exe {00A5C744ACA387ABFDAE381A1955EBE3FC}
O4 - GS\CommonDesktop [Public]: EPSON Scan.lnk . (.SEIKO EPSON CORP. - EPSON Scan.) C:\Windows\twain_32\escndv\escndv.exe =>.SEIKO EPSON CORP.
O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\CommonDesktop [Public]: InstaTrader.lnk . (.MetaQuotes Software Corp. - MetaTrader.) C:\Program Files\InstaTrader\terminal.exe =>.MetaQuotes Software Corp.®
O4 - GS\CommonDesktop [Public]: LiteForex MT4 Terminal.lnk . (.MetaQuotes Software Corp. - MetaTrader.) C:\Program Files\LiteForex MT4 Terminal\terminal.exe =>.MetaQuotes Software Corp.®
O4 - GS\CommonDesktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\CommonDesktop [Public]: OctaFX.lnk . (.MetaQuotes Software Corp. - MetaTrader.) C:\Program Files\OctaFX\terminal.exe =>.MetaQuotes Software Corp.®
O4 - GS\CommonDesktop [Public]: Opera.lnk . (.Opera Software - Opera Internet Browser.) C:\Program Files\Opera\launcher.exe =>.Opera Software ASA®
O4 - GS\CommonDesktop [Public]: Otohits App.lnk . (.Otohits Network - Otohits App.) C:\OtohitsNetwork\OtohitsApp\Otohits.App.exe
O4 - GS\CommonDesktop [Public]: RogueKiller.lnk . (...) C:\Program Files\RogueKiller\RogueKiller.exe =>.Adlice®
O4 - GS\CommonDesktop [Public]: Skype.lnk . (...) C:\WINDOWS\Installer\{FC965A47-4839-40CA-B618-18F486F042C6}\SkypeIcon.exe
O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files\VideoLAN\VLC\vlc.exe =>.VideoLAN®
O4 - GS\CommonDesktop [Public]: XM MT4.lnk . (.MetaQuotes Software Corp. - MetaTrader.) C:\Program Files\XM MT4\terminal.exe =>.MetaQuotes Software Corp.®
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Programs [Public]: 10KHits Exchanger.lnk . (...) C:\Users\YaSs\AppData\Roaming\Microsoft\Installer\{FA26585E-4315-4AF9-9DD1-5AC8CC9152DD}\_2EE35FA0677B8A0533BC14.exe
O4 - GS\Programs [Public]: HitLeap Viewer.lnk . (...) C:\Users\YaSs\AppData\Roaming\Microsoft\Installer\{31B12C11-AE4E-479F-8D6D-242DC265368D}\favicon.exe
O4 - GS\Programs [Public]: LeapFTP.lnk . (.LeapWare - Secure File Transfer Client.) C:\Program Files\LeapFTP 3.0\LeapFTP.exe {455993C98FC05C4AB5EE223BDA01A07E}
O4 - GS\Programs [Public]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\YaSs\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\Programs [Public]: Optional Features.lnk . (.Microsoft Corporation - Features On Demand Helper.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Programs [Public]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) C:\Users\YaSs\Desktop\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Math Input Panel Accessory.) C:\Program Files\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\WINDOWS\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Quick Assist.lnk . (.Microsoft Corporation - Quick Assist.) C:\WINDOWS\system32\quickassist.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\WINDOWS\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Steps Recorder.) C:\WINDOWS\system32\psr.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) C:\WINDOWS\system32\charmap.exe =>.Microsoft Corporation

---\\ Lop.com/Domain Hijackers (4) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = domain.name
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{81a1fc6e-7310-46b9-a7e5-e05597dc6a5c}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{81a1fc6e-7310-46b9-a7e5-e05597dc6a5c}: DhcpDomain = domain.name

---\\ Extra protocols (22) - 1s
O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll =>.Microsoft Corporation
O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll =>.Microsoft Corporation
O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation

---\\ Software installed (131) - 27s
O42 - Logiciel: 10KHits Exchanger 0.9.8 - (.10KHits.) [HKLM] -- {FA26585E-4315-4AF9-9DD1-5AC8CC9152DD}
O42 - Logiciel: Active Directory Authentication Library pour SQL Server (x86) - (.Microsoft Corporation.) [HKLM] -- {245D42A5-AD68-47E1-8AF4-F2CF56DA7AEE} =>.Microsoft Corporation
O42 - Logiciel: Adobe Photoshop CC 2015 - (.Adobe Systems Incorporated.) [HKLM] -- {2D99B50E-431D-4AA8-85C1-172A6F8BCF01} =>.Adobe Systems Incorporated®
O42 - Logiciel: Application Insights Tools for Visual Studio 2015 - (.Microsoft Corporation.) [HKLM] -- {981F324E-98F4-4784-B76F-04E92039F3F6} =>.Microsoft Corporation
O42 - Logiciel: Applications hybrides multi-appareils en C# - Modèles - FRA - (.Microsoft Corporation.) [HKLM] -- {9222F12D-9DD6-3F84-BF8D-A70B9BB4ECAB} =>.Microsoft Corporation
O42 - Logiciel: Assemblys du Kit de développement logiciel (SDK) Windows Phone 8.0 pour Vis - (.Microsoft Corporation.) [HKLM] -- {11EC1574-3EC8-3386-B51D-42C7556A94D0} =>.Microsoft Corporation
O42 - Logiciel: Avast Antivirus Gratuit - (.AVAST Software.) [HKLM] -- Avast =>.AVAST Software a.s.®
O42 - Logiciel: Azure AD Authentication Connected Service - (.Microsoft Corporation.) [HKLM] -- {3FEAC561-1CF6-41D6-B0F3-BECDD9C88A1B} =>.Microsoft Corporation
O42 - Logiciel: AzureTools.Notifications - (.Microsoft Corporation.) [HKLM] -- {1E5CA362-39B6-4BD0-B9C0-69CF15F0FEA2} =>.Microsoft Corporation
O42 - Logiciel: Blend for Visual Studio SDK for .NET 4.5 - (.Microsoft Corporation.) [HKLM] -- {37E53780-3944-4A6A-842F-727128E8616E} =>.Microsoft Corporation
O42 - Logiciel: Camtasia Studio 8 - (.TechSmith Corporation.) [HKLM] -- {AF33D0D2-2627-4AC8-8473-FDBB7892129C} =>.TechSmith Corporation
O42 - Logiciel: Cheat Engine 6.5.1 - (.Cheat Engine.) [HKLM] -- Cheat Engine 6.5.1_is1 {1121C8E7AC6869E3322CCE5E3451CF9142D9} =>.Cheat Engine
O42 - Logiciel: Composants requis pour SSDT - (.Microsoft Corporation.) [HKLM] -- {FAFA0B40-AF76-4158-9DFA-1D2052CD0963} =>.Microsoft Corporation
O42 - Logiciel: Composants requis pour SSDT RC0 - (.Microsoft Corporation.) [HKLM] -- {927D0263-3C15-469C-A144-402D09450030} =>.Microsoft Corporation
O42 - Logiciel: Dotfuscator and Analytics Community Edition 5.19.1 - (.PreEmptive Solutions.) [HKLM] -- {2A7F99F6-88A4-4B44-B350-41C0B147A39C} =>.PreEmptive Solutions
O42 - Logiciel: Elite Proxy Switcher 1.28 - (.http://www.didsoft.com.) [HKLM] -- Elite Proxy Switcher_is1 {00A5C744ACA387ABFDAE381A1955EBE3FC} =>.http://www.didsoft.com
O42 - Logiciel: Entity Framework 6.1.3 Tools for Visual Studio 2015 Update 1 - (.Microsoft Corporation.) [HKLM] -- {2A56910C-69C8-495D-8ED8-9080F0A14E58} =>.Microsoft Corporation
O42 - Logiciel: EPSON Scan - (.Seiko Epson Corporation.) [HKLM] -- EPSON Scanner =>.SEIKO EPSON Corporation®
O42 - Logiciel: EPSON SX218 Series Printer Uninstall - (.SEIKO EPSON Corporation.) [HKLM] -- EPSON SX218 Series =>.SEIKO EPSON Corporation®
O42 - Logiciel: FiddlerCoreAPI - (...) [HKCU] -- FiddlerCoreAPI
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome =>.Google Inc®
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: GSA SEO Indexer v2.09 - (.GSA Software.) [HKLM] -- GSA SEO Indexer_is1 {00A6B4ABF7E1C8A9231AAA5D6FB711ADF0}
O42 - Logiciel: HitLeap Viewer 2.8 - (.HitLeap Ltd..) [HKLM] -- {31B12C11-AE4E-479F-8D6D-242DC265368D} =>.HitLeap Ltd.
O42 - Logiciel: IIS 10.0 Express - (.Microsoft Corporation.) [HKLM] -- {72DE5A4E-9E1B-4E07-B42F-D68A11158C27} =>.Microsoft Corporation
O42 - Logiciel: IIS Express Application Compatibility Database for x86 - (...) [HKLM] -- {ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb
O42 - Logiciel: InstaTrader - (.MetaQuotes Software Corp..) [HKLM] -- InstaTrader =>.MetaQuotes Software Corp.®
O42 - Logiciel: Java 8 Update 101 - (.Oracle Corporation.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F32180101F0} =>.Oracle Corporation
O42 - Logiciel: Java Auto Updater - (.Oracle Corporation.) [HKLM] -- {4A03706F-666A-4037-7777-5F2748764D10} =>.Oracle Corporation
O42 - Logiciel: LeapFTP 3.0 - (.LeapWare.) [HKLM] -- LeapFTP 3.0_is1
O42 - Logiciel: LiteForex MT4 Terminal - (.MetaQuotes Software Corp..) [HKLM] -- LiteForex MT4 Terminal =>.MetaQuotes Software Corp.®
O42 - Logiciel: Microsoft .NET Core 5.0 SDK - (.Microsoft Corporation.) [HKLM] -- {C8AC11BB-B680-44A2-ACE4-2D88D6A711CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft .NET Version Manager (x86) 1.0.0-beta5 - (.Microsoft Corporation.) [HKLM] -- {2a375a89-9d97-35b7-917d-92f1ea73080d} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Agents for Visual Studio 2015 Preview - (.Microsoft Corporation.) [HKLM] -- {CE37CE67-2660-30EE-805B-78829CC3554B} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Agents pour Visual Studio 2015 Preview - FRA - (.Microsoft Corporation.) [HKLM] -- {643108C8-AF54-39A4-AFC2-F8290D9BB870} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Azure Mobile Services Connected Service - (.Microsoft Corporation.) [HKLM] -- {A4495E4F-5218-48FB-8AD2-F3076011B9E1} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Azure Mobile Services SDK V2.0 - (.Microsoft Corporation.) [HKLM] -- {A00EC54A-CE16-4CF6-A14A-5CF81A1FE03F} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Azure Mobile Services Tools for Visual Studio - v1.4 - (.Microsoft Corporation.) [HKLM] -- {5536AAD4-740A-4577-843D-4281D3F30726} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Azure Shared Components for Visual Studio 2015 - v1.7 - (.Microsoft Corporation.) [HKLM] -- {7F6E1C5A-25DF-4352-A9A4-B1CE272CA67F} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Azure Storage Connected Service - (.Microsoft Corporation.) [HKLM] -- {6B3F93BC-7716-4D97-8B80-1334DA37DDE1} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Blend for Visual Studio 2015 - (.Microsoft Corporation.) [HKLM] -- {18073ADD-8C90-3AB7-8B87-BD3B10F3232B} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Blend pour Visual Studio 2015 - FRA - (.Microsoft Corporation.) [HKLM] -- {209865AE-2AAC-3F7B-B0FD-B2D73A462CC9} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Build Tools 14.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {DF27D91D-516E-4DA1-92AC-7D7D59B2D99E} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Build Tools Language Resources 14.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {CBE7F62C-646C-46C3-9AB4-A3F71E5A68CC} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Expression Blend SDK for .NET 4 - (.Microsoft Corporation.) [HKLM] -- {7B6B35D5-404D-498E-95D0-3CCB2B2FC6F9} =>.Microsoft Corporation
O42 - Logiciel: Microsoft NuGet - Visual Studio 2015 - (.Microsoft Corporation.) [HKLM] -- {769EF2AA-ECB5-3686-A387-8980102F79B8} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Portable Library Multi-Targeting Pack - (.Microsoft Corporation.) [HKLM] -- {1634C655-2398-35C0-89BE-291449A72F88} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Portable Library Multi-Targeting Pack Language Pack - fra - (.Microsoft Corporation.) [HKLM] -- {0F61946A-F32F-3F6B-8C5F-9C09C14AADFC} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation
O42 - Logiciel: Microsoft System CLR Types for SQL Server 2014 - (.Microsoft Corporation.) [HKLM] -- {091CE6AA-2753-4F6E-AD1C-0E875744EB54} =>.Microsoft Corporation
O42 - Logiciel: Microsoft System CLR Types pour SQL Server 2016 RC0 - (.Microsoft Corporation.) [HKLM] -- {C7661733-43D1-4551-8DD4-09B0CB36BFA9} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Web Deploy 3.6 - (.Microsoft Corporation.) [HKLM] -- {4B604E42-B6D7-4957-B5A5-CC7450D8E1EB} =>.Microsoft Corporation
O42 - Logiciel: Microsoft.VisualStudio.Office365 - (.Microsoft Corporation.) [HKLM] -- {3196EC29-B75D-4EE3-8AB0-46418BC31483} =>.Microsoft Corporation
O42 - Logiciel: Module linguistique de Dotfuscator and Analytics Community Edition 5.19.1 f - (.PreEmptive Solutions.) [HKLM] -- {FE31FA63-F192-4B89-A528-AB7AED6FC857} =>.PreEmptive Solutions
O42 - Logiciel: Module linguistique de la visionneuse d'aide Microsoft 2.2 - FRA - (.Microsoft Corporation.) [HKLM] -- {FF80D769-287C-3B77-9756-4ACF0362733B} =>.Microsoft Corporation
O42 - Logiciel: Module linguistique des composants partagés Microsoft Azure pour Visual Stu - (.Microsoft Corporation.) [HKLM] -- {A1DB413D-427C-4147-891D-6A2FC5F7EA15} =>.Microsoft Corporation
O42 - Logiciel: Module linguistique Microsoft Azure Mobile Services Tools pour Visual Studi - (.Microsoft Corporation.) [HKLM] -- {DD61292F-143F-4424-B78B-B229F7B99CF7} =>.Microsoft Corporation
O42 - Logiciel: Mozilla Firefox 47.0.1 (x86 en-US) - (.Mozilla.) [HKLM] -- Mozilla Firefox 47.0.1 (x86 en-US) =>.Mozilla Corporation®
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService =>.Mozilla
O42 - Logiciel: MSBuild/NuGet Integration 14.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {13FE8B50-B340-4FDA-BB6E-AA1F5FAB8205} =>.Microsoft Corporation
O42 - Logiciel: OctaFX - (.MetaQuotes Software Corp..) [HKLM] -- OctaFX =>.MetaQuotes Software Corp.®
O42 - Logiciel: Opera Stable 40.0.2308.81 - (.Opera Software.) [HKLM] -- Opera 40.0.2308.81 =>.Opera Software ASA®
O42 - Logiciel: OtohitsApp - (.Otohits Network.) [HKLM] -- {9B85C70F-D649-4290-8C1D-5356A5262066}_is1
O42 - Logiciel: PreEmptive Analytics Client French Language Pack - (.PreEmptive Solutions.) [HKLM] -- {B7B58EF9-6307-4DCF-8276-2F17D1E6DE69} =>.PreEmptive Solutions
O42 - Logiciel: PreEmptive Analytics Visual Studio Components - (.PreEmptive Solutions.) [HKLM] -- {436A18DD-5F2C-4B3C-985E-AD3C13B0CC25} =>.PreEmptive Solutions
O42 - Logiciel: Realtek AC'97 Audio - (...) [HKLM] -- {FB08F381-6533-4108-B7DD-039E11FBC27E}
O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} =>.Realtek Semiconductor Corp®
O42 - Logiciel: RogueKiller version 12.7.3.0 - (.Adlice Software.) [HKLM] -- 8B3D7924-ED89-486B-8322-E8594065D5CB_is1 =>.Adlice®
O42 - Logiciel: Roslyn Language Services - x86 - (.Microsoft Corporation.) [HKLM] -- {263EF873-F5D0-3134-A962-356C21A3510F} =>.Microsoft Corporation
O42 - Logiciel: Roslyn Language Services - x86 - (.Microsoft Corporation.) [HKLM] -- {D8532606-92B2-3D64-84E5-744BFB08411E} =>.Microsoft Corporation
O42 - Logiciel: SafeZone Stable 1.51.2220.62 - (.Avast Software.) [HKLM] -- SafeZone 1.51.2220.62 =>.AVAST Software s.r.o.®
O42 - Logiciel: Sandboxie 5.12 (32-bit) - (.Sandboxie Holdings, LLC.) [HKLM] -- Sandboxie =>.Invincea, Inc.®
O42 - Logiciel: Skype™ 7.29 - (.Skype Technologies S.A..) [HKLM] -- {FC965A47-4839-40CA-B618-18F486F042C6} =>.Skype Technologies S.A.
O42 - Logiciel: Telegram Desktop version 0.10.8 - (.Telegram Messenger LLP.) [HKCU] -- {53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1 =>.Telegram Messenger LLP
O42 - Logiciel: ThinLinc Client 4.6.0 - (...) [HKLM] -- tlclient
O42 - Logiciel: Tools for .Net 3.5 - (.Microsoft Corporation.) [HKLM] -- {1690CE56-2231-4E59-9006-A0876D949EA8} =>.Microsoft Corporation
O42 - Logiciel: Tools for .Net 3.5 - FRA Lang Pack - (.Microsoft Corporation.) [HKLM] -- {C37962EE-EE24-4E9F-8A41-514ACD79177C} =>.Microsoft Corporation
O42 - Logiciel: TypeScript Power Tool - (.Microsoft Corporation.) [HKLM] -- {60890089-588B-4362-B9C5-A9C11D6E5DD1} =>.Microsoft Corporation
O42 - Logiciel: Unity Web Player - (.Unity Technologies ApS.) [HKCU] -- UnityWebPlayer =>.Unity Technologies ApS
O42 - Logiciel: Update for (KB2504637) - (.Microsoft Corporation.) [HKLM] -- {CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637 =>.Microsoft Corporation
O42 - Logiciel: Visual C++ Compiler/Tools X86 Base Package - (.Microsoft Corporation.) [HKLM] -- {99C9FABF-C085-38C9-B2DA-7E4943471D31} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ Compiler/Tools X86 Base Package - (.Microsoft Corporation.) [HKLM] -- {A5E71A84-9BAB-3A96-A5F8-62AD16E09E56} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ Compiler/Tools X86 Base Resource Package - (.Microsoft Corporation.) [HKLM] -- {C9231681-EC95-3B17-AA96-7626235F09AF} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ Compiler/Tools X86 Base Resource Package - (.Microsoft Corporation.) [HKLM] -- {E90D7341-7451-359C-BE31-5CF0C94D9306} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Base Package - (.Microsoft Corporation.) [HKLM] -- {ECC8F805-E519-3314-8C79-DC6CAC3E64DC} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Base Resource Package - (.Microsoft Corporation.) [HKLM] -- {CDC01AE0-9782-32EC-93EA-4BE6A93BB373} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Base Resource Package - (.Microsoft Corporation.) [HKLM] -- {EA440F0D-0860-3C88-9926-6E237525524A} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Common Package - (.Microsoft Corporation.) [HKLM] -- {E57E4E87-61B6-3FDC-A4D3-BAE317678B74} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Common Resource Package - (.Microsoft Corporation.) [HKLM] -- {39A0D1EC-8020-31C8-8EF6-24359C9C58D5} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Core Package - (.Microsoft Corporation.) [HKLM] -- {AB3903D7-8CC4-3708-9558-93F68CED88C5} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Core Professional Plus Resource Package - (.Microsoft Corporation.) [HKLM] -- {19055D06-F01E-3BF2-987B-DF9BC14C69FC} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Core Professional Plus Resource Package - (.Microsoft Corporation.) [HKLM] -- {1E315887-E33F-3726-A9AC-A3A56B0DF4B3} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Core Professional Plus Resource Package - (.Microsoft Corporation.) [HKLM] -- {3CAA7C8A-EF8D-3F7B-9710-197F5C606255} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Core Professional Plus Resource Package - (.Microsoft Corporation.) [HKLM] -- {65FFE121-03FA-345D-8149-50AC21A4F985} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Core Professional Plus Resource Package - (.Microsoft Corporation.) [HKLM] -- {705D1F4A-2E06-3C3C-A1C6-B7572D650418} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Core Professional Plus Resource Package - (.Microsoft Corporation.) [HKLM] -- {B2BA21D5-8973-3AA6-936D-F2C51BF6D764} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Core Professional Plus Resource Package - (.Microsoft Corporation.) [HKLM] -- {BC0FB8BF-E57B-30AB-8B77-DC11C75B4212} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Core Professional Plus Resource Package - (.Microsoft Corporation.) [HKLM] -- {C915EA4E-24C9-3398-983C-CB9B9220B1EE} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Core Professional Plus Resource Package - (.Microsoft Corporation.) [HKLM] -- {CAC666AC-1986-3B50-9670-552432D5B88A} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Core Professional Plus Resource Package - (.Microsoft Corporation.) [HKLM] -- {D84B1C7A-7C28-3133-AA25-2D36763182AD} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Core Professional Plus Resource Package - (.Microsoft Corporation.) [HKLM] -- {E413256C-F028-3C5E-B9B2-728ED1F544C6} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Core Professional Plus Resource Package - (.Microsoft Corporation.) [HKLM] -- {E6597C44-DF3C-3BE6-A5A1-28E6DAECBA30} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Core Professional Plus Resource Package - (.Microsoft Corporation.) [HKLM] -- {EB4B3254-5483-3C7B-AC56-D49231C3B51A} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Core Professional Plus Resource Package - (.Microsoft Corporation.) [HKLM] -- {EF3EE0BB-DDB9-32F0-98CA-32C4B6C47D7E} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Debugger Package - (.Microsoft Corporation.) [HKLM] -- {78EC1C10-1AD9-35ED-9F4D-AC0238AE8A2B} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Debugger Resource Package - (.Microsoft Corporation.) [HKLM] -- {096A32D2-E056-3AEA-928D-B2361E98234F} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ IDE Professional Core Package - (.Microsoft Corporation.) [HKLM] -- {3101E866-DD09-3926-8929-C6B580B951C5} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ Library PGO X86 Package - (.Microsoft Corporation.) [HKLM] -- {2E6C63B5-A075-3591-96CA-F7FEA8226482} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ MSBuild ARM Package - (.Microsoft Corporation.) [HKLM] -- {030702BF-6F52-356B-A223-F9CA15B465DA} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ MSBuild Base Package - (.Microsoft Corporation.) [HKLM] -- {A563F0A7-CF99-37E6-A917-CD6A2509F79C} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ MSBuild Base Resource Package - (.Microsoft Corporation.) [HKLM] -- {CEC9FCE6-B37C-34D2-81AB-5248542B4BE7} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ MSBuild X64 Package - (.Microsoft Corporation.) [HKLM] -- {2AA9034E-6735-30BD-92A4-A18791D1616F} =>.Microsoft Corporation
O42 - Logiciel: Visual C++ MSBuild X86 Package - (.Microsoft Corporation.) [HKLM] -- {ADB88179-BECB-3FA3-AB20-9362E8A2626C} =>.Microsoft Corporation
O42 - Logiciel: Visual F# 4.0 SDK Language Pack - FRA - (.Microsoft Corporation.) [HKLM] -- {2467A7FE-F3AE-3DF8-847E-C592943BC471} =>.Microsoft Corporation
O42 - Logiciel: Visual F# 4.0 VS Language Pack - FRA - (.Microsoft Corporation.) [HKLM] -- {6D8235B9-ADE2-3052-ADFC-55B3E3BCAE00} =>.Microsoft Corporation
O42 - Logiciel: Visual Studio 2012 Verification SDK - (.Microsoft Corporation.) [HKLM] -- {3DCCF375-3903-35C7-967A-9EFEE9ED9A77} =>.Microsoft Corporation
O42 - Logiciel: Visual Studio 2015 Update 2 (KB3022398) - (.Microsoft Corporation.) [HKLM] -- {78c1b501-a6eb-4f29-88c5-84189564827e} =>.Microsoft Corporation®
O42 - Logiciel: Visual Studio Graphics Analyzer - (.Microsoft Corporation.) [HKLM] -- {C70EC402-4FAA-3B06-9BE6-77C52DBCD9B3} =>.Microsoft Corporation
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM] -- VLC media player =>.VideoLAN
O42 - Logiciel: VS Update core components - (.Microsoft Corporation.) [HKLM] -- {6A878817-D626-305A-BE8D-94C93F70E27A} =>.Microsoft Corporation
O42 - Logiciel: WCF Data Services 5.6.4 FRA Language Pack - (.Microsoft Corporation.) [HKLM] -- {314D548C-60FF-48F8-BEAE-C94946706349} =>.Microsoft Corporation
O42 - Logiciel: WCF Data Services 5.6.4 Runtime - (.Microsoft Corporation.) [HKLM] -- {DB85E7BD-B2DD-43D4-B3C0-23D7B527B597} =>.Microsoft Corporation
O42 - Logiciel: Windows Driver Package - MediaTek Inc. (usbser) Ports (05/30/2011 1.1123.0 - (.MediaTek Inc..) [HKLM] -- 9F57DFB5B4E90E617CAF60510F56318C1F80CC8C =>.Microsoft Windows®
O42 - Logiciel: Windows Espc Package - (.Microsoft Corporation.) [HKLM] -- {42AF2A8C-6EBB-3D2E-9BF1-6135379FBABC} =>.Microsoft Corporation
O42 - Logiciel: Windows Espc Resource Package - (.Microsoft Corporation.) [HKLM] -- {FC94D188-1E08-3707-9D23-F41178D44664} =>.Microsoft Corporation
O42 - Logiciel: Windows Software Development Kit DirectX x86 Remote - (.Microsoft Corporation.) [HKLM] -- {A1CB8286-CFB3-A985-D799-721A0F2A27F3} =>.Microsoft Corporation
O42 - Logiciel: Windows Software Development Kit for Windows Store Apps DirectX x86 Remote - (.Microsoft Corporation.) [HKLM] -- {56AD3004-0B49-967F-F682-B05650B61A78} =>.Microsoft Corporation
O42 - Logiciel: WinPcap 4.1.3 - (.Riverbed Technology, Inc..) [HKLM] -- WinPcapInst =>.Riverbed Technology, Inc.
O42 - Logiciel: WinRAR 5.40 (32-bit) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver =>.win.rar GmbH®
O42 - Logiciel: WYSIWYG Web Builder 11 - (...) [HKLM] -- WYSIWYG_Web_Builder_11
O42 - Logiciel: XM MT4 - (.MetaQuotes Software Corp..) [HKLM] -- XM MT4 =>.MetaQuotes Software Corp.®

---\\ HKCU & HKLM Software Keys (97) - 27s
HKLM\SOFTWARE\Adobe =>.Adobe
HKLM\SOFTWARE\AVAST Software =>.AVAST Software
HKLM\SOFTWARE\Cendio
HKLM\SOFTWARE\Comodo =>.COMODO
HKLM\SOFTWARE\ComodoGroup =>.ComodoGroup
HKLM\SOFTWARE\EPSON =>.EPSON
HKLM\SOFTWARE\Google =>.Google
HKLM\SOFTWARE\GSA
HKLM\SOFTWARE\IM Providers
HKLM\SOFTWARE\Intel =>.Intel
HKLM\SOFTWARE\Internet Download Manager
HKLM\SOFTWARE\JavaSoft =>.JavaSoft
HKLM\SOFTWARE\JreMetrics =>.JreMetrics
HKLM\SOFTWARE\Jump Desktop
HKLM\SOFTWARE\LeapWare
HKLM\SOFTWARE\Link-Assistant.Com
HKLM\SOFTWARE\Macromedia =>.Macromedia
HKLM\SOFTWARE\MetaQuotes Software =>.MetaQuotes Software
HKLM\SOFTWARE\Mozilla =>.Mozilla
HKLM\SOFTWARE\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\NuGet
HKLM\SOFTWARE\ODBC
HKLM\SOFTWARE\OEM =>.OEM
HKLM\SOFTWARE\Opera Software =>.Opera Software
HKLM\SOFTWARE\Partner
HKLM\SOFTWARE\PreEmptive Solutions =>.PreEmptive Solutions
HKLM\SOFTWARE\Realtek =>.Realtek
HKLM\SOFTWARE\Realtek Semiconductor Corp. =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\RegisteredApplications
HKLM\SOFTWARE\RTLSetup
HKLM\SOFTWARE\Skype =>.Skype
HKLM\SOFTWARE\SNC =>.SNC
HKLM\SOFTWARE\Sony =>.Sony
HKLM\SOFTWARE\SRS Labs =>.SRS Labs
HKLM\SOFTWARE\TechSmith =>.TechSmith
HKLM\SOFTWARE\ThinPrint =>.ThinPrint
HKLM\SOFTWARE\VideoLAN =>.VideoLAN
HKLM\SOFTWARE\VMware, Inc. =>.VMware, Inc.
HKLM\SOFTWARE\WinPcap
HKLM\SOFTWARE\WinRAR =>.WinRAR
HKLM\SOFTWARE\Wow6432Node
HKCU\SOFTWARE\Adobe =>.Adobe
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\ASProtect
HKCU\SOFTWARE\AVAST Software =>.AVAST Software
HKCU\SOFTWARE\BCGSoft
HKCU\SOFTWARE\Caphyon =>.Caphyon
HKCU\SOFTWARE\Cendio
HKCU\SOFTWARE\Cheat Engine =>.Cheat Engine
HKCU\SOFTWARE\DownloadManager
HKCU\SOFTWARE\ej-technologies
HKCU\SOFTWARE\EPSON =>.EPSON
HKCU\SOFTWARE\Extensoft =>.Extensoft
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\GSA SEO Indexer
HKCU\SOFTWARE\HitLeap
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\iMacros
HKCU\SOFTWARE\JavaSoft =>.JavaSoft
HKCU\SOFTWARE\Jump Desktop
HKCU\SOFTWARE\JumpDesktop
HKCU\SOFTWARE\Macromedia =>.Macromedia
HKCU\SOFTWARE\Magicbit
HKCU\SOFTWARE\MainConcept =>.MainConcept
HKCU\SOFTWARE\MetaQuotes Software =>.MetaQuotes Software
HKCU\SOFTWARE\Mine
HKCU\SOFTWARE\MishkinSoft
HKCU\SOFTWARE\Mozilla =>.Mozilla
HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKCU\SOFTWARE\MTK
HKCU\SOFTWARE\Netscape =>.Netscape
HKCU\SOFTWARE\Opera Software =>.Opera Software
HKCU\SOFTWARE\Pablo Software Solutions =>.Pablo Software Solutions
HKCU\SOFTWARE\QtProject =>.QtProject
HKCU\SOFTWARE\RDP
HKCU\SOFTWARE\Realtek =>.Realtek
HKCU\SOFTWARE\RegisteredApplications
HKCU\SOFTWARE\Sdc
HKCU\SOFTWARE\Skype =>.Skype
HKCU\SOFTWARE\Sony =>.Sony
HKCU\SOFTWARE\Stormdance
HKCU\SOFTWARE\SyncEngines
HKCU\SOFTWARE\Sysinternals =>.Sysinternals
HKCU\SOFTWARE\TechSmith =>.TechSmith
HKCU\SOFTWARE\Telerik =>.Telerik
HKCU\SOFTWARE\Trolltech =>.Trolltech
HKCU\SOFTWARE\Unity
HKCU\SOFTWARE\VB and VBA Program Settings
HKCU\SOFTWARE\WinRAR =>.WinRAR
HKCU\SOFTWARE\WinRAR SFX
HKCU\SOFTWARE\Xpom
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\AppDataLow\Software
HKCU\SOFTWARE\AppDataLow\Software\JavaSoft =>.JavaSoft
HKCU\SOFTWARE\AppDataLow\Software\ThinPrint =>.ThinPrint
HKCU\SOFTWARE\AppDataLow\Software\Unity

---\\ Contents of the Common Files folders (238) - 193s
O43 - CFD: 02/05/2016 - [] D -- C:\Program Files\10KHits Exchanger
O43 - CFD: 06/04/2016 - [] AD -- C:\Program Files\Adobe =>.Adobe Systems Incorporated®
O43 - CFD: 09/03/2016 - [] D -- C:\Program Files\Antenna
O43 - CFD: 19/04/2016 - [] D -- C:\Program Files\AppInsights
O43 - CFD: 09/03/2016 - [0] D -- C:\Program Files\Arabic2
O43 - CFD: 19/04/2016 - [] D -- C:\Program Files\AVAST Software =>.AVAST Software s.r.o.®
O43 - CFD: 06/09/2016 - [] AD -- C:\Program Files\Cheat Engine 6.5.1 =>.Cheat Engine®
O43 - CFD: 17/10/2016 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 11/04/2016 - [] D -- C:\Program Files\Didsoft {00A5C744ACA387ABFDAE381A1955EBE3FC}
O43 - CFD: 29/01/2016 - [] D -- C:\Program Files\DIFX =>.Microsoft Windows®
O43 - CFD: 29/01/2016 - [] D -- C:\Program Files\epson =>.EPSON
O43 - CFD: 17/10/2016 - [0] D -- C:\Program Files\Ghostery Storage Server
O43 - CFD: 06/01/2016 - [] D -- C:\Program Files\Google =>.Google Inc®
O43 - CFD: 27/08/2016 - [] AD -- C:\Program Files\GSA SEO Indexer {00A6B4ABF7E1C8A9231AAA5D6FB711ADF0}
O43 - CFD: 06/01/2016 - [] D -- C:\Program Files\GUMDE78.tmp =>.Google Inc®
O43 - CFD: 19/10/2016 - [] D -- C:\Program Files\HitLeap =>.HitLeap Ltd.®
O43 - CFD: 30/09/2016 - [] AD -- C:\Program Files\IIS =>.Microsoft Corporation®
O43 - CFD: 19/04/2016 - [] AD -- C:\Program Files\IIS Express =>.Microsoft Corporation®
O43 - CFD: 06/01/2016 - [] HD -- C:\Program Files\InstallShield Installation Information =>.Macrovision Corporation®
O43 - CFD: 06/01/2016 - [] AD -- C:\Program Files\InstaTrader =>.MetaQuotes Software Corp.®
O43 - CFD: 06/01/2016 - [] D -- C:\Program Files\Intel =>.Intel Corporation
O43 - CFD: 01/10/2016 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 25/07/2016 - [] D -- C:\Program Files\Java =>.Oracle America, Inc.®
O43 - CFD: 01/03/2016 - [] AD -- C:\Program Files\LeapFTP 3.0 {455993C98FC05C4AB5EE223BDA01A07E}
O43 - CFD: 01/02/2016 - [] AD -- C:\Program Files\LiteForex MT4 Terminal =>.MetaQuotes Software Corp.®
O43 - CFD: 19/04/2016 - [] D -- C:\Program Files\Microsoft ASP.NET =>.Microsoft Corporation®
O43 - CFD: 19/04/2016 - [] D -- C:\Program Files\Microsoft DNX =>.Microsoft Corporation
O43 - CFD: 19/04/2016 - [] D -- C:\Program Files\Microsoft Help Viewer =>.Microsoft Corporation®
O43 - CFD: 19/04/2016 - [] D -- C:\Program Files\Microsoft Office365 Tools
O43 - CFD: 19/04/2016 - [] AD -- C:\Program Files\Microsoft SDKs =>.Windows Phone®
O43 - CFD: 19/04/2016 - [] AD -- C:\Program Files\Microsoft Silverlight =>.Microsoft Corporation®
O43 - CFD: 19/04/2016 - [] AD -- C:\Program Files\Microsoft SQL Server =>.Microsoft Corporation®
O43 - CFD: 19/04/2016 - [] AD -- C:\Program Files\Microsoft SQL Server Compact Edition =>.Microsoft Corporation
O43 - CFD: 30/09/2016 - [] D -- C:\Program Files\Microsoft Visual Studio 11.0
O43 - CFD: 30/09/2016 - [] D -- C:\Program Files\Microsoft Visual Studio 12.0
O43 - CFD: 30/09/2016 - [] AD -- C:\Program Files\Microsoft Visual Studio 14.0 =>.Microsoft Corporation®
O43 - CFD: 19/04/2016 - [] D -- C:\Program Files\Microsoft WCF Data Services =>.Microsoft Corporation®
O43 - CFD: 19/04/2016 - [] AD -- C:\Program Files\Microsoft Web Tools =>.Microsoft Corporation®
O43 - CFD: 30/09/2016 - [] D -- C:\Program Files\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 19/07/2016 - [] AD -- C:\Program Files\Mozilla Firefox =>.Mozilla Corporation®
O43 - CFD: 16/05/2016 - [] D -- C:\Program Files\Mozilla Maintenance Service =>.Mozilla Corporation®
O43 - CFD: 30/09/2016 - [] AD -- C:\Program Files\MSBuild =>.Microsoft Corporation®
O43 - CFD: 19/04/2016 - [] D -- C:\Program Files\NuGet
O43 - CFD: 29/06/2016 - [] AD -- C:\Program Files\OctaFX =>.MetaQuotes Software Corp.®
O43 - CFD: 06/10/2016 - [] AD -- C:\Program Files\Opera =>.Opera Software ASA®
O43 - CFD: 10/02/2016 - [] D -- C:\Program Files\Phase Five Systems
O43 - CFD: 06/01/2016 - [] D -- C:\Program Files\Realtek =>.Realtek Semiconductor Corp®
O43 - CFD: 06/01/2016 - [] D -- C:\Program Files\Realtek AC97 =>.Realtek Semiconductor Corp®
O43 - CFD: 30/09/2016 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 18/10/2016 - [] AD -- C:\Program Files\RogueKiller =>.Adlice®
O43 - CFD: 23/09/2016 - [] D -- C:\Program Files\Sandboxie =>.Invincea, Inc.®
O43 - CFD: 19/04/2016 - [] D -- C:\Program Files\ShellDir
O43 - CFD: 17/10/2016 - [] RD -- C:\Program Files\Skype =>.Skype Software Sarl®
O43 - CFD: 19/05/2016 - [] AD -- C:\Program Files\striphits
O43 - CFD: 09/07/2016 - [] D -- C:\Program Files\TechSmith =>.TechSmith Corporation®
O43 - CFD: 04/09/2016 - [] D -- C:\Program Files\ThinLinc Client
O43 - CFD: 10/07/2015 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 06/09/2016 - [] D -- C:\Program Files\VideoLAN =>.VideoLAN
O43 - CFD: 14/10/2016 - [] AD -- C:\Program Files\Website Traffic Generator
O43 - CFD: 30/09/2016 - [] RD -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 01/10/2016 - [] D -- C:\Program Files\Windows Defender Advanced Threat Protection =>.Microsoft Corporation®
O43 - CFD: 19/04/2016 - [] D -- C:\Program Files\Windows Kits =>.Microsoft Corporation®
O43 - CFD: 30/09/2016 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 30/09/2016 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 16/07/2016 - [] D -- C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 16/07/2016 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 12/10/2016 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation®
O43 - CFD: 16/07/2016 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 16/07/2016 - [] SHD -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 20/10/2016 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation
O43 - CFD: 16/07/2016 - [] D -- C:\Program Files\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 24/08/2016 - [] D -- C:\Program Files\WinPcap =>.Riverbed Technology, Inc.®
O43 - CFD: 15/10/2016 - [] AD -- C:\Program Files\WinRAR =>.win.rar GmbH®
O43 - CFD: 22/04/2016 - [] D -- C:\Program Files\WYSIWYG Web Builder 11
O43 - CFD: 22/04/2016 - [] D -- C:\Program Files\WYSIWYG Web Builder 8
O43 - CFD: 02/09/2016 - [] AD -- C:\Program Files\XM MT4 =>.MetaQuotes Software Corp.®
O43 - CFD: 16/07/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 12/10/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 16/07/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.5.1
O43 - CFD: 21/02/2016 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo =>.Comodo
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elite Proxy Switcher
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON =>.EPSON
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GSA SEO Indexer
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InstaTrader
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java =>.Oracle
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LiteForex MT4 Terminal
O43 - CFD: 16/07/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Expression =>.Microsoft Corporation
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OctaFX
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Otohits Network
O43 - CFD: 18/10/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller =>.Adlice Software
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie =>.Sandboxie
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype =>.Skype
O43 - CFD: 16/07/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp =>.Microsoft Corporation
O43 - CFD: 16/07/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith =>.TechSmith
O43 - CFD: 30/09/2016 - [] SD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ThinLinc
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLAN
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2015
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap =>.Riverbed Technology
O43 - CFD: 15/10/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WYSIWYG Web Builder 11
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XM MT4
O43 - CFD: 06/04/2016 - [] D -- C:\ProgramData\Adobe =>.Adobe
O43 - CFD: 30/09/2016 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 19/04/2016 - [] D -- C:\ProgramData\AVAST Software =>.AVAST Software
O43 - CFD: 16/07/2016 - [0] D -- C:\ProgramData\Comms =>.Microsoft Corporation
O43 - CFD: 30/09/2016 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 30/09/2016 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 24/06/2016 - [] D -- C:\ProgramData\EPS
O43 - CFD: 29/01/2016 - [] D -- C:\ProgramData\EPSON =>.EPSON
O43 - CFD: 04/04/2016 - [0] D -- C:\ProgramData\IDM =>.IDM
O43 - CFD: 06/01/2016 - [] D -- C:\ProgramData\MetaQuotes
O43 - CFD: 30/09/2016 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft
O43 - CFD: 19/04/2016 - [] D -- C:\ProgramData\Microsoft DNX =>.Microsoft Corporation
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\Microsoft OneDrive =>.Microsoft Corporation
O43 - CFD: 08/05/2016 - [] D -- C:\ProgramData\Mozilla =>.Mozilla Corporation
O43 - CFD: 19/04/2016 - [] D -- C:\ProgramData\NuGet
O43 - CFD: 25/07/2016 - [] D -- C:\ProgramData\Oracle =>.Oracle
O43 - CFD: 19/04/2016 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 19/04/2016 - [] D -- C:\ProgramData\PreEmptive Solutions =>.PreEmptive Solutions
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\regid.1986-12.com.adobe =>.Adobe Inc.
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
O43 - CFD: 30/09/2016 - [] AD -- C:\ProgramData\regid.1995-08.com.techsmith =>.TechSmith Corporation
O43 - CFD: 18/10/2016 - [] D -- C:\ProgramData\RogueKiller =>.Adlice Software
O43 - CFD: 17/10/2016 - [] D -- C:\ProgramData\Skype =>.Skype
O43 - CFD: 16/07/2016 - [0] D -- C:\ProgramData\SoftwareDistribution =>.Microsoft Corporation
O43 - CFD: 29/01/2016 - [] D -- C:\ProgramData\SP_FT_Logs
O43 - CFD: 30/09/2016 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation
O43 - CFD: 09/07/2016 - [] AD -- C:\ProgramData\TechSmith =>.TechSmith
O43 - CFD: 30/09/2016 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\USOPrivate =>.Microsoft Corporation
O43 - CFD: 30/09/2016 - [] D -- C:\ProgramData\USOShared =>.Microsoft Corporation
O43 - CFD: 10/02/2016 - [] D -- C:\ProgramData\VMware =>.VMware
O43 - CFD: 08/03/2016 - [0] D -- C:\ProgramData\Web Page Maker
O43 - CFD: 06/04/2016 - [] D -- C:\Program Files\Common Files\Adobe =>.Adobe
O43 - CFD: 19/04/2016 - [] AD -- C:\Program Files\Common Files\Designer =>.Designer
O43 - CFD: 29/01/2016 - [] D -- C:\Program Files\Common Files\EPSON =>.EPSON
O43 - CFD: 06/01/2016 - [] D -- C:\Program Files\Common Files\InstallShield =>.InstallShield
O43 - CFD: 25/07/2016 - [] D -- C:\Program Files\Common Files\Java =>.Oracle
O43 - CFD: 19/04/2016 - [0] D -- C:\Program Files\Common Files\Merge Modules
O43 - CFD: 30/09/2016 - [] AD -- C:\Program Files\Common Files\microsoft shared =>.Microsoft Corporation
O43 - CFD: 16/07/2016 - [] D -- C:\Program Files\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 17/10/2016 - [] AD -- C:\Program Files\Common Files\Skype =>.Skype
O43 - CFD: 16/07/2016 - [] D -- C:\Program Files\Common Files\System =>.Microsoft Corporation
O43 - CFD: 09/07/2016 - [] D -- C:\Program Files\Common Files\TechSmith Shared =>.TechSmith
O43 - CFD: 08/05/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\10KHits
O43 - CFD: 06/04/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 09/03/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\Apple Computer =>.Apple Inc.
O43 - CFD: 09/03/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\Artisteer
O43 - CFD: 06/01/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\AVAST Software =>.AVAST Software
O43 - CFD: 11/04/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\Diabolic Labs
O43 - CFD: 04/05/2016 - [0] D -- C:\Users\YaSs\AppData\Roaming\DMCache =>.DMCache
O43 - CFD: 26/05/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\GSA Proxy Scraper
O43 - CFD: 12/09/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\GSA SEO Indexer
O43 - CFD: 07/01/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 07/01/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\MetaQuotes
O43 - CFD: 30/09/2016 - [] SD -- C:\Users\YaSs\AppData\Roaming\Microsoft =>.Microsoft
O43 - CFD: 09/01/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 20/04/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\NuGet
O43 - CFD: 14/04/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\Opera Software =>.Opera Software
O43 - CFD: 01/05/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\Proxy Mask
O43 - CFD: 09/04/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\RedSurf-client
O43 - CFD: 20/10/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\Skype =>.Skype
O43 - CFD: 18/02/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\Sun =>.Oracle
O43 - CFD: 09/07/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\TechSmith =>.TechSmith
O43 - CFD: 16/10/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\Telegram Desktop
O43 - CFD: 08/05/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\tor =>.Tor
O43 - CFD: 19/02/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\TrafficHive
O43 - CFD: 08/05/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\UBot Studio
O43 - CFD: 17/10/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\vlc =>.VideoLAN
O43 - CFD: 11/02/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\VMware =>.VMware
O43 - CFD: 08/03/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\Web Page Maker
O43 - CFD: 13/10/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\Windows Mask
O43 - CFD: 06/01/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\WinRAR =>.WinRAR
O43 - CFD: 20/10/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 14/10/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\zztiDOTcom
O43 - CFD: 29/01/2016 - [0] D -- C:\Users\YaSs\AppData\Local\ActiveSync =>.Microsoft Corporation
O43 - CFD: 22/04/2016 - [] D -- C:\Users\YaSs\AppData\Local\Adobe =>.Adobe
O43 - CFD: 09/03/2016 - [] D -- C:\Users\YaSs\AppData\Local\Apple Computer =>.Apple Inc.
O43 - CFD: 30/09/2016 - [0] SHD -- C:\Users\YaSs\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 24/03/2016 - [] D -- C:\Users\YaSs\AppData\Local\AVAST Software =>.AVAST Software
O43 - CFD: 29/01/2016 - [] D -- C:\Users\YaSs\AppData\Local\CEF =>.CEF
O43 - CFD: 06/01/2016 - [] D -- C:\Users\YaSs\AppData\Local\Comms =>.Microsoft Corporation
O43 - CFD: 21/02/2016 - [0] D -- C:\Users\YaSs\AppData\Local\Comodo =>.Comodo
O43 - CFD: 30/09/2016 - [] D -- C:\Users\YaSs\AppData\Local\ConnectedDevicesPlatform =>.Microsoft Corporation
O43 - CFD: 26/09/2016 - [] D -- C:\Users\YaSs\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 25/09/2016 - [0] D -- C:\Users\YaSs\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 12/10/2016 - [] D -- C:\Users\YaSs\AppData\Local\Downloaded Installations =>.Microsoft Corporation
O43 - CFD: 18/02/2016 - [] D -- C:\Users\YaSs\AppData\Local\ebesucher
O43 - CFD: 11/09/2016 - [0] D -- C:\Users\YaSs\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation
O43 - CFD: 17/10/2016 - [] D -- C:\Users\YaSs\AppData\Local\Geckofx =>.Geckofx
O43 - CFD: 07/01/2016 - [] D -- C:\Users\YaSs\AppData\Local\Google =>.Google
O43 - CFD: 30/09/2016 - [0] SHD -- C:\Users\YaSs\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 14/10/2016 - [] D -- C:\Users\YaSs\AppData\Local\IM_Buster
O43 - CFD: 24/03/2016 - [] D -- C:\Users\YaSs\AppData\Local\IsolatedStorage =>.id Software
O43 - CFD: 10/02/2016 - [] D -- C:\Users\YaSs\AppData\Local\Jump Desktop
O43 - CFD: 21/01/2016 - [0] D -- C:\Users\YaSs\AppData\Local\Mediatek =>.Mediatek
O43 - CFD: 30/09/2016 - [] D -- C:\Users\YaSs\AppData\Local\Microsoft =>.Microsoft
O43 - CFD: 06/01/2016 - [] D -- C:\Users\YaSs\AppData\Local\MicrosoftEdge =>.Microsoft Corporation
O43 - CFD: 09/01/2016 - [] D -- C:\Users\YaSs\AppData\Local\Mozilla =>.Mozilla Corporation
O43 - CFD: 14/04/2016 - [] D -- C:\Users\YaSs\AppData\Local\Opera Software =>.Opera Software
O43 - CFD: 30/09/2016 - [] D -- C:\Users\YaSs\AppData\Local\Packages =>.Microsoft Corporation
O43 - CFD: 06/01/2016 - [0] D -- C:\Users\YaSs\AppData\Local\PeerDistRepub =>.Microsoft Corporation
O43 - CFD: 29/01/2016 - [] D -- C:\Users\YaSs\AppData\Local\Phantasiac
O43 - CFD: 14/01/2016 - [] D -- C:\Users\YaSs\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 06/01/2016 - [] D -- C:\Users\YaSs\AppData\Local\Publishers =>.Microsoft Corporation
O43 - CFD: 09/07/2016 - [] D -- C:\Users\YaSs\AppData\Local\TechSmith =>.TechSmith
O43 - CFD: 20/10/2016 - [] D -- C:\Users\YaSs\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 30/09/2016 - [0] SHD -- C:\Users\YaSs\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 06/01/2016 - [] D -- C:\Users\YaSs\AppData\Local\TileDataLayer =>.Microsoft Corporation
O43 - CFD: 19/02/2016 - [] D -- C:\Users\YaSs\AppData\Local\TrafficHive
O43 - CFD: 14/10/2016 - [] D -- C:\Users\YaSs\AppData\Local\Unity =>.Unity
O43 - CFD: 08/04/2016 - [] D -- C:\Users\YaSs\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 10/02/2016 - [] D -- C:\Users\YaSs\AppData\Local\VMware =>.VMware
O43 - CFD: 12/10/2016 - [] D -- C:\Users\YaSs\AppData\Local\Website_Visit_Booster
O43 - CFD: 05/05/2016 - [] D -- C:\Users\YaSs\AppData\Local\WindowsFormsApplication1
O43 - CFD: 14/10/2016 - [] D -- C:\Users\YaSs\AppData\Local\zztiDOTcom
O43 - CFD: 12/10/2016 - [] D -- C:\Users\YaSs\AppData\Local\{871019811510511610132841149710210210599327110111010111497116111114}
O43 - CFD: 14/01/2016 - [0] D -- C:\Users\YaSs\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 16/07/2016 - [] RD -- C:\Users\YaSs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 16/07/2016 - [] RD -- C:\Users\YaSs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 01/10/2016 - [] RD -- C:\Users\YaSs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 16/07/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 01/10/2016 - [] RD -- C:\Users\YaSs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 16/07/2016 - [] RD -- C:\Users\YaSs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 30/09/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop
O43 - CFD: 16/07/2016 - [] RD -- C:\Users\YaSs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell =>.Microsoft Corporation
O43 - CFD: 15/10/2016 - [] D -- C:\Users\YaSs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 30/09/2016 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\ConnectedDevicesPlatform =>.Microsoft Corporation
O43 - CFD: 18/10/2016 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 01/10/2016 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\DataSharing =>.DataSharing
O43 - CFD: 30/09/2016 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft
O43 - CFD: 30/09/2016 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Packages =>.Microsoft Corporation
O43 - CFD: 30/09/2016 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 30/09/2016 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft

---\\ ShellIconOverlayIdentifiers (SIOI) (8) - 0s
O106 - SIOI: ErrorOverlayHandler Class [ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\YaSs\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SharedOverlayHandler Class [ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\YaSs\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SharedSyncingOverlayHandler Class [ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\YaSs\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: UpToDateOverlayHandler Class [ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\YaSs\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SyncingOverlayHandler Class [ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\YaSs\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: avast [00avast] - {472083B0-C522-11CF-8763-00608CC02F24}. (.AVAST Software - avast! Shell Extension.) -- C:\Program Files\AVAST Software\Avast\ashShell.dll =>.AVAST Software a.s.®
O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O106 - SIOI: [Offline Files] - {4E77131D-3629-431c-9818-C5679DC83E81}. (.Microsoft Corporation - Client Side Caching UI.) -- C:\Windows\System32\cscui.dll =>.Microsoft Corporation

---\\ System Drivers List (52) - 22s
O58 - SDL:2016/07/16 10:24:54 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [85856] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:54 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1038176] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:54 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [75104] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:54 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [215392] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:54 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [22880] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:54 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [116576] =>.Microsoft Windows®
O58 - SDL:2016/10/17 18:33:25 A . (.AVAST Software - Home Network Security.) -- C:\WINDOWS\System32\drivers\aswHdsKe.sys [65344] =>.AVAST Software s.r.o.®
O58 - SDL:2016/09/06 08:11:06 A . (.AVAST Software - avast! HWID.) -- C:\WINDOWS\System32\drivers\aswHwid.sys [34008] =>.AVAST Software a.s.® (ALWIL Software)
O58 - SDL:2016/09/06 08:10:32 A . (.AVAST Software - avast! Keyboard Filter Driver.) -- C:\WINDOWS\System32\drivers\aswKbd.sys [35096] =>.AVAST Software a.s.®
O58 - SDL:2016/09/06 08:11:06 A . (.AVAST Software - avast! File System Minifilter for Windows 2.) -- C:\WINDOWS\System32\drivers\aswMonFlt.sys [92256] =>.AVAST Software a.s.®
O58 - SDL:2016/09/06 08:11:06 A . (.AVAST Software - avast! WFP Redirect Driver.) -- C:\WINDOWS\System32\drivers\aswRdr2.sys [91232] =>.AVAST Software a.s.®
O58 - SDL:2016/09/06 08:11:06 A . (.AVAST Software - avast! Revert.) -- C:\WINDOWS\System32\drivers\aswRvrt.sys [60424] =>.AVAST Software a.s.® (ALWIL Software)
O58 - SDL:2016/09/13 13:44:25 A . (.AVAST Software - avast! Virtualization Driver.) -- C:\WINDOWS\System32\drivers\aswsnx.sys [735488] =>.AVAST Software s.r.o.®
O58 - SDL:2016/09/22 15:20:31 A . (.AVAST Software - avast! self protection module.) -- C:\WINDOWS\System32\drivers\aswsp.sys [433768] =>.AVAST Software s.r.o.®
O58 - SDL:2016/09/06 08:11:07 A . (.AVAST Software - Stream Filter.) -- C:\WINDOWS\System32\drivers\aswStm.sys [118664] =>.AVAST Software a.s.®
O58 - SDL:2016/10/14 07:05:24 A . (.AVAST Software - avast! VM Monitor.) -- C:\WINDOWS\System32\drivers\aswvmm.sys [224752] =>.AVAST Software s.r.o.® (ALWIL Software)
O58 - SDL:2016/07/16 10:24:54 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn.sys [8192] =>.Windows (R) Win 7 DDK provider
O58 - SDL:2016/07/16 10:24:54 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [8192] =>.Windows (R) Win 7 DDK provider
O58 - SDL:2016/07/16 10:24:54 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [56672] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:57 A . (.Intel(R) Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iagpio.sys [25600] =>.Intel(R) Corporation
O58 - SDL:2016/07/16 10:24:57 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) -- C:\WINDOWS\System32\drivers\iai2c.sys [66560] =>.Intel(R) Corporation
O58 - SDL:2016/07/16 10:24:55 A . (.Intel Corporation - Intel(R) Atom(TM) Processor GPIO Controller.) -- C:\WINDOWS\System32\drivers\iaiogpio.sys [22016] =>.Intel Corporation
O58 - SDL:2016/07/16 10:24:54 A . (.Intel Corporation - Intel(R) Atom(TM) Processor I2C Controller.) -- C:\WINDOWS\System32\drivers\iaioi2c.sys [61936] =>.Intel Corporation
O58 - SDL:2016/07/16 10:24:54 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [524640] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:54 A . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [333664] =>.Microsoft Windows®
O58 - SDL:2016/01/28 12:20:10 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\WINDOWS\System32\drivers\idmwfp.sys [134248] =>.Tonec Inc.®
O58 - SDL:2016/01/06 19:11:30 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\igdkmd32.sys [4815872] =>.Intel Corporation
O58 - SDL:2016/07/16 10:24:54 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [94048] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:54 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [89952] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:54 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [85856] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:54 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [69472] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:54 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [52064] =>.Microsoft Windows®
O58 - SDL:2016/10/05 11:46:02 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\MegaSas2i.sys [56672] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:54 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [464736] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:54 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [58208] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:25:01 A . (...) -- C:\WINDOWS\System32\drivers\NetAdapterCx.sys [62976]
O58 - SDL:2013/03/01 03:48:42 A . (.Riverbed Technology, Inc. - npf.sys (NT5/6 x86) Kernel Driver.) -- C:\WINDOWS\System32\drivers\npf.sys [36600] =>.Riverbed Technology, Inc.®
O58 - SDL:2016/07/16 10:24:54 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [119136] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:54 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [142176] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:54 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [51552] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:54 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [54624] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:55 A . (.Realtek - Realtek 8136/8168/8169 NDIS 6.40 32-bit Dri.) -- C:\WINDOWS\System32\drivers\rt640x86.sys [494080] =>.Realtek
O58 - SDL:2011/12/15 15:14:46 A . (.Realtek Semiconductor Corp. - Realtek AC'97 Audio Driver (WDM).) -- C:\WINDOWS\System32\drivers\RTKVAC.SYS [4172832] =>.Realtek Semiconductor Corp®
O58 - SDL:2016/07/16 10:24:54 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [41312] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:54 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [79200] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:55 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [26976] =>.Microsoft Windows®
O58 - SDL:2016/10/18 18:46:29 A . (...) -- C:\WINDOWS\System32\drivers\TrueSight.sys [24688] =>.Adlice®
O58 - SDL:2011/05/18 10:51:15 A . (.MediaTek Inc. - MediaTek USB to Com Port Driver.) -- C:\WINDOWS\System32\drivers\usb2ser.sys [56832] =>.MediaTek Inc.
O58 - SDL:2016/03/04 17:52:34 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Host-Only Network Adapt.) -- C:\WINDOWS\System32\drivers\VBoxNetAdp6.sys [108208] =>.Oracle Corporation®
O58 - SDL:2016/03/04 17:52:34 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Lightweight Filter Driv.) -- C:\WINDOWS\System32\drivers\VBoxNetLwf.sys [174192] =>.Oracle Corporation®
O58 - SDL:2016/07/16 10:24:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR X86-32.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [149856] =>.Microsoft Windows®
O58 - SDL:2016/07/16 10:24:55 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [276832] =>.Microsoft Windows®

---\\ Last modified or created user files (27) - 146s
O61 - LFC: 2016/10/12 19:21:22 A . (.Copyright © 2015 Navinda Dissanayake.) -- C:\Users\YaSs\Downloads\Fake Traffic Generator 0.4 Stable (1).exe [927744]
O61 - LFC: 2016/10/12 19:13:32 A . (.Copyright © 2015 Navinda Dissanayake.) -- C:\Users\YaSs\Downloads\Fake Traffic Generator 0.4 Stable.exe [927744]
O61 - LFC: 2016/10/18 07:14:28 A . (..) -- C:\Users\YaSs\Downloads\RogueKiller (1).exe [0]
O61 - LFC: 2016/10/18 07:13:43 A . (..) -- C:\Users\YaSs\Downloads\RogueKiller.exe [0]
O61 - LFC: 2016/10/12 14:16:29 A . (.http://www.techipick.com.) -- C:\Users\YaSs\Downloads\Website Auto Traffic Generator V4.0.exe [806912]
O61 - LFC: 2016/10/12 19:13:32 A . (.Copyright © 2015 Navinda Dissanayake.) -- C:\Users\YaSs\Desktop\New folder (5)\Fake Traffic Generator 0.4 Stable.exe [927744]
O61 - LFC: 2016/10/12 18:58:02 A . (.http://www.techipick.com.) -- C:\Users\YaSs\Desktop\New folder (5)\USeQ File Downloader.exe [811520]
O61 - LFC: 2016/10/12 14:16:29 A . (.http://www.techipick.com.) -- C:\Users\YaSs\Desktop\New folder (5)\Website Auto Traffic Generator V4.0.exe [806912]
O61 - LFC: 2016/10/14 08:01:44 A . (..) -- C:\Users\YaSs\Desktop\New folder (5)\Traffik Buster 4.0.2.4\Traffik Buster\DeathByCaptcha.dll [23552]
O61 - LFC: 2016/10/14 08:01:44 A . (..) -- C:\Users\YaSs\Desktop\New folder (5)\Traffik Buster 4.0.2.4\Traffik Buster\DecaptcherLib.dll [60416]
O61 - LFC: 2016/10/14 07:43:43 A . (..) -- C:\Users\YaSs\AppData\Roaming\UBot Studio\Browser\4.2.12\avcodec-53.dll [1093646]
O61 - LFC: 2016/10/14 07:43:50 A . (..) -- C:\Users\YaSs\AppData\Roaming\UBot Studio\Browser\4.2.12\avformat-53.dll [184846]
O61 - LFC: 2016/10/14 07:43:56 A . (..) -- C:\Users\YaSs\AppData\Roaming\UBot Studio\Browser\4.2.12\avutil-51.dll [117262]
O61 - LFC: 2016/10/14 07:43:03 A . (..) -- C:\Users\YaSs\AppData\Roaming\UBot Studio\Browser\4.2.12\Awesomium.dll [23271936]
O61 - LFC: 2016/10/14 07:48:25 A . (..) -- C:\Users\YaSs\AppData\Roaming\UBot Studio\Browser\4.2.12\Browser.exe [625152]
O61 - LFC: 2016/10/19 09:46:34 RA . (..) -- C:\Users\YaSs\AppData\Roaming\Microsoft\Installer\{31B12C11-AE4E-479F-8D6D-242DC265368D}\favicon.exe [318]
O61 - LFC: 2016/10/19 09:46:34 RA . (..) -- C:\Users\YaSs\AppData\Roaming\Microsoft\Installer\{31B12C11-AE4E-479F-8D6D-242DC265368D}\HitLeap_Viewer.exe [1470]
O61 - LFC: 2016/10/13 19:23:40 A . (..) -- C:\Users\YaSs\AppData\Local\{871019811510511610132841149710210210599327110111010111497116111114}\settings.dll [792]
O61 - LFC: 2016/10/02 18:52:58 A . (.Copyright ©2012-2014 Mike Goatly.) -- C:\Users\YaSs\AppData\Local\Packages\VideoLAN.VLCforWindows8_paz6r1rewnh0a\AC\Microsoft\CLR_v4.0_32\NativeImages\WinRT.Triggers\244b48ae06c2feaa4dcebd2a02ecb727\WinRT.Triggers.ni.dll [121856]
O61 - LFC: 2016/10/02 18:51:44 A . (.Copyright © 2014.) -- C:\Users\YaSs\AppData\Local\Packages\VideoLAN.VLCforWindows8_paz6r1rewnh0a\AC\Microsoft\CLR_v4.0_32\NativeImages\VLC_WinRT.Windows\d164c2e3d0b328c36e41494a4cf922c1\VLC_WinRT.Windows.ni.exe [3452416]
O61 - LFC: 2016/10/02 18:52:51 A . (.Copyright © 2014.) -- C:\Users\YaSs\AppData\Local\Packages\VideoLAN.VLCforWindows8_paz6r1rewnh0a\AC\Microsoft\CLR_v4.0_32\NativeImages\ScrollWatcher\b81d3124bd493c478e6c99a0f90e9402\ScrollWatcher.ni.dll [76800]
O61 - LFC: 2016/10/02 18:52:36 A . (..) -- C:\Users\YaSs\AppData\Local\Packages\VideoLAN.VLCforWindows8_paz6r1rewnh0a\AC\Microsoft\CLR_v4.0_32\NativeImages\Microsoft.G180c062c#\9d3c955de5de2735a5c2eda055968673\Microsoft.Graphics.Canvas.ni.dll [675840]
O61 - LFC: 2016/10/02 18:52:25 A . (..) -- C:\Users\YaSs\AppData\Local\Packages\VideoLAN.VLCforWindows8_paz6r1rewnh0a\AC\Microsoft\CLR_v4.0_32\NativeImages\libVLCX\b62b898e169fbc822c8f67e81d8ae611\libVLCX.ni.dll [216064]
O61 - LFC: 2016/10/01 22:24:15 A . (..) -- C:\Users\YaSs\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_0_Data.bin [3177304]
O61 - LFC: 2016/09/30 09:16:53 A . (..) -- C:\Users\YaSs\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_0_Header.bin [12136]
O61 - LFC: 2016/10/20 06:39:15 A . (..) -- C:\Users\YaSs\AppData\Local\Microsoft\Windows\UPPS\UPPS.bin [16148]
O61 - LFC: 2016/09/30 09:19:35 A . (..) -- C:\Users\YaSs\AppData\Local\Microsoft\Windows\1033\StructuredQuerySchema.bin [405410]

---\\ File Associations Shell Spawning (10) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®

---\\ Start Menu Internet (16) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc®
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\Launcher.exe =>.Opera Software ASA®
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Avast Software - Avast SafeZone Browser.) -- C:\Program Files\AVAST Software\SZBrowser\Launcher.exe =>.AVAST Software s.r.o.®
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\launcher.exe =>.Opera Software
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Avast Software - Avast SafeZone Browser.) -- C:\Program Files\AVAST Software\SZBrowser\launcher.exe =>.AVAST Software
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\launcher.exe =>.Opera Software
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Avast Software - Avast SafeZone Browser.) -- C:\Program Files\AVAST Software\SZBrowser\launcher.exe =>.AVAST Software
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\launcher.exe =>.Opera Software
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Avast Software - Avast SafeZone Browser.) -- C:\Program Files\AVAST Software\SZBrowser\launcher.exe =>.AVAST Software

---\\ Search Browser Infection (3) - 13s
O69 - SBI: prefs.js [YaSs - b4kfvpni.default] user_pref("extensions.enabledAddons", "deskCutv2%40gmail.com:0.1.13,%7B81BF1D23-5F17-408D-AC6B-BD6DF7CAF670%7D:8.9.7,%7B972ce4c6-7[...] =>PUP.Optional.DeskCut
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com/
O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/

---\\ Search Svchost Services (45) - 1s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [161792] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [161792] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\Windows\System32\srvsvc.dll [234496] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\Windows\System32\gpsvc.dll [1098752] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\IKEEXT.DLL [740864] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [827392] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\Windows\System32\seclogon.dll [24576] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\Windows\System32\appinfo.dll [102912] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\Windows\System32\iscsiexe.dll [117760] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [96768] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\Windows\System32\schedsvc.dll [733184] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [184832] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [331776] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\Windows\System32\wercplsupport.dll [68608] =>.Microsoft Corporation
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\Windows\System32\XblGameSave.dll [704512] =>.Microsoft Corporation
O83 - Search Svchost Services: shpamsvc (shpamsvc) . (.Microsoft Corporation - SharedPC.AccountManager.) -- C:\Windows\System32\Windows.SharedPC.AccountManager.dll [120320] =>.Microsoft Corporation
O83 - Search Svchost Services: DcpSvc (DcpSvc) . (.Microsoft Corporation - dcpsvc Task.) -- C:\Windows\System32\dcpsvc.dll [155648] =>.Microsoft Corporation
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Network Setup Service.) -- C:\Windows\System32\NetSetupSvc.dll [182272] =>.Microsoft Corporation
O83 - Search Svchost Services: RetailDemo (RetailDemo) . (.Microsoft Corporation - RDXService.) -- C:\Windows\System32\RDXService.dll [473600] =>.Microsoft Corporation
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\Windows\System32\dmwappushsvc.dll [47104] =>.Microsoft Corporation
O83 - Search Svchost Services: wisvc (wisvc) . (.Microsoft Corporation - Flight Settings.) -- C:\Windows\System32\flightsettings.dll [501760] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\Windows\System32\bdesvc.dll [310272] =>.Microsoft Corporation
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - Windows Managent Service DLL.) -- C:\Windows\System32\Windows.Internal.Management.dll [298496] =>.Microsoft Corporation
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Device Setup Manager.) -- C:\Windows\System32\DeviceSetupManager.dll [159232] =>.Microsoft Corporation
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Microsoft Network Connectivity Assistant Se.) -- C:\Windows\System32\NcaSvc.dll [144384] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\Windows\System32\themeservice.dll [55296] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\Windows\System32\XboxNetApiSvc.dll [828928] =>.Microsoft Corporation
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Geolocation Service.) -- C:\Windows\System32\lfsvc.dll [30208] =>.Microsoft Corporation
O83 - Search Svchost Services: WpnService (WpnService) . (.Microsoft Corporation - Windows Push Notification System Service.) -- C:\Windows\System32\WpnService.dll [195584] =>.Microsoft Corporation
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Microsoft® Account Service.) -- C:\Windows\System32\wlidsvc.dll [1584128] =>.Microsoft Corporation
O83 - Search Svchost Services: Irmon (Irmon) . (.Microsoft Corporation - Infrared Monitor.) -- C:\Windows\System32\irmon.dll [20992] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\Windows\System32\rasauto.dll [93184] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [551936] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [431104] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\Windows\System32\Sens.dll [57856] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [482304] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [254976] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\System32\wuaueng.dll [1885696] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\Windows\System32\qmgr.dll [796672] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [566784] =>.Microsoft Corporation
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Software installation Service.) -- C:\Windows\System32\appmgmts.dll [165376] =>.Microsoft Corporation
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Update Session Orchestrator Core.) -- C:\Windows\System32\usocore.dll [416256] =>.Microsoft Corporation
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\Windows\System32\XblAuthManager.dll [576512] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [268800] =>.Microsoft Corporation
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\Windows\System32\usermgr.dll [822272] =>.Microsoft Corporation

---\\ Firewall Active Exception List (15) - 5s
O87 - FAEL: "{46E84A80-AEB2-4A5C-9CD6-1744826BEA73}" [Out-None-P17-TRUE] .(.GSA - GSA SEO Indexer.) -- C:\Program Files\GSA SEO Indexer\SEO_Indexer.exe {00A6B4ABF7E1C8A9231AAA5D6FB711ADF0}
O87 - FAEL: "{03EA9ED7-1E1A-4E6F-BB26-024D94F4386F}" [In-None-P17-TRUE] .(.GSA - GSA SEO Indexer.) -- C:\Program Files\GSA SEO Indexer\SEO_Indexer.exe {00A6B4ABF7E1C8A9231AAA5D6FB711ADF0}
O87 - FAEL: "{3EA10D42-6936-4DBC-B868-33F863D37CC0}" [In-None-P6-TRUE] .(.GSA - GSA SEO Indexer.) -- C:\Program Files\GSA SEO Indexer\SEO_Indexer.exe {00A6B4ABF7E1C8A9231AAA5D6FB711ADF0}
O87 - FAEL: "{59004FE0-736D-4431-B191-1C5A90EF2392}" [Out-None-P6-TRUE] .(...) -- C:\Program Files\GSA Proxy Scraper\Proxy_Scraper.exe (.not file.)
O87 - FAEL: "{B7374FC6-491B-4C11-993E-D496448722E5}" [In-None-P17-TRUE] .(...) -- C:\Program Files\GSA Proxy Scraper\Proxy_Scraper.exe (.not file.)
O87 - FAEL: "{275BCD91-DD8F-4442-B53D-826FC81CE14D}" [In-None-P6-TRUE] .(...) -- C:\Program Files\GSA Proxy Scraper\Proxy_Scraper.exe (.not file.)
O87 - FAEL: "{820A9C1B-EE1A-4624-92B7-DF6063BCE5FF}" [Out-None-P6-TRUE] .(.GSA - GSA SEO Indexer.) -- C:\Program Files\GSA SEO Indexer\SEO_Indexer.exe {00A6B4ABF7E1C8A9231AAA5D6FB711ADF0}
O87 - FAEL: "UDP Query User{92B08C31-1F2B-464A-90B2-D900BBA2DD0E}C:\program files\multiproxy\mproxy.exe" [In-None-P17-TRUE] .(...) -- C:\program files\multiproxy\mproxy.exe (.not file.)
O87 - FAEL: "TCP Query User{3B1914D7-C579-4D26-9C16-A05BE7197452}C:\program files\multiproxy\mproxy.exe" [In-None-P6-TRUE] .(...) -- C:\program files\multiproxy\mproxy.exe (.not file.)
O87 - FAEL: "{E7920F29-5677-4AD4-96A4-557B77A2774C}" [Out-None-P6-TRUE] .(.GSA - GSA SEO Indexer.) -- C:\Program Files\GSA SEO Indexer\SEO_Indexer.exe {00A6B4ABF7E1C8A9231AAA5D6FB711ADF0}
O87 - FAEL: "UDP Query User{7EC4ABF4-80DC-447C-959C-7DE8CB4EB848}C:\users\yass\desktop\embratoriag2_v2.1_stable\embratoriag2_v2.1_stable\es.exe" [In-None-P17-TRUE] .(...) -- C:\users\yass\desktop\embratoriag2_v2.1_stable\embratoriag2_v2.1_stable\es.exe (.not file.)
O87 - FAEL: "TCP Query User{4C12D626-492E-4111-96EA-CE77F02B61C3}C:\users\yass\desktop\embratoriag2_v2.1_stable\embratoriag2_v2.1_stable\es.exe" [In-None-P6-TRUE] .(...) -- C:\users\yass\desktop\embratoriag2_v2.1_stable\embratoriag2_v2.1_stable\es.exe (.not file.)
O87 - FAEL: "{BABA4AEA-403B-419E-83B5-F71BD837736A}" [Out-None-P6-TRUE] .(...) -- C:\Program Files\Artisteer 4\bin\Artisteer.exe (.not file.)
O87 - FAEL: "{819111B1-E4F0-45E4-BCE3-097D8CF96A71}" [Out-None-P6-TRUE] .(...) -- C:\Program Files\Phase Five Systems\Jump Desktop Connect\4.9.8.0\JumpConnect.exe (.not file.)
O87 - FAEL: "{2E141DE1-6719-4DAF-8E48-C90ECCFBAA47}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Phase Five Systems\Jump Desktop Connect\4.9.8.0\JumpConnect.exe (.not file.)

---\\ Additional Scan (O88) (1) - 3s
~ No malicious or unnecessary items found.

---\\ Summary of the elements found (1) - 0s
https://www.nicolascoolman.com/fr/repaquetage-et_infections/ =>PUP.Optional.DeskCut

~ End of the scan, 40305 items in 00h10mn04s (1038)

Publicité


Signaler le contenu de ce document

Publicité