cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2018.3.6.47 By Nicolas Coolman (2018/03/06)
~ Run by VULCAN (Administrator) (2018/03/09 08:27:26)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Illegal
~ State version: Version KO
~ Mode: Scan
~ Report: C:\Users\VULCAN\Desktop\ZHPDiag.txt
~ Report: C:\Users\VULCAN\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ System startup: Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 16299) =>.Microsoft Corporation

---\\ Internet Browsers (4) - 0s
~ GCIE: Google Chrome v65.0.3325.146
~ MFIE: Mozilla Firefox 58.0.2 (x64 zh-CN)
~ MSIE: Microsoft Edge v40
~ MSIE: Internet Explorer v11.248.16299.0

---\\ Windows Product Information (3) - 0s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK

---\\ System protection software (2) - 1s
Windows Defender (Activate) (Protection)
Malwarebytes version 3.1.2.1733 v3.1.2.1733 (Protection)

---\\ Surveillance software (1) - 1s
~ Adobe Flash Player 28 NPAPI (Surveillance)

---\\ Informations on the system (7) - 0s
~ Operating System: Intel64 Family 6 Model 94 Stepping 3, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 8305.264 MB (61% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 55 GB (46%) free of 118 GB : OK =>.Disk Space
Total RAM: 8305.264 MB (55% free) : OK =>.RAM Value

---\\ Connection to the system mode (3) - 0s
~ Computer Name: VULCANTSERIES
~ User Name: VULCAN
~ Logged in as Administrator

---\\ Enumeration of the disk units (6) - 0s
~ Drive C: has 55 GB free of 118 GB (System)
~ Drive D: has 96 GB free of 124 GB
~ Drive E: has 40 GB free of 317 GB
~ Drive F: has 159 GB free of 318 GB
~ Drive G: has 100 GB free of 317 GB
~ Drive H: has 383 GB free of 476 GB

---\\ State of the Windows Security Center (7) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Search Generic System Files (24) - 1s
[MD5.A77D56422C38C1F8A00D95D2D5B1675E] - 10/02/2018 - (.Microsoft Corporation - Windows 资源管理器.) -- C:\WINDOWS\Explorer.exe [3904296] =>.Microsoft Windows?
[MD5.731A783A36A8E69A6434D19D98B12A09] - 29/09/2017 - (.Microsoft Corporation - Windows 主进程 (Rundll32).) -- C:\WINDOWS\System32\rundll32.exe [71168] =>.Microsoft Corporation
[MD5.BF3E1D9B2360C6BE4CC3094CD2DDC617] - 29/09/2017 - (.Microsoft Corporation - Windows 启动应用程序.) -- C:\WINDOWS\System32\Wininit.exe [359584] =>.Microsoft Windows Publisher?
[MD5.D09D24A071007D66C9ED2B6B40B9D1D3] - 10/02/2018 - (.Microsoft Corporation - Win32 的 Internet 扩展.) -- C:\WINDOWS\System32\wininet.dll [3334144] =>.Microsoft Corporation
[MD5.D0926E8FC082646487BD159538F4D9F5] - 01/01/2018 - (.Microsoft Corporation - Windows 登录应用程序.) -- C:\WINDOWS\System32\Winlogon.exe [715776] =>.Microsoft Corporation
[MD5.4D487E7D2B047FB929BE00117C09F9EC] - 29/09/2017 - (.Microsoft Corporation - 软件授权库.) -- C:\WINDOWS\System32\sppcomapi.dll [414720] =>.Microsoft Corporation
[MD5.5AE3B789BC547BBBE2A876F587BE60F6] - 10/02/2018 - (.Microsoft Corporation - DNS 客户端 API DLL.) -- C:\WINDOWS\System32\dnsapi.dll [739696] =>.Microsoft Windows?
[MD5.66342F3BB289A5A370127F8385512A84] - 10/02/2018 - (.Microsoft Corporation - DNS 客户端 API DLL.) -- C:\WINDOWS\Syswow64\dnsapi.dll [597160] =>.Microsoft Windows?
[MD5.AD7B46330B55170ED706043DE88AC1A9] - 10/02/2018 - (.Microsoft Corporation - WinSock 的辅助功能驱动程序.) -- C:\WINDOWS\System32\drivers\AFD.sys [614296] =>.Microsoft Windows?
[MD5.6191B9B2EE0E8CB957C683B9B341CC86] - 29/09/2017 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [28568] =>.Microsoft Windows?
[MD5.9E82A95D77AC78C84BA75FF896B060BF] - 29/09/2017 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [93184] =>.Microsoft Corporation
[MD5.6D83565C1652E80447EDEA6947FA89D7] - 29/09/2017 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [159744] =>.Microsoft Corporation
[MD5.9910E9CFF5ECDCB225F82E72CE9DE459] - 29/09/2017 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\DfsC.sys [151040] =>.Microsoft Corporation
[MD5.99A34FD1F6431A10D8C3BB50E170D0F2] - 29/09/2017 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [86016] =>.Microsoft Corporation
[MD5.56FF074E50F9042FD2856AB3418F4B18] - 29/09/2017 - (.Microsoft Corporation - i8042 端口驱动程序.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [105984] =>.Microsoft Corporation
[MD5.7BEC2AF23F586EFF0DB4DBF4331B0C70] - 29/09/2017 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [214016] =>.Microsoft Corporation
[MD5.71729B1EE949E1B092CB5CB75CC63715] - 10/02/2018 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [494488] =>.Microsoft Windows?
[MD5.7FC54F2AF5EC52C7AC05AD90FFC757E6] - 01/01/2018 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [316928] =>.Microsoft Corporation
[MD5.B6FDEBE8F640E9173AD2BA3F9C014195] - 10/02/2018 - (.Microsoft Corporation - NT 文件系统驱动程序.) -- C:\WINDOWS\System32\drivers\ntfs.sys [2395032] =>.Microsoft Windows?
[MD5.2E07EC2C1622F5E7B535D62DCD61F3AB] - 29/09/2017 - (.Microsoft Corporation - 并行端口驱动程序.) -- C:\WINDOWS\System32\drivers\Parport.sys [98816] =>.Microsoft Corporation
[MD5.E0220BB6580D34001D4D1D133052DAA4] - 29/09/2017 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [106496] =>.Microsoft Corporation
[MD5.DF83769C92527DB50653F8FB57D001FF] - 30/09/2017 - (.Microsoft Corporation - Microsoft RDP 设备重定向程序.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [182784] =>.Microsoft Corporation
[MD5.571D82ABAC428D902ACA0CF60373C039] - 29/09/2017 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [121240] =>.Microsoft Windows?
[MD5.5B27846CF4B1C21AFB3A35A8336BA02F] - 08/12/2017 - (.Microsoft Corporation - 卷映像复制驱动程序.) -- C:\WINDOWS\System32\drivers\volsnap.sys [401304] =>.Microsoft Windows?

---\\ Non Microsoft non disabled Windows Services (24) - 2s
O23 - Service: Becca Service (Becca Service) . (.Rene.E Laboratory - Becca Service.) - E:\Program Files (x86)\Rene.E Laboratory\Becca\x64\bcservice.exe =>.Rene.E Laboratory Co., Ltd.?
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) . (.Intel Corporation - Intel HD Graphics Drivers for Windows(R).) - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2e329e8610bbb375\IntelCpHDCPSvc.exe =>.Intel(R) pGFX?
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) . (.Intel(R) Corporation - Intel(R) PROSet/Wireless Event Log Service.) - C:\Program Files\Intel\WiFi\bin\EvtEng.exe =>.Intel Corporation-Wireless Connectivity Solutions?
O23 - Service: ExpressVpn Service (ExpressVpnService) . (.Public Domain; Author Iain Patterson 2003-2014 - The non-sucking service manager.) - C:\Program Files (x86)\ExpressVPN\bootstrap\AMD64\nssm.exe =>.Express Vpn LLC?
O23 - Service: Google 更新服务 (gupdate) (gupdate) . (.Google Inc. - Google 安装程序.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc?
O23 - Service: @oem29.inf,%SERVICE_NAME%;Intel Bluetooth Service (ibtsiva) . (...) - C:\WINDOWS\System32\ibtsiva (.not file.) =>.Intel Corporation
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) . (.Intel Corporation - igfxCUIService Module.) - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2e329e8610bbb375\igfxCUIService.exe =>.Intel(R) pGFX?
O23 - Service: Intel(R) Security Assist Helper (isaHelperSvc) . (...) - C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe (.not file.) =>.Intel Corporation
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe =>.Intel Corporation - Embedded Subsystems and IP Blocks Group?
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Intel(R) Local Management Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation - Embedded Subsystems and IP Blocks Group?
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) . (.NVIDIA Corporation - NVIDIA Container.) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation?
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) . (.NVIDIA Corporation - NVIDIA Container.) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe =>.NVIDIA Corporation?
O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) . (.NVIDIA Corporation - NVIDIA Container.) - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe =>.NVIDIA Corporation?
O23 - Service: Origin Web Helper Service (Origin Web Helper Service) . (.Electronic Arts - OriginWebHelperService.) - C:\Program Files (x86)\Origin\OriginWebHelperService.exe =>.Electronic Arts, Inc.?
O23 - Service: On Screen Display Service (OSD) . (...) - C:\Program Files (x86)\OEM\OSD\OSDSrv.exe (.not file.)
O23 - Service: PnkBstrA (PnkBstrA) . (...) - C:\Windows\System32\PnkBstrA.exe (.not file.) =>.PunkBuster Games
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) . (.Intel(R) Corporation - Intel(R) PROSet/Wireless Registry Service.) - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe =>.Intel Corporation-Wireless Connectivity Solutions?
O23 - Service: Service KMSELDI (Service KMSELDI) . (.@ByELDI - Service_KMS.) - E:\Program Files\KMSpico\Service_KMS.exe =>HackTool.KMSpico
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) . (.Synaptics Incorporated - 64-bit Synaptics Pointing Enhance Service.) - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe =>.Synaptics Incorporated?
O23 - Service: UPSecurityInputService (UPSecurityInputService) . (.中国银联股份有限公司 - UPSecurityInputService.) - C:\Windows\SysWOW64\UPEditNew\UPService.exe {1F5E46E3B8C0B8C33918E7CB4BE3A31D}
O23 - Service: Windows Defender Helper Service (Windows 1703 Creators Upda (WinDefender) . (...) - C:\Windows\windefender.exe
O23 - Service: XLNXService (XLNXService) . (.深圳市迅雷网络技术有限公司 - XLNXService 动态链接库.) - C:\Users\VULCAN\AppData\Roaming\XLGameBox\ServicePlatform\XLNX.dll =>.ShenZhen Thunder Networking Technologies Ltd.?
O23 - Service: XLServicePlatform (XLServicePlatform) . (.深圳市迅雷网络技术有限公司 - XLServicePlatform.) - C:\Program Files (x86)\Common Files\Thunder Network\ServicePlatform\XLSP.dll {7506B5D2917A135C04E229EE21449A8D}
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) . (.Intel® Corporation - Intel® PROSet/Wireless Zero Configure Servi.) - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe =>.Intel Corporation-Wireless Connectivity Solutions?

---\\ Services not Microsoft (SR=Run, SS=Stop) (34) - 5s
SS - Demand [10/02/2018] [ 272384] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated?
SS - Auto [20/06/2017] [ 79344] Becca Service (Becca Service) . (.Rene.E Laboratory.) - E:\Program Files (x86)\Rene.E Laboratory\Becca\x64\bcservice.exe =>.Rene.E Laboratory Co., Ltd.?
SS - Demand [07/12/2017] [ 494032] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2e329e8610bbb375\IntelCpHeciSvc.exe =>.Intel(R) pGFX?
SS - Auto [07/12/2017] [ 477136] Intel(R) Content Protection HDCP Service (cplspcon) . (.Intel Corporation.) - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2e329e8610bbb375\IntelCpHDCPSvc.exe =>.Intel(R) pGFX?
SS - Demand [23/02/2018] [ 529056] EasyAntiCheat (EasyAntiCheat) . (.EasyAntiCheat Ltd.) - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe =>.EasyAntiCheat Oy?
SS - Auto [10/04/2017] [ 640928] Intel(R) PROSet/Wireless Event Log (EvtEng) . (.Intel(R) Corporation.) - C:\Program Files\Intel\WiFi\bin\EvtEng.exe =>.Intel Corporation-Wireless Connectivity Solutions?
SS - Auto [07/02/2018] [ 339168] ExpressVpn Service (ExpressVpnService) . (.Public Domain; Author Iain Patterson 2003-2014.) - C:\Program Files (x86)\ExpressVPN\bootstrap\AMD64\nssm.exe =>.Express Vpn LLC?
SS - Demand [20/03/2015] [ 344288] Futuremark SystemInfo Service (Futuremark SystemInfo Service) . (.Futuremark.) - C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe =>.FUTUREMARK INC?
SS - Demand [28/01/2018] [ 532552] GalaxyClientService (GalaxyClientService) . (.GOG.com.) - E:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe =>.GOG Sp. z o.o.?
SS - Demand [28/01/2018] [ 8345672] GalaxyCommunication (GalaxyCommunication) . (.GOG.com.) - C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe =>.GOG Sp. z o.o.?
SS - Auto [29/01/2017] [ 153752] Google 更新服务 (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc?
SS - Demand [29/01/2017] [ 153752] Google 更新服务 (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc?
SS - Auto [07/12/2017] [ 406480] Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) . (.Intel Corporation.) - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2e329e8610bbb375\igfxCUIService.exe =>.Intel(R) pGFX?
SS - Demand [22/05/2015] [ 881152] Intel(R) Capability Licensing Service TCP IP Interface (Intel(R) Capability Licensing Service TCP IP Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe =>.Intel® Trusted Connect Service?
SS - Auto [16/10/2015] [ 207648] Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe =>.Intel Corporation - Embedded Subsystems and IP Blocks Group?
SR - Auto [16/10/2015] [ 415520] Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation - Embedded Subsystems and IP Blocks Group?
SS - Demand [09/05/2017] [ 4470736] Malwarebytes Service (MBAMService) . (.Malwarebytes.) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation?
SS - Demand [15/02/2018] [ 194512] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation?
SS - Demand [10/04/2017] [ 268704] Wireless PAN DHCP Server (MyWiFiDHCPDNS) . (.Copyright (C) 2005-2010 by Achal Dhir.) - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe =>.Intel Corporation-Wireless Connectivity Solutions?
SR - Auto [10/01/2018] [ 519992] NVIDIA LocalSystem Container (NvContainerLocalSystem) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation?
SS - Demand [10/01/2018] [ 519992] NVIDIA NetworkService Container (NvContainerNetworkService) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation?
SR - Auto [24/02/2018] [ 462864] NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe =>.NVIDIA Corporation?
SR - Auto [10/01/2018] [ 461616] NVIDIA Telemetry Container (NvTelemetryContainer) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe =>.NVIDIA Corporation?
SS - Demand [19/12/2017] [ 2155328] Origin Client Service (Origin Client Service) . (.Electronic Arts.) - C:\Program Files (x86)\Origin\OriginClientService.exe =>.Electronic Arts, Inc.?
SS - Auto [19/12/2017] [ 3025224] Origin Web Helper Service (Origin Web Helper Service) . (.Electronic Arts.) - C:\Program Files (x86)\Origin\OriginWebHelperService.exe =>.Electronic Arts, Inc.?
SS - Auto [10/04/2017] [ 157600] Intel(R) PROSet/Wireless Registry Service (RegSrvc) . (.Intel(R) Corporation.) - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe =>.Intel Corporation-Wireless Connectivity Solutions?
SS - Auto [12/01/2016] [ 745664] Service KMSELDI (Service KMSELDI) . (.@ByELDI.) - E:\Program Files\KMSpico\Service_KMS.exe =>HackTool.KMSpico
SS - Demand [16/12/2017] [ 1644832] Steam Client Service (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe =>.Valve?
SS - Auto [03/12/2015] [ 251496] SynTPEnh Caller Service (SynTPEnhService) . (.Synaptics Incorporated.) - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe =>.Synaptics Incorporated?
SS - Auto [07/05/2016] [ 361240] UPSecurityInputService (UPSecurityInputService) . (.中国银联股份有限公司.) - C:\Windows\SysWOW64\UPEditNew\UPService.exe {1F5E46E3B8C0B8C33918E7CB4BE3A31D}
SS - Auto [09/03/2018] [ 3451904] Windows Defender Helper Service (Windows 1703 Creators Upda (WinDefender) . (...) - C:\Windows\windefender.exe
SR - Auto [07/12/2017] [ 151488] XLNXService (XLNXService) . (.深圳市迅雷网络技术有限公司.) - C:\Users\VULCAN\AppData\Roaming\XLGameBox\ServicePlatform\XLNX.dll =>.ShenZhen Thunder Networking Technologies Ltd.?
SR - Auto [07/12/2017] [ 164184] XLServicePlatform (XLServicePlatform) . (.深圳市迅雷网络技术有限公司.) - C:\Program Files (x86)\Common Files\Thunder Network\ServicePlatform\XLSP.dll {7506B5D2917A135C04E229EE21449A8D}
SS - Auto [10/04/2017] [ 3750304] Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) . (.Intel® Corporation.) - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe =>.Intel Corporation-Wireless Connectivity Solutions?

---\\ Task Planned Automatically (Register) (3) - 4s
O38 - TASK: {34CD3C1A-80D7-4A08-8152-D6F2DA4C8BE4} [64Bits][\AutoPico Daily Restart] - (.@ByELDI - AutoPico.) -- E:\Program Files\KMSpico\AutoPico.exe [745664] =>HackTool.KMSpico
O38 - TASK: {69DF136F-A45F-4ABF-8916-07C8CCDCB740} [64Bits][\Optimize Thumbnail Cache Files] - (.VULCANTSERIES\VULCAN - .) -- //nologo [0]
O38 - TASK: {95A973E7-DA68-4BDB-8867-061BCD644D2B} [64Bits][\MRT] - (.VULCANTSERIES\VULCAN - .) -- C:\Users\VULCAN\AppData\Local\Temp\csrss\mrt.exe [1482240]

---\\ Auto loading programs from Registry and folders (31) - 1s
O4 - HKLM\..\Run: [SecurityHealth] . (.Microsoft Corporation - Windows Defender notification icon.) -- C:\Program Files\Windows Defender\MSASCuiL.exe =>.Microsoft Windows?
O4 - HKLM\..\Run: [RTHDVCPL] . (. - .) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (.Not File.) =>.SUP.Orphan
O4 - HKLM\..\RunOnce: [rquxmiu5rpc] . (. - HDIZD89.) -- C:\Program Files (x86)\Free\184576.exe
O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\VULCAN\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation?
O4 - HKCU\..\Run: [ctfmon] . (.Microsoft Corporation - CTF 加载程序.) -- C:\Windows\System32\ctfmon.exe =>.Microsoft Corporation
O4 - HKCU\..\Run: [Thunder] . (.深圳市迅雷网络技术有限公司 - 迅雷.) -- C:\Program Files (x86)\Thunder Network\Thunder9\Program\Thunder.exe {7506B5D2917A135C04E229EE21449A8D}
O4 - HKCU\..\Run: [BaiduYunDetect] . (. - .) -- C:\Users\VULCAN\AppData\Roaming\baidu\BaiduNetdisk\YunDetectService.exe (.Not File.) =>.SUP.Orphan
O4 - HKCU\..\Run: [QQ2009] . (. - .) -- C:\Program Files (x86)\Tencent\QQ\Bin\QQ.exe (.Not File.) =>.SUP.Orphan
O4 - HKCU\..\Run: [Steam] . (.Valve Corporation - Steam Client Bootstrapper.) -- E:\Program Files (x86)\Steam\Steam.exe =>.Valve?
O4 - HKCU\..\Run: [XMP] . (. - .) -- C:\Users\Public\THUNDE~1\xmp5\V540~1.608\Program\XMP.exe (.Not File.) =>.SUP.Orphan
O4 - HKCU\..\Run: [SolitarySnowflake] . (.Copyright (C) 2017, naseshgera - .) -- C:\Windows\rss\csrss.exe =>Trojan.Dropper
O4 - HKCU\..\Run: [CloudNet] . (.EpicNet Inc. - Cloud Net.) -- C:\Users\VULCAN\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe =>Adware.MSIL
O4 - HKCU\..\Run: [ExpressVPN4] . (.ExpressVPN - ExpressVpn.) -- C:\Program Files (x86)\ExpressVPN\xvpn-ui\ExpressVpn.exe =>.Express Vpn LLC?
O4 - HKLM\..\Wow6432Node\Run: [OSD] . (. - .) -- C:\Program Files (x86)\OEM\OSD\OSDCtrl.exe (.Not File.) =>.SUP.Orphan
O4 - HKLM\..\Wow6432Node\Run: [EaseUS Cleanup] . (.CHENGDU Yiwo Tech Development Co., Ltd. - CleanUpUI Application.) -- E:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.0\bin\CleanUpUI.exe =>.CHENGDU YIWO Tech Development Co., Ltd.?
O4 - HKLM\..\Wow6432Node\Run: [kwWallpaper] . (...) -- E:\Program Files (x86)\kuwo\kuwomusic\8.7.2.0_BDS1\bin\KwWallpaper.exe {065913BF67E5B81FE1E8A83167EEFBFC}
O4 - HKLM\..\Wow6432Node\Run: [Multitimer] . (. - MutliTimer.) -- C:\Program Files (x86)\Multitimer\Multitimer.exe
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows?
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows?
O4 - HKUS\.DEFAULT\..\RunOnce: [Application Restart #0] . (. - .) -- C:\Program Files (x86)\OEM\OSD\OSD.exe (.Not File.) =>.SUP.Orphan
O4 - HKUS\S-1-5-18\..\RunOnce: [Application Restart #0] . (. - .) -- C:\Program Files (x86)\OEM\OSD\OSD.exe (.Not File.) =>.SUP.Orphan
O4 - HKUS\S-1-5-21-3795826015-3801581077-2544062959-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\VULCAN\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation?
O4 - HKUS\S-1-5-21-3795826015-3801581077-2544062959-1001\..\Run: [ctfmon] . (.Microsoft Corporation - CTF 加载程序.) -- C:\Windows\System32\ctfmon.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-3795826015-3801581077-2544062959-1001\..\Run: [Thunder] . (.深圳市迅雷网络技术有限公司 - 迅雷.) -- C:\Program Files (x86)\Thunder Network\Thunder9\Program\Thunder.exe {7506B5D2917A135C04E229EE21449A8D}
O4 - HKUS\S-1-5-21-3795826015-3801581077-2544062959-1001\..\Run: [BaiduYunDetect] . (. - .) -- C:\Users\VULCAN\AppData\Roaming\baidu\BaiduNetdisk\YunDetectService.exe (.Not File.) =>.SUP.Orphan
O4 - HKUS\S-1-5-21-3795826015-3801581077-2544062959-1001\..\Run: [QQ2009] . (. - .) -- C:\Program Files (x86)\Tencent\QQ\Bin\QQ.exe (.Not File.) =>.SUP.Orphan
O4 - HKUS\S-1-5-21-3795826015-3801581077-2544062959-1001\..\Run: [Steam] . (.Valve Corporation - Steam Client Bootstrapper.) -- E:\Program Files (x86)\Steam\Steam.exe =>.Valve?
O4 - HKUS\S-1-5-21-3795826015-3801581077-2544062959-1001\..\Run: [XMP] . (. - .) -- C:\Users\Public\THUNDE~1\xmp5\V540~1.608\Program\XMP.exe (.Not File.) =>.SUP.Orphan
O4 - HKUS\S-1-5-21-3795826015-3801581077-2544062959-1001\..\Run: [SolitarySnowflake] . (.Copyright (C) 2017, naseshgera - .) -- C:\Windows\rss\csrss.exe =>Trojan.Dropper
O4 - HKUS\S-1-5-21-3795826015-3801581077-2544062959-1001\..\Run: [CloudNet] . (.EpicNet Inc. - Cloud Net.) -- C:\Users\VULCAN\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe =>Adware.MSIL
O4 - HKUS\S-1-5-21-3795826015-3801581077-2544062959-1001\..\Run: [ExpressVPN4] . (.ExpressVPN - ExpressVpn.) -- C:\Program Files (x86)\ExpressVPN\xvpn-ui\ExpressVpn.exe =>.Express Vpn LLC?

---\\ Process running (19) - 2s
[MD5.A16B39D0612F4D0D530B4BD911F3980C] - (...) -- C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1807.264.0_x64__kzf8qxf38zg5c\SkypeHost.exe [86528] [PID.8724] =>.Skype Technologies
[MD5.E0195084724ACFFC70E2D35F418D2764] - (.Copyright (C) 2017, naseshgera - .) -- C:\Windows\rss\csrss.exe [3079168] [PID.12768] =>Trojan.Dropper
[MD5.5AD9D814037E4B3171947140AFA35B36] - (.Intel Corporation - Intel(R) Local Management Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [415520] [PID.5468] =>.Intel Corporation - Embedded Subsystems and IP Blocks Group?
[MD5.8072F1FC6C79F18279E31B95A373CAA2] - (.The OpenVPN Project - OpenVPN Daemon.) -- C:\Program Files (x86)\ExpressVPN\xvpnd\windows\openvpn.exe [768736] [PID.15820] =>.Express Vpn LLC?
[MD5.3918C0F0C8EB439F0B8D1F28E226B8D3] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462864] [PID.8556] =>.NVIDIA Corporation?
[MD5.64473C7916BAF33FE73F1A44C559E672] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [461616] [PID.4228] =>.NVIDIA Corporation?
[MD5.3918C0F0C8EB439F0B8D1F28E226B8D3] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462864] [PID.5612] =>.NVIDIA Corporation?
[MD5.44C7F062F78C5A055F68BF7C88ABA268] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519992] [PID.11816] =>.NVIDIA Corporation?
[MD5.83AB4F43219126138818DC273D596B7E] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe [467760] [PID.13352] =>.NVIDIA Corporation?
[MD5.83AB4F43219126138818DC273D596B7E] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe [467760] [PID.11680] =>.NVIDIA Corporation?
[MD5.22819EB3C648583352AE83003E4C9A56] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [439248] [PID.15196] =>.Mozilla Corporation?
[MD5.22819EB3C648583352AE83003E4C9A56] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [439248] [PID.16928] =>.Mozilla Corporation?
[MD5.22819EB3C648583352AE83003E4C9A56] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [439248] [PID.16232] =>.Mozilla Corporation?
[MD5.22819EB3C648583352AE83003E4C9A56] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [439248] [PID.14564] =>.Mozilla Corporation?
[MD5.9A3D76581E45A6E1AA1A6855315CCA9A] - (...) -- C:\Users\VULCAN\AppData\Local\Temp\wup\wup.exe [728576] [PID.14216]
[MD5.8278F33C1C20A643FD4D4703346356D0] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\VULCAN\Desktop\Cleaner\ZHPDiag3(1).exe [3034496] [PID.6156] =>.Nicolas Coolman
[MD5.22819EB3C648583352AE83003E4C9A56] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [439248] [PID.12596] =>.Mozilla Corporation?
[MD5.22819EB3C648583352AE83003E4C9A56] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [439248] [PID.8292] =>.Mozilla Corporation?
[MD5.EC74E7F21F226EC5B3D77E26B9F3509F] - (.www.xmrig.com - XMRig CUDA miner.) -- C:\Users\VULCAN\AppData\Local\Temp\wup\wupv.exe [2975744] [PID.6792] =>PUP.Optional.BitCoinMiner

---\\ Google Chrome, Start,Search,Extensions (4) - 0s
G2 - GCE: Preference [VULCAN][User Data\Default] [gighmmpiobklfepjocnamgkkbiglidom] Michael Gundlach =>.Wladimir Palant {AdBlock}
G2 - GCE: Preference [VULCAN][User Data\Default] [kffagfnfdicnffbkgpdcfnpgmedkmmdg] 边下边播助手
G2 - GCE: Preference [VULCAN][User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] =>.Google Inc. {Wallet}
G2 - GCE: Preference [VULCAN][User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.

---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (33) - 3s
M0 - MFSP: prefs.js [VULCAN - 2q8o7d6c.default] http://www.google.fr/ =>.Google Inc.
P2 - EXT FILE: (.Firefox Homepage - Customizied Home Page for Firefox.) -- C:\Users\VULCAN\AppData\Roaming\Mozilla\Firefox\Profiles\2q8o7d6c.default\extensions\cehomepage@mozillaonline.com.xpi
P2 - EXT FILE: (. - __MSG_extensionDescription__.) -- C:\Users\VULCAN\AppData\Roaming\Mozilla\Firefox\Profiles\2q8o7d6c.default\extensions\coba@mozilla.com.cn.xpi
P2 - EXT FILE: (.Addons Manager - To manage the addons package in Firefo.) -- C:\Users\VULCAN\AppData\Roaming\Mozilla\Firefox\Profiles\2q8o7d6c.default\extensions\cpmanager@mozillaonline.com.xpi
P2 - EXT FILE: (. - __MSG_extensionDescription__.) -- C:\Users\VULCAN\AppData\Roaming\Mozilla\Firefox\Profiles\2q8o7d6c.default\extensions\easyscreenshot@mozillaonline.com.xpi
P2 - EXT FILE: (.Mozilla Online Limited - Tab Tweak.) -- C:\Users\VULCAN\AppData\Roaming\Mozilla\Firefox\Profiles\2q8o7d6c.default\extensions\tabtweak@mozillaonline.com.xpi
P2 - EXT FILE: (. - __MSG_extensionDescription__.) -- C:\Users\VULCAN\AppData\Roaming\Mozilla\Firefox\Profiles\2q8o7d6c.default\extensions\wx-assistant@mozillaonline.com.xpi
P2 - EXT FILE: (.Search Web - Unzipper - This add-on redirects searches from ex.) -- C:\Users\VULCAN\AppData\Roaming\Mozilla\Firefox\Profiles\2q8o7d6c.default\extensions\{0fc22c4c-93ed-48ea-ad12-dc8039cf3795}.xpi
P2 - EXT FILE: (.Google Inc. - __MSG_description__", .) -- C:\Users\VULCAN\AppData\Roaming\Mozilla\Firefox\Profiles\2q8o7d6c.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi =>.Google Inc.
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\activity-stream@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\aushelper@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\followonsearch@mozilla.com.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\formautofill@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\onboarding@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\shield-recipe-client@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT: (...) -- C:\Users\VULCAN\AppData\Roaming\Mozilla\Firefox\Profiles\2q8o7d6c.default\extensions\trash =>.Mozilla Corporation
P2 - EXT: (.agunchan - xThunder.) -- C:\Users\VULCAN\AppData\Roaming\Mozilla\Firefox\Profiles\2q8o7d6c.default\extensions\xthunder@lshai.com
P2 - FPN: [HKCU] [@1.qq.com/npqqwebgame] - (...) -- C:\Users\VULCAN\AppData\Roaming\Tencent\WebGamePlugin\1.0.4.3\npqqwebgame.dll =>.SUP.Tencent
P2 - FPN: [HKCU] [@xunlei.com/npxunlei;version=1.0.0.2] - (.Thunder.) -- C:\Program Files (x86)\Thunder Network\Thunder9\Data\npxunlei1.0.0.2.dll =>.Thunder
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_161.dll =>.Adobe Systems Incorporated
P2 - FPN: [HKLM] [@baidu.com/BaiduExpert-npplugin] - (.百度在线网络技术(北京)有限公司.) -- C:\Users\VULCAN\AppData\Roaming\baidu\BDWebAdapter\3.0.348.0\npBDExNP.dll
P2 - FPN: [HKLM] [@qq.com/npqscall] - (.Tencent.) -- C:\Program Files (x86)\Common Files\Tencent\Npchrome\npactivex.dll =>.SUP.Tencent
P2 - FPN: [HKLM] [@qq.com/QQMiniDLPlugin] - (.Tencent.) -- C:\Program Files (x86)\Common Files\Tencent\QQMiniDL\60\Browser\npXFMiniDLPlugin.dll =>.SUP.Tencent
P2 - FPN: [HKLM] [@qq.com/QQPhotoDrawEx] - (.QQPhotoDrawEx.) -- C:\Program Files (x86)\Tencent\Qzone\npQQPhotoDrawEx.dll =>.SUP.Tencent
P2 - FPN: [HKLM] [@qq.com/QzoneMusic] - (.Tencent.) -- C:\Program Files (x86)\Tencent\QQMusic\QzoneMusic\npQzoneMusic.dll =>.SUP.Tencent
P2 - FPN: [HKLM] [@qq.com/TXSSO] - (.Tencent.) -- C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.5.18\bin\npSSOAxCtrlForPTLogin.dll =>.SUP.Tencent
P2 - FPN: [HKLM] [@tencent.com/npQQMailWebKit,version=1.0.0.1] - (.Tencent QQMail Plugin for Webkit.) -- C:\Program Files (x86)\QQMailPlugin\npQQMailWebKit.dll =>.SUP.Tencent
P2 - FPN: [HKLM] [@tencent.com/nptxftnWebKit,version=1.0.0.1] - (.Tencent FTN plug-in.) -- C:\Program Files (x86)\QQMailPlugin\nptxftnWebKit.dll =>.SUP.Tencent
P2 - FPN: [HKLM] [@xunlei.com/npaplayer] - (.ShenZhen Thunder Networking Technologies, LTD.) -- C:\Users\Public\Thunder Network\APlayer\codecs\npaplayer.dll
P2 - FPN: [HKLM] [@xunlei.com/npxunlei;version=1.0.0.1] - (.Thunder.) -- C:\Program Files (x86)\Thunder Network\Thunder9\Data\npxunlei1.0.0.2.dll =>.Thunder

---\\ Internet Explorer Extensions, Start, Search (16) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKCU\SOFTWARE\Policies\Microsoft\Internet Explorer\Main,Start Page = http://gotot.fuzhugo.com
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet 浏览器.) (11.00.16299.15 (WinBuild.160101.0800)) -- C:\Windows\System32\ieframe.dll =>.Microsoft Corporation

---\\ Microsoft Edge,Plugins,Start,Search,Extensions (1) - 0s
E0 - Microsoft Edge: HKU\S-1-5-21-3795826015-3801581077-2544062959-1001\HomeButtonPage = http://hao.360.cn/

---\\ Internet Explorer, Proxy Management (3) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 =>.Default.Value
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
F2 - REG:system.ini: UserInit=
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=

---\\ Hosts file redirection (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (53)

---\\ Browser Helper Object (BHO) (1) - 0s
O2 - BHO: XunleiBHO [64Bits] - {004B0726-A010-4ABF-8556-FCDB7F1FCA1E} . (.深圳市迅雷网络技术有限公司 - XunLeiBHO64.) -- C:\Program Files (x86)\Thunder Network\Thunder9\BHO\XunleiBHO649.1.44.952.dll {7506B5D2917A135C04E229EE21449A8D} =>PUP.Optional.Xunlei

---\\ Global shortcuts Startup (273) - 13s
O4 - GS\Desktop [Administrator]: Badoo.lnk . (.Badoo Software Ltd - Badoo.) C:\Users\VULCAN\AppData\Local\Programs\Badoo\Badoo.exe
O4 - GS\Desktop [Administrator]: Crysis with BlackFire's Mod Ultimate.lnk . (...) C:\Users\VULCAN\Desktop\Crysis\BFMU.bat
O4 - GS\Desktop [Administrator]: Crysis.lnk . (...) C:\Users\VULCAN\Desktop\Crysis\Bin64\Crysis.exe -mod CrysisExpanded -devmode
O4 - GS\Desktop [Administrator]: Crysis2 - 快捷方式.lnk . (.Crytek GmbH - .) G:\Youxun\Install\Crysis2_chs\bin32\Crysis2.exe =>.Crytek GmbH
O4 - GS\Desktop [Administrator]: Cuphead - 快捷方式.lnk . (...) F:\Youxun\Install\Cuphead_chs\Cuphead.exe
O4 - GS\Desktop [Administrator]: Detention - 快捷方式.lnk . (...) E:\Detention\Detention.exe
O4 - GS\Desktop [Administrator]: Dolphin.lnk . (...) E:\Program Files\Dolphin\Dolphin.exe
O4 - GS\Desktop [Administrator]: Freedom - 快捷方式.lnk . (...) E:\game\Soldaty Svobody\Freedom.Exe
O4 - GS\Desktop [Administrator]: Furi - 快捷方式.lnk . (...) E:\Program Files (x86)\Furi zhongwenban\Furi.exe
O4 - GS\Desktop [Administrator]: Grim Dawn - 快捷方式.lnk . (...) F:\Grim Dawn\Grim Dawn.exe
O4 - GS\Desktop [Administrator]: nex_machina - 快捷方式.lnk . (...) G:\yxdown\NexMachinaV1.04.0027_chs\nex_machina.exe
O4 - GS\Desktop [Administrator]: Outlast2 - 快捷方式.lnk . (.Red Barrels Inc. - Outlast 2.) F:\Outlast 2\Binaries\Win64\Outlast2.exe =>.Red Barrels Inc.
O4 - GS\Desktop [Administrator]: Renee Becca.lnk . (...) E:\Program Files (x86)\Rene.E Laboratory\Becca\Becca.exe =>.Rene.E Laboratory Co., Ltd.?
O4 - GS\Desktop [Administrator]: Saved files - 快捷方式.lnk . (...) E:\Saved files
O4 - GS\Desktop [Administrator]: SpeedFan.lnk . (...) C:\Program Files (x86)\SpeedFan\speedfan.exe =>.SOKNO S.R.L.?
O4 - GS\Desktop [Administrator]: Steam - 快捷方式.lnk . (...) G:\Program Files (x86)\Steam\Steam.exe
O4 - GS\Desktop [Administrator]: SuicideGuy - 快捷方式.lnk . (...) G:\yxdown\SuicideGuy_en\SuicideGuy.exe
O4 - GS\Desktop [Administrator]: Twitch.lnk . (.Twitch Interactive, Inc. - Twitch.) C:\Users\VULCAN\AppData\Roaming\Twitch\Bin\Twitch.exe =>.Twitch Interactive, Inc.?
O4 - GS\Desktop [Administrator]: Uplay.lnk . (.Ubisoft - Uplay launcher.) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe =>.Ubisoft Entertainment Sweden AB?
O4 - GS\Desktop [Administrator]: witness64_d3d11 - 快捷方式.lnk . (...) G:\Program Files (x86)\The Witness\witness64_d3d11.exe
O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\VULCAN\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Administrator]: 乐游游戏盒.lnk . (.昆山百诺信息科技有限公司 - 游戏盒.) G:\Program Files (x86)\leyoubox\igame.exe {2DDA7BAADFC10935C9DD9523623C9989}
O4 - GS\Desktop [Administrator]: 百度网盘.lnk . (.Baidu. All rights reserved. - BaiduNetdisk.) C:\Users\VULCAN\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdisk.exe {1FD2D30E260FC289CFAF11518F2CD36F}
O4 - GS\Desktop [Administrator]: 迅雷.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷.) C:\Program Files (x86)\Thunder Network\Thunder9\Program\Thunder.exe -StartType:DesktopIcon {7506B5D2917A135C04E229EE21449A8D}
O4 - GS\Desktop [Administrator]: 银联安全控件非插件版.lnk . (.中国银联股份有限公司 - UPSecurityInput.) C:\Windows\SysWOW64\UPEditNew\UPSecurityInput.exe {1F5E46E3B8C0B8C33918E7CB4BE3A31D}
O4 - GS\Quicklaunch [Administrator]: DS3 Tool.lnk . (.www.motioninjoy.com - DS3_Tool.) C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe =>.www.motioninjoy.com
O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc?
O4 - GS\Quicklaunch [Administrator]: Mozilla Firefox.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation?
O4 - GS\Quicklaunch [Administrator]: Nexus Mod Manager.lnk . (.Black Tree Gaming - Nexus Mod Manager.) E:\Program Files\Nexus Mod Manager\NexusClient.exe =>.Black Tree Gaming Ltd.?
O4 - GS\Quicklaunch [Administrator]: Renee Becca.lnk . (...) E:\Program Files (x86)\Rene.E Laboratory\Becca\Becca.exe =>.Rene.E Laboratory Co., Ltd.?
O4 - GS\Quicklaunch [Administrator]: Shareaza.lnk . (.Shareaza Development Team - Shareaza Ultimate File Sharing.) E:\Program Files\Shareaza\Shareaza.exe =>.Shareaza Development Team
O4 - GS\Quicklaunch [Administrator]: 易我分区管理大师 11.0.lnk . (.EaseUS - EaseUS Partition Master Loader Application.) E:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.0\bin\epm0.exe =>.CHENGDU YIWO Tech Development Co., Ltd.?
O4 - GS\Quicklaunch [Administrator]: 百度网盘.lnk . (.Baidu. All rights reserved. - BaiduNetdisk.) C:\Users\VULCAN\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdisk.exe {1FD2D30E260FC289CFAF11518F2CD36F}
O4 - GS\Quicklaunch [Administrator]: 腾讯QQ.lnk . (.Tencent - 腾讯QQ.) C:\Program Files (x86)\Tencent\QQ\Bin\QQScLauncher.exe =>.SUP.Tencent
O4 - GS\Quicklaunch [Administrator]: 迅雷.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷.) C:\Program Files (x86)\Thunder Network\Thunder9\Program\Thunder.exe -StartType:QuickLaunch {7506B5D2917A135C04E229EE21449A8D}
O4 - GS\Quicklaunch [Administrator]: 酷我音乐.lnk . (.酷我科技 - 酷我音乐.) E:\Program Files (x86)\kuwo\kuwomusic\8.7.2.0_BDS1\bin\KwMusic.exe {065913BF67E5B81FE1E8A83167EEFBFC}
O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrator]: 传真收件人.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrator]: 蓝牙文件传送.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: CPUCores.lnk . (...) C:\Users\VULCAN\Desktop\CPUCores18\cpucores.exe
O4 - GS\TaskBar [Administrator]: ExpressVPN.lnk . (.ExpressVPN - ExpressVpn.) C:\Program Files (x86)\ExpressVPN\xvpn-ui\ExpressVpn.exe =>.Express Vpn LLC?
O4 - GS\TaskBar [Administrator]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation?
O4 - GS\TaskBar [Administrator]: nullDC_Win32_Release.lnk . (...) C:\Users\VULCAN\Desktop\nullDC 1.04 r150 SM-A Fixes by masterchan777\nullDC_Win32_Release.exe
O4 - GS\TaskBar [Administrator]: Snipping Tool.lnk . (.Microsoft Corporation - 截图工具.) C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: World of Warcraft.lnk . (.Blizzard Entertainment - World of Warcraft.) G:\WOW-NOSTALGEEK\WoW.exe =>.Blizzard Entertainment
O4 - GS\TaskBar [Administrator]: 迅雷.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷.) C:\Program Files (x86)\Thunder Network\Thunder9\Program\Thunder.exe -StartType:PinTaskbar {7506B5D2917A135C04E229EE21449A8D}
O4 - GS\TaskBar [Administrator]: 迅雷影音.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷影音.) C:\Program Files (x86)\Thunder Network\XMP\V5.4.0.6088\Bin\XMP.exe /sstartfrom QuickLaunch /sopenfrom QuickLaunch {4A9EFF30A343AA0DE042347C}
O4 - GS\TaskBar [Administrator]: 酷我音乐.lnk . (.酷我科技 - 酷我音乐.) E:\Program Files (x86)\kuwo\kuwomusic\8.7.2.0_BDS1\bin\KwMusic.exe {065913BF67E5B81FE1E8A83167EEFBFC}
O4 - GS\Startup [Administrator]: KwGBDeamon.lnk . (.酷我科技 - KwGBDeamon.) C:\ProgramData\KWGameBox\KwGameBox\bin\KwGBDeamon.exe {50DA1504909F7273486D47AC0AB74675}
O4 - GS\Programs [Administrator]: Badoo.lnk . (.Badoo Software Ltd - Badoo.) C:\Users\VULCAN\AppData\Local\Programs\Badoo\Badoo.exe
O4 - GS\Programs [Administrator]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\VULCAN\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation?
O4 - GS\Programs [Administrator]: Twitch.lnk . (.Twitch Interactive, Inc. - Twitch.) C:\Users\VULCAN\AppData\Roaming\Twitch\Bin\Twitch.exe =>.Twitch Interactive, Inc.?
O4 - GS\Programs [Administrator]: 可选功能.lnk . (.Microsoft Corporation - 需求帮助程序的功能.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Desktop [Guest]: Badoo.lnk . (.Badoo Software Ltd - Badoo.) C:\Users\VULCAN\AppData\Local\Programs\Badoo\Badoo.exe
O4 - GS\Desktop [Guest]: Crysis with BlackFire's Mod Ultimate.lnk . (...) C:\Users\VULCAN\Desktop\Crysis\BFMU.bat
O4 - GS\Desktop [Guest]: Crysis.lnk . (...) C:\Users\VULCAN\Desktop\Crysis\Bin64\Crysis.exe -mod CrysisExpanded -devmode
O4 - GS\Desktop [Guest]: Crysis2 - 快捷方式.lnk . (.Crytek GmbH - .) G:\Youxun\Install\Crysis2_chs\bin32\Crysis2.exe =>.Crytek GmbH
O4 - GS\Desktop [Guest]: Cuphead - 快捷方式.lnk . (...) F:\Youxun\Install\Cuphead_chs\Cuphead.exe
O4 - GS\Desktop [Guest]: Detention - 快捷方式.lnk . (...) E:\Detention\Detention.exe
O4 - GS\Desktop [Guest]: Dolphin.lnk . (...) E:\Program Files\Dolphin\Dolphin.exe
O4 - GS\Desktop [Guest]: Freedom - 快捷方式.lnk . (...) E:\game\Soldaty Svobody\Freedom.Exe
O4 - GS\Desktop [Guest]: Furi - 快捷方式.lnk . (...) E:\Program Files (x86)\Furi zhongwenban\Furi.exe
O4 - GS\Desktop [Guest]: Grim Dawn - 快捷方式.lnk . (...) F:\Grim Dawn\Grim Dawn.exe
O4 - GS\Desktop [Guest]: nex_machina - 快捷方式.lnk . (...) G:\yxdown\NexMachinaV1.04.0027_chs\nex_machina.exe
O4 - GS\Desktop [Guest]: Outlast2 - 快捷方式.lnk . (.Red Barrels Inc. - Outlast 2.) F:\Outlast 2\Binaries\Win64\Outlast2.exe =>.Red Barrels Inc.
O4 - GS\Desktop [Guest]: Renee Becca.lnk . (...) E:\Program Files (x86)\Rene.E Laboratory\Becca\Becca.exe =>.Rene.E Laboratory Co., Ltd.?
O4 - GS\Desktop [Guest]: Saved files - 快捷方式.lnk . (...) E:\Saved files
O4 - GS\Desktop [Guest]: SpeedFan.lnk . (...) C:\Program Files (x86)\SpeedFan\speedfan.exe =>.SOKNO S.R.L.?
O4 - GS\Desktop [Guest]: Steam - 快捷方式.lnk . (...) G:\Program Files (x86)\Steam\Steam.exe
O4 - GS\Desktop [Guest]: SuicideGuy - 快捷方式.lnk . (...) G:\yxdown\SuicideGuy_en\SuicideGuy.exe
O4 - GS\Desktop [Guest]: Twitch.lnk . (.Twitch Interactive, Inc. - Twitch.) C:\Users\VULCAN\AppData\Roaming\Twitch\Bin\Twitch.exe =>.Twitch Interactive, Inc.?
O4 - GS\Desktop [Guest]: Uplay.lnk . (.Ubisoft - Uplay launcher.) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe =>.Ubisoft Entertainment Sweden AB?
O4 - GS\Desktop [Guest]: witness64_d3d11 - 快捷方式.lnk . (...) G:\Program Files (x86)\The Witness\witness64_d3d11.exe
O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\VULCAN\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Guest]: 乐游游戏盒.lnk . (.昆山百诺信息科技有限公司 - 游戏盒.) G:\Program Files (x86)\leyoubox\igame.exe {2DDA7BAADFC10935C9DD9523623C9989}
O4 - GS\Desktop [Guest]: 百度网盘.lnk . (.Baidu. All rights reserved. - BaiduNetdisk.) C:\Users\VULCAN\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdisk.exe {1FD2D30E260FC289CFAF11518F2CD36F}
O4 - GS\Desktop [Guest]: 迅雷.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷.) C:\Program Files (x86)\Thunder Network\Thunder9\Program\Thunder.exe -StartType:DesktopIcon {7506B5D2917A135C04E229EE21449A8D}
O4 - GS\Desktop [Guest]: 银联安全控件非插件版.lnk . (.中国银联股份有限公司 - UPSecurityInput.) C:\Windows\SysWOW64\UPEditNew\UPSecurityInput.exe {1F5E46E3B8C0B8C33918E7CB4BE3A31D}
O4 - GS\Quicklaunch [Guest]: DS3 Tool.lnk . (.www.motioninjoy.com - DS3_Tool.) C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe =>.www.motioninjoy.com
O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc?
O4 - GS\Quicklaunch [Guest]: Mozilla Firefox.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation?
O4 - GS\Quicklaunch [Guest]: Nexus Mod Manager.lnk . (.Black Tree Gaming - Nexus Mod Manager.) E:\Program Files\Nexus Mod Manager\NexusClient.exe =>.Black Tree Gaming Ltd.?
O4 - GS\Quicklaunch [Guest]: Renee Becca.lnk . (...) E:\Program Files (x86)\Rene.E Laboratory\Becca\Becca.exe =>.Rene.E Laboratory Co., Ltd.?
O4 - GS\Quicklaunch [Guest]: Shareaza.lnk . (.Shareaza Development Team - Shareaza Ultimate File Sharing.) E:\Program Files\Shareaza\Shareaza.exe =>.Shareaza Development Team
O4 - GS\Quicklaunch [Guest]: 易我分区管理大师 11.0.lnk . (.EaseUS - EaseUS Partition Master Loader Application.) E:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.0\bin\epm0.exe =>.CHENGDU YIWO Tech Development Co., Ltd.?
O4 - GS\Quicklaunch [Guest]: 百度网盘.lnk . (.Baidu. All rights reserved. - BaiduNetdisk.) C:\Users\VULCAN\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdisk.exe {1FD2D30E260FC289CFAF11518F2CD36F}
O4 - GS\Quicklaunch [Guest]: 腾讯QQ.lnk . (.Tencent - 腾讯QQ.) C:\Program Files (x86)\Tencent\QQ\Bin\QQScLauncher.exe =>.SUP.Tencent
O4 - GS\Quicklaunch [Guest]: 迅雷.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷.) C:\Program Files (x86)\Thunder Network\Thunder9\Program\Thunder.exe -StartType:QuickLaunch {7506B5D2917A135C04E229EE21449A8D}
O4 - GS\Quicklaunch [Guest]: 酷我音乐.lnk . (.酷我科技 - 酷我音乐.) E:\Program Files (x86)\kuwo\kuwomusic\8.7.2.0_BDS1\bin\KwMusic.exe {065913BF67E5B81FE1E8A83167EEFBFC}
O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Guest]: 传真收件人.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Guest]: 蓝牙文件传送.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: CPUCores.lnk . (...) C:\Users\VULCAN\Desktop\CPUCores18\cpucores.exe
O4 - GS\TaskBar [Guest]: ExpressVPN.lnk . (.ExpressVPN - ExpressVpn.) C:\Program Files (x86)\ExpressVPN\xvpn-ui\ExpressVpn.exe =>.Express Vpn LLC?
O4 - GS\TaskBar [Guest]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation?
O4 - GS\TaskBar [Guest]: nullDC_Win32_Release.lnk . (...) C:\Users\VULCAN\Desktop\nullDC 1.04 r150 SM-A Fixes by masterchan777\nullDC_Win32_Release.exe
O4 - GS\TaskBar [Guest]: Snipping Tool.lnk . (.Microsoft Corporation - 截图工具.) C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: World of Warcraft.lnk . (.Blizzard Entertainment - World of Warcraft.) G:\WOW-NOSTALGEEK\WoW.exe =>.Blizzard Entertainment
O4 - GS\TaskBar [Guest]: 迅雷.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷.) C:\Program Files (x86)\Thunder Network\Thunder9\Program\Thunder.exe -StartType:PinTaskbar {7506B5D2917A135C04E229EE21449A8D}
O4 - GS\TaskBar [Guest]: 迅雷影音.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷影音.) C:\Program Files (x86)\Thunder Network\XMP\V5.4.0.6088\Bin\XMP.exe /sstartfrom QuickLaunch /sopenfrom QuickLaunch {4A9EFF30A343AA0DE042347C}
O4 - GS\TaskBar [Guest]: 酷我音乐.lnk . (.酷我科技 - 酷我音乐.) E:\Program Files (x86)\kuwo\kuwomusic\8.7.2.0_BDS1\bin\KwMusic.exe {065913BF67E5B81FE1E8A83167EEFBFC}
O4 - GS\Startup [Guest]: KwGBDeamon.lnk . (.酷我科技 - KwGBDeamon.) C:\ProgramData\KWGameBox\KwGameBox\bin\KwGBDeamon.exe {50DA1504909F7273486D47AC0AB74675}
O4 - GS\Programs [Guest]: Badoo.lnk . (.Badoo Software Ltd - Badoo.) C:\Users\VULCAN\AppData\Local\Programs\Badoo\Badoo.exe
O4 - GS\Programs [Guest]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\VULCAN\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation?
O4 - GS\Programs [Guest]: Twitch.lnk . (.Twitch Interactive, Inc. - Twitch.) C:\Users\VULCAN\AppData\Roaming\Twitch\Bin\Twitch.exe =>.Twitch Interactive, Inc.?
O4 - GS\Programs [Guest]: 可选功能.lnk . (.Microsoft Corporation - 需求帮助程序的功能.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Desktop [VULCAN]: Badoo.lnk . (.Badoo Software Ltd - Badoo.) C:\Users\VULCAN\AppData\Local\Programs\Badoo\Badoo.exe
O4 - GS\Desktop [VULCAN]: Crysis with BlackFire's Mod Ultimate.lnk . (...) C:\Users\VULCAN\Desktop\Crysis\BFMU.bat
O4 - GS\Desktop [VULCAN]: Crysis.lnk . (...) C:\Users\VULCAN\Desktop\Crysis\Bin64\Crysis.exe -mod CrysisExpanded -devmode
O4 - GS\Desktop [VULCAN]: Crysis2 - 快捷方式.lnk . (.Crytek GmbH - .) G:\Youxun\Install\Crysis2_chs\bin32\Crysis2.exe =>.Crytek GmbH
O4 - GS\Desktop [VULCAN]: Cuphead - 快捷方式.lnk . (...) F:\Youxun\Install\Cuphead_chs\Cuphead.exe
O4 - GS\Desktop [VULCAN]: Detention - 快捷方式.lnk . (...) E:\Detention\Detention.exe
O4 - GS\Desktop [VULCAN]: Dolphin.lnk . (...) E:\Program Files\Dolphin\Dolphin.exe
O4 - GS\Desktop [VULCAN]: Freedom - 快捷方式.lnk . (...) E:\game\Soldaty Svobody\Freedom.Exe
O4 - GS\Desktop [VULCAN]: Furi - 快捷方式.lnk . (...) E:\Program Files (x86)\Furi zhongwenban\Furi.exe
O4 - GS\Desktop [VULCAN]: Grim Dawn - 快捷方式.lnk . (...) F:\Grim Dawn\Grim Dawn.exe
O4 - GS\Desktop [VULCAN]: nex_machina - 快捷方式.lnk . (...) G:\yxdown\NexMachinaV1.04.0027_chs\nex_machina.exe
O4 - GS\Desktop [VULCAN]: Outlast2 - 快捷方式.lnk . (.Red Barrels Inc. - Outlast 2.) F:\Outlast 2\Binaries\Win64\Outlast2.exe =>.Red Barrels Inc.
O4 - GS\Desktop [VULCAN]: Renee Becca.lnk . (...) E:\Program Files (x86)\Rene.E Laboratory\Becca\Becca.exe =>.Rene.E Laboratory Co., Ltd.?
O4 - GS\Desktop [VULCAN]: Saved files - 快捷方式.lnk . (...) E:\Saved files
O4 - GS\Desktop [VULCAN]: SpeedFan.lnk . (...) C:\Program Files (x86)\SpeedFan\speedfan.exe =>.SOKNO S.R.L.?
O4 - GS\Desktop [VULCAN]: Steam - 快捷方式.lnk . (...) G:\Program Files (x86)\Steam\Steam.exe
O4 - GS\Desktop [VULCAN]: SuicideGuy - 快捷方式.lnk . (...) G:\yxdown\SuicideGuy_en\SuicideGuy.exe
O4 - GS\Desktop [VULCAN]: Twitch.lnk . (.Twitch Interactive, Inc. - Twitch.) C:\Users\VULCAN\AppData\Roaming\Twitch\Bin\Twitch.exe =>.Twitch Interactive, Inc.?
O4 - GS\Desktop [VULCAN]: Uplay.lnk . (.Ubisoft - Uplay launcher.) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe =>.Ubisoft Entertainment Sweden AB?
O4 - GS\Desktop [VULCAN]: witness64_d3d11 - 快捷方式.lnk . (...) G:\Program Files (x86)\The Witness\witness64_d3d11.exe
O4 - GS\Desktop [VULCAN]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\VULCAN\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [VULCAN]: 乐游游戏盒.lnk . (.昆山百诺信息科技有限公司 - 游戏盒.) G:\Program Files (x86)\leyoubox\igame.exe {2DDA7BAADFC10935C9DD9523623C9989}
O4 - GS\Desktop [VULCAN]: 百度网盘.lnk . (.Baidu. All rights reserved. - BaiduNetdisk.) C:\Users\VULCAN\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdisk.exe {1FD2D30E260FC289CFAF11518F2CD36F}
O4 - GS\Desktop [VULCAN]: 迅雷.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷.) C:\Program Files (x86)\Thunder Network\Thunder9\Program\Thunder.exe -StartType:DesktopIcon {7506B5D2917A135C04E229EE21449A8D}
O4 - GS\Desktop [VULCAN]: 银联安全控件非插件版.lnk . (.中国银联股份有限公司 - UPSecurityInput.) C:\Windows\SysWOW64\UPEditNew\UPSecurityInput.exe {1F5E46E3B8C0B8C33918E7CB4BE3A31D}
O4 - GS\Quicklaunch [VULCAN]: DS3 Tool.lnk . (.www.motioninjoy.com - DS3_Tool.) C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe =>.www.motioninjoy.com
O4 - GS\Quicklaunch [VULCAN]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc?
O4 - GS\Quicklaunch [VULCAN]: Mozilla Firefox.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation?
O4 - GS\Quicklaunch [VULCAN]: Nexus Mod Manager.lnk . (.Black Tree Gaming - Nexus Mod Manager.) E:\Program Files\Nexus Mod Manager\NexusClient.exe =>.Black Tree Gaming Ltd.?
O4 - GS\Quicklaunch [VULCAN]: Renee Becca.lnk . (...) E:\Program Files (x86)\Rene.E Laboratory\Becca\Becca.exe =>.Rene.E Laboratory Co., Ltd.?
O4 - GS\Quicklaunch [VULCAN]: Shareaza.lnk . (.Shareaza Development Team - Shareaza Ultimate File Sharing.) E:\Program Files\Shareaza\Shareaza.exe =>.Shareaza Development Team
O4 - GS\Quicklaunch [VULCAN]: 易我分区管理大师 11.0.lnk . (.EaseUS - EaseUS Partition Master Loader Application.) E:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.0\bin\epm0.exe =>.CHENGDU YIWO Tech Development Co., Ltd.?
O4 - GS\Quicklaunch [VULCAN]: 百度网盘.lnk . (.Baidu. All rights reserved. - BaiduNetdisk.) C:\Users\VULCAN\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdisk.exe {1FD2D30E260FC289CFAF11518F2CD36F}
O4 - GS\Quicklaunch [VULCAN]: 腾讯QQ.lnk . (.Tencent - 腾讯QQ.) C:\Program Files (x86)\Tencent\QQ\Bin\QQScLauncher.exe =>.SUP.Tencent
O4 - GS\Quicklaunch [VULCAN]: 迅雷.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷.) C:\Program Files (x86)\Thunder Network\Thunder9\Program\Thunder.exe -StartType:QuickLaunch {7506B5D2917A135C04E229EE21449A8D}
O4 - GS\Quicklaunch [VULCAN]: 酷我音乐.lnk . (.酷我科技 - 酷我音乐.) E:\Program Files (x86)\kuwo\kuwomusic\8.7.2.0_BDS1\bin\KwMusic.exe {065913BF67E5B81FE1E8A83167EEFBFC}
O4 - GS\sendTo [VULCAN]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [VULCAN]: 传真收件人.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [VULCAN]: 蓝牙文件传送.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [VULCAN]: CPUCores.lnk . (...) C:\Users\VULCAN\Desktop\CPUCores18\cpucores.exe
O4 - GS\TaskBar [VULCAN]: ExpressVPN.lnk . (.ExpressVPN - ExpressVpn.) C:\Program Files (x86)\ExpressVPN\xvpn-ui\ExpressVpn.exe =>.Express Vpn LLC?
O4 - GS\TaskBar [VULCAN]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation?
O4 - GS\TaskBar [VULCAN]: nullDC_Win32_Release.lnk . (...) C:\Users\VULCAN\Desktop\nullDC 1.04 r150 SM-A Fixes by masterchan777\nullDC_Win32_Release.exe
O4 - GS\TaskBar [VULCAN]: Snipping Tool.lnk . (.Microsoft Corporation - 截图工具.) C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\TaskBar [VULCAN]: World of Warcraft.lnk . (.Blizzard Entertainment - World of Warcraft.) G:\WOW-NOSTALGEEK\WoW.exe =>.Blizzard Entertainment
O4 - GS\TaskBar [VULCAN]: 迅雷.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷.) C:\Program Files (x86)\Thunder Network\Thunder9\Program\Thunder.exe -StartType:PinTaskbar {7506B5D2917A135C04E229EE21449A8D}
O4 - GS\TaskBar [VULCAN]: 迅雷影音.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷影音.) C:\Program Files (x86)\Thunder Network\XMP\V5.4.0.6088\Bin\XMP.exe /sstartfrom QuickLaunch /sopenfrom QuickLaunch {4A9EFF30A343AA0DE042347C}
O4 - GS\TaskBar [VULCAN]: 酷我音乐.lnk . (.酷我科技 - 酷我音乐.) E:\Program Files (x86)\kuwo\kuwomusic\8.7.2.0_BDS1\bin\KwMusic.exe {065913BF67E5B81FE1E8A83167EEFBFC}
O4 - GS\Startup [VULCAN]: KwGBDeamon.lnk . (.酷我科技 - KwGBDeamon.) C:\ProgramData\KWGameBox\KwGameBox\bin\KwGBDeamon.exe {50DA1504909F7273486D47AC0AB74675}
O4 - GS\Programs [VULCAN]: Badoo.lnk . (.Badoo Software Ltd - Badoo.) C:\Users\VULCAN\AppData\Local\Programs\Badoo\Badoo.exe
O4 - GS\Programs [VULCAN]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\VULCAN\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation?
O4 - GS\Programs [VULCAN]: Twitch.lnk . (.Twitch Interactive, Inc. - Twitch.) C:\Users\VULCAN\AppData\Roaming\Twitch\Bin\Twitch.exe =>.Twitch Interactive, Inc.?
O4 - GS\Programs [VULCAN]: 可选功能.lnk . (.Microsoft Corporation - 需求帮助程序的功能.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Desktop [WDAGUtilityAccount]: Badoo.lnk . (.Badoo Software Ltd - Badoo.) C:\Users\VULCAN\AppData\Local\Programs\Badoo\Badoo.exe
O4 - GS\Desktop [WDAGUtilityAccount]: Crysis with BlackFire's Mod Ultimate.lnk . (...) C:\Users\VULCAN\Desktop\Crysis\BFMU.bat
O4 - GS\Desktop [WDAGUtilityAccount]: Crysis.lnk . (...) C:\Users\VULCAN\Desktop\Crysis\Bin64\Crysis.exe -mod CrysisExpanded -devmode
O4 - GS\Desktop [WDAGUtilityAccount]: Crysis2 - 快捷方式.lnk . (.Crytek GmbH - .) G:\Youxun\Install\Crysis2_chs\bin32\Crysis2.exe =>.Crytek GmbH
O4 - GS\Desktop [WDAGUtilityAccount]: Cuphead - 快捷方式.lnk . (...) F:\Youxun\Install\Cuphead_chs\Cuphead.exe
O4 - GS\Desktop [WDAGUtilityAccount]: Detention - 快捷方式.lnk . (...) E:\Detention\Detention.exe
O4 - GS\Desktop [WDAGUtilityAccount]: Dolphin.lnk . (...) E:\Program Files\Dolphin\Dolphin.exe
O4 - GS\Desktop [WDAGUtilityAccount]: Freedom - 快捷方式.lnk . (...) E:\game\Soldaty Svobody\Freedom.Exe
O4 - GS\Desktop [WDAGUtilityAccount]: Furi - 快捷方式.lnk . (...) E:\Program Files (x86)\Furi zhongwenban\Furi.exe
O4 - GS\Desktop [WDAGUtilityAccount]: Grim Dawn - 快捷方式.lnk . (...) F:\Grim Dawn\Grim Dawn.exe
O4 - GS\Desktop [WDAGUtilityAccount]: nex_machina - 快捷方式.lnk . (...) G:\yxdown\NexMachinaV1.04.0027_chs\nex_machina.exe
O4 - GS\Desktop [WDAGUtilityAccount]: Outlast2 - 快捷方式.lnk . (.Red Barrels Inc. - Outlast 2.) F:\Outlast 2\Binaries\Win64\Outlast2.exe =>.Red Barrels Inc.
O4 - GS\Desktop [WDAGUtilityAccount]: Renee Becca.lnk . (...) E:\Program Files (x86)\Rene.E Laboratory\Becca\Becca.exe =>.Rene.E Laboratory Co., Ltd.?
O4 - GS\Desktop [WDAGUtilityAccount]: Saved files - 快捷方式.lnk . (...) E:\Saved files
O4 - GS\Desktop [WDAGUtilityAccount]: SpeedFan.lnk . (...) C:\Program Files (x86)\SpeedFan\speedfan.exe =>.SOKNO S.R.L.?
O4 - GS\Desktop [WDAGUtilityAccount]: Steam - 快捷方式.lnk . (...) G:\Program Files (x86)\Steam\Steam.exe
O4 - GS\Desktop [WDAGUtilityAccount]: SuicideGuy - 快捷方式.lnk . (...) G:\yxdown\SuicideGuy_en\SuicideGuy.exe
O4 - GS\Desktop [WDAGUtilityAccount]: Twitch.lnk . (.Twitch Interactive, Inc. - Twitch.) C:\Users\VULCAN\AppData\Roaming\Twitch\Bin\Twitch.exe =>.Twitch Interactive, Inc.?
O4 - GS\Desktop [WDAGUtilityAccount]: Uplay.lnk . (.Ubisoft - Uplay launcher.) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe =>.Ubisoft Entertainment Sweden AB?
O4 - GS\Desktop [WDAGUtilityAccount]: witness64_d3d11 - 快捷方式.lnk . (...) G:\Program Files (x86)\The Witness\witness64_d3d11.exe
O4 - GS\Desktop [WDAGUtilityAccount]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\VULCAN\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [WDAGUtilityAccount]: 乐游游戏盒.lnk . (.昆山百诺信息科技有限公司 - 游戏盒.) G:\Program Files (x86)\leyoubox\igame.exe {2DDA7BAADFC10935C9DD9523623C9989}
O4 - GS\Desktop [WDAGUtilityAccount]: 百度网盘.lnk . (.Baidu. All rights reserved. - BaiduNetdisk.) C:\Users\VULCAN\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdisk.exe {1FD2D30E260FC289CFAF11518F2CD36F}
O4 - GS\Desktop [WDAGUtilityAccount]: 迅雷.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷.) C:\Program Files (x86)\Thunder Network\Thunder9\Program\Thunder.exe -StartType:DesktopIcon {7506B5D2917A135C04E229EE21449A8D}
O4 - GS\Desktop [WDAGUtilityAccount]: 银联安全控件非插件版.lnk . (.中国银联股份有限公司 - UPSecurityInput.) C:\Windows\SysWOW64\UPEditNew\UPSecurityInput.exe {1F5E46E3B8C0B8C33918E7CB4BE3A31D}
O4 - GS\Quicklaunch [WDAGUtilityAccount]: DS3 Tool.lnk . (.www.motioninjoy.com - DS3_Tool.) C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe =>.www.motioninjoy.com
O4 - GS\Quicklaunch [WDAGUtilityAccount]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc?
O4 - GS\Quicklaunch [WDAGUtilityAccount]: Mozilla Firefox.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation?
O4 - GS\Quicklaunch [WDAGUtilityAccount]: Nexus Mod Manager.lnk . (.Black Tree Gaming - Nexus Mod Manager.) E:\Program Files\Nexus Mod Manager\NexusClient.exe =>.Black Tree Gaming Ltd.?
O4 - GS\Quicklaunch [WDAGUtilityAccount]: Renee Becca.lnk . (...) E:\Program Files (x86)\Rene.E Laboratory\Becca\Becca.exe =>.Rene.E Laboratory Co., Ltd.?
O4 - GS\Quicklaunch [WDAGUtilityAccount]: Shareaza.lnk . (.Shareaza Development Team - Shareaza Ultimate File Sharing.) E:\Program Files\Shareaza\Shareaza.exe =>.Shareaza Development Team
O4 - GS\Quicklaunch [WDAGUtilityAccount]: 易我分区管理大师 11.0.lnk . (.EaseUS - EaseUS Partition Master Loader Application.) E:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.0\bin\epm0.exe =>.CHENGDU YIWO Tech Development Co., Ltd.?
O4 - GS\Quicklaunch [WDAGUtilityAccount]: 百度网盘.lnk . (.Baidu. All rights reserved. - BaiduNetdisk.) C:\Users\VULCAN\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdisk.exe {1FD2D30E260FC289CFAF11518F2CD36F}
O4 - GS\Quicklaunch [WDAGUtilityAccount]: 腾讯QQ.lnk . (.Tencent - 腾讯QQ.) C:\Program Files (x86)\Tencent\QQ\Bin\QQScLauncher.exe =>.SUP.Tencent
O4 - GS\Quicklaunch [WDAGUtilityAccount]: 迅雷.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷.) C:\Program Files (x86)\Thunder Network\Thunder9\Program\Thunder.exe -StartType:QuickLaunch {7506B5D2917A135C04E229EE21449A8D}
O4 - GS\Quicklaunch [WDAGUtilityAccount]: 酷我音乐.lnk . (.酷我科技 - 酷我音乐.) E:\Program Files (x86)\kuwo\kuwomusic\8.7.2.0_BDS1\bin\KwMusic.exe {065913BF67E5B81FE1E8A83167EEFBFC}
O4 - GS\sendTo [WDAGUtilityAccount]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [WDAGUtilityAccount]: 传真收件人.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [WDAGUtilityAccount]: 蓝牙文件传送.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [WDAGUtilityAccount]: CPUCores.lnk . (...) C:\Users\VULCAN\Desktop\CPUCores18\cpucores.exe
O4 - GS\TaskBar [WDAGUtilityAccount]: ExpressVPN.lnk . (.ExpressVPN - ExpressVpn.) C:\Program Files (x86)\ExpressVPN\xvpn-ui\ExpressVpn.exe =>.Express Vpn LLC?
O4 - GS\TaskBar [WDAGUtilityAccount]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation?
O4 - GS\TaskBar [WDAGUtilityAccount]: nullDC_Win32_Release.lnk . (...) C:\Users\VULCAN\Desktop\nullDC 1.04 r150 SM-A Fixes by masterchan777\nullDC_Win32_Release.exe
O4 - GS\TaskBar [WDAGUtilityAccount]: Snipping Tool.lnk . (.Microsoft Corporation - 截图工具.) C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\TaskBar [WDAGUtilityAccount]: World of Warcraft.lnk . (.Blizzard Entertainment - World of Warcraft.) G:\WOW-NOSTALGEEK\WoW.exe =>.Blizzard Entertainment
O4 - GS\TaskBar [WDAGUtilityAccount]: 迅雷.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷.) C:\Program Files (x86)\Thunder Network\Thunder9\Program\Thunder.exe -StartType:PinTaskbar {7506B5D2917A135C04E229EE21449A8D}
O4 - GS\TaskBar [WDAGUtilityAccount]: 迅雷影音.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷影音.) C:\Program Files (x86)\Thunder Network\XMP\V5.4.0.6088\Bin\XMP.exe /sstartfrom QuickLaunch /sopenfrom QuickLaunch {4A9EFF30A343AA0DE042347C}
O4 - GS\TaskBar [WDAGUtilityAccount]: 酷我音乐.lnk . (.酷我科技 - 酷我音乐.) E:\Program Files (x86)\kuwo\kuwomusic\8.7.2.0_BDS1\bin\KwMusic.exe {065913BF67E5B81FE1E8A83167EEFBFC}
O4 - GS\Startup [WDAGUtilityAccount]: KwGBDeamon.lnk . (.酷我科技 - KwGBDeamon.) C:\ProgramData\KWGameBox\KwGameBox\bin\KwGBDeamon.exe {50DA1504909F7273486D47AC0AB74675}
O4 - GS\Programs [WDAGUtilityAccount]: Badoo.lnk . (.Badoo Software Ltd - Badoo.) C:\Users\VULCAN\AppData\Local\Programs\Badoo\Badoo.exe
O4 - GS\Programs [WDAGUtilityAccount]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\VULCAN\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation?
O4 - GS\Programs [WDAGUtilityAccount]: Twitch.lnk . (.Twitch Interactive, Inc. - Twitch.) C:\Users\VULCAN\AppData\Roaming\Twitch\Bin\Twitch.exe =>.Twitch Interactive, Inc.?
O4 - GS\Programs [WDAGUtilityAccount]: 可选功能.lnk . (.Microsoft Corporation - 需求帮助程序的功能.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\CommonDesktop [Public]: 3D Vision Photo Viewer.lnk . (.NVIDIA Corporation - NVIDIA 3D Vision Photo Viewer.) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe =>.NVIDIA Corporation?
O4 - GS\CommonDesktop [Public]: 3DMark 11.lnk . (.Futuremark - 3DMark 11 GUI.) E:\Program Files\Futuremark\3DMark 11\bin\x64\3DMark11.exe =>.FUTUREMARK INC?
O4 - GS\CommonDesktop [Public]: Audacity.lnk . (.The Audacity Team - Audacity®, the Free, Cross-Platform Sound E.) C:\Program Files (x86)\Audacity\audacity.exe =>.The Audacity Team
O4 - GS\CommonDesktop [Public]: Battle.net.lnk . (.Blizzard Entertainment - Blizzard Battle.net App Launcher.) E:\Program Files (x86)\Battlenet\Battle.net\Battle.net Launcher.exe =>.Blizzard Entertainment, Inc.?
O4 - GS\CommonDesktop [Public]: Bayonetta.lnk . (...) E:\Games\Bayonetta\Bayonetta.exe
O4 - GS\CommonDesktop [Public]: Borderless Gaming.lnk . (.Codeusa Software - Borderless Gaming.) C:\Program Files (x86)\Borderless Gaming\BorderlessGaming.exe {1C7DC54D08621A96136B378AA9E4392B} =>.Codeusa Software
O4 - GS\CommonDesktop [Public]: DS3 Tool.lnk . (.www.motioninjoy.com - DS3_Tool.) C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe =>.www.motioninjoy.com
O4 - GS\CommonDesktop [Public]: ExpressVPN.lnk . (.ExpressVPN - ExpressVpn.) C:\Program Files (x86)\ExpressVPN\xvpn-ui\ExpressVpn.exe =>.Express Vpn LLC?
O4 - GS\CommonDesktop [Public]: GeForce Experience.lnk . (.NVIDIA Corporation - NVIDIA GeForce Experience.) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe =>.NVIDIA Corporation?
O4 - GS\CommonDesktop [Public]: GOG Galaxy.lnk . (.GOG.com - GOG Galaxy.) E:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe =>.GOG Sp. z o.o.?
O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc?
O4 - GS\CommonDesktop [Public]: Gwent.lnk . (...) E:\Program Files (x86)\GOG Galaxy\Games\Gwent\Gwent.exe =>.GOG.com
O4 - GS\CommonDesktop [Public]: LibreOffice 5.3.lnk . (.The Document Foundation - .) C:\Program Files (x86)\LibreOffice 5\program\soffice.exe =>.The Document Foundation
O4 - GS\CommonDesktop [Public]: Lightroom 5 64 bits.lnk . (.Adobe Systems - Adobe Photoshop Lightroom 64-bit.) E:\Program Files\Adobe\Adobe Photoshop Lightroom 5\lightroom.exe =>.Adobe Systems Incorporated?
O4 - GS\CommonDesktop [Public]: LOOT.lnk . (.Copyright (C) 2013-2016 WrinklyNinja - .) C:\Program Files (x86)\LOOT\LOOT.exe
O4 - GS\CommonDesktop [Public]: Malwarebytes.lnk . (.Malwarebytes - Malwarebytes.) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe =>.Malwarebytes Corporation?
O4 - GS\CommonDesktop [Public]: Nexus Mod Manager.lnk . (.Black Tree Gaming - Nexus Mod Manager.) E:\Program Files\Nexus Mod Manager\NexusClient.exe =>.Black Tree Gaming Ltd.?
O4 - GS\CommonDesktop [Public]: Origin.lnk . (.Electronic Arts - Origin.) C:\Program Files (x86)\Origin\Origin.exe =>.Electronic Arts, Inc.?
O4 - GS\CommonDesktop [Public]: Overwatch.lnk . (.Blizzard Entertainment - Overwatch Setup.) E:\Program Files (x86)\Hearthstone\Starcraft II\Overwatch\Overwatch Launcher.exe =>.Blizzard Entertainment, Inc.?
O4 - GS\CommonDesktop [Public]: Shareaza.lnk . (.Shareaza Development Team - Shareaza Ultimate File Sharing.) E:\Program Files\Shareaza\Shareaza.exe =>.Shareaza Development Team
O4 - GS\CommonDesktop [Public]: StarCraft II.lnk . (.Blizzard Entertainment - StarCraft II.) E:\Program Files (x86)\Hearthstone\Starcraft II\StarCraft II\StarCraft II.exe =>.Blizzard Entertainment, Inc.?
O4 - GS\CommonDesktop [Public]: Steam.lnk . (.Valve Corporation - Steam Client Bootstrapper.) E:\Program Files (x86)\Steam\Steam.exe =>.Valve?
O4 - GS\CommonDesktop [Public]: The Witcher Rise of the White Wolf.lnk . (.CD Projekt Red - The Witcher Game Launcher.) E:\SteamLibrary\steamapps\common\The Witcher Enhanced Edition\launcher.exe {044851} =>.CD Projekt RED
O4 - GS\CommonDesktop [Public]: Ultima IV - Quest of the Avatar.lnk . (.DOSBox Team - DOSBox DOS Emulator.) E:\Program Files (x86)\GOG Galaxy\Games\Ultima 4 - Quest of the Avatar\DOSBOX\DOSBox.exe -conf "..\dosboxULTIMA4.conf" -conf "..\dosboxULTIMA4_single.conf" -noconsole -c exit =>.DOSBox Team
O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe =>.VideoLAN?
O4 - GS\CommonDesktop [Public]: XIII.lnk . (...) E:\game\ShaShou13\ShaShou13.exe
O4 - GS\CommonDesktop [Public]: 微信.lnk . (.Tencent - WeChat.) C:\Program Files (x86)\Tencent\WeChat\WeChat.exe =>.SUP.Tencent
O4 - GS\CommonDesktop [Public]: 易我分区管理大师 11.0.lnk . (.EaseUS - EaseUS Partition Master Loader Application.) E:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.0\bin\epm0.exe =>.CHENGDU YIWO Tech Development Co., Ltd.?
O4 - GS\CommonDesktop [Public]: 星际争霸II.lnk . (.Blizzard Entertainment - StarCraft II.) E:\Program Files (x86)\Battlenet\StarCraft II\StarCraft II.exe =>.Blizzard Entertainment, Inc.?
O4 - GS\CommonDesktop [Public]: 看看影音.lnk . (.Shenzhen Video Legend Network Technology Co.,Ltd. - 看看影音 应用程序.) C:\Program Files (x86)\Video Legend\KKP\Program\KKP.exe /sstartfrom desktop {2F45428F979B6FA35CF436C537FDC3C3}
O4 - GS\CommonDesktop [Public]: 腾讯QQ.lnk . (.Tencent - 腾讯QQ.) C:\Program Files (x86)\Tencent\QQ\Bin\QQScLauncher.exe =>.SUP.Tencent
O4 - GS\CommonDesktop [Public]: 迅雷影音.lnk . (.深圳市迅雷网络技术有限公司 - 迅雷影音.) C:\Program Files (x86)\Thunder Network\XMP\V5.4.0.6088\Bin\XMP.exe /sstartfrom Desktop /sopenfrom Desktop {4A9EFF30A343AA0DE042347C}
O4 - GS\CommonDesktop [Public]: 酷我音乐.lnk . (.酷我科技 - 酷我音乐.) E:\Program Files (x86)\kuwo\kuwomusic\8.7.2.0_BDS1\bin\KwMusic.exe {065913BF67E5B81FE1E8A83167EEFBFC}
O4 - GS\CommonDesktop [Public]: 魔兽世界.lnk . (.Blizzard Entertainment - World of Warcraft Setup.) E:\Program Files (x86)\Battlenet\World of Warcraft\World of Warcraft Launcher.exe =>.Blizzard Entertainment, Inc.?
O4 - GS\Programs [Public]: Badoo.lnk . (.Badoo Software Ltd - Badoo.) C:\Users\VULCAN\AppData\Local\Programs\Badoo\Badoo.exe
O4 - GS\Programs [Public]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\VULCAN\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation?
O4 - GS\Programs [Public]: Twitch.lnk . (.Twitch Interactive, Inc. - Twitch.) C:\Users\VULCAN\AppData\Roaming\Twitch\Bin\Twitch.exe =>.Twitch Interactive, Inc.?
O4 - GS\Programs [Public]: 可选功能.lnk . (.Microsoft Corporation - 需求帮助程序的功能.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation?
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - 记事本.) C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Startup [Public]: igame.lnk . (.昆山百诺信息科技有限公司 - 游戏盒.) G:\Program Files (x86)\leyoubox\igame.exe -h {2DDA7BAADFC10935C9DD9523623C9989}
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - 画图.) C:\WINDOWS\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Quick Assist.lnk . (.Microsoft Corporation - Quick Assist.) C:\WINDOWS\system32\quickassist.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - 远程桌面连接.) C:\WINDOWS\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - 截图工具.) C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - 步骤记录器.) C:\WINDOWS\system32\psr.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows 写字板应用程序.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: XPS Viewer.lnk . (.Microsoft Corporation - XPS 查看器.) C:\WINDOWS\system32\xpsrchvw.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - 字符映射表.) C:\WINDOWS\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Adobe Photoshop Lightroom 5 64 bits.lnk . (.Adobe Systems - Adobe Photoshop Lightroom 64-bit.) E:\Program Files\Adobe\Adobe Photoshop Lightroom 5\lightroom.exe =>.Adobe Systems Incorporated?
O4 - GS\ProgramsCommon [Public]: Audacity.lnk . (.The Audacity Team - Audacity®, the Free, Cross-Platform Sound E.) C:\Program Files (x86)\Audacity\audacity.exe =>.The Audacity Team
O4 - GS\ProgramsCommon [Public]: Epic Games Launcher.lnk . (.Epic Games, Inc. - UnrealEngineLauncher.) E:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win32\EpicGamesLauncher.exe =>.Epic Games Inc.?
O4 - GS\ProgramsCommon [Public]: Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation?
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc?
O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\WINDOWS\System32\Control.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: LOOT.lnk . (.Copyright (C) 2013-2016 WrinklyNinja - .) C:\Program Files (x86)\LOOT\LOOT.exe
O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: 酷我音乐.lnk . (.酷我科技 - 酷我音乐.) E:\Program Files (x86)\kuwo\kuwomusic\8.7.2.0_BDS1\bin\KwMusic.exe {065913BF67E5B81FE1E8A83167EEFBFC}

---\\ Lop.com/Domain Hijackers (17) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = lan =>.Local Domain
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.199.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{080d5a5d-1186-4b5f-aaae-fd2e8e0e1215}: DhcpNameServer = 192.168.198.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{0A3479D7-827D-4460-9EC6-3718D4E10C47}: DhcpNameServer = 10.0.1.1 =>.Private IP (10.0.0.0 - 10.255.255.255) =>.Private IP
O17 - HKLM\System\CCS\Services\Tcpip\..\{18DD7DDE-04C4-4ADE-BE90-8601EB6BC3F5}: DhcpNameServer = 10.0.1.1 =>.Private IP (10.0.0.0 - 10.255.255.255) =>.Private IP
O17 - HKLM\System\CCS\Services\Tcpip\..\{4322354C-778F-41E2-9F08-F6F9FFDBFFEB}: DhcpNameServer = 10.0.1.1 =>.Private IP (10.0.0.0 - 10.255.255.255) =>.Private IP
O17 - HKLM\System\CCS\Services\Tcpip\..\{4b428a35-1860-4b27-b5e2-974a51dfce62}: DhcpNameServer = 10.161.0.1 =>.Private IP (10.0.0.0 - 10.255.255.255) =>.Private IP
O17 - HKLM\System\CCS\Services\Tcpip\..\{583F17FA-9B64-424E-A1B2-164C79C6C961}: DhcpNameServer = 10.0.1.1 =>.Private IP (10.0.0.0 - 10.255.255.255) =>.Private IP
O17 - HKLM\System\CCS\Services\Tcpip\..\{797fb0a6-f98b-4c23-83df-02b0520152eb}: DhcpNameServer = 192.168.198.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{A6FC0B3A-2E8F-46E1-998F-ECB03772A3DE}: DhcpNameServer = 10.0.1.1 =>.Private IP (10.0.0.0 - 10.255.255.255) =>.Private IP
O17 - HKLM\System\CCS\Services\Tcpip\..\{b6b26055-58ff-43f2-ac63-2bcf3ff60bc6}: DhcpNameServer = 10.100.130.1 10.100.180.1 =>.Private IP (10.0.0.0 - 10.255.255.255) =>.Private IP
O17 - HKLM\System\CCS\Services\Tcpip\..\{B81450F9-5594-4220-8F52-C1BE73AB55E0}: DhcpNameServer = 10.0.1.1 =>.Private IP (10.0.0.0 - 10.255.255.255) =>.Private IP
O17 - HKLM\System\CCS\Services\Tcpip\..\{c1eab2ba-b1cc-4ac7-9e62-4518e56bac14}: DhcpNameServer = 211.167.230.100 211.167.230.200
O17 - HKLM\System\CCS\Services\Tcpip\..\{CF1F44A6-0BE3-43A6-97A2-A83F5AE7A2BA}: DhcpNameServer = 10.0.1.1 =>.Private IP (10.0.0.0 - 10.255.255.255) =>.Private IP
O17 - HKLM\System\CCS\Services\Tcpip\..\{dab00dcf-d894-4986-aeea-42ac61b20106}: DhcpNameServer = 192.168.199.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{b6b26055-58ff-43f2-ac63-2bcf3ff60bc6}: DhcpDomain = hd.tongfangpc.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{dab00dcf-d894-4986-aeea-42ac61b20106}: DhcpDomain = lan =>.Local Domain

---\\ Extra protocols (22) - 0s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML 查看器.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Win32 的 OLE32 扩展.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - 流视频的 ActiveX 控件.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Win32 的 OLE32 扩展.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Win32 的 OLE32 扩展.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Win32 的 OLE32 扩展.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Win32 的 OLE32 扩展.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML 查看器.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Win32 的 OLE32 扩展.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML 查看器.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Win32 的 OLE32 扩展.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML 查看器.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - 流视频的 ActiveX 控件.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML 查看器.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: windows.tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation

---\\ Software installed (163) - 20s
O42 - Logiciel: 360压缩 - (.360安全中心.) [HKLM][64Bits] -- 360压缩 =>.Qihoo 360 Software (Beijing) Company Limited?
O42 - Logiciel: 3DMark 11 - (.Futuremark.) [HKLM][64Bits] -- {f9e83b9c-ab7e-4005-8f32-4ea69703a5e4} =>.FUTUREMARK INC?
O42 - Logiciel: 3DMark 11 - (.Futuremark.) [HKLM][64Bits] -- {FD67BFA0-E205-47AA-BA09-123B3B72DB5E} =>.Futuremark
O42 - Logiciel: Adobe Flash Player 28 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated?
O42 - Logiciel: Adobe Photoshop Lightroom 5 64-bit - (.Adobe.) [HKLM][64Bits] -- {6C1A010F-9108-4162-A26F-9FEC4AC0F0F0} =>.Adobe
O42 - Logiciel: Asmedia USB Host Controller Driver - (.Asmedia Technology.) [HKLM][64Bits] -- {E4FB0B39-C991-4EE7-95DD-1A1A7857D33D} =>.Asmedia Technology
O42 - Logiciel: Assassin's Creed IV Black Flag Asia - (.Ubisoft.) [HKLM][64Bits] -- Uplay Install 442 =>.Ubisoft Entertainment Sweden AB?
O42 - Logiciel: Audacity 2.1.0 - (.Audacity Team.) [HKLM][64Bits] -- Audacity_is1 =>.Audacity Team
O42 - Logiciel: Audiosurf - (.Dylan Fitterer.) [HKLM][64Bits] -- Steam App 12900 =>.SteamApp.Game
O42 - Logiciel: Badoo 2.0.0 (only current user) - (.Badoo Software Ltd.) [HKCU][64Bits] -- 9c58e07c-77be-5d3f-be9c-687ecb20f62c
O42 - Logiciel: Batman™: Arkham Knight - (.Rocksteady Studios.) [HKLM][64Bits] -- Steam App 208650 =>.SteamApp.Game
O42 - Logiciel: Battle.net - (.Blizzard Entertainment.) [HKLM][64Bits] -- Battle.net =>.Blizzard Entertainment, Inc.?
O42 - Logiciel: Battlefield™ 1 - (.Electronic Arts.) [HKLM][64Bits] -- {335B50BC-6130-4BAF-9A6A-F1561270587B} =>.Electronic Arts, Inc.?
O42 - Logiciel: Bayonetta - (..) [HKLM][64Bits] -- Bayonetta_is1
O42 - Logiciel: BlackFire's Mod Ultimate 1.3 - (.BlackFireBR.) [HKLM][64Bits] -- BlackFire's Mod Ultimate 1.3
O42 - Logiciel: Borderless Gaming - (.Codeusa Software.) [HKLM][64Bits] -- Borderless Gaming_is1 =>.Codeusa Software
O42 - Logiciel: Cities: Skylines - (.Colossal Order Ltd..) [HKLM][64Bits] -- Steam App 255710 =>.SteamApp.Game
O42 - Logiciel: Click Install if prompted - (.ExpressVpn.) [HKLM][64Bits] -- {40830C8E-936E-4E08-AE37-240FF3343927} =>.ExpressVPN
O42 - Logiciel: CloudNet - (.EpicNet Inc..) [HKCU][64Bits] -- CloudNet =>Adware.MSIL
O42 - Logiciel: COBA Helper - (.Mozilla Online Limited.) [HKCU][64Bits] -- MozillaOnlineCOBA
O42 - Logiciel: DisplayDriverAnalyzer - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer =>.NVIDIA Corporation
O42 - Logiciel: Divinity: Original Sin Enhanced Edition - (.Larian Studios.) [HKLM][64Bits] -- Steam App 373420 =>.SteamApp.Game
O42 - Logiciel: Dolphin - (.Dolphin Team.) [HKLM][64Bits] -- Dolphin =>.Dolphin Team
O42 - Logiciel: Door Kickers - (.KillHouse Games.) [HKLM][64Bits] -- Steam App 248610 =>.SteamApp.Game
O42 - Logiciel: Epic Games Launcher - (.Epic Games, Inc..) [HKLM][64Bits] -- {1AA4AE83-6536-4929-A960-B8058395FD35} =>.Epic Games, Inc.
O42 - Logiciel: Epic Games Launcher Prerequisites (x64) - (.Epic Games, Inc..) [HKLM][64Bits] -- {66C5838F-B854-4A55-89E6-A6138747A4DF} =>.Epic Games, Inc.
O42 - Logiciel: ExpressVPN - (.ExpressVPN.) [HKLM][64Bits] -- {B97E1AC2-1F11-43C0-90A7-22B158337D06} =>.ExpressVPN
O42 - Logiciel: ExpressVPN - (.ExpressVPN.) [HKLM][64Bits] -- {e87d0eca-dc93-4f55-bf74-0d155d8c6f07} =>.Express Vpn LLC?
O42 - Logiciel: Farming Simulator 2013 - (.Giants Software.) [HKLM][64Bits] -- Steam App 220260 =>.SteamApp.Game
O42 - Logiciel: Furi 中文版 - (..) [HKLM][64Bits] -- Furi 中文版
O42 - Logiciel: Futuremark SystemInfo - (.Futuremark.) [HKLM][64Bits] -- {79659071-4B68-4EC8-833C-49C97B68FCD0} =>.Futuremark
O42 - Logiciel: GOG Galaxy - (.GOG.com.) [HKLM][64Bits] -- {7258BA11-600C-430E-A759-27E2C691A335}_is1 =>.GOG Limited?
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome =>.Google Inc?
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: Grand Theft Auto V - (.Rockstar North.) [HKLM][64Bits] -- Steam App 271590 =>.SteamApp.Game
O42 - Logiciel: Grand Theft Auto: San Andreas - (.Rockstar Games.) [HKLM][64Bits] -- Steam App 12120 =>.SteamApp.Game
O42 - Logiciel: GTA San Andreas - (.Rockstar Games.) [HKLM][64Bits] -- {D417C96A-FCC7-4590-A1BB-FAF73F5BC98E} =>.InstallShield Software Corporation?
O42 - Logiciel: Gwent - (.GOG.com.) [HKLM][64Bits] -- 1971477531_is1 =>.GOG Limited?
O42 - Logiciel: Hearthstone - (.Blizzard Entertainment.) [HKLM][64Bits] -- Hearthstone =>.Blizzard Entertainment, Inc.?
O42 - Logiciel: Hunt: Showdown - (.Crytek.) [HKLM][64Bits] -- Steam App 594650 =>.SteamApp.Game
O42 - Logiciel: Intel(R) Chipset Device Software - (.Intel Corporation.) [HKLM][64Bits] -- {12CB6BC1-4E71-4890-AA0E-26CED6AD7EDD} =>.Intel Corporation
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {1CEAC85D-2590-4760-800F-8DE5E91F3700} =>.Intel Corporation
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {62260D0F-633D-4B77-B394-BB57DF7223D9} =>.Intel Corporation
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {EA30CEC3-9CC5-4C80-AE8E-209A6F894961} =>.Intel Corporation
O42 - Logiciel: Intel(R) ME UninstallLegacy - (.Intel Corporation.) [HKLM][64Bits] -- {3DF3AC42-174D-4915-9ED2-448AD4338B83} =>.Intel Corporation
O42 - Logiciel: Intel(R) PRO/Wireless Driver - (.Intel Corporation.) [HKLM][64Bits] -- {805619bc-44b5-4ee5-809b-ec644a752d41} =>.Intel Corporation
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} =>.Intel(R) pGFX?
O42 - Logiciel: Intel® PROSet/Wireless WiFi Software - (.Intel Corporation.) [HKLM][64Bits] -- {054CAF3F-AF48-4F02-AB25-919F3B676C33} =>.Intel Corporation
O42 - Logiciel: Intel® Security Assist - (.Intel Corporation.) [HKLM][64Bits] -- {4B230374-6475-4A73-BA6E-41015E9C5013} =>.Intel Corporation
O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {7D84E343-A23D-451C-B123-0195B2D903A6} =>.Intel Corporation
O42 - Logiciel: Killing Floor 2 - (.Tripwire Interactive.) [HKLM][64Bits] -- Steam App 232090 =>.SteamApp.Game
O42 - Logiciel: LAME v3.99.3 (for Windows) - (.Audacity.) [HKLM][64Bits] -- LAME_is1 =>.Audacity
O42 - Logiciel: Launcher Prerequisites (x64) - (.Epic Games, Inc..) [HKLM][64Bits] -- {c6c5a357-c7ca-4a5f-9789-3bb1af579253} =>.Epic Games Inc.?
O42 - Logiciel: LibreOffice 5.3.2.2 - (.The Document Foundation.) [HKLM][64Bits] -- {682C33C0-5D61-48F0-B0A2-1A504F4C5905} =>.The Document Foundation
O42 - Logiciel: LOOT version 0.10.3 - (.LOOT Team.) [HKLM][64Bits] -- {BF634210-A0D4-443F-A657-0DCE38040374}_is1 =>.LOOT Team
O42 - Logiciel: Malwarebytes version 3.1.2.1733 - (.Malwarebytes.) [HKLM][64Bits] -- {35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1 =>.Malwarebytes Corporation?
O42 - Logiciel: Metal Gear Solid V: The Phantom Pain - (.Kojima Productions.) [HKLM][64Bits] -- {48397BFF-7C01-4B64-8F1A-0D468DDE5D73}_is1 =>.Kojima Productions
O42 - Logiciel: Microsoft Games for Windows - LIVE Redistributable - (.Microsoft Corporation.) [HKLM][64Bits] -- {F2508213-9989-4E85-A078-72BE483917EF} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Games for Windows Marketplace - (.Microsoft Corporation.) [HKLM][64Bits] -- {4CB0307C-565E-4441-86BE-0DF2E4FB828C} =>.Microsoft Corporation
O42 - Logiciel: Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtensio - (.Microsoft Corporation.) [HKLM][64Bits] -- {B0169E83-757B-EF66-E2F0-391944D785BC} =>.Microsoft Corporation
O42 - Logiciel: Microsoft OneDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- OneDriveSetup.exe =>.Microsoft Corporation?
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation
O42 - Logiciel: Microsoft XNA Framework Redistributable 4.0 - (.Microsoft Corporation.) [HKLM][64Bits] -- {2BFC7AA0-544C-4E3A-8796-67F3BE655BE9} =>.Microsoft Corporation
O42 - Logiciel: MotioninJoy Gamepad tool 0.7.1001 - (.www.motioninjoy.com.) [HKLM][64Bits] -- {330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1 =>.www.motioninjoy.com
O42 - Logiciel: Mozilla Firefox 58.0.2 (x64 zh-CN) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 58.0.2 (x64 zh-CN) =>.Mozilla Corporation?
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService =>.Mozilla
O42 - Logiciel: Multitimer version 1.0 - (..) [HKLM][64Bits] -- Multitimer_is1
O42 - Logiciel: NarutoOnline 2.3.0.983 - (.Oasgames, Inc..) [HKLM][64Bits] -- NarutoOnline =>.Oasgames, Inc.
O42 - Logiciel: Nexus Mod Manager - (.Black Tree Gaming.) [HKLM][64Bits] -- 6af12c54-643b-4752-87d0-8335503010de_is1 =>.Black Tree Gaming Ltd.?
O42 - Logiciel: Notepad++ (64-bit x64) - (.Notepad++ Team.) [HKLM][64Bits] -- Notepad++ =>.Notepad++ Team
O42 - Logiciel: Nox APP Player - (.Duodian Technology Co. Ltd..) [HKLM][64Bits] -- Nox =>.Beijing Duodian Online Science and Technology Co.,Ltd?
O42 - Logiciel: NVIDIA 3D Vision 驱动程序 391.01 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Ansel - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Backend - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvBackend =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Display Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Display Container LS - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainerLS =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Display Session Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplaySessionContainer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Display Watchdog Plugin - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayPluginWatchdog =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA GeForce Experience 3.12.0.84 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Install Application - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA LocalSystem Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.LocalSystem =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Message Bus for NvContainer - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.MessageBus =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA NetworkService Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NetworkService =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA NodeJS - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Optimus Update 31.0.11.0 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA PhysX 系统软件 9.17.0524 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Session Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.Session =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA ShadowPlay 3.12.0.84 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay =>.NVIDIA Corporation
O42 - Logiciel: Nvidia Share - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_OSC =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA SHIELD Streaming - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA SHIELD Wireless Controller Driver - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Stereoscopic 3D Driver - (.NVIDIA Corporation.) [HKLM][64Bits] -- NVIDIAStereo =>.NVIDIA Corporation?
O42 - Logiciel: NVIDIA Telemetry Client - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Telemetry Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetryContainer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA TelemetryApi helper for NvContainer - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.ContainerTelemetryApiHelper =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Update Core - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA User Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.User =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Virtual Audio 4.04.0 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Virtual Host Controller - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvvHci =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Watchdog Plugin for NvContainer - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvPlugin.Watchdog =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA 更新 31.0.11.0 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA 控制面板 391.01 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA 图形驱动程序 391.01 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver =>.NVIDIA Corporation
O42 - Logiciel: OpenAL - (.Open Audio Library.) [HKLM][64Bits] -- OpenAL =>.Creative Labs Inc?
O42 - Logiciel: OpenIV - (..black/OpenIV Team.) [HKCU][64Bits] -- OpenIV =>..black/OpenIV Team
O42 - Logiciel: Origin - (.Electronic Arts, Inc..) [HKLM][64Bits] -- Origin =>.Electronic Arts, Inc.?
O42 - Logiciel: OSD - (.OEM.) [HKLM][64Bits] -- {445FFA4E-70A8-493B-9A8C-D095244D03BE}_is1 =>.OEM
O42 - Logiciel: Overwatch - (.Blizzard Entertainment.) [HKLM][64Bits] -- Overwatch =>.Blizzard Entertainment, Inc.?
O42 - Logiciel: Phase Shift - (.DWSK.) [HKLM][64Bits] -- Phase Shift
O42 - Logiciel: PunkBuster Services - (.Even Balance, Inc..) [HKLM][64Bits] -- PunkBusterSvc =>.Even Balance, Inc.?
O42 - Logiciel: QQ旋风4.7 - (.腾讯科技(深圳)有限公司.) [HKLM][64Bits] -- QQ旋风
O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} =>.Realtek Semiconductor Corp?
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp?
O42 - Logiciel: Renee Becca 2017.26.44.313 - (.Rene.E Laboratory.) [HKLM][64Bits] -- {A62CB332-45D9-47BD-86D5-A15F016FE2A0}_is1 =>.Rene.E Laboratory
O42 - Logiciel: Rise of the White Wolf - (.CD Projekt RED.) [HKLM][64Bits] -- {339E16B5-E231-4E85-B43D-0C7DD20B76C1} =>.CD Projekt RED
O42 - Logiciel: Rise of the White Wolf - (.CD Projekt RED.) [HKLM][64Bits] -- Rise of the White Wolf 2.0 =>.CD Projekt RED
O42 - Logiciel: Rockstar Games Social Club - (.Rockstar Games.) [HKLM][64Bits] -- Rockstar Games Social Club =>.Rockstar Games
O42 - Logiciel: Shareaza 2.7.9.0 - (.Shareaza Development Team.) [HKLM][64Bits] -- Shareaza_is1 =>.Shareaza Development Team
O42 - Logiciel: ShaShou13 - (.ShaShou13.) [HKLM][64Bits] -- ShaShou13_is1
O42 - Logiciel: Sleeping Dogs: Definitive Edition - (.United Front Games.) [HKLM][64Bits] -- Steam App 307690 =>.SteamApp.Game
O42 - Logiciel: SpeedFan (remove only) - (.Almico Software.) [HKLM][64Bits] -- SpeedFan =>.Almico Software
O42 - Logiciel: Split Tunneling Driver - (.ExpressVpn.) [HKLM][64Bits] -- {F078B0B5-2F41-42C2-9162-B8C628D5E6FE} =>.ExpressVPN
O42 - Logiciel: Steam - (.Valve Corporation.) [HKLM][64Bits] -- Steam =>.Valve?
O42 - Logiciel: Street Fighter V - (.Capcom.) [HKLM][64Bits] -- Steam App 310950 =>.SteamApp.Game
O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey =>.Synaptics Incorporated?
O42 - Logiciel: Tencent QQMail Plugin - (..) [HKLM][64Bits] -- QQMailPlugin =>.SUP.Tencent
O42 - Logiciel: The Binding of Isaac: Rebirth - (.Nicalis, Inc..) [HKLM][64Bits] -- Steam App 250900 =>.SteamApp.Game
O42 - Logiciel: The Elder Scrolls V: Skyrim Special Edition - (.Bethesda Game Studios.) [HKLM][64Bits] -- Steam App 489830 =>.Valve?
O42 - Logiciel: The Witcher: Enhanced Edition - (.CD PROJEKT RED.) [HKLM][64Bits] -- Steam App 20900 =>.SteamApp.Game
O42 - Logiciel: Twitch - (.Twitch Interactive, Inc..) [HKCU][64Bits] -- {DEE70742-F4E9-44CA-B2B9-EE95DCF37295} =>.Twitch Interactive, Inc.?
O42 - Logiciel: Ultima IV - Quest of the Avatar - (.GOG.com.) [HKLM][64Bits] -- 1207658962_is1 =>.GOG Limited?
O42 - Logiciel: Unlocker 1.9.2 - (.Cedrick Collomb.) [HKLM][64Bits] -- Unlocker =>.Cedrick Collomb
O42 - Logiciel: Uplay - (.Ubisoft.) [HKLM][64Bits] -- Uplay =>.Ubisoft Entertainment Sweden AB?
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
O42 - Logiciel: Vulkan Run Time Libraries 1.0.54.1 - (.Intel Corporation Inc..) [HKLM][64Bits] -- VulkanRT1.0.54.1 =>.Intel Corporation Inc.
O42 - Logiciel: Vulkan Run Time Libraries 1.0.65.1 - (.LunarG, Inc..) [HKLM][64Bits] -- VulkanRT1.0.65.1 =>.LunarG, Inc.?
O42 - Logiciel: Watch_Dogs (Asia) - (.Ubisoft.) [HKLM][64Bits] -- Uplay Install 545 =>.Ubisoft Entertainment Sweden AB?
O42 - Logiciel: 百度网盘 - (.百度在线网络技术(北京)有限公司.) [HKLM][64Bits] -- 百度云管家 {1FD2D30E260FC289CFAF11518F2CD36F}
O42 - Logiciel: 百度下载助手 1.6.0.77 - (.Beijing baidu Netcom science and technology co.ltd.) [HKLM][64Bits] -- BaiduRJDownloader =>.Baidu (China) Co., Ltd.?
O42 - Logiciel: 传奇世界网页版 - (.37游戏中心.) [HKLM][64Bits] -- 传奇世界网页版 {3BED0D0695FACA699BE45B5FDBC737AD}
O42 - Logiciel: 法语助手智能输入法 - (.欧路软件.) [HKLM][64Bits] -- Frhelper_ime_is1
O42 - Logiciel: 哈利波特:魁地奇世界杯繁体中文版 - (..) [HKLM][64Bits] -- DoyoGames_10101966
O42 - Logiciel: 看看影音 - (.Shenzhen Video Legend Network Technology Co.,Ltd..) [HKLM][64Bits] -- 看看影音 {2F45428F979B6FA35CF436C537FDC3C3}
O42 - Logiciel: 酷我音乐 - (.酷我科技.) [HKLM][64Bits] -- KwMusic7 {065913BF67E5B81FE1E8A83167EEFBFC}
O42 - Logiciel: 酷我游戏 - (.北京酷我科技有限公司.) [HKLM][64Bits] -- KwGameLite {50DA1504909F7273486D47AC0AB74675}
O42 - Logiciel: 酷我游戏 2.9.4.4 - (.酷我科技.) [HKCU][64Bits] -- 酷我游戏 {50DA1504909F7273486D47AC0AB74675}
O42 - Logiciel: 乐游游戏盒 - (..) [HKCU][64Bits] -- leyoubox {2DDA7BAADFC10935C9DD9523623C9989}
O42 - Logiciel: 魔兽世界 - (.Blizzard Entertainment.) [HKLM][64Bits] -- World of Warcraft =>.Blizzard Entertainment, Inc.?
O42 - Logiciel: 企鹅游戏中心_1.3.544 - (.腾讯科技(深圳)有限公司.) [HKLM][64Bits] -- AppStore
O42 - Logiciel: 死亡机器 - (..) [HKCU][64Bits] -- NexMachinaV1.04.0027_chs
O42 - Logiciel: 搜狗拼音输入法 7.9正式版 - (.Sogou.com.) [HKLM][64Bits] -- Sogou Input
O42 - Logiciel: 腾讯QQ - (.腾讯科技(深圳)有限公司.) [HKLM][64Bits] -- {052CFB79-9D62-42E3-8A15-DE66C2C97C3E}
O42 - Logiciel: 微信 - (.腾讯科技(深圳)有限公司.) [HKLM][64Bits] -- WeChat =>.SUP.Tencent
O42 - Logiciel: 星际争霸II - (.Blizzard Entertainment.) [HKLM][64Bits] -- StarCraft II =>.Blizzard Entertainment, Inc.?
O42 - Logiciel: 迅雷 - (.迅雷网络技术有限公司.) [HKLM][64Bits] -- thunder_is1 {7506B5D2917A135C04E229EE21449A8D}
O42 - Logiciel: 迅雷影音 - (.迅雷网络技术有限公司.) [HKLM][64Bits] -- 迅雷影音
O42 - Logiciel: 易我分区管理大师 11.0 - (.EaseUS.) [HKLM][64Bits] -- EaseUS Partition Master_is1 =>.EaseUS
O42 - Logiciel: 银联安全控件非插件版 1.0.0.2 - (.中国银联股份有限公司.) [HKLM][64Bits] -- 银联安全控件非插件版
O42 - Logiciel: 英特尔® PROSet/无线软件 - (.Intel Corporation.) [HKLM][64Bits] -- {227fd89d-2205-499a-8b73-9ec775789c4d} =>.Intel(R) Wireless Connectivity Solutions?
O42 - Logiciel: 英特尔® 芯片组设备软件 - (.Intel(R) Corporation.) [HKLM][64Bits] -- {fb610cea-ba50-4d4b-a717-cf025419035c} =>.Intel(R) Software and Firmware Products?
O42 - Logiciel: 自杀男 - (..) [HKCU][64Bits] -- SuicideGuy_en
O42 - Logiciel: 自由战士 - (..) [HKLM][64Bits] -- 自由战士

---\\ HKCU & HKLM Software Keys (263) - 20s
HKLM\SOFTWARE\00584ab
HKLM\SOFTWARE\360Safe =>.Qihu 360 Software Co., LTD
HKLM\SOFTWARE\360SD
HKLM\SOFTWARE\360zip
HKLM\SOFTWARE\3DMLAUNCHER
HKLM\SOFTWARE\Activision =>.Activision
HKLM\SOFTWARE\Adobe =>.Adobe
HKLM\SOFTWARE\AGEIA Technologies =>.AGEIA Technologies
HKLM\SOFTWARE\baidu =>.Baidu
HKLM\SOFTWARE\Bethesda Softworks =>.Bethesda Softworks
HKLM\SOFTWARE\Blizzard Entertainment =>.Blizzard Entertainment
HKLM\SOFTWARE\Caphyon =>.Caphyon
HKLM\SOFTWARE\cd projekt red =>.CD Projekt RED
HKLM\SOFTWARE\CoreCodec
HKLM\SOFTWARE\Crysis2AdvacedGraphicsOptions =>.Electronic Arts, Inc.
HKLM\SOFTWARE\dbmkdb
HKLM\SOFTWARE\DuoDianOnline =>.DuoDian Online
HKLM\SOFTWARE\EA Games =>.EA Games
HKLM\SOFTWARE\EaseUS =>.EaseUS Software
HKLM\SOFTWARE\EasyAntiCheat =>.EasyAntiCheat
HKLM\SOFTWARE\Electronic Arts =>.Electronic Arts
HKLM\SOFTWARE\Epic Games =>.Epic Games
HKLM\SOFTWARE\EpicGames =>.Epic Games
HKLM\SOFTWARE\EVP =>.EVP Software
HKLM\SOFTWARE\ExpressVpn =>.ExpressVPN
HKLM\SOFTWARE\Francophonie
HKLM\SOFTWARE\Frets on Fire
HKLM\SOFTWARE\GOG.com =>.GOG.com
HKLM\SOFTWARE\Google =>.Google
HKLM\SOFTWARE\HaaliMkx =>.Haali Media
HKLM\SOFTWARE\iCafe8
HKLM\SOFTWARE\Intel =>.Intel
HKLM\SOFTWARE\Khronos =>.Khronos
HKLM\SOFTWARE\Lame For Audacity =>.Audacity
HKLM\SOFTWARE\lamyu
HKLM\SOFTWARE\LiveUpdate360 =>.Qihu 360 Software Co., LTD
HKLM\SOFTWARE\LOOT
HKLM\SOFTWARE\Luletain
HKLM\SOFTWARE\Macromedia =>.Macromedia
HKLM\SOFTWARE\Mozilla =>.Mozilla
HKLM\SOFTWARE\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\Nuance =>.Nuance
HKLM\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation
HKLM\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\OpenAL =>.Open Audio Library
HKLM\SOFTWARE\Origin =>.Electronic Arts, Inc.
HKLM\SOFTWARE\Phase Shift
HKLM\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Realtek Semiconductor Corp. =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Rene.E Laboratory =>.Rene.E Laboratory
HKLM\SOFTWARE\rising =>.Rising Star Games
HKLM\SOFTWARE\Rockstar Games =>.Rockstar Games
HKLM\SOFTWARE\runic games =>.Runic Games
HKLM\SOFTWARE\Shareaza
HKLM\SOFTWARE\SogouComponents =>.SUP.Sogou
HKLM\SOFTWARE\SogouInput =>.SUP.Sogou
HKLM\SOFTWARE\SpeedFan =>.Almico Software
HKLM\SOFTWARE\square enix =>.Square Enix
HKLM\SOFTWARE\SRS Labs =>.SRS Labs
HKLM\SOFTWARE\Tencent =>.SUP.Tencent
HKLM\SOFTWARE\The Document Foundation =>.The Document Foundation
HKLM\SOFTWARE\Thunder Network
HKLM\SOFTWARE\TPHelper
HKLM\SOFTWARE\Ubisoft =>.Ubisoft
HKLM\SOFTWARE\UCBrowser =>.UCWeb Inc.
HKLM\SOFTWARE\Valve =>.Valve
HKLM\SOFTWARE\Video Legend
HKLM\SOFTWARE\VideoLAN =>.VideoLAN
HKLM\SOFTWARE\Volatile =>.Microsoft Corporation
HKLM\SOFTWARE\WBGames
HKLM\SOFTWARE\WOW6432Node =>.Microsoft Corporation
HKLM\SOFTWARE\yxbox
HKLM\SOFTWARE\yxdown
HKLM\SOFTWARE\Zupidrnosh
HKLM\SOFTWARE\自由战士
HKLM\SOFTWARE\Even Balance =>.Even Balance Inc
HKLM\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\00584ab
HKLM\SOFTWARE\WOW6432Node\360Safe =>.Qihu 360 Software Co., LTD
HKLM\SOFTWARE\WOW6432Node\360SD
HKLM\SOFTWARE\WOW6432Node\360zip
HKLM\SOFTWARE\WOW6432Node\3DMLAUNCHER
HKLM\SOFTWARE\WOW6432Node\Activision =>.Activision
HKLM\SOFTWARE\WOW6432Node\Adobe =>.Adobe
HKLM\SOFTWARE\WOW6432Node\AGEIA Technologies =>.AGEIA Technologies
HKLM\SOFTWARE\WOW6432Node\baidu =>.Baidu
HKLM\SOFTWARE\WOW6432Node\Bethesda Softworks =>.Bethesda Softworks
HKLM\SOFTWARE\WOW6432Node\Blizzard Entertainment =>.Blizzard Entertainment
HKLM\SOFTWARE\WOW6432Node\Caphyon =>.Caphyon
HKLM\SOFTWARE\WOW6432Node\cd projekt red =>.CD Projekt RED
HKLM\SOFTWARE\WOW6432Node\CoreCodec
HKLM\SOFTWARE\WOW6432Node\Crysis2AdvacedGraphicsOptions =>.Electronic Arts, Inc.
HKLM\SOFTWARE\WOW6432Node\dbmkdb
HKLM\SOFTWARE\WOW6432Node\DuoDianOnline =>.DuoDian Online
HKLM\SOFTWARE\WOW6432Node\EA Games =>.EA Games
HKLM\SOFTWARE\WOW6432Node\EaseUS =>.EaseUS Software
HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat =>.EasyAntiCheat
HKLM\SOFTWARE\WOW6432Node\Electronic Arts =>.Electronic Arts
HKLM\SOFTWARE\WOW6432Node\Epic Games =>.Epic Games
HKLM\SOFTWARE\WOW6432Node\EpicGames =>.Epic Games
HKLM\SOFTWARE\WOW6432Node\EVP =>.EVP Software
HKLM\SOFTWARE\WOW6432Node\ExpressVpn =>.ExpressVPN
HKLM\SOFTWARE\WOW6432Node\Francophonie
HKLM\SOFTWARE\WOW6432Node\Frets on Fire
HKLM\SOFTWARE\WOW6432Node\GOG.com =>.GOG.com
HKLM\SOFTWARE\WOW6432Node\Google =>.Google
HKLM\SOFTWARE\WOW6432Node\HaaliMkx =>.Haali Media
HKLM\SOFTWARE\WOW6432Node\iCafe8
HKLM\SOFTWARE\WOW6432Node\Intel =>.Intel
HKLM\SOFTWARE\WOW6432Node\Khronos =>.Khronos
HKLM\SOFTWARE\WOW6432Node\Lame For Audacity =>.Audacity
HKLM\SOFTWARE\WOW6432Node\lamyu
HKLM\SOFTWARE\WOW6432Node\LiveUpdate360 =>.Qihu 360 Software Co., LTD
HKLM\SOFTWARE\WOW6432Node\LOOT
HKLM\SOFTWARE\WOW6432Node\Luletain
HKLM\SOFTWARE\WOW6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\WOW6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\WOW6432Node\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\WOW6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\WOW6432Node\Nuance =>.Nuance
HKLM\SOFTWARE\WOW6432Node\NVIDIA Corporation =>.nVidia Corporation
HKLM\SOFTWARE\WOW6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\WOW6432Node\OpenAL =>.Open Audio Library
HKLM\SOFTWARE\WOW6432Node\Origin =>.Electronic Arts, Inc.
HKLM\SOFTWARE\WOW6432Node\Phase Shift
HKLM\SOFTWARE\WOW6432Node\Realtek =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\WOW6432Node\Realtek Semiconductor Corp. =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\WOW6432Node\Rene.E Laboratory =>.Rene.E Laboratory
HKLM\SOFTWARE\WOW6432Node\rising =>.Rising Star Games
HKLM\SOFTWARE\WOW6432Node\Rockstar Games =>.Rockstar Games
HKLM\SOFTWARE\WOW6432Node\runic games =>.Runic Games
HKLM\SOFTWARE\WOW6432Node\Shareaza
HKLM\SOFTWARE\WOW6432Node\SogouComponents =>.SUP.Sogou
HKLM\SOFTWARE\WOW6432Node\SogouInput =>.SUP.Sogou
HKLM\SOFTWARE\WOW6432Node\SpeedFan =>.Almico Software
HKLM\SOFTWARE\WOW6432Node\square enix =>.Square Enix
HKLM\SOFTWARE\WOW6432Node\SRS Labs =>.SRS Labs
HKLM\SOFTWARE\WOW6432Node\Tencent =>.SUP.Tencent
HKLM\SOFTWARE\WOW6432Node\The Document Foundation =>.The Document Foundation
HKLM\SOFTWARE\WOW6432Node\Thunder Network
HKLM\SOFTWARE\WOW6432Node\TPHelper
HKLM\SOFTWARE\WOW6432Node\Ubisoft =>.Ubisoft
HKLM\SOFTWARE\WOW6432Node\UCBrowser =>.UCWeb Inc.
HKLM\SOFTWARE\WOW6432Node\Valve =>.Valve
HKLM\SOFTWARE\WOW6432Node\Video Legend
HKLM\SOFTWARE\WOW6432Node\VideoLAN =>.VideoLAN
HKLM\SOFTWARE\WOW6432Node\Volatile =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\WBGames
HKLM\SOFTWARE\WOW6432Node\WOW6432Node =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\yxbox
HKLM\SOFTWARE\WOW6432Node\yxdown
HKLM\SOFTWARE\WOW6432Node\Zupidrnosh
HKLM\SOFTWARE\WOW6432Node\自由战士
HKLM\SOFTWARE\WOW6432Node\Even Balance =>.Even Balance Inc
HKLM\SOFTWARE\WOW6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\360 =>.Qihu 360 Software Co., LTD
HKCU\SOFTWARE\360Safe =>.Qihu 360 Software Co., LTD
HKCU\SOFTWARE\360zip
HKCU\SOFTWARE\91yGame
HKCU\SOFTWARE\9c58e07c-77be-5d3f-be9c-687ecb20f62c =>Adware.CrossRider
HKCU\SOFTWARE\Adobe =>.Adobe
HKCU\SOFTWARE\Adobe Lightroom =>.Adobe Inc.
HKCU\SOFTWARE\AMPLITUDE Studios =>.Amplitude Studios
HKCU\SOFTWARE\APlayer
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\Audiosurf, LLC
HKCU\SOFTWARE\Baidu =>.Baidu
HKCU\SOFTWARE\Berserk Games =>.Berserk Games
HKCU\SOFTWARE\Blizzard Entertainment =>.Blizzard Entertainment
HKCU\SOFTWARE\bmk
HKCU\SOFTWARE\BugSplat =>.Bugsplat Game
HKCU\SOFTWARE\cd projekt red =>.CD Projekt RED
HKCU\SOFTWARE\CDProjektRED =>.CD Projekt
HKCU\SOFTWARE\Chromium =>.Chromium
HKCU\SOFTWARE\Chubby Pixel
HKCU\SOFTWARE\Codeusa Software =>.Codeusa Software
HKCU\SOFTWARE\Colossal Order =>.Colossal Order
HKCU\SOFTWARE\CoolROM
HKCU\SOFTWARE\CoreAAC =>.Core Codec
HKCU\SOFTWARE\CrystalIDEA Software =>.CrystalIdea Software
HKCU\SOFTWARE\DisplayCardInfo
HKCU\SOFTWARE\Dolphin Emulator
HKCU\SOFTWARE\downer
HKCU\SOFTWARE\DuoDianApp =>.DuoDianApp
HKCU\SOFTWARE\EaseUS =>.EaseUS Software
HKCU\SOFTWARE\Elecard =>.Elecard
HKCU\SOFTWARE\Epic Games =>.Epic Games
HKCU\SOFTWARE\EpicNet Inc. =>Adware.MSIL
HKCU\SOFTWARE\ExpressVPN =>.ExpressVPN
HKCU\SOFTWARE\FileSmasher
HKCU\SOFTWARE\Flexera
HKCU\SOFTWARE\Futuremark =>.Futuremark
HKCU\SOFTWARE\Gabest =>.Gabest
HKCU\SOFTWARE\GameSpy =>.GameSpy
HKCU\SOFTWARE\GOG.com =>.GOG.com
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\home =>.Unknown
HKCU\SOFTWARE\Intel =>.Intel
HKCU\SOFTWARE\IO Interactive =>.IO Interactive
HKCU\SOFTWARE\kuwo
HKCU\SOFTWARE\LiveUpdate360 =>.Qihu 360 Software Co., LTD
HKCU\SOFTWARE\Logitech =>.Logitech
HKCU\SOFTWARE\Macromedia =>.Macromedia
HKCU\SOFTWARE\Magnet =>.Magnet
HKCU\SOFTWARE\Malwarebytes =>.Malwarebytes
HKCU\SOFTWARE\MediaChance =>.Mediachance
HKCU\SOFTWARE\Mine =>.Microsoft Corporation
HKCU\SOFTWARE\ModManager
HKCU\SOFTWARE\Mozilla =>.Mozilla
HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKCU\SOFTWARE\NewTechnologyStudio =>.New Technology Studio
HKCU\SOFTWARE\NTSCorp =>.NTSCorp Ltd
HKCU\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation
HKCU\SOFTWARE\nwjs =>.NW.js
HKCU\SOFTWARE\Psiphon3
HKCU\SOFTWARE\QtProject =>.QtProject
HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKCU\SOFTWARE\RedCandleGames
HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\Rene.E Laboratory =>.Rene.E Laboratory
HKCU\SOFTWARE\RISING =>.Rising Star Games
HKCU\SOFTWARE\Rockstar Games =>.Rockstar Games
HKCU\SOFTWARE\runic games =>.Runic Games
HKCU\SOFTWARE\SAMP
HKCU\SOFTWARE\SecuROM =>.SecuROM
HKCU\SOFTWARE\Shareaza
HKCU\SOFTWARE\SogouInput =>.SUP.Sogou
HKCU\SOFTWARE\SogouInput.ppup =>.SUP.Sogou
HKCU\SOFTWARE\SpeedFan =>.Almico Software
HKCU\SOFTWARE\Spiderling Games =>.Spiderling Games
HKCU\SOFTWARE\Studio MDHR =>.Pinnacle Systems, Inc.
HKCU\SOFTWARE\SuperChainMedia
HKCU\SOFTWARE\Synaptics =>.Synaptics
HKCU\SOFTWARE\SyncEngines =>.Microsoft Corporation
HKCU\SOFTWARE\Team 17 Digital ltd. =>.Team 17 Digital
HKCU\SOFTWARE\Tencent =>.SUP.Tencent
HKCU\SOFTWARE\TesSafe
HKCU\SOFTWARE\The Document Foundation =>.The Document Foundation
HKCU\SOFTWARE\TheGameBakers
HKCU\SOFTWARE\Thunder Network
HKCU\SOFTWARE\TPHelper
HKCU\SOFTWARE\Trolltech =>.Trolltech
HKCU\SOFTWARE\Twitch
HKCU\SOFTWARE\Ubisoft =>.Ubisoft
HKCU\SOFTWARE\Unity =>.Unity
HKCU\SOFTWARE\Valve =>.Valve
HKCU\SOFTWARE\Video Legend
HKCU\SOFTWARE\VideoLAN =>.VideoLAN
HKCU\SOFTWARE\Volition =>.Volition
HKCU\SOFTWARE\wbgames
HKCU\SOFTWARE\Winamp =>.Nullsoft Inc.
HKCU\SOFTWARE\WinAuth3
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\Wpsrepair
HKCU\SOFTWARE\XPusher
HKCU\SOFTWARE\Youxun
HKCU\SOFTWARE\YXGStart
HKCU\SOFTWARE\ZebHelpProcess Helper =>.Nicolas Coolman
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKCU\SOFTWARE\AppDataLow\Thunder BHO Platform
HKCU\SOFTWARE\AppDataLow\Thunder Network

---\\ Contents of the Common Files folders (426) - 13s
O43 - CFD: 04/11/2017 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 22/04/2017 - [] AD -- C:\Program Files\Frhelper_Ime {101B667A9426A663AC5C64BCA25BD192}
O43 - CFD: 13/12/2017 - [] AD -- C:\Program Files\Intel =>.Intel Corporation
O43 - CFD: 05/01/2018 - [] D -- C:\Program Files\internet explorer =>.Microsoft Corporation
O43 - CFD: 06/03/2018 - [] AD -- C:\Program Files\KMSpico =>HackTool.KMSpico
O43 - CFD: 22/04/2017 - [] AD -- C:\Program Files\LibreOffice 5 =>.LibreOffice
O43 - CFD: 09/08/2017 - [] D -- C:\Program Files\Malwarebytes =>.Malwarebytes
O43 - CFD: 22/10/2016 - [] AD -- C:\Program Files\MotioninJoy =>.MotionInjoy
O43 - CFD: 04/11/2017 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 16/09/2017 - [] D -- C:\Program Files\Notepad++ =>.Don Ho
O43 - CFD: 04/02/2018 - [] D -- C:\Program Files\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\Program Files\Realtek =>.Realtek
O43 - CFD: 04/11/2017 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 08/03/2018 - [] D -- C:\Program Files\Rockstar Games =>.Rockstar Games, Inc.?
O43 - CFD: 04/11/2017 - [] D -- C:\Program Files\Synaptics =>.Synaptics Incorporated?
O43 - CFD: 10/07/2015 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 03/08/2017 - [] D -- C:\Program Files\Unlocker =>.Cedrick Collomb
O43 - CFD: 04/11/2017 - [] AD -- C:\Program Files\UNP =>.Microsoft Corporation
O43 - CFD: 06/03/2018 - [] RD -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 14/12/2017 - [] D -- C:\Program Files\Windows Defender Advanced Threat Protection =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\Program Files\windows nt =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files\Windows Security =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] SHD -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 07/03/2018 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 22/10/2016 - [] D -- C:\Program Files (x86)\360 =>.Qihu 360 Software
O43 - CFD: 28/04/2017 - [] D -- C:\Program Files (x86)\3dm_game_files
O43 - CFD: 22/10/2016 - [] AD -- C:\Program Files (x86)\ASM104xUSB3 =>.ASMedia Technology Inc
O43 - CFD: 22/10/2016 - [] AD -- C:\Program Files (x86)\Audacity =>.Audacity
O43 - CFD: 14/02/2018 - [] D -- C:\Program Files (x86)\Bignox =>.BigNox
O43 - CFD: 22/04/2017 - [] AD -- C:\Program Files (x86)\Borderless Gaming {1C7DC54D08621A96136B378AA9E4392B}
O43 - CFD: 11/02/2017 - [] D -- C:\Program Files (x86)\cache =>.Legitimate
O43 - CFD: 06/11/2016 - [] D -- C:\Program Files (x86)\Coickgrereward =>.Glarysoft LTD?
O43 - CFD: 04/11/2017 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 27/01/2018 - [] D -- C:\Program Files (x86)\EasyAntiCheat =>.EasyAntiCheat Oy?
O43 - CFD: 22/10/2016 - [] D -- C:\Program Files (x86)\Electronic Arts =>.Electronic Arts
O43 - CFD: 08/03/2018 - [] D -- C:\Program Files (x86)\ExpressVPN =>.Express Vpn LLC?
O43 - CFD: 08/03/2018 - [] D -- C:\Program Files (x86)\ExpressVpn SplitTunnel Driver =>.Express Vpn LLC?
O43 - CFD: 08/03/2018 - [] D -- C:\Program Files (x86)\ExpressVpn Tap Driver Win10 =>.ExprsVPN LLC?
O43 - CFD: 10/02/2017 - [] D -- C:\Program Files (x86)\extend
O43 - CFD: 06/03/2018 - [] D -- C:\Program Files (x86)\Free =>.Legitimate
O43 - CFD: 22/10/2016 - [] D -- C:\Program Files (x86)\Futuremark =>.FUTUREMARK INC?
O43 - CFD: 29/01/2017 - [] D -- C:\Program Files (x86)\Google =>.Google Inc?
O43 - CFD: 19/02/2017 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield
O43 - CFD: 31/07/2017 - [] D -- C:\Program Files (x86)\Intel =>.Intel Corporation
O43 - CFD: 05/01/2018 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 06/03/2018 - [] D -- C:\Program Files (x86)\KMSPico 10.2.1 Final =>HackTool.KMSpico
O43 - CFD: 10/09/2017 - [] D -- C:\Program Files (x86)\kuwo {50DA1504909F7273486D47AC0AB74675}
O43 - CFD: 22/10/2016 - [] AD -- C:\Program Files (x86)\Lame For Audacity =>.Audacity
O43 - CFD: 04/05/2017 - [] AD -- C:\Program Files (x86)\LOOT
O43 - CFD: 22/10/2016 - [] HD -- C:\Program Files (x86)\Microsoft =>.Microsoft Corporation
O43 - CFD: 26/10/2016 - [] D -- C:\Program Files (x86)\Microsoft Games for Windows - LIVE =>.Microsoft Corporation
O43 - CFD: 22/10/2016 - [] AD -- C:\Program Files (x86)\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 22/10/2016 - [] D -- C:\Program Files (x86)\Microsoft XNA =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 12/11/2016 - [0] D -- C:\Program Files (x86)\MotioninJoy =>.MotionInjoy
O43 - CFD: 15/02/2018 - [] AD -- C:\Program Files (x86)\Mozilla Firefox =>.Mozilla
O43 - CFD: 19/02/2018 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service =>.Mozilla
O43 - CFD: 04/11/2017 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 06/03/2018 - [] D -- C:\Program Files (x86)\Multitimer
O43 - CFD: 27/12/2016 - [] D -- C:\Program Files (x86)\NarutoOnline =>.OASIS GAMES LIMITED?
O43 - CFD: 14/02/2018 - [] D -- C:\Program Files (x86)\Nox =>.FFmpeg Project
O43 - CFD: 10/02/2018 - [] D -- C:\Program Files (x86)\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 22/10/2016 - [] D -- C:\Program Files (x86)\OEM =>.OEM
O43 - CFD: 22/10/2016 - [] D -- C:\Program Files (x86)\OpenAL =>.Open Audio Library
O43 - CFD: 24/12/2017 - [] AD -- C:\Program Files (x86)\Origin =>.Electronic Arts, Inc.
O43 - CFD: 22/10/2016 - [0] D -- C:\Program Files (x86)\Origin Games =>.Electronic Arts, Inc.
O43 - CFD: 22/10/2016 - [] D -- C:\Program Files (x86)\Realtek =>.Realtek
O43 - CFD: 04/11/2017 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 08/03/2018 - [] D -- C:\Program Files (x86)\Rockstar Games =>.Rockstar Games, Inc.?
O43 - CFD: 01/01/2018 - [] D -- C:\Program Files (x86)\SpeedFan =>.Almico Software
O43 - CFD: 22/10/2016 - [0] HD -- C:\Program Files (x86)\Temp =>.Microsoft Corporation
O43 - CFD: 07/03/2018 - [] D -- C:\Program Files (x86)\Tencent =>.SUP.Tencent
O43 - CFD: 07/12/2017 - [] D -- C:\Program Files (x86)\Thunder Network =>.Thunder Network
O43 - CFD: 30/11/2016 - [] D -- C:\Program Files (x86)\Ubisoft =>.Ubisoft
O43 - CFD: 09/08/2017 - [] D -- C:\Program Files (x86)\UCBrowser
O43 - CFD: 22/04/2017 - [0] HD -- C:\Program Files (x86)\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 10/02/2017 - [] D -- C:\Program Files (x86)\uwdi {4BB052CFC3F3745FF89F3A1D453BAB22}
O43 - CFD: 24/10/2017 - [] D -- C:\Program Files (x86)\Video Legend {2F45428F979B6FA35CF436C537FDC3C3}
O43 - CFD: 30/10/2016 - [] D -- C:\Program Files (x86)\VideoLAN =>.VideoLan Team
O43 - CFD: 08/03/2018 - [] D -- C:\Program Files (x86)\VulkanRT =>.LunarG, Inc
O43 - CFD: 30/09/2017 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files (x86)\windows nt =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] SHD -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files (x86)\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360安全中心
O43 - CFD: 29/09/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 14/02/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 14/02/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net =>.Games Software
O43 - CFD: 20/10/2016 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 1 =>.Electronic Arts, Inc.
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Borderless Gaming
O43 - CFD: 11/10/2016 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolphin =>.Dolphin DevTeam
O43 - CFD: 08/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ExpressVPN =>.ExpressVPN
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Furi 中文版
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Futuremark =>.Futuremark
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com =>.GOG.com
O43 - CFD: 08/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico =>HackTool.KMSpico
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.3 =>.LibreOffice
O43 - CFD: 29/09/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes =>.Malwarebytes
O43 - CFD: 31/12/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metal Gear Solid V The Phantom Pain
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy =>.MotionInjoy
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NarutoOnline
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager =>.Winstep Software Technologies
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ =>.Don Ho
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin =>.Electronic Arts, Inc.
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Overwatch =>.Blizzard Entertainment
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Phase Shift
O43 - CFD: 02/12/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rene.E Laboratory =>.Rene.E Laboratory
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games =>.Rockstar Games
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shareaza =>.Shareaza (P2P)
O43 - CFD: 11/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShaShou13
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II
O43 - CFD: 04/11/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp =>.Microsoft Corporation
O43 - CFD: 08/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam =>.Steam Games
O43 - CFD: 14/02/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] AD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher Rise of the White Wolf =>.Atari Inc
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ultima series
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\哈利波特:魁地奇世界杯繁体中文版
O43 - CFD: 07/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\微信
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\搜狗拼音输入法
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\易我分区管理大师 11.0
O43 - CFD: 17/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\星际争霸II
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\法语助手
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\游迅网
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\看看影音
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
O43 - CFD: 23/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\迅雷软件
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\酷我音乐
O43 - CFD: 11/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\魔兽世界
O43 - CFD: 22/10/2016 - [] D -- C:\ProgramData\.mono =>.Legitimate
O43 - CFD: 08/03/2018 - [] D -- C:\ProgramData\360zip
O43 - CFD: 18/12/2016 - [] D -- C:\ProgramData\Adobe =>.Adobe
O43 - CFD: 04/11/2017 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 22/10/2016 - [] D -- C:\ProgramData\AVAST Software =>.AVAST Software
O43 - CFD: 22/10/2016 - [] D -- C:\ProgramData\Avg =>.AVG Software
O43 - CFD: 22/10/2016 - [] D -- C:\ProgramData\Avira =>.Avira Software
O43 - CFD: 04/02/2017 - [] D -- C:\ProgramData\Baidu =>.Baidu
O43 - CFD: 22/10/2016 - [] D -- C:\ProgramData\Battle.net =>.Games Software
O43 - CFD: 14/10/2016 - [] D -- C:\ProgramData\BDSReport
O43 - CFD: 09/03/2017 - [] D -- C:\ProgramData\Blizzard Entertainment =>.Blizzard Entertainment
O43 - CFD: 04/02/2017 - [] D -- C:\ProgramData\boost_interprocess =>.boost.org
O43 - CFD: 13/11/2016 - [] D -- C:\ProgramData\Caphyon =>.Caphyon
O43 - CFD: 16/02/2017 - [] D -- C:\ProgramData\CDProjekt RED
O43 - CFD: 12/10/2016 - [] D -- C:\ProgramData\CleanAndroid
O43 - CFD: 16/07/2016 - [0] D -- C:\ProgramData\Comms =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 10/02/2017 - [] D -- C:\ProgramData\EA Core =>.Electronic Arts, Inc.
O43 - CFD: 10/02/2017 - [] D -- C:\ProgramData\Electronic Arts =>.Electronic Arts
O43 - CFD: 11/11/2017 - [] D -- C:\ProgramData\Epic =>.Epic
O43 - CFD: 08/03/2018 - [] D -- C:\ProgramData\ExpressVPN =>.ExpressVPN
O43 - CFD: 11/02/2017 - [] D -- C:\ProgramData\For Honor
O43 - CFD: 01/02/2017 - [] D -- C:\ProgramData\gameicon
O43 - CFD: 25/10/2016 - [] D -- C:\ProgramData\GOG.com =>.GOG.com
O43 - CFD: 27/08/2017 - [] D -- C:\ProgramData\InstallShield =>.InstallShield
O43 - CFD: 31/07/2017 - [] D -- C:\ProgramData\Intel =>.Intel Corporation
O43 - CFD: 31/07/2017 - [] D -- C:\ProgramData\Intel.sav =>.Intel Corporation
O43 - CFD: 16/08/2017 - [] D -- C:\ProgramData\kuwodata
O43 - CFD: 14/10/2016 - [] D -- C:\ProgramData\KWGameBox
O43 - CFD: 09/08/2017 - [] D -- C:\ProgramData\Malwarebytes =>.Malwarebytes
O43 - CFD: 04/11/2017 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft OneDrive =>.Microsoft Corporation
O43 - CFD: 09/03/2018 - [] D -- C:\ProgramData\NVIDIA =>.nVidia Corporation
O43 - CFD: 08/03/2018 - [] D -- C:\ProgramData\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 28/12/2017 - [] D -- C:\ProgramData\Origin =>.Electronic Arts, Inc.
O43 - CFD: 08/03/2018 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [0] D -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
O43 - CFD: 31/07/2017 - [] D -- C:\ProgramData\Roaming =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [0] D -- C:\ProgramData\SoftwareDistribution =>.Microsoft Corporation
O43 - CFD: 26/08/2017 - [] D -- C:\ProgramData\SogouInput =>.SUP.Sogou
O43 - CFD: 04/11/2017 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation
O43 - CFD: 24/12/2017 - [] D -- C:\ProgramData\Tencent =>.SUP.Tencent
O43 - CFD: 11/10/2016 - [] D -- C:\ProgramData\Thunder Network =>.Thunder Network
O43 - CFD: 10/12/2017 - [] D -- C:\ProgramData\Ubisoft =>.Ubisoft
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\USOPrivate =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\USOShared =>.Microsoft Corporation
O43 - CFD: 15/10/2016 - [] D -- C:\ProgramData\Windows
O43 - CFD: 30/09/2017 - [] D -- C:\ProgramData\WindowsHolographicDevices =>.Microsoft Corporation
O43 - CFD: 28/02/2017 - [] D -- C:\ProgramData\X360CE =>.Microsoft Corporation
O43 - CFD: 23/01/2017 - [] D -- C:\ProgramData\{plbackup-CFE0-66E8-660553B4C955}
O43 - CFD: 26/01/2016 - [0] SHD -- C:\ProgramData\「开始」菜单
O43 - CFD: 26/01/2016 - [0] SHD -- C:\ProgramData\桌面
O43 - CFD: 27/08/2017 - [] D -- C:\Program Files (x86)\Common Files\InstallShield =>.InstallShield
O43 - CFD: 04/11/2017 - [] D -- C:\Program Files (x86)\Common Files\Intel =>.Intel Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared =>.Microsoft Corporation
O43 - CFD: 26/01/2016 - [] D -- C:\Program Files (x86)\Common Files\PostureAgent =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 08/03/2018 - [] D -- C:\Program Files (x86)\Common Files\Steam =>.Steam Games
O43 - CFD: 30/09/2017 - [] D -- C:\Program Files (x86)\Common Files\system =>.Microsoft Corporation
O43 - CFD: 04/10/2017 - [] D -- C:\Program Files (x86)\Common Files\Tencent =>.SUP.Tencent
O43 - CFD: 24/10/2017 - [] D -- C:\Program Files (x86)\Common Files\Thunder Network =>.Thunder Network
O43 - CFD: 22/10/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\.mono =>.Legitimate
O43 - CFD: 27/01/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\360DiagnoseScan
O43 - CFD: 26/01/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\360Login
O43 - CFD: 06/03/2018 - [] D -- C:\Users\VULCAN\AppData\Roaming\360zip
O43 - CFD: 18/12/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 14/10/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\Audacity =>.Audacity
O43 - CFD: 23/02/2018 - [] D -- C:\Users\VULCAN\AppData\Roaming\Badoo =>.Badoo
O43 - CFD: 04/02/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\baidu =>.Baidu
O43 - CFD: 27/01/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\BaiduYunGuanjia
O43 - CFD: 27/01/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\BaiduYunKernel
O43 - CFD: 27/01/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\BaiduYunKongMing
O43 - CFD: 23/09/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Battle.net =>.Games Software
O43 - CFD: 27/12/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\Brotsoft
O43 - CFD: 13/11/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\CD Projekt RED =>.CD Projekt RED
O43 - CFD: 23/12/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Citra
O43 - CFD: 12/10/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\CleanAndroid
O43 - CFD: 22/04/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Codeusa Software =>.Codeusa Software
O43 - CFD: 17/08/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\CPUCores
O43 - CFD: 12/11/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\cqby
O43 - CFD: 06/10/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\cqsj
O43 - CFD: 06/10/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Cuphead
O43 - CFD: 02/04/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\downer
O43 - CFD: 23/11/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\Doyo
O43 - CFD: 16/04/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Duelyst
O43 - CFD: 24/02/2018 - [] D -- C:\Users\VULCAN\AppData\Roaming\EasyAntiCheat
O43 - CFD: 06/03/2018 - [] D -- C:\Users\VULCAN\AppData\Roaming\EpicNet Inc =>Adware.MSIL
O43 - CFD: 22/10/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\epm =>.Easus
O43 - CFD: 27/01/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\Expert
O43 - CFD: 08/03/2018 - [] D -- C:\Users\VULCAN\AppData\Roaming\ExpressVPN =>.ExpressVPN
O43 - CFD: 11/10/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\Francochinois
O43 - CFD: 27/08/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\fretsonfire
O43 - CFD: 12/11/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\GameSetup
O43 - CFD: 08/10/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\HD Tune Pro =>.EFD Software
O43 - CFD: 27/11/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\HelloGames =>.HelloGames
O43 - CFD: 31/07/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Intel =>.Intel Corporation
O43 - CFD: 19/11/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\Io Interactive =>.IO Interactive
O43 - CFD: 17/03/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\khedge2574
O43 - CFD: 12/11/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\Kuai8Res
O43 - CFD: 09/02/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\leyoubox
O43 - CFD: 22/04/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\LibreOffice =>.LibreOffice
O43 - CFD: 02/04/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\LoginTool
O43 - CFD: 29/01/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\LolClient =>.LolClient
O43 - CFD: 26/01/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 06/03/2018 - [] SD -- C:\Users\VULCAN\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 22/10/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\MotioninJoy =>.MotionInjoy
O43 - CFD: 18/11/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 02/10/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\MS =>.MS
O43 - CFD: 15/10/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\New Technology Studio =>.New Technology Studio
O43 - CFD: 26/08/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Nex Machina
O43 - CFD: 16/09/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Notepad++ =>.Don Ho
O43 - CFD: 14/10/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\NVIDIA =>.nVidia Corporation
O43 - CFD: 28/12/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Origin =>.Electronic Arts, Inc.
O43 - CFD: 22/10/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\Profiles =>.Microsoft Corporation
O43 - CFD: 05/10/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Psiphon3
O43 - CFD: 31/03/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Shareaza =>.Shareaza (P2P)
O43 - CFD: 12/10/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\Skype =>.Skype
O43 - CFD: 15/10/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\Steam =>.Steam Games
O43 - CFD: 02/09/2017 - [0] D -- C:\Users\VULCAN\AppData\Roaming\Temp =>.Microsoft Corporation
O43 - CFD: 07/03/2018 - [] D -- C:\Users\VULCAN\AppData\Roaming\Tencent =>.SUP.Tencent
O43 - CFD: 12/09/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Terrible Toybox
O43 - CFD: 16/08/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\The Witness
O43 - CFD: 01/12/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Twitch
O43 - CFD: 24/10/2017 - [] HD -- C:\Users\VULCAN\AppData\Roaming\Video Legend
O43 - CFD: 23/02/2018 - [] D -- C:\Users\VULCAN\AppData\Roaming\vlc =>.VideoLan Team
O43 - CFD: 07/03/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\WinAuth
O43 - CFD: 14/12/2016 - [] D -- C:\Users\VULCAN\AppData\Roaming\XLGameBox
O43 - CFD: 16/09/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\xplayers
O43 - CFD: 06/10/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\youxunbox
O43 - CFD: 31/01/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\yxqxunyou
O43 - CFD: 09/03/2018 - [] D -- C:\Users\VULCAN\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 24/07/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\迅雷游戏
O43 - CFD: 23/09/2017 - [] D -- C:\Users\VULCAN\AppData\Local\Adobe =>.Adobe
O43 - CFD: 13/10/2016 - [] D -- C:\Users\VULCAN\AppData\Local\ali213GameLauncher
O43 - CFD: 04/11/2017 - [0] SHD -- C:\Users\VULCAN\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 04/02/2017 - [] D -- C:\Users\VULCAN\AppData\Local\Baidu =>.Baidu
O43 - CFD: 04/02/2018 - [] D -- C:\Users\VULCAN\AppData\Local\Battle.net =>.Games Software
O43 - CFD: 01/05/2017 - [] D -- C:\Users\VULCAN\AppData\Local\Black_Tree_Gaming =>.Black Tree Gaming Ltd
O43 - CFD: 22/10/2016 - [] D -- C:\Users\VULCAN\AppData\Local\Blizzard =>.Blizzard
O43 - CFD: 23/09/2017 - [] D -- C:\Users\VULCAN\AppData\Local\Blizzard Entertainment =>.Blizzard Entertainment
O43 - CFD: 11/10/2016 - [] D -- C:\Users\VULCAN\AppData\Local\CEF =>.CEF
O43 - CFD: 13/12/2016 - [] D -- C:\Users\VULCAN\AppData\Local\Chromium =>.Chromium
O43 - CFD: 25/02/2017 - [] D -- C:\Users\VULCAN\AppData\Local\Colossal Order =>.Colossal Order Ltd
O43 - CFD: 18/11/2016 - [] D -- C:\Users\VULCAN\AppData\Local\Comms =>.Microsoft Corporation
O43 - CFD: 30/04/2017 - [] D -- C:\Users\VULCAN\AppData\Local\ConnectedDevicesPlatform =>.Microsoft Corporation
O43 - CFD: 08/03/2018 - [] D -- C:\Users\VULCAN\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 24/02/2018 - [] D -- C:\Users\VULCAN\AppData\Local\CrashRpt
O43 - CFD: 27/01/2018 - [] D -- C:\Users\VULCAN\AppData\Local\DBFighterZ
O43 - CFD: 28/04/2017 - [0] D -- C:\Users\VULCAN\AppData\Local\DBG =>.DBG
O43 - CFD: 03/09/2017 - [0] D -- C:\Users\VULCAN\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 02/04/2017 - [] D -- C:\Users\VULCAN\AppData\Local\downer
O43 - CFD: 27/01/2018 - [] D -- C:\Users\VULCAN\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation
O43 - CFD: 11/11/2017 - [] D -- C:\Users\VULCAN\AppData\Local\EpicGamesLauncher =>.Epic Games
O43 - CFD: 06/02/2017 - [] D -- C:\Users\VULCAN\AppData\Local\ExpressVPN =>.ExpressVPN
O43 - CFD: 14/10/2016 - [] D -- C:\Users\VULCAN\AppData\Local\Futuremark =>.Futuremark
O43 - CFD: 16/02/2017 - [] D -- C:\Users\VULCAN\AppData\Local\GalaxyCommunicationService =>.Galaxy Communication
O43 - CFD: 28/01/2018 - [] D -- C:\Users\VULCAN\AppData\Local\GOG.com =>.GOG.com
O43 - CFD: 29/01/2017 - [] D -- C:\Users\VULCAN\AppData\Local\Google =>.Google
O43 - CFD: 22/10/2016 - [0] D -- C:\Users\VULCAN\AppData\Local\Grijupy
O43 - CFD: 04/11/2017 - [0] SHD -- C:\Users\VULCAN\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 27/08/2017 - [] D -- C:\Users\VULCAN\AppData\Local\id Software =>.id Software
O43 - CFD: 19/11/2016 - [] D -- C:\Users\VULCAN\AppData\Local\IO Interactive =>.IO Interactive
O43 - CFD: 11/10/2016 - [] D -- C:\Users\VULCAN\AppData\Local\IsolatedStorage =>.id Software
O43 - CFD: 12/10/2016 - [] D -- C:\Users\VULCAN\AppData\Local\KBSdata
O43 - CFD: 17/10/2016 - [] D -- C:\Users\VULCAN\AppData\Local\KwGMusic
O43 - CFD: 23/01/2017 - [] D -- C:\Users\VULCAN\AppData\Local\kwmusic
O43 - CFD: 06/05/2017 - [] D -- C:\Users\VULCAN\AppData\Local\LOOT
O43 - CFD: 11/10/2016 - [] D -- C:\Users\VULCAN\AppData\Local\Macromedia =>.Macromedia
O43 - CFD: 04/11/2017 - [] D -- C:\Users\VULCAN\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 11/10/2016 - [] D -- C:\Users\VULCAN\AppData\Local\MicrosoftEdge =>.Microsoft Corporation
O43 - CFD: 11/10/2016 - [] D -- C:\Users\VULCAN\AppData\Local\Mozilla =>.Mozilla Corporation
O43 - CFD: 03/08/2017 - [] D -- C:\Users\VULCAN\AppData\Local\MozillaOnline
O43 - CFD: 26/01/2016 - [0] D -- C:\Users\VULCAN\AppData\Local\NetworkTiles =>.NetworkTiles
O43 - CFD: 15/10/2016 - [] D -- C:\Users\VULCAN\AppData\Local\New Technology Studio =>.New Technology Studio
O43 - CFD: 16/09/2017 - [0] D -- C:\Users\VULCAN\AppData\Local\Notepad++ =>.Don Ho
O43 - CFD: 19/02/2018 - [] D -- C:\Users\VULCAN\AppData\Local\Nox =>.FFmpeg Project
O43 - CFD: 08/03/2018 - [] D -- C:\Users\VULCAN\AppData\Local\NVIDIA =>.nVidia Corporation
O43 - CFD: 25/07/2017 - [] D -- C:\Users\VULCAN\AppData\Local\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 23/10/2016 - [] D -- C:\Users\VULCAN\AppData\Local\Origin =>.Electronic Arts, Inc.
O43 - CFD: 23/12/2017 - [] D -- C:\Users\VULCAN\AppData\Local\Packages =>.Microsoft Corporation
O43 - CFD: 11/10/2016 - [0] D -- C:\Users\VULCAN\AppData\Local\PeerDistRepub =>.Microsoft Corporation
O43 - CFD: 23/12/2017 - [0] D -- C:\Users\VULCAN\AppData\Local\PlaceholderTileLogoFolder
O43 - CFD: 05/10/2017 - [] D -- C:\Users\VULCAN\AppData\Local\Privax Ltd =>.Privax Ltd
O43 - CFD: 09/12/2017 - [] D -- C:\Users\VULCAN\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 26/01/2016 - [] D -- C:\Users\VULCAN\AppData\Local\Publishers =>.Microsoft Corporation
O43 - CFD: 14/01/2017 - [] D -- C:\Users\VULCAN\AppData\Local\RecomTips
O43 - CFD: 31/07/2017 - [] D -- C:\Users\VULCAN\AppData\Local\Recovery =>.Recovery Labs
O43 - CFD: 15/09/2017 - [] D -- C:\Users\VULCAN\AppData\Local\redout
O43 - CFD: 12/10/2016 - [] D -- C:\Users\VULCAN\AppData\Local\Rockstar Games =>.Rockstar Games
O43 - CFD: 31/03/2017 - [] D -- C:\Users\VULCAN\AppData\Local\Shareaza =>.Shareaza (P2P)
O43 - CFD: 01/05/2017 - [] D -- C:\Users\VULCAN\AppData\Local\Skyrim Special Edition =>.Nogenious Skyrim Game
O43 - CFD: 18/10/2016 - [] D -- C:\Users\VULCAN\AppData\Local\speech =>.Microsoft Corporation
O43 - CFD: 06/10/2017 - [] D -- C:\Users\VULCAN\AppData\Local\speed
O43 - CFD: 13/12/2016 - [] D -- C:\Users\VULCAN\AppData\Local\Steam =>.Steam Games
O43 - CFD: 01/01/2018 - [] D -- C:\Users\VULCAN\AppData\Local\StreetFighterV =>.StreetFighter Games
O43 - CFD: 17/10/2017 - [] D -- C:\Users\VULCAN\AppData\Local\TangoGameworks
O43 - CFD: 09/03/2018 - [] D -- C:\Users\VULCAN\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [0] SHD -- C:\Users\VULCAN\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 02/10/2017 - [] D -- C:\Users\VULCAN\AppData\Local\Tencent =>.SUP.Tencent
O43 - CFD: 17/11/2017 - [] D -- C:\Users\VULCAN\AppData\Local\The Witcher =>.Atari Inc
O43 - CFD: 04/11/2017 - [] D -- C:\Users\VULCAN\AppData\Local\TileDataLayer =>.Microsoft Corporation
O43 - CFD: 03/09/2017 - [] D -- C:\Users\VULCAN\AppData\Local\TombRaiderDOX
O43 - CFD: 30/12/2017 - [] D -- C:\Users\VULCAN\AppData\Local\Ubisoft Game Launcher =>.Ubisoft
O43 - CFD: 15/04/2017 - [] D -- C:\Users\VULCAN\AppData\Local\UNP =>.Microsoft Corporation
O43 - CFD: 27/01/2018 - [] D -- C:\Users\VULCAN\AppData\Local\UnrealEngine =>.Unreal Software
O43 - CFD: 11/11/2017 - [] D -- C:\Users\VULCAN\AppData\Local\UnrealEngineLauncher =>.Unreal Software
O43 - CFD: 27/01/2018 - [] D -- C:\Users\VULCAN\AppData\Local\User Data
O43 - CFD: 04/03/2017 - [] D -- C:\Users\VULCAN\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 09/02/2017 - [] D -- C:\Users\VULCAN\AppData\Local\yxh
O43 - CFD: 09/03/2018 - [] D -- C:\Users\VULCAN\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 09/12/2017 - [] D -- C:\Users\VULCAN\AppData\Local\Programs\Badoo =>.Badoo
O43 - CFD: 26/01/2016 - [0] D -- C:\Users\VULCAN\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 12/10/2016 - [] D -- C:\Users\VULCAN\AppData\LocalLow\360WD
O43 - CFD: 14/10/2016 - [] D -- C:\Users\VULCAN\AppData\LocalLow\AMPLITUDE Studios =>.Amplitude Studios
O43 - CFD: 17/10/2016 - [] D -- C:\Users\VULCAN\AppData\LocalLow\Audiosurf, LLC
O43 - CFD: 29/04/2017 - [] D -- C:\Users\VULCAN\AppData\LocalLow\Berserk Games
O43 - CFD: 22/10/2016 - [] D -- C:\Users\VULCAN\AppData\LocalLow\Blizzard Entertainment =>.Blizzard Entertainment
O43 - CFD: 16/02/2017 - [] D -- C:\Users\VULCAN\AppData\LocalLow\CDProjektRED
O43 - CFD: 12/08/2017 - [] D -- C:\Users\VULCAN\AppData\LocalLow\Chubby Pixel
O43 - CFD: 22/10/2016 - [] SD -- C:\Users\VULCAN\AppData\LocalLow\Microsoft =>.Microsoft Corporation
O43 - CFD: 09/03/2018 - [] D -- C:\Users\VULCAN\AppData\LocalLow\Mozilla =>.Mozilla Corporation
O43 - CFD: 10/08/2017 - [0] D -- C:\Users\VULCAN\AppData\LocalLow\MSLiveSticker
O43 - CFD: 10/08/2017 - [0] D -- C:\Users\VULCAN\AppData\LocalLow\MSLiveStickerWhiteList
O43 - CFD: 11/10/2016 - [] D -- C:\Users\VULCAN\AppData\LocalLow\Pusher
O43 - CFD: 25/07/2017 - [0] D -- C:\Users\VULCAN\AppData\LocalLow\QQMiniDL
O43 - CFD: 27/01/2017 - [] D -- C:\Users\VULCAN\AppData\LocalLow\RedCandleGames
O43 - CFD: 28/09/2017 - [] D -- C:\Users\VULCAN\AppData\LocalLow\SogouPY =>.SUP.Sogou
O43 - CFD: 26/08/2017 - [] D -- C:\Users\VULCAN\AppData\LocalLow\SogouPY.users =>.SUP.Sogou
O43 - CFD: 26/08/2017 - [] D -- C:\Users\VULCAN\AppData\LocalLow\Team 17 Digital ltd_
O43 - CFD: 26/01/2016 - [] D -- C:\Users\VULCAN\AppData\LocalLow\Temp =>.Microsoft Corporation
O43 - CFD: 02/10/2017 - [] D -- C:\Users\VULCAN\AppData\LocalLow\TENCENT =>.SUP.Tencent
O43 - CFD: 12/11/2016 - [] D -- C:\Users\VULCAN\AppData\LocalLow\TheGameBakers
O43 - CFD: 07/12/2017 - [] D -- C:\Users\VULCAN\AppData\LocalLow\Thunder Network =>.Thunder Network
O43 - CFD: 06/03/2018 - [] D -- C:\Users\VULCAN\Desktop\cemu_1.9.0
O43 - CFD: 09/03/2018 - [] D -- C:\Users\VULCAN\Desktop\Cleaner
O43 - CFD: 17/08/2017 - [] D -- C:\Users\VULCAN\Desktop\CPUCores18
O43 - CFD: 09/09/2017 - [] D -- C:\Users\VULCAN\Desktop\Dolphin-x64
O43 - CFD: 23/12/2017 - [] D -- C:\Users\VULCAN\Desktop\nightly
O43 - CFD: 01/03/2017 - [] D -- C:\Users\VULCAN\Desktop\nullDC 1.04 r150 SM-A Fixes by masterchan777
O43 - CFD: 24/12/2016 - [] D -- C:\Users\VULCAN\Desktop\Nvidia Inspector
O43 - CFD: 07/01/2018 - [] D -- C:\Users\VULCAN\Desktop\RPCS3
O43 - CFD: 06/03/2018 - [] D -- C:\Users\VULCAN\Desktop\Thimbleweed Park
O43 - CFD: 09/03/2018 - [] D -- C:\Users\VULCAN\Desktop\新建文件夹
O43 - CFD: 04/11/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\37游戏中心
O43 - CFD: 29/09/2017 - [] RD -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] RD -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 15/02/2018 - [] RD -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 04/11/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Frets on Fire
O43 - CFD: 29/09/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ModManager
O43 - CFD: 22/04/2017 - [0] D -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
O43 - CFD: 04/11/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan =>.Almico Software
O43 - CFD: 15/02/2018 - [] RD -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 08/03/2018 - [] D -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam =>.Steam Games
O43 - CFD: 29/09/2017 - [] RD -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft =>.Ubisoft
O43 - CFD: 04/11/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker =>.Cedrick Collomb
O43 - CFD: 29/09/2017 - [] RD -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\乐游游戏盒
O43 - CFD: 04/11/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\百度网盘
O43 - CFD: 04/11/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\精品游戏
O43 - CFD: 04/11/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
O43 - CFD: 04/11/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\自由战士
O43 - CFD: 23/11/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\迅雷软件
O43 - CFD: 04/11/2017 - [] D -- C:\Users\VULCAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\酷我游戏
O43 - CFD: 04/11/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 29/09/2017 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [0] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\PeerDistRepub =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\ExpressVPN =>.ExpressVPN
O43 - CFD: 14/11/2017 - [] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 24/12/2017 - [] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Tencent =>.SUP.Tencent
O43 - CFD: 09/03/2018 - [] D -- C:\Program Files (x86)\KMSPico 10.2.1 Final =>HackTool.KMSpico

---\\ Latest files created in Prefetcher (8) - 11s
O45 - LFCP:[MD5.009F874A5F779AE0001349A52C336E5B] 06/03/2018 A -- C:\WINDOWS\Prefetch\KMSPICO 10.2.2.EXE-12A9AAF8.pf =>HackTool.KMSpico
O45 - LFCP:[MD5.D9665F957DDBF82C0706B65E0200211A] 06/03/2018 A -- C:\WINDOWS\Prefetch\KMSPICOACTIVATOR.EXE-76DF8139.pf =>HackTool.KMSpico
O45 - LFCP:[MD5.E3BDD269BAD8C47EE6C2C2D1489F4330] 06/03/2018 A -- C:\WINDOWS\Prefetch\KMSPICO_SETUP.TMP-289DE684.pf =>HackTool.KMSpico
O45 - LFCP:[MD5.9C747C4223CB39E0F64D82E8075F38C3] 06/03/2018 A -- C:\WINDOWS\Prefetch\KMSPICO_SETUP.TMP-471063F7.pf =>HackTool.KMSpico
O45 - LFCP:[MD5.D292B1E13534AFFFBED1F41AD59003FC] 06/03/2018 A -- C:\WINDOWS\Prefetch\KMSPICO_SETUP.TMP-97F30802.pf =>HackTool.KMSpico
O45 - LFCP:[MD5.61CE20D4379C8BC34A7863F325EE6140] 06/03/2018 A -- C:\WINDOWS\Prefetch\KMSPICO_SETUP.TMP-C0D38EA5.pf =>HackTool.KMSpico
O45 - LFCP:[MD5.96736502CB6F23B5259A52E2CB510C2F] 06/03/2018 A -- C:\WINDOWS\Prefetch\KMSPICO_SETUP.TMP-DCC09203.pf =>HackTool.KMSpico
O45 - LFCP:[MD5.57B6E61244BFECC5844535EA3AC57EF8] 06/03/2018 A -- C:\WINDOWS\Prefetch\KMSPICO_SETUP.TMP-F35BC511.pf =>HackTool.KMSpico

---\\ ShellIconOverlayIdentifiers (SIOI) (4) - 0s
O106 - SIOI: [.Akhedge2574] - {3a223202-ac02-48e2-a7dd-d2a05708f27f}. (. - ShellExt.) -- C:\Users\VULCAN\AppData\Roaming\khedge2574\khedge2574.dll {50DA1504909F7273486D47AC0AB74675}
O106 - SIOI: CShellExt Class [.RBCShellExternal] - {30C5E658-70B6-4570-A780-D362A5BE2049}. (.Shenzhen Video Legend Network Technology Co.,Ltd. - RBCShellExternal Module.) -- C:\Users\Public\Video Legend\RBC\Addins\RBCShellExternal64.dll {2F45428F979B6FA35CF436C537FDC3C3}
O106 - SIOI: [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - Windows 增强的存储外壳扩展 DLL.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O106 - SIOI: [Offline Files] - {4E77131D-3629-431c-9818-C5679DC83E81}. (.Microsoft Corporation - 客户端缓存 UI.) -- C:\WINDOWS\System32\cscui.dll =>.Microsoft Corporation

---\\ Image File Execution Options (18) - 0s
O50 - IFEO:C:\Windows\System32\cscript.exe - (.Microsoft Corporation - Microsoft ® Console Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\dllhost.exe - (.Microsoft Corporation - COM Surrogate.) [DisableExceptionChainValidation\\3] =>.Microsoft Windows?
O50 - IFEO:C:\WINDOWS\System32\drvinst.exe - (.Microsoft Corporation - 驱动程序安装模块.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\ie4uinit.exe - (.Microsoft Corporation - IE 每用户初始化工具.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - IE 7.0 无人参与安装工具.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mmc.exe - (.Microsoft Corporation - Microsoft 管理控制台.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\MRT.exe - (.Microsoft Corporation - Microsoft Windows 恶意软件删除工具.) [CFGOptions\\1] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Microsoft (R) HTML 应用程序主机.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Windows Presentation Foundation 主机.) [MitigationOptions\\1118481] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\PrintIsolationHost.exe - (.Microsoft Corporation - PrintIsolationHost.) [MitigationOptions\\2097152] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\rundll32.exe - (.Microsoft Corporation - Windows 主进程 (Rundll32).) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\\4294967296] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\searchprotocolhost.exe - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - 后台处理程序子系统应用.) [MitigationOptions\\2097152] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Windows 服务主进程.) [MinimumStackCommitInBytes\\32768] =>.Microsoft Windows Publisher?
O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Windows 服务主进程.) [MitigationAuditOptions\\17660905521152] =>.Microsoft Windows Publisher?
O50 - IFEO:C:\Windows\System32\wscript.exe - (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation

---\\ System Drivers List (79) - 5s
O58 - SDL:2015/10/16 15:35:10 A . (.360.cn - 360Box64.) -- C:\WINDOWS\System32\drivers\360Box64.sys [321616] =>.Qihoo 360 Software (Beijing) Company Limited?
O58 - SDL:2014/12/24 19:18:16 A . (.360.cn - 360流量监控模块.) -- C:\WINDOWS\System32\drivers\360netmon.sys [72776] =>.Qihoo 360 Software (Beijing) Company Limited?
O58 - SDL:2017/09/29 21:41:02 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107416] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135512] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [83352] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [258592] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [27032] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [131992] =>.Microsoft Windows?
O58 - SDL:2015/12/01 19:05:18 A . (.360.cn - BAPIDRV.) -- C:\WINDOWS\System32\drivers\BAPIDRV64.SYS [181328] =>.Qihoo 360 Software (Beijing) Company Limited?
O58 - SDL:2017/02/04 18:38:36 A . (.百度在线网络技术(北京)有限公司 - .) -- C:\WINDOWS\System32\drivers\bbnetdriver.sys [126056] =>.Baidu (China) Co., Ltd.?
O58 - SDL:2017/09/29 21:41:02 A . (. - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [9728] =>.Broadcom Corporation
O58 - SDL:2017/09/29 21:41:01 A . (.QLogic Corporation - QLogic Gigabit Ethernet VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [533912] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.Chelsio Communications - Chelsio iSCSI Crash Dump Driver.) -- C:\WINDOWS\System32\drivers\cht4dx64.sys [141208] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.Chelsio Communications - Chelsio iSCSI VMiniport Driver.) -- C:\WINDOWS\System32\drivers\cht4sx64.sys [357272] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.Chelsio Communications - Virtual Bus Driver for Chelsio ® T5/T6 Chip.) -- C:\WINDOWS\System32\drivers\cht4vx64.sys [1723288] =>.Microsoft Windows?
O58 - SDL:2017/09/23 11:37:57 A . (.作者 - .) -- C:\WINDOWS\System32\drivers\EasyAntiCheat.sys [780328] =>.EasyAntiCheat Oy?
O58 - SDL:2017/09/29 21:41:01 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3419032] =>.Microsoft Windows?
O58 - SDL:2017/08/09 21:27:09 A . (.Malwarebytes - Malwarebytes Anti-Ransomware Protection.) -- C:\WINDOWS\System32\drivers\farflt.sys [113592] =>.Malwarebytes Corporation?
O58 - SDL:2017/09/29 21:41:02 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [63520] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:40:59 A . (.Intel(R) Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iagpio.sys [36864] =>.Intel(R) Corporation
O58 - SDL:2017/09/29 21:40:59 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) -- C:\WINDOWS\System32\drivers\iai2c.sys [91648] =>.Intel(R) Corporation
O58 - SDL:2017/09/29 21:40:59 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [79360] =>.Intel Corporation
O58 - SDL:2017/09/29 21:40:59 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [88576] =>.Intel Corporation
O58 - SDL:2017/09/29 21:40:59 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [171520] =>.Intel Corporation
O58 - SDL:2017/09/29 21:40:59 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [174592] =>.Intel Corporation
O58 - SDL:2017/09/29 21:41:01 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] =>.Intel Corporation - Client Components Group?
O58 - SDL:2017/09/29 21:40:59 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [113152] =>.Intel Corporation
O58 - SDL:2017/09/29 21:41:03 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [674200] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:03 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412056] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [526232] =>.Microsoft Windows?
O58 - SDL:2017/01/13 21:12:04 A . (.Intel Corporation - Intel(R) Wireless Bluetooth(R) Filter Drive.) -- C:\WINDOWS\System32\drivers\ibtusb.sys [253696] =>.Intel Corporation-Wireless Connectivity Solutions?
O58 - SDL:2016/11/20 18:05:32 A . (.Highresolution Enterprises [www.highrez.co.uk] - Kernel level port access driver.) -- C:\WINDOWS\System32\drivers\inpoutx64.sys [15008] =>.Red Fox UK Limited?
O58 - SDL:2017/09/14 14:49:58 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\WINDOWS\System32\drivers\IntcDAud.sys [831008] =>.Intel(R) OWR?
O58 - SDL:2015/12/08 01:53:18 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\intelaud.sys [51704] =>.Intel(R) Wireless Display?
O58 - SDL:2015/12/08 01:53:18 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\iwdbus.sys [39920] =>.Intel(R) Wireless Display?
O58 - SDL:2017/09/29 21:41:02 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [108064] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [123800] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [103320] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82840] =>.Microsoft Windows?
O58 - SDL:2017/05/31 11:09:14 A . (.作者 - .) -- C:\WINDOWS\System32\drivers\mbae64.sys [77376] =>.Malwarebytes Corporation?
O58 - SDL:2017/08/09 21:27:05 A . (.Malwarebytes - Malwarebytes Real-Time Protection.) -- C:\WINDOWS\System32\drivers\mbam.sys [44960] =>.Malwarebytes Corporation?
O58 - SDL:2017/08/09 21:27:17 A . (.Malwarebytes - Malwarebytes Chameleon.) -- C:\WINDOWS\System32\drivers\MBAMChameleon.sys [188312] =>.Malwarebytes Corporation?
O58 - SDL:2017/08/09 22:43:41 A . (.Malwarebytes - Malwarebytes SwissArmy.) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [252832] =>.Malwarebytes Corporation?
O58 - SDL:2017/09/29 21:41:02 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59800] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\MegaSas2i.sys [63520] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575896] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [842648] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63896] =>.Microsoft Windows?
O58 - SDL:2017/08/09 21:27:09 A . (.Malwarebytes - Malwarebytes Web Protection.) -- C:\WINDOWS\System32\drivers\mwac.sys [93600] =>.Malwarebytes Corporation?
O58 - SDL:2017/09/29 21:41:02 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [108952] =>.Microsoft Windows?
O58 - SDL:2017/04/13 14:10:36 A . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\WINDOWS\System32\drivers\Netwtw02.sys [6730496] =>.Intel Corporation-Wireless Connectivity Solutions?
O58 - SDL:2017/09/29 21:41:02 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150424] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [166296] =>.Microsoft Windows?
O58 - SDL:2017/12/15 10:03:48 A . (.NVIDIA Corporation - NVIDIA Virtual Audio Driver.) -- C:\WINDOWS\System32\drivers\nvvad64v.sys [59240] =>.NVIDIA Corporation?
O58 - SDL:2018/01/24 08:23:45 A . (.NVIDIA Corporation - Virtual USB Host Controller driver.) -- C:\WINDOWS\System32\drivers\nvvhci.sys [57928] =>.NVIDIA Corporation?
O58 - SDL:2016/11/24 08:14:56 A . (.作者 - SysEnter Application.) -- C:\WINDOWS\System32\drivers\PassGuard_x64.sys [111416] {070FB88B3264E843F8FC566D6768AED3}
O58 - SDL:2017/09/29 21:41:02 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [58776] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [61848] =>.Microsoft Windows?
O58 - SDL:2016/01/20 17:28:32 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.40 64-bit Dr.) -- C:\WINDOWS\System32\drivers\rt640x64.sys [887552] =>.Realtek Semiconductor Corp?
O58 - SDL:2017/09/29 21:41:14 RA . (.Realtek - Realtek PCIe GBE Family Controller Flight.) -- C:\WINDOWS\System32\drivers\rteth.sys [59904] =>.Realtek
O58 - SDL:2015/10/30 10:16:02 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\WINDOWS\System32\drivers\RTKVHD64.sys [4644096] =>.Realtek Semiconductor Corp?
O58 - SDL:2017/09/29 21:41:02 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44952] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81816] =>.Microsoft Windows?
O58 - SDL:2015/12/03 22:00:16 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\WINDOWS\System32\drivers\Smb_driver_AMDASF_Aux.sys [58984] =>.Synaptics Incorporated?
O58 - SDL:2015/12/03 22:00:18 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [62568] =>.Synaptics Incorporated?
O58 - SDL:2015/12/03 22:00:18 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\WINDOWS\System32\drivers\Smb_driver_Intel_Aux.sys [62568] =>.Synaptics Incorporated?
O58 - SDL:2017/09/29 21:41:02 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31128] =>.Microsoft Windows?
O58 - SDL:2015/12/03 22:00:10 A . (.Synaptics Incorporated - Synaptics Touchpad Win64 Driver.) -- C:\WINDOWS\System32\drivers\SynTP.sys [853608] =>.Synaptics Incorporated?
O58 - SDL:2016/07/07 16:23:14 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\WINDOWS\System32\drivers\tap0901.sys [27136] =>.The OpenVPN Project
O58 - SDL:2017/11/21 15:48:30 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\WINDOWS\System32\drivers\tapexpressvpn.sys [45024] =>.ExprsVPN LLC?
O58 - SDL:2015/10/08 21:16:00 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys [185600] =>.Intel Corporation - Embedded Subsystems and IP Blocks Group?
O58 - SDL:2017/09/29 21:41:02 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166808] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305560] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [32152] =>.Microsoft Windows?
O58 - SDL:2017/09/29 21:41:02 A . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [64920] =>.Microsoft Windows?
O58 - SDL:2017/11/29 17:12:52 A . (.深圳市迅雷网络技术有限公司 - XLGuard.sys.) -- C:\WINDOWS\System32\drivers\XLGuard.sys [36112] =>.ShenZhen Thunder Networking Technologies Ltd.?
O58 - SDL:2016/03/29 17:00:16 A . (.深圳市迅雷网络技术有限公司 - xlwfp.sys.) -- C:\WINDOWS\System32\drivers\XLWFP.sys [59664] =>.ShenZhen Thunder Networking Technologies Ltd.?
O58 - SDL:2016/01/20 12:07:38 A . (...) -- C:\WINDOWS\System32\epmntdrv.sys [18016] =>.Microsoft Corporation
O58 - SDL:2016/01/20 12:07:38 A . (...) -- C:\WINDOWS\System32\EuGdiDrv.sys [10848] =>.Intel Corporation

---\\ Last modified or created user files (3) - 14s
O61 - LFC: 2018/03/08 20:15:41 A . (..) -- C:\Users\VULCAN\AppData\Local\NVIDIA\NvBackend\StreamingAssetsData\grand_theft_auto_v\21729386\automated_launch.exe [48128] =>.NVIDIA Corporation
O61 - LFC: 2018/03/09 07:55:42 A . (.EpicNet Inc..) -- C:\Users\VULCAN\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe [680960] =>Adware.MSIL
O61 - LFC: 2018/03/06 20:29:07 A . (.@ByELDI.) -- C:\Users\VULCAN\Desktop\新建文件夹\KMSpico_setup.exe [3866984] =>HackTool.KMSpico

---\\ File Associations Shell Spawning (10) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - 事件查看器管理单元启动程序.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (...) -- C:\Windows\System32\WScript.exe "%1" %* =>.Default.Value
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - 注册表编辑器.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S =>.Default.Value
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation?

---\\ Start Menu Internet (16) - 1s
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation?
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc?
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation?
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (...) -- C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe (.not file.) =>.SUP.UCBrowser
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE 每用户初始化工具.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe (.not file.)
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE 每用户初始化工具.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe (.not file.)
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE 每用户初始化工具.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe (.not file.)

---\\ Search Browser Infection (4) - 8s
O69 - SBI: SearchScopes [HKCU] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKCU] [64Bits]{64AF4D11-6492-4C25-B014-B6C6CEE3B0C5} [DefaultScope] - (百度) - http://www.baidu.com/
O69 - SBI: SearchScopes [HKCU] [64Bits]{B8E20CD7-BAC2-4820-9AA6-1060B3AF25E2} - (百度一下,你就知道) - http://www.baidu.com/
O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com

---\\ Search Svchost Services (48) - 0s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft 智能卡证书传播服务.) -- C:\WINDOWS\System32\certprop.dll [188928] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft 智能卡证书传播服务.) -- C:\Windows\System32\certprop.dll [188928] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - 服务器服务 DLL.) -- C:\Windows\System32\srvsvc.dll [270848] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - 组策略客户端.) -- C:\Windows\System32\gpsvc.dll [1275904] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE 扩展.) -- C:\Windows\System32\IKEEXT.DLL [984064] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - 通过 IPv4 网络提供 IPv6 连接的服务。.) -- C:\Windows\System32\iphlpsvc.dll [820224] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - 辅助登录服务 DLL.) -- C:\Windows\System32\seclogon.dll [30720] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - 应用程序信息服务.) -- C:\Windows\System32\appinfo.dll [144896] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI 发现服务.) -- C:\Windows\System32\iscsiexe.dll [150528] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost 服务.) -- C:\Windows\System32\eapsvc.dll [109056] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - 任务计划程序服务.) -- C:\Windows\System32\schedsvc.dll [880640] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [220160] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [407040] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - 远程桌面配置服务.) -- C:\Windows\System32\SessEnv.dll [387584] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - 问题报告和解决方案.) -- C:\Windows\System32\wercplsupport.dll [108544] =>.Microsoft Corporation
O83 - Search Svchost Services: PushToInstall (PushToInstall) . (.Microsoft Corporation - PushToInstall.) -- C:\Windows\System32\PushToInstall.dll [254976] =>.Microsoft Corporation
O83 - Search Svchost Services: shpamsvc (shpamsvc) . (.Microsoft Corporation - SharedPC.AccountManager.) -- C:\Windows\System32\Windows.SharedPC.AccountManager.dll [194560] =>.Microsoft Corporation
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\Windows\System32\XblGameSave.dll [1272320] =>.Microsoft Corporation
O83 - Search Svchost Services: NaturalAuthentication (NaturalAuthentication) . (.Microsoft Corporation - 自然身份验证服务.) -- C:\Windows\System32\NaturalAuth.dll [795136] =>.Microsoft Corporation
O83 - Search Svchost Services: TokenBroker (TokenBroker) . (.Microsoft Corporation - 令牌代理.) -- C:\Windows\System32\TokenBroker.dll [1228800] =>.Microsoft Corporation
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - 地理定位服务.) -- C:\Windows\System32\lfsvc.dll [46080] =>.Microsoft Corporation
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\Windows\System32\XblAuthManager.dll [1107968] =>.Microsoft Corporation
O83 - Search Svchost Services: Irmon (Irmon) . (.Microsoft Corporation - 红外监视程序.) -- C:\Windows\System32\irmon.dll [24576] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - 远程访问自动拨号管理器.) -- C:\Windows\System32\rasauto.dll [104960] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - 远程访问连接管理器.) -- C:\Windows\System32\rasmans.dll [930816] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - 动态接口管理器.) -- C:\Windows\System32\mprdim.dll [491520] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - 系统事件通知服务(SENS).) -- C:\Windows\System32\Sens.dll [73216] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT 帮助程序组件.) -- C:\Windows\System32\ipnathlp.dll [601088] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft (R) Windows(TM) 电话服务器.) -- C:\Windows\System32\tapisrv.dll [307200] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows 更新代理.) -- C:\Windows\System32\wuaueng.dll [2784256] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - 后台智能传送服务.) -- C:\Windows\System32\qmgr.dll [1345536] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell 服务 Dll.) -- C:\Windows\System32\shsvcs.dll [613376] =>.Microsoft Corporation
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - Windows Managent Service DLL.) -- C:\Windows\System32\Windows.Internal.Management.dll [702464] =>.Microsoft Corporation
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\Windows\System32\dmwappushsvc.dll [57856] =>.Microsoft Corporation
O83 - Search Svchost Services: wisvc (wisvc) . (.Microsoft Corporation - 飞行设置.) -- C:\Windows\System32\flightsettings.dll [779264] =>.Microsoft Corporation
O83 - Search Svchost Services: WpnService (WpnService) . (.Microsoft Corporation - Windows Push Notification System Service.) -- C:\Windows\System32\WpnService.dll [284672] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\Windows\System32\XboxNetApiSvc.dll [1143808] =>.Microsoft Corporation
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - 更新会话 Orchestrator 内核.) -- C:\Windows\System32\usocore.dll [1294848] =>.Microsoft Corporation
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\Windows\System32\usermgr.dll [951808] =>.Microsoft Corporation
O83 - Search Svchost Services: InstallService (InstallService) . (.Microsoft Corporation - InstallService.) -- C:\Windows\System32\InstallService.dll [1313792] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell 主题服务 Dll.) -- C:\Windows\System32\themeservice.dll [69632] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE 服务.) -- C:\Windows\System32\bdesvc.dll [387072] =>.Microsoft Corporation
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - 设备安装管理器.) -- C:\Windows\System32\DeviceSetupManager.dll [238080] =>.Microsoft Corporation
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - 网络安装服务.) -- C:\Windows\System32\NetSetupSvc.dll [308224] =>.Microsoft Corporation
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Microsoft 网络连接助手服务.) -- C:\Windows\System32\NcaSvc.dll [170496] =>.Microsoft Corporation
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Microsoft® 帐户服务.) -- C:\Windows\System32\wlidsvc.dll [2223104] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxGipSvc (XboxGipSvc) . (.Microsoft Corporation - Xbox Gip Management Service.) -- C:\Windows\System32\XboxGipSvc.dll [57856] =>.Microsoft Corporation
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - 软件安装服务.) -- C:\Windows\System32\appmgmts.dll [196096] =>.Microsoft Corporation

---\\ Firewall Active Exception List (106) - 6s
O87 - FAEL: "{9A4829DB-BBB7-4195-BC87-7D1F575868AB}" [In-None-P17-TRUE] .(.Copyright 2010 - 迅雷错误报告.) -- C:\Users\Public\Video Legend\RBC\Program\XLBugReport.exe {40905279E0052E27924A79BD23C00E50}
O87 - FAEL: "{E841C255-18DD-49ED-8794-51F6C1CBC975}" [In-None-P17-TRUE] .(.Copyright 2010 - 迅雷错误报告.) -- C:\Program Files (x86)\Video Legend\KKP\Program\XLBugReport.exe {40905279E0052E27924A79BD23C00E50}
O87 - FAEL: "{9D1404E5-4FC8-4C08-A0FB-5A39A0E899DB}" [In-None-P17-TRUE] .(.Shenzhen Video Legend Network Technology Co.,Ltd. - 看看影音 应用程序.) -- C:\Program Files (x86)\Video Legend\KKP\Program\KKP.exe {2F45428F979B6FA35CF436C537FDC3C3}
O87 - FAEL: "{E3C9DD8D-8E6B-4BB3-9286-538FF26E1E9D}" [In-None-P6-TRUE] .(.Copyright 2010 - 迅雷错误报告.) -- C:\Users\Public\Video Legend\RBC\Program\XLBugReport.exe {40905279E0052E27924A79BD23C00E50}
O87 - FAEL: "{ABEAA19A-76CE-40C0-8668-E38E946E7518}" [In-None-P6-TRUE] .(.Copyright 2010 - 迅雷错误报告.) -- C:\Program Files (x86)\Video Legend\KKP\Program\XLBugReport.exe {40905279E0052E27924A79BD23C00E50}
O87 - FAEL: "{38AEFD8D-D7DA-4976-8909-EC9B0D3683B6}" [In-None-P6-TRUE] .(.Shenzhen Video Legend Network Technology Co.,Ltd. - 看看影音 应用程序.) -- C:\Program Files (x86)\Video Legend\KKP\Program\KKP.exe {2F45428F979B6FA35CF436C537FDC3C3}
O87 - FAEL: "{B9A7AB21-9B0B-447F-8CED-F41543EFEEAE}" [In-None-P17-TRUE] .(.Shenzhen Video Legend Network Technology Co.,Ltd. - KKPSAP Application.) -- C:\Users\Public\Video Legend\RBC\Program\KKPSAP.exe {2F45428F979B6FA35CF436C537FDC3C3}
O87 - FAEL: "{CC48665E-DDE3-4F99-AEC3-DD317BF51210}" [In-None-P17-TRUE] .(.Shenzhen Video Legend Network Technology Co.,Ltd. - KKTIP Application.) -- C:\Users\Public\Video Legend\RBC\Program\KKTip.exe {2F45428F979B6FA35CF436C537FDC3C3}
O87 - FAEL: "{EFD887C4-B8DC-47A8-A34A-91F60A72A3A7}" [In-None-P6-TRUE] .(.Shenzhen Video Legend Network Technology Co.,Ltd. - KKPSAP Application.) -- C:\Users\Public\Video Legend\RBC\Program\KKPSAP.exe {2F45428F979B6FA35CF436C537FDC3C3}
O87 - FAEL: "{E5C654F4-855A-4C8A-A532-8F48D758AC55}" [In-None-P6-TRUE] .(.Shenzhen Video Legend Network Technology Co.,Ltd. - KKTIP Application.) -- C:\Users\Public\Video Legend\RBC\Program\KKTip.exe {2F45428F979B6FA35CF436C537FDC3C3}
O87 - FAEL: "{17EE87C8-176D-4D24-9B42-55DF5D1200D2}" [In-None-P17-TRUE] .(...) -- G:\SteamLibrary\steamapps\common\The Binding of Isaac Rebirth\isaac-ng.exe =>.Steam Games
O87 - FAEL: "{DC81B763-D7B6-4186-8BC5-E54C287354A4}" [In-None-P6-TRUE] .(...) -- G:\SteamLibrary\steamapps\common\The Binding of Isaac Rebirth\isaac-ng.exe =>.Steam Games
O87 - FAEL: "{0F40BF0C-A7AA-42FA-A096-A76F345120D2}" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\common files\tencent\qqdownload\135\bugreport_xf.exe (.not file.) =>.SUP.Tencent
O87 - FAEL: "{019D1C83-7447-4E86-B3BF-9DA52A3961B3}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Documents\Tencent\QQGameMicro\IEProc.exe (.not file.) =>.SUP.Tencent
O87 - FAEL: "{63E47B7F-72E4-4196-9AC9-D8583D558486}" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\common files\tencent\qqdownload\135\bugreport_xf.exe (.not file.) =>.SUP.Tencent
O87 - FAEL: "{4BB93B9C-5301-4EEA-96CB-A4675C519B8C}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Tencent\QQ\Bin\SetupEx\SetupEx.exe (.not file.) =>.SUP.Tencent
O87 - FAEL: "{84B000C1-0E02-4433-AF1B-D633FCD4DD7D}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Tencent\QQ\Bin\txupd.exe (.not file.) =>.SUP.Tencent
O87 - FAEL: "{E203C380-560B-4CF5-B011-F08582BF9FF9}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Tencent\QQ\Bin\QQ.exe (.not file.) =>.SUP.Tencent
O87 - FAEL: "UDP Query User{3CB9BFCF-05B1-4B92-A015-2DF2F9DF612E}C:\program files (x86)\thunder network\thunder9\program\xlplayer\xlplayer.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\thunder network\thunder9\program\xlplayer\xlplayer.exe (.not file.)
O87 - FAEL: "TCP Query User{877FB050-38EA-448D-9C61-D8BEDBF08B0C}C:\program files (x86)\thunder network\thunder9\program\xlplayer\xlplayer.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\thunder network\thunder9\program\xlplayer\xlplayer.exe (.not file.)
O87 - FAEL: "{ABF12248-1833-4D80-ADB2-480AB386A44A}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\Pusher\Pusher\TP\DownloadSDKServer.exe (.not file.)
O87 - FAEL: "{C3018097-2BF4-4BCA-BBE9-E8ACC25B2DA3}" [In-None-P17-TRUE] .(...) -- C:\Users\Public\Thunder Network\Pusher\Pusher\TP\DownloadSDKServer.exe (.not file.)
O87 - FAEL: "{D8797847-52A1-4181-915F-2BD7044ED9EA}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\Pusher\Pusher\TP\DownloadSDKServer.exe (.not file.)
O87 - FAEL: "{2AE7B72E-62D2-4CDF-9E44-512764559292}" [In-None-P17-TRUE] .(...) -- C:\Users\Public\Thunder Network\Pusher\Pusher\XmpTipWnd.1.0.0.99.exe (.not file.)
O87 - FAEL: "{2F0A28D3-D648-4535-80C4-D41897DE3271}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\Pusher\Pusher\XmpTipWnd.1.0.0.99.exe (.not file.)
O87 - FAEL: "{7D0040B4-BF25-4396-8DD5-B0D12F11D26C}" [In-None-P6-TRUE] .(...) -- C:\Users\VULCAN\AppData\Local\Temp\xlliveud\xmp_5.3.1.6065\XLLiveUD.exe (.not file.) =>.Temporary file not necessary
O87 - FAEL: "{69D3118B-7F2D-44CA-B7C5-3F16770DF502}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\DPInst.exe (.not file.)
O87 - FAEL: "{316A452A-A3CF-4B98-960A-EE1983E5738F}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\PreInstall.exe (.not file.)
O87 - FAEL: "{2D838477-477F-4AA0-A728-A5FB55189284}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\InstallDriver.exe (.not file.)
O87 - FAEL: "{862EABFA-FF3E-4C93-956E-06F3D3FBE193}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\DPInstX64.exe (.not file.)
O87 - FAEL: "{7284D3C4-860A-4008-8A7E-06E795C3F5C9}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\adb.exe (.not file.)
O87 - FAEL: "{FF64B096-571A-4263-B3EE-716502C1CAFE}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\aapt.exe (.not file.)
O87 - FAEL: "{BAA5A292-C4B2-49E1-8006-BEC2AD6A86A5}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\XLLiveUD.exe (.not file.)
O87 - FAEL: "{F01CA70F-1F8D-41E3-97F3-3FBD8BAD85D1}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\APlayer.exe (.not file.)
O87 - FAEL: "{24FC8629-AAA4-4DFA-9052-D53118EB328C}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Thunder Network\XMP\V5.3.1.6065\TP\DownloadSDKServer.exe (.not file.)
O87 - FAEL: "{120EE1F7-4415-4F11-B21F-056042596E3B}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Thunder Network\XMP\V5.3.1.6065\Bin\XLBugReport.exe (.not file.)
O87 - FAEL: "{0D8462EB-AD9E-44E3-BE85-5EFB91BEB66A}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Thunder Network\XMP\V5.3.1.6065\Bin\XLLiveUD.exe (.not file.)
O87 - FAEL: "{AEB9F4E2-ACCD-404E-AD1A-5B056F189B45}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Thunder Network\XMP\V5.3.1.6065\Bin\XMP.exe (.not file.)
O87 - FAEL: "{9A4771E6-80AD-4F3D-87FF-10A7D12E4AC6}" [In-None-P17-TRUE] .(...) -- C:\Users\VULCAN\AppData\Local\Temp\xlliveud\xmp_5.3.1.6065\XLLiveUD.exe (.not file.) =>.Temporary file not necessary
O87 - FAEL: "{112F5196-3E73-4436-AEAC-21A6DD2ECFA0}" [In-None-P17-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\DPInst.exe (.not file.)
O87 - FAEL: "{3A432259-DAE1-4E80-8EA0-1A7EB68B503E}" [In-None-P17-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\PreInstall.exe (.not file.)
O87 - FAEL: "{C9B12386-0982-4213-991E-1B6BD152C20A}" [In-None-P17-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\InstallDriver.exe (.not file.)
O87 - FAEL: "{F1D7341F-7330-4B2D-A9C5-1CF15496AF89}" [In-None-P6-TRUE] .(...) -- C:\Users\VULCAN\AppData\Local\Temp\xlliveud\xmp_5.3.1.6065\XLLiveUD.exe (.not file.) =>.Temporary file not necessary
O87 - FAEL: "{8AB9C0CC-CA34-4698-B99B-464985BEFE53}" [In-None-P17-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\DPInstX64.exe (.not file.)
O87 - FAEL: "{2CB1C551-8F19-476C-B357-2CDD0A45E6BF}" [In-None-P17-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\adb.exe (.not file.)
O87 - FAEL: "{78C356EC-81EB-4586-8C80-AA4206C69748}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\DPInst.exe (.not file.)
O87 - FAEL: "{DEFA9F67-18E3-4ED6-9B3A-1D5ED92CB024}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\PreInstall.exe (.not file.)
O87 - FAEL: "{B49FAF15-7F17-4E8F-9C61-243F220AA360}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\InstallDriver.exe (.not file.)
O87 - FAEL: "{66BF7E29-7D3C-4A8D-BFE9-9FD2ADF3B326}" [In-None-P17-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\aapt.exe (.not file.)
O87 - FAEL: "{806CAF16-A232-4588-83FE-07381BE3E0D3}" [In-None-P17-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\XLLiveUD.exe (.not file.)
O87 - FAEL: "{5E7B2420-B93F-47D1-874E-9A5D1DBF78AF}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\DPInstX64.exe (.not file.)
O87 - FAEL: "{09759B71-DB20-4936-BA04-567E677389ED}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\adb.exe (.not file.)
O87 - FAEL: "{4117ADBA-5E03-4B80-81A5-83C8AD76E7FA}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\aapt.exe (.not file.)
O87 - FAEL: "{97F019CF-5165-4B1F-9887-10CAB7EC4CE2}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\XLLiveUD.exe (.not file.)
O87 - FAEL: "{E19FBCD0-A530-4867-A1DE-CC3C9EF60FF4}" [In-None-P17-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\APlayer.exe (.not file.)
O87 - FAEL: "{84FA291E-1EC8-4AD2-AD8A-95072593ED3E}" [In-None-P6-TRUE] .(...) -- C:\Users\Public\Thunder Network\XMP5\V5.3.1.6065\Program\APlayer.exe (.not file.)
O87 - FAEL: "{41DA7103-830B-4A46-99DB-11AE5C8AE211}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Thunder Network\XMP\V5.3.1.6065\TP\DownloadSDKServer.exe (.not file.)
O87 - FAEL: "{1F405D07-EEFC-421F-AE99-FF3EE77822E9}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Thunder Network\XMP\V5.3.1.6065\TP\DownloadSDKServer.exe (.not file.)
O87 - FAEL: "{019628C8-FD02-468B-BCC4-787CE35ED643}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Thunder Network\XMP\V5.3.1.6065\Bin\XLBugReport.exe (.not file.)
O87 - FAEL: "{0851A85D-EFCD-4B88-A112-C0737562D6BF}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Thunder Network\XMP\V5.3.1.6065\Bin\XLBugReport.exe (.not file.)
O87 - FAEL: "{3702EC4B-ABFE-4332-BA94-47E0161C4B0E}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Thunder Network\XMP\V5.3.1.6065\Bin\XLLiveUD.exe (.not file.)
O87 - FAEL: "{254C475D-F80E-450C-A14C-F5C0D3984E5A}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Thunder Network\XMP\V5.3.1.6065\Bin\XLLiveUD.exe (.not file.)
O87 - FAEL: "{AEC239AB-AD99-4FB2-BA98-FEC1E3903966}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Thunder Network\XMP\V5.3.1.6065\Bin\XMP.exe (.not file.)
O87 - FAEL: "{281C084F-4103-4F5C-A3BA-ADF59CED1BB4}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Thunder Network\XMP\V5.3.1.6065\Bin\XMP.exe (.not file.)
O87 - FAEL: "UDP Query User{10BFF505-4809-4760-93A4-157C8BA382A2}C:\program files (x86)\thunder network\thunder9\program\xlplayer\xlplayer.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\thunder network\thunder9\program\xlplayer\xlplayer.exe (.not file.)
O87 - FAEL: "TCP Query User{6F21158B-10B4-46B5-91DD-EB7BA19DB69C}C:\program files (x86)\thunder network\thunder9\program\xlplayer\xlplayer.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\thunder network\thunder9\program\xlplayer\xlplayer.exe (.not file.)
O87 - FAEL: "UDP Query User{71521E53-A5A9-4642-ABED-B1F22E2AA985}C:\users\vulcan\appdata\local\temp\xlliveud\xmp_3.2.14.5710\xlliveud.exe" [In-None-P17-TRUE] .(...) -- C:\users\vulcan\appdata\local\temp\xlliveud\xmp_3.2.14.5710\xlliveud.exe (.not file.) =>.Temporary file not necessary
O87 - FAEL: "TCP Query User{F39917D4-EF18-4BD9-AC22-B6CB3B64C616}C:\users\vulcan\appdata\local\temp\xlliveud\xmp_3.2.14.5710\xlliveud.exe" [In-None-P6-TRUE] .(...) -- C:\users\vulcan\appdata\local\temp\xlliveud\xmp_3.2.14.5710\xlliveud.exe (.not file.) =>.Temporary file not necessary
O87 - FAEL: "UDP Query User{FB581A0B-6723-4B12-8FD4-E94D5F7BCF5D}G:\steamlibrary\steamapps\common\redout demo\redout\binaries\win64\redout-win64-shipping.exe" [In-None-P17-TRUE] .(...) -- G:\steamlibrary\steamapps\common\redout demo\redout\binaries\win64\redout-win64-shipping.exe (.not file.) =>.Steam Games
O87 - FAEL: "TCP Query User{495067AF-62DE-43D4-97B3-79157AED9F2D}G:\steamlibrary\steamapps\common\redout demo\redout\binaries\win64\redout-win64-shipping.exe" [In-None-P6-TRUE] .(...) -- G:\steamlibrary\steamapps\common\redout demo\redout\binaries\win64\redout-win64-shipping.exe (.not file.) =>.Steam Games
O87 - FAEL: "{90A787EA-DB8E-46EA-B19E-05B08A291BB7}" [In-None-P17-TRUE] .(...) -- E:\Program Files (x86)\Hearthstone\Starcraft II\StarCraft II\Versions\Base56787\SC2_x64.exe (.not file.)
O87 - FAEL: "{DACEA424-DB58-47BF-A301-3FDFB4030ACE}" [In-None-P6-TRUE] .(...) -- E:\Program Files (x86)\Hearthstone\Starcraft II\StarCraft II\Versions\Base56787\SC2_x64.exe (.not file.)
O87 - FAEL: "{07254194-BA6D-4557-AFF7-392F7DF56E12}" [In-None-P6-TRUE] .(...) -- G:\steamlibrary\steamapps\common\doom\doomx64vk.exe (.not file.) =>.Steam Games
O87 - FAEL: "{3250D002-7CC2-4519-A4D6-B67ECE1618C8}" [In-None-P17-TRUE] .(...) -- G:\steamlibrary\steamapps\common\doom\doomx64vk.exe (.not file.) =>.Steam Games
O87 - FAEL: "UDP Query User{B084181E-4F19-413F-951C-AE99C6EF4CB6}G:\steamlibrary\steamapps\common\doom\doomx64vk.exe" [In-None-P17-TRUE] .(...) -- G:\steamlibrary\steamapps\common\doom\doomx64vk.exe (.not file.) =>.Steam Games
O87 - FAEL: "TCP Query User{1643E255-0232-4210-A3F0-9E6E31A1E280}G:\steamlibrary\steamapps\common\doom\doomx64vk.exe" [In-None-P6-TRUE] .(...) -- G:\steamlibrary\steamapps\common\doom\doomx64vk.exe (.not file.) =>.Steam Games
O87 - FAEL: "UDP Query User{7B935295-1344-4106-BC7A-6F5A25DF3CC9}G:\yxdown\nexmachinav1.04.0027_chs\nex_machina.exe" [In-None-P17-TRUE] .(...) -- G:\yxdown\nexmachinav1.04.0027_chs\nex_machina.exe
O87 - FAEL: "TCP Query User{55DA0177-C3B1-4171-8FC8-8C3E7DC0EEEF}G:\yxdown\nexmachinav1.04.0027_chs\nex_machina.exe" [In-None-P6-TRUE] .(...) -- G:\yxdown\nexmachinav1.04.0027_chs\nex_machina.exe
O87 - FAEL: "UDP Query User{E1FABC6E-606E-4338-8D50-A4391A39E485}E:\program files (x86)\the escapists 2\theescapists2.exe" [In-None-P17-TRUE] .(...) -- E:\program files (x86)\the escapists 2\theescapists2.exe (.not file.)
O87 - FAEL: "TCP Query User{B505D4D9-0E2D-4A17-9F9B-4FC1512413F2}E:\program files (x86)\the escapists 2\theescapists2.exe" [In-None-P6-TRUE] .(...) -- E:\program files (x86)\the escapists 2\theescapists2.exe (.not file.)
O87 - FAEL: "UDP Query User{58F79E0B-67CD-4C74-99CE-5F40D7D3F67E}E:\program files (x86)\the escapists 2\theescapists2.exe" [In-None-P17-TRUE] .(...) -- E:\program files (x86)\the escapists 2\theescapists2.exe (.not file.)
O87 - FAEL: "TCP Query User{25187E79-4888-41EA-BCBA-977BB90B64E7}E:\program files (x86)\the escapists 2\theescapists2.exe" [In-None-P6-TRUE] .(...) -- E:\program files (x86)\the escapists 2\theescapists2.exe (.not file.)
O87 - FAEL: "{62E99E0B-89F3-48C8-8B6D-BAF58E415DB3}" [In-None-P17-TRUE] .(.Sogou.com Inc. - 搜狗拼音输入法 更新工具.) -- C:\Users\Public\SogouInput\USBDT\OctopusDownloader.exe {7DC702075FCCDB9E63385FF51314C4CE} =>.SUP.Sogou
O87 - FAEL: "{DD7662C8-42DB-4950-BC3B-8FBC6E8E09F8}" [In-None-P6-TRUE] .(.Sogou.com Inc. - 搜狗拼音输入法 更新工具.) -- C:\Users\Public\SogouInput\USBDT\OctopusDownloader.exe {7DC702075FCCDB9E63385FF51314C4CE} =>.SUP.Sogou
O87 - FAEL: "{1E7CDBE6-5B85-4E87-A697-CF943C78586E}" [In-None-P17-TRUE] .(.Sogou.com Inc. - 搜狗拼音输入法 更新工具.) -- C:\Users\Public\SogouInput\USBDT\OctopusDownloader.exe {7DC702075FCCDB9E63385FF51314C4CE} =>.SUP.Sogou
O87 - FAEL: "{C6CA72DF-5481-4AE2-B807-4256EFD77AD3}" [In-None-P6-TRUE] .(.Sogou.com Inc. - 搜狗拼音输入法 更新工具.) -- C:\Users\Public\SogouInput\USBDT\OctopusDownloader.exe {7DC702075FCCDB9E63385FF51314C4CE} =>.SUP.Sogou
O87 - FAEL: "{D2156DD3-B75E-4D51-A713-3F96AAA83F54}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\7.9.0.7504\SGMedalLoader.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{D7248F95-D782-4254-AB9E-CC55F6889DE6}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\7.9.0.7504\SGMedalLoader.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{4435C63E-B4CB-4E8F-BF2E-B99788C6AA8A}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\7.9.0.7504\SGMedalLoader.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{C915011F-864A-4F01-AEDB-534ECF2E4DE9}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\7.9.0.7504\SGMedalLoader.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{FBB1F31B-E52B-44A8-81F3-F88176CD983B}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\7.9.0.7504\userNetSchedule.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{693D73A4-8B51-4474-8D1F-96DBFBAB1C56}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\7.9.0.7504\userNetSchedule.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{1779F3BD-C4DE-48C6-8807-D5B1D5FD9A43}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\7.9.0.7504\userNetSchedule.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{6B0A3D7B-9C50-486E-9A4D-1C92E44CD10B}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\7.9.0.7504\userNetSchedule.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{84417632-EAD1-4197-99CB-E99430545C6C}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\Components\SogouComMgr.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{9DACE02C-D192-48BE-BB5A-A5D690BE48A8}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\Components\SogouComMgr.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{64E5417E-988F-4DD0-BE88-9EB2A9EB4ADA}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\Components\SogouComMgr.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{EE03BE7D-8B1A-48DB-B948-7CDC46C658FF}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\Components\SogouComMgr.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{F09EC6B2-8362-4E38-B1A1-776021C82EF8}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\7.9.0.7504\SogouCloud.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{5669BF73-FD29-41F7-B448-4ADE6C491AAF}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\7.9.0.7504\SogouCloud.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{5CA73B37-09A8-48B0-8E27-1430837F80A4}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\7.9.0.7504\SogouCloud.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{15231BB9-9A9C-43AD-92EE-E11E720E7753}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\7.9.0.7504\SogouCloud.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{FC5B7136-E9D1-41EF-833C-F7868211517F}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\7.9.0.7504\SGDownload.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{EB8D5134-0EE0-44BD-AB8C-3F5204909C84}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\7.9.0.7504\SGDownload.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{59B2D4C1-2E33-4715-9A20-65C716EE4DEF}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\7.9.0.7504\SGDownload.exe (.not file.) =>.SUP.Sogou
O87 - FAEL: "{3E6108EC-2E74-458B-8D1D-64A68CB5B2C3}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\SogouInput\7.9.0.7504\SGDownload.exe (.not file.) =>.SUP.Sogou

---\\ Windows Installer Scan (24) - 2s
[MD5.F20493C25E04BB48A48F59347D384465] [WIS][2016/12/18 12:27:14] (.Adobe - Adobe Photoshop Lightroom 5.) -- C:\WINDOWS\Installer\137aa03e.msi [435645952] =>.Adobe
[MD5.DA99804332889FE38D1AC0A3235A754A] [WIS][2017/11/11 16:17:38] (.Epic Games, Inc. - Epic Games Launcher.) -- C:\WINDOWS\Installer\18fc9f49.msi [32034816] =>.Epic Games, Inc.
[MD5.7873ACD3BFA53B19469E6AB5606C80FE] [WIS][2015/11/19 10:56:58] (.Epic Games, Inc. - Epic Games Launcher Prerequisites (x64).) -- C:\WINDOWS\Installer\18fc9f51.msi [11919360] =>.Epic Games, Inc.
[MD5.3C7ACDF179308E6C15274532073D4753] [WIS][2015/03/26 11:24:58] (.Futuremark - Futuremark SystemInfo.) -- C:\WINDOWS\Installer\1be8bb.msi [2580480] =>.Futuremark
[MD5.42806174A4930A512C9E3A2059A22AB0] [WIS][2017/04/22 12:59:08] (.The Document Foundation - LibreOffice 5.3.) -- C:\WINDOWS\Installer\1f8a529e.msi [244117504] =>.The Document Foundation
[MD5.44CFEBB8D3279F36BC6B60AE1BED5ADE] [WIS][2016/11/13 08:28:00] (.CD Projekt RED - Rise of the White Wolf.) -- C:\WINDOWS\Installer\214e6869.msi [2302976] =>.CD Projekt RED
[MD5.639A0806AE06E8F99F7CA8E671743DEC] [WIS][2017/06/06 22:16:22] (.Intel Corporation - Intel?WiFi.) -- C:\WINDOWS\Installer\216309.msi [32796672] =>.Intel Corporation
[MD5.1995140F35982787628FCC694173F298] [WIS][2017/06/05 21:26:18] (.Intel Corporation - Intel?WiFi.) -- C:\WINDOWS\Installer\2163e8.msi [49676288] =>.Intel Corporation
[MD5.F0EE2E7F283866A2A0FEA9BE2D12A979] [WIS][2017/11/17 07:31:48] (.Google Inc. - Google Update Helper.) -- C:\WINDOWS\Installer\25792c2.msi [40960] =>.Google Inc.
[MD5.A6C1D48FB0ED01E3E1672AB4A89F411F] [WIS][2015/10/16 06:18:06] (.Intel Corporation - Intel(R) ME UninstallLegacy.) -- C:\WINDOWS\Installer\278e8c.msi [425984] =>.Intel Corporation
[MD5.8D63E8CF4AE98B88FA5361841D1D9CA3] [WIS][2015/10/16 06:18:56] (.Intel Corporation - Intel(R) Management Engine Components.) -- C:\WINDOWS\Installer\278e93.msi [9654272] =>.Intel Corporation
[MD5.2F1E630CA77290E619421D6AD06B0594] [WIS][2015/10/16 06:19:12] (.Intel Corporation - Intel(R) Management Engine Components.) -- C:\WINDOWS\Installer\278e9a.msi [17117184] =>.Intel Corporation
[MD5.0ED0C9589B99557E514AC19AF6C73A22] [WIS][2015/05/22 17:27:22] (.Intel Corporation - Intel(R) Trusted Connect Service Client.) -- C:\WINDOWS\Installer\278ea1.msi [11005952] =>.Intel Corporation
[MD5.0D69490E64E1185C42AB13FE88AC6335] [WIS][2015/05/22 01:25:00] (.Intel Corporation - Intel® Security Assist.) -- C:\WINDOWS\Installer\278ea8.msi [1167360] =>.Intel Corporation
[MD5.BDFDF2BE13384BF077085EB6CBE5483A] [WIS][2016/01/26 15:31:15] (.Asmedia Technology - Asmedia USB Host Controller Driver.) -- C:\WINDOWS\Installer\278eae.msi [6623048] =>.Asmedia Technology
[MD5.BF727E12B6A7CF82F87008C97F9E76F7] [WIS][2015/10/28 19:43:34] (.Intel Corporation - Intel(R) Chipset Device Software.) -- C:\WINDOWS\Installer\30b206.msi [770048] =>.Intel Corporation
[MD5.D8940849EDBFA3941E00EC83C194DC0C] [WIS][2017/01/12 00:08:32] (.Microleaves - Online.io Application.) -- C:\WINDOWS\Installer\6b0e3d60.msi [2750464] =>.SUP.Microleaves
[MD5.8269661A680FDD8EEED535A2BD923F28] [WIS][2017/09/29 16:15:50] (.腾讯科技(深圳)有限公司 - 腾讯QQ~1腾讯QQ.) -- C:\WINDOWS\Installer\6c9059.msi [753664]
[MD5.63906C6F1CF6CF616BF84A5992DB85F3] [WIS][2014/02/04 16:45:04] (.Futuremark - 3DMark 11.) -- C:\WINDOWS\Installer\7be6e78.msi [634880] =>.Futuremark
[MD5.1575ABC7991FFDBB890FF6D78975E2FB] [WIS][2017/01/27 18:31:43] (.Microleaves - Traffic Exchange.) -- C:\WINDOWS\Installer\81a5956.msi [2747904] =>.SUP.Microleaves
[MD5.6FE1DA059ED650DF50BE5A656E57F3AC] [WIS][2018/02/07 16:47:06] (.ExpressVpn - Split Tunneling Driver.) -- C:\WINDOWS\Installer\c5e41.msi [1658880] =>.ExpressVpn
[MD5.D96BF0856E1147ADE3EC2C6AC09338F7] [WIS][2018/02/07 16:47:12] (.ExpressVpn - Click Install if prompted.) -- C:\WINDOWS\Installer\c5e4a.msi [925696] =>.ExpressVpn
[MD5.0D9779579CD0A0C9F88AF3ED33F36B47] [WIS][2018/02/07 16:47:06] (.ExpressVPN - ExpressVPN.) -- C:\WINDOWS\Installer\c5e53.msi [20848640] =>.ExpressVPN

---\\ Search Tracing Registry Key (2) - 1s
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\tencentdl_RASAPI32 =>.SUP.Tencent
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\tencentdl_RASMANCS =>.SUP.Tencent

---\\ Additional Scan (O88) (59) - 3s
HKLM\SYSTEM\CurrentControlSet\Services\Service KMSELDI =>HackTool.KMSpico
E:\Program Files\KMSpico\Service_KMS.exe =>HackTool.KMSpico
E:\Program Files\KMSpico\AutoPico.exe =>HackTool.KMSpico
C:\WINDOWS\System32\Tasks\AutoPico Daily Restart =>HackTool.KMSpico
C:\Users\VULCAN\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe =>Adware.MSIL
C:\Windows\rss\csrss.exe =>Trojan.Dropper
HKCU\SOFTWARE\MozillaPlugins\@1.qq.com/npqqwebgame =>.SUP.Tencent
C:\Program Files (x86)\Common Files\Tencent\Npchrome\npactivex.dll =>.SUP.Tencent
HKLM\SOFTWARE\MozillaPlugins\@qq.com/npqscall =>.SUP.Tencent
HKLM\SOFTWARE\MozillaPlugins\@qq.com/QQMiniDLPlugin =>.SUP.Tencent
HKLM\SOFTWARE\MozillaPlugins\@qq.com/QQPhotoDrawEx =>.SUP.Tencent
C:\Program Files (x86)\Tencent\QQMusic\QzoneMusic\npQzoneMusic.dll =>.SUP.Tencent
HKLM\SOFTWARE\MozillaPlugins\@qq.com/QzoneMusic =>.SUP.Tencent
C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.5.18\bin\npSSOAxCtrlForPTLogin.dll =>.SUP.Tencent
HKLM\SOFTWARE\MozillaPlugins\@qq.com/TXSSO =>.SUP.Tencent
HKLM\SOFTWARE\MozillaPlugins\@tencent.com/npQQMailWebKit,version=1.0.0.1 =>.SUP.Tencent
HKLM\SOFTWARE\MozillaPlugins\@tencent.com/nptxftnWebKit,version=1.0.0.1 =>.SUP.Tencent
C:\Program Files (x86)\Thunder Network\Thunder9\BHO\XunleiBHO649.1.44.952.dll =>PUP.Optional.Xunlei
HKLM\Software\WOW6432Node\Classes\CLSID\{004B0726-A010-4ABF-8556-FCDB7F1FCA1E} =>PUP.Optional.Xunlei
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{004B0726-A010-4ABF-8556-FCDB7F1FCA1E} =>PUP.Optional.Xunlei
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QQMailPlugin =>.SUP.Tencent
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\QQMailPlugin =>.SUP.Tencent
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CloudNet =>Adware.MSIL
C:\Program Files\KMSpico =>HackTool.KMSpico
C:\Program Files (x86)\KMSPico 10.2.1 Final =>HackTool.KMSpico
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico =>HackTool.KMSpico
C:\ProgramData\SogouInput =>.SUP.Sogou
C:\ProgramData\Tencent =>.SUP.Tencent
C:\Program Files (x86)\Common Files\Tencent =>.SUP.Tencent
C:\Users\VULCAN\AppData\Roaming\EpicNet Inc =>Adware.MSIL
C:\Users\VULCAN\AppData\Roaming\Tencent =>.SUP.Tencent
C:\Users\VULCAN\AppData\Local\Tencent =>.SUP.Tencent
C:\Users\VULCAN\AppData\LocalLow\SogouPY =>.SUP.Sogou
C:\Users\VULCAN\AppData\LocalLow\SogouPY.users =>.SUP.Sogou
C:\Users\VULCAN\AppData\LocalLow\TENCENT =>.SUP.Tencent
C:\WINDOWS\Prefetch\KMSPICO 10.2.2.EXE-12A9AAF8.pf =>HackTool.KMSpico
C:\WINDOWS\Prefetch\KMSPICOACTIVATOR.EXE-76DF8139.pf =>HackTool.KMSpico
C:\WINDOWS\Prefetch\KMSPICO_SETUP.TMP-289DE684.pf =>HackTool.KMSpico
C:\WINDOWS\Prefetch\KMSPICO_SETUP.TMP-471063F7.pf =>HackTool.KMSpico
C:\WINDOWS\Prefetch\KMSPICO_SETUP.TMP-97F30802.pf =>HackTool.KMSpico
C:\WINDOWS\Prefetch\KMSPICO_SETUP.TMP-C0D38EA5.pf =>HackTool.KMSpico
C:\WINDOWS\Prefetch\KMSPICO_SETUP.TMP-DCC09203.pf =>HackTool.KMSpico
C:\WINDOWS\Prefetch\KMSPICO_SETUP.TMP-F35BC511.pf =>HackTool.KMSpico
C:\Users\VULCAN\Desktop\新建文件夹\KMSpico_setup.exe =>HackTool.KMSpico
C:\Users\Public\SogouInput\USBDT\OctopusDownloader.exe =>.SUP.Sogou
C:\WINDOWS\Installer\6b0e3d60.msi =>.SUP.Microleaves
C:\WINDOWS\Installer\81a5956.msi =>.SUP.Microleaves
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\tencentdl_RASAPI32 =>.SUP.Tencent
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\tencentdl_RASMANCS =>.SUP.Tencent
C:\Users\VULCAN\AppData\Local\Google\Chrome\User Data\Default\File System\000 =>.SUP.Temporary.Chrome
C:\Users\VULCAN\AppData\Local\Google\Chrome\User Data\Default\File System\001 =>.SUP.Temporary.Chrome
C:\Users\VULCAN\AppData\Local\Google\Chrome\User Data\Default\File System\002 =>.SUP.Temporary.Chrome
C:\Users\VULCAN\AppData\Local\Google\Chrome\User Data\Default\File System\003 =>.SUP.Temporary.Chrome
C:\Users\VULCAN\AppData\Local\Google\Chrome\User Data\Default\File System\004 =>.SUP.Temporary.Chrome
C:\Users\VULCAN\AppData\Local\Google\Chrome\User Data\Default\File System\005 =>.SUP.Temporary.Chrome
C:\Users\VULCAN\AppData\Local\Google\Chrome\User Data\Default\File System\006 =>.SUP.Temporary.Chrome
C:\Users\VULCAN\AppData\Local\Google\Chrome\User Data\Default\File System\007 =>.SUP.Temporary.Chrome
Not deleted [: The Phantom Pain.lnk] C:\Users\Public\Desktop\Metal Gear Solid V: The Phantom Pain.lnk =>.SUP.FileADS
C:\Users\VULCAN\AppData\Local\Temp\wup\wupv.exe =>PUP.Optional.BitCoinMiner

---\\ Summary of the elements found (13) - 0s
https://nicolascoolman.eu/2017/02/16/hacktool-kmspico/ =>HackTool.KMSpico
https://nicolascoolman.eu/2017/09/12/origine-lignes-orphelines/ =>.SUP.Orphan
https://www.anti-malware.top/2016/09/07/trojan-dropper/ =>Trojan.Dropper
https://nicolascoolman.eu/2017/09/13/adware-msil/ =>Adware.MSIL
https://nicolascoolman.eu/2017/09/14/pup-optional-bitcoinminer/ =>PUP.Optional.BitCoinMiner
https://nicolascoolman.eu/2017/02/23/tencentadressbar/ =>.SUP.Tencent
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.Xunlei
https://www.nicolascoolman.com/fr/pup-sogou/ =>.SUP.Sogou
https://nicolascoolman.eu/2017/03/11/pup-optional-crossrider/ =>Adware.CrossRider
https://nicolascoolman.eu/2017/03/04/superfluous-ucbrowser/ =>.SUP.UCBrowser
https://nicolascoolman.eu/2017/12/24/sup-microleaves/ =>.SUP.Microleaves
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Temporary.Chrome
https://nicolascoolman.eu/2018/01/04/ads-alternate-data-stream/ =>.SUP.FileADS

~ Unselected Options: O108, O82, O108, O82,
~ End of the scan, 29774 items in 02mn03s (1887)(0)

Publicité


Signaler le contenu de ce document

Publicité