~ ZHPDiag v2015.8.20.122 By Nicolas Coolman (2015/08/20) ~ Run by habash (Administrator) (2015/08/21 13:04:02) ~ Web: http://www.nicolascoolman.fr ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ State version: Version OK ~ Mode: Scan ~ Report: C:\Users\habash\Desktop\ZHPDiag.txt ~ Report: C:\Users\habash\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ System startup: Normal (Normal boot) Windows 7 Ultimate, 64-bit Service Pack 1 (Build 7601) ---\\ Internet Browsers (3) - 0s MFIE: Mozilla Firefox 39.0.3 (x86 en-US) v39.0.3 OPIE: Opera 31.0.1889.174 v31.0.1889.174 MSIE: Internet Explorer v11.0.9600.17959 ---\\ Windows Product Information (4) - 3s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK (Auto) Windows Activation Technologies : OK ---\\ System protection software (1) - 0s Windows Defender W7 (Activate) ---\\ Surveillance software (2) - 1s Adobe Flash Player 18 PPAPI Adobe Reader 9.2 ---\\ Information on the system (6) - 0s ~ Operating System: Intel64 Family 6 Model 26 Stepping 5, GenuineIntel ~ Operating System: 64-bit ~ Boot mode: Normal (Normal boot) Total RAM: 8371.468 MB (51% free) ~ System Restore: Activé (Enable) ~ System drive C: has 51 GB free of 102 GB ---\\ Connection to the system mode (3) - 0s ~ Computer Name: HABASH-PC ~ User Name: habash ~ Logged in as Administrator ---\\ Enumeration of the disk units (4) - 0s ~ Drive C: has 51 GB free of 102 GB (System) ~ Drive D: has 171 GB free of 256 GB ~ Drive E: has 122 GB free of 336 GB ~ Drive F: has 140 GB free of 256 GB ---\\ State of the Windows Security Center (11) - 0s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ---\\ Search Generic System Files (23) - 1s [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Windows Explorer.) () -- C:\Windows\Explorer.exe [2871808] [MD5.DD81D91FF3B0763C392422865C9AC12E] - (.Microsoft Corporation - Windows host process (Rundll32).) () -- C:\Windows\System32\rundll32.exe [45568] [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Windows Start-Up Application.) () -- C:\Windows\System32\Wininit.exe [129024] [MD5.C555B5C8142844DED9E3BD94E6313000] - (.Microsoft Corporation - Internet Extensions for Win32.) () -- C:\Windows\System32\wininet.dll [2427904] [MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - (.Microsoft Corporation - Windows Logon Application.) () -- C:\Windows\System32\Winlogon.exe [455168] [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Software Licensing Library.) () -- C:\Windows\System32\sppcomapi.dll [232448] [MD5.FA886682CFC5D36718D3E436AACF10B9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\Windows\System32\drivers\AFD.sys [497152] [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\Windows\System32\drivers\atapi.sys [24128] [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\Windows\System32\drivers\Cdfs.sys [92160] [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\Windows\System32\drivers\Cdrom.sys [147456] [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\Windows\System32\drivers\DfsC.sys [102400] [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\Windows\System32\drivers\HDAudBus.sys [122368] [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - i8042 Port Driver.) () -- C:\Windows\System32\drivers\i8042prt.sys [105472] [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\Windows\System32\drivers\IpNat.sys [116224] [MD5.B2081803D510DCE174992BA880EDCA70] - (.Microsoft Corporation - Windows NT SMB Minirdr.) () -- C:\Windows\System32\drivers\MRxSmb.sys [159232] [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\Windows\System32\drivers\netBT.sys [261632] [MD5.1A29A59A4C5BA6F8C85062A613B7E2B2] - (.Microsoft Corporation - NT File System Driver.) () -- C:\Windows\System32\drivers\ntfs.sys [1684928] [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Parallel Port Driver.) () -- C:\Windows\System32\drivers\Parport.sys [97280] [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\Windows\System32\drivers\Rasl2tp.sys [129536] [MD5.1B6163C503398B23FF8B939C67747683] - (.Microsoft Corporation - Microsoft RDP Device redirector.) () -- C:\Windows\System32\drivers\rdpdr.sys [165888] [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) () -- C:\Windows\System32\drivers\smb.sys [93184] [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\Windows\System32\drivers\tdx.sys [119296] [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Volume Shadow Copy Driver.) () -- C:\Windows\System32\drivers\volsnap.sys [295808] ---\\ Process running (50) - 4s [MD5.ACD4AF1B9D6E6C0C5BE470E5CF313FE6] - (.IObit - Advanced SystemCare Service.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [814880] [PID.756] [MD5.E3DB177522C33BB449445A3493790820] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 341.6.) -- C:\Windows\system32\nvvsvc.exe [932040] [PID.824] [MD5.2C63158245D2F53333BAA42CDF24883C] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe [1201480] [PID.1384] [MD5.E3DB177522C33BB449445A3493790820] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 341.6.) -- C:\Windows\system32\nvvsvc.exe [932040] [PID.1392] [MD5.0F6A17DC2DA7CFF449C9293CB772DAD5] - (.Adobe Systems Incorporated - Adobe Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [680112] [PID.1484] [MD5.4AA10AEFC7E7FB30BAA8706BC5798E1D] - (.Symantec Corporation - Norton Identity Safe.) -- C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\NST.exe [131144] [PID.1696] [MD5.439BD966130226F464DC15F55ABD266E] - (.TechSmith Corporation - TechSmith Uploader Service.) -- C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3408384] [PID.1908] [MD5.4AA10AEFC7E7FB30BAA8706BC5798E1D] - (.Symantec Corporation - Norton Identity Safe.) -- C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\NST.exe [131144] [PID.2268] [MD5.6009C7F55A71FA7F23692B92214A4CF8] - (.IObit - Performance Monitor.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe [1774880] [PID.2456] [MD5.BF225BCD0EC2D85719C382019B5B4250] - (.Realtek Semiconductor - Realtek HD Audio Manager.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14040792] [PID.3012] [MD5.422963B9386FD4052AA766A6575ED8DE] - (.IObit - Advanced SystemCare 8.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe [2429728] [PID.1640] [MD5.7C53B9549399F19F5EC185BA3FCE08F9] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3903056] [PID.2316] [MD5.E3D991C8B9F7756538DE5C0A26647F65] - (.TechSmith Corporation - Snagit.) -- C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe [7432512] [PID.2840] [MD5.051B5C9492CBAF8AF8BF800A27BE0529] - (.Adobe Systems Incorporated - Adobe Creative Cloud.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2303152] [PID.1240] [MD5.240AF8882E2C0D1280572DFAB3C31D93] - (.Adobe Systems Incorporated - Adobe IPC Broker.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe [1011872] [PID.3132] [MD5.11C79E0D1A1B332B79D1A1402052A4D0] - (.TechSmith Corporation - Snagit RPC Helper.) -- C:\Program Files (x86)\TechSmith\Snagit 12\SnagPriv.exe [151872] [PID.3264] [MD5.69505856F6152A24B02AAAFDB53414A0] - (.Adobe Systems Incorporated - Creative Cloud.) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe [2266800] [PID.3452] [MD5.2BB639512E57F6C38AFE5AC7E5E4005B] - (.Adobe Systems Incorporated - Adobe CEF Helper.) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe [174256] [PID.3480] [MD5.2BB639512E57F6C38AFE5AC7E5E4005B] - (.Adobe Systems Incorporated - Adobe CEF Helper.) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe [174256] [PID.4052] [MD5.DA1074E7E45E78E36CCED6735CFCA7E0] - (.Copyright © 2013-2015, Adobe Systems Incorporated. Al - Core Sync.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe [31535264] [PID.3896] [MD5.0A1810F3CF866F67856C8A4E98194493] - (.TechSmith Corporation - TechSmith HTML Help Helper.) -- C:\Program Files (x86)\TechSmith\Snagit 12\TscHelp.exe [46080] [PID.3548] [MD5.27954CE3A3AFDBC91C91303AF50FADF7] - (.TechSmith Corporation - Snagit Editor.) -- C:\Program Files (x86)\TechSmith\Snagit 12\snagiteditor.exe [8587072] [PID.4760] [MD5.0B6438453DB2A89E0566913D3F2C127F] - (.Nullsoft, Inc. - Winamp.) -- C:\Program Files (x86)\Winamp\winamp.exe [2325600] [PID.4824] [MD5.948FA74B07C4E4DA03BD8272FA85286C] - (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\31.0.1889.174\opera.exe [899704] [PID.4188] [MD5.520002C4A4737CDDD6B860E30ECD7C67] - (.Opera Software - Opera crash-reporter.) -- C:\Program Files (x86)\Opera\31.0.1889.174\opera_crashreporter.exe [511608] [PID.4228] [MD5.948FA74B07C4E4DA03BD8272FA85286C] - (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\31.0.1889.174\opera.exe [899704] [PID.4376] [MD5.948FA74B07C4E4DA03BD8272FA85286C] - (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\31.0.1889.174\opera.exe [899704] [PID.4620] [MD5.948FA74B07C4E4DA03BD8272FA85286C] - (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\31.0.1889.174\opera.exe [899704] [PID.4220] [MD5.948FA74B07C4E4DA03BD8272FA85286C] - (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\31.0.1889.174\opera.exe [899704] [PID.4212] [MD5.948FA74B07C4E4DA03BD8272FA85286C] - (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\31.0.1889.174\opera.exe [899704] [PID.4748] [MD5.2B15967270AD018024286CBA9DA1E4E7] - (.IObit - .) -- C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe [188192] [PID.5528] [MD5.948FA74B07C4E4DA03BD8272FA85286C] - (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\31.0.1889.174\opera.exe [899704] [PID.1844] [MD5.649DD30DB8DD58ECDA2BA50829D44A44] - (.Google Inc. - Google Chrome.) -- C:\Users\habash\AppData\Local\Google\Chrome\Application\chrome.exe [863560] [PID.3260] [MD5.649DD30DB8DD58ECDA2BA50829D44A44] - (.Google Inc. - Google Chrome.) -- C:\Users\habash\AppData\Local\Google\Chrome\Application\chrome.exe [863560] [PID.188] [MD5.649DD30DB8DD58ECDA2BA50829D44A44] - (.Google Inc. - Google Chrome.) -- C:\Users\habash\AppData\Local\Google\Chrome\Application\chrome.exe [863560] [PID.4560] [MD5.649DD30DB8DD58ECDA2BA50829D44A44] - (.Google Inc. - Google Chrome.) -- C:\Users\habash\AppData\Local\Google\Chrome\Application\chrome.exe [863560] [PID.2700] [MD5.649DD30DB8DD58ECDA2BA50829D44A44] - (.Google Inc. - Google Chrome.) -- C:\Users\habash\AppData\Local\Google\Chrome\Application\chrome.exe [863560] [PID.5076] [MD5.649DD30DB8DD58ECDA2BA50829D44A44] - (.Google Inc. - Google Chrome.) -- C:\Users\habash\AppData\Local\Google\Chrome\Application\chrome.exe [863560] [PID.4812] [MD5.649DD30DB8DD58ECDA2BA50829D44A44] - (.Google Inc. - Google Chrome.) -- C:\Users\habash\AppData\Local\Google\Chrome\Application\chrome.exe [863560] [PID.4868] [MD5.649DD30DB8DD58ECDA2BA50829D44A44] - (.Google Inc. - Google Chrome.) -- C:\Users\habash\AppData\Local\Google\Chrome\Application\chrome.exe [863560] [PID.4872] [MD5.649DD30DB8DD58ECDA2BA50829D44A44] - (.Google Inc. - Google Chrome.) -- C:\Users\habash\AppData\Local\Google\Chrome\Application\chrome.exe [863560] [PID.1940] [MD5.A9E21B140737C36D909A0AFFBE44084B] - (.Symantec Corporation - Google Chrome (Norton Identity Safe native.) -- C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\coNatHst.exe [42808] [PID.4896] [MD5.649DD30DB8DD58ECDA2BA50829D44A44] - (.Google Inc. - Google Chrome.) -- C:\Users\habash\AppData\Local\Google\Chrome\Application\chrome.exe [863560] [PID.5728] [MD5.649DD30DB8DD58ECDA2BA50829D44A44] - (.Google Inc. - Google Chrome.) -- C:\Users\habash\AppData\Local\Google\Chrome\Application\chrome.exe [863560] [PID.1776] [MD5.649DD30DB8DD58ECDA2BA50829D44A44] - (.Google Inc. - Google Chrome.) -- C:\Users\habash\AppData\Local\Google\Chrome\Application\chrome.exe [863560] [PID.5928] [MD5.948FA74B07C4E4DA03BD8272FA85286C] - (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\31.0.1889.174\opera.exe [899704] [PID.5056] [MD5.649DD30DB8DD58ECDA2BA50829D44A44] - (.Google Inc. - Google Chrome.) -- C:\Users\habash\AppData\Local\Google\Chrome\Application\chrome.exe [863560] [PID.2940] [MD5.948FA74B07C4E4DA03BD8272FA85286C] - (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\31.0.1889.174\opera.exe [899704] [PID.728] [MD5.63E20985B61368A6172D93D0245DC9F8] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\habash\Desktop\ZHPDiag3.exe [1895424] [PID.4688] [MD5.649DD30DB8DD58ECDA2BA50829D44A44] - (.Google Inc. - Google Chrome.) -- C:\Users\habash\AppData\Local\Google\Chrome\Application\chrome.exe [863560] [PID.5368] ---\\ Google Chrome, Start,Search,Extensions (20) - 1s G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.google.com.eg/?gfe_rd=cr&ei=hndjVdyKLKzA8geFg4DoAg&gws_rd=ssl G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.google.com.eg/?gfe_rd=cr&ei=osbEVd35N4Ld8gf63LHABA&gws_rd=ssl G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [ebkclgoaabaibghklgknnjdemknjaeic] PageEdit G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [homldgnlpldcmdflhnabedgkgpmeanhd] Tweet Button for Chrome (by Shareaholic) G2 - GCE: Preference [User Data\Default] [iikflkcanblccfahdhdonehdalibjnif] Norton Identity Safe G2 - GCE: Preference [User Data\Default] [jcjacdgelmcehgcakabkobhgiamfklah] Deezer Mediakeys Reloaded G2 - GCE: Preference [User Data\Default] [lccekmodgklaepjeofjdjpbminllajkg] Chrome Hotword Shared Module G2 - GCE: Preference [User Data\Default] [nafaimnnclfjfedmmabolbppcngeolgf] iLivid =>PUP.Optional.Bandoo G2 - GCE: Preference [User Data\Default] [ndibdjnfmopecpmkdieinmbadjfpblof] AVG Secure Search =>Toolbar.AVGSearch G2 - GCE: Preference [User Data\Default] [ngpampappnmepgilojfohadhhmbhlaek] IDM Integration Module G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [nppllibpnmahfaklnpggkibhkapjkeob] Norton Security Toolbar G2 - GCE: Preference [User Data\Default] [oppjbdkgpfhhllancffaoaemplhkngoc] Free Games Zone G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc. ---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (14) - 1s M1 - SPR:Search Page Redirection - C:\Program Files (x86)\Mozilla Firefox\extensions\quickstores@quickstores.de =>Toolbar.QuickStores P2 - EXT: (.Tracker Software Products Ltd. - PDF-XChange Viewer Netscape Gecko Plugin.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npPDFXCviewNPPlugin.dll P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\amazondotcom.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\bing.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\ddg.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\eBay.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\google.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\twitter.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wikipedia.xml P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\yahoo.xml =>PUP.Optional.BDYahoo P2 - EXT: (.Mozilla - Default.) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} P2 - FPN: [HKCU] [@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf] - (.Tracker Software Products Ltd..) -- C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll P2 - FPN: [HKLM] [@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf] - (.Tracker Software Products Ltd..) -- C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll ---\\ Internet Explorer Extensions, Start, Search (15) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer ---\\ Internet Explorer, Proxy Management (4) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) ---\\ Hosts file redirection (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (21) ---\\ Browser Helper Object (BHO) (1) - 0s O2 - BHO: IDM Helper [64Bits] - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll ---\\ Auto loading programs from Registry and folders (20) - 1s O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Realtek HD Audio Manager.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe O4 - HKCU\..\Run: [Advanced SystemCare 8] . (.IObit - Advanced SystemCare 8.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Facebook Installer.) -- C:\Users\habash\AppData\Local\Facebook\Update\FacebookUpdate.exe O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe O4 - HKCU\..\Run: [AdobeBridge] (Orphean) O4 - HKLM\..\Wow6432Node\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe O4 - HKLM\..\Wow6432Node\Run: [GrooveMonitor] . (.Microsoft Corporation - GrooveMonitor Utility.) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe O4 - HKLM\..\Wow6432Node\Run: [SwitchBoard] . (.Adobe Systems Incorporated - SwitchBoard Server (32 bit).) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe O4 - HKLM\..\Wow6432Node\Run: [AdobeCS6ServiceManager] . (.Adobe Systems Incorporated - Adobe CS6 Service Manager.) -- C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe O4 - HKLM\..\Wow6432Node\Run: [Adobe Creative Cloud] . (.Adobe Systems Incorporated - Adobe Creative Cloud.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe O4 - HKUS\S-1-5-21-3468095729-3432513675-3933751231-1001\..\Run: [Advanced SystemCare 8] . (.IObit - Advanced SystemCare 8.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe O4 - HKUS\S-1-5-21-3468095729-3432513675-3933751231-1001\..\Run: [Facebook Update] . (.Facebook Inc. - Facebook Installer.) -- C:\Users\habash\AppData\Local\Facebook\Update\FacebookUpdate.exe O4 - HKUS\S-1-5-21-3468095729-3432513675-3933751231-1001\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe O4 - HKUS\S-1-5-21-3468095729-3432513675-3933751231-1001\..\Run: [AdobeBridge] (Orphean) ---\\ Lop.com/Domain Hijackers (6) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = Belkin O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpDomain = Belkin O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpDomain = Belkin ---\\ Non Microsoft non disabled Windows Services (6) - 0s O23 - Service: (AdobeUpdateService) . (.Adobe Systems Incorporated - Adobe Update Service.) - C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe O23 - Service: Advanced SystemCare Service 8 (AdvancedSystemCareService8) . (.IObit - Advanced SystemCare Service.) - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe O23 - Service: LiveUpdate (LiveUpdateSvc) . (.IObit - Product Updater.) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe O23 - Service: Norton Identity Safe (NCO) . (.Symantec Corporation - Norton Identity Safe.) - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\NST.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 341.6.) - C:\Windows\system32\nvvsvc.exe O23 - Service: TechSmith Uploader Service (TechSmith Uploader Service) . (.TechSmith Corporation - TechSmith Uploader Service.) - C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe ---\\ Task Planned Automatically (35) - 5s [MD5.0FBC0E179CA71FAD0832FF479439BFFB] [APT] [Adobe Flash Player PPAPI Notifier] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_18_0_0_232_pepper.exe [1156296] [MD5.368290D0A612D62DA6F3D798B1BB8FE7] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [269000] [MD5.7486DEF5CC9334F58871D6D18B73C562] [APT] [AdobeAAMUpdater-1.0-habash-PC-habash] (.Adobe Systems Incorporated.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936] [MD5.6009C7F55A71FA7F23692B92214A4CF8] [APT] [ASC8_PerformanceMonitor] (.IObit.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe [1774880] [MD5.E2405E793004B179C99D05331635CAF1] [APT] [ASC8_SkipUac_habash] (.IObit.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe [5425440] [MD5.5556C54070E16F917393812335381087] [APT] [Driver Booster Scan] (.IObit.) -- C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [67904] [MD5.A88328A4FBB0847B80FB5315CF4AC040] [APT] [Driver Booster SkipUAC (habash)] (.IObit.) -- C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [4445504] [MD5.5481393F49809D029283B9F5902047CE] [APT] [Driver Booster Update] (.IObit.) -- C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [1737536] [MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-3468095729-3432513675-3933751231-1001Core] (.Facebook Inc..) -- C:\Users\habash\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-3468095729-3432513675-3933751231-1001UA] (.Facebook Inc..) -- C:\Users\habash\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [MD5.044C9C39D1164EB8CB8FA8DFBA6E063C] [APT] [Opera scheduled Autoupdate 1439370420] (.Opera Software.) -- C:\Program Files (x86)\Opera\launcher.exe [931960] [MD5.00000000000000000000000000000000] [APT] [RealDownloader Update Check] (...) -- C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe (.not file.) [0] [MD5.E0DEBE808C0FC71F6CAAB979547F84CD] [APT] [TechSmith Updater] (.TechSmith Corporation.) -- C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe [56704] [MD5.0A6B46C7DF4CC23C106E7494321AE5F3] [APT] [Uninstaller_SkipUac_habash] (.IObit.) -- C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [8032544] [MD5.3D25E7A53FB5F0843F127A92370C5130] [APT] [Norton Identity Safe\Norton Error Analyzer] (.Symantec Corporation.) -- C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\symerr.exe [70496] [MD5.3D25E7A53FB5F0843F127A92370C5130] [APT] [Norton Identity Safe\Norton Error Processor] (.Symantec Corporation.) -- C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\symerr.exe [70496] [MD5.98E4CF7AEDE8F12520B81121DE8291F2] [APT] [Remediation\AntimalwareMigrationTask] (.Symantec Corporation.) -- C:\Program Files\Common Files\AV\Norton AntiVirus\Upgrade.exe [2059272] O39 - APT: Adobe Flash Player PPAPI Notifier - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job [892] =>.Adobe Systems Incorporated O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [830] =>.Adobe Systems Incorporated O39 - APT: FacebookUpdateTaskUserS-1-5-21-3468095729-3432513675-3933751231-1001Core - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3468095729-3432513675-3933751231-1001Core.job [910] =>.Facebook Inc. O39 - APT: FacebookUpdateTaskUserS-1-5-21-3468095729-3432513675-3933751231-1001UA - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3468095729-3432513675-3933751231-1001UA.job [932] =>.Facebook Inc. O39 - APT: Adobe Flash Player PPAPI Notifier - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier [3890] =>.Adobe Systems Incorporated O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [3768] =>.Adobe Systems Incorporated O39 - APT: AdobeAAMUpdater-1.0-habash-PC-habash - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-habash-PC-habash [3506] =>.Adobe Systems Incorporated O39 - APT: ASC8_PerformanceMonitor - (.IObit.) -- C:\Windows\System32\Tasks\ASC8_PerformanceMonitor [3188] =>.IObit O39 - APT: ASC8_SkipUac_habash - (.IObit.) -- C:\Windows\System32\Tasks\ASC8_SkipUac_habash [2876] =>.IObit O39 - APT: Driver Booster Scan - (.IObit.) -- C:\Windows\System32\Tasks\Driver Booster Scan [3236] =>.IObit O39 - APT: Driver Booster SkipUAC (habash) - (.IObit.) -- C:\Windows\System32\Tasks\Driver Booster SkipUAC (habash) [2878] =>.IObit O39 - APT: Driver Booster Update - (.IObit.) -- C:\Windows\System32\Tasks\Driver Booster Update [3180] =>.IObit O39 - APT: FacebookUpdateTaskUserS-1-5-21-3468095729-3432513675-3933751231-1001Core - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3468095729-3432513675-3933751231-1001Core [3542] =>.Facebook Inc. O39 - APT: FacebookUpdateTaskUserS-1-5-21-3468095729-3432513675-3933751231-1001UA - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3468095729-3432513675-3933751231-1001UA [3910] =>.Facebook Inc. O39 - APT: Opera scheduled Autoupdate 1439370420 - (.Opera Software.) -- C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1439370420 [3832] =>.Opera Software O39 - APT: RealDownloader Update Check - (...) -- C:\Windows\System32\Tasks\RealDownloader Update Check [3428] O39 - APT: TechSmith Updater - (.TechSmith Corporation.) -- C:\Windows\System32\Tasks\TechSmith Updater [3808] =>.TechSmith Corporation O39 - APT: Uninstaller_SkipUac_habash - (.IObit.) -- C:\Windows\System32\Tasks\Uninstaller_SkipUac_habash [2908] =>.IObit ---\\ Software installed (28) - 3s O42 - Logiciel: Unlocker 1.9.1-x64 - (.Cedrick Collomb.) [HKLM][64Bits] -- Unlocker O42 - Logiciel: WinRAR 5.30 beta 2 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver O42 - Logiciel: PDF-Viewer - (.Tracker Software Products Ltd.) [HKLM][64Bits] -- {8D273DE5-ABFA-4BD0-A9D7-EE9C971438C4}_is1 O42 - Logiciel: Adobe Creative Cloud - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Creative Cloud O42 - Logiciel: Adobe Flash Player 18 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX O42 - Logiciel: Adobe Flash Player 18 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI O42 - Logiciel: Adobe Flash Player 18 PPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player PPAPI O42 - Logiciel: Advanced SystemCare 8 - (.IObit.) [HKLM][64Bits] -- Advanced SystemCare 8_is1 O42 - Logiciel: Driver Booster 2.4 - (.IObit.) [HKLM][64Bits] -- Driver Booster_is1 O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM][64Bits] -- Internet Download Manager O42 - Logiciel: Surfing Protection - (.IObit.) [HKLM][64Bits] -- IObit Surfing Protection_is1 O42 - Logiciel: IObit Uninstaller - (.IObit.) [HKLM][64Bits] -- IObitUninstall O42 - Logiciel: K-Lite Mega Codec Pack 10.0.0 - (...) [HKLM][64Bits] -- KLiteCodecPack_is1 O42 - Logiciel: Mozilla Firefox 39.0.3 (x86 en-US) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 39.0.3 (x86 en-US) O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService O42 - Logiciel: NirSoft Wireless Network Watcher - (...) [HKLM][64Bits] -- NirSoft Wireless Network Watcher O42 - Logiciel: Norton Identity Safe - (.Symantec Corporation.) [HKLM][64Bits] -- NST O42 - Logiciel: Opera Stable 31.0.1889.174 - (.Opera Software.) [HKLM][64Bits] -- Opera 31.0.1889.174 O42 - Logiciel: QuickStores-Toolbar 1.1.0 - (.AB-Tools.com.) [HKLM][64Bits] -- QuickStores-Toolbar_is1 =>Toolbar.QuickStores O42 - Logiciel: Winamp - (.Nullsoft, Inc.) [HKLM][64Bits] -- Winamp O42 - Logiciel: Facebook Video Calling 3.1.0.521 - (.Skype Limited.) [HKLM][64Bits] -- {2091F234-EB58-4B80-8C96-8EB78C808CF7} O42 - Logiciel: Adobe Photoshop CS6 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {74EB3499-8B95-4B5C-96EB-7B342F3FD0C6} O42 - Logiciel: Adobe Reader 9.2 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1033-7B44-A92000000001} O42 - Logiciel: PDF Settings CS6 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {BFEAAE77-BD7F-4534-B286-9C5CB4697EB1} O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} O42 - Logiciel: Windows ARP Spoofer - (...) [HKLM][64Bits] -- {FB90085B-59E4-40FA-81CA-CBE0E70A7183} O42 - Logiciel: Google Chrome - (.Google Inc..) [HKCU][64Bits] -- Google Chrome O42 - Logiciel: Winamp Detector Plug-in - (.Nullsoft, Inc.) [HKCU][64Bits] -- Winamp Detect ---\\ HKCU & HKLM Software Keys (63) - 3s HKLM\SOFTWARE\Wow6432Node\Adobe HKLM\SOFTWARE\Wow6432Node\Apple Computer, Inc. HKLM\SOFTWARE\Wow6432Node\CDDB HKLM\SOFTWARE\Wow6432Node\GNU HKLM\SOFTWARE\Wow6432Node\Google HKLM\SOFTWARE\Wow6432Node\HaaliMkx HKLM\SOFTWARE\Wow6432Node\Intel HKLM\SOFTWARE\Wow6432Node\Internet Download Manager HKLM\SOFTWARE\Wow6432Node\IObit HKLM\SOFTWARE\Wow6432Node\Khronos HKLM\SOFTWARE\Wow6432Node\KLCodecPack HKLM\SOFTWARE\Wow6432Node\LAV HKLM\SOFTWARE\Wow6432Node\Macromedia HKLM\SOFTWARE\Wow6432Node\Mozilla HKLM\SOFTWARE\Wow6432Node\mozilla.org HKLM\SOFTWARE\Wow6432Node\MozillaPlugins HKLM\SOFTWARE\Wow6432Node\NextSecurity.NET HKLM\SOFTWARE\Wow6432Node\Norton HKLM\SOFTWARE\Wow6432Node\Nuance HKLM\SOFTWARE\Wow6432Node\Nullsoft HKLM\SOFTWARE\Wow6432Node\ODBC HKLM\SOFTWARE\Wow6432Node\Opera Software HKLM\SOFTWARE\Wow6432Node\RealNetworks HKLM\SOFTWARE\Wow6432Node\SRS Labs HKLM\SOFTWARE\Wow6432Node\SystemSafe HKLM\SOFTWARE\Wow6432Node\TechSmith HKLM\SOFTWARE\Wow6432Node\Xing Technology Corp. HKLM\SOFTWARE\Wow6432Node\RegisteredApplications HKCU\SOFTWARE\Adobe HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\Chromium HKCU\SOFTWARE\DownloadManager HKCU\SOFTWARE\EMU HKCU\SOFTWARE\Facebook HKCU\SOFTWARE\Gabest HKCU\SOFTWARE\GNU HKCU\SOFTWARE\Google HKCU\SOFTWARE\Haali HKCU\SOFTWARE\Icaros HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\madshi HKCU\SOFTWARE\MediaInfo HKCU\SOFTWARE\Mozilla HKCU\SOFTWARE\MozillaPlugins HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\NextSecurity HKCU\SOFTWARE\Norton HKCU\SOFTWARE\NVIDIA Corporation HKCU\SOFTWARE\ODBC HKCU\SOFTWARE\Opera Software HKCU\SOFTWARE\RealNetworks HKCU\SOFTWARE\Realtek HKCU\SOFTWARE\Samsung HKCU\SOFTWARE\SystemSafe HKCU\SOFTWARE\TechSmith HKCU\SOFTWARE\Tracker Software HKCU\SOFTWARE\VB and VBA Program Settings HKCU\SOFTWARE\Winamp HKCU\SOFTWARE\WinRAR HKCU\SOFTWARE\WinRAR SFX HKCU\SOFTWARE\Wow6432Node HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Software ---\\ Contents of the Common Files folders (146) - 4s O43 - CFD: 2015/08/16 16:04:24 - [] D -- C:\Program Files (x86)\Adobe O43 - CFD: 2015/08/18 13:51:24 - [] D -- C:\Program Files (x86)\Common Files O43 - CFD: 2015/08/13 20:47:22 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information O43 - CFD: 2015/08/09 08:08:43 - [] D -- C:\Program Files (x86)\Internet Download Manager O43 - CFD: 2015/08/12 14:34:16 - [] D -- C:\Program Files (x86)\Internet Explorer O43 - CFD: 2015/08/07 15:30:15 - [] D -- C:\Program Files (x86)\IObit O43 - CFD: 2015/08/07 16:57:38 - [] D -- C:\Program Files (x86)\K-Lite Codec Pack O43 - CFD: 2015/08/13 20:47:24 - [] D -- C:\Program Files (x86)\MarkAny O43 - CFD: 2015/08/07 17:22:21 - [] D -- C:\Program Files (x86)\Microsoft Office O43 - CFD: 2015/08/07 17:22:19 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio O43 - CFD: 2015/08/07 17:20:54 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio 8 O43 - CFD: 2015/08/07 17:22:28 - [] D -- C:\Program Files (x86)\Microsoft Works O43 - CFD: 2015/08/18 13:33:11 - [] D -- C:\Program Files (x86)\Microsoft.NET O43 - CFD: 2015/08/18 15:33:16 - [] D -- C:\Program Files (x86)\Mozilla Firefox O43 - CFD: 2015/08/07 16:51:30 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service O43 - CFD: 2015/08/07 17:22:23 - [] D -- C:\Program Files (x86)\MSBuild O43 - CFD: 2015/08/07 17:21:08 - [] D -- C:\Program Files (x86)\NextSecurity.NET O43 - CFD: 2015/08/07 17:21:56 - [] D -- C:\Program Files (x86)\NirSoft O43 - CFD: 2015/08/18 22:47:50 - [] D -- C:\Program Files (x86)\Norton Identity Safe O43 - CFD: 2015/08/18 23:32:11 - [] D -- C:\Program Files (x86)\NortonInstaller O43 - CFD: 2015/08/20 18:04:33 - [] D -- C:\Program Files (x86)\Opera O43 - CFD: 2015/08/12 11:04:46 - [0] D -- C:\Program Files (x86)\Real O43 - CFD: 2009/07/14 07:32:38 - [] D -- C:\Program Files (x86)\Reference Assemblies O43 - CFD: 2015/08/18 13:08:06 - [] D -- C:\Program Files (x86)\Samsung O43 - CFD: 2015/08/18 13:51:24 - [] D -- C:\Program Files (x86)\TechSmith O43 - CFD: 2009/07/14 06:57:06 - [0] HD -- C:\Program Files (x86)\Uninstall Information O43 - CFD: 2015/08/07 17:19:13 - [] D -- C:\Program Files (x86)\Winamp O43 - CFD: 2015/08/07 17:18:53 - [] D -- C:\Program Files (x86)\Winamp Detect O43 - CFD: 2014/06/14 14:07:30 - [] D -- C:\Program Files (x86)\Windows Defender O43 - CFD: 2010/11/21 09:06:51 - [] D -- C:\Program Files (x86)\Windows Mail O43 - CFD: 2015/08/08 11:03:14 - [] D -- C:\Program Files (x86)\Windows Media Player O43 - CFD: 2009/07/14 07:32:38 - [] D -- C:\Program Files (x86)\Windows NT O43 - CFD: 2010/11/21 09:06:51 - [] D -- C:\Program Files (x86)\Windows Photo Viewer O43 - CFD: 2010/11/21 05:31:38 - [] D -- C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 2010/11/21 09:06:51 - [] D -- C:\Program Files (x86)\Windows Sidebar O43 - CFD: 2015/08/07 15:00:38 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2015/08/07 15:00:46 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2015/08/07 15:30:11 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8 O43 - CFD: 2015/08/07 15:22:38 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2 O43 - CFD: 2015/08/07 15:00:41 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 2015/08/09 08:08:41 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager O43 - CFD: 2015/08/07 15:30:15 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller O43 - CFD: 2015/08/07 16:57:45 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack O43 - CFD: 2009/07/14 06:57:09 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2015/08/07 17:25:40 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office O43 - CFD: 2015/08/18 22:47:59 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Identity Safe O43 - CFD: 2015/08/07 16:57:04 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange PDF Viewer O43 - CFD: 2015/08/18 14:02:39 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 2010/11/21 09:16:46 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 2015/08/18 14:02:39 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith O43 - CFD: 2015/08/07 17:18:53 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp O43 - CFD: 2015/08/07 17:21:08 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinArp Spoofer O43 - CFD: 2015/08/07 16:47:16 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 2015/08/16 16:06:27 - [] D -- C:\ProgramData\Adobe O43 - CFD: 2009/07/14 07:08:56 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 2015/08/15 19:23:02 - [0] D -- C:\ProgramData\Babylon =>PUP.Optional.Babylon O43 - CFD: 2015/08/21 11:46:46 - [] D -- C:\ProgramData\boost_interprocess O43 - CFD: 2009/07/14 07:08:56 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 2009/07/14 07:08:56 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 2009/07/14 07:08:56 - [0] SHD -- C:\ProgramData\Favorites O43 - CFD: 2015/08/09 08:08:43 - [0] D -- C:\ProgramData\IDM O43 - CFD: 2015/08/07 16:52:36 - [] D -- C:\ProgramData\IObit O43 - CFD: 2015/08/15 01:42:45 - [] D -- C:\ProgramData\KONAMI O43 - CFD: 2015/08/21 02:39:33 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 2015/08/07 17:25:44 - [] D -- C:\ProgramData\Microsoft Help O43 - CFD: 2015/08/07 16:51:30 - [] D -- C:\ProgramData\Mozilla O43 - CFD: 2015/08/15 19:41:42 - [0] D -- C:\ProgramData\NCOTEMP O43 - CFD: 2015/08/18 23:32:10 - [] D -- C:\ProgramData\Norton O43 - CFD: 2015/08/18 22:48:29 - [] D -- C:\ProgramData\NortonInstaller O43 - CFD: 2015/08/07 16:17:34 - [] D -- C:\ProgramData\NVIDIA O43 - CFD: 2015/08/07 16:17:20 - [] D -- C:\ProgramData\NVIDIA Corporation O43 - CFD: 2015/08/18 14:03:00 - [] D -- C:\ProgramData\Package Cache O43 - CFD: 2015/08/14 19:27:49 - [] D -- C:\ProgramData\ProductData O43 - CFD: 2015/08/12 11:02:33 - [] D -- C:\ProgramData\Real O43 - CFD: 2015/08/09 09:52:07 - [] D -- C:\ProgramData\regid.1986-12.com.adobe O43 - CFD: 2015/08/18 14:02:39 - [] D -- C:\ProgramData\regid.1995-08.com.techsmith O43 - CFD: 2015/08/18 13:02:02 - [] D -- C:\ProgramData\Samsung O43 - CFD: 2009/07/14 07:08:56 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 2015/08/18 13:51:33 - [] D -- C:\ProgramData\TechSmith O43 - CFD: 2009/07/14 07:08:56 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 2015/08/07 15:30:15 - [0] D -- C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0} O43 - CFD: 2015/08/16 16:04:55 - [] D -- C:\Program Files (x86)\Common Files\Adobe O43 - CFD: 2015/08/07 17:22:19 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER O43 - CFD: 2015/08/09 08:09:35 - [] D -- C:\Program Files (x86)\Common Files\InstallShield O43 - CFD: 2015/08/07 15:30:12 - [] D -- C:\Program Files (x86)\Common Files\IObit O43 - CFD: 2015/08/07 17:22:27 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared O43 - CFD: 2015/08/07 17:18:49 - [] D -- C:\Program Files (x86)\Common Files\PX Storage Engine O43 - CFD: 2009/07/14 05:20:08 - [] D -- C:\Program Files (x86)\Common Files\Services O43 - CFD: 2009/07/14 05:20:08 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines O43 - CFD: 2015/08/15 19:52:41 - [0] D -- C:\Program Files (x86)\Common Files\Symantec Shared O43 - CFD: 2015/08/07 17:20:42 - [] D -- C:\Program Files (x86)\Common Files\System O43 - CFD: 2015/08/18 13:51:25 - [] D -- C:\Program Files (x86)\Common Files\TechSmith Shared O43 - CFD: 2015/08/18 13:22:12 - [] D -- C:\Users\habash\AppData\Roaming\Adobe O43 - CFD: 2015/08/07 15:30:14 - [] D -- C:\Users\habash\AppData\Roaming\Apple Computer O43 - CFD: 2015/08/15 19:23:02 - [] D -- C:\Users\habash\AppData\Roaming\Babylon =>PUP.Optional.Babylon O43 - CFD: 2015/08/21 05:03:45 - [] D -- C:\Users\habash\AppData\Roaming\DMCache O43 - CFD: 2015/08/07 15:05:11 - [] D -- C:\Users\habash\AppData\Roaming\Identities O43 - CFD: 2015/08/21 13:02:51 - [] D -- C:\Users\habash\AppData\Roaming\IDM O43 - CFD: 2015/08/07 15:30:16 - [] D -- C:\Users\habash\AppData\Roaming\IObit O43 - CFD: 2015/08/08 15:47:46 - [] D -- C:\Users\habash\AppData\Roaming\Macromedia O43 - CFD: 2010/11/21 09:16:46 - [0] D -- C:\Users\habash\AppData\Roaming\Media Center Programs O43 - CFD: 2015/08/20 16:43:42 - [] D -- C:\Users\habash\AppData\Roaming\Media Player Classic O43 - CFD: 2015/08/21 02:39:29 - [] SD -- C:\Users\habash\AppData\Roaming\Microsoft O43 - CFD: 2015/08/07 16:51:37 - [] D -- C:\Users\habash\AppData\Roaming\Mozilla O43 - CFD: 2015/08/09 09:59:31 - [] D -- C:\Users\habash\AppData\Roaming\NVIDIA O43 - CFD: 2015/08/12 11:07:02 - [] D -- C:\Users\habash\AppData\Roaming\Opera Software O43 - CFD: 2015/08/07 15:31:23 - [] D -- C:\Users\habash\AppData\Roaming\ProductData O43 - CFD: 2015/08/18 15:33:16 - [] D -- C:\Users\habash\AppData\Roaming\QuickStoresToolbar =>Toolbar.QuickStores O43 - CFD: 2015/08/12 11:02:26 - [] D -- C:\Users\habash\AppData\Roaming\Real O43 - CFD: 2015/08/18 13:02:47 - [] D -- C:\Users\habash\AppData\Roaming\Samsung O43 - CFD: 2015/08/07 17:20:24 - [] D -- C:\Users\habash\AppData\Roaming\Winamp O43 - CFD: 2015/08/07 16:47:27 - [] D -- C:\Users\habash\AppData\Roaming\WinRAR O43 - CFD: 2015/08/21 13:04:16 - [] D -- C:\Users\habash\AppData\Roaming\ZHP O43 - CFD: 2015/08/21 02:42:25 - [] D -- C:\Users\habash\AppData\Local\Adobe O43 - CFD: 2015/08/07 15:05:03 - [0] SHD -- C:\Users\habash\AppData\Local\Application Data O43 - CFD: 2015/08/18 13:51:39 - [] D -- C:\Users\habash\AppData\Local\assembly O43 - CFD: 2015/08/15 19:23:05 - [] D -- C:\Users\habash\AppData\Local\Babylon =>PUP.Optional.Babylon O43 - CFD: 2015/08/18 00:51:25 - [] D -- C:\Users\habash\AppData\Local\CrashDumps O43 - CFD: 2015/08/13 20:46:23 - [] D -- C:\Users\habash\AppData\Local\Downloaded Installations O43 - CFD: 2015/08/08 15:47:39 - [0] SHD -- C:\Users\habash\AppData\Local\EmieSiteList O43 - CFD: 2015/08/08 15:47:39 - [0] SHD -- C:\Users\habash\AppData\Local\EmieUserList O43 - CFD: 2015/08/07 17:00:15 - [] D -- C:\Users\habash\AppData\Local\Facebook O43 - CFD: 2015/08/07 16:53:14 - [] D -- C:\Users\habash\AppData\Local\Google O43 - CFD: 2015/08/07 15:05:03 - [0] SHD -- C:\Users\habash\AppData\Local\History O43 - CFD: 2015/08/08 16:11:18 - [] D -- C:\Users\habash\AppData\Local\Macromedia O43 - CFD: 2015/08/21 02:39:33 - [] D -- C:\Users\habash\AppData\Local\Microsoft O43 - CFD: 2015/08/07 17:20:29 - [0] D -- C:\Users\habash\AppData\Local\Microsoft Help O43 - CFD: 2015/08/07 16:58:38 - [] D -- C:\Users\habash\AppData\Local\Mozilla O43 - CFD: 2015/08/12 11:07:03 - [] D -- C:\Users\habash\AppData\Local\Opera Software O43 - CFD: 2015/08/07 15:07:46 - [] D -- C:\Users\habash\AppData\Local\Programs O43 - CFD: 2015/08/07 16:49:27 - [] D -- C:\Users\habash\AppData\Local\Real O43 - CFD: 2015/08/13 20:52:11 - [] D -- C:\Users\habash\AppData\Local\Samsung O43 - CFD: 2015/08/18 18:33:05 - [] D -- C:\Users\habash\AppData\Local\TechSmith O43 - CFD: 2015/08/21 13:04:20 - [] D -- C:\Users\habash\AppData\Local\Temp O43 - CFD: 2015/08/07 15:05:03 - [0] SHD -- C:\Users\habash\AppData\Local\Temporary Internet Files O43 - CFD: 2015/08/07 15:05:07 - [0] D -- C:\Users\habash\AppData\Local\VirtualStore O43 - CFD: 2009/07/14 06:54:32 - [] RD -- C:\Users\habash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 2015/08/12 14:36:49 - [] RD -- C:\Users\habash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 2015/08/07 16:53:22 - [] D -- C:\Users\habash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome O43 - CFD: 2015/08/09 08:08:41 - [] D -- C:\Users\habash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager O43 - CFD: 2009/07/14 06:49:38 - [] RD -- C:\Users\habash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 2015/08/07 17:21:56 - [] D -- C:\Users\habash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft Wireless Network Watcher O43 - CFD: 2015/08/12 14:36:49 - [] RD -- C:\Users\habash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 2015/08/18 15:39:51 - [] D -- C:\Users\habash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker O43 - CFD: 2015/08/07 17:18:53 - [] D -- C:\Users\habash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Detector Plug-in O43 - CFD: 2015/08/07 16:47:16 - [] D -- C:\Users\habash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR ---\\ System Drivers List (45) - 12s O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [491088] O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [339536] O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\drivers\adpu320.sys [182864] O58 - SDL:2009/07/14 03:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [15440] O58 - SDL:2014/06/14 13:51:07 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [107904] O58 - SDL:2009/07/14 03:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [194128] O58 - SDL:2014/06/14 13:51:07 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [27008] O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [87632] O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [97856] O58 - SDL:2015/08/18 14:10:58 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60a.sys [467224] O58 - SDL:2009/06/10 22:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [18432] O58 - SDL:2009/06/10 22:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [8704] O58 - SDL:2009/07/14 03:19:07 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [286720] O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [47104] O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [14976] O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [14720] O58 - SDL:2009/06/10 22:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [468480] O58 - SDL:2009/07/14 03:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [17488] O58 - SDL:2009/07/14 03:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [530496] O58 - SDL:2009/06/10 22:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3286016] O58 - SDL:2009/06/10 22:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [31232] O58 - SDL:2010/11/21 05:23:47 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [78720] O58 - SDL:2014/06/14 13:51:07 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [410496] O58 - SDL:2015/05/20 14:55:54 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\drivers\idmwfp.sys [197616] O58 - SDL:2009/07/14 03:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [44112] O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [114752] O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [106560] O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [65600] O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [115776] O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [35392] O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [284736] O58 - SDL:2009/07/14 03:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [51264] O58 - SDL:2015/08/07 16:17:02 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\Windows\System32\drivers\nvlddmkm.sys [12893896] O58 - SDL:2014/06/14 13:51:07 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [148352] O58 - SDL:2014/06/14 13:51:07 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [166272] O58 - SDL:2009/07/14 03:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1524816] O58 - SDL:2009/07/14 03:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [128592] O58 - SDL:2015/08/07 15:42:58 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RTKVHD64.sys [4514008] O58 - SDL:2009/06/10 22:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] O58 - SDL:2009/07/14 02:00:40 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) -- C:\Windows\System32\drivers\serial.sys [94208] O58 - SDL:2009/07/14 03:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [43584] O58 - SDL:2009/07/14 03:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [80464] O58 - SDL:2009/07/14 03:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [24656] O58 - SDL:2009/07/14 03:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [17488] O58 - SDL:2009/07/14 03:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [161872] ---\\ Last modified or created user files (20) - 5s O61 - LFC: 2015/08/18 15:39:35 A . (..) -- C:\Users\habash\Desktop\Unlocker1.9.1-x64.exe [818001] O61 - LFC: 2015/08/18 15:33:15 A . (..) -- C:\Users\habash\AppData\Roaming\QuickStoresToolbar\unins000.exe [704248] =>Toolbar.QuickStores O61 - LFC: 2015/08/18 13:22:13 A . (..) -- C:\Users\habash\AppData\Roaming\NVIDIA\GLCache\0e39299c3d4e8ba10aff7b1283d049fc\1fdc82f16ec7c53c\120e0757d771feba.bin [67986] O61 - LFC: 2015/08/18 20:51:19 A . (..) -- C:\Users\habash\AppData\Roaming\NVIDIA\GLCache\0e39299c3d4e8ba10aff7b1283d049fc\1fdc82f16ec7c53c\2ad2147cf33d62a7.bin [330239] O61 - LFC: 2015/08/21 11:46:34 A . (.Tonec Inc..) -- C:\Users\habash\AppData\Roaming\IDM\idmmzcc5\components2\idmcchandler2.dll [332824] O61 - LFC: 2015/08/21 11:46:34 A . (.Tonec Inc..) -- C:\Users\habash\AppData\Roaming\IDM\idmmzcc5\components2\idmcchandler2_64.dll [460824] O61 - LFC: 2015/08/21 11:46:34 A . (.Tonec Inc..) -- C:\Users\habash\AppData\Roaming\IDM\idmmzcc5\components2\idmmzcc.dll [34216] O61 - LFC: 2015/08/21 11:46:34 A . (.Tonec Inc..) -- C:\Users\habash\AppData\Roaming\IDM\idmmzcc5\components2\idmmzcc64.dll [28512] O61 - LFC: 2015/08/21 11:46:34 A . (.Tonec Inc..) -- C:\Users\habash\AppData\Roaming\IDM\idmmzcc5\components12\idmmzcc.dll [26648] O61 - LFC: 2015/08/21 11:46:34 A . (.Tonec Inc..) -- C:\Users\habash\AppData\Roaming\IDM\idmmzcc5\components12\idmmzcc64.dll [31768] O61 - LFC: 2015/08/21 11:46:34 A . (.Tonec Inc..) -- C:\Users\habash\AppData\Roaming\IDM\idmmzcc5\components\idmmzcc.dll [34216] O61 - LFC: 2015/08/21 05:03:32 A . (..) -- C:\Users\habash\AppData\Local\TechSmith\SnagIt\Tray.bin [688] O61 - LFC: 2015/08/21 11:49:07 A . (..) -- C:\Users\habash\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [1113849] O61 - LFC: 2015/08/21 11:49:16 A . (..) -- C:\Users\habash\AppData\Local\Google\Chrome\User Data\nacl_validation_cache.bin [164] O61 - LFC: 2015/08/18 13:51:39 A . (.Copyright © 2014.) -- C:\Users\habash\AppData\Local\assembly\dl3\63RHYDDY.9AY\PO4THHJB.RBB\eb3569cc\803e060e_5fedcf01\TechSmith.WPF.DLL [26112] O61 - LFC: 2015/08/18 14:02:47 A . (.Copyright © 2014.) -- C:\Users\habash\AppData\Local\assembly\dl3\63RHYDDY.9AY\PO4THHJB.RBB\eb3569cc\00e9d8f6_7d9cd001\TechSmith.WPF.DLL [26112] O61 - LFC: 2015/08/18 13:51:41 A . (.Copyright © 2014.) -- C:\Users\habash\AppData\Local\assembly\dl3\63RHYDDY.9AY\PO4THHJB.RBB\ded2e373\803e060e_5fedcf01\TechSmith.WPF.DLL [26112] O61 - LFC: 2015/08/18 14:02:47 A . (.Copyright © 2014.) -- C:\Users\habash\AppData\Local\assembly\dl3\63RHYDDY.9AY\PO4THHJB.RBB\ded2e373\00e9d8f6_7d9cd001\TechSmith.WPF.DLL [26112] O61 - LFC: 2015/08/18 13:51:45 A . (..) -- C:\Users\habash\AppData\Local\assembly\dl3\63RHYDDY.9AY\PO4THHJB.RBB\4bc443a3\809f49ae_6b19d001\Interop.SNAGITLib.DLL [110592] O61 - LFC: 2015/08/18 14:02:49 A . (..) -- C:\Users\habash\AppData\Local\assembly\dl3\63RHYDDY.9AY\PO4THHJB.RBB\4bc443a3\00296891_35a8d001\Interop.SNAGITLib.DLL [110592] ---\\ File Associations Shell Spawning (11) - 0s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\launcher.exe O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\launcher.exe ---\\ Start Menu Internet (12) - 0s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\Launcher.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\launcher.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\launcher.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\launcher.exe ---\\ Search Browser Infection (1) - 2s O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ ---\\ Search Svchost Services (33) - 1s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\Windows\System32\aelupsvc.dll [72192] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [80384] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [80384] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\Windows\system32\srvsvc.dll [236032] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\Windows\System32\gpsvc.dll [777728] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\ikeext.dll [859648] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\Windows\System32\Audiosrv.dll [680960] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\Windows\System32\rasauto.dll [99328] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [344064] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [97792] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\Windows\System32\Sens.dll [64512] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [359424] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [316928] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remote Desktop Session Host Server Remote C.) -- C:\Windows\System32\termsrv.dll [683520] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\system32\wuaueng.dll [2606080] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\Windows\System32\qmgr.dll [849920] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [370688] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [569344] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\Windows\system32\seclogon.dll [30720] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\Windows\System32\appinfo.dll [70656] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\Windows\system32\iscsiexe.dll [156672] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) -- C:\Windows\system32\mmcss.dll [67584] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [242688] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [121856] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\Windows\System32\browser.dll [136704] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [111104] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\Windows\system32\schedsvc.dll [1110016] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\Windows\system32\kmsvc.dll [90624] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\Windows\System32\wercplsupport.dll [84480] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [210432] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\Windows\system32\themeservice.dll [44544] O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\Windows\System32\bdesvc.dll [100864] O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Software installation Service.) -- C:\Windows\System32\appmgmts.dll [193536] ---\\ Services not Microsoft (SR=Run, SS=Stop) (9) - 6s SS - Demand [2015/08/12 19:47:56] [ 269000] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe SR - Auto [2015/07/22 15:33:12] [ 680112] (AdobeUpdateService) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe SR - Auto [2015/04/03 15:42:26] [ 814880] Advanced SystemCare Service 8 (AdvancedSystemCareService8) . (.IObit.) - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe SS - Auto [2015/08/07 15:32:31] [ 2909472] LiveUpdate (LiveUpdateSvc) . (.IObit.) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe SS - Demand [2015/08/06 13:12:18] [ 148136] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe SR - Auto [2015/03/05 10:46:07] [ 131144] Norton Identity Safe (NCO) . (.Symantec Corporation.) - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.11.42\NST.exe SR - Auto [2015/04/26 18:33:19] [ 932040] NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe SS - Demand [2010/02/19 13:37:14] [ 517096] (SwitchBoard) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe SR - Auto [2015/01/26 08:48:10] [ 3408384] TechSmith Uploader Service (TechSmith Uploader Service) . (.TechSmith Corporation.) - C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe ---\\ Additional Scan (O88) (9) - 0s C:\Users\habash\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf C:\Users\habash\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\yahoo.xml =>PUP.Optional.BDYahoo HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\QuickStores-Toolbar_is1 =>Toolbar.QuickStores C:\ProgramData\Babylon =>PUP.Optional.Babylon C:\Users\habash\AppData\Roaming\Babylon =>PUP.Optional.Babylon C:\Users\habash\AppData\Roaming\QuickStoresToolbar =>Toolbar.QuickStores C:\Users\habash\AppData\Local\Babylon =>PUP.Optional.Babylon C:\Users\habash\AppData\Roaming\QuickStoresToolbar\unins000.exe =>Toolbar.QuickStores ---\\ Summary of the elements found (5) - 0s http://www.nicolascoolman.fr/adware-bandoo/ =>PUP.Optional.Bandoo http://www.nicolascoolman.fr/blog =>Toolbar.AVGSearch http://www.nicolascoolman.fr/blog =>Toolbar.QuickStores http://www.nicolascoolman.fr/blog =>PUP.Optional.BDYahoo http://www.nicolascoolman.fr/pup-babylon/ =>PUP.Optional.Babylon ~ End of the scan, 23918 items in 60 seconds (647)(0)()