OTL logfile created on: 06/04/2016 20:22:10 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Sawab\Desktop 64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.18231) Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy 3,45 Gb Total Physical Memory | 2,08 Gb Available Physical Memory | 60,31% Memory free 4,08 Gb Paging File | 2,47 Gb Available in Paging File | 60,63% Paging File free Paging file location(s): ?:\pagefile.sys %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 907,04 Gb Total Space | 861,14 Gb Free Space | 94,94% Space Free | Partition Type: NTFS Drive D: | 23,45 Gb Total Space | 2,60 Gb Free Space | 11,10% Space Free | Partition Type: NTFS Drive F: | 7,50 Gb Total Space | 7,42 Gb Free Space | 98,96% Space Free | Partition Type: NTFS Computer Name: SAWÂB-PC | User Name: Sawab | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (All) ==========[/color] PRC - [2016/04/06 01:10:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Sawab\Desktop\OTL.exe PRC - [2016/04/02 16:43:10 | 000,330,752 | ---- | M] () -- C:\Program Files (x86)\D68F83A4-1459610434-E511-A26A-5820B16785B8\knsz798F.tmpfs PRC - [2016/03/16 05:24:00 | 005,716,560 | ---- | M] (FreeDownloadManager.ORG) -- C:\Program Files (x86)\Free Download Manager\fdm.exe PRC - [2016/03/03 11:18:55 | 000,465,088 | ---- | M] () -- C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe PRC - [2016/02/15 12:56:58 | 046,344,704 | ---- | M] () -- C:\Program Files (x86)\CleanBrowser\app\bin\nw.exe PRC - [2016/01/08 11:47:10 | 001,433,216 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe PRC - [2016/01/08 11:44:00 | 001,773,696 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe PRC - [2015/02/17 10:39:42 | 000,654,088 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe PRC - [2015/02/17 10:39:10 | 000,608,520 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe PRC - [2015/02/11 14:02:58 | 000,267,224 | ---- | M] (CyberLink Corp.) -- c:\Program Files (x86)\Cyberlink\YouCam\YouCamService.exe PRC - [2015/02/09 20:54:26 | 000,347,200 | ---- | M] (WildTangent) -- C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [color=#E56717]========== Modules (All) ==========[/color] MOD - [2016/04/06 01:10:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Sawab\Desktop\OTL.exe MOD - [2016/03/16 05:24:00 | 005,716,560 | ---- | M] (FreeDownloadManager.ORG) -- C:\Program Files (x86)\Free Download Manager\fdm.exe MOD - [2016/03/16 05:24:00 | 004,932,688 | ---- | M] () -- C:\Program Files (x86)\Free Download Manager\fdmbtsupp.dll MOD - [2016/02/15 12:57:00 | 003,466,856 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\CleanBrowser\app\bin\d3dcompiler_47.dll MOD - [2016/02/15 12:56:58 | 046,344,704 | ---- | M] () -- C:\Program Files (x86)\CleanBrowser\app\bin\nw.exe MOD - [2016/02/15 12:56:58 | 001,481,728 | ---- | M] () -- C:\Program Files (x86)\CleanBrowser\app\bin\libGLESv2.dll MOD - [2016/02/15 12:56:58 | 000,073,728 | ---- | M] () -- C:\Program Files (x86)\CleanBrowser\app\bin\libEGL.dll MOD - [2016/02/15 12:56:12 | 001,681,224 | ---- | M] () -- C:\Program Files (x86)\CleanBrowser\app\bin\ffmpegsumo.dll MOD - [2016/02/08 23:05:38 | 020,352,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mshtml.dll MOD - [2016/02/08 22:34:36 | 002,280,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\iertutil.dll MOD - [2016/02/08 22:02:58 | 013,012,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ieframe.dll MOD - [2016/02/08 21:43:04 | 002,121,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wininet.dll MOD - [2016/02/08 21:39:31 | 001,311,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\urlmon.dll MOD - [2016/02/03 22:36:57 | 001,212,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ole32.dll MOD - [2016/02/03 17:09:37 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\olepro32.dll MOD - [2016/01/22 09:11:11 | 019,794,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shell32.dll MOD - [2016/01/19 20:23:58 | 001,564,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\combase.dll MOD - [2016/01/19 20:23:33 | 001,501,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntdll.dll MOD - [2016/01/19 19:30:39 | 000,862,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\KernelBase.dll MOD - [2016/01/09 03:49:43 | 000,192,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rsaenh.dll MOD - [2015/12/08 21:07:49 | 000,507,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\advapi32.dll MOD - [2015/12/05 07:58:26 | 000,081,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\devenum.dll MOD - [2015/12/04 17:00:36 | 001,097,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\gdi32.dll MOD - [2015/12/03 20:52:09 | 000,340,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\bcryptprimitives.dll MOD - [2015/12/03 19:06:36 | 001,501,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\quartz.dll MOD - [2015/11/08 22:52:10 | 001,559,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\DWrite.dll MOD - [2015/11/08 22:48:20 | 001,376,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\user32.dll MOD - [2015/11/08 22:42:50 | 001,490,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.18123_none_dad9a2585bcb0fd8\GdiPlus.dll MOD - [2015/10/03 21:41:47 | 001,124,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msctf.dll MOD - [2015/09/02 19:09:35 | 001,556,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msxml3.dll MOD - [2015/08/06 19:20:31 | 002,105,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.18006_none_a9ec6aab013aafee\comctl32.dll MOD - [2015/08/06 18:18:28 | 004,068,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d2d1.dll MOD - [2015/06/27 18:42:34 | 000,747,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rpcrt4.dll MOD - [2015/06/27 13:58:44 | 001,488,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WindowsCodecs.dll MOD - [2015/06/27 13:54:30 | 000,560,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\SHCore.dll MOD - [2015/06/27 04:55:30 | 000,061,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.6195_none_03ce2c72205943d3\mfc80FRA.dll MOD - [2015/06/27 04:55:28 | 001,093,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.6195_none_cbf5e994470a1a8f\mfc80u.dll MOD - [2015/04/25 04:33:20 | 000,549,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.9600.17810_none_7c5b6194aa0716f1\comctl32.dll MOD - [2015/04/13 10:05:10 | 000,602,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oleaut32.dll MOD - [2015/04/13 10:03:45 | 001,142,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vssapi.dll MOD - [2015/04/13 10:03:45 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vsstrace.dll MOD - [2015/04/13 09:58:27 | 001,612,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\crypt32.dll MOD - [2015/04/01 04:31:00 | 001,207,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dbghelp.dll MOD - [2015/03/27 15:14:07 | 000,126,848 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWOW64\atiuxpag.dll MOD - [2015/03/27 15:13:56 | 009,406,112 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWOW64\atidxx32.dll MOD - [2015/03/27 15:13:55 | 001,133,128 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWOW64\aticfx32.dll MOD - [2015/03/23 23:45:04 | 000,257,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sechost.dll MOD - [2015/02/17 10:39:42 | 000,654,088 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe MOD - [2015/02/11 14:02:58 | 000,267,224 | ---- | M] (CyberLink Corp.) -- c:\Program Files (x86)\Cyberlink\YouCam\YouCamService.exe MOD - [2015/02/11 14:02:41 | 000,349,144 | ---- | M] (CyberLink) -- c:\Program Files (x86)\Cyberlink\YouCam\subsys\PyFaceLogin\CLWFL.dll MOD - [2014/11/21 07:15:25 | 000,080,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\bcd.dll MOD - [2014/11/21 07:15:24 | 000,060,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\srclient.dll MOD - [2014/11/21 07:15:23 | 000,224,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\spp.dll MOD - [2014/11/21 07:15:22 | 000,800,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msvcrt.dll MOD - [2014/11/21 07:15:22 | 000,397,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winspool.drv MOD - [2014/11/21 07:15:21 | 000,101,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx MOD - [2014/11/21 07:14:59 | 000,631,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winhttp.dll MOD - [2014/11/21 07:14:59 | 000,120,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\IPHLPAPI.DLL MOD - [2014/11/21 07:14:56 | 000,286,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mswsock.dll MOD - [2014/11/21 07:14:56 | 000,241,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cfgmgr32.dll MOD - [2014/11/21 07:14:56 | 000,154,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntmarta.dll MOD - [2014/11/21 07:14:56 | 000,127,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\devobj.dll MOD - [2014/11/21 07:14:56 | 000,111,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\bcrypt.dll MOD - [2014/11/21 07:14:56 | 000,110,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\srvcli.dll MOD - [2014/11/21 07:14:56 | 000,098,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\userenv.dll MOD - [2014/11/21 07:14:56 | 000,096,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptsp.dll MOD - [2014/11/21 07:14:56 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\samlib.dll MOD - [2014/11/21 07:14:56 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\samcli.dll MOD - [2014/11/21 07:14:56 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dhcpcsvc.dll MOD - [2014/11/21 07:14:56 | 000,059,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wkscli.dll MOD - [2014/11/21 07:14:56 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dhcpcsvc6.dll MOD - [2014/11/21 07:14:56 | 000,051,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msasn1.dll MOD - [2014/11/21 07:14:56 | 000,035,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\netutils.dll MOD - [2014/11/21 07:14:56 | 000,021,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dsrole.dll MOD - [2014/11/21 07:14:51 | 000,192,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mlang.dll MOD - [2014/11/21 07:14:50 | 000,278,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shlwapi.dll MOD - [2014/11/21 07:14:50 | 000,026,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\version.dll MOD - [2014/11/21 07:14:48 | 001,287,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\propsys.dll MOD - [2014/11/21 07:14:48 | 000,949,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\uxtheme.dll MOD - [2014/11/21 07:14:48 | 000,609,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll MOD - [2014/11/21 07:14:45 | 000,065,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\nlaapi.dll MOD - [2014/11/21 07:14:45 | 000,027,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\OnDemandConnRouteHelper.dll MOD - [2014/11/21 07:14:44 | 000,016,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wsock32.dll MOD - [2014/11/21 07:14:41 | 000,321,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ws2_32.dll MOD - [2014/11/21 07:14:41 | 000,104,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sspicli.dll MOD - [2014/11/21 07:14:41 | 000,052,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\profapi.dll MOD - [2014/11/21 07:14:41 | 000,030,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptbase.dll MOD - [2014/11/21 07:14:40 | 000,245,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wintrust.dll MOD - [2014/11/21 07:14:40 | 000,068,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\netapi32.dll MOD - [2014/11/21 07:14:40 | 000,024,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\secur32.dll MOD - [2014/11/21 07:14:38 | 000,569,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\clbcatq.dll MOD - [2014/11/21 07:14:35 | 001,040,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\kernel32.dll MOD - [2014/11/21 07:14:35 | 000,642,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\apphelp.dll MOD - [2014/11/21 07:14:34 | 000,029,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\kernel.appcore.dll MOD - [2014/11/21 07:14:34 | 000,016,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\psapi.dll MOD - [2014/11/21 07:14:33 | 001,782,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\setupapi.dll MOD - [2014/11/21 07:14:32 | 000,499,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sxs.dll MOD - [2014/11/21 07:14:32 | 000,255,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\powrprof.dll MOD - [2014/11/21 07:14:29 | 000,786,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\fastprox.dll MOD - [2014/11/21 07:14:29 | 000,401,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbemcomn.dll MOD - [2014/11/21 07:14:28 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\wbemsvc.dll MOD - [2014/11/21 07:14:28 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\wbemprox.dll MOD - [2014/11/21 07:13:25 | 000,370,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\AudioSes.dll MOD - [2014/11/21 07:13:23 | 000,123,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msvfw32.dll MOD - [2014/11/21 07:13:23 | 000,039,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msdmo.dll MOD - [2014/11/21 07:13:22 | 000,331,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\MMDevAPI.dll MOD - [2014/11/21 07:13:22 | 000,136,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winmm.dll MOD - [2014/11/21 07:13:22 | 000,134,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winmmbase.dll MOD - [2014/11/21 07:13:14 | 001,907,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d9.dll MOD - [2014/11/21 07:13:14 | 000,503,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mscms.dll MOD - [2014/11/21 07:13:14 | 000,306,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oleacc.dll MOD - [2014/11/21 07:13:14 | 000,193,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msls31.dll MOD - [2014/11/21 07:13:14 | 000,141,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imm32.dll MOD - [2014/11/21 07:13:14 | 000,102,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dwmapi.dll MOD - [2014/11/21 07:13:14 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msimg32.dll MOD - [2014/11/21 07:13:13 | 000,077,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\usp10.dll MOD - [2014/11/21 07:13:11 | 000,036,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msimtf.dll MOD - [2014/11/21 07:13:09 | 002,174,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d10warp.dll MOD - [2014/11/21 07:13:09 | 001,946,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d11.dll MOD - [2014/11/21 07:13:09 | 000,430,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dxgi.dll MOD - [2014/11/21 07:13:07 | 000,276,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winsta.dll MOD - [2014/11/21 07:13:07 | 000,052,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wtsapi32.dll MOD - [2014/11/21 07:12:54 | 000,026,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winnsi.dll MOD - [2014/11/21 07:12:54 | 000,020,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\nsi.dll MOD - [2014/08/05 10:58:30 | 000,970,912 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Free Download Manager\msvcr120.dll MOD - [2014/08/05 10:58:30 | 000,455,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Free Download Manager\msvcp120.dll MOD - [2013/10/05 01:38:22 | 004,449,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Free Download Manager\mfc120u.dll MOD - [2013/08/22 05:50:04 | 000,179,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\qcap.dll MOD - [2013/08/17 02:06:29 | 000,626,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.8428_none_d08a11e2442dc25d\msvcr80.dll MOD - [2013/08/17 02:06:29 | 000,548,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.8428_none_d08a11e2442dc25d\msvcp80.dll MOD - [2013/05/09 12:09:45 | 000,020,032 | ---- | M] (TODO: ) -- c:\Program Files (x86)\Cyberlink\YouCam\Custom\Lang\FRA\IM.dll MOD - [2011/08/30 23:05:02 | 000,121,704 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Bonjour\mdnsNSP.dll [color=#E56717]========== Services (All) ==========[/color] SRV:[b]64bit:[/b] - [2016/04/02 18:45:37 | 000,237,096 | ---- | M] (AVAST Software) [Auto | Stopped] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV:[b]64bit:[/b] - [2016/03/03 11:18:55 | 000,465,088 | ---- | M] () [Auto | Running] -- C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe -- (SecureLine) SRV:[b]64bit:[/b] - [2016/02/12 17:14:02 | 003,708,416 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv) SRV:[b]64bit:[/b] - [2016/02/06 20:08:28 | 000,031,744 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\seclogon.dll -- (seclogon) SRV:[b]64bit:[/b] - [2016/01/06 18:47:23 | 000,146,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc) SRV:[b]64bit:[/b] - [2015/12/20 16:57:54 | 000,839,168 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon) SRV:[b]64bit:[/b] - [2015/12/02 17:05:12 | 001,694,152 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\CSP\1.8.203.0\McCSPServiceHost.exe -- (mccspsvc) SRV:[b]64bit:[/b] - [2015/11/10 21:15:34 | 000,863,448 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\MSC\McAPExe.exe -- (McAPExe) SRV:[b]64bit:[/b] - [2015/11/08 23:13:56 | 001,383,936 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\FntCache.dll -- (FontCache) SRV:[b]64bit:[/b] - [2015/11/02 21:12:02 | 000,451,960 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe -- (MSK80Service) SRV:[b]64bit:[/b] - [2015/11/02 21:12:02 | 000,451,960 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe -- (McProxy) SRV:[b]64bit:[/b] - [2015/11/02 21:12:02 | 000,451,960 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe -- (mcpltsvc) SRV:[b]64bit:[/b] - [2015/11/02 21:12:02 | 000,451,960 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe -- (McOobeSv2) SRV:[b]64bit:[/b] - [2015/11/02 21:12:02 | 000,451,960 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe -- (McNaiAnn) SRV:[b]64bit:[/b] - [2015/11/02 21:12:02 | 000,451,960 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe -- (McMPFSvc) SRV:[b]64bit:[/b] - [2015/11/02 21:12:02 | 000,451,960 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe -- (HomeNetSvc) SRV:[b]64bit:[/b] - [2015/10/21 11:29:22 | 000,378,848 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe -- (mfemms) SRV:[b]64bit:[/b] - [2015/10/20 19:13:26 | 000,679,120 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\mcafee\VirusScan\mcods.exe -- (McODS) SRV:[b]64bit:[/b] - [2015/10/08 18:08:57 | 001,083,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\IKEEXT.DLL -- (IKEEXT) SRV:[b]64bit:[/b] - [2015/09/24 18:42:22 | 000,348,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\bdesvc.dll -- (BDESVC) SRV:[b]64bit:[/b] - [2015/09/21 14:33:34 | 000,256,840 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp) SRV:[b]64bit:[/b] - [2015/09/21 14:31:26 | 000,233,680 | ---- | M] () [On_Demand | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire) SRV:[b]64bit:[/b] - [2015/08/10 20:15:56 | 000,845,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\BFE.DLL -- (BFE) SRV:[b]64bit:[/b] - [2015/08/01 16:22:36 | 000,039,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appidsvc.dll -- (AppIDSvc) SRV:[b]64bit:[/b] - [2015/08/01 05:38:35 | 001,265,152 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule) SRV:[b]64bit:[/b] - [2015/07/22 15:52:08 | 001,633,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack) SRV:[b]64bit:[/b] - [2015/07/16 20:58:34 | 000,074,752 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup) SRV:[b]64bit:[/b] - [2015/07/10 19:54:09 | 001,217,024 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\sysmain.dll -- (SysMain) SRV:[b]64bit:[/b] - [2015/07/09 18:14:45 | 000,228,864 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc) SRV:[b]64bit:[/b] - [2015/07/07 11:39:32 | 000,366,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc) SRV:[b]64bit:[/b] - [2015/07/07 11:39:32 | 000,023,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend) SRV:[b]64bit:[/b] - [2015/07/02 00:19:08 | 000,228,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WebClnt.dll -- (WebClient) SRV:[b]64bit:[/b] - [2015/06/16 00:41:04 | 000,065,024 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msiexec.exe -- (msiserver) SRV:[b]64bit:[/b] - [2015/05/30 21:36:24 | 000,230,400 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder) SRV:[b]64bit:[/b] - [2015/05/30 21:35:47 | 000,911,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (Audiosrv) SRV:[b]64bit:[/b] - [2015/05/12 15:19:37 | 000,294,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker) SRV:[b]64bit:[/b] - [2015/05/07 17:21:51 | 000,522,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc) SRV:[b]64bit:[/b] - [2015/04/13 10:07:43 | 000,391,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc) SRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 001,454,080 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS) SRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 000,827,392 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler) SRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 000,252,416 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache) SRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 000,076,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\inetsrv\w3logsvc.dll -- (w3logsvc) SRV:[b]64bit:[/b] - [2015/04/13 09:56:47 | 001,356,800 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\gpsvc.dll -- (gpsvc) SRV:[b]64bit:[/b] - [2015/04/01 05:17:33 | 000,903,168 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SearchIndexer.exe -- (WSearch) SRV:[b]64bit:[/b] - [2015/03/27 15:13:56 | 000,246,272 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:[b]64bit:[/b] - [2015/03/06 04:47:37 | 001,696,256 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (EventLog) SRV:[b]64bit:[/b] - [2015/03/05 13:25:12 | 000,293,080 | ---- | M] (Realtek Semiconductor) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe -- (RtkAudioService) SRV:[b]64bit:[/b] - [2015/03/04 22:31:40 | 000,138,752 | ---- | M] () [Auto | Stopped] -- c:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe -- (AdaptiveSleepService) SRV:[b]64bit:[/b] - [2015/03/04 22:31:18 | 000,344,064 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- c:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service) SRV:[b]64bit:[/b] - [2015/03/03 06:20:19 | 000,220,840 | ---- | M] (Synaptics Incorporated) [Auto | Running] -- C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe -- (SynTPEnhService) SRV:[b]64bit:[/b] - [2015/02/21 01:49:18 | 000,780,800 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM) SRV:[b]64bit:[/b] - [2015/01/30 19:11:28 | 000,103,424 | ---- | M] (Softex Inc.) [Auto | Running] -- C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe -- (omniserv) SRV:[b]64bit:[/b] - [2014/12/10 07:11:41 | 000,546,304 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\inetsrv\iisw3adm.dll -- (WAS) SRV:[b]64bit:[/b] - [2014/12/10 07:11:39 | 000,066,048 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\inetsrv\apphostsvc.dll -- (AppHostSvc) SRV:[b]64bit:[/b] - [2014/11/21 11:52:24 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService) SRV:[b]64bit:[/b] - [2014/11/21 07:15:25 | 001,478,144 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:15:23 | 000,445,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\provsvc.dll -- (HomeGroupProvider) SRV:[b]64bit:[/b] - [2014/11/21 07:15:23 | 000,275,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ListSvc.dll -- (HomeGroupListener) SRV:[b]64bit:[/b] - [2014/11/21 07:15:21 | 000,300,032 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\umrdp.dll -- (UmRdpService) SRV:[b]64bit:[/b] - [2014/11/21 07:15:15 | 000,086,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wpdbusenum.dll -- (WPDBusEnum) SRV:[b]64bit:[/b] - [2014/11/21 07:15:14 | 000,440,832 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\p2psvc.dll -- (p2psvc) SRV:[b]64bit:[/b] - [2014/11/21 07:15:14 | 000,380,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pnrpsvc.dll -- (PNRPsvc) SRV:[b]64bit:[/b] - [2014/11/21 07:15:14 | 000,380,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pnrpsvc.dll -- (p2pimsvc) SRV:[b]64bit:[/b] - [2014/11/21 07:15:14 | 000,026,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pnrpauto.dll -- (PNRPAutoReg) SRV:[b]64bit:[/b] - [2014/11/21 07:15:13 | 000,012,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wpcsvc.dll -- (WPCSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:15:12 | 000,243,200 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sensrsvc.dll -- (SensrSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:15:12 | 000,154,112 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService) SRV:[b]64bit:[/b] - [2014/11/21 07:15:00 | 000,658,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FXSSVC.exe -- (Fax) SRV:[b]64bit:[/b] - [2014/11/21 07:14:59 | 001,668,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc) SRV:[b]64bit:[/b] - [2014/11/21 07:14:26 | 000,108,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wersvc.dll -- (WerSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:14:26 | 000,084,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wercplsupport.dll -- (wercplsupport) SRV:[b]64bit:[/b] - [2014/11/21 07:14:17 | 000,043,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WcsPlugInService.dll -- (WcsPlugInService) SRV:[b]64bit:[/b] - [2014/11/21 07:14:16 | 001,114,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\termsrv.dll -- (TermService) SRV:[b]64bit:[/b] - [2014/11/21 07:14:16 | 000,339,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SessEnv.dll -- (SessionEnv) SRV:[b]64bit:[/b] - [2014/11/21 07:14:15 | 000,640,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection) SRV:[b]64bit:[/b] - [2014/11/21 07:14:14 | 000,059,392 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes) SRV:[b]64bit:[/b] - [2014/11/21 07:14:11 | 000,562,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness) SRV:[b]64bit:[/b] - [2014/11/21 07:14:06 | 000,313,344 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv) SRV:[b]64bit:[/b] - [2014/11/21 07:14:05 | 000,670,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc) SRV:[b]64bit:[/b] - [2014/11/21 07:14:05 | 000,067,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc) SRV:[b]64bit:[/b] - [2014/11/21 07:14:02 | 001,547,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wlansvc.dll -- (WlanSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:14:02 | 000,465,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wcncsvc.dll -- (wcncsvc) SRV:[b]64bit:[/b] - [2014/11/21 07:14:01 | 000,457,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\upnphost.dll -- (upnphost) SRV:[b]64bit:[/b] - [2014/11/21 07:14:01 | 000,266,752 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netman.dll -- (Netman) SRV:[b]64bit:[/b] - [2014/11/21 07:14:01 | 000,262,144 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc) SRV:[b]64bit:[/b] - [2014/11/21 07:14:01 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto) SRV:[b]64bit:[/b] - [2014/11/21 07:14:00 | 000,926,208 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\iphlpsvc.dll -- (iphlpsvc) SRV:[b]64bit:[/b] - [2014/11/21 07:14:00 | 000,446,464 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\QAGENTRT.DLL -- (napagent) SRV:[b]64bit:[/b] - [2014/11/21 07:14:00 | 000,374,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc) SRV:[b]64bit:[/b] - [2014/11/21 07:14:00 | 000,249,344 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ssdpsrv.dll -- (SSDPSRV) SRV:[b]64bit:[/b] - [2014/11/21 07:14:00 | 000,101,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\KMSVC.DLL -- (hkmsvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:59 | 000,550,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm) SRV:[b]64bit:[/b] - [2014/11/21 07:13:59 | 000,452,608 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess) SRV:[b]64bit:[/b] - [2014/11/21 07:13:59 | 000,397,312 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent) SRV:[b]64bit:[/b] - [2014/11/21 07:13:59 | 000,303,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\qwave.dll -- (QWAVE) SRV:[b]64bit:[/b] - [2014/11/21 07:13:59 | 000,279,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lltdsvc.dll -- (lltdsvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:59 | 000,110,592 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\eapsvc.dll -- (Eaphost) SRV:[b]64bit:[/b] - [2014/11/21 07:13:59 | 000,014,848 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\snmptrap.exe -- (SNMPTRAP) SRV:[b]64bit:[/b] - [2014/11/21 07:13:56 | 000,880,640 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\MPSSVC.dll -- (MpsSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:56 | 000,542,208 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasmans.dll -- (RasMan) SRV:[b]64bit:[/b] - [2014/11/21 07:13:56 | 000,226,816 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\mprdim.dll -- (RemoteAccess) SRV:[b]64bit:[/b] - [2014/11/21 07:13:56 | 000,166,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:56 | 000,142,848 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sstpsvc.dll -- (SstpSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:56 | 000,096,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG) SRV:[b]64bit:[/b] - [2014/11/21 07:13:55 | 000,513,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wwansvc.dll -- (WwanSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:55 | 000,071,168 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\mmcss.dll -- (THREADORDER) SRV:[b]64bit:[/b] - [2014/11/21 07:13:55 | 000,071,168 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\mmcss.dll -- (MMCSS) SRV:[b]64bit:[/b] - [2014/11/21 07:13:45 | 003,460,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService) SRV:[b]64bit:[/b] - [2014/11/21 07:13:43 | 000,111,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AxInstSv.dll -- (AxInstSV) SRV:[b]64bit:[/b] - [2014/11/21 07:13:43 | 000,110,080 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo) SRV:[b]64bit:[/b] - [2014/11/21 07:13:43 | 000,041,984 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\UI0Detect.exe -- (UI0Detect) SRV:[b]64bit:[/b] - [2014/11/21 07:13:43 | 000,026,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC) SRV:[b]64bit:[/b] - [2014/11/21 07:13:42 | 001,639,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:42 | 000,041,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS) SRV:[b]64bit:[/b] - [2014/11/21 07:13:40 | 000,194,048 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\SCardSvr.dll -- (SCardSvr) SRV:[b]64bit:[/b] - [2014/11/21 07:13:40 | 000,156,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\certprop.dll -- (SCPolicySvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:40 | 000,156,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\certprop.dll -- (CertPropSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:40 | 000,131,072 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum) SRV:[b]64bit:[/b] - [2014/11/21 07:13:39 | 000,411,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\w32time.dll -- (W32Time) SRV:[b]64bit:[/b] - [2014/11/21 07:13:39 | 000,260,608 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:39 | 000,154,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\TabSvc.dll -- (TabletInputService) SRV:[b]64bit:[/b] - [2014/11/21 07:13:38 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\iscsiexe.dll -- (MSiSCSI) SRV:[b]64bit:[/b] - [2014/11/21 07:13:38 | 000,104,960 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\WUDFSvc.dll -- (wudfsvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:38 | 000,094,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\bthserv.dll -- (bthserv) SRV:[b]64bit:[/b] - [2014/11/21 07:13:38 | 000,033,792 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\hidserv.dll -- (hidserv) SRV:[b]64bit:[/b] - [2014/11/21 07:13:38 | 000,020,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\StorSvc.dll -- (StorSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:37 | 000,516,608 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\es.dll -- (EventSystem) SRV:[b]64bit:[/b] - [2014/11/21 07:13:37 | 000,373,248 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msdtckrm.dll -- (KtmRm) SRV:[b]64bit:[/b] - [2014/11/21 07:13:37 | 000,144,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msdtc.exe -- (MSDTC) SRV:[b]64bit:[/b] - [2014/11/21 07:13:37 | 000,124,416 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\trkwks.dll -- (TrkWks) SRV:[b]64bit:[/b] - [2014/11/21 07:13:37 | 000,010,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Locator.exe -- (RpcLocator) SRV:[b]64bit:[/b] - [2014/11/21 07:13:34 | 000,407,040 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService) SRV:[b]64bit:[/b] - [2014/11/21 07:13:34 | 000,270,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure) SRV:[b]64bit:[/b] - [2014/11/21 07:13:34 | 000,034,816 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FDResPub.dll -- (FDResPub) SRV:[b]64bit:[/b] - [2014/11/21 07:13:33 | 000,206,848 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:32 | 000,262,656 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker) SRV:[b]64bit:[/b] - [2014/11/21 07:13:32 | 000,214,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\aelupsvc.dll -- (AeLookupSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:32 | 000,174,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dps.dll -- (DPS) SRV:[b]64bit:[/b] - [2014/11/21 07:13:32 | 000,095,744 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wdi.dll -- (WdiSystemHost) SRV:[b]64bit:[/b] - [2014/11/21 07:13:32 | 000,095,744 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wdi.dll -- (WdiServiceHost) SRV:[b]64bit:[/b] - [2014/11/21 07:13:31 | 001,526,784 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pla.dll -- (pla) SRV:[b]64bit:[/b] - [2014/11/21 07:13:31 | 000,073,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\Sens.dll -- (SENS) SRV:[b]64bit:[/b] - [2014/11/21 07:13:29 | 001,313,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vds.exe -- (vds) SRV:[b]64bit:[/b] - [2014/11/21 07:13:28 | 000,706,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\swprv.dll -- (swprv) SRV:[b]64bit:[/b] - [2014/11/21 07:13:28 | 000,524,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\defragsvc.dll -- (defragsvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:28 | 000,166,400 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\regsvc.dll -- (RemoteRegistry) SRV:[b]64bit:[/b] - [2014/11/21 07:13:28 | 000,022,016 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fdPHost.dll -- (fdPHost) SRV:[b]64bit:[/b] - [2014/11/21 07:13:28 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:28 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost) SRV:[b]64bit:[/b] - [2014/11/21 07:13:27 | 000,121,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:27 | 000,116,736 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay) SRV:[b]64bit:[/b] - [2014/11/21 07:13:27 | 000,116,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\umpnpmgr.dll -- (DeviceInstall) SRV:[b]64bit:[/b] - [2014/11/21 07:13:26 | 000,474,112 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\pcasvc.dll -- (PcaSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:22 | 001,348,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:22 | 000,933,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\qmgr.dll -- (BITS) SRV:[b]64bit:[/b] - [2014/11/21 07:13:21 | 000,209,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wecsvc.dll -- (Wecsvc) SRV:[b]64bit:[/b] - [2014/11/21 07:13:20 | 002,608,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WsmSvc.dll -- (WinRM) SRV:[b]64bit:[/b] - [2014/11/21 07:13:20 | 000,201,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbem\WmiApSrv.exe -- (wmiApSrv) SRV:[b]64bit:[/b] - [2014/11/21 07:13:17 | 000,230,400 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt) SRV:[b]64bit:[/b] - [2014/11/21 07:13:16 | 000,135,168 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\browser.dll -- (Browser) SRV:[b]64bit:[/b] - [2014/11/21 07:13:15 | 001,571,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbengine.exe -- (wbengine) SRV:[b]64bit:[/b] - [2014/11/21 07:13:15 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss) SRV:[b]64bit:[/b] - [2014/11/21 07:13:15 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync) SRV:[b]64bit:[/b] - [2014/11/21 07:13:15 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown) SRV:[b]64bit:[/b] - [2014/11/21 07:13:15 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv) SRV:[b]64bit:[/b] - [2014/11/21 07:13:15 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange) SRV:[b]64bit:[/b] - [2014/11/21 07:13:15 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat) SRV:[b]64bit:[/b] - [2014/11/21 07:13:15 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface) SRV:[b]64bit:[/b] - [2014/11/21 07:13:15 | 000,465,920 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wbiosrvc.dll -- (WbioSrvc) SRV:[b]64bit:[/b] - [2014/11/21 07:12:57 | 000,802,816 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\winhttp.dll -- (WinHttpAutoProxySvc) SRV:[b]64bit:[/b] - [2014/11/21 07:12:57 | 000,365,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp) SRV:[b]64bit:[/b] - [2014/11/21 07:12:57 | 000,131,584 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc) SRV:[b]64bit:[/b] - [2014/11/21 07:12:57 | 000,024,576 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lmhsvc.dll -- (lmhosts) SRV:[b]64bit:[/b] - [2014/11/21 07:12:55 | 000,817,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs) SRV:[b]64bit:[/b] - [2014/11/21 07:12:55 | 000,817,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch) SRV:[b]64bit:[/b] - [2014/11/21 07:12:55 | 000,329,216 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer) SRV:[b]64bit:[/b] - [2014/11/21 07:12:55 | 000,289,280 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation) SRV:[b]64bit:[/b] - [2014/11/21 07:12:55 | 000,080,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpo.dll -- (Power) SRV:[b]64bit:[/b] - [2014/11/21 07:12:55 | 000,062,464 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso) SRV:[b]64bit:[/b] - [2014/11/21 07:12:55 | 000,047,024 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (SamSs) SRV:[b]64bit:[/b] - [2014/11/21 07:12:55 | 000,019,264 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dllhost.exe -- (COMSysApp) SRV:[b]64bit:[/b] - [2014/11/21 07:12:54 | 000,080,896 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\RpcEpMap.dll -- (RpcEptMapper) SRV:[b]64bit:[/b] - [2014/11/21 07:12:54 | 000,028,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nsisvc.dll -- (nsi) SRV:[b]64bit:[/b] - [2014/11/21 07:12:51 | 002,987,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify) SRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,324,608 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\BthHFSrv.dll -- (BthHFSrv) SRV:[b]64bit:[/b] - [2014/11/21 06:50:30 | 006,353,960 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\sppsvc.exe -- (sppsvc) SRV:[b]64bit:[/b] - [2014/04/14 18:59:04 | 000,389,896 | ---- | M] () [Auto | Running] -- C:\Program Files\CyberLink\Shared files\RichVideo64.exe -- (RichVideo64) SRV:[b]64bit:[/b] - [2011/08/30 23:05:32 | 000,462,184 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service) SRV - [2016/04/02 19:03:42 | 000,125,776 | ---- | M] () [Auto | Stopped] -- C:\Users\Sawab\AppData\Roaming\LakjVaiaae\Nerrutiq.exe -- (Iatenl) SRV - [2016/04/02 16:43:10 | 000,330,752 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\D68F83A4-1459610434-E511-A26A-5820B16785B8\knsz798F.tmpfs -- (qozuwumyzbt) SRV - [2016/01/08 11:47:10 | 001,433,216 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc) SRV - [2016/01/08 11:44:00 | 001,773,696 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc) SRV - [2015/12/20 16:43:22 | 000,696,320 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\netlogon.dll -- (Netlogon) SRV - [2015/08/29 17:37:30 | 000,144,200 | ---- | M] (Google Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe -- (gupdatem) SRV - [2015/08/29 17:37:30 | 000,144,200 | ---- | M] (Google Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe -- (gupdate) SRV - [2015/07/09 13:14:04 | 000,327,296 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2015/07/01 23:37:18 | 000,198,656 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\WebClnt.dll -- (WebClient) SRV - [2015/06/15 23:16:41 | 000,059,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\msiexec.exe -- (msiserver) SRV - [2015/05/20 03:22:05 | 000,099,128 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service) SRV - [2015/05/07 17:05:40 | 000,367,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc) SRV - [2015/04/13 10:03:45 | 000,066,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\w3logsvc.dll -- (w3logsvc) SRV - [2015/04/01 04:12:53 | 000,710,144 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWow64\SearchIndexer.exe -- (WSearch) SRV - [2015/02/17 10:39:10 | 000,608,520 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] -- c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe -- (HPWMISVC) SRV - [2015/02/09 20:54:26 | 000,347,200 | ---- | M] (WildTangent) [Auto | Running] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe -- (GamesAppIntegrationService) SRV - [2014/12/17 00:34:18 | 000,265,808 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService) SRV - [2014/12/10 07:11:40 | 000,475,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS) SRV - [2014/12/10 07:11:39 | 000,062,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc) SRV - [2014/11/22 08:44:06 | 000,043,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0) SRV - [2014/11/21 07:15:23 | 000,366,080 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\provsvc.dll -- (HomeGroupProvider) SRV - [2014/11/21 07:15:23 | 000,254,464 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv) SRV - [2014/11/21 07:15:13 | 000,010,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\wpcsvc.dll -- (WPCSvc) SRV - [2014/11/21 07:14:59 | 000,631,808 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\winhttp.dll -- (WinHttpAutoProxySvc) SRV - [2014/11/21 07:14:56 | 000,292,864 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp) SRV - [2014/11/21 07:14:56 | 000,046,592 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\keyiso.dll -- (KeyIso) SRV - [2014/11/21 07:14:56 | 000,017,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\dllhost.exe -- (COMSysApp) SRV - [2014/11/21 07:14:54 | 000,576,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection) SRV - [2014/11/21 07:14:46 | 000,331,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\upnphost.dll -- (upnphost) SRV - [2014/11/21 07:14:44 | 000,261,632 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\qwave.dll -- (QWAVE) SRV - [2014/11/21 07:14:43 | 000,183,296 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysWOW64\mprdim.dll -- (RemoteAccess) SRV - [2014/11/21 07:14:38 | 000,367,616 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\es.dll -- (EventSystem) SRV - [2014/11/21 07:14:34 | 000,084,992 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\wdi.dll -- (WdiSystemHost) SRV - [2014/11/21 07:14:34 | 000,084,992 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\wdi.dll -- (WdiServiceHost) SRV - [2014/11/21 07:14:34 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost) SRV - [2014/11/21 07:14:33 | 001,534,464 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\pla.dll -- (pla) SRV - [2014/11/21 07:14:28 | 002,170,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\WsmSvc.dll -- (WinRM) SRV - [2014/11/21 07:13:14 | 000,034,304 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\WcsPlugInService.dll -- (WcsPlugInService) SRV - [2014/11/21 07:13:07 | 000,296,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\SessEnv.dll -- (SessionEnv) SRV - [2014/11/21 07:12:58 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv) SRV - [2014/11/21 07:12:57 | 000,017,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc) SRV - [2014/11/21 07:12:54 | 000,106,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\servicing\TrustedInstaller.exe -- (TrustedInstaller) SRV - [2014/11/21 07:12:51 | 002,987,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify) SRV - [2014/04/16 01:33:38 | 000,050,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe -- (aspnet_state) SRV - [2014/03/12 14:17:58 | 000,332,528 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- c:\PROGRA~1\COMMON~1\mcafee\actwiz\mcawfwk.exe -- (McAWFwk) SRV - [2013/08/22 06:12:15 | 000,021,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\perfhost.exe -- (PerfHost) SRV - [2013/05/13 20:09:20 | 001,129,760 | ---- | M] (Hewlett-Packard Company) [On_Demand | Stopped] -- C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe -- (hpqwmiex) SRV - [2006/10/26 19:49:34 | 000,441,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv) SRV - [2006/10/26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose) [color=#E56717]========== Driver Services (All) ==========[/color] DRV:[b]64bit:[/b] - [2016/04/02 19:01:07 | 000,037,144 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswKbd.sys -- (aswKbd) DRV:[b]64bit:[/b] - [2016/04/02 18:46:45 | 001,070,904 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx) DRV:[b]64bit:[/b] - [2016/04/02 18:46:45 | 000,107,792 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt) DRV:[b]64bit:[/b] - [2016/04/02 18:46:30 | 000,463,744 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP) DRV:[b]64bit:[/b] - [2016/04/02 18:46:21 | 000,287,016 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm) DRV:[b]64bit:[/b] - [2016/04/02 18:45:43 | 000,165,344 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm) DRV:[b]64bit:[/b] - [2016/04/02 18:45:42 | 000,103,064 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr) DRV:[b]64bit:[/b] - [2016/04/02 18:45:42 | 000,074,544 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt) DRV:[b]64bit:[/b] - [2016/04/02 18:45:42 | 000,037,656 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid) DRV:[b]64bit:[/b] - [2016/04/02 17:14:04 | 000,047,672 | ---- | M] (Disc Soft Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dtliteusbbus.sys -- (dtliteusbbus) DRV:[b]64bit:[/b] - [2016/04/02 17:13:55 | 000,030,264 | ---- | M] (Disc Soft Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dtlitescsibus.sys -- (dtlitescsibus) DRV:[b]64bit:[/b] - [2016/02/10 10:07:26 | 000,561,952 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\cng.sys -- (CNG) DRV:[b]64bit:[/b] - [2016/02/10 10:07:26 | 000,177,496 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ksecpkg.sys -- (KSecPkg) DRV:[b]64bit:[/b] - [2016/01/31 21:16:21 | 000,148,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBSTOR.SYS -- (USBSTOR) DRV:[b]64bit:[/b] - [2016/01/24 20:19:09 | 000,419,160 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport) DRV:[b]64bit:[/b] - [2016/01/10 20:15:49 | 000,202,240 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mrxsmb20.sys -- (mrxsmb20) DRV:[b]64bit:[/b] - [2016/01/10 20:15:00 | 000,401,920 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mrxsmb.sys -- (mrxsmb) DRV:[b]64bit:[/b] - [2016/01/09 03:38:04 | 000,091,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbehci.sys -- (usbehci) DRV:[b]64bit:[/b] - [2016/01/06 20:25:24 | 000,140,800 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mrxdav.sys -- (MRxDAV) DRV:[b]64bit:[/b] - [2016/01/06 20:25:22 | 000,416,768 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\srv.sys -- (srv) DRV:[b]64bit:[/b] - [2015/12/30 23:53:48 | 002,017,624 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\ntfs.sys -- (Ntfs) DRV:[b]64bit:[/b] - [2015/12/08 05:00:58 | 000,214,832 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm) DRV:[b]64bit:[/b] - [2015/12/08 05:00:54 | 000,122,160 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus) DRV:[b]64bit:[/b] - [2015/10/13 19:10:48 | 000,559,616 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\afd.sys -- (AFD) DRV:[b]64bit:[/b] - [2015/10/13 19:10:44 | 000,108,032 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\tdx.sys -- (tdx) DRV:[b]64bit:[/b] - [2015/10/11 08:34:30 | 000,468,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3) DRV:[b]64bit:[/b] - [2015/10/11 08:34:30 | 000,462,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbhub.sys -- (usbhub) DRV:[b]64bit:[/b] - [2015/10/10 20:41:17 | 000,037,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbuhci.sys -- (usbuhci) DRV:[b]64bit:[/b] - [2015/10/10 20:41:14 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbohci.sys -- (usbohci) DRV:[b]64bit:[/b] - [2015/10/10 20:40:25 | 000,078,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\winusb.sys -- (WinUsb) DRV:[b]64bit:[/b] - [2015/10/06 22:32:30 | 000,537,192 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfencbdc.sys -- (mfencbdc) DRV:[b]64bit:[/b] - [2015/10/06 22:32:30 | 000,109,480 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mfencrk.sys -- (mfencrk) DRV:[b]64bit:[/b] - [2015/09/29 14:24:42 | 000,155,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM) DRV:[b]64bit:[/b] - [2015/09/23 10:43:48 | 000,841,944 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk) DRV:[b]64bit:[/b] - [2015/09/23 10:43:48 | 000,497,888 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek) DRV:[b]64bit:[/b] - [2015/09/23 10:43:48 | 000,415,976 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeaack.sys -- (mfeaack) DRV:[b]64bit:[/b] - [2015/09/23 10:43:48 | 000,351,120 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk) DRV:[b]64bit:[/b] - [2015/09/23 10:43:48 | 000,244,544 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk) DRV:[b]64bit:[/b] - [2015/09/23 10:43:48 | 000,082,072 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mfeelamk.sys -- (mfeelamk) DRV:[b]64bit:[/b] - [2015/09/23 10:43:48 | 000,080,760 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids) DRV:[b]64bit:[/b] - [2015/09/04 21:24:04 | 000,154,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tunnel.sys -- (tunnel) DRV:[b]64bit:[/b] - [2015/07/16 02:29:12 | 000,101,720 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mountmgr.sys -- (mountmgr) DRV:[b]64bit:[/b] - [2015/07/14 23:59:47 | 001,113,944 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ndis.sys -- (NDIS) DRV:[b]64bit:[/b] - [2015/07/07 11:40:12 | 000,044,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot) DRV:[b]64bit:[/b] - [2015/07/07 11:40:05 | 000,270,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter) DRV:[b]64bit:[/b] - [2015/07/07 11:40:05 | 000,114,520 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv) DRV:[b]64bit:[/b] - [2015/06/27 05:12:07 | 000,284,672 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\mrxsmb10.sys -- (mrxsmb10) DRV:[b]64bit:[/b] - [2015/06/11 22:12:57 | 002,476,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tcpip.sys -- (TCPIP6) DRV:[b]64bit:[/b] - [2015/06/11 22:12:57 | 002,476,376 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tcpip.sys -- (Tcpip) DRV:[b]64bit:[/b] - [2015/05/19 14:59:02 | 000,207,208 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HipShieldK.sys -- (HipShieldK) DRV:[b]64bit:[/b] - [2015/04/16 08:17:07 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI) DRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 000,551,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vhdmp.sys -- (vhdmp) DRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 000,136,512 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS) DRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 000,108,544 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\i8042prt.sys -- (i8042prt) DRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 000,086,336 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc) DRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 000,072,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ndproxy.sys -- (NDProxy) DRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 000,059,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbdclass.sys -- (kbdclass) DRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 000,058,176 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam) DRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 000,051,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mouclass.sys -- (mouclass) DRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 000,039,744 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep) DRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbdhid.sys -- (kbdhid) DRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mouhid.sys -- (mouhid) DRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 000,026,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sermouse.sys -- (sermouse) DRV:[b]64bit:[/b] - [2015/04/13 10:03:45 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ndistapi.sys -- (NdisTapi) DRV:[b]64bit:[/b] - [2015/04/13 09:56:47 | 000,403,456 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\rdbss.sys -- (rdbss) DRV:[b]64bit:[/b] - [2015/04/13 09:56:47 | 000,138,240 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\dfsc.sys -- (Dfsc) DRV:[b]64bit:[/b] - [2015/04/13 09:56:47 | 000,112,960 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\mup.sys -- (Mup) DRV:[b]64bit:[/b] - [2015/03/27 15:14:10 | 000,223,232 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdWB6.sys -- (AtiHDAudioService) DRV:[b]64bit:[/b] - [2015/03/27 15:14:08 | 000,017,640 | ---- | M] (Advanced Micro Devices, INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmdAS4.sys -- (AmdAS4) DRV:[b]64bit:[/b] - [2015/03/27 15:13:58 | 019,336,192 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:[b]64bit:[/b] - [2015/03/27 15:13:58 | 000,591,872 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:[b]64bit:[/b] - [2015/03/27 15:13:37 | 000,062,152 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdkmpfd.sys -- (amdkmpfd) DRV:[b]64bit:[/b] - [2015/03/20 03:56:10 | 000,080,384 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache) DRV:[b]64bit:[/b] - [2015/03/13 06:03:31 | 000,239,424 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus) DRV:[b]64bit:[/b] - [2015/03/13 04:02:11 | 000,316,416 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Running] -- C:\Windows\SysNative\drivers\udfs.sys -- (udfs) DRV:[b]64bit:[/b] - [2015/03/09 04:02:51 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum) DRV:[b]64bit:[/b] - [2015/03/05 13:25:12 | 004,421,464 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RTKVHD64.sys -- (IntcAzAudAddService) DRV:[b]64bit:[/b] - [2015/03/05 06:13:08 | 003,494,616 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtwlane.sys -- (RTWlanE) DRV:[b]64bit:[/b] - [2015/03/04 12:25:11 | 000,377,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS) DRV:[b]64bit:[/b] - [2015/03/03 06:20:19 | 000,587,944 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) DRV:[b]64bit:[/b] - [2015/03/03 06:20:10 | 000,033,448 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Smb_driver_Intel.sys -- (SmbDrvI) DRV:[b]64bit:[/b] - [2015/03/03 06:20:10 | 000,033,448 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Smb_driver_AMDASF.sys -- (SmbDrv) DRV:[b]64bit:[/b] - [2015/02/24 10:32:52 | 000,991,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\http.sys -- (HTTP) DRV:[b]64bit:[/b] - [2015/01/30 05:01:51 | 000,097,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidbth.sys -- (HidBth) DRV:[b]64bit:[/b] - [2015/01/23 14:50:20 | 000,876,760 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168) DRV:[b]64bit:[/b] - [2014/12/23 13:29:15 | 000,274,648 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR) DRV:[b]64bit:[/b] - [2014/12/15 11:15:34 | 000,071,680 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vwififlt.sys -- (vwififlt) DRV:[b]64bit:[/b] - [2014/12/15 11:15:34 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vwifimp.sys -- (vwifimp) DRV:[b]64bit:[/b] - [2014/11/21 07:54:42 | 000,049,152 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\tcpipreg.sys -- (tcpipreg) DRV:[b]64bit:[/b] - [2014/11/21 07:54:38 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hidusb.sys -- (HidUsb) DRV:[b]64bit:[/b] - [2014/11/21 07:15:32 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\wof.sys -- (Wof) DRV:[b]64bit:[/b] - [2014/11/21 07:15:21 | 000,589,656 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fvevol.sys -- (fvevol) DRV:[b]64bit:[/b] - [2014/11/21 07:15:17 | 000,027,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:[b]64bit:[/b] - [2014/11/21 07:15:13 | 000,054,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr) DRV:[b]64bit:[/b] - [2014/11/21 07:14:20 | 001,552,704 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dxgkrnl.sys -- (DXGKrnl) DRV:[b]64bit:[/b] - [2014/11/21 07:14:02 | 000,445,440 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\nwifi.sys -- (NativeWifiP) DRV:[b]64bit:[/b] - [2014/11/21 07:14:01 | 000,115,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bridge.sys -- (MsBridge) DRV:[b]64bit:[/b] - [2014/11/21 07:14:01 | 000,017,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rasacd.sys -- (RasAcd) DRV:[b]64bit:[/b] - [2014/11/21 07:14:00 | 000,048,128 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\netbios.sys -- (NetBIOS) DRV:[b]64bit:[/b] - [2014/11/21 07:14:00 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ndiscap.sys -- (NdisCap) DRV:[b]64bit:[/b] - [2014/11/21 07:13:59 | 000,151,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\pacer.sys -- (Psched) DRV:[b]64bit:[/b] - [2014/11/21 07:13:59 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform) DRV:[b]64bit:[/b] - [2014/11/21 07:13:59 | 000,047,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qwavedrv.sys -- (QWAVEdrv) DRV:[b]64bit:[/b] - [2014/11/21 07:13:56 | 000,074,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mpsdrv.sys -- (mpsdrv) DRV:[b]64bit:[/b] - [2014/11/21 07:13:56 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp) DRV:[b]64bit:[/b] - [2014/11/21 07:13:55 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu) DRV:[b]64bit:[/b] - [2014/11/21 07:13:53 | 000,921,920 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\refs.sys -- (ReFS) DRV:[b]64bit:[/b] - [2014/11/21 07:13:43 | 000,082,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\appid.sys -- (AppID) DRV:[b]64bit:[/b] - [2014/11/21 07:13:40 | 000,040,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\scfilter.sys -- (scfilter) DRV:[b]64bit:[/b] - [2014/11/21 07:13:38 | 000,226,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WUDFRd.sys -- (WUDFWpdMtp) DRV:[b]64bit:[/b] - [2014/11/21 07:13:38 | 000,226,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WUDFRd.sys -- (WUDFWpdFs) DRV:[b]64bit:[/b] - [2014/11/21 07:13:38 | 000,226,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WUDFRd.sys -- (WUDFSensorLP) DRV:[b]64bit:[/b] - [2014/11/21 07:13:38 | 000,226,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WUDFRd.sys -- (WUDFRd) DRV:[b]64bit:[/b] - [2014/11/21 07:13:38 | 000,146,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101) DRV:[b]64bit:[/b] - [2014/11/21 07:13:38 | 000,113,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WUDFPf.sys -- (WudfPf) DRV:[b]64bit:[/b] - [2014/11/21 07:13:28 | 000,061,248 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fsdepends.sys -- (FsDepends) DRV:[b]64bit:[/b] - [2014/11/21 07:13:28 | 000,033,600 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wimmount.sys -- (WIMMount) DRV:[b]64bit:[/b] - [2014/11/21 07:12:57 | 000,678,400 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\srv2.sys -- (srv2) DRV:[b]64bit:[/b] - [2014/11/21 07:12:57 | 000,246,272 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\srvnet.sys -- (srvnet) DRV:[b]64bit:[/b] - [2014/11/21 07:12:55 | 000,354,112 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\fltMgr.sys -- (FltMgr) DRV:[b]64bit:[/b] - [2014/11/21 07:12:55 | 000,100,672 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ksecdd.sys -- (KSecDD) DRV:[b]64bit:[/b] - [2014/11/21 07:12:54 | 000,088,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\partmgr.sys -- (partmgr) DRV:[b]64bit:[/b] - [2014/11/21 07:12:54 | 000,039,424 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\nsiproxy.sys -- (nsiproxy) DRV:[b]64bit:[/b] - [2014/11/21 07:12:52 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:[b]64bit:[/b] - [2014/11/21 07:12:51 | 000,044,544 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbscan.sys -- (usbscan) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,533,824 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpi.sys -- (ACPI) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,310,080 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\volsnap.sys -- (volsnap) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,280,384 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pci.sys -- (pci) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,275,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msiscsi.sys -- (iScsiPrt) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,212,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbvideo.sys -- (usbvideo) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,189,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,143,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbccgp.sys -- (usbccgp) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,098,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbcir.sys -- (usbcir) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,097,048 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\vmbus.sys -- (vmbus) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,079,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IPMIDrv.sys -- (IPMIDRV) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,076,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hdaudbus.sys -- (HDAudBus) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,069,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,064,000 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthmodem.sys -- (BTHMODEM) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,049,944 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\vmstorfl.sys -- (storflt) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,014,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\drmkaud.sys -- (drmkaud) DRV:[b]64bit:[/b] - [2014/11/21 07:12:50 | 000,014,144 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\swenum.sys -- (swenum) DRV:[b]64bit:[/b] - [2014/11/21 06:50:32 | 000,142,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ipnat.sys -- (IPNAT) DRV:[b]64bit:[/b] - [2014/11/21 06:50:30 | 000,663,040 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\PEAuth.sys -- (PEAUTH) DRV:[b]64bit:[/b] - [2014/11/21 06:50:26 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2) DRV:[b]64bit:[/b] - [2014/11/21 06:50:25 | 000,124,416 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\luafv.sys -- (luafv) DRV:[b]64bit:[/b] - [2014/11/21 06:50:23 | 000,079,192 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\fileinfo.sys -- (FileInfo) DRV:[b]64bit:[/b] - [2014/11/21 06:50:22 | 000,249,688 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\rdyboost.sys -- (rdyboost) DRV:[b]64bit:[/b] - [2014/11/21 06:50:10 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt) DRV:[b]64bit:[/b] - [2014/11/21 06:50:09 | 000,121,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBAUDIO.sys -- (usbaudio) DRV:[b]64bit:[/b] - [2014/11/21 06:50:09 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor) DRV:[b]64bit:[/b] - [2014/11/21 06:50:08 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme) DRV:[b]64bit:[/b] - [2014/11/21 06:50:08 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender) DRV:[b]64bit:[/b] - [2014/11/21 06:20:39 | 000,195,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpdr.sys -- (RDPDR) DRV:[b]64bit:[/b] - [2014/11/21 06:20:35 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt) DRV:[b]64bit:[/b] - [2014/01/28 05:58:37 | 000,041,704 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd) DRV:[b]64bit:[/b] - [2013/11/12 14:25:22 | 000,091,912 | ---- | M] (CyberLink) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\CLVirtualDrive.sys -- (CLVirtualDrive) DRV:[b]64bit:[/b] - [2013/08/22 17:35:09 | 000,023,040 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\secdrv.sys -- (secdrv) DRV:[b]64bit:[/b] - [2013/08/22 15:25:41 | 000,839,488 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Wdf01000.sys -- (Wdf01000) DRV:[b]64bit:[/b] - [2013/08/22 15:25:41 | 000,058,880 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\npfs.sys -- (Npfs) DRV:[b]64bit:[/b] - [2013/08/22 15:25:41 | 000,030,208 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\msfs.sys -- (Msfs) DRV:[b]64bit:[/b] - [2013/08/22 15:25:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\null.sys -- (Null) DRV:[b]64bit:[/b] - [2013/08/22 15:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv) DRV:[b]64bit:[/b] - [2013/08/22 15:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2013/08/22 15:25:35 | 000,366,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msrpc.sys -- (MsRPC) DRV:[b]64bit:[/b] - [2013/08/22 14:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex) DRV:[b]64bit:[/b] - [2013/08/22 14:49:30 | 000,217,952 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\fastfat.sys -- (fastfat) DRV:[b]64bit:[/b] - [2013/08/22 14:49:30 | 000,114,528 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\pcmcia.sys -- (pcmcia) DRV:[b]64bit:[/b] - [2013/08/22 14:49:29 | 000,037,728 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mssmbios.sys -- (mssmbios) DRV:[b]64bit:[/b] - [2013/08/22 14:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis) DRV:[b]64bit:[/b] - [2013/08/22 14:43:49 | 000,017,248 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\msisadrv.sys -- (msisadrv) DRV:[b]64bit:[/b] - [2013/08/22 14:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32) DRV:[b]64bit:[/b] - [2013/08/22 14:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2013/08/22 14:43:45 | 000,575,840 | ---- | M] (LSI Corporation, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\megasr.sys -- (megasr) DRV:[b]64bit:[/b] - [2013/08/22 14:43:45 | 000,412,000 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorV.sys -- (iaStorV) DRV:[b]64bit:[/b] - [2013/08/22 14:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2013/08/22 14:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS) DRV:[b]64bit:[/b] - [2013/08/22 14:43:45 | 000,065,888 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\GAGP30KX.SYS -- (gagp30kx) DRV:[b]64bit:[/b] - [2013/08/22 14:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2013/08/22 14:43:45 | 000,056,672 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\megasas.sys -- (megasas) DRV:[b]64bit:[/b] - [2013/08/22 14:43:45 | 000,021,856 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\isapnp.sys -- (isapnp) DRV:[b]64bit:[/b] - [2013/08/22 14:43:44 | 000,109,408 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas.sys -- (LSI_SAS) DRV:[b]64bit:[/b] - [2013/08/22 14:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3) DRV:[b]64bit:[/b] - [2013/08/22 14:43:44 | 000,018,272 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\intelide.sys -- (intelide) DRV:[b]64bit:[/b] - [2013/08/22 14:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX) DRV:[b]64bit:[/b] - [2013/08/22 14:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2013/08/22 14:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2013/08/22 14:43:41 | 000,114,016 | ---- | M] (PMC-Sierra, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\arcsas.sys -- (arcsas) DRV:[b]64bit:[/b] - [2013/08/22 14:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware) DRV:[b]64bit:[/b] - [2013/08/22 14:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2013/08/22 14:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\atapi.sys -- (atapi) DRV:[b]64bit:[/b] - [2013/08/22 14:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv) DRV:[b]64bit:[/b] - [2013/08/22 14:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass) DRV:[b]64bit:[/b] - [2013/08/22 14:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\AGP440.sys -- (agp440) DRV:[b]64bit:[/b] - [2013/08/22 14:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2013/08/22 14:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID) DRV:[b]64bit:[/b] - [2013/08/22 14:43:34 | 000,168,800 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\vsmraid.sys -- (vsmraid) DRV:[b]64bit:[/b] - [2013/08/22 14:43:34 | 000,019,808 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\viaide.sys -- (viaide) DRV:[b]64bit:[/b] - [2013/08/22 14:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor) DRV:[b]64bit:[/b] - [2013/08/22 14:43:33 | 000,065,888 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\ULIAGPKX.SYS -- (uliagpkx) DRV:[b]64bit:[/b] - [2013/08/22 14:43:33 | 000,064,864 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\UAGP35.SYS -- (uagp35) DRV:[b]64bit:[/b] - [2013/08/22 14:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\nvstor.sys -- (nvstor) DRV:[b]64bit:[/b] - [2013/08/22 14:43:32 | 000,124,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\NV_AGP.SYS -- (nv_agp) DRV:[b]64bit:[/b] - [2013/08/22 14:43:32 | 000,081,760 | ---- | M] (Silicon Integrated Systems) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\sisraid4.sys -- (SiSRaid4) DRV:[b]64bit:[/b] - [2013/08/22 14:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2013/08/22 14:43:31 | 000,150,368 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\nvraid.sys -- (nvraid) DRV:[b]64bit:[/b] - [2013/08/22 14:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci) DRV:[b]64bit:[/b] - [2013/08/22 14:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx) DRV:[b]64bit:[/b] - [2013/08/22 14:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx) DRV:[b]64bit:[/b] - [2013/08/22 14:43:31 | 000,044,896 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\sisraid2.sys -- (SiSRaid2) DRV:[b]64bit:[/b] - [2013/08/22 14:43:31 | 000,014,688 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\pciide.sys -- (pciide) DRV:[b]64bit:[/b] - [2013/08/22 14:39:47 | 000,024,416 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\hwpolicy.sys -- (hwpolicy) DRV:[b]64bit:[/b] - [2013/08/22 14:39:44 | 000,100,192 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\disk.sys -- (disk) DRV:[b]64bit:[/b] - [2013/08/22 14:39:15 | 000,377,696 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\volmgrx.sys -- (volmgrx) DRV:[b]64bit:[/b] - [2013/08/22 14:39:15 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\sbp2port.sys -- (sbp2port) DRV:[b]64bit:[/b] - [2013/08/22 14:39:15 | 000,073,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\volmgr.sys -- (volmgr) DRV:[b]64bit:[/b] - [2013/08/22 14:39:15 | 000,050,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pcw.sys -- (pcw) DRV:[b]64bit:[/b] - [2013/08/22 14:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI) DRV:[b]64bit:[/b] - [2013/08/22 14:37:27 | 000,037,728 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vdrvroot.sys -- (vdrvroot) DRV:[b]64bit:[/b] - [2013/08/22 14:36:48 | 000,045,888 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storvsc.sys -- (storvsc) DRV:[b]64bit:[/b] - [2013/08/22 14:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr) DRV:[b]64bit:[/b] - [2013/08/22 13:40:24 | 000,007,680 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\beep.sys -- (Beep) DRV:[b]64bit:[/b] - [2013/08/22 13:40:18 | 000,200,704 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\exfat.sys -- (exfat) DRV:[b]64bit:[/b] - [2013/08/22 13:40:18 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fdc.sys -- (fdc) DRV:[b]64bit:[/b] - [2013/08/22 13:40:18 | 000,025,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\flpydisk.sys -- (flpydisk) DRV:[b]64bit:[/b] - [2013/08/22 13:40:17 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\serenum.sys -- (Serenum) DRV:[b]64bit:[/b] - [2013/08/22 13:40:15 | 000,088,576 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\cdfs.sys -- (cdfs) DRV:[b]64bit:[/b] - [2013/08/22 13:40:15 | 000,040,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\modem.sys -- (Modem) DRV:[b]64bit:[/b] - [2013/08/22 13:40:08 | 000,083,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\serial.sys -- (Serial) DRV:[b]64bit:[/b] - [2013/08/22 13:40:04 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wmiacpi.sys -- (WmiAcpi) DRV:[b]64bit:[/b] - [2013/08/22 13:40:03 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\ws2ifsl.sys -- (ws2ifsl) DRV:[b]64bit:[/b] - [2013/08/22 13:40:02 | 000,094,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\parport.sys -- (Parport) DRV:[b]64bit:[/b] - [2013/08/22 13:40:00 | 000,017,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sfloppy.sys -- (sfloppy) DRV:[b]64bit:[/b] - [2013/08/22 13:39:43 | 000,025,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CmBatt.sys -- (CmBatt) DRV:[b]64bit:[/b] - [2013/08/22 13:39:41 | 000,034,816 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\filetrace.sys -- (Filetrace) DRV:[b]64bit:[/b] - [2013/08/22 13:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay) DRV:[b]64bit:[/b] - [2013/08/22 13:39:31 | 000,021,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ksthunk.sys -- (ksthunk) DRV:[b]64bit:[/b] - [2013/08/22 13:39:31 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mskssrv.sys -- (MSKSSRV) DRV:[b]64bit:[/b] - [2013/08/22 13:39:31 | 000,006,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mspqm.sys -- (MSPQM) DRV:[b]64bit:[/b] - [2013/08/22 13:39:30 | 000,007,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mspclock.sys -- (MSPCLOCK) DRV:[b]64bit:[/b] - [2013/08/22 13:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo) DRV:[b]64bit:[/b] - [2013/08/22 13:39:16 | 000,045,568 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidir.sys -- (HidIr) DRV:[b]64bit:[/b] - [2013/08/22 13:39:15 | 000,026,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wacompen.sys -- (WacomPen) DRV:[b]64bit:[/b] - [2013/08/22 13:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf) DRV:[b]64bit:[/b] - [2013/08/22 13:39:06 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidkmdf.sys -- (mshidkmdf) DRV:[b]64bit:[/b] - [2013/08/22 13:39:01 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidbatt.sys -- (HidBatt) DRV:[b]64bit:[/b] - [2013/08/22 13:39:00 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vwifibus.sys -- (vwifibus) DRV:[b]64bit:[/b] - [2013/08/22 13:38:59 | 000,046,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\umbus.sys -- (umbus) DRV:[b]64bit:[/b] - [2013/08/22 13:38:58 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\umpass.sys -- (UmPass) DRV:[b]64bit:[/b] - [2013/08/22 13:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime) DRV:[b]64bit:[/b] - [2013/08/22 13:38:53 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipmi.sys -- (AcpiPmi) DRV:[b]64bit:[/b] - [2013/08/22 13:38:52 | 000,022,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rdpbus.sys -- (rdpbus) DRV:[b]64bit:[/b] - [2013/08/22 13:38:48 | 000,036,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CompositeBus.sys -- (CompositeBus) DRV:[b]64bit:[/b] - [2013/08/22 13:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr) DRV:[b]64bit:[/b] - [2013/08/22 13:38:45 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\errdev.sys -- (ErrDev) DRV:[b]64bit:[/b] - [2013/08/22 13:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg) DRV:[b]64bit:[/b] - [2013/08/22 13:38:38 | 000,102,912 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\bowser.sys -- (bowser) DRV:[b]64bit:[/b] - [2013/08/22 13:38:38 | 000,007,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mstee.sys -- (MSTEE) DRV:[b]64bit:[/b] - [2013/08/22 13:38:37 | 000,007,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vms3cap.sys -- (s3cap) DRV:[b]64bit:[/b] - [2013/08/22 13:38:30 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\irenum.sys -- (IRENUM) DRV:[b]64bit:[/b] - [2013/08/22 13:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic) DRV:[b]64bit:[/b] - [2013/08/22 13:38:25 | 000,044,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\circlass.sys -- (circlass) DRV:[b]64bit:[/b] - [2013/08/22 13:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter) DRV:[b]64bit:[/b] - [2013/08/22 13:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig) DRV:[b]64bit:[/b] - [2013/08/22 13:38:21 | 000,395,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HdAudio.sys -- (HdAudAddService) DRV:[b]64bit:[/b] - [2013/08/22 13:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid) DRV:[b]64bit:[/b] - [2013/08/22 13:38:15 | 000,231,424 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\1394ohci.sys -- (1394ohci) DRV:[b]64bit:[/b] - [2013/08/22 13:37:50 | 000,021,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VMBusHID.sys -- (VMBusHID) DRV:[b]64bit:[/b] - [2013/08/22 13:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd) DRV:[b]64bit:[/b] - [2013/08/22 13:37:36 | 000,013,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MTConfig.sys -- (MTConfig) DRV:[b]64bit:[/b] - [2013/08/22 13:37:34 | 000,060,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ndisuio.sys -- (Ndisuio) DRV:[b]64bit:[/b] - [2013/08/22 13:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2013/08/22 13:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c) DRV:[b]64bit:[/b] - [2013/08/22 13:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc) DRV:[b]64bit:[/b] - [2013/08/22 13:37:02 | 000,282,624 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\netbt.sys -- (NetBT) DRV:[b]64bit:[/b] - [2013/08/22 13:36:37 | 000,084,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\raspppoe.sys -- (RasPppoe) DRV:[b]64bit:[/b] - [2013/08/22 13:36:37 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\monitor.sys -- (monitor) DRV:[b]64bit:[/b] - [2013/08/22 13:36:34 | 000,080,384 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rspndr.sys -- (rspndr) DRV:[b]64bit:[/b] - [2013/08/22 13:36:33 | 000,026,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbprint.sys -- (usbprint) DRV:[b]64bit:[/b] - [2013/08/22 13:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus) DRV:[b]64bit:[/b] - [2013/08/22 13:36:18 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lltdio.sys -- (lltdio) DRV:[b]64bit:[/b] - [2013/08/22 13:35:56 | 000,220,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ndiswan.sys -- (NdisWanLegacy) DRV:[b]64bit:[/b] - [2013/08/22 13:35:56 | 000,220,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ndiswan.sys -- (NdisWan) DRV:[b]64bit:[/b] - [2013/08/22 13:35:51 | 000,084,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ipfltdrv.sys -- (IpFilterDriver) DRV:[b]64bit:[/b] - [2013/08/22 10:46:35 | 000,164,352 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\cdrom.sys -- (cdrom) DRV:[b]64bit:[/b] - [2013/08/22 10:46:35 | 000,098,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelppm.sys -- (intelppm) DRV:[b]64bit:[/b] - [2013/08/22 10:46:35 | 000,098,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdppm.sys -- (AmdPPM) DRV:[b]64bit:[/b] - [2013/08/22 10:46:34 | 000,095,744 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdk8.sys -- (AmdK8) DRV:[b]64bit:[/b] - [2013/08/22 10:46:34 | 000,092,160 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\processr.sys -- (Processor) DRV:[b]64bit:[/b] - [2013/08/22 10:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM) DRV:[b]64bit:[/b] - [2013/08/13 01:25:46 | 000,017,624 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2) DRV:[b]64bit:[/b] - [2013/08/10 02:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV) DRV:[b]64bit:[/b] - [2013/07/30 20:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO) DRV:[b]64bit:[/b] - [2013/07/25 21:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C) DRV:[b]64bit:[/b] - [2013/07/22 16:45:58 | 000,020,800 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WirelessButtonDriver64.sys -- (WirelessButtonDriver) [color=#E56717]========== Standard Registry (All) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hp13.msn.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=HPNTDFJS IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hp13.msn.com IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hp13.msn.com IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1908891487-4131021701-3397097638-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hp13.msn.com IE - HKU\S-1-5-21-1908891487-4131021701-3397097638-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKU\S-1-5-21-1908891487-4131021701-3397097638-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKU\S-1-5-21-1908891487-4131021701-3397097638-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-21-1908891487-4131021701-3397097638-1002\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation) IE - HKU\S-1-5-21-1908891487-4131021701-3397097638-1002\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1908891487-4131021701-3397097638-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=HPNTDFJS IE - HKU\S-1-5-21-1908891487-4131021701-3397097638-1002\..\SearchScopes\{A67477D4-5EB9-47FB-8EB9-66C29D13F87A}: "URL" = http://www-mysearch.com/s.ashx?prd=opensearch&q={searchTerms}&s=G42zFTPTN095001,cc65d779-3d69-4831-b1e8-d03a1fd7deab, IE - HKU\S-1-5-21-1908891487-4131021701-3397097638-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1908891487-4131021701-3397097638-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = http://un-stop.org/wpad.dat?12d835ea0b32728f7d64dd3c7b93dffd8330100 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.countryCode: "FR" FF - prefs.js..browser.search.region: "FR" FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:43.0.1 FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll (Foxit Corporation) FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf: C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll (Foxit Corporation) FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp: C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll (Foxit Corporation) FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf: C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll (Foxit Corporation) FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL () FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Sawab\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [2016/04/02 18:49:58 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\firefox@bho.com: C:\Program Files\Hewlett-Packard\SimplePass\FFBHOExt [2015/06/27 04:49:30 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2016/04/02 18:49:58 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK [2015/12/17 22:42:27 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\fdm_ffext@freedownloadmanager.org: C:\Program Files (x86)\Free Download Manager\Firefox\Extension [2016/03/31 22:37:22 | 000,000,000 | ---D | M] [2015/08/29 18:16:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sawab\AppData\Roaming\mozilla\Extensions [2016/04/02 18:35:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sawab\AppData\Roaming\mozilla\Firefox\Profiles\41A66E7E5EE1\extensions [2016/04/02 17:19:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sawab\AppData\Roaming\mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\extensions [2016/04/02 17:18:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sawab\AppData\Roaming\mozilla\Firefox\Profiles\x9f5loxo.default-1449691889519\extensions [2016/03/31 22:08:56 | 001,013,992 | ---- | M] () (No name found) -- C:\Users\Sawab\AppData\Roaming\mozilla\firefox\profiles\41A66E7E5EE1\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016/03/29 08:40:31 | 000,331,500 | ---- | M] () (No name found) -- C:\Users\Sawab\AppData\Roaming\mozilla\firefox\profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi [2016/03/31 22:08:56 | 001,013,992 | ---- | M] () (No name found) -- C:\Users\Sawab\AppData\Roaming\mozilla\firefox\profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016/04/02 16:34:19 | 000,009,654 | ---- | M] () (No name found) -- C:\Users\Sawab\AppData\Roaming\mozilla\firefox\profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\extensions\{f518637a-17a3-43be-af7c-450e996d4ad9}.xpi [2016/04/02 17:07:04 | 000,006,514 | ---- | M] () (No name found) -- C:\Users\Sawab\AppData\Roaming\mozilla\firefox\profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\extensions\{f79b4e0b-a5c0-4d29-8cd4-5887755c0d8e}.xpi [2016/03/31 22:08:56 | 001,013,992 | ---- | M] () (No name found) -- C:\Users\Sawab\AppData\Roaming\mozilla\firefox\profiles\x9f5loxo.default-1449691889519\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016/04/02 16:34:19 | 000,009,654 | ---- | M] () (No name found) -- C:\Users\Sawab\AppData\Roaming\mozilla\firefox\profiles\x9f5loxo.default-1449691889519\extensions\{f518637a-17a3-43be-af7c-450e996d4ad9}.xpi [2016/04/02 21:11:30 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions O1 HOSTS File: ([2016/04/04 23:35:34 | 000,002,265 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 107.178.255.88 google-analytics.com O1 - Hosts: 107.178.248.130 static.doubleclick.net O1 - Hosts: 107.178.247.130 connect.facebook.net O1 - Hosts: 107.178.255.88 www.google-analytics.com O1 - Hosts: 107.178.255.88 www.statcounter.com O1 - Hosts: 107.178.255.88 statcounter.com O1 - Hosts: 107.178.255.88 ssl.google-analytics.com O1 - Hosts: 107.178.255.88 partner.googleadservices.com O1 - Hosts: 107.178.255.88 google-analytics.com O1 - Hosts: 107.178.248.130 static.doubleclick.net O1 - Hosts: 107.178.247.130 connect.facebook.net O1 - Hosts: 127.0.0.1 down.baidu2016.com O1 - Hosts: 127.0.0.1 123.sogou.com O1 - Hosts: 127.0.0.1 www.czzsyzgm.com O1 - Hosts: 127.0.0.1 www.czzsyzxl.com O1 - Hosts: 127.0.0.1 union.baidu2019.com O2:[b]64bit:[/b] - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O2:[b]64bit:[/b] - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation) O2:[b]64bit:[/b] - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Evernote extension) - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) O2 - BHO: (Cash Kitten) - {9ea7bd36-2d13-4df3-837f-7ac273765e7d} - C:\Program Files (x86)\Cash Kitten\Extensions\9ea7bd36-2d13-4df3-837f-7ac273765e7d.dll File not found O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG) O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) O4:[b]64bit:[/b] - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) O4:[b]64bit:[/b] - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software) O4 - HKLM..\Run: [HPMessageService] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.) O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKU\S-1-5-21-1908891487-4131021701-3397097638-1002..\Run: [Free Download Manager] C:\Program Files (x86)\Free Download Manager\fdm.exe (FreeDownloadManager.ORG) O4 - HKU\S-1-5-21-1908891487-4131021701-3397097638-1002..\Run: [Skype] C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.) O4 - Startup: C:\Users\Sawab\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Alertes de surveillance de l'encre - HP ENVY 4500 series.lnk = C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRun = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7 O8:[b]64bit:[/b] - Extra context menu item: E&xporter vers Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O8:[b]64bit:[/b] - Extra context menu item: Télécharger avec Free Download Manager - C:\Program Files (x86)\Free Download Manager\dllink.htm () O8:[b]64bit:[/b] - Extra context menu item: Télécharger la sélection avec Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlselected.htm () O8:[b]64bit:[/b] - Extra context menu item: Télécharger la vidéo avec Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm () O8:[b]64bit:[/b] - Extra context menu item: Tout télécharger avec Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlall.htm () O8 - Extra context menu item: E&xporter vers Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Télécharger avec Free Download Manager - C:\Program Files (x86)\Free Download Manager\dllink.htm () O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlselected.htm () O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm () O8 - Extra context menu item: Tout télécharger avec Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlall.htm () O9:[b]64bit:[/b] - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard) O9:[b]64bit:[/b] - Extra 'Tools' menuitem : HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard) O9:[b]64bit:[/b] - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard) O9:[b]64bit:[/b] - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard) O9:[b]64bit:[/b] - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation) O9:[b]64bit:[/b] - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\AddNote.html () O9:[b]64bit:[/b] - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\AddNote.html () O9 - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard) O9 - Extra 'Tools' menuitem : HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard) O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard) O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard) O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html () O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html () O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation) O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation) O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation) O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation) O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation) O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{178403F4-FCE4-4A13-B844-747D0432CB79}: NameServer = 104.197.191.4 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{47C3C650-306B-4EB6-A637-0D7DB53F73AC}: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{47C3C650-306B-4EB6-A637-0D7DB53F73AC}: NameServer = 104.197.191.4 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8718928D-CBEB-45EA-A621-800A9249001D}: NameServer = 104.197.191.4 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B2B529BB-1A5C-4C07-9CD5-642E3B6D3758}: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B2B529BB-1A5C-4C07-9CD5-642E3B6D3758}: NameServer = 8.8.8.8 O18:[b]64bit:[/b] - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation) O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation) O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation) O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation) O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation) O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~1\mcafee\msc\MCSNIE~1.DLL (McAfee, Inc.) O18:[b]64bit:[/b] - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.) O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (wscript C:\Windows\run.vbs) - C:\Windows\run.vbs () O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (wscript C:\Windows\run.vbs) - C:\Windows\run.vbs () O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O29:[b]64bit:[/b] - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation) O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation) O30:[b]64bit:[/b] - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation) O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ActiveX:[b]64bit:[/b] {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX:[b]64bit:[/b] {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall ActiveX:[b]64bit:[/b] {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX:[b]64bit:[/b] {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX:[b]64bit:[/b] {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX:[b]64bit:[/b] {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX:[b]64bit:[/b] {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX:[b]64bit:[/b] {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX:[b]64bit:[/b] {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX:[b]64bit:[/b] {66C64F22-FC60-4E6C-A6B5-F0D580E680CE} - C:\Windows\System32\ie4uinit.exe -EnableTLS ActiveX:[b]64bit:[/b] {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX:[b]64bit:[/b] {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX:[b]64bit:[/b] {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX:[b]64bit:[/b] {78E345F7-E976-3595-9C30-2458D6A8EC32} - .NET Framework ActiveX:[b]64bit:[/b] {7D715857-A67C-4C2F-A929-038448584D63} - C:\Windows\System32\ie4uinit.exe -DisableSSL3 ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4340} - U ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig ActiveX:[b]64bit:[/b] {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install ActiveX:[b]64bit:[/b] {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX:[b]64bit:[/b] {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX:[b]64bit:[/b] {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX:[b]64bit:[/b] {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX:[b]64bit:[/b] {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework ActiveX:[b]64bit:[/b] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.110\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - .NET Framework ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {EC43E638-09F0-38CC-A585-72FCCDDF035C} - .NET Framework ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP NetSvcs:[b]64bit:[/b] lfsvc - C:\Windows\SysNative\GeofenceMonitorService.dll (Microsoft Corporation) NetSvcs:[b]64bit:[/b] wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation) NetSvcs:[b]64bit:[/b] DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation) NetSvcs:[b]64bit:[/b] NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation) SafeBootMin:[b]64bit:[/b] AppMgmt - Service SafeBootMin:[b]64bit:[/b] Base - Driver Group SafeBootMin:[b]64bit:[/b] BasicDisplay.sys - C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation) SafeBootMin:[b]64bit:[/b] BasicRender.sys - C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation) SafeBootMin:[b]64bit:[/b] Boot Bus Extender - Driver Group SafeBootMin:[b]64bit:[/b] Boot file system - Driver Group SafeBootMin:[b]64bit:[/b] BrokerInfrastructure - C:\Windows\SysNative\bisrv.dll (Microsoft Corporation) SafeBootMin:[b]64bit:[/b] EFS - C:\Windows\SysNative\efssvc.dll (Microsoft Corporation) SafeBootMin:[b]64bit:[/b] File system - Driver Group SafeBootMin:[b]64bit:[/b] Filter - Driver Group SafeBootMin:[b]64bit:[/b] HelpSvc - Service SafeBootMin:[b]64bit:[/b] KeyIso - C:\Windows\SysNative\keyiso.dll (Microsoft Corporation) SafeBootMin:[b]64bit:[/b] LSM - C:\Windows\SysNative\lsm.dll (Microsoft Corporation) SafeBootMin:[b]64bit:[/b] MCODS - C:\Program Files\mcafee\VirusScan\mcods.exe (McAfee, Inc.) SafeBootMin:[b]64bit:[/b] mcpltsvc - C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe (McAfee, Inc.) SafeBootMin:[b]64bit:[/b] Netlogon - C:\Windows\SysNative\netlogon.dll (Microsoft Corporation) SafeBootMin:[b]64bit:[/b] PCI Configuration - Driver Group SafeBootMin:[b]64bit:[/b] PNP Filter - Driver Group SafeBootMin:[b]64bit:[/b] Primary disk - Driver Group SafeBootMin:[b]64bit:[/b] sacsvr - Service SafeBootMin:[b]64bit:[/b] SCSI Class - Driver Group SafeBootMin:[b]64bit:[/b] System Bus Extender - Driver Group SafeBootMin:[b]64bit:[/b] SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation) SafeBootMin:[b]64bit:[/b] TBS - Service SafeBootMin:[b]64bit:[/b] vmms - Service SafeBootMin:[b]64bit:[/b] WinDefend - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) SafeBootMin:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin:[b]64bit:[/b] {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices SafeBootMin:[b]64bit:[/b] {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller SafeBootMin:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootMin: AppMgmt - Service SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: TBS - Service SafeBootMin: vmms - Service SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices SafeBootMin: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet:[b]64bit:[/b] AppMgmt - Service SafeBootNet:[b]64bit:[/b] Base - Driver Group SafeBootNet:[b]64bit:[/b] BasicDisplay.sys - C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation) SafeBootNet:[b]64bit:[/b] BasicRender.sys - C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation) SafeBootNet:[b]64bit:[/b] Boot Bus Extender - Driver Group SafeBootNet:[b]64bit:[/b] Boot file system - Driver Group SafeBootNet:[b]64bit:[/b] BrokerInfrastructure - C:\Windows\SysNative\bisrv.dll (Microsoft Corporation) SafeBootNet:[b]64bit:[/b] EFS - C:\Windows\SysNative\efssvc.dll (Microsoft Corporation) SafeBootNet:[b]64bit:[/b] File system - Driver Group SafeBootNet:[b]64bit:[/b] Filter - Driver Group SafeBootNet:[b]64bit:[/b] HelpSvc - Service SafeBootNet:[b]64bit:[/b] KeyIso - C:\Windows\SysNative\keyiso.dll (Microsoft Corporation) SafeBootNet:[b]64bit:[/b] LSM - C:\Windows\SysNative\lsm.dll (Microsoft Corporation) SafeBootNet:[b]64bit:[/b] McMPFSvc - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc.) SafeBootNet:[b]64bit:[/b] McNaiAnn - C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe (McAfee, Inc.) SafeBootNet:[b]64bit:[/b] MCODS - C:\Program Files\mcafee\VirusScan\mcods.exe (McAfee, Inc.) SafeBootNet:[b]64bit:[/b] mcpltsvc - C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe (McAfee, Inc.) SafeBootNet:[b]64bit:[/b] Messenger - Service SafeBootNet:[b]64bit:[/b] mfeaack - C:\Windows\SysNative\drivers\mfeaack.sys (McAfee, Inc.) SafeBootNet:[b]64bit:[/b] mfeaack.sys - C:\Windows\SysNative\drivers\mfeaack.sys (McAfee, Inc.) SafeBootNet:[b]64bit:[/b] mfeavfk - C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.) SafeBootNet:[b]64bit:[/b] mfeavfk.sys - C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.) SafeBootNet:[b]64bit:[/b] mfefire - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe () SafeBootNet:[b]64bit:[/b] mfefirek - C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.) SafeBootNet:[b]64bit:[/b] mfefirek.sys - C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.) SafeBootNet:[b]64bit:[/b] mfehidk - C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.) SafeBootNet:[b]64bit:[/b] mfehidk.sys - C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.) SafeBootNet:[b]64bit:[/b] mfemms - C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe () SafeBootNet:[b]64bit:[/b] mfencbdc - C:\Windows\SysNative\drivers\mfencbdc.sys (McAfee, Inc.) SafeBootNet:[b]64bit:[/b] mfencbdc.sys - C:\Windows\SysNative\drivers\mfencbdc.sys (McAfee, Inc.) SafeBootNet:[b]64bit:[/b] mfetdi2k - Service SafeBootNet:[b]64bit:[/b] mfetdi2k.sys - Driver SafeBootNet:[b]64bit:[/b] mfevtp - C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.) SafeBootNet:[b]64bit:[/b] NDIS Wrapper - Driver Group SafeBootNet:[b]64bit:[/b] NetBIOSGroup - Driver Group SafeBootNet:[b]64bit:[/b] NetDDEGroup - Driver Group SafeBootNet:[b]64bit:[/b] Netlogon - C:\Windows\SysNative\netlogon.dll (Microsoft Corporation) SafeBootNet:[b]64bit:[/b] netprofm - C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation) SafeBootNet:[b]64bit:[/b] Network - Driver Group SafeBootNet:[b]64bit:[/b] NetworkProvider - Driver Group SafeBootNet:[b]64bit:[/b] PCI Configuration - Driver Group SafeBootNet:[b]64bit:[/b] PNP Filter - Driver Group SafeBootNet:[b]64bit:[/b] PNP_TDI - Driver Group SafeBootNet:[b]64bit:[/b] Primary disk - Driver Group SafeBootNet:[b]64bit:[/b] rdpencdd.sys - Driver SafeBootNet:[b]64bit:[/b] rdsessmgr - Service SafeBootNet:[b]64bit:[/b] sacsvr - Service SafeBootNet:[b]64bit:[/b] SCSI Class - Driver Group SafeBootNet:[b]64bit:[/b] SmartcardSimulator - Driver SafeBootNet:[b]64bit:[/b] Streams Drivers - Driver Group SafeBootNet:[b]64bit:[/b] System Bus Extender - Driver Group SafeBootNet:[b]64bit:[/b] SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation) SafeBootNet:[b]64bit:[/b] TBS - Service SafeBootNet:[b]64bit:[/b] TDI - Driver Group SafeBootNet:[b]64bit:[/b] VaultSvc - C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation) SafeBootNet:[b]64bit:[/b] VirtualSmartcardReader - Driver SafeBootNet:[b]64bit:[/b] vmms - Service SafeBootNet:[b]64bit:[/b] Wcmsvc - C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation) SafeBootNet:[b]64bit:[/b] WinDefend - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) SafeBootNet:[b]64bit:[/b] WudfUsbccidDriver - Driver SafeBootNet:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet:[b]64bit:[/b] {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet:[b]64bit:[/b] {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet:[b]64bit:[/b] {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet:[b]64bit:[/b] {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet:[b]64bit:[/b] {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet:[b]64bit:[/b] {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices SafeBootNet:[b]64bit:[/b] {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller SafeBootNet:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: AppMgmt - Service SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: Messenger - Service SafeBootNet: mfetdi2k - Service SafeBootNet: mfetdi2k.sys - Driver SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdpencdd.sys - Driver SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: SmartcardSimulator - Driver SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TBS - Service SafeBootNet: TDI - Driver Group SafeBootNet: VirtualSmartcardReader - Driver SafeBootNet: vmms - Service SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices SafeBootNet: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices CREATERESTOREPOINT Restore point Set: OTL Restore Point [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2016/04/06 01:13:13 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Sawab\Desktop\OTL.exe [2016/04/04 23:39:57 | 000,000,000 | ---D | C] -- C:\Users\Sawab\AppData\Local\node-webkit [2016/04/04 23:11:57 | 000,000,000 | ---D | C] -- C:\Users\Sawab\AppData\Roaming\ZHP [2016/04/03 08:53:38 | 000,000,000 | ---D | C] -- C:\Users\Sawab\AppData\Roaming\WildTangent [2016/04/02 19:03:50 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ebah [2016/04/02 19:01:10 | 000,037,144 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswKbd.sys [2016/04/02 18:51:55 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\haap [2016/04/02 18:50:06 | 000,398,152 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe [2016/04/02 18:47:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software [2016/04/02 18:46:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AV [2016/04/02 18:45:59 | 001,070,904 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys [2016/04/02 18:45:59 | 000,463,744 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys [2016/04/02 18:45:59 | 000,287,016 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswVmm.sys [2016/04/02 18:45:59 | 000,165,344 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys [2016/04/02 18:45:59 | 000,107,792 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys [2016/04/02 18:45:59 | 000,103,064 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys [2016/04/02 18:45:59 | 000,074,544 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRvrt.sys [2016/04/02 18:45:59 | 000,037,656 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswHwid.sys [2016/04/02 18:45:38 | 000,052,184 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr [2016/04/02 18:13:43 | 000,000,000 | ---D | C] -- C:\Users\Sawab\AppData\Roaming\MCorp [2016/04/02 18:07:16 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\lans [2016/04/02 18:06:02 | 000,000,000 | ---D | C] -- C:\Users\Sawab\AppData\Local\app [2016/04/02 18:03:59 | 000,000,000 | ---D | C] -- C:\Users\Sawab\AppData\Roaming\Dugusiac [2016/04/02 18:03:58 | 000,000,000 | ---D | C] -- C:\Users\Sawab\AppData\Roaming\LakjVaiaae [2016/04/02 18:03:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CleanBrowser [2016/04/02 17:24:40 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\vam [2016/04/02 17:22:57 | 000,000,000 | ---D | C] -- C:\Users\Sawab\AppData\Local\D68F83A4-1459617776-E511-A26A-5820B16785B8 [2016/04/02 17:20:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\D68F83A4-1459610434-E511-A26A-5820B16785B8 [2016/04/02 17:19:06 | 000,000,000 | ---D | C] -- C:\Users\Sawab\AppData\Local\Disc_Soft_Ltd [2016/04/02 17:18:26 | 000,000,000 | ---D | C] -- C:\uninst [2016/04/02 17:18:24 | 000,000,000 | ---D | C] -- C:\Users\Sawab\AppData\Roaming\Mafniurnel [2016/04/02 17:18:21 | 000,000,000 | ---D | C] -- C:\Users\Sawab\AppData\Local\Tempfolder [2016/04/02 17:18:01 | 000,000,000 | ---D | C] -- C:\Users\Sawab\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108 [2016/04/02 17:17:28 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\dmp [2016/04/02 17:14:31 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Daemon Tools Images [2016/04/02 17:14:04 | 000,047,672 | ---- | C] (Disc Soft Ltd) -- C:\Windows\SysNative\drivers\dtliteusbbus.sys [2016/04/02 17:13:55 | 000,030,264 | ---- | C] (Disc Soft Ltd) -- C:\Windows\SysNative\drivers\dtlitescsibus.sys [2016/04/02 17:13:53 | 000,000,000 | ---D | C] -- C:\Users\Sawab\AppData\Roaming\DAEMON Tools Lite [2016/04/02 17:13:34 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite [2016/03/31 22:38:21 | 000,000,000 | ---D | C] -- C:\Downloads [2016/03/31 22:37:37 | 000,000,000 | ---D | C] -- C:\ProgramData\FreeDownloadManager.ORG [2016/03/31 22:37:36 | 000,000,000 | ---D | C] -- C:\Users\Sawab\AppData\Roaming\FreeDownloadManager.ORG [2016/03/31 22:37:36 | 000,000,000 | ---D | C] -- C:\Users\Sawab\AppData\Roaming\Free Download Manager [2016/03/31 22:37:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Download Manager [2016/03/31 22:37:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Free Download Manager [2016/03/31 01:14:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ISO to USB [2016/03/31 01:14:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ISO to USB [2016/03/30 23:10:33 | 000,000,000 | ---D | C] -- C:\Users\Sawab\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool [2016/03/30 23:05:49 | 000,000,000 | ---D | C] -- C:\Users\Sawab\Documents\Abd-El-Mannane [2016/03/09 13:53:13 | 001,373,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appraiser.dll [2016/03/09 13:53:13 | 000,689,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll [2016/03/09 13:53:12 | 001,168,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll [2016/03/09 13:53:12 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\acmigration.dll [2016/03/09 13:53:11 | 000,696,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\invagent.dll [2016/03/09 13:53:11 | 000,499,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\devinv.dll [2016/03/09 13:53:11 | 000,046,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CompatTelRunner.exe [2016/03/09 13:53:01 | 001,335,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mispace.dll [2016/03/09 13:53:01 | 001,063,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mispace.dll [2016/03/09 13:53:01 | 000,419,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\spaceport.sys [2016/03/09 13:53:01 | 000,378,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\storport.sys [2016/03/09 13:53:01 | 000,331,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Classpnp.sys [2016/03/09 13:52:45 | 000,218,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rsaenh.dll [2016/03/09 13:52:43 | 000,177,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wscapi.dll [2016/03/09 13:52:43 | 000,148,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wscapi.dll [2016/03/09 13:52:41 | 001,707,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comsvcs.dll [2016/03/09 13:52:41 | 001,344,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\comsvcs.dll [2016/03/09 13:52:24 | 000,994,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ucrtbase.dll [2016/03/09 13:52:24 | 000,922,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ucrtbase.dll [2016/03/09 13:52:23 | 000,839,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netlogon.dll [2016/03/09 13:52:23 | 000,470,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys [2016/03/09 13:52:16 | 000,616,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msra.exe [2016/03/09 13:52:16 | 000,570,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe [2016/03/09 13:52:13 | 002,487,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\storagewmi.dll [2016/03/09 13:52:13 | 001,482,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\storagewmi.dll [2016/03/09 11:56:18 | 002,050,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2016/03/09 11:56:18 | 000,663,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2016/03/09 11:56:17 | 000,798,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2016/03/09 11:56:17 | 000,571,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2016/03/09 11:56:16 | 002,123,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2016/03/09 11:56:15 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll [2016/03/09 11:56:15 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hlink.dll [2016/03/09 11:56:14 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2016/03/09 11:56:12 | 006,052,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2016/03/09 11:56:12 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll [2016/03/09 11:56:07 | 002,880,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\actxprxy.dll [2016/03/09 11:56:06 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2016/03/09 11:54:02 | 007,784,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Data.Pdf.dll [2016/03/09 11:54:01 | 007,075,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\glcndFilter.dll [2016/03/09 11:54:01 | 005,268,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\glcndFilter.dll [2016/03/09 11:54:01 | 005,264,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Data.Pdf.dll [2016/03/09 11:53:57 | 002,244,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll [2016/03/09 11:53:57 | 000,897,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll [2016/03/09 11:53:57 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapi.dll [2016/03/09 11:53:57 | 000,409,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUSettingsProvider.dll [2016/03/09 11:53:57 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll [2016/03/09 11:53:57 | 000,136,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe [2016/03/09 11:53:57 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuwebv.dll [2016/03/09 11:53:57 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll [2016/03/09 11:53:57 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wudriver.dll [2016/03/09 11:53:57 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe [2016/03/09 11:53:57 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapp.exe [2016/03/09 11:53:55 | 001,661,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ole32.dll [2016/03/09 11:53:54 | 015,432,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll [2016/03/09 11:53:54 | 013,318,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll [2016/03/09 11:53:53 | 000,292,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMASF.DLL [2016/03/09 11:53:44 | 000,875,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcr120_clr0400.dll [2016/03/09 11:53:44 | 000,869,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvcr120_clr0400.dll [2016/03/09 11:53:44 | 000,678,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvcp120_clr0400.dll [2016/03/09 11:53:44 | 000,536,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp120_clr0400.dll [2016/03/09 11:53:40 | 000,358,912 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll [2016/03/09 11:53:40 | 000,301,568 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll [2016/03/09 11:53:40 | 000,044,032 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll [2016/03/09 11:53:40 | 000,035,840 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll [2016/03/09 11:52:30 | 000,603,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfds.dll [2016/03/09 11:52:30 | 000,483,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfds.dll [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2016/04/06 20:08:19 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2016/04/06 20:08:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2016/04/06 10:00:46 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2016/04/06 01:10:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Sawab\Desktop\OTL.exe [2016/04/04 23:56:26 | 000,069,848 | ---- | M] () -- C:\Users\Sawab\Desktop\Error.png [2016/04/04 23:48:46 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys [2016/04/04 23:48:43 | 2967,060,480 | -HS- | M] () -- C:\hiberfil.sys [2016/04/04 23:48:14 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\spu_storage.bin [2016/04/04 23:35:34 | 000,002,265 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts [2016/04/04 23:12:49 | 001,966,994 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2016/04/04 23:12:49 | 000,846,474 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat [2016/04/04 23:12:49 | 000,786,952 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2016/04/04 23:12:49 | 000,174,564 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat [2016/04/04 23:12:49 | 000,161,212 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2016/04/04 23:11:58 | 000,000,845 | ---- | M] () -- C:\Users\Sawab\Desktop\ZHPCleaner.lnk [2016/04/02 19:01:31 | 000,001,060 | ---- | M] () -- C:\Users\Public\Desktop\Avast SafeZone Browser.lnk [2016/04/02 19:01:07 | 000,037,144 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswKbd.sys [2016/04/02 18:47:30 | 000,001,945 | ---- | M] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk [2016/04/02 18:46:45 | 001,070,904 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys [2016/04/02 18:46:45 | 000,107,792 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys [2016/04/02 18:46:30 | 000,463,744 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys [2016/04/02 18:46:21 | 000,287,016 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswVmm.sys [2016/04/02 18:45:43 | 000,165,344 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys [2016/04/02 18:45:42 | 000,398,152 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe [2016/04/02 18:45:42 | 000,103,064 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys [2016/04/02 18:45:42 | 000,074,544 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRvrt.sys [2016/04/02 18:45:42 | 000,037,656 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswHwid.sys [2016/04/02 18:45:38 | 000,052,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2016/04/02 18:40:13 | 000,000,296 | ---- | M] () -- C:\task.vbs [2016/04/02 18:09:33 | 000,001,990 | ---- | M] () -- C:\Users\Sawab\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Alertes de surveillance de l'encre - HP ENVY 4500 series.lnk [2016/04/02 18:04:16 | 000,002,301 | ---- | M] () -- C:\Users\Sawab\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk [2016/04/02 18:04:16 | 000,001,653 | ---- | M] () -- C:\Users\Sawab\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet-Explorer Browser.lnk [2016/04/02 17:17:47 | 000,001,006 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hp.bak [2016/04/02 17:14:04 | 000,047,672 | ---- | M] (Disc Soft Ltd) -- C:\Windows\SysNative\drivers\dtliteusbbus.sys [2016/04/02 17:13:55 | 000,030,264 | ---- | M] (Disc Soft Ltd) -- C:\Windows\SysNative\drivers\dtlitescsibus.sys [2016/03/31 22:37:23 | 000,001,090 | ---- | M] () -- C:\Users\Sawab\Desktop\Free Download Manager.lnk [2016/03/31 01:14:23 | 000,001,044 | ---- | M] () -- C:\Users\Public\Desktop\ISO to USB.lnk [2016/03/30 23:10:33 | 000,002,541 | ---- | M] () -- C:\Users\Sawab\Desktop\Windows 7 USB DVD Download Tool.lnk [2016/03/09 15:36:09 | 000,498,200 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2016/03/09 11:53:05 | 000,718,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe [2016/03/08 09:00:28 | 000,829,944 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2016/03/08 09:00:28 | 000,176,632 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [color=#E56717]========== Files Created - No Company Name ==========[/color] [2016/04/04 23:56:26 | 000,069,848 | ---- | C] () -- C:\Users\Sawab\Desktop\Error.png [2016/04/04 23:11:58 | 000,000,845 | ---- | C] () -- C:\Users\Sawab\Desktop\ZHPCleaner.lnk [2016/04/02 19:01:31 | 000,001,060 | ---- | C] () -- C:\Users\Public\Desktop\Avast SafeZone Browser.lnk [2016/04/02 19:01:31 | 000,001,060 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk [2016/04/02 18:47:30 | 000,001,945 | ---- | C] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk [2016/04/02 18:40:13 | 000,000,296 | ---- | C] () -- C:\task.vbs [2016/03/31 22:37:23 | 000,001,090 | ---- | C] () -- C:\Users\Sawab\Desktop\Free Download Manager.lnk [2016/03/31 01:14:23 | 000,001,044 | ---- | C] () -- C:\Users\Public\Desktop\ISO to USB.lnk [2016/03/30 23:10:33 | 000,002,541 | ---- | C] () -- C:\Users\Sawab\Desktop\Windows 7 USB DVD Download Tool.lnk [2015/09/09 17:42:01 | 000,000,000 | ---- | C] () -- C:\Users\Sawab\AppData\Local\{6E9F0AF7-726E-4A93-A118-B6751B905DE7} [2015/08/31 18:10:28 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini [2015/06/27 04:20:54 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe [2015/06/27 04:19:51 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2015/06/27 04:18:18 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat [2015/06/27 04:18:18 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat [2015/06/27 04:18:17 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [2015/06/27 04:18:16 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe [2015/06/27 04:18:16 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe [2015/06/27 04:18:14 | 000,123,392 | ---- | C] () -- C:\Windows\SysWow64\amdhdl32.dll [2015/03/04 22:52:50 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll [2014/12/10 07:11:53 | 000,931,872 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2014/11/21 07:14:54 | 000,046,080 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2014/11/21 07:12:59 | 000,107,008 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll [2014/11/21 06:50:48 | 000,002,255 | ---- | C] () -- C:\Windows\SysWow64\WimBootCompress.ini [color=#E56717]========== ZeroAccess Check ==========[/color] [2015/06/27 04:11:36 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2016/01/22 10:01:44 | 022,365,992 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2016/01/22 09:11:11 | 019,794,896 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2014/11/21 07:13:17 | 001,013,760 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2014/11/21 07:14:29 | 000,786,944 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2014/11/21 07:13:17 | 000,512,512 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2016/04/06 10:03:25 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Roaming\Audacity [2016/04/02 18:47:36 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Roaming\AVAST Software [2016/04/02 17:15:51 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Roaming\DAEMON Tools Lite [2015/09/01 10:37:12 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Roaming\DropboxOEM [2016/04/02 19:39:03 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Roaming\Dugusiac [2016/01/08 21:51:26 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Roaming\Foxit Software [2016/04/01 07:06:53 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Roaming\Free Download Manager [2016/03/31 22:37:36 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Roaming\FreeDownloadManager.ORG [2016/04/02 19:39:06 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Roaming\LakjVaiaae [2016/04/02 19:39:07 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Roaming\Mafniurnel [2016/04/02 18:13:43 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Roaming\MCorp [2016/02/18 11:17:12 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Roaming\PhotoFiltre Studio X [2015/08/29 15:30:46 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Roaming\Synaptics [2016/04/03 08:53:38 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Roaming\WildTangent [2016/04/04 23:37:43 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Roaming\ZHP [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Custom Scans ==========[/color] [color=#A23BEC]< HKCU\Software >[/color] [HKEY_CURRENT_USER\Software\AppDataLow] [HKEY_CURRENT_USER\Software\ATI] [HKEY_CURRENT_USER\Software\Audacity] [HKEY_CURRENT_USER\Software\AVAST Software] [HKEY_CURRENT_USER\Software\Chromium] [HKEY_CURRENT_USER\Software\Class] [HKEY_CURRENT_USER\Software\Clients] [HKEY_CURRENT_USER\Software\CoreJpeg] [HKEY_CURRENT_USER\Software\CyberLink] [HKEY_CURRENT_USER\Software\Disc Soft] [HKEY_CURRENT_USER\Software\Foxit Software] [HKEY_CURRENT_USER\Software\FreeDownloadManager.ORG] [HKEY_CURRENT_USER\Software\Google] [HKEY_CURRENT_USER\Software\Hewlett-Packard] [HKEY_CURRENT_USER\Software\HP] [HKEY_CURRENT_USER\Software\IM Providers] [HKEY_CURRENT_USER\Software\InstallPath] [HKEY_CURRENT_USER\Software\Macromedia] [HKEY_CURRENT_USER\Software\McAfee] [HKEY_CURRENT_USER\Software\Microsoft] [HKEY_CURRENT_USER\Software\Mine] [HKEY_CURRENT_USER\Software\Mozilla] [HKEY_CURRENT_USER\Software\MozillaPlugins] [HKEY_CURRENT_USER\Software\Netscape] [HKEY_CURRENT_USER\Software\ODBC] [HKEY_CURRENT_USER\Software\PhotoFiltre Studio X] [HKEY_CURRENT_USER\Software\Policies] [HKEY_CURRENT_USER\Software\Realtek] [HKEY_CURRENT_USER\Software\RegisteredApplications] [HKEY_CURRENT_USER\Software\Skype] [HKEY_CURRENT_USER\Software\Softex] [HKEY_CURRENT_USER\Software\Synaptics] [HKEY_CURRENT_USER\Software\Unity] [HKEY_CURRENT_USER\Software\Visan] [HKEY_CURRENT_USER\Software\Wow6432Node] [HKEY_CURRENT_USER\Software\ZebHelpProcess Helper] [HKEY_CURRENT_USER\Software\{1ECE051F-1BDC-413C-8339-D2876B47C552}] [HKEY_CURRENT_USER\Software\{4473BD90-D1FA-4683-85D9-9F2EDF9F417C}] [HKEY_CURRENT_USER\Software\Classes] [color=#A23BEC]< HKCU\Software\AppDataLow /s >[/color] [HKEY_CURRENT_USER\Software\AppDataLow\Software] [HKEY_CURRENT_USER\Software\AppDataLow\Software\Microsoft] [HKEY_CURRENT_USER\Software\AppDataLow\Software\Microsoft\Internet Explorer] [HKEY_CURRENT_USER\Software\AppDataLow\Software\Microsoft\RepService] "i" = 9EBB33D6-2A28-4816-804F-6AF7D621A865 [binary data] "BB" = 1.000000 [binary data] "AA" = .cpl,.exe,.dll,.ocx,.sys,.scr,.drv [Binary data over 200 bytes] "MM" = 0.050000 [binary data] "B" = 50.000000 [binary data] "A" = .cpl,.exe,.dll,.ocx,.sys,.scr,.drv [Binary data over 200 bytes] "E" = 1 [binary data] [HKEY_CURRENT_USER\Software\AppDataLow\Software\Microsoft\Windows] [HKEY_CURRENT_USER\Software\AppDataLow\Software\Microsoft\Windows\CurrentVersion] [HKEY_CURRENT_USER\Software\AppDataLow\Software\Microsoft\Windows\CurrentVersion\Lock Screen] [HKEY_CURRENT_USER\Software\AppDataLow\Software\Unity] [HKEY_CURRENT_USER\Software\AppDataLow\Software\Unity\WebPlayer] "" = [color=#A23BEC]< HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /s >[/color] [color=#A23BEC]< HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /s >[/color] [color=#A23BEC]< HKLM\Software >[/color] "" = [HKEY_LOCAL_MACHINE\Software\Adobe] [HKEY_LOCAL_MACHINE\Software\AppDataLow] [HKEY_LOCAL_MACHINE\Software\Apple Inc.] [HKEY_LOCAL_MACHINE\Software\ATI] [HKEY_LOCAL_MACHINE\Software\ATI Technologies] [HKEY_LOCAL_MACHINE\Software\AVAST Software] [HKEY_LOCAL_MACHINE\Software\Caphyon] [HKEY_LOCAL_MACHINE\Software\CyberLink] [HKEY_LOCAL_MACHINE\Software\Dropbox] [HKEY_LOCAL_MACHINE\Software\Evernote] [HKEY_LOCAL_MACHINE\Software\Foxit Software] [HKEY_LOCAL_MACHINE\Software\FreeDownloadManager.ORG] [HKEY_LOCAL_MACHINE\Software\Google] [HKEY_LOCAL_MACHINE\Software\Hewlett-Packard] [HKEY_LOCAL_MACHINE\Software\IM Providers] [HKEY_LOCAL_MACHINE\Software\Insyde] [HKEY_LOCAL_MACHINE\Software\Intel] [HKEY_LOCAL_MACHINE\Software\Khronos] [HKEY_LOCAL_MACHINE\Software\Lake] [HKEY_LOCAL_MACHINE\Software\Macromedia] [HKEY_LOCAL_MACHINE\Software\McAfee] [HKEY_LOCAL_MACHINE\Software\McAfee.com] [HKEY_LOCAL_MACHINE\Software\Microsoft] [HKEY_LOCAL_MACHINE\Software\Mozilla] [HKEY_LOCAL_MACHINE\Software\mozilla.org] [HKEY_LOCAL_MACHINE\Software\MozillaPlugins] [HKEY_LOCAL_MACHINE\Software\Network Associates] [HKEY_LOCAL_MACHINE\Software\Nuance] [HKEY_LOCAL_MACHINE\Software\ODBC] [HKEY_LOCAL_MACHINE\Software\OldTimer Tools] [HKEY_LOCAL_MACHINE\Software\Realtek] [HKEY_LOCAL_MACHINE\Software\Realtek Semiconductor Corp.] [HKEY_LOCAL_MACHINE\Software\RocketLife] [HKEY_LOCAL_MACHINE\Software\RtWLan] [HKEY_LOCAL_MACHINE\Software\Skype] [HKEY_LOCAL_MACHINE\Software\SrpnFiles] [HKEY_LOCAL_MACHINE\Software\Visan] [HKEY_LOCAL_MACHINE\Software\WildTangent] [HKEY_LOCAL_MACHINE\Software\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}] [HKEY_LOCAL_MACHINE\Software\{E6276374-DE18-4AA5-A365-9016A2F98A2D}] [HKEY_LOCAL_MACHINE\Software\{G6276374-DEEE-4AAA-A355-9016A2F98A2D}] [HKEY_LOCAL_MACHINE\Software\Classes] [HKEY_LOCAL_MACHINE\Software\Clients] [HKEY_LOCAL_MACHINE\Software\Policies] [HKEY_LOCAL_MACHINE\Software\RegisteredApplications] [color=#A23BEC]< HKCU\Software\Microsoft\Command Processor /s >[/color] "PathCompletionChar" = 9 "EnableExtensions" = 1 "CompletionChar" = 9 "DefaultColor" = 0 [color=#A23BEC]< HKLM\Software\Microsoft\Command Processor /s >[/color] "PathCompletionChar" = 64 "EnableExtensions" = 1 "CompletionChar" = 64 "DefaultColor" = 0 [color=#A23BEC]< HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /s >[/color] "ForceActiveDesktopOn" = 0 "NoActiveDesktopChanges" = 1 "NoActiveDesktop" = 1 "NoRun" = 0 "NoFolderOptions" = 0 "NoControlPanel" = 0 [color=#A23BEC]< HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /s >[/color] "EnableVirtualization" = 1 "EnableInstallerDetection" = 1 "PromptOnSecureDesktop" = 1 "EnableLUA" = 1 "EnableSecureUIAPaths" = 1 "ConsentPromptBehaviorAdmin" = 5 "ValidateAdminCodeSignatures" = 0 "EnableUIADesktopToggle" = 0 "EnableCursorSuppression" = 1 "ConsentPromptBehaviorUser" = 3 "dontdisplaylastusername" = 0 "legalnoticecaption" = "legalnoticetext" = "scforceoption" = 0 "shutdownwithoutlogon" = 1 "undockwithoutlogon" = 1 "FilterAdministratorToken" = 0 "DisableTaskMgr" = 0 "DisableRegistryTools" = 0 "SoftwareSASGeneration" = 1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\Audit] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UIPI] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UIPI\Clipboard] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UIPI\Clipboard\ExceptionFormats] "CF_UNICODETEXT" = 13 "CF_DIBV5" = 17 "CF_PALETTE" = 9 "CF_BITMAP" = 2 "CF_TEXT" = 1 "CF_DIB" = 8 "CF_OEMTEXT" = 7 [color=#A23BEC]< HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU /s >[/color] [color=#A23BEC]< HKLM\System\CurrentControlSet\Control\Session Manager\AppcertDlls /s >[/color] [color=#A23BEC]< %Homedrive%\* >[/color] [2014/11/21 07:13:53 | 000,404,250 | RHS- | M] () -- C:\bootmgr [2013/06/18 14:18:29 | 000,000,001 | -HS- | M] () -- C:\BOOTNXT [2016/04/04 23:48:43 | 2967,060,480 | -HS- | M] () -- C:\hiberfil.sys [2016/04/04 23:48:45 | 671,088,640 | -HS- | M] () -- C:\pagefile.sys [2016/04/04 23:48:46 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys [2016/04/02 18:40:13 | 000,000,296 | ---- | M] () -- C:\task.vbs [color=#A23BEC]< %Homedrive%\*. >[/color] [2015/09/13 18:40:12 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin [2015/12/07 10:07:06 | 000,000,000 | ---D | M] -- C:\BurnTempLog [2013/08/22 16:45:52 | 000,000,000 | -HSD | M] -- C:\Documents and Settings [2016/03/31 22:38:21 | 000,000,000 | ---D | M] -- C:\Downloads [2015/06/27 14:00:13 | 000,000,000 | -H-D | M] -- C:\hp [2014/12/10 07:11:42 | 000,000,000 | ---D | M] -- C:\inetpub [2015/08/29 18:30:56 | 000,000,000 | RH-D | M] -- C:\MSOCache [2013/08/22 17:22:35 | 000,000,000 | ---D | M] -- C:\PerfLogs [2016/04/02 18:04:37 | 000,000,000 | R--D | M] -- C:\Program Files [2016/04/04 23:37:15 | 000,000,000 | R--D | M] -- C:\Program Files (x86) [2016/04/02 23:44:47 | 000,000,000 | -H-D | M] -- C:\ProgramData [2015/06/27 06:34:13 | 000,000,000 | ---D | M] -- C:\SWSetup [2016/04/06 01:18:02 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2015/08/29 15:30:46 | 000,000,000 | -H-D | M] -- C:\SYSTEM.SAV [2016/04/02 17:18:26 | 000,000,000 | ---D | M] -- C:\uninst [2015/08/29 15:30:35 | 000,000,000 | R--D | M] -- C:\Users [2016/04/02 18:50:02 | 000,000,000 | ---D | M] -- C:\Windows [color=#A23BEC]< %Homedrive%\Recycler\*.exe /s >[/color] [color=#A23BEC]< %Homedrive%\Recycler\*.scr /s >[/color] [color=#A23BEC]< %Homedrive%\Recycler\*.pif /s >[/color] [color=#A23BEC]< %Homedrive%\Recycler\*.vb* /s >[/color] [color=#A23BEC]< %Homedrive%\$Recycle.bin\*.exe /s >[/color] [2016/04/04 23:54:40 | 000,000,544 | ---- | M] () -- C:\$Recycle.bin\S-1-5-21-1908891487-4131021701-3397097638-1002\$IA7IS1C.exe [2016/04/02 18:42:14 | 005,066,104 | ---- | M] (AVAST Software) -- C:\$Recycle.bin\S-1-5-21-1908891487-4131021701-3397097638-1002\$RA7IS1C.exe [color=#A23BEC]< %Homedrive%\$Recycle.bin\*.scr /s >[/color] [color=#A23BEC]< %Homedrive%\$Recycle.bin\*.pif /s >[/color] [color=#A23BEC]< %Homedrive%\$Recycle.bin\*.vb* /s >[/color] [color=#A23BEC]< %Userprofile%\* >[/color] [2016/04/04 23:48:17 | 003,407,872 | -HS- | M] () -- C:\Users\Sawab\NTUSER.DAT [2015/08/29 15:30:36 | 006,561,792 | -HS- | M] () -- C:\Users\Sawab\ntuser.dat.LOG1 [2015/08/29 15:30:36 | 001,130,496 | -HS- | M] () -- C:\Users\Sawab\ntuser.dat.LOG2 [2015/08/29 18:41:20 | 000,065,536 | -HS- | M] () -- C:\Users\Sawab\NTUSER.DAT{bbed3e3b-0b41-11e3-8249-d6927d06400b}.TM.blf [2015/08/29 18:41:20 | 000,524,288 | -HS- | M] () -- C:\Users\Sawab\NTUSER.DAT{bbed3e3b-0b41-11e3-8249-d6927d06400b}.TMContainer00000000000000000001.regtrans-ms [2015/08/29 18:41:20 | 000,524,288 | -HS- | M] () -- C:\Users\Sawab\NTUSER.DAT{bbed3e3b-0b41-11e3-8249-d6927d06400b}.TMContainer00000000000000000002.regtrans-ms [2015/08/29 15:30:36 | 000,000,020 | -HS- | M] () -- C:\Users\Sawab\ntuser.ini [color=#A23BEC]< %Userprofile%\*. >[/color] [2015/08/29 15:30:36 | 000,000,000 | -H-D | M] -- C:\Users\Sawab\AppData [2015/08/29 15:30:36 | 000,000,000 | -HSD | M] -- C:\Users\Sawab\Application Data [2016/02/10 19:47:43 | 000,000,000 | R--D | M] -- C:\Users\Sawab\Contacts [2015/08/29 15:30:36 | 000,000,000 | -HSD | M] -- C:\Users\Sawab\Cookies [2016/04/06 20:16:04 | 000,000,000 | R--D | M] -- C:\Users\Sawab\Desktop [2016/04/04 23:52:05 | 000,000,000 | R--D | M] -- C:\Users\Sawab\Documents [2016/04/03 09:11:23 | 000,000,000 | R--D | M] -- C:\Users\Sawab\Downloads [2016/02/10 19:47:43 | 000,000,000 | R--D | M] -- C:\Users\Sawab\Favorites [2016/02/10 19:47:46 | 000,000,000 | R--D | M] -- C:\Users\Sawab\Links [2015/08/29 15:30:36 | 000,000,000 | -HSD | M] -- C:\Users\Sawab\Local Settings [2015/08/29 15:30:36 | 000,000,000 | -HSD | M] -- C:\Users\Sawab\Menu Démarrer [2015/08/29 15:30:36 | 000,000,000 | -HSD | M] -- C:\Users\Sawab\Mes documents [2015/08/29 15:30:36 | 000,000,000 | -HSD | M] -- C:\Users\Sawab\Modèles [2016/04/03 09:10:20 | 000,000,000 | R--D | M] -- C:\Users\Sawab\Music [2015/09/25 13:51:38 | 000,000,000 | ---D | M] -- C:\Users\Sawab\OneDrive [2016/04/03 09:10:29 | 000,000,000 | R--D | M] -- C:\Users\Sawab\Pictures [2015/08/29 15:30:36 | 000,000,000 | -HSD | M] -- C:\Users\Sawab\Recent [2016/02/10 19:47:45 | 000,000,000 | R--D | M] -- C:\Users\Sawab\Saved Games [2016/02/10 19:47:45 | 000,000,000 | R--D | M] -- C:\Users\Sawab\Searches [2015/08/29 15:30:36 | 000,000,000 | -HSD | M] -- C:\Users\Sawab\SendTo [2015/09/18 21:04:33 | 000,000,000 | ---D | M] -- C:\Users\Sawab\Tracing [2016/02/10 19:47:43 | 000,000,000 | R--D | M] -- C:\Users\Sawab\Videos [2015/08/29 15:30:36 | 000,000,000 | -HSD | M] -- C:\Users\Sawab\Voisinage d'impression [2015/08/29 15:30:36 | 000,000,000 | -HSD | M] -- C:\Users\Sawab\Voisinage réseau [color=#A23BEC]< %Allusersprofile%\* >[/color] [2015/08/31 18:10:28 | 000,000,057 | ---- | M] () -- C:\ProgramData\Ament.ini [color=#A23BEC]< %Allusersprofile%\*. >[/color] [2015/10/06 21:03:04 | 000,000,000 | ---D | M] -- C:\ProgramData\AMD [2015/06/27 04:28:13 | 000,000,000 | ---D | M] -- C:\ProgramData\Apple [2013/08/22 16:45:52 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data [2016/04/02 19:01:07 | 000,000,000 | ---D | M] -- C:\ProgramData\AVAST Software [2015/08/29 15:26:57 | 000,000,000 | -HSD | M] -- C:\ProgramData\Bureau [2015/12/09 22:46:32 | 000,000,000 | ---D | M] -- C:\ProgramData\CyberLink [2016/04/02 17:13:34 | 000,000,000 | ---D | M] -- C:\ProgramData\DAEMON Tools Lite [2013/08/22 16:45:52 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop [2013/08/22 16:45:52 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents [2016/03/31 22:37:37 | 000,000,000 | ---D | M] -- C:\ProgramData\FreeDownloadManager.ORG [2015/06/27 05:24:36 | 000,000,000 | ---D | M] -- C:\ProgramData\Hewlett-Packard [2015/08/31 18:13:16 | 000,000,000 | ---D | M] -- C:\ProgramData\HP [2015/08/31 18:13:35 | 000,000,000 | ---D | M] -- C:\ProgramData\HP Photo Creations [2015/06/27 04:55:51 | 000,000,000 | ---D | M] -- C:\ProgramData\install_clap [2016/02/10 19:47:39 | 000,000,000 | ---D | M] -- C:\ProgramData\McAfee [2015/08/29 15:26:58 | 000,000,000 | -HSD | M] -- C:\ProgramData\Menu Démarrer [2015/09/03 09:59:05 | 000,000,000 | --SD | M] -- C:\ProgramData\Microsoft [2015/08/29 18:36:15 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft Help [2015/08/29 15:26:58 | 000,000,000 | -HSD | M] -- C:\ProgramData\Modèles [2015/06/27 04:18:32 | 000,000,000 | ---D | M] -- C:\ProgramData\Package Cache [2015/12/07 10:04:59 | 000,000,000 | ---D | M] -- C:\ProgramData\PassMark [2015/06/27 05:00:05 | 000,000,000 | ---D | M] -- C:\ProgramData\regid.1991-06.com.microsoft [2016/02/23 13:55:37 | 000,000,000 | ---D | M] -- C:\ProgramData\Skype [2015/06/27 04:17:50 | 000,000,000 | ---D | M] -- C:\ProgramData\SRS Labs [2013/08/22 16:45:52 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu [2015/06/27 04:25:07 | 000,000,000 | ---D | M] -- C:\ProgramData\Synaptics [2015/06/27 04:56:09 | 000,000,000 | ---D | M] -- C:\ProgramData\Temp [2013/08/22 16:45:52 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates [2015/08/31 18:13:35 | 000,000,000 | ---D | M] -- C:\ProgramData\Visan [2015/06/27 04:35:28 | 000,000,000 | ---D | M] -- C:\ProgramData\WildTangent [2015/06/27 04:08:22 | 000,000,000 | ---D | M] -- C:\ProgramData\{65AB91D4-DDD0-48D4-804D-C24E1FC90D44} [color=#A23BEC]< %LocalAppData%\* >[/color] [2016/04/06 10:04:09 | 000,095,683 | -H-- | M] () -- C:\Users\Sawab\AppData\Local\IconCache.db [2015/09/09 17:42:01 | 000,000,000 | ---- | M] () -- C:\Users\Sawab\AppData\Local\{6E9F0AF7-726E-4A93-A118-B6751B905DE7} [color=#A23BEC]< %LocalAppData%\*. >[/color] [2016/04/02 17:19:37 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108 [2016/04/04 23:39:55 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\app [2015/08/29 15:30:36 | 000,000,000 | -HSD | M] -- C:\Users\Sawab\AppData\Local\Application Data [2016/03/30 23:10:33 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\Apps [2015/12/09 22:40:28 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\CyberLink [2016/04/02 19:31:49 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\D68F83A4-1459617776-E511-A26A-5820B16785B8 [2015/08/29 17:37:26 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\Deployment [2016/04/05 18:57:42 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\Diagnostics [2016/04/02 17:19:06 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\Disc_Soft_Ltd [2015/08/29 15:33:04 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\DropboxOEM [2016/04/04 23:10:16 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\ElevatedDiagnostics [2015/09/09 23:01:07 | 000,000,000 | -HSD | M] -- C:\Users\Sawab\AppData\Local\EmieBrowserModeList [2015/09/09 23:01:07 | 000,000,000 | -HSD | M] -- C:\Users\Sawab\AppData\Local\EmieSiteList [2015/09/09 23:01:07 | 000,000,000 | -HSD | M] -- C:\Users\Sawab\AppData\Local\EmieUserList [2015/09/12 19:34:55 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\Google [2015/09/04 11:22:07 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\GWX [2015/08/29 15:33:39 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\Hewlett-Packard [2015/08/29 15:30:36 | 000,000,000 | -HSD | M] -- C:\Users\Sawab\AppData\Local\Historique [2016/01/11 15:54:10 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\HP [2015/12/09 22:44:16 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\MediaShow [2015/09/19 18:13:47 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\Microsoft [2016/04/03 09:00:37 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\Microsoft Help [2015/09/05 14:27:22 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\Mozilla [2016/04/06 20:08:13 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\node-webkit [2016/04/03 08:55:11 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\Packages [2016/02/10 16:52:28 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\Programs [2016/02/09 23:26:52 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\Skype [2016/04/06 20:16:02 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\Temp [2016/04/02 18:04:01 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\Tempfolder [2015/08/29 15:30:36 | 000,000,000 | -HSD | M] -- C:\Users\Sawab\AppData\Local\Temporary Internet Files [2015/12/16 16:56:36 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\Unity [2015/12/18 17:43:53 | 000,000,000 | ---D | M] -- C:\Users\Sawab\AppData\Local\VirtualStore [color=#A23BEC]< %Userprofile%\Local Settings\* >[/color] [color=#A23BEC]< %Userprofile%\Local Settings\*. >[/color] [color=#A23BEC]< %Userprofile%\Local Settings\Application Data\* >[/color] [color=#A23BEC]< %Userprofile%\Local Settings\Application Data\*. >[/color] [color=#A23BEC]< %Userprofile%\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\* >[/color] [color=#A23BEC]< %Userprofile%\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*. >[/color] [color=#A23BEC]< %Userprofile%\Local Settings\Application Data\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\* >[/color] [color=#A23BEC]< %Userprofile%\Local Settings\Application Data\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\*. >[/color] [color=#A23BEC]< %programFiles%\* >[/color] [color=#A23BEC]< %programFiles%\*. >[/color] [2015/06/27 04:20:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\AMD AVT [2015/06/27 04:20:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ATI Technologies [2016/02/10 16:56:13 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Audacity [2015/06/27 04:28:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Bonjour [2015/06/27 04:21:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Cisco [2016/04/02 18:07:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CleanBrowser [2016/04/02 18:46:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files [2015/06/27 04:55:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Cyberlink [2016/04/02 20:52:56 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\D68F83A4-1459610434-E511-A26A-5820B16785B8 [2015/06/27 04:38:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dropbox [2015/06/27 04:31:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Evernote [2015/04/13 00:38:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Foxit PhantomPDF [2016/03/31 22:37:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Free Download Manager [2015/08/29 17:41:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Google [2015/08/31 18:13:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Hewlett-Packard [2015/08/31 18:13:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\HP [2015/08/31 18:13:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\HP Photo Creations [2015/06/27 04:55:51 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information [2016/03/09 15:31:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer [2016/03/31 01:14:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ISO to USB [2016/02/10 19:46:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\McAfee [2015/06/27 04:44:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mcafee.com [2015/08/29 18:34:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office [2015/08/29 18:34:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Visual Studio [2015/08/29 18:31:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 8 [2015/08/29 18:35:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Works [2015/08/29 18:34:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET [2016/04/02 21:19:07 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox [2015/08/29 18:34:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild [2015/06/27 05:24:36 | 000,000,000 | R--D | M] -- C:\Program Files (x86)\Online Services [2016/02/17 22:15:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PhotoFiltre Studio X [2015/06/27 04:22:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Realtek [2014/12/10 07:10:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies [2016/02/09 23:26:55 | 000,000,000 | R--D | M] -- C:\Program Files (x86)\Skype [2015/06/27 04:17:52 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Temp [2015/06/27 04:35:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WildGames [2015/06/27 04:35:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WildTangent Games [2015/09/04 15:08:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender [2015/09/04 15:08:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail [2015/09/04 15:08:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player [2014/11/21 14:39:00 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Multimedia Platform [2013/08/22 17:36:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT [2015/09/04 15:08:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Viewer [2014/11/21 14:39:00 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices [2013/08/22 17:36:30 | 000,000,000 | -HSD | M] -- C:\Program Files (x86)\Windows Sidebar [2013/08/22 17:36:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WindowsPowerShell [color=#A23BEC]< %programfiles%\Google\Desktop\*. >[/color] [color=#A23BEC]< %ProgramFiles%\Common Files\*. >[/color] [2015/06/27 04:20:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\ATI Technologies [2016/04/02 18:46:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\AV [2015/06/27 04:53:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\CyberLink [2015/08/29 18:34:48 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\DESIGNER [2015/06/27 04:45:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\McAfee [2015/09/03 09:59:01 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Microsoft Shared [2015/06/27 04:57:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Nikon [2013/08/22 17:36:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Services [2016/02/09 23:26:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Skype [2015/09/04 15:08:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\System [color=#A23BEC]< %ProgramFiles(X86)%\Common Files\*. >[/color] [2015/06/27 04:20:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\ATI Technologies [2016/04/02 18:46:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\AV [2015/06/27 04:53:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\CyberLink [2015/08/29 18:34:48 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\DESIGNER [2015/06/27 04:45:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\McAfee [2015/09/03 09:59:01 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Microsoft Shared [2015/06/27 04:57:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Nikon [2013/08/22 17:36:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Services [2016/02/09 23:26:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\Skype [2015/09/04 15:08:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files\System [color=#A23BEC]< %Systemroot%\Installer\*. >[/color] [2015/06/27 04:16:44 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\$PatchCache$ [2015/06/27 04:20:08 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{005F2F6D-BA20-741C-77C7-F2A8392862BE} [2015/06/27 04:54:53 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{01FB4998-33C4-4431-85ED-079E3EEFE75D} [2015/06/27 04:20:06 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{055A1E15-04F4-D498-544D-348E1ED32E96} [2015/06/27 04:12:30 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{07FA4960-B038-49EB-891B-9F95930AA544} [2015/06/27 04:20:13 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{12083670-1959-6682-0E1C-A87B05235320} [2015/06/27 04:55:42 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79} [2015/06/27 04:20:06 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{2618D8E7-F21B-A147-22E9-8D213D2E4182} [2015/06/27 04:20:09 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{29BA8925-231D-C4DD-0783-AB48DCBFA616} [2015/06/27 04:53:20 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2} [2015/06/27 04:49:46 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{2DE6247C-7077-451B-8BA7-FFD1A2ABBB47} [2015/06/27 04:19:57 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{2E7B23D4-8E5A-66A7-606D-C7ADA06A4C3C} [2015/06/27 04:28:24 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{30B2D1D8-0A07-4B71-9553-0710C5D31E35} [2015/06/27 04:49:24 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{314FAD12-F785-4471-BCE8-AB506642B9A1} [2015/06/27 04:20:11 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{37F1E909-02C1-EB21-5FDE-209A8483C265} [2015/06/27 04:20:08 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{3F0C6C09-4089-2AB5-FDFC-1EBD9E90F56D} [2015/06/27 04:27:53 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{465CA2B6-98AF-4E77-BE22-A908C34BB9EC} [2015/06/27 04:20:03 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{47B6D730-1207-54F5-00F6-3E3BB4245744} [2015/06/27 04:27:45 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{4AD6381C-DBAC-4591-A9C2-DF1DB9F153D3} [2015/06/27 04:20:04 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{4D1875AD-EF40-0A56-088F-724C80C9E07B} [2015/04/13 00:39:01 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{4E32271C-B55A-4CDF-8DB7-88FD1C45927C} [2015/06/27 04:31:38 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{4FD2D1C8-8636-11E4-9D21-00163E98E7D6} [2015/06/27 04:20:16 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{50D0973F-55D6-16AC-A0BD-836EE1A8F703} [2015/06/27 04:20:14 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{53142956-5A31-641D-413B-C45F38D7A994} [2015/06/27 04:38:54 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{597A58EC-42D6-4940-8739-FB94491B013C} [2015/06/27 04:57:17 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{5A454EC5-217A-42a5-8CE1-2DDEC4E70E01} [2015/06/27 04:20:17 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{5A8C4BEA-779C-FD02-2294-224F01A0EB34} [2015/04/13 00:37:59 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{612C34C7-5E90-47D8-9B5C-0F717DD82726} [2015/06/27 04:20:12 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{628837D2-F7D2-B268-8EF1-AD45746653AA} [2015/06/27 04:37:54 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{64BAA990-F1FC-4145-A7B1-E41FBBC9DA47} [2015/06/27 04:20:02 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{65844965-3921-1E73-C26B-674E547C1E7E} [2016/01/14 01:55:56 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{6D1221A9-17BF-4EC0-81F2-27D30EC30701} [2015/06/27 04:28:14 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D} [2015/06/27 04:12:18 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{6F340107-F9AA-47C6-B54C-C3A19F11553F} [2015/06/27 04:20:13 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{7949C3C8-0DBB-EC92-D432-BB016E99EBBD} [2015/06/27 04:20:07 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{875DEC14-CAFC-1FBD-9AC0-BFCCBCCF7484} [2015/06/27 04:49:50 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{878F6913-7421-4713-97F7-0A736EE2A188} [2015/06/27 04:20:05 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{8D68DA1D-22BA-87B9-E9AE-7AEA27A006EE} [2015/08/29 18:35:50 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{90120000-0011-0000-0000-0000000FF1CE} [2015/08/29 18:33:25 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{90120000-002A-0000-1000-0000000FF1CE} [2015/08/29 18:31:17 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{90120000-006E-040C-0000-0000000FF1CE} [2015/06/27 05:00:05 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{90150000-0138-0409-0000-0000000FF1CE} [2015/06/27 04:11:24 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{904822F1-6C7D-4B91-B936-6A1C0810544C} [2015/06/27 04:20:35 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{956386BF-95CC-FCC4-0C4F-3A0D52C87F43} [2015/06/27 04:20:09 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{989293BB-CEBB-2EB7-2C34-66B04153FF7C} [2015/08/31 18:13:27 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{9A9B64A8-A9E8-4588-B924-D1898D3E6355} [2015/06/27 04:18:35 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{A7EDF9AB-2D95-7B52-DE15-351E9011B49E} [2015/06/27 04:20:15 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{ACAB8E80-23F6-E3DA-2F6A-C2A2DFA7A7BB} [2015/06/27 04:47:55 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{ADD5DB49-72CF-11D8-9D75-000129760D75} [2015/06/27 04:20:10 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{B2BFCD15-5043-B307-0082-91E90A72B742} [2015/06/27 04:52:11 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{B46BEA36-0B71-4A4E-AE41-87241643FA0A} [2015/06/27 04:18:42 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{B7A315D3-3F4C-0633-2434-7BF7331AC884} [2015/06/27 04:20:23 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{CD0FC314-ECB6-6B5A-C938-B7464849E549} [2015/04/13 00:39:16 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{D17A3B70-B75E-4C49-83D6-C17DDF65B35F} [2015/06/27 04:16:44 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{D1E8F2D7-7794-4245-B286-87ED86C1893C} [2015/06/27 04:19:59 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{D3C49D06-7FA6-CE04-A17A-2074E314DBB6} [2015/06/27 04:20:15 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{D69D7C88-3AA5-BA3B-A343-C0CAE1821739} [2015/06/27 04:20:02 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{DDD5BA4D-185B-CF60-3A56-3DD476ABB810} [2015/06/27 04:20:00 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{DDF21364-8F6E-6794-F0F4-A59B66CD9C35} [2015/06/27 04:20:01 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{DF64219D-79B4-CE68-44BF-8F489C749E8F} [2015/06/27 04:43:16 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{E1646825-D391-42A0-93AA-27FA810DA093} [2015/06/27 04:20:18 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{E401B7B3-E1E7-3969-8A5C-49CFB3F1F241} [2015/06/27 04:20:11 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{F6C0D50D-B893-39BF-5B3C-80CBAD04A5D0} [2016/02/23 13:55:25 | 000,000,000 | ---D | M] -- C:\Windows\Installer\{FC965A47-4839-40CA-B618-18F486F042C6} [color=#A23BEC]< %Systemroot%\Temp\*.exe /s >[/color] [color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color] [2016/02/08 22:02:58 | 013,012,480 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\system32\ieframe.dll [color=#A23BEC]< %systemroot%\system32\*.exe /lockedfiles >[/color] [color=#A23BEC]< %systemroot%\system32\*.in* >[/color] [2015/03/13 03:55:15 | 000,016,303 | ---- | M] () -- C:\Windows\system32\ieuinit.inf [2014/11/21 07:14:27 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\Microsoft.Management.Infrastructure.Native.Unmanaged.dll [2014/12/10 07:11:53 | 000,931,872 | ---- | M] () -- C:\Windows\system32\PerfStringBackup.INI [2014/11/21 06:50:48 | 000,002,255 | ---- | M] () -- C:\Windows\system32\WimBootCompress.ini [2015/03/04 03:12:52 | 000,141,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\Windows.UI.Input.Inking.dll [color=#A23BEC]< %systemroot%\PSS\* /s >[/color] [color=#A23BEC]< %systemroot%\Tasks\* >[/color] [2016/04/06 20:08:19 | 000,001,090 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [2016/04/06 10:00:46 | 000,001,094 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [2016/04/04 23:49:14 | 000,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT [color=#A23BEC]< %systemroot%\Tasks\*. >[/color] [color=#A23BEC]< %systemroot%\system32\Tasks\* >[/color] [color=#A23BEC]< %systemroot%\system32\Tasks\*. >[/color] [2013/08/22 17:36:31 | 000,000,000 | ---D | M] -- C:\Windows\system32\Tasks\Microsoft [color=#A23BEC]< %systemroot%\syswow64\Tasks\* >[/color] [color=#A23BEC]< %systemroot%\syswow64\Tasks\*. >[/color] [2013/08/22 17:36:31 | 000,000,000 | ---D | M] -- C:\Windows\syswow64\Tasks\Microsoft [color=#A23BEC]< %systemroot%\system32\drivers\*.sy* /lockedfiles >[/color] [color=#A23BEC]< %systemroot%\system32\config\*.exe /s >[/color] [color=#A23BEC]< %Systemroot%\ServiceProfiles\*.exe /s >[/color] [color=#A23BEC]< %systemroot%\system32\*.sys >[/color] [color=#A23BEC]< dir %Homedrive%\* /S /A:L /C >[/color] Le volume dans le lecteur C s'appelle Windows Le num‚ro de s‚rie du volume est 206A-1AAE R‚pertoire de C:\ 22/08/2013 16:45 Documents and Settings [C:\Users] 0 fichier(s) 0 octets R‚pertoire de C:\Program Files 29/08/2015 15:26 Fichiers communs [C:\Program Files\Common Files] 0 fichier(s) 0 octets R‚pertoire de C:\Program Files\Windows NT 29/08/2015 15:26 Accessoires [C:\Program Files\Windows NT\Accessories] 0 fichier(s) 0 octets R‚pertoire de C:\Program Files (x86)\Common Files\AV 02/04/2016 18:46 avast! Antivirus [C:\Program Files\Common Files\AV\avast! Antivirus] 0 fichier(s) 0 octets R‚pertoire de C:\ProgramData 22/08/2013 16:45 Application Data [C:\ProgramData] 29/08/2015 15:26 Bureau [C:\Users\Public\Desktop] 22/08/2013 16:45 Desktop [C:\Users\Public\Desktop] 22/08/2013 16:45 Documents [C:\Users\Public\Documents] 29/08/2015 15:26 Menu D‚marrer [C:\ProgramData\Microsoft\Windows\Start Menu] 29/08/2015 15:26 ModŠles [C:\ProgramData\Microsoft\Windows\Templates] 22/08/2013 16:45 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 22/08/2013 16:45 Templates [C:\ProgramData\Microsoft\Windows\Templates] 0 fichier(s) 0 octets R‚pertoire de C:\ProgramData\Microsoft\Windows\Start Menu 29/08/2015 15:26 Programmes [C:\ProgramData\Microsoft\Windows\Start Menu\Programs] 0 fichier(s) 0 octets R‚pertoire de C:\Users 22/08/2013 16:45 All Users [C:\ProgramData] 22/08/2013 16:45 Default User [C:\Users\Default] 0 fichier(s) 0 octets R‚pertoire de C:\Users\All Users 22/08/2013 16:45 Application Data [C:\ProgramData] 29/08/2015 15:26 Bureau [C:\Users\Public\Desktop] 22/08/2013 16:45 Desktop [C:\Users\Public\Desktop] 22/08/2013 16:45 Documents [C:\Users\Public\Documents] 29/08/2015 15:26 Menu D‚marrer [C:\ProgramData\Microsoft\Windows\Start Menu] 29/08/2015 15:26 ModŠles [C:\ProgramData\Microsoft\Windows\Templates] 22/08/2013 16:45 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 22/08/2013 16:45 Templates [C:\ProgramData\Microsoft\Windows\Templates] 0 fichier(s) 0 octets R‚pertoire de C:\Users\All Users\Microsoft\Windows\Start Menu 29/08/2015 15:26 Programmes [C:\ProgramData\Microsoft\Windows\Start Menu\Programs] 0 fichier(s) 0 octets R‚pertoire de C:\Users\Default 22/08/2013 16:45 Application Data [C:\Users\Default\AppData\Roaming] 22/08/2013 16:45 Cookies [C:\Users\Default\AppData\Local\Microsoft\Windows\INetCookies] 22/08/2013 16:45 Local Settings [C:\Users\Default\AppData\Local] 29/08/2015 15:26 Menu D‚marrer [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu] 29/08/2015 15:26 Mes documents [C:\Users\Default\Documents] 29/08/2015 15:26 ModŠles [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates] 22/08/2013 16:45 My Documents [C:\Users\Default\Documents] 22/08/2013 16:45 NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts] 22/08/2013 16:45 PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 22/08/2013 16:45 Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent] 22/08/2013 16:45 SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo] 22/08/2013 16:45 Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu] 22/08/2013 16:45 Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates] 29/08/2015 15:26 Voisinage d'impression [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 29/08/2015 15:26 Voisinage r‚seau [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts] 0 fichier(s) 0 octets R‚pertoire de C:\Users\Default\AppData\Local 22/08/2013 16:45 Application Data [C:\Users\Default\AppData\Local] 29/08/2015 15:26 Historique [C:\Users\Default\AppData\Local\Microsoft\Windows\History] 22/08/2013 16:45 History [C:\Users\Default\AppData\Local\Microsoft\Windows\History] 22/08/2013 16:45 Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache] 0 fichier(s) 0 octets R‚pertoire de C:\Users\Default\AppData\Local\Microsoft\Windows 22/08/2013 16:45 Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache] 0 fichier(s) 0 octets R‚pertoire de C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu 29/08/2015 15:26 Programmes [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs] 0 fichier(s) 0 octets R‚pertoire de C:\Users\Default\Documents 29/08/2015 15:26 Ma musique [C:\Users\Default\Music] 29/08/2015 15:26 Mes images [C:\Users\Default\Pictures] 29/08/2015 15:26 Mes vid‚os [C:\Users\Default\Videos] 22/08/2013 16:45 My Music [C:\Users\Default\Music] 22/08/2013 16:45 My Pictures [C:\Users\Default\Pictures] 22/08/2013 16:45 My Videos [C:\Users\Default\Videos] 0 fichier(s) 0 octets R‚pertoire de C:\Users\Public\Documents 29/08/2015 15:26 Ma musique [C:\Users\Public\Music] 29/08/2015 15:26 Mes images [C:\Users\Public\Pictures] 29/08/2015 15:26 Mes vid‚os [C:\Users\Public\Videos] 22/08/2013 16:45 My Music [C:\Users\Public\Music] 22/08/2013 16:45 My Pictures [C:\Users\Public\Pictures] 22/08/2013 16:45 My Videos [C:\Users\Public\Videos] 0 fichier(s) 0 octets R‚pertoire de C:\Users\Sawab 29/08/2015 15:30 Application Data [C:\Users\Sawab\AppData\Roaming] 29/08/2015 15:30 Cookies [C:\Users\Sawab\AppData\Local\Microsoft\Windows\INetCookies] 29/08/2015 15:30 Local Settings [C:\Users\Sawab\AppData\Local] 29/08/2015 15:30 Menu D‚marrer [C:\Users\Sawab\AppData\Roaming\Microsoft\Windows\Start Menu] 29/08/2015 15:30 Mes documents [C:\Users\Sawab\Documents] 29/08/2015 15:30 ModŠles [C:\Users\Sawab\AppData\Roaming\Microsoft\Windows\Templates] 29/08/2015 15:30 Recent [C:\Users\Sawab\AppData\Roaming\Microsoft\Windows\Recent] 29/08/2015 15:30 SendTo [C:\Users\Sawab\AppData\Roaming\Microsoft\Windows\SendTo] 29/08/2015 15:30 Voisinage d'impression [C:\Users\Sawab\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 29/08/2015 15:30 Voisinage r‚seau [C:\Users\Sawab\AppData\Roaming\Microsoft\Windows\Network Shortcuts] 0 fichier(s) 0 octets R‚pertoire de C:\Users\Sawab\AppData\Local 29/08/2015 15:30 Application Data [C:\Users\Sawab\AppData\Local] 29/08/2015 15:30 Historique [C:\Users\Sawab\AppData\Local\Microsoft\Windows\History] 29/08/2015 15:30 Temporary Internet Files [C:\Users\Sawab\AppData\Local\Microsoft\Windows\INetCache] 0 fichier(s) 0 octets R‚pertoire de C:\Users\Sawab\AppData\Local\Microsoft\Windows 29/08/2015 15:30 Temporary Internet Files [C:\Users\Sawab\AppData\Local\Microsoft\Windows\INetCache] 0 fichier(s) 0 octets R‚pertoire de C:\Users\Sawab\AppData\Local\Microsoft\Windows\INetCache 29/08/2015 15:30 Content.IE5 [C:\Users\Sawab\AppData\Local\Microsoft\Windows\INetCache\IE\] 0 fichier(s) 0 octets R‚pertoire de C:\Users\Sawab\AppData\Local\Microsoft\Windows\INetCache\Low 29/08/2015 17:34 Content.IE5 [C:\Users\Sawab\AppData\Local\Microsoft\Windows\INetCache\Low\IE\] 0 fichier(s) 0 octets R‚pertoire de C:\Users\Sawab\AppData\Roaming\Microsoft\Windows\Start Menu 29/08/2015 15:30 Programmes [C:\Users\Sawab\AppData\Roaming\Microsoft\Windows\Start Menu\Programs] 0 fichier(s) 0 octets R‚pertoire de C:\Users\Sawab\Documents 29/08/2015 15:30 Ma musique [C:\Users\Sawab\Music] 29/08/2015 15:30 Mes images [C:\Users\Sawab\Pictures] 29/08/2015 15:30 Mes vid‚os [C:\Users\Sawab\Videos] 0 fichier(s) 0 octets R‚pertoire de C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache 27/06/2015 04:32 Content.IE5 [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\] 0 fichier(s) 0 octets R‚pertoire de C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache 27/06/2015 04:32 Content.IE5 [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\] 0 fichier(s) 0 octets Total des fichiers list‚sÿ: 0 fichier(s) 0 octets 79 R‚p(s) 924ÿ641ÿ800ÿ192 octets libres [color=#A23BEC]< MD5 for: AFD.SYS >[/color] [2016/01/12 12:38:45 | 000,082,345 | ---- | M] () MD5=0C3BFF2960B47F486AA561E5A9F4C68F -- C:\Windows\WinSxS\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.3.9600.17194_none_c89bb81d326c6108\afd.sys [2015/10/13 19:10:48 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=A460C3AF3755A2A79A3C8EFE72E147B5 -- C:\Windows\SysNative\drivers\afd.sys [2015/10/13 19:10:48 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=A460C3AF3755A2A79A3C8EFE72E147B5 -- C:\Windows\WinSxS\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.3.9600.18089_none_c8ab70cd325fe044\afd.sys [color=#A23BEC]< MD5 for: ATAPI.SYS >[/color] [2013/08/22 14:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\Windows\SysNative\drivers\atapi.sys [2013/08/22 14:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_64aa4354da84c2df\atapi.sys [2013/08/22 14:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.3.9600.16384_none_cdf68824f580d510\atapi.sys [color=#A23BEC]< MD5 for: CDROM.SYS >[/color] [2013/08/22 10:46:35 | 000,164,352 | ---- | M] (Microsoft Corporation) MD5=C6796EA22B513E3457514D92DCDB1A3D -- C:\Windows\SysNative\drivers\cdrom.sys [2013/08/22 10:46:35 | 000,164,352 | ---- | M] (Microsoft Corporation) MD5=C6796EA22B513E3457514D92DCDB1A3D -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_42e9c29f0affc440\cdrom.sys [2013/08/22 10:46:35 | 000,164,352 | ---- | M] (Microsoft Corporation) MD5=C6796EA22B513E3457514D92DCDB1A3D -- C:\Windows\WinSxS\amd64_cdrom.inf_31bf3856ad364e35_6.3.9600.16384_none_5067bbed77be70be\cdrom.sys [color=#A23BEC]< MD5 for: DNSAPI.DLL >[/color] [2015/04/13 10:03:45 | 000,657,920 | ---- | M] (Microsoft Corporation) MD5=0B082D6D7A53D91678E7409DD145E89C -- C:\Windows\SysNative\dnsapi.dll [2015/04/13 10:03:45 | 000,657,920 | ---- | M] (Microsoft Corporation) MD5=0B082D6D7A53D91678E7409DD145E89C -- C:\Windows\WinSxS\amd64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_6.3.9600.17481_none_8646fe0af71f6b1d\dnsapi.dll [2015/04/13 10:03:45 | 000,498,688 | ---- | M] (Microsoft Corporation) MD5=205BDB00F4C032AF45A6BFD18EA7886C -- C:\Windows\WinSxS\wow64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_6.3.9600.17481_none_909ba85d2b802d18\dnsapi.dll [2015/04/13 10:03:45 | 000,498,688 | ---- | M] (Microsoft Corporation) MD5=68DF0C65BBE174F5697544F0B52DACC1 -- C:\Users\Sawab\AppData\Roaming\ZHP\Quarantine\dnsapi.dll [2015/04/13 10:03:45 | 000,657,920 | ---- | M] (Microsoft Corporation) MD5=6E311B91C2C821C254FC75AA64634E11 -- C:\Users\Sawab\AppData\Local\Temp\dnsapi.dll [color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color] [2015/09/07 18:32:04 | 000,087,190 | ---- | M] () MD5=1BF154F7BFAE2B9E0545FB09946C1817 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_42bfa1f94d79e1bb\explorer.exe [2015/09/07 20:19:20 | 000,107,122 | ---- | M] () MD5=52063502D4A2E28FEBEA781D0EE5C453 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_4d144c4b81daa3b6\explorer.exe [2015/06/27 13:58:51 | 002,207,488 | ---- | M] (Microsoft Corporation) MD5=91E24273FCA076EA9E65DAFA98901225 -- C:\Windows\SysWOW64\explorer.exe [2015/06/27 13:58:51 | 002,207,488 | ---- | M] (Microsoft Corporation) MD5=91E24273FCA076EA9E65DAFA98901225 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17667_none_4ce0410f82015c67\explorer.exe [2015/06/27 13:58:50 | 002,501,368 | ---- | M] (Microsoft Corporation) MD5=C10A66189DC8C090E7C84873EDCEBC88 -- C:\Windows\explorer.exe [2015/06/27 13:58:50 | 002,501,368 | ---- | M] (Microsoft Corporation) MD5=C10A66189DC8C090E7C84873EDCEBC88 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17667_none_428b96bd4da09a6c\explorer.exe [color=#A23BEC]< MD5 for: I8042PRT.SYS >[/color] [2015/04/13 10:03:45 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=49EE0AE9E5B64FFBBD06D55C4984B598 -- C:\Windows\SysNative\drivers\i8042prt.sys [2015/04/13 10:03:45 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=49EE0AE9E5B64FFBBD06D55C4984B598 -- C:\Windows\SysNative\DriverStore\FileRepository\keyboard.inf_amd64_554fdd4258a8be33\i8042prt.sys [2015/04/13 10:03:45 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=49EE0AE9E5B64FFBBD06D55C4984B598 -- C:\Windows\SysNative\DriverStore\FileRepository\msmouse.inf_amd64_1d3d10670190b8c1\i8042prt.sys [2015/04/13 10:03:45 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=49EE0AE9E5B64FFBBD06D55C4984B598 -- C:\Windows\WinSxS\amd64_keyboard.inf_31bf3856ad364e35_6.3.9600.17808_none_88674121acab842a\i8042prt.sys [2015/04/13 10:03:45 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=49EE0AE9E5B64FFBBD06D55C4984B598 -- C:\Windows\WinSxS\amd64_msmouse.inf_31bf3856ad364e35_6.3.9600.17808_none_3f4cdec5a60dcafe\i8042prt.sys [2015/09/07 18:28:33 | 000,000,012 | ---- | M] () MD5=E4151015F7A3FD7A0B165BC4B8C4425E -- C:\Windows\WinSxS\amd64_keyboard.inf_31bf3856ad364e35_6.3.9600.17480_none_8808b7d9acf3a45e\i8042prt.sys [2015/09/07 19:01:39 | 000,000,012 | ---- | M] () MD5=E4151015F7A3FD7A0B165BC4B8C4425E -- C:\Windows\WinSxS\amd64_msmouse.inf_31bf3856ad364e35_6.3.9600.17480_none_3eee557da655eb32\i8042prt.sys [color=#A23BEC]< MD5 for: NDIS.SYS >[/color] [2015/09/07 18:43:25 | 000,045,557 | ---- | M] () MD5=1AB7E4E27CE503B6C13409CB5617B967 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17400_none_4a664795fbc5e415\ndis.sys [2015/07/14 23:59:47 | 001,113,944 | ---- | M] (Microsoft Corporation) MD5=97DC5967F65503213FD1F1B3E4A6F983 -- C:\Windows\SysNative\drivers\ndis.sys [2015/07/14 23:59:47 | 001,113,944 | ---- | M] (Microsoft Corporation) MD5=97DC5967F65503213FD1F1B3E4A6F983 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17933_none_4a48e22dfbdb75b0\ndis.sys [color=#A23BEC]< MD5 for: NETBT.SYS >[/color] [2013/08/22 13:37:02 | 000,282,624 | ---- | M] (Microsoft Corporation) MD5=0217532E19A748F0E5D569307363D5FD -- C:\Windows\SysNative\drivers\netbt.sys [2013/08/22 13:37:02 | 000,282,624 | ---- | M] (Microsoft Corporation) MD5=0217532E19A748F0E5D569307363D5FD -- C:\Windows\WinSxS\amd64_microsoft-windows-netbt-minwin_31bf3856ad364e35_6.3.9600.16384_none_dc6ae14cabd6cc52\netbt.sys [color=#A23BEC]< MD5 for: TDX.SYS >[/color] [2015/10/13 19:10:44 | 000,108,032 | ---- | M] (Microsoft Corporation) MD5=E0BD2D83875464FEEEB242CBA8B7E073 -- C:\Windows\SysNative\drivers\tdx.sys [2015/10/13 19:10:44 | 000,108,032 | ---- | M] (Microsoft Corporation) MD5=E0BD2D83875464FEEEB242CBA8B7E073 -- C:\Windows\WinSxS\amd64_microsoft-windows-tdi-over-tcpip_31bf3856ad364e35_6.3.9600.18089_none_db00f686b00869ab\tdx.sys [2016/01/12 12:38:07 | 000,027,658 | ---- | M] () MD5=EC4E4B174D120B2654C6EE95F4ED5C0B -- C:\Windows\WinSxS\amd64_microsoft-windows-tdi-over-tcpip_31bf3856ad364e35_6.3.9600.16384_none_dafc2856b00caf2b\tdx.sys [color=#A23BEC]< MD5 for: VOLSNAP.SYS >[/color] [2014/11/21 07:12:50 | 000,310,080 | ---- | M] (Microsoft Corporation) MD5=64CA2B4A49A8EAF495E435623ECCE7DB -- C:\Windows\SysNative\drivers\volsnap.sys [2014/11/21 07:12:50 | 000,310,080 | ---- | M] (Microsoft Corporation) MD5=64CA2B4A49A8EAF495E435623ECCE7DB -- C:\Windows\SysNative\DriverStore\FileRepository\volume.inf_amd64_8687137d6e4faf5d\volsnap.sys [2014/11/21 07:12:50 | 000,310,080 | ---- | M] (Microsoft Corporation) MD5=64CA2B4A49A8EAF495E435623ECCE7DB -- C:\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_6.3.9600.17215_none_06c1ae9bcfd2737b\volsnap.sys [color=#A23BEC]< MD5 for: WININIT.EXE >[/color] [2016/01/12 12:38:42 | 000,014,762 | ---- | M] () MD5=46E896010015E22424B65055719EC363 -- C:\Windows\WinSxS\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.3.9600.17415_none_21fdb3b5d80e199e\wininit.exe [2015/10/05 20:28:10 | 000,146,432 | ---- | M] (Microsoft Corporation) MD5=EC302D06155F8E3C383750993FCB6B27 -- C:\Windows\SysNative\wininit.exe [2015/10/05 20:28:10 | 000,146,432 | ---- | M] (Microsoft Corporation) MD5=EC302D06155F8E3C383750993FCB6B27 -- C:\Windows\WinSxS\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.3.9600.18083_none_21afe54dd848cf8c\wininit.exe [color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color] [2016/01/12 12:38:44 | 000,050,608 | ---- | M] () MD5=139F3E7820BF0640805DE98C32D07B92 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17415_none_60cdfbfda8aeeef1\winlogon.exe [2016/03/10 18:09:32 | 000,076,560 | ---- | M] () MD5=373BAD8DF7EB7B148168E50885A1ABB8 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.18083_none_60802d95a8e9a4df\winlogon.exe [2016/01/05 17:00:41 | 000,570,880 | ---- | M] (Microsoft Corporation) MD5=B1102BBDDD9C87B3D609D6C08F7A3DBD -- C:\Windows\SysNative\winlogon.exe [2016/01/05 17:00:41 | 000,570,880 | ---- | M] (Microsoft Corporation) MD5=B1102BBDDD9C87B3D609D6C08F7A3DBD -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.18188_none_608530eda8e520b9\winlogon.exe [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 220 bytes -> C:\Users\Sawab\OneDrive:ms-properties < End of report >