~ ZHPDiag v2016.5.21.98 By Nicolas Coolman (2016/05/21) ~ Run by hju (Administrator) (2016/05/22 15:29:21) ~ Web: http://www.nicolascoolman.com ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ State version: Version OK ~ Mode: Scan ~ Report: C:\Users\hju\Desktop\ZHPDiag.txt ~ Report: C:\Users\hju\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ System startup: Normal (Normal boot) Windows VISTA, 32-bit Service Pack 1 (Build 6001) ---\\ Internet Browsers (2) - 0s GCIE: Google Chrome v49.0.2623.112 MSIE: Internet Explorer v7.0.6001.18000 ---\\ Windows Product Information (4) - 0s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK Windows Activation Technologies : KO ---\\ System protection software (2) - 5s ESET Smart Security v9.0.381.2 Malwarebytes Anti-Malware version 2.2.1.1043 ---\\ System protection software (Superfluous) (1) - 5s McAfee Security Scan Plus v3.8.141.11 ---\\ Surveillance software (2) - 6s Adobe Flash Player 21 PPAPI Adobe Reader X ---\\ Information on the system (6) - 0s ~ Operating System: x86 Family 6 Model 15 Stepping 13, GenuineIntel ~ Operating System: 32-bit ~ Boot mode: Normal (Normal boot) Total RAM: 3074.504 MB (43% free) System Restore: Activé (Enable) System drive C: has 44 GB () free of 228 GB ---\\ Connection to the system mode (3) - 0s ~ Computer Name: HJU-PC ~ User Name: hju ~ Logged in as Administrator ---\\ Enumeration of the disk units (2) - 0s ~ Drive C: has 44 GB free of 228 GB (System) ~ Drive D: has 1 GB free of 9 GB ---\\ State of the Windows Security Center (11) - 0s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ---\\ Search Generic System Files (23) - 2s [MD5.4F554999D7D5F05DAAEBBA7B5BA1089D] - 29/10/2008 - (.Microsoft Corporation - Windows Explorer.) -- C:\Windows\Explorer.exe [2927104] =>.Microsoft Corporation [MD5.4B555106290BD117334E9A08761C035A] - 02/11/2006 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe [44544] =>.Microsoft Corporation [MD5.101BA3EA053480BB5D957EF37C06B5ED] - 21/01/2008 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\Windows\System32\Wininit.exe [96768] =>.Microsoft Corporation [MD5.DA5A72211661C7F162B332FEA4F09A69] - 21/04/2011 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\Windows\System32\wininet.dll [833024] =>.Microsoft Corporation [MD5.C2610B6BDBEFC053BBDAB4F1B965CB24] - 21/01/2008 - (.Microsoft Corporation - Windows Logon Application.) -- C:\Windows\System32\Winlogon.exe [314880] =>.Microsoft Corporation [MD5.5665120753FCE7123C4DEACE241EE715] - 02/03/2011 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\System32\dnsapi.dll [167936] =>.Microsoft Corporation [MD5.48EB99503533C27AC6135648E5474457] - 21/04/2011 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [273408] =>.Microsoft Corporation [MD5.2D9C903DC76A66813D350A562DE40ED9] - 21/01/2008 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [21560] =>.Microsoft Windows® [MD5.7ADD03E75BEB9E6DD102C3081D29840A] - 21/01/2008 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [70144] =>.Microsoft Corporation [MD5.1EC25CEA0DE6AC4718BF89F9E1778B57] - 21/01/2008 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [67072] =>.Microsoft Corporation [MD5.A3E9FA213F443AC77C7746119D13FEEC] - 14/04/2011 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [75264] =>.Microsoft Corporation [MD5.C87B1EE051C0464491C1A7B03FA0BC99] - 21/01/2008 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [53760] =>.Microsoft Corporation [MD5.22D56C8184586B7A1F6FA60BE5F5A2BD] - 21/01/2008 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\Windows\System32\drivers\i8042prt.sys [54784] =>.Microsoft Corporation [MD5.8793643A67B42CEC66490B2A0CF92D68] - 21/01/2008 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [100864] =>.Microsoft Corporation [MD5.5734A0F2BE7E495F7D3ED6EFD4B9F5A1] - 29/04/2011 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [105984] =>.Microsoft Corporation [MD5.7C5FEE5B1C5728507CD96FB4A13E7A02] - 21/01/2008 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [184320] =>.Microsoft Corporation [MD5.B4EFFE29EB4F15538FD8A9681108492D] - 21/01/2008 - (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\drivers\ntfs.sys [1081912] =>.Microsoft Windows® [MD5.0FA9B5055484649D63C303FE404E5F4D] - 02/11/2006 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\Windows\System32\drivers\Parport.sys [79360] =>.Microsoft Corporation [MD5.A214ADBAF4CB47DD2728859EF31F26B0] - 21/01/2008 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [76288] =>.Microsoft Corporation [MD5.FBC0BACD9C3D7F6956853F64A66E252D] - 21/01/2008 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [248832] =>.Microsoft Corporation [MD5.031E6BCD53C9B2B9ACE111EAFEC347B6] - 21/01/2008 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [66560] =>.Microsoft Corporation [MD5.D09276B1FAB033CE1D40DCBDF303D10F] - 21/01/2008 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [71680] =>.Microsoft Corporation [MD5.D8B4A53DD2769F226B3EB374374987C9] - 21/01/2008 - (.Microsoft Corporation - Volume Shadow Copy Driver.) -- C:\Windows\System32\drivers\volsnap.sys [227896] =>.Microsoft Windows® ---\\ Non Microsoft non disabled Windows Services (16) - 3s O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated® O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe =>.Apple Inc.® O23 - Service: Bonjour Service (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.® O23 - Service: ESET Service (ekrn) . (.ESET - ESET Service.) - C:\Program Files\ESET\ESET Smart Security\ekrn.exe =>.ESET, spol. s r.o.® O23 - Service: خدمة Google Update (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc® O23 - Service: HP Health Check Service (HP Health Check Service) . (.Hewlett-Packard - HP Health Check Service.) - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe =>.Hewlett-Packard O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) . (.Hewlett-Packard Company - LightScribe Service.) - C:\Program Files\Common Files\LightScribe\LSSrvc.exe =>.Hewlett-Packard Company O23 - Service: (MBAMScheduler) . (.Malwarebytes - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe =>.Malwarebytes Corporation® O23 - Service: (MBAMService) . (.Malwarebytes - Malwarebytes Anti-Malware.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation® O23 - Service: PLFlash DeviceIoControl Service (PLFlash DeviceIoControl Service) . (.Prolific Technology Inc. - PLFlash DeviceIoControl Service.) - C:\WINDOWS\System32\IoctlSvc.exe =>.Prolific Technology Inc. O23 - Service: RealNetworks Downloader Resolver Service (RealNetworks Downloader Resolver Service) . (...) - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe =>.RealNetworks, Inc.® O23 - Service: Recovery Service for Windows (Recovery Service for Windows) . (.Copyright (C) 2008 - STServices.) - C:\WINDOWS\SMINST\BLService.exe {495AEE4183E3ED8C627F91A02FF07DF4} O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) . (.Copyright 2004 - RichVideo Module.) - C:\Program Files\CyberLink\Shared Files\RichVideo.exe =>.CyberLink® O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe =>.Skype Software Sarl® O23 - Service: خدمة Vodafone Mobile Broadband (VmbService) . (.Vodafone - VmbService.) - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe =>.Vodafone O23 - Service: XAudioService (XAudioService) . (.Conexant Systems, Inc. - Modem Audio Service.) - C:\WINDOWS\System32\drivers\XAudio.exe =>.Conexant Systems, Inc. ---\\ Services not Microsoft (SR=Run, SS=Stop) (27) - 143s SR - Auto [18/12/2013] [ 65432] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated® SS - Demand [22/05/2016] [ 269504] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\WINDOWS\System32\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated® SR - Auto [02/09/2015] [ 60720] Apple Mobile Device (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe =>.Apple Inc.® SR - Auto [30/08/2011] [ 390504] Bonjour Service (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.® SR - Demand [03/04/2008] [ 193840] Com4QLBEx (Com4QLBEx) . (.Hewlett-Packard Development Company, L.P..) - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe =>.Hewlett-Packard Company® SR - Auto [13/04/2016] [ 1982752] ESET Service (ekrn) . (.ESET.) - C:\Program Files\ESET\ESET Smart Security\ekrn.exe =>.ESET, spol. s r.o.® SS - Demand [13/08/2015] [ 209952] GamesAppService (GamesAppService) . (.WildTangent, Inc..) - C:\Program Files\WildTangent Games\App\GamesAppService.exe =>.WildTangent Inc® SS - Auto [28/08/2015] [ 144200] خدمة Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc® SS - Demand [28/08/2015] [ 144200] خدمة Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc® SR - Auto [15/04/2008] [ 94208] HP Health Check Service (HP Health Check Service) . (.Hewlett-Packard.) - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe =>.Hewlett-Packard SR - Demand [02/05/2008] [ 165192] hpqwmiex (hpqwmiex) . (.Hewlett-Packard Development Company, L.P..) - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe =>.Hewlett-Packard Company® SS - Demand [22/10/2004] [ 73728] InstallDriver Table Manager (IDriverT) . (.Macrovision Corporation.) - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe =>.Macrovision Corporation SR - Demand [11/09/2015] [ 540944] خدمة iPod (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe =>.Apple Inc.® SR - Auto [26/02/2008] [ 73728] LightScribeService Direct Disc Labeling Service (LightScribeService) . (.Hewlett-Packard Company.) - C:\Program Files\Common Files\LightScribe\LSSrvc.exe =>.Hewlett-Packard Company SR - Auto [10/03/2016] [ 1514464] (MBAMScheduler) . (.Malwarebytes.) - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe =>.Malwarebytes Corporation® SR - Auto [10/03/2016] [ 1136608] (MBAMService) . (.Malwarebytes.) - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation® SS - Demand [16/01/2014] [ 235696] McAfee Security Scan Component Host Service (McComponentHostService) . (.McAfee, Inc..) - C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe =>.McAfee, Inc.® SS - Demand [07/04/2008] [ 800040] NBService (NBService) . (.Nero AG.) - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe =>.Nero AG® SR - Demand [21/01/2008] [ 275752] NMIndexingService (NMIndexingService) . (.Nero AG.) - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe =>.Nero AG® SR - Auto [18/12/2006] [ 81920] PLFlash DeviceIoControl Service (PLFlash DeviceIoControl Service) . (.Prolific Technology Inc..) - C:\WINDOWS\System32\IoctlSvc.exe =>.Prolific Technology Inc. SR - Auto [14/08/2013] [ 39056] RealNetworks Downloader Resolver Service (RealNetworks Downloader Resolver Service) . (...) - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe =>.RealNetworks, Inc.® SR - Auto [26/04/2008] [ 361808] Recovery Service for Windows (Recovery Service for Windows) . (.Copyright (C) 2008.) - C:\WINDOWS\SMINST\BLService.exe {495AEE4183E3ED8C627F91A02FF07DF4} SR - Auto [09/01/2007] [ 272024] Cyberlink RichVideo Service(CRVS) (RichVideo) . (.Copyright 2004.) - C:\Program Files\CyberLink\Shared Files\RichVideo.exe =>.CyberLink® SS - Auto [10/12/2014] [ 315496] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe =>.Skype Software Sarl® SR - Auto [05/02/2013] [ 8704] خدمة Vodafone Mobile Broadband (VmbService) . (.Vodafone.) - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe =>.Vodafone SR - Auto [18/10/2007] [ 386560] XAudioService (XAudioService) . (.Conexant Systems, Inc..) - C:\WINDOWS\System32\drivers\XAudio.exe =>.Conexant Systems, Inc. ---\\ Process running (49) - 6s [MD5.48640AEF703DAD46BD2F84573B6AEBBF] - (.ESET - ESET Service.) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1982752] [PID.864] =>.ESET, spol. s r.o.® [MD5.B362181ED3771DC03B4141927C80F801] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [65432] [PID.268] =>.Adobe Systems, Incorporated® [MD5.A9AE03362A846898368653E94B6DB1AA] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [60720] [PID.308] =>.Apple Inc.® [MD5.DB5BEA73EDAF19AC68B2C0FAD0F92B1A] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [390504] [PID.312] =>.Apple Inc.® [MD5.984ECB68ED2A2B2E6A544E87E24FBA2D] - (.Hewlett-Packard Company - LightScribe Service.) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728] [PID.748] =>.Hewlett-Packard Company [MD5.9611577752E293259C7DCE19E9026362] - (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464] [PID.1524] =>.Malwarebytes Corporation® [MD5.F1A89A34388B5626F1548D393B23ECB1] - (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1136608] [PID.768] =>.Malwarebytes Corporation® [MD5.875E4E0661F3A5994DF9E5E3A0A4F96B] - (.Prolific Technology Inc. - PLFlash DeviceIoControl Service.) -- C:\WINDOWS\System32\IoctlSvc.exe [81920] [PID.2100] =>.Prolific Technology Inc. [MD5.96EFEC24346A8EB1157E80523079ADDC] - (...) -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056] [PID.2124] =>.RealNetworks, Inc.® [MD5.431723F23D0E065BEF502389E8FFDC10] - (.Copyright (C) 2008 - STServices.) -- C:\WINDOWS\SMINST\BLService.exe [361808] [PID.2152] {495AEE4183E3ED8C627F91A02FF07DF4} [MD5.17E0BEF5CA5C9CE52CC8082AC6EBC449] - (.Copyright 2004 - RichVideo Module.) -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024] [PID.2184] =>.CyberLink® [MD5.CD5F291A1161F15896D1A4D63DAFF5DF] - (.Conexant Systems, Inc. - Modem Audio Service.) -- C:\WINDOWS\System32\drivers\XAudio.exe [386560] [PID.2376] =>.Conexant Systems, Inc. [MD5.A56DD75BCDA446D2305F00E793406493] - (.Vodafone - VmbService.) -- C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [8704] [PID.2436] =>.Vodafone [MD5.D13E6BFD7E9189D26A42E94CB2447044] - (.Hewlett-Packard - HP Health Check Service.) -- c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [94208] [PID.3648] =>.Hewlett-Packard [MD5.56FE3C885B0901601549E23E7A435984] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files\Google\Update\1.3.30.3\GoogleCrashHandler.exe [250008] [PID.3680] =>.Google Inc® [MD5.67F104A5FE8A52CD1D7FBAE85FE9C71C] - (.ESET - ESET Main GUI.) -- C:\Program Files\ESET\ESET Smart Security\egui.exe [5584032] [PID.2396] =>.ESET, spol. s r.o.® [MD5.8E98E3EC16D2641005B4748CD330FB45] - (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes Anti-Malware\mbam.exe [9926112] [PID.3248] =>.Malwarebytes Corporation® [MD5.AE567D261D281B51BE55E53A786E8574] - (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1049896] [PID.3516] =>.Synaptics Incorporated® [MD5.7F297042DC60B6BB1A5B13261EE5F0F1] - (.Intel Corporation - hkcmd Module.) -- C:\WINDOWS\System32\hkcmd.exe [170520] [PID.2508] =>.Intel Corporation® [MD5.4F694D7518AA5353C382959AD7D7A233] - (.Intel Corporation - persistence Module.) -- C:\WINDOWS\System32\igfxpers.exe [145944] [PID.3660] =>.Intel Corporation® [MD5.4551FB332E320838724C38925BF46DC0] - (.CyberLink Corp. - HP QuickPlay Resident Program.) -- C:\Program Files\HP\QuickPlay\QPService.exe [468264] [PID.3272] =>.CyberLink® [MD5.DCB36D4ED2950F3F675D27D422A6B365] - (.Hewlett-Packard Development Company, L.P. - Quick Launch Buttons.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe [202032] [PID.3664] =>.Hewlett-Packard Company® [MD5.8CB896C573FD15AE8B13180DA53E93D2] - (.Hewlett-Packard Development Company, L.P. - HPWAMain Module.) -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [488752] [PID.1932] =>.Hewlett-Packard Company® [MD5.E7BAA318D3F1287C828F323B3BA9A96E] - (.Intel Corporation - igfxsrvc Module.) -- C:\WINDOWS\System32\igfxsrvc.exe [256536] [PID.2776] =>.Intel Corporation® [MD5.627201AE01E87E730C70C6E256937E8D] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [157456] [PID.2420] =>.Apple Inc.® [MD5.6513807FEE68E6C32E67437EE3FFB6C8] - (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe [596504] [PID.1388] =>.Oracle America, Inc.® [MD5.DE959229C196DB0067F867190D2E14A1] - (.Vodafone - MobileBroadband.) -- C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [76288] [PID.2360] =>.Vodafone [MD5.3B29C6706DFA5C312A69D82285AD8A72] - (.Vodafone - VmbNotifier.) -- C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbNotifier.exe [1861632] [PID.3752] =>.Vodafone [MD5.6CF023F0A798C56599B8EA9FF9F083A0] - (.Hewlett-Packard Company - .) -- C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2289664] [PID.3348] =>.Hewlett-Packard Company [MD5.9C207FAA17BAD53FC8104B25545928E0] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe [30872168] [PID.2352] =>.Skype Software Sarl® [MD5.1B31D1266691EDD4224B0036449F14B4] - (.Nero AG - Nero Home.) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [152872] [PID.2172] =>.Nero AG® [MD5.1665C7121A026DF10C903DB9BC5E9D43] - (.Hewlett-Packard Development Company, L.P. - hpqwmiex Module.) -- C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [165192] [PID.3676] =>.Hewlett-Packard Company® [MD5.28F169A082AD94C13F7D245287A5FB90] - (.Google - Google Drive.) -- C:\Program Files\Google\Drive\googledrivesync.exe [23484296] [PID.1164] =>.Google Inc® [MD5.DD7423ABBE2913E70D50E9318AD57EE4] - (.Google Inc. - Google Installer.) -- C:\Users\hju\AppData\Local\Google\Update\GoogleUpdate.exe [144200] [PID.840] =>.Google Inc® [MD5.8D07F0687318214A3CEF62EA1048D101] - (.Hewlett-Packard Development Company, L.P. - Module to process WiFi messages..) -- C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.exe [316720] [PID.4540] =>.Hewlett-Packard Company® [MD5.7795F8CEBC284A426B53F541E538695F] - (.Hewlett-Packard Development Company, L.P. - Com for QLB application.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [193840] [PID.4636] =>.Hewlett-Packard Company® [MD5.56FE3C885B0901601549E23E7A435984] - (.Google Inc. - Google Crash Handler.) -- C:\Users\hju\AppData\Local\Google\Update\1.3.30.3\GoogleCrashHandler.exe [250008] [PID.5300] =>.Google Inc® [MD5.1EDC4865C8003A0251956835273904B1] - (.Copyright (c) 2005 - 2008 Hewlett-Packard Development - HpqToaster Module.) -- C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe [685360] [PID.1232] =>.Hewlett-Packard Company® [MD5.193FA51DDDD0BFFDED1C340F0434999A] - (.Nero AG - Nero Home.) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [275752] [PID.5188] =>.Nero AG® [MD5.96E8CF4D3731D90058DE39A3BECAD707] - (.Nero AG - Nero Home.) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe [1201448] [PID.5512] =>.Nero AG® [MD5.C23748B33D431E4CD5CA2E62500545FF] - (.Apple Inc. - iPodService Module (32-bit).) -- C:\Program Files\iPod\bin\iPodService.exe [540944] [PID.4236] =>.Apple Inc.® [MD5.A8AD97956A0F4408CB3AA03EDD2B8BC1] - (.Synaptics, Inc. - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [103720] [PID.3736] =>.Synaptics Incorporated® [MD5.388DE3C872874C49EF5E7B18EC36047A] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\hju\AppData\Roaming\ZHP\ZHPDiag3.exe [2208768] [PID.4432] =>.Nicolas Coolman [MD5.28F169A082AD94C13F7D245287A5FB90] - (.Google - Google Drive.) -- C:\Program Files\Google\Drive\googledrivesync.exe [23484296] [PID.6128] =>.Google Inc® [MD5.1BF101278422AFCD6793092AED8E899C] - (.Google Inc. - Google Chrome.) -- C:\Users\hju\AppData\Local\Google\Chrome SxS\Application\chrome.exe [743752] [PID.5868] =>.Google Inc® [MD5.1BF101278422AFCD6793092AED8E899C] - (.Google Inc. - Google Chrome.) -- C:\Users\hju\AppData\Local\Google\Chrome SxS\Application\chrome.exe [743752] [PID.3720] =>.Google Inc® [MD5.1BF101278422AFCD6793092AED8E899C] - (.Google Inc. - Google Chrome.) -- C:\Users\hju\AppData\Local\Google\Chrome SxS\Application\chrome.exe [743752] [PID.4692] =>.Google Inc® [MD5.1BF101278422AFCD6793092AED8E899C] - (.Google Inc. - Google Chrome.) -- C:\Users\hju\AppData\Local\Google\Chrome SxS\Application\chrome.exe [743752] [PID.5536] =>.Google Inc® [MD5.1BF101278422AFCD6793092AED8E899C] - (.Google Inc. - Google Chrome.) -- C:\Users\hju\AppData\Local\Google\Chrome SxS\Application\chrome.exe [743752] [PID.3152] =>.Google Inc® ---\\ Google Chrome, Start,Search,Extensions (16) - 1s G0 - GCSP: Preferences [User Data\Default][HomePage] http://img15.hostingpics.net G0 - GCSP: Preferences [User Data\Default][HomePage] http://platform.twitter.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google-analytics.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.startimes.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://clients2.google.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.gstatic.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://stats.g.doubleclick.net G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.ro G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [lmjegmlicamnimmfhcmpkclmigmmcbeh] Application Launcher for Drive (by Google) G2 - GCE: Preference [User Data\Default] [ngpampappnmepgilojfohadhhmbhlaek] IDM Integration Module G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc. ---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (11) - 8s M0 - MFSP: prefs.js [hju - ch0apz00.default-1416242166785] http://mysearch.sweetpacks.com/?barid=1605756271880948072&src=10&i=48&did=11034&&st=23 =>PUP.Optional.SweetIM P2 - EXT FILE: (...) -- C:\Users\hju\AppData\Roaming\Mozilla\Firefox\Profiles\ch0apz00.default-1416242166785\extensions\{8ced2570-079f-4462-9a2e-59320557c691}.xpi P2 - EXT FILE: (...) -- C:\Users\hju\AppData\Roaming\Mozilla\Firefox\Profiles\ch0apz00.default-1416242166785\searchplugins\dsrlte1.xml =>PUP.Optional.PaybyAds P2 - EXT: (. - SuperBuy4U.) -- C:\Users\hju\AppData\Roaming\Mozilla\Firefox\Profiles\ch0apz00.default-1416242166785\extensions\8dmmgBOD@gmail.com P2 - EXT: (. - web disco.) -- C:\Users\hju\AppData\Roaming\Mozilla\Firefox\Profiles\ch0apz00.default-1416242166785\extensions\FlaM6L@gmail.com P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\WINDOWS\System32\Macromed\Flash\NPSWF32_21_0_0_242.dll =>.Adobe Systems Incorporated P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (.Apple Inc..) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll =>.Apple Inc. P2 - FPN: [HKLM] [@flyordie.com/GamesPlugin] - (.Solware.) -- C:\Program Files\Flyordie Plugin\npfod.dll P2 - FPN: [HKLM] [@veetle.com/veetleCorePlugin,version=0.9.19] - (.Veetle Inc.) -- C:\Program Files\Veetle\plugins\npVeetle.dll P2 - FPN: [HKLM] [@veetle.com/veetlePlayerPlugin,version=0.9.18] - (.Veetle Inc.) -- C:\Program Files\Veetle\Player\npvlc.dll P2 - FPN: [HKLM] [@WildTangent.com/GamesAppPresenceDetector,Version=1.0] - (.WildTangent.) -- C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll =>.WildTangent ---\\ Internet Explorer Extensions, Start, Search (10) - 0s R0 - HKCU\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.whitesmoke.com/ =>PUP.Optional.WhiteSmoke R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = http://www.google.com R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 1 ---\\ Internet Explorer, Proxy Management (6) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl" ---\\ Hosts file redirection (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (20) ---\\ Browser Helper Object (BHO) (9) - 1s O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files\Internet Download Manager\IDMIECC.dll =>.Tonec Inc.® O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} . (.McAfee, Inc. - Quick Browser Identifier for MSS+ Tool.) -- C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll =>.McAfee, Inc.® O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} . (.RealDownloader - RealPlayer Download and Record Plugin.) -- C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll =>.RealNetworks, Inc.® O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} . (.Microsoft Corp. - Microsoft Search Helper Extention.) -- C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll =>.Microsoft Corporation® O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} . (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll =>.Microsoft Corporation® O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll =>.Oracle America, Inc.® O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll =>.Microsoft Corporation® O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Skype Technologies S.A. - Skype add-on for IE.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll =>.Skype Technologies SA® O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll =>.Oracle America, Inc.® ---\\ Auto loading programs from Registry and folders (42) - 3s O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe =>.Synaptics Incorporated® O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\WINDOWS\System32\igfxtray.exe =>.Intel Corporation® O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\WINDOWS\System32\hkcmd.exe =>.Intel Corporation® O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\WINDOWS\System32\igfxpers.exe =>.Intel Corporation® O4 - HKLM\..\Run: [UCam_Menu] . (.CyberLink Corp. - StartMen Application.) -- C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe =>.CyberLink® O4 - HKLM\..\Run: [QPService] . (.CyberLink Corp. - HP QuickPlay Resident Program.) -- C:\Program Files\HP\QuickPlay\QPService.exe =>.CyberLink® O4 - HKLM\..\Run: [Windows Defender] . (.Microsoft Corporation - Windows Defender User Interface.) -- C:\Program Files\Windows Defender\MSASCui.exe =>.Microsoft Windows® O4 - HKLM\..\Run: [QlbCtrl.exe] . (.Hewlett-Packard Development Company, L.P. - Quick Launch Buttons.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe =>.Hewlett-Packard Company® O4 - HKLM\..\Run: [hpWirelessAssistant] . (.Hewlett-Packard Development Company, L.P. - HPWAMain Module.) -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe =>.Hewlett-Packard Company® O4 - HKLM\..\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe =>.Apple Inc.® O4 - HKLM\..\Run: [GrooveMonitor] . (.Microsoft Corporation - GrooveMonitor Utility.) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe =>.Microsoft Corporation® O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe =>.Adobe Systems Incorporated® O4 - HKLM\..\Run: [NeroFilterCheck] . (.Nero AG - NeroCheck.) -- C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe =>.Nero AG® O4 - HKLM\..\Run: [Chedot] C:\Users\300049\AppData\Local\Chedot\Application\chedot.exe (.not file.) O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe =>.Apple Inc.® O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe =>.Oracle America, Inc.® O4 - HKLM\..\Run: [MobileBroadband] . (.Vodafone - MobileBroadband.) -- C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe =>.Vodafone O4 - HKLM\..\Run: [VmbNotifier] . (.Vodafone - VmbNotifier.) -- C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbNotifier.exe =>.Vodafone O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Sidebar.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation O4 - HKCU\..\Run: [LightScribe Control Panel] . (.Hewlett-Packard Company - .) -- C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe =>.Hewlett-Packard Company O4 - HKCU\..\Run: [WebcamMaxAutoRun] . (.CoolwareMax - WebcamMax.) -- C:\Program Files\WebcamMax\WebcamMax.exe {00BB9E5872C907F4BB51ED8D5898FCDBF4} O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Facebook Installer.) -- C:\Users\hju\AppData\Local\Facebook\Update\FacebookUpdate.exe =>.Facebook, Inc.® O4 - HKCU\..\Run: [UIExec] C:\Program Files\Cela.C.M\cm\UIExec.exe (.not file.) O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] . (.Nero AG - Nero Home.) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe =>.Nero AG® O4 - HKCU\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\WINDOWS\ehome\ehtray.exe =>.Microsoft Corporation O4 - HKCU\..\Run: [GoogleDriveSync] . (.Google - Google Drive.) -- C:\Program Files\Google\Drive\googledrivesync.exe =>.Google Inc® O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Google Installer.) -- C:\Users\hju\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc® O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Sidebar.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] . (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Sidebar.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] . (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-460551808-122963112-912713091-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Sidebar.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-460551808-122963112-912713091-1000\..\Run: [LightScribe Control Panel] . (.Hewlett-Packard Company - .) -- C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe =>.Hewlett-Packard Company O4 - HKUS\S-1-5-21-460551808-122963112-912713091-1000\..\Run: [WebcamMaxAutoRun] . (.CoolwareMax - WebcamMax.) -- C:\Program Files\WebcamMax\WebcamMax.exe {00BB9E5872C907F4BB51ED8D5898FCDBF4} O4 - HKUS\S-1-5-21-460551808-122963112-912713091-1000\..\Run: [Facebook Update] . (.Facebook Inc. - Facebook Installer.) -- C:\Users\hju\AppData\Local\Facebook\Update\FacebookUpdate.exe =>.Facebook, Inc.® O4 - HKUS\S-1-5-21-460551808-122963112-912713091-1000\..\Run: [UIExec] C:\Program Files\Cela.C.M\cm\UIExec.exe (.not file.) O4 - HKUS\S-1-5-21-460551808-122963112-912713091-1000\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - HKUS\S-1-5-21-460551808-122963112-912713091-1000\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] . (.Nero AG - Nero Home.) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe =>.Nero AG® O4 - HKUS\S-1-5-21-460551808-122963112-912713091-1000\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\WINDOWS\ehome\ehtray.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-460551808-122963112-912713091-1000\..\Run: [GoogleDriveSync] . (.Google - Google Drive.) -- C:\Program Files\Google\Drive\googledrivesync.exe =>.Google Inc® O4 - HKUS\S-1-5-21-460551808-122963112-912713091-1000\..\Run: [Google Update] . (.Google Inc. - Google Installer.) -- C:\Users\hju\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc® ---\\ Global shortcuts Startup (74) - 17s O4 - GS\Desktop [300049]: CueClub.lnk . (...) C:\Program Files\CueClub\cueclub.exe O4 - GS\Desktop [300049]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\hju\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc® O4 - GS\Desktop [300049]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files\Internet Download Manager\IDMan.exe {7828C7315808BC8717710E13FA3C0B24} =>.Tonec Inc. O4 - GS\Desktop [300049]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\hju\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [300049]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\hju\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [300049]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [300049]: Mozilla Firefox.lnk . (...) C:\Program Files\Mozilla Firefox\firefox.exe O4 - GS\Quicklaunch [300049]: Nero Home.lnk . (.Nero AG - Nero Home.) C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe =>.Nero AG® O4 - GS\Quicklaunch [300049]: Nero StartSmart.lnk . (.Nero AG - Nero StartSmart.) C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe =>.Nero AG® O4 - GS\Quicklaunch [300049]: PhotoScape.lnk . (.Copyright (C) 2005 - PhotoScape.) C:\Program Files\PhotoScape\PhotoScape.exe =>.Mooii Tech® O4 - GS\Quicklaunch [300049]: Samsung Kies 3.lnk . (.Samsung - Kies.) C:\Program Files\SAMSUNG\Kies3\Kies3.exe =>.Samsung Electronics CO., LTD.® O4 - GS\Quicklaunch [300049]: Uninstall Athan.lnk . (.Indigo Rose Corporation - SUF60Runtime.) C:\Windows\iun6002.exe O4 - GS\Quicklaunch [300049]: WildTangent Games App - hp.lnk . (.WildTangent - WildTangent Games App.) C:\Program Files\WildTangent Games\App\GameConsole-wt.exe =>.WildTangent Inc® O4 - GS\Quicklaunch [300049]: Yahoo! Messenger.lnk . (.Yahoo! Inc. - Yahoo! Messenger.) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe =>.Yahoo! Inc.® O4 - GS\sendTo [300049]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - GS\Desktop [Administrator]: CueClub.lnk . (...) C:\Program Files\CueClub\cueclub.exe O4 - GS\Desktop [Administrator]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\hju\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc® O4 - GS\Desktop [Administrator]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files\Internet Download Manager\IDMan.exe {7828C7315808BC8717710E13FA3C0B24} =>.Tonec Inc. O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\hju\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Administrator]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\hju\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Administrator]: Mozilla Firefox.lnk . (...) C:\Program Files\Mozilla Firefox\firefox.exe O4 - GS\Quicklaunch [Administrator]: Nero Home.lnk . (.Nero AG - Nero Home.) C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe =>.Nero AG® O4 - GS\Quicklaunch [Administrator]: Nero StartSmart.lnk . (.Nero AG - Nero StartSmart.) C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe =>.Nero AG® O4 - GS\Quicklaunch [Administrator]: PhotoScape.lnk . (.Copyright (C) 2005 - PhotoScape.) C:\Program Files\PhotoScape\PhotoScape.exe =>.Mooii Tech® O4 - GS\Quicklaunch [Administrator]: Samsung Kies 3.lnk . (.Samsung - Kies.) C:\Program Files\SAMSUNG\Kies3\Kies3.exe =>.Samsung Electronics CO., LTD.® O4 - GS\Quicklaunch [Administrator]: Uninstall Athan.lnk . (.Indigo Rose Corporation - SUF60Runtime.) C:\Windows\iun6002.exe O4 - GS\Quicklaunch [Administrator]: WildTangent Games App - hp.lnk . (.WildTangent - WildTangent Games App.) C:\Program Files\WildTangent Games\App\GameConsole-wt.exe =>.WildTangent Inc® O4 - GS\Quicklaunch [Administrator]: Yahoo! Messenger.lnk . (.Yahoo! Inc. - Yahoo! Messenger.) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe =>.Yahoo! Inc.® O4 - GS\sendTo [Administrator]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - GS\Desktop [Guest]: CueClub.lnk . (...) C:\Program Files\CueClub\cueclub.exe O4 - GS\Desktop [Guest]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\hju\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc® O4 - GS\Desktop [Guest]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files\Internet Download Manager\IDMan.exe {7828C7315808BC8717710E13FA3C0B24} =>.Tonec Inc. O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\hju\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Guest]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\hju\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Guest]: Mozilla Firefox.lnk . (...) C:\Program Files\Mozilla Firefox\firefox.exe O4 - GS\Quicklaunch [Guest]: Nero Home.lnk . (.Nero AG - Nero Home.) C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe =>.Nero AG® O4 - GS\Quicklaunch [Guest]: Nero StartSmart.lnk . (.Nero AG - Nero StartSmart.) C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe =>.Nero AG® O4 - GS\Quicklaunch [Guest]: PhotoScape.lnk . (.Copyright (C) 2005 - PhotoScape.) C:\Program Files\PhotoScape\PhotoScape.exe =>.Mooii Tech® O4 - GS\Quicklaunch [Guest]: Samsung Kies 3.lnk . (.Samsung - Kies.) C:\Program Files\SAMSUNG\Kies3\Kies3.exe =>.Samsung Electronics CO., LTD.® O4 - GS\Quicklaunch [Guest]: Uninstall Athan.lnk . (.Indigo Rose Corporation - SUF60Runtime.) C:\Windows\iun6002.exe O4 - GS\Quicklaunch [Guest]: WildTangent Games App - hp.lnk . (.WildTangent - WildTangent Games App.) C:\Program Files\WildTangent Games\App\GameConsole-wt.exe =>.WildTangent Inc® O4 - GS\Quicklaunch [Guest]: Yahoo! Messenger.lnk . (.Yahoo! Inc. - Yahoo! Messenger.) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe =>.Yahoo! Inc.® O4 - GS\sendTo [Guest]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - GS\Desktop [hju]: CueClub.lnk . (...) C:\Program Files\CueClub\cueclub.exe O4 - GS\Desktop [hju]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\hju\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc® O4 - GS\Desktop [hju]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files\Internet Download Manager\IDMan.exe {7828C7315808BC8717710E13FA3C0B24} =>.Tonec Inc. O4 - GS\Desktop [hju]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\hju\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [hju]: Google Chrome Canary.lnk . (.Google Inc. - Google Chrome.) C:\Users\hju\AppData\Local\Google\Chrome SxS\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [hju]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [hju]: Mozilla Firefox.lnk . (...) C:\Program Files\Mozilla Firefox\firefox.exe O4 - GS\Quicklaunch [hju]: Nero Home.lnk . (.Nero AG - Nero Home.) C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe =>.Nero AG® O4 - GS\Quicklaunch [hju]: Nero StartSmart.lnk . (.Nero AG - Nero StartSmart.) C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe =>.Nero AG® O4 - GS\Quicklaunch [hju]: PhotoScape.lnk . (.Copyright (C) 2005 - PhotoScape.) C:\Program Files\PhotoScape\PhotoScape.exe =>.Mooii Tech® O4 - GS\Quicklaunch [hju]: Samsung Kies 3.lnk . (.Samsung - Kies.) C:\Program Files\SAMSUNG\Kies3\Kies3.exe =>.Samsung Electronics CO., LTD.® O4 - GS\Quicklaunch [hju]: Uninstall Athan.lnk . (.Indigo Rose Corporation - SUF60Runtime.) C:\Windows\iun6002.exe O4 - GS\Quicklaunch [hju]: WildTangent Games App - hp.lnk . (.WildTangent - WildTangent Games App.) C:\Program Files\WildTangent Games\App\GameConsole-wt.exe =>.WildTangent Inc® O4 - GS\Quicklaunch [hju]: Yahoo! Messenger.lnk . (.Yahoo! Inc. - Yahoo! Messenger.) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe =>.Yahoo! Inc.® O4 - GS\sendTo [hju]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - GS\CommonDesktop [Public]: Ayat.lnk . (...) C:\Program Files\Ayat\Ayat.exe O4 - GS\CommonDesktop [Public]: ESETحماية الدفع المصرفي.lnk . (.ESET - ESET command line interface.) C:\Program Files\ESET\ESET Smart Security\ecmd.exe =>.ESET, spol. s r.o.® O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\CommonDesktop [Public]: iTunes.lnk . (.Apple Inc. - iTunes.) C:\Program Files\iTunes\iTunes.exe =>.Apple Inc.® O4 - GS\CommonDesktop [Public]: Malwarebytes Anti-Malware.lnk . (.Malwarebytes - Malwarebytes Anti-Malware.) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe =>.Malwarebytes Corporation® O4 - GS\CommonDesktop [Public]: Nero StartSmart.lnk . (.Nero AG - Nero StartSmart.) C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe =>.Nero AG® O4 - GS\CommonDesktop [Public]: Samsung Kies 3.lnk . (.Samsung - Kies.) C:\Program Files\SAMSUNG\Kies3\Kies3.exe =>.Samsung Electronics CO., LTD.® O4 - GS\CommonDesktop [Public]: Skype.lnk . (...) C:\Windows\Installer\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}\SkypeIcon.exe O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files\VideoLAN\VLC\vlc.exe =>.VideoLAN® O4 - GS\CommonDesktop [Public]: Vodafone Mobile Broadband.lnk . (.Vodafone - MobileBroadband.) C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe =>.Vodafone O4 - GS\CommonDesktop [Public]: WebcamMax.lnk . (.CoolwareMax - WebcamMax.) C:\Program Files\WebcamMax\WebcamMax.exe {00BB9E5872C907F4BB51ED8D5898FCDBF4} O4 - GS\CommonDesktop [Public]: Yahoo! Messenger.lnk . (.Yahoo! Inc. - Yahoo! Messenger.) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe =>.Yahoo! Inc.® O4 - GS\Programs [Public]: Viber.lnk . (...) C:\Users\hju\AppData\Local\Viber\Viber.exe O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) C:\WINDOWS\System32\taskschd.msc ---\\ Lop.com/Domain Hijackers (7) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{DE22C31C-66DA-4688-B54A-EDBB6D9F9675}: NameServer = 8.8.8.8,4.4.4.4 =>.Google Public DNS O17 - HKLM\System\CCS\Services\Tcpip\..\{18168ADA-FB23-44A8-92A9-9D7997BCB4FB}: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{81D9F859-84B9-4414-AB5E-EA1E62F9C728}: DhcpNameServer = 192.168.42.129 O17 - HKLM\System\CCS\Services\Tcpip\..\{B810F952-E732-42D0-99D8-E0E6BC6FA697}: DhcpNameServer = 192.168.9.1 192.168.9.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{DE22C31C-66DA-4688-B54A-EDBB6D9F9675}: DhcpNameServer = 62.240.32.5 62.68.42.2 O17 - HKLM\System\CCS\Services\Tcpip\..\{DE22C31C-66DA-4688-B54A-EDBB6D9F9675}: DhcpDomain = ltt.ly ---\\ Extra protocols (28) - 1s O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\WINDOWS\System32\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} . (.Microsoft Corporation - GrooveSystemServices Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll =>.Microsoft Corporation® O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\System32\itss.dll =>.Microsoft Corporation O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\WINDOWS\System32\inetcomm.dll =>.Microsoft Corporation O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll =>.Microsoft Corporation® O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\System32\itss.dll =>.Microsoft Corporation O18 - Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll =>.Microsoft Corporation® O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} . (.Skype Technologies S.A. - Skype add-on for IE.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll =>.Skype Technologies SA® O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\WINDOWS\System32\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\WINDOWS\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (.Microsoft Corporation - Windows Live Mail.) -- C:\Program Files\Windows Live\Mail\mailcomm.dll =>.Microsoft Corporation® O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\System32\urlmon.dll =>.Microsoft Corporation O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\System32\urlmon.dll =>.Microsoft Corporation O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL =>.Microsoft Corporation® ---\\ Software installed (107) - 46s O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- {19687AD5-7E54-4C5E-A796-125C95079C1D} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- Adobe AIR =>.Adobe Systems Incorporated® O42 - Logiciel: Adobe Flash Player 21 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX =>.Adobe Systems Incorporated® O42 - Logiciel: Adobe Flash Player 21 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated® O42 - Logiciel: Adobe Flash Player 21 PPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player PPAPI =>.Adobe Systems Incorporated® O42 - Logiciel: Adobe Reader X (10.1.9) - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1033-7B44-AA1000000001} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Shockwave Player - (.Adobe Systems, Inc..) [HKLM] -- {1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A} =>.Adobe Systems, Inc. O42 - Logiciel: Any Video Converter Professional 3.0.7 - (.Any-Video-Converter.com.) [HKLM] -- Any Video Converter Professional_is1 =>.AnvSoft Co., Ltd.® O42 - Logiciel: AOL Toolbar 5.0 - (.AOL LLC.) [HKLM] -- AOL Toolbar =>.AOL LLC O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {A75CA58D-DB9C-4D14-9428-E0C7B0F623DC} =>.Apple Inc. O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF} =>.Apple Inc. O42 - Logiciel: Atheros Driver Installation Program - (.Atheros.) [HKLM] -- {C3A32068-8AB1-4327-BB16-BED9C6219DC7} =>.Atheros O42 - Logiciel: AVS Photo Editor 2.2.1.140 - (.Online Media Technologies Ltd..) [HKLM] -- AVS Photo Editor_is1 =>.Online Media Technologies Ltd. O42 - Logiciel: Ayat - (.UNKNOWN.) [HKLM] -- {D1566597-887B-6FAB-A761-018A5D75D6EC} O42 - Logiciel: Ayat - (.UNKNOWN.) [HKLM] -- sa.edu.ksa.ayat O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {79155F2B-9895-49D7-8612-D92580E0DE5B} =>.Apple Inc. O42 - Logiciel: BrowserProtect - (...) [HKLM] -- BrowserProtect =>PUP.Optional.Eazel O42 - Logiciel: Cela.C.M - (.Huawei Technologies Co.,Ltd.) [HKLM] -- Cela.C.M =>.Huawei Technologies Co.,Ltd O42 - Logiciel: Cisco EAP-FAST Module - (.Cisco Systems, Inc..) [HKLM] -- {415B2719-AD3A-4944-B404-C472DB6085B3} =>.Cisco Systems, Inc. O42 - Logiciel: Cisco LEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {83770D14-21B9-44B3-8689-F7B523F94560} =>.Cisco Systems, Inc. O42 - Logiciel: Cisco PEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E} =>.Cisco Systems, Inc. O42 - Logiciel: Compatibility Pack for the 2007 Office system - (.Microsoft Corporation.) [HKLM] -- {90120000-0020-0409-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Conexant HD Audio - (.Conexant.) [HKLM] -- CNXT_AUDIO_HDA =>.Conexant O42 - Logiciel: CyberLink DVD Suite - (.CyberLink Corp..) [HKLM] -- {1FBF6C24-C1FD-4101-A42B-0C564F9E8E79} =>.CyberLink Corp. O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM] -- {01FB4998-33C4-4431-85ED-079E3EEFE75D} =>.CyberLink® O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM] -- InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D} =>.CyberLink® O42 - Logiciel: Elementary Language Practice CD-ROM - (.Macmillan.) [HKLM] -- {C8349D42-1AF0-41EB-95CF-EFA4C0C4B24D} =>.Macmillan O42 - Logiciel: ESET Smart Security - (.ESET, spol. s r.o..) [HKLM] -- {C81F7A3D-5E68-4B0C-BD7E-63CE501C35A0} =>.ESET, spol. s r.o. O42 - Logiciel: ESU for Microsoft Vista - (.Hewlett-Packard.) [HKLM] -- {3877C901-7B90-4727-A639-B6ED2DD59D43} =>.Hewlett-Packard O42 - Logiciel: Facebook Video Calling 3.1.0.521 - (.Skype Limited.) [HKLM] -- {2091F234-EB58-4B80-8C96-8EB78C808CF7} =>.Skype Limited O42 - Logiciel: FastestTube-2.2.10.5 - (.Kwizzu.) [HKLM] -- FastestTube_is1 O42 - Logiciel: Golden Al-Wafi Translator - (...) [HKLM] -- ST6UNST #1 O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome =>.Google Inc® O42 - Logiciel: Google Chrome Canary - (.Google Inc..) [HKCU] -- Google Chrome SxS =>.Google Inc® O42 - Logiciel: Google Drive - (.Google, Inc..) [HKLM] -- {D7269C20-B3CE-4CD0-8E88-3D307D3BD41A} =>.Google, Inc. O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc. O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>Heuristic.Suspect O42 - Logiciel: HDAUDIO Soft Data Fax Modem with SmartCP - (...) [HKLM] -- CNXT_MODEM_HDAUDIO_HERMOSA_HSF O42 - Logiciel: Hewlett-Packard Active Check for Health Check - (.Hewlett-Packard.) [HKLM] -- {254C37AA-6B72-4300-84F6-98A82419187E} =>.Hewlett-Packard O42 - Logiciel: Hewlett-Packard Asset Agent for Health Check - (.HP.) [HKLM] -- {669D4A35-146B-4314-89F1-1AC3D7B88367} =>.HP O42 - Logiciel: HP Active Support Library - (.Hewlett-Packard.) [HKLM] -- {9E2CCD5E-1990-4EF2-9B61-32F0BBACC29B} =>.Hewlett-Packard O42 - Logiciel: HP Customer Experience Enhancements - (.Hewlett-Packard.) [HKLM] -- {B16DA0F8-26BC-4FFC-9363-1D9F3E6C3E21} =>.Hewlett-Packard O42 - Logiciel: HP Doc Viewer - (.Hewlett-Packard.) [HKLM] -- {082702D5-5DD8-4600-BCE5-48B15174687F} =>.Hewlett-Packard O42 - Logiciel: HP DVD Play 3.7 - (.Hewlett-Packard.) [HKLM] -- {45D707E9-F3C4-11D9-A373-0050BAE317E1} =>.Hewlett-Packard O42 - Logiciel: HP Easy Setup - Frontend - (.Hewlett-Packard.) [HKLM] -- {51E5C397-0AA0-48DD-9CB6-7259AFFDFB0A} =>.Hewlett-Packard O42 - Logiciel: HP Help and Support - (.Hewlett-Packard.) [HKLM] -- {E333CA5F-00ED-4EEF-90E5-6A33A8FE969F} =>.Hewlett-Packard O42 - Logiciel: HP Quick Launch Buttons 6.40 F1 - (.Hewlett-Packard.) [HKLM] -- {34D2AB40-150D-475D-AE32-BD23FB5EE355} =>.Hewlett-Packard Company® O42 - Logiciel: HP Total Care Advisor - (.Hewlett-Packard.) [HKLM] -- {f32502b5-5b64-4882-bf61-77f23edcac4f} =>.Hewlett-Packard O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM] -- {C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F} =>.Hewlett-Packard O42 - Logiciel: HP User Guides 0118 - (.Hewlett-Packard.) [HKLM] -- {B6D0B141-B2BE-4DD0-B08F-B9186F3E36B3} =>.Hewlett-Packard O42 - Logiciel: HP Wireless Assistant - (.Hewlett-Packard.) [HKLM] -- {340F521E-3576-4E1A-B75C-EB0ACF751379} =>.Hewlett-Packard O42 - Logiciel: HPNetworkAssistant - (.Hewlett-Packard..) [HKLM] -- {228C6B46-64E2-404E-898A-EF0830603EF4} =>.Hewlett-Packard. O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- HDMI =>.Intel Corporation® O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM] -- Internet Download Manager =>.Tonec Inc.® O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {868B9974-4F23-494D-B6BC-4FAB92B2755D} =>.Apple Inc. O42 - Logiciel: Java 8 Update 91 - (.Oracle Corporation.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83218091F0} =>.Oracle Corporation O42 - Logiciel: Java Auto Updater - (.Oracle Corporation.) [HKLM] -- {4A03706F-666A-4037-7777-5F2748764D10} =>.Oracle Corporation O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {8E5233E1-7495-44FB-8DEB-4BE906D59619} =>.Microsoft Corporation O42 - Logiciel: LabelPrint - (.CyberLink Corp..) [HKLM] -- {C59C179C-668D-49A9-B6EA-0121CCFC1243} =>.CyberLink Corp. O42 - Logiciel: LightScribe System Software 1.12.33.2 - (.LightScribe.) [HKLM] -- {582287DA-0806-4AC0-BF19-C15E3A466034} =>.LightScribe O42 - Logiciel: Malwarebytes Anti-Malware version 2.2.1.1043 - (.Malwarebytes.) [HKLM] -- Malwarebytes Anti-Malware_is1 =>.Malwarebytes O42 - Logiciel: McAfee Security Scan Plus - (.McAfee, Inc..) [HKLM] -- McAfee Security Scan =>.McAfee, Inc. O42 - Logiciel: Microsoft Application Error Reporting - (.Microsoft Corporation.) [HKLM] -- {95120000-00B9-0409-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570} =>.Microsoft Corporation O42 - Logiciel: Microsoft Search Enhancement Pack - (.Microsoft Corporation.) [HKLM] -- {9C9CEB9D-53FD-49A7-85D2-FE674F72F24E} =>.Microsoft Corporation O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation O42 - Logiciel: Microsoft Sync Framework Runtime Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {8A74E887-8F0F-4017-AF53-CBA42211AAA5} =>.Microsoft Corporation O42 - Logiciel: Microsoft Sync Framework Services Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {BD64AF4A-8C80-4152-AD77-FCDDF05208AB} =>.Microsoft Corporation O42 - Logiciel: Microsoft Text-to-Speech Engine 4.0 (English) - (...) [HKLM] -- MSTTS O42 - Logiciel: Microsoft Works - (.Microsoft Corporation.) [HKLM] -- {15BC8CD0-A65B-47D0-A2DD-90A824590FA8} =>.Microsoft Corporation O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94} =>.Microsoft O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71} =>.Microsoft Corporation O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC} =>.Microsoft Corporation O42 - Logiciel: muvee autoProducer 6.1 - (.muvee Technologies.) [HKLM] -- {35F83303-C0C0-46B7-B8A8-ADA7C2AC5645} =>.muvee Technologies O42 - Logiciel: My HP Games - (.WildTangent.) [HKLM] -- WildTangent hp Master Uninstall =>.WildTangent Inc O42 - Logiciel: My Program version 1.5 - (...) [HKLM] -- My Program_is1 =>.Superfluous.MyProgram O42 - Logiciel: Nero 7 Ultra Edition - (.Nero AG.) [HKLM] -- {C6115A28-F277-4E82-B067-84D28BF21033} =>.Nero AG O42 - Logiciel: neroxml - (.Nero AG.) [HKLM] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B} =>.Nero AG O42 - Logiciel: NetWaiting - (.BVRP Software, Inc.) [HKLM] -- {3F92ABBB-6BBF-11D5-B229-002078017FBF} =>.Avanquest® O42 - Logiciel: PhotoScape - (...) [HKLM] -- PhotoScape O42 - Logiciel: Power2Go - (.CyberLink Corp..) [HKLM] -- {40BF1E83-20EB-11D8-97C5-0009C5020658} =>.CyberLink Corp. O42 - Logiciel: PowerDirector - (.CyberLink Corp..) [HKLM] -- {CB099890-1D5F-11D5-9EA9-0050BAE317E1} =>.CyberLink Corp. O42 - Logiciel: PowerDirector - (.CyberLink Corp..) [HKLM] -- InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1} =>.CyberLink® O42 - Logiciel: QuickPlay SlingPlayer 0.4.6 - (.SlingMedia.) [HKLM] -- SlingMedia.QPSlingPlayer_is1 =>.SlingMedia O42 - Logiciel: RealDownloader - (.RealNetworks, Inc..) [HKLM] -- {C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE} =>.RealNetworks, Inc. O42 - Logiciel: RealPlayer - (.RealNetworks.) [HKLM] -- RealPlayer 16.0 =>.RealNetworks, Inc.® O42 - Logiciel: Realtek 8169 8168 8101E 8102E Ethernet Driver - (.Realtek.) [HKLM] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} =>.Macrovision Corporation® O42 - Logiciel: Realtek USB 2.0 Card Reader - (.Realtek Semiconductor Corp..) [HKLM] -- {DC24971E-1946-445D-8A82-CE685433FA7D} =>.Macrovision Corporation® O42 - Logiciel: RealUpgrade 1.1 - (.RealNetworks, Inc..) [HKLM] -- {28C2DED6-325B-4CC7-983A-1777C8F7FBAB} =>.RealNetworks, Inc. O42 - Logiciel: Samsung Kies3 - (.Samsung Electronics Co., Ltd..) [HKLM] -- {88547073-C566-4895-9005-EBE98EA3F7C7} =>.Samsung Electronics Co., Ltd. O42 - Logiciel: Samsung Kies3 - (.Samsung Electronics Co., Ltd..) [HKLM] -- InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7} =>.Samsung Electronics Co., Ltd. O42 - Logiciel: Skype Toolbars - (.Skype Technologies S.A..) [HKLM] -- {B6CF2967-C81E-40C0-9815-C05774FEF120} =>.Skype Technologies S.A. O42 - Logiciel: Skype™ 7.0 - (.Skype Technologies S.A..) [HKLM] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7} =>.Skype Technologies S.A. O42 - Logiciel: SweeetPlayer bundle - (.Perion Network LTD..) [HKLM] -- SweeetPlayer bundle =>.Superfluous.PerionNetwork O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics.) [HKLM] -- SynTPDeinstKey =>.Synaptics O42 - Logiciel: Unity Web Player - (.Unity Technologies ApS.) [HKCU] -- UnityWebPlayer =>.Unity Technologies ApS O42 - Logiciel: Update Installer for WildTangent Games App - (.WildTangent.) [HKLM] -- {2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App =>.WildTangent Inc® O42 - Logiciel: UpdateChecker - (.SqueakyChocolate, LLC.) [HKLM] -- SqueakyChocolate, LLC UpdateChecker =>PUP.Optional.Squeaky O42 - Logiciel: Veetle TV - (.Veetle, Inc.) [HKLM] -- Veetle TV =>.Veetle, Inc O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM] -- VLC media player =>.VideoLAN O42 - Logiciel: Vodafone Mobile Broadband - (.Vodafone.) [HKLM] -- {6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2} =>.Vodafone O42 - Logiciel: WebcamMax - (...) [HKLM] -- WebcamMax O42 - Logiciel: WhiteSmoke Search - (.WhiteSmoke Search.) [HKLM] -- WhiteSmoke Search =>PUP.Optional.WhiteSmoke O42 - Logiciel: WildTangent Games App for HP - (.WildTangent.) [HKLM] -- {70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp =>.WildTangent Inc® O42 - Logiciel: WinRAR 5.00 بيتا 4 (32-بت) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver =>.win.rar GmbH O42 - Logiciel: Yahoo! Messenger - (.Yahoo! Inc..) [HKLM] -- Yahoo! Messenger =>.Yahoo! Inc. O42 - Logiciel: دعم تطبيقات Apple‏ (32 بت) - (.Apple Inc..) [HKLM] -- {AFA1153A-F547-409B-B837-3A0D6C5A3FEC} =>.Apple Inc. ---\\ HKCU & HKLM Software Keys (162) - 46s HKLM\SOFTWARE\Adobe HKLM\SOFTWARE\Ahead HKLM\SOFTWARE\America Online HKLM\SOFTWARE\Apple Computer, Inc. HKLM\SOFTWARE\Apple Inc. HKLM\SOFTWARE\Atheros HKLM\SOFTWARE\Audible HKLM\SOFTWARE\AVG HKLM\SOFTWARE\AVS4YOU HKLM\SOFTWARE\BlueStacks HKLM\SOFTWARE\BVRP Software, Inc HKLM\SOFTWARE\CDDB HKLM\SOFTWARE\Client HKLM\SOFTWARE\Conexant HKLM\SOFTWARE\Conexant Systems Inc HKLM\SOFTWARE\CXT HKLM\SOFTWARE\CyberLink HKLM\SOFTWARE\Debug HKLM\SOFTWARE\EasyBits HKLM\SOFTWARE\ErrorLists-crcodedownloader =>PUP.Optional.SoftwareEngine HKLM\SOFTWARE\ESET HKLM\SOFTWARE\FastestTube HKLM\SOFTWARE\FilmOn.com HKLM\SOFTWARE\FlashPeak HKLM\SOFTWARE\GEAR Software HKLM\SOFTWARE\GN2 HKLM\SOFTWARE\Golden Al-Wafi Translator HKLM\SOFTWARE\Google HKLM\SOFTWARE\Hauppauge HKLM\SOFTWARE\Hewlett-Packard HKLM\SOFTWARE\HP HKLM\SOFTWARE\HPQ HKLM\SOFTWARE\Huawei technologies HKLM\SOFTWARE\IM Providers HKLM\SOFTWARE\InstalledOptions HKLM\SOFTWARE\InstallShield HKLM\SOFTWARE\Intel HKLM\SOFTWARE\Internet Download Manager HKLM\SOFTWARE\JavaSoft HKLM\SOFTWARE\JreMetrics HKLM\SOFTWARE\Licenses HKLM\SOFTWARE\LightScribe HKLM\SOFTWARE\Macmillan HKLM\SOFTWARE\Macromedia HKLM\SOFTWARE\Malwarebytes' Anti-Malware HKLM\SOFTWARE\McAfee.com HKLM\SOFTWARE\MimarSinan HKLM\SOFTWARE\Mooii HKLM\SOFTWARE\Mozilla HKLM\SOFTWARE\mozilla.org HKLM\SOFTWARE\MozillaPlugins HKLM\SOFTWARE\muvee Technologies HKLM\SOFTWARE\Nero HKLM\SOFTWARE\Netscape HKLM\SOFTWARE\ODBC HKLM\SOFTWARE\Opera Software HKLM\SOFTWARE\PCDataApp HKLM\SOFTWARE\RealNetworks HKLM\SOFTWARE\Realtek HKLM\SOFTWARE\Realtek Semiconductor Corp. HKLM\SOFTWARE\RegisteredApplications HKLM\SOFTWARE\RTLSetup HKLM\SOFTWARE\SAMSUNG HKLM\SOFTWARE\Skype HKLM\SOFTWARE\Software HKLM\SOFTWARE\Sonic HKLM\SOFTWARE\Sony Ericsson HKLM\SOFTWARE\Symantec HKLM\SOFTWARE\Synaptics HKLM\SOFTWARE\TuneUp HKLM\SOFTWARE\Veetle HKLM\SOFTWARE\VideoLAN HKLM\SOFTWARE\Vodafone HKLM\SOFTWARE\Voice HKLM\SOFTWARE\WebcamMax HKLM\SOFTWARE\WhiteSmoke Search =>PUP.Optional.WhiteSmoke HKLM\SOFTWARE\WildTangent HKLM\SOFTWARE\WiMax HKLM\SOFTWARE\Windows HKLM\SOFTWARE\WinRAR HKLM\SOFTWARE\WNLT =>PUP.Optional.IncrediBar HKLM\SOFTWARE\WombatUpdater HKLM\SOFTWARE\WOW6432Node HKLM\SOFTWARE\Xing Technology Corp. HKLM\SOFTWARE\yahoo =>.Yahoo! HKCU\SOFTWARE\4shared HKCU\SOFTWARE\Ada99 HKCU\SOFTWARE\Adobe HKCU\SOFTWARE\Affinix HKCU\SOFTWARE\Ahead HKCU\SOFTWARE\AnvSoft HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\Apple Computer, Inc. HKCU\SOFTWARE\Apple Inc. HKCU\SOFTWARE\AVG HKCU\SOFTWARE\AVS4YOU HKCU\SOFTWARE\Binary Noise HKCU\SOFTWARE\BVRP Software HKCU\SOFTWARE\CC HKCU\SOFTWARE\CDDB HKCU\SOFTWARE\Chedot =>PUP.Optional.ChedotBrowser HKCU\SOFTWARE\CyberLink HKCU\SOFTWARE\DivXNetworks HKCU\SOFTWARE\DownloadManager HKCU\SOFTWARE\ESET HKCU\SOFTWARE\Facebook HKCU\SOFTWARE\Falco & Flight Dream Studio Alex Dudkin a.k.a. Alcatraz HKCU\SOFTWARE\FilmOn.com HKCU\SOFTWARE\FimOnInstaller HKCU\SOFTWARE\FlashPeak HKCU\SOFTWARE\FLEXnet HKCU\SOFTWARE\FlyOrDie HKCU\SOFTWARE\GN2 HKCU\SOFTWARE\Google HKCU\SOFTWARE\Hewlett-Packard HKCU\SOFTWARE\IM Providers HKCU\SOFTWARE\IncrediMail HKCU\SOFTWARE\Informer Technologies, Inc. HKCU\SOFTWARE\Intel HKCU\SOFTWARE\JavaSoft HKCU\SOFTWARE\kde.org HKCU\SOFTWARE\Licenses HKCU\SOFTWARE\LightScribe HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\MainConcept HKCU\SOFTWARE\Mooii HKCU\SOFTWARE\Mozilla HKCU\SOFTWARE\MozillaPlugins HKCU\SOFTWARE\muvee Technologies HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\Nimbuzz HKCU\SOFTWARE\ODBC HKCU\SOFTWARE\Opera Software HKCU\SOFTWARE\PCDataApp HKCU\SOFTWARE\QtProject HKCU\SOFTWARE\RealNetworks HKCU\SOFTWARE\Samsung HKCU\SOFTWARE\Skype HKCU\SOFTWARE\SkypeRS HKCU\SOFTWARE\Sony Ericsson HKCU\SOFTWARE\Synaptics HKCU\SOFTWARE\Trolltech HKCU\SOFTWARE\TuneUp HKCU\SOFTWARE\Unity HKCU\SOFTWARE\Veetle HKCU\SOFTWARE\Viber HKCU\SOFTWARE\Vodafone HKCU\SOFTWARE\Voice HKCU\SOFTWARE\web disco HKCU\SOFTWARE\webdisco =>PUP.Optional.WebDisco HKCU\SOFTWARE\WildTangent HKCU\SOFTWARE\Windows Live Writer HKCU\SOFTWARE\WinRAR HKCU\SOFTWARE\WinRAR SFX HKCU\SOFTWARE\WNLT =>PUP.Optional.IncrediBar HKCU\SOFTWARE\yahoo =>.Yahoo! HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Software HKCU\SOFTWARE\AppDataLow\Software\JavaSoft HKCU\SOFTWARE\AppDataLow\Software\Macromedia HKCU\SOFTWARE\AppDataLow\Software\Unity ---\\ Contents of the Common Files folders (328) - 180s O43 - CFD: 31/07/2008 - [] D -- C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites O43 - CFD: 04/06/2013 - [] D -- C:\Program Files\Adobe =>.Adobe Systems, Incorporated® O43 - CFD: 04/11/2012 - [] D -- C:\Program Files\AnvSoft O43 - CFD: 31/07/2008 - [] D -- C:\Program Files\AOL {515BAD266FBAF6EFA9767CE8F0D53022} O43 - CFD: 29/03/2016 - [] D -- C:\Program Files\Apple Software Update =>.Apple Inc.® O43 - CFD: 03/11/2014 - [] D -- C:\Program Files\Athan O43 - CFD: 02/11/2012 - [] D -- C:\Program Files\Atheros O43 - CFD: 14/08/2014 - [] D -- C:\Program Files\AVS4YOU O43 - CFD: 29/12/2014 - [] D -- C:\Program Files\Ayat O43 - CFD: 03/02/2014 - [] D -- C:\Program Files\Bonjour =>.Apple Inc.® O43 - CFD: 02/11/2012 - [] D -- C:\Program Files\Cisco O43 - CFD: 12/10/2015 - [] D -- C:\Program Files\Common Files O43 - CFD: 02/11/2012 - [] D -- C:\Program Files\CONEXANT =>.Conexant Systems, Inc.® O43 - CFD: 15/10/2015 - [] D -- C:\Program Files\CueClub O43 - CFD: 02/11/2012 - [] D -- C:\Program Files\CyberLink =>.CyberLink® O43 - CFD: 31/07/2008 - [] D -- C:\Program Files\EasyBits For Kids O43 - CFD: 22/05/2016 - [] D -- C:\Program Files\ESET =>.ESET, spol. s r.o.® O43 - CFD: 20/07/2015 - [] D -- C:\Program Files\FastestTube O43 - CFD: 04/02/2014 - [] D -- C:\Program Files\FLV Video Player O43 - CFD: 28/08/2013 - [] D -- C:\Program Files\Flyordie Plugin O43 - CFD: 28/06/2013 - [] D -- C:\Program Files\Golden Al-Wafi Translator O43 - CFD: 11/04/2016 - [] D -- C:\Program Files\Google =>.Google Inc® O43 - CFD: 18/12/2015 - [] D -- C:\Program Files\GUME6D5.tmp =>.Google Inc® O43 - CFD: 02/11/2012 - [] D -- C:\Program Files\Hewlett-Packard =>.Hewlett-Packard Company® O43 - CFD: 31/07/2008 - [] D -- C:\Program Files\HP =>.CyberLink® O43 - CFD: 24/08/2015 - [] D -- C:\Program Files\HP Games O43 - CFD: 04/06/2013 - [] HD -- C:\Program Files\InstallJammer Registry O43 - CFD: 11/02/2015 - [] HD -- C:\Program Files\InstallShield Installation Information =>.Macrovision Corporation® O43 - CFD: 02/11/2012 - [] D -- C:\Program Files\Intel O43 - CFD: 22/05/2016 - [] D -- C:\Program Files\Internet Download Manager {7828C7315808BC8717710E13FA3C0B24} O43 - CFD: 29/03/2016 - [] D -- C:\Program Files\Internet Explorer O43 - CFD: 29/03/2016 - [] D -- C:\Program Files\iPod =>.Apple Inc.® O43 - CFD: 29/03/2016 - [] D -- C:\Program Files\iTunes =>.Apple Inc.® O43 - CFD: 11/04/2016 - [] D -- C:\Program Files\Java =>.Oracle America, Inc.® O43 - CFD: 15/10/2013 - [] D -- C:\Program Files\Libyamax-Cela O43 - CFD: 19/01/2014 - [] D -- C:\Program Files\Macmillan {113C0EB86CB9137624A4C4DEF8095435} O43 - CFD: 22/05/2016 - [] D -- C:\Program Files\Malwarebytes Anti-Malware =>.Malwarebytes Corporation® O43 - CFD: 01/04/2014 - [] D -- C:\Program Files\McAfee Security Scan O43 - CFD: 12/11/2014 - [] D -- C:\Program Files\Microsoft =>.Microsoft Corporation® O43 - CFD: 02/11/2006 - [] D -- C:\Program Files\Microsoft Games O43 - CFD: 14/09/2013 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation® O43 - CFD: 28/08/2013 - [] D -- C:\Program Files\Microsoft Office Outlook Connector =>.Microsoft Corporation® O43 - CFD: 18/12/2015 - [] D -- C:\Program Files\Microsoft Silverlight =>.Microsoft Corporation® O43 - CFD: 29/08/2013 - [] D -- C:\Program Files\Microsoft SQL Server Compact Edition O43 - CFD: 09/06/2013 - [] D -- C:\Program Files\Microsoft Sync Framework O43 - CFD: 24/08/2013 - [] D -- C:\Program Files\Microsoft Visual Studio O43 - CFD: 24/08/2013 - [] D -- C:\Program Files\Microsoft Visual Studio 8 O43 - CFD: 19/11/2012 - [] D -- C:\Program Files\Microsoft Works =>.Microsoft Corporation® O43 - CFD: 03/02/2013 - [] D -- C:\Program Files\Microsoft.NET O43 - CFD: 27/11/2013 - [] D -- C:\Program Files\Mobile Partner O43 - CFD: 19/11/2012 - [] D -- C:\Program Files\Movie Maker O43 - CFD: 27/08/2014 - [] D -- C:\Program Files\Movie Maker 2.6 O43 - CFD: 11/04/2016 - [] D -- C:\Program Files\Mozilla Firefox O43 - CFD: 25/08/2015 - [] D -- C:\Program Files\Mozilla Firefox.bak =>.Mozilla Corporation® O43 - CFD: 24/08/2013 - [] D -- C:\Program Files\MSBuild O43 - CFD: 19/11/2012 - [0] D -- C:\Program Files\MSXML 4.0 O43 - CFD: 31/07/2008 - [] D -- C:\Program Files\muvee Technologies O43 - CFD: 15/10/2015 - [] D -- C:\Program Files\MyRealGames.com O43 - CFD: 22/08/2014 - [] D -- C:\Program Files\Nero =>.Nero AG® O43 - CFD: 02/11/2012 - [] D -- C:\Program Files\NetWaiting =>.Avanquest® O43 - CFD: 02/11/2012 - [] RD -- C:\Program Files\Online Services =>.Skype Technologies SA® O43 - CFD: 11/04/2016 - [] D -- C:\Program Files\Opera O43 - CFD: 14/04/2014 - [] D -- C:\Program Files\PhotoScape =>.Mooii Tech® O43 - CFD: 02/04/2014 - [] D -- C:\Program Files\Real =>.RealNetworks, Inc.® O43 - CFD: 09/09/2013 - [] D -- C:\Program Files\RealNetworks =>.RealNetworks, Inc.® O43 - CFD: 02/11/2012 - [] D -- C:\Program Files\Realtek O43 - CFD: 02/11/2006 - [] D -- C:\Program Files\Reference Assemblies O43 - CFD: 11/02/2015 - [] D -- C:\Program Files\SAMSUNG =>.Samsung Electronics CO., LTD.® O43 - CFD: 06/06/2015 - [] RD -- C:\Program Files\Skype =>.Skype Software Sarl® O43 - CFD: 22/05/2016 - [0] D -- C:\Program Files\sweetpacks bundle uninstaller_SweetPlayer_1348381 =>PUP.Optional.SweetIM O43 - CFD: 02/11/2012 - [] D -- C:\Program Files\Synaptics =>.Synaptics Incorporated® O43 - CFD: 02/11/2006 - [0] HD -- C:\Program Files\Uninstall Information O43 - CFD: 29/01/2014 - [] D -- C:\Program Files\Veetle O43 - CFD: 04/11/2012 - [] D -- C:\Program Files\VideoLAN O43 - CFD: 11/04/2016 - [] D -- C:\Program Files\Vodafone =>.Huawei Technologies Co., Ltd.® O43 - CFD: 04/11/2012 - [] D -- C:\Program Files\WebcamMax O43 - CFD: 07/04/2014 - [] D -- C:\Program Files\WhiteSmoke Search =>PUP.Optional.WhiteSmoke O43 - CFD: 24/08/2015 - [] D -- C:\Program Files\WildTangent Games =>.WildTangent Inc® O43 - CFD: 21/01/2008 - [] D -- C:\Program Files\Windows Calendar O43 - CFD: 21/01/2008 - [] D -- C:\Program Files\Windows Collaboration O43 - CFD: 21/01/2008 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Windows® O43 - CFD: 21/01/2008 - [] D -- C:\Program Files\Windows Journal O43 - CFD: 28/11/2013 - [] D -- C:\Program Files\Windows Live =>.Microsoft Corporation® O43 - CFD: 08/06/2013 - [] D -- C:\Program Files\Windows Live SkyDrive O43 - CFD: 19/11/2012 - [] D -- C:\Program Files\Windows Mail O43 - CFD: 19/11/2012 - [] D -- C:\Program Files\Windows Media Player O43 - CFD: 02/11/2006 - [] D -- C:\Program Files\Windows NT O43 - CFD: 21/01/2008 - [] D -- C:\Program Files\Windows Photo Gallery O43 - CFD: 21/01/2008 - [] D -- C:\Program Files\Windows Sidebar O43 - CFD: 25/08/2013 - [] D -- C:\Program Files\WinRAR O43 - CFD: 04/11/2012 - [] D -- C:\Program Files\Yahoo! O43 - CFD: 05/12/2012 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 05/12/2012 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 04/11/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnvSoft O43 - CFD: 14/08/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU O43 - CFD: 25/10/2015 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CueClub O43 - CFD: 22/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET O43 - CFD: 21/01/2008 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Extras and Upgrades O43 - CFD: 20/07/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastestTube O43 - CFD: 24/08/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 28/06/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Golden Al-Wafi Translator O43 - CFD: 11/04/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive O43 - CFD: 29/01/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP O43 - CFD: 22/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager O43 - CFD: 29/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes O43 - CFD: 11/04/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java O43 - CFD: 02/11/2012 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling O43 - CFD: 19/01/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macmillan O43 - CFD: 02/11/2006 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 22/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware O43 - CFD: 01/04/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus O43 - CFD: 14/09/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office O43 - CFD: 12/11/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in O43 - CFD: 18/12/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight O43 - CFD: 19/11/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works O43 - CFD: 31/07/2008 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\muvee O43 - CFD: 24/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games O43 - CFD: 15/10/2015 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyRealGames.com O43 - CFD: 22/08/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition O43 - CFD: 02/11/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetWaiting O43 - CFD: 04/11/2012 - [0] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security O43 - CFD: 02/11/2012 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services O43 - CFD: 14/04/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape O43 - CFD: 02/04/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks O43 - CFD: 31/07/2008 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery Manager O43 - CFD: 11/02/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung O43 - CFD: 06/06/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype O43 - CFD: 07/04/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 22/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SweeetPlayer bundle O43 - CFD: 02/11/2006 - [] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 07/04/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN O43 - CFD: 11/04/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vodafone O43 - CFD: 04/11/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebcamMax O43 - CFD: 24/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games for HP O43 - CFD: 28/11/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live O43 - CFD: 24/08/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 04/11/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Messenger O43 - CFD: 17/11/2014 - [] D -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 O43 - CFD: 07/06/2013 - [] D -- C:\ProgramData\Adobe O43 - CFD: 22/08/2014 - [] D -- C:\ProgramData\Ahead O43 - CFD: 31/07/2008 - [] D -- C:\ProgramData\AOL O43 - CFD: 26/10/2014 - [] D -- C:\ProgramData\Apple O43 - CFD: 29/03/2016 - [] D -- C:\ProgramData\Apple Computer O43 - CFD: 02/11/2006 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 25/12/2012 - [] D -- C:\ProgramData\Arcade Lab O43 - CFD: 02/11/2012 - [] D -- C:\ProgramData\Atheros O43 - CFD: 19/07/2014 - [] D -- C:\ProgramData\AVG O43 - CFD: 14/08/2014 - [] D -- C:\ProgramData\AVS4YOU O43 - CFD: 29/03/2016 - [] D -- C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB O43 - CFD: 27/11/2013 - [] D -- C:\ProgramData\BlueStacks O43 - CFD: 27/11/2013 - [] D -- C:\ProgramData\BlueStacksSetup O43 - CFD: 24/01/2014 - [] HD -- C:\ProgramData\Common Files O43 - CFD: 22/02/2013 - [] D -- C:\ProgramData\CyberLink O43 - CFD: 02/11/2006 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 02/11/2006 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 22/05/2016 - [] D -- C:\ProgramData\ESET O43 - CFD: 02/11/2006 - [0] SHD -- C:\ProgramData\Favorites O43 - CFD: 13/01/2014 - [] D -- C:\ProgramData\FilmOn.com O43 - CFD: 27/11/2013 - [] D -- C:\ProgramData\FLEXnet O43 - CFD: 04/11/2012 - [] D -- C:\ProgramData\Google O43 - CFD: 02/11/2012 - [] D -- C:\ProgramData\Hewlett-Packard O43 - CFD: 17/06/2013 - [] D -- C:\ProgramData\Hi O43 - CFD: 17/04/2014 - [] D -- C:\ProgramData\IconCache O43 - CFD: 12/08/2014 - [0] D -- C:\ProgramData\IDM O43 - CFD: 13/01/2014 - [] D -- C:\ProgramData\Informer Technologies, Inc O43 - CFD: 22/08/2014 - [] D -- C:\ProgramData\LightScribe O43 - CFD: 27/11/2013 - [] D -- C:\ProgramData\Macrovision O43 - CFD: 22/05/2016 - [] D -- C:\ProgramData\Malwarebytes O43 - CFD: 23/03/2013 - [] D -- C:\ProgramData\McAfee O43 - CFD: 23/03/2013 - [] D -- C:\ProgramData\McAfee Security Scan O43 - CFD: 29/08/2013 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 11/04/2016 - [] D -- C:\ProgramData\Microsoft Help O43 - CFD: 31/07/2008 - [] D -- C:\ProgramData\muvee Technologies O43 - CFD: 22/08/2014 - [] D -- C:\ProgramData\Nero O43 - CFD: 29/03/2016 - [] D -- C:\ProgramData\Oracle O43 - CFD: 02/04/2014 - [] D -- C:\ProgramData\Real O43 - CFD: 09/09/2013 - [] D -- C:\ProgramData\RealNetworks O43 - CFD: 01/12/2013 - [] D -- C:\ProgramData\Samsung O43 - CFD: 06/06/2015 - [] D -- C:\ProgramData\Skype O43 - CFD: 26/11/2012 - [] D -- C:\ProgramData\Skype Extras O43 - CFD: 02/11/2006 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 28/08/2013 - [] D -- C:\ProgramData\Sun O43 - CFD: 04/11/2012 - [] D -- C:\ProgramData\Symantec O43 - CFD: 17/11/2014 - [0] AD -- C:\ProgramData\TEMP O43 - CFD: 02/11/2006 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 25/01/2014 - [] D -- C:\ProgramData\TuneUp Software O43 - CFD: 11/04/2016 - [] D -- C:\ProgramData\Vodafone O43 - CFD: 18/11/2012 - [] D -- C:\ProgramData\WebcamMax O43 - CFD: 24/08/2015 - [] D -- C:\ProgramData\WildTangent O43 - CFD: 30/10/2014 - [] D -- C:\ProgramData\WindowsSearch O43 - CFD: 19/11/2012 - [] D -- C:\ProgramData\Yahoo! O43 - CFD: 19/07/2014 - [0] SHD -- C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} O43 - CFD: 19/07/2014 - [0] D -- C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3} O43 - CFD: 19/07/2014 - [0] SHD -- C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} O43 - CFD: 19/07/2014 - [] D -- C:\Program Files\Common Files\Adobe O43 - CFD: 11/04/2016 - [] D -- C:\Program Files\Common Files\Adobe AIR O43 - CFD: 22/08/2014 - [] D -- C:\Program Files\Common Files\Ahead O43 - CFD: 29/03/2016 - [] D -- C:\Program Files\Common Files\Apple O43 - CFD: 14/08/2014 - [] D -- C:\Program Files\Common Files\AVSMedia O43 - CFD: 22/05/2016 - [] D -- C:\Program Files\Common Files\Config O43 - CFD: 24/05/2014 - [] D -- C:\Program Files\Common Files\DESIGNER O43 - CFD: 27/11/2013 - [] D -- C:\Program Files\Common Files\InstallShield O43 - CFD: 02/08/2015 - [] D -- C:\Program Files\Common Files\Java O43 - CFD: 02/11/2012 - [] D -- C:\Program Files\Common Files\LightScribe O43 - CFD: 05/09/2013 - [] D -- C:\Program Files\Common Files\microsoft shared O43 - CFD: 31/07/2008 - [] D -- C:\Program Files\Common Files\muvee Technologies O43 - CFD: 02/11/2006 - [] D -- C:\Program Files\Common Files\Services O43 - CFD: 06/06/2015 - [] D -- C:\Program Files\Common Files\Skype O43 - CFD: 02/11/2006 - [] D -- C:\Program Files\Common Files\SpeechEngines O43 - CFD: 04/11/2012 - [] D -- C:\Program Files\Common Files\Symantec Shared O43 - CFD: 28/08/2013 - [] D -- C:\Program Files\Common Files\System O43 - CFD: 07/06/2013 - [] D -- C:\Program Files\Common Files\Windows Live O43 - CFD: 02/04/2014 - [] D -- C:\Program Files\Common Files\xing shared O43 - CFD: 04/06/2013 - [] D -- C:\Users\hju\AppData\Roaming\Adobe O43 - CFD: 25/08/2014 - [] D -- C:\Users\hju\AppData\Roaming\Ahead O43 - CFD: 04/11/2012 - [] D -- C:\Users\hju\AppData\Roaming\AnvSoft O43 - CFD: 26/10/2014 - [] D -- C:\Users\hju\AppData\Roaming\Apple Computer O43 - CFD: 19/07/2014 - [] D -- C:\Users\hju\AppData\Roaming\AVG O43 - CFD: 14/08/2014 - [] D -- C:\Users\hju\AppData\Roaming\AVS4YOU O43 - CFD: 17/06/2013 - [] D -- C:\Users\hju\AppData\Roaming\Baidu O43 - CFD: 27/08/2014 - [] D -- C:\Users\hju\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant O43 - CFD: 24/12/2012 - [] D -- C:\Users\hju\AppData\Roaming\CyberLink O43 - CFD: 15/08/2014 - [] D -- C:\Users\hju\AppData\Roaming\DMCache O43 - CFD: 05/10/2013 - [] D -- C:\Users\hju\AppData\Roaming\dvdcss O43 - CFD: 13/01/2014 - [] D -- C:\Users\hju\AppData\Roaming\FilmOn.com O43 - CFD: 27/11/2013 - [] D -- C:\Users\hju\AppData\Roaming\FLEXnet O43 - CFD: 16/05/2013 - [] D -- C:\Users\hju\AppData\Roaming\funkitron O43 - CFD: 26/04/2013 - [] D -- C:\Users\hju\AppData\Roaming\GTek O43 - CFD: 02/11/2012 - [] D -- C:\Users\hju\AppData\Roaming\Hewlett-Packard O43 - CFD: 02/11/2012 - [] D -- C:\Users\hju\AppData\Roaming\Identities O43 - CFD: 22/05/2016 - [] D -- C:\Users\hju\AppData\Roaming\IDM O43 - CFD: 02/11/2012 - [] D -- C:\Users\hju\AppData\Roaming\Macromedia O43 - CFD: 02/11/2006 - [0] D -- C:\Users\hju\AppData\Roaming\Media Center Programs O43 - CFD: 12/08/2015 - [] SD -- C:\Users\hju\AppData\Roaming\Microsoft O43 - CFD: 26/02/2013 - [] D -- C:\Users\hju\AppData\Roaming\Mozilla O43 - CFD: 05/05/2013 - [] D -- C:\Users\hju\AppData\Roaming\muvee Technologies O43 - CFD: 14/10/2015 - [] D -- C:\Users\hju\AppData\Roaming\Nero O43 - CFD: 11/02/2015 - [] D -- C:\Users\hju\AppData\Roaming\ODIN O43 - CFD: 27/09/2013 - [] D -- C:\Users\hju\AppData\Roaming\Opera O43 - CFD: 06/06/2015 - [] D -- C:\Users\hju\AppData\Roaming\Opera Software O43 - CFD: 14/04/2014 - [] D -- C:\Users\hju\AppData\Roaming\PhotoScape O43 - CFD: 02/04/2014 - [] D -- C:\Users\hju\AppData\Roaming\Real O43 - CFD: 09/09/2013 - [] D -- C:\Users\hju\AppData\Roaming\RealNetworks O43 - CFD: 26/07/2015 - [0] D -- C:\Users\hju\AppData\Roaming\rmi O43 - CFD: 29/12/2014 - [] D -- C:\Users\hju\AppData\Roaming\sa.edu.ksa.ayat O43 - CFD: 11/02/2015 - [] D -- C:\Users\hju\AppData\Roaming\Samsung O43 - CFD: 22/05/2016 - [] D -- C:\Users\hju\AppData\Roaming\Skype O43 - CFD: 28/11/2012 - [] D -- C:\Users\hju\AppData\Roaming\skypePM O43 - CFD: 27/08/2014 - [] D -- C:\Users\hju\AppData\Roaming\SlimBrowser O43 - CFD: 07/08/2014 - [] D -- C:\Users\hju\AppData\Roaming\Software Informer O43 - CFD: 27/09/2015 - [] D -- C:\Users\hju\AppData\Roaming\Sun O43 - CFD: 02/11/2012 - [] D -- C:\Users\hju\AppData\Roaming\Symantec O43 - CFD: 19/06/2014 - [] D -- C:\Users\hju\AppData\Roaming\Thinstall O43 - CFD: 24/01/2014 - [] D -- C:\Users\hju\AppData\Roaming\TuneUp Software O43 - CFD: 07/11/2014 - [] D -- C:\Users\hju\AppData\Roaming\Unity O43 - CFD: 01/04/2014 - [] D -- C:\Users\hju\AppData\Roaming\ViberPC O43 - CFD: 05/08/2015 - [] D -- C:\Users\hju\AppData\Roaming\vlc O43 - CFD: 27/11/2013 - [] D -- C:\Users\hju\AppData\Roaming\Vodafone O43 - CFD: 04/11/2012 - [] D -- C:\Users\hju\AppData\Roaming\WebcamMax O43 - CFD: 24/08/2015 - [] D -- C:\Users\hju\AppData\Roaming\WildTangent O43 - CFD: 22/08/2014 - [0] D -- C:\Users\hju\AppData\Roaming\Windows Live Writer O43 - CFD: 18/06/2013 - [] D -- C:\Users\hju\AppData\Roaming\WinRAR O43 - CFD: 09/02/2013 - [] D -- C:\Users\hju\AppData\Roaming\Yahoo! O43 - CFD: 22/05/2016 - [] D -- C:\Users\hju\AppData\Roaming\ZHP O43 - CFD: 01/09/2015 - [] D -- C:\Users\hju\AppData\Roaming\敎潲䍄敔灭慬整sAppData O43 - CFD: 22/05/2016 - [] D -- C:\Users\hju\AppData\Local\9861 O43 - CFD: 15/09/2015 - [] D -- C:\Users\hju\AppData\Local\Adobe O43 - CFD: 14/02/2015 - [] D -- C:\Users\hju\AppData\Local\Ahead O43 - CFD: 05/07/2013 - [] D -- C:\Users\hju\AppData\Local\Alexa O43 - CFD: 30/07/2013 - [] D -- C:\Users\hju\AppData\Local\Apple O43 - CFD: 26/10/2014 - [] D -- C:\Users\hju\AppData\Local\Apple Computer O43 - CFD: 02/11/2012 - [0] SHD -- C:\Users\hju\AppData\Local\Application Data O43 - CFD: 19/07/2014 - [] D -- C:\Users\hju\AppData\Local\AVG O43 - CFD: 21/07/2015 - [] D -- C:\Users\hju\AppData\Local\Ball Component O43 - CFD: 02/04/2014 - [] D -- C:\Users\hju\AppData\Local\Bromium O43 - CFD: 01/12/2013 - [] D -- C:\Users\hju\AppData\Local\cache O43 - CFD: 22/05/2016 - [] D -- C:\Users\hju\AppData\Local\Chedot O43 - CFD: 07/04/2014 - [] D -- C:\Users\hju\AppData\Local\ChromeTabManager O43 - CFD: 02/04/2014 - [] D -- C:\Users\hju\AppData\Local\Chromium O43 - CFD: 02/04/2014 - [] D -- C:\Users\hju\AppData\Local\Comodo O43 - CFD: 22/05/2016 - [] D -- C:\Users\hju\AppData\Local\CrashDumps O43 - CFD: 28/08/2013 - [] D -- C:\Users\hju\AppData\Local\CrashRpt =>.Superfluous.CrashReports O43 - CFD: 11/02/2015 - [] D -- C:\Users\hju\AppData\Local\Downloaded Installations O43 - CFD: 22/05/2016 - [] D -- C:\Users\hju\AppData\Local\ESET O43 - CFD: 11/02/2013 - [] D -- C:\Users\hju\AppData\Local\Facebook O43 - CFD: 13/01/2014 - [] D -- C:\Users\hju\AppData\Local\FilmOn.com O43 - CFD: 28/07/2015 - [] D -- C:\Users\hju\AppData\Local\Google O43 - CFD: 02/11/2012 - [0] SHD -- C:\Users\hju\AppData\Local\History O43 - CFD: 23/03/2013 - [] D -- C:\Users\hju\AppData\Local\Macromedia O43 - CFD: 10/03/2016 - [] D -- C:\Users\hju\AppData\Local\Microsoft O43 - CFD: 30/03/2013 - [] D -- C:\Users\hju\AppData\Local\Microsoft Games O43 - CFD: 24/08/2013 - [0] D -- C:\Users\hju\AppData\Local\Microsoft Help O43 - CFD: 26/02/2013 - [] D -- C:\Users\hju\AppData\Local\Mozilla O43 - CFD: 27/09/2013 - [] D -- C:\Users\hju\AppData\Local\Opera O43 - CFD: 18/12/2015 - [] D -- C:\Users\hju\AppData\Local\Opera Software O43 - CFD: 02/04/2014 - [] D -- C:\Users\hju\AppData\Local\Skype O43 - CFD: 11/04/2016 - [] D -- C:\Users\hju\AppData\Local\SWDS =>PUP.Optional.InstallBrain O43 - CFD: 22/05/2016 - [] D -- C:\Users\hju\AppData\Local\Temp O43 - CFD: 02/11/2012 - [0] SHD -- C:\Users\hju\AppData\Local\Temporary Internet Files O43 - CFD: 14/01/2015 - [] D -- C:\Users\hju\AppData\Local\Temp{8F0881F0-6604-4AFF-9B51-090D29FAC337} O43 - CFD: 22/05/2016 - [] D -- C:\Users\hju\AppData\Local\Temp{E311F95F-9500-4BCC-82AF-F356C3F18F41} O43 - CFD: 14/03/2015 - [0] D -- C:\Users\hju\AppData\Local\Unity O43 - CFD: 11/03/2013 - [] D -- C:\Users\hju\AppData\Local\VirtualStore O43 - CFD: 22/08/2014 - [] D -- C:\Users\hju\AppData\Local\Windows Live Writer O43 - CFD: 26/02/2013 - [] D -- C:\Users\hju\AppData\Local\Yahoo O43 - CFD: 02/04/2014 - [] D -- C:\Users\hju\AppData\Local\Yandex O43 - CFD: 21/01/2008 - [] RD -- C:\Users\hju\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 02/11/2012 - [] RD -- C:\Users\hju\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 14/08/2014 - [] D -- C:\Users\hju\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AVS4YOU O43 - CFD: 15/10/2015 - [0] D -- C:\Users\hju\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CueClub O43 - CFD: 29/01/2013 - [] D -- C:\Users\hju\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite O43 - CFD: 02/11/2012 - [] D -- C:\Users\hju\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam O43 - CFD: 28/06/2013 - [0] D -- C:\Users\hju\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Golden Al-Wafi Translator O43 - CFD: 29/12/2014 - [] D -- C:\Users\hju\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome Canary O43 - CFD: 22/05/2016 - [] D -- C:\Users\hju\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager O43 - CFD: 21/01/2008 - [] RD -- C:\Users\hju\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 10/11/2014 - [] RD -- C:\Users\hju\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 24/08/2013 - [] D -- C:\Users\hju\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 31/07/2008 - [0] SHD -- C:\Windows\System32\Config\systemprofile\AppData\Local\Application Data O43 - CFD: 19/07/2014 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\AVG O43 - CFD: 06/06/2015 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\CrashDumps O43 - CFD: 22/05/2016 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\ESET O43 - CFD: 16/04/2014 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Google O43 - CFD: 31/07/2008 - [0] SHD -- C:\Windows\System32\Config\systemprofile\AppData\Local\History O43 - CFD: 31/07/2008 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft O43 - CFD: 31/07/2008 - [0] SHD -- C:\Windows\System32\Config\systemprofile\AppData\Local\Temporary Internet Files O43 - CFD: 31/07/2008 - [] RD -- C:\Windows\System32\Config\systemprofile\Start Menu\Programs\Administrative Tools O43 - CFD: 31/07/2008 - [] RD -- C:\Windows\System32\Config\systemprofile\Start Menu\Programs\Startup ---\\ Latest files created in Prefetcher (1) - 16s O45 - LFCP:[MD5.FC999B549038A266DDA6970AE97F7DDE] 22/05/2016 A -- C:\Windows\Prefetch\PLUS-HD-9.4-NOVAINSTALLER.EXE-244FAC2E.pf =>PUP.Optional.CrossRider ---\\ ShellIconOverlayIdentifiers (SIOI) (9) - 1s O106 - SIOI: IDM Shell Extension [ IDM Shell Extension] - {CDC95B92-E27C-4745-A8C5-64A52A78855D}. (.Tonec Inc. - Internet Download Manager module.) -- C:\Program Files\Internet Download Manager\IDMShellExt.dll =>.Tonec Inc.® O106 - SIOI: Google Drive Shell extension [ GoogleDriveBlacklisted] - {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}. (.Google - Google Drive shell extension.) -- C:\Program Files\Google\Drive\googledrivesync32.dll =>.Google Inc® O106 - SIOI: Google Drive Shell extension [ GoogleDriveSynced] - {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}. (.Google - Google Drive shell extension.) -- C:\Program Files\Google\Drive\googledrivesync32.dll =>.Google Inc® O106 - SIOI: Google Drive Shell extension [ GoogleDriveSyncing] - {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}. (.Google - Google Drive shell extension.) -- C:\Program Files\Google\Drive\googledrivesync32.dll =>.Google Inc® O106 - SIOI: Groove Explorer Icon Overlay 1 (GFS Unread Stub) [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] - {99FD978C-D287-4F50-827F-B2C658EDA8E7}. (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll =>.Microsoft Corporation® O106 - SIOI: Groove Explorer Icon Overlay 2 (GFS Stub) [Groove Explorer Icon Overlay 2 (GFS Stub)] - {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}. (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll =>.Microsoft Corporation® O106 - SIOI: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] - {920E6DB1-9907-4370-B3A0-BAFC03D81399}. (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll =>.Microsoft Corporation® O106 - SIOI: Groove Explorer Icon Overlay 3 (GFS Folder) [Groove Explorer Icon Overlay 3 (GFS Folder)] - {16F3DD56-1AF5-4347-846D-7C10C4192619}. (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll =>.Microsoft Corporation® O106 - SIOI: Groove Explorer Icon Overlay 4 (GFS Unread Mark) [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] - {2916C86E-86A6-43FE-8112-43ABE6BF8DCC}. (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll =>.Microsoft Corporation® ---\\ System Drivers List (93) - 20s O58 - SDL:2008/01/21 03:23:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [422968] =>.Microsoft Windows® O58 - SDL:2008/01/21 03:23:25 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [300600] =>.Microsoft Windows® O58 - SDL:2008/01/21 03:23:26 A . (.Adaptec, Inc. - Adaptec LH Ultra160 Driver (x86).) -- C:\Windows\System32\drivers\adpu160m.sys [101432] =>.Microsoft Windows® O58 - SDL:2008/01/21 03:23:27 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\drivers\adpu320.sys [149560] =>.Microsoft Windows® O58 - SDL:2008/01/21 03:23:00 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [17464] =>.Microsoft Windows® O58 - SDL:2008/01/21 03:23:23 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [79416] =>.Microsoft Windows® O58 - SDL:2008/01/21 03:23:24 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [79928] =>.Microsoft Windows® O58 - SDL:2008/04/27 19:07:44 A . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driv.) -- C:\Windows\System32\drivers\athr.sys [909824] =>.Atheros Communications, Inc. O58 - SDL:2010/10/27 16:48:04 A . (.Beceem communications pvt ltd. - Beceem Communications Inc. WiMAX driver.) -- C:\Windows\System32\drivers\BcmBusCtr.sys [48512] O58 - SDL:2006/11/02 08:30:53 A . (.Broadcom Corporation - BCM 802.11g Network Adapter wireless driver.) -- C:\Windows\System32\drivers\BCMWL6.SYS [464384] =>.Broadcom Corporation O58 - SDL:2006/11/02 09:24:45 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [13568] =>.Brother Industries, Ltd. O58 - SDL:2006/11/02 09:24:46 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [5248] =>.Brother Industries, Ltd. O58 - SDL:2006/11/02 09:25:24 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [71808] =>.Brother Industries Ltd. O58 - SDL:2006/11/02 09:24:44 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [62336] =>.Brother Industries Ltd. O58 - SDL:2006/11/02 09:24:44 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [12160] =>.Brother Industries Ltd. O58 - SDL:2006/11/02 09:24:47 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [11904] =>.Brother Industries Ltd. O58 - SDL:2008/06/05 17:58:42 A . (.Conexant Systems Inc. - High Definition Audio Function Driver.) -- C:\Windows\System32\drivers\CHDRT32.sys [222208] =>.Conexant Systems Inc. O58 - SDL:2008/01/21 03:23:00 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [19000] =>.Microsoft Windows® O58 - SDL:2006/11/02 10:50:11 A . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\drivers\djsvs.sys [71272] =>.Microsoft Windows® O58 - SDL:2010/10/27 16:48:04 A . (.Beceem communications pvt ltd. - Beceem Communications Inc. WiMAX driver.) -- C:\Windows\System32\drivers\drxvi314.sys [331264] O58 - SDL:2008/01/21 03:23:24 A . (.Intel Corporation - Intel(R) PRO/1000 Adapter NDIS 6 deserializ.) -- C:\Windows\System32\drivers\E1G60I32.sys [118784] =>.Intel Corporation O58 - SDL:2016/05/12 10:48:30 A . (.ESET - Amon monitor.) -- C:\Windows\System32\drivers\eamonm.sys [206312] =>.ESET, spol. s r.o.® O58 - SDL:2016/05/12 10:48:30 A . (.ESET - ESET Helper driver.) -- C:\Windows\System32\drivers\ehdrv.sys [146024] =>.ESET, spol. s r.o.® O58 - SDL:2016/05/12 10:48:30 A . (.ESET - ESET OPP Keyboard Filter.) -- C:\Windows\System32\drivers\ekbdflt.sys [111040] =>.ESET, spol. s r.o.® O58 - SDL:2008/01/21 03:23:22 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [342584] =>.Microsoft Windows® O58 - SDL:2016/05/12 10:48:30 A . (.ESET - ESET Personal Firewall driver.) -- C:\Windows\System32\drivers\epfw.sys [152728] =>.ESET, spol. s r.o.® O58 - SDL:2016/05/12 10:48:30 A . (.ESET - Epfw NDIS LightWeight Filter.) -- C:\Windows\System32\drivers\EpfwLWF.sys [44608] =>.ESET, spol. s r.o.® O58 - SDL:2016/05/12 10:48:30 A . (.ESET - ESET Personal Firewall driver.) -- C:\Windows\System32\drivers\epfwwfp.sys [71488] =>.ESET, spol. s r.o.® O58 - SDL:2012/08/21 13:01:22 A . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\System32\drivers\GEARAspiWDM.sys [26840] =>.GEAR Software Inc.® O58 - SDL:2008/01/21 03:23:26 A . (.Hewlett-Packard Company - Smart Array Storport Driver.) -- C:\Windows\System32\drivers\HpCISSs.sys [40504] =>.Microsoft Windows® O58 - SDL:2007/06/19 01:12:04 A . (.Hewlett-Packard Development Company, L.P. - HpqKbFiltr Keyboard Filter Driver.) -- C:\Windows\System32\drivers\HpqKbFiltr.sys [16768] =>.Hewlett-Packard Development Company, L.P. O58 - SDL:2007/11/01 02:47:54 A . (.Conexant Systems, Inc. - HSF_HWAZL WDM driver.) -- C:\Windows\System32\drivers\HSXHWAZL.sys [208896] =>.Conexant Systems, Inc. O58 - SDL:2007/11/01 02:47:08 A . (.Conexant Systems, Inc. - HSF_CNXT driver.) -- C:\Windows\System32\drivers\HSX_CNXT.sys [661504] =>.Conexant Systems, Inc. O58 - SDL:2007/11/01 02:51:26 A . (.Conexant Systems, Inc. - HSF_DP driver.) -- C:\Windows\System32\drivers\HSX_DPV.sys [985600] =>.Conexant Systems, Inc. O58 - SDL:2008/12/16 21:08:20 A . (.HUAWEI Communication - HuaweiWiMAXUSB Device Driver.) -- C:\Windows\System32\drivers\HuaweiWiMAXUSB.sys [46080] O58 - SDL:2008/01/21 03:23:23 A . (.Intel Corporation - Intel Matrix Storage Manager driver (base).) -- C:\Windows\System32\drivers\iaStorV.sys [235064] =>.Microsoft Windows® O58 - SDL:2016/05/20 13:28:01 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\drivers\idmwfp.sys [132040] {7828C7315808BC8717710E13FA3C0B24} =>.Tonec Inc. O58 - SDL:2008/06/12 19:43:16 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd32.sys [2381312] =>.Intel Corporation O58 - SDL:2006/11/02 10:50:17 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [41576] =>.Microsoft Windows® O58 - SDL:2008/06/04 18:54:22 A . (.Intel(R) Corporation - Intel(R) High Definition Audio HDMI.) -- C:\Windows\System32\drivers\IntcHdmi.sys [113664] =>.Intel(R) Corporation O58 - SDL:2006/11/02 10:50:07 A . (.Integrated Technology Express, Inc. - ITE IT8211 ATA/ATAPI SCSI miniport.) -- C:\Windows\System32\drivers\iteatapi.sys [35944] =>.Microsoft Windows® O58 - SDL:2006/11/02 10:50:09 A . (.Integrated Technology Express, Inc. - ITE IT8212 ATA RAID SCSI miniport.) -- C:\Windows\System32\drivers\iteraid.sys [35944] =>.Microsoft Windows® O58 - SDL:2008/01/21 03:23:23 A . (.LSI Logic - LSI Logic Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [96312] =>.Microsoft Windows® O58 - SDL:2008/01/21 03:23:25 A . (.LSI Logic - LSI Logic Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [89656] =>.Microsoft Windows® O58 - SDL:2008/01/21 03:23:23 A . (.LSI Logic - LSI Logic Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [96312] =>.Microsoft Windows® O58 - SDL:2016/03/10 14:08:52 A . (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\mbam.sys [24448] =>.Malwarebytes Corporation® O58 - SDL:2016/03/10 14:08:56 A . (.Malwarebytes - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\drivers\mbamchameleon.sys [126336] =>.Malwarebytes Corporation® O58 - SDL:2016/05/22 15:27:45 A . (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys [170200] =>.Malwarebytes Corporation® O58 - SDL:2006/06/18 23:26:58 A . (.Conexant - Diagnostic Interface x86 Driver.) -- C:\Windows\System32\drivers\mdmxsdk.sys [12672] =>.Conexant O58 - SDL:2008/01/21 03:23:27 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [31288] =>.Microsoft Windows® O58 - SDL:2008/01/21 03:23:27 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [386616] =>.Microsoft Windows® O58 - SDL:2006/11/02 10:49:59 A . (.LSI Logic Corporation - MegaRAID RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\Mraid35x.sys [33384] =>.Microsoft Windows® O58 - SDL:2016/03/10 14:09:00 A . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\drivers\mwac.sys [53120] =>.Malwarebytes Corporation® O58 - SDL:2006/11/02 10:50:19 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [45160] =>.Microsoft Windows® O58 - SDL:2006/11/02 08:36:50 A . (.N-trig Innovative Technologies - N-trig tablet digitizer in-box driver.) -- C:\Windows\System32\drivers\ntrigdigi.sys [20608] =>.N-trig Innovative Technologies O58 - SDL:2006/11/02 08:30:56 A . (.NVIDIA Corporation - NVIDIA MCP Networking Function Driver..) -- C:\Windows\System32\drivers\nvm60x32.sys [429056] =>.NVIDIA Corporation O58 - SDL:2008/01/21 03:23:21 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [102968] =>.Microsoft Windows® O58 - SDL:2008/01/21 03:23:21 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [45112] =>.Microsoft Windows® O58 - SDL:2008/01/21 03:23:24 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1122360] =>.Microsoft Windows® O58 - SDL:2006/11/02 10:50:35 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [106088] =>.Microsoft Windows® O58 - SDL:2008/06/10 19:54:36 A . (.Realtek Corporation - Realtek 8101E/8168/8169 NDIS6 32-bit Driver.) -- C:\Windows\System32\drivers\Rtlh86.sys [123904] =>.Realtek Corporation O58 - SDL:2008/06/06 03:01:50 A . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for Vista.) -- C:\Windows\System32\drivers\RTSTOR.sys [62464] =>.Realtek Semiconductor Corp. O58 - SDL:2006/11/02 07:37:21 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [20480] =>.Macrovision Corporation, Macrovision Europe Limited, O58 - SDL:2008/01/21 03:23:26 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [74808] =>.Microsoft Windows® O58 - SDL:2006/11/02 10:50:05 A . (.LSI Logic - LSI Logic 8XX SCSI Miniport Driver.) -- C:\Windows\System32\drivers\symc8xx.sys [35944] =>.Microsoft Windows® O58 - SDL:2006/11/02 10:49:56 A . (.LSI Logic - LSI Logic Hi-Perf SCSI Miniport Driver.) -- C:\Windows\System32\drivers\sym_hi.sys [31848] =>.Microsoft Windows® O58 - SDL:2006/11/02 10:50:03 A . (.LSI Logic - LSI Logic Ultra160 SCSI Miniport Driver.) -- C:\Windows\System32\drivers\sym_u3.sys [34920] =>.Microsoft Windows® O58 - SDL:2008/04/17 19:05:16 A . (.Synaptics, Inc. - Synaptics Touchpad Driver.) -- C:\Windows\System32\drivers\SynTP.sys [199344] =>.Synaptics Incorporated® O58 - SDL:2008/01/21 03:23:20 A . (.ULi Electronics Inc. - ULi SATA Controller Driver.) -- C:\Windows\System32\drivers\uliahci.sys [238648] =>.Microsoft Windows® O58 - SDL:2006/11/02 10:50:35 A . (.Promise Technology, Inc. - Promise Ultra/Sata Series Driver for Win200.) -- C:\Windows\System32\drivers\ulsata.sys [98408] =>.Microsoft Windows® O58 - SDL:2008/01/21 03:23:23 A . (.Promise Technology, Inc. - Promise SATAII150 Series Windows Drivers.) -- C:\Windows\System32\drivers\ulsata2.sys [115816] =>.Microsoft Windows® O58 - SDL:2015/06/17 05:04:22 A . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\drivers\usbaapl.sys [45056] =>.Apple, Inc. O58 - SDL:2008/01/21 03:23:00 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [20024] =>.Microsoft Windows® O58 - SDL:2008/01/21 03:23:23 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [130616] =>.Microsoft Windows® O58 - SDL:2008/01/21 03:23:22 A . (.Conexant Systems, Inc. - HSF_HWAZL WDM driver.) -- C:\Windows\System32\drivers\VSTAZL3.SYS [200704] =>.Conexant Systems, Inc. O58 - SDL:2008/01/21 03:23:23 A . (.Conexant Systems, Inc. - HSF_CNXT driver.) -- C:\Windows\System32\drivers\VSTCNXT3.SYS [654336] =>.Conexant Systems, Inc. O58 - SDL:2008/01/21 03:23:22 A . (.Conexant Systems, Inc. - HSF_DP driver.) -- C:\Windows\System32\drivers\VSTDPV3.SYS [987648] =>.Conexant Systems, Inc. O58 - SDL:2007/10/18 00:36:54 A . (.Conexant Systems, Inc. - Modem Audio Device Driver.) -- C:\Windows\System32\drivers\XAudio.sys [8704] =>.Conexant Systems, Inc. O58 - SDL:2006/11/02 08:09:42 A . (...) -- C:\Windows\System32\ANSI.SYS [9029] O58 - SDL:2006/11/02 08:09:45 A . (...) -- C:\Windows\System32\country.sys [27097] O58 - SDL:2006/11/02 08:09:41 A . (...) -- C:\Windows\System32\HIMEM.SYS [4768] O58 - SDL:2006/11/02 08:09:44 A . (...) -- C:\Windows\System32\KEY01.SYS [42809] O58 - SDL:2006/11/02 08:09:44 A . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537] O58 - SDL:2006/11/02 08:09:29 A . (...) -- C:\Windows\System32\NTDOS.SYS [27866] O58 - SDL:2006/11/02 08:09:35 A . (...) -- C:\Windows\System32\NTDOS404.SYS [29146] O58 - SDL:2006/11/02 08:09:38 A . (...) -- C:\Windows\System32\NTDOS411.SYS [29370] O58 - SDL:2006/11/02 08:09:40 A . (...) -- C:\Windows\System32\NTDOS412.SYS [29274] O58 - SDL:2006/11/02 08:09:31 A . (...) -- C:\Windows\System32\NTDOS804.SYS [29146] O58 - SDL:2006/11/02 08:09:20 A . (...) -- C:\Windows\System32\NTIO.SYS [33952] O58 - SDL:2006/11/02 08:09:23 A . (...) -- C:\Windows\System32\NTIO404.SYS [34672] O58 - SDL:2006/11/02 08:09:24 A . (...) -- C:\Windows\System32\NTIO411.SYS [35776] O58 - SDL:2006/11/02 08:09:26 A . (...) -- C:\Windows\System32\NTIO412.SYS [35536] O58 - SDL:2006/11/02 08:09:22 A . (...) -- C:\Windows\System32\NTIO804.SYS [34672] ---\\ Last modified or created user files (1) - 80s O61 - LFC: 2016/05/22 14:54:30 A . (..) -- C:\Users\hju\AppData\Local\SWDS\SWDS.bin [5612] ---\\ File Associations Shell Spawning (9) - 0s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\WINDOWS\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\WINDOWS\System32\eventvwr.exe =>.Microsoft Corporation O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\System32\wscript.exe =>.Microsoft Corporation O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\WINDOWS\regedit.exe =>.Microsoft Corporation O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S ---\\ Start Menu Internet (12) - 1s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Internet Explorer\iexplore.ex http://istart.webssearches.com/ =>PUP.Optional.IsStart O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Opera\Opera.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\WINDOWS\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Program Files\Opera\Opera.exe (.not file.) O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\WINDOWS\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Program Files\Opera\Opera.exe (.not file.) O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\WINDOWS\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Program Files\Opera\Opera.exe (.not file.) ---\\ Search Browser Infection (19) - 25s O69 - SBI: prefs.js [hju - ch0apz00.default-1416242166785] user_pref("browser.newtab.url", "http://mysearch.sweetpacks.com/?barid=1605756271880948072&src=97&i=48&did=11034&&st=23"); =>PUP.Optional.SweetIM O69 - SBI: prefs.js [hju - ch0apz00.default-1416242166785] user_pref("browser.startup.homepage", "http://mysearch.sweetpacks.com/?barid=1605756271880948072&src=10&i=48&did=11034&&st=23"); =>PUP.Optional.SweetIM O69 - SBI: prefs.js [hju - ch0apz00.default-1416242166785] user_pref("extensions.PlurPush.asul", "1440463264898"); =>PUP.Optional.PlurPush O69 - SBI: prefs.js [hju - ch0apz00.default-1416242166785] user_pref("extensions.PlurPush.aul", "1440463249364"); =>PUP.Optional.PlurPush O69 - SBI: prefs.js [hju - ch0apz00.default-1416242166785] user_pref("extensions.a55d597b4643f421eb00726a68e26903ba62d99f0140244d586717a618c9c4868com53164.53164.name", "Plus-HD-9.4"); =>PUP.Optional.CrossRider O69 - SBI: prefs.js [hju - ch0apz00.default-1416242166785] user_pref("keyword.URL", "http://mysearch.sweetpacks.com?src=6&barid=1605756271880948072&i=48&did=11034&&st=23&q="); =>PUP.Optional.SweetIM O69 - SBI: SearchScopes [HKCU] {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKCU] {9AD09901-06DD-4DDD-A62D-6D2243B771AB} [DefaultScope] - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (@ieframe.dll,-12512) - http://search.live.com/ O69 - SBI: SearchScopes [HKLM] {80c554b9-c7f8-4a21-9471-06d606da78a2} [DefaultScope] - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKLM] {AD9BF020-AE3E-49BA-8FA0-85F599D75B35} - (WhiteSmoke Search) - http://search.whitesmoke.com/ =>PUP.Optional.WhiteSmoke O69 - SBI: SearchScopes [HKUS\.DEFAULT] {80c554b9-c7f8-4a21-9471-06d606da78a2} [DefaultScope] - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKUS\.DEFAULT] {AD9BF020-AE3E-49BA-8FA0-85F599D75B35} - (WhiteSmoke Search) - http://search.whitesmoke.com/ =>PUP.Optional.WhiteSmoke O69 - SBI: SearchScopes [HKUS\S-1-5-18] {80c554b9-c7f8-4a21-9471-06d606da78a2} [DefaultScope] - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKUS\S-1-5-18] {AD9BF020-AE3E-49BA-8FA0-85F599D75B35} - (WhiteSmoke Search) - http://search.whitesmoke.com/ =>PUP.Optional.WhiteSmoke O69 - SBI: SearchScopes [HKUS\S-1-5-19] {80c554b9-c7f8-4a21-9471-06d606da78a2} [DefaultScope] - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKUS\S-1-5-19] {AD9BF020-AE3E-49BA-8FA0-85F599D75B35} - (WhiteSmoke Search) - http://search.whitesmoke.com/ =>PUP.Optional.WhiteSmoke O69 - SBI: SearchScopes [HKUS\S-1-5-20] {80c554b9-c7f8-4a21-9471-06d606da78a2} [DefaultScope] - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKUS\S-1-5-20] {AD9BF020-AE3E-49BA-8FA0-85F599D75B35} - (WhiteSmoke Search) - http://search.whitesmoke.com/ =>PUP.Optional.WhiteSmoke ---\\ Search Svchost Services (32) - 1s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\WINDOWS\System32\aelupsvc.dll [24576] =>.Microsoft Corporation O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\WINDOWS\System32\wercplsupport.dll [62976] =>.Microsoft Corporation O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\WINDOWS\System32\shsvcs.dll [247808] =>.Microsoft Corporation O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\WINDOWS\System32\certprop.dll [40448] =>.Microsoft Corporation O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\WINDOWS\System32\certprop.dll [40448] =>.Microsoft Corporation O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\WINDOWS\System32\srvsvc.dll [125952] =>.Microsoft Corporation O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\WINDOWS\System32\gpsvc.dll [574464] =>.Microsoft Corporation O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\WINDOWS\System32\IKEEXT.DLL [438272] =>.Microsoft Corporation O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\WINDOWS\System32\audiosrv.dll [314368] =>.Microsoft Corporation O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\WINDOWS\System32\rasauto.dll [90624] =>.Microsoft Corporation O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINDOWS\System32\rasmans.dll [260608] =>.Microsoft Corporation O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\WINDOWS\System32\mprdim.dll [68608] =>.Microsoft Corporation O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\WINDOWS\System32\Sens.dll [47104] =>.Microsoft Corporation O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\WINDOWS\System32\ipnathlp.dll [288256] =>.Microsoft Corporation O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\WINDOWS\System32\tapisrv.dll [242688] =>.Microsoft Corporation O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Terminal Server Remote Connections Manager.) -- C:\WINDOWS\System32\termsrv.dll [448512] =>.Microsoft Corporation O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\WINDOWS\System32\wuaueng.dll [1695232] =>.Microsoft Corporation O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\WINDOWS\System32\qmgr.dll [758272] =>.Microsoft Corporation O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\WINDOWS\System32\shsvcs.dll [247808] =>.Microsoft Corporation O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\WINDOWS\System32\iphlpsvc.dll [190464] =>.Microsoft Corporation O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\WINDOWS\System32\seclogon.dll [19968] =>.Microsoft Corporation O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\WINDOWS\System32\appinfo.dll [33280] =>.Microsoft Corporation O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\WINDOWS\System32\iscsiexe.dll [111616] =>.Microsoft Corporation O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) -- C:\WINDOWS\System32\mmcss.dll [45056] =>.Microsoft Corporation O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\WINDOWS\System32\profsvc.dll [153600] =>.Microsoft Corporation O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\WINDOWS\System32\eapsvc.dll [57344] =>.Microsoft Corporation O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\System32\wbem\WMIsvc.dll [161792] =>.Microsoft Corporation O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\WINDOWS\System32\schedsvc.dll [603648] =>.Microsoft Corporation O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Terminal Services Configuration service.) -- C:\WINDOWS\System32\SessEnv.dll [84992] =>.Microsoft Corporation O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\WINDOWS\System32\browser.dll [81920] =>.Microsoft Corporation O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\WINDOWS\System32\KMSVC.DLL [68096] =>.Microsoft Corporation O83 - Search Svchost Services: ezSharedSvc (ezSharedSvc) . (.EasyBits Sofware AS - Shared EasyBits services for Windows.) -- C:\WINDOWS\System32\ezsvc7.dll [129992] ---\\ Firewall Active Exception List (14) - 6s O87 - FAEL: "TCP Query User{FF8DDF42-4585-400F-825B-FFF76CA0A8C6}C:\program files\nimbuzz\nimbuzz.exe" [In-None-P6-TRUE] .(...) -- C:\program files\nimbuzz\nimbuzz.exe (.not file.) O87 - FAEL: "UDP Query User{7E6CB6C2-9C80-451E-96CC-0E4F4E328F30}C:\program files\nimbuzz\nimbuzz.exe" [In-None-P17-TRUE] .(...) -- C:\program files\nimbuzz\nimbuzz.exe (.not file.) O87 - FAEL: "{4B3FD25A-D8FB-4A4E-A08C-C502730D84D9}" [In-None-P6-TRUE] .(.Hi-Player.com, Inc. - HiPlayer Web Installer.) -- C:\ProgramData\Hi\HiPlayer\PlayerWebInstaller_Hi.exe {60F6AD6D09199C81989F5CD146FBBF4F} O87 - FAEL: "{9962FBFB-6D33-43D8-AC04-8F56F98DB8B4}" [In-None-P17-TRUE] .(.Hi-Player.com, Inc. - HiPlayer Web Installer.) -- C:\ProgramData\Hi\HiPlayer\PlayerWebInstaller_Hi.exe {60F6AD6D09199C81989F5CD146FBBF4F} O87 - FAEL: "{FDED8C6F-72E6-4B11-B811-21CEF3192450}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Opera\opera.exe (.not file.) O87 - FAEL: "{4403A19E-5957-4A74-BE8E-CCC88BE1694A}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Opera\opera.exe (.not file.) O87 - FAEL: "{33016809-C9AE-43DA-B10D-0808D9D6F65E}" [In-None-P17-TRUE] .(...) -- C:\Users\hju\AppData\Local\Viber\Viber.exe (.not file.) O87 - FAEL: "{E13FD650-4760-4F33-B61B-2985471B9DEF}" [In-None-P6-TRUE] .(...) -- C:\Program Files\PCDApp\dgen.exe (.not file.) O87 - FAEL: "{83E66BE9-2EA2-422E-AEA4-E9D30C034A8B}" [In-None-P17-TRUE] .(...) -- C:\Program Files\PCDApp\dgen.exe (.not file.) O87 - FAEL: "{BE74D749-34F0-403A-96A4-2929BEF43A44}" [In-None-P17-TRUE] .(...) -- C:\Users\hju\AppData\Local\Torch\Plugins\Hola\hola_plugin_x64.exe (.not file.) =>.Superfluous.Torch O87 - FAEL: "TCP Query User{6CCC4539-27A2-41D0-B5FD-E5BF6E4DECE8}E:\easysetupassistant\tl-wdr4300\easysetupassistant.exe" [In-None-P6-TRUE] .(...) -- E:\easysetupassistant\tl-wdr4300\easysetupassistant.exe (.not file.) O87 - FAEL: "UDP Query User{6BB61586-1E70-4A49-9632-1FC20BE4FDB7}E:\easysetupassistant\tl-wdr4300\easysetupassistant.exe" [In-None-P17-TRUE] .(...) -- E:\easysetupassistant\tl-wdr4300\easysetupassistant.exe (.not file.) O87 - FAEL: "{FF43E25D-6355-44C1-8DF8-5616AE00B29F}" [In-None-P17-TRUE] .(...) -- C:\Users\hju\AppData\Local\Chedot\Application\chedot.exe (.not file.) O87 - FAEL: "{E46E5BEC-A6E9-4585-A590-3BF1C2942CED}" [In-None-P17-TRUE] .(...) -- C:\Users\300049\AppData\Local\Chedot\Application\chedot.exe (.not file.) ---\\ Additional Scan (O88) (29) - 0s C:\Users\hju\AppData\Roaming\Mozilla\Firefox\Profiles\ch0apz00.default-1416242166785\searchplugins\dsrlte1.xml =>PUP.Optional.PaybyAds HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserProtect =>PUP.Optional.Eazel HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\My Program_is1 =>.Superfluous.MyProgram HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SqueakyChocolate, LLC UpdateChecker =>PUP.Optional.Squeaky HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SweeetPlayer bundle =>.Superfluous.PerionNetwork HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhiteSmoke Search =>PUP.Optional.WhiteSmoke HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>Heuristic.Suspect HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserProtect =>PUP.Optional.Eazel HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\My Program_is1 =>.Superfluous.MyProgram HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SqueakyChocolate, LLC UpdateChecker =>PUP.Optional.Squeaky HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SweeetPlayer bundle =>.Superfluous.PerionNetwork HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhiteSmoke Search =>PUP.Optional.WhiteSmoke HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>Heuristic.Suspect HKLM\SOFTWARE\ErrorLists-crcodedownloader =>PUP.Optional.SoftwareEngine HKLM\SOFTWARE\WhiteSmoke Search =>PUP.Optional.WhiteSmoke HKLM\SOFTWARE\WNLT =>PUP.Optional.IncrediBar HKCU\SOFTWARE\Chedot =>PUP.Optional.ChedotBrowser HKCU\SOFTWARE\webdisco =>PUP.Optional.WebDisco HKCU\SOFTWARE\WNLT =>PUP.Optional.IncrediBar C:\Program Files\sweetpacks bundle uninstaller_SweetPlayer_1348381 =>PUP.Optional.SweetIM C:\Program Files\WhiteSmoke Search =>PUP.Optional.WhiteSmoke C:\Users\hju\AppData\Local\CrashRpt =>.Superfluous.CrashReports C:\Users\hju\AppData\Local\SWDS =>PUP.Optional.InstallBrain C:\Windows\Prefetch\PLUS-HD-9.4-NOVAINSTALLER.EXE-244FAC2E.pf =>PUP.Optional.CrossRider HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{AD9BF020-AE3E-49BA-8FA0-85F599D75B35} =>PUP.Optional.WhiteSmoke HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{AD9BF020-AE3E-49BA-8FA0-85F599D75B35} =>PUP.Optional.WhiteSmoke HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\{AD9BF020-AE3E-49BA-8FA0-85F599D75B35} =>PUP.Optional.WhiteSmoke HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\{AD9BF020-AE3E-49BA-8FA0-85F599D75B35} =>PUP.Optional.WhiteSmoke HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\{AD9BF020-AE3E-49BA-8FA0-85F599D75B35} =>PUP.Optional.WhiteSmoke ---\\ Summary of the elements found (18) - 0s http://www.nicolascoolman.fr/?p=332 =>PUP.Optional.SweetIM http://www.nicolascoolman.fr/?p=1754 =>PUP.Optional.PaybyAds http://www.nicolascoolman.fr/?p=318 =>PUP.Optional.WhiteSmoke http://www.nicolascoolman.fr/?p=314 =>PUP.Optional.Eazel http://www.nicolascoolman.fr/?p=5145 =>.Superfluous.MyProgram http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.Squeaky http://www.nicolascoolman.fr/?p=5145 =>.Superfluous.PerionNetwork http://www.nicolascoolman.info/2016/04/22/heuristic-suspect/ =>Heuristic.Suspect http://www.nicolascoolman.fr/?p=1040 =>PUP.Optional.SoftwareEngine http://www.nicolascoolman.fr/?p=175 =>PUP.Optional.IncrediBar http://www.nicolascoolman.fr/pup-optional-chedotbrowser/ =>PUP.Optional.ChedotBrowser http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.WebDisco http://www.nicolascoolman.fr/?p=5145 =>.Superfluous.CrashReports http://www.nicolascoolman.fr/?p=600 =>PUP.Optional.InstallBrain http://www.nicolascoolman.info/2016/04/30/pup-optional-crossrider/ =>PUP.Optional.CrossRider http://www.nicolascoolman.fr/pup-isstart/ =>PUP.Optional.IsStart http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.PlurPush http://www.nicolascoolman.fr/?p=5145 =>.Superfluous.Torch ~ End of the scan, 46593 items in 00h14mn17s (1227)(0)