~ ZHPDiag v2017.4.28.73 By Nicolas Coolman (2017/04/26) ~ Run by tarek (Administrator) (2017/04/29 10:18:30) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ State version: Version OK ~ Mode: Scan ~ Report: C:\Users\tarek\Desktop\ZHPDiag.txt ~ Report: C:\Users\tarek\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Deactivate ~ System startup: Normal (Normal boot) Windows 7 Ultimate, 32-bit Service Pack 1 (Build 7601) =>.Microsoft Corporation ---\\ Internet Browsers (3) - 0s ~ GCIE: Google Chrome v57.0.2987.133 ~ MFIE: Mozilla Firefox 48.0.2 (x86 ar) ~ MSIE: Internet Explorer v10.0.9200.16686 ---\\ Windows Product Information (5) - 0s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Key Management Service client information : KO Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ System protection software (2) - 4s Malwarebytes version 3.0.6.1469 v3.0.6.1469 (Protection) McAfee VirusScan Enterprise v8.7.0 (Protection) ---\\ System protection software (Superfluous) (1) - 5s ~ ESET Online Scanner v3 (Superfluous) ---\\ System optimization software (2) - 6s ~ CCleaner v5.09 (Optimize) ~ Tweaking.com - Windows Repair v3.4.3 (Optimize) ---\\ Surveillance software (2) - 6s ~ Adobe Flash Player 25 NPAPI (Surveillance) ~ Adobe Reader X - Arabic (Surveillance) ---\\ Sharing software PeerToPeer (1) - 6s ~ µTorrent v3.4.9.43295 (P2P) ---\\ Information on the system (6) - 0s ~ Operating System: x86 Family 6 Model 15 Stepping 13, GenuineIntel ~ Operating System: 32-bit ~ Boot mode: Normal (Normal boot) Total RAM: 2086.072 MB (37% free) : OK =>.RAM Value System Restore: Activé (Enable) System drive C: has 15 GB (19%) free of 76 GB : ATTENTION =>Warning Disk Space ---\\ Connection to the system mode (3) - 0s ~ Computer Name: TAREK-PC ~ User Name: tarek ~ Logged in as Administrator ---\\ Enumeration of the disk units (3) - 0s ~ Drive C: has 15 GB free of 76 GB (System) ~ Drive D: has 6 GB free of 76 GB ~ Drive G: has 7 GB free of 7 GB ---\\ State of the Windows Security Center (13) - 0s [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK [HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] WarnOnHTTPSToHTTPRedirect: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK ---\\ Search Generic System Files (25) - 4s [MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - 03/04/2014 - (.Microsoft Corporation - مستكشف Windows.) -- C:\Windows\Explorer.exe [2616320] =>.Microsoft Corporation [MD5.51138BEEA3E2C21EC44D0932C71762A8] - 03/04/2014 - (.Microsoft Corporation - عملية مضيف Windows (Rundll32)‎.) -- C:\Windows\System32\rundll32.exe [44544] =>.Microsoft Corporation [MD5.B5C5DCAD3899512020D135600129D665] - 03/04/2014 - (.Microsoft Corporation - ‎‎تطبيق بدء تشغيل Windows.) -- C:\Windows\System32\Wininit.exe [96256] =>.Microsoft Corporation [MD5.535F6263035F2530A62D5D64EF6E73D3] - 03/04/2014 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\Windows\System32\wininet.dll [1767936] =>.Microsoft Corporation [MD5.6D13E1406F50C66E2A95D97F22C47560] - 03/04/2014 - (.Microsoft Corporation - تطبيق تسجيل دخول Windows.) -- C:\Windows\System32\Winlogon.exe [286720] =>.Microsoft Corporation [MD5.E3AE23569749DE12D45BA3B489A036AE] - 03/04/2014 - (.Microsoft Corporation - مكتبة تراخيص البرامج.) -- C:\Windows\System32\sppcomapi.dll [193536] =>.Microsoft Corporation [MD5.B40420876B9288E0A1C8CCA8A84E5DC9] - 03/04/2014 - (.Microsoft Corporation - مكتبة الارتباط الديناميكي لواجهة برمجة تطبي.) -- C:\Windows\System32\dnsapi.dll [270336] =>.Microsoft Corporation [MD5.129F80D7868E30DF3E3DE33A1D3132B4] - 03/04/2014 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [20480] =>.Microsoft Corporation [MD5.9EBBBA55060F786F0FCAA3893BFA2806] - 03/04/2014 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [338944] =>.Microsoft Corporation [MD5.338C86357871C167A96AB976519BF59E] - 03/04/2014 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [21584] =>.Microsoft Windows® [MD5.77EA11B065E0A8AB902D78145CA51E10] - 03/04/2014 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [70656] =>.Microsoft Corporation [MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - 03/04/2014 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [108544] =>.Microsoft Corporation [MD5.F024449C97EC1E464AAFFDA18593DB88] - 03/04/2014 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [78336] =>.Microsoft Corporation [MD5.9036377B8A6C15DC2EEC53E489D159B5] - 03/04/2014 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [108544] =>.Microsoft Corporation [MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - 03/04/2014 - (.Microsoft Corporation - برنامج تشغيل منفذ i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [80896] =>.Microsoft Corporation [MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - 03/04/2014 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [101888] =>.Microsoft Corporation [MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - 03/04/2014 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [123904] =>.Microsoft Corporation [MD5.280122DDCF04B378EDD1AD54D71C1E54] - 03/04/2014 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [187904] =>.Microsoft Corporation [MD5.5E43D2B0EE64123D4880DFA6626DEFDE] - 03/04/2014 - (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\drivers\ntfs.sys [1211752] =>.Microsoft Windows® [MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - 03/04/2014 - (.Microsoft Corporation - برنامج تشغيل المنفذ المتوازي.) -- C:\Windows\System32\drivers\Parport.sys [79360] =>.Microsoft Corporation [MD5.D9F91EAFEC2815365CBE6D167E4E332A] - 03/04/2014 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [78848] =>.Microsoft Corporation [MD5.B973FCFC50DC1434E1970A146F7E3885] - 03/04/2014 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [133632] =>.Microsoft Corporation [MD5.3E21C083B8A01CB70BA1F09303010FCE] - 03/04/2014 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [71168] =>.Microsoft Corporation [MD5.B459575348C20E8121D6039DA063C704] - 03/04/2014 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [74752] =>.Microsoft Corporation [MD5.F497F67932C6FA693D7DE2780631CFE7] - 03/04/2014 - (.Microsoft Corporation - برنامج تشغيل خدمة ملفات الظل الاحتياطية لوح.) -- C:\Windows\System32\drivers\volsnap.sys [245632] =>.Microsoft Windows® ---\\ Non Microsoft non disabled Windows Services (29) - 6s O23 - Service: (ADSafeSvc) . (...) - C:\Program Files\ADSafe\ADSafeSvc.exe (.not file.) O23 - Service: Bonjour Service (Bonjour Service) . (...) - C:\Program Files\Bonjour\mDNSResponder.exe (.not file.) O23 - Service: Bluetooth Service (btwdins) . (.Broadcom Corporation. - Bluetooth Support Server.) - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe =>.Broadcom Corporation® O23 - Service: CyberGhost 6 Service (CG6Service) . (.CyberGhost S.R.L - CyberGhost Service.) - C:\Program Files\CyberGhost\CyberGhost.Service.exe =>.CyberGhost SRL® O23 - Service: ‏خدمة سطح المكتب البعيد من Chrome (chromoting) . (.Google Inc‎.‎ - عملية المضيف.) - C:\Program Files\Google\Chrome Remote Desktop\57.0.2987.37\remoting_host.exe =>.Google Inc® O23 - Service: EaseUS Agent Service (EaseUS Agent) . (.CHENGDU YIWO Tech Development Co., Ltd - EaseUS Todo Backup Agent Application.) - C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe =>.CHENGDU YIWO Tech Development Co., Ltd O23 - Service: Guard Agent Service (Guard Agent) . (.CHENGDU YIWO Tech Development Co., Ltd - EaseUS Todo Backup Agent Application.) - C:\Program Files\EaseUS\Todo Backup\bin\GuardAgent.exe =>.CHENGDU YIWO Tech Development Co., Ltd O23 - Service: خدمة Google Update (gupdate) (gupdate) . (.Google Inc. - مثبِّت Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc® O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) . (.LogMeIn Inc. - Hamachi Client Tunneling Engine.) - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe =>.LogMeIn, Inc.® O23 - Service: KMService (KMService) . (...) - C:\Windows\System32\srvany.exe =>PUP.Optional.Office O23 - Service: LMIGuardianSvc (LMIGuardianSvc) . (.LogMeIn, Inc. - LMIGuardianSvc.) - C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe =>.LogMeIn, Inc.® O23 - Service: Malwarebytes Service (MBAMService) . (.Malwarebytes - Malwarebytes Service.) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation® O23 - Service: McAfee Engine Service (McAfeeEngineService) . (.McAfee, Inc. - Common Shell3 - Scanners' interface to the.) - C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe =>.McAfee, Inc.® O23 - Service: McAfee Framework Service (McAfeeFramework) . (.McAfee, Inc. - Framework Service.) - C:\Program Files\McAfee\Common Framework\FrameworkService.exe =>.McAfee, Inc.® O23 - Service: McAfee McShield (McShield) . (.McAfee, Inc. - On-Access Scanner service.) - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe =>.McAfee, Inc.® O23 - Service: McAfee Task Manager (McTaskManager) . (.McAfee, Inc. - Task Manager.) - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe =>.McAfee, Inc.® O23 - Service: McAfee Validation Trust Protection Service (mfevtp) . (.McAfee, Inc. - McAfee Process Validation Service.) - C:\Windows\System32\mfevtps.exe =>.McAfee, Inc.® O23 - Service: Mysql (Mysql) . (...) - C:\ProgramData\{C57FE420-6939-4E16-A1BD-CAA50C9F1884}\mysqldata\my.ini" Mysql (.not file.) O23 - Service: (Net Driver HPZ12) . (.Hewlett-Packard - Dot4Net Module.) - C:\Windows\System32\HPZinw12.dll =>.Hewlett-Packard O23 - Service: Norton Ghost (Norton Ghost) . (...) - C:\Program Files\Norton Ghost\Agent\VProSvc.exe (.not file.) O23 - Service: Phenixbackup (Phenixbackup) . (...) - C:\Program Files\Sitech\Phenix\Phenixhotbackup.exe O23 - Service: (Pml Driver HPZ12) . (.Hewlett-Packard - PmlDrv Module.) - C:\Windows\System32\HPZipm12.dll =>.Hewlett-Packard O23 - Service: Realtek Audio Service (RtkAudioService) . (.Realtek Semiconductor - Realtek Audio Service.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe =>.Realtek Semiconductor Corp® O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe =>.Skype Software Sarl® O23 - Service: SAMSUNG Mobile Connectivity Service (ss_conn_service) . (.DEVGURU Co., LTD. - MSS CS Connectivity Service.) - C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe =>.Samsung Electronics CO., LTD.® O23 - Service: TeamViewer 11 (TeamViewer) . (.TeamViewer GmbH - TeamViewer 11.) - C:\Program Files\TeamViewer\TeamViewer_Service.exe =>.TeamViewer® O23 - Service: WD SmartWare Drive Manager (WDDMService) . (.WDC - WD Drive Manager Service.) - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe =>.WDC O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) . (.Memeo - WDSmartWareBackgroundService.) - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe =>.Memeo O23 - Service: Wondershare Application Framework Service (WsAppService) . (.Wondershare - Wondershare AppService.) - C:\Program Files\Wondershare\WAF\2.3.1.1\WsAppService.exe =>.Wondershare software CO., LIMITED® ---\\ Services not Microsoft (SR=Run, SS=Stop) (29) - 134s SS - Demand [03/04/2014] [ 315008] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated® SR - Auto [03/04/2014] [ 315008] Bluetooth Service (btwdins) . (.Broadcom Corporation..) - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe =>.Broadcom Corporation® SR - Auto [03/04/2014] [ 315008] CyberGhost 6 Service (CG6Service) . (.CyberGhost S.R.L.) - C:\Program Files\CyberGhost\CyberGhost.Service.exe =>.CyberGhost SRL® SR - Auto [03/04/2014] [ 315008] ‏خدمة سطح المكتب البعيد من Chrome (chromoting) . (.Google Inc‎.‎.) - C:\Program Files\Google\Chrome Remote Desktop\57.0.2987.37\remoting_host.exe =>.Google Inc® SR - Auto [03/04/2014] [ 315008] EaseUS Agent Service (EaseUS Agent) . (.CHENGDU YIWO Tech Development Co., Ltd.) - C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe =>.CHENGDU YIWO Tech Development Co., Ltd SR - Auto [03/04/2014] [ 315008] Guard Agent Service (Guard Agent) . (.CHENGDU YIWO Tech Development Co., Ltd.) - C:\Program Files\EaseUS\Todo Backup\bin\GuardAgent.exe =>.CHENGDU YIWO Tech Development Co., Ltd SS - Auto [03/04/2014] [ 315008] خدمة Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc® SS - Demand [03/04/2014] [ 315008] خدمة Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc® SR - Auto [03/04/2014] [ 315008] LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) . (.LogMeIn Inc..) - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe =>.LogMeIn, Inc.® SS - Auto [03/04/2014] [ 315008] KMService (KMService) . (...) - C:\Windows\System32\srvany.exe =>PUP.Optional.Office SR - Auto [03/04/2014] [ 315008] LMIGuardianSvc (LMIGuardianSvc) . (.LogMeIn, Inc..) - C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe =>.LogMeIn, Inc.® SR - Auto [03/04/2014] [ 315008] Malwarebytes Service (MBAMService) . (.Malwarebytes.) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation® SR - Auto [03/04/2014] [ 315008] McAfee Engine Service (McAfeeEngineService) . (.McAfee, Inc..) - C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe =>.McAfee, Inc.® SR - Auto [03/04/2014] [ 315008] McAfee Framework Service (McAfeeFramework) . (.McAfee, Inc..) - C:\Program Files\McAfee\Common Framework\FrameworkService.exe =>.McAfee, Inc.® SR - Auto [03/04/2014] [ 315008] McAfee McShield (McShield) . (.McAfee, Inc..) - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe =>.McAfee, Inc.® SR - Auto [03/04/2014] [ 315008] McAfee Task Manager (McTaskManager) . (.McAfee, Inc..) - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe =>.McAfee, Inc.® SR - Auto [03/04/2014] [ 315008] McAfee Validation Trust Protection Service (mfevtp) . (.McAfee, Inc..) - C:\Windows\System32\mfevtps.exe =>.McAfee, Inc.® SS - Demand [03/04/2014] [ 315008] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation® SR - Auto [03/04/2014] [ 315008] (Net Driver HPZ12) . (.Hewlett-Packard.) - C:\Windows\System32\HPZinw12.dll =>.Hewlett-Packard SS - Demand [03/04/2014] [ 315008] OpenVPN Service (OpenVPNService) . (.The OpenVPN Project.) - C:\Program Files\OpenVPN\bin\openvpnserv.exe {03E49B29AE75DF4C50DC1662670776B9} =>.The OpenVPN Project SR - Auto [03/04/2014] [ 315008] Phenixbackup (Phenixbackup) . (...) - C:\Program Files\Sitech\Phenix\Phenixhotbackup.exe SR - Auto [03/04/2014] [ 315008] (Pml Driver HPZ12) . (.Hewlett-Packard.) - C:\Windows\System32\HPZipm12.dll =>.Hewlett-Packard SR - Auto [03/04/2014] [ 315008] Realtek Audio Service (RtkAudioService) . (.Realtek Semiconductor.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe =>.Realtek Semiconductor Corp® SS - Auto [03/04/2014] [ 315008] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe =>.Skype Software Sarl® SR - Auto [03/04/2014] [ 315008] SAMSUNG Mobile Connectivity Service (ss_conn_service) . (.DEVGURU Co., LTD..) - C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe =>.Samsung Electronics CO., LTD.® SR - Auto [03/04/2014] [ 315008] TeamViewer 11 (TeamViewer) . (.TeamViewer GmbH.) - C:\Program Files\TeamViewer\TeamViewer_Service.exe =>.TeamViewer® SR - Auto [03/04/2014] [ 315008] WD SmartWare Drive Manager (WDDMService) . (.WDC.) - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe =>.WDC SR - Auto [03/04/2014] [ 315008] WD SmartWare Background Service (WDSmartWareBackgroundService) . (.Memeo.) - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe =>.Memeo SR - Auto [03/04/2014] [ 315008] Wondershare Application Framework Service (WsAppService) . (.Wondershare.) - C:\Program Files\Wondershare\WAF\2.3.1.1\WsAppService.exe =>.Wondershare software CO., LIMITED® ---\\ Task Planned Automatically (29) - 38s [MD5.BE62B286791F715E430FB022C1707BBA] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [271448] (.Activate.) =>.Adobe Systems Incorporated® [MD5.7245B4C192D20107B4A3E887AED3F76E] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6490904] (.Activate.) =>.Piriform Ltd® [MD5.88FBBB1C601A6BC42054E57C2897FA45] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [144200] (.Activate.) =>.Google Inc® [MD5.88FBBB1C601A6BC42054E57C2897FA45] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [144200] (.Activate.) =>.Google Inc® [MD5.8007AF9F2434F390AA51F0A516B9756F] [APT] [Tweaking.com - Windows Repair Tray Icon] (.Tweaking.com.) -- C:\Program Files\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [66816] (.Activate.) =>.Tweaking LLC® [MD5.00000000000000000000000000000000] [APT] [{38C024F1-DEED-4D80-AC6D-8DA613D9E741}] (...) -- C:\Users\tarek\Downloads\EZInstall.exe (.not file.) [0] (.Activate.) =>.Superfluous.Empty [MD5.00000000000000000000000000000000] [APT] [{50B33E55-E718-89FE-CE45-0EC8A83E322B}] (...) -- C:\ProgramData\{3A30719E-8D9B-C635-E283-E4A6AB84CFF7}\9A7D092A-2DD6-BE81-BB36-B26349FFA6D1.exe (.not file.) [0] (.Activate.) =>.Superfluous.Empty [MD5.00000000000000000000000000000000] [APT] [{5CCF58D2-4D0D-4430-A0A6-E604FAF2ED3D}] (...) -- G:\untitled.exe (.not file.) [0] (.Activate.) =>.Superfluous.Empty [MD5.7B791BA8F9D5E38EF0F2D1ED10D08AE9] [APT] [{8D478519-C8CE-46B0-8AC5-DC97B4CC091D}] (.Hewlett-Packard Company.) -- C:\Users\tarek\Downloads\Programs\sp74791.exe [317987416] (.Activate.) {02092131EB4406BF27CE742B679019BB} =>.Hewlett-Packard Company [MD5.00000000000000000000000000000000] [APT] [{9165DE4F-7EB7-4D20-B88A-8C324B544A9A}] (...) -- K:\ںéمں \ ï« 10 ي12\ ï« 10  ں¢¬ gaming èں« ںéمںéê\Install.exe (.not file.) [0] (.Activate.) =>.Superfluous.Empty [MD5.00000000000000000000000000000000] [APT] [{A478807B-2376-4136-8467-48D1C61D708A}] (...) -- H:\d\ں¦©î\ںéهéں¬، 1\ںé¥ىںھ ï §ڑ  «ê ںééى\startup-shutdown-sound.exe (.not file.) [0] (.Activate.) =>.Superfluous.Empty [MD5.00000000000000000000000000000000] [APT] [{C203164A-3198-4B0E-A366-97D4275D3C16}] (...) -- C:\Users\tarek\AppData\Local\Temp\jre-8u73-windows-au.exe (.not file.) [0] (.Activate.) =>.Superfluous.Empty [MD5.00000000000000000000000000000000] [APT] [{E4EDA4C8-DD20-4EDC-BFAA-24680AC4149C}] (...) -- H:\ں«ليںëں¢\ںéيïë§يھ\ ©ëںê¤ ي뫦 çي«¢\Norton Ghost 15.0.0.35659 +Recovery Disk(SRD) ISO+KEYS\Norton Ghost 15.0.0.35659 +Recovery Disk(SRD) ISO+KEYS\Norton Ghost setup\NGH150_AllWin_EnglishTryBuy30.exe (.not file.) [0] (.Activate.) =>.Superfluous.Empty [MD5.C08A5FCEFA5EE421E6146A8F674D1A2A] [APT] [Lenovo\Lenovo Customer Feedback Program 35] (.Lenovo.) -- C:\Program Files\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [16832] (.Activate.) =>.LENOVO® O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [4312] =>.Adobe Systems Incorporated® O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\Windows\System32\Tasks\CCleanerSkipUAC [2790] =>.Piriform Ltd® O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [3134] =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [3262] =>.Google Inc® O39 - APT: Tweaking.com - Windows Repair Tray Icon - (.Tweaking.com.) -- C:\Windows\System32\Tasks\Tweaking.com - Windows Repair Tray Icon [3630] =>.Tweaking LLC® O39 - APT: {38C024F1-DEED-4D80-AC6D-8DA613D9E741} - (...) -- C:\Windows\System32\Tasks\{38C024F1-DEED-4D80-AC6D-8DA613D9E741} [3126] (.Orphan.) =>.Superfluous.Orphan O39 - APT: {50B33E55-E718-89FE-CE45-0EC8A83E322B} - (...) -- C:\Windows\System32\Tasks\{50B33E55-E718-89FE-CE45-0EC8A83E322B} [3818] (.Orphan.) =>.Superfluous.Orphan O39 - APT: {5CCF58D2-4D0D-4430-A0A6-E604FAF2ED3D} - (...) -- C:\Windows\System32\Tasks\{5CCF58D2-4D0D-4430-A0A6-E604FAF2ED3D} [2896] (.Orphan.) =>.Superfluous.Orphan O39 - APT: {8D478519-C8CE-46B0-8AC5-DC97B4CC091D} - (.Hewlett-Packard Company.) -- C:\Windows\System32\Tasks\{8D478519-C8CE-46B0-8AC5-DC97B4CC091D} [3158] {02092131EB4406BF27CE742B679019BB} =>.Hewlett-Packard Company O39 - APT: {9165DE4F-7EB7-4D20-B88A-8C324B544A9A} - (...) -- C:\Windows\System32\Tasks\{9165DE4F-7EB7-4D20-B88A-8C324B544A9A} [3234] (.Orphan.) =>.Superfluous.Orphan O39 - APT: {A478807B-2376-4136-8467-48D1C61D708A} - (...) -- C:\Windows\System32\Tasks\{A478807B-2376-4136-8467-48D1C61D708A} [3224] (.Orphan.) =>.Superfluous.Orphan O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{B53E77DB-F976-46FA-8BBC-1C35916308ED} [3170] O39 - APT: {C203164A-3198-4B0E-A366-97D4275D3C16} - (...) -- C:\Windows\System32\Tasks\{C203164A-3198-4B0E-A366-97D4275D3C16} [3230] (.Orphan.) =>.Superfluous.Orphan O39 - APT: {E4EDA4C8-DD20-4EDC-BFAA-24680AC4149C} - (...) -- C:\Windows\System32\Tasks\{E4EDA4C8-DD20-4EDC-BFAA-24680AC4149C} [3742] (.Orphan.) =>.Superfluous.Orphan O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{F45B7025-8ADB-CF83-F49E-5CB33FA4D513} [3728] ---\\ Auto loading programs from Registry and folders (13) - 3s O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - إدارة صوت Realtek HD.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe =>.Realtek Semiconductor Corp® O4 - HKLM\..\Run: [PWRISOVM.EXE] . (.Power Software Ltd - PowerISO Virtual Drive Manager.) -- C:\Program Files\PowerISO\PWRISOVM.EXE =>.Power Software Ltd® O4 - HKLM\..\Run: [UnlockerAssistant] . (...) -- C:\Program Files\Unlocker\UnlockerAssistant.exe =>.Cedrick Collomb O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] . (.LogMeIn Inc. - Hamachi Client Application.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe =>.LogMeIn, Inc.® O4 - HKLM\..\Run: [McAfeeUpdaterUI] . (.McAfee, Inc. - Common User Interface.) -- C:\Program Files\McAfee\Common Framework\UdaterUI.exe =>.McAfee, Inc.® O4 - HKLM\..\Run: [ShStatEXE] . (.McAfee, Inc. - VirusScan tray icon.) -- C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe =>.McAfee, Inc.® O4 - HKLM\..\Run: [Malwarebytes TrayApp] . (.Malwarebytes - Malwarebytes Tray Application.) -- C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe =>.Malwarebytes Corporation® O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd® O4 - HKCU\..\Run: [SuperCopier2.exe] . (.SFX TEAM - SuperCopier 2 (explorer file copy replaceme.) -- C:\Program Files\SuperCopier2\SuperCopier2.exe =>.SFX TEAM O4 - HKCU\..\Run: [AirDroid 3] . (.Sand Studio - AirDroid 3.) -- C:\Program Files\AirDroid\AirDroid.exe =>.TONGBU TECHNOLOGY (HK) LIMITED® O4 - HKUS\S-1-5-21-1306966254-1056958433-191034392-1000\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd® O4 - HKUS\S-1-5-21-1306966254-1056958433-191034392-1000\..\Run: [SuperCopier2.exe] . (.SFX TEAM - SuperCopier 2 (explorer file copy replaceme.) -- C:\Program Files\SuperCopier2\SuperCopier2.exe =>.SFX TEAM O4 - HKUS\S-1-5-21-1306966254-1056958433-191034392-1000\..\Run: [AirDroid 3] . (.Sand Studio - AirDroid 3.) -- C:\Program Files\AirDroid\AirDroid.exe =>.TONGBU TECHNOLOGY (HK) LIMITED® ---\\ Process running (45) - 6s [MD5.66C6D6A9F283DE5786E7BF8DEEC0E519] - (.Realtek Semiconductor - Realtek Audio Service.) -- C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe [268032] [PID.1344] =>.Realtek Semiconductor Corp® [MD5.1D30F6AFD0C6AA2A3A1346378D5E8A89] - (.Realtek Semiconductor - HD Audio Background Process.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe [1028352] [PID.1396] =>.Realtek Semiconductor Corp® [MD5.F55C99818FD1EACFC7784958A8592536] - (.Broadcom Corporation. - Bluetooth Support Server.) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [595232] [PID.1852] =>.Broadcom Corporation® [MD5.3687D9511202015A8C6C3DE9145FD5AE] - (.Google Inc‎.‎ - عملية المضيف.) -- C:\Program Files\Google\Chrome Remote Desktop\57.0.2987.37\remoting_host.exe [72024] [PID.1884] =>.Google Inc® [MD5.34820F6A33918BE24B76AD670C167F28] - (.CHENGDU YIWO Tech Development Co., Ltd - EaseUS Todo Backup Agent Application.) -- C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe [36936] [PID.1924] =>.CHENGDU YIWO Tech Development Co., Ltd [MD5.3687D9511202015A8C6C3DE9145FD5AE] - (.Google Inc‎.‎ - عملية المضيف.) -- C:\Program Files\Google\Chrome Remote Desktop\57.0.2987.37\remoting_host.exe [72024] [PID.1944] =>.Google Inc® [MD5.B5B81876470C099E6DB3B63BDFBE58FC] - (.CHENGDU YIWO Tech Development Co., Ltd - EaseUS Todo Backup Agent Application.) -- C:\Program Files\EaseUS\Todo Backup\bin\GuardAgent.exe [23624] [PID.436] =>.CHENGDU YIWO Tech Development Co., Ltd [MD5.93A4E2B886E2815B6B732A2380B0F068] - (.LogMeIn, Inc. - LMIGuardianSvc.) -- C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe [405424] [PID.796] =>.LogMeIn, Inc.® [MD5.C3D7E3DCC470D0A5230A485549F21908] - (.McAfee, Inc. - Common Shell3 - Scanners' interface to the.) -- C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe [19456] [PID.1340] =>.McAfee, Inc.® [MD5.4CD3EE64736B4D156DAC5C1D6EB60C24] - (.McAfee, Inc. - Framework Service.) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe [103744] [PID.1472] =>.McAfee, Inc.® [MD5.9DF3A434657512B31549F8D20AFFAD5F] - (.McAfee, Inc. - Task Manager.) -- C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe [62800] [PID.1624] =>.McAfee, Inc.® [MD5.9916F961341557B3ED2D39CA3C5C8C09] - (.McAfee, Inc. - NAI Product Manager.) -- C:\Program Files\McAfee\Common Framework\naPrdMgr.exe [226624] [PID.2092] =>.McAfee, Inc.® [MD5.B87B41F2C05788F04A3B487902803FD2] - (.McAfee, Inc. - McAfee Process Validation Service.) -- C:\Windows\System32\mfevtps.exe [67904] [PID.2136] =>.McAfee, Inc.® [MD5.5B9B8398717B43039FCC9E52D0992FDD] - (...) -- C:\Program Files\Sitech\Phenix\Mysql\bin\mysqld.exe [10948096] [PID.2172] [MD5.2D49D3B4B29D5A69262A4D793F9B91DB] - (...) -- C:\Program Files\Sitech\Phenix\Phenixhotbackup.exe [2583040] [PID.2340] [MD5.7DB9E612A2742ACEAB080B882E83141C] - (.DEVGURU Co., LTD. - MSS CS Connectivity Service.) -- C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784] [PID.2548] =>.Samsung Electronics CO., LTD.® [MD5.D778B8E00A5ABF6C27DDB74F382ACBE9] - (.TeamViewer GmbH - TeamViewer 11.) -- C:\Program Files\TeamViewer\TeamViewer_Service.exe [7534864] [PID.2648] =>.TeamViewer® [MD5.7D1E301E2EEAF6D3730887DE933413E6] - (.WDC - WD Drive Manager Service.) -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [110592] [PID.2764] =>.WDC [MD5.138AB06ADBBF300AA804D7974A5AEC82] - (.Memeo - WDSmartWareBackgroundService.) -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [20480] [PID.2840] =>.Memeo [MD5.7F78CEC3A96BEF80E1D20439BDE08A53] - (.Wondershare - Wondershare AppService.) -- C:\Program Files\Wondershare\WAF\2.3.1.1\WsAppService.exe [437392] [PID.2928] =>.Wondershare software CO., LIMITED® [MD5.608724BBF7EB2EC5C943B13B82BFB068] - (.LogMeIn Inc. - Hamachi Client Tunneling Engine.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2282504] [PID.3076] =>.LogMeIn, Inc.® [MD5.ADED0E73F165B8353690F8055A51154D] - (.Malwarebytes - Malwarebytes Service.) -- C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [3303888] [PID.3456] =>.Malwarebytes Corporation® [MD5.291ADFCB72658349A929B903BC47F8EA] - (.McAfee, Inc. - On-Access Scanner service.) -- C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe [143088] [PID.3580] =>.McAfee, Inc.® [MD5.576FC5ADADEC22F5EF1BDF01F5982606] - (.McAfee, Inc. - VSCore Announcer.) -- C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe [26672] [PID.3688] =>.McAfee, Inc.® [MD5.2C1AB8D6F92D455C5CDBEF2F88585F49] - (.CyberGhost S.R.L - CyberGhost Service.) -- C:\Program Files\CyberGhost\CyberGhost.Service.exe [71728] [PID.3492] =>.CyberGhost SRL® [MD5.33A8EB087889659F2DA8BFF57E0A1F88] - (.TeamViewer GmbH - TeamViewer 11.) -- C:\Program Files\TeamViewer\TeamViewer.exe [26901168] [PID.4444] =>.TeamViewer® [MD5.DE34A3BAE159220440D68512B2D1B790] - (.TeamViewer GmbH - TeamViewer 11.) -- C:\Program Files\TeamViewer\tv_w32.exe [240912] [PID.4828] =>.TeamViewer® [MD5.E01BFACD61B64B8E946D69382454A2F7] - (.Realtek Semiconductor - إدارة صوت Realtek HD.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [14696704] [PID.4940] =>.Realtek Semiconductor Corp® [MD5.1AE00E12D9A6C9AF6E7388C75478DB24] - (.Power Software Ltd - PowerISO Virtual Drive Manager.) -- C:\Program Files\PowerISO\PWRISOVM.EXE [336992] [PID.5120] =>.Power Software Ltd® [MD5.255E405D801CF01247390F38F92D8042] - (...) -- C:\Program Files\Unlocker\UnlockerAssistant.exe [17408] [PID.5200] [MD5.96D50F109AD1224354919F9521974093] - (.LogMeIn Inc. - Hamachi Client Application.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [5883912] [PID.5236] =>.LogMeIn, Inc.® [MD5.19DFA4463D9FBA9E7046E8264D0656D8] - (.McAfee, Inc. - Common User Interface.) -- C:\Program Files\McAfee\Common Framework\UdaterUI.exe [136512] [PID.5284] =>.McAfee, Inc.® [MD5.825A1841A76429732BC6C03BD5C656AA] - (.McAfee, Inc. - VirusScan tray icon.) -- C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe [124240] [PID.5352] =>.McAfee, Inc.® [MD5.A6A21A7D544675E98C040DA18904CF50] - (.Malwarebytes - Malwarebytes Tray Application.) -- C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe [2780112] [PID.5376] =>.Malwarebytes Corporation® [MD5.7245B4C192D20107B4A3E887AED3F76E] - (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe [6490904] [PID.5436] =>.Piriform Ltd® [MD5.7A2FAB25EDDC6B2C6AA19BA3EB5E0A04] - (.McAfee, Inc. - McAfee Security Agent Taskbar Extension.) -- C:\Program Files\McAfee\Common Framework\McTray.exe [91456] [PID.5444] =>.McAfee, Inc.® [MD5.F6987FF6C6D683F79FDCE707B071A997] - (.SFX TEAM - SuperCopier 2 (explorer file copy replaceme.) -- C:\Program Files\SuperCopier2\SuperCopier2.exe [955392] [PID.5488] =>.SFX TEAM [MD5.17D094ACBFCEF7CDDA31A3801C36D855] - (.Sand Studio - AirDroid 3.) -- C:\Program Files\AirDroid\AirDroid.exe [8652408] [PID.5512] =>.TONGBU TECHNOLOGY (HK) LIMITED® [MD5.8007AF9F2434F390AA51F0A516B9756F] - (.Tweaking.com - Tweaking.com - Windows Repair Tray Icon.) -- C:\Program Files\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [66816] [PID.2660] =>.Tweaking LLC® [MD5.64F911CA43AF4099B679CD85759EAC04] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [941912] [PID.5016] =>.Google Inc® [MD5.64F911CA43AF4099B679CD85759EAC04] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [941912] [PID.5412] =>.Google Inc® [MD5.64F911CA43AF4099B679CD85759EAC04] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [941912] [PID.1304] =>.Google Inc® [MD5.64F911CA43AF4099B679CD85759EAC04] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [941912] [PID.5848] =>.Google Inc® [MD5.64F911CA43AF4099B679CD85759EAC04] - (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe [941912] [PID.3912] =>.Google Inc® [MD5.F4BC619667C6DA7BA4883278A4240BBB] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\tarek\AppData\Roaming\ZHP\ZHPDiag3.exe [2720768] [PID.2124] =>.Nicolas Coolman ---\\ Google Chrome, Start,Search,Extensions (2) - 0s G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.arabyonline.com/ =>PUP.Optional.Vonteera G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] ---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (3) - 7s M0 - MFSP: prefs.js [tarek - ajiyv7np.default-1450206470513] http://www.google.com.sa/ =>.Google Inc. P2 - EXT FILE: (.Adblock Plus - Ads were yesterday!.) -- C:\Users\tarek\AppData\Roaming\Mozilla\Firefox\Profiles\ajiyv7np.default-1450206470513\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi =>.Adblock Plus P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\NPSWF32_25_0_0_148.dll =>.Adobe Systems Incorporated ---\\ Internet Explorer Extensions, Start, Search (10) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank =>.Microsoft Corporation R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphan =>.Microsoft Internet Explorer R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 2 ---\\ Internet Explorer, Proxy Management (7) - 0s R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll R5 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft ---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: VMApplet=C:\Windows\system32\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation ---\\ Hosts file redirection (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (1) ---\\ Browser Helper Object (BHO) (5) - 0s O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files\Internet Download Manager\IDMIECC.dll =>.Tonec Inc.® O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} . (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll =>.Microsoft Corporation® O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll =>.Oracle America, Inc.® O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} . (.McAfee, Inc. - VSCore Script Scanner.) -- C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll =>.McAfee, Inc.® O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll =>.Oracle America, Inc.® ---\\ Global shortcuts Startup (193) - 28s O4 - GS\Desktop [Administrator]: Al Aqaree Online Support.lnk . (...) C:\Users\tarek\AppData\Roaming\Microsoft\Installer\{33036E23-E7CE-4860-AFA3-1B0D92C98989}\Icon33036E236.exe O4 - GS\Desktop [Administrator]: Al Aqaree.lnk . (...) C:\Program Files\Al Aqaree\AlAqareeRun.exe O4 - GS\Desktop [Administrator]: Microsoft Office Access 2003.lnk . (...) C:\Windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\accicons.exe O4 - GS\Desktop [Administrator]: Microsoft Office Excel 2003.lnk . (...) C:\Windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\xlicons.exe =>.Microsoft Corporation O4 - GS\Desktop [Administrator]: Microsoft Office Excel 2007.lnk . (...) C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe =>.Microsoft Corporation® O4 - GS\Desktop [Administrator]: Microsoft Office Word 2007.lnk . (...) C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe =>.Microsoft Corporation® O4 - GS\Desktop [Administrator]: scanner.lnk . (...) D:\trk\scanner O4 - GS\Desktop [Administrator]: Snipping Tool.lnk . (.Microsoft Corporation - ‎‎أداة القطع.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation O4 - GS\Desktop [Administrator]: watsap.lnk . (...) D:\trk\watsap O4 - GS\Desktop [Administrator]: wiaacmgr - رمز اختصار.lnk . (.Microsoft Corporation - ‎‎معالج الحصول على الصور لـ Windows.) C:\Windows\System32\wiaacmgr.exe =>.Microsoft Corporation O4 - GS\Desktop [Administrator]: Your Unin-staller!.lnk . (.URSoft,Inc - Your Uninstaller! - New way to uninstall pr.) C:\Program Files\Your Uninstaller 2010\urmain.exe =>.URSoft, Inc.® O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\tarek\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Desktop [Administrator]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\tarek\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc® O4 - GS\Desktop [Administrator]: اعداد ميزانية مدينة الكمبيوتر 2015.lnk . (...) D:\trk\ملفات وورد واكسل\اعداد ميزانية مدينة الكمبيوتر 2015 O4 - GS\Desktop [Administrator]: التحصيل - رمز اختصار.lnk . (...) D:\trk\ملفات وورد واكسل\التحصيل O4 - GS\Desktop [Administrator]: الرواتب - رمز اختصار.lnk . (...) D:\trk\ملفات وورد واكسل\الرواتب O4 - GS\Desktop [Administrator]: العقود الجديدة.lnk . (...) D:\trk\العقود الجديدة O4 - GS\Desktop [Administrator]: المصادقات.lnk . (...) D:\trk\ملفات وورد واكسل\المصادقات O4 - GS\Desktop [Administrator]: كشوف حسابات البنك.lnk . (...) D:\trk\ملفات وورد واكسل\كشوف حسابات البنك O4 - GS\Desktop [Administrator]: مطالبات حديثة.lnk . (...) D:\trk\ملفات وورد واكسل\مطالبات حديثة O4 - GS\Desktop [Administrator]: ملفات سكانر.lnk . (...) D:\trk\ملفات وورد واكسل\ملفات سكانر O4 - GS\Desktop [Administrator]: ملفات وورد واكسل.lnk . (...) D:\trk\ملفات وورد واكسل O4 - GS\Desktop [Administrator]: ميزانية العروبة.lnk . (...) D:\trk\ملفات وورد واكسل\ميزانية العروبة O4 - GS\Quicklaunch [Administrator]: AirDroid.lnk . (.Sand Studio - AirDroid 3 Launcher.) C:\Program Files\AirDroid\Launcher.exe =>.TONGBU TECHNOLOGY (HK) LIMITED® O4 - GS\Quicklaunch [Administrator]: Apowersoft Phone Manager.lnk . (.Apowersoft - Apowersoft Phone Manager.) C:\Program Files\Apowersoft\Apowersoft Phone Manager\Apowersoft Phone Manager.exe =>.APOWERSOFT LIMITED® O4 - GS\Quicklaunch [Administrator]: Folder Lock 6.lnk . (.NewSoftwares.net, Inc. - Folder Lock.) C:\Program Files\Folder Lock 6\Folder Lock 6.exe =>.NewSoftwares.net Inc. SDN. BHD.® O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Administrator]: Microsoft Office Outlook.lnk . (.Microsoft Corporation - Microsoft Office Outlook.) C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE /recycle =>.Microsoft Corporation® O4 - GS\Quicklaunch [Administrator]: Samsung Kies (Lite).lnk . (...) C:\Program Files\Samsung\Kies\KiesAgent.exe /lite =>.Samsung Electronics CO., LTD.® O4 - GS\Quicklaunch [Administrator]: Samsung Kies 3.lnk . (.Samsung - Kies.) C:\Program Files\Samsung\Kies3\Kies3.exe =>.Samsung Electronics CO., LTD.® O4 - GS\Quicklaunch [Administrator]: Samsung Kies.lnk . (...) C:\Program Files\Samsung\Kies\KiesAgent.exe =>.Samsung Electronics CO., LTD.® O4 - GS\Quicklaunch [Administrator]: Xilisoft HD Video Converter.lnk . (...) C:\Program Files\Xilisoft\HD Video Converter\vcloader.exe O4 - GS\Quicklaunch [Administrator]: Yahoo! Messenger.lnk . (.Yahoo! Inc. - Yahoo! Messenger.) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe =>.Yahoo! Inc.® O4 - GS\Quicklaunch [Administrator]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\tarek\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc® O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\sendTo [Administrator]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl® O4 - GS\sendTo [Administrator]: TeamViewer.lnk . (.TeamViewer GmbH - TeamViewer 11.) C:\Program Files\TeamViewer\TeamViewer.exe --sendto =>.TeamViewer® O4 - GS\TaskBar [Administrator]: Alaqaree.lnk . (...) C:\Program Files\Al Aqaree\Alaqaree.exe O4 - GS\TaskBar [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [Administrator]: Microsoft Office Excel 2007.lnk . (...) C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe =>.Microsoft Corporation® O4 - GS\TaskBar [Administrator]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\mozilla firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\TaskBar [Administrator]: Windows Explorer.lnk . (.Microsoft Corporation - مستكشف Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation O4 - GS\Programs [Administrator]: FreeAccountantSoftware.lnk . (...) C:\Users\tarek\AppData\Roaming\Microsoft\Installer\{48FD7BF2-4F93-4FEE-9DC1-76AB51E8A455}\_64996F6E6BF7299700CA41.exe O4 - GS\Programs [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Programs [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\Programs [Administrator]: منتديات توب لاب توب.lnk . (...) C:\Windows\System32\منتديات توب لاب توب.url O4 - GS\Desktop [Guest]: Al Aqaree Online Support.lnk . (...) C:\Users\tarek\AppData\Roaming\Microsoft\Installer\{33036E23-E7CE-4860-AFA3-1B0D92C98989}\Icon33036E236.exe O4 - GS\Desktop [Guest]: Al Aqaree.lnk . (...) C:\Program Files\Al Aqaree\AlAqareeRun.exe O4 - GS\Desktop [Guest]: Microsoft Office Access 2003.lnk . (...) C:\Windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\accicons.exe O4 - GS\Desktop [Guest]: Microsoft Office Excel 2003.lnk . (...) C:\Windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\xlicons.exe =>.Microsoft Corporation O4 - GS\Desktop [Guest]: Microsoft Office Excel 2007.lnk . (...) C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe =>.Microsoft Corporation® O4 - GS\Desktop [Guest]: Microsoft Office Word 2007.lnk . (...) C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe =>.Microsoft Corporation® O4 - GS\Desktop [Guest]: scanner.lnk . (...) D:\trk\scanner O4 - GS\Desktop [Guest]: Snipping Tool.lnk . (.Microsoft Corporation - ‎‎أداة القطع.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation O4 - GS\Desktop [Guest]: watsap.lnk . (...) D:\trk\watsap O4 - GS\Desktop [Guest]: wiaacmgr - رمز اختصار.lnk . (.Microsoft Corporation - ‎‎معالج الحصول على الصور لـ Windows.) C:\Windows\System32\wiaacmgr.exe =>.Microsoft Corporation O4 - GS\Desktop [Guest]: Your Unin-staller!.lnk . (.URSoft,Inc - Your Uninstaller! - New way to uninstall pr.) C:\Program Files\Your Uninstaller 2010\urmain.exe =>.URSoft, Inc.® O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\tarek\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Desktop [Guest]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\tarek\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc® O4 - GS\Desktop [Guest]: اعداد ميزانية مدينة الكمبيوتر 2015.lnk . (...) D:\trk\ملفات وورد واكسل\اعداد ميزانية مدينة الكمبيوتر 2015 O4 - GS\Desktop [Guest]: التحصيل - رمز اختصار.lnk . (...) D:\trk\ملفات وورد واكسل\التحصيل O4 - GS\Desktop [Guest]: الرواتب - رمز اختصار.lnk . (...) D:\trk\ملفات وورد واكسل\الرواتب O4 - GS\Desktop [Guest]: العقود الجديدة.lnk . (...) D:\trk\العقود الجديدة O4 - GS\Desktop [Guest]: المصادقات.lnk . (...) D:\trk\ملفات وورد واكسل\المصادقات O4 - GS\Desktop [Guest]: كشوف حسابات البنك.lnk . (...) D:\trk\ملفات وورد واكسل\كشوف حسابات البنك O4 - GS\Desktop [Guest]: مطالبات حديثة.lnk . (...) D:\trk\ملفات وورد واكسل\مطالبات حديثة O4 - GS\Desktop [Guest]: ملفات سكانر.lnk . (...) D:\trk\ملفات وورد واكسل\ملفات سكانر O4 - GS\Desktop [Guest]: ملفات وورد واكسل.lnk . (...) D:\trk\ملفات وورد واكسل O4 - GS\Desktop [Guest]: ميزانية العروبة.lnk . (...) D:\trk\ملفات وورد واكسل\ميزانية العروبة O4 - GS\Quicklaunch [Guest]: AirDroid.lnk . (.Sand Studio - AirDroid 3 Launcher.) C:\Program Files\AirDroid\Launcher.exe =>.TONGBU TECHNOLOGY (HK) LIMITED® O4 - GS\Quicklaunch [Guest]: Apowersoft Phone Manager.lnk . (.Apowersoft - Apowersoft Phone Manager.) C:\Program Files\Apowersoft\Apowersoft Phone Manager\Apowersoft Phone Manager.exe =>.APOWERSOFT LIMITED® O4 - GS\Quicklaunch [Guest]: Folder Lock 6.lnk . (.NewSoftwares.net, Inc. - Folder Lock.) C:\Program Files\Folder Lock 6\Folder Lock 6.exe =>.NewSoftwares.net Inc. SDN. BHD.® O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Guest]: Microsoft Office Outlook.lnk . (.Microsoft Corporation - Microsoft Office Outlook.) C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE /recycle =>.Microsoft Corporation® O4 - GS\Quicklaunch [Guest]: Samsung Kies (Lite).lnk . (...) C:\Program Files\Samsung\Kies\KiesAgent.exe /lite =>.Samsung Electronics CO., LTD.® O4 - GS\Quicklaunch [Guest]: Samsung Kies 3.lnk . (.Samsung - Kies.) C:\Program Files\Samsung\Kies3\Kies3.exe =>.Samsung Electronics CO., LTD.® O4 - GS\Quicklaunch [Guest]: Samsung Kies.lnk . (...) C:\Program Files\Samsung\Kies\KiesAgent.exe =>.Samsung Electronics CO., LTD.® O4 - GS\Quicklaunch [Guest]: Xilisoft HD Video Converter.lnk . (...) C:\Program Files\Xilisoft\HD Video Converter\vcloader.exe O4 - GS\Quicklaunch [Guest]: Yahoo! Messenger.lnk . (.Yahoo! Inc. - Yahoo! Messenger.) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe =>.Yahoo! Inc.® O4 - GS\Quicklaunch [Guest]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\tarek\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc® O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\sendTo [Guest]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl® O4 - GS\sendTo [Guest]: TeamViewer.lnk . (.TeamViewer GmbH - TeamViewer 11.) C:\Program Files\TeamViewer\TeamViewer.exe --sendto =>.TeamViewer® O4 - GS\TaskBar [Guest]: Alaqaree.lnk . (...) C:\Program Files\Al Aqaree\Alaqaree.exe O4 - GS\TaskBar [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [Guest]: Microsoft Office Excel 2007.lnk . (...) C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe =>.Microsoft Corporation® O4 - GS\TaskBar [Guest]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\mozilla firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\TaskBar [Guest]: Windows Explorer.lnk . (.Microsoft Corporation - مستكشف Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation O4 - GS\Programs [Guest]: FreeAccountantSoftware.lnk . (...) C:\Users\tarek\AppData\Roaming\Microsoft\Installer\{48FD7BF2-4F93-4FEE-9DC1-76AB51E8A455}\_64996F6E6BF7299700CA41.exe O4 - GS\Programs [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Programs [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\Programs [Guest]: منتديات توب لاب توب.lnk . (...) C:\Windows\System32\منتديات توب لاب توب.url O4 - GS\Desktop [tarek]: Al Aqaree Online Support.lnk . (...) C:\Users\tarek\AppData\Roaming\Microsoft\Installer\{33036E23-E7CE-4860-AFA3-1B0D92C98989}\Icon33036E236.exe O4 - GS\Desktop [tarek]: Al Aqaree.lnk . (...) C:\Program Files\Al Aqaree\AlAqareeRun.exe O4 - GS\Desktop [tarek]: Microsoft Office Access 2003.lnk . (...) C:\Windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\accicons.exe O4 - GS\Desktop [tarek]: Microsoft Office Excel 2003.lnk . (...) C:\Windows\Installer\{90110401-6000-11D3-8CFE-0150048383C9}\xlicons.exe =>.Microsoft Corporation O4 - GS\Desktop [tarek]: Microsoft Office Excel 2007.lnk . (...) C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe =>.Microsoft Corporation® O4 - GS\Desktop [tarek]: Microsoft Office Word 2007.lnk . (...) C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe =>.Microsoft Corporation® O4 - GS\Desktop [tarek]: scanner.lnk . (...) D:\trk\scanner O4 - GS\Desktop [tarek]: Snipping Tool.lnk . (.Microsoft Corporation - ‎‎أداة القطع.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation O4 - GS\Desktop [tarek]: watsap.lnk . (...) D:\trk\watsap O4 - GS\Desktop [tarek]: wiaacmgr - رمز اختصار.lnk . (.Microsoft Corporation - ‎‎معالج الحصول على الصور لـ Windows.) C:\Windows\System32\wiaacmgr.exe =>.Microsoft Corporation O4 - GS\Desktop [tarek]: Your Unin-staller!.lnk . (.URSoft,Inc - Your Uninstaller! - New way to uninstall pr.) C:\Program Files\Your Uninstaller 2010\urmain.exe =>.URSoft, Inc.® O4 - GS\Desktop [tarek]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\tarek\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Desktop [tarek]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\tarek\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc® O4 - GS\Desktop [tarek]: اعداد ميزانية مدينة الكمبيوتر 2015.lnk . (...) D:\trk\ملفات وورد واكسل\اعداد ميزانية مدينة الكمبيوتر 2015 O4 - GS\Desktop [tarek]: التحصيل - رمز اختصار.lnk . (...) D:\trk\ملفات وورد واكسل\التحصيل O4 - GS\Desktop [tarek]: الرواتب - رمز اختصار.lnk . (...) D:\trk\ملفات وورد واكسل\الرواتب O4 - GS\Desktop [tarek]: العقود الجديدة.lnk . (...) D:\trk\العقود الجديدة O4 - GS\Desktop [tarek]: المصادقات.lnk . (...) D:\trk\ملفات وورد واكسل\المصادقات O4 - GS\Desktop [tarek]: كشوف حسابات البنك.lnk . (...) D:\trk\ملفات وورد واكسل\كشوف حسابات البنك O4 - GS\Desktop [tarek]: مطالبات حديثة.lnk . (...) D:\trk\ملفات وورد واكسل\مطالبات حديثة O4 - GS\Desktop [tarek]: ملفات سكانر.lnk . (...) D:\trk\ملفات وورد واكسل\ملفات سكانر O4 - GS\Desktop [tarek]: ملفات وورد واكسل.lnk . (...) D:\trk\ملفات وورد واكسل O4 - GS\Desktop [tarek]: ميزانية العروبة.lnk . (...) D:\trk\ملفات وورد واكسل\ميزانية العروبة O4 - GS\Quicklaunch [tarek]: AirDroid.lnk . (.Sand Studio - AirDroid 3 Launcher.) C:\Program Files\AirDroid\Launcher.exe =>.TONGBU TECHNOLOGY (HK) LIMITED® O4 - GS\Quicklaunch [tarek]: Apowersoft Phone Manager.lnk . (.Apowersoft - Apowersoft Phone Manager.) C:\Program Files\Apowersoft\Apowersoft Phone Manager\Apowersoft Phone Manager.exe =>.APOWERSOFT LIMITED® O4 - GS\Quicklaunch [tarek]: Folder Lock 6.lnk . (.NewSoftwares.net, Inc. - Folder Lock.) C:\Program Files\Folder Lock 6\Folder Lock 6.exe =>.NewSoftwares.net Inc. SDN. BHD.® O4 - GS\Quicklaunch [tarek]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [tarek]: Microsoft Office Outlook.lnk . (.Microsoft Corporation - Microsoft Office Outlook.) C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE /recycle =>.Microsoft Corporation® O4 - GS\Quicklaunch [tarek]: Samsung Kies (Lite).lnk . (...) C:\Program Files\Samsung\Kies\KiesAgent.exe /lite =>.Samsung Electronics CO., LTD.® O4 - GS\Quicklaunch [tarek]: Samsung Kies 3.lnk . (.Samsung - Kies.) C:\Program Files\Samsung\Kies3\Kies3.exe =>.Samsung Electronics CO., LTD.® O4 - GS\Quicklaunch [tarek]: Samsung Kies.lnk . (...) C:\Program Files\Samsung\Kies\KiesAgent.exe =>.Samsung Electronics CO., LTD.® O4 - GS\Quicklaunch [tarek]: Xilisoft HD Video Converter.lnk . (...) C:\Program Files\Xilisoft\HD Video Converter\vcloader.exe O4 - GS\Quicklaunch [tarek]: Yahoo! Messenger.lnk . (.Yahoo! Inc. - Yahoo! Messenger.) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe =>.Yahoo! Inc.® O4 - GS\Quicklaunch [tarek]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\tarek\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc® O4 - GS\sendTo [tarek]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\sendTo [tarek]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl® O4 - GS\sendTo [tarek]: TeamViewer.lnk . (.TeamViewer GmbH - TeamViewer 11.) C:\Program Files\TeamViewer\TeamViewer.exe --sendto =>.TeamViewer® O4 - GS\TaskBar [tarek]: Alaqaree.lnk . (...) C:\Program Files\Al Aqaree\Alaqaree.exe O4 - GS\TaskBar [tarek]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [tarek]: Microsoft Office Excel 2007.lnk . (...) C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe =>.Microsoft Corporation® O4 - GS\TaskBar [tarek]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\mozilla firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\TaskBar [tarek]: Windows Explorer.lnk . (.Microsoft Corporation - مستكشف Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation O4 - GS\Programs [tarek]: FreeAccountantSoftware.lnk . (...) C:\Users\tarek\AppData\Roaming\Microsoft\Installer\{48FD7BF2-4F93-4FEE-9DC1-76AB51E8A455}\_64996F6E6BF7299700CA41.exe O4 - GS\Programs [tarek]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Programs [tarek]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\Programs [tarek]: منتديات توب لاب توب.lnk . (...) C:\Windows\System32\منتديات توب لاب توب.url O4 - GS\CommonDesktop [Public]: Apowersoft Phone Manager.lnk . (.Apowersoft - Apowersoft Phone Manager.) C:\Program Files\Apowersoft\Apowersoft Phone Manager\Apowersoft Phone Manager.exe =>.APOWERSOFT LIMITED® O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Ltd - CCleaner.) C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd® O4 - GS\CommonDesktop [Public]: EaseUS Todo Backup Free 6.5.lnk . (.CHENGDU YIWO Tech Development Co., Ltd - EaseUS Todo Backup.) C:\Program Files\EaseUS\Todo Backup\bin\Loader.exe =>.CHENGDU YIWO Tech Development Co., Ltd O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\CommonDesktop [Public]: Kingo ROOT.lnk . (.Kingosoft - Kingo Root.) C:\Program Files\Kingo ROOT\Kingo Root.exe =>.Finger Power Technology Co., Ltd.® O4 - GS\CommonDesktop [Public]: Malwarebytes.lnk . (.Malwarebytes - Malwarebytes.) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe =>.Malwarebytes Corporation® O4 - GS\CommonDesktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\mozilla firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\CommonDesktop [Public]: PowerISO.lnk . (.Power Software Ltd - PowerISO.) C:\Program Files\PowerISO\PowerISO.exe =>.Power Software Ltd® O4 - GS\CommonDesktop [Public]: Samsung Kies (Lite).lnk . (...) C:\Program Files\Samsung\Kies\KiesAgent.exe /lite =>.Samsung Electronics CO., LTD.® O4 - GS\CommonDesktop [Public]: Samsung Kies 3.lnk . (.Samsung - Kies.) C:\Program Files\Samsung\Kies3\Kies3.exe =>.Samsung Electronics CO., LTD.® O4 - GS\CommonDesktop [Public]: TeamViewer 11.lnk . (.TeamViewer GmbH - TeamViewer 11.) C:\Program Files\TeamViewer\TeamViewer.exe =>.TeamViewer® O4 - GS\CommonDesktop [Public]: UmmyVideoDownloader.lnk . (.Magicbit, Inc - Ummy Video Downloader.) C:\Users\tarek\AppData\Local\UmmyVideoDownloader\UmmyVideoDownloader.exe =>.Superfluous.Magicbit O4 - GS\Programs [Public]: FreeAccountantSoftware.lnk . (...) C:\Users\tarek\AppData\Roaming\Microsoft\Installer\{48FD7BF2-4F93-4FEE-9DC1-76AB51E8A455}\_64996F6E6BF7299700CA41.exe O4 - GS\Programs [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Programs [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\Programs [Public]: منتديات توب لاب توب.lnk . (...) C:\Windows\System32\منتديات توب لاب توب.url O4 - GS\Accessories [Public]: Command Prompt.lnk . (.Microsoft Corporation - Windows Command Processor.) C:\Windows\system32\cmd.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - ‎‎المفكرة.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Windows Explorer.lnk . (.Microsoft Corporation - مستكشف Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\SystemTools [Public]: Private Character Editor.lnk . (.Microsoft Corporation - ‎‎محرر الأحرف الخاصة.) C:\Windows\system32\eudcedit.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Bluetooth File Transfer Wizard.lnk . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - ‎‎حاسبة Windows.) C:\Windows\system32\calc.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - ‎‎تبديل شاشة العرض.) C:\Windows\system32\displayswitch.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - ‎‎ملحق لوحة إدخال العمليات الرياضية.) C:\Program Files\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - ‎‎‫مركز إعدادات الكمبيوتر المحمول لـ Window.) C:\Windows\system32\mblctr.exe /open =>.Microsoft Corporation O4 - GS\Accessories [Public]: NetworkProjection.lnk . (.Microsoft Corporation - Connect to a Network Projector.) C:\Windows\system32\NetProj.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - ‎‎الرسام.) C:\Windows\system32\mspaint.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\Windows\system32\mstsc.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - ‎‎أداة القطع.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - ‎‎مسجل صوت Windows.) C:\Windows\system32\SoundRecorder.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - ‎‎Sticky Notes.) C:\Windows\system32\StikyNot.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) C:\Windows\System32\mobsync.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Welcome Center.lnk . (.Microsoft Corporation - عملية مضيف Windows (Rundll32)‎.) C:\Windows\system32\rundll32.exe %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut =>.Microsoft Corporation O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - ‎‎تطبيق المفكرة لـ Windows.) C:\Program Files\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - ‎‎مخطط توزيع الأحرف.) C:\Windows\system32\charmap.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - ‎‎Microsoft® Disk Defragmenter.) C:\Windows\system32\dfrgui.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - ‎‎إدارة تنظيف مساحة القرص لـ Windows.) C:\Windows\system32\cleanmgr.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - ‎‎مراقبة الأداء والموارد.) C:\Windows\system32\perfmon.exe /res =>.Microsoft Corporation O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - ‎‎معلومات النظام.) C:\Windows\system32\msinfo32.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - ‎‎Microsoft® Windows System Restore.) C:\Windows\system32\rstrui.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) C:\Windows\system32\taskschd.msc /s =>..Microsoft Corporation O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - ‎‎تطبيق ما بعد عملية الترحيل لأداة النقل ال.) C:\Windows\system32\migwiz\postmig.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - ‎‎تطبيق أداة النقل السريع في Windows.) C:\Windows\system32\migwiz\migwiz.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Adobe Reader X.lnk . (...) C:\Windows\Installer\{AC76BA86-7AD7-1025-7B44-AA0000000001}\SC_Reader.ico =>.Adobe Inc. O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\ProgramsCommon [Public]: Media Center.lnk . (.Microsoft Corporation - Windows Media Center.) C:\Windows\ehome\ehshell.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\mozilla firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\ProgramsCommon [Public]: Sidebar.lnk . (.Microsoft Corporation - ‎‎الأدوات الذكية على سطح المكتب لـ Windows.) C:\Program Files\Windows Sidebar\sidebar.exe /showgadgets =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: TeamViewer 11.lnk . (.TeamViewer GmbH - TeamViewer 11.) C:\Program Files\TeamViewer\TeamViewer.exe =>.TeamViewer® O4 - GS\ProgramsCommon [Public]: Windows DVD Maker.lnk . (.Microsoft Corporation - ‎‎أداة إنشاء قرص DVD من Windows.) C:\Program Files\DVD Maker\DVDMaker.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - ‎‎Windows Media Player.) C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: XPS Viewer.lnk . (.Microsoft Corporation - ‎‎عارض XPS.) C:\Windows\system32\xpsrchvw.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: المصحف الرقمي.lnk . (...) C:\Program Files\Quranzu1\المصحف الرقمي.exe ---\\ Lop.com/Domain Hijackers (7) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 86.51.35.24 86.51.34.24 O17 - HKLM\System\CCS\Services\Tcpip\..\{100CD25F-3CA0-4D9B-9861-17A207860E21}: NameServer = 8.8.8.8 =>.Google Inc O17 - HKLM\System\CCS\Services\Tcpip\..\{9DFFDA5E-3F31-4E31-B70F-C2A6421F2AF1}: NameServer = 8.8.8.8 =>.Google Inc O17 - HKLM\System\CCS\Services\Tcpip\..\{ADE57923-D2EF-4593-B9C3-8917A44DA814}: NameServer = 8.8.8.8 =>.Google Inc O17 - HKLM\System\CCS\Services\Tcpip\..\{e29ac6c2-7037-11de-816d-806e6f6e6963}: NameServer = 8.8.8.8 =>.Google Inc O17 - HKLM\System\CCS\Services\Tcpip\..\{EB30551D-6976-496A-A9E4-62229741883C}: NameServer = 8.8.8.8 =>.Google Inc O17 - HKLM\System\CCS\Services\Tcpip\..\{ADE57923-D2EF-4593-B9C3-8917A44DA814}: DhcpNameServer = 86.51.35.24 86.51.34.24 ---\\ Extra protocols (25) - 4s O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - عنصر تحكم ActiveX للفيديو المتدفق.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} . (.Microsoft Corporation - GrooveSystemServices Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll =>.Microsoft Corporation® O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll =>.Microsoft Corporation® O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation O18 - Handler: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} . (.Microsoft Corporation - Microsoft Office XP Web Components.) -- C:\Program Files\Common Files\microsoft shared\Web Components\10\OWC10.DLL =>.Microsoft Corporation® O18 - Handler: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} . (.Microsoft Corporation - Microsoft Office Web Components 2003.) -- C:\Program Files\Common Files\microsoft shared\Web Components\11\OWC11.DLL =>.Microsoft Corporation® O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - عنصر تحكم ActiveX للفيديو المتدفق.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL =>.Microsoft Corporation® ---\\ Software installed (75) - 30s O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU] -- uTorrent =>.BitTorrent Inc® O42 - Logiciel: 32 Bit HP CIO Components Installer - (.Hewlett-Packard.) [HKLM] -- {61B4684A-F09D-49D5-ADD8-7EA95D8EC790} =>.Hewlett-Packard O42 - Logiciel: 7-Zip 15.14 - (.Igor Pavlov.) [HKLM] -- 7-Zip =>.Igor Pavlov O42 - Logiciel: Adobe Flash Player 25 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX =>.Adobe Systems Incorporated® O42 - Logiciel: Adobe Flash Player 25 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated® O42 - Logiciel: Adobe Reader X - Arabic - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1025-7B44-AA0000000001} =>.Adobe Systems Incorporated O42 - Logiciel: Adobe Shockwave Player + Authorware Web Player - (.Adobe Systems, Inc..) [HKLM] -- Adobe Shockwave Player + Authorware Web Player =>.Adobe Systems, Inc. O42 - Logiciel: AirDroid 3.3.5.3 - (.Sand Studio.) [HKLM] -- AirDroid =>.Sand Studio O42 - Logiciel: Al Aqaree - (.www.alaqareesoft.com.) [HKLM] -- {33036E23-E7CE-4860-AFA3-1B0D92C98989} O42 - Logiciel: Apowersoft Phone Manager version 2.5.1 - (.APOWERSOFT LIMITED.) [HKLM] -- {4A00E3C4-2D0F-4AE7-9F2A-74870BE09EF8}_is1 =>.APOWERSOFT LIMITED O42 - Logiciel: Betternet for Windows - (.Betternet Technologies Inc..) [HKLM] -- {2E77104D-96E1-4A9C-86F2-C7CF4C703730} O42 - Logiciel: Betternet for Windows - (.Betternet Technologies Inc..) [HKLM] -- {2E77104D-96E1-4A9C-86F2-C7CF4C703740} O42 - Logiciel: BtwMfcMM - (.Broadcom Corporation.) [HKLM] -- {D5B46D30-F054-4C64-9C0F-97C8451E7D04} =>.Broadcom Corporation O42 - Logiciel: Bullzip PDF Printer 10.24.0.2543 - (.Bullzip.) [HKLM] -- Bullzip PDF Printer_is1 =>.Bullzip O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner =>.Piriform Ltd® O42 - Logiciel: Chrome Remote Desktop Host - (.Google Inc..) [HKLM] -- {88D5D9A4-48C4-4D0A-88B9-3E18661CF0D9} =>.Google Inc. O42 - Logiciel: EaseUS Todo Backup Free 6.5 - (.CHENGDU YIWO Tech Development Co., Ltd.) [HKLM] -- EaseUS Todo Backup Free 6.5_is1 =>.CHENGDU YIWO Tech Development Co., Ltd O42 - Logiciel: EasyBCD 2.3 - (.NeoSmart Technologies.) [HKLM] -- EasyBCD =>.NeoSmart Technologies® O42 - Logiciel: ESET Online Scanner v3 - (..) [HKLM] -- ESET Online Scanner =>.ESET, spol. s r.o.® O42 - Logiciel: Folder Lock 6.6.5 - (.Folder Lock.) [HKLM] -- {C04FE77E-2A5D-46EB-AAAC-1C1F0F1A8A1E} O42 - Logiciel: FreeAccountantSoftware - (.Baytalejtiaz.) [HKLM] -- {48FD7BF2-4F93-4FEE-9DC1-76AB51E8A455} O42 - Logiciel: Google Chrome - (.Google Inc‎.‎.) [HKCU] -- Google Chrome =>.Google Inc® O42 - Logiciel: Google Chrome - (.Google Inc‎.‎.) [HKLM] -- Google Chrome =>.Google Inc® O42 - Logiciel: Google Earth - (.Google.) [HKLM] -- {C1940CF0-E2DD-11E0-BB25-B8AC6F97B88E} =>.Google O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc. O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>Heuristic.Suspect O42 - Logiciel: HP Deskjet 2050 J510 series برنامج الجهاز الأساسي - (.Hewlett-Packard Co..) [HKLM] -- {47B8C876-E208-4ED1-AB6D-37C696187E09} =>.Hewlett-Packard Co. O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- HDMI =>.Intel Corporation® O42 - Logiciel: Intel(R) TV Wizard - (.Intel Corporation.) [HKLM] -- TVWiz =>.Intel Corporation O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM] -- Internet Download Manager =>.Tonec Inc.® O42 - Logiciel: Java 8 Update 91 - (.Oracle Corporation.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83218091F0} =>.Oracle Corporation O42 - Logiciel: Java Auto Updater - (.Oracle Corporation.) [HKLM] -- {4A03706F-666A-4037-7777-5F2748764D10} =>.Oracle Corporation O42 - Logiciel: Kingo ROOT version 1.4.4.2620 - (.Kingosoft Technology Ltd..) [HKLM] -- {AE7675D6-0B31-494F-ABFA-822E1A0FDF17}_is1 =>.Kingosoft Technology Ltd. O42 - Logiciel: K-Lite Mega Codec Pack 9.9.5 - (.KLite Inc.) [HKLM] -- KLiteCodecPack_is1 =>.KLite Inc O42 - Logiciel: LogMeIn Hamachi - (.LogMeIn, Inc..) [HKLM] -- {89E5827E-EAE7-47F2-A57F-52D92C671983} =>.LogMeIn, Inc. O42 - Logiciel: LogMeIn Hamachi - (.LogMeIn, Inc..) [HKLM] -- LogMeIn Hamachi =>.LogMeIn, Inc. O42 - Logiciel: Malwarebytes version 3.0.6.1469 - (.Malwarebytes.) [HKLM] -- {35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1 =>.Malwarebytes Corporation® O42 - Logiciel: McAfee Agent - (.McAfee, Inc..) [HKLM] -- {A638557B-1F13-40A0-9627-C892FBCA6960} =>.McAfee, Inc. O42 - Logiciel: McAfee AntiSpyware Enterprise Module - (.McAfee, Inc..) [HKLM] -- McAfee Anti-Spyware Enterprise Module =>.McAfee, Inc.® O42 - Logiciel: McAfee VirusScan Enterprise - (.McAfee, Inc..) [HKLM] -- {147BCE03-C0F1-4C9F-8157-6A89B6D2D973} =>.McAfee, Inc. O42 - Logiciel: Metric Collection SDK 35 - (.Lenovo Group Limited.) [HKLM] -- {C2B5B5B0-2545-4E94-B4BA-548D4BF0B196} =>.Lenovo Group Limited O42 - Logiciel: Mozilla Firefox 48.0.2 (x86 ar) - (.Mozilla.) [HKLM] -- Mozilla Firefox 48.0.2 (x86 ar) =>.Mozilla Corporation® O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService =>.Mozilla O42 - Logiciel: OpenVPN 2.3.12-I602 - (.OpenVPN Technologie.) [HKLM] -- OpenVPN =>.OpenVPN Technologie O42 - Logiciel: PowerISO - (.Power Software Ltd.) [HKLM] -- PowerISO =>.Power Software Ltd O42 - Logiciel: Realtek Card Reader - (.Realtek Semiconduct Corp..) [HKLM] -- {5BC2B5AB-80DE-4E83-B8CF-426902051D0A} =>.Realtek Semiconductor Corp® O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp® O42 - Logiciel: Recover My Files - (.GetData Pty Ltd.) [HKLM] -- Recover My Files_is1 =>.GetData Pty Ltd O42 - Logiciel: SAM CoDeC Pack - (.www.SamLab.ws.) [HKLM] -- SAM CoDeC Pack =>.www.SamLab.ws O42 - Logiciel: Samsung Kies - (.Samsung Electronics Co., Ltd..) [HKLM] -- {758C8301-2696-4855-AF45-534B1200980A} =>.Samsung Electronics Co., Ltd. O42 - Logiciel: Samsung Kies - (.Samsung Electronics Co., Ltd..) [HKLM] -- InstallShield_{758C8301-2696-4855-AF45-534B1200980A} =>.Samsung Electronics Co., Ltd. O42 - Logiciel: Samsung Kies3 - (.Samsung Electronics Co., Ltd..) [HKLM] -- {88547073-C566-4895-9005-EBE98EA3F7C7} =>.Samsung Electronics Co., Ltd. O42 - Logiciel: Samsung Kies3 - (.Samsung Electronics Co., Ltd..) [HKLM] -- InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7} =>.Samsung Electronics Co., Ltd. O42 - Logiciel: Samsung USB Driver for Mobile Phones - (.Samsung Electronics Co., Ltd..) [HKLM] -- {D0795B21-0CDA-4a92-AB9E-6E92D8111E44} =>.Samsung Electronics CO., LTD.® O42 - Logiciel: Skype™ 6.16 - (.Skype Technologies S.A..) [HKLM] -- {7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7} =>.Skype Technologies S.A. O42 - Logiciel: SuperCopier2 - (.SFX Team.) [HKLM] -- SuperCopier2 =>.SFX TEAM O42 - Logiciel: TAP-Windows 9.21.2 - (.OpenVPN Technologie.) [HKLM] -- TAP-Windows =>.OpenVPN Technologie O42 - Logiciel: TeamViewer 11 - (.TeamViewer.) [HKLM] -- TeamViewer =>.TeamViewer® O42 - Logiciel: Tweaking.com - Windows Repair - (.Tweaking.com.) [HKLM] -- Tweaking.com - Windows Repair =>.Tweaking.com O42 - Logiciel: UmmyVideoDownloader - (..) [HKLM] -- {E028DBDA-EEE7-48A0-ADF7-D250589A02C5}_is1 O42 - Logiciel: Unlocker 1.9.2 - (.Cedrick Collomb.) [HKLM] -- Unlocker =>.Cedrick Collomb O42 - Logiciel: WD SmartWare - (.Western Digital.) [HKLM] -- {232DB76D-4751-41A9-9EC2-CDC0DAC1FAB6} =>.Western Digital O42 - Logiciel: WIDCOMM Bluetooth Software - (.Broadcom Corporation.) [HKLM] -- {9E9D49A4-1DF4-4138-B7DB-5D87A893088E} =>.Broadcom Corporation O42 - Logiciel: Windows Driver Package - Broadcom Bluetooth (06/15/2009 6.2.0.9000) - (.Broadcom.) [HKLM] -- B7541EC5F72AA713F557569278EB6273725F5607 =>.Microsoft Windows Component Publisher® O42 - Logiciel: Windows Driver Package - Broadcom Bluetooth (07/30/2009 6.2.0.9405) - (.Broadcom.) [HKLM] -- A6A8668C0A13640CA28FE2A7D9654BE4AE478B13 =>.Microsoft Windows Component Publisher® O42 - Logiciel: Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) - (.Broadcom.) [HKLM] -- BF20603967CFDCB2BBF91950E8A56DFBC5C833FE =>.Microsoft Windows Component Publisher® O42 - Logiciel: WinRAR archiver - (.RarLab.) [HKLM] -- WinRAR archiver =>.RarLab O42 - Logiciel: WinZip 15.5 - (.WinZip Computing, S.L..) [HKLM] -- {CD95F661-A5C4-44F5-A6AA-ECDD91C240C3} =>.WinZip Computing, S.L. O42 - Logiciel: Yahoo! Messenger - (.Yahoo! Inc..) [HKLM] -- Yahoo! Messenger =>.Yahoo! Inc. O42 - Logiciel: Your Uninstaller! 2010 - (.URSoft, Inc..) [HKLM] -- YU2010_is1 =>.URSoft, Inc.® O42 - Logiciel: أحكام التجويد - الإصدار الأول - (.linux.man@laposte.net.) [HKLM] -- أحكام التجويد_is1 O42 - Logiciel: بالتولك عربي - (.MrAlone Inc.) [HKLM] -- {B60CF50E-3CA0-4822-BBE2-12A86ABB6074}_is1 O42 - Logiciel: برنامج صندوق المتجر - (..) [HKLM] -- برنامج صندوق المتجر O42 - Logiciel: برنامج محاسبة كتاب المحاسبة لدار شعاع - (..) [HKLM] -- ST6UNST #1 O42 - Logiciel: مصحف المدينة النبوية - (.My Company Name.) [HKLM] -- {1136FCB8-E1E9-4A02-B3B5-E2598DFB16CE} ---\\ HKCU & HKLM Software Keys (184) - 30s HKLM\SOFTWARE\7-Zip =>.Igor Pavlov HKLM\SOFTWARE\Adobe =>.Adobe HKLM\SOFTWARE\AMD =>.AMD HKLM\SOFTWARE\Apple Inc. =>.Apple Inc. HKLM\SOFTWARE\ATI Technologies =>.ATI Technologies HKLM\SOFTWARE\Autodesk =>.Autodesk HKLM\SOFTWARE\Baidu Security =>.Baidu Technology HKLM\SOFTWARE\Baidu_Drp_pos =>.Baidu Technology HKLM\SOFTWARE\Bullzip =>.Bullzip HKLM\SOFTWARE\CBSTEST =>.CBS Test HKLM\SOFTWARE\CloudOpt HKLM\SOFTWARE\CyberGhost =>.CyberGhost S.R.L HKLM\SOFTWARE\Dosadi HKLM\SOFTWARE\Driver-Soft =>.Driver-Soft HKLM\SOFTWARE\drpsu =>.Driver PackSolution HKLM\SOFTWARE\EaseUS =>.EaseUS Software HKLM\SOFTWARE\EaseUS Todo Backup =>.EaseUS Software HKLM\SOFTWARE\EASEUSTODOBACKUPCHECK =>.EaseUS Software HKLM\SOFTWARE\Eset =>.ESET HKLM\SOFTWARE\EVP =>.EVP Software HKLM\SOFTWARE\FolderLock6 HKLM\SOFTWARE\Fortemedia =>.Lugert Europe HKLM\SOFTWARE\Free YouTube Downloader =>.DawnArk, Inc HKLM\SOFTWARE\GEAR Software =>.GEAR Software HKLM\SOFTWARE\GNU =>.GNU HKLM\SOFTWARE\Golden Al-Wafi Translator HKLM\SOFTWARE\Google =>.Google HKLM\SOFTWARE\HaaliMkx =>.Haali Media HKLM\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard HKLM\SOFTWARE\HP =>.HP HKLM\SOFTWARE\Icaros =>.Icaros HKLM\SOFTWARE\IM Providers =>.IM Providers HKLM\SOFTWARE\InstallShield =>.InstallShield HKLM\SOFTWARE\Intel =>.Intel HKLM\SOFTWARE\Internet Download Manager =>.Tonec Inc HKLM\SOFTWARE\JavaSoft =>.JavaSoft HKLM\SOFTWARE\JreMetrics =>.JreMetrics HKLM\SOFTWARE\KLCodecPack =>.KLite Inc HKLM\SOFTWARE\Kmgi HKLM\SOFTWARE\KONAMI =>.Konami HKLM\SOFTWARE\LAV =>.LAV Inc HKLM\SOFTWARE\Lavasoft =>.Lavasoft HKLM\SOFTWARE\Lenovo =>.Lenovo HKLM\SOFTWARE\Licenses =>.Microsoft Corporation HKLM\SOFTWARE\LogMeIn Hamachi =>.LogMeIn Entreprise HKLM\SOFTWARE\LogMeIn, Inc. =>.LogMeIn Entreprise HKLM\SOFTWARE\Macromedia =>.Macromedia HKLM\SOFTWARE\McAfee =>.McAfee Inc. HKLM\SOFTWARE\Mozilla =>.Mozilla HKLM\SOFTWARE\mozilla.org =>.mozilla.org HKLM\SOFTWARE\MozillaPlugins =>.MozillaPlugins HKLM\SOFTWARE\My Company Name HKLM\SOFTWARE\NeoSmart Technologies =>.NeoSmart Technologies HKLM\SOFTWARE\Network Associates =>.Network Associates HKLM\SOFTWARE\Nico Mak Computing =>.Nico Mak Computing HKLM\SOFTWARE\Nuance =>.Nuance HKLM\SOFTWARE\ODBC =>.DB Connectivity Solutions HKLM\SOFTWARE\OpenVPN =>.OpenVPN Technologie HKLM\SOFTWARE\OpenVPN-GUI =>.OpenVPN Technologie HKLM\SOFTWARE\Panda Security =>.Panda Security HKLM\SOFTWARE\Panda Software =>.Panda Software HKLM\SOFTWARE\Piriform =>.Piriform HKLM\SOFTWARE\PowerISO =>.PowerISO Computing HKLM\SOFTWARE\RealNetworks =>.RealNetworks HKLM\SOFTWARE\Realtek =>.Realtek Semiconductor Corp. HKLM\SOFTWARE\RecordDISCXXX =>.Propellerhead Reason HKLM\SOFTWARE\RegisteredApplications =>.Microsoft Corporation HKLM\SOFTWARE\SAKHR HKLM\SOFTWARE\SAMSUNG =>.Samsung Electronics HKLM\SOFTWARE\Sitech HKLM\SOFTWARE\Skype =>.Skype HKLM\SOFTWARE\Softgogo =>.YNET Technology Co.,Ltd HKLM\SOFTWARE\Softland =>.Softland HKLM\SOFTWARE\Software =>.Unknow HKLM\SOFTWARE\Sonic =>.Sonic HKLM\SOFTWARE\SRS Labs =>.SRS Labs HKLM\SOFTWARE\Swearware =>.Swearware HKLM\SOFTWARE\Symantec =>.Symantec HKLM\SOFTWARE\TAP-Windows HKLM\SOFTWARE\TeamViewer =>.TeamViewer HKLM\SOFTWARE\Voice =>.Legitimate HKLM\SOFTWARE\Volatile =>.Microsoft Corporation HKLM\SOFTWARE\WafCX =>.WafCX HKLM\SOFTWARE\Western Digital =>.Western Digital HKLM\SOFTWARE\Widcomm =>.Widcomm HKLM\SOFTWARE\WIDCOMM_TEMP HKLM\SOFTWARE\Wondershare =>.Wondershare HKLM\SOFTWARE\WOW6432Node =>.Microsoft Corporation HKLM\SOFTWARE\Xilisoft =>.Xilisoft HKLM\SOFTWARE\Yahoo =>.Yahoo! Inc. HKLM\SOFTWARE\zbshareware =>.Zbshareware HKCU\SOFTWARE\7-Zip =>.Igor Pavlov HKCU\SOFTWARE\AC3Filter =>.Vigovsky Alexander HKCU\SOFTWARE\Ada99 HKCU\SOFTWARE\Adobe =>.Adobe HKCU\SOFTWARE\ADSafe4 HKCU\SOFTWARE\Akeo Consulting =>.Akeo Consulting HKCU\SOFTWARE\AOMEI =>.AOMEI Tech Co HKCU\SOFTWARE\Apowersoft =>.Apowersoft HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation HKCU\SOFTWARE\AVI MP4 Converter 6 HKCU\SOFTWARE\Baidu =>.Baidu HKCU\SOFTWARE\Baidu Security =>.Baidu Technology HKCU\SOFTWARE\BitTorrent HKCU\SOFTWARE\Bullzip =>.Bullzip HKCU\SOFTWARE\Cineform =>.CineForm HKCU\SOFTWARE\CyberGhost =>.CyberGhost S.R.L HKCU\SOFTWARE\DownloadManager =>.DownloadManager HKCU\SOFTWARE\drpsu =>.Driver PackSolution HKCU\SOFTWARE\DRPSu Updater HKCU\SOFTWARE\DSP-worx =>.Microsoft Corporation HKCU\SOFTWARE\EaseUS =>.EaseUS Software HKCU\SOFTWARE\Ela-Salaty =>.Ela-Salaty HKCU\SOFTWARE\ESET =>.ESET HKCU\SOFTWARE\Fast Reports =>.Fast Reports HKCU\SOFTWARE\Folder Manager HKCU\SOFTWARE\FolderLock6 HKCU\SOFTWARE\Gabest =>.Gabest HKCU\SOFTWARE\GetData =>.GetData HKCU\SOFTWARE\GNU =>.GNU HKCU\SOFTWARE\Google =>.Google HKCU\SOFTWARE\Haali =>.Haali Media HKCU\SOFTWARE\Harf HKCU\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard HKCU\SOFTWARE\HP =>.HP HKCU\SOFTWARE\Icaros =>.Icaros HKCU\SOFTWARE\IM Providers =>.IM Providers HKCU\SOFTWARE\INTEL =>.Intel HKCU\SOFTWARE\JavaSoft =>.JavaSoft HKCU\SOFTWARE\KasperskyLab =>.Kaspersky Labs HKCU\SOFTWARE\KasperskyLabSetup =>.Kaspersky Labs HKCU\SOFTWARE\Local AppWizard-Generated Applications =>.ZWCAD HKCU\SOFTWARE\Macromedia =>.Macromedia HKCU\SOFTWARE\Magicbit =>.Superfluous.Magicbit HKCU\SOFTWARE\Malwarebytes =>.Malwarebytes HKCU\SOFTWARE\McAfee =>.McAfee Inc. HKCU\SOFTWARE\MediaInfo =>.Jérôme Martinez HKCU\SOFTWARE\Memeo =>.Memeo HKCU\SOFTWARE\Mozilla =>.Mozilla HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins HKCU\SOFTWARE\MPC-BE HKCU\SOFTWARE\Netscape =>.Netscape HKCU\SOFTWARE\Nico Mak Computing =>.Nico Mak Computing HKCU\SOFTWARE\Nilings =>.Nilings HKCU\SOFTWARE\Northcode Inc =>.Northcode Inc HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions HKCU\SOFTWARE\Opera Software =>.Opera Software HKCU\SOFTWARE\Paltalk HKCU\SOFTWARE\Piriform =>.Piriform HKCU\SOFTWARE\PowerISO =>.PowerISO Computing HKCU\SOFTWARE\Psiphon3 HKCU\SOFTWARE\RealNetworks =>.RealNetworks HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp. HKCU\SOFTWARE\RLZer HKCU\SOFTWARE\Rtp =>.RTP Software HKCU\SOFTWARE\SamLab.ws HKCU\SOFTWARE\Samsung =>.Samsung Electronics HKCU\SOFTWARE\SFX TEAM =>.SFX TEAM HKCU\SOFTWARE\Skype =>.Skype HKCU\SOFTWARE\Softland =>.Softland HKCU\SOFTWARE\SourceForge =>.SourceForge HKCU\SOFTWARE\Sysinternals =>.Sysinternals HKCU\SOFTWARE\TeamViewer =>.TeamViewer HKCU\SOFTWARE\Tencent =>.Superfluous.Tencent HKCU\SOFTWARE\Trolltech =>.Trolltech HKCU\SOFTWARE\undefined =>.Superfluous.Downloader HKCU\SOFTWARE\URSoft =>.URSoft HKCU\SOFTWARE\Ut Video Codec Suite HKCU\SOFTWARE\uTorrentPlus HKCU\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation HKCU\SOFTWARE\WebApp =>.Superfluous.Downloader HKCU\SOFTWARE\Wget =>.Wget HKCU\SOFTWARE\Widcomm =>.Widcomm HKCU\SOFTWARE\WinRAR =>.WinRAR HKCU\SOFTWARE\WinRAR SFX =>.RarLab HKCU\SOFTWARE\WinZip Computing =>.WinZip Computing HKCU\SOFTWARE\Wondershare =>.Wondershare HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation HKCU\SOFTWARE\Xilisoft =>.Xilisoft HKCU\SOFTWARE\yahoo =>.Yahoo! Inc. HKCU\SOFTWARE\ZHP =>.Nicolas Coolman HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation HKCU\SOFTWARE\AppDataLow\Software\Adobe =>.Adobe HKCU\SOFTWARE\AppDataLow\Software\JavaSoft =>.JavaSoft ---\\ Contents of the Common Files folders (319) - 28s O43 - CFD: 09/05/2016 - [] D -- C:\Program Files\7-Zip =>.Igor Pavlov O43 - CFD: 01/06/2014 - [] D -- C:\Program Files\Adobe =>.Adobe Systems, Incorporated® O43 - CFD: 20/12/2015 - [0] D -- C:\Program Files\ADSafe O43 - CFD: 25/01/2017 - [] D -- C:\Program Files\AirDroid =>.AirDroid O43 - CFD: 12/02/2017 - [] D -- C:\Program Files\Al Aqaree O43 - CFD: 28/02/2016 - [] D -- C:\Program Files\almatjer O43 - CFD: 08/02/2016 - [] D -- C:\Program Files\Apowersoft =>.Apowersoft O43 - CFD: 14/05/2016 - [] D -- C:\Program Files\Athan O43 - CFD: 18/06/2014 - [] D -- C:\Program Files\AVI MP4 Converter 6 O43 - CFD: 05/11/2014 - [] D -- C:\Program Files\Baidu Security =>.Baidu Technology O43 - CFD: 28/02/2016 - [] D -- C:\Program Files\Baytalejtiaz O43 - CFD: 24/11/2016 - [] D -- C:\Program Files\Betternet O43 - CFD: 24/04/2017 - [] D -- C:\Program Files\Bonjour =>.Apple Inc. O43 - CFD: 05/11/2016 - [] D -- C:\Program Files\Bullzip {00A53768EA4CD61658F05AD9ACC3318D8D} =>.Bullzip O43 - CFD: 11/09/2015 - [] D -- C:\Program Files\CCleaner =>.Piriform Ltd O43 - CFD: 28/09/2015 - [0] D -- C:\Program Files\Cheat Engine 6.4 =>.Dark Byte O43 - CFD: 27/04/2017 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation O43 - CFD: 10/11/2016 - [] D -- C:\Program Files\CyberGhost =>.CyberGhost S.R.L O43 - CFD: 12/04/2015 - [0] D -- C:\Program Files\Daum =>.DAUM O43 - CFD: 12/04/2015 - [] D -- C:\Program Files\DaumBack O43 - CFD: 11/04/2016 - [] D -- C:\Program Files\DIFX =>.Microsoft Corporation O43 - CFD: 14/03/2015 - [] D -- C:\Program Files\Driver Checker O43 - CFD: 04/06/2014 - [] D -- C:\Program Files\Driver-Soft =>.Driver-Soft O43 - CFD: 15/12/2015 - [0] D -- C:\Program Files\DriversCloud.com =>.Cybelsoft O43 - CFD: 02/11/2013 - [] D -- C:\Program Files\DVD Maker =>.Aone Software O43 - CFD: 24/06/2014 - [] D -- C:\Program Files\EaseUS =>.EaseUS Software O43 - CFD: 09/03/2016 - [0] D -- C:\Program Files\Ela-Salaty =>.Ela-Salaty O43 - CFD: 24/04/2017 - [] D -- C:\Program Files\ESET =>.ESET, spol. s r.o.® O43 - CFD: 28/05/2016 - [] D -- C:\Program Files\Fifa Master =>.Electronic Arts, Inc. O43 - CFD: 13/02/2017 - [] D -- C:\Program Files\Folder Lock 6 =>.NewSoftwares.net Inc. SDN. BHD.® O43 - CFD: 14/04/2015 - [0] D -- C:\Program Files\Free YouTube Downloader =>.DawnArk, Inc O43 - CFD: 12/08/2014 - [] D -- C:\Program Files\GetData =>.GetData Pty Ltd® O43 - CFD: 03/04/2017 - [] D -- C:\Program Files\Google =>.Google Inc® O43 - CFD: 07/06/2014 - [] D -- C:\Program Files\Hewlett-Packard =>.Hewlett-Packard O43 - CFD: 04/06/2014 - [] D -- C:\Program Files\HP =>.Hewlett-Packard O43 - CFD: 07/04/2015 - [] HD -- C:\Program Files\InstallShield Installation Information =>.InstallShield Software O43 - CFD: 09/02/2016 - [0] D -- C:\Program Files\Intel =>.Intel Corporation O43 - CFD: 27/12/2016 - [] D -- C:\Program Files\Internet Download Manager =>.Tonec Inc O43 - CFD: 07/08/2014 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation O43 - CFD: 10/05/2016 - [] D -- C:\Program Files\Java =>.Oracle O43 - CFD: 29/03/2015 - [] D -- C:\Program Files\K-Lite Codec Pack =>.KLite Inc O43 - CFD: 07/11/2016 - [] D -- C:\Program Files\Kingo ROOT =>.Kingosoft Technology Ltd O43 - CFD: 25/04/2017 - [0] D -- C:\Program Files\Lavasoft =>.Lavasoft O43 - CFD: 15/12/2015 - [] D -- C:\Program Files\Lenovo =>.Lenovo O43 - CFD: 13/03/2017 - [] D -- C:\Program Files\LogMeIn Hamachi =>.LogMeIn Entreprise O43 - CFD: 27/04/2017 - [] D -- C:\Program Files\Malwarebytes =>.Malwarebytes O43 - CFD: 07/03/2015 - [0] D -- C:\Program Files\Malwarebytes Anti-Malware =>.Malwarebytes O43 - CFD: 29/10/2014 - [] D -- C:\Program Files\MarkAny =>.MarkAny O43 - CFD: 01/06/2014 - [] D -- C:\Program Files\McAfee =>.McAfee O43 - CFD: 11/12/2014 - [0] D -- C:\Program Files\McAfee Security Scan =>.McAfee O43 - CFD: 12/04/2011 - [] D -- C:\Program Files\Microsoft Games =>.Microsoft Corporation O43 - CFD: 01/06/2016 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation O43 - CFD: 19/12/2015 - [0] D -- C:\Program Files\Microsoft Silverlight =>.Microsoft Corporation O43 - CFD: 01/06/2016 - [] D -- C:\Program Files\Microsoft Visual Studio =>.Microsoft Corporation O43 - CFD: 01/06/2016 - [] D -- C:\Program Files\Microsoft Visual Studio 8 =>.Microsoft Corporation O43 - CFD: 01/06/2016 - [] D -- C:\Program Files\Microsoft Works =>.Microsoft Corporation O43 - CFD: 01/06/2016 - [] D -- C:\Program Files\Microsoft.NET =>.Microsoft Corporation O43 - CFD: 25/04/2017 - [] D -- C:\Program Files\mozilla firefox =>.Mozilla O43 - CFD: 17/09/2016 - [] D -- C:\Program Files\Mozilla Maintenance Service =>.Mozilla O43 - CFD: 01/06/2016 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation O43 - CFD: 27/06/2016 - [] D -- C:\Program Files\NeoSmart Technologies =>.NeoSmart Technologies O43 - CFD: 01/06/2016 - [0] D -- C:\Program Files\Office 2016 Permanent Activator Ultimate v1.1 =>.Microsoft Corporation O43 - CFD: 24/11/2016 - [] D -- C:\Program Files\OpenVPN =>.OpenVPN Technologie O43 - CFD: 28/01/2016 - [0] D -- C:\Program Files\Opera =>.Opera Software O43 - CFD: 22/04/2017 - [] D -- C:\Program Files\Panda Security =>.Panda Security O43 - CFD: 16/11/2016 - [0] D -- C:\Program Files\PlatinumHideIP =>.Platinum Hide IP O43 - CFD: 14/07/2014 - [] D -- C:\Program Files\Portable O43 - CFD: 01/06/2014 - [] D -- C:\Program Files\PowerISO =>.PowerISO Computing O43 - CFD: 17/05/2016 - [] D -- C:\Program Files\Quranzu1 O43 - CFD: 01/06/2014 - [] D -- C:\Program Files\Realtek =>.Realtek O43 - CFD: 25/02/2015 - [0] D -- C:\Program Files\Recuva =>.Piriform O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation O43 - CFD: 30/01/2016 - [] D -- C:\Program Files\SAM CoDeC Pack O43 - CFD: 16/05/2016 - [] D -- C:\Program Files\Samsung =>.Samsung Electronics O43 - CFD: 10/07/2016 - [] D -- C:\Program Files\Sitech O43 - CFD: 01/06/2014 - [] RD -- C:\Program Files\Skype =>.Skype O43 - CFD: 27/08/2015 - [0] D -- C:\Program Files\softutiful O43 - CFD: 25/04/2017 - [] D -- C:\Program Files\Square Abuse O43 - CFD: 20/12/2015 - [] D -- C:\Program Files\SuperCopier2 =>.Ultracopier O43 - CFD: 26/03/2015 - [] D -- C:\Program Files\Synei =>.Synei O43 - CFD: 24/11/2016 - [] D -- C:\Program Files\TAP-Windows =>.OpenVPN Technologie O43 - CFD: 27/04/2017 - [] D -- C:\Program Files\TeamViewer =>.TeamViewer® O43 - CFD: 29/08/2015 - [] D -- C:\Program Files\Tweaking.com =>.Tweaking LLC® O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation O43 - CFD: 20/07/2016 - [] D -- C:\Program Files\Unlocker =>.Cedrick Collomb O43 - CFD: 28/09/2015 - [0] D -- C:\Program Files\uTorrent =>.Superfluous.Empty O43 - CFD: 16/09/2014 - [] D -- C:\Program Files\Western Digital =>.Western Digital O43 - CFD: 11/04/2016 - [] D -- C:\Program Files\WIDCOMM =>.Broadcom Corporation® O43 - CFD: 27/07/2015 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation O43 - CFD: 02/11/2013 - [] D -- C:\Program Files\Windows Journal =>.Microsoft Corporation O43 - CFD: 02/11/2013 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation O43 - CFD: 02/11/2013 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation O43 - CFD: 02/11/2013 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation O43 - CFD: 21/11/2010 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation O43 - CFD: 02/11/2013 - [] D -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation O43 - CFD: 02/06/2014 - [] D -- C:\Program Files\WinRAR =>.WinRAR O43 - CFD: 01/06/2014 - [] D -- C:\Program Files\WinZip =>.WinZip Computing® O43 - CFD: 26/04/2017 - [] D -- C:\Program Files\Wondershare =>.Wondershare O43 - CFD: 29/05/2016 - [] D -- C:\Program Files\Xilisoft =>.Xilisoft O43 - CFD: 01/06/2014 - [] D -- C:\Program Files\Yahoo! =>.Yahoo! O43 - CFD: 20/09/2015 - [] D -- C:\Program Files\Your Uninstaller 2010 =>.Ursoftware O43 - CFD: 01/06/2014 - [] D -- C:\Program Files\أحكام التجويد O43 - CFD: 16/06/2014 - [] D -- C:\Program Files\للبالتولك O43 - CFD: 01/06/2014 - [] D -- C:\Program Files\مصحف المدينة النبوية O43 - CFD: 09/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip =>.Igor Pavlov O43 - CFD: 16/04/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation O43 - CFD: 01/06/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools O43 - CFD: 12/12/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AirDroid =>.AirDroid O43 - CFD: 08/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apowersoft =>.Apowersoft O43 - CFD: 19/11/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Betternet Technologies Inc O43 - CFD: 05/11/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bullzip =>.Bullzip O43 - CFD: 26/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd O43 - CFD: 14/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Disabled Startup O43 - CFD: 24/06/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Todo Backup Free 6.5 =>.EaseUS Software O43 - CFD: 01/06/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation O43 - CFD: 01/06/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth =>.Google Earth O43 - CFD: 04/06/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP =>.Hewlett-Packard O43 - CFD: 20/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager =>.Tonec Inc O43 - CFD: 10/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java =>.Oracle O43 - CFD: 29/03/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack =>.KLite Inc O43 - CFD: 07/11/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kingo ROOT =>.Kingosoft Technology Ltd O43 - CFD: 13/03/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi =>.LogMeIn Entreprise O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation O43 - CFD: 27/04/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes =>.Malwarebytes O43 - CFD: 27/04/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee =>.McAfee O43 - CFD: 01/06/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office =>.Microsoft Corporation O43 - CFD: 27/06/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoSmart Technologies =>.NeoSmart Technologies O43 - CFD: 01/06/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO =>.PowerISO Computing O43 - CFD: 30/01/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SAM CoDeC Pack O43 - CFD: 16/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung =>.Samsung Electronics O43 - CFD: 01/06/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype =>.Skype O43 - CFD: 26/04/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation O43 - CFD: 12/04/2011 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC =>.Wacom Technology O43 - CFD: 24/11/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TAP-Windows =>.OpenVPN Technologie O43 - CFD: 29/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com =>.Tweaking.com O43 - CFD: 04/06/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UmmyVideoDownloader =>.UmmyVideoDownloader O43 - CFD: 16/09/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WD SmartWare O43 - CFD: 01/06/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR O43 - CFD: 01/06/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip =>.WinZip O43 - CFD: 29/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xilisoft =>.Xilisoft O43 - CFD: 01/06/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Messenger =>.Yahoo! O43 - CFD: 20/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Your Uninstaller 2010 =>.Ursoftware O43 - CFD: 01/06/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\أحكام التجويد O43 - CFD: 01/06/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\النسخة العربية للبالتولك O43 - CFD: 01/06/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\مصحف المدينة النبوية O43 - CFD: 26/08/2015 - [0] D -- C:\ProgramData\51679a000003820 O43 - CFD: 21/12/2015 - [] D -- C:\ProgramData\abelboimikelhpgpjepophojmoambfml O43 - CFD: 07/06/2014 - [] D -- C:\ProgramData\Adobe =>.Adobe O43 - CFD: 12/12/2016 - [] D -- C:\ProgramData\AirDroid =>.AirDroid O43 - CFD: 01/06/2014 - [] D -- C:\ProgramData\AomeiBR =>.AOMEI Technology O43 - CFD: 14/12/2016 - [] D -- C:\ProgramData\Apple =>.Apple Inc. O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation O43 - CFD: 05/11/2014 - [] D -- C:\ProgramData\Baidu Security =>.Baidu Technology O43 - CFD: 12/04/2017 - [] D -- C:\ProgramData\Betternet O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation O43 - CFD: 04/06/2014 - [] D -- C:\ProgramData\DriverGenius =>.Bluesquad O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Favorites =>.Microsoft Corporation O43 - CFD: 12/04/2015 - [] D -- C:\ProgramData\Free YouTube Downloader =>.DawnArk, Inc O43 - CFD: 23/01/2016 - [] D -- C:\ProgramData\Google =>.Google O43 - CFD: 04/06/2014 - [] D -- C:\ProgramData\Hewlett-Packard =>.Hewlett-Packard O43 - CFD: 04/06/2014 - [] D -- C:\ProgramData\HP =>.Hewlett-Packard O43 - CFD: 01/06/2014 - [0] D -- C:\ProgramData\IDM =>.IDM O43 - CFD: 01/06/2014 - [] D -- C:\ProgramData\InstallShield =>.InstallShield O43 - CFD: 16/11/2016 - [] D -- C:\ProgramData\Kaspersky Lab Setup Files =>.Kaspersky Lab O43 - CFD: 01/06/2014 - [] D -- C:\ProgramData\LogMeIn =>.LogMeIn O43 - CFD: 27/04/2017 - [] D -- C:\ProgramData\Malwarebytes =>.Malwarebytes O43 - CFD: 27/04/2017 - [] D -- C:\ProgramData\McAfee =>.McAfee O43 - CFD: 01/06/2016 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation O43 - CFD: 14/03/2017 - [] D -- C:\ProgramData\Microsoft Help =>.Microsoft Corporation O43 - CFD: 01/06/2014 - [] D -- C:\ProgramData\Mozilla =>.Mozilla Corporation O43 - CFD: 10/05/2016 - [] D -- C:\ProgramData\Oracle =>.Oracle O43 - CFD: 16/05/2016 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation O43 - CFD: 05/11/2016 - [] D -- C:\ProgramData\PDF Writer =>.Acro Software O43 - CFD: 16/11/2016 - [] D -- C:\ProgramData\PlatinumHideIP =>.Platinum Hide IP O43 - CFD: 21/12/2015 - [] D -- C:\ProgramData\RogueKiller =>.Adlice O43 - CFD: 05/06/2014 - [] D -- C:\ProgramData\Samsung =>.Samsung Electronics O43 - CFD: 01/06/2014 - [] D -- C:\ProgramData\Skype =>.Skype O43 - CFD: 14/05/2016 - [] D -- C:\ProgramData\Softland =>.Softland O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation O43 - CFD: 14/05/2016 - [] D -- C:\ProgramData\Symantec =>.Symantec O43 - CFD: 26/04/2017 - [0] AD -- C:\ProgramData\TEMP =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation O43 - CFD: 20/12/2015 - [0] D -- C:\ProgramData\TXPCMGR O43 - CFD: 16/09/2014 - [] D -- C:\ProgramData\Western Digital =>.Western Digital O43 - CFD: 04/06/2014 - [] D -- C:\ProgramData\WinZip =>.WinZip O43 - CFD: 12/12/2015 - [] D -- C:\ProgramData\wondershare =>.Wondershare O43 - CFD: 29/05/2016 - [] D -- C:\ProgramData\Xilisoft =>.Xilisoft O43 - CFD: 01/06/2014 - [] D -- C:\ProgramData\Yahoo! =>.Yahoo! O43 - CFD: 25/04/2017 - [0] D -- C:\ProgramData\{C57FE420-6939-4E16-A1BD-CAA50C9F1884} O43 - CFD: 01/06/2014 - [] SHD -- C:\ProgramData\سطح المكتب O43 - CFD: 01/06/2014 - [] SHD -- C:\ProgramData\قائمة ابدأ O43 - CFD: 01/06/2014 - [] D -- C:\Program Files\Common Files\Adobe =>.Adobe O43 - CFD: 05/11/2016 - [] D -- C:\Program Files\Common Files\Bullzip =>.Bullzip O43 - CFD: 01/06/2014 - [] D -- C:\Program Files\Common Files\Cisco Systems =>.Cisco Systems O43 - CFD: 01/06/2016 - [] D -- C:\Program Files\Common Files\DESIGNER =>.Designer O43 - CFD: 01/06/2014 - [] D -- C:\Program Files\Common Files\InstallShield =>.InstallShield O43 - CFD: 10/05/2016 - [] D -- C:\Program Files\Common Files\Java =>.Oracle O43 - CFD: 27/04/2017 - [] D -- C:\Program Files\Common Files\McAfee =>.McAfee O43 - CFD: 07/06/2016 - [] D -- C:\Program Files\Common Files\microsoft shared =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Common Files\Services =>.Microsoft Corporation O43 - CFD: 01/06/2014 - [] D -- C:\Program Files\Common Files\Skype =>.Skype O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Common Files\SpeechEngines =>.Microsoft Corporation O43 - CFD: 02/09/2014 - [] D -- C:\Program Files\Common Files\SWF Studio =>.SWF Studio O43 - CFD: 01/06/2014 - [] D -- C:\Program Files\Common Files\System =>.Microsoft Corporation O43 - CFD: 10/02/2016 - [] D -- C:\Users\tarek\AppData\Roaming\AC3Filter =>.Vigovsky Alexander O43 - CFD: 07/06/2014 - [] D -- C:\Users\tarek\AppData\Roaming\Adobe =>.Adobe O43 - CFD: 20/12/2015 - [] D -- C:\Users\tarek\AppData\Roaming\ADSafe3 O43 - CFD: 27/04/2017 - [] D -- C:\Users\tarek\AppData\Roaming\AirDroid =>.AirDroid O43 - CFD: 08/02/2016 - [] D -- C:\Users\tarek\AppData\Roaming\Apowersoft =>.Apowersoft O43 - CFD: 25/04/2017 - [0] D -- C:\Users\tarek\AppData\Roaming\baidu =>.Baidu O43 - CFD: 05/11/2014 - [0] D -- C:\Users\tarek\AppData\Roaming\Baidu Security =>.Baidu Technology O43 - CFD: 12/06/2016 - [] D -- C:\Users\tarek\AppData\Roaming\DB O43 - CFD: 25/04/2017 - [] D -- C:\Users\tarek\AppData\Roaming\DMCache =>.DMCache O43 - CFD: 14/05/2016 - [] D -- C:\Users\tarek\AppData\Roaming\doctor O43 - CFD: 26/04/2017 - [] D -- C:\Users\tarek\AppData\Roaming\HMYGSetting =>Adware.Suspect O43 - CFD: 01/06/2014 - [] D -- C:\Users\tarek\AppData\Roaming\Identities =>.Microsoft Corporation O43 - CFD: 24/04/2017 - [] D -- C:\Users\tarek\AppData\Roaming\IDM =>.IDM O43 - CFD: 07/11/2016 - [] D -- C:\Users\tarek\AppData\Roaming\Kingosoft =>.Kingosoft O43 - CFD: 01/06/2014 - [] D -- C:\Users\tarek\AppData\Roaming\Macromedia =>.Macromedia O43 - CFD: 12/04/2011 - [0] D -- C:\Users\tarek\AppData\Roaming\Media Center Programs =>.Microsoft Corporation O43 - CFD: 19/04/2017 - [0] D -- C:\Users\tarek\AppData\Roaming\Media Player Classic =>.Microsoft Corporation O43 - CFD: 31/05/2016 - [] SD -- C:\Users\tarek\AppData\Roaming\Microsoft =>.Microsoft Corporation O43 - CFD: 01/06/2014 - [] D -- C:\Users\tarek\AppData\Roaming\Mozilla =>.Mozilla Corporation O43 - CFD: 26/08/2015 - [0] D -- C:\Users\tarek\AppData\Roaming\MPC-HC =>.MPC-HC Team O43 - CFD: 28/01/2016 - [] D -- C:\Users\tarek\AppData\Roaming\Opera Software =>.Opera Software O43 - CFD: 28/06/2016 - [] AD -- C:\Users\tarek\AppData\Roaming\Oracle =>.Oracle O43 - CFD: 05/11/2016 - [] D -- C:\Users\tarek\AppData\Roaming\PDF Writer =>.Acro Software O43 - CFD: 16/11/2016 - [] D -- C:\Users\tarek\AppData\Roaming\PlatinumHideIP =>.Platinum Hide IP O43 - CFD: 01/06/2014 - [] D -- C:\Users\tarek\AppData\Roaming\PowerISO =>.PowerISO Computing O43 - CFD: 16/11/2016 - [] D -- C:\Users\tarek\AppData\Roaming\Psiphon3 O43 - CFD: 07/04/2015 - [] D -- C:\Users\tarek\AppData\Roaming\Samsung =>.Samsung Electronics O43 - CFD: 21/09/2014 - [] D -- C:\Users\tarek\AppData\Roaming\Skype =>.Skype O43 - CFD: 14/05/2016 - [] D -- C:\Users\tarek\AppData\Roaming\Softland =>.Softland O43 - CFD: 30/01/2016 - [] D -- C:\Users\tarek\AppData\Roaming\Sun =>.Oracle O43 - CFD: 26/03/2015 - [] D -- C:\Users\tarek\AppData\Roaming\Synei =>.Synei O43 - CFD: 06/03/2017 - [] D -- C:\Users\tarek\AppData\Roaming\TeamViewer =>.TeamViewer O43 - CFD: 01/03/2015 - [] D -- C:\Users\tarek\AppData\Roaming\Thinstall =>.VMare O43 - CFD: 01/06/2014 - [] D -- C:\Users\tarek\AppData\Roaming\URSoft =>.URSoft O43 - CFD: 15/04/2017 - [] D -- C:\Users\tarek\AppData\Roaming\uTorrent O43 - CFD: 12/04/2015 - [] D -- C:\Users\tarek\AppData\Roaming\Vitzo =>.Vitzo Ltd O43 - CFD: 16/09/2014 - [] D -- C:\Users\tarek\AppData\Roaming\Western Digital =>.Western Digital O43 - CFD: 26/04/2017 - [] D -- C:\Users\tarek\AppData\Roaming\Wondershare =>.Wondershare O43 - CFD: 29/05/2016 - [] D -- C:\Users\tarek\AppData\Roaming\Xilisoft =>.Xilisoft O43 - CFD: 24/09/2014 - [] D -- C:\Users\tarek\AppData\Roaming\Yahoo! =>.Yahoo! O43 - CFD: 29/04/2017 - [] D -- C:\Users\tarek\AppData\Roaming\ZHP =>.Nicolas Coolman O43 - CFD: 14/07/2016 - [] D -- C:\Users\tarek\AppData\Local\Adobe =>.Adobe O43 - CFD: 01/06/2014 - [0] SHD -- C:\Users\tarek\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 11/04/2016 - [] D -- C:\Users\tarek\AppData\Local\Broadcom =>.Broadcom O43 - CFD: 15/04/2017 - [0] D -- C:\Users\tarek\AppData\Local\CrashDumps =>.Microsoft Corporation O43 - CFD: 24/11/2016 - [] D -- C:\Users\tarek\AppData\Local\Downloaded Installations =>.Microsoft Corporation O43 - CFD: 06/03/2017 - [0] D -- C:\Users\tarek\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation O43 - CFD: 16/11/2016 - [] D -- C:\Users\tarek\AppData\Local\Google =>.Google O43 - CFD: 01/06/2014 - [0] SHD -- C:\Users\tarek\AppData\Local\History =>.Microsoft Corporation O43 - CFD: 04/06/2014 - [] D -- C:\Users\tarek\AppData\Local\HP =>.Hewlett-Packard O43 - CFD: 07/11/2016 - [] D -- C:\Users\tarek\AppData\Local\Kingosoft =>.Kingosoft O43 - CFD: 01/06/2014 - [] D -- C:\Users\tarek\AppData\Local\LogMeIn =>.LogMeIn O43 - CFD: 29/04/2017 - [] D -- C:\Users\tarek\AppData\Local\LogMeIn Hamachi =>.LogMeIn Entreprise O43 - CFD: 20/06/2016 - [] D -- C:\Users\tarek\AppData\Local\Mega Limited =>.MEGA Limited O43 - CFD: 20/06/2016 - [0] D -- C:\Users\tarek\AppData\Local\MEGAsync =>.MegaSystems O43 - CFD: 12/12/2015 - [] D -- C:\Users\tarek\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 01/06/2014 - [0] D -- C:\Users\tarek\AppData\Local\Microsoft Help =>.Microsoft Corporation O43 - CFD: 28/02/2016 - [] D -- C:\Users\tarek\AppData\Local\Moayad_Myro O43 - CFD: 01/06/2014 - [] D -- C:\Users\tarek\AppData\Local\Mozilla =>.Mozilla Corporation O43 - CFD: 27/06/2016 - [] D -- C:\Users\tarek\AppData\Local\NeoSmart_Technologies =>.NeoSmart Technologies O43 - CFD: 28/01/2016 - [] D -- C:\Users\tarek\AppData\Local\Opera Software =>.Opera Software O43 - CFD: 05/11/2016 - [] D -- C:\Users\tarek\AppData\Local\PDF Writer =>.Acro Software O43 - CFD: 01/06/2014 - [] D -- C:\Users\tarek\AppData\Local\Programs =>.Microsoft Corporation O43 - CFD: 15/01/2015 - [] D -- C:\Users\tarek\AppData\Local\Samsung =>.Samsung Electronics O43 - CFD: 21/09/2014 - [] D -- C:\Users\tarek\AppData\Local\Skype =>.Skype O43 - CFD: 12/05/2016 - [] D -- C:\Users\tarek\AppData\Local\SquirrelTemp =>.Squirrels O43 - CFD: 03/02/2016 - [] D -- C:\Users\tarek\AppData\Local\TeamViewer =>.TeamViewer O43 - CFD: 29/04/2017 - [] D -- C:\Users\tarek\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 01/06/2014 - [0] SHD -- C:\Users\tarek\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 01/03/2015 - [] D -- C:\Users\tarek\AppData\Local\Thinstall =>.VMare O43 - CFD: 15/04/2017 - [] D -- C:\Users\tarek\AppData\Local\UmmyVideoDownloader =>.UmmyVideoDownloader O43 - CFD: 01/06/2014 - [] D -- C:\Users\tarek\AppData\Local\VirtualStore =>.Microsoft Corporation O43 - CFD: 16/09/2014 - [] D -- C:\Users\tarek\AppData\Local\Western Digital =>.Western Digital O43 - CFD: 16/09/2014 - [] D -- C:\Users\tarek\AppData\Local\Western_Digital O43 - CFD: 12/05/2016 - [] D -- C:\Users\tarek\AppData\Local\WhatsApp =>.WhatsApp O43 - CFD: 06/03/2016 - [] D -- C:\Users\tarek\AppData\Local\WinZip =>.WinZip O43 - CFD: 23/04/2017 - [] D -- C:\Users\tarek\AppData\Local\ZHP =>.Nicolas Coolman O43 - CFD: 01/06/2014 - [0] D -- C:\Users\tarek\AppData\Local\Programs\Common =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] RD -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation O43 - CFD: 01/06/2014 - [] RD -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools O43 - CFD: 12/02/2017 - [] D -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Al Aqaree O43 - CFD: 01/06/2014 - [] D -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Comptability for Ray Book O43 - CFD: 14/05/2016 - [] D -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Disabled Startup O43 - CFD: 14/05/2016 - [] D -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Folder Lock 6 O43 - CFD: 19/10/2016 - [] D -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation O43 - CFD: 20/09/2015 - [] D -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager =>.Tonec Inc O43 - CFD: 14/07/2009 - [] RD -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation O43 - CFD: 14/07/2014 - [] D -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Portable Programs O43 - CFD: 12/08/2014 - [] D -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recover My Files v4 =>.GetData O43 - CFD: 20/06/2016 - [] RD -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation O43 - CFD: 20/12/2015 - [] D -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SuperCopier2 =>.Ultracopier O43 - CFD: 20/07/2016 - [] D -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker =>.Cedrick Collomb O43 - CFD: 01/06/2014 - [] D -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Utorrent O43 - CFD: 01/06/2014 - [] D -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\µTorrent 3 O43 - CFD: 16/04/2016 - [] D -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\أجهزة Bluetooth O43 - CFD: 28/02/2016 - [] D -- C:\Users\tarek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\برنامج صندوق المتجر O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation O43 - CFD: 15/03/2017 - [] D -- C:\Users\Default\AppData\Local\LogMeIn Hamachi =>.LogMeIn Entreprise O43 - CFD: 14/07/2009 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 26/04/2017 - [0] D -- C:\Users\Default\AppData\Local\temp =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation O43 - CFD: 15/03/2017 - [] D -- C:\Users\Default User\AppData\Local\LogMeIn Hamachi =>.LogMeIn Entreprise O43 - CFD: 14/07/2009 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 26/04/2017 - [0] D -- C:\Users\Default User\AppData\Local\temp =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 27/04/2017 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\CrashDumps =>.Microsoft Corporation O43 - CFD: 01/06/2014 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Google =>.Google O43 - CFD: 11/04/2016 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 16/09/2014 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\ServiceTest O43 - CFD: 28/09/2015 - [] SD -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation ---\\ ShellIconOverlayIdentifiers (SIOI) (9) - 0s O106 - SIOI: IDM Shell Extension [ IDM Shell Extension] - {CDC95B92-E27C-4745-A8C5-64A52A78855D}. (.Tonec Inc. - Internet Download Manager module.) -- C:\Program Files\Internet Download Manager\IDMShellExt.dll =>.Tonec Inc.® O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - مكتبة DLL الخاصة بملحق Shell للتخزين المحسّ.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation O106 - SIOI: Groove Explorer Icon Overlay 1 (GFS Unread Stub) [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] - {99FD978C-D287-4F50-827F-B2C658EDA8E7}. (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll =>.Microsoft Corporation® O106 - SIOI: Groove Explorer Icon Overlay 2 (GFS Stub) [Groove Explorer Icon Overlay 2 (GFS Stub)] - {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}. (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll =>.Microsoft Corporation® O106 - SIOI: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] - {920E6DB1-9907-4370-B3A0-BAFC03D81399}. (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll =>.Microsoft Corporation® O106 - SIOI: Groove Explorer Icon Overlay 3 (GFS Folder) [Groove Explorer Icon Overlay 3 (GFS Folder)] - {16F3DD56-1AF5-4347-846D-7C10C4192619}. (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll =>.Microsoft Corporation® O106 - SIOI: Groove Explorer Icon Overlay 4 (GFS Unread Mark) [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] - {2916C86E-86A6-43FE-8112-43ABE6BF8DCC}. (.Microsoft Corporation - GrooveShellExtensions Module.) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll =>.Microsoft Corporation® O106 - SIOI: [Offline Files] - {4E77131D-3629-431c-9818-C5679DC83E81}. (.Microsoft Corporation - واجهة مستخدم ذاكرة التخزين المؤقت من جانب ا.) -- C:\Windows\System32\cscui.dll =>.Microsoft Corporation O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - امتداد Shell الخاص بالمشاركة.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation ---\\ Image File Execution Options (1) - 1s O50 - IFEO:C:\Windows\System32\FlashPlayerApp.exe - (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) [DisableExceptionChainValidation\\0] =>.Adobe Systems Incorporated® ---\\ System Drivers List (116) - 27s O58 - SDL:2009/07/14 04:26:15 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [422976] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:26:17 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [297552] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:26:15 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\drivers\adpu320.sys [146512] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:26:15 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [14400] =>.Microsoft Windows® O58 - SDL:2013/09/15 08:24:38 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [80256] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:26:15 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [159312] =>.Microsoft Windows® O58 - SDL:2013/09/15 08:24:38 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [22400] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:26:15 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [76368] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:26:15 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [86608] =>.Microsoft Windows® O58 - SDL:2012/11/08 14:41:32 A . (.ASMedia Technology Inc - ASMedia USB3 Hub Driver.) -- C:\Windows\System32\drivers\asmthub3.sys [110920] =>.MCCI Corporation® O58 - SDL:2012/11/08 14:41:32 A . (.ASMedia Technology Inc - ASMEDIA XHCI Host Controller Driver.) -- C:\Windows\System32\drivers\asmtxhci.sys [333128] =>.MCCI Corporation® O58 - SDL:2009/07/14 01:02:49 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60x.sys [229888] =>.Broadcom Corporation O58 - SDL:2014/03/11 06:14:02 A . (.Baidu, Inc. - Baidu Antivirus Hook Base.) -- C:\Windows\System32\drivers\Bhbase.sys [47456] =>.Baidu Online Network Technology (Beijing)Co., Ltd® O58 - SDL:2009/07/14 01:53:28 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [13568] =>.Brother Industries, Ltd. O58 - SDL:2009/07/14 01:53:28 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [5248] =>.Brother Industries, Ltd. O58 - SDL:2009/07/14 03:57:25 A . (.Brother Industries Ltd. - برنامج تشغيل I/F التسلسلي لـ Brotehr (WDM)‎.) -- C:\Windows\System32\drivers\BrSerId.sys [272128] =>.Brother Industries Ltd. O58 - SDL:2009/07/14 01:53:32 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [62336] =>.Brother Industries Ltd. O58 - SDL:2009/07/14 01:53:33 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [12160] =>.Brother Industries Ltd. O58 - SDL:2009/07/14 01:53:33 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [11904] =>.Brother Industries Ltd. O58 - SDL:2015/05/13 04:44:16 A . (.Broadcom Corporation. - Bluetooth Audio Device.) -- C:\Windows\System32\drivers\btwaudio.sys [165120] =>.Broadcom Corporation® O58 - SDL:2015/05/12 06:07:10 A . (.Broadcom Corporation. - Broadcom Bluetooth AVDT Service.) -- C:\Windows\System32\drivers\btwavdt.sys [188672] =>.Broadcom Corporation® O58 - SDL:2009/04/07 15:32:50 A . (.Broadcom Corporation. - Broadcom Bluetooth L2CAP Service.) -- C:\Windows\System32\drivers\btwl2cap.sys [29472] =>.Broadcom Corporation® O58 - SDL:2015/05/12 06:07:02 A . (.Broadcom Corporation. - Bluetooth Remote Control HID Minidriver.) -- C:\Windows\System32\drivers\btwrchid.sys [19968] =>.Broadcom Corporation® O58 - SDL:2012/03/08 12:09:40 A . (.Broadcom Corporation - Broadcom NetXtreme II Diagnostic Driver.) -- C:\Windows\System32\drivers\bxdiagx.sys [75816] =>.Broadcom Corporation® O58 - SDL:2012/02/22 19:05:54 A . (.Broadcom Corporation - FCoE offload x86 FREE.) -- C:\Windows\System32\drivers\bxfcoe.sys [150568] =>.Broadcom Corporation® O58 - SDL:2012/02/22 19:33:32 A . (.Broadcom Corporation - iSCSI offload x86 FREE.) -- C:\Windows\System32\drivers\bxois.sys [435240] =>.Broadcom Corporation® O58 - SDL:2012/01/24 18:44:14 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbdx.sys [483880] =>.Broadcom Corporation® O58 - SDL:2009/07/14 04:26:21 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [15952] =>.Microsoft Windows® O58 - SDL:2015/09/14 13:03:06 A . (...) -- C:\Windows\System32\drivers\DasPtct.SYS [38520] =>.Panda Security S.L.® O58 - SDL:2009/07/14 04:20:28 A . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\drivers\djsvs.sys [70720] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:20:28 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [453712] =>.Microsoft Windows® O58 - SDL:2012/07/24 22:58:00 A . (.Etron Technology Inc - Etron eXtensible Hub Driver..) -- C:\Windows\System32\drivers\EtronHub3.sys [65152] =>.Etron Technology Inc O58 - SDL:2012/07/24 22:58:00 A . (.Etron Technology Inc - Etron Enhance USB Mass Storage Driver..) -- C:\Windows\System32\drivers\EtronSTOR.sys [32512] =>.Etron Technology Inc O58 - SDL:2012/07/24 22:58:00 A . (.Etron Technology Inc - Etron eXtensible Host Controller Driver..) -- C:\Windows\System32\drivers\EtronXHCI.sys [88832] =>.Etron Technology Inc O58 - SDL:2013/09/04 11:23:38 A . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Backup Driver.) -- C:\Windows\System32\drivers\eubakup.sys [51784] =>.CHENGDU YIWO Tech Development Co., Ltd O58 - SDL:2013/09/04 11:23:38 A . (...) -- C:\Windows\System32\drivers\EUBKMON.sys [41544] =>.Microsoft Corporation O58 - SDL:2013/09/04 11:23:38 A . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Access Driver.) -- C:\Windows\System32\drivers\eudskacs.sys [15944] =>.CHENGDU YIWO Tech Development Co., Ltd O58 - SDL:2013/09/04 11:23:38 A . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Backup Image Preview Driver.) -- C:\Windows\System32\drivers\EuFdDisk.sys [186952] =>.CHENGDU YIWO Tech Development Co., Ltd O58 - SDL:2012/03/26 07:23:46 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbdx.sys [3194960] =>.Broadcom Corporation® O58 - SDL:2017/04/27 20:35:55 A . (.Malwarebytes - Malwarebytes Anti-Ransomware Protection.) -- C:\Windows\System32\drivers\farflt.sys [96704] =>.Malwarebytes Corporation® O58 - SDL:2009/09/09 12:23:38 A . (.Intel Corporation - BIOS Update Driver.) -- C:\Windows\System32\drivers\flashud.sys [42496] =>.Intel Corporation O58 - SDL:2009/05/18 14:17:00 A . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\System32\drivers\GEARAspiWDM.sys [26600] =>.GEAR Software Inc.® O58 - SDL:2009/09/21 20:26:10 A . (.Symantec Corporation - Symantec Corporation Generic Mount.) -- C:\Windows\System32\drivers\GenericMount.sys [46192] =>.Symantec Corporation® O58 - SDL:2009/03/18 18:35:40 AH . (.LogMeIn, Inc. - Hamachi Virtual Network Interface Driver.) -- C:\Windows\System32\drivers\hamachi.sys [26176] =>.LogMeIn, Inc.® O58 - SDL:2009/07/14 01:54:14 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [26624] =>.Hauppauge Computer Works, Inc. O58 - SDL:2009/07/14 04:20:28 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [67152] =>.Microsoft Windows® O58 - SDL:2013/09/15 08:24:38 A . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\drivers\iaStorV.sys [332160] =>.Microsoft Windows® O58 - SDL:2016/07/28 17:37:24 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\drivers\idmwfp.sys [134248] =>.Tonec Inc.® O58 - SDL:2012/03/23 03:29:58 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd32.sys [4815872] =>.Intel Corporation O58 - SDL:2009/07/14 04:20:36 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [41040] =>.Microsoft Windows® O58 - SDL:2012/12/21 08:44:10 A . (.Intel Corporation - Intel(R) USB 3.0 Hub Driver.) -- C:\Windows\System32\drivers\iusb3hub.sys [359560] =>.Intel Corporation - Software and Firmware Products® O58 - SDL:2012/12/21 08:44:10 A . (.Intel Corporation - Intel(R) USB 3.0 eXtensible Host Controller.) -- C:\Windows\System32\drivers\iusb3xhc.sys [792712] =>.Intel Corporation - Software and Firmware Products® O58 - SDL:2009/07/14 04:20:36 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [95824] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:20:37 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [89168] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:20:36 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [54864] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:20:36 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [96848] =>.Microsoft Windows® O58 - SDL:2017/03/22 11:02:44 A . (...) -- C:\Windows\System32\drivers\mbae.sys [59904] =>.Malwarebytes Corporation® O58 - SDL:2017/04/27 20:35:49 A . (.Malwarebytes - Malwarebytes Real-Time Protection.) -- C:\Windows\System32\drivers\mbam.sys [39360] =>.Malwarebytes Corporation® O58 - SDL:2017/04/27 20:04:52 A . (.Malwarebytes - Malwarebytes Chameleon.) -- C:\Windows\System32\drivers\MBAMChameleon.sys [161216] =>.Malwarebytes Corporation® O58 - SDL:2017/04/27 20:34:05 A . (.Malwarebytes - Malwarebytes SwissArmy.) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys [220088] =>.Malwarebytes Corporation® O58 - SDL:2009/07/14 04:20:36 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [30800] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:20:36 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [235584] =>.Microsoft Windows® O58 - SDL:2008/09/29 08:07:00 A . (.McAfee, Inc. - Access Protection Filter Driver.) -- C:\Windows\System32\drivers\mfeapfk.sys [74648] =>.McAfee, Inc.® O58 - SDL:2008/09/29 08:07:00 A . (.McAfee, Inc. - Anti-Virus File System Filter Driver.) -- C:\Windows\System32\drivers\mfeavfk.sys [90360] =>.McAfee, Inc.® O58 - SDL:2008/09/29 08:07:00 A . (.McAfee, Inc. - Buffer Overflow Protection Driver.) -- C:\Windows\System32\drivers\mfebopk.sys [42424] =>.McAfee, Inc.® O58 - SDL:2008/09/29 08:07:00 A . (.McAfee, Inc. - McAfee Link Driver.) -- C:\Windows\System32\drivers\mfehidk.sys [340592] =>.McAfee, Inc.® O58 - SDL:2008/09/29 08:07:00 A . (.McAfee, Inc. - McAfee Code Analysis Driver.) -- C:\Windows\System32\drivers\mferkdet.sys [64432] =>.McAfee, Inc.® O58 - SDL:2008/09/29 08:07:00 A . (.McAfee, Inc. - Anti-Virus Mini-Firewall Driver.) -- C:\Windows\System32\drivers\mfetdik.sys [62704] =>.McAfee, Inc.® O58 - SDL:2017/04/29 07:45:12 A . (.Malwarebytes - Malwarebytes Web Protection.) -- C:\Windows\System32\drivers\mwac.sys [64288] =>.Malwarebytes Corporation® O58 - SDL:2009/07/14 04:20:44 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [44624] =>.Microsoft Windows® O58 - SDL:2011/10/25 20:57:14 A . (.Renesas Electronics Corporation - USB 3.0 Hub Driver.) -- C:\Windows\System32\drivers\nusb3hub.sys [73984] =>.Renesas Electronics Corporation O58 - SDL:2011/10/25 20:57:14 A . (.Renesas Electronics Corporation - USB 3.0 Host Controller Driver.) -- C:\Windows\System32\drivers\nusb3xhc.sys [165120] =>.Renesas Electronics Corporation O58 - SDL:2013/09/15 08:24:38 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [117120] =>.Microsoft Windows® O58 - SDL:2013/09/15 08:24:38 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [143744] =>.Microsoft Windows® O58 - SDL:2015/01/29 18:21:38 A . (.Panda Security, S.L. - Panda Kernel Memory Access Driver (x86).) -- C:\Windows\System32\drivers\PSKMAD.sys [50320] =>.Panda Security S.L.® O58 - SDL:2009/07/14 04:19:04 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1383488] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:19:04 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [106064] =>.Microsoft Windows® O58 - SDL:2016/04/01 11:08:12 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.20 32-bit Dr.) -- C:\Windows\System32\drivers\Rt86win7.sys [770304] =>.Realtek Semiconductor Corp® O58 - SDL:2015/10/13 13:27:22 A . (.Realtek Semiconductor Corporation - Realtek Bluetooth Filter Driver.) -- C:\Windows\System32\drivers\RtkBtfilter.sys [542512] =>.Realtek Semiconductor Corp® O58 - SDL:2016/01/14 05:34:30 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RTKVHDA.sys [3718400] =>.Realtek Semiconductor Corp® O58 - SDL:2015/12/22 08:39:54 A . (.Realsil Semiconductor Corporation - RTS USB READER Driver.) -- C:\Windows\System32\drivers\RtsUer.sys [302808] =>.Realtek Semiconductor Corp® O58 - SDL:2014/02/27 08:32:26 A . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/V.) -- C:\Windows\System32\drivers\RtsUStor.sys [215768] =>.Realtek Semiconductor Corp® O58 - SDL:2012/08/17 07:41:50 A . (.Power Software Ltd - PowerISO Virtual Drive.) -- C:\Windows\System32\drivers\scdemu.sys [113104] =>.Power Software Ltd® O58 - SDL:2009/07/13 23:50:20 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [20480] =>.Macrovision Corporation, Macrovision Europe Limited, O58 - SDL:2009/07/14 02:45:33 A . (.Brother Industries Ltd. - برنامج تشغيل I/F التسلسلي لـ Brotehr (WDM)‎.) -- C:\Windows\System32\drivers\serial.sys [83456] =>.Brother Industries Ltd. O58 - SDL:2009/07/14 04:19:04 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [40016] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:19:04 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [77888] =>.Microsoft Windows® O58 - SDL:2016/01/08 11:51:54 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ve.) -- C:\Windows\System32\drivers\ssudbus.sys [99296] =>.Samsung Electronics CO., LTD.® O58 - SDL:2016/01/08 11:51:54 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ve.) -- C:\Windows\System32\drivers\ssudmdm.sys [191200] =>.Samsung Electronics CO., LTD.® O58 - SDL:2009/07/14 04:19:04 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [21072] =>.Microsoft Windows® O58 - SDL:2016/04/21 12:05:12 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\Windows\System32\drivers\tap0901.sys [23040] =>.The OpenVPN Project O58 - SDL:2017/04/24 21:43:17 A . (...) -- C:\Windows\System32\drivers\TrueSight.sys [30848] =>.Adlice® O58 - SDL:2009/07/14 04:19:10 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [16976] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:19:11 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [141904] =>.Microsoft Windows® O58 - SDL:2009/02/13 11:02:52 A . (.Western Digital Technologies - WD SCSI Architecture Model (SAM) driver.) -- C:\Windows\System32\drivers\wdcsam.sys [11520] =>.Western Digital Technologies O58 - SDL:2012/02/22 17:27:02 A . (.Bigfoot Networks, Inc. - Bigfoot Networks Killer(TM) PCI-E Gaming Ad.) -- C:\Windows\System32\drivers\Xeno7x86.sys [130152] =>.Bigfoot Networks, Inc.® O58 - SDL:2013/05/07 14:27:10 A . (...) -- C:\Windows\System32\ambakdrv.sys [26424] =>.AOMEI Tech Co O58 - SDL:2013/05/07 14:27:10 A . (...) -- C:\Windows\System32\ammntdrv.sys [129720] =>.AOMEI Tech Co O58 - SDL:2013/02/06 15:52:48 A . (...) -- C:\Windows\System32\amwrtdrv.sys [14392] =>.AOMEI Tech Co O58 - SDL:2009/07/14 00:40:41 A . (...) -- C:\Windows\System32\ANSI.SYS [9029] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:40:44 A . (...) -- C:\Windows\System32\country.sys [27097] =>.Microsoft Corporation O58 - SDL:2017/03/02 13:26:10 AH . (.LogMeIn, Inc. - Hamachi Virtual Network Interface Driver.) -- C:\Windows\System32\hamachi.sys [27040] =>.LogMeIn, Inc.® O58 - SDL:2009/07/14 00:40:40 A . (...) -- C:\Windows\System32\HIMEM.SYS [4768] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:40:43 A . (...) -- C:\Windows\System32\KEY01.SYS [42809] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:40:43 A . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:40:23 A . (...) -- C:\Windows\System32\NTDOS.SYS [27866] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:40:31 A . (...) -- C:\Windows\System32\NTDOS404.SYS [29146] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:40:35 A . (...) -- C:\Windows\System32\NTDOS411.SYS [29370] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:40:39 A . (...) -- C:\Windows\System32\NTDOS412.SYS [29274] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:40:27 A . (...) -- C:\Windows\System32\NTDOS804.SYS [29146] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:40:11 A . (...) -- C:\Windows\System32\NTIO.SYS [33952] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:40:15 A . (...) -- C:\Windows\System32\NTIO404.SYS [34672] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:40:17 A . (...) -- C:\Windows\System32\NTIO411.SYS [35776] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:40:19 A . (...) -- C:\Windows\System32\NTIO412.SYS [35536] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:40:13 A . (...) -- C:\Windows\System32\NTIO804.SYS [34672] =>.Microsoft Corporation O58 - SDL:2011/06/21 18:22:42 A . (...) -- C:\Windows\System32\WinVd32.sys [180224] ---\\ File Associations Shell Spawning (10) - 0s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - ‎‎مشغل الأداة الإضافية لعارض الأحداث.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - ‎‎محرر التسجيل.) -- C:\Windows\regedit.exe =>.Microsoft Corporation O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S ---\\ Start Menu Internet (16) - 1s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\mozilla firefox\firefox.exe =>.Mozilla Corporation® O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc® O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\tarek\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc® O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\mozilla firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Users\tarek\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\mozilla firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Users\tarek\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\mozilla firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Users\tarek\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation ---\\ Search Browser Infection (2) - 17s O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ =>.Bing.com O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com ---\\ Search Svchost Services (33) - 1s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\Windows\System32\aelupsvc.dll [62464] =>.Microsoft Corporation O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - خدمة نشر شهادة البطاقة الذكية لـ Microsoft.) -- C:\Windows\System32\certprop.dll [67584] =>.Microsoft Corporation O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - خدمة نشر شهادة البطاقة الذكية لـ Microsoft.) -- C:\Windows\System32\certprop.dll [67584] =>.Microsoft Corporation O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمة الخادم.) -- C:\Windows\System32\srvsvc.dll [168960] =>.Microsoft Corporation O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - عميل نهج المجموعة.) -- C:\Windows\System32\gpsvc.dll [593408] =>.Microsoft Corporation O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\IKEEXT.DLL [674304] =>.Microsoft Corporation O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - خدمة صوت Windows.) -- C:\Windows\System32\audiosrv.dll [473600] =>.Microsoft Corporation O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - إدارة الطلب التلقائي للوصول عن بُعد.) -- C:\Windows\System32\rasauto.dll [90624] =>.Microsoft Corporation O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [286208] =>.Microsoft Corporation O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [75264] =>.Microsoft Corporation O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - خدمة الإعلام بأحداث النظام (SENS).) -- C:\Windows\System32\Sens.dll [49664] =>.Microsoft Corporation O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [300544] =>.Microsoft Corporation O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [242176] =>.Microsoft Corporation O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remote Desktop Session Host Server Remote C.) -- C:\Windows\System32\termsrv.dll [521216] =>.Microsoft Corporation O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - عامل Windows Update.) -- C:\Windows\System32\wuaueng.dll [1914368] =>.Microsoft Corporation O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - خدمة النقل الذكي في الخلفية.) -- C:\Windows\System32\qmgr.dll [585728] =>.Microsoft Corporation O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمات Windows Sh.) -- C:\Windows\System32\shsvcs.dll [328192] =>.Microsoft Corporation O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [499712] =>.Microsoft Corporation O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي الخاصة بخدمة تسجي.) -- C:\Windows\System32\seclogon.dll [21504] =>.Microsoft Corporation O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - خدمة معلومات التطبيقات.) -- C:\Windows\System32\appinfo.dll [47104] =>.Microsoft Corporation O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - خدمة اكتشاف iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688] =>.Microsoft Corporation O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - خدمة جدولة فئات تعدد الوسائط.) -- C:\Windows\System32\mmcss.dll [49664] =>.Microsoft Corporation O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - تقارير المشاكل وحلولها.) -- C:\Windows\System32\wercplsupport.dll [61440] =>.Microsoft Corporation O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [98304] =>.Microsoft Corporation O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164352] =>.Microsoft Corporation O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - خدمة جدولة المهام.) -- C:\Windows\System32\schedsvc.dll [750592] =>.Microsoft Corporation O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\Windows\System32\KMSVC.DLL [71168] =>.Microsoft Corporation O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - خدمة تكوين سطح المكتب البعيد.) -- C:\Windows\System32\SessEnv.dll [113664] =>.Microsoft Corporation O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960] =>.Microsoft Corporation O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمة مستعرض الكم.) -- C:\Windows\System32\browser.dll [102912] =>.Microsoft Corporation O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمات نُسق Windo.) -- C:\Windows\System32\themeservice.dll [37376] =>.Microsoft Corporation O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - خدمة BDE.) -- C:\Windows\System32\bdesvc.dll [76800] =>.Microsoft Corporation O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - خدمة تثبت البرامج.) -- C:\Windows\System32\appmgmts.dll [149504] =>.Microsoft Corporation ---\\ Firewall Active Exception List (32) - 9s O87 - FAEL: "TCP Query User{FAD67125-F0BE-43B5-B3BB-FFBD4AA15675}C:\users\tarek\appdata\roaming\utorrent\updates\3.4.1_31139.exe" [In-None-P6-TRUE] .(...) -- C:\users\tarek\appdata\roaming\utorrent\updates\3.4.1_31139.exe (.not file.) O87 - FAEL: "UDP Query User{760A6F47-3CE9-4D4A-89D9-9B22F0DEF9A1}C:\users\tarek\appdata\roaming\utorrent\updates\3.4.1_31139.exe" [In-None-P17-TRUE] .(...) -- C:\users\tarek\appdata\roaming\utorrent\updates\3.4.1_31139.exe (.not file.) O87 - FAEL: "{2E8BDBA0-A85A-499B-A624-9468DF800F57}" [In-None-P6-TRUE] .(...) -- C:\Program Files\ma-config.com\MaConfigAgent.exe (.not file.) O87 - FAEL: "{2A50E66A-DAA0-42E7-8289-EC737BA77A60}" [In-None-P17-TRUE] .(...) -- C:\Program Files\ma-config.com\MaConfigAgent.exe (.not file.) O87 - FAEL: "{429959E0-8DC8-41DC-BA8C-07250FB07FC0}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Google\Google Talk\googletalk.exe (.not file.) O87 - FAEL: "{69BE5AE8-DBD4-40D2-8557-91B5EE3F0D02}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Google\Google Talk\googletalk.exe (.not file.) O87 - FAEL: "{9FCA35EF-FBA2-4F02-86BA-2EA5E8AD5415}" [In-None-P6-TRUE] .(...) -- C:\Program Files\TeamViewer\Version9\TeamViewer.exe (.not file.) O87 - FAEL: "{B1A80AC1-60E0-4398-BF5F-E828605CE36B}" [In-None-P17-TRUE] .(...) -- C:\Program Files\TeamViewer\Version9\TeamViewer.exe (.not file.) O87 - FAEL: "{65D57ACC-9D05-40E8-BCC1-EB28EA21F1B2}" [In-None-P6-TRUE] .(...) -- C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe (.not file.) O87 - FAEL: "{5C2FB76E-A24A-4896-B6AC-84FD3C33DAE6}" [In-None-P17-TRUE] .(...) -- C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe (.not file.) O87 - FAEL: "TCP Query User{E972BF86-B96E-4C22-A18C-0129E6632084}C:\program files\utorrent\utorrent.exe" [In-None-P6-TRUE] .(...) -- C:\program files\utorrent\utorrent.exe (.not file.) O87 - FAEL: "UDP Query User{DB80F296-DE8A-486E-A267-A9E9A97A0133}C:\program files\utorrent\utorrent.exe" [In-None-P17-TRUE] .(...) -- C:\program files\utorrent\utorrent.exe (.not file.) O87 - FAEL: "TCP Query User{BEEAF802-33E3-48BE-BD7C-5CB89C3102C7}C:\program files\wondershare\mirrorgo\mirrorgo.exe" [In-None-P6-TRUE] .(...) -- C:\program files\wondershare\mirrorgo\mirrorgo.exe (.not file.) O87 - FAEL: "UDP Query User{39FE48D7-D7BD-4267-BEE0-0C3CAE4239AC}C:\program files\wondershare\mirrorgo\mirrorgo.exe" [In-None-P17-TRUE] .(...) -- C:\program files\wondershare\mirrorgo\mirrorgo.exe (.not file.) O87 - FAEL: "{5FFDC5BA-24AE-4D28-8930-14147FC9C746}" [In-None-P6-TRUE] .(...) -- C:\Program Files\DriversCloud.com\MCDetection.exe (.not file.) O87 - FAEL: "{7510FAF6-E9DA-466B-BCE2-71D7314D238F}" [In-None-P17-TRUE] .(...) -- C:\Program Files\DriversCloud.com\MCDetection.exe (.not file.) O87 - FAEL: "{EF6D003F-6642-48A9-9F35-F24C8C470407}" [In-None-P17-TRUE] .(...) -- C:\program files\common files\tencent\qqdownload\130\bugreport_xf.exe (.not file.) =>.Superfluous.Tencent O87 - FAEL: "{1FB68232-10E3-43BE-8C02-FFF16C0DD863}" [In-None-P17-TRUE] .(...) -- C:\program files\common files\tencent\qqdownload\130\tencentdl.exe (.not file.) =>.Superfluous.Tencent O87 - FAEL: "TCP Query User{0EFA326C-D1E6-4CB6-8192-FF33EE742D75}C:\program files\adsafe\adsafe.exe" [In-None-P6-TRUE] .(...) -- C:\program files\adsafe\adsafe.exe (.not file.) O87 - FAEL: "UDP Query User{DAD86119-3096-4993-A201-CB421B943D51}C:\program files\adsafe\adsafe.exe" [In-None-P17-TRUE] .(...) -- C:\program files\adsafe\adsafe.exe (.not file.) O87 - FAEL: "{2F4946F8-FFD6-41B7-BB9E-D3CA975B5398}" [In-None-P17-TRUE] .(...) -- C:\Program Files\ADSafe\ADSafeSvc.exe (.not file.) O87 - FAEL: "{2E0BD9A5-FC47-49F6-9EA7-D4F510DF2038}" [In-None-P17-TRUE] .(...) -- C:\Program Files\ADSafe\ADSafe.exe (.not file.) O87 - FAEL: "{2BC42A70-8F1E-401A-BC2A-74B49E5076B9}" [In-None-P6-TRUE] .(...) -- G:\العاب\بيس 10 و12\بيس 10 باتش gaming كاس العالم\PES 2010\2010 FIFA World Cup.exe (.not file.) O87 - FAEL: "{C9290034-A514-49C6-9753-A6CFEC437CBD}" [In-None-P17-TRUE] .(...) -- G:\العاب\بيس 10 و12\بيس 10 باتش gaming كاس العالم\PES 2010\2010 FIFA World Cup.exe (.not file.) O87 - FAEL: "{7223C815-EF66-4CA8-9C82-467CB0DB8335}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Sitech\Phenix\Phenix.exe (.not file.) O87 - FAEL: "{8DE4CC82-83E2-41E2-8564-DBEFBCEDB0CB}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Sitech\Phenix\Phenix.exe (.not file.) O87 - FAEL: "{1B59EE76-9966-4C92-A879-0F77081E44E0}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Bonjour\mDNSResponder.exe (.not file.) O87 - FAEL: "{A46224C3-CAFA-486E-9755-131EAB31E9E3}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Bonjour\mDNSResponder.exe (.not file.) O87 - FAEL: "TCP Query User{0467441E-B016-42D5-8FC7-42821531CDDB}C:\program files\wondershare\mobilego\mobilegoservice.exe" [In-None-P6-TRUE] .(...) -- C:\program files\wondershare\mobilego\mobilegoservice.exe (.not file.) O87 - FAEL: "UDP Query User{6B0824CF-6964-451A-A628-C975095848FD}C:\program files\wondershare\mobilego\mobilegoservice.exe" [In-None-P17-TRUE] .(...) -- C:\program files\wondershare\mobilego\mobilegoservice.exe (.not file.) O87 - FAEL: "TCP Query User{8FFE1FC2-4C0F-4400-A3BA-2C1FAE85B8B5}C:\program files\wondershare\mobilego\mobilego.exe" [In-None-P6-TRUE] .(...) -- C:\program files\wondershare\mobilego\mobilego.exe (.not file.) O87 - FAEL: "UDP Query User{7242D3B2-CB7A-464F-865B-6997453BE006}C:\program files\wondershare\mobilego\mobilego.exe" [In-None-P17-TRUE] .(...) -- C:\program files\wondershare\mobilego\mobilego.exe (.not file.) ---\\ Additional Scan (O88) (8) - 1s HKLM\SYSTEM\CurrentControlSet\Services\KMService =>PUP.Optional.Office C:\Windows\System32\srvany.exe =>PUP.Optional.Office HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>Heuristic.Suspect HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>Heuristic.Suspect C:\Program Files\uTorrent =>.Superfluous.Empty C:\Users\tarek\AppData\Roaming\HMYGSetting =>Adware.Suspect [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{EF6D003F-6642-48A9-9F35-F24C8C470407} =>.Superfluous.Tencent [HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{1FB68232-10E3-43BE-8C02-FFF16C0DD863} =>.Superfluous.Tencent ---\\ Summary of the elements found (8) - 0s https://www.nicolascoolman.com/fr/hijacker-office/ =>PUP.Optional.Office https://www.nicolascoolman.com/fr/trojan-vonteera/ =>PUP.Optional.Vonteera https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Magicbit https://nicolascoolman.eu/2017/01/28/heuristic-suspect/ =>Heuristic.Suspect https://nicolascoolman.eu/2017/02/23/tencentadressbar/ =>.Superfluous.Tencent https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Downloader https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Empty https://nicolascoolman.eu/2017/03/02/adware-suspect/ =>Adware.Suspect ~ Unselected Options: O82, ~ End of the scan, 31696 items in 14mn22s (1375)(0)