~ ZHPDiag v2020.9.11.230 By Nicolas Coolman (2020/09/11) ~ Run by lonly (Administrator) (2020/09/13 17:52:20) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Certificate ZHPDiag: Legal ~ State version: Version OK ~ Mode: Scan ~ Report: C:\Users\lonly\Desktop\ZHPDiag.txt ~ Report: C:\Users\lonly\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Deactivate ~ System startup: Normal (Normal boot) Windows 7 Ultimate, 32-bit Service Pack 1 (Build 7601) =>.Microsoft Corporation ---\\ Internet Browsers (3) - 0s ~ MFIE: Mozilla Firefox 80.0.1 (x86 en-US) ~ OPIE: Opera 70.0.3728.178 ~ MSIE: Internet Explorer v8.0.7601.17514 ---\\ Windows Product Information (4) - 3s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK Windows Activation Technologies : KO ---\\ System optimization software (1) - 0s ~ CCleaner v5.69 (Optimisation) ---\\ Sharing software PeerToPeer (1) - 0s ~ µTorrent v3.5.5.45790 (P2P) ---\\ Informations on the system (6) - 0s ~ Operating System: x86 Family 6 Model 15 Stepping 13, GenuineIntel ~ Operating System: 32-bit ~ Boot mode: Normal (Normal boot) Total RAM: 3010.56 MB (79% free) : OK =>.RAM Value System Restore: Activé (Enable) System drive C: has 62 GB (62%) free of 99 GB : OK =>.Disk Space ---\\ Connection to the system mode (3) - 0s ~ Computer Name: LONLY-PC ~ User Name: lonly ~ Logged in as Administrator ---\\ Enumeration of the disk units (2) - 0s ~ Drive C: has 62 GB free of 99 GB (System) ~ Drive D: has 19 GB free of 205 GB ---\\ State of the Windows Security Center (10) - 0s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK ---\\ Search Generic System Files (26) - 1s [MD5.6DDCA324434FFA506CF7DC4E51DB7935] - 20/04/2020 - (.Microsoft Corporation - Windows Explorer.) -- C:\Windows\Explorer.exe [2972672] [Unsigned] =>.Microsoft Corporation [MD5.C648901695E275C8F2AD04B687A68CE2] - 20/04/2020 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe [45056] [Unsigned] =>.Microsoft Corporation [MD5.B5C5DCAD3899512020D135600129D665] - 14/07/2009 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\Windows\System32\Wininit.exe [96256] [Unsigned] =>.Microsoft Corporation [MD5.44214C94911C7CFB1D52CB64D5E8368D] - 20/11/2010 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\Windows\System32\wininet.dll [980992] [Unsigned] =>.Microsoft Corporation [MD5.C5A164338B12BFBEBA2EB55757A27E8B] - 20/04/2020 - (.Microsoft Corporation - Windows Logon Application.) -- C:\Windows\System32\Winlogon.exe [304640] [Unsigned] =>.Microsoft Corporation [MD5.E3AE23569749DE12D45BA3B489A036AE] - 20/11/2010 - (.Microsoft Corporation - Software Licensing Library.) -- C:\Windows\System32\sppcomapi.dll [193536] [Unsigned] =>.Microsoft Corporation [MD5.4A35D7B172AFF9C6B362D7297568836A] - 20/04/2020 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\System32\dnsapi.dll [269824] [Unsigned] =>.Microsoft Corporation [MD5.7E53EACF9C5D57D0B5FCBD79AE974293] - 20/04/2020 - (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\System32\wuaueng.dll [2091520] [Unsigned] =>.Microsoft Corporation [MD5.06D05195ACAD2DE2F63861F96DB6AAA0] - 21/04/2020 - (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\System32\wuaueng2.dll [2091520] [Unsigned] =>.Microsoft Corporation [MD5.F582FC7976F1248AC5FBD6875C626B41] - 20/04/2020 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [338944] [Unsigned] =>.Microsoft Corporation [MD5.F288A334552C9FCB72C7CEFD9F27D0B5] - 20/04/2020 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [21224] =>.Microsoft® [MD5.B840B24D3BDBB4ADEF9FA890AE1EDD07] - 20/04/2020 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [70656] [Unsigned] =>.Microsoft Corporation [MD5.6BA23E2886FAEC9C7E242207EE7C77BE] - 20/04/2020 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [108544] [Unsigned] =>.Microsoft Corporation [MD5.7A067803AD6DAA139DA74334E1BCEA82] - 20/04/2020 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [88576] [Unsigned] =>.Microsoft Corporation [MD5.C04A9F1C9CA1EA822B97C6DC70419E6B] - 20/04/2020 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [109056] [Unsigned] =>.Microsoft Corporation [MD5.062E2C01AB2FD69EEA2FAF3A484DC4CA] - 20/04/2020 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\Windows\System32\drivers\i8042prt.sys [80896] [Unsigned] =>.Microsoft Corporation [MD5.F2107EB61ACBB1166F75DC9719E2597D] - 20/04/2020 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [101888] [Unsigned] =>.Microsoft Corporation [MD5.5F6B0A8A468AA1C7A694A77B68EC50B2] - 20/04/2020 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [126464] [Unsigned] =>.Microsoft Corporation [MD5.01B4CBF175B5CA311D29830F8C4D6251] - 20/04/2020 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [188928] [Unsigned] =>.Microsoft Corporation [MD5.F475235756CFBAF569E59CA932DBE6DF] - 20/04/2020 - (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\drivers\ntfs.sys [1216736] =>.Microsoft® [MD5.DA82266D907CAAB2351D2E99113CE75E] - 20/04/2020 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\Windows\System32\drivers\Parport.sys [79360] [Unsigned] =>.Microsoft Corporation [MD5.D9F91EAFEC2815365CBE6D167E4E332A] - 14/07/2009 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [78848] [Unsigned] =>.Microsoft Corporation [MD5.3BB042D86B9225A2D92EC5B52929F5E9] - 20/04/2020 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [133632] [Unsigned] =>.Microsoft Corporation [MD5.3E21C083B8A01CB70BA1F09303010FCE] - 14/07/2009 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [71168] [Unsigned] =>.Microsoft Corporation [MD5.8F143F86FDD8CF4F7BD25973C5983F9D] - 20/04/2020 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [74752] [Unsigned] =>.Microsoft Corporation [MD5.F4C6A1AE619F644C1C4A5F18171AD078] - 20/04/2020 - (.Microsoft Corporation - Volume Shadow Copy Driver.) -- C:\Windows\System32\drivers\volsnap.sys [246504] =>.Microsoft® ---\\ No disabled Windows Services (45) - 3s O23 - Service: C:\Windows\System32\audiosrv.dll (AudioEndpointBuilder) . (.Microsoft Corporation - Windows Audio Service.) - C:\Windows\System32\audiosrv.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\audiosrv.dll (Audiosrv) . (.Microsoft Corporation - Windows Audio Service.) - C:\Windows\System32\audiosrv.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\BFE.DLL (BFE) . (.Microsoft Corporation - Base Filtering Engine.) - C:\Windows\System32\BFE.DLL [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\qmgr.dll (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) - C:\Windows\System32\qmgr.dll [Unsigned] =>.Microsoft Corporation O23 - Service: Microsoft .NET Framework NGEN v4.0.30319_X86 (clr_optimization_v4.0.30319_32) . (.Microsoft Corporation - .NET Runtime Optimization Service.) - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe =>.Microsoft® O23 - Service: C:\Windows\System32\cryptsvc.dll (CryptSvc) . (.Microsoft Corporation - Cryptographic Services.) - C:\Windows\System32\cryptsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\cscsvc.dll (CscService) . (.Microsoft Corporation - CSC Service DLL.) - C:\Windows\System32\cscsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\dhcpcore.dll (Dhcp) . (.Microsoft Corporation - DHCP Client Service.) - C:\Windows\System32\dhcpcore.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\dnsapi.dll (Dnscache) . (.Microsoft Corporation - DNS Caching Resolver Service.) - C:\Windows\System32\dnsrslvr.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\wevtsvc.dll (eventlog) . (.Microsoft Corporation - Host Process for Windows Services.) - C:\Windows\System32\svchost.exe [Unsigned] =>.Microsoft Corporation O23 - Service: @comres.dll,-2450 (EventSystem) . (.Microsoft Corporation - COM+.) - C:\Windows\System32\es.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\FDResPub.dll (FDResPub) . (.Microsoft Corporation - Function Discovery Resource Publication Ser.) - C:\Windows\System32\FDResPub.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\FntCache.dll (FontCache) . (.Microsoft Corporation - Windows Font Cache Service.) - C:\Windows\System32\FntCache.dll [Unsigned] =>.Microsoft Corporation O23 - Service: Foxit PhantomPDF Update Service (FoxitPhantomPDFUpdateService) . (.Foxit Software Inc. - Foxit PhantomPDF Update Service.) - C:\Program Files\Foxit Software\Foxit PhantomPDF\FoxitPhantomPDFUpdateService.exe =>.FOXIT SOFTWARE INC.® O23 - Service: Foxit Reader Update Service (FoxitReaderUpdateService) . (.Foxit Software Inc. - Foxit Reader Update Service.) - C:\Program Files\Foxit Software\Foxit Reader\FoxitReaderUpdateService.exe =>.FOXIT SOFTWARE INC.® O23 - Service: @gpapi.dll,-112 (gpsvc) . (.Microsoft Corporation - Group Policy Client.) - C:\Windows\System32\gpsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\IKEEXT.DLL (IKEEXT) . (.Microsoft Corporation - IKE extension.) - C:\Windows\System32\IKEEXT.DLL [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\iphlpsvc.dll (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) - C:\Windows\System32\iphlpsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\srvsvc.dll (LanmanServer) . (.Microsoft Corporation - Server Service DLL.) - C:\Windows\System32\srvsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\wkssvc.dll (LanmanWorkstation) . (.Microsoft Corporation - Workstation Service DLL.) - C:\Windows\System32\wkssvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\lmhsvc.dll (lmhosts) . (.Microsoft Corporation - TCPIP NetBios Transport Services DLL.) - C:\Windows\System32\lmhsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\mmcss.dll (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) - C:\Windows\System32\mmcss.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\FirewallAPI.dll (MpsSvc) . (.Microsoft Corporation - Microsoft Protection Service.) - C:\Windows\System32\MPSSVC.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\nlasvc.dll (NlaSvc) . (.Microsoft Corporation - Network Location Awareness 2.) - C:\Windows\System32\nlasvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: nordvpn-service (nordvpn-service) . (.TEFINCOM S.A. - NordVPN.) - C:\Program Files\NordVPN\nordvpn-service.exe =>.TEFINCOM S.A.® O23 - Service: C:\Windows\System32\nsisvc.dll (nsi) . (.Microsoft Corporation - Network Store Interface RPC server.) - C:\Windows\System32\nsisvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\umpnpmgr.dll (PlugPlay) . (.Microsoft Corporation - User-mode Plug-and-Play Service.) - C:\Windows\System32\umpnpmgr.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\umpo.dll (Power) . (.Microsoft Corporation - User-mode Power Service.) - C:\Windows\System32\umpo.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\profsvc.dll (ProfSvc) . (.Microsoft Corporation - ProfSvc.) - C:\Windows\System32\profsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\RpcEpMap.dll (RpcEptMapper) . (.Microsoft Corporation - RPC Endpoint Mapper.) - C:\Windows\System32\RpcEpMap.dll [Unsigned] =>.Microsoft Corporation O23 - Service: @oleres.dll,-5010 (RpcSs) . (.Microsoft Corporation - Distributed COM Services.) - C:\Windows\System32\rpcss.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\schedsvc.dll (Schedule) . (.Microsoft Corporation - Task Scheduler Service.) - C:\Windows\System32\schedsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\Sens.dll (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) - C:\Windows\System32\Sens.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\shsvcs.dll (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) - C:\Windows\System32\shsvcs.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\spoolsv.exe,-1 (Spooler) . (.Microsoft Corporation - Spooler SubSystem App.) - C:\Windows\System32\spoolsv.exe [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\sppsvc.exe,-101 (sppsvc) . (.Microsoft Corporation - Microsoft Software Protection Platform Serv.) - C:\Windows\System32\sppsvc.exe [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\wiaservc.dll (StiSvc) . (.Microsoft Corporation - Still Image Devices Service.) - C:\Windows\System32\wiaservc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\sysmain.dll (SysMain) . (.Microsoft Corporation - Superfetch Service Host.) - C:\Windows\System32\sysmain.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\themeservice.dll (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) - C:\Windows\System32\themeservice.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\dwm.exe,-2000 (UxSms) . (.Microsoft Corporation - Microsoft User Experience Session Managemen.) - C:\Windows\System32\uxsms.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\wbem\WMIsvc.dll (Winmgmt) . (.Microsoft Corporation - WMI.) - C:\Windows\System32\wbem\WMIsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\wlansvc.dll (Wlansvc) . (.Microsoft Corporation - Windows WLAN AutoConfig Service DLL.) - C:\Windows\System32\wlansvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\wscsvc.dll (wscsvc) . (.Microsoft Corporation - Windows Security Center Service.) - C:\Windows\System32\wscsvc.dll [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\SearchIndexer.exe,-103 (WSearch) . (.Microsoft Corporation - Microsoft Windows Search Indexer.) - C:\Windows\System32\SearchIndexer.exe [Unsigned] =>.Microsoft Corporation O23 - Service: C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) - C:\Windows\System32\wuaueng2.dll [Unsigned] =>.Microsoft Corporation ---\\ Services not Microsoft (SR=Run, SS=Stop) (75) - 13s SR - Demand [14/07/2009] [ 422976] (adp94xx) . (.Adaptec, Inc..) - C:\Windows\System32\drivers\adp94xx.sys =>.Microsoft Windows® SR - Demand [14/07/2009] [ 297552] (adpahci) . (.Adaptec, Inc..) - C:\Windows\System32\drivers\adpahci.sys =>.Microsoft Windows® SR - Demand [14/07/2009] [ 146512] (adpu320) . (.Adaptec, Inc..) - C:\Windows\System32\drivers\adpu320.sys =>.Microsoft Windows® SR - Demand [14/07/2009] [ 70720] (aic78xx) . (.Adaptec, Inc..) - C:\Windows\System32\drivers\djsvs.sys =>.Microsoft Windows® SR - Demand [20/04/2020] [ 14056] (aliide) . (.Acer Laboratories Inc..) - C:\Windows\System32\drivers\aliide.sys =>.Microsoft® SR - Demand [20/04/2020] [ 80104] (amdsata) . (.Advanced Micro Devices.) - C:\Windows\System32\drivers\amdsata.sys =>.Microsoft® SR - Demand [14/07/2009] [ 159312] (amdsbs) . (.AMD Technologies Inc..) - C:\Windows\System32\drivers\amdsbs.sys =>.Microsoft Windows® SR - Boot [20/04/2020] [ 22248] (amdxata) . (.Advanced Micro Devices.) - C:\Windows\System32\drivers\amdxata.sys =>.Microsoft® SR - Demand [14/07/2009] [ 76368] (arc) . (.Adaptec, Inc..) - C:\Windows\System32\drivers\arc.sys =>.Microsoft Windows® SR - Demand [14/07/2009] [ 86608] (arcsas) . (.Adaptec, Inc..) - C:\Windows\System32\drivers\arcsas.sys =>.Microsoft Windows® SR - Demand [13/12/2011] [ 2228224] Atheros Extensible Wireless LAN device driver (athr) . (.Atheros Communications, Inc..) - C:\Windows\System32\drivers\athr.sys [Unsigned] =>.Atheros Communications, Inc. SR - Demand [24/01/2012] [ 483880] (b06bdrv) . (.Broadcom Corporation.) - C:\Windows\System32\drivers\bxvbdx.sys =>.Broadcom Corporation® SR - Demand [08/03/2012] [ 75816] Broadcom NetXtreme II Diag Driver (b06diag) . (.Broadcom Corporation.) - C:\Windows\System32\drivers\bxdiagx.sys =>.Broadcom Corporation® SR - Demand [13/07/2009] [ 229888] Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 (b57nd60x) . (.Broadcom Corporation.) - C:\Windows\System32\drivers\b57nd60x.sys [Unsigned] =>.Broadcom Corporation SR - Demand [22/02/2012] [ 130152] Bigfoot Networks Killer Gaming Service (BFN7x86) . (.Bigfoot Networks, Inc..) - C:\Windows\System32\drivers\Xeno7x86.sys =>.Bigfoot Networks, Inc.® SR - Demand [13/07/2009] [ 13568] Brother USB Mass-Storage Lower Filter Driver (BrFiltLo) . (.Brother Industries, Ltd..) - C:\Windows\System32\drivers\BrFiltLo.sys [Unsigned] =>.Brother Industries, Ltd. SR - Demand [13/07/2009] [ 5248] Brother USB Mass-Storage Upper Filter Driver (BrFiltUp) . (.Brother Industries, Ltd..) - C:\Windows\System32\drivers\BrFiltUp.sys [Unsigned] =>.Brother Industries, Ltd. SR - Demand [14/07/2009] [ 272128] Brother MFC Serial Port Interface Driver (WDM) (Brserid) . (.Brother Industries Ltd..) - C:\Windows\System32\drivers\BrSerId.sys [Unsigned] =>.Brother Industries Ltd. SR - Demand [13/07/2009] [ 62336] Brother WDM Serial driver (BrSerWdm) . (.Brother Industries Ltd..) - C:\Windows\System32\drivers\BrSerWdm.sys [Unsigned] =>.Brother Industries Ltd. SR - Demand [13/07/2009] [ 12160] Brother MFC USB Fax Only Modem (BrUsbMdm) . (.Brother Industries Ltd..) - C:\Windows\System32\drivers\BrUsbMdm.sys [Unsigned] =>.Brother Industries Ltd. SR - Demand [13/07/2009] [ 11904] Brother MFC USB Serial WDM Driver (BrUsbSer) . (.Brother Industries Ltd..) - C:\Windows\System32\drivers\BrUsbSer.sys [Unsigned] =>.Brother Industries Ltd. SR - Demand [22/02/2012] [ 150568] (bxfcoe) . (.Broadcom Corporation.) - C:\Windows\System32\drivers\bxfcoe.sys =>.Broadcom Corporation® SR - Demand [22/02/2012] [ 435240] (bxois) . (.Broadcom Corporation.) - C:\Windows\System32\drivers\bxois.sys =>.Broadcom Corporation® SR - Demand [20/04/2020] [ 15592] (cmdide) . (.CMD Technology, Inc..) - C:\Windows\System32\drivers\cmdide.sys =>.Microsoft® SR - Demand [13/07/2009] [ 118784] Intel(R) PRO/1000 NDIS 6 Adapter Driver (E1G60) . (.Intel Corporation.) - C:\Windows\System32\drivers\E1G60I32.sys [Unsigned] =>.Intel Corporation SR - Demand [13/07/2009] [ 3100160] Broadcom NetXtreme II 10 GigE VBD (ebdrv) . (.Broadcom Corporation.) - C:\Windows\System32\drivers\evbdx.sys [Unsigned] =>.Broadcom Corporation SR - Demand [14/07/2009] [ 453712] (elxstor) . (.Emulex.) - C:\Windows\System32\drivers\elxstor.sys =>.Microsoft Windows® SR - Auto [29/04/2020] [ 1995184] Foxit PhantomPDF Update Service (FoxitPhantomPDFUpdateService) . (.Foxit Software Inc..) - C:\Program Files\Foxit Software\Foxit PhantomPDF\FoxitPhantomPDFUpdateService.exe =>.FOXIT SOFTWARE INC.® SR - Auto [29/04/2020] [ 1995184] Foxit Reader Update Service (FoxitReaderUpdateService) . (.Foxit Software Inc..) - C:\Program Files\Foxit Software\Foxit Reader\FoxitReaderUpdateService.exe =>.FOXIT SOFTWARE INC.® SR - Demand [13/07/2009] [ 26624] Hauppauge Consumer Infrared Receiver (hcw85cir) . (.Hauppauge Computer Works, Inc..) - C:\Windows\System32\drivers\hcw85cir.sys [Unsigned] =>.Hauppauge Computer Works, Inc. SR - Demand [14/07/2009] [ 67152] (HpSAMD) . (.Hewlett-Packard Company.) - C:\Windows\System32\drivers\HpSAMD.sys =>.Microsoft Windows® SR - System [30/04/2020] [ 23840] HWiNFO32/64 Kernel Driver (HWiNFO32) . (.REALiX(tm).) - C:\Windows\System32\drivers\HWiNFO32.SYS =>.Martin Malik - REALiX® SR - Demand [25/04/2018] [ 120816] (IaNVMe) . (.Intel Corporation.) - C:\Windows\System32\drivers\IaNVMe.sys {330000C10A26A958EEA067060C00020000C10A}. =>.Intel Corporation SR - Boot [25/04/2018] [ 33768] (IaNVMeF) . (.Intel Corporation.) - C:\Windows\System32\drivers\IaNVMeF.sys {330000C10A26A958EEA067060C00020000C10A}. =>.Intel Corporation SR - Demand [20/04/2020] [ 332008] (iaStorV) . (.Intel Corporation.) - C:\Windows\System32\drivers\iaStorV.sys =>.Microsoft® SR - Auto [20/12/2018] [ 151872] IDMWFP (IDMWFP) . (.Tonec Inc..) - C:\Windows\System32\drivers\idmwfp.sys =>.Tonec Inc.® SR - Demand [30/04/2020] [ 5946368] (igfx) . (.Intel Corporation.) - C:\Windows\System32\drivers\igdkmd32.sys [Unsigned] =>.Intel Corporation SR - Demand [14/07/2009] [ 41040] (iirsp) . (.Intel Corp./ICP vortex GmbH.) - C:\Windows\System32\drivers\iirsp.sys =>.Microsoft Windows® SR - Disabl [00/00/0000] [ 0] IUFileFilter (IUFileFilter) . (...) - C:\PROGRA~1\IObit\IOBITU~1\drivers\win7_x86\IUFileFilter.sys (.not file.) [Unsigned] SR - Demand [00/00/0000] [ 0] IUProcessFilter (IUProcessFilter) . (...) - C:\PROGRA~1\IObit\IOBITU~1\drivers\win7_x86\IUProcessFilter.sys (.not file.) [Unsigned] SR - Demand [00/00/0000] [ 0] IURegistryFilter (IURegistryFilter) . (...) - C:\PROGRA~1\IObit\IOBITU~1\drivers\win7_x86\IURegistryFilter.sys (.not file.) [Unsigned] SR - Demand [14/07/2009] [ 95824] (LSI_FC) . (.LSI Corporation.) - C:\Windows\System32\drivers\lsi_fc.sys =>.Microsoft Windows® SR - Demand [14/07/2009] [ 89168] (LSI_SAS) . (.LSI Corporation.) - C:\Windows\System32\drivers\lsi_sas.sys =>.Microsoft Windows® SR - Demand [14/07/2009] [ 54864] (LSI_SAS2) . (.LSI Corporation.) - C:\Windows\System32\drivers\lsi_sas2.sys =>.Microsoft Windows® SR - Demand [14/07/2009] [ 96848] (LSI_SCSI) . (.LSI Corporation.) - C:\Windows\System32\drivers\lsi_scsi.sys =>.Microsoft Windows® SR - Demand [14/07/2009] [ 30800] (megasas) . (.LSI Corporation.) - C:\Windows\System32\drivers\megasas.sys =>.Microsoft Windows® SR - Demand [14/07/2009] [ 235584] (MegaSR) . (.LSI Corporation, Inc..) - C:\Windows\System32\drivers\MegaSR.sys =>.Microsoft Windows® SS - Demand [03/04/2020] [ 223432] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation® SR - Demand [10/05/2016] [ 101864] (mtinvme) . (.Micron Technology, Inc..) - C:\Windows\System32\drivers\mtinvme.sys {0EFEAFE9BF5BACB6FFA5881DF9EA0A1A}. =>.Micron Technology, Inc. SR - Demand [14/07/2009] [ 44624] (nfrd960) . (.IBM Corporation.) - C:\Windows\System32\drivers\nfrd960.sys =>.Microsoft Windows® SR - Demand [10/06/2020] [ 27336] Nlwt (nlwt) . (.WireGuard LLC.) - C:\Windows\System32\drivers\nlwt.sys =>.TEFINCOM S.A.® SR - System [05/08/2020] [ 26816] NordVPN LightWeight Firewall (nordlwf) . (.TEFINCOM S.A..) - C:\Windows\System32\drivers\nordlwf.sys =>.TEFINCOM S.A.® SR - Auto [05/08/2020] [ 248080] nordvpn-service (nordvpn-service) . (.TEFINCOM S.A..) - C:\Program Files\NordVPN\nordvpn-service.exe =>.TEFINCOM S.A.® SR - Demand [00/00/0000] [ 0] NPF (NPF) . (...) - \D:\Programe\New folder (2)\npf.sys (.not file.) [Unsigned] SR - Demand [17/08/2016] [ 64688] (nvme) . (. {38A6B946724226498C48291D33CFCDD3}..) - C:\Windows\System32\drivers\nvme.sys {38A6B946724226498C48291D33CFCDD3}. SR - Demand [20/04/2020] [ 116968] (nvraid) . (.NVIDIA Corporation.) - C:\Windows\System32\drivers\nvraid.sys =>.Microsoft® SR - Demand [20/04/2020] [ 143592] (nvstor) . (.NVIDIA Corporation.) - C:\Windows\System32\drivers\nvstor.sys =>.Microsoft® SR - Demand [10/06/2016] [ 83624] (ocznvme) . (.TOSHIBA CORPORATION.) - C:\Windows\System32\drivers\ocznvme.sys =>.Toshiba America Electronic Components, Inc.® SR - Boot [10/06/2016] [ 25936] SSD Device Filter (ocztrimfilter) . (.TOSHIBA CORPORATION.) - C:\Windows\System32\drivers\ocztrimfilter.sys =>.Toshiba America Electronic Components, Inc.® SR - Demand [14/07/2009] [ 1383488] (ql2300) . (.QLogic Corporation.) - C:\Windows\System32\drivers\ql2300.sys =>.Microsoft Windows® SR - Demand [14/07/2009] [ 106064] (ql40xx) . (.QLogic Corporation.) - C:\Windows\System32\drivers\ql40xx.sys =>.Microsoft Windows® SR - Demand [25/10/2012] [ 585872] Realtek 8167 NT Driver (RTL8167) . (.Realtek.) - C:\Windows\System32\drivers\Rt86win7.sys =>.Realtek Semiconductor Corp® SR - Demand [13/02/2018] [ 75360] (secnvme) . (.Samsung Electronics Co., Ltd.) - C:\Windows\System32\drivers\secnvme.sys =>.Samsung Electronics Co., Ltd.® SR - Boot [13/02/2018] [ 28528] (secnvmeF) . (.Samsung Electronics Co., Ltd.) - C:\Windows\System32\drivers\secnvmeF.sys =>.Samsung Electronics Co., Ltd.® SR - Demand [20/04/2020] [ 83968] (Serial) . (.Brother Industries Ltd..) - C:\Windows\System32\drivers\serial.sys [Unsigned] =>.Brother Industries Ltd. SR - Demand [14/07/2009] [ 40016] (SiSRaid2) . (.Silicon Integrated Systems Corp..) - C:\Windows\System32\drivers\sisraid2.sys =>.Microsoft Windows® SR - Demand [14/07/2009] [ 77888] (SiSRaid4) . (.Silicon Integrated Systems.) - C:\Windows\System32\drivers\sisraid4.sys =>.Microsoft Windows® SR - Demand [13/07/2009] [ 207360] (SrvHsfHDA) . (.Conexant Systems, Inc..) - C:\Windows\System32\drivers\VSTAZL3.SYS [Unsigned] =>.Conexant Systems, Inc. SR - Demand [13/07/2009] [ 980992] (SrvHsfV92) . (.Conexant Systems, Inc..) - C:\Windows\System32\drivers\VSTDPV3.SYS [Unsigned] =>.Conexant Systems, Inc. SR - Demand [13/07/2009] [ 661504] (SrvHsfWinac) . (.Conexant Systems, Inc..) - C:\Windows\System32\drivers\VSTCNXT3.SYS [Unsigned] =>.Conexant Systems, Inc. SR - Demand [14/07/2009] [ 21072] (stexstor) . (.Promise Technology.) - C:\Windows\System32\drivers\stexstor.sys =>.Microsoft Windows® SR - Demand [09/06/2020] [ 31496] TAP-NordVPN Windows Adapter V9 (tapnordvpn) . (.The OpenVPN Project.) - C:\Windows\System32\drivers\tapnordvpn.sys =>.TEFINCOM S.A.® SR - Demand [00/00/0000] [ 0] (VGPU) . (...) - C:\Windows\System32\drivers\rdvgkmd.sys (.not file.) [Unsigned] SR - Demand [20/04/2020] [ 16616] (viaide) . (.VIA Technologies, Inc..) - C:\Windows\System32\drivers\viaide.sys =>.Microsoft® SR - Demand [14/07/2009] [ 141904] (vsmraid) . (.VIA Technologies Inc.,Ltd.) - C:\Windows\System32\drivers\vsmraid.sys =>.Microsoft Windows® ---\\ Task Planned Automatically (Register) (10) - 5s O38 - TASK: {4DB42EA8-67EB-44DE-B5A7-4C56D4FF0CB4}[\Opera scheduled assistant Autoupdate 1588794218] - (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opa\launcher.exe [1335320] =>.Opera Software O38 - TASK: {565EC037-3B86-4AC0-AA75-055907357FE1}[\Opera GX scheduled Autoupdate 1599070457] - (...) -- C:\Users\lonly\AppData\Local\Programs\Opera GX\launcher.exe [1314328] O38 - TASK: {99F8C6CC-D34D-42D6-8DF6-A4DBCD49250C}[\CCleaner Update] - (.Piriform Software Ltd - CCleaner emergency updater.) -- C:\Program Files\CCleaner\CCUpdate.exe [686384] =>.Piriform Software Ltd O38 - TASK: {CC765CEF-EC54-45AD-B596-C21543A8779D}[\Opera scheduled Autoupdate 1588793633] - (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opa\launcher.exe [1335320] =>.Opera Software O38 - TASK: {D0D9DE2F-80FB-4BEA-84BC-0B1496FC5458}[\CCleanerSkipUAC] - (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe [24910520] =>.Piriform Software Ltd C:\Windows\System32\Tasks\Opera scheduled assistant Autoupdate 1588794218 - (.Opera Software.) -- C:\Program Files\Opa\launcher.exe [--scheduledautoupdate --component-name=assistant --component-path="C:\Program Files\Opa\assistant" .] =>.Opera Software C:\Windows\System32\Tasks\Opera GX scheduled Autoupdate 1599070457 - (...) -- C:\Users\lonly\AppData\Local\Programs\Opera GX\launcher.exe [--scheduledautoupdate .--scheduledautoupdate] C:\Windows\System32\Tasks\CCleaner Update - (.Piriform Software Ltd.) -- C:\Program Files\CCleaner\CCUpdate.exe [] =>.Piriform Software Ltd C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1588793633 - (.Opera Software.) -- C:\Program Files\Opa\launcher.exe [--scheduledautoupdate .--scheduledautoupdate] =>.Opera Software C:\Windows\System32\Tasks\CCleanerSkipUAC - (.Piriform Software Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [$(Arg0)] =>.Piriform Software Ltd ---\\ Auto loading programs from Registry and folders (18) - 2s O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\System32\hkcmd.exe =>.Intel Corporation® O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe =>.Intel Corporation® O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe =>.Oracle America, Inc.® O4 - HKLM\..\Run: [BCSSync] . (.Microsoft Corporation - Microsoft Office 2010 component.) -- C:\Program Files\Microsoft Office\Office14\BCSSync.exe =>.Microsoft Corporation® O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe [Unsigned] =>.Tonec Inc. O4 - HKCU\..\Run: [Web Companion] . (.Lavasoft - Web Companion.) -- C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe =>PUP.Optional.LavasoftWebCompanion O4 - HKCU\..\Run: [uTorrent] . (...) -- C:\Users\lonly\AppData\Roaming\uTorrent\uTorrent.exe [Unsigned] O4 - HKCU\..\Run: [CCleaner Smart Cleaning] . (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Software Ltd® O4 - HKCU\..\Run: [Opera Browser Assistant] . (.Opera Software - Opera Browser Assistant.) -- C:\Program Files\Opa\assistant\browser_assistant.exe =>.Opera Software AS® O4 - HKCU\..\Run: [NordVPN] . (.TEFINCOM S.A. - NordVPN.) -- C:\Program Files\NordVPN\NordVPN.exe =>.TEFINCOM S.A.® O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe [Unsigned] =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe [Unsigned] =>.Microsoft Corporation O4 - HKUS\S-1-5-21-1335184104-3918391407-3771364805-1000\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe [Unsigned] =>.Tonec Inc. O4 - HKUS\S-1-5-21-1335184104-3918391407-3771364805-1000\..\Run: [Web Companion] . (.Lavasoft - Web Companion.) -- C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe =>PUP.Optional.LavasoftWebCompanion O4 - HKUS\S-1-5-21-1335184104-3918391407-3771364805-1000\..\Run: [uTorrent] . (...) -- C:\Users\lonly\AppData\Roaming\uTorrent\uTorrent.exe [Unsigned] O4 - HKUS\S-1-5-21-1335184104-3918391407-3771364805-1000\..\Run: [CCleaner Smart Cleaning] . (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Software Ltd® O4 - HKUS\S-1-5-21-1335184104-3918391407-3771364805-1000\..\Run: [Opera Browser Assistant] . (.Opera Software - Opera Browser Assistant.) -- C:\Program Files\Opa\assistant\browser_assistant.exe =>.Opera Software AS® O4 - HKUS\S-1-5-21-1335184104-3918391407-3771364805-1000\..\Run: [NordVPN] . (.TEFINCOM S.A. - NordVPN.) -- C:\Program Files\NordVPN\NordVPN.exe =>.TEFINCOM S.A.® ---\\ Process running (11) - 2s [MD5.35AB885D5102DAB468B47E0DFA208477] - (.Foxit Software Inc. - Foxit PhantomPDF Update Service.) -- C:\Program Files\Foxit Software\Foxit PhantomPDF\FoxitPhantomPDFUpdateService.exe [1995184] [PID.1572] =>.FOXIT SOFTWARE INC.® [MD5.E2BACC0D33E55BEE235154773FBA700A] - (.Foxit Software Inc. - Foxit Reader Update Service.) -- C:\Program Files\Foxit Software\Foxit Reader\FoxitReaderUpdateService.exe [1995184] [PID.1604] =>.FOXIT SOFTWARE INC.® [MD5.729276EEA86D28B020C837E74BDC3038] - (.TEFINCOM S.A. - NordVPN.) -- C:\Program Files\NordVPN\nordvpn-service.exe [248080] [PID.1684] =>.TEFINCOM S.A.® [MD5.17BA811DA9E17F74F529B6EFA1CF61C5] - (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe [151064] [PID.2488] =>.Intel Corporation® [MD5.0AC7A7E1293322F9FC415BAE839600E3] - (.Intel Corporation - hkcmd Module.) -- C:\Windows\System32\hkcmd.exe [174104] [PID.2496] =>.Intel Corporation® [MD5.15556E800CE3434F583C2D7B1189A5E2] - (.Intel Corporation - igfxTray Module.) -- C:\Windows\System32\igfxtray.exe [141848] [PID.2504] =>.Intel Corporation® [MD5.EE451AFC24AF84979429FAC7DF6188A0] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe [3994736] [PID.2524] [Unsigned] =>.Tonec Inc. [MD5.054E5B2861F2AF8E41E13CC2E436A245] - (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe [646776] [PID.2544] =>.Oracle America, Inc.® [MD5.84EB5313FA2063E37D09239ACA8F4AC7] - (.Intel Corporation - igfxsrvc Module.) -- C:\Windows\System32\igfxsrvc.exe [252952] [PID.2664] =>.Intel Corporation® [MD5.7631C33878C331D7396679B0C391FCA8] - (.Tonec Inc. - Internet Download Manager agent for click m.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe [384312] [PID.3452] =>.Tonec Inc.® [MD5.420C25CF191D23D71CD74401A720A84A] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\lonly\Downloads\ZHPDiag3.exe [3306368] [PID.3440] [Unsigned] =>.Nicolas Coolman ---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (20) - 2s P2 - EXT FILE: (.Default Search Engine - Default-search-engine.) -- C:\Users\lonly\AppData\Roaming\Mozilla\Firefox\Profiles\bjwvsb0f.default-release\searchplugins\yahoo.xml [Unsigned] =>PUP.Optional.BDYahoo P2 - EXT FILE: (.Legitimate.) -- C:\Program Files\Mozilla Firefox\browser\features\doh-rollout@mozilla.org.xpi [Unsigned] P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\browser\features\formautofill@mozilla.org.xpi [Unsigned] =>.Mozilla Corporation P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi [Unsigned] =>.Mozilla Corporation P2 - EXT FILE: (.webcompat.com.) -- C:\Program Files\Mozilla Firefox\browser\features\webcompat-reporter@mozilla.org.xpi [Unsigned] =>.webcompat.com P2 - EXT FILE: (.webcompat.com.) -- C:\Program Files\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi [Unsigned] =>.webcompat.com C:\Users\lonly\AppData\Roaming\Mozilla\Firefox\Profiles\bjwvsb0f.default-release\bookmarkbackups =>Mozilla Corporation C:\Users\lonly\AppData\Roaming\Mozilla\Firefox\Profiles\bjwvsb0f.default-release\crashes =>Mozilla Corporation C:\Users\lonly\AppData\Roaming\Mozilla\Firefox\Profiles\bjwvsb0f.default-release\datareporting =>Mozilla Corporation C:\Users\lonly\AppData\Roaming\Mozilla\Firefox\Profiles\bjwvsb0f.default-release\extensions =>Mozilla Corporation C:\Users\lonly\AppData\Roaming\Mozilla\Firefox\Profiles\bjwvsb0f.default-release\gmp =>Mozilla Corporation C:\Users\lonly\AppData\Roaming\Mozilla\Firefox\Profiles\bjwvsb0f.default-release\gmp-gmpopenh264 =>Mozilla Corporation C:\Users\lonly\AppData\Roaming\Mozilla\Firefox\Profiles\bjwvsb0f.default-release\gmp-widevinecdm =>Mozilla Corporation C:\Users\lonly\AppData\Roaming\Mozilla\Firefox\Profiles\bjwvsb0f.default-release\minidumps =>Mozilla Corporation C:\Users\lonly\AppData\Roaming\Mozilla\Firefox\Profiles\bjwvsb0f.default-release\saved-telemetry-pings =>Mozilla Corporation C:\Users\lonly\AppData\Roaming\Mozilla\Firefox\Profiles\bjwvsb0f.default-release\searchplugins =>Mozilla Corporation C:\Users\lonly\AppData\Roaming\Mozilla\Firefox\Profiles\bjwvsb0f.default-release\security_state =>Mozilla Corporation C:\Users\lonly\AppData\Roaming\Mozilla\Firefox\Profiles\bjwvsb0f.default-release\sessionstore-backups =>Mozilla Corporation C:\Users\lonly\AppData\Roaming\Mozilla\Firefox\Profiles\bjwvsb0f.default-release\storage =>Mozilla Corporation C:\Users\lonly\AppData\Roaming\Mozilla\Firefox\Profiles\bjwvsb0f.default-release\weave =>Mozilla Corporation ---\\ Internet Explorer Extensions, Start, Search (10) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Browser.) (8.00.7600.16385 (win7_rtm.090713-1255)) -- C:\Windows\System32\ieframe.dll =>.Microsoft Corporation ---\\ INTERNET EXPLORER, trusted site and sensitive site (4) - 0s ~ IE Restricted Site Good: localhost IE Restricted Site Good: webcompanion.com =>PUP.Optional.LavasoftWebCompanion ~ Microsoft Internet Explorer Restricted Site(s) Domains: 2(Good) / 0(Bad) ~ Microsoft Internet Explorer Restricted Site(s) EscDomains: 0(Good) / 0(Bad) ---\\ Internet Explorer, Proxy Management (5) - 0s R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 =>.Default.Value R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 =>.Default.Value R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 =>.Default.Value R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft ---\\ Line Analysis, IniFiles, Auto loading programs (3) - 1s F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: VMApplet=C:\Windows\system32\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation ---\\ Hosts file redirection (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (21) ---\\ Browser Helper Object (BHO) (6) - 0s O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files\Internet Download Manager\IDMIECC.dll =>.Tonec Inc.® O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_251\bin\ssv.dll =>.Oracle America, Inc.® O2 - BHO: Foxit PhantomPDF Create PDF ToolBar Helper - {A5DD10F7-5ABB-4EEF-B4C8-6748D44DAF2A} . (...) -- C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll =>.FOXIT SOFTWARE INC.® O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL =>.Microsoft Corporation® O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_251\bin\jp2ssv.dll =>.Oracle America, Inc.® ---\\ Internet Explorer Toolbars (1) - 0s O3 - Toolbar: 0x00 - [HKLM]{BFD9D8A8-57FF-488A-B919-065EC77CF82F} . (...) -- C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll =>.FOXIT SOFTWARE INC.® ---\\ Global shortcuts Startup (114) - 15s O4 - GS\Desktop [Administrator]: CS 1.6 Original EN.lnk . (...) C:\Games\CS 1.6 Original EN\Counter-Strike.bat [Unsigned] O4 - GS\Desktop [Administrator]: Discord.lnk . (...) C:\Users\lonly\AppData\Local\Discord\Update.exe --processStart Discord.exe [Unsigned] O4 - GS\Desktop [Administrator]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files\Internet Download Manager\IDMan.exe [Unsigned] =>.Tonec Inc. O4 - GS\Desktop [Administrator]: MPC-HC.lnk . (.MPC-HC Team - MPC-HC.) C:\Program Files\MPC-HC\mpc-hc.exe =>.Fotis Zafiropoulos® O4 - GS\Desktop [Administrator]: NordVPN.lnk . (.TEFINCOM S.A. - NordVPN.) C:\Program Files\NordVPN\NordVPN.exe =>.TEFINCOM S.A.® O4 - GS\Desktop [Administrator]: Opera Browser.lnk . (.Opera Software - Opera Internet Browser.) C:\Program Files\Opa\launcher.exe --disable-update =>.Opera Software AS® O4 - GS\Desktop [Administrator]: Opera GX Browser.lnk . (...) C:\Users\lonly\AppData\Local\Programs\Opera GX\launcher.exe [Unsigned] O4 - GS\Desktop [Administrator]: Tactical Ops.lnk . (...) C:\Tactical Ops\System\TacticalOps.exe [Unsigned] O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\lonly\AppData\Roaming\ZHP\ZHPDiag3.exe [Unsigned] =>.Nicolas Coolman O4 - GS\Desktop [Administrator]: µTorrent.lnk . (...) C:\Users\lonly\AppData\Roaming\uTorrent\uTorrent.exe [Unsigned] O4 - GS\Quicklaunch [Administrator]: Foxit Reader.lnk . (.Foxit Software Inc. - Foxit Reader 10.0.) C:\Program Files\Foxit Software\Foxit Reader\FoxitReader.exe =>.FOXIT SOFTWARE INC.® O4 - GS\Quicklaunch [Administrator]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\Quicklaunch [Administrator]: µTorrent.lnk . (...) C:\Users\lonly\AppData\Roaming\uTorrent\uTorrent.exe [Unsigned] O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo [Unsigned] =>.Microsoft Corporation O4 - GS\TaskBar [Administrator]: Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\TaskBar [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\TaskBar [Administrator]: Opera Browser.lnk . (.Opera Software - Opera Internet Browser.) C:\Program Files\Opa\launcher.exe --disable-update =>.Opera Software AS® O4 - GS\TaskBar [Administrator]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe [Unsigned] =>.Microsoft Corporation O4 - GS\TaskBar [Administrator]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:1 [Unsigned] =>.Microsoft Corporation O4 - GS\Programs [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\Programs [Administrator]: Opera Browser.lnk . (.Opera Software - Opera Internet Browser.) C:\Program Files\Opa\launcher.exe =>.Opera Software AS® O4 - GS\Programs [Administrator]: Opera GX Browser.lnk . (...) C:\Users\lonly\AppData\Local\Programs\Opera GX\launcher.exe [Unsigned] O4 - GS\Programs [Administrator]: uTorrent Web.lnk . (...) C:\Users\lonly\AppData\Roaming\uTorrent Web\utweb.exe [Unsigned] O4 - GS\Desktop [Guest]: CS 1.6 Original EN.lnk . (...) C:\Games\CS 1.6 Original EN\Counter-Strike.bat [Unsigned] O4 - GS\Desktop [Guest]: Discord.lnk . (...) C:\Users\lonly\AppData\Local\Discord\Update.exe --processStart Discord.exe [Unsigned] O4 - GS\Desktop [Guest]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files\Internet Download Manager\IDMan.exe [Unsigned] =>.Tonec Inc. O4 - GS\Desktop [Guest]: MPC-HC.lnk . (.MPC-HC Team - MPC-HC.) C:\Program Files\MPC-HC\mpc-hc.exe =>.Fotis Zafiropoulos® O4 - GS\Desktop [Guest]: NordVPN.lnk . (.TEFINCOM S.A. - NordVPN.) C:\Program Files\NordVPN\NordVPN.exe =>.TEFINCOM S.A.® O4 - GS\Desktop [Guest]: Opera Browser.lnk . (.Opera Software - Opera Internet Browser.) C:\Program Files\Opa\launcher.exe --disable-update =>.Opera Software AS® O4 - GS\Desktop [Guest]: Opera GX Browser.lnk . (...) C:\Users\lonly\AppData\Local\Programs\Opera GX\launcher.exe [Unsigned] O4 - GS\Desktop [Guest]: Tactical Ops.lnk . (...) C:\Tactical Ops\System\TacticalOps.exe [Unsigned] O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\lonly\AppData\Roaming\ZHP\ZHPDiag3.exe [Unsigned] =>.Nicolas Coolman O4 - GS\Desktop [Guest]: µTorrent.lnk . (...) C:\Users\lonly\AppData\Roaming\uTorrent\uTorrent.exe [Unsigned] O4 - GS\Quicklaunch [Guest]: Foxit Reader.lnk . (.Foxit Software Inc. - Foxit Reader 10.0.) C:\Program Files\Foxit Software\Foxit Reader\FoxitReader.exe =>.FOXIT SOFTWARE INC.® O4 - GS\Quicklaunch [Guest]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\Quicklaunch [Guest]: µTorrent.lnk . (...) C:\Users\lonly\AppData\Roaming\uTorrent\uTorrent.exe [Unsigned] O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo [Unsigned] =>.Microsoft Corporation O4 - GS\TaskBar [Guest]: Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\TaskBar [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\TaskBar [Guest]: Opera Browser.lnk . (.Opera Software - Opera Internet Browser.) C:\Program Files\Opa\launcher.exe --disable-update =>.Opera Software AS® O4 - GS\TaskBar [Guest]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe [Unsigned] =>.Microsoft Corporation O4 - GS\TaskBar [Guest]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:1 [Unsigned] =>.Microsoft Corporation O4 - GS\Programs [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\Programs [Guest]: Opera Browser.lnk . (.Opera Software - Opera Internet Browser.) C:\Program Files\Opa\launcher.exe =>.Opera Software AS® O4 - GS\Programs [Guest]: Opera GX Browser.lnk . (...) C:\Users\lonly\AppData\Local\Programs\Opera GX\launcher.exe [Unsigned] O4 - GS\Programs [Guest]: uTorrent Web.lnk . (...) C:\Users\lonly\AppData\Roaming\uTorrent Web\utweb.exe [Unsigned] O4 - GS\Desktop [lonly]: CS 1.6 Original EN.lnk . (...) C:\Games\CS 1.6 Original EN\Counter-Strike.bat [Unsigned] O4 - GS\Desktop [lonly]: Discord.lnk . (...) C:\Users\lonly\AppData\Local\Discord\Update.exe --processStart Discord.exe [Unsigned] O4 - GS\Desktop [lonly]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files\Internet Download Manager\IDMan.exe [Unsigned] =>.Tonec Inc. O4 - GS\Desktop [lonly]: MPC-HC.lnk . (.MPC-HC Team - MPC-HC.) C:\Program Files\MPC-HC\mpc-hc.exe =>.Fotis Zafiropoulos® O4 - GS\Desktop [lonly]: NordVPN.lnk . (.TEFINCOM S.A. - NordVPN.) C:\Program Files\NordVPN\NordVPN.exe =>.TEFINCOM S.A.® O4 - GS\Desktop [lonly]: Opera Browser.lnk . (.Opera Software - Opera Internet Browser.) C:\Program Files\Opa\launcher.exe --disable-update =>.Opera Software AS® O4 - GS\Desktop [lonly]: Opera GX Browser.lnk . (...) C:\Users\lonly\AppData\Local\Programs\Opera GX\launcher.exe [Unsigned] O4 - GS\Desktop [lonly]: Tactical Ops.lnk . (...) C:\Tactical Ops\System\TacticalOps.exe [Unsigned] O4 - GS\Desktop [lonly]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\lonly\AppData\Roaming\ZHP\ZHPDiag3.exe [Unsigned] =>.Nicolas Coolman O4 - GS\Desktop [lonly]: µTorrent.lnk . (...) C:\Users\lonly\AppData\Roaming\uTorrent\uTorrent.exe [Unsigned] O4 - GS\Quicklaunch [lonly]: Foxit Reader.lnk . (.Foxit Software Inc. - Foxit Reader 10.0.) C:\Program Files\Foxit Software\Foxit Reader\FoxitReader.exe =>.FOXIT SOFTWARE INC.® O4 - GS\Quicklaunch [lonly]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\Quicklaunch [lonly]: µTorrent.lnk . (...) C:\Users\lonly\AppData\Roaming\uTorrent\uTorrent.exe [Unsigned] O4 - GS\sendTo [lonly]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo [Unsigned] =>.Microsoft Corporation O4 - GS\TaskBar [lonly]: Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\TaskBar [lonly]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\TaskBar [lonly]: Opera Browser.lnk . (.Opera Software - Opera Internet Browser.) C:\Program Files\Opa\launcher.exe --disable-update =>.Opera Software AS® O4 - GS\TaskBar [lonly]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe [Unsigned] =>.Microsoft Corporation O4 - GS\TaskBar [lonly]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:1 [Unsigned] =>.Microsoft Corporation O4 - GS\Programs [lonly]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\Programs [lonly]: Opera Browser.lnk . (.Opera Software - Opera Internet Browser.) C:\Program Files\Opa\launcher.exe =>.Opera Software AS® O4 - GS\Programs [lonly]: Opera GX Browser.lnk . (...) C:\Users\lonly\AppData\Local\Programs\Opera GX\launcher.exe [Unsigned] O4 - GS\Programs [lonly]: uTorrent Web.lnk . (...) C:\Users\lonly\AppData\Roaming\uTorrent Web\utweb.exe [Unsigned] O4 - GS\CommonDesktop [Public]: AssaultCube.lnk . (...) C:\Program Files\AssaultCube\assaultcube.bat [Unsigned] O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Software Ltd - CCleaner.) C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Software Ltd® O4 - GS\CommonDesktop [Public]: Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\CommonDesktop [Public]: Foxit PhantomPDF.lnk . (.Foxit Software Inc. - Foxit PhantomPDF 10.0.) C:\Program Files\Foxit Software\Foxit PhantomPDF\FoxitPhantomPDF.exe =>.FOXIT SOFTWARE INC.® O4 - GS\CommonDesktop [Public]: Foxit Reader.lnk . (.Foxit Software Inc. - Foxit Reader 10.0.) C:\Program Files\Foxit Software\Foxit Reader\FoxitReader.exe =>.FOXIT SOFTWARE INC.® O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files\VideoLAN\VLC\vlc.exe =>.VideoLAN® O4 - GS\CommonDesktop [Public]: Windows IPTV Player.lnk . (.Xtream Codes LTD - Windows IPTV Player.) C:\Program Files\Xtream Codes LTD\Windows IPTV Player\WindowsIPTVPlayer.exe [Unsigned] O4 - GS\Programs [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\Programs [Public]: Opera Browser.lnk . (.Opera Software - Opera Internet Browser.) C:\Program Files\Opa\launcher.exe =>.Opera Software AS® O4 - GS\Programs [Public]: Opera GX Browser.lnk . (...) C:\Users\lonly\AppData\Local\Programs\Opera GX\launcher.exe [Unsigned] O4 - GS\Programs [Public]: uTorrent Web.lnk . (...) C:\Users\lonly\AppData\Roaming\uTorrent Web\utweb.exe [Unsigned] O4 - GS\Accessories [Public]: Command Prompt.lnk . (.Microsoft Corporation - Windows Command Processor.) C:\Windows\system32\cmd.exe [Unsigned] =>.Microsoft Corporation O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\Windows\system32\notepad.exe [Unsigned] =>.Microsoft Corporation O4 - GS\Accessories [Public]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe [Unsigned] =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe -extoff =>.Microsoft Corporation® O4 - GS\SystemTools [Public]: Private Character Editor.lnk . (.Microsoft Corporation - Private Character Editor.) C:\Windows\system32\eudcedit.exe [Unsigned] =>.Microsoft Corporation O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Windows Calculator.) C:\Windows\system32\calc.exe [Unsigned] =>.Microsoft Corporation O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - Display Switch.) C:\Windows\system32\displayswitch.exe [Unsigned] =>.Microsoft Corporation O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Math Input Panel Accessory.) C:\Program Files\Common Files\Microsoft Shared\Ink\mip.exe [Unsigned] =>.Microsoft Corporation O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - Windows Mobility Center.) C:\Windows\system32\mblctr.exe /open [Unsigned] =>.Microsoft Corporation O4 - GS\Accessories [Public]: NetworkProjection.lnk . (.Microsoft Corporation - Connect to a Network Projector.) C:\Windows\system32\NetProj.exe [Unsigned] =>.Microsoft Corporation O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\Windows\system32\mspaint.exe [Unsigned] =>.Microsoft Corporation O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\Windows\system32\mstsc.exe [Unsigned] =>.Microsoft Corporation O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe [Unsigned] =>.Microsoft Corporation O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Windows Sound Recorder.) C:\Windows\system32\SoundRecorder.exe [Unsigned] =>.Microsoft Corporation O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - Sticky Notes.) C:\Windows\system32\StikyNot.exe [Unsigned] =>.Microsoft Corporation O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) C:\Windows\System32\mobsync.exe [Unsigned] =>.Microsoft Corporation O4 - GS\Accessories [Public]: Welcome Center.lnk . (.Microsoft Corporation - Windows host process (Rundll32).) C:\Windows\system32\rundll32.exe %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut [Unsigned] =>..Microsoft Corporation O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files\Windows NT\Accessories\wordpad.exe [Unsigned] =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) C:\Windows\system32\charmap.exe [Unsigned] =>.Microsoft Corporation O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - Microsoft® Disk Defragmenter.) C:\Windows\system32\dfrgui.exe [Unsigned] =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - Disk Space Cleanup Manager for Windows.) C:\Windows\system32\cleanmgr.exe [Unsigned] =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - Resource and Performance Monitor.) C:\Windows\system32\perfmon.exe /res [Unsigned] =>.Microsoft Corporation O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - System Information.) C:\Windows\system32\msinfo32.exe [Unsigned] =>.Microsoft Corporation O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - Microsoft® Windows System Restore.) C:\Windows\system32\rstrui.exe [Unsigned] =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) C:\Windows\system32\taskschd.msc /s [Unsigned] =>..Microsoft Corporation O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - Windows Easy Transfer Post Migration Applic.) C:\Windows\system32\migwiz\postmig.exe [Unsigned] =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - Windows Easy Transfer Application.) C:\Windows\system32\migwiz\migwiz.exe [Unsigned] =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\ProgramsCommon [Public]: Media Center.lnk . (.Microsoft Corporation - Windows Media Center.) C:\Windows\ehome\ehshell.exe [Unsigned] =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Sidebar.lnk . (.Microsoft Corporation - Windows Desktop Gadgets.) C:\Program Files\Windows Sidebar\sidebar.exe /showgadgets [Unsigned] =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Windows DVD Maker.lnk . (.Microsoft Corporation - Windows DVD Maker.) C:\Program Files\DVD Maker\DVDMaker.exe [Unsigned] =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe [Unsigned] =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:1 [Unsigned] =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: XPS Viewer.lnk . (.Microsoft Corporation - XPS Viewer.) C:\Windows\system32\xpsrchvw.exe [Unsigned] =>.Microsoft Corporation ---\\ Lop.com/Domain Hijackers (2) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 =>.Local IP Adress O17 - HKLM\System\CCS\Services\Tcpip\..\{DD3D2B6B-F015-4FA6-B2C3-81ADA1F0EABD}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress ---\\ Extra protocols (24) - 1s O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\System32\MSVidCtl.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll =>.Microsoft Corporation® O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\System32\MSVidCtl.dll [Unsigned] =>.Microsoft Corporation O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll [Unsigned] =>.Microsoft Corporation O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll [Unsigned] =>.Microsoft Corporation O18 - Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL =>.Microsoft Corporation® ---\\ AppInit_DLLs Registry value Autorun (1) - 0s O20 - Winlogon : UserInit . (.Microsoft Corporation - Userinit Logon Application.) - C:\Windows\system32\userinit.exe =>.Microsoft Corporation ---\\ ASIC (ActiveSetup Installed Components) (7) - 2s O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll [Unsigned] =>.Microsoft Corporation O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - Microsoft(C) Register Server.) -- C:\Windows\System32\regsvr32.exe [Unsigned] =>.Microsoft Corporation O40 - ASIC: Internet Explorer - {2D46B6DC-2207-486B-B523-A557E6D54B47} . (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe [Unsigned] =>.Microsoft Corporation O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe [Unsigned] =>.Microsoft Corporation O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Microsoft Windows Media Player Setup Utilit.) -- C:\Windows\System32\unregmp2.exe [Unsigned] =>.Microsoft Corporation O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe [Unsigned] =>.Microsoft Corporation O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll =>.Microsoft® ---\\ Software installed (68) - 19s O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU] -- uTorrent [Unsigned] O42 - Logiciel: 7-Zip 19.00 - (.Igor Pavlov.) [HKLM] -- 7-Zip [Unsigned] =>.Igor Pavlov O42 - Logiciel: AssaultCube 1.2.0.2 - (.Rabid Viper Productions.) [HKLM] -- AssaultCube [Unsigned] O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner =>.Piriform Software Ltd® O42 - Logiciel: Counter-strike 1.6 - (.Valve Original.) [HKLM] -- Counter-strike 1.6 [Unsigned] O42 - Logiciel: Discord - (.Discord Inc..) [HKCU] -- Discord [Unsigned] =>.Discord Inc. O42 - Logiciel: Foxit PhantomPDF - (.Foxit Software Inc..) [HKLM] -- {a54f485e-8a55-11ea-bf0f-54bf64a63c26} [Unsigned] =>.Foxit Software Inc. (Hidden) O42 - Logiciel: Foxit PhantomPDF - (.Foxit Software Inc..) [HKLM] -- {e2317bb3-892b-48ba-84f8-c35efbb78acd} [Unsigned] =>.Foxit Software Inc. O42 - Logiciel: Foxit Reader - (.Foxit Software Inc..) [HKLM] -- Foxit Reader_is1 =>.FOXIT SOFTWARE INC.® O42 - Logiciel: IBM SPSS Statistics 21 - (.IBM Corp.) [HKLM] -- {1E26B9C2-ED08-4EEA-83C8-A786502B41E5} [Unsigned] =>.IBM Corp O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- HDMI =>.Intel Corporation® O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM] -- Internet Download Manager =>.Tonec Inc.® O42 - Logiciel: Java 8 Update 251 - (.Oracle Corporation.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F32180251F0} [Unsigned] =>.Oracle Corporation O42 - Logiciel: Java Auto Updater - (.Oracle Corporation.) [HKLM] -- {4A03706F-666A-4037-7777-5F2748764D10} [Unsigned] =>.Oracle Corporation (Hidden) O42 - Logiciel: Microsoft .NET Framework 4.8 - (.Microsoft Corporation.) [HKLM] -- {B29F8740-372B-312F-8EEE-18FF857CCBB8} [Unsigned] =>.Microsoft Corporation O42 - Logiciel: Microsoft Office Access MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0015-0401-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Access MUI (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0015-0409-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Access Setup Metadata MUI (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0117-0409-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Excel MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0016-0401-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Excel MUI (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0016-0409-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Groove MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-00BA-0401-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Groove MUI (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-00BA-0409-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office InfoPath MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0044-0401-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office InfoPath MUI (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0044-0409-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Language Pack 2010 - Arabic العربية - (.Microsoft Corporation.) [HKLM] -- Office14.OMUI.ar-sa =>.Microsoft Corporation® O42 - Logiciel: Microsoft Office O MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0100-0401-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office OneNote MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-00A1-0401-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office OneNote MUI (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-00A1-0409-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Outlook MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001A-0401-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Outlook MUI (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001A-0409-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office PowerPoint MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0018-0401-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office PowerPoint MUI (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0018-0409-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Professional Plus 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Professional Plus 2010 - (.Microsoft Corporation.) [HKLM] -- Office14.PROPLUS =>.Microsoft Corporation® O42 - Logiciel: Microsoft Office Proof (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0401-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Proof (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0409-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Proof (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-040C-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Proof (Spanish) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0C0A-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Proofing (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-002C-0401-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Proofing (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-002C-0409-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Publisher MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0019-0401-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Publisher MUI (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0019-0409-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Shared MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-006E-0401-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Shared MUI (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-006E-0409-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Shared Setup Metadata MUI (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0115-0409-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office SharePoint Designer MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0017-0401-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Word MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001B-0401-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office Word MUI (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001B-0409-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Office X MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0101-0401-0000-0000000FF1CE} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 - (.Microsoft Corporation.) [HKLM] -- {9A25302D-30C0-39D9-BD6F-21E6EC160475} [Unsigned] =>.Microsoft Corporation O42 - Logiciel: Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 - (.Microsoft Corporation.) [HKLM] -- {e2803110-78b3-4664-a479-3611a381656a} [Unsigned] =>.Microsoft Corporation O42 - Logiciel: Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24215 - (.Microsoft Corporation.) [HKLM] -- {69BCE4AC-9572-3271-A2FB-9423BDA36A43} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24215 - (.Microsoft Corporation.) [HKLM] -- {BBF2AC74-720C-3CB3-8291-5E34039232FA} [Unsigned] =>.Microsoft Corporation (Hidden) O42 - Logiciel: Mozilla Firefox 80.0.1 (x86 en-US) - (.Mozilla.) [HKLM] -- Mozilla Firefox 80.0.1 (x86 en-US) =>.Mozilla Corporation® O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService [Unsigned] =>.Mozilla O42 - Logiciel: MPC-HC 1.7.13 - (.MPC-HC Team.) [HKLM] -- {2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1 =>.Fotis Zafiropoulos® O42 - Logiciel: NordVPN - (.TEFINCOM S.A..) [HKLM] -- {19465C24-3D5D-4327-B99F-3CC0A1D38151}_is1 =>.TEFINCOM S.A.® O42 - Logiciel: NordVPN network TAP - (.NordVPN.) [HKLM] -- {97DEC5D6-2BE9-45BB-BFC5-274B851B486B} [Unsigned] =>.NordVPN O42 - Logiciel: NordVPN network TUN - (.NordVPN.) [HKLM] -- {73EC9EBF-8350-4C38-9262-3CB464532FA9} [Unsigned] =>.NordVPN O42 - Logiciel: OpenAL - (.Open Audio Library.) [HKLM] -- OpenAL =>.Creative Labs Inc® O42 - Logiciel: Opera GX Stable 68.0.3618.206 - (.Opera Software.) [HKCU] -- Opera GX 68.0.3618.206 [Unsigned] =>.Opera Software O42 - Logiciel: Opera Stable 70.0.3728.178 - (.Opera Software.) [HKCU] -- Opera 70.0.3728.178 =>.Opera Software AS® O42 - Logiciel: Tactical Ops - (..) [HKLM] -- Tactical Ops [Unsigned] O42 - Logiciel: Update for Microsoft .NET Framework 4.8 (KB4503575) - (.Microsoft Corporation.) [HKLM] -- {92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB4503575 [Unsigned] =>.Microsoft Corporation O42 - Logiciel: Update for Microsoft .NET Framework 4.8 (KB4532941) - (.Microsoft Corporation.) [HKLM] -- {92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB4532941 [Unsigned] =>.Microsoft Corporation O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM] -- VLC media player [Unsigned] =>.VideoLAN O42 - Logiciel: Windows IPTV Player - (.Xtream Codes LTD.) [HKLM] -- {D1F0A04F-B987-4373-9E26-40DC6F1F9906} [Unsigned] O42 - Logiciel: WinRAR 5.90 (32-bit) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver =>.win.rar GmbH® ---\\ HKCU & HKLM Software Keys (117) - 19s HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com =>PUP.Optional.LavasoftWebCompanion HKCU\Software\Lavasoft\Web Companion =>PUP.Optional.LavasoftWebCompanion HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com =>PUP.Optional.LavasoftWebCompanion HKLM\SOFTWARE\Lavasoft\Web Companion =>PUP.Optional.LavasoftWebCompanion HKLM\SOFTWARE\7-Zip =>.Igor Pavlov HKLM\SOFTWARE\AssaultCube =>.Rapid Viper HKLM\SOFTWARE\ATI Technologies =>.ATI Technologies HKLM\SOFTWARE\Aureal =>.Aureal Semiconductor HKLM\SOFTWARE\BCL Technologies =>.BCL Technologies HKLM\SOFTWARE\Caphyon =>.Caphyon HKLM\SOFTWARE\CBSTEST =>.CBS Test HKLM\SOFTWARE\CLSYSTEM =>.ClSystem HKLM\SOFTWARE\CXT =>.CXT Software HKLM\SOFTWARE\Foxit Software =>.Foxit Software HKLM\SOFTWARE\Google =>.Google HKLM\SOFTWARE\Hummingbird =>.Hummingbird HKLM\SOFTWARE\IBM =>.IBM HKLM\SOFTWARE\Intel =>.Intel HKLM\SOFTWARE\Internet Download Manager =>.Tonec Inc HKLM\SOFTWARE\IObit =>.IObit HKLM\SOFTWARE\JavaSoft =>.JavaSoft HKLM\SOFTWARE\JreMetrics =>.JreMetrics HKLM\SOFTWARE\Lavasoft =>.Lavasoft HKLM\SOFTWARE\Licenses =>.Microsoft Corporation HKLM\SOFTWARE\Macromedia =>.Macromedia HKLM\SOFTWARE\Mozilla =>.Mozilla HKLM\SOFTWARE\mozilla.org =>.mozilla.org HKLM\SOFTWARE\MozillaPlugins =>.MozillaPlugins HKLM\SOFTWARE\NordVPN =>.NordVPN HKLM\SOFTWARE\Ntpad =>.Ntpad HKLM\SOFTWARE\ODBC =>.DB Connectivity Solutions HKLM\SOFTWARE\OpenAL =>.Open Audio Library HKLM\SOFTWARE\Oracle =>.Oracle HKLM\SOFTWARE\Piriform =>.Piriform HKLM\SOFTWARE\Rainbow Technologies =>.Rainbow Technologies HKLM\SOFTWARE\RegisteredApplications =>.Microsoft Corporation HKLM\SOFTWARE\Sonic =>.Sonic HKLM\SOFTWARE\VideoLAN =>.VideoLan Team HKLM\SOFTWARE\Volatile =>.Microsoft Corporation HKLM\SOFTWARE\WinRAR =>.WinRAR HKLM\SOFTWARE\WOW6432Node =>.Microsoft Corporation HKLM\SOFTWARE\Xtream Codes LTD HKLM\SOFTWARE\WOW6432Node\Foxit Software =>.Foxit Software HKLM\SOFTWARE\WOW6432Node\Internet Download Manager =>.Tonec Inc HKCU\SOFTWARE\7-Zip =>.Igor Pavlov HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation HKCU\SOFTWARE\BCL Technologies =>.BCL Technologies HKCU\SOFTWARE\BitTorrent =>.BitTorrent (P2P) HKCU\SOFTWARE\BitTorrentPersist HKCU\SOFTWARE\CocCoc HKCU\SOFTWARE\Discord =>.Discord HKCU\SOFTWARE\DownloadManager =>.DownloadManager HKCU\SOFTWARE\Easy Docx Merger HKCU\SOFTWARE\Foxit Software =>.Foxit Software HKCU\SOFTWARE\Google =>.Google HKCU\SOFTWARE\Icecream =>.Icecream HKCU\SOFTWARE\ILOVEPDF HKCU\SOFTWARE\Intel =>.Intel HKCU\SOFTWARE\JavaSoft =>.JavaSoft HKCU\SOFTWARE\kingsoft =>.Kingosoft Technology Ltd HKCU\SOFTWARE\Lavasoft =>.Lavasoft HKCU\SOFTWARE\Macromedia =>.Macromedia HKCU\SOFTWARE\Mozilla =>.Mozilla HKCU\SOFTWARE\MPC-HC =>.MPC-HC Team HKCU\SOFTWARE\Netscape =>.Netscape HKCU\SOFTWARE\NetVoyage HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions HKCU\SOFTWARE\Opera Software =>.Opera Software HKCU\SOFTWARE\PCurVersion =>.Unknown HKCU\SOFTWARE\Piriform =>.Piriform HKCU\SOFTWARE\QtProject =>.QtProject HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation HKCU\SOFTWARE\Valve =>.Valve HKCU\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation HKCU\SOFTWARE\WinRAR =>.WinRAR HKCU\SOFTWARE\WinRAR SFX =>.RarLab HKCU\SOFTWARE\Wintertree =>.Wintertree Software HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation HKCU\SOFTWARE\ZHP =>.Nicolas Coolman HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation HKU\.DEFAULT\SOFTWARE\Foxit Software =>.Foxit Software HKU\.DEFAULT\SOFTWARE\Piriform =>.Piriform HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\7-Zip =>.Igor Pavlov HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\AppDataLow =>.Microsoft Corporation HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\BCL Technologies =>.BCL Technologies HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\BitTorrent =>.BitTorrent (P2P) HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\BitTorrentPersist HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\CocCoc HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\Discord =>.Discord HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\DownloadManager =>.DownloadManager HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\Easy Docx Merger HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\Foxit Software =>.Foxit Software HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\Google =>.Google HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\Icecream =>.Icecream HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\ILOVEPDF HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\Intel =>.Intel HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\JavaSoft =>.JavaSoft HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\kingsoft =>.Kingosoft Technology Ltd HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\Lavasoft =>.Lavasoft HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\Macromedia =>.Macromedia HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\Mozilla =>.Mozilla HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\MPC-HC =>.MPC-HC Team HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\Netscape =>.Netscape HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\NetVoyage HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\ODBC =>.DB Connectivity Solutions HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\Opera Software =>.Opera Software HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\PCurVersion =>.Unknown HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\Piriform =>.Piriform HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\QtProject =>.QtProject HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\RegisteredApplications =>.Microsoft Corporation HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\Valve =>.Valve HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\WinRAR =>.WinRAR HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\WinRAR SFX =>.RarLab HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\Wintertree =>.Wintertree Software HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\Wow6432Node =>.Microsoft Corporation HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\SOFTWARE\ZHP =>.Nicolas Coolman ---\\ Contents of the Common Files folders (184) - 8s O43 - CFD: 10/05/2020 - [] D -- C:\Program Files\7-Zip =>.Igor Pavlov O43 - CFD: 28/08/2020 - [] D -- C:\Program Files\AssaultCube =>.Rapid Viper O43 - CFD: 04/08/2020 - [] D -- C:\Program Files\CCleaner =>.Piriform Ltd O43 - CFD: 07/06/2020 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation O43 - CFD: 20/04/2020 - [] D -- C:\Program Files\DVD Maker =>.Aone Software O43 - CFD: 31/05/2020 - [] D -- C:\Program Files\Foxit Software =>.Foxit Software O43 - CFD: 13/09/2020 - [] D -- C:\Program Files\Google =>.Google O43 - CFD: 17/05/2020 - [] D -- C:\Program Files\IBM =>.IBM O43 - CFD: 28/05/2020 - [] D -- C:\Program Files\ILOVEPDF O43 - CFD: 29/05/2020 - [] D -- C:\Program Files\Internet Download Manager =>.Tonec Inc O43 - CFD: 30/04/2020 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation O43 - CFD: 09/05/2020 - [] D -- C:\Program Files\Java =>.Oracle O43 - CFD: 04/08/2020 - [] D -- C:\Program Files\Lavasoft =>.Lavasoft O43 - CFD: 11/05/2020 - [] D -- C:\Program Files\Microsoft Analysis Services =>.Microsoft Corporation O43 - CFD: 20/04/2020 - [] D -- C:\Program Files\Microsoft Games =>.Microsoft Corporation O43 - CFD: 11/05/2020 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation O43 - CFD: 11/05/2020 - [] D -- C:\Program Files\Microsoft SQL Server Compact Edition =>.Microsoft Corporation O43 - CFD: 11/05/2020 - [] D -- C:\Program Files\Microsoft Sync Framework =>.Microsoft Corporation O43 - CFD: 11/05/2020 - [] D -- C:\Program Files\Microsoft Synchronization Services =>.Microsoft Corporation O43 - CFD: 11/05/2020 - [] D -- C:\Program Files\Microsoft Visual Studio 8 =>.Microsoft Corporation O43 - CFD: 11/05/2020 - [] D -- C:\Program Files\Microsoft.NET =>.Microsoft Corporation O43 - CFD: 02/09/2020 - [] D -- C:\Program Files\Mozilla Firefox =>.Mozilla O43 - CFD: 02/09/2020 - [] D -- C:\Program Files\Mozilla Maintenance Service =>.Mozilla O43 - CFD: 12/05/2020 - [] D -- C:\Program Files\MPC-HC =>.MPC-HC Team O43 - CFD: 11/05/2020 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation O43 - CFD: 13/09/2020 - [] D -- C:\Program Files\NordVPN =>.TEFINCOM S.A.® O43 - CFD: 13/09/2020 - [] D -- C:\Program Files\NordVPN network TAP =>.OpenVPN Technologies, Inc.® O43 - CFD: 13/09/2020 - [] D -- C:\Program Files\NordVPN network TUN O43 - CFD: 13/09/2020 - [] D -- C:\Program Files\Opa =>.Opera Software AS® O43 - CFD: 28/08/2020 - [] D -- C:\Program Files\OpenAL =>.Open Audio Library O43 - CFD: 13/08/2020 - [] D -- C:\Program Files\OriginLab =>.OriginLab O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation O43 - CFD: 01/06/2020 - [] D -- C:\Program Files\VideoLAN =>.VideoLan Team O43 - CFD: 20/04/2020 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation O43 - CFD: 20/04/2020 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation O43 - CFD: 20/04/2020 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation O43 - CFD: 20/04/2020 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation O43 - CFD: 20/11/2010 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation O43 - CFD: 12/04/2011 - [] D -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation O43 - CFD: 27/05/2020 - [] D -- C:\Program Files\WinRAR =>.win.rar GmbH® O43 - CFD: 08/09/2020 - [] D -- C:\Program Files\Xtream Codes LTD [Unsigned] O43 - CFD: 10/05/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip =>.Igor Pavlov O43 - CFD: 21/04/2020 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation O43 - CFD: 21/04/2020 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools O43 - CFD: 28/08/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AssaultCube =>.Rapid Viper O43 - CFD: 04/08/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd O43 - CFD: 31/05/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit PhantomPDF =>.Foxit Corporation O43 - CFD: 28/05/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader =>.Foxit Corporation O43 - CFD: 21/04/2020 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation O43 - CFD: 17/05/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IBM SPSS Statistics =>.IBM Corporation O43 - CFD: 30/04/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager =>.Tonec Inc O43 - CFD: 09/05/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java =>.Oracle O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation O43 - CFD: 11/05/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office =>.Microsoft Corporation O43 - CFD: 12/05/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC =>.MPC-HC Team O43 - CFD: 13/08/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OriginLab =>.OriginLab O43 - CFD: 11/05/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation O43 - CFD: 30/04/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tactical Ops O43 - CFD: 01/06/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team O43 - CFD: 30/04/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Favorites =>.Microsoft Corporation O43 - CFD: 02/09/2020 - [] D -- C:\ProgramData\FileOpen =>.FileOpen Systems Inc. O43 - CFD: 11/05/2020 - [] D -- C:\ProgramData\Foxit ContentPlatform =>.Foxit Corporation O43 - CFD: 31/05/2020 - [] D -- C:\ProgramData\Foxit Software =>.Foxit Software O43 - CFD: 30/04/2020 - [0] D -- C:\ProgramData\IDM =>.IDM O43 - CFD: 06/05/2020 - [] D -- C:\ProgramData\IObit =>.IObit O43 - CFD: 06/08/2020 - [] D -- C:\ProgramData\Lavasoft =>.Lavasoft O43 - CFD: 11/05/2020 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation O43 - CFD: 11/06/2020 - [] D -- C:\ProgramData\Microsoft Help =>.Microsoft Corporation O43 - CFD: 11/05/2020 - [] D -- C:\ProgramData\Microsoft Toolkit =>.Microsoft Corporation O43 - CFD: 02/05/2020 - [] D -- C:\ProgramData\Mozilla =>.Mozilla Corporation O43 - CFD: 13/09/2020 - [] D -- C:\ProgramData\NordVPN =>.NordVPN O43 - CFD: 09/05/2020 - [] D -- C:\ProgramData\Oracle =>.Oracle O43 - CFD: 04/08/2020 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation O43 - CFD: 04/08/2020 - [] D -- C:\ProgramData\ProductData =>.Microsoft Corporation O43 - CFD: 17/05/2020 - [] D -- C:\ProgramData\SafeNet Sentinel =>.SafeNet O43 - CFD: 29/05/2020 - [0] D -- C:\ProgramData\SolidDocuments =>.SolidDocuments O43 - CFD: 17/05/2020 - [] D -- C:\ProgramData\SPSS =>.SPSS O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation O43 - CFD: 30/08/2020 - [0] AD -- C:\ProgramData\TEMP =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation O43 - CFD: 07/06/2020 - [0] D -- C:\Program Files\Common Files\Adobe =>.Adobe O43 - CFD: 11/05/2020 - [] D -- C:\Program Files\Common Files\DESIGNER =>.Designer O43 - CFD: 17/05/2020 - [] D -- C:\Program Files\Common Files\IBM =>.IBM O43 - CFD: 06/05/2020 - [] D -- C:\Program Files\Common Files\IObit =>.IObit O43 - CFD: 09/05/2020 - [] D -- C:\Program Files\Common Files\Java =>.Oracle O43 - CFD: 17/05/2020 - [] D -- C:\Program Files\Common Files\microsoft shared =>.Microsoft Corporation O43 - CFD: 09/05/2020 - [] D -- C:\Program Files\Common Files\Oracle =>.Oracle O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Common Files\Services =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Common Files\SpeechEngines =>.Microsoft Corporation O43 - CFD: 11/05/2020 - [] D -- C:\Program Files\Common Files\System =>.Microsoft Corporation O43 - CFD: 30/04/2020 - [] D -- C:\Users\lonly\AppData\Roaming\Adobe =>.Adobe O43 - CFD: 05/06/2020 - [] D -- C:\Users\lonly\AppData\Roaming\discord =>.GitHub O43 - CFD: 13/09/2020 - [] D -- C:\Users\lonly\AppData\Roaming\DMCache =>.DMCache O43 - CFD: 10/06/2020 - [] D -- C:\Users\lonly\AppData\Roaming\Easy Docx Merger O43 - CFD: 11/05/2020 - [] D -- C:\Users\lonly\AppData\Roaming\Foxit AgentInformation =>.Foxit Corporation O43 - CFD: 31/05/2020 - [] D -- C:\Users\lonly\AppData\Roaming\Foxit Software =>.Foxit Software O43 - CFD: 30/04/2020 - [] D -- C:\Users\lonly\AppData\Roaming\Identities =>.Microsoft Corporation O43 - CFD: 02/09/2020 - [] D -- C:\Users\lonly\AppData\Roaming\IDM =>.IDM O43 - CFD: 30/05/2020 - [] D -- C:\Users\lonly\AppData\Roaming\ILOVEPDF O43 - CFD: 04/08/2020 - [] D -- C:\Users\lonly\AppData\Roaming\IObit =>.IObit O43 - CFD: 12/05/2020 - [] D -- C:\Users\lonly\AppData\Roaming\Macromedia =>.Macromedia O43 - CFD: 20/04/2020 - [0] D -- C:\Users\lonly\AppData\Roaming\Media Center Programs =>.Microsoft Corporation O43 - CFD: 16/06/2020 - [] SD -- C:\Users\lonly\AppData\Roaming\Microsoft =>.Microsoft Corporation O43 - CFD: 02/05/2020 - [] D -- C:\Users\lonly\AppData\Roaming\Mozilla =>.Mozilla Corporation O43 - CFD: 04/09/2020 - [] D -- C:\Users\lonly\AppData\Roaming\MPC-HC =>.MPC-HC Team O43 - CFD: 02/09/2020 - [] D -- C:\Users\lonly\AppData\Roaming\Opera Software =>.Opera Software O43 - CFD: 17/05/2020 - [] D -- C:\Users\lonly\AppData\Roaming\SPSSInc =>.SPSS Inc O43 - CFD: 09/05/2020 - [] D -- C:\Users\lonly\AppData\Roaming\Sun =>.Oracle O43 - CFD: 11/05/2020 - [] D -- C:\Users\lonly\AppData\Roaming\Thinstall =>.VMare O43 - CFD: 09/09/2020 - [] D -- C:\Users\lonly\AppData\Roaming\uTorrent O43 - CFD: 12/09/2020 - [] D -- C:\Users\lonly\AppData\Roaming\vlc =>.VideoLan Team O43 - CFD: 08/09/2020 - [] D -- C:\Users\lonly\AppData\Roaming\WindowsIPTVPlayer O43 - CFD: 02/05/2020 - [] D -- C:\Users\lonly\AppData\Roaming\WinRAR =>.WinRAR O43 - CFD: 11/06/2020 - [] D -- C:\Users\lonly\AppData\Roaming\wps_download O43 - CFD: 13/09/2020 - [] D -- C:\Users\lonly\AppData\Roaming\ZHP =>.Nicolas Coolman O43 - CFD: 07/06/2020 - [0] D -- C:\Users\lonly\AppData\Local\Adobe =>.Adobe O43 - CFD: 30/04/2020 - [0] SHD -- C:\Users\lonly\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 26/08/2020 - [] D -- C:\Users\lonly\AppData\Local\BitTorrentHelper O43 - CFD: 28/05/2020 - [] D -- C:\Users\lonly\AppData\Local\CrashRpt O43 - CFD: 04/06/2020 - [0] D -- C:\Users\lonly\AppData\Local\Diagnostics =>.Microsoft Corporation O43 - CFD: 09/05/2020 - [] D -- C:\Users\lonly\AppData\Local\Discord =>.GitHub O43 - CFD: 04/09/2020 - [0] D -- C:\Users\lonly\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation O43 - CFD: 10/06/2020 - [] D -- C:\Users\lonly\AppData\Local\Foxit PhantomPDF =>.Foxit Corporation O43 - CFD: 10/08/2020 - [] D -- C:\Users\lonly\AppData\Local\Foxit Reader =>.Foxit Corporation O43 - CFD: 30/04/2020 - [0] SHD -- C:\Users\lonly\AppData\Local\History =>.Microsoft Corporation O43 - CFD: 17/05/2020 - [] D -- C:\Users\lonly\AppData\Local\IBM =>.IBM O43 - CFD: 28/05/2020 - [] D -- C:\Users\lonly\AppData\Local\Icecream =>.Icecream O43 - CFD: 28/05/2020 - [] D -- C:\Users\lonly\AppData\Local\ILOVEPDF O43 - CFD: 10/06/2020 - [] D -- C:\Users\lonly\AppData\Local\IsolatedStorage =>.id Software O43 - CFD: 06/06/2020 - [] D -- C:\Users\lonly\AppData\Local\javasharedresources =>.Legitimate O43 - CFD: 11/06/2020 - [] D -- C:\Users\lonly\AppData\Local\Kingsoft =>.Kingosoft Technology Ltd O43 - CFD: 04/08/2020 - [] D -- C:\Users\lonly\AppData\Local\Lavasoft =>.Lavasoft O43 - CFD: 05/09/2020 - [] D -- C:\Users\lonly\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 27/05/2020 - [] D -- C:\Users\lonly\AppData\Local\Microsoft Games =>.Microsoft Corporation O43 - CFD: 11/05/2020 - [0] D -- C:\Users\lonly\AppData\Local\Microsoft Help =>.Microsoft Corporation O43 - CFD: 02/05/2020 - [] D -- C:\Users\lonly\AppData\Local\Mozilla =>.Mozilla Corporation O43 - CFD: 13/09/2020 - [] D -- C:\Users\lonly\AppData\Local\NordVPN =>.NordVPN O43 - CFD: 02/09/2020 - [] D -- C:\Users\lonly\AppData\Local\Opera Software =>.Opera Software O43 - CFD: 28/05/2020 - [] D -- C:\Users\lonly\AppData\Local\PDF Tools AG O43 - CFD: 02/09/2020 - [] D -- C:\Users\lonly\AppData\Local\Programs =>.Microsoft Corporation O43 - CFD: 29/05/2020 - [] D -- C:\Users\lonly\AppData\Local\SolidDocuments =>.SolidDocuments O43 - CFD: 09/05/2020 - [] D -- C:\Users\lonly\AppData\Local\SquirrelTemp =>.Squirrels O43 - CFD: 13/09/2020 - [] D -- C:\Users\lonly\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 30/04/2020 - [0] SHD -- C:\Users\lonly\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 11/05/2020 - [] D -- C:\Users\lonly\AppData\Local\Thinstall =>.VMare O43 - CFD: 30/04/2020 - [0] D -- C:\Users\lonly\AppData\Local\VirtualStore =>.Microsoft Corporation O43 - CFD: 13/09/2020 - [] D -- C:\Users\lonly\AppData\Local\ZHP =>.Nicolas Coolman O43 - CFD: 30/04/2020 - [0] D -- C:\Users\lonly\AppData\Local\Programs\Common =>.Microsoft Corporation O43 - CFD: 07/05/2020 - [] D -- C:\Users\lonly\AppData\Local\Programs\Opera =>.Opera Software O43 - CFD: 02/09/2020 - [] D -- C:\Users\lonly\AppData\Local\Programs\Opera GX O43 - CFD: 11/05/2020 - [] D -- C:\Users\lonly\AppData\LocalLow\Foxit O43 - CFD: 30/04/2020 - [] D -- C:\Users\lonly\AppData\LocalLow\IObit =>.IObit O43 - CFD: 30/04/2020 - [] D -- C:\Users\lonly\AppData\LocalLow\Microsoft =>.Microsoft Corporation O43 - CFD: 13/09/2020 - [0] D -- C:\Users\lonly\AppData\LocalLow\Mozilla =>.Mozilla Corporation O43 - CFD: 09/05/2020 - [] D -- C:\Users\lonly\AppData\LocalLow\Sun =>.Oracle O43 - CFD: 09/09/2020 - [] D -- C:\Users\lonly\AppData\LocalLow\uTorrent O43 - CFD: 17/08/2020 - [] D -- C:\Users\lonly\Desktop\New folder O43 - CFD: 14/07/2009 - [] RD -- C:\Users\lonly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation O43 - CFD: 30/04/2020 - [] RD -- C:\Users\lonly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools O43 - CFD: 09/05/2020 - [] D -- C:\Users\lonly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc =>.Discord Inc O43 - CFD: 30/04/2020 - [] D -- C:\Users\lonly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager =>.Tonec Inc O43 - CFD: 14/07/2009 - [] RD -- C:\Users\lonly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation O43 - CFD: 30/04/2020 - [] RD -- C:\Users\lonly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation O43 - CFD: 30/04/2020 - [] D -- C:\Users\lonly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tactical Ops O43 - CFD: 30/04/2020 - [] D -- C:\Users\lonly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 01/05/2020 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 02/05/2020 - [] SD -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation ---\\ ShellIconOverlayIdentifiers (SIOI) (9) - 1s O106 - SIOI: IDM Shell Extension [ IDM Shell Extension] - {CDC95B92-E27C-4745-A8C5-64A52A78855D}. (.Tonec Inc. - Internet Download Manager module.) -- C:\Program Files\Internet Download Manager\IDMShellExt.dll =>.Tonec Inc.® O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) -- C:\Windows\System32\EhStorShell.dll [Unsigned] =>.Microsoft Corporation O106 - SIOI: Groove Explorer Icon Overlay 1 (GFS Unread Stub) [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] - {99FD978C-D287-4F50-827F-B2C658EDA8E7}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O106 - SIOI: Groove Explorer Icon Overlay 2 (GFS Stub) [Groove Explorer Icon Overlay 2 (GFS Stub)] - {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O106 - SIOI: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] - {920E6DB1-9907-4370-B3A0-BAFC03D81399}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O106 - SIOI: Groove Explorer Icon Overlay 3 (GFS Folder) [Groove Explorer Icon Overlay 3 (GFS Folder)] - {16F3DD56-1AF5-4347-846D-7C10C4192619}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O106 - SIOI: Groove Explorer Icon Overlay 4 (GFS Unread Mark) [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] - {2916C86E-86A6-43FE-8112-43ABE6BF8DCC}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O106 - SIOI: [Offline Files] - {4E77131D-3629-431c-9818-C5679DC83E81}. (.Microsoft Corporation - Client Side Caching UI.) -- C:\Windows\System32\cscui.dll [Unsigned] =>.Microsoft Corporation O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation ---\\ Search Context Menu Handlers (SCMH) (32) - 2s O108 - CMH1: 7-Zip - {23170F69-40C1-278A-1000-000100020000} . (.Igor Pavlov - 7-Zip Shell Extension.) -- C:\Program Files\7-Zip\7-zip.dll [Unsigned] =>.Igor Pavlov O108 - CMH1: BriefcaseMenu - {85BBD920-42A0-1069-A2E4-08002B30309D} . (.Microsoft Corporation - Windows Briefcase.) -- C:\Windows\System32\syncui.dll [Unsigned] =>.Microsoft Corporation O108 - CMH1: Foxit_ConvertToPDF - {C5269811-4A29-4818-A4BB-111F9FC63A5F} . (.Foxit Software Inc. - ConvertToPDFShellExtension.) -- C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x86.dll =>.FOXIT SOFTWARE INC.® O108 - CMH1: Open With - {09799AFB-AD67-11d1-ABCD-00C04FC30936} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll [Unsigned] =>.Microsoft Corporation O108 - CMH1: Open With EncryptionMenu - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll [Unsigned] =>.Microsoft Corporation O108 - CMH1: Sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation O108 - CMH1: WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files\WinRAR\RarExt.dll =>.win.rar GmbH® O108 - CMH1: XXX Groove GFS Context Menu Handler XXX - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O108 - CMH2: Compatibility - {1d27f844-3a1f-4410-85ac-14651078412d} . (.Microsoft Corporation - Compatibility Tab Shell Extension Library.) -- C:\Windows\System32\acppage.dll [Unsigned] =>.Microsoft Corporation O108 - CMH2: OpenContainingFolderMenu - {37ea3a21-7493-4208-a011-7f9ea79ce9f5} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll [Unsigned] =>.Microsoft Corporation O108 - CMH2: WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files\WinRAR\RarExt.dll =>.win.rar GmbH® O108 - CMH3: CopyAsPathMenu - {f3d06e7c-1e45-4a26-847e-f9fcdee59be0} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll [Unsigned] =>.Microsoft Corporation O108 - CMH3: SendTo - {7BA4C740-9E81-11CF-99D3-00AA004AE837} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll [Unsigned] =>.Microsoft Corporation O108 - CMH3: XXX Groove GFS Context Menu Handler XXX - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O108 - CMH4: 7-Zip - {23170F69-40C1-278A-1000-000100020000} . (.Igor Pavlov - 7-Zip Shell Extension.) -- C:\Program Files\7-Zip\7-zip.dll [Unsigned] =>.Igor Pavlov O108 - CMH4: EncryptionMenu - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll [Unsigned] =>.Microsoft Corporation O108 - CMH4: Offline Files - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Microsoft Corporation - Client Side Caching UI.) -- C:\Windows\System32\cscui.dll [Unsigned] =>.Microsoft Corporation O108 - CMH4: Sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation O108 - CMH4: XXX Groove GFS Context Menu Handler XXX - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O108 - CMH5: Gadgets - {6B9228DA-9C15-419e-856C-19E768A13BDC} . (.Microsoft Corporation - Sidebar droptarget.) -- C:\Program Files\Windows Sidebar\sbdrop.dll [Unsigned] =>.Microsoft Corporation O108 - CMH5: New - {D969A300-E7FF-11d0-A93B-00A0C90F2719} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll [Unsigned] =>.Microsoft Corporation O108 - CMH5: Sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation O108 - CMH5: XXX Groove GFS Context Menu Handler XXX - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O108 - CMH6: 7-Zip - {23170F69-40C1-278A-1000-000100020000} . (.Igor Pavlov - 7-Zip Shell Extension.) -- C:\Program Files\7-Zip\7-zip.dll [Unsigned] =>.Igor Pavlov O108 - CMH6: BriefcaseMenu - {85BBD920-42A0-1069-A2E4-08002B30309D} . (.Microsoft Corporation - Windows Briefcase.) -- C:\Windows\System32\syncui.dll [Unsigned] =>.Microsoft Corporation O108 - CMH6: Foxit_ConvertToPDF - {C5269811-4A29-4818-A4BB-111F9FC63A5F} . (.Foxit Software Inc. - ConvertToPDFShellExtension.) -- C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x86.dll =>.FOXIT SOFTWARE INC.® O108 - CMH6: Library Location - {3dad6c5d-2167-4cae-9914-f99e41c12cfa} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll [Unsigned] =>.Microsoft Corporation O108 - CMH6: Offline Files - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Microsoft Corporation - Client Side Caching UI.) -- C:\Windows\System32\cscui.dll [Unsigned] =>.Microsoft Corporation O108 - CMH6: WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files\WinRAR\RarExt.dll =>.win.rar GmbH® O108 - CMH6: XXX Groove GFS Context Menu Handler XXX - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O108 - CMH7: EnhancedStorageShell - {2854F705-3548-414C-A113-93E27C808C85} . (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) -- C:\Windows\System32\EhStorShell.dll [Unsigned] =>.Microsoft Corporation O108 - CMH7: Sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll [Unsigned] =>.Microsoft Corporation ---\\ System Drivers List (330) - 17s O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - 1394 Bus Device Driver.) -- C:\Windows\System32\drivers\1394bus.sys [54784] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - 1394 OpenHCI Port Driver.) -- C:\Windows\System32\drivers\1394ohci.sys [164864] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - ACPI Driver for NT.) -- C:\Windows\System32\drivers\acpi.sys [274624] =>.Microsoft Windows® O58 - SDL:2010/11/20 22:29:03 A . (.Microsoft Corporation - ACPI Power Metering Driver.) -- C:\Windows\System32\drivers\acpipmi.sys [10240] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 02:26:15 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [422976] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:26:17 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [297552] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:26:15 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\drivers\adpu320.sys [146512] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\afd.sys [338944] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:05 A . (.Microsoft Corporation - RAS Agile Vpn Miniport Call Manager.) -- C:\Windows\System32\drivers\agilevpn.sys [49152] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - 440 NT AGP Filter.) -- C:\Windows\System32\drivers\AGP440.sys [52968] =>.Microsoft® O58 - SDL:2020/04/20 22:23:00 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [14056] =>.Microsoft® O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - AMD NT AGP Filter.) -- C:\Windows\System32\drivers\AMDAGP.SYS [52968] =>.Microsoft® O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - AMD IDE Driver.) -- C:\Windows\System32\drivers\amdide.sys [14568] =>.Microsoft® O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\amdk8.sys [55296] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\amdppm.sys [52736] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:00 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [80104] =>.Microsoft® O58 - SDL:2009/07/14 02:26:15 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [159312] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:23:00 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [22248] =>.Microsoft® O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - AppID Driver.) -- C:\Windows\System32\drivers\appid.sys [50688] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 02:26:15 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [76368] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:26:15 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [86608] =>.Microsoft Windows® O58 - SDL:2009/07/14 00:54:46 A . (.Microsoft Corporation - MS Remote Access serial network driver.) -- C:\Windows\System32\drivers\asyncmac.sys [17920] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [21224] =>.Microsoft® O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - ATAPI Driver Extension.) -- C:\Windows\System32\drivers\ataport.sys [132840] =>.Microsoft® O58 - SDL:2011/12/13 04:32:24 A . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driv.) -- C:\Windows\System32\drivers\athr.sys [2228224] [Unsigned] =>.Atheros Communications, Inc. O58 - SDL:2009/07/13 23:02:49 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60x.sys [229888] [Unsigned] =>.Broadcom Corporation O58 - SDL:2009/07/14 02:26:15 A . (.Microsoft Corporation - Battery Class Driver.) -- C:\Windows\System32\drivers\battc.sys [25168] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:23:06 A . (.Microsoft Corporation - BEEP Driver.) -- C:\Windows\System32\drivers\beep.sys [6144] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:23:04 A . (.Microsoft Corporation - BLB Drive Driver.) -- C:\Windows\System32\drivers\blbdrive.sys [35328] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:01 A . (.Microsoft Corporation - NT Lan Manager Datagram Receiver Driver.) -- C:\Windows\System32\drivers\bowser.sys [68608] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/13 23:53:28 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [13568] [Unsigned] =>.Brother Industries, Ltd. O58 - SDL:2009/07/13 23:53:28 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [5248] [Unsigned] =>.Brother Industries, Ltd. O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - MAC Bridge Driver.) -- C:\Windows\System32\drivers\bridge.sys [78336] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 01:57:25 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [272128] [Unsigned] =>.Brother Industries Ltd. O58 - SDL:2009/07/13 23:53:32 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [62336] [Unsigned] =>.Brother Industries Ltd. O58 - SDL:2009/07/13 23:53:33 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [12160] [Unsigned] =>.Brother Industries Ltd. O58 - SDL:2009/07/13 23:53:33 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [11904] [Unsigned] =>.Brother Industries Ltd. O58 - SDL:2009/07/14 00:51:34 A . (.Microsoft Corporation - Bluetooth Communications Driver.) -- C:\Windows\System32\drivers\bthmodem.sys [56320] [Unsigned] =>.Microsoft Corporation O58 - SDL:2012/03/08 10:09:40 A . (.Broadcom Corporation - Broadcom NetXtreme II Diagnostic Driver.) -- C:\Windows\System32\drivers\bxdiagx.sys [75816] =>.Broadcom Corporation® O58 - SDL:2012/02/22 17:05:54 A . (.Broadcom Corporation - FCoE offload x86 FREE.) -- C:\Windows\System32\drivers\bxfcoe.sys [150568] =>.Broadcom Corporation® O58 - SDL:2012/02/22 17:33:32 A . (.Broadcom Corporation - iSCSI offload x86 FREE.) -- C:\Windows\System32\drivers\bxois.sys [435240] =>.Broadcom Corporation® O58 - SDL:2012/01/24 16:44:14 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbdx.sys [483880] =>.Broadcom Corporation® O58 - SDL:2020/04/20 22:25:01 A . (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\cdfs.sys [70656] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\cdrom.sys [108544] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:51:17 A . (.Microsoft Corporation - Consumer IR Class Driver for eHome.) -- C:\Windows\System32\drivers\circlass.sys [37888] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:05 A . (.Microsoft Corporation - SCSI Class System Dll.) -- C:\Windows\System32\drivers\Classpnp.sys [146152] =>.Microsoft® O58 - SDL:2009/07/14 00:19:18 A . (.Microsoft Corporation - Control Method Battery Driver.) -- C:\Windows\System32\drivers\CmBatt.sys [14080] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:00 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [15592] =>.Microsoft® O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - Kernel Cryptography, Next Generation.) -- C:\Windows\System32\drivers\cng.sys [372960] =>.Microsoft® O58 - SDL:2009/07/14 02:26:21 A . (.Microsoft Corporation - Composite Battery Driver.) -- C:\Windows\System32\drivers\compbatt.sys [19024] =>.Microsoft Windows® O58 - SDL:2010/11/20 22:29:03 A . (.Microsoft Corporation - Multi-Transport Composite Bus Enumerator.) -- C:\Windows\System32\drivers\CompositeBus.sys [31232] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:06 A . (.Microsoft Corporation - Crash Dump Driver.) -- C:\Windows\System32\drivers\crashdmp.sys [35048] =>.Microsoft® O58 - SDL:2009/07/14 02:20:28 A . (.Microsoft Corporation - Disk Block Verification Filter Driver.) -- C:\Windows\System32\drivers\crcdisk.sys [22096] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:25:01 A . (.Microsoft Corporation - Windows Client Side Caching Driver.) -- C:\Windows\System32\drivers\csc.sys [389632] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:01 A . (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\dfsc.sys [88576] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:05 A . (.Microsoft Corporation - System Indexer/Cache Driver.) -- C:\Windows\System32\drivers\discache.sys [33280] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - PnP Disk Driver.) -- C:\Windows\System32\drivers\disk.sys [57064] =>.Microsoft® O58 - SDL:2020/04/20 22:23:06 A . (.Microsoft Corporation - Crash Dump Disk Driver.) -- C:\Windows\System32\drivers\Diskdump.sys [26856] =>.Microsoft® O58 - SDL:2009/07/14 02:20:28 A . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\drivers\djsvs.sys [70720] =>.Microsoft Windows® O58 - SDL:2010/11/20 22:29:03 A . (.Microsoft Corporation - Dynamic Memory.) -- C:\Windows\System32\drivers\dmvsc.sys [62464] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\Windows\System32\drivers\drmk.sys [81408] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\Windows\System32\drivers\drmkaud.sys [5120] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 02:20:28 A . (.Microsoft Corporation - ATAPI Dump Driver.) -- C:\Windows\System32\drivers\Dumpata.sys [26704] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:23:10 A . (.Microsoft Corporation - Bitlocker Drive Encryption Crashdump Filter.) -- C:\Windows\System32\drivers\dumpfve.sys [55456] =>.Microsoft® O58 - SDL:2009/07/14 00:25:26 A . (.Microsoft Corporation - DirectX API Driver.) -- C:\Windows\System32\drivers\dxapi.sys [13312] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:25:25 A . (.Microsoft Corporation - DirectX Graphics Driver.) -- C:\Windows\System32\drivers\dxg.sys [76288] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\Windows\System32\drivers\dxgkrnl.sys [732384] =>.Microsoft® O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - DirectX Graphics MMS.) -- C:\Windows\System32\drivers\dxgmms1.sys [221624] =>.Microsoft® O58 - SDL:2009/07/13 23:02:50 A . (.Intel Corporation - Intel(R) PRO/1000 Adapter NDIS 6 deserializ.) -- C:\Windows\System32\drivers\E1G60I32.sys [118784] [Unsigned] =>.Intel Corporation O58 - SDL:2009/07/14 02:20:28 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [453712] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Error Device Driver.) -- C:\Windows\System32\drivers\errdev.sys [7168] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/13 23:02:48 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbdx.sys [3100160] [Unsigned] =>.Broadcom Corporation O58 - SDL:2020/04/20 22:25:01 A . (.Microsoft Corporation - Microsoft Extended FAT File System.) -- C:\Windows\System32\drivers\exfat.sys [142336] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:01 A . (.Microsoft Corporation - Fast FAT File System Driver.) -- C:\Windows\System32\drivers\fastfat.sys [148992] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:45:45 A . (.Microsoft Corporation - Floppy Disk Controller Driver.) -- C:\Windows\System32\drivers\fdc.sys [25088] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 02:20:28 A . (.Microsoft Corporation - FileInfo Filter Driver.) -- C:\Windows\System32\drivers\fileinfo.sys [58448] =>.Microsoft Windows® O58 - SDL:2009/07/14 00:15:29 A . (.Microsoft Corporation - File Trace Filter Driver.) -- C:\Windows\System32\drivers\filetrace.sys [28160] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:45:45 A . (.Microsoft Corporation - Floppy Driver.) -- C:\Windows\System32\drivers\flpydisk.sys [19968] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:01 A . (.Microsoft Corporation - Microsoft Filesystem Filter Manager.) -- C:\Windows\System32\drivers\fltMgr.sys [201960] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:20:28 A . (.Microsoft Corporation - File System Dependency Manager Mini Filter.) -- C:\Windows\System32\drivers\fsdepends.sys [46160] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:23:06 A . (.Microsoft Corporation - File System Recognizer Driver.) -- C:\Windows\System32\drivers\fs_rec.sys [19688] =>.Microsoft® O58 - SDL:2020/04/20 22:23:10 A . (.Microsoft Corporation - BitLocker Drive Encryption Driver.) -- C:\Windows\System32\drivers\fvevol.sys [166472] =>.Microsoft® O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - FWP/IPsec Kernel-Mode API.) -- C:\Windows\System32\drivers\FWPKCLNT.SYS [189152] =>.Microsoft® O58 - SDL:2009/07/14 02:20:28 A . (.Microsoft Corporation - MS Generic AGPv3.0 Filter for K8/9 Processo.) -- C:\Windows\System32\drivers\GAGP30KX.SYS [57936] =>.Microsoft Windows® O58 - SDL:2009/07/13 23:54:14 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [26624] [Unsigned] =>.Hauppauge Computer Works, Inc. O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\hdaudbus.sys [109056] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - High Definition Audio Function Driver.) -- C:\Windows\System32\drivers\HdAudio.sys [304128] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:19:21 A . (.Microsoft Corporation - Hid Battery Driver.) -- C:\Windows\System32\drivers\hidbatt.sys [21504] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - Bluetooth Miniport Driver for HID Devices.) -- C:\Windows\System32\drivers\hidbth.sys [91136] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Hid Class Library.) -- C:\Windows\System32\drivers\hidclass.sys [56320] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:51:05 A . (.Microsoft Corporation - Infrared Miniport Driver for Input Devices.) -- C:\Windows\System32\drivers\hidir.sys [37888] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Hid Parsing Library.) -- C:\Windows\System32\drivers\hidparse.sys [26368] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - USB Miniport Driver for Input Devices.) -- C:\Windows\System32\drivers\hidusb.sys [24064] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 02:20:28 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [67152] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - HTTP Protocol Stack.) -- C:\Windows\System32\drivers\http.sys [515072] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/30 18:47:22 A . (.REALiX(tm) - HWiNFO x86 Kernel Driver.) -- C:\Windows\System32\drivers\HWiNFO32.SYS [23840] =>.Martin Malik - REALiX® O58 - SDL:2010/11/20 22:29:04 A . (.Microsoft Corporation - Hardware Policy Driver.) -- C:\Windows\System32\drivers\hwpolicy.sys [14208] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - i8042 Port Driver.) -- C:\Windows\System32\drivers\i8042prt.sys [80896] [Unsigned] =>.Microsoft Corporation O58 - SDL:2018/04/25 14:30:04 A . (.Intel Corporation - NVMe Storport Miniport Driver - x86.) -- C:\Windows\System32\drivers\IaNVMe.sys [120816] {330000C10A26A958EEA067060C00020000C10A}. =>.Intel Corporation O58 - SDL:2018/04/25 14:30:04 A . (.Intel Corporation - Intel NVMe Filter driver - x86.) -- C:\Windows\System32\drivers\IaNVMeF.sys [33768] {330000C10A26A958EEA067060C00020000C10A}. =>.Intel Corporation O58 - SDL:2020/04/20 22:23:00 A . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\drivers\iaStorV.sys [332008] =>.Microsoft® O58 - SDL:2018/12/20 12:05:18 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\drivers\idmwfp.sys [151872] =>.Tonec Inc.® O58 - SDL:2020/04/30 18:52:46 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd32.sys [5946368] [Unsigned] =>.Intel Corporation O58 - SDL:2009/07/14 02:20:36 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [41040] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - Intel PCI IDE Driver.) -- C:\Windows\System32\drivers\intelide.sys [15080] =>.Microsoft® O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\intelppm.sys [53760] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:54:29 A . (.Microsoft Corporation - IP FILTER DRIVER.) -- C:\Windows\System32\drivers\ipfltdrv.sys [58880] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - WMI IPMI DRIVER.) -- C:\Windows\System32\drivers\IPMIDrv.sys [66048] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:06 A . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\ipnat.sys [101888] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:53:32 A . (.Microsoft Corporation - IRDA Protocol Driver.) -- C:\Windows\System32\drivers\irda.sys [96768] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:53:27 A . (.Microsoft Corporation - Infra-Red Bus Enumerator.) -- C:\Windows\System32\drivers\irenum.sys [13824] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - PNP ISA Bus Driver.) -- C:\Windows\System32\drivers\isapnp.sys [46312] =>.Microsoft® O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - Keyboard Class Driver.) -- C:\Windows\System32\drivers\kbdclass.sys [42216] =>.Microsoft® O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - HID Keyboard Filter Driver.) -- C:\Windows\System32\drivers\kbdhid.sys [28160] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - Kernel CSA Library.) -- C:\Windows\System32\drivers\ks.sys [190976] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\drivers\ksecdd.sys [68848] =>.Microsoft® O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\drivers\ksecpkg.sys [137456] =>.Microsoft® O58 - SDL:2009/07/14 00:53:19 A . (.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) -- C:\Windows\System32\drivers\lltdio.sys [48128] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 02:20:36 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [95824] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:20:37 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [89168] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:20:36 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [54864] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:20:36 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [96848] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - LUA File Virtualization Filter Driver.) -- C:\Windows\System32\drivers\luafv.sys [88064] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:45:57 A . (.Microsoft Corporation - Medium changer class driver.) -- C:\Windows\System32\drivers\mcd.sys [18432] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 02:20:36 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [30800] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:20:36 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [235584] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:23:03 A . (.Microsoft Corporation - Modem Device Driver.) -- C:\Windows\System32\drivers\modem.sys [31744] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Monitor Driver.) -- C:\Windows\System32\drivers\monitor.sys [23552] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 02:20:44 A . (.Microsoft Corporation - Mouse Class Driver.) -- C:\Windows\System32\drivers\mouclass.sys [41552] =>.Microsoft Windows® O58 - SDL:2009/07/14 00:45:08 A . (.Microsoft Corporation - HID Mouse Filter Driver.) -- C:\Windows\System32\drivers\mouhid.sys [26112] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - Mount Point Manager.) -- C:\Windows\System32\drivers\mountmgr.sys [78568] =>.Microsoft® O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - MultiPath Support Bus-Driver.) -- C:\Windows\System32\drivers\mpio.sys [138472] =>.Microsoft® O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Microsoft Protection Service Driver.) -- C:\Windows\System32\drivers\mpsdrv.sys [60416] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Windows NT WebDav Minirdr.) -- C:\Windows\System32\drivers\mrxdav.sys [117248] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\mrxsmb.sys [126464] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - Longhorn SMB Downlevel SubRdr.) -- C:\Windows\System32\drivers\mrxsmb10.sys [226304] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Longhorn SMB 2.0 Redirector.) -- C:\Windows\System32\drivers\mrxsmb20.sys [98816] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - MS AHCI 1.0 Standard Driver.) -- C:\Windows\System32\drivers\msahci.sys [27880] =>.Microsoft® O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - Microsoft Device Specific Module.) -- C:\Windows\System32\drivers\msdsm.sys [117992] =>.Microsoft® O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - Mailslot driver.) -- C:\Windows\System32\drivers\msfs.sys [22528] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:51:08 A . (.Microsoft Corporation - Pass-through HID to KMDF Filter Driver.) -- C:\Windows\System32\drivers\mshidkmdf.sys [4096] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - ISA Driver.) -- C:\Windows\System32\drivers\msisadrv.sys [13544] =>.Microsoft® O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - Microsoft iSCSI Initiator Driver.) -- C:\Windows\System32\drivers\msiscsi.sys [235240] =>.Microsoft® O58 - SDL:2009/07/14 00:45:08 A . (.Microsoft Corporation - MS KS Server.) -- C:\Windows\System32\drivers\mskssrv.sys [8320] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:45:08 A . (.Microsoft Corporation - MS Proxy Clock.) -- C:\Windows\System32\drivers\mspclock.sys [5888] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:45:07 A . (.Microsoft Corporation - MS Proxy Quality Manager.) -- C:\Windows\System32\drivers\mspqm.sys [5504] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - Kernel Remote Procedure Call Provider.) -- C:\Windows\System32\drivers\msrpc.sys [164064] =>.Microsoft® O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - System Management BIOS Driver.) -- C:\Windows\System32\drivers\mssmbios.sys [27880] =>.Microsoft® O58 - SDL:2009/07/14 00:45:08 A . (.Microsoft Corporation - WDM Tee/Communication Transform Filter.) -- C:\Windows\System32\drivers\mstee.sys [6144] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:46:55 A . (.Microsoft Corporation - Microsoft Multi-Touch HID Driver.) -- C:\Windows\System32\drivers\MTConfig.sys [12288] [Unsigned] =>.Microsoft Corporation O58 - SDL:2016/05/10 11:36:12 A . (.Micron Technology, Inc. - Micron NVMe PCIe Controller Driver.) -- C:\Windows\System32\drivers\mtinvme.sys [101864] {0EFEAFE9BF5BACB6FFA5881DF9EA0A1A}. =>.Micron Technology, Inc. O58 - SDL:2020/04/20 22:23:13 A . (.Microsoft Corporation - Multiple UNC Provider Driver.) -- C:\Windows\System32\drivers\mup.sys [92392] =>.Microsoft® O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - NDIS 6.20 driver.) -- C:\Windows\System32\drivers\ndis.sys [715192] =>.Microsoft® O58 - SDL:2009/07/14 00:52:44 A . (.Microsoft Corporation - NDIS Packet Capture Filter Driver.) -- C:\Windows\System32\drivers\ndiscap.sys [27136] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - NDIS 3.0 connection wrapper driver.) -- C:\Windows\System32\drivers\ndistapi.sys [20992] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:06 A . (.Microsoft Corporation - NDIS User mode I/O driver.) -- C:\Windows\System32\drivers\ndisuio.sys [46080] [Unsigned] =>.Microsoft Corporation O58 - SDL:2010/11/20 22:29:19 A . (.Microsoft Corporation - MS PPP Framing Driver (Strong Encryption).) -- C:\Windows\System32\drivers\ndiswan.sys [118784] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - NDIS Proxy.) -- C:\Windows\System32\drivers\ndproxy.sys [48640] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - NetBIOS interface driver.) -- C:\Windows\System32\drivers\netbios.sys [36352] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netbt.sys [188928] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - Network I/O Subsystem.) -- C:\Windows\System32\drivers\netio.sys [242400] =>.Microsoft® O58 - SDL:2009/07/14 02:20:44 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [44624] =>.Microsoft Windows® O58 - SDL:2020/06/10 13:40:56 A . (.WireGuard LLC - Nlwt Driver.) -- C:\Windows\System32\drivers\nlwt.sys [27336] =>.TEFINCOM S.A.® O58 - SDL:2020/08/05 11:53:54 A . (.TEFINCOM S.A. - NordVPN LightWeight Firewall.) -- C:\Windows\System32\drivers\nordlwf.sys [26816] =>.TEFINCOM S.A.® O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - NPFS Driver.) -- C:\Windows\System32\drivers\npfs.sys [35328] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\drivers\nsiproxy.sys [17920] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\drivers\ntfs.sys [1216736] =>.Microsoft® O58 - SDL:2009/07/14 00:11:12 A . (.Microsoft Corporation - NULL Driver.) -- C:\Windows\System32\drivers\null.sys [4608] [Unsigned] =>.Microsoft Corporation O58 - SDL:2016/08/17 18:15:56 A . (. - Standard NVMe Storport Miniport Driver.) -- C:\Windows\System32\drivers\nvme.sys [64688] {38A6B946724226498C48291D33CFCDD3}. O58 - SDL:2020/04/20 22:23:00 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [116968] =>.Microsoft® O58 - SDL:2020/04/20 22:23:00 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [143592] =>.Microsoft® O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - NForce NT AGP Filter.) -- C:\Windows\System32\drivers\NV_AGP.SYS [104680] =>.Microsoft® O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - NativeWiFi Miniport Driver.) -- C:\Windows\System32\drivers\nwifi.sys [271360] [Unsigned] =>.Microsoft Corporation O58 - SDL:2016/06/10 12:58:14 A . (.TOSHIBA CORPORATION - Toshiba NVMe Driver.) -- C:\Windows\System32\drivers\ocznvme.sys [83624] =>.Toshiba America Electronic Components, Inc.® O58 - SDL:2016/06/10 12:58:14 A . (.TOSHIBA CORPORATION - Toshiba SSD controller TRIM filter driver.) -- C:\Windows\System32\drivers\ocztrimfilter.sys [25936] =>.Toshiba America Electronic Components, Inc.® O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - 1394 OpenHCI Port Driver.) -- C:\Windows\System32\drivers\ohci1394.sys [62464] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - QoS Packet Scheduler.) -- C:\Windows\System32\drivers\pacer.sys [104448] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - Parallel Port Driver.) -- C:\Windows\System32\drivers\parport.sys [79360] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:05 A . (.Microsoft Corporation - Partition Management Driver.) -- C:\Windows\System32\drivers\partmgr.sys [56040] =>.Microsoft® O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - VDM Parallel Driver.) -- C:\Windows\System32\drivers\parvdm.sys [8704] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - NT Plug and Play PCI Enumerator.) -- C:\Windows\System32\drivers\pci.sys [154344] =>.Microsoft® O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\pciide.sys [12520] =>.Microsoft® O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - PCI IDE Bus Driver Extension.) -- C:\Windows\System32\drivers\pciidex.sys [42728] =>.Microsoft® O58 - SDL:2009/07/14 02:19:03 A . (.Microsoft Corporation - PCMCIA Bus Driver.) -- C:\Windows\System32\drivers\pcmcia.sys [180288] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:19:04 A . (.Microsoft Corporation - Performance Counters for Windows Driver.) -- C:\Windows\System32\drivers\pcw.sys [43088] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - Protected Environment Authentication and Au.) -- C:\Windows\System32\drivers\PEAuth.sys [593920] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - Port Class (Class Driver for Port/Miniport.) -- C:\Windows\System32\drivers\portcls.sys [177152] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\processr.sys [52224] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 02:19:04 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1383488] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:19:04 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [106064] =>.Microsoft Windows® O58 - SDL:2009/07/14 00:54:13 A . (.Microsoft Corporation - Microsoft Quality Windows Audio Video Exper.) -- C:\Windows\System32\drivers\qwavedrv.sys [31744] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:54:40 A . (.Microsoft Corporation - RAS Automatic Connection Driver.) -- C:\Windows\System32\drivers\rasacd.sys [11776] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:54:34 A . (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\rasl2tp.sys [78848] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:05 A . (.Microsoft Corporation - RAS PPPoE mini-port/call-manager driver.) -- C:\Windows\System32\drivers\raspppoe.sys [78336] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:05 A . (.Microsoft Corporation - Peer-to-Peer Tunneling Protocol.) -- C:\Windows\System32\drivers\raspptp.sys [73728] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:54:58 A . (.Microsoft Corporation - RAS SSTP Miniport Call Manager.) -- C:\Windows\System32\drivers\rassstp.sys [75264] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) -- C:\Windows\System32\drivers\rdbss.sys [248320] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 01:02:41 A . (.Microsoft Corporation - Microsoft RDP Bus Device driver.) -- C:\Windows\System32\drivers\rdpbus.sys [18944] [Unsigned] =>.Microsoft Corporation O58 - SDL:2010/11/20 22:29:12 A . (.Microsoft Corporation - RDP Miniport.) -- C:\Windows\System32\drivers\RDPCDD.sys [6656] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:12 A . (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [133632] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 01:01:39 A . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\drivers\RDPENCDD.sys [6656] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 01:01:41 A . (.Microsoft Corporation - RDP Reflector Driver Miniport.) -- C:\Windows\System32\drivers\RDPREFMP.sys [7168] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:18:48 A . (.Microsoft Corporation - Microsoft RDP Video Miniport driver.) -- C:\Windows\System32\drivers\rdpvideominiport.sys [14848] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:05 A . (.Microsoft Corporation - RDP Terminal Stack Driver.) -- C:\Windows\System32\drivers\rdpwd.sys [186368] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - ReadyBoost Driver.) -- C:\Windows\System32\drivers\rdyboost.sys [173288] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:23:05 A . (.Microsoft Corporation - Reliable Multicast Transport.) -- C:\Windows\System32\drivers\rmcast.sys [117760] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:05 A . (.Microsoft Corporation - Remote NDIS Miniport.) -- C:\Windows\System32\drivers\RNDISMP.sys [33280] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:55:21 A . (.Microsoft Corporation - Legacy Non-Pnp Modem Device Driver.) -- C:\Windows\System32\drivers\rootmdm.sys [8192] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:53:20 A . (.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) -- C:\Windows\System32\drivers\rspndr.sys [60928] [Unsigned] =>.Microsoft Corporation O58 - SDL:2012/10/25 17:20:28 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.20 32-bit Dr.) -- C:\Windows\System32\drivers\Rt86win7.sys [585872] =>.Realtek Semiconductor Corp® O58 - SDL:2010/11/20 22:29:03 A . (.Microsoft Corporation - SBP-2 Protocol Driver.) -- C:\Windows\System32\drivers\sbp2port.sys [85376] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:23:13 A . (.Microsoft Corporation - Microsoft Smart Card Reader Filter Driver.) -- C:\Windows\System32\drivers\scfilter.sys [26624] [Unsigned] =>.Microsoft Corporation O58 - SDL:2010/11/20 22:29:12 A . (.Microsoft Corporation - SCSI Port Driver.) -- C:\Windows\System32\drivers\scsiport.sys [140160] =>.Microsoft Windows® O58 - SDL:2009/07/13 21:50:20 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [20480] [Unsigned] =>.Rovi Corporation O58 - SDL:2018/02/13 19:13:54 A . (.Samsung Electronics Co., Ltd - Samsung NVM Express Storport Miniport Drive.) -- C:\Windows\System32\drivers\secnvme.sys [75360] =>.Samsung Electronics Co., Ltd.® O58 - SDL:2018/02/13 19:13:54 A . (.Samsung Electronics Co., Ltd - Samsung NVMe Filter driver.) -- C:\Windows\System32\drivers\secnvmeF.sys [28528] =>.Samsung Electronics Co., Ltd.® O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - Serial Port Enumerator.) -- C:\Windows\System32\drivers\serenum.sys [17920] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:00 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) -- C:\Windows\System32\drivers\serial.sys [83968] [Unsigned] =>.Brother Industries Ltd. O58 - SDL:2009/07/14 00:45:08 A . (.Microsoft Corporation - Serial Mouse Filter Driver.) -- C:\Windows\System32\drivers\sermouse.sys [19968] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - Small Form Factor Disk Driver.) -- C:\Windows\System32\drivers\sffdisk.sys [11776] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - Small Form Factor MMC Protocol Driver.) -- C:\Windows\System32\drivers\sffp_mmc.sys [12288] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - Small Form Factor SD Protocol Driver.) -- C:\Windows\System32\drivers\sffp_sd.sys [12800] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:45:52 A . (.Microsoft Corporation - SCSI Floppy Driver.) -- C:\Windows\System32\drivers\sfloppy.sys [13824] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - SIS NT AGP Filter.) -- C:\Windows\System32\drivers\SISAGP.SYS [51944] =>.Microsoft® O58 - SDL:2009/07/14 02:19:04 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [40016] =>.Microsoft Windows® O58 - SDL:2009/07/14 02:19:04 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [77888] =>.Microsoft Windows® O58 - SDL:2009/07/14 00:53:41 A . (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [71168] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:45:28 A . (.Microsoft Corporation - Smart Card Driver Library.) -- C:\Windows\System32\drivers\smclib.sys [17408] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 02:19:03 A . (.Microsoft Corporation - loader for security processor.) -- C:\Windows\System32\drivers\spldr.sys [17472] =>.Microsoft Windows® O58 - SDL:2009/07/13 21:34:43 A . (.Microsoft Corporation - security processor.) -- C:\Windows\System32\drivers\spsys.sys [405504] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Server driver.) -- C:\Windows\System32\drivers\srv.sys [317440] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Smb 2.0 Server driver.) -- C:\Windows\System32\drivers\srv2.sys [314880] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Server Network driver.) -- C:\Windows\System32\drivers\srvnet.sys [117248] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 02:19:04 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [21072] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - Microsoft NVM Express Storport Miniport Dri.) -- C:\Windows\System32\drivers\stornvme.sys [41192] =>.Microsoft® O58 - SDL:2020/04/20 22:23:05 A . (.Microsoft Corporation - Microsoft Storage Port Driver.) -- C:\Windows\System32\drivers\storport.sys [150248] =>.Microsoft® O58 - SDL:2010/11/20 22:29:03 A . (.Microsoft Corporation - Storage VSC Driver.) -- C:\Windows\System32\drivers\storvsc.sys [28032] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:23:05 A . (.Microsoft Corporation - WDM CODEC Class Device Driver 2.0.) -- C:\Windows\System32\drivers\stream.sys [54656] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Plug and Play Software Device Enumerator.) -- C:\Windows\System32\drivers\swenum.sys [11880] =>.Microsoft® O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - Synthetic 3D SMT Support Driver.) -- C:\Windows\System32\drivers\Synth3dVsc.sys [77544] =>.Microsoft® O58 - SDL:2009/07/14 00:45:53 A . (.Microsoft Corporation - SCSI Tape Class Driver.) -- C:\Windows\System32\drivers\tape.sys [24576] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/06/09 10:25:46 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\Windows\System32\drivers\tapnordvpn.sys [31496] =>.TEFINCOM S.A.® O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - TCP/IP Driver.) -- C:\Windows\System32\drivers\tcpip.sys [1312992] =>.Microsoft® O58 - SDL:2020/04/20 22:20:47 A . (.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) -- C:\Windows\System32\drivers\tcpipreg.sys [35840] [Unsigned] =>.Microsoft Corporation O58 - SDL:2010/11/20 22:29:12 A . (.Microsoft Corporation - TDI Wrapper.) -- C:\Windows\System32\drivers\tdi.sys [21504] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:05 A . (.Microsoft Corporation - Named Pipe Transport Driver.) -- C:\Windows\System32\drivers\tdpipe.sys [21504] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:03 A . (.Microsoft Corporation - TCP Transport Driver.) -- C:\Windows\System32\drivers\tdtcp.sys [28672] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [74752] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Remote Desktop Server Driver.) -- C:\Windows\System32\drivers\termdd.sys [53992] =>.Microsoft® O58 - SDL:2020/04/20 22:18:48 A . (.Microsoft Corporation - Terminal Server Input Driver.) -- C:\Windows\System32\drivers\terminpt.sys [24064] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - TS Security Filter Driver.) -- C:\Windows\System32\drivers\tssecsrv.sys [31744] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:19:30 A . (.Microsoft Corporation - Remote Desktop USB Hub Filter Driver.) -- C:\Windows\System32\drivers\TsUsbFlt.sys [49152] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:19:30 A . (.Microsoft Corporation - Remote Desktop Generic USB Driver.) -- C:\Windows\System32\drivers\TsUsbGD.sys [26880] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Remote Desktop USB Hub.) -- C:\Windows\System32\drivers\tsusbhub.sys [113664] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:03 A . (.Microsoft Corporation - Microsoft Tunnel Interface Driver.) -- C:\Windows\System32\drivers\tunnel.sys [108544] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 02:19:10 A . (.Microsoft Corporation - MS AGPv3.5 Filter.) -- C:\Windows\System32\drivers\UAGP35.SYS [55888] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - UDF File System Driver.) -- C:\Windows\System32\drivers\udfs.sys [247296] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - ULi AGPv3.0 Filter for K8/9 Processor Platf.) -- C:\Windows\System32\drivers\ULIAGPKX.SYS [57064] =>.Microsoft® O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - User-Mode Bus Enumerator.) -- C:\Windows\System32\drivers\umbus.sys [39936] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:51:35 A . (.Microsoft Corporation - Generic pass-through driver.) -- C:\Windows\System32\drivers\umpass.sys [8192] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:05 A . (.Microsoft Corporation - Remote NDIS USB Driver.) -- C:\Windows\System32\drivers\usb8023.sys [15872] [Unsigned] =>.Microsoft Corporation O58 - SDL:2010/11/20 22:29:20 A . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) -- C:\Windows\System32\drivers\USBCAMD.sys [25856] [Unsigned] =>.Microsoft Corporation O58 - SDL:2010/11/20 22:29:20 A . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) -- C:\Windows\System32\drivers\USBCAMD2.sys [25856] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - USB Common Class Generic Parent Driver.) -- C:\Windows\System32\drivers\usbccgp.sys [76288] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - USB Consumer IR Driver for eHome.) -- C:\Windows\System32\drivers\usbcir.sys [86016] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Universal Serial Bus Driver.) -- C:\Windows\System32\drivers\usbd.sys [6016] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - EHCI eUSB Miniport Driver.) -- C:\Windows\System32\drivers\usbehci.sys [46592] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Default Hub Driver for USB.) -- C:\Windows\System32\drivers\usbhub.sys [259584] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - OHCI USB Miniport Driver.) -- C:\Windows\System32\drivers\usbohci.sys [20480] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - USB 1.1 & 2.0 Port Driver.) -- C:\Windows\System32\drivers\usbport.sys [285184] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 01:17:06 A . (.Microsoft Corporation - USB Printer driver.) -- C:\Windows\System32\drivers\usbprint.sys [19968] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:12 A . (.Microsoft Corporation - Windows USB Redirection Policy Manager.) -- C:\Windows\System32\drivers\usbrpm.sys [26112] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - USB Mass Storage Class Driver.) -- C:\Windows\System32\drivers\USBSTOR.SYS [76288] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - UHCI USB Miniport Driver.) -- C:\Windows\System32\drivers\usbuhci.sys [24576] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - USB Video Class Driver.) -- C:\Windows\System32\drivers\usbvideo.sys [146816] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Virtual Drive Root Enumerator.) -- C:\Windows\System32\drivers\vdrvroot.sys [32488] =>.Microsoft® O58 - SDL:2009/07/14 00:25:51 A . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\drivers\vga.sys [25088] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:25:49 A . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\drivers\vgapnp.sys [26112] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - VHD Miniport Driver.) -- C:\Windows\System32\drivers\vhdmp.sys [159976] =>.Microsoft® O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - VIA NT AGP Filter.) -- C:\Windows\System32\drivers\VIAAGP.SYS [52968] =>.Microsoft® O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\viac7.sys [53248] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:00 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [16616] =>.Microsoft® O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Video Port Driver.) -- C:\Windows\System32\drivers\videoprt.sys [107520] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - Virtual Machine Bus.) -- C:\Windows\System32\drivers\vmbus.sys [175336] =>.Microsoft® O58 - SDL:2010/11/20 22:29:03 A . (.Microsoft Corporation - Microsoft VMBus HID Miniport.) -- C:\Windows\System32\drivers\VMBusHID.sys [17920] [Unsigned] =>.Microsoft Corporation O58 - SDL:2010/11/20 22:29:03 A . (.Microsoft Corporation - Microsoft S3 Emulated Device Cap Driver.) -- C:\Windows\System32\drivers\vms3cap.sys [5632] [Unsigned] =>.Microsoft Corporation O58 - SDL:2010/11/20 22:29:03 A . (.Microsoft Corporation - Virtual Storage Filter Driver.) -- C:\Windows\System32\drivers\vmstorfl.sys [40704] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\drivers\volmgr.sys [52968] =>.Microsoft® O58 - SDL:2020/04/20 22:25:01 A . (.Microsoft Corporation - Volume Manager Extension Driver.) -- C:\Windows\System32\drivers\volmgrx.sys [296680] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:23:00 A . (.Microsoft Corporation - Volume Shadow Copy Driver.) -- C:\Windows\System32\drivers\volsnap.sys [246504] =>.Microsoft® O58 - SDL:2009/07/14 02:19:11 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [141904] =>.Microsoft Windows® O58 - SDL:2009/07/13 23:13:45 A . (.Conexant Systems, Inc. - HSF_HWAZL WDM driver.) -- C:\Windows\System32\drivers\VSTAZL3.SYS [207360] [Unsigned] =>.Conexant Systems, Inc. O58 - SDL:2009/07/13 23:13:45 A . (.Conexant Systems, Inc. - HSF_CNXT driver.) -- C:\Windows\System32\drivers\VSTCNXT3.SYS [661504] [Unsigned] =>.Conexant Systems, Inc. O58 - SDL:2009/07/13 23:13:46 A . (.Conexant Systems, Inc. - HSF_DP driver.) -- C:\Windows\System32\drivers\VSTDPV3.SYS [980992] [Unsigned] =>.Conexant Systems, Inc. O58 - SDL:2020/04/20 22:23:02 A . (.Microsoft Corporation - Virtual WiFi Bus Driver.) -- C:\Windows\System32\drivers\vwifibus.sys [20480] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:02 A . (.Microsoft Corporation - Virtual WiFi Filter Driver.) -- C:\Windows\System32\drivers\vwififlt.sys [48640] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:23:02 A . (.Microsoft Corporation - Virtual WiFi Miniport Driver.) -- C:\Windows\System32\drivers\vwifimp.sys [14848] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:46:53 A . (.Microsoft Corporation - Wacom Serial Pen Tablet HID Driver.) -- C:\Windows\System32\drivers\wacompen.sys [21632] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) -- C:\Windows\System32\drivers\wanarp.sys [63488] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 00:24:11 A . (.Microsoft Corporation - Watchdog Driver.) -- C:\Windows\System32\drivers\watchdog.sys [35328] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 02:19:11 A . (.Microsoft Corporation - Microsoft Watchdog Timer Driver.) -- C:\Windows\System32\drivers\wd.sys [19024] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:23:03 A . (.Microsoft Corporation - Kernel Mode Driver Framework Runtime.) -- C:\Windows\System32\drivers\Wdf01000.sys [527064] =>.Microsoft® O58 - SDL:2020/04/20 22:19:03 A . (.Microsoft Corporation - Kernel Mode Driver Framework Loader.) -- C:\Windows\System32\drivers\WdfLdr.sys [47720] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:23:03 A . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) -- C:\Windows\System32\drivers\wfplwf.sys [16616] =>.Microsoft® O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - Wim file system Driver.) -- C:\Windows\System32\drivers\wimmount.sys [20704] =>.Microsoft® O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - Windows Hypervisor Interface Driver.) -- C:\Windows\System32\drivers\winhv.sys [43240] =>.Microsoft® O58 - SDL:2020/04/20 22:23:01 A . (.Microsoft Corporation - Windows USB Class Driver BETA.) -- C:\Windows\System32\drivers\winusb.sys [36096] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:24:59 A . (.Microsoft Corporation - Windows Management Interface for ACPI.) -- C:\Windows\System32\drivers\wmiacpi.sys [11264] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/14 02:19:10 A . (.Microsoft Corporation - WMILIB WMI support library Dll.) -- C:\Windows\System32\drivers\wmilib.sys [14912] =>.Microsoft Windows® O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - Winsock2 IFS Layer.) -- C:\Windows\System32\drivers\ws2ifsl.sys [16384] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:19:06 A . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\drivers\WUDFPf.sys [66560] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:19:06 A . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\drivers\WUDFRd.sys [155136] [Unsigned] =>.Microsoft Corporation O58 - SDL:2012/02/22 15:27:02 A . (.Bigfoot Networks, Inc. - Bigfoot Networks Killer(TM) PCI-E Gaming Ad.) -- C:\Windows\System32\drivers\Xeno7x86.sys [130152] =>.Bigfoot Networks, Inc.® O58 - SDL:2009/07/13 22:40:41 A . (...) -- C:\Windows\System32\ANSI.SYS [9029] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:01 A . (.Microsoft Corporation - Common Log File System Driver.) -- C:\Windows\System32\clfs.sys [253880] =>.Microsoft® O58 - SDL:2009/07/13 22:40:44 A . (...) -- C:\Windows\System32\country.sys [27097] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:40 A . (...) -- C:\Windows\System32\HIMEM.SYS [4768] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:43 A . (...) -- C:\Windows\System32\KEY01.SYS [42809] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:43 A . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:23 A . (...) -- C:\Windows\System32\NTDOS.SYS [27866] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:31 A . (...) -- C:\Windows\System32\NTDOS404.SYS [29146] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:35 A . (...) -- C:\Windows\System32\NTDOS411.SYS [29370] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:39 A . (...) -- C:\Windows\System32\NTDOS412.SYS [29274] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:27 A . (...) -- C:\Windows\System32\NTDOS804.SYS [29146] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:11 A . (...) -- C:\Windows\System32\NTIO.SYS [33952] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:15 A . (...) -- C:\Windows\System32\NTIO404.SYS [34672] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:17 A . (...) -- C:\Windows\System32\NTIO411.SYS [35776] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:19 A . (...) -- C:\Windows\System32\NTIO412.SYS [35536] [Unsigned] =>.Microsoft Corporation O58 - SDL:2009/07/13 22:40:13 A . (...) -- C:\Windows\System32\NTIO804.SYS [34672] [Unsigned] =>.Microsoft Corporation O58 - SDL:2020/04/20 22:25:00 A . (.Microsoft Corporation - Multi-User Win32 Driver.) -- C:\Windows\System32\win32k.sys [2408960] [Unsigned] =>.Microsoft Corporation ---\\ Last modified or created user files (19) - 61s O61 - LFC: 2020/09/13 16:49:25 A . (..) -- C:\Users\lonly\AppData\Local\Programs\Opera GX\68.0.3618.206\installer.exe [5733912] [Unsigned] O61 - LFC: 2020/09/07 10:34:35 A . (..) -- C:\Users\lonly\AppData\Local\Programs\Opera GX\68.0.3618.206\installer_helper.exe [360472] [Unsigned] O61 - LFC: 2020/09/07 10:34:35 A . (..) -- C:\Users\lonly\AppData\Local\Programs\Opera GX\68.0.3618.206\notification_helper.exe [761368] [Unsigned] O61 - LFC: 2020/09/02 22:29:38 A . (..) -- C:\Users\lonly\AppData\Local\Programs\Opera GX\68.0.3618.206\opera.exe [993304] [Unsigned] O61 - LFC: 2020/09/07 10:34:35 A . (..) -- C:\Users\lonly\AppData\Local\Programs\Opera GX\68.0.3618.206\opera_autoupdate.exe [3224600] [Unsigned] O61 - LFC: 2020/09/07 10:34:35 A . (..) -- C:\Users\lonly\AppData\Local\Programs\Opera GX\68.0.3618.206\opera_crashreporter.exe [1309208] [Unsigned] O61 - LFC: 2020/09/07 10:34:35 A . (..) -- C:\Users\lonly\AppData\Local\Programs\Opera GX\68.0.3618.206\opera_gx_splash.exe [1710104] [Unsigned] O61 - LFC: 2020/09/04 16:18:52 A . (..) -- C:\Users\lonly\AppData\Local\Programs\Opera GX\launcher.exe [1314328] [Unsigned] O61 - LFC: 2020/09/12 09:30:51 A . (..) -- C:\Users\lonly\AppData\Roaming\Foxit Software\Addon\Foxit PhantomPDF\FoxitPhantomPDFUpdater.exe [5576624] [Unsigned] O61 - LFC: 2020/09/07 09:15:51 A . (..) -- C:\Users\lonly\AppData\Roaming\Foxit Software\Addon\Foxit Reader\FoxitReaderUpdater.exe [4514224] [Unsigned] O61 - LFC: 2020/08/29 08:48:59 A . (..) -- C:\Users\lonly\AppData\Roaming\uTorrent\helper\helper.exe [4781800] [Unsigned] O61 - LFC: 2020/08/29 08:48:59 A . (..) -- C:\Users\lonly\AppData\Roaming\uTorrent\updates\3.5.5_45724\utorrentie.exe [467688] [Unsigned] O61 - LFC: 2020/08/26 09:45:05 A . (..) -- C:\Users\lonly\AppData\Roaming\uTorrent\updates\3.5.5_45790.exe [2154712] [Unsigned] O61 - LFC: 2020/09/12 10:45:03 A . (..) -- C:\Users\lonly\AppData\Roaming\uTorrent\updates\3.5.5_45790\utorrentie.exe [469208] [Unsigned] O61 - LFC: 2020/09/13 17:00:32 A . (..) -- C:\Users\lonly\AppData\Roaming\uTorrent\uTorrent.exe [2237656] [Unsigned] O61 - LFC: 2020/08/19 06:50:50 N . (..) -- C:\Users\lonly\Desktop\New folder\Detection.exe [4165720] [Unsigned] O61 - LFC: 2020/08/19 06:50:50 A . (..) -- C:\Users\lonly\Desktop\New folder\SportSwitcherSetup_210.exe [1757817] [Unsigned] O61 - LFC: 2020/09/07 10:35:07 A . (..) -- C:\Users\lonly\Desktop\OperaGXSetup.exe [3874984] [Unsigned] O61 - LFC: 2020/09/13 17:04:31 A . (..) -- C:\Users\lonly\Downloads\ChromeSetup.exe [1337048] [Unsigned] ---\\ File Associations Shell Spawning (11) - 0s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe [Unsigned] =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe [Unsigned] =>.Microsoft Corporation O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- Bad: (C:\Windows\svchost.com "%1" %*) Good: ("%1" %*) =>Broken.OpenCommand =>.Default.Value O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (...) -- C:\Windows\System32\WScript.exe "%1" %* =>.Default.Value O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe [Unsigned] =>.Microsoft Corporation O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S =>.Default.Value O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opa\launcher.exe =>.Opera Software AS® ---\\ Start Menu Internet (8) - 1s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation ---\\ Search Browser Infection (3) - 15s O69 - SBI: SearchScopes [HKCU]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ =>.Bing.com O69 - SBI: SearchScopes [HKCU]{993F5746-4C15-42BC-99C1-064A1764271B} - (DefaultSearchYahoo) - http://securesearch.org? O69 - SBI: SearchScopes [HKLM]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com ---\\ Search Svchost Services (33) - 2s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\Windows\System32\aelupsvc.dll [61952] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [69120] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [69120] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\Windows\System32\srvsvc.dll [167936] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\Windows\System32\gpsvc.dll [606720] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\IKEEXT.DLL [681984] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\Windows\System32\audiosrv.dll [474624] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\Windows\System32\rasauto.dll [90624] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [286720] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [75264] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\Windows\System32\Sens.dll [49664] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [300032] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [242176] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remote Desktop Session Host Server Remote C.) -- C:\Windows\System32\termsrv.dll [527872] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\System32\wuaueng2.dll [2091520] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\Windows\System32\qmgr.dll [586240] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [328704] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [502784] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\Windows\System32\seclogon.dll [21504] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\Windows\System32\appinfo.dll [47104] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\Windows\System32\iscsiexe.dll [114688] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) -- C:\Windows\System32\mmcss.dll [49664] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\Windows\System32\wercplsupport.dll [62976] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [98304] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [177152] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\Windows\System32\schedsvc.dll [751104] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\Windows\System32\KMSVC.DLL [71168] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [119296] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\Windows\System32\browser.dll [101888] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\Windows\System32\themeservice.dll [37376] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\Windows\System32\bdesvc.dll [76800] [Unsigned] =>.Microsoft Corporation O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Software installation Service.) -- C:\Windows\System32\appmgmts.dll [149504] [Unsigned] =>.Microsoft Corporation ---\\ Firewall Active Exception List (15) - 2s O87 - FAEL: "TCP Query User{0C8DCB34-1E60-4548-B0DF-DC29DE27078E}C:\tactical ops\system\tacticalops.exe" [In-None-P6-TRUE] .(...) -- C:\tactical ops\system\tacticalops.exe [Unsigned] O87 - FAEL: "UDP Query User{E6372284-2747-4156-9635-B598561ECEB8}C:\tactical ops\system\tacticalops.exe" [In-None-P17-TRUE] .(...) -- C:\tactical ops\system\tacticalops.exe [Unsigned] O87 - FAEL: "{EE20285B-74D3-4C80-9E85-6E62127A2BE5}" [In-None-P6-TRUE] .(.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O87 - FAEL: "{484264DE-F68F-47C6-8195-BFA8D98D185C}" [In-None-P17-TRUE] .(.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation® O87 - FAEL: "{CB570287-13CD-43D2-B1BC-E8EDCBE0AE7B}" [In-None-P6-FALSE] .(.IBM Corp. - IBM SPSS Statistics 21.0 Command.) -- C:\Program Files\IBM\SPSS\Statistics\21\stats.com [Unsigned] =>.IBM Corp. O87 - FAEL: "{0D4C6E3A-AF5C-486A-9421-F127C1CA87B7}" [In-None-P6-FALSE] .(.IBM Corp. - IBM SPSS Statistics 21.0.) -- C:\Program Files\IBM\SPSS\Statistics\21\stats.exe [Unsigned] =>.IBM Corp. O87 - FAEL: "{7A53E0EA-650F-4C46-979C-0D569D2B6093}" [In-None-P6-FALSE] .(.IBM Corp. - IBM SPSS WinWrap Basic IDE 21.0.) -- C:\Program Files\IBM\SPSS\Statistics\21\WinWrapIDE.exe [Unsigned] =>.IBM Corp. O87 - FAEL: "{B348DBA0-0724-4F8B-8C5D-6A1F001561EA}" [In-None-P17-FALSE] .(.IBM Corp. - IBM SPSS Statistics 21.0 Command.) -- C:\Program Files\IBM\SPSS\Statistics\21\stats.com [Unsigned] =>.IBM Corp. O87 - FAEL: "{9E98C48F-DE1B-42DE-B5EC-6663084A1475}" [In-None-P17-FALSE] .(.IBM Corp. - IBM SPSS Statistics 21.0.) -- C:\Program Files\IBM\SPSS\Statistics\21\stats.exe [Unsigned] =>.IBM Corp. O87 - FAEL: "{C18F2AC9-86D9-4860-9D9A-E8B0B58416FC}" [In-None-P17-FALSE] .(.IBM Corp. - IBM SPSS WinWrap Basic IDE 21.0.) -- C:\Program Files\IBM\SPSS\Statistics\21\WinWrapIDE.exe [Unsigned] =>.IBM Corp. O87 - FAEL: "{352BA8E4-1F06-4AB2-8145-61E44D6DE3F8}" [In-None-P6-TRUE] .(...) -- C:\Users\lonly\AppData\Roaming\uTorrent\uTorrent.exe [Unsigned] O87 - FAEL: "{EBC8CBEB-DC6F-47DC-8D8F-A5A772F187B1}" [In-None-P17-TRUE] .(...) -- C:\Users\lonly\AppData\Roaming\uTorrent\uTorrent.exe [Unsigned] O87 - FAEL: "{66685C92-FB66-45CC-B52E-EDAC044B7DE2}" [In-None-P17-TRUE] .(...) -- C:\Users\lonly\AppData\Local\Programs\Opera GX\68.0.3618.206\opera.exe [Unsigned] O87 - FAEL: "{62B99719-E20A-49DE-A971-ECD35E516711}" [In-None-P17-TRUE] .(.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opa\70.0.3728.154\opera.exe =>.Opera Software AS® O87 - FAEL: "{0BB4AF5C-96A8-437A-9A26-ABE851471436}" [In-None-P17-TRUE] .(.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opa\70.0.3728.178\opera.exe =>.Opera Software AS® ---\\ Product Upgrade Codes (43) - 2s O90 - PUC: "00004109001010400000000000F01FEC" [HKLM] . (.Microsoft Office O MUI (Arabic) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109101010400000000000F01FEC" [HKLM] . (.Microsoft Office X MUI (Arabic) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109110000000000000000F01FEC" [HKLM] . (.Microsoft Office Professional Plus 2010.) =>.Microsoft Corporation O90 - PUC: "000041091A0010400000000000F01FEC" [HKLM] . (.Microsoft Office OneNote MUI (Arabic) 2010.) =>.Microsoft Corporation O90 - PUC: "000041091A0090400000000000F01FEC" [HKLM] . (.Microsoft Office OneNote MUI (English) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109440010400000000000F01FEC" [HKLM] . (.Microsoft Office InfoPath MUI (Arabic) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109440090400000000000F01FEC" [HKLM] . (.Microsoft Office InfoPath MUI (English) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109510010400000000000F01FEC" [HKLM] . (.Microsoft Office Access MUI (Arabic) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109510090400000000000F01FEC" [HKLM] . (.Microsoft Office Access MUI (English) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109511090400000000000F01FEC" [HKLM] . (.Microsoft Office Shared Setup Metadata MUI (English) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109610010400000000000F01FEC" [HKLM] . (.Microsoft Office Excel MUI (Arabic) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109610090400000000000F01FEC" [HKLM] . (.Microsoft Office Excel MUI (English) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109710010400000000000F01FEC" [HKLM] . (.Microsoft Office SharePoint Designer MUI (Arabic) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109711090400000000000F01FEC" [HKLM] . (.Microsoft Office Access Setup Metadata MUI (English) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109810010400000000000F01FEC" [HKLM] . (.Microsoft Office PowerPoint MUI (Arabic) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109810090400000000000F01FEC" [HKLM] . (.Microsoft Office PowerPoint MUI (English) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109910010400000000000F01FEC" [HKLM] . (.Microsoft Office Publisher MUI (Arabic) 2010.) =>.bl.org O90 - PUC: "00004109910090400000000000F01FEC" [HKLM] . (.Microsoft Office Publisher MUI (English) 2010.) =>.bl.org O90 - PUC: "00004109A10010400000000000F01FEC" [HKLM] . (.Microsoft Office Outlook MUI (Arabic) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109A10090400000000000F01FEC" [HKLM] . (.Microsoft Office Outlook MUI (English) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109AB0010400000000000F01FEC" [HKLM] . (.Microsoft Office Groove MUI (Arabic) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109AB0090400000000000F01FEC" [HKLM] . (.Microsoft Office Groove MUI (English) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109B10010400000000000F01FEC" [HKLM] . (.Microsoft Office Word MUI (Arabic) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109B10090400000000000F01FEC" [HKLM] . (.Microsoft Office Word MUI (English) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109C20010400000000000F01FEC" [HKLM] . (.Microsoft Office Proofing (Arabic) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109C20090400000000000F01FEC" [HKLM] . (.Microsoft Office Proofing (English) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109E60010400000000000F01FEC" [HKLM] . (.Microsoft Office Shared MUI (Arabic) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109E60090400000000000F01FEC" [HKLM] . (.Microsoft Office Shared MUI (English) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109F10010400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (Arabic) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109F10090400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (English) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109F100A0C00000000000F01FEC" [HKLM] . (.Microsoft Office Proof (Spanish) 2010.) =>.Microsoft Corporation O90 - PUC: "00004109F100C0400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (French) 2010.) =>.Microsoft Corporation O90 - PUC: "0478F92BB273F213E8EE81FF58C7BC8B" [HKLM] . (.Microsoft .NET Framework 4.8.) -- C:\Windows\Installer\{B29F8740-372B-312F-8EEE-18FF857CCBB8}\DisplayIcon =>.Microsoft Corporation O90 - PUC: "2C9B62E180DEAEE4388C7A6805B2145E" [HKLM] . (.IBM SPSS Statistics 21.) -- C:\Windows\Installer\{1E26B9C2-ED08-4EEA-83C8-A786502B41E5}\ARPPRODUCTICON.exe =>.IBM Corporation O90 - PUC: "47CA2FBBC0273BC32819E543302923AF" [HKLM] . (.Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24215.) =>.Microsoft Corporation O90 - PUC: "4EA42A62D9304AC4784BF2238120150F" [HKLM] . (.Java 8 Update 251.) -- C:\Program Files\Java\jre1.8.0_251\\bin\javaws.exe =>.Sun Microsystems O90 - PUC: "6D5CED799EB2BB54FB5C72B458B184B6" [HKLM] . (.NordVPN network TAP.) -- C:\Windows\Installer\{97DEC5D6-2BE9-45BB-BFC5-274B851B486B}\appwindow.exe =>.Hewlett-Packard O90 - PUC: "CA4ECB96275917232ABF4932DB3AA634" [HKLM] . (.Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24215.) =>.Microsoft Corporation O90 - PUC: "D20352A90C039D93DBF6126ECE614057" [HKLM] . (.Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17.) =>.bl.org O90 - PUC: "e584f45a55a8ae11fbf045fb466ac362" [HKLM] . (.Foxit PhantomPDF.) -- C:\Windows\Installer\{a54f485e-8a55-11ea-bf0f-54bf64a63c26}\IconName.exe =>.Foxit Corporation O90 - PUC: "F40A0F1D789B3734E96204CDF6F19960" [HKLM] . (.Windows IPTV Player.) -- C:\Windows\Installer\{D1F0A04F-B987-4373-9E26-40DC6F1F9906}\windows_iptv_player.exe =>.Microsoft Corporation O90 - PUC: "F60730A4A66673047777F5728467D401" [HKLM] . (.Java Auto Updater.) =>.Sun Microsystems O90 - PUC: "FBE9CE37053883C42926C34B4635F29A" [HKLM] . (.NordVPN network TUN.) -- C:\Windows\Installer\{73EC9EBF-8350-4C38-9262-3CB464532FA9}\appwindow.exe =>.Hewlett-Packard ---\\ Windows Installer Scan (7) - 46s [MD5.A59A9355E1891EEE1D43601495E888EC] [WIS][2020/04/29 13:12:24] (.Foxit Software Inc. - Foxit PhantomPDF.) -- C:\Windows\Installer\4977887.msi [638676992] =>.Foxit Software Inc. [MD5.C1E2138037F154751E37711E5DC252AD] [WIS][2020/05/09 20:49:58] (.Oracle Corporation - Java SE Runtime Environment 8 Update 251.) -- C:\Windows\Installer\511e9d.msi [65818624] =>.Oracle Corporation [MD5.2973BAD4D8C3F304022410562F9C3FA0] [WIS][2020/05/09 20:50:57] (.Oracle Corporation - Java Auto Updater.) -- C:\Windows\Installer\511ea3.msi [782336] =>.Oracle Corporation [MD5.4CA5C03E71F44E9EC0517FD525FE4551] [WIS][2020/05/16 23:58:41] (.IBM Corp - SPSS Statistics 21.0.) -- C:\Windows\Installer\a9aa1b7.msi [1033838872] =>.IBM Corp [MD5.CAF295DA27D1225AC76DE35B1EE7D5FD] [WIS][2020/09/08 22:03:51] (.Xtream Codes LTD - Windows IPTV Player.) -- C:\Windows\Installer\d44560.msi [1972736] [MD5.B253838FCF46217C4D7508D904B05125] [WIS][2020/08/05 12:24:51] (.NordVPN - NordVPN network TUN.) -- C:\Windows\Installer\eaa00dc.msi [2057728] =>.NordVPN [MD5.BB7246C741E7DE22FF8523D905EF250E] [WIS][2020/09/13 05:50:24] (.NordVPN - NordVPN network TAP.) -- C:\Windows\Installer\eaa00e2.msi [1558528] =>.NordVPN ---\\ FEATURE CONTROL. (173) - 0s [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:clview.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:GROOVE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OUTLOOK.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:infopath.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:ehExtHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:msn6.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:clview.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:FoxitReader.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:AcqWeb.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:Activation.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:FoxitPhantomPDF.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_ISO_2022_JP_SNIFFING]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPfewgsrv.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGuiIT.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGUI.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLgPad.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLOGON.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:Scale_for_R3.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:ehExtHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:clview.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:ieuser.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK]:YahooMusicEngine.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:devenv.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:dexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:helppane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS]:msfeedssync.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HIGH_CONTRAST_BACKGROUND_IMAGES]:sidebar.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:ehExtHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:clview.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:GROOVE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OUTLOOK.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PROLOG]:msiexec.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:wm.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:cs.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:waol.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPARAMS]:helppane.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS]:wlmail.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:clview.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:msaccess.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Groove.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OUTLOOK.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:ehExtHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:clview.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:GROOVE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OUTLOOK.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:ehExtHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:clview.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:GROOVE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OUTLOOK.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:mshta.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:outlook.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:sidebar.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:ehExtHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:clview.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:GROOVE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OUTLOOK.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:ehExtHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING]:communicator.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:GROOVE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OUTLOOK.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:clview.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msimn.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:winmail.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:clview.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:GROOVE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OUTLOOK.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:ehExtHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:clview.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:GROOVE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OUTLOOK.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:clview.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:GROOVE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OUTLOOK.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:winmail.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:msimn.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:outlook.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:ehExtHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:clview.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:GROOVE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OUTLOOK.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:infopath.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:winword.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:excel.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:powerpnt.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:ehExtHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:GROOVE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OUTLOOK.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD]:msn.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD]:msn6.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:GROOVE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OUTLOOK.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:clview.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:GROOVE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OUTLOOK.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:explorer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:iexplore.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:prevhost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:wmplayer.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:PresentationHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:ehExtHost.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:clview.exe =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:GROOVE.EXE =>.Legitimate [HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OUTLOOK.EXE =>.Legitimate ---\\ Observer Of Events (109) - 54s Application.Error: Application Error (68) ~Numéro: 6227 ~Date: 09/13/2020 04:59:53 PM ~ID: 1000 ~Description: Faulting application name: %1, version: %2, time stamp: 0x5f4019f5 Faulting module name: %4, version: %5, time stamp: 0x5e82f304 Exception code: 0xc0000005 Fault offset: 0x00065339 Faulting process id: 0xa10 Faulting application start time: 0x01d689e ~Suggestion: Réparer ou réinstaller l'application. Application.Error: WinMgmt (88) ~Numéro: 6226 ~ID: 10 ~Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ~Suggestion: Aucune Application.Warning: Microsoft-Windows-User Profiles Service (14) ~Numéro: 6217 ~Date: 09/13/2020 04:58:21 PM ~ID: 1530 ~Description: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 12 user registry hand Application.Error: VSS (2) ~Numéro: 6202 ~Date: 09/13/2020 04:47:46 PM ~ID: 8194 ~Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = %1. This is often caused by incorrect security settings in either the writer or requestor process. Operation: Gathering Writer DataContext: Wr ~Suggestion: Localiser les enregistreurs VSS qui se trompent et changer le compte sous lequel ils s'exécutent du service réseau au système local. Ajuster les autorisations d'activation du service COM par défaut Application.Warning: Windows Search Service (23) ~Numéro: 6068 ~Date: 09/09/2020 02:37:38 PM ~ID: 3036 ~Description: The content source <%2> cannot be accessed.Context: Application, SystemIndex CatalogDetails: The URL was already processed during this update. If you received this message while processing alerts, then the alerts are redundant, or else Modify should ~Suggestion: https://www.repairwin.com/fix-windows-event-3036-search-content-source-cannot-accessed-solved/ Application.Error: Microsoft Office 14 (5) ~Numéro: 5903 ~Date: 09/07/2020 08:17:20 AM ~ID: 2000 ~Description: %1: Accepted Safe Mode action : %2. Accepted Safe Mode action : %1. Application.Warning: EventSystem (2) ~Numéro: 5771 ~Date: 09/02/2020 10:28:57 PM ~ID: 4627 ~Description: 800705b4DisplayLock{D5978630-5B9F-11D1-8DD2-00AA004ABD5E}Explorer180 Application.Error: ESENT (1) ~Numéro: 5661 ~Date: 09/02/2020 10:35:50 AM ~ID: 455 ~Description: %1 (%2) %3Error %5 occurred while opening logfile %4. ~Suggestion: Créer un dossier C:\Windows\system32\config\systemprofile\AppData\Local\TileDataLayer\Database Application.Warning: Microsoft-Windows-CAPI2 (1) ~Numéro: 4778 ~Date: 07/28/2020 09:11:37 PM ~ID: 4102 ~Description: Reached crypt32 threshold of %1 events and will suspend logging for %2 minutes. ~Suggestion: https://support.microsoft.com/en-gb/help/321208/troubleshooting-wins-error-event-id-4102-4243-4242-and-4286-messages Application.Error: Application Hang (3) ~Numéro: 3454 ~Date: 06/18/2020 10:11:17 PM ~ID: 1002 ~Description: The program %1 version %2 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 13f4 Start Time: 01d645b4eb07346f Termi ~Suggestion: Essayer les commandes suivantes ipconfig /release et ipconfig / renew. Application.Error: SideBySide (12) ~Numéro: 2796 ~Date: 06/09/2020 08:19:09 AM ~ID: 33 ~Description: Activation context generation failed for "%11". Dependent Assembly %1 could not be found. Please use sxstrace.exe for detailed diagnosis. ~Suggestion: Ces erreurs peuvent généralement être ignorées System.Error: Schannel (163) ~Numéro: 29705 ~Date: 09/13/2020 05:47:08 PM ~ID: 4119 ~Description: The following fatal alert was received: %1. System.Error: Disk (66) ~Numéro: 29702 ~Date: 09/13/2020 05:43:28 PM ~ID: 7 ~Description: The device, %1, has a bad block. System.Warning: Microsoft-Windows-DNS-Client (81) ~Numéro: 29700 ~Date: 09/13/2020 05:41:07 PM ~ID: 1014 ~Description: Name resolution for the name %1 timed out after none of the configured DNS servers responded. ~Suggestion: https://social.technet.microsoft.com/wiki/contents/articles/3336.event-id-1014-microsoft-windows-dns-client.aspx System.Warning: Microsoft-Windows-WLAN-AutoConfig (3) ~Numéro: 29581 ~Date: 09/13/2020 04:58:34 PM ~ID: 4001 ~Description: WLAN AutoConfig service has successfully stopped. System.Error: Service Control Manager (7) ~Numéro: 29544 ~Date: 09/13/2020 04:58:26 PM ~ID: 7034 ~Description: The %1 service terminated unexpectedly. It has done this %2 time(s). System.Warning: Tcpip (1) ~Numéro: 29463 ~Date: 09/13/2020 07:53:40 AM ~ID: 4228 ~Description: TCP/IP has chosen to restrict the scale factor due to a network condition. This could be related to a problem in a network device and will cause degraded throughput. System.Error: Ntfs (318) ~Numéro: 28895 ~Date: 09/10/2020 09:22:32 AM ~ID: 55 ~Description: The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume %2. System.Warning: Microsoft-Windows-Kernel-PnP (1) ~Numéro: 28865 ~Date: 09/10/2020 05:04:31 AM ~ID: 219 ~Description: 122WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ADATA&PROD_USB_FLASH_DRIVE&REV_0.00#1522711392160089&0#322122634114\Driver\WUDFRd0 ~Suggestion: Vérifier que le pilote a bien été chargé dans les informations système System.Error: EventLog (14) ~Numéro: 28678 ~Date: 09/09/2020 02:37:09 PM ~ID: 6008 ~Description: The previous system shutdown at %1 on %2 was unexpected. ---\\ Additional Scan (O88) (12) - 9s C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe =>PUP.Optional.LavasoftWebCompanion C:\Users\lonly\AppData\Roaming\Mozilla\Firefox\Profiles\bjwvsb0f.default-release\searchplugins\yahoo.xml =>PUP.Optional.BDYahoo HKU\S-1-5-21-1335184104-3918391407-3771364805-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com =>PUP.Optional.LavasoftWebCompanion HKCU\Software\Lavasoft\Web Companion =>PUP.Optional.LavasoftWebCompanion HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com =>PUP.Optional.LavasoftWebCompanion HKLM\SOFTWARE\Lavasoft\Web Companion =>PUP.Optional.LavasoftWebCompanion C:\Program Files\lavasoft\web companion =>PUP.Optional.LavasoftWebCompanion C:\ProgramData\lavasoft\web companion =>PUP.Optional.LavasoftWebCompanion C:\Users\lonly\AppData\Roaming\IObit\Advanced SystemCare =>SUP.Optional.AdvancedSystemCare C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS C:\ProgramData\IObit\Advanced SystemCare =>SUP.Optional.AdvancedSystemCare C:\ProgramData\Application Data\lavasoft\web companion =>PUP.Optional.LavasoftWebCompanion ---\\ Summary of the elements found (5) - 0s https://nicolascoolman.eu/2017/03/12/superfluous-lavasoftwebcompanion/ =>PUP.Optional.LavasoftWebCompanion https://nicolascoolman.eu/forum/Topic/warning-eventlogapp-evenement-dapplication/ =>Warning.EventLogApp https://nicolascoolman.eu/forum/Topic/warning-eventlogsys-evenement-systeme/ =>Warning.EventLogSys https://nicolascoolman.eu/wp-content/uploads/2017/12/26/sup-advancedsystemcare/ =>SUP.Optional.AdvancedSystemCare https://nicolascoolman.eu/2017/02/02/hacktool-autokms/ =>HackTool.AutoKMS ---\\ Serial Number [02FA994D660DE659EE9037ECB437D766] [29/07/2020] (.Piriform Software Ltd.) - C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Software Ltd [02FA994D660DE659EE9037ECB437D766] [29/07/2020] (.Piriform Software Ltd.) - C:\Program Files\CCleaner\uninst.exe =>.Piriform Software Ltd [034F328F3EFF4FB98F5343811788F78A] [13/09/2020] (.Tonec Inc..) - C:\Users\lonly\AppData\Roaming\IDM\idmmzcc5\components12\idmmzcc.dll =>.Tonec Inc. [034F328F3EFF4FB98F5343811788F78A] [13/09/2020] (.Tonec Inc..) - C:\Users\lonly\AppData\Roaming\IDM\idmmzcc5\components12\idmmzcc64.dll =>.Tonec Inc. [034F328F3EFF4FB98F5343811788F78A] [13/09/2020] (.Tonec Inc..) - C:\Users\lonly\AppData\Roaming\IDM\idmmzcc5\components2\idmcchandler2.dll =>.Tonec Inc. [034F328F3EFF4FB98F5343811788F78A] [13/09/2020] (.Tonec Inc..) - C:\Users\lonly\AppData\Roaming\IDM\idmmzcc5\components2\idmcchandler2_64.dll =>.Tonec Inc. [04D54DC0A2016B263EEEB255D321056E] [09/06/2020] (.OpenVPN Technologies, Inc..) - C:\Program Files\NordVPN network TAP\bin\i386\tapinstall.exe =>.OpenVPN Technologies, Inc. [05F4210DB2B283A32FF2AED29FCB68A4] [07/09/2020] (.Opera Software AS.) - C:\Program Files\Opa\70.0.3728.154\opera.exe =>.Opera Software AS [05F4210DB2B283A32FF2AED29FCB68A4] [08/09/2020] (.Opera Software AS.) - C:\Program Files\Opa\assistant\browser_assistant.exe =>.Opera Software AS [05F4210DB2B283A32FF2AED29FCB68A4] [08/09/2020] (.Opera Software AS.) - C:\Program Files\Opa\launcher.exe =>.Opera Software AS [05F4210DB2B283A32FF2AED29FCB68A4] [11/09/2020] (.Opera Software AS.) - C:\Program Files\Opa\70.0.3728.178\opera.exe =>.Opera Software AS [06C5078AA528BBD3B8668AB10B035F94] [13/03/2020] (.Tonec Inc..) - C:\Program Files\Internet Download Manager\IEMonitor.exe =>.Tonec Inc. [06C5078AA528BBD3B8668AB10B035F94] [18/04/2020] (.Tonec Inc..) - C:\Program Files\Internet Download Manager\Uninstall.exe =>.Tonec Inc. [06C5078AA528BBD3B8668AB10B035F94] [21/01/2020] (.Tonec Inc..) - C:\PROGRA~1\INTERN~2\IDMIECC.dll =>.Tonec Inc. [08404767E0D6C26CBD443F664AEF0A5C] [22/04/2020] (.FOXIT SOFTWARE INC..) - C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x86.dll =>.FOXIT SOFTWARE INC. [08404767E0D6C26CBD443F664AEF0A5C] [22/04/2020] (.FOXIT SOFTWARE INC..) - C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll =>.FOXIT SOFTWARE INC. [08404767E0D6C26CBD443F664AEF0A5C] [28/05/2020] (.FOXIT SOFTWARE INC..) - C:\Program Files\Foxit Software\Foxit Reader\unins000.exe =>.FOXIT SOFTWARE INC. [08404767E0D6C26CBD443F664AEF0A5C] [29/04/2020] (.FOXIT SOFTWARE INC..) - C:\Program Files\Foxit Software\Foxit PhantomPDF\FoxitPhantomPDF.exe =>.FOXIT SOFTWARE INC. [08404767E0D6C26CBD443F664AEF0A5C] [29/04/2020] (.FOXIT SOFTWARE INC..) - C:\Program Files\Foxit Software\Foxit PhantomPDF\FoxitPhantomPDFUpdateService.exe =>.FOXIT SOFTWARE INC. [08404767E0D6C26CBD443F664AEF0A5C] [29/04/2020] (.FOXIT SOFTWARE INC..) - C:\Program Files\Foxit Software\Foxit Reader\FoxitReader.exe =>.FOXIT SOFTWARE INC. [08404767E0D6C26CBD443F664AEF0A5C] [29/04/2020] (.FOXIT SOFTWARE INC..) - C:\Program Files\Foxit Software\Foxit Reader\FoxitReaderUpdateService.exe =>.FOXIT SOFTWARE INC. [09105884EB959D3BC8B994F918A7B6EE] [09/05/2020] (.Oracle America, Inc..) - C:\Program Files\Java\jre1.8.0_251\bin\jp2ssv.dll =>.Oracle America, Inc. [09105884EB959D3BC8B994F918A7B6EE] [09/05/2020] (.Oracle America, Inc..) - C:\Program Files\Java\jre1.8.0_251\bin\ssv.dll =>.Oracle America, Inc. [09105884EB959D3BC8B994F918A7B6EE] [12/03/2020] (.Oracle America, Inc..) - C:\Program Files\Common Files\Java\Java Update\jusched.exe =>.Oracle America, Inc. [0B1F8CD59E64746BEAE153ECCA21066B] [03/04/2020] (.Mozilla Corporation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation [0D173151D3DB317E050EFC22C5B3A0DD] [12/05/2020] (.Fotis Zafiropoulos.) - C:\Program Files\MPC-HC\unins000.exe =>.Fotis Zafiropoulos [0D173151D3DB317E050EFC22C5B3A0DD] [16/07/2017] (.Fotis Zafiropoulos.) - C:\Program Files\MPC-HC\mpc-hc.exe =>.Fotis Zafiropoulos [0D31C23EB2249CE611B953FB16EA0D25] [13/09/2020] (.Opera Software AS.) - C:\Users\lonly\AppData\Local\Temp\3582-490\launcher.exe =>.Opera Software AS [0DDEB53F957337FBEAF98C4A615B149D] [02/09/2020] (.Mozilla Corporation.) - C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation [0DDEB53F957337FBEAF98C4A615B149D] [02/09/2020] (.Mozilla Corporation.) - C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation [0EFEAFE9BF5BACB6FFA5881DF9EA0A1A] [10/05/2016] (.Micron Technology, Inc..) - C:\Windows\System32\drivers\mtinvme.sys =>.Not verified [0FA5B80428F4624CF9672211E1956FBE] [23/04/2020] (.VideoLAN.) - C:\Program Files\VideoLAN\VLC\vlc.exe =>.VideoLAN [11217744F4734203086E7A2B2312FE1225D5] [30/04/2020] (.Martin Malik - REALiX.) - C:\Windows\System32\drivers\HWiNFO32.SYS =>.Martin Malik - REALiX [1121ACEBD596BFF219C4231915D84B0B0549] [13/02/2018] (.Samsung Electronics Co., Ltd..) - C:\Windows\System32\drivers\secnvme.sys =>.Samsung Electronics Co., Ltd. [1121ACEBD596BFF219C4231915D84B0B0549] [13/02/2018] (.Samsung Electronics Co., Ltd..) - C:\Windows\System32\drivers\secnvmeF.sys =>.Samsung Electronics Co., Ltd. [1C71DEFE3284E66D55131E70] [09/06/2020] (.TEFINCOM S.A..) - C:\Windows\System32\drivers\tapnordvpn.sys =>.TEFINCOM S.A. [2C80892E0115B0B77AA3594B9A733953] [25/10/2012] (.Realtek Semiconductor Corp.) - C:\Windows\System32\drivers\Rt86win7.sys =>.Realtek Semiconductor Corp [330000C10A26A958EEA067060C00020000C10A] [25/04/2018] (.Intel(R) NVMe Windows Driver.) - C:\Windows\System32\drivers\IaNVMe.sys =>.Not verified [330000C10A26A958EEA067060C00020000C10A] [25/04/2018] (.Intel(R) NVMe Windows Driver.) - C:\Windows\System32\drivers\IaNVMeF.sys =>.Not verified [332CAF63F76463D734C823DC3B93DC4C] [04/08/2020] (.LAVASOFT SOFTWARE CANADA INC.) - C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe =>PUP.Optional.LavasoftWebCompanion [36336D836A19E244FF0E52882EB5B1DE] [15/06/2009] (.Creative Labs Inc.) - C:\Program Files\OpenAL\oalinst.exe =>.Creative Labs Inc [372F633F64D62ECB541B7D0CDB27BFF6] [22/02/2012] (.Bigfoot Networks, Inc..) - C:\Windows\System32\drivers\Xeno7x86.sys =>.Bigfoot Networks, Inc. [38A6B946724226498C48291D33CFCDD3] [17/08/2016] (.Lite-On Technology Corporation.) - C:\Windows\System32\drivers\nvme.sys =>.Not verified [3A8E4911EA414DE537BCEE2AAAB74FC7] [08/03/2012] (.Broadcom Corporation.) - C:\Windows\System32\drivers\bxdiagx.sys =>.Broadcom Corporation [3A8E4911EA414DE537BCEE2AAAB74FC7] [22/02/2012] (.Broadcom Corporation.) - C:\Windows\System32\drivers\bxfcoe.sys =>.Broadcom Corporation [3A8E4911EA414DE537BCEE2AAAB74FC7] [22/02/2012] (.Broadcom Corporation.) - C:\Windows\System32\drivers\bxois.sys =>.Broadcom Corporation [3A8E4911EA414DE537BCEE2AAAB74FC7] [24/01/2012] (.Broadcom Corporation.) - C:\Windows\System32\drivers\bxvbdx.sys =>.Broadcom Corporation [4660FC32BD521D77F211C1336AA98B9E] [13/09/2020] (.Tonec Inc..) - C:\Users\lonly\AppData\Roaming\IDM\idmmzcc5\components\idmmzcc.dll =>.Tonec Inc. [4660FC32BD521D77F211C1336AA98B9E] [13/09/2020] (.Tonec Inc..) - C:\Users\lonly\AppData\Roaming\IDM\idmmzcc5\components2\idmmzcc.dll =>.Tonec Inc. [4660FC32BD521D77F211C1336AA98B9E] [13/09/2020] (.Tonec Inc..) - C:\Users\lonly\AppData\Roaming\IDM\idmmzcc5\components2\idmmzcc64.dll =>.Tonec Inc. [529E3F9FCF7D58D520D607AB74395002] [26/03/2020] (.win.rar GmbH.) - C:\Program Files\WinRAR\Rar.exe =>.win.rar GmbH [529E3F9FCF7D58D520D607AB74395002] [26/03/2020] (.win.rar GmbH.) - C:\Program Files\WinRAR\RarExt.dll =>.win.rar GmbH [529E3F9FCF7D58D520D607AB74395002] [29/03/2020] (.win.rar GmbH.) - C:\Program Files\WinRAR\uninstall.exe =>.win.rar GmbH [7422A954D54D4AA4A0F7AEE028A8CB93] [10/06/2016] (.Toshiba America Electronic Components, Inc..) - C:\Windows\System32\drivers\ocznvme.sys =>.Toshiba America Electronic Components, Inc. [7422A954D54D4AA4A0F7AEE028A8CB93] [10/06/2016] (.Toshiba America Electronic Components, Inc..) - C:\Windows\System32\drivers\ocztrimfilter.sys =>.Toshiba America Electronic Components, Inc. [7828C7315808BC8717710E13FA3C0B24] [02/05/2019] (.Tonec Inc..) - C:\Program Files\Internet Download Manager\IDMShellExt.dll =>.Tonec Inc. [7828C7315808BC8717710E13FA3C0B24] [20/12/2018] (.Tonec Inc..) - C:\Windows\System32\drivers\idmwfp.sys =>.Tonec Inc. [7B0F7049634BD8FD7F77A580] [05/08/2020] (.TEFINCOM S.A..) - C:\Program Files\NordVPN\NordVPN.exe =>.TEFINCOM S.A. [7B0F7049634BD8FD7F77A580] [05/08/2020] (.TEFINCOM S.A..) - C:\Program Files\NordVPN\nordvpn-service.exe =>.TEFINCOM S.A. [7B0F7049634BD8FD7F77A580] [05/08/2020] (.TEFINCOM S.A..) - C:\Windows\System32\drivers\nordlwf.sys =>.TEFINCOM S.A. [7B0F7049634BD8FD7F77A580] [10/06/2020] (.TEFINCOM S.A..) - C:\Windows\System32\drivers\nlwt.sys =>.TEFINCOM S.A. [7B0F7049634BD8FD7F77A580] [13/09/2020] (.TEFINCOM S.A..) - C:\Program Files\NordVPN\unins000.exe =>.TEFINCOM S.A. [7B0F7049634BD8FD7F77A580] [13/09/2020] (.TEFINCOM S.A..) - C:\Users\lonly\Downloads\Programs\NordVPNSetup.exe =>.TEFINCOM S.A. ~ Unselected Options: WR, O82, ~ End of the scan, 8078 items in 05mn08s (1782)(0)