~ ZHPDiag v2016.9.30.177 By Nicolas Coolman (2016/09/30) ~ Run by MARK (Administrator) (2016/10/01 10:59:08) ~ Web: https://www.nicolascoolman.com ~ Blog: https://www.anti-malware.top ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ State version: Version OK ~ Mode: Scan ~ Report: C:\Users\MARK\Desktop\ZHPDiag.txt ~ Report: C:\Users\MARK\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ System startup: Normal (Normal boot) Windows 7 Ultimate, 64-bit Service Pack 1 (Build 7601) =>.Microsoft Corporation ---\\ Internet Browsers (1) - 0s ~ MSIE: Internet Explorer v8.0.7601.17514 ---\\ Windows Product Information (4) - 3s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK Windows Activation Technologies : KO ---\\ Information on the system (6) - 0s ~ Operating System: Intel64 Family 6 Model 69 Stepping 1, GenuineIntel ~ Operating System: 64-bit ~ Boot mode: Normal (Normal boot) Total RAM: 4095.984 MB (45% free) System Restore: Activé (Enable) System drive C: has 98 GB () free of 211 GB ---\\ Connection to the system mode (3) - 0s ~ Computer Name: MARK-PC ~ User Name: MARK ~ Logged in as Administrator ---\\ Enumeration of the disk units (4) - 0s ~ Drive C: has 98 GB free of 211 GB (System) ~ Drive D: has 69 GB free of 249 GB ~ Drive F: has 0 GB free of 0 GB ~ Drive H: has 3 GB free of 7 GB ---\\ State of the Windows Security Center (10) - 0s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK ---\\ Search Generic System Files (25) - 2s [MD5.AC4C51EB24AA95B77F705AB159189E24] - 21/11/2010 - (.Microsoft Corporation - Windows Explorer.) -- C:\Windows\Explorer.exe [2872320] =>.Microsoft Corporation [MD5.51138BEEA3E2C21EC44D0932C71762A8] - 14/07/2009 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe [44544] =>.Microsoft Corporation [MD5.B5C5DCAD3899512020D135600129D665] - 14/07/2009 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\Windows\System32\Wininit.exe [96256] =>.Microsoft Corporation [MD5.44214C94911C7CFB1D52CB64D5E8368D] - 21/11/2010 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\Windows\System32\wininet.dll [980992] =>.Microsoft Corporation [MD5.] - 0 - (.Microsoft Corporation - Windows Logon Application.) -- C:\Windows\System32\Winlogon.exe [0] =>.Microsoft Corporation [MD5.E3AE23569749DE12D45BA3B489A036AE] - 21/11/2010 - (.Microsoft Corporation - Software Licensing Library.) -- C:\Windows\System32\sppcomapi.dll [193536] =>.Microsoft Corporation [MD5.59DF156711A76BCB993253EC6C9BBF41] - 21/11/2010 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\System32\dnsapi.dll [270336] =>.Microsoft Corporation [MD5.59DF156711A76BCB993253EC6C9BBF41] - 21/11/2010 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\Syswow64\dnsapi.dll [270336] =>.Microsoft Corporation [MD5.] - 0 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [0] =>.Microsoft Corporation [MD5.] - 0 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [0] =>.Microsoft Windows® [MD5.] - 0 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [0] =>.Microsoft Corporation [MD5.] - 0 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [0] =>.Microsoft Corporation [MD5.] - 0 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [0] =>.Microsoft Corporation [MD5.] - 0 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [0] =>.Microsoft Corporation [MD5.] - 0 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\Windows\System32\drivers\i8042prt.sys [0] =>.Microsoft Corporation [MD5.] - 0 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [0] =>.Microsoft Corporation [MD5.] - 0 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [0] =>.Microsoft Corporation [MD5.] - 0 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [0] =>.Microsoft Corporation [MD5.] - 0 - (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\drivers\ntfs.sys [0] =>.Microsoft Windows® [MD5.] - 0 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\Windows\System32\drivers\Parport.sys [0] =>.Microsoft Corporation [MD5.] - 0 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [0] =>.Microsoft Corporation [MD5.] - 0 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [0] =>.Microsoft Corporation [MD5.] - 0 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [0] =>.Microsoft Corporation [MD5.] - 0 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [0] =>.Microsoft Corporation [MD5.] - 0 - (.Microsoft Corporation - Volume Shadow Copy Driver.) -- C:\Windows\System32\drivers\volsnap.sys [0] =>.Microsoft Windows® ---\\ Non Microsoft non disabled Windows Services (8) - 3s O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation - igfxCUIService Module.) - C:\Windows\system32\igfxCUIService.exe =>.Intel Corporation O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) . (.NVIDIA Corporation - NVIDIA Container.) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation® O23 - Service: NVIDIA Wireless Controller Service (NVIDIA Wireless Controller Service) . (.NVIDIA Corporation - NVIDIA Wireless Controller Service.) - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe =>.NVIDIA Corporation® O23 - Service: Origin Web Helper Service (Origin Web Helper Service) . (.Electronic Arts - OriginWebHelperService.) - C:\Program Files (x86)\Origin\OriginWebHelperService.exe =>.Electronic Arts, Inc.® O23 - Service: PnkBstrA (PnkBstrA) . (...) - C:\Windows\System32\PnkBstrA.exe (.not file.) O23 - Service: Razer Game Scanner (Razer Game Scanner Service) . (.Copyright © 2013-2015 - GameScannerService.) - C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe =>.Razer USA Ltd.® O23 - Service: Realtek Audio Service (RtkAudioService) . (.Realtek Semiconductor - Realtek Audio Service.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe =>.Realtek Semiconductor Corp® O23 - Service: RzKLService (RzKLService) . (.Razer Inc. - RzKLService.exe.) - C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe =>.Razer USA Ltd.® ---\\ Services not Microsoft (SR=Run, SS=Stop) (12) - 31s SS - Demand [13/01/2016] [ 280696] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe =>.Intel Corporation - pGFX® SR - Auto [13/01/2016] [ 319096] Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation.) - C:\Windows\system32\igfxCUIService.exe =>.Intel Corporation SR - Auto [17/09/2016] [ 458808] NVIDIA LocalSystem Container (NvContainerLocalSystem) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation® SS - Demand [17/09/2016] [ 458808] NVIDIA NetworkService Container (NvContainerNetworkService) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation® SR - Auto [17/09/2016] [ 1165368] NVIDIA Wireless Controller Service (NVIDIA Wireless Controller Service) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe =>.NVIDIA Corporation® SS - Demand [23/09/2016] [ 2141192] Origin Client Service (Origin Client Service) . (.Electronic Arts.) - C:\Program Files (x86)\Origin\OriginClientService.exe =>.Electronic Arts, Inc.® SS - Auto [23/09/2016] [ 2206224] Origin Web Helper Service (Origin Web Helper Service) . (.Electronic Arts.) - C:\Program Files (x86)\Origin\OriginWebHelperService.exe =>.Electronic Arts, Inc.® SR - Auto [01/06/2016] [ 187824] Razer Game Scanner (Razer Game Scanner Service) . (.Copyright © 2013-2015.) - C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe =>.Razer USA Ltd.® SS - Demand [01/03/2013] [ 118520] Remote Packet Capture Protocol v.0 (experimental) (rpcapd) . (.Riverbed Technology, Inc..) - C:\Program Files (x86)\WinPcap\rpcapd.exe =>.Riverbed Technology, Inc.® SR - Auto [03/05/2016] [ 312576] Realtek Audio Service (RtkAudioService) . (.Realtek Semiconductor.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe =>.Realtek Semiconductor Corp® SR - Auto [30/05/2016] [ 133376] RzKLService (RzKLService) . (.Razer Inc..) - C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe =>.Razer USA Ltd.® ---\\ Task Planned Automatically (30) - 8s =>.Superfluous.Empty [MD5.C2C9E42D6C51E99C1BAB44F108E8851C] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6868696] (.Activate.) =>.Piriform Ltd® [MD5.50FCC5C822A6B4FC6F377EE9F9F37C7B] [APT] [Google Update] (.Google Inc..) -- C:\Users\MARK\AppData\Local\Google\Update\GoogleUpdate.exe [152216] (.Activate.) =>.Google Inc® [MD5.50FCC5C822A6B4FC6F377EE9F9F37C7B] [APT] [GoogleUpdateTaskUserS-1-5-21-678541255-2295460757-2273824982-1000Core] (.Google Inc..) -- C:\Users\MARK\AppData\Local\Google\Update\GoogleUpdate.exe [152216] (.Activate.) =>.Google Inc® [MD5.50FCC5C822A6B4FC6F377EE9F9F37C7B] [APT] [GoogleUpdateTaskUserS-1-5-21-678541255-2295460757-2273824982-1000UA] (.Google Inc..) -- C:\Users\MARK\AppData\Local\Google\Update\GoogleUpdate.exe [152216] (.Activate.) =>.Google Inc® [MD5.304D92120D0C3EFEDACBB85ACC61A7BF] [APT] [NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] (.NVIDIA Corporation.) -- C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [782904] (.Activate.) =>.NVIDIA Corporation® [MD5.9A0DED66966EC6CED5AA19BF2C00D24F] [APT] [NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] (.NVIDIA Corporation.) -- C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [611384] (.Activate.) =>.NVIDIA Corporation® [MD5.9A0DED66966EC6CED5AA19BF2C00D24F] [APT] [NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] (.NVIDIA Corporation.) -- C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [611384] (.Activate.) =>.NVIDIA Corporation® [MD5.83AA8C4894F17B65F162801896B5BEDE] [APT] [NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] (.NVIDIA Corporation.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [421944] (.Activate.) =>.NVIDIA Corporation® [MD5.2666D87A2F5ECD4D4EC236C0116FC9F0] [APT] [NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] (.NVIDIA Corporation.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [690232] (.Activate.) =>.NVIDIA Corporation® [MD5.2666D87A2F5ECD4D4EC236C0116FC9F0] [APT] [NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] (.NVIDIA Corporation.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [690232] (.Activate.) =>.NVIDIA Corporation® [MD5.91AF427D88C39185216856FFD2B2B4AE] [APT] [RtHDVBg_PushButton] (.Realtek Semiconductor.) -- C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1429248] (.Activate.) =>.Realtek Semiconductor Corp® [MD5.4CB8D9D5F3FBFE84873B7F14173BB230] [APT] [TechUtilities] (.Seven Servos Software, Pvt Ltd..) -- C:\Program Files\TechUtilities\TechUtilities.exe [865760] (.Activate.) {71EBD09B54A645EF7DC9D5562433CD2C} [MD5.00000000000000000000000000000000] [APT] [{5D210CAE-9BAC-4730-B438-EEC4E769E050}] (...) -- D:\Games\BioShock 2 Remastered\Build\Final\Bioshock2.exe (.not file.) [0] (.Activate.) =>.Superfluous.Empty O39 - APT: GoogleUpdateTaskUserS-1-5-21-678541255-2295460757-2273824982-1000Core - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-678541255-2295460757-2273824982-1000Core.job [796] =>.Google Inc® O39 - APT: GoogleUpdateTaskUserS-1-5-21-678541255-2295460757-2273824982-1000UA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-678541255-2295460757-2273824982-1000UA.job [848] =>.Google Inc® O39 - APT: TechUtilities - (.Seven Servos Software, Pvt Ltd..) -- C:\Windows\Tasks\TechUtilities.job [332] {71EBD09B54A645EF7DC9D5562433CD2C} O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\Windows\System32\Tasks\CCleanerSkipUAC [2786] =>.Piriform Ltd® O39 - APT: Google Update - (.Google Inc..) -- C:\Windows\System32\Tasks\Google Update [3826] =>.Google Inc® O39 - APT: GoogleUpdateTaskUserS-1-5-21-678541255-2295460757-2273824982-1000Core - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-678541255-2295460757-2273824982-1000Core [3424] =>.Google Inc® O39 - APT: GoogleUpdateTaskUserS-1-5-21-678541255-2295460757-2273824982-1000UA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-678541255-2295460757-2273824982-1000UA [3820] =>.Google Inc® O39 - APT: NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} [3780] =>.NVIDIA Corporation® O39 - APT: NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} [3828] =>.NVIDIA Corporation® O39 - APT: NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} [3532] =>.NVIDIA Corporation® O39 - APT: NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} [3768] =>.NVIDIA Corporation® O39 - APT: NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} [3592] =>.NVIDIA Corporation® O39 - APT: NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} [3828] =>.NVIDIA Corporation® O39 - APT: RtHDVBg_PushButton - (.Realtek Semiconductor.) -- C:\Windows\System32\Tasks\RtHDVBg_PushButton [3146] =>.Realtek Semiconductor Corp® O39 - APT: TechUtilities - (.Seven Servos Software, Pvt Ltd..) -- C:\Windows\System32\Tasks\TechUtilities [3162] {71EBD09B54A645EF7DC9D5562433CD2C} O39 - APT: {5D210CAE-9BAC-4730-B438-EEC4E769E050} - (...) -- C:\Windows\System32\Tasks\{5D210CAE-9BAC-4730-B438-EEC4E769E050} [2974] (.Orphan.) ---\\ Process running (27) - 1s [MD5.00000000000000000000000000000000] - (.Intel Corporation - igfxCUIService Module.) -- C:\Windows\system32\igfxCUIService.exe [0] [PID.1120] =>.Intel Corporation [MD5.24345BC48A36334F8090095852068A63] - (.Realtek Semiconductor - Realtek Audio Service.) -- C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [312576] [PID.1172] =>.Realtek Semiconductor Corp® [MD5.91AF427D88C39185216856FFD2B2B4AE] - (.Realtek Semiconductor - HD Audio Background Process.) -- C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1429248] [PID.1328] =>.Realtek Semiconductor Corp® [MD5.91AF427D88C39185216856FFD2B2B4AE] - (.Realtek Semiconductor - HD Audio Background Process.) -- C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1429248] [PID.1336] =>.Realtek Semiconductor Corp® [MD5.B92E71B4A2B77D887D93A8A03E71D262] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [458808] [PID.1728] =>.NVIDIA Corporation® [MD5.7AA87B2AB72E9DADCF056ED375CD2249] - (.NVIDIA Corporation - NVIDIA Wireless Controller Service.) -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1165368] [PID.1792] =>.NVIDIA Corporation® [MD5.AD9917A27515628F69E05F84E63D1897] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe [421432] [PID.1884] =>.NVIDIA Corporation® [MD5.48559EB0E1C6831FF31383C7C3AB172E] - (.Realtek Semiconductor - Realtek HD Audio Manager.) -- C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8805120] [PID.2308] =>.Realtek Semiconductor Corp® [MD5.91AF427D88C39185216856FFD2B2B4AE] - (.Realtek Semiconductor - HD Audio Background Process.) -- C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1429248] [PID.2316] =>.Realtek Semiconductor Corp® [MD5.3A2E85F7D90D15460C337CE80C2E3B29] - (...) -- C:\Windows\SysWOW64\PnkBstrA.exe [76888] [PID.2176] =>.Even Balance, Inc.® [MD5.3ED3D2FD983A4649A2E466DE75627A5E] - (.Copyright © 2013-2015 - GameScannerService.) -- C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187824] [PID.2240] =>.Razer USA Ltd.® [MD5.2F128896F653F8510FA70BB2D076D07E] - (.Razer Inc. - RzKLService.exe.) -- C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [133376] [PID.2384] =>.Razer USA Ltd.® [MD5.00000000000000000000000000000000] - (.Intel Corporation - igfxEM Module.) -- C:\Windows\system32\igfxEM.exe [0] [PID.3112] =>.Intel Corporation [MD5.00000000000000000000000000000000] - (.Intel Corporation - igfxHK Module.) -- C:\Windows\system32\igfxHK.exe [0] [PID.3120] =>.Intel Corporation [MD5.00000000000000000000000000000000] - (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxTray.exe [0] [PID.3156] =>.Intel Corporation [MD5.91AF427D88C39185216856FFD2B2B4AE] - (.Realtek Semiconductor - HD Audio Background Process.) -- C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1429248] [PID.3496] =>.Realtek Semiconductor Corp® [MD5.51EE1B50E5ABFB8A62374591AF251EB8] - (.Google Inc. - Google Chrome.) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe [967496] [PID.3900] =>.Google Inc® [MD5.51EE1B50E5ABFB8A62374591AF251EB8] - (.Google Inc. - Google Chrome.) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe [967496] [PID.1908] =>.Google Inc® [MD5.51EE1B50E5ABFB8A62374591AF251EB8] - (.Google Inc. - Google Chrome.) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe [967496] [PID.2608] =>.Google Inc® [MD5.51EE1B50E5ABFB8A62374591AF251EB8] - (.Google Inc. - Google Chrome.) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe [967496] [PID.1180] =>.Google Inc® [MD5.51EE1B50E5ABFB8A62374591AF251EB8] - (.Google Inc. - Google Chrome.) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe [967496] [PID.4436] =>.Google Inc® [MD5.51EE1B50E5ABFB8A62374591AF251EB8] - (.Google Inc. - Google Chrome.) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe [967496] [PID.3188] =>.Google Inc® [MD5.51EE1B50E5ABFB8A62374591AF251EB8] - (.Google Inc. - Google Chrome.) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe [967496] [PID.660] =>.Google Inc® [MD5.51EE1B50E5ABFB8A62374591AF251EB8] - (.Google Inc. - Google Chrome.) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe [967496] [PID.2064] =>.Google Inc® [MD5.51EE1B50E5ABFB8A62374591AF251EB8] - (.Google Inc. - Google Chrome.) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe [967496] [PID.124] =>.Google Inc® [MD5.51EE1B50E5ABFB8A62374591AF251EB8] - (.Google Inc. - Google Chrome.) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe [967496] [PID.2296] =>.Google Inc® [MD5.7B791086C7BBA021F6DDAADD632EA144] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\MARK\Downloads\ZHPDiag3.exe [2375680] [PID.3840] =>.Nicolas Coolman ---\\ Google Chrome, Start,Search,Extensions (24) - 1s G0 - GCSP: Preferences [User Data\Default][HomePage] http://fbcdn-profile-a.akamaihd.net =>.Superfluous.AkamaiHD G0 - GCSP: Preferences [User Data\Default][HomePage] http://fonts.gstatic.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://i.ytimg.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://s.ytimg.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://s2.googleusercontent.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.gstatic.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.facebook.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.iq G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.youtube.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://yt3.ggpht.com G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.mystartsearch.com/ =>PUP.Optional.StartSearch G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [cfhdojbkjhnklbpkdaibdccddilifddb] __MSG_name__ =>.AdblocPlus Plugin G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [ngpampappnmepgilojfohadhhmbhlaek] IDM Integration Module G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [oadiaahhieelhhffeofkdchgfpjehjok] __MSG_ext_name__ G2 - GCE: Preference [User Data\Default] [pfpeapihoiogbcmdmnibeplnikfnhoge] Outlook.com G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc. ---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (1) - 1s P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll =>.Adobe Systems Incorporated ---\\ Internet Explorer Extensions, Start, Search (7) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphan =>.Microsoft Internet Explorer ---\\ Internet Explorer, Proxy Management (4) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation ---\\ Hosts file redirection (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (23) ---\\ Browser Helper Object (BHO) (3) - 0s O2 - BHO: IDM Helper [64Bits] - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll =>.Tonec Inc.® O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre7\bin\ssv.dll =>.Oracle America, Inc.® O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll =>.Oracle America, Inc.® ---\\ Auto loading programs from Registry and folders (10) - 1s O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Realtek HD Audio Manager.) -- C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe =>.Realtek Semiconductor Corp® O4 - HKLM\..\Run: [RtHDVBg] . (.Realtek Semiconductor - HD Audio Background Process.) -- C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe =>.Realtek Semiconductor Corp® O4 - HKLM\..\Run: [ShadowPlay] . (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe =>.Microsoft Corporation O4 - HKLM\..\Run: [XboxStat] . (.Microsoft Corporation - XBoxStat.exe.) -- C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe =>.Microsoft Corporation® O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc. O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Desktop Gadgets.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Desktop Gadgets.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-678541255-2295460757-2273824982-1000\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc. ---\\ Global shortcuts Startup (77) - 8s O4 - GS\Desktop [Administrator]: Blur.lnk . (...) D:\Blur\Blur.exe O4 - GS\Desktop [Administrator]: Cain.lnk . (.oxid.it - Cain - Password Recovery Utility.) C:\Program Files (x86)\Cain\Cain.exe =>.oxid.it O4 - GS\Desktop [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Desktop [Administrator]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc. O4 - GS\Desktop [Administrator]: The Bunker.lnk . (...) D:\Games\The Bunker\TheBunker.exe O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\MARK\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\sendTo [Administrator]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\TaskBar [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [Administrator]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation O4 - GS\TaskBar [Administrator]: Windows Task Manager.lnk . (.Microsoft Corporation - Windows Task Manager.) C:\Windows\System32\taskmgr.exe =>.Microsoft Corporation O4 - GS\Programs [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Desktop [Guest]: Blur.lnk . (...) D:\Blur\Blur.exe O4 - GS\Desktop [Guest]: Cain.lnk . (.oxid.it - Cain - Password Recovery Utility.) C:\Program Files (x86)\Cain\Cain.exe =>.oxid.it O4 - GS\Desktop [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Desktop [Guest]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc. O4 - GS\Desktop [Guest]: The Bunker.lnk . (...) D:\Games\The Bunker\TheBunker.exe O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\MARK\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\sendTo [Guest]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\TaskBar [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [Guest]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation O4 - GS\TaskBar [Guest]: Windows Task Manager.lnk . (.Microsoft Corporation - Windows Task Manager.) C:\Windows\System32\taskmgr.exe =>.Microsoft Corporation O4 - GS\Programs [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Desktop [MARK]: Blur.lnk . (...) D:\Blur\Blur.exe O4 - GS\Desktop [MARK]: Cain.lnk . (.oxid.it - Cain - Password Recovery Utility.) C:\Program Files (x86)\Cain\Cain.exe =>.oxid.it O4 - GS\Desktop [MARK]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Desktop [MARK]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc. O4 - GS\Desktop [MARK]: The Bunker.lnk . (...) D:\Games\The Bunker\TheBunker.exe O4 - GS\Desktop [MARK]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\MARK\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [MARK]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\sendTo [MARK]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation O4 - GS\sendTo [MARK]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\TaskBar [MARK]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [MARK]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation O4 - GS\TaskBar [MARK]: Windows Task Manager.lnk . (.Microsoft Corporation - Windows Task Manager.) C:\Windows\System32\taskmgr.exe =>.Microsoft Corporation O4 - GS\Programs [MARK]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\CommonDesktop [Public]: Battlefield 4.lnk . (.EA Digital Illusions CE AB - Battlefield/Battlelog Web Helper.) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe =>.Electronic Arts® O4 - GS\CommonDesktop [Public]: BioShock 2 Remastered.lnk . (...) D:\Games\BioShock 2 Remastered\Build\Final\Bioshock2.exe O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Ltd - CCleaner.) C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd® O4 - GS\CommonDesktop [Public]: GeForce Experience.lnk . (.NVIDIA Corporation - NVIDIA GeForce Experience.) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe =>.NVIDIA Corporation® O4 - GS\CommonDesktop [Public]: Need for Speed™ Most Wanted.lnk . (.Electronic Arts - Need for Speed™ Most Wanted.) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe =>.Electronic Arts® O4 - GS\CommonDesktop [Public]: Origin.lnk . (.Electronic Arts - Origin.) C:\Program Files (x86)\Origin\Origin.exe =>.Electronic Arts, Inc.® O4 - GS\CommonDesktop [Public]: Razer Cortex.lnk . (.Razer Inc. - CortexLauncher.exe.) C:\Program Files (x86)\Razer\Razer Cortex\CortexLauncher.exe =>.Razer USA Ltd.® O4 - GS\CommonDesktop [Public]: TechUtilities.lnk . (.Seven Servos Software, Pvt Ltd. - TechUtilities for pc optimization.) C:\Program Files\TechUtilities\TechUtilities.exe {71EBD09B54A645EF7DC9D5562433CD2C} O4 - GS\CommonDesktop [Public]: Virtual CloneDrive.lnk . (.Elaborate Bytes AG - VirtualCloneDrive Preferences.) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDPrefs.exe =>.Elaborate Bytes AG O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files\VideoLAN\VLC\vlc.exe =>.VideoLAN® O4 - GS\Accessories [Public]: Command Prompt.lnk . (.Microsoft Corporation - Windows Command Processor.) C:\Windows\system32\cmd.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Private Character Editor.lnk . (.Microsoft Corporation - Private Character Editor.) C:\Windows\system32\eudcedit.exe =>.Microsoft Corporation O4 - GS\Programs [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Accessories [Public]: Bluetooth File Transfer Wizard.lnk . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Windows Calculator.) C:\Windows\system32\calc.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - Display Switch.) C:\Windows\system32\displayswitch.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Math Input Panel Accessory.) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - Windows Mobility Center.) C:\Windows\system32\mblctr.exe /open =>.Microsoft Corporation O4 - GS\Accessories [Public]: NetworkProjection.lnk . (.Microsoft Corporation - Connect to a Network Projector.) C:\Windows\system32\NetProj.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\Windows\system32\mspaint.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\Windows\system32\mstsc.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Windows Sound Recorder.) C:\Windows\system32\SoundRecorder.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - Sticky Notes.) C:\Windows\system32\StikyNot.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) C:\Windows\System32\mobsync.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Welcome Center.lnk . (.Microsoft Corporation - Windows host process (Rundll32).) C:\Windows\system32\rundll32.exe %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut =>.Microsoft Corporation O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) C:\Windows\system32\charmap.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - Microsoft® Disk Defragmenter.) C:\Windows\system32\dfrgui.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - Disk Space Cleanup Manager for Windows.) C:\Windows\system32\cleanmgr.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - Resource and Performance Monitor.) C:\Windows\system32\perfmon.exe /res =>.Microsoft Corporation O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - System Information.) C:\Windows\system32\msinfo32.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - Microsoft® Windows System Restore.) C:\Windows\system32\rstrui.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) C:\Windows\system32\taskschd.msc /s O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - Windows Easy Transfer Post Migration Applic.) C:\Windows\system32\migwiz\postmig.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - Windows Easy Transfer Application.) C:\Windows\system32\migwiz\migwiz.exe =>.Microsoft Corporation ---\\ Lop.com/Domain Hijackers (2) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 =>.Local IP Adress O17 - HKLM\System\CCS\Services\Tcpip\..\{BAA36787-D12F-4DCB-B93A-85462C3057D3}: DhcpNameServer = 192.168.0.1 =>.Local IP Adress ---\\ Extra protocols (22) - 0s O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation® O18 - Filter: deflate [64Bits] - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Filter: gzip [64Bits] - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation ---\\ Software installed (59) - 21s O42 - Logiciel: 7-Zip 15.14 - (.Igor Pavlov.) [HKLM][64Bits] -- 7-Zip =>.Igor Pavlov O42 - Logiciel: Adobe Flash Player 21 ActiveX & Plugins 64-bit - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX =>.Adobe Systems Incorporated® O42 - Logiciel: Adobe Shockwave Player 12.0 - (.Adobe Systems, Inc.) [HKLM][64Bits] -- {AA3B06B1-E89A-43C6-A26B-7109DB4BEE7B} =>.Adobe Systems, Inc O42 - Logiciel: Allgemeine Runtime Files (x86) - (.Sereby Corporation.) [HKLM][64Bits] -- {1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1 =>.Sereby Corporation O42 - Logiciel: Battlefield 4™ - (.Electronic Arts.) [HKLM][64Bits] -- {ABADE36E-EC37-413B-8179-B432AD3FACE7} =>.Electronic Arts, Inc.® O42 - Logiciel: Battlelog Web Plugins - (.EA Digital Illusions CE AB.) [HKLM][64Bits] -- Battlelog Web Plugins =>.EA Digital Illusions CE AB O42 - Logiciel: BioShock 2 Remastered - (...) [HKLM][64Bits] -- BioShock 2 Remastered_is1 O42 - Logiciel: Blur - (.R.G. Mechanics, ProZorg_tm.) [HKLM][64Bits] -- Blur_R.G. Mechanics_is1 =>.R.G. Mechanics, ProZorg_tm O42 - Logiciel: Cain & Abel 4.9.56 - (...) [HKLM][64Bits] -- Cain & Abel 4.9.56 O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>.Piriform Ltd® O42 - Logiciel: ESN Sonar - (.ESN Social Software AB.) [HKLM][64Bits] -- ESN Sonar-0.70.4 =>.ESN Social Software AB O42 - Logiciel: Google Chrome - (.Google Inc..) [HKCU][64Bits] -- Google Chrome =>.Google Inc® O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} =>.Intel Corporation - pGFX® O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM][64Bits] -- Internet Download Manager =>.Tonec Inc.® O42 - Logiciel: Java 7 Update 51 - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83217051FF} =>.Oracle O42 - Logiciel: Java 7 Update 51 (64-bit) - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F86417051FF} =>.Oracle O42 - Logiciel: Java Auto Updater - (.Sun Microsystems, Inc..) [HKLM][64Bits] -- {4A03706F-666A-4037-7777-5F2748764D10} =>.Sun Microsystems, Inc. O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation O42 - Logiciel: Microsoft Xbox 360 Accessories 1.2 - (.Microsoft.) [HKLM][64Bits] -- {D9C50188-12D5-4D3E-8F00-682346C2AA5F} =>.Microsoft O42 - Logiciel: Need for Speed™ Most Wanted - (.Electronic Arts.) [HKLM][64Bits] -- {FB0127F3-985B-44CE-AE29-378CAF60B361} =>.Electronic Arts® O42 - Logiciel: NVIDIA Backend - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvBackend =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Elevated User Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.UserElevated =>.NVIDIA Corporation O42 - Logiciel: NVIDIA GeForce Experience 3.0.6.48 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Install Application - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer =>.NVIDIA Corporation O42 - Logiciel: NVIDIA LocalSystem Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.LocalSystem =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Message Bus for NvContainer - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.MessageBus =>.NVIDIA Corporation O42 - Logiciel: NVIDIA NetworkService Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NetworkService =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Optimus Update 2.13.0.21 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus =>.NVIDIA Corporation O42 - Logiciel: NVIDIA PhysX (Legacy) - (.NVIDIA Corporation.) [HKLM][64Bits] -- {FAAC26AD-73BA-40CE-86AA-C9213F9E064A} =>.NVIDIA Corporation O42 - Logiciel: NVIDIA PhysX System Software 9.15.0428 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX =>.NVIDIA Corporation O42 - Logiciel: NVIDIA ShadowPlay 2.13.0.21 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay =>.NVIDIA Corporation O42 - Logiciel: Nvidia Share - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_OSC =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Update 2.13.0.21 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Update Core - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core =>.NVIDIA Corporation O42 - Logiciel: NVIDIA User Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.User =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Virtual Audio 1.2.41 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Watchdog Plugin for NvContainer - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvPlugin.Watchdog =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Wireless Controller Service - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GfExperienceService =>.NVIDIA Corporation O42 - Logiciel: NvNodejs - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs =>.NVIDIA Corporation O42 - Logiciel: NvTelemetry - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry =>.NVIDIA Corporation O42 - Logiciel: OpenAL - (...) [HKLM][64Bits] -- OpenAL =>.Creative Labs Inc® O42 - Logiciel: Origin - (.Electronic Arts, Inc..) [HKLM][64Bits] -- Origin =>.Electronic Arts, Inc.® O42 - Logiciel: PunkBuster Services - (.Even Balance, Inc..) [HKLM][64Bits] -- PunkBusterSvc =>.Even Balance, Inc.® O42 - Logiciel: Razer Cortex - (.Razer Inc..) [HKLM][64Bits] -- Razer Cortex_is1 =>.Razer USA Ltd.® O42 - Logiciel: Realtek Card Reader - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {5BC2B5AB-80DE-4E83-B8CF-426902051D0A} {0A9997ACCB4B384C80E313DD2854407B} =>.Realtek Semiconductor Corp. O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp® O42 - Logiciel: Rockstar Games Social Club - (.Rockstar Games.) [HKLM][64Bits] -- Rockstar Games Social Club =>.Take-Two Interactive Software, Inc.® O42 - Logiciel: SAM CoDeC Pack - (.www.SamLab.ws.) [HKLM][64Bits] -- SAM CoDeC Pack O42 - Logiciel: SHIELD Streaming - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv =>.NVIDIA Corporation O42 - Logiciel: SHIELD Wireless Controller Driver - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController =>.NVIDIA Corporation O42 - Logiciel: TechUtilities - (.Seven Servos Software Pvt Ltd..) [HKLM][64Bits] -- TechUtilities_is1 O42 - Logiciel: The Bunker - (...) [HKLM][64Bits] -- The Bunker_is1 O42 - Logiciel: VirtualCloneDrive - (.Elaborate Bytes.) [HKLM][64Bits] -- VirtualCloneDrive =>.Elaborate Bytes O42 - Logiciel: Visual Studio 2012 x64 Redistributables - (.AVG Technologies.) [HKLM][64Bits] -- {8C775E70-A791-4DA8-BCC3-6AB7136F4484} =>.AVG Technologies O42 - Logiciel: Visual Studio 2012 x86 Redistributables - (.AVG Technologies CZ, s.r.o..) [HKLM][64Bits] -- {98EFF19A-30AB-4E4B-B943-F06B1C63EBF8} =>.AVG Technologies CZ, s.r.o. O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN O42 - Logiciel: WinPcap 4.1.3 - (.Riverbed Technology, Inc..) [HKLM][64Bits] -- WinPcapInst =>.Riverbed Technology, Inc. O42 - Logiciel: WinRAR 5.40 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver =>.win.rar GmbH® ---\\ HKCU & HKLM Software Keys (79) - 22s HKLM\SOFTWARE\Wow6432Node\7-Zip HKLM\SOFTWARE\Wow6432Node\Activision =>.Activision HKLM\SOFTWARE\Wow6432Node\Adobe =>.Adobe HKLM\SOFTWARE\Wow6432Node\AGEIA Technologies =>.AGEIA Technologies HKLM\SOFTWARE\Wow6432Node\AMD =>.AMD HKLM\SOFTWARE\Wow6432Node\AppDataLow HKLM\SOFTWARE\Wow6432Node\Aureal HKLM\SOFTWARE\Wow6432Node\AVG HKLM\SOFTWARE\Wow6432Node\DMA Design Ltd HKLM\SOFTWARE\Wow6432Node\drpsu HKLM\SOFTWARE\Wow6432Node\EA Games =>.EA Games HKLM\SOFTWARE\Wow6432Node\Elaborate Bytes =>.Elaborate Bytes HKLM\SOFTWARE\Wow6432Node\Electronic Arts =>.Electronic Arts HKLM\SOFTWARE\Wow6432Node\ESN Launcher HKLM\SOFTWARE\Wow6432Node\ESN Sonar-0.70.4 HKLM\SOFTWARE\Wow6432Node\GNU =>.GNU HKLM\SOFTWARE\Wow6432Node\Google =>.Google HKLM\SOFTWARE\Wow6432Node\Intel =>.Intel HKLM\SOFTWARE\Wow6432Node\Internet Download Manager HKLM\SOFTWARE\Wow6432Node\JavaSoft =>.JavaSoft HKLM\SOFTWARE\Wow6432Node\JreMetrics =>.JreMetrics HKLM\SOFTWARE\Wow6432Node\Khronos =>.Khronos HKLM\SOFTWARE\Wow6432Node\Macromedia =>.Macromedia HKLM\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware =>.Malwarebytes' Anti-Malware HKLM\SOFTWARE\Wow6432Node\MozillaPlugins =>.MozillaPlugins HKLM\SOFTWARE\Wow6432Node\Nuance HKLM\SOFTWARE\Wow6432Node\NVIDIA Corporation =>.NVIDIA Corporation HKLM\SOFTWARE\Wow6432Node\ODBC HKLM\SOFTWARE\Wow6432Node\OpenAL HKLM\SOFTWARE\Wow6432Node\Origin HKLM\SOFTWARE\Wow6432Node\Origin Games HKLM\SOFTWARE\Wow6432Node\Razer =>.Razer HKLM\SOFTWARE\Wow6432Node\Rockstar Games =>.Rockstar Games HKLM\SOFTWARE\Wow6432Node\Valve =>.Valve HKLM\SOFTWARE\Wow6432Node\Volatile HKLM\SOFTWARE\Wow6432Node\Waves Audio HKLM\SOFTWARE\Wow6432Node\WinPcap HKLM\SOFTWARE\Wow6432Node\Even Balance HKLM\SOFTWARE\Wow6432Node\RegisteredApplications HKCU\SOFTWARE\7-Zip HKCU\SOFTWARE\AC3Filter HKCU\SOFTWARE\Adobe =>.Adobe HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\AVG HKCU\SOFTWARE\Cain HKCU\SOFTWARE\Cygnus Solutions =>.Cygnus Solutions HKCU\SOFTWARE\DownloadManager HKCU\SOFTWARE\DRP HKCU\SOFTWARE\drpsu HKCU\SOFTWARE\Elaborate Bytes =>.Elaborate Bytes HKCU\SOFTWARE\Electronic Arts =>.Electronic Arts HKCU\SOFTWARE\ESET =>.ESET HKCU\SOFTWARE\Gabest =>.Gabest HKCU\SOFTWARE\GNU =>.GNU HKCU\SOFTWARE\Google =>.Google HKCU\SOFTWARE\Intel =>.Intel HKCU\SOFTWARE\JavaSoft =>.JavaSoft HKCU\SOFTWARE\Macromedia =>.Macromedia HKCU\SOFTWARE\Malwarebytes' Anti-Malware =>.Malwarebytes' Anti-Malware HKCU\SOFTWARE\Mozilla =>.Mozilla HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins HKCU\SOFTWARE\NVIDIA Corporation =>.NVIDIA Corporation HKCU\SOFTWARE\Piriform =>.Piriform HKCU\SOFTWARE\Razer =>.Razer HKCU\SOFTWARE\RealNetworks =>.RealNetworks HKCU\SOFTWARE\Realtek =>.Realtek HKCU\SOFTWARE\SamLab.ws HKCU\SOFTWARE\SplitmediaLabs =>.SplitMediaLabs HKCU\SOFTWARE\Valve =>.Valve HKCU\SOFTWARE\VB and VBA Program Settings HKCU\SOFTWARE\WinRAR =>.WinRAR HKCU\SOFTWARE\WinRAR SFX HKCU\SOFTWARE\Wow6432Node HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Software HKCU\SOFTWARE\AppDataLow\Software\Adobe =>.Adobe HKCU\SOFTWARE\AppDataLow\Software\Macromedia =>.Macromedia HKCU\SOFTWARE\AppDataLow\Software\Unity HKCU\SOFTWARE\AppDataLow\Software\Wales Interactive ---\\ Contents of the Common Files folders (171) - 23s O43 - CFD: 25/09/2016 - [] D -- C:\Program Files\CCleaner =>.Piriform Ltd® O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation O43 - CFD: 21/11/2010 - [] D -- C:\Program Files\DVD Maker =>.Aone Software O43 - CFD: 24/09/2016 - [0] D -- C:\Program Files\HitmanPro =>.EIDOS hitman Game O43 - CFD: 23/09/2016 - [] D -- C:\Program Files\Intel =>.Intel Corporation O43 - CFD: 21/11/2010 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] D -- C:\Program Files\Java =>.Oracle America, Inc.® O43 - CFD: 21/11/2010 - [] D -- C:\Program Files\Microsoft Games =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] D -- C:\Program Files\Microsoft Silverlight =>.Microsoft Corporation® O43 - CFD: 26/09/2016 - [] D -- C:\Program Files\Microsoft Xbox 360 Accessories =>.Microsoft Corporation® O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] D -- C:\Program Files\NVIDIA Corporation =>.NVIDIA Corporation® O43 - CFD: 23/09/2016 - [] D -- C:\Program Files\Realtek =>.Andrea Electronics® O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation O43 - CFD: 25/09/2016 - [] D -- C:\Program Files\Rockstar Games =>.Take-Two Interactive Software, Inc.® O43 - CFD: 23/09/2016 - [] D -- C:\Program Files\SAM CoDeC Pack O43 - CFD: 23/09/2016 - [] D -- C:\Program Files\Synaptics =>.Synaptics O43 - CFD: 23/09/2016 - [] D -- C:\Program Files\TechUtilities {71EBD09B54A645EF7DC9D5562433CD2C} O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation O43 - CFD: 26/09/2016 - [] D -- C:\Program Files\VideoLAN =>.VideoLAN O43 - CFD: 21/11/2010 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation O43 - CFD: 21/11/2010 - [] D -- C:\Program Files\Windows Journal =>.Microsoft Corporation O43 - CFD: 21/11/2010 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation O43 - CFD: 21/11/2010 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation O43 - CFD: 21/11/2010 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation® O43 - CFD: 21/11/2010 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation O43 - CFD: 21/11/2010 - [] D -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] D -- C:\Program Files\WinRAR =>.win.rar GmbH® O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\7-Zip =>.Igor Pavlov O43 - CFD: 23/09/2016 - [0] D -- C:\Program Files (x86)\AGEIA Technologies =>.AGEIA Technologies O43 - CFD: 26/09/2016 - [] D -- C:\Program Files (x86)\AVG =>.AVG Software O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\Battlelog Web Plugins =>.EA Digital Illusions CE AB® O43 - CFD: 29/09/2016 - [] D -- C:\Program Files (x86)\Cain O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\Elaborate Bytes =>.Elaborate Bytes O43 - CFD: 24/09/2016 - [] D -- C:\Program Files (x86)\Google =>.Google O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\Intel =>.Intel Corporation - pGFX® O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\Internet Download Manager =>.Tonec Inc O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\Java =>.Oracle America, Inc.® O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\Microsoft Silverlight =>.Microsoft Corporation® O43 - CFD: 24/09/2016 - [] D -- C:\Program Files (x86)\Microsoft-data O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\NVIDIA Corporation =>.NVIDIA Corporation® O43 - CFD: 26/09/2016 - [] D -- C:\Program Files (x86)\OpenAL =>.Creative Labs Inc® O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\Origin =>.Electronic Arts, Inc.® O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\Origin Games =>.Electronic Arts® O43 - CFD: 29/09/2016 - [] D -- C:\Program Files (x86)\Portable O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\Razer =>.Razer USA Ltd.® O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation O43 - CFD: 26/09/2016 - [] D -- C:\Program Files (x86)\Rockstar Games =>.Take-Two Interactive Software, Inc.® O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\SAM CoDeC Pack O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files (x86)\Uninstall Information =>.Microsoft Corporation O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation® O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation O43 - CFD: 29/09/2016 - [] D -- C:\Program Files (x86)\WinPcap =>.Riverbed Technology, Inc.® O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip =>.Igor Pavlov O43 - CFD: 23/09/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 4 O43 - CFD: 29/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cain O43 - CFD: 25/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes =>.Elaborate Bytes O43 - CFD: 23/09/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager =>.Tonec Inc O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java =>.Oracle O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight =>.Microsoft Corporation O43 - CFD: 26/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Xbox 360 Accessories =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need for Speed™ Most Wanted O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation =>.NVIDIA Corporation O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin =>.Electronic Arts, Inc. O43 - CFD: 24/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics =>.R.G. Mechanics O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer =>.Razer O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SAM CoDeC Pack O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation O43 - CFD: 21/11/2010 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC =>.Wacom Technology O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechUtilities O43 - CFD: 27/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Bunker O43 - CFD: 26/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLAN O43 - CFD: 29/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap =>.Riverbed Technology O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation O43 - CFD: 26/09/2016 - [] D -- C:\ProgramData\Avg =>.AVG Software O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Codemasters =>.Codemasters O43 - CFD: 25/09/2016 - [] HD -- C:\ProgramData\Common Files =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Electronic Arts =>.Electronic Arts O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Favorites =>.Microsoft Corporation O43 - CFD: 24/09/2016 - [] D -- C:\ProgramData\HitmanPro =>.EIDOS hitman Game O43 - CFD: 23/09/2016 - [0] D -- C:\ProgramData\IDM =>.IDM O43 - CFD: 24/09/2016 - [] D -- C:\ProgramData\Malwarebytes =>.Malwarebytes O43 - CFD: 23/09/2016 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft O43 - CFD: 01/10/2016 - [] D -- C:\ProgramData\NVIDIA =>.NVIDIA Corporation O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\NVIDIA Corporation =>.NVIDIA Corporation O43 - CFD: 26/09/2016 - [] D -- C:\ProgramData\Origin =>.Electronic Arts, Inc. O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Razer =>.Razer O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Steam =>.SteamApps O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\Sun =>.Oracle O43 - CFD: 23/09/2016 - [] D -- C:\ProgramData\TechUtilities64 O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] HD -- C:\Program Files (x86)\Common Files\EAInstaller =>.Electronic Arts, Inc. O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\Common Files\Intel =>.Intel Corporation O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\Common Files\Java =>.Oracle O43 - CFD: 23/09/2016 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines =>.Microsoft Corporation O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation O43 - CFD: 29/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\AC3Filter =>.Vigovsky Alexander O43 - CFD: 23/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\Adobe =>.Adobe O43 - CFD: 26/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\BioshockHD O43 - CFD: 24/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\bizarre creations =>.Bizarre Creations O43 - CFD: 24/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\Blur =>.Blur O43 - CFD: 01/10/2016 - [] D -- C:\Users\MARK\AppData\Roaming\DMCache =>.DMCache O43 - CFD: 23/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\DRPNPS O43 - CFD: 23/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\DRPSu O43 - CFD: 23/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\Identities =>.Microsoft Corporation O43 - CFD: 25/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\IDM =>.IDM O43 - CFD: 24/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\Malwarebytes =>.Malwarebytes O43 - CFD: 21/11/2010 - [0] D -- C:\Users\MARK\AppData\Roaming\Media Center Programs =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] SD -- C:\Users\MARK\AppData\Roaming\Microsoft =>.Microsoft O43 - CFD: 26/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\Origin =>.Electronic Arts, Inc. O43 - CFD: 26/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\Steam =>.SteamApps O43 - CFD: 01/10/2016 - [] D -- C:\Users\MARK\AppData\Roaming\vlc =>.VideoLAN O43 - CFD: 23/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\WinRAR =>.WinRAR O43 - CFD: 01/10/2016 - [] D -- C:\Users\MARK\AppData\Roaming\ZHP =>.Nicolas Coolman O43 - CFD: 23/09/2016 - [0] SHD -- C:\Users\MARK\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 25/09/2016 - [] D -- C:\Users\MARK\AppData\Local\Avg =>.AVG Software O43 - CFD: 26/09/2016 - [] D -- C:\Users\MARK\AppData\Local\AvgSetupLog =>.AVG O43 - CFD: 23/09/2016 - [] D -- C:\Users\MARK\AppData\Local\CEF =>.CEF O43 - CFD: 29/09/2016 - [] D -- C:\Users\MARK\AppData\Local\CrashDumps =>.Microsoft Corporation O43 - CFD: 29/09/2016 - [] D -- C:\Users\MARK\AppData\Local\Diagnostics =>.Microsoft Corporation O43 - CFD: 24/09/2016 - [] D -- C:\Users\MARK\AppData\Local\ESET =>.ESET O43 - CFD: 24/09/2016 - [] D -- C:\Users\MARK\AppData\Local\Google =>.Google O43 - CFD: 23/09/2016 - [0] SHD -- C:\Users\MARK\AppData\Local\History =>.Microsoft Corporation O43 - CFD: 29/09/2016 - [] D -- C:\Users\MARK\AppData\Local\Microsoft =>.Microsoft O43 - CFD: 23/09/2016 - [] D -- C:\Users\MARK\AppData\Local\NVIDIA =>.NVIDIA Corporation O43 - CFD: 24/09/2016 - [] D -- C:\Users\MARK\AppData\Local\NVIDIA Corporation =>.NVIDIA Corporation O43 - CFD: 23/09/2016 - [] D -- C:\Users\MARK\AppData\Local\Origin =>.Electronic Arts, Inc. O43 - CFD: 23/09/2016 - [] D -- C:\Users\MARK\AppData\Local\Programs =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] D -- C:\Users\MARK\AppData\Local\Razer =>.Razer O43 - CFD: 24/09/2016 - [] D -- C:\Users\MARK\AppData\Local\Rockstar Games =>.Rockstar Games O43 - CFD: 01/10/2016 - [] D -- C:\Users\MARK\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [0] SHD -- C:\Users\MARK\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [0] D -- C:\Users\MARK\AppData\Local\VirtualStore =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [0] D -- C:\Users\MARK\AppData\Local\Programs\Common =>.Microsoft Corporation O43 - CFD: 14/07/2009 - [] RD -- C:\Users\MARK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] RD -- C:\Users\MARK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools O43 - CFD: 29/09/2016 - [0] D -- C:\Users\MARK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cain O43 - CFD: 28/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager =>.Tonec Inc O43 - CFD: 14/07/2009 - [] RD -- C:\Users\MARK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation O43 - CFD: 29/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Portable Programs O43 - CFD: 23/09/2016 - [] RD -- C:\Users\MARK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation O43 - CFD: 23/09/2016 - [] D -- C:\Users\MARK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR O43 - CFD: 25/09/2016 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Avg =>.AVG Software O43 - CFD: 26/09/2016 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\AvgSetupLog =>.AVG O43 - CFD: 24/09/2016 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\ESET =>.ESET O43 - CFD: 24/09/2016 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft O43 - CFD: 23/09/2016 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Razer =>.Razer O43 - CFD: 23/09/2016 - [] SD -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft ---\\ ShellIconOverlayIdentifiers (SIOI) (2) - 1s O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation ---\\ ShareTools MSconfig StartupReg (3) - 0s O53 - SMSR:HKLM\...\startupreg\IDMan [Key] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc. O53 - SMSR:HKLM\...\startupreg\SunJavaUpdateSched [Key] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle Corporation O53 - SMSR:HKLM\...\startupreg\VirtualCloneDrive [Key] . (.Elaborate Bytes AG - Virtual CloneDrive Daemon.) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe =>.Elaborate Bytes AG ---\\ System Drivers List (67) - 12s O58 - SDL:2009/07/14 04:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [491088] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [339536] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\drivers\adpu320.sys [182864] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [15440] =>.Microsoft Windows® O58 - SDL:2010/11/21 06:23:47 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [107904] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [194128] =>.Microsoft Windows® O58 - SDL:2010/11/21 06:23:47 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [27008] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [87632] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [97856] =>.Microsoft Windows® O58 - SDL:2015/09/09 05:16:16 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\Windows\System32\drivers\athrx.sys [4162560] =>.Qualcomm Atheros Communications, Inc. O58 - SDL:2009/06/10 23:34:23 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60a.sys [270848] =>.Broadcom Corporation O58 - SDL:2009/06/10 23:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [18432] =>.Brother Industries, Ltd. O58 - SDL:2009/06/10 23:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [8704] =>.Brother Industries, Ltd. O58 - SDL:2009/07/14 04:19:07 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [286720] =>.Brother Industries Ltd. O58 - SDL:2009/06/10 23:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [47104] =>.Brother Industries Ltd. O58 - SDL:2009/06/10 23:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [14976] =>.Brother Industries Ltd. O58 - SDL:2009/06/10 23:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [14720] =>.Brother Industries Ltd. O58 - SDL:2015/09/28 01:52:38 A . (.Qualcomm Atheros - Qualcomm Atheros BtFilter Driver.) -- C:\Windows\System32\drivers\btfilter.sys [601240] =>.Qualcomm Atheros® O58 - SDL:2009/06/10 23:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [468480] =>.Broadcom Corporation O58 - SDL:2009/07/14 04:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [17488] =>.Microsoft Windows® O58 - SDL:2008/07/21 15:11:56 A . (.Elaborate Bytes AG - ElbyCD Windows x64 I/O driver.) -- C:\Windows\System32\drivers\ElbyCDIO.sys [32200] =>.Elaborate Bytes AG® O58 - SDL:2009/07/14 04:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [530496] =>.Microsoft Windows® O58 - SDL:2016/05/12 10:48:30 A . (.ESET - Epfw NDIS LightWeight Filter.) -- C:\Windows\System32\drivers\EpfwLWF.sys [53384] =>.ESET, spol. s r.o.® O58 - SDL:2009/06/10 23:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3286016] =>.Broadcom Corporation O58 - SDL:2009/09/09 12:23:46 A . (.Intel Corporation - BIOS Update Driver.) -- C:\Windows\System32\drivers\flashud.sys [51712] =>.Intel Corporation O58 - SDL:2009/06/10 23:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [31232] =>.Hauppauge Computer Works, Inc. O58 - SDL:2010/11/21 06:23:47 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [78720] =>.Microsoft Windows® O58 - SDL:2016/08/29 21:15:48 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver -.) -- C:\Windows\System32\drivers\iaStorA.sys [1469944] {330000B97FAEF583F53CC47FCD00020000B97F} =>.Intel Corporation O58 - SDL:2016/08/29 21:15:48 A . (.Intel Corporation - Intel(R) Rapid Storage Technology Filter dr.) -- C:\Windows\System32\drivers\iaStorF.sys [31712] {330000B97FAEF583F53CC47FCD00020000B97F} =>.Intel Corporation O58 - SDL:2010/11/21 06:23:47 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [410496] =>.Microsoft Windows® O58 - SDL:2016/08/05 17:04:22 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\drivers\idmwfp.sys [217256] =>.Tonec Inc.® O58 - SDL:2016/01/13 16:37:52 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd64.sys [3793872] =>.Intel(R) pGFX® O58 - SDL:2009/07/14 04:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [44112] =>.Microsoft Windows® O58 - SDL:2015/08/21 11:50:48 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\Windows\System32\drivers\IntcDAud.sys [463112] =>.Intel Corporation - Client Components Group® O58 - SDL:2016/03/17 19:39:16 A . (.Intel Corporation - Intel(R) USB 3.0 eXtensible Host Controller.) -- C:\Windows\System32\drivers\iusb3xhc.sys [806896] {330000B8E17CE5BD0363496E0900020000B8E1} =>.Intel Corporation O58 - SDL:2009/07/14 04:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [114752] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [106560] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [65600] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [115776] =>.Microsoft Windows® O58 - SDL:2016/09/24 19:25:27 A . (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys [192216] =>.Malwarebytes Corporation® O58 - SDL:2009/07/14 04:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [35392] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [284736] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [51264] =>.Microsoft Windows® O58 - SDL:2013/03/01 04:49:12 A . (.Riverbed Technology, Inc. - npf.sys (NT5/6 AMD64) Kernel Driver.) -- C:\Windows\System32\drivers\npf.sys [36600] =>.Riverbed Technology, Inc.® O58 - SDL:2016/04/27 17:35:11 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\Windows\System32\drivers\nvlddmkm.sys [12539960] =>.NVIDIA Corporation® O58 - SDL:2016/04/27 17:35:11 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\Windows\System32\drivers\nvpciflt.sys [38336] =>.NVIDIA Corporation® O58 - SDL:2010/11/21 06:23:47 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [148352] =>.Microsoft Windows® O58 - SDL:2010/11/21 06:23:47 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [166272] =>.Microsoft Windows® O58 - SDL:2016/09/17 04:42:26 A . (.NVIDIA Corporation - NVIDIA Virtual Audio Driver.) -- C:\Windows\System32\drivers\nvvad64v.sys [47672] =>.NVIDIA Corporation® O58 - SDL:2009/07/14 04:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1524816] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [128592] =>.Microsoft Windows® O58 - SDL:2016/04/21 10:03:34 A . (.Realtek - Realtek 8136/8168/8169 NDIS 6.20 64-bit Dri.) -- C:\Windows\System32\drivers\Rt64win7.sys [1028352] =>.Realtek Semiconductor Corp® O58 - SDL:2016/05/03 10:33:28 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RTKVHD64.sys [5007104] =>.Realtek Semiconductor Corp® O58 - SDL:2016/09/01 08:25:44 A . (.Realsil Semiconductor Corporation - RTS USB READER Driver.) -- C:\Windows\System32\drivers\RtsUer.sys [418784] =>.Realtek Semiconductor Corp.® O58 - SDL:2016/05/07 01:50:37 A . (.Razer, Inc. - Razer Overlay Support.) -- C:\Windows\System32\drivers\rzpmgrk.sys [44144] =>.Razer Inc.® O58 - SDL:2016/06/01 23:32:32 A . (.Razer, Inc. - Razer Overlay Support.) -- C:\Windows\System32\drivers\rzpnk.sys [137840] =>.Razer Inc.® O58 - SDL:2009/06/10 23:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] =>.Macrovision Corporation, Macrovision Europe Limited, O58 - SDL:2009/07/14 03:00:40 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) -- C:\Windows\System32\drivers\serial.sys [94208] =>.Brother Industries Ltd. O58 - SDL:2009/07/14 04:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [43584] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [80464] =>.Microsoft Windows® O58 - SDL:2013/08/13 14:19:12 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\Windows\System32\drivers\Smb_driver_Intel.sys [34544] =>.Synaptics Incorporated® O58 - SDL:2016/01/08 11:51:54 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ve.) -- C:\Windows\System32\drivers\ssudbus.sys [120416] =>.Samsung Electronics CO., LTD.® O58 - SDL:2009/07/14 04:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [24656] =>.Microsoft Windows® O58 - SDL:2016/07/29 18:29:16 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\drivers\TeeDriverx64.sys [199736] =>.Intel(R) Embedded Subsystems and IP Blocks Group® O58 - SDL:2008/07/17 03:12:49 A . (.Elaborate Bytes AG - VirtualCloneCD Driver.) -- C:\Windows\System32\drivers\VClone.sys [35328] =>.Elaborate Bytes AG O58 - SDL:2009/07/14 04:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [17488] =>.Microsoft Windows® O58 - SDL:2009/07/14 04:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [161872] =>.Microsoft Windows® ---\\ Last modified or created user files (17) - 28s O61 - LFC: 2016/09/29 19:27:00 A . (..) -- C:\Users\MARK\Downloads\Programs\cain20.exe [676652] O61 - LFC: 2016/09/29 19:33:29 A . (..) -- C:\Users\MARK\Downloads\Programs\ca_setup.exe [8244106] O61 - LFC: 2016/09/26 09:24:07 A . (..) -- C:\Users\MARK\Documents\Rockstar Games\GTA V\Profiles\DFE3B7FD\pc_settings.bin [896] O61 - LFC: 2016/09/26 18:01:26 A . (..) -- C:\Users\MARK\AppData\Roaming\IDM\DwnlData\MARK\directx_Jun2010_redist_44\directx_Jun2010_redist.exe [333340] O61 - LFC: 2016/09/23 13:43:39 A . (..) -- C:\Users\MARK\AppData\Roaming\DRPSu\PROGRAMS\DriverPack-Notifier.exe [386457] O61 - LFC: 2016/09/23 13:43:41 A . (..) -- C:\Users\MARK\AppData\Roaming\DRPSu\PROGRAMS\Firefox.exe [271252] O61 - LFC: 2016/09/23 13:43:40 A . (..) -- C:\Users\MARK\AppData\Roaming\DRPSu\PROGRAMS\OperaBlink.exe [360226] O61 - LFC: 2016/09/23 13:43:46 A . (..) -- C:\Users\MARK\AppData\Roaming\DRPSu\PROGRAMS\WinRARx86Eng.exe [471683] O61 - LFC: 2016/09/24 08:39:39 A . (..) -- C:\Users\MARK\AppData\Roaming\Blur\Uninstall\unins000.exe [924513] O61 - LFC: 2016/09/23 17:57:25 A . (..) -- C:\Users\MARK\AppData\Local\Origin\ThinSetup\10.0.2.33129\icudt51.dll [727457] O61 - LFC: 2016/09/23 17:57:26 A . (..) -- C:\Users\MARK\AppData\Local\Origin\ThinSetup\10.0.2.33129\libEGL.dll [12288] O61 - LFC: 2016/09/23 17:57:26 A . (..) -- C:\Users\MARK\AppData\Local\Origin\ThinSetup\10.0.2.33129\libGLESv2.dll [2493440] O61 - LFC: 2016/09/23 17:57:28 A . (..) -- C:\Users\MARK\AppData\Local\Origin\ThinSetup\10.0.2.33129\QtWebEngineProcess.exe [15872] O61 - LFC: 2016/09/25 10:45:34 A . (..) -- C:\Users\MARK\AppData\Local\Microsoft\Windows\1033\StructuredQuerySchema.bin [296502] O61 - LFC: 2016/09/30 19:06:26 A . (..) -- C:\Users\MARK\AppData\Local\Google\Chrome\User Data\nacl_validation_cache.bin [128] O61 - LFC: 2016/09/14 03:25:09 A . (..) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\53.0.2785.116\natives_blob.bin [367250] O61 - LFC: 2016/09/14 03:25:09 A . (..) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\53.0.2785.116\snapshot_blob.bin [648432] ---\\ File Associations Shell Spawning (10) - 0s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe =>.Microsoft Corporation O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc® ---\\ Start Menu Internet (4) - 0s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc® O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Users\MARK\AppData\Local\Google\Chrome\Application\chrome.exe =>.Google Inc. ---\\ Search Browser Infection (2) - 1s O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ ---\\ Search Svchost Services (33) - 1s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\Windows\System32\aelupsvc.dll [72192] =>.Microsoft Corporation O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [80384] =>.Microsoft Corporation O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [80384] =>.Microsoft Corporation O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\Windows\system32\srvsvc.dll [236032] =>.Microsoft Corporation O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\Windows\System32\gpsvc.dll [777728] =>.Microsoft Corporation O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\ikeext.dll [853504] =>.Microsoft Corporation O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\Windows\System32\Audiosrv.dll [679424] =>.Microsoft Corporation O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\Windows\System32\rasauto.dll [99328] =>.Microsoft Corporation O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [344064] =>.Microsoft Corporation O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [97792] =>.Microsoft Corporation O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\Windows\System32\Sens.dll [64512] =>.Microsoft Corporation O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [359424] =>.Microsoft Corporation O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [316928] =>.Microsoft Corporation O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remote Desktop Session Host Server Remote C.) -- C:\Windows\System32\termsrv.dll [680960] =>.Microsoft Corporation O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\system32\wuaueng.dll [2420736] =>.Microsoft Corporation O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\Windows\System32\qmgr.dll [849920] =>.Microsoft Corporation O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [370688] =>.Microsoft Corporation O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [569344] =>.Microsoft Corporation O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\Windows\system32\seclogon.dll [30720] =>.Microsoft Corporation O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\Windows\System32\appinfo.dll [70656] =>.Microsoft Corporation O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\Windows\system32\iscsiexe.dll [156672] =>.Microsoft Corporation O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) -- C:\Windows\system32\mmcss.dll [67584] =>.Microsoft Corporation O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [242688] =>.Microsoft Corporation O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [121856] =>.Microsoft Corporation O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\Windows\System32\browser.dll [136192] =>.Microsoft Corporation O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [111104] =>.Microsoft Corporation O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\Windows\system32\schedsvc.dll [1110016] =>.Microsoft Corporation O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\Windows\system32\kmsvc.dll [90624] =>.Microsoft Corporation O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\Windows\System32\wercplsupport.dll [84480] =>.Microsoft Corporation O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [209920] =>.Microsoft Corporation O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\Windows\system32\themeservice.dll [44544] =>.Microsoft Corporation O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\Windows\System32\bdesvc.dll [100864] =>.Microsoft Corporation O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Software installation Service.) -- C:\Windows\System32\appmgmts.dll [193536] =>.Microsoft Corporation ---\\ Firewall Active Exception List (2) - 4s O87 - FAEL: "TCP Query User{9FAD8EB8-64F5-4746-BC5F-00C6D8476107}D:\blur\blur.exe" [In-None-P6-TRUE] .(...) -- D:\blur\blur.exe O87 - FAEL: "UDP Query User{3B229FCE-C768-4ED7-AC0D-379E5CC6DD0C}D:\blur\blur.exe" [In-None-P17-TRUE] .(...) -- D:\blur\blur.exe ---\\ Additional Scan (O88) (1) - 0s C:\Users\MARK\AppData\Roaming\Setup.exe =>Heuristic.Suspect ---\\ Summary of the elements found (3) - 0s https://www.nicolascoolman.com/fr/logiciels-superflus =>.Superfluous.AkamaiHD https://www.nicolascoolman.com/fr/pup-optional-startsearch/ =>PUP.Optional.StartSearch https://www.anti-malware.top/2016/04/22/heuristic-suspect/ =>Heuristic.Suspect ~ End of the scan, 15545 items in 00h03mn56s (823)