~ ZHPDiag v2016.4.14.87 By Nicolas Coolman (2016/04/14) ~ Run by hocky_000 (Administrator) (2016/04/14 20:07:09) ~ Web: http://www.nicolascoolman.com ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ State version: Version OK ~ Mode: Scan ~ Report: C:\Users\hocky_000\Desktop\ZHPDiag.txt ~ Report: C:\Users\hocky_000\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ System startup: Normal (Normal boot) Windows 10 Home, 32-bit (Build 10586) ---\\ Internet Browsers (1) - 0s MSIE: Internet Explorer v11.212.10586.0 ---\\ Windows Product Information (3) - 3s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK ---\\ System protection software (1) - 4s Windows Defender (Activate) ---\\ System optimization software (1) - 4s CCleaner v5.16 ---\\ Information on the system (6) - 0s ~ Operating System: x86 Family 6 Model 55 Stepping 3, GenuineIntel ~ Operating System: 32-bit ~ Boot mode: Normal (Normal boot) Total RAM: 1979.548 MB (25% free) System Restore: Activé (Enable) System drive C: has 34 GB () free of 50 GB ---\\ Connection to the system mode (3) - 0s ~ Computer Name: USER ~ User Name: hocky_000 ~ Logged in as Administrator ---\\ Enumeration of the disk units (1) - 0s ~ Drive C: has 34 GB free of 50 GB (System) ---\\ State of the Windows Security Center (7) - 1s [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK ---\\ Search Generic System Files (23) - 1s [MD5.FCBCED2A237DCD7EF86CED551B731742] - 29/01/2016 - (.Microsoft Corporation - Windows Explorer.) -- C:\WINDOWS\Explorer.exe [4064320] =>.Microsoft Windows® [MD5.2DBCA4E4BB09FF7F8F171CC364DFAF67] - 29/10/2015 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\WINDOWS\System32\rundll32.exe [53760] =>.Microsoft Corporation [MD5.DE3A10032AE77199B1E7FBC8D6E21636] - 29/10/2015 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\WINDOWS\System32\Wininit.exe [192200] =>.Microsoft Windows Publisher® [MD5.2BFF4D19D7FC686C150879A2FD5BAE77] - 29/03/2016 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\WINDOWS\System32\wininet.dll [2229760] =>.Microsoft Corporation [MD5.66FC7843E349C68F424EB79E0A17D8D2] - 04/01/2016 - (.Microsoft Corporation - Windows Logon Application.) -- C:\WINDOWS\System32\Winlogon.exe [493056] =>.Microsoft Corporation [MD5.97FA4FB31B988CFA3E8F39788BC16562] - 29/10/2015 - (.Microsoft Corporation - Software Licensing Library.) -- C:\WINDOWS\System32\sppcomapi.dll [419328] =>.Microsoft Corporation [MD5.6A7ACABAE92C837F5C1330188EAE36AE] - 29/03/2016 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\WINDOWS\System32\dnsapi.dll [535080] =>.Microsoft Windows® [MD5.0E423A5854E1265F3B6D27332601355F] - 05/11/2015 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\WINDOWS\System32\drivers\AFD.sys [471392] =>.Microsoft Windows® [MD5.845E9A40B9B3CAD20B5EE45A2A58EE11] - 29/10/2015 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [23392] =>.Microsoft Windows® [MD5.40FF3DCC427730779DDF301A0F9FC0E1] - 29/10/2015 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [74752] =>.Microsoft Corporation [MD5.568DF0072AD005D29D6E987698C8225A] - 29/10/2015 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [130560] =>.Microsoft Corporation [MD5.BE1E27EBF119A4487BF6B510C8A4D258] - 29/03/2016 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\DfsC.sys [114176] =>.Microsoft Corporation [MD5.1CB5E8AA58EE45207109AD07D50BB7D2] - 29/10/2015 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [68096] =>.Microsoft Corporation [MD5.14DDBB0CBE11A736C089A4F2813A5EDF] - 29/10/2015 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [90624] =>.Microsoft Corporation [MD5.F97C1D68DE39952F880F98CFCE0DAF1A] - 29/10/2015 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [124416] =>.Microsoft Corporation [MD5.89A56A86A03414C8ED5A96A52C3BA7B2] - 23/02/2016 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [381280] =>.Microsoft Windows® [MD5.1CA44BC32773FCB9FE4ADAA077AB642E] - 29/10/2015 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [211968] =>.Microsoft Corporation [MD5.C195E7756F795F10338ECE0AD20B72D2] - 29/03/2016 - (.Microsoft Corporation - NT File System Driver.) -- C:\WINDOWS\System32\drivers\ntfs.sys [1820512] =>.Microsoft Windows® [MD5.B69B323395ABC1303EB9F69E9B8460F8] - 29/10/2015 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\WINDOWS\System32\drivers\Parport.sys [81408] =>.Microsoft Corporation [MD5.D49CBC052916F95D184713CA6FC37C5C] - 23/02/2016 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [80896] =>.Microsoft Corporation [MD5.288DA2E52BFE6A90937FF9A994FA56ED] - 30/10/2015 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [132608] =>.Microsoft Corporation [MD5.1683BCB69B9950CD8C97865F3EC6781E] - 05/11/2015 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [95072] =>.Microsoft Windows® [MD5.2E5522E831E616B37F06908B7B56C3B3] - 29/10/2015 - (.Microsoft Corporation - Volume Shadow Copy Driver.) -- C:\WINDOWS\System32\drivers\volsnap.sys [349536] =>.Microsoft Windows® ---\\ Non Microsoft non disabled Windows Services (10) - 3s O23 - Service: ASUS HID Access Service (AsHidService) . (.ASUSTek Computer Inc. - AsHidSrv Service.) - C:\Program Files\ASUS\ATK Package\ATK Hotkey\AsHidSrv.exe =>.ASUSTeK Computer Inc.® O23 - Service: ASLDR Service (ASLDRService) . (.ASUSTek Computer Inc. - ASLDR Service.) - C:\Program Files\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe =>.ASUSTeK Computer Inc.® O23 - Service: Asus WebStorage Windows Service (Asus WebStorage Windows Service) . (.ASUS Cloud Corporation - Asus WebStorage Windows Service.) - C:\Program Files\ASUS\WebStorage\2.0.3.226\AsusWSWinService.exe =>.ASUS Cloud Corporation O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) . (.ASUS - GFNEXSrv.) - C:\Program Files\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe =>.ASUSTeK Computer Inc.® O23 - Service: @oem26.inf,%BcmBtRSupport.SVCNAME%;Bluetooth Driver Managem (BcmBtRSupport) . (.Broadcom Corporation. - Bluetooth Radio Management Support.) - C:\Windows\System32\BtwRSupportService.exe =>.Broadcom Corporation® O23 - Service: @oem10.inf,%WIN32_DPTF_PARTICIPANT_PROC_SERVICE_DISPLAY_NAM (DptfParticipantProcessorService) . (.Intel Corporation - Intel DPTF Processor Service.) - C:\Windows\System32\DptfParticipantProcessorService.exe =>.Intel Corporation O23 - Service: @oem10.inf,%WIN32_DPTF_POLICY_CRITICAL_SERVICE_DISPLAY_NAME (DptfPolicyCriticalService) . (.Intel Corporation - Intel DPTF Critical Service.) - C:\Windows\System32\DptfPolicyCriticalService.exe =>.Intel Corporation O23 - Service: @oem10.inf,%WIN32_DPTF_POLICY_LPM_SERVICE_DISPLAY_NAME%;Int (DptfPolicyLpmService) . (.Intel Corporation - Intel DPTF LPM Service.) - C:\Windows\System32\DptfPolicyLpmService.exe =>.Intel Corporation O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation - igfxCUIService Module.) - C:\Windows\System32\igfxCUIService.exe =>.Intel Corporation - pGFX® O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe =>.Skype Software Sarl® ---\\ Services not Microsoft (SR=Run, SS=Stop) (13) - 33s SR - Auto [16/05/2013] [ 103224] ASUS HID Access Service (AsHidService) . (.ASUSTek Computer Inc..) - C:\Program Files\ASUS\ATK Package\ATK Hotkey\AsHidSrv.exe =>.ASUSTeK Computer Inc.® SR - Auto [15/01/2013] [ 107320] ASLDR Service (ASLDRService) . (.ASUSTek Computer Inc..) - C:\Program Files\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe =>.ASUSTeK Computer Inc.® SR - Auto [16/08/2013] [ 71680] Asus WebStorage Windows Service (Asus WebStorage Windows Service) . (.ASUS Cloud Corporation.) - C:\Program Files\ASUS\WebStorage\2.0.3.226\AsusWSWinService.exe =>.ASUS Cloud Corporation SR - Auto [21/11/2011] [ 96896] ATKGFNEX Service (ATKGFNEXSrv) . (.ASUS.) - C:\Program Files\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe =>.ASUSTeK Computer Inc.® SS - Auto [29/11/2013] [ 1678040] @oem26.inf,%BcmBtRSupport.SVCNAME%;Bluetooth Driver Managem (BcmBtRSupport) . (.Broadcom Corporation..) - C:\Windows\System32\BtwRSupportService.exe =>.Broadcom Corporation® SR - Demand [27/08/2015] [ 290224] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\System32\IntelCpHeciSvc.exe =>.Intel Corporation - pGFX® SR - Auto [23/08/2013] [ 75264] @oem10.inf,%WIN32_DPTF_PARTICIPANT_PROC_SERVICE_DISPLAY_NAM (DptfParticipantProcessorService) . (.Intel Corporation.) - C:\Windows\System32\DptfParticipantProcessorService.exe =>.Intel Corporation SR - Auto [23/08/2013] [ 89088] @oem10.inf,%WIN32_DPTF_POLICY_CRITICAL_SERVICE_DISPLAY_NAME (DptfPolicyCriticalService) . (.Intel Corporation.) - C:\Windows\System32\DptfPolicyCriticalService.exe =>.Intel Corporation SR - Auto [23/08/2013] [ 82432] @oem10.inf,%WIN32_DPTF_POLICY_LPM_SERVICE_DISPLAY_NAME%;Int (DptfPolicyLpmService) . (.Intel Corporation.) - C:\Windows\System32\DptfPolicyLpmService.exe =>.Intel Corporation SS - Demand [24/04/2012] [ 169752] Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe =>.Intel Corporation® SR - Auto [27/08/2015] [ 283568] Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation.) - C:\Windows\System32\igfxCUIService.exe =>.Intel Corporation - pGFX® SS - Auto [29/01/2016] [ 327296] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe =>.Skype Software Sarl® ---\\ Task Planned Automatically (15) - 6s [MD5.00000000000000000000000000000000] [APT] [TaskName] (...) -- Task To Run (.not file.) [0] (.Activate.) =>.Superfluous.Empty [MD5.B1F15D633A4F8D2A534C876959D98389] [APT] [ASUS AC Reminder] (.ASUSTek Computer INC..) -- C:\Program Files\ASUS\ASUS AC Reminder\ACReminderSrv.exe [1314416] (.Activate.) =>.ASUSTeK Computer Inc.® [MD5.BE163A49AF17E292B8D27AB52437FDC7] [APT] [ASUS Live Update1] (.ASUSTeK Computer Inc..) -- C:\Program Files\ASUS\ASUS Live Update\LiveUpdate.exe [3202872] (.Activate.) =>.ASUSTeK Computer Inc.® [MD5.BE163A49AF17E292B8D27AB52437FDC7] [APT] [ASUS Live Update2] (.ASUSTeK Computer Inc..) -- C:\Program Files\ASUS\ASUS Live Update\LiveUpdate.exe [3202872] (.Activate.) =>.ASUSTeK Computer Inc.® [MD5.EBCB7B97A720AE9E445CFA7119F5C5B0] [APT] [ASUS Patch for Touch Panel] (.ASUSTek Computer INC..) -- C:\ProgramData\AsTouchPanel\AsPatchTouchPanel.exe [144512] (.Activate.) =>.ASUSTeK Computer Inc.® [MD5.D1144FBF6FC1B82BAECB47CF862F1A89] [APT] [Asus Reading Mode] (.Copyright © 2013.) -- C:\Program Files\ASUS\ASUS Reading Mode\ReadingModeWatchDogx86.exe [56320] (.Activate.) [MD5.86926BE9D1B70350E8B4B815606179BC] [APT] [ASUS Smart Gesture Launcher] (.AsusTek.) -- C:\Program Files\ASUS\ASUS Smart Gesture\AsTPCenter\x86\AsusTPLauncher.exe [17392] (.Activate.) =>.ASUSTeK Computer Inc.® [MD5.EC7BF707FBE2C766A567E47515D7F746] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6667992] (.Activate.) =>.Piriform Ltd® O39 - APT: ASUS AC Reminder - (.ASUSTek Computer INC..) -- C:\WINDOWS\System32\Tasks\ASUS AC Reminder [2278] =>.ASUSTeK Computer Inc.® O39 - APT: ASUS Live Update1 - (.ASUSTeK Computer Inc..) -- C:\WINDOWS\System32\Tasks\ASUS Live Update1 [3532] =>.ASUSTeK Computer Inc.® O39 - APT: ASUS Live Update2 - (.ASUSTeK Computer Inc..) -- C:\WINDOWS\System32\Tasks\ASUS Live Update2 [3522] =>.ASUSTeK Computer Inc.® O39 - APT: ASUS Patch for Touch Panel - (.ASUSTek Computer INC..) -- C:\WINDOWS\System32\Tasks\ASUS Patch for Touch Panel [2476] =>.ASUSTeK Computer Inc.® O39 - APT: Asus Reading Mode - (.Copyright © 2013.) -- C:\WINDOWS\System32\Tasks\Asus Reading Mode [2276] O39 - APT: ASUS Smart Gesture Launcher - (.AsusTek.) -- C:\WINDOWS\System32\Tasks\ASUS Smart Gesture Launcher [3616] =>.ASUSTeK Computer Inc.® O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\WINDOWS\System32\Tasks\CCleanerSkipUAC [2856] =>.Piriform Ltd® ---\\ Process running (30) - 4s [MD5.3F9E28BCDF8E1620C1E505D37E4193AB] - (.Intel Corporation - IntelCpHeciSvc Executable.) -- C:\Windows\System32\IntelCpHeciSvc.exe [290224] [PID.1592] =>.Intel Corporation - pGFX® [MD5.AF4EAD6335AAC1F01D632A9BA4594908] - (.Intel Corporation - igfxCUIService Module.) -- C:\Windows\System32\igfxCUIService.exe [283568] [PID.1604] =>.Intel Corporation - pGFX® [MD5.DBC598E47E7A382E60E2A4745D41FEF9] - (.ASUS - GFNEXSrv.) -- C:\Program Files\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896] [PID.1960] =>.ASUSTeK Computer Inc.® [MD5.DC2BA6926FA0CDCE273CC9897F05584A] - (.ASUSTek Computer Inc. - ASLDR Service.) -- C:\Program Files\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe [107320] [PID.1972] =>.ASUSTeK Computer Inc.® [MD5.F0130AFFCF3CDEB19010DA1BC6D492F5] - (.ASUSTek Computer Inc. - AsHidSrv Service.) -- C:\Program Files\ASUS\ATK Package\ATK Hotkey\AsHidSrv.exe [103224] [PID.2236] =>.ASUSTeK Computer Inc.® [MD5.A915251FF7218A47C9EE4379804DE8EA] - (.Intel Corporation - Intel DPTF Processor Service.) -- C:\Windows\System32\DptfParticipantProcessorService.exe [75264] [PID.2268] =>.Intel Corporation [MD5.44A17208F438F915FCB490DE8FF052AD] - (.ASUS Cloud Corporation - Asus WebStorage Windows Service.) -- C:\Program Files\ASUS\WebStorage\2.0.3.226\AsusWSWinService.exe [71680] [PID.2276] =>.ASUS Cloud Corporation [MD5.8FC2BD02A5CA70386A701C4E202ADA25] - (.Intel Corporation - Intel DPTF LPM Service.) -- C:\Windows\System32\DptfPolicyLpmService.exe [82432] [PID.2284] =>.Intel Corporation [MD5.C11987B099FB57205256302A8D8CD5CD] - (.Intel Corporation - Intel DPTF Critical Service.) -- C:\Windows\System32\DptfPolicyCriticalService.exe [89088] [PID.2292] =>.Intel Corporation [MD5.CF060ECF514B1B71488843D46460F4F0] - (.ASUSTek Computer Inc. - HControl.) -- C:\Program Files\ASUS\ATK Package\ATK Hotkey\HControl.exe [303928] [PID.7864] =>.ASUSTeK Computer Inc.® [MD5.B1F15D633A4F8D2A534C876959D98389] - (.ASUSTek Computer INC. - ASUS AC Reminder Service.) -- C:\Program Files\ASUS\ASUS AC Reminder\ACReminderSrv.exe [1314416] [PID.1368] =>.ASUSTeK Computer Inc.® [MD5.EBCB7B97A720AE9E445CFA7119F5C5B0] - (.ASUSTek Computer INC. - ASUS Patch For Touch Panel.) -- C:\ProgramData\AsTouchPanel\AsPatchTouchPanel.exe [144512] [PID.5332] =>.ASUSTeK Computer Inc.® [MD5.D1144FBF6FC1B82BAECB47CF862F1A89] - (.Copyright © 2013 - ReadingModeWatchDogx86.) -- C:\Program Files\ASUS\ASUS Reading Mode\ReadingModeWatchDogx86.exe [56320] [PID.3868] [MD5.31A130B1235721C16B2BF80A48BE7C62] - (.Intel Corporation - igfxEM Module.) -- C:\Windows\System32\igfxEM.exe [425392] [PID.1068] =>.Intel Corporation - pGFX® [MD5.C5E1A4A1562E291A2B2C968B468D3F7B] - (.Intel Corporation - igfxHK Module.) -- C:\Windows\System32\igfxHK.exe [219048] [PID.5220] =>.Intel Corporation - pGFX® [MD5.0F2644DAA234BAF4E20B80196C23364C] - (.ASUSTek Computer Inc. - ATK Media.) -- C:\Program Files\ASUS\ATK Package\ATK Media\DMedia.exe [205624] [PID.4036] =>.ASUSTeK Computer Inc.® [MD5.2ABAD4BFC7A1CACF84466323E65B8F4B] - (.ASUSTek Computer Inc. - ATKOSD2.) -- C:\Program Files\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [406328] [PID.1736] =>.ASUSTeK Computer Inc.® [MD5.EDB7D046D7BCFEE8C01105E13C7EDCB7] - (.Intel Corporation - igfxTray Module.) -- C:\Windows\System32\igfxTray.exe [417696] [PID.4276] =>.Intel Corporation - pGFX® [MD5.72B93B15F83F2DCCDD91CEC54859AEDB] - (.AsusTek - ASUS Smart Gesture Loader.) -- C:\Program Files\ASUS\ASUS Smart Gesture\AsTPCenter\x86\AsusTPLoader.exe [363504] [PID.5684] =>.ASUSTeK Computer Inc.® [MD5.DFA9738F1736F53E60CE921FFE59A59D] - (.Intel Corporation - Intel DPTF LPM Service Helper.) -- C:\Windows\System32\DptfPolicyLpmServiceHelper.exe [73216] [PID.7256] =>.Intel Corporation [MD5.DF33395437DCA560E409A5C1D94C7CCB] - (.Realtek Semiconductor - Realtek Audio Manager.) -- C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe [2653912] [PID.4188] =>.Realtek Semiconductor Corp® [MD5.F02BD4C76C6B367CC04F0528A89E0FF5] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe [50670720] [PID.2388] =>.Skype Software Sarl® [MD5.EFFE7293C6D8A80A26D50B4431DCA825] - (.AsusTek - ASUS Smart Gesture Helper.) -- C:\Program Files\ASUS\ASUS Smart Gesture\AsTPCenter\x86\AsusTPHelper.exe [176624] [PID.7228] =>.ASUSTeK Computer Inc.® [MD5.EC7BF707FBE2C766A567E47515D7F746] - (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe [6667992] [PID.5528] =>.Piriform Ltd® [MD5.63D0E6CF50C4D4D7661EC1A7AF287E4F] - (.Intel Corporation - igfxext Module.) -- C:\Windows\System32\igfxext.exe [172448] [PID.5312] =>.Intel Corporation - pGFX® [MD5.904CA475F6ADD4080B0EA5144D23FDF1] - (...) -- C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe [144384] [PID.6664] [MD5.26D531B9ED41B83C54A0DC1994E43115] - (.ASUS Cloud Corporation - .) -- C:\Program Files\ASUS\WebStorage\2.0.3.226\AsusWSPanel.exe [4972864] [PID.1044] =>.ASUS Cloud Corporation® [MD5.BE163A49AF17E292B8D27AB52437FDC7] - (.ASUSTeK Computer Inc. - ASUS Live Update.) -- C:\Program Files\ASUS\ASUS Live Update\LiveUpdate.exe [3202872] [PID.7048] =>.ASUSTeK Computer Inc.® [MD5.3613EE93524E01EFB5A5DC17946DFC0C] - (.AsusTek - ASUS Smart Gesture Center.) -- C:\Program Files\ASUS\ASUS Smart Gesture\AsTPCenter\x86\AsusTPCenter.exe [304624] [PID.6692] =>.ASUSTeK Computer Inc.® [MD5.85EC7A6E8957C3B3E53ED53CEC027215] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\hocky_000\Downloads\ZHPDiag3.exe [2187264] [PID.6104] =>.Nicolas Coolman ---\\ Internet Explorer Extensions, Start, Search (11) - 1s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 ---\\ Internet Explorer, Proxy Management (4) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: VMApplet=C:\WINDOWS\system32\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation ---\\ Hosts file redirection (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (21) ---\\ Browser Helper Object (BHO) (1) - 0s O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll =>.Skype Software Sarl® ---\\ Auto loading programs from Registry and folders (12) - 2s O4 - HKLM\..\Run: [DptfPolicyLpmServiceHelper] . (.Intel Corporation - Intel DPTF LPM Service Helper.) -- C:\Windows\System32\DptfPolicyLpmServiceHelper.exe =>.Intel Corporation O4 - HKLM\..\Run: [ASUSPRP] . (.ASUSTek Computer Inc. - ASUS Product Register Program.) -- C:\Program Files\ASUS\APRP\aprp.exe =>.ASUSTek Computer Inc. O4 - HKLM\..\Run: [WebStorage] . (...) -- C:\Program Files\ASUS\WebStorage\2.0.3.226\ASUSWSLoader.exe =>.ASUS Cloud Corporation® O4 - HKLM\..\Run: [RtkNGUI] . (.Realtek Semiconductor - Realtek Audio Manager.) -- C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe =>.Realtek Semiconductor Corp® O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\hocky_000\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd® O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\System32\OneDriveSetup.exe =>.Microsoft Corporation® O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\System32\OneDriveSetup.exe =>.Microsoft Corporation® O4 - HKUS\S-1-5-21-2529037023-2540447892-3470744646-1004\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\hocky_000\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - HKUS\S-1-5-21-2529037023-2540447892-3470744646-1004\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - HKUS\S-1-5-21-2529037023-2540447892-3470744646-1004\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd® ---\\ Global shortcuts Startup (16) - 4s O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\hocky_000\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\sendTo [Administrator]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - GS\TaskBar [Administrator]: eManual.Lnk . (.ASUSTek Computer Inc. - EManual Application.) C:\eSupport\Manual\eManual.exe =>.ASUSTeK Computer Inc.® O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\hocky_000\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\sendTo [Guest]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - GS\TaskBar [Guest]: eManual.Lnk . (.ASUSTek Computer Inc. - EManual Application.) C:\eSupport\Manual\eManual.exe =>.ASUSTeK Computer Inc.® O4 - GS\Desktop [hocky_000]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\hocky_000\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\sendTo [hocky_000]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - GS\TaskBar [hocky_000]: eManual.Lnk . (.ASUSTek Computer Inc. - EManual Application.) C:\eSupport\Manual\eManual.exe =>.ASUSTeK Computer Inc.® O4 - GS\Desktop [owner]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\hocky_000\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\sendTo [owner]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - GS\TaskBar [owner]: eManual.Lnk . (.ASUSTek Computer Inc. - EManual Application.) C:\eSupport\Manual\eManual.exe =>.ASUSTeK Computer Inc.® O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Ltd - CCleaner.) C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd® O4 - GS\CommonDesktop [Public]: Skype.lnk . (...) C:\WINDOWS\Installer\{FC965A47-4839-40CA-B618-18F486F042C6}\SkypeIcon.exe O4 - GS\Programs [Public]: ACReminderSrv.lnk . (.ASUSTek Computer INC. - ASUS AC Reminder Service.) C:\Program Files\ASUS\ASUS AC Reminder\ACReminderSrv.exe =>.ASUSTeK Computer Inc.® O4 - GS\Programs [Public]: ReadingModeWatchDogShortcut.lnk . (.Copyright © 2013 - ReadingModeWatchDogx86.) C:\Program Files\ASUS\ASUS Reading Mode\ReadingModeWatchDogx86.exe ---\\ Lop.com/Domain Hijackers (3) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{1fc83821-36bf-4f17-8ec6-3bbd1a51c4c8}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{f63d06e4-e711-4e43-9e96-0b28061c54aa}: DhcpNameServer = 169.254.18.38 ---\\ Extra protocols (23) - 0s O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll =>.Skype Software Sarl® O18 - Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll =>.Microsoft Corporation O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation O18 - Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll =>.Microsoft Corporation O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation ---\\ Software installed (15) - 14s O42 - Logiciel: ASUS AC Reminder - (.ASUS.) [HKLM] -- {B002B54C-FFE8-4331-8F9B-90CC9366362A} =>.ASUS O42 - Logiciel: ASUS Live Update - (.ASUS.) [HKLM] -- {FA540E67-095C-4A1B-97BA-4D547DEC9AF4} =>.ASUS O42 - Logiciel: ASUS Reading Mode - (.ASUS.) [HKLM] -- {47CE1F58-C6AB-4316-BFA1-1D64CCE674B1} =>.ASUS O42 - Logiciel: ASUS Screen Saver - (.ASUS.) [HKLM] -- {0FBEEDF8-30FA-4FA3-B31F-C9C7E7E8DFA2} =>.ASUS O42 - Logiciel: ASUS Smart Gesture - (.ASUS.) [HKLM] -- {4D3286A6-F6AB-498A-82A4-E4F040529F3D} =>.ASUS O42 - Logiciel: ATK Package - (.ASUS.) [HKLM] -- {AB5C933E-5C7D-4D30-B314-9C83A49B94BE} =>.ASUS O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner =>.Piriform Ltd® O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} =>.Intel Corporation - pGFX® O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation O42 - Logiciel: Realtek I2S Audio - (.Realtek Semiconductor Corp..) [HKLM] -- {89A448AA-3301-46AA-AFC3-34F2D7C670E8} =>.Realtek Semiconductor Corp. O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701} =>.Microsoft Corporation O42 - Logiciel: Skype™ 7.21 - (.Skype Technologies S.A..) [HKLM] -- {FC965A47-4839-40CA-B618-18F486F042C6} =>.Skype Technologies S.A. O42 - Logiciel: WebStorage - (.ASUS Cloud Corporation.) [HKLM] -- WebStorage =>.ASUS Cloud Corporation O42 - Logiciel: Windows Driver Package - ASUS (AsusSGDrv) Mouse (10/21/2015 8.0.0.19) - (.ASUS.) [HKLM] -- DE393C6A9AB085F9E19765D003555C3D360497DB =>.ASUSTeK Computer Inc.® O42 - Logiciel: WinFlash - (.ASUS.) [HKLM] -- {8F21291E-0444-4B1D-B9F9-4370A73E346D} =>.ASUS ---\\ HKCU & HKLM Software Keys (38) - 14s HKLM\SOFTWARE\Agere HKLM\SOFTWARE\AsLdr HKLM\SOFTWARE\ASUS HKLM\SOFTWARE\camera HKLM\SOFTWARE\Canon HKLM\SOFTWARE\ECAREME HKLM\SOFTWARE\Google HKLM\SOFTWARE\IM Providers HKLM\SOFTWARE\Intel HKLM\SOFTWARE\Khronos HKLM\SOFTWARE\LogMeIn Rescue HKLM\SOFTWARE\LSI HKLM\SOFTWARE\Macromedia HKLM\SOFTWARE\MozillaPlugins HKLM\SOFTWARE\ODBC HKLM\SOFTWARE\OEM HKLM\SOFTWARE\Partner HKLM\SOFTWARE\Piriform HKLM\SOFTWARE\Realtek HKLM\SOFTWARE\Realtek Semiconductor Corp. HKLM\SOFTWARE\RegisteredApplications HKLM\SOFTWARE\Skype HKLM\SOFTWARE\Synaptics HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\ASUS HKCU\SOFTWARE\Canon HKCU\SOFTWARE\ECAREME HKCU\SOFTWARE\IM Providers HKCU\SOFTWARE\Intel HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\Mine HKCU\SOFTWARE\Piriform HKCU\SOFTWARE\Realtek HKCU\SOFTWARE\RegisteredApplications HKCU\SOFTWARE\Skype HKCU\SOFTWARE\SyncEngines HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Software ---\\ Contents of the Common Files folders (98) - 20s O43 - CFD: 25/02/2016 - [] D -- C:\Program Files\ASUS =>.ASUSTeK Computer Inc.® O43 - CFD: 13/04/2016 - [] D -- C:\Program Files\CCleaner =>.Piriform Ltd® O43 - CFD: 29/03/2016 - [] D -- C:\Program Files\Common Files O43 - CFD: 25/02/2016 - [] D -- C:\Program Files\DIFX =>.ASUSTeK Computer Inc.® O43 - CFD: 29/11/2013 - [] HD -- C:\Program Files\InstallShield Installation Information =>.Macrovision Corporation® O43 - CFD: 25/02/2016 - [] D -- C:\Program Files\Intel =>.Intel Corporation - pGFX® O43 - CFD: 18/03/2016 - [] D -- C:\Program Files\Internet Explorer O43 - CFD: 05/09/2013 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation® O43 - CFD: 29/03/2016 - [] D -- C:\Program Files\Microsoft Silverlight =>.Microsoft Corporation® O43 - CFD: 29/10/2015 - [] D -- C:\Program Files\Microsoft.NET O43 - CFD: 25/02/2016 - [] D -- C:\Program Files\MSBuild O43 - CFD: 29/11/2013 - [] D -- C:\Program Files\Realtek =>.Realtek Semiconductor Corp® O43 - CFD: 25/02/2016 - [] D -- C:\Program Files\Reference Assemblies O43 - CFD: 29/03/2016 - [] RD -- C:\Program Files\Skype =>.Skype Software Sarl® O43 - CFD: 22/08/2013 - [0] HD -- C:\Program Files\Uninstall Information O43 - CFD: 30/10/2015 - [] D -- C:\Program Files\Windows Defender O43 - CFD: 18/03/2016 - [] D -- C:\Program Files\Windows Journal O43 - CFD: 25/02/2016 - [] D -- C:\Program Files\Windows Mail O43 - CFD: 18/03/2016 - [] D -- C:\Program Files\Windows Media Player O43 - CFD: 18/03/2016 - [] D -- C:\Program Files\Windows Multimedia Platform O43 - CFD: 29/10/2015 - [] D -- C:\Program Files\Windows NT O43 - CFD: 25/02/2016 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation® O43 - CFD: 18/03/2016 - [] D -- C:\Program Files\Windows Portable Devices O43 - CFD: 29/10/2015 - [] SHD -- C:\Program Files\Windows Sidebar O43 - CFD: 13/04/2016 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation® O43 - CFD: 29/10/2015 - [] SD -- C:\Program Files\WindowsPowerShell O43 - CFD: 29/10/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 30/10/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 29/10/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 25/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS O43 - CFD: 25/02/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel O43 - CFD: 29/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 29/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight O43 - CFD: 29/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype O43 - CFD: 29/10/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp O43 - CFD: 29/10/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 30/10/2015 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 25/02/2016 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 29/11/2013 - [] D -- C:\ProgramData\AsTouchPanel O43 - CFD: 14/04/2016 - [] D -- C:\ProgramData\ASUS Smart Gesture O43 - CFD: 05/09/2013 - [] D -- C:\ProgramData\ASUS WebStorage O43 - CFD: 05/09/2013 - [] D -- C:\ProgramData\ASUSLogos O43 - CFD: 26/02/2016 - [] HD -- C:\ProgramData\CanonBJ O43 - CFD: 29/10/2015 - [0] D -- C:\ProgramData\Comms O43 - CFD: 25/02/2016 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 25/02/2016 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 29/03/2016 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 25/02/2016 - [] D -- C:\ProgramData\Microsoft OneDrive O43 - CFD: 03/04/2016 - [] D -- C:\ProgramData\Package Cache O43 - CFD: 19/02/2016 - [] D -- C:\ProgramData\PassMark O43 - CFD: 25/02/2016 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft O43 - CFD: 25/02/2016 - [] D -- C:\ProgramData\SetupTPDriver O43 - CFD: 29/03/2016 - [] D -- C:\ProgramData\Skype O43 - CFD: 29/10/2015 - [0] D -- C:\ProgramData\SoftwareDistribution O43 - CFD: 25/02/2016 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 19/02/2016 - [0] D -- C:\ProgramData\TEMP O43 - CFD: 25/02/2016 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 25/02/2016 - [] D -- C:\ProgramData\USOPrivate O43 - CFD: 25/02/2016 - [] D -- C:\ProgramData\USOShared O43 - CFD: 05/09/2013 - [] D -- C:\ProgramData\WebStorage O43 - CFD: 05/09/2013 - [] D -- C:\Program Files\Common Files\AWS O43 - CFD: 29/11/2013 - [] D -- C:\Program Files\Common Files\InstallShield O43 - CFD: 25/02/2016 - [] D -- C:\Program Files\Common Files\Intel O43 - CFD: 25/02/2016 - [] D -- C:\Program Files\Common Files\microsoft shared O43 - CFD: 29/10/2015 - [] D -- C:\Program Files\Common Files\Services O43 - CFD: 29/03/2016 - [] D -- C:\Program Files\Common Files\Skype O43 - CFD: 25/02/2016 - [] D -- C:\Program Files\Common Files\System O43 - CFD: 25/02/2016 - [] D -- C:\Users\hocky_000\AppData\Roaming\Adobe O43 - CFD: 25/02/2016 - [] D -- C:\Users\hocky_000\AppData\Roaming\Macromedia O43 - CFD: 25/02/2016 - [] SD -- C:\Users\hocky_000\AppData\Roaming\Microsoft O43 - CFD: 25/02/2016 - [] D -- C:\Users\hocky_000\AppData\Roaming\ReadingModeUISetting O43 - CFD: 14/04/2016 - [] D -- C:\Users\hocky_000\AppData\Roaming\Skype O43 - CFD: 25/02/2016 - [] D -- C:\Users\hocky_000\AppData\Roaming\WebStorage O43 - CFD: 14/04/2016 - [] D -- C:\Users\hocky_000\AppData\Roaming\ZHP O43 - CFD: 25/02/2016 - [0] D -- C:\Users\hocky_000\AppData\Local\ActiveSync O43 - CFD: 25/02/2016 - [0] SHD -- C:\Users\hocky_000\AppData\Local\Application Data O43 - CFD: 19/03/2016 - [] D -- C:\Users\hocky_000\AppData\Local\Apps O43 - CFD: 25/02/2016 - [] D -- C:\Users\hocky_000\AppData\Local\Comms O43 - CFD: 27/02/2016 - [] D -- C:\Users\hocky_000\AppData\Local\Diagnostics O43 - CFD: 25/02/2016 - [0] SHD -- C:\Users\hocky_000\AppData\Local\History O43 - CFD: 13/04/2016 - [] D -- C:\Users\hocky_000\AppData\Local\LogMeIn Rescue Applet O43 - CFD: 27/02/2016 - [] D -- C:\Users\hocky_000\AppData\Local\Microsoft O43 - CFD: 27/02/2016 - [] D -- C:\Users\hocky_000\AppData\Local\MicrosoftEdge O43 - CFD: 25/02/2016 - [0] D -- C:\Users\hocky_000\AppData\Local\NetworkTiles O43 - CFD: 13/04/2016 - [] D -- C:\Users\hocky_000\AppData\Local\Packages O43 - CFD: 25/02/2016 - [0] D -- C:\Users\hocky_000\AppData\Local\PackageStaging O43 - CFD: 25/02/2016 - [] D -- C:\Users\hocky_000\AppData\Local\Publishers O43 - CFD: 14/04/2016 - [] D -- C:\Users\hocky_000\AppData\Local\Temp O43 - CFD: 25/02/2016 - [0] SHD -- C:\Users\hocky_000\AppData\Local\Temporary Internet Files O43 - CFD: 25/02/2016 - [] D -- C:\Users\hocky_000\AppData\Local\TileDataLayer O43 - CFD: 25/02/2016 - [0] D -- C:\Users\hocky_000\AppData\Local\VirtualStore O43 - CFD: 29/10/2015 - [] RD -- C:\Users\hocky_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 25/02/2016 - [] RD -- C:\Users\hocky_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 19/03/2016 - [] RD -- C:\Users\hocky_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 29/10/2015 - [] D -- C:\Users\hocky_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 19/03/2016 - [] RD -- C:\Users\hocky_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 29/10/2015 - [] RD -- C:\Users\hocky_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 29/10/2015 - [] RSD -- C:\Users\hocky_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell ---\\ ShellIconOverlayIdentifiers (SIOI) (9) - 1s O106 - SIOI: ErrorOverlayHandler Class [ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\hocky_000\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileSyncShell.dll =>.Microsoft Corporation® O106 - SIOI: SharedOverlayHandler Class [ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\hocky_000\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileSyncShell.dll =>.Microsoft Corporation® O106 - SIOI: SharedSyncingOverlayHandler Class [ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\hocky_000\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileSyncShell.dll =>.Microsoft Corporation® O106 - SIOI: UpToDateOverlayHandler Class [ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\hocky_000\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileSyncShell.dll =>.Microsoft Corporation® O106 - SIOI: SyncingOverlayHandler Class [ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\hocky_000\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileSyncShell.dll =>.Microsoft Corporation® O106 - SIOI: AsusWSShellExt_BN Class [!AsusWSShellExt_BN] - {CC5FC992-B0AA-47CD-9DC2-83445083CBB9}. (.ASUS Cloud Corporation. - AsusWSShellExt Module.) -- C:\Program Files\Common Files\AWS\2.0.3.226\ASUSWSShellExt.dll =>.ASUS Cloud Corporation. O106 - SIOI: AsusWSShellExt_ON Class [!AsusWSShellExt_ON] - {618A47A2-528B-4D9A-AFC8-97D3233511E3}. (.ASUS Cloud Corporation. - AsusWSShellExt Module.) -- C:\Program Files\Common Files\AWS\2.0.3.226\ASUSWSShellExt.dll =>.ASUS Cloud Corporation. O106 - SIOI: AsusWSShellExt_UN Class [!AsusWSShellExt_UN] - {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E}. (.ASUS Cloud Corporation. - AsusWSShellExt Module.) -- C:\Program Files\Common Files\AWS\2.0.3.226\ASUSWSShellExt.dll =>.ASUS Cloud Corporation. O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation ---\\ System Drivers List (57) - 14s O58 - SDL:2015/10/29 23:44:28 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [85856] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1038176] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [75104] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [215392] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [22880] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [116576] =>.Microsoft Windows® O58 - SDL:2013/11/04 05:32:06 A . (.ASUS - HID driver for ASUS Wireless Radio Control.) -- C:\WINDOWS\System32\drivers\AsHIDSwitch.sys [17720] =>.ASUSTeK Computer Inc.® O58 - SDL:2013/09/04 13:38:24 A . (.ASUS Corporation - Asus TP Filter Driver (X86).) -- C:\WINDOWS\System32\drivers\AsusHID.sys [64312] =>.ASUSTeK Computer Inc.® O58 - SDL:2015/12/14 15:28:42 A . (.ASUS Corporation - Asus TP Filter Driver (x86).) -- C:\WINDOWS\System32\drivers\AsusSGDrv.sys [118264] =>.ASUSTeK Computer Inc.® O58 - SDL:2013/10/16 04:32:20 A . (.Broadcom Corp - Broadcom SDIO WiFi Driver wireless driver.) -- C:\WINDOWS\System32\drivers\bcmdhd63.sys [304344] =>.Broadcom Corporation® O58 - SDL:2015/10/29 23:44:28 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn.sys [8192] =>.Windows (R) Win 7 DDK provider O58 - SDL:2013/09/23 20:22:08 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [16088] =>.Broadcom Corporation® O58 - SDL:2013/09/23 19:12:02 A . (.Broadcom Corporation. - Broadcom Bluetooth USB AMP Filter for Windo.) -- C:\WINDOWS\System32\drivers\btwampfl.sys [144600] =>.Broadcom Corporation® O58 - SDL:2013/09/23 19:12:04 A . (.Broadcom Corporation. - Bluetooth Serial Bus Driver.) -- C:\WINDOWS\System32\drivers\BtwSerialBus.sys [130776] =>.Broadcom Corporation® O58 - SDL:2014/12/05 06:40:02 A . (.Intel Corporation - Intel(R) Imaging Signal Processor 2400.) -- C:\WINDOWS\System32\drivers\camera.sys [461824] =>.Intel Corporation O58 - SDL:2014/06/19 05:02:06 A . (.Capella Microsystems, Inc. - Capella Micro Sensor Filter Driver.) -- C:\WINDOWS\System32\drivers\CPLMACPI.sys [16488] {0997AC355ADA3872BF9C9EF34D2E5A72} O58 - SDL:2013/08/23 18:31:30 A . (.Intel Corporation - Intel Dynamic Platform & Thermal Framework.) -- C:\WINDOWS\System32\drivers\DptfDevAmbient.sys [36352] =>.Intel Corporation O58 - SDL:2013/08/23 18:31:30 A . (.Intel Corporation - Intel Dynamic Platform & Thermal Framework.) -- C:\WINDOWS\System32\drivers\DptfDevDisplay.sys [20480] =>.Intel Corporation O58 - SDL:2013/08/23 18:31:30 A . (.Intel Corporation - Intel Dynamic Platform & Thermal Framework.) -- C:\WINDOWS\System32\drivers\DptfDevGen.sys [28160] =>.Intel Corporation O58 - SDL:2013/08/23 18:31:31 A . (.Intel Corporation - Intel Dynamic Platform & Thermal Framework.) -- C:\WINDOWS\System32\drivers\DptfDevPower.sys [17408] =>.Intel Corporation O58 - SDL:2013/08/23 18:31:31 A . (.Intel Corporation - Intel Dynamic Platform & Thermal Framework.) -- C:\WINDOWS\System32\drivers\DptfDevProc.sys [72192] =>.Intel Corporation O58 - SDL:2013/08/23 18:31:31 A . (.Intel Corporation - Intel Dynamic Platform & Thermal Framework.) -- C:\WINDOWS\System32\drivers\DptfManager.sys [176640] =>.Intel Corporation O58 - SDL:2014/12/05 06:40:02 A . (.Intel Corporation - Camera Sensor HM2056.) -- C:\WINDOWS\System32\drivers\hm2056.sys [43008] =>.Intel Corporation O58 - SDL:2015/10/29 23:44:28 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [56672] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:25 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) -- C:\WINDOWS\System32\drivers\iai2c.sys [66048] =>.Intel(R) Corporation O58 - SDL:2013/08/23 16:18:44 N . (.Intel Corporation - Intel(R) Atom(TM) Processor GPIO Controller.) -- C:\WINDOWS\System32\drivers\iaiogpio.sys [23040] =>.Intel Corporation O58 - SDL:2013/08/21 01:22:12 A . (.Intel Corporation - Intel(R) Atom(TM) Processor GPIOVirtual Con.) -- C:\WINDOWS\System32\drivers\iaiogpiovirtual.sys [17408] =>.Intel Corporation O58 - SDL:2013/08/23 16:18:36 N . (.Intel Corporation - Intel(R) Atom(TM) Processor I2C Controller.) -- C:\WINDOWS\System32\drivers\iaioi2c.sys [58368] =>.Intel Corporation O58 - SDL:2013/08/21 01:22:12 A . (.Intel Corporation - Intel(R) Atom(TM) Processor UART Controller.) -- C:\WINDOWS\System32\drivers\iaiouart.sys [88064] =>.Intel Corporation O58 - SDL:2013/08/08 20:31:54 A . (.Intel Corporation - Intel Rapid Storage Technology driver - x86.) -- C:\WINDOWS\System32\drivers\iaStorA.sys [505192] =>.Intel Corporation - Intel® Rapid Storage Technology® O58 - SDL:2015/10/29 23:44:28 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [524632] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [333664] =>.Microsoft Windows® O58 - SDL:2015/08/27 19:20:20 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\igdkmd32.sys [3035568] =>.Intel Corporation - pGFX® O58 - SDL:2015/07/20 13:45:04 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\intelaud.sys [44096] =>.Intel(R) Wireless Display® O58 - SDL:2013/08/26 12:46:10 A . (.Intel(R) Corporation - Intel(R) SST Audio Driver.) -- C:\WINDOWS\System32\drivers\isstrtc.sys [242176] =>.Intel(R) Corporation O58 - SDL:2015/07/20 13:45:04 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\iwdbus.sys [35392] =>.Intel(R) Wireless Display® O58 - SDL:2015/10/29 23:44:28 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [94040] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [88928] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [83288] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [69472] =>.Microsoft Windows® O58 - SDL:2013/08/21 01:22:12 A . (.Intel Corporation - MBI driver.) -- C:\WINDOWS\System32\drivers\MBI.sys [21456] =>.Intel MCG PIV Tablet Validation® O58 - SDL:2015/10/29 23:44:28 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [52064] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [464728] =>.Microsoft Windows® O58 - SDL:2013/08/22 20:54:48 N . (.Intel Corporation - Camera Sensor MT9M114.) -- C:\WINDOWS\System32\drivers\mt9m114.sys [38400] =>.Intel Corporation O58 - SDL:2015/10/29 23:44:28 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [58208] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [119136] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [142176] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [51040] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [51552] =>.Microsoft Windows® O58 - SDL:2013/08/21 01:22:12 A . (.Intel Corporation - BayTrail PMIC driver.) -- C:\WINDOWS\System32\drivers\PMIC.sys [46592] =>.Intel Corporation O58 - SDL:2013/09/13 03:42:00 A . (.Realtek Semiconductor Corp. - Realtek I2S Audio Codec Device Driver.) -- C:\WINDOWS\System32\drivers\rtii2sac.sys [129752] =>.Realtek Semiconductor Corp® O58 - SDL:2015/10/29 23:44:28 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [41312] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [79200] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [26976] =>.Microsoft Windows® O58 - SDL:2013/08/03 10:23:28 A . (.Intel Corporation - Intel(R) Trusted Execution Engine Interface.) -- C:\WINDOWS\System32\drivers\TXEI.sys [76304] =>.Intel Corporation - Client Components Group® O58 - SDL:2015/10/29 23:44:28 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR X86-32.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [149856] =>.Microsoft Windows® O58 - SDL:2015/10/29 23:44:28 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [276832] =>.Microsoft Windows® ---\\ Last modified or created user files (14) - 6s O61 - LFC: 2016/04/13 20:51:12 A . (..) -- C:\Users\hocky_000\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_0_Data.bin [4223516] O61 - LFC: 2016/04/14 20:00:28 A . (..) -- C:\Users\hocky_000\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\speech_onecorereg.bin [8192] O61 - LFC: 2016/04/13 20:48:24 A . (..) -- C:\Users\hocky_000\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\Contacts_01.0409.digest.bin [492] O61 - LFC: 2016/04/14 11:29:31 A . (..) -- C:\Users\hocky_000\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\Contacts_02.0409.digest.bin [492] O61 - LFC: 2016/04/13 20:47:36 A . (..) -- C:\Users\hocky_000\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest2_01.0409.digest.bin [32] O61 - LFC: 2016/04/14 19:25:38 A . (..) -- C:\Users\hocky_000\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest2_02.0409.digest.bin [32] O61 - LFC: 2016/04/13 20:47:35 A . (..) -- C:\Users\hocky_000\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest_01.0409.digest.bin [32] O61 - LFC: 2016/04/14 19:25:37 A . (..) -- C:\Users\hocky_000\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\PointsOfInterest_02.0409.digest.bin [32] O61 - LFC: 2016/04/14 11:44:29 A . (..) -- C:\Users\hocky_000\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\VaStartMenu_01.0409.digest.bin [8892] O61 - LFC: 2016/04/13 21:03:36 A . (..) -- C:\Users\hocky_000\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\Grammars\VaStartMenu_02.0409.digest.bin [8892] O61 - LFC: 2016/04/13 20:37:41 A . (..) -- C:\Users\hocky_000\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\cache\proactive\proactive-cache.bin [254583] O61 - LFC: 2016/04/13 11:44:14 A . (..) -- C:\Users\hocky_000\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\UrlBlock\urlblock_635961568431445315.bin [45527] O61 - LFC: 2016/04/14 20:00:04 A . (..) -- C:\Users\hocky_000\AppData\Local\Microsoft\Windows\UPPS\UPPS.bin [16148] O61 - LFC: 2016/04/14 20:01:27 A . (..) -- C:\Users\hocky_000\AppData\Local\Microsoft\Internet Explorer\UrlBlock\urlblock_635962773923641733.bin [57531] ---\\ File Associations Shell Spawning (10) - 1s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe =>.Microsoft Corporation O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S ---\\ Start Menu Internet (4) - 0s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation ---\\ Search Browser Infection (1) - 0s O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ ---\\ Search Svchost Services (41) - 1s O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [160768] =>.Microsoft Corporation O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [160768] =>.Microsoft Corporation O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\Windows\System32\srvsvc.dll [218624] =>.Microsoft Corporation O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\Windows\System32\gpsvc.dll [1190912] =>.Microsoft Corporation O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\IKEEXT.DLL [742400] =>.Microsoft Corporation O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [842752] =>.Microsoft Corporation O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\Windows\System32\seclogon.dll [24576] =>.Microsoft Corporation O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\Windows\System32\appinfo.dll [76288] =>.Microsoft Corporation O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\Windows\System32\iscsiexe.dll [116224] =>.Microsoft Corporation O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [95232] =>.Microsoft Corporation O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\Windows\System32\schedsvc.dll [810496] =>.Microsoft Corporation O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [185344] =>.Microsoft Corporation O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\Windows\System32\browser.dll [107520] =>.Microsoft Corporation O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [246272] =>.Microsoft Corporation O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [313344] =>.Microsoft Corporation O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\Windows\System32\wercplsupport.dll [68608] =>.Microsoft Corporation O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Microsoft® Account Service.) -- C:\Windows\System32\wlidsvc.dll [1552896] =>.Microsoft Corporation O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Microsoft Network Connectivity Assistant Se.) -- C:\Windows\System32\NcaSvc.dll [144384] =>.Microsoft Corporation O83 - Search Svchost Services: DcpSvc (DcpSvc) . (.Microsoft Corporation - dcpsvc Task.) -- C:\Windows\System32\dcpsvc.dll [156160] =>.Microsoft Corporation O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Network Setup Service.) -- C:\Windows\System32\NetSetupSvc.dll [142336] =>.Microsoft Corporation O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\Windows\System32\dmwappushsvc.dll [47616] =>.Microsoft Corporation O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\Windows\System32\XblGameSave.dll [722432] =>.Microsoft Corporation O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Device Setup Manager.) -- C:\Windows\System32\DeviceSetupManager.dll [163840] =>.Microsoft Corporation O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\Windows\System32\XblAuthManager.dll [538624] =>.Microsoft Corporation O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\Windows\System32\XboxNetApiSvc.dll [820224] =>.Microsoft Corporation O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - Windows Managent Service DLL.) -- C:\Windows\System32\Windows.Internal.Management.dll [200192] =>.Microsoft Corporation O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\Windows\System32\themeservice.dll [45568] =>.Microsoft Corporation O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\Windows\System32\usermgr.dll [706048] =>.Microsoft Corporation O83 - Search Svchost Services: RetailDemo (RetailDemo) . (.Microsoft Corporation - RDXService.) -- C:\Windows\System32\RDXService.dll [796672] =>.Microsoft Corporation O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\Windows\System32\bdesvc.dll [307712] =>.Microsoft Corporation O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Update Session Orchestrator Core.) -- C:\Windows\System32\usocore.dll [251392] =>.Microsoft Corporation O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Geolocation Service.) -- C:\Windows\System32\lfsvc.dll [22528] =>.Microsoft Corporation O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\Windows\System32\rasauto.dll [93184] =>.Microsoft Corporation O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [601088] =>.Microsoft Corporation O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [436224] =>.Microsoft Corporation O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\Windows\System32\Sens.dll [57856] =>.Microsoft Corporation O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [396288] =>.Microsoft Corporation O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [254976] =>.Microsoft Corporation O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\System32\wuaueng.dll [1894912] =>.Microsoft Corporation O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\Windows\System32\qmgr.dll [857600] =>.Microsoft Corporation O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [559616] =>.Microsoft Corporation ---\\ Additional Scan (O88) (1) - 0s ~ No malicious or unnecessary items found. ---\\ Summary of the elements found (1) - 0s ~ No malicious or unnecessary items found. ~ End of the scan, 7760 items in 00h02mn17s (511)(0)