Virus/malware or something else? Keyboard issue

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Malnutrition
    PCHF Moderator
    • Jul 2016
    • 7041

    #16
    Originally posted by Goldfish
    Do you need me to re-run the ZHP and FRST afterwards?
    No, but the logs will take me a while to look over. So run the tool below, I have to run out for a few hours…

    9-Lab Scan.

    [ul]
    [li]Download 9-Lab Removal Tool. [/li][li]CLICK HERE to determine whether you’re running 32-bit or 64-bit for Windows.[/li][li]Disable your antivirus prior to this scan.[/li]
    [li]Install the program onto your computer, then right click the icon run as administrator.[/li][li]Update the program and then run a Quick scan![/li][li]Make sure the program updates, might be better to install it update reboot and check for updates again.[/li][li]You need to make sure the database updates!!![/li][li]Upon Scan Completion Click on Show Results.[/li][li]Then Click On Clean[/li][li]Then Click on Save Log.[/li][li]Save it to your desktop, copy and paste the contents of the log here in your next reply.[/li][/ul]

    Comment

    • Goldfish
      PCHF Member
      • Mar 2017
      • 26

      #17
      No probs, it’s taking a while to run Adware Removal and it’s quite late at night here - might be tomorrow when I can run 9-Lab.

      Comment

      • Goldfish
        PCHF Member
        • Mar 2017
        • 26

        #18
        Here they are:

        Adware Removal Tool 5.1
        Time: 2017_03_04_22_26_49
        OS: Windows 7 Home Premium - x64 Bit
        Account Name: goldfish
        Adware Definition: 03032017
        Elapsed time: 37:18
        Repair Status:- Automatic Done
        \\\\\\\\\\\\ Repair Logs \\\\\\\\\\\

        [-] Deleted ->> Registry Value Data ->> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility{98889811-442D-49DD-99D7-DC866BE87DBC}\ RegValue: DllName RegData: BabylonToolbarTlbr.dll : BabylonToolbarTlbr.dll

        [-] Deleted ->> Registry Value Data ->> HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\ Internet Explorer\Extension Compatibility{98889811-442D-49DD-99D7-DC866BE87DBC}\ RegValue: DllName RegData: BabylonToolbarTlbr.dll : BabylonToolbarTlbr.dll

        [-] Deleted ->> Registry Value Data ->> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility{98889811-442D-49DD-99D7-DC866BE87DBC}\ RegValue: DllName RegData: BabylonToolbarTlbr.dll : BabylonToolbarTlbr.dll

        [-] Deleted ->> Registry Value Data ->> HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\ Internet Explorer\Extension Compatibility{98889811-442D-49DD-99D7-DC866BE87DBC}\ RegValue: DllName RegData: BabylonToolbarTlbr.dll : BabylonToolbarTlbr.dll

        [-] Repaired ->> File ->> C:\Users\goldfish\AppData\Local\Google\Chrome\User Data\Default\Preferences

        [-] Deleted ->> Registry Key ->> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\localdatasearch.co m

        [-] Deleted ->> Registry Key ->> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\myway.com

        [-] Deleted ->> Registry Key ->> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage[www.localdatasearch.com](‘http://www.localdatasearch.com’)

        [-] Deleted ->> Registry Key ->> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility{2EECD738-5844-4A99-B4B6-146BF802613B}

        [-] Deleted ->> Registry Key ->> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}

        [-] Deleted ->> Registry Key ->> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility{98889811-442D-49DD-99D7-DC866BE87DBC}

        [-] Deleted ->> Registry Key ->> HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\ Internet Explorer\Extension Compatibility{2EECD738-5844-4A99-B4B6-146BF802613B}

        [-] Deleted ->> Registry Key ->> HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\ Internet Explorer\Extension Compatibility{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}

        [-] Deleted ->> Registry Key ->> HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\ Internet Explorer\Extension Compatibility{98889811-442D-49DD-99D7-DC866BE87DBC}

        [-] Deleted ->> Registry Key ->> HKEY_LOCAL_MACHINE\SOFTWARE\classes\CLSID{6DDA37BA-0553-499A-AE0D-BEBA67204548}

        [-] Deleted ->> Registry Key ->> HKEY_CLASSES_ROOT\CLSID{6DDA37BA-0553-499A-AE0D-BEBA67204548}

        ================================================== =================================


        Adware Removal Tool 5.1
        Time: 2017_03_04_22_26_49
        OS: Windows 7 Home Premium - x64 Bit
        Account Name: goldfish
        Adware Definition: 03032017
        Elapsed time: 37:18
        Scan Status:- Automatic Done

        \\\\\\\\\\\\ Scan Logs \\\\\\\\\\\

        Registry Key Found : Adware.Tasearch.com : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ RegKey: localdatasearch.com
        Registry Key Found : Adware.myway.com : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ RegKey: myway.com
        Registry Key Found : Adware.Tasearch.com : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ RegKey: www.localdatasearch.com
        Registry Key Found : PUP.BabylonToolbar : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\ RegKey: {2EECD738-5844-4A99-B4B6-146BF802613B}
        Registry Key Found : PUP.BabylonToolbar : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\ RegKey: {97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
        Registry Key Found : PUP.BabylonToolbar : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\ RegKey: {98889811-442D-49DD-99D7-DC866BE87DBC}
        Registry Data Found : PUP.BabylonToolbar : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility{98889811-442D-49DD-99D7-DC866BE87DBC}\ RegValue: DllName RegData: BabylonToolbarTlbr.dll
        Registry Key Found : PUP.BabylonToolbar : HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\ Internet Explorer\Extension Compatibility\ RegKey: {2EECD738-5844-4A99-B4B6-146BF802613B}
        Registry Key Found : PUP.BabylonToolbar : HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\ Internet Explorer\Extension Compatibility\ RegKey: {97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
        Registry Key Found : PUP.BabylonToolbar : HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\ Internet Explorer\Extension Compatibility\ RegKey: {98889811-442D-49DD-99D7-DC866BE87DBC}
        Registry Data Found : PUP.BabylonToolbar : HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\ Internet Explorer\Extension Compatibility{98889811-442D-49DD-99D7-DC866BE87DBC}\ RegValue: DllName RegData: BabylonToolbarTlbr.dll
        Registry Data Found : PUP.BabylonToolbar : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility{98889811-442D-49DD-99D7-DC866BE87DBC}\ RegValue: DllName RegData: BabylonToolbarTlbr.dll
        Registry Data Found : PUP.BabylonToolbar : HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\ Internet Explorer\Extension Compatibility{98889811-442D-49DD-99D7-DC866BE87DBC}\ RegValue: DllName RegData: BabylonToolbarTlbr.dll
        Registry Key Found : Adware.Vosteran : HKEY_LOCAL_MACHINE\SOFTWARE\classes\CLSID\ RegKey: {6DDA37BA-0553-499A-AE0D-BEBA67204548}
        Registry Key Found : Adware.Vosteran : HKEY_CLASSES_ROOT\CLSID\ RegKey: {6DDA37BA-0553-499A-AE0D-BEBA67204548}
        Browser: Chrome Found : Unknown.Service : C:\Users\goldfish\AppData\Local\Google\Chrome\User Data\Default\Preferences

        ================================================== =================================

        9-lab Removal Tool 1.0.0.39 BETA
        Database version: 161.47443

        Windows 7 Service Pack 1 (Version 6.1, Build 7601, 64-bit Edition)
        Internet Explorer 9.11.9600.18537
        goldfish :: goldfish-VAIO

        04/03/2017 23:14:06
        9lab-log-2017-03-04 (23-14-06).txt

        Scan type: Quick
        Objects scanned: 27878
        Time Elapsed: 38 m 26 s

        Registry Keys detected: 7
        Susp.RPL.Gen.vl [HKEY_LOCAL_MACHINE\SOFTWARE\DeviceVM]
        Susp.RPL.Gen.vl [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\DeviceVM]
        Adware.RPL.Gen.vl [HKEY_CLASSES_ROOT\Interface{BD51A48E-EB5F-4454-8774-EF962DF64546}]
        Adware.RPL.Gen.vl [HKEY_CLASSES_ROOT\Interface{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}]
        Adware.RPL.Gen.vl [HKEY_CLASSES_ROOT\Interface{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}]
        Adware.RPL.Gen.vl [HKEY_CLASSES_ROOT\Interface{03E2A1F3-4402-4121-8B35-733216D61217}]
        Adware.RMPL.Shopper.vl [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node{DAF8B7E5-449D-4180-8281-10E536E597F2}]

        Files detected: 733
        [3688374325B992DEF12793500307566D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\h osts]
        [5D20B86806DDA7819991BC2C375EEC51] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\annoanno.pdef]
        [97105F395DA4B2A19FC29EFAD5762765] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\moovaudi.pdef]
        [A2DC148647FEFA8DD75E84AE3719DA0D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\moovpres.pdef]
        [DD0D21549231BF6BD3A42BC0FE67EC58] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.qpa]
        [424B1447C0D150252873DFDD182FD561] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ da.lproj\PanelHelperBaseLocalized.qtr]
        [7CD3D7D020FBCC8252594E64138918C5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ de.lproj\PanelHelperBaseLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ en.lproj\locversion.plist]
        [BCEA97045A0FD66DAB6EF8CCF0462E99] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ en.lproj\PanelHelperBaseLocalized.qtr]
        [43D856A20EB96A00A2B8E23FC160ABBC] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ es.lproj\PanelHelperBaseLocalized.qtr]
        [DA247313D21BC88C90646ED247A4EB4E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ fi.lproj\PanelHelperBaseLocalized.qtr]
        [FD300C3D00AAEA1CC67BD88CD3209D82] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ fr.lproj\PanelHelperBaseLocalized.qtr]
        [DF6E38E2970886496A4F2392E111166D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ it.lproj\PanelHelperBaseLocalized.qtr]
        [DEB5062AC86BD6980D37165B21DE932B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ ja.lproj\PanelHelperBaseLocalized.qtr]
        [B1AE1481DEA2294A7EFAC293BC23DAEC] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ ko.lproj\PanelHelperBaseLocalized.qtr]
        [AADE7B018F83C00FC4A942C1B605D7CB] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ nb.lproj\PanelHelperBaseLocalized.qtr]
        [640AA787347E8F79FB9E0CE4CF9DAC60] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ nl.lproj\PanelHelperBaseLocalized.qtr]
        [57B6900A56F6348D6570FBD6DE5609D6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ PanelHelperBase.qtr]
        [9318465E7A3EA8BC1F629E03224E7A05] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ pl.lproj\PanelHelperBaseLocalized.qtr]
        [9D273EA4C799AD40E3C1749645E2958A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ pt.lproj\PanelHelperBaseLocalized.qtr]
        [633700D288667931EEA7CF94956C4523] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ pt_PT.lproj\PanelHelperBaseLocalized.qtr]
        [E9B0FAAB3D229CAC3D62B49BF30EF5B3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ ru.lproj\PanelHelperBaseLocalized.qtr]
        [15FB97C62934C44D0F9FA9C456A15BDC] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ sv.lproj\PanelHelperBaseLocalized.qtr]
        [B0E2A4175FDF7B86AB5AACFEBFB6FCEF] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ zh_CN.lproj\PanelHelperBaseLocalized.qtr]
        [55DE316ADE66EC44952EFFD1BF737D28] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PanelHelperBase.Resources\ zh_TW.lproj\PanelHelperBaseLocalized.qtr]
        [7A54BF9F1ED68BF544E28006F97CFFF0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropertyPanels.plist]
        [015EE89604362C3B1F5A04DA7D295505] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.qpa]
        [61EB9D7727748995BF30342A43E88B4B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \da.lproj\PropPanelHelpersLocalized.qtr]
        [347406D6752277588E49EA1ADFADF6E7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \de.lproj\PropPanelHelpersLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \en.lproj\locversion.plist]
        [FCB42481E036F4B9F6DDFFB607DFF0F3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \en.lproj\PropPanelHelpersLocalized.qtr]
        [12747B5AA9111008E4B970FC7CA580B4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \es.lproj\PropPanelHelpersLocalized.qtr]
        [2C21C34E0B9136EB3124DC27634AB59D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \fi.lproj\PropPanelHelpersLocalized.qtr]
        [7C73E2C7B2A894FC62D945A473EB0CDB] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \fr.lproj\PropPanelHelpersLocalized.qtr]
        [E0CF61B84F7AA53F6FB2805D0901E432] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \it.lproj\PropPanelHelpersLocalized.qtr]
        [FA0F2358E131949E45C99ADF65CA9491] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \ja.lproj\PropPanelHelpersLocalized.qtr]
        [6007522F6FFF04B27E1E98CB15B376C5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \ko.lproj\PropPanelHelpersLocalized.qtr]
        [B73A46EDC7B9264FEDAC445F55AAE1F4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \nb.lproj\PropPanelHelpersLocalized.qtr]
        [6C85CD5214FCD0F31D0F51496D712ABD] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \nl.lproj\PropPanelHelpersLocalized.qtr]
        [30134340184A46BAD04749322D7D658D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \pl.lproj\PropPanelHelpersLocalized.qtr]
        [0519395DB923B093C00211A18CEB3D47] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \PropPanelHelpers.qtr]
        [EE97EF29E8C639DC0A32C212225941FE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \pt.lproj\PropPanelHelpersLocalized.qtr]
        [A16D5D1B10BFA811CECDA2F14D8E2409] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \pt_PT.lproj\PropPanelHelpersLocalized.qtr]
        [B4F78B1E8CDC2485E8BBE217670FEED7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \ru.lproj\PropPanelHelpersLocalized.qtr]
        [E3ACC65E37CEBAEAFFABDF828BA7F106] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \sv.lproj\PropPanelHelpersLocalized.qtr]
        [E65D7BD3D3D0AF873AC81E925D7D3038] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \zh_CN.lproj\PropPanelHelpersLocalized.qtr]
        [CB7518D43A61B2E6C98633CF6E7F3A72] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\PropPanelHelpers.Resources \zh_TW.lproj\PropPanelHelpersLocalized.qtr]
        [1D4DE188894FE9BE200958EFE53A2A23] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\rsrcrsrc.pdef]
        [70D394931C1A4BB65B4329E9A7D1A50B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\trakaudi.pdef]
        [A181FB9E17534DB9BD9EB86FBCBDBE10] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\trakhint.pdef]
        [6DA83CB93D7C3DB0BD5FC900CD625004] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\trakothr.pdef]
        [03123CEF8DCFD2D3DE0A1A66E1B515C5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\trakstrm.pdef]
        [C438D3C5F145A1AAF7121009AC7E008B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\PropertyPanels\trakvisl.pdef]
        [50850E14716C83FE717804AF952C5790] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTOControl.dll]
        [FC2F2A652B4F72D80292D695A9C4FD6C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTOLibrary.dll]
        [4B4DC2002795316CA5E4F0CE48D11D82] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\AppleProResDecoder.qtx]
        [B53A9836BC1B6A735C655F1E4FA7E619] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CFCharacterSetBitmaps.bitmap]
        [67C18382F63C39B17328ED03F68C35E1] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CFUniCharPropertyDatabase.data]
        [62E265CF156659E305A862EC22C641D4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CFUnicodeData-B.mapping]
        [B10CAB969FB143F20B90AA8988495C03] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CFUnicodeData-L.mapping]
        [09C39150C0C9B057745CECFDBA941A7B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.qtx]
        [5ABD3215EA3FB8E0880E0D7688FCE7E1] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\CoreVideo.qt r]
        [E1EBABD9C9B7E80E225D8E6A717DF946] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\da.lproj\Cor eVideoLocalized.dll]
        [CD102B5AB33CC54CF67797CD88868F77] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\da.lproj\Cor eVideoLocalized.qtr]
        [F18D9460311653E818C2E8325091D9BD] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\de.lproj\Cor eVideoLocalized.dll]
        [4FF53A1EE9681763ABD3B9DB35FC7456] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\de.lproj\Cor eVideoLocalized.qtr]
        [FE210DF7F560FCEB4D180E9D7B17E5FD] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\en.lproj\Cor eVideoLocalized.dll]
        [48C79C1322D3D3E4CEA2DF7203B6FE21] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\en.lproj\Cor eVideoLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\en.lproj\loc version.plist]
        [CA16F1026E6C61D1FFF9E5E7136C7E7E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\es.lproj\Cor eVideoLocalized.dll]
        [12C8D0F39F22F607D22AD6423CDB042C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\es.lproj\Cor eVideoLocalized.qtr]
        [53D37E45D3E90644B64CC4AB9735730B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\fi.lproj\Cor eVideoLocalized.dll]
        [B66F358EA3F6E1836ED97EF497788CF1] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\fi.lproj\Cor eVideoLocalized.qtr]
        [5C80075E21B7946E03F2A2D9C5AC6BD4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\fr.lproj\Cor eVideoLocalized.dll]
        [D032D7EFD6BA94015CCB2A7186FE5892] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\fr.lproj\Cor eVideoLocalized.qtr]
        [9909A70EEC858B499C7CBB63FDA70534] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\it.lproj\Cor eVideoLocalized.dll]
        [7E3C0626C5FCAF92B9376FB22ED8F3E4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\it.lproj\Cor eVideoLocalized.qtr]
        [407FB509AFD9D021CA1DFDE860EFB645] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\ja.lproj\Cor eVideoLocalized.dll]
        [404E7BF44C22DAC2529BDD4851CDFE39] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\ja.lproj\Cor eVideoLocalized.qtr]
        [3D62007FB406A75031C3B536F92F768D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\ko.lproj\Cor eVideoLocalized.dll]
        [3191BF2829A43BBB834892AA81417457] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\ko.lproj\Cor eVideoLocalized.qtr]
        [A0CAE5A70924558CDED3A491EB27222B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\nb.lproj\Cor eVideoLocalized.dll]
        [C1C57CFA8ED13F2BDD253F0F6CFC2E56] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\nb.lproj\Cor eVideoLocalized.qtr]
        [316C753739C9E323EFE013938848265F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\nl.lproj\Cor eVideoLocalized.dll]
        [DB50F63101AFB4A62DD80E31B8A7F7EE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\nl.lproj\Cor eVideoLocalized.qtr]
        [6B4EC4E16AAF3BC05752C0B1A0A3832B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\pl.lproj\Cor eVideoLocalized.dll]
        [0E03001B6D84C141AC9D7566282568CD] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\pl.lproj\Cor eVideoLocalized.qtr]
        [036005C357DD622D18596C0CF935CA65] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\pt.lproj\Cor eVideoLocalized.dll]
        [75E3FA78B6290F02F773EC6E8BFE390A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\pt.lproj\Cor eVideoLocalized.qtr]
        [26B28D81CE559F630FAFA39E41A23FC7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\pt_PT.lproj\ CoreVideoLocalized.dll]
        [90FC117E2A76DE4D5C68EDCF7ED61C78] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\pt_PT.lproj\ CoreVideoLocalized.qtr]
        [582540EFDD5772F1F20D92C9DC8241D6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\ru.lproj\Cor eVideoLocalized.dll]
        [8555503964F6A241199FC6DF6F3BFB5C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\ru.lproj\Cor eVideoLocalized.qtr]
        [A2C1E254EFA516BB1CAF1E43EB52B611] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\sv.lproj\Cor eVideoLocalized.dll]
        [61FEDBCE28AE228F6904A46D111DA2A2] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\sv.lproj\Cor eVideoLocalized.qtr]
        [A1ECB0D3786AA4CA1D029632D6B3EB96] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\zh_CN.lproj\ CoreVideoLocalized.dll]
        [BDD2B5A5E5817F030D4531260744F074] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\zh_CN.lproj\ CoreVideoLocalized.qtr]
        [79ED8D80599582C2540ABBB91E501BCE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\zh_TW.lproj\ CoreVideoLocalized.dll]
        [57E6619AABFBECF1784B39452FD8B225] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\CoreVideo.Resources\zh_TW.lproj\ CoreVideoLocalized.qtr]
        [379B72A6FADEB462EC884CA868025B6C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\ExportController.exe]
        [5AC2F4BE5CBEE4FA26797F4BBFA9EF86] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\ExportControllerPS.dll]
        [718C93327D203DCCB500EAC11420C954] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QTCF.dll]
        [F9490B9C34299D6AB2402A769E8FEEF6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QTMLClient.dll]
        [D56F2C54F013BA522743CFECFD9DA594] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.cpl]
        [A37251C74995A95D586B1E288855AAE3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.qts]
        [10EDC19A59D1D61F5F4462D093172C88] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\da.lproj\Qui ckTimeLocalized.dll]
        [A6F9F1058E97BD380CBDA25CD58C3F1F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\da.lproj\Qui ckTimeLocalized.qtr]
        [CD078D2A17054D81C567846F1D44D60D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\de.lproj\Qui ckTimeLocalized.dll]
        [2485AE765DB51ABD65ABBD63978936F3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\de.lproj\Qui ckTimeLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\en.lproj\loc version.plist]
        [BC0D820CE6FDBE40E9E0B61E972EBC9A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\en.lproj\Qui ckTimeLocalized.dll]
        [104E68165FF34BEA34BA11D055759503] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\en.lproj\Qui ckTimeLocalized.qtr]
        [2B7372C41BB4984814E9928AA5FF7651] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\es.lproj\Qui ckTimeLocalized.dll]
        [307152B8E180C5D75BF1A81F54A15836] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\es.lproj\Qui ckTimeLocalized.qtr]
        [837FE8810CEE0F4B5F98898C232E9B87] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\fi.lproj\Qui ckTimeLocalized.dll]
        [257203B967C48CE474A9FF0BC0FEF374] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\fi.lproj\Qui ckTimeLocalized.qtr]
        [BB30A1F456434E2EBE1338C78B438EC3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\fr.lproj\Qui ckTimeLocalized.dll]
        [CB541BA2C429AC3A41FEE80BF1999B77] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\fr.lproj\Qui ckTimeLocalized.qtr]
        [E117C206B19CAC14B575BFA5C1AB8988] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\it.lproj\Qui ckTimeLocalized.dll]
        [EF56F109EA14BBBBCF6EBCD0C932C01B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\it.lproj\Qui ckTimeLocalized.qtr]
        [4484E57FF0EC318F09C2ABEDA0B17B2A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\ja.lproj\Qui ckTimeLocalized.dll]
        [F85EE430A38C113CAC774EF7C0A19328] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\ja.lproj\Qui ckTimeLocalized.qtr]
        [80FE0F551115DDE8D312E0500C5C1CC4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\ko.lproj\Qui ckTimeLocalized.dll]
        [2583C707940A87838EAE83DF732E16C8] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\ko.lproj\Qui ckTimeLocalized.qtr]
        [4E5E3F46C39271CA1FA864A428188A4C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\nb.lproj\Qui ckTimeLocalized.dll]
        [374B00C6FACAA7A20B3BB850E9695087] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\nb.lproj\Qui ckTimeLocalized.qtr]
        [7D45FD46012EFE4975BC1B48BC22239D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\nl.lproj\Qui ckTimeLocalized.dll]
        [1483A68ED8F8D534FD2214DC3CA4F035] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\nl.lproj\Qui ckTimeLocalized.qtr]
        [0E8E436A54C9DF71974D2D9FA458010F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\pl.lproj\Qui ckTimeLocalized.dll]
        [CA05910B608FC9B70B6CE61B21850DAB] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\pl.lproj\Qui ckTimeLocalized.qtr]
        [C429E0161DD4268B58B5A988B6A6A025] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\pt.lproj\Qui ckTimeLocalized.dll]
        [63E33600C6E766F570DB7D2E60F52815] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\pt.lproj\Qui ckTimeLocalized.qtr]
        [9F935ECAAAF7B1169B14D2AB5BF2EE61] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\pt_PT.lproj\ QuickTimeLocalized.dll]
        [167CC9362C8BC59BE142418137B86A02] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\pt_PT.lproj\ QuickTimeLocalized.qtr]
        [5F0DAD3EA071879F96553DA2D11058D7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\QuickTime.dl l]
        [364A1D952CC14D5367DD37104C298920] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\QuickTime.qt r]
        [A5ECCE9AD05DC2C7C2D78F1FBEA5EDA0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\QuickTime.qt xs]
        [60E211FE2F0AFFD690A66A77149FDBFA] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\ru.lproj\Qui ckTimeLocalized.dll]
        [FB07862C2F260D34BFF9F59753F9F318] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\ru.lproj\Qui ckTimeLocalized.qtr]
        [AB622032C1A2F3B036F8DE729A6178DF] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\sv.lproj\Qui ckTimeLocalized.dll]
        [2867CEFD481E9BC230AA3B04BBE4DA09] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\sv.lproj\Qui ckTimeLocalized.qtr]
        [136CCCBBB88905FF6D116AACB2AB58A1] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\zh_CN.lproj\ QuickTimeLocalized.dll]
        [2C386F43E0D34DD32DE84261AEE2A581] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\zh_CN.lproj\ QuickTimeLocalized.qtr]
        [A99D5E2EA3FC588CDCF0B4CFCD2AB883] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\zh_TW.lproj\ QuickTimeLocalized.dll]
        [9DE92DC012353A6F74942E8ACC0E2EF6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime.Resources\zh_TW.lproj\ QuickTimeLocalized.qtr]
        [360CBBE86BE4564821CE8BB5E4E0BB3C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.qtx]
        [140DE5F9494C0DCA3BFBBCB187CF002D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\da.lproj \QuickTime3GPPLocalized.qtr]
        [574707A925676553E264E0A723FC704F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\de.lproj \QuickTime3GPPLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\en.lproj \locversion.plist]
        [1E1023229BDCC775383C28A4513F1CA3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\en.lproj \QuickTime3GPPLocalized.qtr]
        [E06F5A5302A3B5ADF84C76B9C4EA59ED] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\es.lproj \QuickTime3GPPLocalized.qtr]
        [5B9646E884E9180FA3DEF22374B18E2F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\fi.lproj \QuickTime3GPPLocalized.qtr]
        [877A9DD607DEA44495FB68D8554E043A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\fr.lproj \QuickTime3GPPLocalized.qtr]
        [7A16753A4F630E2D0A8A800F4199EFCF] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\it.lproj \QuickTime3GPPLocalized.qtr]
        [7D7A9060A402B15CCD090CAA5CA18650] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\ja.lproj \QuickTime3GPPLocalized.qtr]
        [D3F45A4730165B84AD58FDD2EE1EDE17] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\ko.lproj \QuickTime3GPPLocalized.qtr]
        [BF5F046DE5F6B6EA8AE6E8537DB258A1] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\nb.lproj \QuickTime3GPPLocalized.qtr]
        [5217A0CCE590F1B007E2D85C8C2B8C65] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\nl.lproj \QuickTime3GPPLocalized.qtr]
        [0D6D10E843E26F0B412A638F22C06968] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\pl.lproj \QuickTime3GPPLocalized.qtr]
        [86165C00D736DFBECC7381397E583664] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\pt.lproj \QuickTime3GPPLocalized.qtr]
        [D4FFDE2D45D33F74A6106AE97994C556] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\pt_PT.lp roj\QuickTime3GPPLocalized.qtr]
        [72B2140FEBCC28D6A109730290415968] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\QuickTim e3GPP.qtr]
        [8B32DDC39406EF1E24E91FC5C048CE73] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\ru.lproj \QuickTime3GPPLocalized.qtr]
        [76F665720566F89AB480D8467D06838A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\sv.lproj \QuickTime3GPPLocalized.qtr]
        [EE0D145C3ED8DD32825EEDA069A7998F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\zh_CN.lp roj\QuickTime3GPPLocalized.qtr]
        [FB39BF0E832FB929FBCBD2BB812CBAEC] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPP.Resources\zh_TW.lp roj\QuickTime3GPPLocalized.qtr]
        [DF239E3457F5BE15E045BD1B3067ADDB] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.qtx]
        [E2A45AFA04D5243E515A8F1E9D5CDBB7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \da.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [F074AA3B0D20816967286250C7303646] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \de.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \en.lproj\locversion.plist]
        [4EA3F062E179C512E75EAF1EDADFAB7B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \en.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [A6D34B69F78808D944D4AB4FF4C8F236] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \es.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [8B80B76343A39E17C0D88C675B1D1C02] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \fi.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [95D4790506AA77C4BE92EAF5D5F6F785] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \fr.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [0FAE827654EFF942941B875FE09622D6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \it.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [EA0A4F2A78312B9811CF0E2DC9EE571E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \ja.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [3E250B920999CDDACDB2B4005C8F9F19] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \ko.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [01D0D637E26CBE66E81D68B346B48D1E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \nb.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [50145596197FEA525B1F577747171D8F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \nl.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [C4F36A1D75030F6011B45EDE468645C6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \pl.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [12F79FE095CD9091F6B44A4669FF5FFB] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \pt.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [2B384A1CCD0F2220BEC2360AB420F3DF] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \pt_PT.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [439CF318AE1A29A417B3C8DF712857A3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \QuickTime3GPPAuthoring.qtr]
        [FE0C3F9A656117D62E72C0DEAA2D9A11] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \ru.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [B67B0749571ECDC835342D0CC623FCD8] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \sv.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [469331BB7265B0CAC3B1FEDA2648C6F3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \zh_CN.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [7CAB28EEA410777978556FC1579C27ED] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTime3GPPAuthoring.Resources \zh_TW.lproj\QuickTime3GPPAuthoringLocalized.qtr]
        [47F3395F3A6CE80CD019CBE09CACB5C5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.qtx]
        [A72AA80BC8233FC8D1181DD25A786E48] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ da.lproj\QuickTimeAudioSupportLocalized.dll]
        [2AE685A15A4AD1B0734AC1C450389E44] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ da.lproj\QuickTimeAudioSupportLocalized.qtr]
        [654EC373CA1A7D67A1BAF71B930C1BE7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ de.lproj\QuickTimeAudioSupportLocalized.dll]
        [00E388A9F0DDFB4795D9E40BAA3E5CF4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ de.lproj\QuickTimeAudioSupportLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ en.lproj\locversion.plist]
        [79036AAE87D159933CEBCB820FE31302] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ en.lproj\QuickTimeAudioSupportLocalized.dll]
        [0E6B79723539DFCA3785AAF748A8D007] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ en.lproj\QuickTimeAudioSupportLocalized.qtr]
        [677F8FA233C251148DBA942250336487] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ es.lproj\QuickTimeAudioSupportLocalized.dll]
        [A82DE1BB350D75C8E615E89ACAB61283] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ es.lproj\QuickTimeAudioSupportLocalized.qtr]
        [623B0D3F1CC808D978D4B72864C9B451] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ fi.lproj\QuickTimeAudioSupportLocalized.dll]
        [BFD3287BAC31521FE3AFD9928D05AE91] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ fi.lproj\QuickTimeAudioSupportLocalized.qtr]
        [F1B8607B5FDE9FF9E92AF79E7FEE9D1B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ fr.lproj\QuickTimeAudioSupportLocalized.dll]
        [46680D059DFC8B361928B4CD8B941355] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ fr.lproj\QuickTimeAudioSupportLocalized.qtr]
        [F39699856BDDC628F309AD3EB6BA0AF7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ it.lproj\QuickTimeAudioSupportLocalized.dll]
        [71108311AD06A03E5F10392C92C5F11C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ it.lproj\QuickTimeAudioSupportLocalized.qtr]
        [7089ABD9FD89C22CA3F5790A7EF540A7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ ja.lproj\QuickTimeAudioSupportLocalized.dll]
        [ABC03BFCEA62BB16711D5CD875B247D0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ ja.lproj\QuickTimeAudioSupportLocalized.qtr]
        [1CBFC19636C76FDB495702F12430C21E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ ko.lproj\QuickTimeAudioSupportLocalized.dll]
        [540E78C7DDE0203FF64E22B1B86450A4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ ko.lproj\QuickTimeAudioSupportLocalized.qtr]
        [6C1A9A62E38C91D914C7808A30738F06] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ nb.lproj\QuickTimeAudioSupportLocalized.dll]
        [D95331C490905336A9FA65B3C85C30D3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ nb.lproj\QuickTimeAudioSupportLocalized.qtr]
        [65AA43660A2C7ADE19ED098029E7A223] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ nl.lproj\QuickTimeAudioSupportLocalized.dll]
        [4A338DB706ACAF2FCCC848D0DB2CC748] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ nl.lproj\QuickTimeAudioSupportLocalized.qtr]
        [C35AFAEB48197FB155F021445BE59785] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ pl.lproj\QuickTimeAudioSupportLocalized.dll]
        [F308D1AE2AB439072E639BF396389CD7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ pl.lproj\QuickTimeAudioSupportLocalized.qtr]
        [22632EA780F1FA926FA1DDE85996979E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ pt.lproj\QuickTimeAudioSupportLocalized.dll]
        [81102E0DA3EE84A6DD8F9D70AEBBC616] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ pt.lproj\QuickTimeAudioSupportLocalized.qtr]
        [129DDA045A92F295989878F5C51C267B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ pt_PT.lproj\QuickTimeAudioSupportLocalized.dll]
        [93C12573BBDBB47CC74BB10FB23A5D4C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ pt_PT.lproj\QuickTimeAudioSupportLocalized.qtr]
        [D3C0A10C9F69E170032C1C428D51B528] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ QuickTimeAudioSupport.qtr]
        [E88C0BA6E57076F9C78F24D9FB534FAB] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ ru.lproj\QuickTimeAudioSupportLocalized.dll]
        [A7C61534E9B0182C93538AFA7D9C46F0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ ru.lproj\QuickTimeAudioSupportLocalized.qtr]
        [AD54D12072D92CF9DBF017A3DC4D01B2] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ sv.lproj\QuickTimeAudioSupportLocalized.dll]
        [DA0BBF1486B929100C5A79D174A9B0EE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ sv.lproj\QuickTimeAudioSupportLocalized.qtr]
        [F18A673F88186DABED2BF47EAD67F0D0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ zh_CN.lproj\QuickTimeAudioSupportLocalized.dll]
        [133EA6C1C9B5630E731344321EEB3E0F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ zh_CN.lproj\QuickTimeAudioSupportLocalized.qtr]
        [AD89AAD1C17808508BF1ABB85AF33B95] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ zh_TW.lproj\QuickTimeAudioSupportLocalized.dll]
        [8532496E12841FC85F30D8D046A62064] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAudioSupport.Resources\ zh_TW.lproj\QuickTimeAudioSupportLocalized.qtr]
        [D9443257E8C0E05DC4846A8BCB00FB5B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.qtx]
        [BC37BC1148B079062FFDA854D64865BC] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\da. lproj\QuickTimeAuthoringLocalized.dll]
        [DE33D5DF6672C7AF69877288F6B1B3F6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\da. lproj\QuickTimeAuthoringLocalized.qtr]
        [34B9787B978E3F287FD7CFF385F25F18] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\de. lproj\QuickTimeAuthoringLocalized.dll]
        [DAB6E0C8E1C05DC33967E2116CF08FAF] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\de. lproj\QuickTimeAuthoringLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\en. lproj\locversion.plist]
        [254D77315EB9C200D5147C313D7A6733] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\en. lproj\QuickTimeAuthoringLocalized.dll]
        [7F9B1076F058B18F788B3BC3120718DA] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\en. lproj\QuickTimeAuthoringLocalized.qtr]
        [5F78E84BB32CD16416AB4F0C249008AB] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\es. lproj\QuickTimeAuthoringLocalized.dll]
        [A714F745ED21170AAC6D0C3FDA60F3AE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\es. lproj\QuickTimeAuthoringLocalized.qtr]
        [36A1065D2BBBAAD526A7B9C7AFF93746] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\fi. lproj\QuickTimeAuthoringLocalized.dll]
        [5E80F8ED1805235C7472797008D779CE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\fi. lproj\QuickTimeAuthoringLocalized.qtr]
        [51C4F26756E51AA2431D463C77E1C216] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\fr. lproj\QuickTimeAuthoringLocalized.dll]
        [02572CFE57C158AB6FA9BD145579320E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\fr. lproj\QuickTimeAuthoringLocalized.qtr]
        [1364BD10C67DDD22ABFFEDADB3A98AF4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\it. lproj\QuickTimeAuthoringLocalized.dll]
        [A0E251E4B70FE2E68E93867FF0228EC3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\it. lproj\QuickTimeAuthoringLocalized.qtr]
        [C88DDD70113C1692246363934D066F8E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\ja. lproj\QuickTimeAuthoringLocalized.dll]
        [989FF129983AD1FC10A723062CAA47CF] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\ja. lproj\QuickTimeAuthoringLocalized.qtr]
        [9003040ACD4FEA9BE163081D26F9A2D2] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\ko. lproj\QuickTimeAuthoringLocalized.dll]
        [D69F16BA2297E326931FA5488B44CC7B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\ko. lproj\QuickTimeAuthoringLocalized.qtr]
        [020033D8B12411028D9A2AF94114467E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\nb. lproj\QuickTimeAuthoringLocalized.dll]
        [6F829503F700F844C15D87539815DC0F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\nb. lproj\QuickTimeAuthoringLocalized.qtr]
        [F69B705542F149E77C95DC3A2C6BB8DF] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\nl. lproj\QuickTimeAuthoringLocalized.dll]
        [9A6DFD3E6F92B249625781640F3D33C1] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\nl. lproj\QuickTimeAuthoringLocalized.qtr]
        [12CC5C79ADAFDCA3C42BC140BC7CC3DE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\pl. lproj\QuickTimeAuthoringLocalized.dll]
        [DF786D7D0B8055DAFA8A38C1A4EFAD46] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\pl. lproj\QuickTimeAuthoringLocalized.qtr]
        [F7FC2CB6116B28AC250EC3B7EC125254] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\pt. lproj\QuickTimeAuthoringLocalized.dll]
        [AE87E21A2FFC3D92E23FDA9A7677ADD4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\pt. lproj\QuickTimeAuthoringLocalized.qtr]
        [7962D48D8DCC320F9409C0AD278BC15A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\pt_ PT.lproj\QuickTimeAuthoringLocalized.dll]
        [BD92CC913C78E0BFB07A0D4725BD1D2B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\pt_ PT.lproj\QuickTimeAuthoringLocalized.qtr]
        [3EDCC9F25D21E1D6E274F1CB7E47AD5A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\Qui ckTimeAuthoring.qtr]
        [CD02B981D24D2D7B8C88515BD4A706CC] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\ru. lproj\QuickTimeAuthoringLocalized.dll]
        [4481091E2BC2B19C51D0BE8474D68808] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\ru. lproj\QuickTimeAuthoringLocalized.qtr]
        [76C99C2F77637C28BCC5F96E14C98DB3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\sv. lproj\QuickTimeAuthoringLocalized.dll]
        [C60DD0884ABE03012CD945167C69F771] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\sv. lproj\QuickTimeAuthoringLocalized.qtr]
        [95551CEEAA430193D757B43293430146] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\zh_ CN.lproj\QuickTimeAuthoringLocalized.dll]
        [06C9CD86E8CCD19F8C7CD4483115268C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\zh_ CN.lproj\QuickTimeAuthoringLocalized.qtr]
        [E0A4C27A4198897B1104B148F13CC241] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\zh_ TW.lproj\QuickTimeAuthoringLocalized.dll]
        [C03FF6E3A69EE25B09FDAC29686BC775] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeAuthoring.Resources\zh_ TW.lproj\QuickTimeAuthoringLocalized.qtr]
        [388EB328ACED68F3C1DB885A1DE8D132] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.qtx]
        [235F5B9269E7E7FC1032AB31853A2765] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\da.lp roj\QuickTimeCaptureLocalized.qtr]
        [89DB6A1BBDB7F63C403C8A1898E18AC2] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\de.lp roj\QuickTimeCaptureLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\en.lp roj\locversion.plist]
        [08E46D0846F0F7503A213B3AD948BD97] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\en.lp roj\QuickTimeCaptureLocalized.qtr]
        [CB4A69BFF6B7152AB6FF6B3F0B62CA9A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\es.lp roj\QuickTimeCaptureLocalized.qtr]
        [8A84C44482C757A116E72E1A526164B2] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\fi.lp roj\QuickTimeCaptureLocalized.qtr]
        [4ABBC64E7B1D86C173A3C520A1FC473B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\fr.lp roj\QuickTimeCaptureLocalized.qtr]
        [CBC9EEA845802A2A9ED2D5506E728A72] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\it.lp roj\QuickTimeCaptureLocalized.qtr]
        [BEC166CEB6AECD99D522FF1FB595B6E8] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\ja.lp roj\QuickTimeCaptureLocalized.qtr]
        [9A63DB85E2DA38D1C3EB8A7E740D3000] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\ko.lp roj\QuickTimeCaptureLocalized.qtr]
        [EE2314C867A406C61900310704337E7E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\nb.lp roj\QuickTimeCaptureLocalized.qtr]
        [1D4CD11E32F3117B6D91CD415F2F930D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\nl.lp roj\QuickTimeCaptureLocalized.qtr]
        [DBAE3421BC6A2DBF83B92D3EBC6EC4B6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\pl.lp roj\QuickTimeCaptureLocalized.qtr]
        [68AB0E46AFDEE7E92DB73F08A9B7D71A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\pt.lp roj\QuickTimeCaptureLocalized.qtr]
        [A95FDE424966722BA2B554FEE857B98C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\pt_PT .lproj\QuickTimeCaptureLocalized.qtr]
        [6A5261C0013AEC8323296359381CA8FA] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\Quick TimeCapture.qtr]
        [27334632B6DC94CC042B78E34B0788E0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\ru.lp roj\QuickTimeCaptureLocalized.qtr]
        [E027E464C621F8457DDC96FF71A3AED9] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\sv.lp roj\QuickTimeCaptureLocalized.qtr]
        [ECA5D833C77AE09066F96F99AA33917D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\zh_CN .lproj\QuickTimeCaptureLocalized.qtr]
        [32ADAA8CC269545322687F78B9089D7C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCapture.Resources\zh_TW .lproj\QuickTimeCaptureLocalized.qtr]
        [6E21CF79ECA59606D7C8D2F4A1E613E7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeCheck.ocx]
        [82506F812CE93021ABBA73D4CA816EDE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.qtx]
        [DEF8E1EF0357100DABEC1E44C87DD4C2] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\da.lp roj\QuickTimeEffectsLocalized.qtr]
        [E70D1AFADF5E07330E64F0052B330C26] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\de.lp roj\QuickTimeEffectsLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\en.lp roj\locversion.plist]
        [0BEF7E934F7CD030C732EE96C58FF9DE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\en.lp roj\QuickTimeEffectsLocalized.qtr]
        [E0252A8F76B87C5B6651EAAC3EEABE15] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\es.lp roj\QuickTimeEffectsLocalized.qtr]
        [D2F9CFEB535068861B4189553F0AFBCD] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\fi.lp roj\QuickTimeEffectsLocalized.qtr]
        [20CA8D059D8D26B65435642012F4FC70] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\fr.lp roj\QuickTimeEffectsLocalized.qtr]
        [130DB86DDDA774E1925AE37A86266C1C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\it.lp roj\QuickTimeEffectsLocalized.qtr]
        [CA7B33FB7BC0444CC90EF85C63B56D28] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\ja.lp roj\QuickTimeEffectsLocalized.qtr]
        [DE6BC284E4BC4C23BD51DB2C900DE553] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\ko.lp roj\QuickTimeEffectsLocalized.qtr]
        [7CD45F8699E068BCF2D1ACD7C70FF44A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\nb.lp roj\QuickTimeEffectsLocalized.qtr]
        [F19B3E7F3A512C10AF8D2170A811815D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\nl.lp roj\QuickTimeEffectsLocalized.qtr]
        [1E5F0680D6A5770DD0E5FB088D63BC23] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\pl.lp roj\QuickTimeEffectsLocalized.qtr]
        [FBB2963A9D0911E2105683F46289D9B1] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\pt.lp roj\QuickTimeEffectsLocalized.qtr]
        [9C4B29118EEB7E6484ADB9539392790D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\pt_PT .lproj\QuickTimeEffectsLocalized.qtr]
        [170819E69451C3887CDDF353D5C3FB69] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\Quick TimeEffects.qtr]
        [29B8EE375E9CD2EA7B358CD2C4723C3F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\ru.lp roj\QuickTimeEffectsLocalized.qtr]
        [B3A13F885A7A75E3BA63D0774F3EA7A3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\sv.lp roj\QuickTimeEffectsLocalized.qtr]
        [192E1C5D5C48305016CB0C0B8DDF34C5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\zh_CN .lproj\QuickTimeEffectsLocalized.qtr]
        [093AA6335E368AA02FE178181C2E442C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEffects.Resources\zh_TW .lproj\QuickTimeEffectsLocalized.qtr]
        [2B14243EB246EFF79A6C73F4B4A7338D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.qtx]
        [E8223F0D0515B47650330A4940618874] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\da .lproj\QuickTimeEssentialsLocalized.qtr]
        [E6A2D3F51094A1F62B30FA857A062200] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\de .lproj\QuickTimeEssentialsLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\en .lproj\locversion.plist]
        [4E1E9AFD11E85CA185AA8B3EA674721F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\en .lproj\QuickTimeEssentialsLocalized.qtr]
        [866073228C1320B1021A64A66AAFDAB4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\es .lproj\QuickTimeEssentialsLocalized.qtr]
        [F0008CF4426AB882B6AB55154B4000F5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\fi .lproj\QuickTimeEssentialsLocalized.qtr]
        [5B2CBC2373BFA9CC41549718AFB2731E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\fr .lproj\QuickTimeEssentialsLocalized.qtr]
        [114027ED289A4CE9A70D28AE141CFFB7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\it .lproj\QuickTimeEssentialsLocalized.qtr]
        [C588FAE1C631A791F4C9A542AB44D4F6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\ja .lproj\QuickTimeEssentialsLocalized.qtr]
        [4AB05BCD472D800102ACBCC5BB65AD18] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\ko .lproj\QuickTimeEssentialsLocalized.qtr]
        [FF3C6F4E6D33B39FA1E37D531DB1BA57] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\nb .lproj\QuickTimeEssentialsLocalized.qtr]
        [BE1AF53AAB641B1BB8255E48B2665DAD] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\nl .lproj\QuickTimeEssentialsLocalized.qtr]
        [ABF031B8C04EA922F24AE582BA24EAE7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\pl .lproj\QuickTimeEssentialsLocalized.qtr]
        [C49B4FD3920B29325092873A7FDD7450] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\pt .lproj\QuickTimeEssentialsLocalized.qtr]
        [C7873225F1C776DCEF38D9A2251DF0FF] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\pt _PT.lproj\QuickTimeEssentialsLocalized.qtr]
        [26D2FDCD7874292834F6BC1FB029F212] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\Qu ickTimeEssentials.qtr]
        [EEC0B36252F49AE9DB445061E01E0553] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\ru .lproj\QuickTimeEssentialsLocalized.qtr]
        [BA1AAC20F1557F3BFE2838F89867A9EA] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\sv .lproj\QuickTimeEssentialsLocalized.qtr]
        [870F41118AA2032D96598A3A64C2E945] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\zh _CN.lproj\QuickTimeEssentialsLocalized.qtr]
        [F9568FC8DB478B315C9BEC1EB22B09AB] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeEssentials.Resources\zh _TW.lproj\QuickTimeEssentialsLocalized.qtr]
        [7594C92D0AEDD74C7C77E2B6BDC890A0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.qtx]
        [26FCAF15D4509F7492A13DB55E79E3E3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\da.lproj \QuickTimeH264Localized.qtr]
        [8AAEBB06EE0AEA3390722F87A7E66A4F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\de.lproj \QuickTimeH264Localized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\en.lproj \locversion.plist]
        [43C5B37C33CA9F5BCE91ABB9A28AE74D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\en.lproj \QuickTimeH264Localized.qtr]
        [3A631E1548BDDF96AF91EFA6A5738AA0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\es.lproj \QuickTimeH264Localized.qtr]
        [6BB376971587DF298BE89436ED44E145] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\fi.lproj \QuickTimeH264Localized.qtr]
        [69BB20F6C0E81799DBCD77F0FD9DB3BF] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\fr.lproj \QuickTimeH264Localized.qtr]
        [50BFC308A5C9113CA8B0D53C4891D24F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\it.lproj \QuickTimeH264Localized.qtr]
        [9147764F7BC83B1875DA5375BCF75B3F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\ja.lproj \QuickTimeH264Localized.qtr]
        [8BD505424CAAA08EB60067F3E75E54D4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\ko.lproj \QuickTimeH264Localized.qtr]
        [9A9F32CFBD8852875CF1E13189C6A643] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\nb.lproj \QuickTimeH264Localized.qtr]
        [17D2377489921C3D0CB935A81D789E60] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\nl.lproj \QuickTimeH264Localized.qtr]
        [1363988643852EF82E1CFAD452B58A47] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\pl.lproj \QuickTimeH264Localized.qtr]
        [5544E9C109396000BFDC0B891F2B638C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\pt.lproj \QuickTimeH264Localized.qtr]
        [C90C1CE86CB95C0DAAE69AE435814071] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\pt_PT.lp roj\QuickTimeH264Localized.qtr]
        [E435021EBD255AD1BF2B8EA84D3D4565] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\QuickTim eH264.qtr]
        [E389B73E7BA945B733DE770EAB7A517A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\ru.lproj \QuickTimeH264Localized.qtr]
        [ED795F08AF061364F0F65A370E9C87ED] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\sv.lproj \QuickTimeH264Localized.qtr]
        [9FAB3161F2DED02D801DF839EC422A2C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\zh_CN.lp roj\QuickTimeH264Localized.qtr]
        [ED2C8C5D01429E29D7989266FAFF44C7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeH264.Resources\zh_TW.lp roj\QuickTimeH264Localized.qtr]
        [45C9F942603B96B05B4CDC5301031514] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.qtx]
        [2CBABA9DB66D34FD2E2E16F37FF20626] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\da.lpro j\QuickTimeImageLocalized.qtr]
        [301E94B02A0C6102216DC46B6E52B909] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\de.lpro j\QuickTimeImageLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\en.lpro j\locversion.plist]
        [FDE97CA6187A21529DC480C41EBD8788] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\en.lpro j\QuickTimeImageLocalized.qtr]
        [99B1BC922CE450A43B67747E16D1AAA1] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\es.lpro j\QuickTimeImageLocalized.qtr]
        [921C8CC5712E005E904D8CF3267CE6FB] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\fi.lpro j\QuickTimeImageLocalized.qtr]
        [26FD7D0B21ADFCB213ADBF4EE90AAAC4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\fr.lpro j\QuickTimeImageLocalized.qtr]
        [36911573C76023AA64043A97F60F1422] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\it.lpro j\QuickTimeImageLocalized.qtr]
        [D540532C1C68E2B181F665E9FF152AC4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\ja.lpro j\QuickTimeImageLocalized.qtr]
        [9DF8ACFC9B3EEC0794AB807063D73B12] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\ko.lpro j\QuickTimeImageLocalized.qtr]
        [64DB48A22E30A861AC3CA28A6595A70F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\nb.lpro j\QuickTimeImageLocalized.qtr]
        [FC0C0673A3DA24A125D42C10DB4970F3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\nl.lpro j\QuickTimeImageLocalized.qtr]
        [BCF48DADF17CE86424EEF8B9A4555C33] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\pl.lpro j\QuickTimeImageLocalized.qtr]
        [E9BE1036AB366C579E20A44031644FC5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\pt.lpro j\QuickTimeImageLocalized.qtr]
        [E5A5306F18B52D89C287C5541035598B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\pt_PT.l proj\QuickTimeImageLocalized.qtr]
        [7AF74C317DE126FF5B431243773973C0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\QuickTi meImage.qtr]
        [7DFE9CC7A8007606BB74CD92D70188A6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\ru.lpro j\QuickTimeImageLocalized.qtr]
        [EE0CC252D6042EB2874A73EDDDE23A4A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\sv.lpro j\QuickTimeImageLocalized.qtr]
        [64C08FFF1B2F652D4085861CFE5AE340] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\zh_CN.l proj\QuickTimeImageLocalized.qtr]
        [A481EF84BD2513EDB6AEBA1BBC4983D1] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeImage.Resources\zh_TW.l proj\QuickTimeImageLocalized.qtr]
        [C0733D9131B880E5795D7A83996CC66E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.qtx]
        [A3654DE3F6148815D354FA16C6E9CD5A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\da.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [0029B079272185D919157E24CB7AF234] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\de.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\en.lproj\locversion.plist]
        [E3BE252CE4DFA4FEC6459AD5EDAE496B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\en.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [8EF0276FA038178F481D4F75E4D8D094] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\es.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [FAAFA4F8BCCA42CC3BF421A70044F759] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\fi.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [F73F68AEE725A5AB78B1767E44F3CE48] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\fr.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [D46A2EE9383F7C2A84C992E95C38C64A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\it.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [BEBBF90F34CAD16F968680FD6065E70C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\ja.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [BAC2B17B431BFA462DB2B186AA5E7F4F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\ko.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [63D3F9527D2CB6BD89D2CBF2BF700467] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\nb.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [13E27412A5E2E473CCD4ABFBA80EEDA8] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\nl.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [C1B17BAA8A3A49DD71AAEB336212E457] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\pl.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [FCEF24A61C77ADD794F49DAC5608641E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\pt.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [D92A5621DEFA51512F005DEAD2A5EAA0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\pt_PT.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [0E3DF93FC88E1A2F67AD361A78554798] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\QuickTimeInternetExtras.qtr]
        [A1D2CBF90A1216A5BF8FAC01515AFF63] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\ru.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [8CA3FB68E4B936B592966E914F5BE68A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\sv.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [9B9DBAB91CE745003901E3F05AAED19A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\zh_CN.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [8587C9CC589D341BDDBFE86D7BB41482] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeInternetExtras.Resource s\zh_TW.lproj\QuickTimeInternetExtrasLocalized.qtr]
        [9246C5561D9B0FAE5844BB6553825002] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.qtx]
        [2B2619FA62A2A931D7C7649CA8222DCD] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\da.lproj \QuickTimeMPEGLocalized.qtr]
        [B964D452EF6C0A881B5D69EC5830FDB9] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\de.lproj \QuickTimeMPEGLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\en.lproj \locversion.plist]
        [B5E1D7DC0AB926B7DA0CB06A98E22608] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\en.lproj \QuickTimeMPEGLocalized.qtr]
        [77E73616670FB3AE896A3D13CD354F6C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\es.lproj \QuickTimeMPEGLocalized.qtr]
        [BA4C4917D348B11CB9160610F65D15DC] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\fi.lproj \QuickTimeMPEGLocalized.qtr]
        [05F6FCF2DD3889EF0FEC667AF84E9CEE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\fr.lproj \QuickTimeMPEGLocalized.qtr]
        [930CE13D43F8A946626EE1CD084A99A9] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\it.lproj \QuickTimeMPEGLocalized.qtr]
        [D6A7C66DCB784414945442724E975DB7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\ja.lproj \QuickTimeMPEGLocalized.qtr]
        [400F2FEB74F5EF2B36C2AC0B8AE45B19] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\ko.lproj \QuickTimeMPEGLocalized.qtr]
        [DB8A369BDDC8D2DA2D42E7B48028D873] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\nb.lproj \QuickTimeMPEGLocalized.qtr]
        [35BE1260C90BADF15B0A58CB745DFB39] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\nl.lproj \QuickTimeMPEGLocalized.qtr]
        [E022E21E39D0B9E0F71CF46E225389AF] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\pl.lproj \QuickTimeMPEGLocalized.qtr]
        [DA6349F628C3AA4DF3B2C310475E0D36] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\pt.lproj \QuickTimeMPEGLocalized.qtr]
        [E45229750CD2FE1FA2EACF7CB12471A5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\pt_PT.lp roj\QuickTimeMPEGLocalized.qtr]
        [742EFDE12DD5D98172D186A56B977A22] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\QuickTim eMPEG.qtr]
        [25AD35B171AD268459A59C6C28CF9041] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\ru.lproj \QuickTimeMPEGLocalized.qtr]
        [45BA327A5670AECB80B49E12295F6AA3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\sv.lproj \QuickTimeMPEGLocalized.qtr]
        [F2E21EDCAF978C127A1CAC76E95901DE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\zh_CN.lp roj\QuickTimeMPEGLocalized.qtr]
        [4A8E0F38A6D8CB14F4ABFC03A953CD30] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG.Resources\zh_TW.lp roj\QuickTimeMPEGLocalized.qtr]
        [AED5F9F09F068AEFEACBDB72F5C5775F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.qtx]
        [757ABAC01269121C0F87A08B654D38E0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\da.lpro j\QuickTimeMPEG4Localized.qtr]
        [E9C1E5FA928A920BF63A1F1B0DD90B39] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\de.lpro j\QuickTimeMPEG4Localized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\en.lpro j\locversion.plist]
        [0BE0A93335345B7593A907BBA48EDC7B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\en.lpro j\QuickTimeMPEG4Localized.qtr]
        [73A95EC983167B6190FD80C1884C08B3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\es.lpro j\QuickTimeMPEG4Localized.qtr]
        [8F7C557A713A28CD9810D116C7C1BFB6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\fi.lpro j\QuickTimeMPEG4Localized.qtr]
        [FBF9B53FB48B37CF72E21805F15BDDA7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\fr.lpro j\QuickTimeMPEG4Localized.qtr]
        [92FC289D83BDE3E696779909477DD9B6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\it.lpro j\QuickTimeMPEG4Localized.qtr]
        [F8B1694EA1CEB08D169DBDECA7B5123D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\ja.lpro j\QuickTimeMPEG4Localized.qtr]
        [D51B3ED20F3E3547B4F3B6A11A61878E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\ko.lpro j\QuickTimeMPEG4Localized.qtr]
        [69D955B971E48C86D7B5C615A039FEA7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\nb.lpro j\QuickTimeMPEG4Localized.qtr]
        [EED0BB7B9C99FD875CB60473A2C0FEB9] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\nl.lpro j\QuickTimeMPEG4Localized.qtr]
        [2EDA7DECBDFDCFF19DE51D117BFF1728] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\pl.lpro j\QuickTimeMPEG4Localized.qtr]
        [CEF1D4CC37E54F89034C15C3B50A637E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\pt.lpro j\QuickTimeMPEG4Localized.qtr]
        [23176B8996296D6F678BE177E89FFB31] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\pt_PT.l proj\QuickTimeMPEG4Localized.qtr]
        [938AB45AC7C133B33CBE190811621D6E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\QuickTi meMPEG4.qtr]
        [371FD437E632886CEF176E51D604C915] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\ru.lpro j\QuickTimeMPEG4Localized.qtr]
        [F317525E276678BF4C2FA91236EA9D3E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\sv.lpro j\QuickTimeMPEG4Localized.qtr]
        [306CEF859EB169BF074F9D9E155329B1] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\zh_CN.l proj\QuickTimeMPEG4Localized.qtr]
        [DD1B385775C9CF41DF06AC5E14700C30] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4.Resources\zh_TW.l proj\QuickTimeMPEG4Localized.qtr]
        [4D93B56BED39BC2E3ED7B75FF724A71C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.qtx]
        [7AF45311C83613A0D30CED60F266FE64] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\da.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [1A8C641EEBFB05D1CFD20E6EEF9FBA51] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\de.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\en.lproj\locversion.plist]
        [5FD11D5D6E0BAF099F332DCEA0CAEBC9] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\en.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [125511E22985E008A0D90D47D43760F8] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\es.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [BD5C27BD94E0EA16C3ADDC533549168B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\fi.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [52A71F602184EA84A9D389392131CEF6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\fr.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [227C43D3BED0C199047EF2A49E2289CE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\it.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [3C62132F3DF9D879ECE0C0B3850FC105] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\ja.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [057D7D68F8F0A20F3CC4F3B4B4FB32D0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\ko.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [8CA090C13FEE5B56B9F428EBF4C74F71] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\nb.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [5B0FCB0A91DE81202517E431B9020C09] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\nl.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [655BDDE48FD77E5CCDFEF27D46268393] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\pl.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [D4288052F13647E52195EACA97BF35DE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\pt.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [C4B7649273027919373CEC8860E88AAA] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\pt_PT.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [606514ADBF1229418ADB4F7997E37663] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\QuickTimeMPEG4Authoring.qtr]
        [B773F124856EF22EE73BE0433D50043F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\ru.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [06360B0602233346D05DD54337DDB560] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\sv.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [A3D0ABDE9BA31351D6D76B65EF4F3AA6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\zh_CN.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [035BA729008D4D7533F6C77F22829D85] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMPEG4Authoring.Resource s\zh_TW.lproj\QuickTimeMPEG4AuthoringLocalized.qtr]
        [F84E9E0EE9870C1C3C35EF00FC31B4ED] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.qtx]
        [657D52AD087D8B30A2C1C67B9A2963E5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\da.lpro j\QuickTimeMusicLocalized.qtr]
        [AF71072B0766F1B65A6193FE8CCA25F3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\de.lpro j\QuickTimeMusicLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\en.lpro j\locversion.plist]
        [BBF2764BC64AA5A31E303DDBB3A67D6E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\en.lpro j\QuickTimeMusicLocalized.qtr]
        [7D470F03D7F14AA36FFE0FB33AD83E00] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\es.lpro j\QuickTimeMusicLocalized.qtr]
        [E8657596187D6887129A0ADD3216AA1D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\fi.lpro j\QuickTimeMusicLocalized.qtr]
        [E0BAA9387BCADAA56A4DD1AA52B1A84B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\fr.lpro j\QuickTimeMusicLocalized.qtr]
        [3B753D0994EA1567E5741F1CACAAC615] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\it.lpro j\QuickTimeMusicLocalized.qtr]
        [8D77C27C4B86AC991356CEBEF53C0EE4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\ja.lpro j\QuickTimeMusicLocalized.qtr]
        [0E8C849FDF8B64EC6F2ECB3381B3DEA3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\ko.lpro j\QuickTimeMusicLocalized.qtr]
        [E415563DBE4BC1432DF4FCD7F21DD4B2] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\nb.lpro j\QuickTimeMusicLocalized.qtr]
        [F842522405A505E270D0CCDF15CE5E69] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\nl.lpro j\QuickTimeMusicLocalized.qtr]
        [EBDADCBC08FA20F6CA965A25E96C7048] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\pl.lpro j\QuickTimeMusicLocalized.qtr]
        [C68B7595F27DC3F1C8FA25AE6A0D09E8] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\pt.lpro j\QuickTimeMusicLocalized.qtr]
        [8E20ED581A90FB54F080D828B35CD0EB] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\pt_PT.l proj\QuickTimeMusicLocalized.qtr]
        [511EE1DEEE0D20F9005342A8EB4EF95D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\QuickTi meMusic.qtr]
        [CBA8AC104FBF7D91B79F17BBCB730D6F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\ru.lpro j\QuickTimeMusicLocalized.qtr]
        [603CBC6BDAEAB5340674117C10DA704A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\sv.lpro j\QuickTimeMusicLocalized.qtr]
        [19A3CF1B9F89423149D4471FB3CFB6FE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\zh_CN.l proj\QuickTimeMusicLocalized.qtr]
        [941DDAF75A1D6DF4BC77E17EA897570E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusic.Resources\zh_TW.l proj\QuickTimeMusicLocalized.qtr]
        [FC811DA3C0DC96709D958641C0604516] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeMusicalInstruments.qtx]
        [10F9799849ABE6B6AB3A3C38B7449FA0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.qtx]
        [88BA9A53F83A44CF723B205B70BEF644] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\da. lproj\QuickTimeStreamingLocalized.dll]
        [C455FF9465F3D0F00D9A733CE65F0EED] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\da. lproj\QuickTimeStreamingLocalized.qtr]
        [64B8CF0C03B0D90EC86E60A7B4F83447] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\de. lproj\QuickTimeStreamingLocalized.dll]
        [11D2C2BA4049B0EA1A84D34E51D04F30] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\de. lproj\QuickTimeStreamingLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\en. lproj\locversion.plist]
        [CBE2D25B9068579752C3B6928C9CBB6F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\en. lproj\QuickTimeStreamingLocalized.dll]
        [712A4AD324D80C6B993CDA7D86B9B035] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\en. lproj\QuickTimeStreamingLocalized.qtr]
        [4551A96D5C3C0F59BD6BD96017FD107F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\es. lproj\QuickTimeStreamingLocalized.dll]
        [A7CCAABDB123EC720EEBBA7FC927054E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\es. lproj\QuickTimeStreamingLocalized.qtr]
        [1AFCB689869808002B11CFA46CCEA05F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\fi. lproj\QuickTimeStreamingLocalized.dll]
        [657BA938316A89FF72A41C0AF1D2EA24] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\fi. lproj\QuickTimeStreamingLocalized.qtr]
        [0B661AEA4409C643E3D3874D235EA335] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\fr. lproj\QuickTimeStreamingLocalized.dll]
        [9977B4FC84FBB474AEF2BC24D2D8F515] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\fr. lproj\QuickTimeStreamingLocalized.qtr]
        [96B718D728FAE2FEAE53E1221919BC61] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\it. lproj\QuickTimeStreamingLocalized.dll]
        [B637DF0125FFA380170E66C9B4A00A75] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\it. lproj\QuickTimeStreamingLocalized.qtr]
        [915D9DDF2206E2FC3C27AACF2F13CA12] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\ja. lproj\QuickTimeStreamingLocalized.dll]
        [429B4982C12B67D399E39101C30283FD] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\ja. lproj\QuickTimeStreamingLocalized.qtr]
        [F79B488563BDDC8D5C686C96F7712607] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\ko. lproj\QuickTimeStreamingLocalized.dll]
        [5E47DDBF41E006D1F79BF069C90199E9] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\ko. lproj\QuickTimeStreamingLocalized.qtr]
        [C7F4E933769AE8111B1B84729541E524] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\nb. lproj\QuickTimeStreamingLocalized.dll]
        [AD0AC0DA6D8072A006ABDA46B2F27C13] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\nb. lproj\QuickTimeStreamingLocalized.qtr]
        [20A4889C40F586C69A87D9758591012C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\nl. lproj\QuickTimeStreamingLocalized.dll]
        [E3C127AC48B77AC53331F40AD261AB30] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\nl. lproj\QuickTimeStreamingLocalized.qtr]
        [D4862BDC7913240C17B81D2E231FA2E4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\pl. lproj\QuickTimeStreamingLocalized.dll]
        [D0A9D00E6F0F8CB25CDF554671C2B385] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\pl. lproj\QuickTimeStreamingLocalized.qtr]
        [7B11559FF100E4AA120075868880987E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\pt. lproj\QuickTimeStreamingLocalized.dll]
        [C536E704769450D66D177C946DBB47D7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\pt. lproj\QuickTimeStreamingLocalized.qtr]
        [6008165989C83F5F73770A527D9B8D88] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\pt_ PT.lproj\QuickTimeStreamingLocalized.dll]
        [60E38C7105858471F16CB2A5195F043A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\pt_ PT.lproj\QuickTimeStreamingLocalized.qtr]
        [CA5F7F67450F5462E840BEAC97DAADA7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\Qui ckTimeStreaming.qtr]
        [A7D593F53064B61D30D8AEA5EEDA8744] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\ru. lproj\QuickTimeStreamingLocalized.dll]
        [E74A8716C5535DB25BB738BF05E2C1B4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\ru. lproj\QuickTimeStreamingLocalized.qtr]
        [AF2EAA99E0F5FDF8DBB01DEA5BE18600] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\sv. lproj\QuickTimeStreamingLocalized.dll]
        [FC794EF75BF0AE478A4C4E83F40217C2] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\sv. lproj\QuickTimeStreamingLocalized.qtr]
        [FA3DAC1A3BD7740CCE3029BCD1AA6CE1] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\zh_ CN.lproj\QuickTimeStreamingLocalized.dll]
        [0E6E75DFCF600C601619689EC016B2D3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\zh_ CN.lproj\QuickTimeStreamingLocalized.qtr]
        [BC4E338BE0784D2267A890401AC642AE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\zh_ TW.lproj\QuickTimeStreamingLocalized.dll]
        [23196CC13B47434536149FF6CD16B5F5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreaming.Resources\zh_ TW.lproj\QuickTimeStreamingLocalized.qtr]
        [75076D59A117AB8C300C51353EA01678] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.qtx]
        [0D74F34F3850DD6443DFABF4D15B29B7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\da.lproj\QuickTimeStreamingAuthoringLocalize d.qtr]
        [CECFA213FDE8A68FFD0F42BB440AAEBB] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\de.lproj\QuickTimeStreamingAuthoringLocalize d.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\en.lproj\locversion.plist]
        [08223C5C6902B9D1638E355DD0907C42] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\en.lproj\QuickTimeStreamingAuthoringLocalize d.qtr]
        [47A0BD157467C84576534D913157F979] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\es.lproj\QuickTimeStreamingAuthoringLocalize d.qtr]
        [36559ED4C6A9B2A2C33FC5EA08C09C79] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\fi.lproj\QuickTimeStreamingAuthoringLocalize d.qtr]
        [F84AB552C9950D55449820B0F13AA178] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\fr.lproj\QuickTimeStreamingAuthoringLocalize d.qtr]
        [20359E832BB0FFF9006F38744AA0B597] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\it.lproj\QuickTimeStreamingAuthoringLocalize d.qtr]
        [48BFD00D668526C0CFA537D273996230] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\ja.lproj\QuickTimeStreamingAuthoringLocalize d.qtr]
        [B72E7AAE35FDA17934BBA402F74E82F1] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\ko.lproj\QuickTimeStreamingAuthoringLocalize d.qtr]
        [E1D8352A644DF7C093FD01D09F8D840B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\nb.lproj\QuickTimeStreamingAuthoringLocalize d.qtr]
        [D9408CA1841B16402134A4C91638FFF5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\nl.lproj\QuickTimeStreamingAuthoringLocalize d.qtr]
        [9E5A88AAB01C4C1D98E038C40189818B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\pl.lproj\QuickTimeStreamingAuthoringLocalize d.qtr]
        [4D775C74F011DE87653ABBCF5D275AD1] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\pt.lproj\QuickTimeStreamingAuthoringLocalize d.qtr]
        [E5A7CE3C88CFA338758D211419DCD5FE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\pt_PT.lproj\QuickTimeStreamingAuthoringLocal ized.qtr]
        [C59D5D681B69F96E1E03C71D9C1B11A1] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\QuickTimeStreamingAuthoring.qtr]
        [2ADFAA3192055E6A1D83ED3C6B02D70A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\ru.lproj\QuickTimeStreamingAuthoringLocalize d.qtr]
        [8E835205CBAE411CA06D73A269ACFFEF] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\sv.lproj\QuickTimeStreamingAuthoringLocalize d.qtr]
        [A9316E272FA464E24D6313FAD99AC937] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\zh_CN.lproj\QuickTimeStreamingAuthoringLocal ized.qtr]
        [2494278F9A1A6164D0C2749C32C93F1B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingAuthoring.Reso urces\zh_TW.lproj\QuickTimeStreamingAuthoringLocal ized.qtr]
        [EA4871340CD05F58488C3F940A3567C4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.qtx]
        [D988D8F38553D642A63C60C227839519] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\da.lproj\QuickTimeStreamingExtrasLocalized.qtr]
        [D203F569A2FEB79241B474DD3A8B3ECD] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\de.lproj\QuickTimeStreamingExtrasLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\en.lproj\locversion.plist]
        [E51240E812EE564F5C7A6A242F839838] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\en.lproj\QuickTimeStreamingExtrasLocalized.qtr]
        [A6D23411B865524BD5871B0B4EFAD9A6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\es.lproj\QuickTimeStreamingExtrasLocalized.qtr]
        [3850536136F714AEBD6101A5B2F67616] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\fi.lproj\QuickTimeStreamingExtrasLocalized.qtr]
        [F077DC70D321B27AFB394BACB6FD939B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\fr.lproj\QuickTimeStreamingExtrasLocalized.qtr]
        [EE74939F2ECC63B7AEA3378339D85A84] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\it.lproj\QuickTimeStreamingExtrasLocalized.qtr]
        [3EB8EED58AE06AB11037A6512D01D82C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\ja.lproj\QuickTimeStreamingExtrasLocalized.qtr]
        [D57EFE8A51D8A17E460C4731207EF273] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\ko.lproj\QuickTimeStreamingExtrasLocalized.qtr]
        [6B5ACF496ECE03A9F402D53490410575] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\nb.lproj\QuickTimeStreamingExtrasLocalized.qtr]
        [7419975E9D7D57D589765ED5C331A68F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\nl.lproj\QuickTimeStreamingExtrasLocalized.qtr]
        [1668B12F9DE12B5C0A19BE329F1EB190] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\pl.lproj\QuickTimeStreamingExtrasLocalized.qtr]
        [BBB91086146DE76C5AD183EEBBA4AB3C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\pt.lproj\QuickTimeStreamingExtrasLocalized.qtr]
        [EEC07AEEF5F3EB6E0176DCE84F4644B9] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\pt_PT.lproj\QuickTimeStreamingExtrasLocalized.q tr]
        [C3376E57486B1E4BEB937296B2243AEC] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\QuickTimeStreamingExtras.qtr]
        [23A9FBD9F8CCC05582B124E4B7CE3C33] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\ru.lproj\QuickTimeStreamingExtrasLocalized.qtr]
        [60B75FAF21B6DBCA71D149B61AACD051] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\sv.lproj\QuickTimeStreamingExtrasLocalized.qtr]
        [FA53ABA5DEECACF1C7CD44E8C4C3B775] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\zh_CN.lproj\QuickTimeStreamingExtrasLocalized.q tr]
        [D33E7FF7AA4DE6E29382CF976890D9F9] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeStreamingExtras.Resourc es\zh_TW.lproj\QuickTimeStreamingExtrasLocalized.q tr]
        [3DE409A9B85D918B9812543A0A5C7685] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.qtx]
        [28F0977893F8D921467446A4B01C771F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\da .lproj\QuickTimeThirdPartyLocalized.qtr]
        [95E8F27A7000B34A32018AF903B938E8] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\de .lproj\QuickTimeThirdPartyLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\en .lproj\locversion.plist]
        [3D691AE6EED9E4F02376A68B1248A51D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\en .lproj\QuickTimeThirdPartyLocalized.qtr]
        [DA9576F0D4CF75BDA2EB3D1008D19903] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\es .lproj\QuickTimeThirdPartyLocalized.qtr]
        [4253A5D1E9845454E5D0DF5D4DB3B0AD] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\fi .lproj\QuickTimeThirdPartyLocalized.qtr]
        [1EF1CCF181CF03CD35C670C7FA3464A7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\fr .lproj\QuickTimeThirdPartyLocalized.qtr]
        [7E4C800E671791851FC63F594C418854] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\it .lproj\QuickTimeThirdPartyLocalized.qtr]
        [4F85AACD003B888AAB2E938FA85BC0E7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\ja .lproj\QuickTimeThirdPartyLocalized.qtr]
        [2162D602636C2A316B340F065AE546C2] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\ko .lproj\QuickTimeThirdPartyLocalized.qtr]
        [21A0486944E45B37E0BB341D59BF3BDD] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\nb .lproj\QuickTimeThirdPartyLocalized.qtr]
        [D89B53999F4913803868031A7BC7FB11] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\nl .lproj\QuickTimeThirdPartyLocalized.qtr]
        [3E72FA1990C4F8B76D2038095715C003] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\pl .lproj\QuickTimeThirdPartyLocalized.qtr]
        [26828684EA95B85C44C67D17AA2D2DA8] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\pt .lproj\QuickTimeThirdPartyLocalized.qtr]
        [418C4A730F9D7C1FF486F20AA81F5E96] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\pt _PT.lproj\QuickTimeThirdPartyLocalized.qtr]
        [A8E30186CE2D063EE63EA1260CF4C6DF] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\Qu ickTimeThirdParty.qtr]
        [191711E4DA84DF3430FE21B2CBB7E357] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\ru .lproj\QuickTimeThirdPartyLocalized.qtr]
        [E25777EAE132F791504E589004159836] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\sv .lproj\QuickTimeThirdPartyLocalized.qtr]
        [AA28A8F6B3BDDA18F51FDA52D83EBBFC] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\zh _CN.lproj\QuickTimeThirdPartyLocalized.qtr]
        [01E998DD2FC0B2052DACE9391C11F6C4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeThirdParty.Resources\zh _TW.lproj\QuickTimeThirdPartyLocalized.qtr]
        [857BB7C6341D65B0FAAF9C2CC608AA08] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeUpdateHelper.exe]
        [55982FF0FCD0B98DAF90E6D49029A41C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.qtx]
        [B54DF224AD649F3C829AD643CE4E20FD] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\da.lproj\Q uickTimeVRLocalized.qtr]
        [FD7DB72F96682A6572AAB9ECECE15B6F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\de.lproj\Q uickTimeVRLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\en.lproj\l ocversion.plist]
        [2501970ADB3006CAF0F215AF50969084] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\en.lproj\Q uickTimeVRLocalized.qtr]
        [1E3714E757DD2834174E303DBCAFC87C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\es.lproj\Q uickTimeVRLocalized.qtr]
        [6ACA1A57F7FB91870BCAFD9AE6EBE156] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\fi.lproj\Q uickTimeVRLocalized.qtr]
        [23A45FD0A468034A2D0D09E752228002] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\fr.lproj\Q uickTimeVRLocalized.qtr]
        [202C6B57A0C97511685DC0B7DF553098] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\it.lproj\Q uickTimeVRLocalized.qtr]
        [1B517080A1D732E9740CDB6ABCE8A0D2] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\ja.lproj\Q uickTimeVRLocalized.qtr]
        [01063F6362C15E99767184C525C0E637] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\ko.lproj\Q uickTimeVRLocalized.qtr]
        [27772138B218AD3B12AF893B8103889E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\nb.lproj\Q uickTimeVRLocalized.qtr]
        [4F28EB4861B116C2256371CA5F9588A2] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\nl.lproj\Q uickTimeVRLocalized.qtr]
        [CF1453FB6899F6433166A621BC1840DD] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\pl.lproj\Q uickTimeVRLocalized.qtr]
        [42CFA2977B89D97D0BF5AC64D8FBF812] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\pt.lproj\Q uickTimeVRLocalized.qtr]
        [DDB89D6A21EC650A00914471AEB5C061] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\pt_PT.lpro j\QuickTimeVRLocalized.qtr]
        [C583670D5CC43D005EDE5F260DE466FA] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\QuickTimeV R.qtr]
        [9660472C53AD11E8856A3753988C9CCA] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\ru.lproj\Q uickTimeVRLocalized.qtr]
        [5C94FCE76A4A0C2CAA3344AA014BE84A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\sv.lproj\Q uickTimeVRLocalized.qtr]
        [736605E2F12D803E75AADAAE4FA9BF81] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\zh_CN.lpro j\QuickTimeVRLocalized.qtr]
        [5185BDFA26A6B4D5F8BED49E2A01F27E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVR.Resources\zh_TW.lpro j\QuickTimeVRLocalized.qtr]
        [58E18BDEB2138E7FCA7CA0C3FE2111C4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.qtx]
        [33FE719082922AE4EBF514AEFAAB8E94] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\d a.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [ED9B2AA5B1D929884ECFAE156ACE31C1] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\d e.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\e n.lproj\locversion.plist]
        [E7C53E286FEE4CC812D4457ED61C0A1B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\e n.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [81DFEEC93A181F99A36E5298D342C334] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\e s.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [E57999A6AEE935A3DCCC3FAD96F0C7E0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\f i.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [C2282D338EFE1923C6891021A5BF0FC5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\f r.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [0A630F30CA17CE7060576B999E03DD01] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\i t.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [B5402E3E231AFA98ADE089C41205FEE3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\j a.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [8E7BAD47A3FB32ADE17CBAB84C2D3843] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\k o.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [33F6ECB38F80039FDAD96C08FAFFDE41] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\n b.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [0F719326880E13931AE223790CC8CF3D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\n l.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [7E32A49FE600A681FE19ABF6461F91AA] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\p l.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [2B2BB279CF1718BCB5F2A3A87E03AE75] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\p t.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [CB7D041D65B0000357EAE9CA32C8915E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\p t_PT.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [0515100842EE998F0B68D7739A98CA72] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\Q uickTimeVRAuthoring.qtr]
        [77917F80D78BFEE2984BA6A5C8782ED5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\r u.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [C3D45917B777981F9538717A41618FC2] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\s v.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [AD8B54E41DE2D30CF44A87FE86107C82] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\z h_CN.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [6620C04208709D929A773A5F59BE38F0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeVRAuthoring.Resources\z h_TW.lproj\QuickTimeVRAuthoringLocalized.qtr]
        [A626A498D71795066E1DD040DFCC5B7F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.qtx]
        [498DB2A264D2A50C0007DD88AA2D2704] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\da. lproj\QuickTimeWebHelperLocalized.dll]
        [AC92E2B0425378B5774BCB48CDD94719] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\da. lproj\QuickTimeWebHelperLocalized.qtr]
        [BAB0BA0391A64E935C74CCB3EA42F363] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\de. lproj\QuickTimeWebHelperLocalized.dll]
        [E668D3874F066D90DFEC0BD044EB1FE5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\de. lproj\QuickTimeWebHelperLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\en. lproj\locversion.plist]
        [997828CE44F7FA69EC02F2139DC9B037] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\en. lproj\QuickTimeWebHelperLocalized.dll]
        [4BDD175657B88D24DAC7FB7D541E1CE1] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\en. lproj\QuickTimeWebHelperLocalized.qtr]
        [ED57E49D6C10CAB126E24E332957CEAC] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\es. lproj\QuickTimeWebHelperLocalized.dll]
        [E2B4A3DE18240059CDE97CF7C5DD2037] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\es. lproj\QuickTimeWebHelperLocalized.qtr]
        [7BFE3C9158176D06568467CDCB80DED0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\fi. lproj\QuickTimeWebHelperLocalized.dll]
        [2B601F6A28041F3E2F98C1D2BAC209BB] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\fi. lproj\QuickTimeWebHelperLocalized.qtr]
        [9A437B75530D9D93293A45AF5B1578D0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\fr. lproj\QuickTimeWebHelperLocalized.dll]
        [537DF745099CC006409A42D0329DA905] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\fr. lproj\QuickTimeWebHelperLocalized.qtr]
        [1B77581A7CDBB731D2CBC9CBD4AE5366] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\it. lproj\QuickTimeWebHelperLocalized.dll]
        [ED05C63E6BDBCB161AEAA07BB4FC159A] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\it. lproj\QuickTimeWebHelperLocalized.qtr]
        [7E02097A48EE8236DE4101A4F7971371] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\ja. lproj\QuickTimeWebHelperLocalized.dll]
        [B4C9F808E635CE8BE984E610F66B0F96] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\ja. lproj\QuickTimeWebHelperLocalized.qtr]
        [EE2A5515FC5D13C0C4FB2D7AE34D3F34] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\ko. lproj\QuickTimeWebHelperLocalized.dll]
        [032C392FD060CF408D309A6D29C0C1D4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\ko. lproj\QuickTimeWebHelperLocalized.qtr]
        [E53DF219F83628F5400D16703C133B9B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\nb. lproj\QuickTimeWebHelperLocalized.dll]
        [C8963DEFC542514AB896ACF97B1BAF79] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\nb. lproj\QuickTimeWebHelperLocalized.qtr]
        [CCA113D35289ADBFF2D4FADA0D0A07F7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\nl. lproj\QuickTimeWebHelperLocalized.dll]
        [9B6FAB2D03FF3405BFE7F4AEC89DF275] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\nl. lproj\QuickTimeWebHelperLocalized.qtr]
        [7E4BA52EDF40005AAE8A493430EE7B8E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\pl. lproj\QuickTimeWebHelperLocalized.dll]
        [568F1FF174798F15D3E71593FE2BCAB9] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\pl. lproj\QuickTimeWebHelperLocalized.qtr]
        [09808067B78D81BF03B3CF3255DAC287] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\pt. lproj\QuickTimeWebHelperLocalized.dll]
        [F162719863FA519F2E4B6B6869597153] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\pt. lproj\QuickTimeWebHelperLocalized.qtr]
        [489E2395991DDAD775111B13CAF6E726] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\pt_ PT.lproj\QuickTimeWebHelperLocalized.dll]
        [88EC9E584D62DB15717C8EE26B56CBCD] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\pt_ PT.lproj\QuickTimeWebHelperLocalized.qtr]
        [6C5D1FA255BD688102F4641BD7586D33] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\Qui ckTimeWebHelper.dll]
        [BDE5432BA37954E10A1CA56E1EA044FD] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\Qui ckTimeWebHelper.qtr]
        [B07FEECF4D33A14FD9BCAA9A9EA57971] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\ru. lproj\QuickTimeWebHelperLocalized.dll]
        [240724B95A9E35AC833BF2A6DEF350AE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\ru. lproj\QuickTimeWebHelperLocalized.qtr]
        [01B1802BC6EDEA44A9D4D1D403DDD031] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\sv. lproj\QuickTimeWebHelperLocalized.dll]
        [6E9E510D44C486B77E9CEB45CDC7AB00] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\sv. lproj\QuickTimeWebHelperLocalized.qtr]
        [D5FB354811DD63D674CF33B25137D175] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\zh_ CN.lproj\QuickTimeWebHelperLocalized.dll]
        [FE6D703579E1961E136C0E109AC744AE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\zh_ CN.lproj\QuickTimeWebHelperLocalized.qtr]
        [9A1B60A5D34D10F970DA99F31771653B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\zh_ TW.lproj\QuickTimeWebHelperLocalized.dll]
        [1334B7CBDB84883DD2676F3D29F5DE5F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTSystem\QuickTimeWebHelper.Resources\zh_ TW.lproj\QuickTimeWebHelperLocalized.qtr]
        [BBF84B7D2715F4A04583DBD26C923D45] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QTUIPanelControl.dll]
        [960D55C0193B88B8B256E4A69D0EF243] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTime\About QuickTime.lnk]
        [871CF585CCA3E39340E25F526B78E093] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTime\QuickTime Player.lnk]
        [EB8F6AC0A1BF20E683F6FD6703C1F36B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTime\Uninstall QuickTime.lnk]
        [956A7334508867914984192DCC8F4558] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTime Read Me.htm]
        [D7C54BBF10B5F6428596CDE30EE958B0] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTime.Resources\QuickTime.qtxs]
        [3D3ED358DA5D2D4D19809027014E22E5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.dll]
        [26ED6521A62F49C93D6F0AF5D221A6DD] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.exe]
        [AA05635E8489F52DAB99A1D9C77A2DC7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\da.lproj\QuickT imePlayerLocalized.qtr]
        [4DFC3BDCA86D17ACFA62860A9824075C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\de.lproj\QuickT imePlayerLocalized.qtr]
        [25A7915ED2CE187B1233C3754B41CE59] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\en.lproj\locver sion.plist]
        [5697CF519B24A7549F4E5F658DDDB62B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\en.lproj\QuickT imePlayerLocalized.qtr]
        [1E1187219982E94406FD4726A1C7C5B6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\es.lproj\QuickT imePlayerLocalized.qtr]
        [8FF82AB045E5F8301FE2564BDDFF5293] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\fi.lproj\QuickT imePlayerLocalized.qtr]
        [A4D0DA290D243A50C1A5B01AEBAC0D14] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\fr.lproj\QuickT imePlayerLocalized.qtr]
        [E2D42F21BFD26972E7200AD78796C63C] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\it.lproj\QuickT imePlayerLocalized.qtr]
        [CCB212217BC6D28B5800BC5222BDCC5B] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\ja.lproj\QuickT imePlayerLocalized.qtr]
        [B5C29ED511125BA1B2C212EE5EBC9496] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\ko.lproj\QuickT imePlayerLocalized.qtr]
        [C12B744EB96DA1B0546ADFFCA80A8B5D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\nb.lproj\QuickT imePlayerLocalized.qtr]
        [EC3FCC4C92CD7D5B2D1BDBA933AF51A7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\nl.lproj\QuickT imePlayerLocalized.qtr]
        [6B344BF2A7A182B63C985161C356B6C6] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\pl.lproj\QuickT imePlayerLocalized.qtr]
        [EDEC83E0FCFD96FB8574164C90727AB7] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\pt.lproj\QuickT imePlayerLocalized.qtr]
        [F6F6F984A7F0037D636F877382F6AD5D] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\pt_PT.lproj\Qui ckTimePlayerLocalized.qtr]
        [2F2321DD435BFF383CA13D23DC83F0B5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\QuickTimePlayer .qtr]
        [8BEB0A268F22C672D872F85D799AE5F5] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\ru.lproj\QuickT imePlayerLocalized.qtr]
        [16FD61BF68A487706C9DE673E30DBFEB] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\sv.lproj\QuickT imePlayerLocalized.qtr]
        [202698980920AB9D3C9525F113B981FE] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\zh_CN.lproj\Qui ckTimePlayerLocalized.qtr]
        [5F21C703C35970D19BBA1F68698E5D43] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\QuickTimePlayer.Resources\zh_TW.lproj\Qui ckTimePlayerLocalized.qtr]
        [0E242AB2D25193687BFFDF12813E6E67] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\Q uickTime\Sample.mov]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{05BFB060-4F22-4710-B0A2-2801A1B606C5}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{2F72F540-1F60-4266-9506-952B21D6640D}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{33EB1061-ABF1-4470-A540-32E97A610536}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{3540181E-340A-4E7A-B409-31663472B2F7}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{439760BC-7737-4386-9B1D-A90A3E8A22EA}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{5ED7462B-EF58-4757-B609-53755021EC34}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{75104836-CAC7-444E-A39E-3F54151942F5}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{7774002B-60B3-4146-BF82-5BF767D468B8}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{787136D2-F0F8-4625-AA3F-72D7795AC842}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{8F473675-D702-45F9-8EBC-342B40C17BF5}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{963BFE7E-C350-4346-B43C-B02358306A45}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{B678797F-DF38-4556-8A31-8B818E261868}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{B8AD779A-82DA-4365-A7D0-AD3DCFC55CFF}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{C4123106-B685-48E6-B9BD-E4F911841EB4}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{D4D86CB2-2370-4691-8272-3869EDED6C64}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{E5C95CA5-4565-4B9D-97ED-05088D775614}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{F7513E19-6224-485E-988D-9BF45BE64B53}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}.SchedServiceConfig.rmi]
        [D41D8CD98F00B204E9800998ECF8427E] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Quarantine\w ix{FE86CB0C-FCB3-4358-B4B0-B0A41E33B3DD}.SchedServiceConfig.rmi]
        [3AC3E89CDD11E306BFFF701CE97BC126] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\Tempo.txt]
        [83756DBD9C30884D7EBF50FE6C341B75] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\TraceZHPClea ner.txt]
        [35C9DDFCBCD2DC2BE425B989C862F0EA] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\ZHPCleaner-[R]-04032017-20_08_06.txt]
        [0FA8DD83EA37D6643C007A58FFB3E2A4] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\ZHPCleaner–0 4032017-19_59_58.txt]
        [84111C56B64E5E605F807F6351C68932] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\ZHPCleaner.e xe]
        [9EEEF2834A0C6A3078E77636E0785EA3] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\ZHPCleaner.t xt]
        [7B5E1D30E89E0EF1C86FECB977131673] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\ZHPCleaner_Q uarantine.txt]
        [E827802F505F1FDF617412D4A4DD607F] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\ZHPCleaner_T empo.txt]
        [2510069D933E2441C1E19489AC5E8219] Trojan.FPL.Rotbrow.vl [c:\users\goldfish\appdata\roaming\ZHP\ZHPQ_Files.t xt]
        [3B6A157D409CA7C442A176BF773A1A7B] Adware.FMPL.Gen.se [C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\DIFxInstallLog.txt]
        [6D47483DE61BA05C68BF0A3F502FB81C] Adware.FMPL.Gen.se [C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7\x64\DIFxInstallLog.txt]
        [E675C7006BDC625BC4EE9CF5BB1F7677] Malware.MPL.Heur.vl [c:\users\goldfish\appdata\roaming\microsoft\window s\templates\iTunes12x64Patch.exe]
        [9F7F3294F2CD26EAB0DB92100E70186C] Pack.Win32.Gen.bot!ep-9 [c:\windows\syswow64\VaioScreensaversGeneric.scr]
        [9F7F3294F2CD26EAB0DB92100E70186C] Pack.Win32.Gen.bot!ep-9 [C:\Program Files (x86)\VAIO screensavers\VaioScreensaversGeneric.scr]

        Comment

        • Malnutrition
          PCHF Moderator
          • Jul 2016
          • 7041

          #19
          FRST Fix.

          Download attached fixlist.txt file and save it to the Desktop. NOTE. It’s important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

          ClearLNK

          Download ClearLNK save it to your desktop.
          Drag the file Shortcut.txt made with FRST earlier.
          As per picture.
          A report on the work as a file ClearLNK- .log
          Will be produced, post that log.

          https://pchelpforum.net/proxy.php?image=https%3A%2F%2Fup2sha.re%2Fuploads% 2F2015%2F3%2FBPD7B3BAgEQl.gif&hash=f65630ba2178027 f4643224f28999e44

          Rogue Killer Scan.

          Originally posted by Goldfish
          I’ve also run RogueKiller (blue-screens partway through)



          Download RogueKiller – (Portable) – from one of the following links and save it to your Desktop:

          Link 1
          Link 2


          [ul]
          [li]Close all other the running programs[/li][li]Disable ALL Antivirus – Antimalware – Applications.[/li][li]Right Click Rogue Killer and Run as Administrator.[/li][li]Click the Start Scan button.[/li][li]Allow the scan to run – it can take ten minutes or more.[/li][li]Once the scan is complete check All items for removal.[/li][li]https://pchelpforum.net/attachments/...5-54-png.1658/ [/li]
          [li]After All items are checked then press Remove Selected.[/li]
          [li]Wait until the Status box shows Deleting Finished.[/li][li]Click on open report – then open txt[/li]
          [li]Copy the content of the report and paste it here in your next reply.[/li]
          [/ul]

          Comment

          • Malnutrition
            PCHF Moderator
            • Jul 2016
            • 7041

            #20
            ZHP Diag Scan

            Download ZHP Diag to your desktop.
            1. Right Click Run as Admin.
              2. Click the Scanner button.



            When complete please push the report button.
            A notepad will open… copy and paste the report in your next reply.

            Comment

            • Goldfish
              PCHF Member
              • Mar 2017
              • 26

              #21
              The scans for the fix and ClearLNK are below.

              RogueKiller bluescreened at the same point as before - details below.

              ================================================== ==================================
              Fix result of Farbar Recovery Scan Tool (x64) Version: 04-03-2017
              Ran by goldfish (05-03-2017 10:24:42) Run:1
              Running from C:\Users\goldfish\Desktop
              Loaded Profiles: goldfish (Available Profiles: goldfish)
              Boot Mode: Normal
              ==============================================
              fixlist content:


              Start
              CreateRestorePoint:
              Closeprocesses:
              Emptytemp:
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000...\MountPoints2: {3966f36d-41b6-11e0-8b3f-c44619b2e2e4} - D:.\Setup.exe AUTORUN=1
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000...\MountPoints2: {cfdc1e4e-78d4-11e0-aa4f-c44619b2e2e4} - D:.\Setup.exe AUTORUN=1
              ShellIconOverlayIdentifiers: [00avg] → {472083B0-C522-11CF-8763-00608CC02F24} => → No File
              Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
              Tcpip..\Interfaces{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}: [DhcpNameServer] 192.168.1.1 192.168.1.1
              Tcpip..\Interfaces{927587AB-1894-493E-8E72-6063314BF69A}: [DhcpNameServer] 192.168.1.1 192.168.1.1
              Tcpip..\Interfaces{EC19D428-B36F-4D8F-B458-DB4400362D30}: [DhcpNameServer] 172.20.10.1
              HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?bcutc=sp-014-756
              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?bcutc=sp-014-756&q={searchTerms}
              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?bcutc=sp-014-756&q={searchTerms}
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://uk-mg5.mail.yahoo.com/neo/launch?.rand=872fenf2dujii
              SearchScopes: HKLM-x32 → DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-014-756&q={searchTerms}
              SearchScopes: HKLM-x32 → {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-014-756&q={searchTerms}
              SearchScopes: HKU\S-1-5-21-928801702-3077407482-3869533313-1000 → DefaultScope {67B4F6F6-DEA2-42F9-84A7-6785674F4D19} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.micros oft:{language}:{referrer:source}&ie={inputEncoding }&oe={outputEncoding}&rlz=1I7SVEC
              SearchScopes: HKU\S-1-5-21-928801702-3077407482-3869533313-1000 → {1686262A-C27D-4A79-8D82-C55F4D8BB35A} URL = hxxp://uk.shopping.com/?linkin_id=8056359
              SearchScopes: HKU\S-1-5-21-928801702-3077407482-3869533313-1000 → {67B4F6F6-DEA2-42F9-84A7-6785674F4D19} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.micros oft:{language}:{referrer:source}&ie={inputEncoding }&oe={outputEncoding}&rlz=1I7SVEC
              SearchScopes: HKU\S-1-5-21-928801702-3077407482-3869533313-1000 → {8FD01E4A-8F30-4C90-8E35-DEF880420C67} URL = hxxp://rover.ebay.com/rover/1/710-42480-16445-5/4?satitle={searchTerms}
              SearchScopes: HKU\S-1-5-21-928801702-3077407482-3869533313-1000 → {96B8ABCB-AC35-45F0-886C-1C2B912B5FFD} URL = hxxp://www.zinio.com/search/index.jsp?s={searchTerms}&rf=sonyie8search
              SearchScopes: HKU\S-1-5-21-928801702-3077407482-3869533313-1000 → {B2EC8D7B-5F99-4D85-94B8-E3BF03379046} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q={searchTerms}&src=IE-SearchBox
              SearchScopes: HKU\S-1-5-21-928801702-3077407482-3869533313-1000 → {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-014-756&q={searchTerms}
              DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
              DPF: HKLM-x32 {76496E5E-244A-424F-B5A5-B677051BD958} hxxp://www.genavsystems.com/ftu/2096/FLIGHTOFFICE.CAB
              DPF: HKLM-x32 {BEA7310D-06C4-4339-A784-DC3804819809} hxxp://www.tescophoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
              DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
              Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
              Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-20] (Microsoft Corporation)
              Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.)
              Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.)
              Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-01-01] (Skype Technologies)
              Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
              Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
              Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
              Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
              Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
              Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
              Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
              Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
              Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
              Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
              Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
              Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
              Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
              Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
              Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
              Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
              FF Homepage: Prism\Profiles\1nquevq8.default → hxxp://127.0.0.1:888/
              FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\fcotwa47.default → Bing
              FF NetworkProxy: Mozilla\Firefox\Profiles\fcotwa47.default → type", 0
              FF Extension: (Bing Search Engine) - C:\Users\goldfish\AppData\Roaming\Mozilla\Firefox\ Profiles\fcotwa47.default\Extensions\bingsearch.full@microsoft.com [2017-03-03] [not signed]
              FF HKLM-x32...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG Secure Search\FireFoxExt\18.9.0.230 => not found
              FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\avg-secure-search.xml [2015-12-15]
              FF Plugin: @microsoft.com/GENUINE → disabled [No File]
              FF Plugin-x32: @microsoft.com/GENUINE → disabled [No File]
              FF Plugin HKU\S-1-5-21-928801702-3077407482-3869533313-1000: amazon.com/AmazonMP3DownloaderPlugin → C:\Users\goldfish\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-22] (Amazon.com, Inc.)
              CHR StartupUrls: Default → “hxxps://login.yahoo.com/?.src=ym&.intl=us&.lang=en-US&.done=https%3a//mail.yahoo.com”,“hxxps://accounts.google.com/ServiceLogin?service=mail&continue=hxxps://mail.google.com/mail/#identifier”,“hxxps://www.facebook.com/”
              CHR HKLM...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
              CHR HKLM-x32...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
              CHR HKLM-x32...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
              S2 ADExchange; no ImagePath
              S2 HDD & SSD access service; no ImagePath
              S3 TBS; %SystemRoot%\System32\tbssvc.dll
              S2 WMPNetworkSvc; “%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe”
              S3 WsDrvInst; no ImagePath
              S3 pccsmcfd; no ImagePath
              S3 dbx; system32\DRIVERS\dbx.sys
              2017-02-26 22:24 - 2017-02-26 22:24 - 00000000 _____ C:\Users\goldfish\AppData\Local{C960B433-5DA9-48AB-83A8-605A368C6C7E}
              2017-02-20 20:04 - 2017-02-20 20:04 - 00029153 _____ C:\ProgramData\agent.1487621032.bdinstall.bin
              2017-02-20 19:10 - 2017-02-20 19:10 - 00000000 ____D C:\Users\goldfish\AppData\Roaming\QuickScan
              2017-02-20 19:06 - 2017-02-20 19:06 - 00048200 _____ C:\ProgramData\agent.1487617558.bdinstall.bin
              2017-02-20 19:06 - 2017-02-20 19:06 - 00000000 ____D C:\ProgramData\BDLogging
              2017-02-20 19:05 - 2017-02-20 19:06 - 00000000 ____D C:\ProgramData\Bitdefender Agent
              2017-02-08 19:32 - 2017-02-21 11:48 - 00992488 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgsnx.sys.14876779264 2001
              C:\Windows\system32\Drivers\avgsnx.sys
              2017-02-21 23:14 - 2015-10-26 22:44 - 00000000 ____D C:\ProgramData\Avg
              2017-02-21 23:13 - 2015-10-26 22:33 - 00000000 ____D C:\Users\goldfish\AppData\Local\AvgSetupLog
              2017-02-21 23:08 - 2012-02-19 11:40 - 00000000 ____D C:\Users\goldfish\AppData\Roaming\AVG
              2017-02-21 11:42 - 2015-05-30 11:41 - 00000000 __D C:\Users\goldfish\AppData\Local\Avg
              MSCONFIG\Services: !SASCORE => 2
              MSCONFIG\Services: ACDaemon => 3
              MSCONFIG\Services: btwdins => 2
              MSCONFIG\Services: gupdate => 2
              MSCONFIG\Services: gupdatem => 3
              MSCONFIG\Services: ServiceLayer => 3
              MSCONFIG\Services: uCamMonitor => 2
              MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\Windows\pss\Bluetooth.lnk.CommonStartup
              MSCONFIG\startupfolder: C:^Users^goldfish^AppData^Roaming^Microsoft^Window s^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup
              MSCONFIG\startupreg: Adobe ARM => “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
              MSCONFIG\startupreg: Adobe Reader Speed Launcher => “C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe”
              MSCONFIG\startupreg: AmazonMP3DownloaderHelper => C:\Users\goldfish\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
              MSCONFIG\startupreg: Apoint => %ProgramFiles%\Apoint\Apoint.exe
              MSCONFIG\startupreg: ApplePhotoStreams => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
              MSCONFIG\startupreg: APSDaemon => “C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe”
              MSCONFIG\startupreg: avgnt => “C:\Program Files (x86)\Avira\Antivirus\avgnt.exe” /min
              MSCONFIG\startupreg: BrStsInd00 => C:\Program Files (x86)\BrownyInd\Brother\BrIndicator.exe /AUTORUN
              MSCONFIG\startupreg: BrStsMon00 => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
              MSCONFIG\startupreg: CCleaner => “C:\Program Files\CCleaner\CCleaner64.exe” /AUTO
              MSCONFIG\startupreg: CitrixReceiver => “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk”
              MSCONFIG\startupreg: ConnectionCenter => “C:\Program Files (x86)\Citrix\ICA Client\concentr.exe” /startup
              MSCONFIG\startupreg: DriveUtilitiesHelper => C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe
              MSCONFIG\startupreg: Dropbox => “C:\Program Files (x86)\Dropbox\Client\Dropbox.exe” /systemstartup
              MSCONFIG\startupreg: iCloudDrive => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
              MSCONFIG\startupreg: iCloudServices => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
              MSCONFIG\startupreg: iTunesHelper => “C:\Program Files\iTunes\iTunesHelper.exe”
              MSCONFIG\startupreg: MSC => “c:\Program Files\Microsoft Security Client\msseces.exe” -hide -runkey
              MSCONFIG\startupreg: PC Suite Tray => “C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe” -onlytray
              MSCONFIG\startupreg: Redirector => “C:\Program Files (x86)\Citrix\ICA Client\redirector.exe” /startup
              MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
              MSCONFIG\startupreg: Skype => “C:\Program Files (x86)\Skype\Phone\Skype.exe” /minimized /regrun
              MSCONFIG\startupreg: SunJavaUpdateSched => “C:\Program Files\Java\jre6\bin\jusched.exe”
              MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
              MSCONFIG\startupreg: WDAppManager => C:\Program Files (x86)\Western Digital\WD App Manager\AppManagerLauncher.exe
              MSCONFIG\startupreg: Windows Mobile Device Center => %windir%\WindowsMobile\wmdc.exe
              C:\Windows\system32\Drivers\etc\hosts
              hosts:
              AlternateDataStreams: C:\ProgramData\TEMP:0B4227B4 [268]
              C:\ProgramData\TEMP:0B4227B4
              Task: C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe
              C:\ProgramData\AVG January 2013 Campaign
              Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpda teService.exe
              Task: {02BEB9D0-7890-4F25-AF0D-BF58A97B79E6} - System32\Tasks{12FCE0CC-9445-4AA9-8D95-E4F80F6C6440} => C:\Program Files (x86)\B737 CBT\install.exe [2000-03-30] (Macromedia, Inc.)
              Task: {06C6A861-269E-4E42-9795-B94F8F690B25} - System32\Tasks{2E0B2CC6-E47D-46B5-A5D7-B8DBE4924FFE} => pcalua.exe -a “C:\Program Files\SUPERAntiSpyware\Uninstall.exe”
              Task: {0E364092-14AD-4480-B09D-7C5DD704AD73} - System32\Tasks{5A1F6414-9B70-4221-A069-2C3136C8F3BC} => Chrome.exe hxxps://ui.skype.com/ui/0/7.29.80.102/en/abandoninstall?page=tsProgressBar
              Task: {0EA45EDA-39CC-4ADB-A6D9-4BAF33D5FA30} - System32\Tasks\SONY\VAIO Gate\StartExecuteProxy => C:\Program Files\Sony\VAIO Gate\ExecutionProxy.exe [2010-10-25] (Sony Corporation)
              Task: {1268C5BA-AB72-49DD-8BEE-AA1346A5E26A} - System32\Tasks\SONY\VAIO Power Management\VPM Logon Start => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-19] (Sony Corporation)
              Task: {1ABF9405-23CC-4197-BE3D-1DAF5349D2AD} - System32\Tasks{2093FCAC-5EB6-4537-A8F9-03FC034783F2} => C:\Program Files (x86)\iTunes\iTunes.exe
              Task: {1B6F7527-6051-4588-9CC3-26DBBA3F5906} - System32\Tasks\SONY\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2010-10-25] (Sony Corporation)
              Task: {1DFE7133-E445-4A03-8AC0-F74053E51AD2} - System32\Tasks\TunnelBear => C:\Program Files (x86)\TunnelBear\TBear.Client.exe
              Task: {2B73086E-33A6-44C4-87DA-29D189E2786E} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2011-02-16] (Sony Corporation)
              Task: {36251C2B-C530-4941-AF8D-09CCF2332640} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpda teService.exe [2017-02-15] (Adobe Systems Incorporated)
              Task: {411ABCC0-9D14-474C-903F-AF8565D5BC4B} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update 5 => C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe [2011-04-20] (Sony Corporation)
              Task: {47B7819F-92DD-43AC-9FF0-5CBB64863D3C} - System32\Tasks{96C12997-A4BC-4A31-982B-4770E5B9F850} => C:\Program Files (x86)\B737 CBT\install.exe [2000-03-30] (Macromedia, Inc.)
              Task: {5221FD53-7E3D-4540-84E1-5FE536E23F55} - System32\Tasks{E2A5F6B9-C55D-4083-94E2-C7D27EDDC5EE} => pcalua.exe -a “C:\Program Files (x86)\Sony Corporation\VAIO Partners\uninstall.exe” -c -prepareUninstall
              Task: {5C46E2A4-DEB2-414F-A340-38C9780099FC} - System32\Tasks{9C2AC3BE-3FFF-46A1-A323-14AB69C2DAB0} => pcalua.exe -a C:\Users\goldfish\Desktop\setup.exe -d C:\Users\goldfish\Desktop
              Task: {6512F9BC-6D3C-470B-8BA9-43E008628A6E} - System32\Tasks{9A2D62CF-9308-4BCD-AE33-79916B90C09B} => pcalua.exe -a F:\setup.exe -d F:
              Task: {70557BF9-78EC-4476-A384-73A5E50B6AF7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-07] (Google Inc.)
              Task: {768AD431-53A2-4F5A-BC74-932F41B28F00} - System32\Tasks{93FCEB53-8810-4B44-9077-E63EEC818449} => C:\Program Files (x86)\B737 CBT\install.exe [2000-03-30] (Macromedia, Inc.)
              Task: {91F065EA-BDE3-4099-89D8-B581A51BD4FA} - System32\Tasks{926AC40F-1299-447B-AEF6-54EFD36B56DA} => C:\Program Files (x86)\B737 CBT\install.exe [2000-03-30] (Macromedia, Inc.)
              Task: {9DC9BC20-0D4B-4598-9C66-0F592842E6DB} - System32\Tasks{92A54289-B4FD-4AED-801A-802259F7E495} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2017-02-08] (Skype Technologies S.A.)
              Task: {A324975A-EFC0-454C-8124-7A26F20C9E52} - System32\Tasks\SONY\SUS-BCF\Level4Daily => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2009-11-20] (Sony Corporation)
              Task: {A69AFC5B-57F5-4600-A5F6-F777C0CF3DF1} - System32\Tasks{97EC3147-E1A9-4701-B32D-CE6CD97B78EC} => C:\Program Files (x86)\B737 CBT\install.exe [2000-03-30] (Macromedia, Inc.)
              Task: {B1DF4585-6B0E-49E9-B6F3-5BE3466BF754} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
              Task: {B1E5F863-1AEB-49C1-812E-B8527F2CCA92} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-07] (Google Inc.)
              Task: {B33446C5-DD85-45C5-ADA6-44C81406E9FC} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => %SystemRoot%\ehome\mcupdate.exe
              Task: {C956B962-51DE-45C7-A315-B1146AEB98A1} - System32\Tasks{E1FE020E-4198-444A-883E-2A2DF6C27E01} => pcalua.exe -a “C:\Program Files (x86)\Sony\Marketing Tools\Uninstaller.exe” -c /bootstrap
              Task: {CB60D4A6-73F1-4DA8-9A34-05310F59783E} - System32\Tasks\Sony Corporation\VAIO Update\Launch Application => C:\Program Files\Sony\VAIO Update 5\ShellExeProxy.exe
              Task: {CE928646-2D82-4350-8674-BCB03E35528E} - System32\Tasks{81432782-934F-47AD-9717-49765EBAB508} => pcalua.exe -a C:\ProgramData\Installations{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}\Nokia_PC_Suite_eng_web[1].exe
              Task: {D7D6F1EF-7E7F-4AE7-8533-2937A6126C0B} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe [2013-01-17] ()
              Task: {DCFC64A1-29B0-4A44-AAA4-B2237C97138D} - System32\Tasks{D35BEE58-0154-4836-AE23-AA6300E98B3B} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=4.2.0.187.25 9&LastError=12002
              Task: {DDC020A3-0340-45AD-8E21-A677F2C9B4F9} - System32\Tasks\Games\UpdateCheck_S-1-5-21-928801702-3077407482-3869533313-1000
              Task: {DE506D78-8716-41A5-A982-BBD96130BB2C} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => %SystemRoot%\ehome\ehrec.exe
              Task: {E10E381B-C0E3-481C-98BA-A7E64260B292} - System32\Tasks{CE7BA935-73B5-4BD7-9385-01F9719511C3} => C:\Program Files (x86)\B737 CBT\install.exe [2000-03-30] (Macromedia, Inc.)
              Task: {EF840724-63CF-4693-A308-CB19C44B02DE} - System32\Tasks{4B63717F-6C21-438B-B556-4FD5C933CCE5} => Firefox.exe hxxp://ui.skype.com/ui/0/7.16.0.102/en/abandoninstall?page=tsProgressBar
              Task: {F3A59D10-47AD-4A35-ACC0-FBDA91E1639C} - System32\Tasks{7A33B700-5810-48F2-9DEB-84DBBFB81049} => pcalua.exe -a C:\Users\goldfish\Desktop\freecol-0.9.5-installer.exe -d C:\Users\goldfish\Desktop
              Task: {F64247EC-2515-4E5B-85EC-1809CF0D7BE7} - System32\Tasks\0915wtUpdateInfo => C:\ProgramData\Avg_Update_0915wt\0915wt
              {B87CCAC6-8764-480D-A2EC-6EEC605C96A9}.exe
              Task: {F87E4381-891C-48AC-B7FB-337A3E3EE276} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCOneClick.exe [2011-02-16] (Sony Corporation)
              C:\ProgramData\Avg_Update_0915wt\0915wt
              {B87CCAC6-8764-480D-A2EC-6EEC605C96A9}.exe
              RemoveProxy:
              CMD: netsh advfirewall reset
              CMD: netsh advfirewall set allprofiles state On
              CMD: ipconfig /flushdns
              reboot:
              end


              Restore point was successfully created.
              Processes closed successfully.
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\MountPoints2{3966f36d-41b6-11e0-8b3f-c44619b2e2e4} => key removed successfully
              HKCR\CLSID{3966f36d-41b6-11e0-8b3f-c44619b2e2e4} => key not found.
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\MountPoints2{cfdc1e4e-78d4-11e0-aa4f-c44619b2e2e4} => key removed successfully
              HKCR\CLSID{cfdc1e4e-78d4-11e0-aa4f-c44619b2e2e4} => key not found.
              HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellIconOverlayIdentifiers\00avg => key removed successfully
              HKCR\CLSID{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
              HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\DhcpNameServer => value removed successfully
              HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}\DhcpNameServer => value removed successfully
              HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{927587AB-1894-493E-8E72-6063314BF69A}\DhcpNameServer => value removed successfully
              HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{EC19D428-B36F-4D8F-B458-DB4400362D30}\DhcpNameServer => value removed successfully
              HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => key removed successfully
              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\Start Page => value restored successfully
              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\Search Page => value restored successfully
              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\Default_Page_URL => value restored successfully
              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\Default_Search_URL => value restored successfully
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000\Software\Microsoft\Internet Explorer\Main\Search Page => value restored successfully
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000\Software\Microsoft\Internet Explorer\Main\Start Page => value restored successfully
              HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\DefaultScope => value restored successfully
              HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key removed successfully
              HKCR\Wow6432Node\CLSID{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key not found.
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\DefaultScope => value removed successfully
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{1686262A-C27D-4A79-8D82-C55F4D8BB35A} => key removed successfully
              HKCR\CLSID{1686262A-C27D-4A79-8D82-C55F4D8BB35A} => key not found.
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{67B4F6F6-DEA2-42F9-84A7-6785674F4D19} => key removed successfully
              HKCR\CLSID{67B4F6F6-DEA2-42F9-84A7-6785674F4D19} => key not found.
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{8FD01E4A-8F30-4C90-8E35-DEF880420C67} => key removed successfully
              HKCR\CLSID{8FD01E4A-8F30-4C90-8E35-DEF880420C67} => key not found.
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{96B8ABCB-AC35-45F0-886C-1C2B912B5FFD} => key removed successfully
              HKCR\CLSID{96B8ABCB-AC35-45F0-886C-1C2B912B5FFD} => key not found.
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{B2EC8D7B-5F99-4D85-94B8-E3BF03379046} => key removed successfully
              HKCR\CLSID{B2EC8D7B-5F99-4D85-94B8-E3BF03379046} => key not found.
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key removed successfully
              HKCR\CLSID{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key not found.
              HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units{17492023-C23A-453E-A040-C7C580BBF700} => key removed successfully
              HKCR\Wow6432Node\CLSID{17492023-C23A-453E-A040-C7C580BBF700} => key not found.
              HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units{76496E5E-244A-424F-B5A5-B677051BD958} => key removed successfully
              HKCR\Wow6432Node\CLSID{76496E5E-244A-424F-B5A5-B677051BD958} => key not found.
              HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units{BEA7310D-06C4-4339-A784-DC3804819809} => key removed successfully
              HKCR\Wow6432Node\CLSID{BEA7310D-06C4-4339-A784-DC3804819809} => key not found.
              HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units{D27CDB6E-AE6D-11CF-96B8-444553540000} => key removed successfully
              HKCR\Wow6432Node\CLSID{D27CDB6E-AE6D-11CF-96B8-444553540000} => key not found.
              HKCR\PROTOCOLS\Handler\linkscanner => key not found.
              HKCR\CLSID{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Handler\osf => key not found.
              HKCR\Wow6432Node\CLSID{D924BDC6-C83A-4BD5-90D0-095128A113D1} => key not found.
              HKCR\PROTOCOLS\Handler\skype-ie-addon-data => key not found.
              HKCR\CLSID{91774881-D725-4E58-B298-07617B9B86A8} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Handler\skype-ie-addon-data => key not found.
              HKCR\Wow6432Node\CLSID{91774881-D725-4E58-B298-07617B9B86A8} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Handler\skype4com => key not found.
              HKCR\Wow6432Node\CLSID{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica => key not found.
              HKCR\Wow6432Node\CLSID{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica; charset=euc-jp => key not found.
              HKCR\Wow6432Node\CLSID{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica; charset=ISO-8859-1 => key not found.
              HKCR\Wow6432Node\CLSID{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica; charset=MS936 => key not found.
              HKCR\Wow6432Node\CLSID{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica; charset=MS949 => key not found.
              HKCR\Wow6432Node\CLSID{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica; charset=MS950 => key not found.
              HKCR\Wow6432Node\CLSID{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica; charset=UTF-8 => key not found.
              HKCR\Wow6432Node\CLSID{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica; charset=UTF8 => key not found.
              HKCR\Wow6432Node\CLSID{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica;charset=euc-jp => key not found.
              HKCR\Wow6432Node\CLSID{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica;charset=ISO-8859-1 => key not found.
              HKCR\Wow6432Node\CLSID{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica;charset=MS936 => key not found.
              HKCR\Wow6432Node\CLSID{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica;charset=MS949 => key not found.
              HKCR\Wow6432Node\CLSID{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica;charset=MS950 => key not found.
              HKCR\Wow6432Node\CLSID{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica;charset=UTF-8 => key not found.
              HKCR\Wow6432Node\CLSID{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica;charset=UTF8 => key not found.
              HKCR\Wow6432Node\CLSID{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Filter\ica => key not found.
              HKCR\Wow6432Node\CLSID{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
              Firefox “homepage” removed successfully
              Firefox SearchEngineOrder.3 removed successfully
              Firefox Proxy settings were reset.
              C:\Users\goldfish\AppData\Roaming\Mozilla\Firefox\ Profiles\fcotwa47.default\Extensions\bingsearch.full@microsoft.com => not found.
              HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensio ns\avg@toolbar => value removed successfully
              C:\Program Files (x86)\mozilla firefox\browser\searchplugins\avg-secure-search.xml => moved successfully
              HKLM\Software\MozillaPlugins@microsoft.com/GENUINE => key removed successfully
              HKLM\Software\Wow6432Node\MozillaPlugins@microsoft.com/GENUINE => key removed successfully
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin => key removed successfully
              C:\Users\goldfish\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll => not found.
              Chrome StartupUrls => removed successfully
              HKLM\SOFTWARE\Google\Chrome\Extensions\flliilndjeo hchalpbbcdekjklbdgfkk => key removed successfully
              HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions \efaidnbmnnnibpcajpcglclefindmkaj => key removed successfully
              HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions \flliilndjeohchalpbbcdekjklbdgfkk => key removed successfully
              HKLM\System\CurrentControlSet\Services\ADExchange => key removed successfully
              ADExchange => service removed successfully
              HKLM\System\CurrentControlSet\Services\HDD & SSD access service => key removed successfully
              HDD & SSD access service => service removed successfully
              HKLM\System\CurrentControlSet\Services\TBS => key removed successfully
              TBS => service removed successfully
              HKLM\System\CurrentControlSet\Services\WMPNetworkS vc => key removed successfully
              WMPNetworkSvc => service removed successfully
              HKLM\System\CurrentControlSet\Services\WsDrvInst => key removed successfully
              WsDrvInst => service removed successfully
              HKLM\System\CurrentControlSet\Services\pccsmcfd => key removed successfully
              pccsmcfd => service removed successfully
              HKLM\System\CurrentControlSet\Services\dbx => key removed successfully
              dbx => service removed successfully
              “C:\Users\goldfish\AppData\Local{C960B433-5DA9-48AB-83A8-605A368C6C7E}” => not found.
              C:\ProgramData\agent.1487621032.bdinstall.bin => moved successfully
              “C:\Users\goldfish\AppData\Roaming\QuickScan” => not found.
              C:\ProgramData\agent.1487617558.bdinstall.bin => moved successfully
              C:\ProgramData\BDLogging => moved successfully
              C:\ProgramData\Bitdefender Agent => moved successfully
              C:\Windows\system32\Drivers\avgsnx.sys.14876779264 2001 => moved successfully
              “C:\Windows\system32\Drivers\avgsnx.sys” => not found.
              C:\ProgramData\Avg => moved successfully
              “C:\Users\goldfish\AppData\Local\AvgSetupLog” => not found.
              “C:\Users\goldfish\AppData\Roaming\AVG” => not found.
              “C:\Users\goldfish\AppData\Local\Avg” => not found.
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services!SASCORE => key removed successfully
              HKLM\System\CurrentControlSet\Services!SASCORE => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\ACDaemon => key removed successfully
              HKLM\System\CurrentControlSet\Services\ACDaemon => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\btwdins => key removed successfully
              HKLM\System\CurrentControlSet\Services\btwdins => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdate => key removed successfully
              HKLM\System\CurrentControlSet\Services\gupdate => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdatem => key removed successfully
              HKLM\System\CurrentControlSet\Services\gupdatem => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\ServiceLayer => key removed successfully
              HKLM\System\CurrentControlSet\Services\ServiceLaye r => key not found.
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\uCamMonitor => key removed successfully
              HKLM\System\CurrentControlSet\Services\uCamMonitor => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Micros oft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => key removed successfully
              C:\Windows\pss\Bluetooth.lnk.CommonStartup => moved successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^goldfish^App Data^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => key not found.
              C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup => moved successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AmazonMP3DownloaderHelpe r => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Apoint => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\ApplePhotoStreams => key not found.
              HKLM\System\CurrentControlSet\Services\ApplePhotoS treams => key not found.
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\APSDaemon => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\avgnt => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BrStsInd00 => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BrStsMon00 => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CCleaner => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CitrixReceiver => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ConnectionCenter => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DriveUtilitiesHelper => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Dropbox => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\iCloudDrive => key not found.
              HKLM\System\CurrentControlSet\Services\iCloudDrive => key not found.
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\iCloudServices => key not found.
              HKLM\System\CurrentControlSet\Services\iCloudServi ces => key not found.
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\iTunesHelper => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSC => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PC Suite Tray => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Redirector => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RtHDVCpl => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SUPERAntiSpyware => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WDAppManager => key removed successfully
              HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Windows Mobile Device Center => key removed successfully
              C:\Windows\system32\Drivers\etc\hosts => moved successfully
              Hosts restored successfully.
              C:\ProgramData\TEMP => “:0B4227B4” ADS removed successfully.
              “C:\ProgramData\TEMP:0B4227B4” => not found.
              C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => moved successfully
              C:\ProgramData\AVG January 2013 Campaign => moved successfully
              C:\Windows\Tasks\Adobe Flash Player Updater.job => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{02BEB9D 0-7890-4F25-AF0D-BF58A97B79E6} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{02BEB9D 0-7890-4F25-AF0D-BF58A97B79E6} => key removed successfully
              C:\Windows\System32\Tasks{12FCE0CC-9445-4AA9-8D95-E4F80F6C6440} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{12FCE0CC-9445-4AA9-8D95-E4F80F6C6440} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{06C6A86 1-269E-4E42-9795-B94F8F690B25} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{06C6A86 1-269E-4E42-9795-B94F8F690B25} => key removed successfully
              C:\Windows\System32\Tasks{2E0B2CC6-E47D-46B5-A5D7-B8DBE4924FFE} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{2E0B2CC6-E47D-46B5-A5D7-B8DBE4924FFE} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{0E36409 2-14AD-4480-B09D-7C5DD704AD73} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{0E36409 2-14AD-4480-B09D-7C5DD704AD73} => key removed successfully
              C:\Windows\System32\Tasks{5A1F6414-9B70-4221-A069-2C3136C8F3BC} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{5A1F6414-9B70-4221-A069-2C3136C8F3BC} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot{0EA45EDA-39CC-4ADB-A6D9-4BAF33D5FA30} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{0EA45ED A-39CC-4ADB-A6D9-4BAF33D5FA30} => key removed successfully
              C:\Windows\System32\Tasks\SONY\VAIO Gate\StartExecuteProxy => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SONY\VAI O Gate\StartExecuteProxy => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{1268C5B A-AB72-49DD-8BEE-AA1346A5E26A} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{1268C5B A-AB72-49DD-8BEE-AA1346A5E26A} => key removed successfully
              C:\Windows\System32\Tasks\SONY\VAIO Power Management\VPM Logon Start => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SONY\VAI O Power Management\VPM Logon Start => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{1ABF940 5-23CC-4197-BE3D-1DAF5349D2AD} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{1ABF940 5-23CC-4197-BE3D-1DAF5349D2AD} => key removed successfully
              C:\Windows\System32\Tasks{2093FCAC-5EB6-4537-A8F9-03FC034783F2} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{2093FCAC-5EB6-4537-A8F9-03FC034783F2} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{1B6F752 7-6051-4588-9CC3-26DBBA3F5906} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{1B6F752 7-6051-4588-9CC3-26DBBA3F5906} => key removed successfully
              C:\Windows\System32\Tasks\SONY\VAIO Gate\VAIO Gate => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SONY\VAI O Gate\VAIO Gate => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{1DFE713 3-E445-4A03-8AC0-F74053E51AD2} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{1DFE713 3-E445-4A03-8AC0-F74053E51AD2} => key removed successfully
              C:\Windows\System32\Tasks\TunnelBear => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\TunnelBe ar => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{2B73086 E-33A6-44C4-87DA-29D189E2786E} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{2B73086 E-33A6-44C4-87DA-29D189E2786E} => key removed successfully
              C:\Windows\System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sony Corporation\VAIO Care\VAIO Care => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{36251C2 B-C530-4941-AF8D-09CCF2332640} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{36251C2 B-C530-4941-AF8D-09CCF2332640} => key removed successfully
              C:\Windows\System32\Tasks\Adobe Flash Player Updater => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{411ABCC 0-9D14-474C-903F-AF8565D5BC4B} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{411ABCC 0-9D14-474C-903F-AF8565D5BC4B} => key removed successfully
              C:\Windows\System32\Tasks\Sony Corporation\VAIO Update\VAIO Update 5 => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sony Corporation\VAIO Update\VAIO Update 5 => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{47B7819 F-92DD-43AC-9FF0-5CBB64863D3C} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{47B7819 F-92DD-43AC-9FF0-5CBB64863D3C} => key removed successfully
              C:\Windows\System32\Tasks{96C12997-A4BC-4A31-982B-4770E5B9F850} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{96C12997-A4BC-4A31-982B-4770E5B9F850} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{5221FD5 3-7E3D-4540-84E1-5FE536E23F55} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{5221FD5 3-7E3D-4540-84E1-5FE536E23F55} => key removed successfully
              C:\Windows\System32\Tasks{E2A5F6B9-C55D-4083-94E2-C7D27EDDC5EE} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{E2A5F6B9-C55D-4083-94E2-C7D27EDDC5EE} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{5C46E2A 4-DEB2-414F-A340-38C9780099FC} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{5C46E2A 4-DEB2-414F-A340-38C9780099FC} => key removed successfully
              C:\Windows\System32\Tasks{9C2AC3BE-3FFF-46A1-A323-14AB69C2DAB0} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{9C2AC3BE-3FFF-46A1-A323-14AB69C2DAB0} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{6512F9B C-6D3C-470B-8BA9-43E008628A6E} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{6512F9B C-6D3C-470B-8BA9-43E008628A6E} => key removed successfully
              C:\Windows\System32\Tasks{9A2D62CF-9308-4BCD-AE33-79916B90C09B} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{9A2D62CF-9308-4BCD-AE33-79916B90C09B} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{70557BF 9-78EC-4476-A384-73A5E50B6AF7} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{70557BF 9-78EC-4476-A384-73A5E50B6AF7} => key removed successfully
              C:\Windows\System32\Tasks\GoogleUpdateTaskMachineU A => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUp dateTaskMachineUA => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{768AD43 1-53A2-4F5A-BC74-932F41B28F00} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{768AD43 1-53A2-4F5A-BC74-932F41B28F00} => key removed successfully
              C:\Windows\System32\Tasks{93FCEB53-8810-4B44-9077-E63EEC818449} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{93FCEB53-8810-4B44-9077-E63EEC818449} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{91F065E A-BDE3-4099-89D8-B581A51BD4FA} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{91F065E A-BDE3-4099-89D8-B581A51BD4FA} => key removed successfully
              C:\Windows\System32\Tasks{926AC40F-1299-447B-AEF6-54EFD36B56DA} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{926AC40F-1299-447B-AEF6-54EFD36B56DA} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{9DC9BC2 0-0D4B-4598-9C66-0F592842E6DB} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{9DC9BC2 0-0D4B-4598-9C66-0F592842E6DB} => key removed successfully
              C:\Windows\System32\Tasks{92A54289-B4FD-4AED-801A-802259F7E495} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{92A54289-B4FD-4AED-801A-802259F7E495} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{A324975 A-EFC0-454C-8124-7A26F20C9E52} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{A324975 A-EFC0-454C-8124-7A26F20C9E52} => key removed successfully
              C:\Windows\System32\Tasks\SONY\SUS-BCF\Level4Daily => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SONY\SUS-BCF\Level4Daily => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{A69AFC5 B-57F5-4600-A5F6-F777C0CF3DF1} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{A69AFC5 B-57F5-4600-A5F6-F777C0CF3DF1} => key removed successfully
              C:\Windows\System32\Tasks{97EC3147-E1A9-4701-B32D-CE6CD97B78EC} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{97EC3147-E1A9-4701-B32D-CE6CD97B78EC} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{B1DF458 5-6B0E-49E9-B6F3-5BE3466BF754} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{B1DF458 5-6B0E-49E9-B6F3-5BE3466BF754} => key removed successfully
              C:\Windows\System32\Tasks\Adobe Acrobat Update Task => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Acrobat Update Task => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{B1E5F86 3-1AEB-49C1-812E-B8527F2CCA92} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{B1E5F86 3-1AEB-49C1-812E-B8527F2CCA92} => key removed successfully
              C:\Windows\System32\Tasks\GoogleUpdateTaskMachineC ore => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUp dateTaskMachineCore => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{B33446C 5-DD85-45C5-ADA6-44C81406E9FC} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{B33446C 5-DD85-45C5-ADA6-44C81406E9FC} => key removed successfully
              C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsof t\Windows\Media Center\mcupdate_scheduled => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{C956B96 2-51DE-45C7-A315-B1146AEB98A1} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{C956B96 2-51DE-45C7-A315-B1146AEB98A1} => key removed successfully
              C:\Windows\System32\Tasks{E1FE020E-4198-444A-883E-2A2DF6C27E01} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{E1FE020E-4198-444A-883E-2A2DF6C27E01} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{CB60D4A 6-73F1-4DA8-9A34-05310F59783E} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{CB60D4A 6-73F1-4DA8-9A34-05310F59783E} => key removed successfully
              C:\Windows\System32\Tasks\Sony Corporation\VAIO Update\Launch Application => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sony Corporation\VAIO Update\Launch Application => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{CE92864 6-2D82-4350-8674-BCB03E35528E} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{CE92864 6-2D82-4350-8674-BCB03E35528E} => key removed successfully
              C:\Windows\System32\Tasks{81432782-934F-47AD-9717-49765EBAB508} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{81432782-934F-47AD-9717-49765EBAB508} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{D7D6F1E F-7E7F-4AE7-8533-2937A6126C0B} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{D7D6F1E F-7E7F-4AE7-8533-2937A6126C0B} => key removed successfully
              C:\Windows\System32\Tasks\ROC_REG_JAN_DELETE => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ROC_REG_ JAN_DELETE => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{DCFC64A 1-29B0-4A44-AAA4-B2237C97138D} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{DCFC64A 1-29B0-4A44-AAA4-B2237C97138D} => key removed successfully
              C:\Windows\System32\Tasks{D35BEE58-0154-4836-AE23-AA6300E98B3B} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{D35BEE58-0154-4836-AE23-AA6300E98B3B} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{DDC020A 3-0340-45AD-8E21-A677F2C9B4F9} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{DDC020A 3-0340-45AD-8E21-A677F2C9B4F9} => key removed successfully
              C:\Windows\System32\Tasks\Games\UpdateCheck_S-1-5-21-928801702-3077407482-3869533313-1000 => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Games\Up dateCheck_S-1-5-21-928801702-3077407482-3869533313-1000 => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{DE506D7 8-8716-41A5-A982-BBD96130BB2C} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{DE506D7 8-8716-41A5-A982-BBD96130BB2C} => key removed successfully
              C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\StartRecording => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsof t\Windows\Media Center\StartRecording => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{E10E381 B-C0E3-481C-98BA-A7E64260B292} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{E10E381 B-C0E3-481C-98BA-A7E64260B292} => key removed successfully
              C:\Windows\System32\Tasks{CE7BA935-73B5-4BD7-9385-01F9719511C3} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{CE7BA935-73B5-4BD7-9385-01F9719511C3} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{EF84072 4-63CF-4693-A308-CB19C44B02DE} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{EF84072 4-63CF-4693-A308-CB19C44B02DE} => key removed successfully
              C:\Windows\System32\Tasks{4B63717F-6C21-438B-B556-4FD5C933CCE5} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{4B63717F-6C21-438B-B556-4FD5C933CCE5} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{F3A59D1 0-47AD-4A35-ACC0-FBDA91E1639C} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{F3A59D1 0-47AD-4A35-ACC0-FBDA91E1639C} => key removed successfully
              C:\Windows\System32\Tasks{7A33B700-5810-48F2-9DEB-84DBBFB81049} => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree{7A33B700-5810-48F2-9DEB-84DBBFB81049} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{F64247E C-2515-4E5B-85EC-1809CF0D7BE7} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{F64247E C-2515-4E5B-85EC-1809CF0D7BE7} => key removed successfully
              C:\Windows\System32\Tasks\0915wtUpdateInfo => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\0915wtUp dateInfo => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{F87E438 1-891C-48AC-B7FB-337A3E3EE276} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{F87E438 1-891C-48AC-B7FB-337A3E3EE276} => key removed successfully
              C:\Windows\System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => moved successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sony Corporation\VAIO Care\VCOneClick => key removed successfully
              “C:\ProgramData\Avg_Update_0915wt\0915wt_{B87CCAC6-8764-480D-A2EC-6EEC605C96A9}.exe” => not found.

              ========= RemoveProxy: =========

              HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVers ion\Internet Settings\Connections\DefaultConnectionSettings => value removed successfully
              HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVers ion\Internet Settings\Connections\SavedLegacySettings => value removed successfully
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings\Connections\DefaultConnectionSettings => value removed successfully
              HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings\Connections\SavedLegacySettings => value removed successfully

              ========= End of RemoveProxy: =========

              ========= netsh advfirewall reset =========

              Ok.

              ========= End of CMD: =========

              ========= netsh advfirewall set allprofiles state On =========

              Ok.

              ========= End of CMD: =========

              ========= ipconfig /flushdns =========

              Windows IP Configuration

              Successfully flushed the DNS Resolver Cache.

              ========= End of CMD: =========

              =========== EmptyTemp: ==========

              BITS transfer queue => 8388608 B
              DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 4751748 B
              Java, Flash, Steam htmlcache => 523 B
              Windows/system/drivers => 3072070 B
              Edge => 0 B
              Chrome => 82128751 B
              Firefox => 70352562 B
              Opera => 0 B

              Temp, IE cache, history, cookies, recent:
              Users => 0 B
              Default => 66228 B
              Public => 0 B
              ProgramData => 0 B
              systemprofile => 157729 B
              systemprofile32 => 90203 B
              LocalService => 99476 B
              NetworkService => 48997044 B
              goldfish => 26233878 B

              RecycleBin => 0 B
              EmptyTemp: => 233 MB temporary data Removed.

              ================================

              The system needed a reboot.

              ==== End of Fixlog 10:26:50 ====

              ================================================== ==================================

              ClearLNK by Alex Dragokas ver. 2.9.0.11

              OS: x64 Windows 7 Home Premium, 6.1.7601, Service Pack: 1
              Time: 05.03.2017 - 10:34
              Language: OS: EN (0x409). Display: EN (0x409). Non-Unicode: en-GB (0x809)
              Elevated: Yes
              User: goldfish (group: Administrator)

              _____________________________ Begin of Log ______________________________
              .
              [SKIP] 1 “C:\Windows\pss\Bluetooth.lnk” (shortcut was not found)
              [SKIP] 2 “C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk” (shortcut was not found)
              [SKIP] 3 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk” (shortcut was not found)
              [SKIP] 4 “C:\Windows\pss\Bluetooth.lnk” (shortcut was not found)
              [SKIP] 5 “C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk” (shortcut was not found)
              .
              ______________________________ Statistics _______________________________
              Cure ran per today: 1 times.

              Total processed: 5
              Code:
                   Omitted:   5
              ______________________________ End of Log _______________________________CRC32: C9EFE33B

              ================================================== ==================================

              [ATTACH]1754[/ATTACH]

              [ATTACH]1755[/ATTACH]
              Message after Windows restarts:

              Problem signature:
              Problem Event Name: BlueScreen
              OS Version: 6.1.7601.2.1.0.768.3
              Locale ID: 2057

              Additional information about the problem:
              BCCode: 50
              BCP1: FFFFFA8019F82DA0
              BCP2: 0000000000000001
              BCP3: FFFFF880045E3CE0
              BCP4: 0000000000000002
              OS Version: 6_1_7601
              Service Pack: 1_0
              Product: 768_1

              Files that help describe the problem:
              C:\Windows\Minidump\030517-23103-01.dmp
              C:\Users\goldfish\AppData\Local\Temp\WER-133505-0.sysdata.xml

              Read our privacy statement online:
              Windows 7 Privacy Statement

              If the online privacy statement is not available, please read our privacy statement offline:
              C:\Windows\system32\en-US\erofflps.txt

              Comment

              • Goldfish
                PCHF Member
                • Mar 2017
                • 26

                #22
                There had been zero threats found by RogueKiller at the point that the laptop bluescreened, which was 1 - 1.5 hours into the scan.

                Also, since running the above tools I get this error when I open Google Chrome. Maybe it’s because I replaced my actual name with “goldfish” in the logs? Or maybe the OS is not correctly set (this is the data that chrome requests to send when the error is generated).

                [ATTACH]1758[/ATTACH]

                [ATTACH]1757[/ATTACH]

                Comment

                • Malnutrition
                  PCHF Moderator
                  • Jul 2016
                  • 7041

                  #23
                  Back up your chrome data and clean install it.
                  Remove it Geek Uninstaller.
                  Reboot your machine.
                  Grab a new copy of Chrome from here.

                  ZHP Diag Scan

                  Download ZHP Diag to your desktop.
                  1. Right Click Run as Admin.
                    2. Click the Scanner button.



                  When complete please push the report button.
                  A notepad will open… copy and paste the report in your next reply.

                  Comment

                  • Malnutrition
                    PCHF Moderator
                    • Jul 2016
                    • 7041

                    #24
                    Analyze the minidump below here, and then copy paste the results for me. Also upload it so our experts can analyze it.

                    Find the file below with the everything search engine portable version, drag it to your desktop.

                    C:\Windows\Minidump\030517-23103-01.dmp

                    Click here to analyze the dump file.

                    Comment

                    • Goldfish
                      PCHF Member
                      • Mar 2017
                      • 26

                      #25
                      The Ninite installer froze partway through and wouldn’t cancel either, but it seems to have installed okay (and no error when I log in).

                      The ZHPDiag log is below.

                      The file C:\Windows\Minidump\030517-23103-01.dmp
                      is not found with everything, and when I manually go to the directory using Windows Explorer it is empty. This happened when I had the error previously too - couldn’t find the file.

                      [ATTACH]1764[/ATTACH]

                      ================================================== ==================================


                      ~ ZHPDiag v2017.3.4.39 By Nicolas Coolman (2017/03/04)
                      [/quote]


                      ~ Run by goldfish (Administrator) (2017/03/05 18:31:05)
                      ~ Web: https://www.nicolascoolman.com
                      ~ Blog: https://nicolascoolman.eu/
                      ~ Facebook: ZHP
                      ~ State version: Version OK
                      ~ Mode: Scan
                      ~ Report: C:\Users\goldfish\Desktop\ZHPDiag.txt
                      ~ Report: C:\Users\goldfish\AppData\Roaming\ZHP\ZHPDiag.txt
                      ~ UAC: Activate
                      ~ System startup: Normal (Normal boot)
                      Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601) =>.Microsoft Corporation

                      —\ Internet Browsers (2) - 1s
                      ~ MSIE: Internet Explorer v11.0.9600.18537
                      ~ OBIE: Avira Scout v17.1.2924.2344

                      —\ Windows Product Information (4) - 3s
                      ~ Windows Server License Manager Script : OK
                      ~ Licence Script File Génération : OK
                      Windows Automatic Updates : OK
                      Windows Activation Technologies : OK

                      —\ System protection software (1) - 11s
                      Avira Antivirus v15.0.25.154 (Protection)

                      —\ Surveillance software (2) - 15s
                      ~ Adobe Flash Player 24 NPAPI (Surveillance)
                      ~ Adobe Acrobat Reader DC (Surveillance)

                      —\ Information on the system (6) - 0s
                      ~ Operating System: Intel64 Family 6 Model 37 Stepping 5, GenuineIntel
                      ~ Operating System: 64-bit
                      ~ Boot mode: Normal (Normal boot)
                      Total RAM: 6142.052 MB (67% free) : OK =>.RAM Value
                      System Restore: Activé (Enable)
                      System drive C: has 180 GB (38%) free of 464 GB : OK =>.Disk Space

                      —\ Connection to the system mode (3) - 0s
                      ~ Computer Name: goldfish-VAIO
                      ~ User Name: goldfish
                      ~ Logged in as Administrator

                      —\ Enumeration of the disk units (1) - 0s
                      ~ Drive C: has 180 GB free of 464 GB (System)

                      —\ State of the Windows Security Center (11) - 0s
                      [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
                      [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
                      [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
                      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Pol icies\Explorer] NoActiveDesktopChanges: Modified
                      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\system] EnableLUA: OK
                      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
                      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
                      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Associations] Application: OK
                      [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
                      [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
                      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Win dowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

                      —\ Search Generic System Files (24) - 2s
                      [MD5.38AE1B3C38FAEF56FE4907922F0385BA] - 29/08/2016 - (.Microsoft Corporation - Windows Explorer.) – C:\Windows\Explorer.exe [3229696] =>.Microsoft Corporation
                      [MD5.DD81D91FF3B0763C392422865C9AC12E] - 14/07/2009 - (.Microsoft Corporation - Windows host process (Rundll32).) – C:\Windows\System32\rundll32.exe [45568] =>.Microsoft Corporation
                      [MD5.94355C28C1970635A31B3FE52EB7CEBA] - 14/07/2009 - (.Microsoft Corporation - Windows Start-Up Application.) – C:\Windows\System32\Wininit.exe [129024] =>.Microsoft Corporation
                      [MD5.105954F9BEAD700A6DF4B5B489FCCB4B] - 12/11/2016 - (.Microsoft Corporation - Internet Extensions for Win32.) – C:\Windows\System32\wininet.dll [2920960] =>.Microsoft Corporation
                      [MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - 17/07/2014 - (.Microsoft Corporation - Windows Logon Application.) – C:\Windows\System32\Winlogon.exe [455168] =>.Microsoft Corporation
                      [MD5.067FA52BFB59A56110A12312EF9AF243] - 20/11/2010 - (.Microsoft Corporation - Software Licensing Library.) – C:\Windows\System32\sppcomapi.dll [232448] =>.Microsoft Corporation
                      [MD5.492D07D79E7024CA310867B526D9636D] - 03/03/2011 - (.Microsoft Corporation - DNS Client API DLL.) – C:\Windows\System32\dnsapi.dll [357888] =>.Microsoft Corporation
                      [MD5.B40420876B9288E0A1C8CCA8A84E5DC9] - 03/03/2011 - (.Microsoft Corporation - DNS Client API DLL.) – C:\Windows\Syswow64\dnsapi.dll [270336] =>.Microsoft Corporation
                      [MD5.9A4A1EEE802BF2F878EE8EAB407B21B7] - 13/10/2015 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) – C:\Windows\System32\drivers\AFD.sys [497664] =>.Microsoft Corporation
                      [MD5.02062C0B390B7729EDC9E69C680A6F3C] - 14/07/2009 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) – C:\Windows\System32\drivers\atapi.sys [24128] =>.Microsoft Windows®
                      [MD5.B8BD2BB284668C84865658C77574381A] - 13/07/2009 - (.Microsoft Corporation - CD-ROM File System Driver.) – C:\Windows\System32\drivers\Cdfs.sys [92160] =>.Microsoft Corporation
                      [MD5.F036CE71586E93D94DAB220D7BDF4416] - 20/11/2010 - (.Microsoft Corporation - SCSI CD-ROM Driver.) – C:\Windows\System32\drivers\Cdrom.sys [147456] =>.Microsoft Corporation
                      [MD5.9B38580063D281A99E68EF5813022A5F] - 08/09/2016 - (.Microsoft Corporation - DFS Namespace Client Driver.) – C:\Windows\System32\drivers\DfsC.sys [106496] =>.Microsoft Corporation
                      [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - 20/11/2010 - (.Microsoft Corporation - High Definition Audio Bus Driver.) – C:\Windows\System32\drivers\HDAudBus.sys [122368] =>.Microsoft Corporation
                      [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - 13/07/2009 - (.Microsoft Corporation - i8042 Port Driver.) – C:\Windows\System32\drivers\i8042prt.sys [105472] =>.Microsoft Corporation
                      [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - 14/07/2009 - (.Microsoft Corporation - IP Network Address Translator.) – C:\Windows\System32\drivers\IpNat.sys [116224] =>.Microsoft Corporation
                      [MD5.632E8A00090E4F85F304E152C92C7F2C] - 05/01/2017 - (.Microsoft Corporation - Windows NT SMB Minirdr.) – C:\Windows\System32\drivers\MRxSmb.sys [159744] =>.Microsoft Corporation
                      [MD5.E47D571FEC2C76E867935109AB2A770C] - 11/05/2016 - (.Microsoft Corporation - MBT Transport driver.) – C:\Windows\System32\drivers\netBT.sys [262144] =>.Microsoft Corporation
                      [MD5.47B2D0B31BDC3EBE6090228E2BA3764D] - 11/01/2016 - (.Microsoft Corporation - NT File System Driver.) – C:\Windows\System32\drivers\ntfs.sys [1684416] =>.Microsoft Windows®
                      [MD5.0086431C29C35BE1DBC43F52CC273887] - 14/07/2009 - (.Microsoft Corporation - Parallel Port Driver.) – C:\Windows\System32\drivers\Parport.sys [97280] =>.Microsoft Corporation
                      [MD5.471815800AE33E6F1C32FB1B97C490CA] - 20/11/2010 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) – C:\Windows\System32\drivers\Rasl2tp.sys [129536] =>.Microsoft Corporation
                      [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - 14/07/2009 - (.Microsoft Corporation - SMB Transport driver.) – C:\Windows\System32\drivers\smb.sys [93184] =>.Microsoft Corporation
                      [MD5.AA77EB517D2F07A947294F260E3ACA83] - 13/10/2015 - (.Microsoft Corporation - TDI Translation Driver.) – C:\Windows\System32\drivers\tdx.sys [118272] =>.Microsoft Corporation
                      [MD5.0D08D2F3B3FF84E433346669B5E0F639] - 20/11/2010 - (.Microsoft Corporation - Volume Shadow Copy Driver.) – C:\Windows\System32\drivers\volsnap.sys [295808] =>.Microsoft Windows®

                      —\ Non Microsoft non disabled Windows Services (45) - 6s
                      O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
                      O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated - Adobe® Flash® Player Update Service 24.0 r0.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpda teService.exe =>.Adobe Systems Incorporated®
                      O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\system32\atiesrxx.exe =>.AMD
                      O23 - Service: Avira Mail Protection (AntiVirMailService) . (.Avira Operations GmbH & Co. KG - Antivirus MailScanner WFP Service.) - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe =>.Avira Operations GmbH & Co. KG®
                      O23 - Service: Avira Scheduler (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - C:\Program Files (x86)\Avira\Antivirus\sched.exe =>.Avira Operations GmbH & Co. KG®
                      O23 - Service: Avira Real-Time Protection (AntiVirService) . (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - C:\Program Files (x86)\Avira\Antivirus\avguard.exe =>.Avira Operations GmbH & Co. KG®
                      O23 - Service: Avira Web Protection (AntiVirWebService) . (.Avira Operations GmbH & Co. KG - AntiVir WebGuard WFP Service.) - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe =>.Avira Operations GmbH & Co. KG®
                      O23 - Service: Apple Mobile Device Service (Apple Mobile Device Service) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe =>.Apple Inc.®
                      O23 - Service: ATPL Digital v6 update service (ATPLupd) . (…) - C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\updatescripts\srvany.exe
                      O23 - Service: Avira Service Host (Avira.ServiceHost) . (.Avira Operations GmbH & Co. KG - Avira Service Host.) - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe =>.Avira Operations GmbH & Co. KG®
                      O23 - Service: Avira Phantom VPN (AviraPhantomVPN) . (.Avira Operations GmbH & Co. KG - Avira.VpnService.) - C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe =>.Avira Operations GmbH & Co. KG®
                      O23 - Service: BGS (BGS) . (.Apache Software Foundation - Apache HTTP Server.) - C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\bin\Apache.exe =>.Apache Software Foundation
                      O23 - Service: Bonjour Service (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.®
                      O23 - Service: BrYNSvc (BrYNSvc) . (.Brother Industries, Ltd. - BrYNCSvc.) - C:\Program Files (x86)\Browny02\BrYNSvc.exe =>.Brother Industries, Ltd.
                      O23 - Service: Dropbox Update Service (dbupdate) (dbupdate) . (.Dropbox, Inc. - Dropbox Update.) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe =>.Dropbox, Inc®
                      O23 - Service: Dropbox Update Service (dbupdatem) (dbupdatem) . (.Dropbox, Inc. - Dropbox Update.) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe =>.Dropbox, Inc®
                      O23 - Service: DbxSvc (DbxSvc) . (.Dropbox, Inc. - Dropbox Service.) - C:\Windows\system32\DbxSvc.exe =>.Dropbox, Inc.
                      O23 - Service: FLEXnet Licensing Service (FLEXnet Licensing Service) . (.Flexera Software, Inc. - Activation Licensing Service.) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe =>.Flexera Software, Inc. ®
                      O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation - IAStorDataSvc.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe =>.Intel Corporation®
                      O23 - Service: InstallDriver Table Manager (IDriverT) . (.Macrovision Corporation - IDriverT Module.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe =>.Macrovision Corporation
                      O23 - Service: iPod Service (iPod Service) . (.Apple Inc. - iPodService Module (64-bit).) - C:\Program Files\iPod\bin\iPodService.exe =>.Apple Inc.®
                      O23 - Service: IviRegMgr (IviRegMgr) . (.InterVideo - RegMgr Module.) - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe =>.Intervideo, Inc.®
                      O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation®
                      O23 - Service: Maxtor Service (Maxtor Sync Service) . (.Seagate Technology LLC - Sync Windows Services.) - C:\Program Files (x86)\Maxtor\Sync\SyncServices.exe {25B1DD7CD102F294C6B4A039166590E7} =>.Seagate Technology LLC
                      O23 - Service: PMBDeviceInfoProvider (PMBDeviceInfoProvider) . (.Sony Corporation - Device Information Provider.) - C:\Program Files (x86)\SONY\PMB\PMBDeviceInfoProvider.exe =>.Sony Corporation®
                      O23 - Service: Protexis Licensing V2 (PSI_SVC_2) . (.Protexis Inc. - PsiService PsiService.) - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe =>.Protexis Inc.®
                      O23 - Service: Roxio UPnP Renderer 10 (Roxio UPnP Renderer 10) . (.Sonic Solutions - Roxio UPnP PRenderer Service.) - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe =>.Sonic Solutions®
                      O23 - Service: Roxio Upnp Server 10 (Roxio Upnp Server 10) . (.Sonic Solutions - RoxioUpnpService10 Module.) - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe =>.Sonic Solutions®
                      O23 - Service: VAIO Care Performance Service (SampleCollector) . (.Sony Corporation - VAIO Care Performance Service.) - C:\Program Files\Sony\VAIO Care\VCPerfService.exe =>.Sony Corporation of America®
                      O23 - Service: Scout Update Service (scupdate) (scupdate) . (.Avira Operations GmbH & Co. KG - Avira Scout Update.) - C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe =>.Avira Operations GmbH & Co. KG®
                      O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl®
                      O23 - Service: VAIO Media plus Content Importer (SOHCImp) . (.Sony Corporation - VAIO Media plus Content Importer.) - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe =>.Sony Corporation®
                      O23 - Service: VAIO Media plus Digital Media Server (SOHDms) . (.Sony Corporation - VAIO Media plus Digital Media Server.) - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe =>.Sony Corporation®
                      O23 - Service: VAIO Media plus Device Searcher (SOHDs) . (.Sony Corporation - VAIO Media plus Device Searcher.) - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe =>.Sony Corporation®
                      O23 - Service: VAIO Entertainment Common Service (SpfService) . (.Sony Corporation - VAIO Entertainment Common Service.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe =>.Sony Corporation®
                      O23 - Service: Intel(R) Management & Security Application User Notificatio (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe =>.Intel Corporation®
                      O23 - Service: VAIO Entertainment TV Device Arbitration Service (VAIO Entertainment TV Device Arbitration Service) . (.Sony Corporation - Hardware Resource Manager.) - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResou rceManager\VzHardwareResourceManager.exe =>.Sony Corporation®
                      O23 - Service: VAIO Event Service (VAIO Event Service) . (.Sony Corporation - VAIO Event Service (Service Module).) - C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe =>.Sony Corporation®
                      O23 - Service: VAIO Content Folder Watcher (VCFw) . (.Sony Corporation - VAIO Content Folder Watcher.) - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe =>.Sony Corporation®
                      O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) . (.Sony Corporation - VcmXml Helper Interface.) - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe =>.Sony Corporation®
                      O23 - Service: VCService (VCService) . (.Sony Corporation - VAIOCare.) - C:\Program Files\Sony\VAIO Care\VCService.exe =>.Sony Corporation®
                      O23 - Service: VSNService (VSNService) . (.Sony Corporation - VAIO Smart Network Service.) - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe =>.Sony Corporation
                      O23 - Service: VUAgent (VUAgent) . (.Sony Corporation - VUAgent.exe.) - C:\Program Files\Sony\VAIO Update Common\VUAgent.exe =>.Sony Corporation®
                      O23 - Service: WD Drive Manager (WDDriveService) . (.Western Digital Technologies, Inc. - WD Drive Service.) - C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe =>.Western Digital Technologies, Inc.®
                      O23 - Service: Wondershare Application Framework Service (WsAppService) . (.Wondershare - Wondershare AppService.) - C:\Program Files (x86)\Wondershare\WAF\2.3.0.5\WsAppService.exe =>.Wondershare

                      —\ Services not Microsoft (SR=Run, SS=Stop) (50) - 48s
                      SR - Auto [19/12/2016] [ 82640] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
                      SS - Auto [15/02/2017] [ 270936] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpda teService.exe =>.Adobe Systems Incorporated®
                      SR - Auto [08/10/2010] [ 202752] (AMD External Events Utility) . (.AMD.) - C:\Windows\system32\atiesrxx.exe =>.AMD
                      SS - Auto [15/02/2017] [ 1115552] Avira Mail Protection (AntiVirMailService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe =>.Avira Operations GmbH & Co. KG®
                      SR - Auto [15/02/2017] [ 487424] Avira Scheduler (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Antivirus\sched.exe =>.Avira Operations GmbH & Co. KG®
                      SR - Auto [15/02/2017] [ 487424] Avira Real-Time Protection (AntiVirService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Antivirus\avguard.exe =>.Avira Operations GmbH & Co. KG®
                      SS - Auto [15/02/2017] [ 1519144] Avira Web Protection (AntiVirWebService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe =>.Avira Operations GmbH & Co. KG®
                      SR - Auto [22/09/2016] [ 83768] Apple Mobile Device Service (Apple Mobile Device Service) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe =>.Apple Inc.®
                      SR - Auto [18/04/2003] [ 8192] ATPL Digital v6 update service (ATPLupd) . (…) - C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\updatescripts\srvany.exe
                      SR - Auto [29/12/2016] [ 372272] Avira Service Host (Avira.ServiceHost) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe =>.Avira Operations GmbH & Co. KG®
                      SS - Auto [10/02/2017] [ 310152] Avira Phantom VPN (AviraPhantomVPN) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe =>.Avira Operations GmbH & Co. KG®
                      SR - Auto [18/10/2010] [ 20550] BGS (BGS) . (.Apache Software Foundation.) - C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\bin\Apache.exe =>.Apache Software Foundation
                      SR - Auto [12/08/2015] [ 462096] Bonjour Service (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.®
                      SR - Auto [26/10/2012] [ 282112] BrYNSvc (BrYNSvc) . (.Brother Industries, Ltd..) - C:\Program Files (x86)\Browny02\BrYNSvc.exe =>.Brother Industries, Ltd.
                      SS - Auto [22/02/2017] [ 143144] Dropbox Update Service (dbupdate) (dbupdate) . (.Dropbox, Inc..) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe =>.Dropbox, Inc®
                      SS - Auto [22/02/2017] [ 143144] Dropbox Update Service (dbupdatem) (dbupdatem) . (.Dropbox, Inc..) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe =>.Dropbox, Inc®
                      SR - Auto [09/02/2017] [ 46408] DbxSvc (DbxSvc) . (.Dropbox, Inc..) - C:\Windows\system32\DbxSvc.exe =>.Dropbox, Inc®
                      SR - Auto [13/03/2016] [ 1044816] FLEXnet Licensing Service (FLEXnet Licensing Service) . (.Flexera Software, Inc..) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe =>.Flexera Software, Inc. ®
                      SR - Auto [20/11/2009] [ 13336] Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe =>.Intel Corporation®
                      SR - Auto [03/04/2005] [ 69632] InstallDriver Table Manager (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe =>.Macrovision Corporation
                      SR - Auto [19/01/2017] [ 651576] iPod Service (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe =>.Apple Inc.®
                      SR - Auto [04/01/2007] [ 112152] IviRegMgr (IviRegMgr) . (.InterVideo.) - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe =>.Intervideo, Inc.®
                      SR - Auto [14/12/2009] [ 268824] Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation®
                      SR - Auto [28/09/2007] [ 156976] Maxtor Service (Maxtor Sync Service) . (.Seagate Technology LLC.) - C:\Program Files (x86)\Maxtor\Sync\SyncServices.exe {25B1DD7CD102F294C6B4A039166590E7} =>.Seagate Technology LLC
                      SS - Demand [20/01/2017] [ 4355024] Malwarebytes Service (MBAMService) . (.Malwarebytes.) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation®
                      SR - Auto [24/10/2009] [ 360224] PMBDeviceInfoProvider (PMBDeviceInfoProvider) . (.Sony Corporation.) - C:\Program Files (x86)\SONY\PMB\PMBDeviceInfoProvider.exe =>.Sony Corporation®
                      SR - Auto [24/07/2007] [ 185632] Protexis Licensing V2 (PSI_SVC_2) . (.Protexis Inc..) - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe =>.Protexis Inc.®
                      SS - Auto [31/08/2009] [ 313840] Roxio UPnP Renderer 10 (Roxio UPnP Renderer 10) . (.Sonic Solutions.) - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe =>.Sonic Solutions®
                      SS - Auto [31/08/2009] [ 362992] Roxio Upnp Server 10 (Roxio Upnp Server 10) . (.Sonic Solutions.) - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe =>.Sonic Solutions®
                      SR - Auto [29/01/2011] [ 259192] VAIO Care Performance Service (SampleCollector) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Care\VCPerfService.exe =>.Sony Corporation of America®
                      SS - Auto [21/02/2017] [ 116312] Scout Update Service (scupdate) (scupdate) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe =>.Avira Operations GmbH & Co. KG®
                      SS - Demand [21/02/2017] [ 116312] Scout Update Service (scupdatem) (scupdatem) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe =>.Avira Operations GmbH & Co. KG®
                      SS - Auto [16/01/2017] [ 317400] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl®
                      SR - Auto [16/01/2017] [ 317400] VAIO Media plus Content Importer (SOHCImp) . (.Sony Corporation.) - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe =>.Sony Corporation®
                      SR - Auto [16/01/2017] [ 317400] VAIO Media plus Digital Media Server (SOHDms) . (.Sony Corporation.) - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe =>.Sony Corporation®
                      SR - Auto [16/01/2017] [ 317400] VAIO Media plus Device Searcher (SOHDs) . (.Sony Corporation.) - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe =>.Sony Corporation®
                      SR - Auto [16/01/2017] [ 317400] VAIO Entertainment Common Service (SpfService) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe =>.Sony Corporation®
                      SR - Auto [16/01/2017] [ 317400] Intel(R) Management & Security Application User Notificatio (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe =>.Intel Corporation®
                      SR - Auto [16/01/2017] [ 317400] VAIO Entertainment TV Device Arbitration Service (VAIO Entertainment TV Device Arbitration Service) . (.Sony Corporation.) - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResou rceManager\VzHardwareResourceManager.exe =>.Sony Corporation®
                      SR - Auto [16/01/2017] [ 317400] VAIO Event Service (VAIO Event Service) . (.Sony Corporation.) - C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe =>.Sony Corporation®
                      SS - Demand [16/01/2017] [ 317400] VAIO Power Management (VAIO Power Management) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Power Management\SPMService.exe =>.Sony Corporation®
                      SR - Auto [16/01/2017] [ 317400] VAIO Content Folder Watcher (VCFw) . (.Sony Corporation.) - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe =>.Sony Corporation®
                      SR - Demand [16/01/2017] [ 317400] VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) . (.Sony Corporation.) - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe =>.Sony Corporation®
                      SS - Demand [16/01/2017] [ 317400] VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) . (.Sony Corporation.) - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe =>.Sony Corporation®
                      SR - Auto [16/01/2017] [ 317400] VAIO Content Metadata XML Interface (VcmXmlIfHelper) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe =>.Sony Corporation®
                      SR - Auto [16/01/2017] [ 317400] VCService (VCService) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Care\VCService.exe =>.Sony Corporation®
                      SR - Auto [16/01/2017] [ 317400] VSNService (VSNService) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe =>.Sony Corporation
                      SR - Auto [16/01/2017] [ 317400] VUAgent (VUAgent) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Update Common\VUAgent.exe =>.Sony Corporation®
                      SR - Auto [16/01/2017] [ 317400] WD Drive Manager (WDDriveService) . (.Western Digital Technologies, Inc..) - C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe =>.Western Digital Technologies, Inc.®
                      SR - Auto [16/01/2017] [ 317400] Wondershare Application Framework Service (WsAppService) . (.Wondershare.) - C:\Program Files (x86)\Wondershare\WAF\2.3.0.5\WsAppService.exe =>.Wondershare

                      —\ Task Planned Automatically (25) - 7s
                      [MD5.4EA38FE58411907624030BF31C5AD5AD] [APT] [ATPL Update maintenance] (…) – C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\htdocs\scripts\removelock.bat [317400] (.Activate.)
                      [MD5.370EE0B2DF7E416C23EAD422A9CA159E] [APT] [AviraScoutUpdateTaskMachineCore] (.Avira Operations GmbH & Co. KG.) – C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe [317400] (.Activate.) =>.Avira Operations GmbH & Co. KG®
                      [MD5.370EE0B2DF7E416C23EAD422A9CA159E] [APT] [AviraScoutUpdateTaskMachineUA] (.Avira Operations GmbH & Co. KG.) – C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe [317400] (.Activate.) =>.Avira Operations GmbH & Co. KG®
                      [MD5.3B2336A8281ABE998D156B580D6FAC4F] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) – C:\Program Files\CCleaner\CCleaner.exe [317400] (.Activate.) =>.Piriform Ltd®
                      [MD5.A1F58FFF448E4099297D6EE0641D4D0E] [APT] [DropboxUpdateTaskMachineCore] (.Dropbox, Inc..) – C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [317400] (.Activate.) =>.Dropbox, Inc®
                      [MD5.A1F58FFF448E4099297D6EE0641D4D0E] [APT] [DropboxUpdateTaskMachineUA] (.Dropbox, Inc..) – C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [317400] (.Activate.) =>.Dropbox, Inc®
                      [MD5.988A613C7D9B39E8684B5B4CF2CDA65F] [APT] [G2MUpdateTask-S-1-5-21-928801702-3077407482-3869533313-1000] (.Citrix Online, a division of Citrix Systems, Inc..) – C:\Users\goldfish\AppData\Local\Citrix\GoToMeeting \6441\g2mupdate.exe [317400] (.Activate.) =>.Citrix Online®
                      [MD5.988A613C7D9B39E8684B5B4CF2CDA65F] [APT] [G2MUploadTask-S-1-5-21-928801702-3077407482-3869533313-1000] (.Citrix Online, a division of Citrix Systems, Inc..) – C:\Users\goldfish\AppData\Local\Citrix\GoToMeeting \6441\g2mupload.exe [317400] (.Activate.) =>.Citrix Online®
                      [MD5.23985274780D27117C470AA259B79B30] [APT] [Apple\AppleSoftwareUpdate] (.Apple Inc..) – C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [317400] (.Activate.) =>.Apple Inc.®
                      O39 - APT: ATPL Update maintenance - (…) – C:\Windows\Tasks\ATPL Update maintenance.job [317400]
                      O39 - APT: AviraScoutUpdateTaskMachineCore - (.Avira Operations GmbH & Co. KG.) – C:\Windows\Tasks\AviraScoutUpdateTaskMachineCore.j ob [317400] =>.Avira Operations GmbH & Co. KG®
                      O39 - APT: AviraScoutUpdateTaskMachineUA - (.Avira Operations GmbH & Co. KG.) – C:\Windows\Tasks\AviraScoutUpdateTaskMachineUA.job [317400] =>.Avira Operations GmbH & Co. KG®
                      O39 - APT: DropboxUpdateTaskMachineCore - (.Dropbox, Inc..) – C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job [317400] =>.Dropbox, Inc®
                      O39 - APT: DropboxUpdateTaskMachineUA - (.Dropbox, Inc..) – C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job [317400] =>.Dropbox, Inc®
                      O39 - APT: G2MUpdateTask-S-1-5-21-928801702-3077407482-3869533313-1000 - (.Citrix Online, a division of Citrix Systems, Inc..) – C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-928801702-3077407482-3869533313-1000.job [317400] =>.Citrix Online®
                      O39 - APT: G2MUploadTask-S-1-5-21-928801702-3077407482-3869533313-1000 - (.Citrix Online, a division of Citrix Systems, Inc..) – C:\Windows\Tasks\G2MUploadTask-S-1-5-21-928801702-3077407482-3869533313-1000.job [317400] =>.Citrix Online®
                      O39 - APT: ATPL Update maintenance - (…) – C:\Windows\System32\Tasks\ATPL Update maintenance [317400]
                      O39 - APT: AviraScoutUpdateTaskMachineCore - (.Avira Operations GmbH & Co. KG.) – C:\Windows\System32\Tasks\AviraScoutUpdateTaskMach ineCore [317400] =>.Avira Operations GmbH & Co. KG®
                      O39 - APT: AviraScoutUpdateTaskMachineUA - (.Avira Operations GmbH & Co. KG.) – C:\Windows\System32\Tasks\AviraScoutUpdateTaskMach ineUA [317400] =>.Avira Operations GmbH & Co. KG®
                      O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) – C:\Windows\System32\Tasks\CCleanerSkipUAC [317400] =>.Piriform Ltd®
                      O39 - APT: Unknown - (.Microsoft Corporation.) – C:\Windows\System32\Tasks\CreateChoiceProcessTask [317400] =>.Microsoft Corporation
                      O39 - APT: DropboxUpdateTaskMachineCore - (.Dropbox, Inc..) – C:\Windows\System32\Tasks\DropboxUpdateTaskMachine Core [317400] =>.Dropbox, Inc®
                      O39 - APT: DropboxUpdateTaskMachineUA - (.Dropbox, Inc..) – C:\Windows\System32\Tasks\DropboxUpdateTaskMachine UA [317400] =>.Dropbox, Inc®
                      O39 - APT: G2MUpdateTask-S-1-5-21-928801702-3077407482-3869533313-1000 - (.Citrix Online, a division of Citrix Systems, Inc..) – C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-928801702-3077407482-3869533313-1000 [317400] =>.Citrix Online®
                      O39 - APT: G2MUploadTask-S-1-5-21-928801702-3077407482-3869533313-1000 - (.Citrix Online, a division of Citrix Systems, Inc..) – C:\Windows\System32\Tasks\G2MUploadTask-S-1-5-21-928801702-3077407482-3869533313-1000 [317400] =>.Citrix Online®

                      —\ Auto loading programs from Registry and folders (8) - 0s
                      O4 - HKCU..\Run: [CCleaner] . (.Piriform Ltd - CCleaner.) – C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
                      O4 - HKLM..\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH & Co. KG - Avira system tray application.) – C:\Program Files (x86)\Avira\Antivirus\avgnt.exe =>.Avira Operations GmbH & Co. KG®
                      O4 - HKLM..\Wow6432Node\Run: [Avira SystrayStartTrigger] . (.Avira Operations GmbH & Co. KG - Avira Connect.) – C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe =>.Avira Operations GmbH & Co. KG®
                      O4 - HKUS\S-1-5-19..\Run: [Sidebar] . (.Microsoft Corporation - Windows Desktop Gadgets.) – C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
                      O4 - HKUS\S-1-5-20..\Run: [Sidebar] . (.Microsoft Corporation - Windows Desktop Gadgets.) – C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
                      O4 - HKUS\S-1-5-19..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) – C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
                      O4 - HKUS\S-1-5-20..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) – C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
                      O4 - HKUS\S-1-5-21-928801702-3077407482-3869533313-1000..\Run: [CCleaner] . (.Piriform Ltd - CCleaner.) – C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®

                      —\ Process running (52) - 3s
                      [MD5.00000000000000000000000000000000] - (.AMD - AMD External Events Service Module.) – C:\Windows\system32\atiesrxx.exe [0] [PID.996] =>.AMD
                      [MD5.00000000000000000000000000000000] - (.AMD - AMD External Events Client Module.) – C:\Windows\system32\atieclxx.exe [0] [PID.1292] =>.AMD
                      [MD5.58FD213E044D88825E411A1A0A6AEE64] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) – C:\Program Files (x86)\Avira\Antivirus\sched.exe [487424] [PID.1496] =>.Avira Operations GmbH & Co. KG®
                      [MD5.B932E0EE190778D840F1442DFC0F9612] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [82640] [PID.1556] =>.Adobe Systems, Incorporated®
                      [MD5.58FD213E044D88825E411A1A0A6AEE64] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) – C:\Program Files (x86)\Avira\Antivirus\avguard.exe [487424] [PID.1612] =>.Avira Operations GmbH & Co. KG®
                      [MD5.7D811EA7A2AAA49B0446D42CBC1CD338] - (.Apple Inc. - MobileDeviceService.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768] [PID.1968] =>.Apple Inc.®
                      [MD5.1E0029B9936F42C86138EADB5C27439E] - (.Avira Operations GmbH & Co. KG - Avira system tray application.) – C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [909744] [PID.2112] =>.Avira Operations GmbH & Co. KG®
                      [MD5.4635935FC972C582632BF45C26BFCB0E] - (…) – C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\updatescripts\srvany.exe [8192] [PID.2164]
                      [MD5.2D23F723CD072EA0677BADB604B24CCF] - (.The PHP Group - CLI.) – C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\php\php.exe [28739] [PID.2192] =>.The PHP Group
                      [MD5.020EC70045C677B40FEA89C3FE483137] - (.Apache Software Foundation - Apache HTTP Server.) – C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\bin\Apache.exe [20550] [PID.2704] =>.Apache Software Foundation
                      [MD5.B5C2F92EE1106DFE7BB1CCE4D35B6037] - (.Apple Inc. - Bonjour Service.) – C:\Program Files\Bonjour\mDNSResponder.exe [462096] [PID.2760] =>.Apple Inc.®
                      [MD5.0E03E300CB28F30843F40069563CE2AD] - (.Brother Industries, Ltd. - BrYNCSvc.) – C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112] [PID.2784] =>.Brother Industries, Ltd.
                      [MD5.020EC70045C677B40FEA89C3FE483137] - (.Apache Software Foundation - Apache HTTP Server.) – C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\bin\Apache.exe [20550] [PID.2932] =>.Apache Software Foundation
                      [MD5.A1F58FFF448E4099297D6EE0641D4D0E] - (.Dropbox, Inc. - Dropbox Update.) – C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144] [PID.3604] =>.Dropbox, Inc®
                      [MD5.00000000000000000000000000000000] - (.Dropbox, Inc. - Dropbox Service.) – C:\Windows\system32\DbxSvc.exe [0] [PID.3612] =>.Dropbox, Inc.
                      [MD5.73081CF28F0AE20A52CA4F67CEE6E6B0] - (.Flexera Software, Inc. - Activation Licensing Service.) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1044816] [PID.3868] =>.Flexera Software, Inc. ®
                      [MD5.1CF03C69B49ACB70C722DF92755C0C8C] - (.Macrovision Corporation - IDriverT Module.) – C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632] [PID.3940] =>.Macrovision Corporation
                      [MD5.97C9EBB84A761D48DC17E0E6B913C164] - (.Apple Inc. - iPodService Module (64-bit).) – C:\Program Files\iPod\bin\iPodService.exe [651576] [PID.3824] =>.Apple Inc.®
                      [MD5.213822072085B5BBAD9AF30AB577D817] - (.InterVideo - RegMgr Module.) – C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe [112152] [PID.3844] =>.Intervideo, Inc.®
                      [MD5.5460828F8951D310B42B442877603B8D] - (.Intel Corporation - Local Manageability Service.) – C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [268824] [PID.152] =>.Intel Corporation®
                      [MD5.3E6C47A46BDDE1B6B084012B5B69C069] - (.Seagate Technology LLC - Sync Windows Services.) – C:\Program Files (x86)\Maxtor\Sync\SyncServices.exe [156976] [PID.1464] {25B1DD7CD102F294C6B4A039166590E7} =>.Seagate Technology LLC
                      [MD5.627FA58ADC043704F9D14CA44340956F] - (.Sony Corporation - Device Information Provider.) – C:\Program Files (x86)\SONY\PMB\PMBDeviceInfoProvider.exe [360224] [PID.4296] =>.Sony Corporation®
                      [MD5.A6A7AD767BF5141665F5C675F671B3E1] - (.Protexis Inc. - PsiService PsiService.) – C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [185632] [PID.4320] =>.Protexis Inc.®
                      [MD5.65CC4779A29C3E82B987BD4961790DFF] - (.Sony Corporation - VAIO Media plus Digital Media Server.) – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe [423280] [PID.4428] =>.Sony Corporation®
                      [MD5.F47D75CEE1844EEF4A9EA6EE768828FB] - (.Sony Corporation - VAIO Media plus Device Searcher.) – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [67952] [PID.4456] =>.Sony Corporation®
                      [MD5.9E89C2D6945389270DE067CE51FF7425] - (.Intel Corporation - User Notification Service.) – C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2320920] [PID.4520] =>.Intel Corporation®
                      [MD5.8E68E4AA2D7ABBF7C9159D9D2A38AE0F] - (.Sony Corporation - Hardware Resource Manager.) – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResou rceManager\VzHardwareResourceManager.exe [74496] [PID.4596] =>.Sony Corporation®
                      [MD5.6B31C9CB94927DBEEB62E15275F4CC54] - (.Sony Corporation - VAIO Event Service (Service Module).) – C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe [205168] [PID.4668] =>.Sony Corporation®
                      [MD5.6888526AEB8DDABDE6F778FD40FC0693] - (.Sony Corporation - VAIO Content Folder Watcher.) – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [864000] [PID.4704] =>.Sony Corporation®
                      [MD5.C8E3BA694CC5EACEC4C01660ACE40D56] - (.Sony Corporation - VcmXml Helper Interface.) – C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [101152] [PID.4740] =>.Sony Corporation®
                      [MD5.D347D3ABE070AA09C22FC37121555D52] - (.Sony Corporation - VAIOCare.) – C:\Program Files\Sony\VAIO Care\VCService.exe [44736] [PID.4792] =>.Sony Corporation®
                      [MD5.047F22BDFDAE6DF6F1E47E747A1237A2] - (.Sony Corporation - VAIO Smart Network Service.) – C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [845312] [PID.4856] =>.Sony Corporation
                      [MD5.D62D16E057BE87F5B84A54D1B83822C4] - (.Sony Corporation - VUAgent.exe.) – C:\Program Files\Sony\VAIO Update Common\VUAgent.exe [1429608] [PID.4936] =>.Sony Corporation®
                      [MD5.E84CF717E854D02DF30BD1BCC612BEAC] - (.Western Digital Technologies, Inc. - WD Drive Service.) – C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [308088] [PID.5020] =>.Western Digital Technologies, Inc.®
                      [MD5.357CABBF155AFD1D3926E62539D2A3A7] - (.Microsoft Corp. - Microsoft® Windows Live ID Service.) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2292480] [PID.5112] =>.Microsoft Corporation®
                      [MD5.3E2F9D42647CDC1024511839762ABC0C] - (.Sony Corporation - VAIO Smart Network.) – C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe [2367376] [PID.3812] =>.Sony Corporation®
                      [MD5.7CD368DFF5D7D4BA9F8F46F31EA8877D] - (.Sony Corporation - VAIO Event Service(Service Sub Module).) – C:\Program Files (x86)\SONY\VAIO Event Service\VESMgrSub.exe [112488] [PID.1192] =>.Sony Corporation®
                      [MD5.04F75064637D7409519DD52B61E8BB43] - (.Wondershare - Wondershare AppService.) – C:\Program Files (x86)\Wondershare\WAF\2.3.0.5\WsAppService.exe [415232] [PID.4904] =>.Wondershare
                      [MD5.D790CAFEFF0291D0AF8C76F5A1EE2E4E] - (.Microsoft Corp. - Microsoft® Windows Live ID Service Monitor.) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE [223488] [PID.5200] =>.Microsoft Corporation®
                      [MD5.2AEE4D1D7E668F1CCF97EDE93509B0EE] - (.Avira Operations GmbH & Co. KG - Avira Service Host.) – C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [372272] [PID.5688] =>.Avira Operations GmbH & Co. KG®
                      [MD5.CC800D2D9FD467542BAC7C186C4774AD] - (.Intel Corporation - IAStorDataSvc.) – C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [13336] [PID.5796] =>.Intel Corporation®
                      [MD5.C3E69DB0A4E59564230E053232F39AC7] - (.Sony Corporation - VAIO Media plus Content Importer.) – C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [108400] [PID.6044] =>.Sony Corporation®
                      [MD5.B8047E776E50FC2384801083A77900E0] - (.Sony Corporation - VAIO Entertainment Common Service.) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [303872] [PID.2016] =>.Sony Corporation®
                      [MD5.2508D922074C96B4E7C25D011550EFCA] - (.Avira Operations GmbH & Co. KG - AntiVir shadow copy service.) – C:\Program Files (x86)\Avira\Antivirus\avshadow.exe [1063016] [PID.5964] =>.Avira Operations GmbH & Co. KG®
                      [MD5.F0672B2368E859284A4C44AE2CCA4C72] - (.Sony Corporation - VCM Intelligent Analyzing Manager.) – C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [549168] [PID.1304] =>.Sony Corporation®
                      [MD5.F48D4468C499D04ACA7B9E6656F5FE69] - (.Avira Operations GmbH & Co. KG - Avira.) – C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe [159536] [PID.6968] =>.Avira Operations GmbH & Co. KG®
                      [MD5.735099A055C50FE534D4781D67FD6B83] - (.Sony Corporation - VAIO Care Performance Service.) – C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192] [PID.7332] =>.Sony Corporation of America®
                      [MD5.4D96F6F7508BDF46771262EEEA505F98] - (.Sony of America Corporation - VaioCare Window Listener Application.) – C:\Program Files\Sony\VAIO Care\listener.exe [81016] [PID.7176] =>.Sony Corporation of America®
                      [MD5.5E8B711CFA94692414D41F01DB04BE64] - (.Google Inc. - Google Update Setup.) – C:\Windows\Installer\MSI314F.tmp [50403944] [PID.7280] =>.Google Inc®
                      [MD5.A8FD9222E4D72596BB37DA8BE95C0BA4] - (.Google Inc. - Google Installer.) – C:\Program Files (x86)\GUM5198.tmp\GoogleUpdate.exe [153752] [PID.8076] =>.Google Inc®
                      [MD5.DD7423ABBE2913E70D50E9318AD57EE4] - (.Google Inc. - Google Installer.) – C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] [PID.6884] =>.Google Inc®
                      [MD5.043AA33C9487A2046734C29E53A7DA47] - (.Nicolas Coolman - ZHPDiag.) – C:\Users\goldfish\Desktop\ZHPDiag3.exe [2707968] [PID.4252] =>.Nicolas Coolman

                      —\ Google Chrome, Start,Search,Extensions (20) - 0s
                      G0 - GCSP: Preferences [User Data\Default][HomePage] http://accounts.google.com =>.Google Inc.
                      G0 - GCSP: Preferences [User Data\Default][HomePage] http://accounts.youtube.com =>.Youtube
                      G0 - GCSP: Preferences [User Data\Default][HomePage] http://apis.google.com =>.Google Inc.
                      G0 - GCSP: Preferences [User Data\Default][HomePage] http://clients5.google.com =>.Google Inc.
                      G0 - GCSP: Preferences [User Data\Default][HomePage] http://docs.google.com =>.Google Inc.
                      G0 - GCSP: Preferences [User Data\Default][HomePage] http://fonts.gstatic.com =>.Google Inc.
                      G0 - GCSP: Preferences [User Data\Default][HomePage] http://lh3.googleusercontent.com =>.Google Inc.
                      G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.gstatic.com =>.Google Inc.
                      G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.co.uk =>.Google Inc.
                      G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.gstatic.com =>.Google Inc.
                      G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://login.yahoo.com/ =>.Yahoo! Inc.
                      G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://accounts.google.com/ =>.Google Inc.
                      G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.facebook.com =>.Facebook
                      G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc. =>.Google Inc.
                      G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc.
                      G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc.
                      G2 - GCE: Preference [User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] Google Chrome manifest =>.Google Inc. =>.Google Inc.
                      G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.
                      G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc.
                      G2 - GCE: Preference [User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.

                      —\ Mozilla Firefox,Plugins,Start,Search,Extensions (11) - 4s
                      M0 - MFSP: prefs.js [goldfish - fcotwa47.default] http://www.google.com/ =>.Google Inc.
                      M1 - SPR:Search Page Redirection - C:\Program Files (x86)\Mozilla Firefox\extensions{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
                      P2 - EXT FILE: (.Firefox Hotfix - Firefox Hotfix: avoid updates that wou.) – C:\Users\goldfish\AppData\Roaming\Mozilla\Firefox\ Profiles\fcotwa47.default\extensions\firefox-hotfix@mozilla.org.xpi =>.Firefox Hotfix
                      P2 - EXT FILE: (.Gareth Hunt - Add, modify and filter HTTP request he.) – C:\Users\goldfish\AppData\Roaming\Mozilla\Firefox\ Profiles\fcotwa47.default\extensions{b749fc7c-e949-447f-926c-3f4eed6accfe}.xpi
                      P2 - EXT FILE: (.Google (avast) - Google Search from avast.) – C:\Users\goldfish\AppData\Roaming\Mozilla\Firefox\ Profiles\fcotwa47.default\searchplugins\google-avast.xml =>.Google (avast)
                      P2 - EXT: (.Skype Technologies S.A. - Skype Click to Call.) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} =>.Skype Technologies S.A.
                      P2 - EXT: (…) – C:\Users\goldfish\AppData\Roaming\Mozilla\Extensio ns\prism@developer.mozilla.org
                      P2 - EXT: (…) – C:\Users\goldfish\AppData\Roaming\Mozilla\Firefox\ Profiles\fcotwa47.default\extensions\abs@avira.com =>.Avira Software
                      P2 - EXT: (.Microsoft Corporation - Bing Search Engine.) – C:\Users\goldfish\AppData\Roaming\Mozilla\Firefox\ Profiles\fcotwa47.default\extensions\bingsearch.full@microsoft.com =>.Microsoft Corporation
                      P2 - EXT: (.Avira - Avira SafeSearch Plus.) – C:\Users\goldfish\AppData\Roaming\Mozilla\Firefox\ Profiles\fcotwa47.default\extensions\safesearchplus2@avira.com =>.Avira
                      P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) – C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_ 221.dll =>.Adobe Systems Incorporated

                      —\ Internet Explorer Extensions, Start, Search (20) - 0s
                      R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk-mg5.mail.yahoo.com/ =>.Yahoo! Inc.
                      R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
                      R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
                      R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
                      R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ =>.Google Inc.
                      R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
                      R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
                      R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
                      R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
                      R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
                      R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = about:newtab =>.Microsoft Corporation
                      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = about:newtab =>.Microsoft Corporation
                      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
                      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ =>.Google Inc.
                      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
                      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
                      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
                      R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
                      R1 - HKEY_USERS\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ =>.Google Inc.
                      R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphan =>.Microsoft Internet Explorer

                      —\ Internet Explorer, Proxy Management (6) - 0s
                      R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyEnable = 0
                      R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings,MigrateProxy = 1
                      R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings,EnableHttp1_1 = 1
                      R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyHttp1.1 = 0
                      R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings,AutoConfigProxy = wininet.dll
                      R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Para meters\Internet\ManualProxies

                      —\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
                      F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
                      F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
                      F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerfo rmance.exe (.Microsoft Corporation.) =>.Microsoft Corporation

                      —\ Hosts file redirection (1) - 0s
                      ~ Le fichier hôte est sain (The hosts file is clean) (1)

                      —\ Browser Helper Object (BHO) (6) - 1s
                      O2 - BHO: Skype for Business Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} (.Orphan.)
                      O2 - BHO: Windows Live ID Sign-in Helper [64Bits] - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) – C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll =>.Microsoft Corporation®
                      O2 - BHO: SkypeIEPluginBHO [64Bits] - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Skype Technologies S.A. - Skype Click to Call for Internet Explorer.) – C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll =>.Skype Technologies SA®
                      O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) – C:\Program Files\Microsoft Office 15\root\office15\urlredir.dll =>.Microsoft Corporation®
                      O2 - BHO: Microsoft SkyDrive Pro Browser Helper [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} (.Orphan.)
                      O2 - BHO: Java™ Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (…) – C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (.not file.)

                      —\ Global shortcuts Startup (153) - 29s
                      O4 - GS\Desktop [Administrator]: C901 Budget.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\C901 Budget 20161106.xlsx
                      O4 - GS\Desktop [Administrator]: C902 Banking.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\C902 Banking 20160721.xlsx
                      O4 - GS\Desktop [Administrator]: Contact List.lnk . (…) C:\Users\goldfish\Documents_Flying\Contacts\CONTAC T LIST.txt
                      O4 - GS\Desktop [Administrator]: DIARY.lnk . (.goldfish goldfish - .) C:\Users\goldfish\Documents\DIARY.doc
                      O4 - GS\Desktop [Administrator]: DiskCheckup.lnk . (.PassMark ™ Software - www.passmark.com - DiskCheckup.) C:\Program Files (x86)\DiskCheckup\DiskCheckup.exe {38E7FA0DB1A398F805BB85A69171DC9D}
                      O4 - GS\Desktop [Administrator]: Dropbox.lnk . (.Dropbox, Inc. - Dropbox.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe /home =>.Dropbox, Inc®
                      O4 - GS\Desktop [Administrator]: Four Six Four.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\Four Six Four.xlsx
                      O4 - GS\Desktop [Administrator]: GoToMeeting Quick Connect.lnk . (.Citrix Online, a division of Citrix Systems, Inc. - GoToMeeting.) C:\Users\goldfish\AppData\Local\Citrix\GoToMeeting \6291\g2mstart.exe /Mode Terse /Action Join /Trigger Shortcut /Product G2M /FreeTrialUrl http://s.gotomeeting.com/ =>.Citrix Online, a division of Citrix Systems, Inc.
                      O4 - GS\Desktop [Administrator]: mccPILOTCAL.lnk . (.MCC bvba - .) C:\Users\goldfish\AppData\Roaming\MCC Pilotlog\mccPILOTCAL.exe
                      O4 - GS\Desktop [Administrator]: mccPILOTLOG.lnk . (.MCC bvba - .) C:\Program Files (x86)\MCC Pilotlog\mccPILOTLOG.exe
                      O4 - GS\Desktop [Administrator]: Outlook 2013.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office 15\root\office15\OUTLOOK.EXE =>.Microsoft Corporation
                      O4 - GS\Desktop [Administrator]: Roxio Easy Media Creator 10 LJ.lnk . (.Copyright (C) 2000-2007 - Roxio Creator.) C:\Program Files (x86)\Common Files\Roxio Shared\10.0\Roxio Central36\Main\Roxio_Central36.exe =>.Sonic Solutions®
                      O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\goldfish\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
                      O4 - GS\Quicklaunch [Administrator]: Avira Scout.lnk . (.Avira Operations GmbH & Co. KG - Avira Scout.) C:\Program Files (x86)\Avira\Scout\Application\scout.exe =>.Avira Operations GmbH & Co. KG®
                      O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
                      O4 - GS\Quicklaunch [Administrator]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
                      O4 - GS\Quicklaunch [Administrator]: Microsoft Outlook.lnk . (.Microsoft Corporation - Microsoft Outlook.) C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE /recycle =>.Microsoft Corporation®
                      O4 - GS\Quicklaunch [Administrator]: Wickr Me.lnk . (…) C:\Program Files (x86)\Wickr Inc\Wickr Me\Wickr Me.exe {045D55AD7640E014A9B074ACF4E03319}
                      O4 - GS\sendTo [Administrator]: Dropbox.lnk . (…) C:\Users\goldfish\Dropbox
                      O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
                      O4 - GS\sendTo [Administrator]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
                      O4 - GS\TaskBar [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
                      O4 - GS\TaskBar [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
                      O4 - GS\TaskBar [Administrator]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
                      O4 - GS\TaskBar [Administrator]: Wickr Me.lnk . (…) C:\Program Files (x86)\Wickr Inc\Wickr Me\Wickr Me.exe {045D55AD7640E014A9B074ACF4E03319}
                      O4 - GS\Programs [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
                      O4 - GS\Programs [Administrator]: Windows Install Clean Up.lnk . (.Microsoft Corporation - Windows Installer Clean Up Application.) C:\Program Files (x86)\Windows Installer Clean Up\msicuu.exe =>.Microsoft Corporation
                      O4 - GS\Desktop [goldfish]: C901 Budget.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\C901 Budget 20161106.xlsx
                      O4 - GS\Desktop [goldfish]: C902 Banking.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\C902 Banking 20160721.xlsx
                      O4 - GS\Desktop [goldfish]: Contact List.lnk . (…) C:\Users\goldfish\Documents_Flying\Contacts\CONTAC T LIST.txt
                      O4 - GS\Desktop [goldfish]: DIARY.lnk . (.goldfish goldfish - .) C:\Users\goldfish\Documents\DIARY.doc
                      O4 - GS\Desktop [goldfish]: DiskCheckup.lnk . (.PassMark ™ Software - www.passmark.com - DiskCheckup.) C:\Program Files (x86)\DiskCheckup\DiskCheckup.exe {38E7FA0DB1A398F805BB85A69171DC9D}
                      O4 - GS\Desktop [goldfish]: Dropbox.lnk . (.Dropbox, Inc. - Dropbox.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe /home =>.Dropbox, Inc®
                      O4 - GS\Desktop [goldfish]: Four Six Four.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\Four Six Four.xlsx
                      O4 - GS\Desktop [goldfish]: GoToMeeting Quick Connect.lnk . (.Citrix Online, a division of Citrix Systems, Inc. - GoToMeeting.) C:\Users\goldfish\AppData\Local\Citrix\GoToMeeting \6291\g2mstart.exe /Mode Terse /Action Join /Trigger Shortcut /Product G2M /FreeTrialUrl http://s.gotomeeting.com/ =>.Citrix Online, a division of Citrix Systems, Inc.
                      O4 - GS\Desktop [goldfish]: mccPILOTCAL.lnk . (.MCC bvba - .) C:\Users\goldfish\AppData\Roaming\MCC Pilotlog\mccPILOTCAL.exe
                      O4 - GS\Desktop [goldfish]: mccPILOTLOG.lnk . (.MCC bvba - .) C:\Program Files (x86)\MCC Pilotlog\mccPILOTLOG.exe
                      O4 - GS\Desktop [goldfish]: Outlook 2013.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office 15\root\office15\OUTLOOK.EXE =>.Microsoft Corporation
                      O4 - GS\Desktop [goldfish]: Roxio Easy Media Creator 10 LJ.lnk . (.Copyright (C) 2000-2007 - Roxio Creator.) C:\Program Files (x86)\Common Files\Roxio Shared\10.0\Roxio Central36\Main\Roxio_Central36.exe =>.Sonic Solutions®
                      O4 - GS\Desktop [goldfish]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\goldfish\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
                      O4 - GS\Quicklaunch [goldfish]: Avira Scout.lnk . (.Avira Operations GmbH & Co. KG - Avira Scout.) C:\Program Files (x86)\Avira\Scout\Application\scout.exe =>.Avira Operations GmbH & Co. KG®
                      O4 - GS\Quicklaunch [goldfish]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
                      O4 - GS\Quicklaunch [goldfish]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
                      O4 - GS\Quicklaunch [goldfish]: Microsoft Outlook.lnk . (.Microsoft Corporation - Microsoft Outlook.) C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE /recycle =>.Microsoft Corporation®
                      O4 - GS\Quicklaunch [goldfish]: Wickr Me.lnk . (…) C:\Program Files (x86)\Wickr Inc\Wickr Me\Wickr Me.exe {045D55AD7640E014A9B074ACF4E03319}
                      O4 - GS\sendTo [goldfish]: Dropbox.lnk . (…) C:\Users\goldfish\Dropbox
                      O4 - GS\sendTo [goldfish]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
                      O4 - GS\sendTo [goldfish]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
                      O4 - GS\TaskBar [goldfish]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
                      O4 - GS\TaskBar [goldfish]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
                      O4 - GS\TaskBar [goldfish]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
                      O4 - GS\TaskBar [goldfish]: Wickr Me.lnk . (…) C:\Program Files (x86)\Wickr Inc\Wickr Me\Wickr Me.exe {045D55AD7640E014A9B074ACF4E03319}
                      O4 - GS\Programs [goldfish]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
                      O4 - GS\Programs [goldfish]: Windows Install Clean Up.lnk . (.Microsoft Corporation - Windows Installer Clean Up Application.) C:\Program Files (x86)\Windows Installer Clean Up\msicuu.exe =>.Microsoft Corporation
                      O4 - GS\Desktop [Guest]: C901 Budget.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\C901 Budget 20161106.xlsx
                      O4 - GS\Desktop [Guest]: C902 Banking.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\C902 Banking 20160721.xlsx
                      O4 - GS\Desktop [Guest]: Contact List.lnk . (…) C:\Users\goldfish\Documents_Flying\Contacts\CONTAC T LIST.txt
                      O4 - GS\Desktop [Guest]: DIARY.lnk . (.goldfish goldfish - .) C:\Users\goldfish\Documents\DIARY.doc
                      O4 - GS\Desktop [Guest]: DiskCheckup.lnk . (.PassMark ™ Software - www.passmark.com - DiskCheckup.) C:\Program Files (x86)\DiskCheckup\DiskCheckup.exe {38E7FA0DB1A398F805BB85A69171DC9D}
                      O4 - GS\Desktop [Guest]: Dropbox.lnk . (.Dropbox, Inc. - Dropbox.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe /home =>.Dropbox, Inc®
                      O4 - GS\Desktop [Guest]: Four Six Four.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\Four Six Four.xlsx
                      O4 - GS\Desktop [Guest]: GoToMeeting Quick Connect.lnk . (.Citrix Online, a division of Citrix Systems, Inc. - GoToMeeting.) C:\Users\goldfish\AppData\Local\Citrix\GoToMeeting \6291\g2mstart.exe /Mode Terse /Action Join /Trigger Shortcut /Product G2M /FreeTrialUrl http://s.gotomeeting.com/ =>.Citrix Online, a division of Citrix Systems, Inc.
                      O4 - GS\Desktop [Guest]: mccPILOTCAL.lnk . (.MCC bvba - .) C:\Users\goldfish\AppData\Roaming\MCC Pilotlog\mccPILOTCAL.exe
                      O4 - GS\Desktop [Guest]: mccPILOTLOG.lnk . (.MCC bvba - .) C:\Program Files (x86)\MCC Pilotlog\mccPILOTLOG.exe
                      O4 - GS\Desktop [Guest]: Outlook 2013.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office 15\root\office15\OUTLOOK.EXE =>.Microsoft Corporation
                      O4 - GS\Desktop [Guest]: Roxio Easy Media Creator 10 LJ.lnk . (.Copyright (C) 2000-2007 - Roxio Creator.) C:\Program Files (x86)\Common Files\Roxio Shared\10.0\Roxio Central36\Main\Roxio_Central36.exe =>.Sonic Solutions®
                      O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\goldfish\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
                      O4 - GS\Quicklaunch [Guest]: Avira Scout.lnk . (.Avira Operations GmbH & Co. KG - Avira Scout.) C:\Program Files (x86)\Avira\Scout\Application\scout.exe =>.Avira Operations GmbH & Co. KG®
                      O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
                      O4 - GS\Quicklaunch [Guest]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
                      O4 - GS\Quicklaunch [Guest]: Microsoft Outlook.lnk . (.Microsoft Corporation - Microsoft Outlook.) C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE /recycle =>.Microsoft Corporation®
                      O4 - GS\Quicklaunch [Guest]: Wickr Me.lnk . (…) C:\Program Files (x86)\Wickr Inc\Wickr Me\Wickr Me.exe {045D55AD7640E014A9B074ACF4E03319}
                      O4 - GS\sendTo [Guest]: Dropbox.lnk . (…) C:\Users\goldfish\Dropbox
                      O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
                      O4 - GS\sendTo [Guest]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
                      O4 - GS\TaskBar [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
                      O4 - GS\TaskBar [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
                      O4 - GS\TaskBar [Guest]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
                      O4 - GS\TaskBar [Guest]: Wickr Me.lnk . (…) C:\Program Files (x86)\Wickr Inc\Wickr Me\Wickr Me.exe {045D55AD7640E014A9B074ACF4E03319}
                      O4 - GS\Programs [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
                      O4 - GS\Programs [Guest]: Windows Install Clean Up.lnk . (.Microsoft Corporation - Windows Installer Clean Up Application.) C:\Program Files (x86)\Windows Installer Clean Up\msicuu.exe =>.Microsoft Corporation
                      O4 - GS\CommonDesktop [Public]: 3 Malwarebytes.lnk . (.Malwarebytes - Malwarebytes.) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe =>.Malwarebytes Corporation®
                      O4 - GS\CommonDesktop [Public]: 4 SUPERAntiSpyware Free Edition.lnk . (.SUPERAntiSpyware - SUPERAntiSpyware Application.) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe =>.SUPERAntiSpyware.com®
                      O4 - GS\CommonDesktop [Public]: ATPL Digital.lnk . (.Bristol.gs - ATPL Digital.) C:\Program Files (x86)\Bristol.gs\ATPL Digital\AtplDigital.exe
                      O4 - GS\CommonDesktop [Public]: Avira Connect.lnk . (.Avira Operations GmbH & Co. KG - Avira.) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe /showMiniGui =>.Avira Operations GmbH & Co. KG®
                      O4 - GS\CommonDesktop [Public]: Avira Phantom VPN.lnk . (.Avira Operations GmbH & Co. KG - Avira.WebAppHost.) C:\Program Files (x86)\Avira\VPN\Avira.WebAppHost.exe =>.Avira Operations GmbH & Co. KG®
                      O4 - GS\CommonDesktop [Public]: Avira Scout.lnk . (.Avira Operations GmbH & Co. KG - Avira Scout.) C:\Program Files (x86)\Avira\Scout\Application\scout.exe =>.Avira Operations GmbH & Co. KG®
                      O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Ltd - CCleaner.) C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
                      O4 - GS\CommonDesktop [Public]: Family Tree Maker 2006.lnk . (.MyFamily.com, Inc. - Family Tree Maker executable.) C:\Program Files (x86)\Family Tree Maker 2006\FTW.exe
                      O4 - GS\CommonDesktop [Public]: Free iTunes Backup Extractor.lnk . (.Apex Co. Ltd. - Jihosoft iTunes Extractor.) C:\Program Files (x86)\Jihosoft\Free iTunes Backup Extractor\iTunes Backup Extractor.exe =>.HONGKONG JIHO CO., LIMITED®
                      O4 - GS\CommonDesktop [Public]: iTunes.lnk . (.Apple Inc. - .) C:\Program Files (x86)\iTunes\iTunes.exe =>.Apple Inc.
                      O4 - GS\CommonDesktop [Public]: Maxtor Manager.lnk . (.Macrovision Corporation - InstallShield.) C:\Windows\Installer{ED01D958-AEDC-40C8-93FD-0C08E8AA9530}\NewShortcut2_60EEB642E9E045A2A676B9D 8FE17C4A9.exe =>.Macrovision Corporation
                      O4 - GS\CommonDesktop [Public]: RANT XL.lnk . (…) C:\Program Files (x86)\RANTXL\Rant.exe
                      O4 - GS\CommonDesktop [Public]: Removal Tool.lnk . (.9-lab LLC - 9-lab Malware Removal Tool.) C:\Program Files\9-lab\Removal Tool\rmtool.exe =>.9-Lab®
                      O4 - GS\CommonDesktop [Public]: RogueKiller.lnk . (…) C:\Program Files\RogueKiller\RogueKiller64.exe =>.Adlice®
                      O4 - GS\CommonDesktop [Public]: Run ATP Digital 6.lnk . (.Mozilla Foundation - .) C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\client\prism.exe -webapp BGS =>.Mozilla Foundation
                      O4 - GS\CommonDesktop [Public]: SeaTools for Windows.lnk . (…) C:\Windows\Installer{98613C99-1399-416C-A07C-1EE1C585D872}\Icon98613C992.exe
                      O4 - GS\CommonDesktop [Public]: Skype.lnk . (…) C:\Windows\Installer{FC965A47-4839-40CA-B618-18F486F042C6}\SkypeIcon.exe =>.Skype Technologies
                      O4 - GS\CommonDesktop [Public]: WD Backup.lnk . (.Western Digital Technologies, Inc. - WD App Manager.) C:\Program Files (x86)\Western Digital\WD App Manager\WDAppManager.exe -launchbackupdefault =>.WESTERN DIGITAL TECHNOLOGIES®
                      O4 - GS\CommonDesktop [Public]: Wickr Me.lnk . (…) C:\Program Files (x86)\Wickr Inc\Wickr Me\Wickr Me.exe {045D55AD7640E014A9B074ACF4E03319}
                      O4 - GS\CommonDesktop [Public]: ZoomBrowser EX.lnk . (.Copyright © 2002-2006 CISRA - Zb Module.) C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\ZoomBrowser.exe
                      O4 - GS\Programs [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
                      O4 - GS\Programs [Public]: Windows Install Clean Up.lnk . (.Microsoft Corporation - Windows Installer Clean Up Application.) C:\Program Files (x86)\Windows Installer Clean Up\msicuu.exe =>.Microsoft Corporation
                      O4 - GS\Accessories [Public]: Command Prompt.lnk . (.Microsoft Corporation - Windows Command Processor.) C:\Windows\system32\cmd.exe =>.Microsoft Corporation
                      O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation
                      O4 - GS\Accessories [Public]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation
                      O4 - GS\SystemTools [Public]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe -extoff =>.Microsoft Corporation®
                      O4 - GS\SystemTools [Public]: Private Character Editor.lnk . (.Microsoft Corporation - Private Character Editor.) C:\Windows\system32\eudcedit.exe =>.Microsoft Corporation
                      O4 - GS\Accessories [Public]: Bluetooth File Transfer Wizard.lnk . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
                      O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Windows Calculator.) C:\Windows\system32\calc.exe =>.Microsoft Corporation
                      O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - Display Switch.) C:\Windows\system32\displayswitch.exe =>.Microsoft Corporation
                      O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Math Input Panel Accessory.) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
                      O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - Windows Mobility Center.) C:\Windows\system32\mblctr.exe /open =>.Microsoft Corporation
                      O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\Windows\system32\mspaint.exe =>.Microsoft Corporation
                      O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\Windows\system32\mstsc.exe =>.Microsoft Corporation
                      O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
                      O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Windows Sound Recorder.) C:\Windows\system32\SoundRecorder.exe =>.Microsoft Corporation
                      O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - Sticky Notes.) C:\Windows\system32\StikyNot.exe =>.Microsoft Corporation
                      O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) C:\Windows\System32\mobsync.exe =>.Microsoft Corporation
                      O4 - GS\Accessories [Public]: Welcome Center.lnk . (.Microsoft Corporation - Windows host process (Rundll32).) C:\Windows\system32\rundll32.exe %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCent er LaunchedBy_StartMenuShortcut =>.Microsoft Corporation
                      O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
                      O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) C:\Windows\system32\charmap.exe =>.Microsoft Corporation
                      O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - Microsoft® Disk Defragmenter.) C:\Windows\system32\dfrgui.exe =>.Microsoft Corporation
                      O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - Disk Space Cleanup Manager for Windows.) C:\Windows\system32\cleanmgr.exe =>.Microsoft Corporation
                      O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - Resource and Performance Monitor.) C:\Windows\system32\perfmon.exe /res =>.Microsoft Corporation
                      O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - System Information.) C:\Windows\system32\msinfo32.exe =>.Microsoft Corporation
                      O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - Microsoft® Windows System Restore.) C:\Windows\system32\rstrui.exe =>.Microsoft Corporation
                      O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (…) C:\Windows\system32\taskschd.msc /s =>..Microsoft Corporation
                      O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - Windows Easy Transfer Post Migration Applic.) C:\Windows\system32\migwiz\postmig.exe =>.Microsoft Corporation
                      O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - Windows Easy Transfer Application.) C:\Windows\system32\migwiz\migwiz.exe =>.Microsoft Corporation
                      O4 - GS\ProgramsCommon [Public]: Acrobat Reader DC.lnk . (.Flexera Software LLC - InstallShield.) C:\Windows\Installer{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\SC_Reader.ico =>.Flexera Software LLC
                      O4 - GS\ProgramsCommon [Public]: Apple Software Update.lnk . (…) C:\Windows\Installer{56EC47AA-5813-4FF6-8E75-544026FBEA83}\AppleSoftwareUpdateIco.exe =>.Apple Inc.
                      O4 - GS\ProgramsCommon [Public]: Citrix Receiver.lnk . (.Citrix Systems, Inc. - Citrix Receiver.) C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfService.exe -showAppPicker {1DCED972D082A6A82CA2A99FBCEA3A95} =>.Citrix Systems, Inc.
                      O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
                      O4 - GS\ProgramsCommon [Public]: Media Gallery.lnk . (.Sony Corporation - Media Gallery.) C:\Program Files (x86)\SONY\Media Gallery\VRLP.exe =>.Sony Corporation®
                      O4 - GS\ProgramsCommon [Public]: Movie Maker.lnk . (.Microsoft Corporation - Movie Maker.) C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe =>.Microsoft Corporation®
                      O4 - GS\ProgramsCommon [Public]: Photo Gallery.lnk . (.Microsoft Corporation - Photo Gallery.) C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe =>.Microsoft Corporation®
                      O4 - GS\ProgramsCommon [Public]: PMB.lnk . (.Sony Corporation - Browser.) C:\Program Files (x86)\SONY\PMB\PMBBrowser.exe =>.Sony Corporation
                      O4 - GS\ProgramsCommon [Public]: VAIO Care.lnk . (.Sony Corporation - VAIOCare.) C:\Program Files\Sony\VAIO Care\VAIOCare.exe =>.Sony Corporation®
                      O4 - GS\ProgramsCommon [Public]: VAIO Control Center.lnk . (.Sony Corporation - VAIO Control Center.) C:\Program Files (x86)\SONY\VAIO Control Center\VAIO Control Center.exe /VCC =>.Sony Corporation®
                      O4 - GS\ProgramsCommon [Public]: VAIO Data Restore Tool.lnk . (.Sony Corporation - Restore Data.) C:\Program Files (x86)\Sony\VAIO Data Restore Tool\Restore.exe =>.Sony Corporation®
                      O4 - GS\ProgramsCommon [Public]: VAIO Documentation.lnk . (…) C:\Documentation\Documentation
                      O4 - GS\ProgramsCommon [Public]: VAIO Gate.lnk . (.Sony Corporation - .) C:\Program Files (x86)\Sony\VAIO Gate\VAIO Gate.exe =>.Sony Corporation
                      O4 - GS\ProgramsCommon [Public]: VAIO Media plus.lnk . (.Sony Corporation - VAIO Media plus.) C:\Program Files (x86)\SONY\VAIO Media plus\VMp.exe =>.Sony Corporation®
                      O4 - GS\ProgramsCommon [Public]: VAIO Premium Partners.lnk . (…) C:\Program Files (x86)\Sony Corporation\VAIO Partners\VAIOPartners.exe
                      O4 - GS\ProgramsCommon [Public]: VAIO Recovery Center.lnk . (.Copyright 2002 - 2009 Sony Corporation - VAIO Recovery Center.) C:\Program Files (x86)\SONY\VAIO RECOVERY\VAIORecv.exe =>.Sony Corporation of America®
                      O4 - GS\ProgramsCommon [Public]: VAIO Transfer Support.lnk . (.Sony Corporation - VAIO Transfer Support.) C:\Program Files (x86)\SONY\VAIO Transfer Support\VAIOTransfer.exe =>.Sony Corporation®
                      O4 - GS\ProgramsCommon [Public]: VAIO Update.lnk . (.Sony Corporation - .) C:\Program Files (x86)\Sony\VAIO Update 5\VAIOUpdt.exe =>.Sony Corporation
                      O4 - GS\ProgramsCommon [Public]: Windows Anytime Upgrade.lnk . (.Microsoft Corporation - Windows Anytime Upgrade User Interface.) C:\Windows\system32\WindowsAnytimeUpgradeUI.exe =>.Microsoft Corporation
                      O4 - GS\ProgramsCommon [Public]: Windows DVD Maker.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\DVD Maker\DVDMaker.exe =>.Microsoft Corporation
                      O4 - GS\ProgramsCommon [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe =>.Microsoft Corporation
                      O4 - GS\ProgramsCommon [Public]: Windows Mobile Device Center.lnk . (.Microsoft Corporation - Windows Mobile Device Center.) C:\Windows\Installer{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}\wmdc.exe /show =>.Microsoft Corporation®
                      O4 - GS\ProgramsCommon [Public]: XPS Viewer.lnk . (.Microsoft Corporation - XPS Viewer.) C:\Windows\system32\xpsrchvw.exe =>.Microsoft Corporation

                      —\ Lop.com/Domain Hijackers (5) - 0s
                      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = lan =>.Local Domain
                      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 =>.Local IP Adress
                      O17 - HKLM\System\CCS\Services\Tcpip..{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}: DhcpNameServer = 192.168.1.1 192.168.1.1 =>.Local IP Adress
                      O17 - HKLM\System\CCS\Services\Tcpip..{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}: DhcpDomain = lan =>.Local Domain
                      O17 - HKLM\System\CCS\Services\Tcpip..{927587AB-1894-493E-8E72-6063314BF69A}: DhcpDomain = lan =>.Local Domain

                      —\ Extra protocols (42) - 3s
                      O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
                      O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
                      O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) – C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
                      O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
                      O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
                      O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
                      O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
                      O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) – C:\Windows\System32\itss.dll =>.Microsoft Corporation
                      O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
                      O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
                      O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
                      O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) – C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation
                      O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) – C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
                      O18 - Handler: ms-help [64Bits] - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) – C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll =>.Microsoft Corporation®
                      O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) – C:\Windows\System32\itss.dll =>.Microsoft Corporation
                      O18 - Handler: osf [64Bits] - {D924BDC6-C83A-4BD5-90D0-095128A113D1} . (.Microsoft Corporation - Microsoft Office 2013 component.) – C:\Program Files\Microsoft Office 15\root\office15\msosb.dll =>.Microsoft Corporation®
                      O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
                      O18 - Handler: skype-ie-addon-data [64Bits] - {91774881-D725-4E58-B298-07617B9B86A8} . (.Skype Technologies S.A. - Skype Click to Call for Internet Explorer.) – C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll =>.Skype Technologies SA®
                      O18 - Handler: skype4com [64Bits] - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} . (.Skype Technologies - Skype4COM.) – C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll =>.Skype Software Sarl®
                      O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) – C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
                      O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) – C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
                      O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Photo Gallery Album Download Protocol Handl.) – C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll =>.Microsoft Corporation®
                      O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) – C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
                      O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) – C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
                      O18 - Filter: application/x-ica [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) – C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O18 - Filter: application/x-ica; charset=euc-jp [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) – C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O18 - Filter: application/x-ica; charset=ISO-8859-1 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) – C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O18 - Filter: application/x-ica; charset=MS936 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) – C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O18 - Filter: application/x-ica; charset=MS949 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) – C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O18 - Filter: application/x-ica; charset=MS950 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) – C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O18 - Filter: application/x-ica; charset=UTF-8 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) – C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O18 - Filter: application/x-ica; charset=UTF8 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) – C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O18 - Filter: application/x-ica;charset=euc-jp [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) – C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O18 - Filter: application/x-ica;charset=ISO-8859-1 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) – C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O18 - Filter: application/x-ica;charset=MS936 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) – C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O18 - Filter: application/x-ica;charset=MS949 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) – C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O18 - Filter: application/x-ica;charset=MS950 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) – C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O18 - Filter: application/x-ica;charset=UTF-8 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) – C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O18 - Filter: application/x-ica;charset=UTF8 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) – C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) – C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
                      O18 - Filter: ica [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) – C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O18 - Filter: text/xml [64Bits] - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) – C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL =>.Microsoft Corporation®

                      —\ Software installed (188) - 53s
                      O42 - Logiciel: 9-lab Removal Tool - (..) [HKLM][64Bits] – 9-lab Removal Tool =>.9-Lab®
                      O42 - Logiciel: Adobe Acrobat Reader DC - (.Adobe Systems Incorporated.) [HKLM][64Bits] – {AC76BA86-7AD7-1033-7B44-AC0F074E4100} =>.Adobe Systems Incorporated
                      O42 - Logiciel: Adobe Flash Player 24 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] – Adobe Flash Player ActiveX =>.Adobe Systems Incorporated®
                      O42 - Logiciel: Adobe Flash Player 24 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] – Adobe Flash Player NPAPI =>.Adobe Systems Incorporated®
                      O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] – {AC76BA86-0804-1033-1959-001824211354} =>.Adobe Systems Incorporated
                      O42 - Logiciel: Alps Pointing-device for VAIO - (.ALPS ELECTRIC CO., LTD..) [HKLM][64Bits] – {9F72EF8B-AEC9-4CA5-B483-143980AFD6FD} =>.Alps Electric Co., LTD.®
                      O42 - Logiciel: Apple Application Support (32-bit) - (.Apple Inc..) [HKLM][64Bits] – {9BA1A894-B42F-4805-BC8C-349C905A3930} =>.Apple Inc.
                      O42 - Logiciel: Apple Application Support (64-bit) - (.Apple Inc..) [HKLM][64Bits] – {7EAC8A42-9FAC-4F6B-AABF-C08C9F2E0F13} =>.Apple Inc.
                      O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM][64Bits] – {55BB2110-FB43-49B3-93F4-945A0CFB0A6C} =>.Apple Inc.
                      O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM][64Bits] – {56EC47AA-5813-4FF6-8E75-544026FBEA83} =>.Apple Inc.
                      O42 - Logiciel: ArcSoft Magic-i Visual Effects 2 - (.ArcSoft.) [HKLM][64Bits] – {7BB90344-0647-468E-925A-7F69F7983421} =>.ArcSoft
                      O42 - Logiciel: ArcSoft WebCam Companion 3 - (.ArcSoft.) [HKLM][64Bits] – {DE8AAC73-6D8D-483E-96EA-CAEDDADB9079} =>.ArcSoft
                      O42 - Logiciel: ATI Catalyst Install Manager - (.ATI Technologies, Inc..) [HKLM][64Bits] – {5BC83141-83DD-07BE-C940-04B385540F04} =>.ATI Technologies, Inc.
                      O42 - Logiciel: ATP DIGITAL 6 - (.ATP DIGITAL.) [HKLM][64Bits] – {0C264625-303E-4458-93BB-B95CA9CB0209}
                      O42 - Logiciel: Avira Antivirus v15.0.25.154 - (.Avira Operations GmbH & Co. KG.) [HKLM][64Bits] – Avira Antivirus =>.Avira Operations GmbH & Co. KG®
                      O42 - Logiciel: Avira Connect v1.2.77.41287 - (.Avira Operations GmbH & Co. KG.) [HKLM][64Bits] – {7774002B-60B3-4146-BF82-5BF767D468B8} =>.Avira Operations GmbH & Co. KG
                      O42 - Logiciel: Avira Connect v1.2.77.41287 - (.Avira Operations GmbH & Co. KG.) [HKLM][64Bits] – {845380e2-f0b5-4584-bc40-cc54345b3c06} =>.Avira Operations GmbH & Co. KG®
                      O42 - Logiciel: Avira Phantom VPN v2.6.1.20906 - (.Avira Operations GmbH & Co. KG.) [HKLM][64Bits] – Avira Phantom VPN =>.Avira Operations GmbH & Co. KG®
                      O42 - Logiciel: Avira Scout v17.1.2924.2344 - (.Avira Operations GmbH & Co. KG.) [HKLM][64Bits] – Avira Scout =>.Avira Operations GmbH & Co. KG®
                      O42 - Logiciel: Aware System Update - (.Airbox Aerospace Ltd.) [HKCU][64Bits] – b9355229a2e7c67c
                      O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM][64Bits] – {56DDDFB8-7F79-4480-89D5-25E1F52AB28F} =>.Apple Inc.
                      O42 - Logiciel: Canon MOV Decoder - (.Canon Inc..) [HKLM][64Bits] – Canon MOV Decoder =>.Canon Inc.®
                      O42 - Logiciel: Canon MOV Encoder - (.Canon Inc..) [HKLM][64Bits] – Canon MOV Encoder =>.Canon Inc.®
                      O42 - Logiciel: Canon MovieEdit Task for ZoomBrowser EX - (.Canon Inc..) [HKLM][64Bits] – MovieEditTask =>.Canon Inc.®
                      O42 - Logiciel: Canon Utilities CameraWindow - (.Canon Inc..) [HKLM][64Bits] – CameraWindowLauncher =>.Canon Inc.®
                      O42 - Logiciel: Canon Utilities CameraWindow DC - (.Canon Inc..) [HKLM][64Bits] – CameraWindowDC =>.Canon Inc.®
                      O42 - Logiciel: Canon Utilities CameraWindow DC 8 - (.Canon Inc..) [HKLM][64Bits] – CameraWindowDC8 =>.Canon Inc.®
                      O42 - Logiciel: Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX - (.Canon Inc..) [HKLM][64Bits] – CameraWindowDVC6 =>.Canon Inc.®
                      O42 - Logiciel: Canon Utilities MyCamera - (.Canon Inc..) [HKLM][64Bits] – MyCamera =>.Canon Inc.®
                      O42 - Logiciel: Canon Utilities MyCamera DC - (.Canon Inc..) [HKLM][64Bits] – MyCameraDC =>.Canon Inc.®
                      O42 - Logiciel: Canon Utilities PhotoStitch - (.Canon Inc..) [HKLM][64Bits] – PhotoStitch =>.Canon Inc.®
                      O42 - Logiciel: Canon Utilities RemoteCapture Task for ZoomBrowser EX - (.Canon Inc..) [HKLM][64Bits] – RemoteCaptureTask =>.Canon Inc.®
                      O42 - Logiciel: Canon Utilities ZoomBrowser EX - (.Canon Inc..) [HKLM][64Bits] – ZoomBrowser EX =>.Canon Inc.®
                      O42 - Logiciel: Canon ZoomBrowser EX Memory Card Utility - (.Canon Inc..) [HKLM][64Bits] – ZoomBrowser EX Memory Card Utility =>.Canon Inc.®
                      O42 - Logiciel: Catalyst Control Center - Branding - (.ATI.) [HKLM][64Bits] – {C5529BC1-C2BF-44E8-B62A-01913D70081C} =>.ATI
                      O42 - Logiciel: Catalyst Control Center Core Implementation - (.ATI.) [HKLM][64Bits] – {5736590B-36C7-4881-5EBE-F9B390F00774} =>.ATI
                      O42 - Logiciel: Catalyst Control Center Graphics Full Existing - (.ATI.) [HKLM][64Bits] – {88001121-87E2-2104-F9F5-ECC15DFCA1E0} =>.ATI
                      O42 - Logiciel: Catalyst Control Center Graphics Full New - (.ATI.) [HKLM][64Bits] – {A8D53A4E-77A1-E23E-A396-6D9C86A2F273} =>.ATI
                      O42 - Logiciel: Catalyst Control Center Graphics Light - (.ATI.) [HKLM][64Bits] – {265F0D95-A883-7162-0458-B78085B6B693} =>.ATI
                      O42 - Logiciel: Catalyst Control Center Graphics Previews Common - (.ATI.) [HKLM][64Bits] – {D49989B0-7BC2-F7F1-8017-3257F617347A} =>.ATI
                      O42 - Logiciel: Catalyst Control Center Graphics Previews Vista - (.ATI.) [HKLM][64Bits] – {C2E171F6-9B58-4CE1-7B8B-B69FA04EBAB8} =>.ATI
                      O42 - Logiciel: Catalyst Control Center InstallProxy - (.ATI Technologies, Inc..) [HKLM][64Bits] – {935B5086-C002-0FBC-0723-5741D2478EE7} =>.ATI Technologies, Inc.
                      O42 - Logiciel: Catalyst Control Center InstallProxy - (.ATI Technologies, Inc..) [HKLM][64Bits] – {F7E8DD1D-9BFD-38BB-86A5-BEF313B00C51} =>.ATI Technologies, Inc.
                      O42 - Logiciel: Catalyst Control Center Localization All - (.ATI.) [HKLM][64Bits] – {F5CC9A13-6C57-4948-75A8-3A2C92A3183B} =>.ATI
                      O42 - Logiciel: ccc-core-static - (.ATI.) [HKLM][64Bits] – {F1B95046-E9DA-CFEC-42A8-C8224646AA32} =>.ATI
                      O42 - Logiciel: ccc-utility64 - (.ATI.) [HKLM][64Bits] – {259FD439-13B0-0136-D0A0-FA89BB05831D} =>.ATI
                      O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] – CCleaner =>.Piriform Ltd®
                      O42 - Logiciel: Chinese Traditional Fonts Support For Adobe Reader 9 - (.Adobe Systems Incorporated.) [HKLM][64Bits] – {AC76BA86-7AD7-2448-0000-900000000003} =>.Adobe Systems Incorporated
                      O42 - Logiciel: Citrix Authentication Manager - (.Citrix Systems, Inc..) [HKLM][64Bits] – {CA55005D-94AC-4596-9646-679D6CC0D620} =>.Citrix Systems, Inc.
                      O42 - Logiciel: Citrix Receiver - (.Citrix Systems, Inc..) [HKLM][64Bits] – CitrixOnlinePluginPackWeb {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
                      O42 - Logiciel: Citrix Receiver (HDX Flash Redirection) - (.Citrix Systems, Inc..) [HKLM][64Bits] – {C4E28723-0663-4012-9BDC-E21A14C1316C} =>.Citrix Systems, Inc.
                      O42 - Logiciel: Citrix Receiver Inside - (.Citrix Systems, Inc..) [HKLM][64Bits] – {D9EE360A-7C19-47EC-93C7-97DEFF64804B} =>.Citrix Systems, Inc.
                      O42 - Logiciel: Citrix Receiver Updater - (.Citrix Systems, Inc..) [HKLM][64Bits] – {5E8AC853-65BB-4C99-A09E-19B81851E14C} =>.Citrix Systems, Inc.
                      O42 - Logiciel: Citrix Receiver(Aero) - (.Citrix Systems, Inc..) [HKLM][64Bits] – {012C59CF-074A-43DA-8085-B6E636733B59} =>.Citrix Systems, Inc.
                      O42 - Logiciel: Citrix Receiver(DV) - (.Citrix Systems, Inc..) [HKLM][64Bits] – {ADE8A83D-BB70-4FB5-BA19-26C47EA31894} =>.Citrix Systems, Inc.
                      O42 - Logiciel: Citrix Receiver(USB) - (.Citrix Systems, Inc..) [HKLM][64Bits] – {0E1C5B43-1837-4F98-A96B-79A8A0A5955F} =>.Citrix Systems, Inc.
                      O42 - Logiciel: Click to Disc MergeModules x64 - (.Sony Corporation.) [HKLM][64Bits] – {393A9268-A428-4F5A-9B20-BD753309A98E} =>.Sony Corporation
                      O42 - Logiciel: Corel WinDVD - (.Corel Inc..) [HKLM][64Bits] – {5C1F18D2-F6B7-4242-B803-B5A78648185D} =>.Corel Inc.
                      O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] – {E09C4DB7-630C-4F06-A631-8EA7239923AF} =>.Microsoft
                      O42 - Logiciel: DiskCheckup v3.1 - (.PassMark Software.) [HKLM][64Bits] – DiskCheckup_is1 =>.PassMark Software
                      O42 - Logiciel: Dropbox - (.Dropbox, Inc..) [HKLM][64Bits] – Dropbox =>.Dropbox, Inc®
                      O42 - Logiciel: Dropbox Update Helper - (.Dropbox, Inc..) [HKLM][64Bits] – {099218A5-A723-43DC-8DB5-6173656A1E94} =>.Dropbox, Inc.
                      O42 - Logiciel: Family Tree Maker 2006 - (..) [HKLM][64Bits] – {F2F4C144-7D1A-47C4-9D53-395A57B0CD64}
                      O42 - Logiciel: Free iTunes Backup Extractor version 5.4.0.2 - (.HONGKONG JIHO CO., LIMITED.) [HKLM][64Bits] – {F891E77B-EB1C-4035-BCC4-4DEF91EDD69E}is1
                      O42 - Logiciel: Gleim FAA Test Prep 2010 WebDeploy - (.Gleim.) [HKLM][64Bits] – FAATPWSUEW49 {2A700F66256B25560000A7B9B691F8ED}
                      O42 - Logiciel: Google Earth Plug-in - (.Google.) [HKLM][64Bits] – {57BB4801-61C8-4E74-9672-2160728A461E} =>.Google
                      O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] – {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
                      O42 - Logiciel: GoToMeeting 8.0.0.6441 - (.CitrixOnline.) [HKCU][64Bits] – GoToMeeting =>.Citrix Online®
                      O42 - Logiciel: HL-1110 series - (.Brother Industries, Ltd..) [HKLM][64Bits] – {4F2442B7-A89E-42A4-8F0E-6937499855CA} =>.Macrovision Corporation®
                      O42 - Logiciel: iCloud - (.Apple Inc..) [HKLM][64Bits] – {709A2D23-C25E-47B5-9268-CB6FEE648504} =>.Apple Inc.
                      O42 - Logiciel: Intel(R) Control Center - (.Intel Corporation.) [HKLM][64Bits] – {F8A9085D-4C7A-41a9-8A77-C8998A96C421} =>.Intel Corporation®
                      O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] – {65153EA5-8B6E-43B6-857B-C6E4FC25798A} =>.Intel Corporation®
                      O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] – {3E29EE6C-963A-4aae-86C1-DC237C4A49FC} =>.Intel Corporation®
                      O42 - Logiciel: Intel(R) Turbo Boost Technology Driver - (.Intel Corporation.) [HKLM][64Bits] – {D6C630BF-8DBB-4042-8562-DC9A52CB6E7E} =>.Intel Corporation®
                      O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM][64Bits] – {9D0D2A8B-7E7B-4D88-8D50-24286ED6A5EB} =>.Apple Inc.
                      O42 - Logiciel: Java Auto Updater - (.Sun Microsystems, Inc..) [HKLM][64Bits] – {4A03706F-666A-4037-7777-5F2748764D10} =>.Sun Microsystems, Inc.
                      O42 - Logiciel: Malwarebytes version 3.0.6.1469 - (.Malwarebytes.) [HKLM][64Bits] – {35065F43-4BB2-439A-BFF7-0F1014F2E0CD}is1 =>.Malwarebytes Corporation®
                      O42 - Logiciel: Maxtor Manager - (.Seagate Technology.) [HKLM][64Bits] – {ED01D958-AEDC-40C8-93FD-0C08E8AA9530} =>.Seagate Technology
                      O42 - Logiciel: Maxtor Manager - (.Seagate Technology.) [HKLM][64Bits] – InstallShield
                      {ED01D958-AEDC-40C8-93FD-0C08E8AA9530} {25B1DD7CD102F294C6B4A039166590E7} =>.Seagate Technology
                      O42 - Logiciel: mccPILOTLOG - (.MCC bvba.) [HKLM][64Bits] – {BAA273F2-67DC-4D05-8C1C-5DEE893EAF1E}
                      O42 - Logiciel: Media Gallery - (.Sony Corporation.) [HKLM][64Bits] – {2110ECBD-BF15-4673-8852-8C68DDEB26AC} =>.Sony Corporation
                      O42 - Logiciel: Media Gallery - (.Sony Corporation.) [HKLM][64Bits] – {DD88F979-FA58-41AC-980C-A6E1A82B61D9} =>.Sony Corporation®
                      O42 - Logiciel: Microsoft Application Error Reporting - (.Microsoft Corporation.) [HKLM][64Bits] – {95120000-00B9-0409-1000-0000000FF1CE} =>.Microsoft Corporation
                      O42 - Logiciel: Microsoft Flight Simulator X - (.Microsoft Game Studios.) [HKLM][64Bits] – {9527A496-5DF9-412A-ADC7-168BA5379CA6} =>.Microsoft Game Studios
                      O42 - Logiciel: Microsoft Flight Simulator X - (.Microsoft Game Studios.) [HKLM][64Bits] – InstallShield
                      {9527A496-5DF9-412A-ADC7-168BA5379CA6} =>.Microsoft Game Studios
                      O42 - Logiciel: Microsoft Flight Simulator X Demo - (.Microsoft Game Studios.) [HKLM][64Bits] – {B98A34C0-A6A2-4087-B272-557C1C6D0A07} =>.Microsoft Game Studios
                      O42 - Logiciel: Microsoft Flight Simulator X Demo - (.Microsoft Game Studios.) [HKLM][64Bits] – InstallShield_{B98A34C0-A6A2-4087-B272-557C1C6D0A07} =>.Microsoft Game Studios
                      O42 - Logiciel: Microsoft Flight Simulator X: Acceleration - (.Microsoft Game Studios.) [HKLM][64Bits] – {A9729B90-D37B-4A69-B66A-7436AC1F7274} =>.Microsoft Game Studios
                      O42 - Logiciel: Microsoft Flight Simulator X: Acceleration - (.Microsoft Game Studios.) [HKLM][64Bits] – FlightSim_{A9729B90-D37B-4A69-B66A-7436AC1F7274} =>.Microsoft Game Studios
                      O42 - Logiciel: Microsoft Outlook 2013 - en-us - (.Microsoft Corporation.) [HKLM][64Bits] – OutlookRetail - en-us =>.Microsoft Corporation®
                      O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] – {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation
                      O42 - Logiciel: MSVC80_x64_v2 - (.Nokia.) [HKLM][64Bits] – {4D668D4F-FAA2-4726-834C-31F4614F312E} =>.Nokia
                      O42 - Logiciel: MSVC80_x86_v2 - (.Nokia.) [HKLM][64Bits] – {6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6} =>.Nokia
                      O42 - Logiciel: MSVC90_x64 - (.Nokia.) [HKLM][64Bits] – {AB071C8B-873C-459F-ACA9-9EBE03C3E89B} =>.Nokia
                      O42 - Logiciel: MSVC90_x86 - (.Nokia.) [HKLM][64Bits] – {AF111648-99A1-453E-81DD-80DBBF6DAD0D} =>.Nokia
                      O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] – {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} =>.Microsoft
                      O42 - Logiciel: MSVCRT110 - (.Microsoft.) [HKLM][64Bits] – {8E14DDC8-EA60-4E18-B3E3-1937104D5BDA} =>.Microsoft
                      O42 - Logiciel: MSVCRT110_amd64 - (.Microsoft.) [HKLM][64Bits] – {E9FA781F-3E80-4399-825A-AD3E11C28C77} =>.Microsoft
                      O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM][64Bits] – {86493ADD-824D-4B8E-BD72-8C5DCDC52A71} =>.Microsoft Corporation
                      O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM][64Bits] – {F662A8E6-F4DC-41A2-901E-8C11F044BDEC} =>.Microsoft Corporation
                      O42 - Logiciel: MSXML 4.0 SP2 Parser and SDK - (.Microsoft Corporation.) [HKLM][64Bits] – {716E0306-8318-4364-8B8F-0CC4E9376BAC} =>.Microsoft Corporation
                      O42 - Logiciel: MusicStation - (.Omnifone.) [HKLM][64Bits] – {AB259D46-F851-41B0-9AFA-AED8998AD68A} =>.Omnifone
                      O42 - Logiciel: Office 15 Click-to-Run Extensibility Component - (.Microsoft Corporation.) [HKLM][64Bits] – {90150000-008C-0000-0000-0000000FF1CE} =>.Microsoft Corporation
                      O42 - Logiciel: Office 15 Click-to-Run Licensing Component - (.Microsoft Corporation.) [HKLM][64Bits] – {90150000-008F-0000-1000-0000000FF1CE} =>.Microsoft Corporation
                      O42 - Logiciel: Office 15 Click-to-Run Localization Component - (.Microsoft Corporation.) [HKLM][64Bits] – {90150000-008C-0409-0000-0000000FF1CE} =>.Microsoft Corporation
                      O42 - Logiciel: Online Plug-in - (.Citrix Systems, Inc..) [HKLM][64Bits] – {F390D923-76F1-458E-8218-8C0C156CDCFD} =>.Citrix Systems, Inc.
                      O42 - Logiciel: PMB - (.Sony Corporation.) [HKLM][64Bits] – {B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C} =>.Sony Corporation
                      O42 - Logiciel: PMB VAIO Edition Guide - (.Sony Corporation.) [HKLM][64Bits] – {339F9B4D-00CB-4C1C-BED8-EC86A9AB602A} =>.Sony Corporation
                      O42 - Logiciel: PMB VAIO Edition plug-in (Click to Disc) - (.Sony Corporation.) [HKLM][64Bits] – {4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF} =>.Sony Corporation
                      O42 - Logiciel: PMB VAIO Edition plug-in (Click to Disc) - (.Sony Corporation.) [HKLM][64Bits] – InstallShield_{4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF} =>.Sony Corporation
                      O42 - Logiciel: PMB VAIO Edition plug-in (VAIO Image Optimizer) - (.Sony Corporation.) [HKLM][64Bits] – {1873FFC1-FDCB-47E1-B7C7-F418211E3530} =>.Sony Corporation
                      O42 - Logiciel: PMB VAIO Edition plug-in (VAIO Image Optimizer) - (.Sony Corporation.) [HKLM][64Bits] – InstallShield_{1873FFC1-FDCB-47E1-B7C7-F418211E3530} =>.Sony Corporation
                      O42 - Logiciel: PMB VAIO Edition plug-in (VAIO Movie Story) - (.Sony Corporation.) [HKLM][64Bits] – {B25563A0-41F4-4A81-A6C1-6DBC0911B1F3} =>.Sony Corporation
                      O42 - Logiciel: PMB VAIO Edition plug-in (VAIO Movie Story) - (.Sony Corporation.) [HKLM][64Bits] – InstallShield_{B25563A0-41F4-4A81-A6C1-6DBC0911B1F3} =>.Sony Corporation
                      O42 - Logiciel: PMDG 737 8900 NGX Base Package FSX - (.PMDG Simulations, LLC..) [HKLM][64Bits] – {20708FD5-E94D-4097-A21E-E28564CDBC06} =>.PMDG Simulations, LLC.
                      O42 - Logiciel: QuickTime 7 - (.Apple Inc..) [HKLM][64Bits] – {FF59BD75-466A-4D5A-AD23-AAD87C5FD44C} =>Riskware.QuickTime
                      O42 - Logiciel: Radio Aids Navigation Tutor XL Release 4 - (.Oddsoft Limited.) [HKLM][64Bits] – Radio Aids Navigation Tutor XL_is1
                      O42 - Logiciel: RANT XL V 6.13 - (.Oddsoft Limited.) [HKLM][64Bits] – Radio Aids Navigation Tutor XL Release 4_is1
                      O42 - Logiciel: Realtek HDMI Audio Driver for ATI - (.Realtek Semiconductor Corp..) [HKLM][64Bits] – {5449FB4F-1802-4D5B-A6D8-087DB1142147} =>.Realtek Semiconductor Corp®
                      O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] – {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp.
                      O42 - Logiciel: RogueKiller version 12.9.9.0 - (.Adlice Software.) [HKLM][64Bits] – 8B3D7924-ED89-486B-8322-E8594065D5CB_is1 =>.Adlice®
                      O42 - Logiciel: Roxio Central Audio - (.Roxio.) [HKLM][64Bits] – {73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83} =>.Roxio
                      O42 - Logiciel: Roxio Central Copy - (.Roxio.) [HKLM][64Bits] – {B6A26DE5-F2B5-4D58-9570-4FC760E00FCD} =>.Roxio
                      O42 - Logiciel: Roxio Central Core - (.Roxio.) [HKLM][64Bits] – {ED439A64-F018-4DD4-8BA5-328D85AB09AB} =>.Roxio
                      O42 - Logiciel: Roxio Central Data - (.Roxio.) [HKLM][64Bits] – {08E81ABD-79F7-49C2-881F-FD6CB0975693} =>.Roxio
                      O42 - Logiciel: Roxio Central Tools - (.Roxio.) [HKLM][64Bits] – {1F54DAFA-9261-4A62-B59D-6C9F26B48FE4} =>.Roxio
                      O42 - Logiciel: Roxio Easy Media Creator 10 LJ - (.Roxio.) [HKLM][64Bits] – {537BF16E-7412-448C-95D8-846E85A1D817} =>.Sonic Solutions®
                      O42 - Logiciel: Roxio Easy Media Creator Home - (.Roxio.) [HKLM][64Bits] – {FE51662F-D8F6-43B5-99D9-D4894AF00F83} =>.Roxio
                      O42 - Logiciel: SeaTools for Windows - (.Seagate Technology.) [HKLM][64Bits] – {98613C99-1399-416C-A07C-1EE1C585D872} =>.Seagate Technology
                      O42 - Logiciel: Self-service Plug-in - (.Citrix Systems, Inc..) [HKLM][64Bits] – {47117FCA-0D00-4B6D-9D68-00B763629463} =>.Citrix Systems, Inc.
                      O42 - Logiciel: Setting Utility Series - (.Sony Corporation.) [HKLM][64Bits] – {A7DA438C-2E43-4C20-BFDA-C1F4A6208558} =>.Sony Corporation®
                      O42 - Logiciel: Setup_msm_VCMS_x64 - (.Sony Corporation.) [HKLM][64Bits] – {1C6B6716-84AC-412A-A296-247D41EBB7FB} =>.Sony Corporation
                      O42 - Logiciel: Setup_msm_VOFS_x64 - (.Sony Corporation.) [HKLM][64Bits] – {C69A835B-67A5-4542-AD24-FE36E3140BA9} =>.Sony Corporation
                      O42 - Logiciel: Setup_VEP_x64_Contain_SSDB - (.Sony Corporation.) [HKLM][64Bits] – {7ECD4ACB-E1B6-425B-B8AA-5761A59B77E0} =>.Sony Corporation
                      O42 - Logiciel: Skype Click to Call - (.Skype Technologies S.A..) [HKLM][64Bits] – {B6CF2967-C81E-40C0-9815-C05774FEF120} =>.Skype Technologies S.A.
                      O42 - Logiciel: Skype™ 7.32 - (.Skype Technologies S.A..) [HKLM][64Bits] – {FC965A47-4839-40CA-B618-18F486F042C6} =>.Skype Technologies S.A.
                      O42 - Logiciel: SOHLib Merge Module - (.Sony Corporation.) [HKLM][64Bits] – {4A221E47-E361-45C3-886A-7B2D7AD0E5AA} =>.Sony Corporation
                      O42 - Logiciel: Sony Home Network Library - (.Sony Corporation.) [HKLM][64Bits] – {9B163B82-3B46-4CE5-BF01-A53E550A8E58} =>.Sony Corporation
                      O42 - Logiciel: SUPERAntiSpyware - (.SUPERAntiSpyware.com.) [HKLM][64Bits] – {CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA} =>.SUPERAntiSpyware.com®
                      O42 - Logiciel: VAIO - PMB VAIO Edition Guide - (.Sony Corporation.) [HKLM][64Bits] – InstallShield_{339F9B4D-00CB-4C1C-BED8-EC86A9AB602A} =>.Sony Corporation
                      O42 - Logiciel: VAIO BD Menu Data - (.Sony Corporation.) [HKLM][64Bits] – {DF0415CC-0563-407F-B560-9B7F277122C5} =>.Macrovision Corporation®
                      O42 - Logiciel: VAIO Care - (.Sony Corporation.) [HKLM][64Bits] – {36C5BBF0-E5BF-4DE1-B684-7E90B0C93FB5} =>.Sony Corporation®
                      O42 - Logiciel: VAIO Care - (.Sony Corporation.) [HKLM][64Bits] – {D531F5A4-18F6-4130-B9A4-9179D6E349FC} =>.Sony Corporation
                      O42 - Logiciel: VAIO Content Metadata Intelligent Analyzing Manager - (.Sony Corporation.) [HKLM][64Bits] – {A1255354-11F3-4D25-95CC-C9B1C2320761} =>.Sony Corporation
                      O42 - Logiciel: VAIO Content Metadata Intelligent Analyzing Manager - (.Sony Corporation.) [HKLM][64Bits] – {B1DADBEB-7F82-4B29-84D6-5F14A020F0A0} =>.Sony Corporation
                      O42 - Logiciel: VAIO Content Metadata Intelligent Network Service Manager - (.Sony Corporation.) [HKLM][64Bits] – {725D5BA4-E9FA-452B-8CF5-D7E5F8055C71} =>.Sony Corporation
                      O42 - Logiciel: VAIO Content Metadata Manager Settings - (.Sony Corporation.) [HKLM][64Bits] – {8FE3CF66-4484-4D39-B47D-DEBBA173619D} =>.Sony Corporation
                      O42 - Logiciel: VAIO Content Metadata XML Interface Library - (.Sony Corporation.) [HKLM][64Bits] – {97C58294-36D8-4594-8A49-7AB4AE096504} =>.Sony Corporation
                      O42 - Logiciel: VAIO Content Monitoring Settings - (.Sony Corporation.) [HKLM][64Bits] – {06C05B90-2127-4933-8ABA-61833BDE13FA} =>.Sony Corporation
                      O42 - Logiciel: VAIO Control Center - (.Sony Corporation.) [HKLM][64Bits] – {72042FA6-5609-489F-A8EA-3C2DD650F667} =>.Sony Corporation®
                      O42 - Logiciel: VAIO Data Restore Tool - (.Sony Corporation.) [HKLM][64Bits] – {34DC654E-6E43-4BFA-9E00-6C16CFA7B9F0} =>.Sony Corporation
                      O42 - Logiciel: VAIO Data Restore Tool - (.Sony Corporation.) [HKLM][64Bits] – {57B955CE-B5D3-495D-AF1B-FAEE0540BFEF} =>.Sony Corporation®
                      O42 - Logiciel: VAIO DVD Menu Data - (.Sony Corporation.) [HKLM][64Bits] – {596BED91-A1D8-4DF1-8CD1-1C777F7588AC} =>.Macrovision Corporation®
                      O42 - Logiciel: VAIO Entertainment Platform - (.Sony Corporation.) [HKLM][64Bits] – {0489D044-6386-4BDF-9F98-577D60CF79DD} =>.Sony Corporation
                      O42 - Logiciel: VAIO Event Service - (.Sony Corporation.) [HKLM][64Bits] – {C7477742-DDB4-43E5-AC8D-0259E1E661B1} =>.Sony Corporation®
                      O42 - Logiciel: VAIO Gate - (.Sony Corporation.) [HKLM][64Bits] – {A7C30414-2382-4086-B0D6-01A88ABA21C3} =>.Sony Corporation®
                      O42 - Logiciel: VAIO Gate Default - (.Sony Corporation.) [HKLM][64Bits] – {B7546697-2A80-4256-A24B-1C33163F535B} =>.Sony Corporation®
                      O42 - Logiciel: VAIO Hardware Diagnostics - (.Sony Corporation.) [HKLM][64Bits] – {9DA53D22-D922-494C-B1D7-51CD9BCB9E4A} =>.Sony Corporation
                      O42 - Logiciel: VAIO Marketing Tools - (.Sony Corporation.) [HKLM][64Bits] – MarketingTools =>.Sony Corporation
                      O42 - Logiciel: VAIO Media plus - (.Sony Corporation.) [HKLM][64Bits] – {8DE50158-80AA-4FF2-9E9F-0A7C46F71FCD} =>.Sony Corporation®
                      O42 - Logiciel: VAIO Media plus Opening Movie - (.Sony Corporation.) [HKLM][64Bits] – {9238E8A4-BEBA-43A3-B926-769BDBF194C5} =>.Sony Corporation®
                      O42 - Logiciel: VAIO Movie Story MergeModules x64 - (.Sony Corporation.) [HKLM][64Bits] – {C37B6246-7D4A-4E5C-BFB4-11C8660BDC99} =>.Sony Corporation
                      O42 - Logiciel: VAIO Original Function Settings - (.Sony Corporation.) [HKLM][64Bits] – {04EAE65A-CDCF-480F-B754-5C3A9364239C} =>.Sony Corporation
                      O42 - Logiciel: VAIO Personalization Manager - (.Sony Corporation.) [HKLM][64Bits] – {DBB823F3-E8BD-4578-9D16-42AF176FD777} =>.Sony Corporation
                      O42 - Logiciel: VAIO Power Management - (.Sony Corporation.) [HKLM][64Bits] – {803E4FA5-A940-4420-B89D-A8BC2E160247} =>.Sony Corporation®
                      O42 - Logiciel: VAIO Premium Partners - (.Sony Europe.) [HKLM][64Bits] – VAIO Premium Partners =>.Sony Europe
                      O42 - Logiciel: VAIO Quick Web Access - (.Sony Corporation.) [HKLM][64Bits] – {5A92468F-3ED8-4F96-A9E1-4F176C80EC29} =>.Sony Corporation
                      O42 - Logiciel: VAIO Quick Web Access - (.Sony Corporation.) [HKLM][64Bits] – splashtop =>.Sony Corporation
                      O42 - Logiciel: VAIO screensaver - (.Sony Europe.) [HKLM][64Bits] – VAIO screensaver =>.Sony Europe
                      O42 - Logiciel: VAIO Smart Network - (.Sony Corporation.) [HKLM][64Bits] – {0899D75A-C2FC-42EA-A702-5B9A5F24EAD5} =>.Sony Corporation
                      O42 - Logiciel: VAIO Transfer Support - (.Sony Corporation.) [HKLM][64Bits] – {5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF} =>.Sony Corporation®
                      O42 - Logiciel: VAIO Update - (.Sony Corporation.) [HKLM][64Bits] – {5BEE8F1F-BD32-4553-8107-500439E43BD7} =>.Sony Corporation®
                      O42 - Logiciel: VAIO Update Merge Module x64 - (.Sony Corporation.) [HKLM][64Bits] – {11D25EF7-85FC-4B58-8278-485939C8637F} =>.Sony Corporation
                      O42 - Logiciel: VAIO Wallpaper Contents - (.Sony Corporation.) [HKLM][64Bits] – {D60F97EC-EF06-4E1E-B0D1-C2CBABA62FA3} =>.Sony Corporation®
                      O42 - Logiciel: Visual Studio 2008 x64 Redistributables - (.AVG Technologies.) [HKLM][64Bits] – {FCDBEA60-79F0-4FAE-BBA8-55A26C609A49} =>.AVG Technologies
                      O42 - Logiciel: Visual Studio 2010 x64 Redistributables - (.AVG Technologies.) [HKLM][64Bits] – {21B133D6-5979-47F0-BE1C-F6A6B304693F} =>.AVG Technologies
                      O42 - Logiciel: Visual Studio 2012 x64 Redistributables - (.AVG Technologies.) [HKLM][64Bits] – {8C775E70-A791-4DA8-BCC3-6AB7136F4484} =>.AVG Technologies
                      O42 - Logiciel: Visual Studio 2012 x86 Redistributables - (.AVG Technologies CZ, s.r.o..) [HKLM][64Bits] – {98EFF19A-30AB-4E4B-B943-F06B1C63EBF8} =>.AVG Technologies CZ, s.r.o.
                      O42 - Logiciel: WD Backup - (.Western Digital Technologies, Inc.) [HKLM][64Bits] – {4AACAFC7-951A-4215-B430-3DFCFF2E6CED} =>.Western Digital Technologies, Inc
                      O42 - Logiciel: WD Backup - (.Western Digital Technologies, Inc..) [HKLM][64Bits] – {a8c9535a-ecd9-4172-a330-0cb5ff9dbed9} =>.WESTERN DIGITAL TECHNOLOGIES®
                      O42 - Logiciel: WD Drive Utilities - (.Western Digital Technologies, Inc..) [HKLM][64Bits] – {48996CDD-DD81-4197-93FE-0971E73C5CA7} =>.Western Digital Technologies, Inc.
                      O42 - Logiciel: WD Drive Utilities - (.Western Digital Technologies, Inc..) [HKLM][64Bits] – {eab1fb93-61fb-48de-b815-b4e9b68d2ef1} =>.Western Digital Technologies, Inc.®
                      O42 - Logiciel: Wickr Me - (.Wickr Inc..) [HKLM][64Bits] – {7668652D-F198-4E7B-8FF4-5E2DC13D9AD7}
                      O42 - Logiciel: WIDCOMM Bluetooth Software - (.Broadcom Corporation.) [HKLM][64Bits] – {9E9D49A4-1DF4-4138-B7DB-5D87A893088E} =>.Broadcom Corporation
                      O42 - Logiciel: Windows Driver Package - Broadcom Bluetooth (09/09/2009 6.2.0.9405) - (.Broadcom.) [HKLM][64Bits] – 930E4792BDAEAFB62A9514EE7578775658A5D07C =>.Microsoft Windows Component Publisher®
                      O42 - Logiciel: Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) - (.Broadcom.) [HKLM][64Bits] – 3BA80AB4C7E9F8497C115C844953A3D4BEB84D21 =>.Microsoft Windows Component Publisher®
                      O42 - Logiciel: Windows Installer Clean Up - (.Microsoft Corporation.) [HKLM][64Bits] – {121634B0-2F4A-11D3-ADA3-00C04F52DD53} =>.Microsoft Corporation
                      O42 - Logiciel: Windows Mobile Device Center - (.Microsoft Corporation.) [HKLM][64Bits] – {626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B} =>.Microsoft Corporation

                      —\ HKCU & HKLM Software Keys (154) - 53s
                      HKLM\SOFTWARE\Wow6432Node\Adobe =>.Adobe
                      HKLM\SOFTWARE\Wow6432Node\Adware Removal Tool by TSA =>.TSA Softwares
                      HKLM\SOFTWARE\Wow6432Node\Amazon =>.Amazon
                      HKLM\SOFTWARE\Wow6432Node\America Online =>.America Online
                      HKLM\SOFTWARE\Wow6432Node\Apple Computer, Inc. =>.Apple Computer, Inc.
                      HKLM\SOFTWARE\Wow6432Node\Apple Inc. =>.Apple Inc.
                      HKLM\SOFTWARE\Wow6432Node\ArcSoft =>.ArcSoft
                      HKLM\SOFTWARE\Wow6432Node\ATI =>.ATI
                      HKLM\SOFTWARE\Wow6432Node\ATI Technologies =>.ATI Technologies
                      HKLM\SOFTWARE\Wow6432Node\ATP DIGITAL
                      HKLM\SOFTWARE\Wow6432Node\AVG =>.AVG Software
                      HKLM\SOFTWARE\Wow6432Node\Avg Secure Update =>.AVG Software
                      HKLM\SOFTWARE\Wow6432Node\Avira =>.Avira
                      HKLM\SOFTWARE\Wow6432Node\BinarySense =>.BinarySense
                      HKLM\SOFTWARE\Wow6432Node\Brother =>.Brother
                      HKLM\SOFTWARE\Wow6432Node\Brother Industries, Ltd. =>.Brother Industries, Ltd.
                      HKLM\SOFTWARE\Wow6432Node\Canon =>.Canon
                      HKLM\SOFTWARE\Wow6432Node\Canon_Inc_IC =>.Canon Inc.
                      HKLM\SOFTWARE\Wow6432Node\Caphyon =>.Caphyon
                      HKLM\SOFTWARE\Wow6432Node\CDDB =>.Cddb Software
                      HKLM\SOFTWARE\Wow6432Node\Citrix =>.Citrix
                      HKLM\SOFTWARE\Wow6432Node\Corel =>.Corel
                      HKLM\SOFTWARE\Wow6432Node\Debug =>.Legitimate
                      HKLM\SOFTWARE\Wow6432Node\Dropbox =>.Dropbox
                      HKLM\SOFTWARE\Wow6432Node\DropboxUpdate =>.Dropbox Inc.
                      HKLM\SOFTWARE\Wow6432Node\ej-technologies =>.ej-technologies
                      HKLM\SOFTWARE\Wow6432Node\Freemake =>.Freemake
                      HKLM\SOFTWARE\Wow6432Node\Google =>.Google
                      HKLM\SOFTWARE\Wow6432Node\GuidGuid13
                      HKLM\SOFTWARE\Wow6432Node\illiminable =>.illiminable
                      HKLM\SOFTWARE\Wow6432Node\IM Providers =>.IM Providers
                      HKLM\SOFTWARE\Wow6432Node\InstallShield =>.InstallShield
                      HKLM\SOFTWARE\Wow6432Node\Intel =>.Intel
                      HKLM\SOFTWARE\Wow6432Node\JavaSoft =>.JavaSoft
                      HKLM\SOFTWARE\Wow6432Node\JreMetrics =>.JreMetrics
                      HKLM\SOFTWARE\Wow6432Node\Licenses =>.Microsoft Corporation
                      HKLM\SOFTWARE\Wow6432Node\Macromedia =>.Macromedia
                      HKLM\SOFTWARE\Wow6432Node\Macrovision =>.Macrovision
                      HKLM\SOFTWARE\Wow6432Node\Maxtor =>.Maxtor
                      HKLM\SOFTWARE\Wow6432Node\McAfee =>.McAfee Inc.
                      HKLM\SOFTWARE\Wow6432Node\McAfee.com =>.McAfee Inc.
                      HKLM\SOFTWARE\Wow6432Node\McAfeeInstaller =>.McAfee Inc.
                      HKLM\SOFTWARE\Wow6432Node\Mozilla =>.Mozilla
                      HKLM\SOFTWARE\Wow6432Node\mozilla.org =>.mozilla.org
                      HKLM\SOFTWARE\Wow6432Node\MozillaPlugins =>.MozillaPlugins
                      HKLM\SOFTWARE\Wow6432Node\MyFamily.com
                      HKLM\SOFTWARE\Wow6432Node\NewHouse
                      HKLM\SOFTWARE\Wow6432Node\Nokia =>.Nokia
                      HKLM\SOFTWARE\Wow6432Node\ODBC =>.DB Connectivity Solutions
                      HKLM\SOFTWARE\Wow6432Node\Oddsoft
                      HKLM\SOFTWARE\Wow6432Node\Piriform =>.Piriform
                      HKLM\SOFTWARE\Wow6432Node\PMDG Simulations, LLC. =>.PMDG Simulations, LLC.
                      HKLM\SOFTWARE\Wow6432Node\PocketSoft
                      HKLM\SOFTWARE\Wow6432Node\Realtek =>.Realtek Semiconductor Corp.
                      HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp. =>.Realtek Semiconductor Corp.
                      HKLM\SOFTWARE\Wow6432Node\Roxio =>.Roxio
                      HKLM\SOFTWARE\Wow6432Node\Skype =>.Skype
                      HKLM\SOFTWARE\Wow6432Node\Sonic =>.Sonic
                      HKLM\SOFTWARE\Wow6432Node\Sony =>.Sony
                      HKLM\SOFTWARE\Wow6432Node\Sony Corporation =>.Sony Corporation
                      HKLM\SOFTWARE\Wow6432Node\SourceCodeControlProvide r =>.Microsoft Corporation
                      HKLM\SOFTWARE\Wow6432Node\VideoLAN =>.VideoLAN
                      HKLM\SOFTWARE\Wow6432Node\Volatile =>.Microsoft Corporation
                      HKLM\SOFTWARE\Wow6432Node\WafCX =>.WafCX
                      HKLM\SOFTWARE\Wow6432Node\Western Digital =>.Western Digital
                      HKLM\SOFTWARE\Wow6432Node\Wickr
                      HKLM\SOFTWARE\Wow6432Node\Windows =>.Microsoft Corporation
                      HKLM\SOFTWARE\Wow6432Node\Wondershare =>.Wondershare
                      HKLM\SOFTWARE\Wow6432Node\X-AVCSD =>.Avira Software
                      HKLM\SOFTWARE\Wow6432Node\RegisteredApplications =>.Microsoft Corporation
                      HKCU\SOFTWARE\9-lab =>.9-lab
                      HKCU\SOFTWARE\Adobe =>.Adobe
                      HKCU\SOFTWARE\Alps =>.ALPS
                      HKCU\SOFTWARE\Amazon =>.Amazon
                      HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
                      HKCU\SOFTWARE\Apple Computer, Inc. =>.Apple Computer, Inc.
                      HKCU\SOFTWARE\Apple Inc. =>.Apple Inc.
                      HKCU\SOFTWARE\ArcSoft =>.ArcSoft
                      HKCU\SOFTWARE\ATI =>.ATI
                      HKCU\SOFTWARE\Aurigma =>.Aurigma
                      HKCU\SOFTWARE\Avg =>.AVG Software
                      HKCU\SOFTWARE\Avg Secure Update =>.AVG Software
                      HKCU\SOFTWARE\AVG Web TuneUp =>.AVG Web TuneUp
                      HKCU\SOFTWARE\Avira =>.Avira
                      HKCU\SOFTWARE\BinarySense =>.BinarySense
                      HKCU\SOFTWARE\Brother =>.Brother
                      HKCU\SOFTWARE\Canon =>.Canon
                      HKCU\SOFTWARE\Canon_Inc_IC =>.Canon Inc.
                      HKCU\SOFTWARE\CDDB =>.Cddb Software
                      HKCU\SOFTWARE\Citrix =>.Citrix
                      HKCU\SOFTWARE\Corel =>.Corel
                      HKCU\SOFTWARE\DatCard
                      HKCU\SOFTWARE\Dropbox =>.Dropbox
                      HKCU\SOFTWARE\DropboxUpdate =>.Dropbox Inc.
                      HKCU\SOFTWARE\EasyBits =>.EasyBits
                      HKCU\SOFTWARE\ej-technologies =>.ej-technologies
                      HKCU\SOFTWARE\Evaer
                      HKCU\SOFTWARE\Evernote =>.Evernote
                      HKCU\SOFTWARE\FLEXlm License Manager =>.FlexNet
                      HKCU\SOFTWARE\Freemake =>.Freemake
                      HKCU\SOFTWARE\G4FON Software
                      HKCU\SOFTWARE\GARMIN International =>.Garmin Ltd
                      HKCU\SOFTWARE\Geek Uninstaller =>.Geek Uninstaller
                      HKCU\SOFTWARE\Gleim
                      HKCU\SOFTWARE\Google =>.Google
                      HKCU\SOFTWARE\IM Providers =>.IM Providers
                      HKCU\SOFTWARE\Imobie =>.iMobie Inc
                      HKCU\SOFTWARE\JavaSoft =>.JavaSoft
                      HKCU\SOFTWARE\JEDI-VCL =>.JEDI Project
                      HKCU\SOFTWARE\Jihosoft =>.Jihosoft
                      HKCU\SOFTWARE\Lake =>.Lake Sofware
                      HKCU\SOFTWARE\LANGAGENT =>.LangAgent
                      HKCU\SOFTWARE\LAV =>.LAV Inc
                      HKCU\SOFTWARE\Licenses =>.Microsoft Corporation
                      HKCU\SOFTWARE\Local AppWizard-Generated Applications =>.ZWCAD
                      HKCU\SOFTWARE\Macromedia =>.Macromedia
                      HKCU\SOFTWARE\Malwarebytes =>.Malwarebytes
                      HKCU\SOFTWARE\Maxtor =>.Maxtor
                      HKCU\SOFTWARE\MCAFEE =>.McAfee Inc.
                      HKCU\SOFTWARE\Mozilla =>.Mozilla
                      HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins
                      HKCU\SOFTWARE\MyFamily.com
                      HKCU\SOFTWARE\Netscape =>.Netscape
                      HKCU\SOFTWARE\Northcode Inc =>.Northcode Inc
                      HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions
                      HKCU\SOFTWARE\Oddsoft
                      HKCU\SOFTWARE\Piriform =>.Piriform
                      HKCU\SOFTWARE\ProtectedStorage
                      HKCU\SOFTWARE\QtProject =>.QtProject
                      HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
                      HKCU\SOFTWARE\Roxio =>.Roxio
                      HKCU\SOFTWARE\RtkPCEE3sMsg
                      HKCU\SOFTWARE\Settings =>.Samsung Electronics
                      HKCU\SOFTWARE\Skype =>.Skype
                      HKCU\SOFTWARE\SkypeApps =>.Skype Technologies
                      HKCU\SOFTWARE\Sonic =>.Sonic
                      HKCU\SOFTWARE\Sony Corporation =>.Sony Corporation
                      HKCU\SOFTWARE\SpecItems
                      HKCU\SOFTWARE\SUPERAntiSpyware.com =>.SUPERAntiSpyware.com
                      HKCU\SOFTWARE\Sysinternals =>.Sysinternals
                      HKCU\SOFTWARE\Trolltech =>.Trolltech
                      HKCU\SOFTWARE\VFRGenX - Volume 1: South England and South Wales
                      HKCU\SOFTWARE\Western Digital =>.Western Digital
                      HKCU\SOFTWARE\Wickr
                      HKCU\SOFTWARE\Widcomm =>.Widcomm
                      HKCU\SOFTWARE\Wondershare =>.Wondershare
                      HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
                      HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
                      HKCU\SOFTWARE\アプリケーション ウィザードで生成されたローカル アプリケーション
                      HKCU\SOFTWARE\AppDataLow\Google =>.Google
                      HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
                      HKCU\SOFTWARE\AppDataLow\Software\Avg =>.AVG Software
                      HKCU\SOFTWARE\AppDataLow\Software\Citrix =>.Citrix
                      HKCU\SOFTWARE\AppDataLow\Software\Google =>.Google

                      —\ Contents of the Common Files folders (387) - 65s
                      O43 - CFD: 04/03/2017 - D – C:\Program Files\9-lab =>.9-Lab®
                      O43 - CFD: 13/09/2010 - D – C:\Program Files\Apoint =>.Alps Electric Co., LTD.®
                      O43 - CFD: 19/05/2010 - D – C:\Program Files\ATI =>.ATI Technologies, Inc®
                      O43 - CFD: 26/09/2015 - D – C:\Program Files\Bonjour =>.Apple Inc.
                      O43 - CFD: 04/03/2017 - D – C:\Program Files\CCleaner =>.Piriform Ltd
                      O43 - CFD: 25/09/2016 - D – C:\Program Files\Common Files =>.Microsoft Corporation
                      O43 - CFD: 24/10/2010 - D – C:\Program Files\DIFX =>.Microsoft Corporation
                      O43 - CFD: 15/03/2016 - D – C:\Program Files\DVD Maker =>.Aone Software
                      O43 - CFD: 25/09/2010 - [0] D – C:\Program Files\Google =>.Google
                      O43 - CFD: 13/12/2016 - D – C:\Program Files\Internet Explorer =>.Microsoft Corporation
                      O43 - CFD: 01/02/2017 - D – C:\Program Files\iPod =>.Apple Inc.®
                      O43 - CFD: 01/02/2017 - D – C:\Program Files\iTunes =>.Apple Inc.
                      O43 - CFD: 13/09/2010 - D – C:\Program Files\Java =>.Oracle
                      O43 - CFD: 26/02/2017 - D – C:\Program Files\Malwarebytes =>.Malwarebytes
                      O43 - CFD: 24/11/2013 - [0] D – C:\Program Files\McAfee =>.McAfee
                      O43 - CFD: 20/05/2010 - D – C:\Program Files\Microsoft Games =>.Microsoft Corporation
                      O43 - CFD: 30/03/2014 - D – C:\Program Files\Microsoft Office =>.Microsoft Corporation
                      O43 - CFD: 01/03/2017 - D – C:\Program Files\Microsoft Office 15 =>.Microsoft Corporation
                      O43 - CFD: 13/10/2016 - D – C:\Program Files\Microsoft Silverlight =>.Microsoft Corporation
                      O43 - CFD: 13/09/2010 - D – C:\Program Files\Microsoft SQL Server Compact Edition =>.Microsoft Corporation
                      O43 - CFD: 13/09/2010 - D – C:\Program Files\Microsoft Synchronization Services =>.Microsoft Corporation
                      O43 - CFD: 14/07/2009 - D – C:\Program Files\MSBuild =>.Microsoft Corporation
                      O43 - CFD: 13/09/2010 - D – C:\Program Files\Realtek =>.Realtek
                      O43 - CFD: 14/07/2009 - D – C:\Program Files\Reference Assemblies =>.Microsoft Corporation
                      O43 - CFD: 03/03/2017 - D – C:\Program Files\RogueKiller =>.Adlice
                      O43 - CFD: 21/11/2011 - D – C:\Program Files\Sony =>.Sony Corporation®
                      O43 - CFD: 26/02/2017 - D – C:\Program Files\SUPERAntiSpyware =>.SUPERAntiSpyware
                      O43 - CFD: 27/10/2016 - D – C:\Program Files\tinyumbrella
                      O43 - CFD: 14/07/2009 - [0] HD – C:\Program Files\Uninstall Information =>.Microsoft Corporation
                      O43 - CFD: 19/05/2010 - D – C:\Program Files\WIDCOMM =>.Broadcom Corporation®
                      O43 - CFD: 15/03/2016 - D – C:\Program Files\Windows Defender =>.Microsoft Corporation
                      O43 - CFD: 25/09/2010 - D – C:\Program Files\Windows Live =>.Microsoft Corporation
                      O43 - CFD: 15/03/2016 - D – C:\Program Files\Windows Mail =>.Microsoft Corporation
                      O43 - CFD: 25/02/2012 - D – C:\Program Files\Windows Media Player =>.Microsoft Corporation
                      O43 - CFD: 14/07/2009 - D – C:\Program Files\Windows NT =>.Microsoft Corporation
                      O43 - CFD: 03/07/2011 - D – C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
                      O43 - CFD: 03/07/2011 - D – C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
                      O43 - CFD: 15/03/2016 - D – C:\Program Files\Windows Sidebar =>.Microsoft Corporation
                      O43 - CFD: 09/02/2017 - [0] D – C:\Program Files (x86)\7-Zip =>.Igor Pavlov
                      O43 - CFD: 09/02/2017 - D – C:\Program Files (x86)\Adobe =>.Adobe Systems, Incorporated®
                      O43 - CFD: 04/03/2017 - D – C:\Program Files (x86)\Adware Removal Tool by TSA =>.TSA Softwares
                      O43 - CFD: 13/03/2016 - [0] D – C:\Program Files (x86)\Amazon =>.Amazon
                      O43 - CFD: 23/03/2016 - D – C:\Program Files (x86)\Apple Software Update =>.Apple Inc.
                      O43 - CFD: 19/10/2014 - D – C:\Program Files (x86)\ArcSoft =>.ArcSoft
                      O43 - CFD: 04/12/2010 - D – C:\Program Files (x86)\ATI Technologies =>.ATI Technologies
                      O43 - CFD: 26/07/2011 - D – C:\Program Files (x86)\ATP DIGITAL
                      O43 - CFD: 26/02/2017 - D – C:\Program Files (x86)\Avira =>.Avira Software
                      O43 - CFD: 26/09/2016 - D – C:\Program Files (x86)\B737 CBT
                      O43 - CFD: 26/09/2015 - D – C:\Program Files (x86)\Bonjour =>.Apple Inc.
                      O43 - CFD: 11/12/2010 - D – C:\Program Files (x86)\Bristol.gs
                      O43 - CFD: 12/09/2016 - D – C:\Program Files (x86)\Brother =>.Brother
                      O43 - CFD: 14/09/2014 - D – C:\Program Files (x86)\Browny02 =>.Brother Industries, Ltd.
                      O43 - CFD: 14/09/2014 - D – C:\Program Files (x86)\BrownyInd =>.Brother Industries, Ltd.
                      O43 - CFD: 18/12/2010 - D – C:\Program Files (x86)\Canon =>.Canon
                      O43 - CFD: 23/02/2017 - [0] D – C:\Program Files (x86)\Chat Undetected
                      O43 - CFD: 29/10/2013 - D – C:\Program Files (x86)\Citrix =>.Citrix
                      O43 - CFD: 09/02/2017 - D – C:\Program Files (x86)\Common Files =>.Microsoft Corporation
                      O43 - CFD: 13/09/2010 - D – C:\Program Files (x86)\Corel =>.Corel Corporation
                      O43 - CFD: 07/12/2012 - D – C:\Program Files (x86)\DiskCheckup {38E7FA0DB1A398F805BB85A69171DC9D}
                      O43 - CFD: 25/09/2010 - D – C:\Program Files (x86)\Downloaded Installations =>.Microsoft Corporation
                      O43 - CFD: 28/02/2017 - D – C:\Program Files (x86)\Dropbox =>.Dropbox, Inc®
                      O43 - CFD: 08/02/2017 - D – C:\Program Files (x86)\FAATP2010 {138C6B1CEA71EBA363F25979E2DB9AAE}
                      O43 - CFD: 26/09/2010 - D – C:\Program Files (x86)\Family Tree Maker 2006
                      O43 - CFD: 09/11/2010 - D – C:\Program Files (x86)\Freeciv-2.2.2-gtk2
                      O43 - CFD: 12/03/2012 - D – C:\Program Files (x86)\Freeciv-2.2.3-gtk2
                      O43 - CFD: 09/11/2010 - D – C:\Program Files (x86)\freecol
                      O43 - CFD: 13/03/2016 - D – C:\Program Files (x86)\Freemake =>.Freemake
                      O43 - CFD: 25/10/2015 - D – C:\Program Files (x86)\G4FON Software
                      O43 - CFD: 05/03/2017 - D – C:\Program Files (x86)\Google =>.Google Inc®
                      O43 - CFD: 05/03/2017 - D – C:\Program Files (x86)\GUM1B92.tmp =>.Google Inc®
                      O43 - CFD: 05/03/2017 - D – C:\Program Files (x86)\GUM5198.tmp =>.Google Inc®
                      O43 - CFD: 20/03/2016 - HD – C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield Software
                      O43 - CFD: 23/09/2010 - D – C:\Program Files (x86)\Intel =>.Intel Corporation
                      O43 - CFD: 13/12/2016 - D – C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
                      O43 - CFD: 27/10/2016 - D – C:\Program Files (x86)\iTunes =>.Apple Inc.
                      O43 - CFD: 09/04/2016 - D – C:\Program Files (x86)\Jihosoft =>.HONGKONG JIHO CO., LIMITED®
                      O43 - CFD: 02/10/2010 - D – C:\Program Files (x86)\Maxtor {25B1DD7CD102F294C6B4A039166590E7} =>.Maxtor
                      O43 - CFD: 26/11/2013 - D – C:\Program Files (x86)\McAfee =>.McAfee
                      O43 - CFD: 01/01/2016 - D – C:\Program Files (x86)\MCC Pilotlog
                      O43 - CFD: 30/03/2014 - D – C:\Program Files (x86)\Microsoft Analysis Services =>.Microsoft Corporation
                      O43 - CFD: 15/03/2016 - D – C:\Program Files (x86)\Microsoft Games =>.Microsoft Corporation
                      O43 - CFD: 08/03/2015 - D – C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation
                      O43 - CFD: 13/10/2016 - D – C:\Program Files (x86)\Microsoft Silverlight =>.Microsoft Corporation
                      O43 - CFD: 13/09/2010 - D – C:\Program Files (x86)\Microsoft SQL Server Compact Edition =>.Microsoft Corporation
                      O43 - CFD: 13/09/2010 - D – C:\Program Files (x86)\Microsoft Synchronization Services =>.Microsoft Corporation
                      O43 - CFD: 30/03/2014 - D – C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
                      O43 - CFD: 26/02/2017 - D – C:\Program Files (x86)\Mozilla Firefox =>.Mozilla
                      O43 - CFD: 09/02/2017 - D – C:\Program Files (x86)\Mozilla Maintenance Service =>.Mozilla
                      O43 - CFD: 14/07/2009 - D – C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
                      O43 - CFD: 25/09/2010 - [0] D – C:\Program Files (x86)\MSXML 4.0 =>.Microsoft Corporation
                      O43 - CFD: 31/12/2011 - D – C:\Program Files (x86)\MusicStation =>.MusicStation
                      O43 - CFD: 20/03/2016 - D – C:\Program Files (x86)\PMDG Operations Center
                      O43 - CFD: 24/02/2016 - D – C:\Program Files (x86)\RANTXL
                      O43 - CFD: 13/09/2010 - D – C:\Program Files (x86)\Realtek =>.Realtek
                      O43 - CFD: 14/07/2009 - D – C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
                      O43 - CFD: 13/09/2010 - D – C:\Program Files (x86)\Roxio =>.Roxio
                      O43 - CFD: 07/12/2012 - D – C:\Program Files (x86)\Seagate =>.Seagate
                      O43 - CFD: 09/02/2017 - RD – C:\Program Files (x86)\Skype =>.Skype
                      O43 - CFD: 31/12/2011 - D – C:\Program Files (x86)\SONY =>.Sony Corporation®
                      O43 - CFD: 13/09/2010 - D – C:\Program Files (x86)\Sony Corporation =>.Sony Corporation
                      O43 - CFD: 16/12/2015 - D – C:\Program Files (x86)\SpeedFan =>.Almico Software
                      O43 - CFD: 02/01/2012 - [0] D – C:\Program Files (x86)\T-Mobile
                      O43 - CFD: 13/09/2010 - [0] HD – C:\Program Files (x86)\Temp =>.Microsoft Corporation
                      O43 - CFD: 27/10/2016 - D – C:\Program Files (x86)\Tenorshare ReiBoot
                      O43 - CFD: 27/10/2016 - D – C:\Program Files (x86)\tinyumbrella
                      O43 - CFD: 27/10/2016 - D – C:\Program Files (x86)\tinyumbrellaNEW
                      O43 - CFD: 14/07/2009 - [0] HD – C:\Program Files (x86)\Uninstall Information =>.Microsoft Corporation
                      O43 - CFD: 04/03/2017 - D – C:\Program Files (x86)\VAIO screensavers
                      O43 - CFD: 05/02/2012 - D – C:\Program Files (x86)\Virgin Mobile Broadband
                      O43 - CFD: 01/10/2016 - D – C:\Program Files (x86)\Western Digital =>.Western Digital Technologies, Inc.®
                      O43 - CFD: 14/02/2017 - D – C:\Program Files (x86)\Wickr Inc {045D55AD7640E014A9B074ACF4E03319}
                      O43 - CFD: 14/07/2013 - D – C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
                      O43 - CFD: 30/03/2014 - D – C:\Program Files (x86)\Windows Installer Clean Up =>.Microsoft Corporation
                      O43 - CFD: 24/09/2016 - D – C:\Program Files (x86)\Windows Live =>.Microsoft Corporation
                      O43 - CFD: 15/03/2016 - D – C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
                      O43 - CFD: 14/07/2009 - D – C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
                      O43 - CFD: 03/07/2011 - D – C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
                      O43 - CFD: 03/07/2011 - D – C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
                      O43 - CFD: 15/03/2016 - D – C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
                      O43 - CFD: 27/10/2016 - D – C:\Program Files (x86)\Wondershare =>.Wondershare
                      O43 - CFD: 04/03/2017 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\9-lab Removal Tool
                      O43 - CFD: 23/10/2016 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
                      O43 - CFD: 14/07/2009 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
                      O43 - CFD: 13/03/2016 - [0] D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon =>.Amazon
                      O43 - CFD: 13/09/2010 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft Magic-i Visual Effects 2 =>.ArcSoft
                      O43 - CFD: 13/09/2010 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft WebCam Companion 3 =>.Labtec
                      O43 - CFD: 26/07/2011 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ATPL Digital v6
                      O43 - CFD: 28/02/2017 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira =>.Avira Software
                      O43 - CFD: 11/12/2010 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bristol.gs
                      O43 - CFD: 14/09/2014 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother =>.Brother
                      O43 - CFD: 18/12/2010 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities =>.Canon Inc.
                      O43 - CFD: 04/12/2010 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center =>.Advanced Micro Devices Inc
                      O43 - CFD: 04/03/2017 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd
                      O43 - CFD: 13/09/2010 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel =>.Corel Corporation
                      O43 - CFD: 09/02/2017 - [0] D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diamond DA40D G1000 Trainer v6.14
                      O43 - CFD: 07/12/2012 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DiskCheckup
                      O43 - CFD: 28/02/2017 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox =>.Dropbox
                      O43 - CFD: 26/09/2010 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Family Tree Maker 2006
                      O43 - CFD: 09/04/2016 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free iTunes Backup Extractor
                      O43 - CFD: 09/11/2010 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeCol
                      O43 - CFD: 25/10/2015 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G4FON Software
                      O43 - CFD: 20/03/2016 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
                      O43 - CFD: 17/10/2010 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gleim Publications
                      O43 - CFD: 02/05/2015 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud =>.Apple Inc.
                      O43 - CFD: 19/05/2010 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel =>.Intel Corporation
                      O43 - CFD: 01/02/2017 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes =>.Apple Inc.
                      O43 - CFD: 14/07/2009 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
                      O43 - CFD: 26/02/2017 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes =>.Malwarebytes
                      O43 - CFD: 02/10/2010 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxtor =>.Maxtor
                      O43 - CFD: 04/02/2012 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games =>.Microsoft Corporation
                      O43 - CFD: 30/03/2014 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office =>.Microsoft Corporation
                      O43 - CFD: 08/03/2015 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 =>.Microsoft Corporation
                      O43 - CFD: 13/10/2016 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight =>.Microsoft Corporation
                      O43 - CFD: 25/09/2010 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PMB =>.Sony Corporation
                      O43 - CFD: 15/03/2016 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PMDG Simulations
                      O43 - CFD: 21/06/2014 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RANT XL
                      O43 - CFD: 03/03/2017 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller =>.Adlice
                      O43 - CFD: 28/10/2011 - [0] D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio Easy Media Creator 10 LJ =>.Roxio
                      O43 - CFD: 07/12/2012 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate =>.Seagate
                      O43 - CFD: 28/12/2015 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype =>.Skype
                      O43 - CFD: 13/09/2010 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony =>.Sony
                      O43 - CFD: 08/04/2014 - RD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
                      O43 - CFD: 21/02/2017 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware =>.SUPERAntiSpyware
                      O43 - CFD: 10/07/2011 - HD – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Care
                      O43 - CFD: 01/10/2016 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital =>.Western Digital
                      O43 - CFD: 14/02/2017 - D – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wickr Me
                      O43 - CFD: 04/03/2017 - D – C:\ProgramData\9-lab =>.9-lab
                      O43 - CFD: 25/12/2015 - D – C:\ProgramData\Adobe =>.Adobe
                      O43 - CFD: 26/01/2014 - D – C:\ProgramData\Apple =>.Apple Inc.
                      O43 - CFD: 04/02/2012 - D – C:\ProgramData\Apple Computer =>.Apple Inc.
                      O43 - CFD: 14/07/2009 - [0] SHD – C:\ProgramData\Application Data =>.Microsoft Corporation
                      O43 - CFD: 21/02/2017 - D – C:\ProgramData\ArcSoft =>.ArcSoft
                      O43 - CFD: 04/12/2010 - D – C:\ProgramData\ATI =>.ATI
                      O43 - CFD: 26/02/2017 - D – C:\ProgramData\Avira =>.Avira Software
                      O43 - CFD: 14/09/2014 - D – C:\ProgramData\Brother =>.Brother
                      O43 - CFD: 29/10/2013 - D – C:\ProgramData\Citrix =>.Citrix
                      O43 - CFD: 18/02/2012 - HD – C:\ProgramData\Common Files =>.Microsoft Corporation
                      O43 - CFD: 12/01/2014 - D – C:\ProgramData\Corel =>.Corel Corporation
                      O43 - CFD: 14/07/2009 - [0] SHD – C:\ProgramData\Desktop =>.Microsoft Corporation
                      O43 - CFD: 14/07/2009 - [0] SHD – C:\ProgramData\Documents =>.Microsoft Corporation
                      O43 - CFD: 22/02/2017 - D – C:\ProgramData\Dropbox =>.Dropbox
                      O43 - CFD: 13/09/2010 - D – C:\ProgramData\Evernote =>.EverNote Corporation
                      O43 - CFD: 14/07/2009 - [0] SHD – C:\ProgramData\Favorites =>.Microsoft Corporation
                      O43 - CFD: 20/03/2016 - D – C:\ProgramData\FLEXnet =>.Flexera Software
                      O43 - CFD: 13/03/2016 - [0] D – C:\ProgramData\Freemake =>.Freemake
                      O43 - CFD: 13/03/2016 - D – C:\ProgramData\Installations =>.Unknow
                      O43 - CFD: 26/02/2017 - D – C:\ProgramData\Malwarebytes =>.Malwarebytes
                      O43 - CFD: 26/09/2010 - D – C:\ProgramData\Maxtor =>.Maxtor
                      O43 - CFD: 26/11/2013 - D – C:\ProgramData\McAfee =>.McAfee
                      O43 - CFD: 20/03/2016 - SD – C:\ProgramData\Microsoft =>.Microsoft Corporation
                      O43 - CFD: 13/12/2016 - D – C:\ProgramData\Microsoft Help =>.Microsoft Corporation
                      O43 - CFD: 10/05/2012 - D – C:\ProgramData\Mozilla =>.Mozilla Corporation
                      O43 - CFD: 09/02/2017 - D – C:\ProgramData\Oracle =>.Oracle
                      O43 - CFD: 21/02/2017 - D – C:\ProgramData\Package Cache =>.Microsoft Corporation
                      O43 - CFD: 11/12/2010 - D – C:\ProgramData\pbTPLVyBrsWMQuu
                      O43 - CFD: 24/10/2010 - D – C:\ProgramData\PC Suite =>.Nokia Inc.
                      O43 - CFD: 15/11/2015 - [0] D – C:\ProgramData\PhotoStitch
                      O43 - CFD: 01/03/2017 - D – C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
                      O43 - CFD: 05/03/2017 - D – C:\ProgramData\RogueKiller =>.Adlice
                      O43 - CFD: 21/10/2016 - [0] D – C:\ProgramData\Roxio =>.Roxio
                      O43 - CFD: 13/09/2010 - D – C:\ProgramData\SiteAdvisor =>.McAfee Inc.
                      O43 - CFD: 09/02/2017 - D – C:\ProgramData\Skype =>.Skype
                      O43 - CFD: 15/08/2011 - D – C:\ProgramData\Skype Extras =>.Skype
                      O43 - CFD: 17/04/2011 - D – C:\ProgramData\Sonic =>.Sonic
                      O43 - CFD: 25/02/2017 - D – C:\ProgramData\Sony Corporation =>.Sony Corporation
                      O43 - CFD: 14/07/2009 - [0] SHD – C:\ProgramData\Start Menu =>.Microsoft Corporation
                      O43 - CFD: 17/10/2010 - D – C:\ProgramData\Sun =>.Oracle
                      O43 - CFD: 11/10/2016 - D – C:\ProgramData\SUPERAntiSpyware.com =>.SUPERAntiSpyware.com
                      O43 - CFD: 14/02/2017 - D – C:\ProgramData\SUPERSetup
                      O43 - CFD: 07/12/2012 - [0] AD – C:\ProgramData\TEMP =>.Microsoft Corporation
                      O43 - CFD: 14/07/2009 - [0] SHD – C:\ProgramData\Templates =>.Microsoft Corporation
                      O43 - CFD: 13/09/2010 - D – C:\ProgramData\Uninstall =>.Unknow
                      O43 - CFD: 01/10/2016 - D – C:\ProgramData\Western Digital =>.Western Digital
                      O43 - CFD: 27/10/2016 - D – C:\ProgramData\Wondershare =>.Wondershare
                      O43 - CFD: 18/12/2010 - [0] D – C:\ProgramData\ZoomBrowser =>.Canon Inc.
                      O43 - CFD: 04/02/2012 - D – C:\ProgramData{93E26451-CD9A-43A5-A2FA-C42392EA4001} =>.GEAR Software, Inc.
                      O43 - CFD: 25/12/2015 - D – C:\Program Files (x86)\Common Files\Adobe =>.Adobe
                      O43 - CFD: 27/10/2016 - D – C:\Program Files (x86)\Common Files\Apple =>.Apple Inc.
                      O43 - CFD: 19/10/2014 - D – C:\Program Files (x86)\Common Files\ArcSoft =>.ArcSoft
                      O43 - CFD: 18/12/2010 - D – C:\Program Files (x86)\Common Files\Canon =>.Canon
                      O43 - CFD: 29/10/2013 - D – C:\Program Files (x86)\Common Files\Citrix =>.Citrix
                      O43 - CFD: 22/07/2015 - D – C:\Program Files (x86)\Common Files\DESIGNER =>.Designer
                      O43 - CFD: 10/06/2011 - D – C:\Program Files (x86)\Common Files\InstallShield =>.InstallShield
                      O43 - CFD: 30/10/2012 - D – C:\Program Files (x86)\Common Files\Intel Corporation =>.Intel Corporation
                      O43 - CFD: 13/09/2010 - D – C:\Program Files (x86)\Common Files\InterVideo =>.InterVideo
                      O43 - CFD: 11/12/2011 - D – C:\Program Files (x86)\Common Files\Java =>.Oracle
                      O43 - CFD: 15/03/2016 - D – C:\Program Files (x86)\Common Files\Macrovision Shared =>.Rovi Corporation
                      O43 - CFD: 05/02/2012 - D – C:\Program Files (x86)\Common Files\McAfee =>.McAfee
                      O43 - CFD: 24/09/2016 - D – C:\Program Files (x86)\Common Files\microsoft shared =>.Microsoft Corporation
                      O43 - CFD: 19/05/2010 - D – C:\Program Files (x86)\Common Files\postureAgent =>.Microsoft Corporation
                      O43 - CFD: 13/09/2010 - D – C:\Program Files (x86)\Common Files\Protexis =>.Protexis Inc.
                      O43 - CFD: 13/09/2010 - D – C:\Program Files (x86)\Common Files\PX Storage Engine =>.Sonic Solutions
                      O43 - CFD: 13/09/2010 - D – C:\Program Files (x86)\Common Files\Roxio Shared =>.Roxio
                      O43 - CFD: 15/03/2016 - D – C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
                      O43 - CFD: 09/02/2017 - D – C:\Program Files (x86)\Common Files\Skype =>.Skype
                      O43 - CFD: 13/09/2010 - D – C:\Program Files (x86)\Common Files\Sonic Shared =>.Sonic
                      O43 - CFD: 15/07/2011 - D – C:\Program Files (x86)\Common Files\Sony Shared =>.Sony Corporation
                      O43 - CFD: 14/07/2009 - D – C:\Program Files (x86)\Common Files\SpeechEngines =>.Microsoft Corporation
                      O43 - CFD: 15/03/2016 - D – C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
                      O43 - CFD: 01/10/2016 - D – C:\Program Files (x86)\Common Files\Western Digital =>.Western Digital
                      O43 - CFD: 13/09/2010 - D – C:\Program Files (x86)\Common Files\Windows Live =>.Microsoft Corporation
                      O43 - CFD: 07/12/2012 - D – C:\Program Files (x86)\Common Files\Wise Installation Wizard =>.Seagate
                      O43 - CFD: 09/04/2016 - D – C:\Program Files (x86)\Common Files\Wondershare =>.Wondershare
                      O43 - CFD: 25/09/2010 - [0] SHD – C:\Users\goldfish\AppData\Roaming.#
                      O43 - CFD: 11/03/2012 - D – C:\Users\goldfish\AppData\Roaming.freeciv
                      O43 - CFD: 04/03/2017 - D – C:\Users\goldfish\AppData\Roaming\9-lab =>.9-lab
                      O43 - CFD: 16/03/2013 - D – C:\Users\goldfish\AppData\Roaming\Adobe =>.Adobe
                      O43 - CFD: 13/03/2016 - [0] D – C:\Users\goldfish\AppData\Roaming\Amazon =>.Amazon
                      O43 - CFD: 24/02/2017 - D – C:\Users\goldfish\AppData\Roaming\Apple Computer =>.Apple Inc.
                      O43 - CFD: 19/10/2014 - D – C:\Users\goldfish\AppData\Roaming\ArcSoft =>.ArcSoft
                      O43 - CFD: 23/09/2010 - D – C:\Users\goldfish\AppData\Roaming\ATI =>.ATI
                      O43 - CFD: 20/02/2017 - D – C:\Users\goldfish\AppData\Roaming\Avira =>.Avira Software
                      O43 - CFD: 11/12/2010 - D – C:\Users\goldfish\AppData\Roaming\Bristol.gs
                      O43 - CFD: 28/11/2015 - RD – C:\Users\goldfish\AppData\Roaming\Brother =>.Brother
                      O43 - CFD: 11/09/2011 - D – C:\Users\goldfish\AppData\Roaming\Bytemobile
                      O43 - CFD: 18/12/2010 - [0] D – C:\Users\goldfish\AppData\Roaming\CameraWindowDC
                      O43 - CFD: 09/06/2012 - D – C:\Users\goldfish\AppData\Roaming\Canon =>.Canon
                      O43 - CFD: 10/04/2011 - D – C:\Users\goldfish\AppData\Roaming\CANON INC =>.Canon Inc.
                      O43 - CFD: 18/12/2010 - D – C:\Users\goldfish\AppData\Roaming\Corel =>.Corel Corporation
                      O43 - CFD: 22/02/2017 - D – C:\Users\goldfish\AppData\Roaming\Dropbox =>.Dropbox
                      O43 - CFD: 23/02/2013 - D – C:\Users\goldfish\AppData\Roaming\Evaer
                      O43 - CFD: 09/05/2012 - D – C:\Users\goldfish\AppData\Roaming\FastStone =>.FastStone Soft
                      O43 - CFD: 05/03/2017 - D – C:\Users\goldfish\AppData\Roaming\Geek Uninstaller =>.Geek Uninstaller
                      O43 - CFD: 17/10/2010 - D – C:\Users\goldfish\AppData\Roaming\Gleim
                      O43 - CFD: 29/10/2013 - D – C:\Users\goldfish\AppData\Roaming\ICAClient =>.Citrix
                      O43 - CFD: 23/09/2010 - D – C:\Users\goldfish\AppData\Roaming\Identities =>.Microsoft Corporation
                      O43 - CFD: 09/04/2016 - D – C:\Users\goldfish\AppData\Roaming\iMobie =>.iMobie Inc
                      O43 - CFD: 25/09/2010 - D – C:\Users\goldfish\AppData\Roaming\InstallShield =>.InstallShield
                      O43 - CFD: 23/09/2010 - D – C:\Users\goldfish\AppData\Roaming\Intel Corporation =>.Intel Corporation
                      O43 - CFD: 09/04/2016 - D – C:\Users\goldfish\AppData\Roaming\JihoiTunesExtrac tor
                      O43 - CFD: 25/09/2010 - D – C:\Users\goldfish\AppData\Roaming\Macromedia =>.Macromedia
                      O43 - CFD: 15/03/2016 - D – C:\Users\goldfish\AppData\Roaming\MCC Pilotlog
                      O43 - CFD: 20/05/2010 - [0] D – C:\Users\goldfish\AppData\Roaming\Media Center Programs =>.Microsoft Corporation
                      O43 - CFD: 12/09/2016 - SD – C:\Users\goldfish\AppData\Roaming\Microsoft =>.Microsoft Corporation
                      O43 - CFD: 11/06/2011 - D – C:\Users\goldfish\AppData\Roaming\Mozilla =>.Mozilla Corporation
                      O43 - CFD: 26/09/2010 - D – C:\Users\goldfish\AppData\Roaming\MyFamily.com
                      O43 - CFD: 24/10/2010 - D – C:\Users\goldfish\AppData\Roaming\Nokia =>.Nokia
                      O43 - CFD: 24/10/2010 - D – C:\Users\goldfish\AppData\Roaming\PC Suite =>.Nokia Inc.
                      O43 - CFD: 13/03/2016 - D – C:\Users\goldfish\AppData\Roaming\PMDG =>.PMDG Simulations, LLC
                      O43 - CFD: 26/07/2011 - D – C:\Users\goldfish\AppData\Roaming\Prism
                      O43 - CFD: 19/10/2014 - D – C:\Users\goldfish\AppData\Roaming\PTGui
                      O43 - CFD: 20/02/2017 - [0] D – C:\Users\goldfish\AppData\Roaming\QuickScan =>.Bitdefender
                      O43 - CFD: 18/12/2010 - D – C:\Users\goldfish\AppData\Roaming\Roxio =>.Roxio
                      O43 - CFD: 04/03/2017 - D – C:\Users\goldfish\AppData\Roaming\Skype =>.Skype
                      O43 - CFD: 01/09/2011 - D – C:\Users\goldfish\AppData\Roaming\skypePM =>.Skype Technologies
                      O43 - CFD: 25/09/2010 - D – C:\Users\goldfish\AppData\Roaming\Sony Corporation =>.Sony Corporation
                      O43 - CFD: 14/02/2017 - D – C:\Users\goldfish\AppData\Roaming\SUPERAntiSpyware .com =>.SUPERAntiSpyware.com
                      O43 - CFD: 11/09/2011 - D – C:\Users\goldfish\AppData\Roaming\T-Mobile
                      O43 - CFD: 07/05/2011 - D – C:\Users\goldfish\AppData\Roaming\Temp =>.Microsoft Corporation
                      O43 - CFD: 27/10/2016 - D – C:\Users\goldfish\AppData\Roaming\Tenorshare =>.Tenorshare
                      O43 - CFD: 09/06/2013 - D – C:\Users\goldfish\AppData\Roaming\vlc =>.VideoLan Team
                      O43 - CFD: 01/10/2016 - D – C:\Users\goldfish\AppData\Roaming\Western Digital =>.Western Digital
                      O43 - CFD: 27/10/2016 - D – C:\Users\goldfish\AppData\Roaming\Wondershare =>.Wondershare
                      O43 - CFD: 05/03/2017 - D – C:\Users\goldfish\AppData\Roaming\ZHP =>.Nicolas Coolman
                      O43 - CFD: 24/09/2016 - [0] D – C:\Users\goldfish\AppData\Roaming\ZoomBrowser EX =>.Canon Inc.
                      O43 - CFD: 24/02/2017 - D – C:\Users\goldfish\AppData\Local\748A0AB9-F073-4E14-BCD2-A692572E4A9D.aplzod
                      O43 - CFD: 09/02/2017 - D – C:\Users\goldfish\AppData\Local\Adobe =>.Adobe
                      O43 - CFD: 15/03/2016 - D – C:\Users\goldfish\AppData\Local\Apple =>.Apple Inc.
                      O43 - CFD: 15/04/2012 - D – C:\Users\goldfish\AppData\Local\Apple Computer =>.Apple Inc.
                      O43 - CFD: 25/02/2017 - D – C:\Users\goldfish\AppData\Local\Apple Inc =>.Apple Inc.
                      O43 - CFD: 23/09/2010 - [0] SHD – C:\Users\goldfish\AppData\Local\Application Data =>.Microsoft Corporation
                      O43 - CFD: 16/06/2012 - D – C:\Users\goldfish\AppData\Local\Apps =>.Microsoft Corporation
                      O43 - CFD: 19/10/2014 - D – C:\Users\goldfish\AppData\Local\ArcSoft =>.ArcSoft
                      O43 - CFD: 23/09/2010 - D – C:\Users\goldfish\AppData\Local\ATI =>.ATI
                      O43 - CFD: 21/02/2017 - D – C:\Users\goldfish\AppData\Local\Avg =>.AVG Software
                      O43 - CFD: 21/02/2017 - D – C:\Users\goldfish\AppData\Local\Avira =>.Avira Software
                      O43 - CFD: 21/02/2017 - [0] D – C:\Users\goldfish\AppData\Local\AviraSpeedup =>.Avira Software
                      O43 - CFD: 11/12/2010 - D – C:\Users\goldfish\AppData\Local\Bristol.gs
                      O43 - CFD: 23/09/2010 - D – C:\Users\goldfish\AppData\Local\Broadcom =>.Broadcom
                      O43 - CFD: 28/12/2015 - D – C:\Users\goldfish\AppData\Local\CEF =>.CEF
                      O43 - CFD: 14/02/2017 - D – C:\Users\goldfish\AppData\Local\Citrix =>.Citrix
                      O43 - CFD: 13/08/2015 - [0] D – C:\Users\goldfish\AppData\Local\Deployment =>.Microsoft Corporation
                      O43 - CFD: 20/02/2017 - D – C:\Users\goldfish\AppData\Local\Diagnostics =>.Microsoft Corporation
                      O43 - CFD: 30/12/2012 - D – C:\Users\goldfish\AppData\Local\Downloaded Installations =>.Microsoft Corporation
                      O43 - CFD: 22/02/2017 - D – C:\Users\goldfish\AppData\Local\Dropbox =>.Dropbox
                      O43 - CFD: 21/02/2017 - D – C:\Users\goldfish\AppData\Local\ElevatedDiagnostic s =>.Microsoft Corporation
                      O43 - CFD: 12/06/2015 - [0] SHD – C:\Users\goldfish\AppData\Local\EmieBrowserModeLis t =>.Enterprise mode Site List Mgr
                      O43 - CFD: 12/06/2015 - [0] SHD – C:\Users\goldfish\AppData\Local\EmieSiteList =>.Enterprise mode Site List Mgr
                      O43 - CFD: 12/06/2015 - [0] SHD – C:\Users\goldfish\AppData\Local\EmieUserList =>.Enterprise mode Site List Mgr
                      O43 - CFD: 11/06/2011 - D – C:\Users\goldfish\AppData\Local\Evernote =>.EverNote Corporation
                      O43 - CFD: 05/03/2017 - D – C:\Users\goldfish\AppData\Local\Google =>.Google
                      O43 - CFD: 12/06/2015 - D – C:\Users\goldfish\AppData\Local\GWX =>.GWX
                      O43 - CFD: 23/09/2010 - [0] SHD – C:\Users\goldfish\AppData\Local\History =>.Microsoft Corporation
                      O43 - CFD: 15/06/2014 - [0] D – C:\Users\goldfish\AppData\Local\HockeyCrashes
                      O43 - CFD: 19/12/2010 - D – C:\Users\goldfish\AppData\Local\IsolatedStorage =>.id Software
                      O43 - CFD: 03/09/2012 - D – C:\Users\goldfish\AppData\Local\Macromedia =>.Macromedia
                      O43 - CFD: 30/10/2016 - D – C:\Users\goldfish\AppData\Local\Microsoft =>.Microsoft Corporation
                      O43 - CFD: 20/03/2016 - D – C:\Users\goldfish\AppData\Local\Microsoft Game Studios =>.Microsoft Corporation
                      O43 - CFD: 08/03/2015 - D – C:\Users\goldfish\AppData\Local\Microsoft Help =>.Microsoft Corporation
                      O43 - CFD: 04/03/2017 - [0] DC – C:\Users\goldfish\AppData\Local\MigWiz =>.MigWiz
                      O43 - CFD: 02/10/2013 - D – C:\Users\goldfish\AppData\Local\Mozilla =>.Mozilla Corporation
                      O43 - CFD: 26/07/2011 - D – C:\Users\goldfish\AppData\Local\Prism
                      O43 - CFD: 24/12/2013 - D – C:\Users\goldfish\AppData\Local\Program Files
                      O43 - CFD: 06/11/2010 - D – C:\Users\goldfish\AppData\Local\Programs =>.Microsoft Corporation
                      O43 - CFD: 28/12/2015 - [0] D – C:\Users\goldfish\AppData\Local\Skype =>.Skype
                      O43 - CFD: 13/11/2010 - D – C:\Users\goldfish\AppData\Local\Sony Corporation =>.Sony Corporation
                      O43 - CFD: 31/12/2011 - D – C:\Users\goldfish\AppData\Local\Sony_Corporation
                      O43 - CFD: 05/03/2017 - D – C:\Users\goldfish\AppData\Local\Temp =>.Microsoft Corporation
                      O43 - CFD: 23/09/2010 - [0] SHD – C:\Users\goldfish\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
                      O43 - CFD: 17/10/2010 - D – C:\Users\goldfish\AppData\Local\VirtualStore =>.Microsoft Corporation
                      O43 - CFD: 01/10/2016 - D – C:\Users\goldfish\AppData\Local\Western Digital =>.Western Digital
                      O43 - CFD: 14/02/2017 - D – C:\Users\goldfish\AppData\Local\Wickr, LLC
                      O43 - CFD: 24/09/2016 - D – C:\Users\goldfish\AppData\Local\Windows Live =>.Microsoft Corporation
                      O43 - CFD: 09/04/2016 - D – C:\Users\goldfish\AppData\Local\Wondershare =>.Wondershare
                      O43 - CFD: 09/04/2016 - D – C:\Users\goldfish\AppData\Local\微软公司
                      O43 - CFD: 06/11/2010 - [0] D – C:\Users\goldfish\AppData\Local\Programs\Common =>.Microsoft Corporation
                      O43 - CFD: 14/07/2009 - RD – C:\Users\goldfish\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Accessories =>.Microsoft Corporation
                      O43 - CFD: 23/09/2016 - RD – C:\Users\goldfish\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Administrative Tools =>.Administrative Tools
                      O43 - CFD: 16/06/2012 - D – C:\Users\goldfish\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Airbox Aerospace Ltd
                      O43 - CFD: 24/12/2013 - D – C:\Users\goldfish\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Amazon =>.Amazon
                      O43 - CFD: 21/02/2017 - [0] D – C:\Users\goldfish\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Avira =>.Avira Software
                      O43 - CFD: 25/09/2016 - D – C:\Users\goldfish\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Games =>.Microsoft Corporation
                      O43 - CFD: 30/11/2014 - [0] D – C:\Users\goldfish\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Hugin =>.Hugin
                      O43 - CFD: 14/07/2009 - RD – C:\Users\goldfish\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Maintenance =>.Microsoft Corporation
                      O43 - CFD: 01/01/2016 - D – C:\Users\goldfish\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\MCC Pilotlog
                      O43 - CFD: 05/02/2012 - D – C:\Users\goldfish\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Playsims
                      O43 - CFD: 04/03/2017 - RD – C:\Users\goldfish\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Startup =>.Microsoft Corporation
                      O43 - CFD: 30/01/2012 - D – C:\Users\goldfish\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\UK2000 Scenery
                      O43 - CFD: 14/07/2009 - [0] SHD – C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
                      O43 - CFD: 14/07/2009 - [0] SHD – C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
                      O43 - CFD: 14/07/2009 - D – C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
                      O43 - CFD: 11/04/2012 - [0] D – C:\Users\Default\AppData\Local\Microsoft Help =>.Microsoft Corporation
                      O43 - CFD: 14/07/2009 - [0] D – C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
                      O43 - CFD: 14/07/2009 - [0] SHD – C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
                      O43 - CFD: 14/07/2009 - [0] SHD – C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
                      O43 - CFD: 14/07/2009 - [0] SHD – C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
                      O43 - CFD: 14/07/2009 - D – C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
                      O43 - CFD: 11/04/2012 - [0] D – C:\Users\Default User\AppData\Local\Microsoft Help =>.Microsoft Corporation
                      O43 - CFD: 14/07/2009 - [0] D – C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
                      O43 - CFD: 14/07/2009 - [0] SHD – C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
                      O43 - CFD: 06/11/2010 - [0] – C:\Windows\System32\Config\systemprofile\AppData\L ocal\Application Data =>.Microsoft Corporation
                      O43 - CFD: 25/09/2016 - – C:\Windows\System32\Config\systemprofile\AppData\L ocal\Avg =>.AVG Software
                      O43 - CFD: 25/02/2017 - – C:\Windows\System32\Config\systemprofile\AppData\L ocal\Avira =>.Avira Software
                      O43 - CFD: 28/02/2017 - – C:\Windows\System32\Config\systemprofile\AppData\L ocal\Dropbox =>.Dropbox
                      O43 - CFD: 23/04/2011 - – C:\Windows\System32\Config\systemprofile\AppData\L ocal\Google =>.Google
                      O43 - CFD: 06/11/2010 - [0] – C:\Windows\System32\Config\systemprofile\AppData\L ocal\History =>.Microsoft Corporation
                      O43 - CFD: 21/02/2017 - D – C:\Windows\System32\Config\systemprofile\AppData\L ocal\Microsoft =>.Microsoft Corporation
                      O43 - CFD: 10/06/2011 - – C:\Windows\System32\Config\systemprofile\AppData\L ocal\Programs =>.Microsoft Corporation
                      O43 - CFD: 06/11/2010 - [0] – C:\Windows\System32\Config\systemprofile\AppData\L ocal\Temporary Internet Files =>.Microsoft Corporation
                      O43 - CFD: 26/11/2011 - D – C:\Windows\System32\Config\systemprofile\AppData\R oaming\Apple Computer =>.Apple Inc.
                      O43 - CFD: 20/02/2017 - – C:\Windows\System32\Config\systemprofile\AppData\R oaming\Avira =>.Avira Software
                      O43 - CFD: 11/09/2011 - – C:\Windows\System32\Config\systemprofile\AppData\R oaming\Bytemobile
                      O43 - CFD: 28/02/2017 - – C:\Windows\System32\Config\systemprofile\AppData\R oaming\Dropbox =>.Dropbox
                      O43 - CFD: 10/06/2011 - SD – C:\Windows\System32\Config\systemprofile\AppData\R oaming\Microsoft =>.Microsoft Corporation
                      O43 - CFD: 26/11/2011 - – C:\Windows\System32\Config\systemprofile\AppData\R oaming\PC Suite =>.Nokia Inc.
                      O43 - CFD: 26/09/2010 - – C:\Windows\System32\Config\systemprofile\AppData\R oaming\SACore =>.SACore
                      O43 - CFD: 13/09/2010 - D – C:\Windows\System32\Config\systemprofile\AppData\R oaming\Sony Corporation =>.Sony Corporation

                      —\ ShellIconOverlayIdentifiers (SIOI) (12) - 3s
                      O106 - SIOI: DropboxExt1 Class [ DropboxExt01] - {FB314ED9-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) – C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
                      O106 - SIOI: DropboxExt7 Class [ DropboxExt02] - {FB314EDF-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) – C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
                      O106 - SIOI: DropboxExt9 Class [ DropboxExt03] - {FB314EE1-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) – C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
                      O106 - SIOI: DropboxExt3 Class [ DropboxExt04] - {FB314EDB-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) – C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
                      O106 - SIOI: DropboxExt2 Class [ DropboxExt05] - {FB314EDA-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) – C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
                      O106 - SIOI: DropboxExt4 Class [ DropboxExt06] - {FB314EDC-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) – C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
                      O106 - SIOI: DropboxExt5 Class [ DropboxExt07] - {FB314EDD-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) – C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
                      O106 - SIOI: DropboxExt8 Class [ DropboxExt08] - {FB314EE0-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) – C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
                      O106 - SIOI: DropboxExt10 Class [ DropboxExt09] - {FB314EE2-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) – C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
                      O106 - SIOI: DropboxExt6 Class [ DropboxExt10] - {FB314EDE-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) – C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
                      O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) – C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
                      O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - Shell extensions for sharing.) – C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation

                      —\ System Drivers List (92) - 17s
                      O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) – C:\Windows\System32\drivers\adp94xx.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) – C:\Windows\System32\drivers\adpahci.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) – C:\Windows\System32\drivers\adpu320.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/07/14 01:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) – C:\Windows\System32\drivers\aliide.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2011/03/11 06:41:12 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) – C:\Windows\System32\drivers\amdsata.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/07/14 01:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) – C:\Windows\System32\drivers\amdsbs.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2011/03/11 06:41:12 A . (.Advanced Micro Devices - Storage Filter Driver.) – C:\Windows\System32\drivers\amdxata.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/11/04 09:59:59 A . (.Alps Electric Co., Ltd. - Alps Touch Pad Driver.) – C:\Windows\System32\drivers\Apfiltr.sys [317400] =>.Alps Electric Co., LTD.®
                      O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) – C:\Windows\System32\drivers\arc.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) – C:\Windows\System32\drivers\arcsas.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/05/26 13:32:04 A . (.ArcSoft, Inc. - For X64.) – C:\Windows\System32\drivers\ArcSoftKsUFilter.sys [317400] =>.ArcSoft, Inc.®
                      O58 - SDL:2009/11/12 20:06:44 A . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driv.) – C:\Windows\System32\drivers\athrx.sys [317400] =>.Atheros Communications, Inc.
                      O58 - SDL:2010/10/08 06:55:08 A . (.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) – C:\Windows\System32\drivers\atikmdag.sys [317400] =>.ATI Technologies Inc.
                      O58 - SDL:2010/10/08 06:55:08 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) – C:\Windows\System32\drivers\atikmpag.sys [317400] =>.Advanced Micro Devices, Inc.
                      O58 - SDL:2017/02/15 16:55:52 A . (.Avira Operations GmbH & Co. KG - Avira Minifilter Driver.) – C:\Windows\System32\drivers\avgntflt.sys [317400] =>.Avira Operations GmbH & Co. KG®
                      O58 - SDL:2017/02/15 16:55:52 A . (.Avira Operations GmbH & Co. KG - Avira Driver for Security Enhancement.) – C:\Windows\System32\drivers\avipbb.sys [317400] =>.Avira Operations GmbH & Co. KG®
                      O58 - SDL:2017/02/15 16:55:52 A . (.Avira Operations GmbH & Co. KG - Avira Manager Driver.) – C:\Windows\System32\drivers\avkmgr.sys [317400] =>.Avira Operations GmbH & Co. KG®
                      O58 - SDL:2017/02/15 16:55:52 A . (.Avira Operations GmbH & Co. KG - Avira WFP Network Driver.) – C:\Windows\System32\drivers\avnetflt.sys [317400] =>.Avira Operations GmbH & Co. KG®
                      O58 - SDL:2017/02/15 16:55:52 A . (.Avira Operations GmbH & Co. KG - Avira USB Filter Driver.) – C:\Windows\System32\drivers\avusbflt.sys [317400] =>.Avira Operations GmbH & Co. KG®
                      O58 - SDL:2009/06/10 20:34:23 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) – C:\Windows\System32\drivers\b57nd60a.sys [317400] =>.Broadcom Corporation
                      O58 - SDL:2009/06/10 20:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) – C:\Windows\System32\drivers\BrFiltLo.sys [317400] =>.Brother Industries, Ltd.
                      O58 - SDL:2009/06/10 20:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) – C:\Windows\System32\drivers\BrFiltUp.sys [317400] =>.Brother Industries, Ltd.
                      O58 - SDL:2009/07/14 01:19:07 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) – C:\Windows\System32\drivers\BrSerId.sys [317400] =>.Brother Industries Ltd.
                      O58 - SDL:2009/06/10 20:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) – C:\Windows\System32\drivers\BrSerWdm.sys [317400] =>.Brother Industries Ltd.
                      O58 - SDL:2009/06/10 20:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) – C:\Windows\System32\drivers\BrUsbMdm.sys [317400] =>.Brother Industries Ltd.
                      O58 - SDL:2009/06/10 20:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) – C:\Windows\System32\drivers\BrUsbSer.sys [317400] =>.Brother Industries Ltd.
                      O58 - SDL:2009/11/18 04:30:21 A . (.Broadcom Corporation. - Widcomm Bluetooth USB Filter for Windows XP.) – C:\Windows\System32\drivers\btusbflt.sys [317400] =>.Broadcom Corporation®
                      O58 - SDL:2009/11/18 04:30:32 A . (.Broadcom Corporation. - Bluetooth Audio Device.) – C:\Windows\System32\drivers\btwaudio.sys [317400] =>.Broadcom Corporation®
                      O58 - SDL:2009/11/18 04:30:32 A . (.Broadcom Corporation. - Broadcom Bluetooth AVDT Service.) – C:\Windows\System32\drivers\btwavdt.sys [317400] =>.Broadcom Corporation®
                      O58 - SDL:2009/11/18 04:23:46 A . (.Broadcom Corporation. - Broadcom Bluetooth L2CAP Service.) – C:\Windows\System32\drivers\btwl2cap.sys [317400] =>.Broadcom Corporation®
                      O58 - SDL:2009/11/18 04:30:44 A . (.Broadcom Corporation. - Bluetooth Remote Control HID Minidriver.) – C:\Windows\System32\drivers\btwrchid.sys [317400] =>.Broadcom Corporation®
                      O58 - SDL:2009/06/10 20:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) – C:\Windows\System32\drivers\bxvbda.sys [317400] =>.Broadcom Corporation
                      O58 - SDL:2009/05/15 10:00:00 N . (.Sonic Solutions - CDR4 64-bit CD and DVD Place Holder Driver.) – C:\Windows\System32\drivers\cdr4_xp.sys [317400] =>.Sonic Solutions®
                      O58 - SDL:2009/05/15 10:00:00 N . (.Sonic Solutions - CDRAL 64-bit Place Holder Driver (see PxHel.) – C:\Windows\System32\drivers\cdralw2k.sys [317400] =>.Sonic Solutions®
                      O58 - SDL:2009/07/14 01:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) – C:\Windows\System32\drivers\cmdide.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2013/09/24 07:10:34 A . (.Citrix Systems, Inc. - Citrix USB Filter Driver.) – C:\Windows\System32\drivers\ctxusbm.sys [317400] {1DCED972D082A6A82CA2A99FBCEA3A95} =>.Citrix Systems, Inc.
                      O58 - SDL:2017/02/21 18:49:04 A . (.Dropbox, Inc. - Dropbox Filter Driver.) – C:\Windows\System32\drivers\dbx-canary.sys [317400] =>.Microsoft Windows Hardware Compatibility Publisher®
                      O58 - SDL:2017/02/21 18:49:04 A . (.Dropbox, Inc. - Dropbox Filter Driver.) – C:\Windows\System32\drivers\dbx-dev.sys [317400] =>.Microsoft Windows Hardware Compatibility Publisher®
                      O58 - SDL:2017/02/09 08:33:38 A . (.Dropbox, Inc. - Dropbox Filter Driver.) – C:\Windows\System32\drivers\dbx-stable.sys [317400] =>.Microsoft Windows Hardware Compatibility Publisher®
                      O58 - SDL:2009/07/14 01:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) – C:\Windows\System32\drivers\elxstor.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/06/10 20:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) – C:\Windows\System32\drivers\evbda.sys [317400] =>.Broadcom Corporation
                      O58 - SDL:2011/03/01 20:44:55 A . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) – C:\Windows\System32\drivers\ewusbfake.sys [317400] =>.Huawei Technologies Co., Ltd.
                      O58 - SDL:2011/03/01 20:44:55 A . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) – C:\Windows\System32\drivers\ewusbmdm.sys [317400] =>.Huawei Technologies Co., Ltd.
                      O58 - SDL:2017/03/03 22:55:56 A . (.Malwarebytes - Malwarebytes Anti-Ransomware Protection.) – C:\Windows\System32\drivers\farflt.sys [317400] =>.Malwarebytes Corporation®
                      O58 - SDL:2012/08/21 12:01:20 A . (.GEAR Software Inc. - CD DVD Filter.) – C:\Windows\System32\drivers\GEARAspiWDM.sys [317400] =>.GEAR Software Inc.®
                      O58 - SDL:2009/06/10 20:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) – C:\Windows\System32\drivers\hcw85cir.sys [317400] =>.Hauppauge Computer Works, Inc.
                      O58 - SDL:2009/12/14 20:06:07 A . (.Intel Corporation - Intel(R) Management Engine Interface.) – C:\Windows\System32\drivers\HECIx64.sys [317400] =>.Intel Corporation®
                      O58 - SDL:2014/06/15 16:12:37 A . (.Hola Networks Ltd. - Hola Network Monitor Driver.) – C:\Windows\System32\drivers\hola_mon_drv.sys [317400] {08D34F3F819F7FB1B4FAB09F4F5B5D39} =>.Hola Networks Ltd.
                      O58 - SDL:2010/11/20 13:33:35 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) – C:\Windows\System32\drivers\HpSAMD.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/11/20 22:09:48 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) – C:\Windows\System32\drivers\iaStor.sys [317400] =>.Intel Corporation®
                      O58 - SDL:2011/03/11 06:41:26 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) – C:\Windows\System32\drivers\iaStorV.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/12/16 20:03:04 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) – C:\Windows\System32\drivers\igdkmd64.sys [317400] =>.Intel Corporation
                      O58 - SDL:2009/07/14 01:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) – C:\Windows\System32\drivers\iirsp.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/11/13 20:08:21 A . (.Intel Corporation - Intel(R) Turbo Boost Technology Driver.) – C:\Windows\System32\drivers\Impcd.sys [317400] =>.Intel Corporation
                      O58 - SDL:2009/12/16 20:03:59 A . (.Intel(R) Corporation - Intel(R) Display HD Audio driver.) – C:\Windows\System32\drivers\IntcDAud.sys [317400] =>.Intel(R) Corporation
                      O58 - SDL:2009/11/17 09:44:54 A . (.TCT International Mobile Ltd - USB Modem/Serial Device Driver.) – C:\Windows\System32\drivers\jrdusbser.sys [317400] =>.TCT International Mobile Ltd
                      O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) – C:\Windows\System32\drivers\lsi_fc.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) – C:\Windows\System32\drivers\lsi_sas.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) – C:\Windows\System32\drivers\lsi_sas2.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) – C:\Windows\System32\drivers\lsi_scsi.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2017/01/20 07:47:44 A . (.Authors - .) – C:\Windows\System32\drivers\mbae64.sys [317400] =>.Malwarebytes Corporation®
                      O58 - SDL:2017/03/03 22:55:55 A . (.Malwarebytes - Malwarebytes Real-Time Protection.) – C:\Windows\System32\drivers\mbam.sys [317400] =>.Malwarebytes Corporation®
                      O58 - SDL:2017/02/26 18:30:58 A . (.Malwarebytes - Malwarebytes Chameleon.) – C:\Windows\System32\drivers\MBAMChameleon.sys [317400] =>.Malwarebytes Corporation®
                      O58 - SDL:2017/03/03 22:55:53 A . (.Malwarebytes - Malwarebytes SwissArmy.) – C:\Windows\System32\drivers\MBAMSwissArmy.sys [317400] =>.Malwarebytes Corporation®
                      O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) – C:\Windows\System32\drivers\megasas.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) – C:\Windows\System32\drivers\MegaSR.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2017/02/26 21:57:34 A . (.Malwarebytes - Malwarebytes Web Protection.) – C:\Windows\System32\drivers\mwac.sys [317400] =>.Malwarebytes Corporation®
                      O58 - SDL:2013/08/06 15:13:30 A . (.Apple Inc. - Apple Mobile Device Ethernet.) – C:\Windows\System32\drivers\netaapl64.sys [317400] =>.Apple Inc.
                      O58 - SDL:2009/07/14 01:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) – C:\Windows\System32\drivers\nfrd960.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2011/03/11 06:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce™ RAID Driver.) – C:\Windows\System32\drivers\nvraid.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2011/03/11 06:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce™ Sata Performance Driver.) – C:\Windows\System32\drivers\nvstor.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/05/20 10:00:00 N . (.Sonic Solutions - Px Engine Device Driver for 64-bit Windows.) – C:\Windows\System32\drivers\PxHlpa64.sys [317400] =>.Sonic Solutions®
                      O58 - SDL:2009/07/14 01:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) – C:\Windows\System32\drivers\ql2300.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/07/14 01:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) – C:\Windows\System32\drivers\ql40xx.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2007/04/17 10:51:50 A . (.InterVideo - regi driver.) – C:\Windows\System32\drivers\regi.sys [317400] =>.Intervideo, Inc.®
                      O58 - SDL:2009/11/06 20:27:30 A . (.REDC - RICOH MS Driver.) – C:\Windows\System32\drivers\rimssne64.sys [317400] =>.REDC
                      O58 - SDL:2009/09/15 20:09:08 A . (.REDC - RICOH PCIe SD/MMC Driver.) – C:\Windows\System32\drivers\risdsne64.sys [317400] =>.REDC
                      O58 - SDL:2009/12/16 02:49:48 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) – C:\Windows\System32\drivers\RtHDMIVX.sys [317400] =>.Realtek Semiconductor Corp®
                      O58 - SDL:2009/12/16 05:08:00 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) – C:\Windows\System32\drivers\RTKVHD64.sys [317400] =>.Realtek Semiconductor Corp®
                      O58 - SDL:2009/06/10 20:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) – C:\Windows\System32\drivers\secdrv.sys [317400] =>.Macrovision Corporation, Macrovision Europe Limited,
                      O58 - SDL:2009/08/19 20:09:21 A . (.Sony Corporation - Sony Firmware Extension Parser driver.) – C:\Windows\System32\drivers\SFEP.sys [317400] =>.Sony Corporation
                      O58 - SDL:2009/07/14 01:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) – C:\Windows\System32\drivers\sisraid2.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/07/14 01:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) – C:\Windows\System32\drivers\sisraid4.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/07/14 01:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) – C:\Windows\System32\drivers\stexstor.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2014/03/24 10:43:26 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver.) – C:\Windows\System32\drivers\tap0901.sys [317400] =>.OpenVPN Technologies, Inc.®
                      O58 - SDL:2017/03/05 10:39:28 A . (.Authors - .) – C:\Windows\System32\drivers\TrueSight.sys [317400] =>.Adlice®
                      O58 - SDL:2015/06/10 22:08:36 A . (.Apple, Inc. - Apple Mobile Device USB Driver.) – C:\Windows\System32\drivers\usbaapl64.sys [317400] =>.Apple, Inc.
                      O58 - SDL:2009/07/14 01:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) – C:\Windows\System32\drivers\viaide.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2009/07/14 01:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) – C:\Windows\System32\drivers\vsmraid.sys [317400] =>.Microsoft Windows®
                      O58 - SDL:2015/04/29 23:01:06 A . (.Western Digital Technologies - WD SCSI Architecture Model (SAM) driver.) – C:\Windows\System32\drivers\wdcsam64.sys [317400] =>.Microsoft Windows Hardware Compatibility Publisher®
                      O58 - SDL:2016/01/14 10:10:44 A . (.Western Digital Technologies - WD SCSI Architecture Model (SAM) driver.) – C:\Windows\System32\drivers\wdcsam64_prewin8.sys [317400] =>.Microsoft Windows Hardware Compatibility Publisher®
                      O58 - SDL:2009/11/12 20:16:19 A . (.Authors - .) – C:\Windows\System32\drivers\yk62x64.sys [317400]

                      —\ Last modified or created user files (2) - 138s
                      O61 - LFC: 2017/03/04 22:26:20 A . (.Copyright © 2015.) – C:\Users\goldfish\Desktop\Antivirus EXEs\Adware Removal Tool by TSA.exe [752296] {317DD1C55F51AC2756D9C93C060C6FA5}
                      O61 - LFC: 2017/03/05 10:22:51 A . (.Alex Dragokas.) – C:\Users\goldfish\Desktop\laptop issue\clearlnk_2.9.0.11.exe [462976]

                      —\ File Associations Shell Spawning (10) - 1s
                      O67 - Shell Spawning: <.bat> [HKLM..\open\Command] (…) – “%1” %*
                      O67 - Shell Spawning: <.cpl> [HKLM..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) – C:\Windows\System32\control.exe =>.Microsoft Corporation
                      O67 - Shell Spawning: <.cmd> [HKLM..\open\Command] (…) – “%1” %*
                      O67 - Shell Spawning: <.com> [HKLM..\open\Command] (…) – “%1” %*
                      O67 - Shell Spawning: <.evt> [HKLM..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) – C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
                      O67 - Shell Spawning: <.exe> [HKLM..\open\Command] (…) – “%1” %*
                      O67 - Shell Spawning: <.html> [HKLM..\open\Command] (.Microsoft Corporation - Internet Explorer.) – C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
                      O67 - Shell Spawning: <.js> [HKLM..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) – C:\Windows\System32\wscript.exe =>.Microsoft Corporation
                      O67 - Shell Spawning: <.reg> [HKLM..\open\Command] (.Microsoft Corporation - Registry Editor.) – C:\Windows\regedit.exe =>.Microsoft Corporation
                      O67 - Shell Spawning: <.scr> [HKLM..\open\Command] (…) – “%1” /S

                      —\ Start Menu Internet (12) - 0s
                      O68 - StartMenuInternet: [HKLM..\Shell\open\Command] (.Avira Operations GmbH & Co. KG - Avira Scout.) – C:\Program Files (x86)\Avira\Scout\Application\scout.exe =>.Avira Operations GmbH & Co. KG®
                      O68 - StartMenuInternet: [HKLM..\Shell\open\Command] (.Google Inc. - Google Chrome.) – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
                      O68 - StartMenuInternet: <IEXPLORE.EXE> [HKLM..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) – C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
                      O68 - StartMenuInternet: [HKLM..\InstallInfo\ShowIconsCommand] (.Avira Operations GmbH & Co. KG - Avira Scout.) – C:\Program Files (x86)\Avira\Scout\Application\scout.exe =>.Avira Operations GmbH & Co. KG
                      O68 - StartMenuInternet: [HKLM..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
                      O68 - StartMenuInternet: <IEXPLORE.EXE> [HKLM..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) – C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
                      O68 - StartMenuInternet: [HKLM..\InstallInfo\ReinstallCommand] (.Avira Operations GmbH & Co. KG - Avira Scout.) – C:\Program Files (x86)\Avira\Scout\Application\scout.exe =>.Avira Operations GmbH & Co. KG
                      O68 - StartMenuInternet: [HKLM..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
                      O68 - StartMenuInternet: <IEXPLORE.EXE> [HKLM..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) – C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
                      O68 - StartMenuInternet: [HKLM..\InstallInfo\HideIconsCommand] (.Avira Operations GmbH & Co. KG - Avira Scout.) – C:\Program Files (x86)\Avira\Scout\Application\scout.exe =>.Avira Operations GmbH & Co. KG
                      O68 - StartMenuInternet: [HKLM..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
                      O68 - StartMenuInternet: <IEXPLORE.EXE> [HKLM..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) – C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

                      —\ Search Browser Infection (5) - 11s
                      O69 - SBI: SearchScopes [HKCU] {67B4F6F6-DEA2-42F9-84A7-6785674F4D19} [DefaultScope] - (Google) - http://www.google.com/ =>.Google Inc.
                      O69 - SBI: SearchScopes [HKCU] {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} - (Google) - http://www.google.com/ =>.Google Inc.
                      O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com
                      O69 - SBI: SearchScopes [HKLM] {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} - (Google) - http://www.google.com/ =>.Google Inc.
                      O69 - SBI: SearchScopes [HKLM] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - http://www.google.com/ =>.Google Inc.

                      —\ Search Svchost Services (32) - 0s
                      O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) – C:\Windows\System32\aelupsvc.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) – C:\Windows\System32\certprop.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) – C:\Windows\System32\certprop.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) – C:\Windows\system32\srvsvc.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) – C:\Windows\System32\gpsvc.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) – C:\Windows\System32\ikeext.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) – C:\Windows\System32\Audiosrv.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) – C:\Windows\System32\rasauto.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) – C:\Windows\System32\rasmans.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) – C:\Windows\System32\mprdim.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) – C:\Windows\System32\Sens.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) – C:\Windows\System32\ipnathlp.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows™ Telephony Server.) – C:\Windows\System32\tapisrv.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remote Desktop Session Host Server Remote C.) – C:\Windows\System32\termsrv.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) – C:\Windows\system32\wuaueng.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) – C:\Windows\System32\qmgr.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) – C:\Windows\System32\shsvcs.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) – C:\Windows\System32\iphlpsvc.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) – C:\Windows\system32\seclogon.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) – C:\Windows\System32\appinfo.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) – C:\Windows\system32\iscsiexe.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) – C:\Windows\system32\mmcss.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) – C:\Windows\system32\wbem\WMIsvc.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) – C:\Windows\System32\SessEnv.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) – C:\Windows\System32\browser.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) – C:\Windows\System32\eapsvc.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) – C:\Windows\system32\schedsvc.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) – C:\Windows\system32\kmsvc.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) – C:\Windows\System32\wercplsupport.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) – C:\Windows\system32\profsvc.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) – C:\Windows\system32\themeservice.dll [317400] =>.Microsoft Corporation
                      O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) – C:\Windows\System32\bdesvc.dll [317400] =>.Microsoft Corporation

                      —\ Additional Scan (O88) (7) - 0s
                      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} =>.Superfluous.Orphan
                      HKCU\Software\Microsoft\Windows\CurrentVersion\Ext \Stats{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} =>.Superfluous.Orphan
                      HKCU\Software\Microsoft\Windows\CurrentVersion\Ext \Settings{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} =>.Superfluous.Orphan
                      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} =>.Superfluous.Orphan
                      HKCU\Software\Microsoft\Windows\CurrentVersion\Ext \Stats{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} =>.Superfluous.Orphan
                      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uni nstall{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C} =>Riskware.QuickTime
                      HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Curren tVersion\Uninstall{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C} =>Riskware.QuickTime

                      —\ Summary of the elements found (1) - 0s
                      https://nicolascoolman.eu/2017/01/15...are-quicktime/ =>Riskware.QuickTime

                      ~ Unselected Options: O82,
                      ~ End of the scan, 94527 items in 07mn38s (1490)(0)

                      Comment

                      • Malnutrition
                        PCHF Moderator
                        • Jul 2016
                        • 7041

                        #26
                        Originally posted by Goldfish
                        The Ninite installer froze partway through and wouldn’t cancel either, but it seems to have installed okay (and no error when I log in).
                        Sweet.
                        Originally posted by Goldfish
                        The file C:\Windows\Minidump\030517-23103-01.dmp
                        is not found with everything, and when I manually go to the directory using Windows Explorer it is empty. This happened when I had the error previously too - couldn’t find the file.
                        Ccleaner settings, Uncheck the option that deletes the dump files.

                        [ATTACH]1765[/ATTACH]

                        Comment

                        • Malnutrition
                          PCHF Moderator
                          • Jul 2016
                          • 7041

                          #27
                          You have any idea what this is?

                          C:\Users\goldfish\AppData\Local\微软公司

                          Also, on a side note you will need to replace your user name in order for these fixes to work.

                          Comment

                          • Goldfish
                            PCHF Member
                            • Mar 2017
                            • 26

                            #28
                            Sure, apologies, I’m quite conscious of security when posting publicly. Should I re-run the fixlist.txt with “goldfish” replaced with my name? Then run RogueKiller again? RogueKiller takes a long time so if there is anything else I should run first, please let me know.

                            I’m not sure what that file is. I lived in Hong Kong so might have some Chinese-language things on my laptop, but it was a long time ago and I don’t speak Chinese myself so shouldn’t be much. (Google translate says it is "Microsoft Corporation if that helps?)

                            Comment

                            • Malnutrition
                              PCHF Moderator
                              • Jul 2016
                              • 7041

                              #29
                              No, lets not run the fixlist again, for the most part everything listed was removed.

                              Would you like the Chinese stuff removed from your machine, or leave it?

                              I would like you to run RogueKiller again, cause I am curious as to why it is BSOD. So run it, allow it to crash (if it does) then analyze the dump file and post it. It will take some time to go over this latest log.

                              Also, is this a business machine? Or your personal?

                              Have any idea what this file is??

                              C:\Users\goldfish\AppData\Roaming.#

                              Comment

                              • Goldfish
                                PCHF Member
                                • Mar 2017
                                • 26

                                #30
                                Okay, I’ll run RogueKiller again. It’s my personal machine but right now I don’t have a job so I am doing some freelancing from home.
                                It’s fine to remove the Chinese language things.
                                No idea what that file is!

                                Comment

                                Working...