--------------- QuickDiag | g3n-h@ckm@n | V3_02.04.17.1 ---------------
----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 19/04/2017 16:49:23
Updated 02/04/2017 | 14.30 (GMT) by g3n-h@ckm@n
Contact :
http://www.sosvirus.net/
Time Zone : (UTC-08:00) Pacific Time (US & Canada)
[Mitch (Administrator)] - [MITCH-PC] (S-1-5-21-2113883840-1160270776-2747418757-1000)
System: Microsoft Windows 7 Home Premium - Service Pack 1 - (6.1.7601) - BuildType: Multiprocessor Free - OSLanguage: 1033 (0409)
System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True
Boot : Microsoft Windows 7 Home Premium |C:\windows|\Device\Harddisk0\Partition2
Boot : Normal boot
PC: Satellite L755 - TOSHIBA - IdNumber: XB319792W - UUID: 71136460-FBBA-11E0-961F-047D7B056E26
Processor : X64 - 2394 Mhz - Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz
InsydeH2O Version 03.60.453.40 - en|US|iso8859-1 - INSYDE - S/N: XB319792W - 3.40 - TOSQCI - 1
CoreTemp : ? Celsius
----------| Quick
---------- | SoundDevice
Conexant SmartAudio HD - Status: OK - Manufacturer: Conexant - PNPDeviceID: HDAUDIO\FUNC_01&VEN_14F1&DEV_5069&SUBSYS_1179FC52&REV_1003\4&2152523C&0&0001
Intel(R) Display Audio - Status: OK - Manufacturer: Intel(R) Corporation - PNPDeviceID: HDAUDIO\FUNC_01&VEN_8086&DEV_2805&SUBSYS_1179FC50&REV_1000\4&2152523C&0&0301
---------- | Video
Intel(R) HD Graphics Family - Resolution: 1366x768 - Colors: 4294967296 - RefreshRate: 59 - 32 Bits Per Pixel - DeviceID: VideoController1 - Drivers: igdumd64,igd10umd64.dll,igd10umd64.dll,igdumdx32,igd10umd32,igd10umd32 - PNPDeviceID: PCI\VEN_8086&DEV_0116&SUBSYS_FC501179&REV_09\3&11583659&1&10 - AdapterCompatibility: Intel Corporation - RAM: 1885265920
Inegrated Video Chipset DeviceName: Intel(R) HD Graphics Family - DriverVersion: 8.15.10.2353 - SpecificationVersion: 1025
---------- | Codecs
c:\windows\system32\msrle32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 16384 - Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\msvidc32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 38912 - Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\imaadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 22016 - Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\msg711.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 14848 - Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\msgsm32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 29184 - Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\msadp32.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 24064 - Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\msyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 25600 - Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\iyuv_32.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 54272 - Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\tsbyuv.dll - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 14848 - Manufacturer: Microsoft Corporation - Status: OK
c:\windows\system32\l3codeca.acm - ClassName: Win32_CodecFile - FSName: NTFS - FileSize: 81408 - Manufacturer: Fraunhofer Institut Integrierte Schaltungen IIS - Status: OK
---------- | CPU
---------- | Network
WAN Miniport (SSTP) - - Microsoft - Status: - PnPID : ROOT\MS_SSTPMINIPORT\0000
WAN Miniport (IKEv2) - - Microsoft - Status: - PnPID : ROOT\MS_AGILEVPNMINIPORT\0000
WAN Miniport (L2TP) - - Microsoft - Status: - PnPID : ROOT\MS_L2TPMINIPORT\0000
WAN Miniport (PPTP) - - Microsoft - Status: - PnPID : ROOT\MS_PPTPMINIPORT\0000
WAN Miniport (PPPOE) - - Microsoft - Status: - PnPID : ROOT\MS_PPPOEMINIPORT\0000
WAN Miniport (IPv6) - - Microsoft - Status: - PnPID : ROOT\MS_NDISWANIPV6\0000
WAN Miniport (Network Monitor) - - Microsoft - Status: - PnPID : ROOT\MS_NDISWANBH\0000
Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC - Ethernet 802.3 - Realtek Semiconductor Corp. - Status: - PnPID : PCI\VEN_10EC&DEV_8176&SUBSYS_818110EC&REV_01\4&2EF5F2DC&0&00E5
WAN Miniport (IP) - - Microsoft - Status: - PnPID : ROOT\MS_NDISWANIP\0000
Microsoft ISATAP Adapter - Tunnel - Microsoft - Status: - PnPID : ROOT\*ISATAP\0000
RAS Async Adapter - - - Status: - PnPID :
Atheros AR8152/8158 PCI-E Fast Ethernet Controller (NDIS 6.20) - Ethernet 802.3 - Atheros - Status: - PnPID : PCI\VEN_1969&DEV_2062&SUBSYS_FC501179&REV_C1\4&2F28935&0&00E6
Teredo Tunneling Pseudo-Interface - Tunnel - Microsoft - Status: - PnPID : ROOT\*TEREDO\0000
Microsoft 6to4 Adapter - Tunnel - Microsoft - Status: - PnPID : ROOT\*6TO4MP\0000
Microsoft ISATAP Adapter #2 - Tunnel - Microsoft - Status: - PnPID : ROOT\*ISATAP\0001
---------- | Memory
RAM = Total (MB) : 4141 | Free (MB) : 2938
Pagefile = Total (MB) : 8280 | Free (MB) : 7039
Virtual = Total (MB) : 4194 | Free (MB) : 4020
Physical Memory 0 : Capacity: 2147483648 - ChannelA-DIMM0 - Posit.: 1 - Manufacturer: Micron Technology - PartNumber: 8JSF25664HZ-1G4D1 - S/N: 3756A6B0
Physical Memory 2 : Capacity: 2147483648 - ChannelB-DIMM0 - Posit.: 2 - Manufacturer: Micron Technology - PartNumber: 8JSF25664HZ-1G4D1 - S/N: 3756A6AF
---------- | SID Users
Administrator : [S-1-5-21-2113883840-1160270776-2747418757-500]
Guest : [S-1-5-21-2113883840-1160270776-2747418757-501]
HomeGroupUser$ : [S-1-5-21-2113883840-1160270776-2747418757-1002]
Mitch : [S-1-5-21-2113883840-1160270776-2747418757-1000]
Administrators : [S-1-5-32-544]
Distributed COM Users : [S-1-5-32-562]
Event Log Readers : [S-1-5-32-573]
Guests : [S-1-5-32-546]
IIS_IUSRS : [S-1-5-32-568]
Performance Log Users : [S-1-5-32-559]
Performance Monitor Users : [S-1-5-32-558]
Users : [S-1-5-32-545]
HomeUsers : [S-1-5-21-2113883840-1160270776-2747418757-1001]
---------- | SystemAccounts
Name: Everyone - SID: S-1-1-0 - SIDType: 5 - Status: OK
Name: LOCAL - SID: S-1-2-0 - SIDType: 5 - Status: OK
Name: CREATOR OWNER - SID: S-1-3-0 - SIDType: 5 - Status: OK
Name: CREATOR GROUP - SID: S-1-3-1 - SIDType: 5 - Status: OK
Name: CREATOR OWNER SERVER - SID: S-1-3-2 - SIDType: 5 - Status: OK
Name: CREATOR GROUP SERVER - SID: S-1-3-3 - SIDType: 5 - Status: OK
Name: OWNER RIGHTS - SID: S-1-3-4 - SIDType: 5 - Status: OK
Name: DIALUP - SID: S-1-5-1 - SIDType: 5 - Status: OK
Name: NETWORK - SID: S-1-5-2 - SIDType: 5 - Status: OK
Name: BATCH - SID: S-1-5-3 - SIDType: 5 - Status: OK
Name: INTERACTIVE - SID: S-1-5-4 - SIDType: 5 - Status: OK
Name: SERVICE - SID: S-1-5-6 - SIDType: 5 - Status: OK
Name: ANONYMOUS LOGON - SID: S-1-5-7 - SIDType: 5 - Status: OK
Name: PROXY - SID: S-1-5-8 - SIDType: 5 - Status: OK
Name: SYSTEM - SID: S-1-5-18 - SIDType: 5 - Status: OK
Name: ENTERPRISE DOMAIN CONTROLLERS - SID: S-1-5-9 - SIDType: 5 - Status: OK
Name: SELF - SID: S-1-5-10 - SIDType: 5 - Status: OK
Name: Authenticated Users - SID: S-1-5-11 - SIDType: 5 - Status: OK
Name: RESTRICTED - SID: S-1-5-12 - SIDType: 5 - Status: OK
Name: TERMINAL SERVER USER - SID: S-1-5-13 - SIDType: 5 - Status: OK
Name: REMOTE INTERACTIVE LOGON - SID: S-1-5-14 - SIDType: 5 - Status: OK
Name: IUSR - SID: S-1-5-17 - SIDType: 5 - Status: OK
Name: LOCAL SERVICE - SID: S-1-5-19 - SIDType: 5 - Status: OK
Name: NETWORK SERVICE - SID: S-1-5-20 - SIDType: 5 - Status: OK
Name: BUILTIN - SID: S-1-5-32 - SIDType: 3 - Status: OK
---------- | Drives
C:\ -> [Fixed] | [TI106234W0C] | Total : 449.77 Go | Free : 402.28 Go -> NTFS [ATA]
E:\ -> [Removable] | [] | Total : 1.9 Go | Free : 1.5 Go -> FAT [USB]
F:\ -> [CDROM] | [U3 System] | Total : 0.01 Go | Free : 0 Go -> CDFS [USB]
DeviceID: \\.\PHYSICALDRIVE0 - Status: OK - IDE - Fixed hard disk media - 3 Part. - PnPID : IDE\DISKTOSHIBA_MK5075GSX_______________________GT001M__\4&2838251D&0&0.0.0
DeviceID: \\.\PHYSICALDRIVE1 - Status: OK - USB - Removable Media - 1 Part. - PnPID : USBSTOR\DISK&VEN_SANDISK&PROD_U3_CRUZER_MICRO&REV_4.05\00001889E574CD5F&0
---------- | Windows updates
Last detection : 2012-08-12 21:11:03
Downloaded last ones : 2012-11-16 02:18:27
Installed last ones : 2012-11-16 03:04:58
Next search : 2017-04-19 01:49:50
Windows Is Activated
---------- | Browsers
IE : 9.0.8112.16447 (© Microsoft Corporation.)
GC : 57.0.2987.133 (Copyright 2016 Google Inc.)
Default : "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1"
---------- | FlashPlayer
FlashPlayer ActiveX : 18.0.0.232
FlashPlayer Plugin : 18.0.0.232
---------- | Security
AM : Malwarebytes' Anti-Malware ( 2.3.55.0) [Update : 08/09/2015 10:46:40]
FW : avast! Antivirus Disabled
WMI : OK
WU: Windows Update Service [Auto(2)] = Running
WMI: Windows Management Instrumentation [Auto(2)] = Running
---------- | Running processes
428 | [Owner : SYSTEM | Parent : 4(System) | 1.22 Mo] - (.Microsoft Corporation - Windows Session Manager.) - (6.1.7600.16385) = C:\Windows\System32\smss.exe [13/07/2009 16:19:50]
528 | [Owner : SYSTEM | Parent : 512() | 4.87 Mo] - (.Microsoft Corporation - Client Server Runtime Process.) - (6.1.7600.16385) = C:\Windows\System32\csrss.exe [13/07/2009 16:19:49]
600 | [Owner : SYSTEM | Parent : 512() | 4.53 Mo] - (.Microsoft Corporation - Windows Start-Up Application.) - (6.1.7600.16385) = C:\Windows\System32\wininit.exe [13/07/2009 16:52:37]
624 | [Owner : SYSTEM | Parent : 608() | 20.11 Mo] - (.Microsoft Corporation - Client Server Runtime Process.) - (6.1.7600.16385) = C:\Windows\System32\csrss.exe [13/07/2009 16:19:49]
656 | [Owner : SYSTEM | Parent : 600(wininit.exe) | 8.78 Mo] - (.Microsoft Corporation - Services and Controller app.) - (6.1.7600.16385) = C:\Windows\System32\services.exe [13/07/2009 16:19:46]
672 | [Owner : SYSTEM | Parent : 600(wininit.exe) | 11.12 Mo] - (.Microsoft Corporation - Local Security Authority Process.) - (6.1.7601.17725) = C:\Windows\System32\lsass.exe [31/01/2012 15:40:16]
680 | [Owner : SYSTEM | Parent : 600(wininit.exe) | 4.36 Mo] - (.Microsoft Corporation - Local Session Manager Service.) - (6.1.7601.17514) = C:\Windows\System32\lsm.exe [20/11/2010 20:23:53]
784 | [Owner : SYSTEM | Parent : 656(services.exe) | 9.6 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (6.1.7601.17568) = C:\Windows\System32\svchost.exe [01/08/2011 00:21:59]
876 | [Owner : NETWORK SERVICE | Parent : 656(services.exe) | 7.44 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (6.1.7601.17568) = C:\Windows\System32\svchost.exe [01/08/2011 00:21:59]
936 | [Owner : LOCAL SERVICE | Parent : 656(services.exe) | 18.42 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (6.1.7601.17568) = C:\Windows\System32\svchost.exe [01/08/2011 00:21:59]
968 | [Owner : SYSTEM | Parent : 656(services.exe) | 89.41 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (6.1.7601.17568) = C:\Windows\System32\svchost.exe [01/08/2011 00:21:59]
1012 | [Owner : SYSTEM | Parent : 656(services.exe) | 37.3 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (6.1.7601.17568) = C:\Windows\System32\svchost.exe [01/08/2011 00:21:59]
384 | [Owner : LOCAL SERVICE | Parent : 936(svchost.exe) | ?????] - (.Microsoft Corporation - Windows Audio Device Graph Isolation.) - (6.1.7601.17514) = C:\Windows\System32\audiodg.exe [20/11/2010 20:24:32]
540 | [Owner : LOCAL SERVICE | Parent : 656(services.exe) | 11.31 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (6.1.7601.17568) = C:\Windows\System32\svchost.exe [01/08/2011 00:21:59]
892 | [Owner : NETWORK SERVICE | Parent : 656(services.exe) | 12.26 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (6.1.7601.17568) = C:\Windows\System32\svchost.exe [01/08/2011 00:21:59]
1076 | [Owner : SYSTEM | Parent : 608() | 7.17 Mo] - (.Microsoft Corporation - Windows Logon Application.) - (6.1.7601.17514) = C:\Windows\System32\winlogon.exe [20/11/2010 20:24:29]
1108 | [Owner : SYSTEM | Parent : 656(services.exe) | 42.52 Mo] - (.AVAST Software - avast! Service.) - (12.1.3076.0) = C:\Program Files\AVAST Software\Avast\AvastSvc.exe [19/07/2016 18:28:30]
1456 | [Owner : SYSTEM | Parent : 1012(svchost.exe) | 5.28 Mo] - (.Microsoft Corporation - Task Scheduler Engine.) - (6.1.7601.17514) = C:\Windows\System32\taskeng.exe [20/11/2010 20:24:27]
1488 | [Owner : SYSTEM | Parent : 656(services.exe) | 12.18 Mo] - (.Microsoft Corporation - Spooler SubSystem App.) - (6.1.7601.17514) = C:\Windows\System32\spoolsv.exe [20/11/2010 20:24:27]
1524 | [Owner : LOCAL SERVICE | Parent : 656(services.exe) | 13.9 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (6.1.7601.17568) = C:\Windows\System32\svchost.exe [01/08/2011 00:21:59]
1660 | [Owner : LOCAL SERVICE | Parent : 656(services.exe) | 11.41 Mo] - (.Microsoft Corporation - Host Process for Windows Services.) - (6.1.7601.17568) = C:\Windows\System32\svchost.exe [01/08/2011 00:21:59]
1700 | [Owner : SYSTEM | Parent : 656(services.exe) | 6.54 Mo] - (.Giraffic - Giraffic Video Accelerator Watchdog.) - (0.86.412.230) = C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe [13/05/2013 04:56:02]
1352 | [Owner : SYSTEM | Parent : 656(services.exe) | 4.9 Mo] - (.Microsoft Corporation - Microsoft Application Virtualization Virtual Service Agent.) - (4.6.2.22610) = C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [01/10/2011 09:30:22]
1848 | [Owner : SYSTEM | Parent : 656(services.exe) | 4.31 Mo] - (.TOSHIBA Corporation - TDCSrv Application.) - (1.0.0.8) = C:\Windows\System32\TODDSrv.exe [01/08/2011 00:31:59]
2056 | [Owner : SYSTEM | Parent : 656(services.exe) | 7.18 Mo] - (.TOSHIBA Corporation - TOSHIBA Power Saver.) - (1.0.0.5) = C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe [17/05/2011 14:34:18]
2076 | [Owner : SYSTEM | Parent : 1700(Veoh_GirafficWatchdog.exe) | 8.87 Mo] - (.Giraffic - Giraffic Video Accelerator.) - (0.86.412.230) = C:\Program Files (x86)\Giraffic\Veoh_Giraffic.exe [13/05/2013 04:55:30]
2180 | [Owner : SYSTEM | Parent : 656(services.exe) | 10.96 Mo] - (.Microsoft Corp. - Microsoft® Windows Live ID Service.) - (7.250.4232.0) = C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [28/03/2011 21:11:06]
2444 | [Owner : Mitch | Parent : 968(svchost.exe) | 48.48 Mo] - (.Microsoft Corporation - Desktop Window Manager.) - (6.1.7600.16385) = C:\Windows\System32\dwm.exe [13/07/2009 16:37:38]
2500 | [Owner : SYSTEM | Parent : 656(services.exe) | 16.26 Mo] - (.Copyright 2017. - ZAM.) - (2.72.0.101) = C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [08/09/2015 10:44:23]
2516 | [Owner : SYSTEM | Parent : 2180(WLIDSVC.EXE) | 3.49 Mo] - (.Microsoft Corp. - Microsoft® Windows Live ID Service Monitor.) - (7.250.4232.0) = C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE [28/03/2011 21:11:06]
2584 | [Owner : Mitch | Parent : 2436() | 62.96 Mo] - (.Microsoft Corporation - Windows Explorer.) - (6.1.7601.17567) = C:\Windows\explorer.exe [01/08/2011 00:22:16]
2884 | [Owner : SYSTEM | Parent : 656(services.exe) | 14.34 Mo] - (.Microsoft Corporation - Microsoft Application Virtualization Client Service.) - (4.6.2.22610) = C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [01/10/2011 09:30:18]
2460 | [Owner : SYSTEM | Parent : 656(services.exe) | 7.2 Mo] - (.TOSHIBA Corporation - TOSHIBA eco Utility Service.) - (1.3.0.0) = C:\Program Files\Toshiba\TECO\TecoService.exe [24/05/2011 09:58:12]
2328 | [Owner : SYSTEM | Parent : 656(services.exe) | 10.2 Mo] - (.Microsoft Corporation - Microsoft Office Client Virtualization Service.) - (14.0.6114.5003) = C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [04/01/2012 15:22:40]
3108 | [Owner : SYSTEM | Parent : 784(svchost.exe) | 7.09 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (6.1.7601.17514) = C:\Windows\System32\wbem\WmiPrvSE.exe [20/11/2010 20:24:15]
3460 | [Owner : LOCAL SERVICE | Parent : 968(svchost.exe) | 6.33 Mo] - (.Microsoft Corporation - Windows Driver Foundation - User-mode Driver Framework Host Process.) - (6.1.7601.17514) = C:\Windows\System32\WUDFHost.exe [20/11/2010 20:23:50]
3836 | [Owner : Mitch | Parent : 2584(explorer.exe) | 12.93 Mo] - (.TOSHIBA Corporation - TOSHIBA Power Saver.) - (1.0.0.7) = C:\Program Files\Toshiba\Power Saver\TPwrMain.exe [17/05/2011 14:34:50]
3884 | [Owner : Mitch | Parent : 2584(explorer.exe) | 46.19 Mo] - (.TOSHIBA Corporation - TOSHIBA Flash Cards Main Module.) - (1.0.11.64) = C:\Program Files\Toshiba\FlashCards\TCrdMain.exe [27/04/2011 14:00:42]
4012 | [Owner : Mitch | Parent : 2584(explorer.exe) | 6.25 Mo] - (.Conexant Systems, Inc. - Conexant High Definition Audio Filter Agent.) - (1.7.32.0) = C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe [20/10/2011 10:16:13]
1840 | [Owner : Mitch | Parent : 2584(explorer.exe) | 7.57 Mo] - (.TOSHIBA Corporation - TOSHIBA eco Utility.) - (1.3.0.0) = C:\Program Files\Toshiba\TECO\Teco.exe [24/05/2011 09:57:52]
1368 | [Owner : Mitch | Parent : 2584(explorer.exe) | 6.89 Mo] - (.TOSHIBA Corporation -.) - (1.0.0.2) = C:\Program Files\Toshiba\TPHM\TosWaitSrv.exe [01/07/2011 11:46:44]
1364 | [Owner : Mitch | Parent : 2584(explorer.exe) | 5.52 Mo] - (.TOSHIBA Corporation - Toshiba Volume Regulator.) - (1.0.0.6) = C:\Program Files\Toshiba\TosVolRegulator\TosVolRegulator.exe [20/10/2011 11:03:32]
812 | [Owner : Mitch | Parent : 2584(explorer.exe) | 7.92 Mo] - (.TOSHIBA Corporation - Message Center.) - (1.6.0.64) = C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [27/07/2011 15:44:14]
2808 | [Owner : Mitch | Parent : 2584(explorer.exe) | 25.83 Mo] - (.TOSHIBA Corporation - Monitor of TOSHIBA ReelTime.) - (1.7.9.0) = C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe [28/06/2011 11:29:56]
3720 | [Owner : Mitch | Parent : 1012(svchost.exe) | 6.47 Mo] - (.Microsoft Corporation - Task Scheduler Engine.) - (6.1.7601.17514) = C:\Windows\System32\taskeng.exe [20/11/2010 20:24:27]
1152 | [Owner : Mitch | Parent : 3608() | 12 Mo] - (.- DivX Update.) - (1.0.6.15) = C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [28/07/2011 16:08:12]
264 | [Owner : Mitch | Parent : 3608() | 17.14 Mo] - (.AVAST Software - avast! Antivirus.) - (12.1.3076.11) = C:\Program Files\AVAST Software\Avast\avastui.exe [08/08/2016 16:11:02]
3520 | [Owner : SYSTEM | Parent : 656(services.exe) | 10.32 Mo] - (.Microsoft Corporation - Microsoft Windows Search Indexer.) - (7.0.7601.17610) = C:\Windows\System32\SearchIndexer.exe [01/08/2011 00:26:30]
4648 | [Owner : Mitch | Parent : 2584(explorer.exe) | 26.24 Mo] - (.SosVirus - QuickDiag.) - (2.4.17.1) = E:\quickdiag_3_02.04.17.1.exe [19/04/2017 11:00:56]
5080 | [Owner : SYSTEM | Parent : 656(services.exe) | 4.7 Mo] - (.Intel Corporation - Local Manageability Service.) - (7.0.2.1164) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [20/10/2011 10:07:44]
5104 | [Owner : NETWORK SERVICE | Parent : 656(services.exe) | 12.59 Mo] - (.Microsoft Corporation - Microsoft Software Protection Platform Service.) - (6.1.7601.17514) = C:\Windows\System32\sppsvc.exe [20/11/2010 20:23:56]
2004 | [Owner : NETWORK SERVICE | Parent : 656(services.exe) | 25.34 Mo] - (.Microsoft Corporation - Windows Media Player Network Sharing Service.) - (12.0.7601.17514) = C:\Program Files\Windows Media Player\wmpnetwk.exe [20/11/2010 20:25:05]
2204 | [Owner : SYSTEM | Parent : 656(services.exe) | 7.24 Mo] - (.Intel Corporation - User Notification Service.) - (7.0.2.1164) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [20/10/2011 10:07:46]
3312 | [Owner : NETWORK SERVICE | Parent : 784(svchost.exe) | 11.9 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (6.1.7601.17514) = C:\Windows\System32\wbem\WmiPrvSE.exe [20/11/2010 20:24:15]
3036 | [Owner : NETWORK SERVICE | Parent : 784(svchost.exe) | 7.12 Mo] - (.Microsoft Corporation - WMI Provider Host.) - (6.1.7601.17514) = C:\Windows\SysWOW64\wbem\WmiPrvSE.exe [20/11/2010 20:24:27]
---------- | MD5
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - [01/08/2011 00:22:16] - (.© Microsoft Corporation. - Windows Explorer.) - [2804.5 Ko] - (6.1.7601.17567) : C:\windows\Explorer.exe
[MD5.5746BD7E255DD6A8AFA06F7C42C1BA41] - [20/11/2010 20:23:55] - (.© Microsoft Corporation. - Windows Command Processor.) - [337 Ko] - (6.1.7601.17514) : C:\windows\System32\cmd.exe
[MD5.60C2862B4BF0FD9F582EF344C2B1EC72] - [13/07/2009 16:19:49] - (.© Microsoft Corporation. - Client Server Runtime Process.) - [7.5 Ko] - (6.1.7600.16385) : C:\windows\System32\csrss.exe
[MD5.A8EDB86FC2A4D6D1285E4C70384AC35A] - [13/07/2009 16:59:17] - (.© Microsoft Corporation. - COM Surrogate.) - [9.5 Ko] - (6.1.7600.16385) : C:\windows\System32\dllhost.exe
[MD5.B9B42A302325537D7B9DC52D47F33A73] - [27/12/2011 16:02:44] - (.© Microsoft Corporation. - Windows NT BASE API Client DLL.) - [1135.5 Ko] - (6.1.7601.17651) : C:\windows\System32\Kernel32.dll
[MD5.C118A82CD78818C29AB228366EBF81C3] - [31/01/2012 15:40:16] - (.© Microsoft Corporation. - Local Security Authority Process.) - [30.5 Ko] - (6.1.7601.17725) : C:\windows\System32\lsass.exe
[MD5.5C627D1B1138676C0A7AB2C2C190D123] - [20/11/2010 20:24:01] - (.© Microsoft Corporation. - Distributed COM Services.) - [500 Ko] - (6.1.7601.17514) : C:\windows\System32\rpcss.dll
[MD5.DD81D91FF3B0763C392422865C9AC12E] - [13/07/2009 16:57:20] - (.© Microsoft Corporation. - Windows host process (Rundll32).) - [44.5 Ko] - (6.1.7600.16385) : C:\windows\System32\rundll32.exe
[MD5.24ACB7E5BE595468E3B9AA488B9B4FCB] - [13/07/2009 16:19:46] - (.© Microsoft Corporation. - Services and Controller app.) - [321 Ko] - (6.1.7600.16385) : C:\windows\System32\services.exe
[MD5.6F68F63794097E54F36474ED4384B759] - [01/08/2011 00:21:59] - (.© Microsoft Corporation. - Host Process for Windows Services.) - [27 Ko] - (6.1.7601.17568) : C:\windows\System32\svchost.exe
[MD5.FE70103391A64039A921DBFFF9C7AB1B] - [20/11/2010 20:24:09] - (.© Microsoft Corporation. - Multi-User Windows USER API Client DLL.) - [984.5 Ko] - (6.1.7601.17514) : C:\windows\System32\user32.dll
[MD5.BAFE84E637BF7388C96EF48D4D3FDD53] - [20/11/2010 20:24:28] - (.© Microsoft Corporation. - Userinit Logon Application.) - [30 Ko] - (6.1.7601.17514) : C:\windows\System32\userinit.exe
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - [13/07/2009 16:52:37] - (.© Microsoft Corporation. - Windows Start-Up Application.) - [126 Ko] - (6.1.7600.16385) : C:\windows\System32\Wininit.exe
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - [20/11/2010 20:24:29] - (.© Microsoft Corporation. - Windows Logon Application.) - [381.5 Ko] - (6.1.7601.17514) : C:\windows\System32\Winlogon.exe
[MD5.1C7857B62DE5994A75B054A9FD4C3825] - [15/02/2012 17:41:01] - (.© Microsoft Corporation. - Ancillary Function Driver for WinSock.) - [487 Ko] - (6.1.7601.17752) : C:\windows\System32\Drivers\afd.sys
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - [13/07/2009 16:19:47] - (.© Microsoft Corporation. - ATAPI IDE Miniport Driver.) - [23.56 Ko] - (6.1.7600.16385) : C:\windows\System32\Drivers\atapi.sys
[MD5.A34FE1E025E88798E746F484956C0720] - [20/11/2010 20:23:47] - (.© Microsoft Corporation. - ATAPI Driver Extension.) - [151.88 Ko] - (6.1.7601.17514) : C:\windows\System32\Drivers\ataport.sys
[MD5.B8BD2BB284668C84865658C77574381A] - [13/07/2009 16:19:47] - (.© Microsoft Corporation. - CD-ROM File System Driver.) - [90 Ko] - (6.1.7600.16385) : C:\windows\System32\Drivers\cdfs.sys
[MD5.F036CE71586E93D94DAB220D7BDF4416] - [20/11/2010 20:23:47] - (.© Microsoft Corporation. - SCSI CD-ROM Driver.) - [144 Ko] - (6.1.7601.17514) : C:\windows\System32\Drivers\cdrom.sys
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - [20/11/2010 20:24:32] - (.© Microsoft Corporation. - DFS Namespace Client Driver.) - [100 Ko] - (6.1.7601.17514) : C:\windows\System32\Drivers\dfsc.sys
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - [20/11/2010 20:23:47] - (.© Microsoft Corporation. - High Definition Audio Bus Driver.) - [119.5 Ko] - (6.1.7601.17514) : C:\windows\System32\Drivers\hdaudbus.sys
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - [13/07/2009 16:19:58] - (.© Microsoft Corporation. - i8042 Port Driver.) - [103 Ko] - (6.1.7600.16385) : C:\windows\System32\Drivers\i8042prt.sys
[MD5.D469B77687E12FE43E344806740B624D] - [20/10/2011 10:11:10] - (.Copyright(C) Intel Corporation 1994-2011 - Intel Rapid Storage Technology driver - x64.) - [429.02 Ko] - (10.1.2.1004) : C:\windows\System32\Drivers\iastor.sys
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - [13/07/2009 17:10:03] - (.© Microsoft Corporation. - IP Network Address Translator.) - [113.5 Ko] - (6.1.7600.16385) : C:\windows\System32\Drivers\ipnat.sys
[MD5.A5D9106A73DC88564C825D317CAC68AC] - [01/08/2011 00:25:13] - (.© Microsoft Corporation. - Windows NT SMB Minirdr.) - [154.5 Ko] - (6.1.7601.17605) : C:\windows\System32\Drivers\mrxsmb.sys
[MD5.79B47FD40D9A817E932F9D26FAC0A81C] - [20/11/2010 20:23:55] - (.© Microsoft Corporation. - NDIS 6.20 driver.) - [929.38 Ko] - (6.1.7601.17514) : C:\windows\System32\Drivers\ndis.sys
[MD5.09594D1089C523423B32A4229263F068] - [20/11/2010 20:23:51] - (.© Microsoft Corporation. - MBT Transport driver.) - [255.5 Ko] - (6.1.7601.17514) : C:\windows\System32\Drivers\netbt.sys
[MD5.A2F74975097F52A00745F9637451FDD8] - [01/08/2011 00:11:50] - (.© Microsoft Corporation. - NT File System Driver.) - [1620.88 Ko] - (6.1.7601.17577) : C:\windows\System32\Drivers\ntfs.sys
[MD5.0086431C29C35BE1DBC43F52CC273887] - [13/07/2009 17:00:41] - (.© Microsoft Corporation. - Parallel Port Driver.) - [95 Ko] - (6.1.7600.16385) : C:\windows\System32\Drivers\parport.sys
[MD5.471815800AE33E6F1C32FB1B97C490CA] - [20/11/2010 20:24:33] - (.© Microsoft Corporation. - RAS L2TP mini-port/call-manager driver.) - [126.5 Ko] - (6.1.7601.17514) : C:\windows\System32\Drivers\rasl2tp.sys
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - [13/07/2009 17:09:09] - (.© Microsoft Corporation. - SMB Transport driver.) - [91 Ko] - (6.1.7600.16385) : C:\windows\System32\Drivers\smb.sys
[MD5.ACB82BDA8F46C84F465C1AFA517DC4B9] - [14/05/2012 12:32:59] - (.© Microsoft Corporation. - TCP/IP Driver.) - [1873.36 Ko] - (6.1.7601.17802) : C:\windows\System32\Drivers\tcpip.sys
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - [20/11/2010 20:24:32] - (.© Microsoft Corporation. - TDI Translation Driver.) - [116.5 Ko] - (6.1.7601.17514) : C:\windows\System32\Drivers\tdx.sys
[MD5.DF8126BD41180351A093A3AD2FC8903B] - [01/08/2011 00:17:36] - (.© Microsoft Corporation. - Volume Shadow Copy Driver.) - [289.38 Ko] - (6.1.7601.17567) : C:\windows\System32\Drivers\volsnap.sys
---------- | Locked Applications
---------- | Explorer.exe component call (Microsoft Files Whitelisted)
(.AVAST Software.-.avast! Shell Extension.) - (12.1.3076.0) -- C:\Program Files\AVAST Software\Avast\ashShA64.dll
---------- | Svchost.exe component call (Microsoft Files Whitelisted)
---------- | ZeroAccess Check
[HKLM\Software\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll
[HKLM\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\shell32.dll
[HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll
[HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] : %systemroot%\system32\wbem\wbemess.dll
[HKLM\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll
[HKLM\Software\WOW6432Node\Classes\CLSID\{1108BE51-F58A-4CDA-BB99-7A0227D11D5E}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll
[HKLM\Software\WOW6432Node\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] : %SystemRoot%\system32\shell32.dll
[HKLM\Software\WOW6432Node\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] : %systemroot%\system32\wbem\fastprox.dll
[HKLM\Software\WOW6432Node\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] : %SystemRoot%\system32\shell32.dll
---------- | Startings up
Sidebar - (%ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [HKU\S-1-5-19\SOFTWARE\...\Run]) - User: NT AUTHORITY\LOCAL SERVICE
Sidebar - (%ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [HKU\S-1-5-20\SOFTWARE\...\Run]) - User: NT AUTHORITY\NETWORK SERVICE
CCleaner - ("C:\Program Files\CCleaner\CCleaner64.exe" /AUTO [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\...\Run]) - User: Mitch-PC\Mitch
TPwrMain - (%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE [HKLM\SOFTWARE\...\Run]) - User: Public
HSON - (%ProgramFiles%\TOSHIBA\TBS\HSON.exe [HKLM\SOFTWARE\...\Run]) - User: Public
TCrdMain - (%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe [HKLM\SOFTWARE\...\Run]) - User: Public
SmartAudio - (C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [HKLM\SOFTWARE\...\Run]) - User: Public
cAudioFilterAgent - (C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [HKLM\SOFTWARE\...\Run]) - User: Public
SynTPEnh - (%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [HKLM\SOFTWARE\...\Run]) - User: Public
Teco - ("%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r [HKLM\SOFTWARE\...\Run]) - User: Public
TosWaitSrv - (%ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe [HKLM\SOFTWARE\...\Run]) - User: Public
TosVolRegulator - (C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [HKLM\SOFTWARE\...\Run]) - User: Public
TosSENotify - (C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [HKLM\SOFTWARE\...\Run]) - User: Public
TosNC - (%ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe [HKLM\SOFTWARE\...\Run]) - User: Public
TosReelTimeMonitor - (%ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [HKLM\SOFTWARE\...\Run]) - User: Public
ZAM - ("C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe" /minimized [HKLM\SOFTWARE\...\Run]) - User: Public
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Command Processor]
"CompletionChar"=9
"DefaultColor"=0
"EnableExtensions"=1
"PathCompletionChar"=9
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner"="C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"Device"=Microsoft XPS Document Writer,winspool,Ne00:
"UserSelectedDefault"=0
[HKLM\Software\Microsoft\Command Processor]
"CompletionChar"=64
"DefaultColor"=0
"EnableExtensions"=1
"PathCompletionChar"=64
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"TPwrMain"=%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
"HSON"=%ProgramFiles%\TOSHIBA\TBS\HSON.exe
"TCrdMain"=%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [20/10/2011 10:16:13]
"SynTPEnh"=%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
"Teco"="%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
"TosWaitSrv"=%ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
"TosVolRegulator"=C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [20/10/2011 11:03:32]
"TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [09/06/2011 21:10:20]
"TosNC"=%ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
"TosReelTimeMonitor"=%ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
"ZAM"="C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe" /minimized
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"IconServiceLib"=IconCodecService.dll
"DdeSendTimeout"=0
"DesktopHeapLogging"=1
"GDIProcessHandleQuota"=10000
"ShutdownWarningDialogTimeout"=4294967295
"USERNestedWindowLimit"=50
"USERPostMessageLimit"=10000
"USERProcessHandleQuota"=10000
""=mnmsrvc
"DeviceNotSelectedTimeout"=15
"Spooler"=yes
"TransmissionRetryTimeout"=90
"LoadAppInit_DLLs"=1
"AppInit_DLLs"=
[HKLM\Software\WOW6432Node\Microsoft\Command Processor]
"CompletionChar"=64
"DefaultColor"=0
"EnableExtensions"=1
"PathCompletionChar"=64
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run]
"TSleepSrv"=%ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
"NortonOnlineBackupReminder"="C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe" UNATTENDED
"ToshibaAppPlace"="C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe"
"DivXUpdate"="C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows]
"IconServiceLib"=IconCodecService.dll
"DdeSendTimeout"=0
"DesktopHeapLogging"=1
"GDIProcessHandleQuota"=10000
"ShutdownWarningDialogTimeout"=4294967295
"USERNestedWindowLimit"=50
"USERPostMessageLimit"=10000
"USERProcessHandleQuota"=10000
""=mnmsrvc
"DeviceNotSelectedTimeout"=15
"Spooler"=yes
"TransmissionRetryTimeout"=90
"LoadAppInit_DLLs"=1
"AppInit_DLLs"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebCheck"={E6FB5E20-DE35-11CF-9C87-00AA005127ED}
---------- | Win.ini :
---------- | System.ini :
---------- | Tasks List
avast! Emergency Update
CCleanerSkipUAC
GoogleUpdateTaskMachineCore
GoogleUpdateTaskMachineUA
SafeZone scheduled Autoupdate 1463186051
{1426D1E5-5A00-4D59-985A-2107F1BEF83C}
{2FB9F27A-DE3A-4CD6-B8B6-B233E63B6955}
{65C76270-92BA-4F63-B82C-13F0D18DD623}
{A8D2B036-36FC-403B-8061-05969D1469A2}
{E210F47C-43C1-4A1F-B297-CCB4BE5B7E4D}
---------- | Startings up registry ¦ Folder
---------- | Other keys
[HKLM\System\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders"=credssp.dll
[HKLM\System\CurrentControlSet\Control\Terminal Server]
"RCDependentServices"=CertPropSvc
SessionEnv
"NotificationTimeOut"=0
"SnapshotMonitors"=1
"ProductVersion"=5.1
"AllowRemoteRPC"=0
"DelayConMgrTimeout"=0
"fDenyTSConnections"=1
"StartRCM"=0
"TSAdvertise"=0
"DeleteTempDirsOnExit"=1
"fSingleSessionPerUser"=1
"PerSessionTempDir"=0
"TSUserEnabled"=0
"InstanceID"=ca4daa9c-9a14-471f-b520-1caccd3
[HKLM\System\CurrentControlSet\Control\Session Manager]
"CriticalSectionTimeout"=2592000
"GlobalFlag"=0
"HeapDeCommitFreeBlockThreshold"=0
"HeapDeCommitTotalFreeThreshold"=0
"HeapSegmentCommit"=0
"HeapSegmentReserve"=0
"ProcessorControl"=2
"ResourceTimeoutCount"=648000
"BootExecute"=autocheck autochk *
"ExcludeFromKnownDlls"=
"ObjectDirectories"=\Windows
\RPC Control
"ProtectionMode"=1
"NumberOfInitialSessions"=2
[HKLM\System\CurrentControlSet\Control]
"PreshutdownOrder"=wuauserv
gpsvc
trustedinstaller
"WaitToKillServiceTimeout"=200
"CurrentUser"=USERNAME
"BootDriverFlags"=0
"ServiceControlManagerExtension"=%systemroot%\system32\scext.dll
"SystemStartOptions"= TESTSIGNING NOEXECUTE=OPTIN
"SystemBootDevice"=multi(0)disk(0)rdisk(0)partition(2)
"FirmwareBootDevice"=multi(0)disk(0)rdisk(0)partition(1)
[HKLM\System\CurrentControlSet\Control\lsa]
"auditbaseobjects"=0
"auditbasedirectories"=0
"crashonauditfail"=0
"fullprivilegeauditing"=0x00
"Bounds"=0x0030000000200000
"LimitBlankPasswordUse"=1
"NoLmHash"=1
"Notification Packages"=scecli
"Security Packages"=kerberos
msv1_0
schannel
wdigest
tspkg
pku2u
livessp
"Authentication Packages"=msv1_0
"LsaPid"=672
"SecureBoot"=1
"ProductType"=3
"disabledomaincreds"=0
"everyoneincludesanonymous"=0
"forceguest"=0
"restrictanonymous"=0
"restrictanonymoussam"=1
---------- | .LNK with Arguments
---------- | AppCertDlls
---------- | Dnsapi.dll
C:\windows\System32\dnsapi.dll -> OK : \drivers\etc\hosts
C:\windows\SysWOW64\dnsapi.dll -> OK : \drivers\etc\hosts
---------- | Policies | Registry
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Control Panel\Desktop]
"ScreenSaveActive"=1
"ActiveWndTrackTimeout"=0
"BlockSendInputResets"=0
"CaretWidth"=1
"ClickLockTime"=1200
"CoolSwitchColumns"=7
"CoolSwitchRows"=3
"CursorBlinkRate"=530
"DockMoving"=1
"DragFromMaximize"=1
"DragFullWindows"=1
"DragHeight"=4
"DragWidth"=4
"FocusBorderHeight"=1
"FocusBorderWidth"=1
"FontSmoothing"=2
"FontSmoothingGamma"=0
"FontSmoothingOrientation"=1
"FontSmoothingType"=2
"ForegroundFlashCount"=7
"ForegroundLockTimeout"=200000
"LeftOverlapChars"=3
"MenuShowDelay"=400
"PaintDesktopVersion"=0
"Pattern"=0
"RightOverlapChars"=3
"SnapSizing"=1
"TileWallpaper"=0
"WallpaperOriginX"=0
"WallpaperOriginY"=0
"WallpaperStyle"=10
"WheelScrollChars"=3
"WheelScrollLines"=3
"WindowArrangementActive"=1
"UserPreferencesMask"=0x9E3E078012000000
"Wallpaper"=C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg [26/12/2011 12:57:51]
"WaitToKillAppTimeout"=200
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Explorer]
"ExplorerStartupTraceRecorded"=1
"ShellState"=0x240000003028000000000000000000000000000001000000120000000000000022000000
"CleanShutdown"=0
"Browse For Folder Width"=318
"Browse For Folder Height"=288
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Start_SearchFiles"=2
"ServerAdminUI"=0
"Hidden"=2
"ShowCompColor"=1
"HideFileExt"=1
"DontPrettyPath"=0
"ShowInfoTip"=1
"HideIcons"=0
"MapNetDrvBtn"=0
"WebView"=1
"Filter"=0
"SuperHidden"=0
"SeparateProcess"=0
"AutoCheckSelect"=0
"IconsOnly"=0
"ShowTypeOverlay"=1
"ListviewAlphaSelect"=1
"ListviewShadow"=1
"TaskbarAnimations"=1
"StartMenuInit"=4
"DisablePreviewDesktop"=1
[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableInstallerDetection"=1
"EnableLUA"=1
"EnableSecureUIAPaths"=1
"EnableUIADesktopToggle"=0
"EnableVirtualization"=1
"PromptOnSecureDesktop"=1
"ValidateAdminCodeSignatures"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"scforceoption"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"FilterAdministratorToken"=0
[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]
"NoAddingComponents"=1
"NoComponents"=1
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]
"{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1
"{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1
"{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1
"{871C5380-42A0-1069-A2EA-08002B30309D}"=1
"{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1
"{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1
"{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1
"{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1
"{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu]
"{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0
"{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
"Text"=@shell32.dll,-30500
"Type"=radio
"CheckedValue"=1
"ValueName"=Hidden
"DefaultValue"=2
"HKeyRoot"=2147483649
"HelpID"=shell.hlp#51105
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer]
"ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed}
"BrowserCFCreator"={57f8510b-a5e2-41da-a8f0-8a5ae85dfffd}
"GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}
"LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff}
"FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7}
"IconUnderline"=2
"GlobalAssocChangedCounter"=22
"DoNotCleanTaskBar"=1
"MultipleInvokePromptMinimum"=10000
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"TaskbarSizeMove"=0
"StartMenuFavorites"=1
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations]
"Application"=
http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableInstallerDetection"=1
"EnableLUA"=1
"EnableSecureUIAPaths"=1
"EnableUIADesktopToggle"=0
"EnableVirtualization"=1
"PromptOnSecureDesktop"=1
"ValidateAdminCodeSignatures"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"scforceoption"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"FilterAdministratorToken"=0
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]
"NoAddingComponents"=1
"NoComponents"=1
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]
"{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=1
"{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=1
"{208D2C60-3AEA-1069-A2D7-08002B30309D}"=1
"{871C5380-42A0-1069-A2EA-08002B30309D}"=1
"{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=1
"{59031a47-3f72-44a7-89c5-5595fe6b30ee}"=1
"{031E4825-7B94-4dc3-B131-E946B44C8DD5}"=1
"{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}"=1
"{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu]
"{871C5380-42A0-1069-A2EA-08002B30309D}.default"=0
"{9343812e-1c37-4a49-a12e-4b2d810d956b}"=1
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"RegPath"=Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
"Text"=@shell32.dll,-30500
"Type"=radio
"CheckedValue"=1
"ValueName"=Hidden
"DefaultValue"=2
"HKeyRoot"=2147483649
"HelpID"=shell.hlp#51105
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer]
"ListViewPopupControl"={8be9f5ea-e746-4e47-ad57-3fb191ca1eed}
"BrowserCFCreator"={57f8510b-a5e2-41da-a8f0-8a5ae85dfffd}
"GlobalFolderSettings"={EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}
"LVPopupSearchControl"={fccf70c8-f4d7-4d8b-8c17-cd6715e37fff}
"FileOpenDialog"={DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7}
"IconUnderline"=2
"GlobalAssocChangedCounter"=92
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"TaskbarSizeMove"=0
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations]
"Application"=
http://go.microsoft.com/fwlink/?LinkId=57426&Ext=%s
---------- | Winlogon
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"ExcludeProfileDirs"=AppData\Local;AppData\LocalLow;$Recycle.Bin
"BuildNumber"=7601
"FirstLogon"=0
"ParseAutoexec"=1
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"ReportBootOk"=1
"Shell"=explorer.exe
"PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16}
"Userinit"=C:\Windows\system32\userinit.exe,
"VMApplet"=SystemPropertiesPerformance.exe /pagefile
"AutoRestartShell"=1
"Background"=0 0 0
"CachedLogonsCount"=10
"DebugServerCommand"=no
"ForceUnlockLogon"=0
"LegalNoticeCaption"=
"LegalNoticeText"=
"PasswordExpiryWarning"=5
"PowerdownAfterShutdown"=0
"ShutdownWithoutLogon"=0
"WinStationsDisabled"=0
"DisableCAD"=1
"scremoveoption"=0
"ShutdownFlags"=7
"AutoAdminLogon"=0
"DefaultUserName"=Mitch
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon]
"ReportBootOk"=1
"Shell"=explorer.exe
"PreCreateKnownFolders"={A520A1A4-1780-4FF6-BD18-167343C5AF16}
"DefaultDomainName"=
"DefaultUserName"=
"Userinit"=userinit.exe,
"VMApplet"=SystemPropertiesPerformance.exe /pagefile
---------- | Associations
[HKLM\Software\Classes\.exe]
""=exefile
"Content Type"=application/x-msdownload
[HKLM\Software\Classes\exefile\Shell\Open\Command]
""="%1" %*
"IsolatedCommand"="%1" %*
[HKLM\Software\Classes\.com]
""=comfile
[HKLM\Software\Classes\comfile\Shell\Open\Command]
""="%1" %*
[HKLM\Software\Classes\.reg]
""=regfile
[HKLM\Software\Classes\regfile\Shell\Open\Command]
""=regedit.exe "%1"
[HKLM\Software\Classes\.scr]
""=scrfile
[HKLM\Software\Classes\scrfile\Shell\Open\Command]
""="%1" /S
[HKLM\Software\Classes\.bat]
""=batfile
[HKLM\Software\Classes\batfile\Shell\Open\Command]
""="%1" %*
[HKLM\Software\Classes\.cmd]
""=cmdfile
[HKLM\Software\Classes\cmdfile\Shell\Open\Command]
""="%1" %*
[HKLM\Software\Classes\.pif]
""=piffile
[HKLM\Software\Classes\piffile\Shell\Open\Command]
""="%1" %*
[HKLM\Software\Classes\.inf]
""=inffile
[HKLM\Software\Classes\inffile\Shell\Open\Command]
""=%SystemRoot%\system32\NOTEPAD.EXE %1
[HKLM\Software\Classes\.url]
""=InternetShortcut
[HKLM\Software\Classes\.lnk]
""=lnkfile
[HKLM\Software\Classes\.hta]
"PerceivedType"=text
""=htafile
"Content Type"=application/hta
[HKLM\Software\Classes\htafile\Shell\Open\Command]
""=C:\Windows\SysWOW64\mshta.exe "%1" %*
[HKLM\Software\Classes\InternetShortcut]
"NeverShowExt"=
"InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment
"EditFlags"=2
"FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment
"IsShortcut"=
"FriendlyTypeName"=@C:\Windows\System32\ieframe.dll,-10046
"PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment
[HKLM\Software\Classes\Application.Manifest]
""=Application Manifest
"EditFlags"=65536
"BrowserFlags"=4096
"FriendlyTypeName"=@dfshim.dll,-200
[HKLM\Software\Classes\Application.Reference]
"NeverShowExt"=
""=Application Reference
"IsShortcut"=
"EditFlags"=131072
"FriendlyTypeName"=@dfshim.dll,-201
[HKLM\Software\Classes\Folder]
"ContentViewModeLayoutPatternForBrowse"=delta
"ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified
"ContentViewModeLayoutPatternForSearch"=alpha
"ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay
""=
"EditFlags"=0xD2030000
"FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size
"NoRecentDocs"=
"ThumbnailCutoff"=0
"TileInfo"=prop:System.Title;System.ItemTypeText
[HKLM\Software\WOW6432Node\Classes\.exe]
""=exefile
"Content Type"=application/x-msdownload
[HKLM\Software\WOW6432Node\Classes\exefile\Shell\Open\Command]
""="%1" %*
"IsolatedCommand"="%1" %*
[HKLM\Software\WOW6432Node\Classes\.com]
""=comfile
[HKLM\Software\WOW6432Node\Classes\comfile\Shell\Open\Command]
""="%1" %*
[HKLM\Software\WOW6432Node\Classes\.reg]
""=regfile
[HKLM\Software\WOW6432Node\Classes\regfile\Shell\Open\Command]
""=regedit.exe "%1"
[HKLM\Software\WOW6432Node\Classes\.scr]
""=scrfile
[HKLM\Software\WOW6432Node\Classes\scrfile\Shell\Open\Command]
""="%1" /S
[HKLM\Software\WOW6432Node\Classes\.bat]
""=batfile
[HKLM\Software\WOW6432Node\Classes\batfile\Shell\Open\Command]
""="%1" %*
[HKLM\Software\WOW6432Node\Classes\.cmd]
""=cmdfile
[HKLM\Software\WOW6432Node\Classes\cmdfile\Shell\Open\Command]
""="%1" %*
[HKLM\Software\WOW6432Node\Classes\.pif]
""=piffile
[HKLM\Software\WOW6432Node\Classes\piffile\Shell\Open\Command]
""="%1" %*
[HKLM\Software\WOW6432Node\Classes\.inf]
""=inffile
[HKLM\Software\WOW6432Node\Classes\inffile\Shell\Open\Command]
""=%SystemRoot%\system32\NOTEPAD.EXE %1
[HKLM\Software\WOW6432Node\Classes\.url]
""=InternetShortcut
[HKLM\Software\WOW6432Node\Classes\.lnk]
""=lnkfile
[HKLM\Software\WOW6432Node\Classes\.hta]
"PerceivedType"=text
""=htafile
"Content Type"=application/hta
[HKLM\Software\WOW6432Node\Classes\htafile\Shell\Open\Command]
""=C:\Windows\SysWOW64\mshta.exe "%1" %*
[HKLM\Software\WOW6432Node\Classes\InternetShortcut]
"NeverShowExt"=
"InfoTip"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment
"EditFlags"=2
"FullDetails"=prop:System.Link.TargetUrl;System.Rating;System.Link.Description;System.Link.Comment
"IsShortcut"=
"FriendlyTypeName"=@C:\Windows\System32\ieframe.dll,-10046
"PreviewDetails"=prop:System.Link.TargetUrl;System.Rating;System.History.VisitCount;System.History.DateChanged;System.Link.DateVisited;System.Link.Description;System.Link.Comment
[HKLM\Software\WOW6432Node\Classes\Application.Manifest]
""=Application Manifest
"EditFlags"=65536
"BrowserFlags"=4096
"FriendlyTypeName"=@dfshim.dll,-200
[HKLM\Software\WOW6432Node\Classes\Application.Reference]
"NeverShowExt"=
""=Application Reference
"IsShortcut"=
"EditFlags"=131072
"FriendlyTypeName"=@dfshim.dll,-201
[HKLM\Software\WOW6432Node\Classes\Folder]
"ContentViewModeLayoutPatternForBrowse"=delta
"ContentViewModeForBrowse"=prop:~System.ItemNameDisplay;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;~System.LayoutPattern.PlaceHolder;System.DateModified
"ContentViewModeLayoutPatternForSearch"=alpha
"ContentViewModeForSearch"=prop:~System.ItemNameDisplay;System.DateModified;~System.ItemFolderPathDisplay
""=
"EditFlags"=0xD2030000
"FullDetails"=prop:System.PropGroup.Description;System.ItemNameDisplay;System.ItemTypeText;System.Size
"NoRecentDocs"=
"ThumbnailCutoff"=0
"TileInfo"=prop:System.Title;System.ItemTypeText
[HKLM\Software\Clients\StartMenuInternet\Google Chrome\Shell\open\Command]
""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
[HKLM\Software\Clients\StartMenuInternet\Google Chrome\InstallInfo]
"ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser
[HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command]
""=C:\Program Files (x86)\Internet Explorer\iexplore.exe [12/07/2012 12:00:36]
[HKLM\Software\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo]
"ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall
[HKLM\Software\Clients\StartMenuInternet\SafeZoneStable\Shell\open\Command]
""="C:\Program Files\AVAST Software\SZBrowser\Launcher.exe"
[HKLM\Software\Clients\StartMenuInternet\SafeZoneStable\InstallInfo]
"ReinstallCommand"="C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" --makedefaultbrowser
[HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\Shell\open\Command]
""="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
[HKLM\Software\WOW6432Node\Clients\StartMenuInternet\Google Chrome\InstallInfo]
"ReinstallCommand"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser
[HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\Shell\open\Command]
""=C:\Program Files (x86)\Internet Explorer\iexplore.exe [12/07/2012 12:00:36]
[HKLM\Software\WOW6432Node\Clients\StartMenuInternet\IEXPLORE.EXE\InstallInfo]
"ReinstallCommand"="C:\Windows\System32\ie4uinit.exe" -reinstall
[HKLM\Software\WOW6432Node\Clients\StartMenuInternet\SafeZoneStable\Shell\open\Command]
""="C:\Program Files\AVAST Software\SZBrowser\Launcher.exe"
[HKLM\Software\WOW6432Node\Clients\StartMenuInternet\SafeZoneStable\InstallInfo]
"ReinstallCommand"="C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" --makedefaultbrowser
---------- | AppcompatFlags
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Program Files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe"=2
"SIGN.MEDIA=1D75FBE setup.exe"=1
"SIGN.IE=0E2560 DivXInstaller.exe"=1
"C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe"=1
"C:\ProgramData\WebEx\WebEx\1124\atinst.exe"=1
"C:\Users\Mitch\Desktop\setup.exe"=1
"C:\Users\Mitch\Desktop\OpenOffice 4.1.1 (en-US) Installation Files\setup.exe"=1
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Program Files\AVAST Software\SZBrowser\Launcher.exe"=32
---------- | IFEO
---------- | Mountpoints2
---------- | Windows
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows]
"MouseSpeed"=#USR:Control Panel\Mouse
"MouseThreshold1"=#USR:Control Panel\Mouse
"MouseThreshold2"=#USR:Control Panel\Mouse
"SwapMouseButtons"=#USR:Control Panel\Mouse
"Beep"=#USR:Control Panel\Sound
"DoubleClickSpeed"=#USR:Control Panel\Mouse
"CoolSwitch"=USR:Control Panel\Desktop
"DoubleClickHeight"=#USR:Control Panel\Mouse
"DoubleClickWidth"=#USR:Control Panel\Mouse
"DragFullWindows"=USR:Control Panel\Desktop
"InitialKeyboardIndicators"=USR:Control Panel\Keyboard
"LowPowerActive"=#USR:Control Panel\Desktop
"LowPowerTimeOut"=#USR:Control Panel\Desktop
"PowerOffActive"=#USR:Control Panel\Desktop
"PowerOffTimeOut"=#USR:Control Panel\Desktop
"ScreenSaveActive"=#USR:Control Panel\Desktop
"ScreenSaveTimeOut"=#USR:Control Panel\Desktop
"SnapToDefaultButton"=#USR:Control Panel\Mouse
""=USR:Software\Microsoft\Windows NT\CurrentVersion\Windows
"Spooler"=#SYS:Microsoft\Windows NT\CurrentVersion\Windows
"TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS
"DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW
"APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS
"DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS
"SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot]
""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot
"ScreenSaverActive"=USR:Control Panel\Desktop
"ScreenSaverIsSecure"=USR:Control Panel\Desktop
"SCRNSAVE.EXE"=USR:Control Panel\Desktop
"Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows]
"MouseSpeed"=#USR:Control Panel\Mouse
"MouseThreshold1"=#USR:Control Panel\Mouse
"MouseThreshold2"=#USR:Control Panel\Mouse
"SwapMouseButtons"=#USR:Control Panel\Mouse
"Beep"=#USR:Control Panel\Sound
"DoubleClickSpeed"=#USR:Control Panel\Mouse
"CoolSwitch"=USR:Control Panel\Desktop
"DoubleClickHeight"=#USR:Control Panel\Mouse
"DoubleClickWidth"=#USR:Control Panel\Mouse
"DragFullWindows"=USR:Control Panel\Desktop
"InitialKeyboardIndicators"=USR:Control Panel\Keyboard
"LowPowerActive"=#USR:Control Panel\Desktop
"LowPowerTimeOut"=#USR:Control Panel\Desktop
"PowerOffActive"=#USR:Control Panel\Desktop
"PowerOffTimeOut"=#USR:Control Panel\Desktop
"ScreenSaveActive"=#USR:Control Panel\Desktop
"ScreenSaveTimeOut"=#USR:Control Panel\Desktop
"SnapToDefaultButton"=#USR:Control Panel\Mouse
"TRANSMISSIONRETRYTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS
"DEFAULTSEPARATEVDM"=\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\CONTROL\\WOW
"APPINIT_DLLS"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS
"DEVICENOTSELECTEDTIMEOUT"=#SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS
"SWAPDISK"=SYS:MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\WINDOWS
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot]
""=SYS:Microsoft\Windows NT\CurrentVersion\WOW\boot
"ScreenSaverActive"=USR:Control Panel\Desktop
"ScreenSaverIsSecure"=USR:Control Panel\Desktop
"SCRNSAVE.EXE"=USR:Control Panel\Desktop
"Shell"=SYS:Microsoft\Windows NT\CurrentVersion\Winlogon
[HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems]
"windows"=%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
---------- | Security center
[HKLM\SOFTWARE\Microsoft\Security Center]
"cval"=1
[HKLM\SOFTWARE\Microsoft\Security Center\svc]
"VistaSp1"=128920218544262440
"AntiVirusOverride"=0
"AntiSpywareOverride"=0
"FirewallOverride"=0
[HKLM\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=0
"DisableRoutinelyTakingAction"=0
"ProductStatus"=0
"InstallTime"=0xC13BA4F84A8FCC01
[HKLM\Software\WOW6432Node\Microsoft\Windows Defender]
"DisableAntiSpyware"=0
"DisableRoutinelyTakingAction"=1
[HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall"=1
[HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=1
[HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall"=1
---------- | Safeboot
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\87566282.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vga.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\87566282.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppInfo]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BFE]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\bowser]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dfsc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dot3Svc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Eaphost]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EFS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\IKEEXT]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\KeyIso]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSDrv]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MPSSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb10]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mrxsmb20]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NativeWifiP]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ndiscap]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\netprofm]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NlaSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nsi]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nsiproxy.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NTDS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PolicyAgent]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Power]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ProfSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdbss]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpencdd.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcEptMapper]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sacsvr]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCardSvr]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SWPRV]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TabletInputService]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TBS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TrustedInstaller]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VaultSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDS]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vga.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vgasave.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vmms]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgr.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\volmgrx.sys]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinDefend]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wlansvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfPf]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfRd]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfSvc]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WudfUsbccidDriver]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
---------- | Winsock (Whitelist)
---------- | Hosts
#
#
#
#
#
127.0.0.1 localhost
::1 localhost
---------- | Ping
Ping request could not find host google.com. Please check the name and try again.
---------- | @
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Internet Explorer\Main]
"Disable Script Debugger"=yes
"Anchor Underline"=yes
"Cache_Update_Frequency"=Once_Per_Session
"Display Inline Images"=yes
"Do404Search"=0x01000000
"Local Page"=C:\windows\system32\blank.htm
"Save_Session_History_On_Exit"=no
"Show_FullURL"=no
"Show_StatusBar"=yes
"Show_ToolBar"=yes
"Show_URLinStatusBar"=yes
"Show_URLToolBar"=yes
"Use_DlgBox_Colors"=yes
"Search Page"=
http://go.microsoft.com/fwlink/?LinkId=54896
"XMLHTTP"=1
"NoUpdateCheck"=1
"DisableScriptDebuggerIE"=yes
"UseClearType"=no
"Enable Browser Extensions"=yes
"Play_Background_Sounds"=yes
"Play_Animations"=yes
"Default_Page_URL"=
http://go.microsoft.com/fwlink/?LinkId=69157
"DisableFirstRunCustomize"=1
"SearchDefaultBranded"=1
"CompatibilityFlags"=0
"FullScreen"=no
"Window_Placement"=0x2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC8000000320000001D04000082020000
"IconCache"=o3f9fvg
"Use FormSuggest"=yes
"DownloadWindowPlacement"=0x2C0000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3B01000055000000BB03000035020000
"Use Search Asst"=no
"SSLTLSTokens"=0x010000001C000000716E5438394C4763396545736E4A76566633617A6B6E746A4B76673D000000000000000000000000
"AllowWindowReuse"=0
"Isolation"=PMIL
"Start Page"=
http://www.google.com
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Internet settings]
"IE5_UA_Backup_Flag"=5.0
"User Agent"=Mozilla/4.0 (compatible; MSIE 8.0; Win32)
"EmailName"=User@
"PrivDiscUiShown"=1
"EnableHttp1_1"=1
"WarnOnIntranet"=1
"MimeExclusionListForCache"=multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
"AutoConfigProxy"=wininet.dll
"UseSchannelDirectly"=0x01000000
"WarnOnPost"=0x01000000
"UrlEncoding"=0
"SecureProtocols"=160
"PrivacyAdvanced"=0
"ZonesSecurityUpgrade"=0xC27F1CA508C4CC01
"DisableCachingOfSSLPages"=0
"WarnonZoneCrossing"=0
"CertificateRevocation"=1
"EnableNegotiate"=1
"MigrateProxy"=1
"ProxyEnable"=0
"ReceiveTimeout"=10000
"GlobalUserOffline"=0
[HKLM\Software\Microsoft\Internet Explorer\Main]
"AutoHide"=yes
"Security Risk Page"=about:SecurityRisk
"Extensions Off Page"=about:NoAdd-ons
"Default_Search_URL"=
http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Page_URL"=
http://go.microsoft.com/fwlink/?LinkId=69157
"Anchor_Visitation_Horizon"=0x01000000
"Cache_Percent_of_Disk"=0x0A000000
"Placeholder_Width"=0x1A000000
"Placeholder_Height"=0x1A000000
"Default_Secondary_Page_URL"=
"Use_Async_DNS"=yes
"Start Page"=
http://go.microsoft.com/fwlink/?LinkId=69157
"Local Page"=C:\Windows\System32\blank.htm
"Search Page"=
http://go.microsoft.com/fwlink/?LinkId=54896
"Delete_Temp_Files_On_Exit"=yes
"Enable_Disk_Cache"=yes
"Check_Associations"=yes
"TabProcGrowth"=Medium
"Print_Background"=0
"AlwaysShowMenus"=0
"StatusBarWeb"=1
[HKLM\Software\Microsoft\Internet Explorer\AboutURLs]
"blank"=res://mshtml.dll/blank.htm
"NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm
"InPrivate"=res://ieframe.dll/inprivate.htm
"NavigationFailure"=res://ieframe.dll/navcancl.htm
"NoAdd-ons"=res://ieframe.dll/noaddon.htm
"Home"=270
"PostNotCached"=res://ieframe.dll/repost.htm
"DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm
"NavigationCanceled"=res://ieframe.dll/navcancl.htm
"OfflineInformation"=res://ieframe.dll/offcancl.htm
"SecurityRisk"=res://ieframe.dll/securityatrisk.htm
[HKLM\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
[HKLM\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes]
"mosaic"=http://
"www"=http://
"home"=http://
"ftp"=ftp://
"gopher"=gopher://
[HKLM\Software\Microsoft\Windows\CurrentVersion\Internet settings]
"EnablePunycode"=1
"CodeBaseSearchPath"=CODEBASE
"WarnOnIntranet"=1
"MinorVersion"=0
"ActiveXCache"=C:\Windows\Downloaded Program Files
[HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Main]
"AutoHide"=yes
"Security Risk Page"=about:SecurityRisk
"Extensions Off Page"=about:NoAdd-ons
"Default_Search_URL"=
http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Page_URL"=
http://go.microsoft.com/fwlink/?LinkId=69157
"Anchor_Visitation_Horizon"=0x01000000
"Cache_Percent_of_Disk"=0x0A000000
"Placeholder_Width"=0x1A000000
"Placeholder_Height"=0x1A000000
"Default_Secondary_Page_URL"=
"Use_Async_DNS"=yes
"Start Page"=
http://go.microsoft.com/fwlink/?LinkId=69157
"Local Page"=C:\Windows\SysWOW64\blank.htm
"Search Page"=
http://go.microsoft.com/fwlink/?LinkId=54896
"Delete_Temp_Files_On_Exit"=yes
"Enable_Disk_Cache"=yes
"TabProcGrowth"=Medium
"Print_Background"=0
"AlwaysShowMenus"=0
"StatusBarWeb"=1
"Enable Browser Extensions"=yes
"Use Search Asst"=no
[HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\AboutURLs]
"blank"=res://mshtml.dll/blank.htm
"NoAdd-onsInfo"=res://ieframe.dll/noaddoninfo.htm
"InPrivate"=res://ieframe.dll/inprivate.htm
"NavigationFailure"=res://ieframe.dll/navcancl.htm
"NoAdd-ons"=res://ieframe.dll/noaddon.htm
"Home"=270
"PostNotCached"=res://ieframe.dll/repost.htm
"DesktopItemNavigationFailure"=res://ieframe.dll/navcancl.htm
"NavigationCanceled"=res://ieframe.dll/navcancl.htm
"OfflineInformation"=res://ieframe.dll/offcancl.htm
"SecurityRisk"=res://ieframe.dll/securityatrisk.htm
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\URL\Prefixes]
"mosaic"=http://
"www"=http://
"home"=http://
"ftp"=ftp://
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet settings]
"EnablePunycode"=1
"CodeBaseSearchPath"=CODEBASE
"WarnOnIntranet"=1
"MinorVersion"=0
"ActiveXCache"=C:\Windows\Downloaded Program Files
---------- | reparsepoint
---------- | Detection of offsets
---------- | Notify
---------- | Execution FileExts
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi]
"DivX.AAR.backup"=Windows Media Player
"Progid"=divx_avi_file
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.div]
"Progid"=divx_div_file
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.divx]
"Progid"=divx_divx_file
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv]
"Progid"=divx_mkv_file
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qt]
"Progid"=divx_qt_file
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tix]
"Progid"=divx_tix_file
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vob]
"Progid"=divx_vob_file
---------- | SIOI | SEH | URLSH
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast] - {472083B0-C522-11CF-8763-00608CC02F24} -- C:\Program Files\AVAST Software\Avast\ashShA64.dll [19/07/2016 18:28:45]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} -- %SystemRoot%\system32\EhStorShell.dll
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235} -- %SystemRoot%\system32\ntshrui.dll
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} -- %SystemRoot%\system32\EhStorShell.dll
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235} -- %SystemRoot%\system32\ntshrui.dll
---------- | Toolbar
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"Locked"=0
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"ITBar7Layout"=0x13000000000000000000000030000000100006003A00000001000000800600005E010000080000008100000000000000070000008100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000006458B9555132E945BB301A82589AAFF173BF90CDF620EF44993DBB920303BD2E000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
"ITBar7Height"=0
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"Version"=1
"KnownProvidersUpgradeTime"=0x778451D408C4CC01
"DownloadRetries"=0
"ShowSearchSuggestionsInAddressGlobal"=1
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"Locked"=0
[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Toolbar]
"Locked"=0
[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
---------- | Extensions
[HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extensions\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}] : (@C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003) - []
---------- | SearchScopes
---------- | Browser Helper Objects
---------- | Chrome
C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo = : Google & co -
http://www.youtube.com -
http://www.youtube.com/ - Google & co -
http://clients2.google.com/service/update2/crx
C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\extensions\coobgpohoikkiipiblmjeljniedjpjpf = : Google & co -
http://www.google.com/webhp?source=search_app - Google & co - [*://
www.google.com/search*://www.google.com/webhp*://www.google.com/imgres] -
http://clients2.google.com/service/update2/crx
C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\extensions\ekdjfcdinekpfcedakhpngcnaamhiihn = : Bflix browser extension - TheBflix
C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\extensions\nneajnkjbffgblleaoojgaacokifdkhm = : __MSG_extdesc__ - __MSG_extname__
C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\extensions\pjkljhegncpnkpknbcohdijeoejaedia = : Google & co -
https://mail.google.com/mail/ca - Google & co - [*://mail.google.com/mail/ca] -
http://clients2.google.com/service/update2/crx
C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\extensions\cfhdojbkjhnklbpkdaibdccddilifddb = : __MSG_description__ - short_name: __MSG_name__ -
https://clients2.google.com/service/update2/crx
C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\extensions\gomekmidlodglbbmalcneegieacbdmki = : Avast Browser Security and Web Reputation Plugin. - Avast Online Security - matches:[\u003Call_urls>] -
https://clients2.google.com/service/update2/crx
C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\extensions\nlgfkngkdcjlfgcfdmjoafonkkhacilj = : The free Chrome companion to OpenOffice - short_name: OpenOffice for Chrome -
https://clients2.google.com/service/update2/crx
C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\extensions\nmmhkkegccagdldgiimedpiccmgmieda = : Google & co - Google & co - 203784468217.apps.googleusercontent.com -
https://clients2.google.com/service/update2/crx
C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\extensions\nneajnkjbffgblleaoojgaacokifdkhm = : __MSG_extdesc__ - __MSG_extname__
C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm = : Provider for discovery and services for mirroring of Chrome Media Router - Chrome Media Router - 919648714761-55j965o0km033psv3i9qls5mo3qtdrb0.apps.googleusercontent.com -
https://clients2.google.com/service/update2/crx
[HKLM\Software\WOW6432Node\Google\Chrome\Extensions\nneajnkjbffgblleaoojgaacokifdkhm]
---------- | Opera
---------- | Firefox
[HKLM\Software\WOW6432Node\mozilla\Firefox\Extensions]
"{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"=C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
[HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer] - (Adobe® Flash® Player 18.0.0.232 Plugin) : C:\windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll
[HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0] - (DivX VOD Helper Plug-in) : C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
[HKLM\Software\WOW6432Node\MozillaPlugins\@adobe.com/FlashPlayer] - (Adobe® Flash® Player 18.0.0.232 Plugin) : C:\windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll
[HKLM\Software\WOW6432Node\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0] - (DivX Plus Web Player) : C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
[HKLM\Software\WOW6432Node\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0] - (DivX VOD Helper Plug-in) : C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
[HKLM\Software\WOW6432Node\MozillaPlugins\@java.com/JavaPlugin] - (Oracle® Next Generation Java™ Plug-In) : C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
[HKLM\Software\WOW6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] - (Ag Player Plugin) : c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
[HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] - (Microsoft SharePoint Plug-in for Firefox) : C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
[HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922] - (WLPG Install MIME type) : C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKLM\Software\WOW6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513] - (WLPG Install MIME type) : C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKLM\Software\WOW6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3] - (Google Update) : C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll
[HKLM\Software\WOW6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9] - (Google Update) : C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll
[HKLM\Software\WOW6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0] - (WildTangent Games App Presence Detector Plugin) : C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
---------- | DNS
---------- | Applications
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Classes\Applications\FreeTorrentViewer.exe] : "C:\Program Files (x86)\FreeTorrentViewer\FreeTorrentViewer.exe" "%1"
[HKLM\SOFTWARE\Classes\Applications\ehshell.exe] : "C:\Windows\eHome\ehshell.exe" "%1"
[HKLM\SOFTWARE\Classes\Applications\iexplore.exe] : "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1
[HKLM\SOFTWARE\Classes\Applications\MovieMaker.exe] : "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe" "%1"
[HKLM\SOFTWARE\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1
[HKLM\SOFTWARE\Classes\Applications\photoviewer.dll] : %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1
[HKLM\SOFTWARE\Classes\Applications\SZBrowser.exe] : "C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" "%1"
[HKLM\SOFTWARE\Classes\Applications\WLXPhotoViewer.dll] : "C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /LaunchPhotoViewer /v "%1"
[HKLM\SOFTWARE\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L"
[HKLM\SOFTWARE\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"
[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\ehshell.exe] : "C:\Windows\eHome\ehshell.exe" "%1"
[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\iexplore.exe] : "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1
[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\MovieMaker.exe] : "C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe" "%1"
[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\notepad.exe] : %SystemRoot%\system32\NOTEPAD.EXE %1
[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\photoviewer.dll] : %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1
[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\SZBrowser.exe] : "C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" "%1"
[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\WLXPhotoViewer.dll] : "C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /LaunchPhotoViewer /v "%1"
[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wmplayer.exe] : "%ProgramFiles(x86)%\Windows Media Player\wmplayer.exe" /Open "%L"
[HKLM\SOFTWARE\WOW6432Node\Classes\Applications\wordpad.exe] : "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"
---------- | SvcHost (Whitelist)
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost]
"regsvc"=RemoteRegistry
"DcomLaunch"=Power
PlugPlay
DcomLaunch
"secsvcs"=WinDefend
"bthsvcs"=bthserv
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost]
"DcomLaunch"=Power
PlugPlay
DcomLaunch
---------- | SvcHost - Netsvcs (Whitelist)
Term - :
---------- | Software
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\9-lab]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Adobe]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\AI_RecycleBin]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\AppDataLow]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\AVAST Software]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Blehjoqlir]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Caphyon]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Clients]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\DivX]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\DivXNetworks]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\g3n-h@ckm@n]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\GNU]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Google]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Intel]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\JavaSoft]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\KineticJump]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Macromedia]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\MCAFEE]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Mixi.DJ]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\MozillaPlugins]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\ORL]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Piriform]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Policies]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\QtProject]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\SimonTatham]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Stronghold Online Backup]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Strongvault]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Synaptics]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Sysinternals]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Tific]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\TightVNC]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Toshiba]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Trolltech]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\VB and VBA Program Settings]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Veoh]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\WebEx]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Wow6432Node]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\ZebHelpProcess Helper]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Zemana]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\ZHP]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\AppDataLow\Software\DivX]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\AppDataLow\Software\Microsoft]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\AppDataLow\Software\Yahoo]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\DWM]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\Shell]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\TabletPC]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\Windows Error Reporting]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows NT\CurrentVersion]
[HKLM\Software\ATI Technologies]
[HKLM\Software\CBSTEST]
[HKLM\Software\Clients]
[HKLM\Software\Cnxt_Uiu_Parms]
[HKLM\Software\Conexant]
[HKLM\Software\CXT]
[HKLM\Software\Cyberlink]
[HKLM\Software\DivX]
[HKLM\Software\ESET]
[HKLM\Software\g3n-h@ckm@n]
[HKLM\Software\InstalledOptions]
[HKLM\Software\Intel]
[HKLM\Software\IntelVolatile]
[HKLM\Software\JL2005D]
[HKLM\Software\JL2005D_5]
[HKLM\Software\JL2005D_7]
[HKLM\Software\Macromedia]
[HKLM\Software\Microsoft]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\ODBC]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\Realtek]
[HKLM\Software\Realtek Semiconductor Corp.]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\REGSERVO]
[HKLM\Software\SOFTWARE]
[HKLM\Software\Sonic]
[HKLM\Software\Synaptics]
[HKLM\Software\sysinternals]
[HKLM\Software\Toshiba]
[HKLM\Software\TOSHIBA Corporation]
[HKLM\Software\UIU]
[HKLM\Software\Waves Audio]
[HKLM\Software\Wow6432Node]
[HKLM\Software\Zemana]
[HKLM\Software\ZmnGlobalSDK]
[HKLM\Software\Microsoft\Windows\CurrentVersion]
[HKLM\Software\Microsoft\Windows\HTML Help]
[HKLM\Software\Microsoft\Windows\ITStorage]
[HKLM\Software\Microsoft\Windows\ScheduledDiagnostics]
[HKLM\Software\Microsoft\Windows\ScriptedDiagnosticsProvider]
[HKLM\Software\Microsoft\Windows\Tablet PC]
[HKLM\Software\Microsoft\Windows\TabletPC]
[HKLM\Software\Microsoft\Windows\Windows Error Reporting]
[HKLM\Software\Microsoft\Windows\Windows Search]
[HKLM\Software\Microsoft\Windows NT\CurrentVersion]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\AxInstSVGroup]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\defragsvc]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\SDRSVC]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\swprv]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wcssvc]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\wercplsupport]
[HKLM\Software\WOW6432Node\Adobe]
[HKLM\Software\WOW6432Node\AdobeFlashPlayerUpdate]
[HKLM\Software\WOW6432Node\Atheros Communications Inc.]
[HKLM\Software\WOW6432Node\AVAST Software]
[HKLM\Software\WOW6432Node\DivX]
[HKLM\Software\WOW6432Node\DivXNetworks]
[HKLM\Software\WOW6432Node\Eset]
[HKLM\Software\WOW6432Node\Giraffic]
[HKLM\Software\WOW6432Node\GNU]
[HKLM\Software\WOW6432Node\Google]
[HKLM\Software\WOW6432Node\HaaliMkx]
[HKLM\Software\WOW6432Node\Hyperlync]
[HKLM\Software\WOW6432Node\InstallShield]
[HKLM\Software\WOW6432Node\Intel]
[HKLM\Software\WOW6432Node\JavaSoft]
[HKLM\Software\WOW6432Node\JL2005D]
[HKLM\Software\WOW6432Node\JL2005D_5]
[HKLM\Software\WOW6432Node\JL2005D_7]
[HKLM\Software\WOW6432Node\JL6_DECODE]
[HKLM\Software\WOW6432Node\Licenses]
[HKLM\Software\WOW6432Node\Macromedia]
[HKLM\Software\WOW6432Node\Malwarebytes' Anti-Malware]
[HKLM\Software\WOW6432Node\Microsoft]
[HKLM\Software\WOW6432Node\MimarSinan]
[HKLM\Software\WOW6432Node\Mozilla]
[HKLM\Software\WOW6432Node\MozillaPlugins]
[HKLM\Software\WOW6432Node\Norton]
[HKLM\Software\WOW6432Node\Norton PC Checkup]
[HKLM\Software\WOW6432Node\NPCCU]
[HKLM\Software\WOW6432Node\ODBC]
[HKLM\Software\WOW6432Node\PCTools]
[HKLM\Software\WOW6432Node\Piriform]
[HKLM\Software\WOW6432Node\REALTEK Semiconductor Corp.]
[HKLM\Software\WOW6432Node\SOS]
[HKLM\Software\WOW6432Node\Symantec]
[HKLM\Software\WOW6432Node\Tific]
[HKLM\Software\WOW6432Node\TightVNC]
[HKLM\Software\WOW6432Node\TOSHIBA]
[HKLM\Software\WOW6432Node\TOSHIBA CORPORATION]
[HKLM\Software\WOW6432Node\Ulead Systems]
[HKLM\Software\WOW6432Node\WildTangent]
[HKLM\Software\WOW6432Node\Clients]
[HKLM\Software\WOW6432Node\Policies]
[HKLM\Software\WOW6432Node\RegisteredApplications]
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion]
[HKLM\Software\WOW6432Node\Microsoft\Windows\HTML Help]
[HKLM\Software\WOW6432Node\Microsoft\Windows\ITStorage]
[HKLM\Software\WOW6432Node\Microsoft\Windows\ScriptedDiagnosticsProvider]
[HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Error Reporting]
[HKLM\Software\WOW6432Node\Microsoft\Windows\Windows Search]
[HKLM\Software\WOW6432Node\Microsoft\Windows\Tablet PC]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceAndNoImpersonation]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNetworkRestricted]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalServiceNoNetwork]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalSystemNetworkRestricted]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkService]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopHyperVAgent]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\NetworkServiceRemoteDesktopPublishing]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs]
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\wcssvc]
---------- | Drives
E:
[18/04/2017 16:25:08] - |N| - (.© 2005-2017 Blizzard Entertainment Inc. - StarCraft Launcher.) - [3205616] - (1.0.0.2716) - E:\StarCraft-Setup.exe
[19/04/2017 11:00:56] - |N| - (.Copyright (C) 2013-2017 SosVirus Software - QuickDiag.) - [2776488] - (2.4.17.1) - E:\quickdiag_3_02.04.17.1.exe
[19/04/2017 11:00:59] - |N| - (.-.) - [26286152] - (12.10.5.0) - E:\RogueKillerX64.exe
[15/04/2017 19:57:22] - |N| - (.Malwarebytes - AdwCleaner is a free Adware/PUP removal tool..) - [4089296] - (6.0.4.5) - E:\AdwCleaner.exe
[15/04/2017 19:57:24] - |N| - (.sUBs - ComboFix NSIS Installer.) - [5659546] - (17.4.5.1) - E:\ComboFix.exe
[15/04/2017 19:57:29] - |N| - (.©1999-2015 Jonathan Bennett & AutoIt Team - Farbar Recovery Scan Tool.) - [1766912] - (15.3.2017.0) - E:\FRST.exe
[15/04/2017 19:57:31] - |N| - (.©1999-2015 Jonathan Bennett & AutoIt Team - Farbar Recovery Scan Tool.) - [2424832] - (15.3.2017.0) - E:\FRST64.exe
[15/04/2017 19:57:35] - |N| - (.- Junkware Removal Tool.) - [1663672] - (8.1.3.0) - E:\JRT.exe
[15/04/2017 19:57:36] - |N| - (.© BleepingComputer.com. - Terminates malware processes so that you can run your normal security programs..) - [2030536] - (2.8.4.0) - E:\rkill.exe
[15/04/2017 19:57:36] - |N| - (.© 1997-2017 AO Kaspersky Lab. - TDSS rootkit removing tool.) - [4922400] - (3.1.0.15) - E:\tdsskiller.exe
[15/04/2017 19:57:37] - |N| - (.Nicolas Coolman - ZHPCleane.) - [2760704] - (2017.4.12.64) - E:\ZHPCleaner.exe
[15/04/2017 19:57:39] - |N| - (.Nicolas Coolman - ZHPDiag.) - [2717696] - (2017.4.11.63) - E:\ZHPDiag3.exe
[15/04/2017 19:59:26] - |N| - (.Copyright (c) 2010 AVAST Software. - avast! Antirootkit.) - [5198336] - (1.0.1.2252) - E:\aswMBR.exe
[15/04/2017 19:59:50] - |N| - (.Copyright (C) 2002-2017 Mark Russinovich - Autostart program viewer.) - [716456] - (13.70.0.0) - E:\Autoruns.exe
[15/04/2017 19:59:50] - |N| - (.Copyright (C) 2002-2017 Mark Russinovich - Autostart program viewer.) - [844464] - (13.70.0.0) - E:\Autoruns64.exe
[15/04/2017 19:59:50] - |N| - (.Copyright (C) 2002-2017 Mark Russinovich - Autostart program viewer.) - [629928] - (13.70.0.0) - E:\autorunsc.exe
[15/04/2017 19:59:50] - |N| - (.Copyright (C) 2002-2017 Mark Russinovich - Autostart program viewer.) - [743088] - (13.70.0.0) - E:\autorunsc64.exe
[16/04/2017 12:41:27] - |N| - (.© Copyright 2017 - Advanced Malware Protection .) - [5774688] - (2.72.0.388) - E:\Zemana.AntiMalware.Setup.exe
[16/04/2017 12:41:31] - |N| - (.Copyright © 2015 - Destroy Windows 10 Spying Rollup Edition.) - [294400] - (1.6.722.0) - E:\DWS_Lite.exe
[16/04/2017 12:41:33] - |N| - (.2005-2017 COMODO. - COMODO Internet Security.) - [5363680] - (10.0.1.6209) - E:\cfw_installer.exe
[16/04/2017 12:41:35] - |N| - (.Copyright (c) 2014 AVAST Software - Avast Antivirus Installer.) - [298459488] - (17.4.3450.0) - E:\avast_free_antivirus_setup_offline.exe
F:
[12/02/2007 18:33:37] - |R| - (.-.) - [1110016] - (1.4.0.7) - F:\LaunchU3.exe
[12/02/2007 12:53:42] - |R| - (.-.) - [277] - (0.0.0.0) - F:\autorun.inf
---------- | C:
[09/09/2015 09:03:18] - |SHD| - [129] - C:\$RECYCLE.BIN
[08/09/2015 10:26:24] - |D| - [6280261] - C:\AdwCleaner
[01/08/2011 16:33:07] - |SHD| - [14594356] - C:\Boot
[MD5.259525CFB422E6AC8E87BC9777B1DF73] - [01/08/2011 16:33:08] - |RASH| - (.-.) - [383786] - (0.0.0.0) - C:\bootmgr
[MD5.25D84C10EB6F8103365CEBA15E4FC10C] - [01/08/2011 16:33:10] - |RASH| - (.-.) - [8192] - (0.0.0.0) - C:\BOOTSECT.BAK
[05/03/2012 17:06:38] - |D| - [7376] - C:\codec-info
[12/02/2014 17:33:25] - |D| - [0] - C:\components
[13/07/2009 22:08:56] - |SHD| - [0] - C:\Documents and Settings
[MD5.9147A93F43D8E58218EBCB15FDA888C9] - [07/11/2007 09:00:40] - |A| - (.-.) - [17734] - (0.0.0.0) - C:\eula.1028.txt
[MD5.9147A93F43D8E58218EBCB15FDA888C9] - [07/11/2007 09:00:40] - |A| - (.-.) - [17734] - (0.0.0.0) - C:\eula.1031.txt
[MD5.99C22D4A31F4EAD4351B71D6F4E5F6A1] - [07/11/2007 09:00:40] - |A| - (.-.) - [10134] - (0.0.0.0) - C:\eula.1033.txt
[MD5.9147A93F43D8E58218EBCB15FDA888C9] - [07/11/2007 09:00:40] - |A| - (.-.) - [17734] - (0.0.0.0) - C:\eula.1036.txt
[MD5.9147A93F43D8E58218EBCB15FDA888C9] - [07/11/2007 09:00:40] - |A| - (.-.) - [17734] - (0.0.0.0) - C:\eula.1040.txt
[MD5.9B15A3A055CC6E67EA191A1B7885649A] - [07/11/2007 09:00:40] - |A| - (.-.) - [118] - (0.0.0.0) - C:\eula.1041.txt
[MD5.9147A93F43D8E58218EBCB15FDA888C9] - [07/11/2007 09:00:40] - |A| - (.-.) - [17734] - (0.0.0.0) - C:\eula.1042.txt
[MD5.9147A93F43D8E58218EBCB15FDA888C9] - [07/11/2007 09:00:40] - |A| - (.-.) - [17734] - (0.0.0.0) - C:\eula.2052.txt
[MD5.9147A93F43D8E58218EBCB15FDA888C9] - [07/11/2007 09:00:40] - |A| - (.-.) - [17734] - (0.0.0.0) - C:\eula.3082.txt
[MD5.EDE06CD4D95178D6A2DEF6B60BD267F4] - [08/09/2015 19:06:15] - |A| - (.-.) - [42] - (0.0.0.0) - C:\folders.log
[08/09/2015 12:07:03] - |D| - [172037122] - C:\FRST
[MD5.E7832D67AD190A920970CB5ADFC6D5D1] - [06/07/2015 00:59:04] - |A| - (.-.) - [383] - (0.0.0.0) - C:\ftconfig.ini
[MD5.0A6B586FABD072BD7382B5E24194EAC7] - [07/11/2007 09:00:40] - |A| - (.-.) - [1110] - (0.0.0.0) - C:\globdata.ini
[MD5.D41D8CD98F00B204E9800998ECF8427E] - [20/10/2011 10:01:22] - |ASH| - (.-.) - [3180220416] - (0.0.0.0) - C:\hiberfil.sys
[MD5.520A6D1CBCC9CF642C625FE814C93C58] - [07/11/2007 09:03:18] - |A| - (.© Microsoft Corporation. - External Installer.) - [562688] - (9.0.21022.8) - C:\install.exe
[MD5.0DA9AB4977F3E7BA8C65734DF42FDAB6] - [07/11/2007 09:00:40] - |A| - (.-.) - [843] - (0.0.0.0) - C:\install.ini
[MD5.4151A4D07640863783F837E588235837] - [07/11/2007 09:03:18] - |A| - (.(C) Microsoft Corporation. - UI Wrapper Resource DLL.) - [76304] - (9.0.21022.8) - C:\install.res.1028.dll
[MD5.3B8A82E04238655EAEF97E074FB29911] - [07/11/2007 09:03:18] - |A| - (.© Microsoft Corporation. Alle Rechte vorbehalten. - Ressourcen-DLL für UI-Wrapper.) - [96272] - (9.0.21022.8) - C:\install.res.1031.dll
[MD5.9EDEB8B1C5C0A4CD3A3016B85108127D] - [07/11/2007 09:03:18] - |A| - (.© Microsoft Corporation. - UI Wrapper Resource DLL.) - [91152] - (9.0.21022.8) - C:\install.res.1033.dll
[MD5.5B6FF470CFA7087690E61F87E81EF78A] - [07/11/2007 09:03:18] - |A| - (.© Microsoft Corporation. Tous droits réservés. - UI Wrapper Resource DLL.) - [97296] - (9.0.21022.8) - C:\install.res.1036.dll
[MD5.6310AB8FC9E3DBEE80592FC453A34FEE] - [07/11/2007 09:03:18] - |A| - (.© Microsoft Corporation. Tutti i diritti riservati. - DLL di risorse del wrapper dell'interfaccia utente.) - [95248] - (9.0.21022.8) - C:\install.res.1040.dll
[MD5.13ED4517152203DE4BC52ACC0255D952] - [07/11/2007 09:03:18] - |A| - (.(C) Copyright Microsoft Corporation. - UI Wrapper Resource DLL.) - [81424] - (9.0.21022.8) - C:\install.res.1041.dll
[MD5.0D4FB4095EA49C1EC89B9E8DB0B936A3] - [07/11/2007 09:03:18] - |A| - (.(C) Microsoft Corporation. - UI 래퍼 리소스 DLL.) - [79888] - (9.0.21022.8) - C:\install.res.1042.dll
[MD5.D7366B34E8AFB605C39EF56E2201FE85] - [07/11/2007 09:03:18] - |A| - (.(C) Microsoft Corporation。保留所有权利。 - 用户界面包装资源 DLL.) - [75792] - (9.0.21022.8) - C:\install.res.2052.dll
[MD5.41BB37A347121F3E5E88D85100638B79] - [07/11/2007 09:03:18] - |A| - (.© Microsoft Corporation. Reservados todos los derechos. - Archivo DLL de recursos del contenedor de la interfaz de usuario.) - [96272] - (9.0.21022.8) - C:\install.res.3082.dll
[20/10/2011 10:08:24] - |D| - [0] - C:\Intel
[26/12/2011 13:29:10] - |RHD| - [51376] - C:\MSOCache
[MD5.D41D8CD98F00B204E9800998ECF8427E] - [20/10/2011 10:01:22] - |ASH| - (.-.) - [4240293888] - (0.0.0.0) - C:\pagefile.sys
[13/07/2009 20:20:08] - |RD| - [3620391207] - C:\Program Files
[13/07/2009 20:20:08] - |RD| - [2821275980] - C:\Program Files (x86)
[13/07/2009 20:20:08] - |HD| - [5932317728] - C:\ProgramData
[19/04/2017 16:49:02] - |D| - [262056] - C:\QuickDiag
[MD5.175ACC4E1CE86A21323F958ACADC63EA] - [19/04/2017 16:49:23] - |A| - (.-.) - [109335] - (0.0.0.0) - C:\QuickDiag.txt
[MD5.DE48895209CD1788ED6A868E36810AE1] - [08/09/2015 18:56:30] - |A| - (.-.) - [3010] - (0.0.0.0) - C:\runcheck.txt
[MD5.F35AAA221EB79BB2F220BCBB354A95A0] - [16/02/2012 08:37:48] - |A| - (.-.) - [510] - (0.0.0.0) - C:\settings.ini
[07/08/2011 05:12:28] - |SHD| - [0] - C:\System Volume Information
[MD5.B0C34B7D3814F5960D5F287F1B6F99B2] - [15/04/2017 20:27:08] - |A| - (.-.) - [5156] - (0.0.0.0) - C:\TDSSKiller.3.1.0.12_15.04.2017_20.27.08_log.txt
[MD5.EE15621FF5868EEF8F5996241E0999CD] - [15/04/2017 20:29:05] - |A| - (.-.) - [662380] - (0.0.0.0) - C:\TDSSKiller.3.1.0.12_15.04.2017_20.29.05_log.txt
[13/07/2009 20:20:08] - |RD| - [12703902262] - C:\Users
[MD5.06FBA95313F26E300917C6CEA4480890] - [07/11/2007 09:00:40] - |A| - (.-.) - [5686] - (0.0.0.0) - C:\vcredist.bmp
[MD5.E10F2F6E6379E9185F71AEC1421F37B4] - [07/11/2007 09:09:22] - |A| - (.-.) - [1442522] - (0.0.0.0) - C:\VC_RED.cab
[MD5.E0951D3CB1038EB2D2B2B2F336E1AB32] - [07/11/2007 09:12:28] - |A| - (.-.) - [232960] - (0.0.0.0) - C:\VC_RED.MSI
[13/07/2009 20:20:08] - |AD| - [17821766236] - C:\Windows
[09/09/2015 08:23:11] - |D| - [129] - C:\zoek
[MD5.5D100859987E944A435D0FDE6470B9E0] - [08/09/2015 18:57:33] - |A| - (.-.) - [13972] - (0.0.0.0) - C:\zoek-results.log
[MD5.E2F9C6FEE8C7452E5C73A4451B06B93B] - [09/09/2015 08:14:02] - |A| - (.-.) - [14334] - (0.0.0.0) - C:\zoek-results2015-09-09-020615.log
[08/09/2015 18:56:12] - |D| - [0] - C:\zoek_backup
---------- | C:\windows
[13/07/2009 22:32:38] - |D| - [802] - C:\windows\addins
[13/07/2009 20:20:08] - |D| - [5866392] - C:\windows\AppCompat
[13/07/2009 20:20:08] - |D| - [10986720] - C:\windows\AppPatch
[13/07/2009 20:20:08] - |RSD| - [1354042456] - C:\windows\assembly
[MD5.7EFB1577EFBD72521E670188AA546C7D] - [19/07/2016 18:28:32] - |A| - (.Copyright (c) 2014 AVAST Software - avast! Screen Saver stub.) - [53208] - (12.1.3076.0) - C:\windows\avastSS.scr
[MD5.317CD1CE327B6520BF4EE007BCD39E61] - [20/11/2010 20:24:22] - |A| - (.© Microsoft Corporation. - Boot File Servicing Utility.) - [71168] - (6.1.7601.17514) - C:\windows\bfsvc.exe
[MD5.7FDE6771C64AC3B14FEE4997509D1735] - [01/08/2011 00:09:54] - |A| - (.-.) - [2359350] - (0.0.0.0) - C:\windows\Bluestream.bmp
[13/07/2009 20:20:09] - |D| - [29000590] - C:\windows\Boot
[MD5.5F37037B4BE454274C2ABD7F83D4D1AB] - [13/07/2009 22:38:36] - |AS| - (.-.) - [67584] - (0.0.0.0) - C:\windows\bootstat.dat
[13/07/2009 20:20:09] - |D| - [2418176] - C:\windows\Branding
[MD5.127F716BBD6C46421F08173D9BBD4724] - [01/08/2011 00:55:40] - |A| - (.-.) - [10] - (0.0.0.0) - C:\windows\csup.txt
[13/07/2009 20:20:09] - |D| - [2113488] - C:\windows\Cursors
[13/07/2009 21:45:54] - |D| - [14831063] - C:\windows\debug
[13/07/2009 22:32:38] - |D| - [3003724] - C:\windows\diagnostics
[13/07/2009 22:37:46] - |D| - [0] - C:\windows\DigitalLocker
[13/07/2009 22:32:38] - |D| - [65] - C:\windows\Downloaded Program Files
[21/11/2010 00:16:47] - |D| - [117959129] - C:\windows\ehome
[01/08/2011 00:36:57] - |D| - [106864] - C:\windows\en
[13/07/2009 22:37:46] - |D| - [110080] - C:\windows\en-US
[MD5.2A66E81AE941E54A237490FC35D387C8] - [26/01/2012 14:55:20] - |A| - (.-.) - [1945] - (0.0.0.0) - C:\windows\epplauncher.mif
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - [01/08/2011 00:22:16] - |A| - (.© Microsoft Corporation. - Windows Explorer.) - [2871808] - (6.1.7601.17567) - C:\windows\explorer.exe
[13/07/2009 20:20:09] - |RSD| - [354514815] - C:\windows\Fonts
[MD5.92BB2E9AA28542C685C59EFCBAC2490B] - [13/07/2009 16:22:13] - |A| - (.© Microsoft Corporation. - BitLocker Drive Encryption Servicing Utility.) - [15360] - (6.1.7600.16385) - C:\windows\fveupdate.exe
[13/07/2009 20:20:09] - |D| - [30247011] - C:\windows\Globalization
[13/07/2009 20:20:09] - |D| - [29929539] - C:\windows\Help
[MD5.CD47548A52B02D254BF6D7F7A5F2BFD3] - [13/07/2009 17:29:53] - |A| - (.© Microsoft Corporation. - Microsoft Help and Support.) - [733696] - (6.1.7600.16385) - C:\windows\HelpPane.exe
[MD5.3D0B9EA79BF1F828324447D84AA9DCE2] - [13/07/2009 17:29:03] - |A| - (.© Microsoft Corporation. - Microsoft® HTML Help Executable.) - [16896] - (6.1.7600.16385) - C:\windows\hh.exe
[MD5.1AEB4967A760D6EC21A3270F1B004AC1] - [21/11/2010 00:17:39] - |A| - (.-.) - [48265] - (0.0.0.0) - C:\windows\HomePremium.xml
[13/07/2009 20:20:09] - |D| - [143546732] - C:\windows\IME
[13/07/2009 20:20:10] - |D| - [75787446] - C:\windows\inf
[01/08/2011 00:10:06] - |SHD| - [1471684921] - C:\windows\Installer
[13/07/2009 20:20:10] - |D| - [48371] - C:\windows\L2Schemas
[13/07/2009 20:20:10] - |D| - [0] - C:\windows\LiveKernelReports
[13/07/2009 20:20:10] - |D| - [61435958] - C:\windows\Logs
[13/07/2009 20:20:10] - |RSD| - [13327133] - C:\windows\Media
[MD5.23AF90D2355D8C83AA4567EF1763B467] - [13/07/2009 17:10:29] - |A| - (.-.) - [43131] - (0.0.0.0) - C:\windows\mib.bin
[13/07/2009 20:20:10] - |D| - [713051405] - C:\windows\Microsoft.NET
[13/07/2009 20:20:10] - |D| - [0] - C:\windows\ModemLogs
[MD5.B9FB94A8DA62711C6955825DEFB25C5A] - [13/07/2009 19:35:42] - |A| - (.-.) - [1405] - (0.0.0.0) - C:\windows\msdfmap.ini
[01/08/2011 00:11:29] - |HD| - [0] - C:\windows\msdownld.tmp
[MD5.F2C7BB8ACC97F92E987A2D4087D021B1] - [13/07/2009 16:56:36] - |A| - (.© Microsoft Corporation. - Notepad.) - [193536] - (6.1.7600.16385) - C:\windows\notepad.exe
[13/07/2009 22:32:38] - |D| - [65] - C:\windows\Offline Web Pages
[01/08/2011 16:33:22] - |D| - [1511152] - C:\windows\Panther
[01/08/2011 00:34:48] - |D| - [0] - C:\windows\PCHEALTH
[13/07/2009 22:32:38] - |D| - [62090266] - C:\windows\Performance
[13/07/2009 20:20:10] - |D| - [1117380] - C:\windows\PLA
[13/07/2009 20:20:10] - |D| - [2185740] - C:\windows\PolicyDefinitions
[01/08/2011 00:03:11] - |D| - [42683980] - C:\windows\Prefetch
[MD5.2E2C937846A0B8789E5E91739284D17A] - [13/07/2009 16:27:10] - |A| - (.© Microsoft Corporation. - Registry Editor.) - [427008] - (6.1.7600.16385) - C:\windows\regedit.exe
[13/07/2009 20:20:10] - |D| - [22588] - C:\windows\registration
[13/07/2009 20:20:10] - |D| - [4734993] - C:\windows\rescache
[13/07/2009 20:20:10] - |D| - [1677002] - C:\windows\Resources
[13/07/2009 20:20:10] - |D| - [0] - C:\windows\SchCache
[13/07/2009 20:20:10] - |D| - [55533] - C:\windows\schemas
[13/07/2009 20:20:10] - |D| - [1056768] - C:\windows\security
[13/07/2009 21:45:47] - |D| - [37000059] - C:\windows\ServiceProfiles
[13/07/2009 20:20:10] - |D| - [36378692] - C:\windows\servicing
[13/07/2009 21:45:50] - |AD| - [15702] - C:\windows\Setup
[21/11/2010 00:16:47] - |D| - [4544] - C:\windows\ShellNew
[20/10/2011 10:09:09] - |D| - [102468379] - C:\windows\SoftwareDistribution
[13/07/2009 20:20:10] - |D| - [181014046] - C:\windows\Speech
[MD5.D01628AF9F7FB3F415B357D446FBE6D9] - [20/11/2010 20:24:16] - |A| - (.© Microsoft Corporation. - Print driver host for 32bit applications.) - [67072] - (6.1.7601.17514) - C:\windows\splwow64.exe
[MD5.9060C3C745E7B2D8E1A81DD061021546] - [13/07/2009 22:28:38] - |A| - (.-.) - [48201] - (0.0.0.0) - C:\windows\Starter.xml
[13/07/2009 20:20:10] - |D| - [0] - C:\windows\system
[MD5.286A9EDB379DC3423A528B0864A0F111] - [13/07/2009 19:34:57] - |A| - (.-.) - [219] - (0.0.0.0) - C:\windows\system.ini
[13/07/2009 20:20:10] - |AD| - [3222266207] - C:\windows\System32
[13/07/2009 20:20:14] - |D| - [1193758223] - C:\windows\SysWOW64
[13/07/2009 20:20:14] - |D| - [15] - C:\windows\TAPI
[13/07/2009 20:20:14] - |D| - [32634] - C:\windows\Tasks
[13/07/2009 20:20:14] - |D| - [270614] - C:\windows\Temp
[13/07/2009 20:20:14] - |D| - [0] - C:\windows\tracing
[MD5.0BEA3F79A36B1F67B2CE0F595524C77C] - [10/06/2009 14:41:17] - |A| - (.- Twain Source Manager (Image Acquisition Interface).) - [94784] - (1.7.0.0) - C:\windows\twain.dll
[13/07/2009 22:32:38] - |D| - [1724357] - C:\windows\twain_32
[MD5.163A95975E1D8819E653AA3E961371CA] - [20/11/2010 20:25:10] - |A| - (.- Twain_32 Source Manager (Image Acquisition Interface).) - [51200] - (1.7.1.3) - C:\windows\twain_32.dll
[MD5.F36A271706EDD23C94956AFB56981184] - [13/07/2009 15:47:26] - |A| - (.- Twain_32.dll Client's 16-Bit Thunking Server.) - [49680] - (1.7.0.0) - C:\windows\twunk_16.exe
[MD5.0BD6E68F3EA0DD62CD86283D86895381] - [13/07/2009 17:14:40] - |A| - (.- Twain.dll Client's 32-Bit Thunking Server.) - [31232] - (1.7.1.0) - C:\windows\twunk_32.exe
[13/07/2009 20:20:14] - |D| - [12420] - C:\windows\Vss
[13/07/2009 20:20:14] - |D| - [50738281] - C:\windows\Web
[MD5.162904DAA5412143F5403233E77F787E] - [13/07/2009 19:34:57] - |A| - (.-.) - [403] - (0.0.0.0) - C:\windows\win.ini
[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - [13/07/2009 21:54:24] - |RAH| - (.-.) - [749] - (0.0.0.0) - C:\windows\WindowsShell.Manifest
[MD5.C5E3EE1CA9A5E3E23F412F06EC1AB974] - [19/04/2017 16:49:21] - |A| - (.-.) - [3825] - (0.0.0.0) - C:\windows\WindowsUpdate.log
[MD5.1D420D66250BCAAAED05724FB34008CF] - [13/07/2009 17:12:29] - |A| - (.© Microsoft Corporation. - Windows Winhlp32 Stub.) - [9728] - (6.1.7600.16385) - C:\windows\winhlp32.exe
[13/07/2009 20:20:14] - |D| - [8436793729] - C:\windows\winsxs
[MD5.4D620865394151B96C54752B743D6D12] - [13/05/2011 15:42:24] - |A| - (.© 2010 Microsoft Corporation. - Windows Live Photos Screen Saver.) - [302448] - (15.4.3538.513) - C:\windows\WLXPGSS.SCR
[MD5.DC17DD0189B0C36D863B4DD0A036C10F] - [10/06/2009 13:52:44] - |A| - (.-.) - [316640] - (0.0.0.0) - C:\windows\WMSysPr9.prx
[MD5.F8ED3B4B209E2CB49028E36CF06CA851] - [13/07/2009 16:56:28] - |A| - (.© Microsoft Corporation. - Windows Write.) - [10240] - (6.1.7600.16385) - C:\windows\write.exe
[MD5.6E3603F3AE9B89E730DF9D9331C76613] - [27/11/2015 18:13:48] - |A| - (.-.) - [216313] - (0.0.0.0) - C:\windows\ZAM.krnl.trace
[MD5.9B0A1BAF95208D25093B2E0611224F54] - [27/11/2015 18:13:43] - |A| - (.-.) - [36708] - (0.0.0.0) - C:\windows\ZAM_Guard.krnl.trace
---------- | C:\windows\System32\GroupPolicy
[10/02/2014 17:29:39] - |D| - [0] - C:\windows\System32\GroupPolicy\User
---------- | Systemroot\System
---------- | Systemroot\Installer (Microsoft Files Whitelisted)
[12/04/2017 15:51:06] - C:\windows\Installer\102958.msi : (Google Update Helper - Google Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[01/08/2011 00:39:47] - C:\windows\Installer\10c67.msi : ( - K-NFB Reading Technology, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[01/08/2011 00:40:21] - C:\windows\Installer\10c6c.msi : (TOSHIBA ReelTime - TOSHIBA Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[15/11/2014 13:59:20] - C:\windows\Installer\13ada4.msi : (Google Update Helper - Google Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[20/10/2011 10:18:48] - C:\windows\Installer\18f09.msi : ( - Cisco Systems, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[20/10/2011 10:18:53] - C:\windows\Installer\18f0e.msi : ( - Cisco Systems, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[20/10/2011 10:18:55] - C:\windows\Installer\18f13.msi : ( - Cisco Systems, Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[13/06/2011 15:17:12] - C:\windows\Installer\18f21.msi : (Blank Project Template - TOSHIBA CORPORATION) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[23/02/2011 15:46:54] - C:\windows\Installer\18f28.msi : ( - Conexant Systems, Inc) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[20/10/2011 10:22:08] - C:\windows\Installer\18f2d.msi : (TOSHIBA Web Camera Application - TOSHIBA Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[20/10/2011 10:23:19] - C:\windows\Installer\18f37.msi : (TOSHIBA Face Recognition - TOSHIBA Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[28/06/2011 17:43:30] - C:\windows\Installer\18f3c.msi : (Blank Project Template - Macrovision Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[04/07/2011 23:58:24] - C:\windows\Installer\18f41.msi : (TOSHIBA PC Health Monitor - TOSHIBA Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[22/06/2011 14:31:42] - C:\windows\Installer\18f45.msi : (Toshiba Online Backup - Toshiba) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[23/09/2010 10:03:36] - C:\windows\Installer\18f4a.msi : (Toshiba App Place - Toshiba) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[20/10/2011 10:36:08] - C:\windows\Installer\18f5f.msi : (Google Toolbar for Internet Explorer - Google Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[01/08/2011 00:30:14] - C:\windows\Installer\1f3b4.msi : (Java(TM) SE Runtime Environment 6.0 - Oracle) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[01/08/2011 00:30:26] - C:\windows\Installer\1f3b9.msi : (Additional Font and Media Support - The J2SE Runtime Environment with European languages. This requires [Core]MB on your hard drive.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[14/06/2011 14:14:34] - C:\windows\Installer\1f3c3.msi : (TOSHIBA Supervisor Password - TOSHIBA) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[14/06/2011 13:59:32] - C:\windows\Installer\1f3cd.msi : (TOSHIBA Hardware Setup - TOSHIBA) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[09/06/2011 21:41:26] - C:\windows\Installer\1f3d2.msi : (Blank Project Template - TOSHIBA Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[28/06/2011 02:36:48] - C:\windows\Installer\1f3d7.msi : (Blank Project Template - Macrovision Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[01/08/2011 00:32:13] - C:\windows\Installer\1f3dd.msi : (TOSHIBA Media Controller for IE - TOSHIBA CORPORATION) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[16/11/2010 00:03:30] - C:\windows\Installer\1f3e2.msi : (ADOBER~1.0|Adobe Reader X - Adobe Systems Incorporated) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[01/08/2011 00:33:16] - C:\windows\Installer\1f3e7.msi : (Adobe AIR Installer - Adobe Systems Incorporated) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[01/08/2011 00:37:38] - C:\windows\Installer\1f5ec.msi : (TOSHIBA Bulletin Board - TOSHIBA Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[04/02/2012 19:45:55] - C:\windows\Installer\262be5.msi : (iLivid Installation - Bandoo Media Inc.) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[27/10/2009 14:11:28] - C:\windows\Installer\36d5b.msi : (Blank Project Template - InstallShield) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[19/03/2013 16:06:23] - C:\windows\Installer\9118a6.msi : (Strongvault Online Backup - [|Brand]) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[11/03/2013 17:54:26] - C:\windows\Installer\9118ad.msi : (Strongvault Online Backup - Strongvault Online Backup) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[26/07/2011 11:36:38] - C:\windows\Installer\938618.msi : ( - DivX, Inc) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
[27/06/2011 19:19:36] - C:\windows\Installer\f0c8.msi : (TOSHIBA Value Added Package - Macrovision Corporation) [Offsets ok ! : D0CF11E0A1B11AE10000000000000000]
---------- | %System%\*.in*
[13/07/2009 21:57:09] - [73] - C:\windows\System32\desktop.ini
[01/08/2011 00:11:09] - [72822] - C:\windows\System32\ieuinit.inf
[10/06/2009 14:01:25] - [60124] - C:\windows\System32\tcpmon.ini
[01/08/2011 00:11:10] - [72822] - C:\windows\Syswow64\ieuinit.inf
[13/07/2009 21:55:01] - [535] - C:\windows\Syswow64\mapisvc.inf
[26/12/2011 13:20:18] - [744944] - C:\windows\Syswow64\PerfStringBackup.INI
---------- | Listing no Microsoft signed files (Not necessary Malwares) | system32 | Syswow64 | General scan
[MD5.00000000000000000000000000000000] - |HD| - [13/07/2009 20:20:08] - [0 Ko] - C:\windows\AppPatch\Custom\Custom64
[MD5.69AD30E0F6F3EAA751193990F5C48F91] - |A| - [01/08/2011 00:16:03] - (.-.) - [121.76 Ko] - (0.0.0.0) - C:\windows\AppPatch\AppPatch64\sysmain.sdb
[MD5.00000000000000000000000000000000] - |D| - [13/05/2016 17:33:57] - [264.27 Ko] - C:\windows\Temp\SafeZone Installer
[MD5.00000000000000000000000000000000] - |D| - [15/04/2017 20:15:32] - [0 Ko] - C:\windows\Temp\_avast_
[MD5.00000000000000000000000000000000] - |D| - [21/11/2010 00:06:51] - [0 Ko] - C:\windows\System32\0409
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |AH| - [13/07/2009 21:45:49] - (.-.) - [24.03 Ko] - (0.0.0.0) - C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |AH| - [13/07/2009 21:45:49] - (.-.) - [24.03 Ko] - (0.0.0.0) - C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:10] - [4986 Ko] - C:\windows\System32\AdvancedInstallers
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:10] - [201.5 Ko] - C:\windows\System32\ar-SA
[MD5.4E118AC95A15BD14B8C1E49C5B4CD79B] - |A| - [19/07/2016 18:28:50] - (.Copyright (c) 2014 AVAST Software - avast! start-up scanner.) - [381.82 Ko] - (12.1.3076.0) - C:\windows\System32\aswBoot.exe
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:10] - [173 Ko] - C:\windows\System32\bg-BG
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:10] - [2401.97 Ko] - C:\windows\System32\Boot
[MD5.7D00FF6A4315FDF4ACAFBB4EF157EA9F] - |A| - [13/07/2009 17:07:04] - (.Copyright (C) 2008 - Bthpan Context Handler.) - [91.5 Ko] - (1.0.0.1) - C:\windows\System32\BthpanContextHandler.dll
[MD5.6794D9D442E31DC5E95BDF65F37E4386] - |A| - [13/07/2009 16:56:54] - (.Copyright (C) 2006 - CardGames Resources.) - [6068.5 Ko] - (1.0.0.1) - C:\windows\System32\CardGames.dll
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:10] - [34687.98 Ko] - C:\windows\System32\catroot
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:10] - [24355.13 Ko] - C:\windows\System32\catroot2
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:10] - [6111.42 Ko] - C:\windows\System32\CodeIntegrity
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:10] - [357 Ko] - C:\windows\System32\com
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:10] - [370033.18 Ko] - C:\windows\System32\config
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:10] - [219.5 Ko] - C:\windows\System32\cs-CZ
[MD5.AA0B1A7B4750F655936F2F82B5E84428] - |A| - [16/12/2010 17:08:00] - (.©Conexant Systems Inc. - Conexant Audio Processing Objects.) - [1512.13 Ko] - (4.80.40.0) - C:\windows\System32\CX64AP40.dll
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:10] - [216.5 Ko] - C:\windows\System32\da-DK
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:10] - [240.5 Ko] - C:\windows\System32\de-DE
[MD5.079B8AEB4A55BF8493BD1EC70285D920] - |ASH| - [13/07/2009 21:57:09] - (.-.) - [0.07 Ko] - (0.0.0.0) - C:\windows\System32\desktop.ini
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:10] - [4419.5 Ko] - C:\windows\System32\Dism
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:10] - [70516.23 Ko] - C:\windows\System32\drivers
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [965199 Ko] - C:\windows\System32\DriverStore
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [240.5 Ko] - C:\windows\System32\el-GR
[MD5.00000000000000000000000000000000] - |D| - [21/11/2010 00:06:51] - [1804 Ko] - C:\windows\System32\en
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [34138.31 Ko] - C:\windows\System32\en-US
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [230.5 Ko] - C:\windows\System32\es-ES
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [160.5 Ko] - C:\windows\System32\et-EE
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [218 Ko] - C:\windows\System32\fi-FI
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [236 Ko] - C:\windows\System32\fr-FR
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 22:32:38] - [0 Ko] - C:\windows\System32\FxsTmp
[MD5.2AE808CB0D9A667B0CF41EA74B3B9BAC] - |A| - [10/06/2009 13:36:24] - (.-.) - [39.6 Ko] - (0.0.0.0) - C:\windows\System32\gatherNetworkInfo.vbs
[MD5.00000000000000000000000000000000] - |HD| - [13/07/2009 20:20:11] - [0 Ko] - C:\windows\System32\GroupPolicy
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [0 Ko] - C:\windows\System32\GroupPolicyUsers
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [191.5 Ko] - C:\windows\System32\he-IL
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [168 Ko] - C:\windows\System32\hr-HR
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [221 Ko] - C:\windows\System32\hu-HU
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [5.36 Ko] - C:\windows\System32\ias
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [36.27 Ko] - C:\windows\System32\icsxml
[MD5.7A495CA1402C2F9F5D035092AD808669] - |A| - [13/07/2009 13:17:48] - (.-.) - [0.85 Ko] - (0.0.0.0) - C:\windows\System32\manage-bde.wsf
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [1981.88 Ko] - C:\windows\System32\manifeststore
[MD5.03E0955A7D8E5E74E7F6986A56A66196] - |A| - [03/10/2010 14:46:00] - (.© Waves Audio Ltd. - MaxxAudio APO.) - [333.34 Ko] - (3.2.1.1) - C:\windows\System32\MaxxAudioAPO30.dll
[MD5.00000000000000000000000000000000] - |SD| - [13/07/2009 21:45:42] - [24.77 Ko] - C:\windows\System32\Microsoft
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [3508.43 Ko] - C:\windows\System32\migration
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [37766.2 Ko] - C:\windows\System32\migwiz
[MD5.00000000000000000000000000000000] - |D| - [14/08/2012 13:58:12] - [0 Ko] - C:\windows\System32\MpEngineStore
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [4148.28 Ko] - C:\windows\System32\Msdtc
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [11.33 Ko] - C:\windows\System32\MUI
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [212 Ko] - C:\windows\System32\nb-NO
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [512 Ko] - C:\windows\System32\NDF
[MD5.CD48AD912839B9FB6CCA5D4AA9B37500] - |A| - [13/07/2009 15:01:19] - (.-.) - [21.3 Ko] - (0.0.0.0) - C:\windows\System32\NetTrace.PLA.Diagnostics.xml
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [85 Ko] - C:\windows\System32\NetworkList
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [229 Ko] - C:\windows\System32\nl-NL
[MD5.2901049544FDF863362FABA2363EB647] - |A| - [13/07/2009 13:24:21] - (.-.) - [0.82 Ko] - (0.0.0.0) - C:\windows\System32\onlinesetup.cmd
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [13469.97 Ko] - C:\windows\System32\oobe
[MD5.B7795BC96C1CEB86E04E8DC843E9C784] - |A| - [10/06/2009 13:33:35] - (.-.) - [113.56 Ko] - (0.0.0.0) - C:\windows\System32\PerfCenterCpl.ico
[MD5.284A4599C9BB58A9ADF4A7F8C498CCF0] - |A| - [08/09/2015 13:49:30] - (.-.) - [5.28 Ko] - (0.0.0.0) - C:\windows\System32\PerfStringBackup.TMP
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [224 Ko] - C:\windows\System32\pl-PL
[MD5.00000000000000000000000000000000] - |D| - [21/11/2010 00:06:50] - [413.88 Ko] - C:\windows\System32\Printing_Admin_Scripts
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [222.5 Ko] - C:\windows\System32\pt-BR
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [224 Ko] - C:\windows\System32\pt-PT
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [23.75 Ko] - C:\windows\System32\ras
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [165248.8 Ko] - C:\windows\System32\Recovery
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 22:32:38] - [0.07 Ko] - C:\windows\System32\restore
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [169 Ko] - C:\windows\System32\ro-RO
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:11] - [219 Ko] - C:\windows\System32\ru-RU
[MD5.5C18CD22BE4628865FCB63337A6E5EF6] - |A| - [20/11/2010 20:24:25] - (.-.) - [10.18 Ko] - (0.0.0.0) - C:\windows\System32\ScavengeSpace.xml
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:13] - [169.5 Ko] - C:\windows\System32\sk-SK
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:13] - [166 Ko] - C:\windows\System32\sl-SI
[MD5.00000000000000000000000000000000] - |D| - [21/11/2010 00:06:51] - [37.8 Ko] - C:\windows\System32\slmgr
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:13] - [11586.02 Ko] - C:\windows\System32\SMI
[MD5.C74D61FCA22F36791105D7878AF73572] - |A| - [10/06/2009 14:08:17] - (.-.) - [8.09 Ko] - (0.0.0.0) - C:\windows\System32\spcinstrumentation.man
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:13] - [26875.5 Ko] - C:\windows\System32\Speech
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:13] - [26136.83 Ko] - C:\windows\System32\spool
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:13] - [1956.87 Ko] - C:\windows\System32\spp
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:13] - [30.19 Ko] - C:\windows\System32\sppui
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:13] - [170 Ko] - C:\windows\System32\sr-Latn-CS
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:13] - [216.5 Ko] - C:\windows\System32\sv-SE
[MD5.00000000000000000000000000000000] - |AD| - [13/07/2009 20:20:13] - [409.01 Ko] - C:\windows\System32\sysprep
[MD5.5EC92F0EAE3CA59F647C3CA5AA7CB053] - |A| - [20/11/2010 20:24:36] - (.-.) - [339.75 Ko] - (0.0.0.0) - C:\windows\System32\systemsf.ebd
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:13] - [304.27 Ko] - C:\windows\System32\Tasks
[MD5.47F22CAD4A16BB40153555D631546B94] - |A| - [10/06/2009 14:01:25] - (.-.) - [58.71 Ko] - (0.0.0.0) - C:\windows\System32\tcpmon.ini
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:13] - [157 Ko] - C:\windows\System32\th-TH
[MD5.F79C9E3947B904FA3200A2204F9C52BB] - |A| - [20/10/2011 10:19:14] - (.Copyright (C) 2011 TOSHIBA CORPORATION - Credential Provider Dll for TOSHIBA Wireless LAN Indicator.) - [96.99 Ko] - (1.0.12.3) - C:\windows\System32\tosWirelessLANIndicatorCP.dll
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:13] - [212.5 Ko] - C:\windows\System32\tr-TR
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:13] - [166.5 Ko] - C:\windows\System32\uk-UA
[MD5.00000000000000000000000000000000] - |D| - [28/12/2011 14:28:42] - [1754.83 Ko] - C:\windows\System32\Wat
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [45558.25 Ko] - C:\windows\System32\wbem
[MD5.00000000000000000000000000000000] - |D| - [21/11/2010 00:06:50] - [60.46 Ko] - C:\windows\System32\WCN
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [82214.23 Ko] - C:\windows\System32\wdi
[MD5.6EDD021A8B6457DDE09DE7B7FA4E8C8B] - |A| - [13/07/2009 14:54:15] - (.-.) - [0.6 Ko] - (0.0.0.0) - C:\windows\System32\WdsUnattendTemplate.xml
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [0 Ko] - C:\windows\System32\wfp
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 22:32:38] - [0 Ko] - C:\windows\System32\WinBioDatabase
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 22:32:38] - [73.5 Ko] - C:\windows\System32\WinBioPlugIns
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 22:32:38] - [8584.71 Ko] - C:\windows\System32\WindowsPowerShell
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [46460 Ko] - C:\windows\System32\winevt
[MD5.00000000000000000000000000000000] - |D| - [21/11/2010 00:06:51] - [99.06 Ko] - C:\windows\System32\winrm
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [141.5 Ko] - C:\windows\System32\zh-CN
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [63 Ko] - C:\windows\System32\zh-HK
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [141.5 Ko] - C:\windows\System32\zh-TW
[MD5.00000000000000000000000000000000] - |HD| - [21/11/2010 00:06:51] - [0 Ko] - C:\windows\SysWOW64\0409
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [2258.5 Ko] - C:\windows\SysWOW64\AdvancedInstallers
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [201.5 Ko] - C:\windows\SysWOW64\ar-SA
[MD5.00000000000000000000000000000000] - |D| - [20/10/2011 10:20:21] - [87.04 Ko] - C:\windows\SysWOW64\Atheros_L1e
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [173 Ko] - C:\windows\SysWOW64\bg-BG
[MD5.00000000000000000000000000000000] - |HD| - [13/07/2009 20:20:14] - [0 Ko] - C:\windows\SysWOW64\catroot
[MD5.00000000000000000000000000000000] - |HD| - [13/07/2009 20:20:14] - [0 Ko] - C:\windows\SysWOW64\catroot2
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [302.5 Ko] - C:\windows\SysWOW64\com
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [9620.15 Ko] - C:\windows\SysWOW64\config
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [219.5 Ko] - C:\windows\SysWOW64\cs-CZ
[MD5.B9A550873AB27DB299AEA3D9DE5489D4] - |A| - [20/10/2011 10:05:57] - (.Copyright 2008 - CSVer.) - [52 Ko] - (9.2.0.1015) - C:\windows\SysWOW64\CSVer.dll
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [216.5 Ko] - C:\windows\SysWOW64\da-DK
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [240.5 Ko] - C:\windows\SysWOW64\de-DE
[MD5.4E14C3CCBB313666F9DC3D8DAD120C46] - |A| - [13/05/2016 17:50:43] - (.-.) - [221.2 Ko] - (0.0.0.0) - C:\windows\SysWOW64\debug.log
[MD5.C88C969B8E477E4297E4A65D66852BF3] - |A| - [01/08/2011 00:30:24] - (.Copyright © 2011 - Java(TM) Platform SE binary.) - [461.73 Ko] - (6.0.250.6) - C:\windows\SysWOW64\deployJava1.dll
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [3386.5 Ko] - C:\windows\SysWOW64\Dism
[MD5.F42E95BFB193754E9148DB6434D2E88E] - |A| - [19/02/2010 12:27:36] - (.Copyright © 2000-2009 DivX, Inc. - DivX.) - [703.5 Ko] - (6.9.2.26) - C:\windows\SysWOW64\DivX.dll
[MD5.BF8B26F3B97219B08230E6ADD3A703F7] - |A| - [03/01/2012 17:48:42] - (.© Copyright 2000 - 2009 DivX, Inc. - DivX Control Panel.) - [345.88 Ko] - (1.2.0.11) - C:\windows\SysWOW64\DivXControlPanelApplet.cpl
[MD5.A266D3E430E9FF97E9D659E5F087EF99] - |A| - [19/02/2010 12:27:16] - (.Copyright © 2001-2008 DivX, Inc. - DivX.) - [836 Ko] - (6.9.2.26) - C:\windows\SysWOW64\divx_xx07.dll
[MD5.0DADCB1C15AB04A655F7B386FE625B35] - |A| - [19/02/2010 12:27:16] - (.Copyright © 2001-2008 DivX, Inc. - DivX.) - [828 Ko] - (6.9.2.26) - C:\windows\SysWOW64\divx_xx0a.dll
[MD5.725C556795DFC534660E784F9324515C] - |A| - [19/02/2010 12:27:16] - (.Copyright © 2001-2008 DivX, Inc. - DivX.) - [836 Ko] - (6.9.2.26) - C:\windows\SysWOW64\divx_xx0c.dll
[MD5.E1F94DFDC350BB8CE14655F5DB567149] - |A| - [19/02/2010 12:27:16] - (.Copyright ゥ 2001-2008 DivX, Inc. - DivX.) - [820 Ko] - (6.9.2.26) - C:\windows\SysWOW64\divx_xx11.dll
[MD5.AD8E4393EAD5A8A71378BEEE95C59FDA] - |A| - [19/02/2010 12:27:16] - (.Copyright © 2001-2008 DivX, Inc. - DivX.) - [824 Ko] - (6.9.2.26) - C:\windows\SysWOW64\divx_xx16.dll
[MD5.90C7F5E71EEFE13F762CFE7B42C7157A] - |A| - [20/10/2011 16:26:22] - (.Copyright © 2005-2006 - dpl100.) - [92 Ko] - (1.3.0.25) - C:\windows\SysWOW64\dpl100.dll
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [3472.71 Ko] - C:\windows\SysWOW64\drivers
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [1.05 Ko] - C:\windows\SysWOW64\DriverStore
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [240.5 Ko] - C:\windows\SysWOW64\el-GR
[MD5.00000000000000000000000000000000] - |D| - [21/11/2010 00:06:51] - [1648 Ko] - C:\windows\SysWOW64\en
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [30987.63 Ko] - C:\windows\SysWOW64\en-US
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [230.5 Ko] - C:\windows\SysWOW64\es-ES
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [160.5 Ko] - C:\windows\SysWOW64\et-EE
[MD5.093A41D0865DA5C7BE09A0F60A37B7D1] - |A| - [02/01/2012 13:46:19] - (.-.) - [56 Ko] - (0.0.0.0) - C:\windows\SysWOW64\ff_vfw.dll
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [218 Ko] - C:\windows\SysWOW64\fi-FI
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [236 Ko] - C:\windows\SysWOW64\fr-FR
[MD5.00000000000000000000000000000000] - |HD| - [13/07/2009 22:32:38] - [0 Ko] - C:\windows\SysWOW64\FxsTmp
[MD5.ABCB973D716F4F0DCC1E7DB99E8B03A3] - |A| - [10/02/2016 17:07:32] - (.-.) - [83.85 Ko] - (0.0.0.0) - C:\windows\SysWOW64\generic_uninstaller.log
[MD5.00000000000000000000000000000000] - |HD| - [13/07/2009 20:20:14] - [0 Ko] - C:\windows\SysWOW64\GroupPolicy
[MD5.00000000000000000000000000000000] - |HD| - [13/07/2009 20:20:14] - [0 Ko] - C:\windows\SysWOW64\GroupPolicyUsers
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [191.5 Ko] - C:\windows\SysWOW64\he-IL
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [168 Ko] - C:\windows\SysWOW64\hr-HR
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [221 Ko] - C:\windows\SysWOW64\hu-HU
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [36.27 Ko] - C:\windows\SysWOW64\icsxml
[MD5.481F6E1CD63E09F0516B5E78B35D333E] - |A| - [04/04/2011 20:07:00] - (.-.) - [142.39 Ko] - (0.0.0.0) - C:\windows\SysWOW64\igcompkrng600.bin
[MD5.D3EEBC1763F15A8EEBB6F056D9726FF8] - |A| - [04/04/2011 20:06:58] - (.-.) - [211.79 Ko] - (0.0.0.0) - C:\windows\SysWOW64\igfcg600m.bin
[MD5.2DAE8EF56FA66F1A76A628CF7B039596] - |A| - [04/04/2011 20:06:58] - (.-.) - [940.54 Ko] - (0.0.0.0) - C:\windows\SysWOW64\igkrng600.bin
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [34095.44 Ko] - C:\windows\SysWOW64\IME
[MD5.00000000000000000000000000000000] - |HD| - [13/07/2009 20:20:14] - [0 Ko] - C:\windows\SysWOW64\inetsrv
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [1160 Ko] - C:\windows\SysWOW64\InstallShield
[MD5.6B7D1357B144F6FEE941FF1B97F4C5D3] - |A| - [20/10/2011 10:18:27] - (.-.) - [440.5 Ko] - (0.0.0.0) - C:\windows\SysWOW64\ISSRemoveSP.exe
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [235 Ko] - C:\windows\SysWOW64\it-IT
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [163 Ko] - C:\windows\SysWOW64\ja-JP
[MD5.B157E305260FF2A607591F33DE41BFCA] - |A| - [01/08/2011 00:30:24] - (.Copyright © 2011 - Java(TM) Platform SE binary.) - [141.78 Ko] - (6.0.250.6) - C:\windows\SysWOW64\java.exe
[MD5.364F7A2B4B535659F3B50DE5E5C20123] - |A| - [01/08/2011 00:30:24] - (.Copyright © 2011 - Java(TM) Platform SE binary.) - [141.78 Ko] - (6.0.250.6) - C:\windows\SysWOW64\javaw.exe
[MD5.A0AC7907D47B54238CA60FC47807F119] - |A| - [01/08/2011 00:30:24] - (.Copyright © 2011 - Java(TM) Web Start Launcher.) - [153.78 Ko] - (6.0.250.6) - C:\windows\SysWOW64\javaws.exe
[MD5.C1B7AB03AC2F3C990A40BC2E18E02CF1] - |A| - [13/07/2009 19:35:50] - (.-.) - [11687.04 Ko] - (0.0.0.0) - C:\windows\SysWOW64\korwbrkr.lex
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [05/08/2016 17:07:18] - (.-.) - [0 Ko] - (0.0.0.0) - C:\windows\SysWOW64\last.dump
[MD5.D41D8CD98F00B204E9800998ECF8427E] - |A| - [20/10/2011 10:07:48] - (.-.) - [0.02 Ko] - (0.0.0.0) - C:\windows\SysWOW64\log.txt
[MD5.00000000000000000000000000000000] - |HD| - [13/07/2009 22:32:38] - [0 Ko] - C:\windows\SysWOW64\LogFiles
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [165 Ko] - C:\windows\SysWOW64\lt-LT
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [166 Ko] - C:\windows\SysWOW64\lv-LV
[MD5.00000000000000000000000000000000] - |D| - [01/08/2011 00:32:35] - [41496.63 Ko] - C:\windows\SysWOW64\Macromed
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [1968.26 Ko] - C:\windows\SysWOW64\manifeststore
[MD5.98071B6EE16AA76DABFF377A5DC69C86] - |A| - [13/07/2009 21:55:01] - (.-.) - [0.52 Ko] - (0.0.0.0) - C:\windows\SysWOW64\mapisvc.inf
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [3208.93 Ko] - C:\windows\SysWOW64\migration
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [32669.71 Ko] - C:\windows\SysWOW64\migwiz
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [52.28 Ko] - C:\windows\SysWOW64\Msdtc
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [11.33 Ko] - C:\windows\SysWOW64\MUI
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [212 Ko] - C:\windows\SysWOW64\nb-NO
[MD5.00000000000000000000000000000000] - |HD| - [13/07/2009 20:20:14] - [0 Ko] - C:\windows\SysWOW64\NDF
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [51 Ko] - C:\windows\SysWOW64\NetworkList
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [229 Ko] - C:\windows\SysWOW64\nl-NL
[MD5.1C96B3DA6ABE5E18B63C64DF75884F6A] - |A| - [13/07/2009 19:35:50] - (.-.) - [1.45 Ko] - (0.0.0.0) - C:\windows\SysWOW64\noise.kor
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [2566.05 Ko] - C:\windows\SysWOW64\oobe
[MD5.B7795BC96C1CEB86E04E8DC843E9C784] - |A| - [10/06/2009 14:17:19] - (.-.) - [113.56 Ko] - (0.0.0.0) - C:\windows\SysWOW64\PerfCenterCpl.ico
[MD5.217033BD2448E2831F4D77B001C63763] - |A| - [26/12/2011 13:20:18] - (.-.) - [727.48 Ko] - (0.0.0.0) - C:\windows\SysWOW64\PerfStringBackup.INI
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [224 Ko] - C:\windows\SysWOW64\pl-PL
[MD5.00000000000000000000000000000000] - |D| - [21/11/2010 00:06:51] - [413.88 Ko] - C:\windows\SysWOW64\Printing_Admin_Scripts
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [222.5 Ko] - C:\windows\SysWOW64\pt-BR
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [224 Ko] - C:\windows\SysWOW64\pt-PT
[MD5.CE931021E18F385F519E945A8A10548E] - |A| - [02/01/2012 13:46:19] - (.Copyright (C) Project contributors 1998-2004 - POSIX Threads for Windows32 Library.) - [58.86 Ko] - (2.8.0.0) - C:\windows\SysWOW64\pthreadGC2.dll
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [23.75 Ko] - C:\windows\SysWOW64\ras
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [0.64 Ko] - C:\windows\SysWOW64\Recovery
[MD5.00000000000000000000000000000000] - |HD| - [13/07/2009 22:32:38] - [0 Ko] - C:\windows\SysWOW64\restore
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [169 Ko] - C:\windows\SysWOW64\ro-RO
[MD5.9E53C231B0A511A48BAF102EDA4FC198] - |A| - [03/02/2011 19:56:46] - (.Copyright (C) Synaptics Incorporated 1996-2011 - SynCOM.) - [169.29 Ko] - (15.2.11.1) - C:\windows\SysWOW64\SynCOM.dll
[MD5.23FECDF8EA830C69325A4A9CC21A7F1B] - |A| - [03/02/2011 19:56:48] - (.Copyright (C) Synaptics Incorporated 1996-2011 - SynCtrl.) - [213.29 Ko] - (15.2.11.1) - C:\windows\SysWOW64\SynCtrl.dll
[MD5.01C809AEEE4C10100B35D640925A6DB3] - |A| - [03/02/2011 19:56:54] - (.Copyright (C) Synaptics Incorporated 1996-2011 - Synaptics TouchPad Interfaces.) - [105.29 Ko] - (15.2.11.1) - C:\windows\SysWOW64\SynTPCOM.dll
[MD5.179D3637464E602FADD7DF5C428BB9E4] - |A| - [03/02/2011 19:56:58] - (.-.) - [65.29 Ko] - (0.0.0.0) - C:\windows\SysWOW64\SynTPEnhPS.dll
[MD5.00000000000000000000000000000000] - |D| - [21/11/2010 00:06:51] - [977.89 Ko] - C:\windows\SysWOW64\sysprep
[MD5.00000000000000000000000000000000] - |HD| - [13/07/2009 20:20:14] - [0 Ko] - C:\windows\SysWOW64\Tasks
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [157 Ko] - C:\windows\SysWOW64\th-TH
[MD5.2BAB54632EAF98ED75D55E19C46955E4] - |A| - [20/10/2011 10:12:43] - (.Copyright © 1997-8 - THCI.) - [24 Ko] - (1.0.0.1) - C:\windows\SysWOW64\THCI.dll
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [212.5 Ko] - C:\windows\SysWOW64\tr-TR
[MD5.2611F58AEC4BB39387162F749FE8A558] - |A| - [20/10/2011 10:12:43] - (.Copyright © 1997-8 - TSCI.) - [24 Ko] - (1.0.0.1) - C:\windows\SysWOW64\TSCI.dll
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [166.5 Ko] - C:\windows\SysWOW64\uk-UA
[MD5.15BD0F8D507546F512EE5D73C3721FA8] - |A| - [13/07/2009 19:35:41] - (.Copyright © 2000 - vfpodbc.) - [20.05 Ko] - (1.0.2.0) - C:\windows\SysWOW64\vfpodbc.dll
[MD5.00000000000000000000000000000000] - |D| - [28/12/2011 14:28:42] - [237.33 Ko] - C:\windows\SysWOW64\Wat
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [8731.34 Ko] - C:\windows\SysWOW64\wbem
[MD5.00000000000000000000000000000000] - |D| - [21/11/2010 00:06:51] - [60.46 Ko] - C:\windows\SysWOW64\WCN
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [96.48 Ko] - C:\windows\SysWOW64\wdi
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 22:32:38] - [8539.71 Ko] - C:\windows\SysWOW64\WindowsPowerShell
[MD5.00000000000000000000000000000000] - |D| - [21/11/2010 00:06:51] - [99.06 Ko] - C:\windows\SysWOW64\winrm
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [141.5 Ko] - C:\windows\SysWOW64\zh-CN
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [63 Ko] - C:\windows\SysWOW64\zh-HK
[MD5.00000000000000000000000000000000] - |D| - [13/07/2009 20:20:14] - [141.5 Ko] - C:\windows\SysWOW64\zh-TW
[MD5.E4E50E87DE25BD9FDA3DBC4030147981] - |A| - [27/04/2013 16:34:52] - (.-.) - [0.05 Ko] - (0.0.0.0) - C:\windows\SysWOW64\~stg
---------- | Shell Folders
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"!Do not use this registry key"=Use the SHGetFolderPath or SHGetKnownFolderPath function instead
"AppData"=C:\Users\Mitch\AppData\Roaming [26/12/2011 12:56:44]
"Local AppData"=C:\Users\Mitch\AppData\Local [26/12/2011 12:56:44]
"My Video"=C:\Users\Mitch\Videos [26/12/2011 12:56:44]
"{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}"=C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Libraries [26/12/2011 12:58:02]
"My Pictures"=C:\Users\Mitch\Pictures [26/12/2011 12:56:44]
"Desktop"=C:\Users\Mitch\Desktop [26/12/2011 12:56:44]
"History"=C:\Users\Mitch\AppData\Local\Microsoft\Windows\History [26/12/2011 12:56:44]
"NetHood"=C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Network Shortcuts [26/12/2011 12:56:44]
"{56784854-C6CB-462B-8169-88E350ACB882}"=C:\Users\Mitch\Contacts [26/12/2011 12:57:51]
"Cookies"=C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Cookies [26/12/2011 12:56:44]
"Favorites"=C:\Users\Mitch\Favorites [26/12/2011 12:56:44]
"SendTo"=C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\SendTo [26/12/2011 12:56:44]
"Start Menu"=C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu [26/12/2011 12:56:44]
"My Music"=C:\Users\Mitch\Music [26/12/2011 12:56:44]
"Programs"=C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [26/12/2011 12:56:44]
"Recent"=C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Recent [26/12/2011 12:56:44]
"CD Burning"=C:\Users\Mitch\AppData\Local\Microsoft\Windows\Burn\Burn [26/12/2011 12:58:13]
"PrintHood"=C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Printer Shortcuts [26/12/2011 12:56:44]
"{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}"=C:\Users\Mitch\Searches [26/12/2011 12:58:02]
"{374DE290-123F-4565-9164-39C4925E467B}"=C:\Users\Mitch\Downloads [26/12/2011 12:56:44]
"{A520A1A4-1780-4FF6-BD18-167343C5AF16}"=C:\Users\Mitch\AppData\LocalLow [26/12/2011 12:56:45]
"Startup"=C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [26/12/2011 12:58:02]
"Administrative Tools"=C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [26/12/2011 12:58:02]
"Personal"=C:\Users\Mitch\Documents [26/12/2011 12:56:44]
"{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}"=C:\Users\Mitch\Links [26/12/2011 12:56:44]
"Cache"=C:\Users\Mitch\AppData\Local\Microsoft\Windows\Temporary Internet Files [26/12/2011 12:56:44]
"Templates"=C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Templates [26/12/2011 12:56:44]
"{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}"=C:\Users\Mitch\Saved Games [26/12/2011 12:56:44]
"Fonts"=C:\windows\Fonts [13/07/2009 20:20:09]
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders]
"AppData"=%USERPROFILE%\AppData\Roaming
"Cache"=%USERPROFILE%\AppData\Local\Microsoft\Windows\Temporary Internet Files
"Cookies"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Cookies
"Desktop"=%USERPROFILE%\Desktop
"Favorites"=%USERPROFILE%\Favorites
"History"=%USERPROFILE%\AppData\Local\Microsoft\Windows\History
"Local AppData"=%USERPROFILE%\AppData\Local
"My Music"=%USERPROFILE%\Music
"My Pictures"=%USERPROFILE%\Pictures
"My Video"=%USERPROFILE%\Videos
"NetHood"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts
"Personal"=%USERPROFILE%\Documents
"Programs"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
"Recent"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent
"SendTo"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo
"Startup"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
"Start Menu"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu
"Templates"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates
"{374DE290-123F-4565-9164-39C4925E467B}"=%USERPROFILE%\Downloads
"PrintHood"=%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop"=C:\Users\Public\Desktop [13/07/2009 20:20:08]
"Common Start Menu"=C:\ProgramData\Microsoft\Windows\Start Menu [13/07/2009 20:20:08]
"CommonVideo"=C:\Users\Public\Videos [13/07/2009 20:20:08]
"CommonPictures"=C:\Users\Public\Pictures [13/07/2009 20:20:08]
"Common Programs"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs [13/07/2009 20:20:08]
"CommonMusic"=C:\Users\Public\Music [13/07/2009 20:20:08]
"Common Administrative Tools"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [13/07/2009 22:32:38]
"Common Startup"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [13/07/2009 20:20:08]
"Common Documents"=C:\Users\Public\Documents [13/07/2009 20:20:08]
"OEM Links"=C:\ProgramData\OEM Links
"Common Templates"=C:\ProgramData\Microsoft\Windows\Templates [13/07/2009 20:20:08]
"Common AppData"=C:\ProgramData [13/07/2009 20:20:08]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders]
"Common Desktop"=%PUBLIC%\Desktop
"Common Documents"=%PUBLIC%\Documents
"CommonPictures"=%PUBLIC%\Pictures
"CommonMusic"=%PUBLIC%\Music
"CommonVideo"=%PUBLIC%\Videos
"{3D644C9B-1FB8-4f30-9B45-F670235F79C0}"=%PUBLIC%\Downloads
"Common Start Menu"=%ProgramData%\Microsoft\Windows\Start Menu
"Common Programs"=%ProgramData%\Microsoft\Windows\Start Menu\Programs
"Common Startup"=%ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup
"Common AppData"=%ProgramData%
"Common Templates"=%ProgramData%\Microsoft\Windows\Templates
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop"=C:\Users\Public\Desktop [13/07/2009 20:20:08]
"Common Start Menu"=C:\ProgramData\Microsoft\Windows\Start Menu [13/07/2009 20:20:08]
"CommonVideo"=C:\Users\Public\Videos [13/07/2009 20:20:08]
"CommonPictures"=C:\Users\Public\Pictures [13/07/2009 20:20:08]
"Common Programs"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs [13/07/2009 20:20:08]
"CommonMusic"=C:\Users\Public\Music [13/07/2009 20:20:08]
"Common Administrative Tools"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools [13/07/2009 22:32:38]
"Common Startup"=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup [13/07/2009 20:20:08]
"Common Documents"=C:\Users\Public\Documents [13/07/2009 20:20:08]
"OEM Links"=C:\ProgramData\OEM Links
"Common Templates"=C:\ProgramData\Microsoft\Windows\Templates [13/07/2009 20:20:08]
"Common AppData"=C:\ProgramData [13/07/2009 20:20:08]
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders]
"Common Desktop"=%PUBLIC%\Desktop
"Common Documents"=%PUBLIC%\Documents
"CommonPictures"=%PUBLIC%\Pictures
"CommonMusic"=%PUBLIC%\Music
"CommonVideo"=%PUBLIC%\Videos
"{3D644C9B-1FB8-4f30-9B45-F670235F79C0}"=%PUBLIC%\Downloads
"Common Start Menu"=%ProgramData%\Microsoft\Windows\Start Menu
"Common Programs"=%ProgramData%\Microsoft\Windows\Start Menu\Programs
"Common Startup"=%ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup
"Common AppData"=%ProgramData%
"Common Templates"=%ProgramData%\Microsoft\Windows\Templates
---------- | [John]
[30/10/2012 21:56:55] - |D| - [137692117] - C:\Users\John\AppData\Local
[30/10/2012 21:56:55] - |D| - [23523] - C:\Users\John\AppData\LocalLow
[30/10/2012 21:56:55] - |D| - [999663] - C:\Users\John\AppData\Roaming
[30/10/2012 21:56:55] - |SHD| - [1533511099] - C:\Users\John\AppData\Local\Application Data
[30/10/2012 21:57:25] - |A| - [57560] - C:\Users\John\AppData\Local\GDIPFONTCACHEV1.DAT
[30/10/2012 22:02:33] - |D| - [116688372] - C:\Users\John\AppData\Local\Google
[30/10/2012 21:56:55] - |SHD| - [49152] - C:\Users\John\AppData\Local\History
[30/10/2012 22:16:45] - |AH| - [782118] - C:\Users\John\AppData\Local\IconCache.db
[30/10/2012 21:56:55] - |D| - [19912641] - C:\Users\John\AppData\Local\Microsoft
[30/10/2012 21:56:55] - |HD| - [251341] - C:\Users\John\AppData\Local\Temp
[30/10/2012 21:56:55] - |SHD| - [105098] - C:\Users\John\AppData\Local\Temporary Internet Files
[30/10/2012 21:57:25] - |D| - [85] - C:\Users\John\AppData\Local\TOSHIBA
[30/10/2012 21:56:58] - |SD| - [23523] - C:\Users\John\AppData\LocalLow\Microsoft
[30/10/2012 21:57:04] - |D| - [0] - C:\Users\John\AppData\Roaming\Identities
[30/10/2012 21:56:55] - |D| - [2834] - C:\Users\John\AppData\Roaming\Macromedia
[30/10/2012 21:56:55] - |HD| - [0] - C:\Users\John\AppData\Roaming\Media Center Programs
[30/10/2012 21:56:55] - |D| - [994963] - C:\Users\John\AppData\Roaming\Microsoft
[30/10/2012 21:58:42] - |D| - [1866] - C:\Users\John\AppData\Roaming\Toshiba
[30/10/2012 21:56:55] - |D| - [0] - C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
[30/10/2012 21:56:55] - |D| - [0] - C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
---------- | [Mitch]
[26/12/2011 12:56:44] - |D| - [582652008] - C:\Users\Mitch\AppData\Local
[26/12/2011 12:56:45] - |D| - [14149585] - C:\Users\Mitch\AppData\LocalLow
[26/12/2011 12:56:44] - |D| - [93623248] - C:\Users\Mitch\AppData\Roaming
[03/01/2012 14:45:28] - |HD| - [662420] - C:\Users\Mitch\AppData\Local\Adobe
[26/12/2011 12:56:45] - |SHD| - [6149263590] - C:\Users\Mitch\AppData\Local\Application Data
[01/01/2012 15:53:03] - |HD| - [0] - C:\Users\Mitch\AppData\Local\Apps
[21/07/2016 16:22:09] - |D| - [443696] - C:\Users\Mitch\AppData\Local\CEF
[28/01/2012 16:44:43] - |HD| - [0] - C:\Users\Mitch\AppData\Local\CrashDumps
[19/01/2012 16:41:54] - |HD| - [106] - C:\Users\Mitch\AppData\Local\DDMSettings
[06/02/2012 17:55:19] - |HD| - [34649854] - C:\Users\Mitch\AppData\Local\Diagnostics
[19/04/2017 16:48:18] - |A| - [57560] - C:\Users\Mitch\AppData\Local\GDIPFONTCACHEV1.DAT
[26/12/2011 12:58:38] - |HD| - [135702737] - C:\Users\Mitch\AppData\Local\Google
[26/12/2011 12:56:45] - |SHD| - [65826] - C:\Users\Mitch\AppData\Local\History
[26/12/2011 19:37:50] - |AH| - [3778060] - C:\Users\Mitch\AppData\Local\IconCache.db
[08/01/2013 17:46:39] - |D| - [12549] - C:\Users\Mitch\AppData\Local\Kjs.AppLife.Update
[26/12/2011 12:56:44] - |D| - [33306558] - C:\Users\Mitch\AppData\Local\Microsoft
[08/09/2015 12:00:02] - |D| - [4841] - C:\Users\Mitch\AppData\Local\Microsoft Games
[08/09/2015 10:44:05] - |D| - [0] - C:\Users\Mitch\AppData\Local\Programs
[26/12/2011 13:21:07] - |HD| - [630784] - C:\Users\Mitch\AppData\Local\SoftGrid Client
[26/12/2011 12:56:44] - |D| - [0] - C:\Users\Mitch\AppData\Local\Temp
[26/12/2011 12:56:45] - |SHD| - [32902] - C:\Users\Mitch\AppData\Local\Temporary Internet Files
[01/03/2012 16:06:40] - |D| - [11178124] - C:\Users\Mitch\AppData\Local\Tific
[26/12/2011 12:58:15] - |D| - [2374] - C:\Users\Mitch\AppData\Local\TOSHIBA
[09/09/2015 08:24:22] - |D| - [0] - C:\Users\Mitch\AppData\Local\VirtualStore
[02/01/2012 13:49:23] - |HD| - [481033] - C:\Users\Mitch\AppData\Local\Vivitar Experience Image Manager
[08/09/2015 10:44:09] - |D| - [361505328] - C:\Users\Mitch\AppData\Local\Zemana
[15/04/2017 20:19:39] - |D| - [235984] - C:\Users\Mitch\AppData\Local\ZHP
[03/01/2012 14:45:28] - |HD| - [72761] - C:\Users\Mitch\AppData\LocalLow\Adobe
[19/01/2012 16:41:17] - |HD| - [65536] - C:\Users\Mitch\AppData\LocalLow\boost_interprocess
[26/12/2011 12:56:52] - |SD| - [14009219] - C:\Users\Mitch\AppData\LocalLow\Microsoft
[12/01/2012 16:40:23] - |D| - [2069] - C:\Users\Mitch\AppData\LocalLow\Sun
[01/01/2012 15:03:57] - |SD| - [0] - C:\Users\Mitch\AppData\LocalLow\Temp
[12/07/2012 10:00:11] - |HD| - [0] - C:\Users\Mitch\AppData\LocalLow\WebEx
[26/01/2012 14:49:38] - |HD| - [0] - C:\Users\Mitch\AppData\LocalLow\Yahoo!
[08/09/2015 15:57:04] - |D| - [8180458] - C:\Users\Mitch\AppData\Roaming\9-lab
[26/12/2011 12:58:53] - |D| - [50066919] - C:\Users\Mitch\AppData\Roaming\Adobe
[09/09/2015 09:49:51] - |D| - [1076143] - C:\Users\Mitch\AppData\Roaming\AVAST Software
[08/01/2013 17:10:21] - |D| - [96951] - C:\Users\Mitch\AppData\Roaming\Book Place
[19/01/2012 16:39:36] - |HD| - [93184] - C:\Users\Mitch\AppData\Roaming\DivX
[06/02/2012 16:17:02] - |HD| - [25163] - C:\Users\Mitch\AppData\Roaming\FreeTorrentViewer
[26/12/2011 12:58:41] - |HD| - [0] - C:\Users\Mitch\AppData\Roaming\Google
[26/12/2011 12:57:54] - |HD| - [0] - C:\Users\Mitch\AppData\Roaming\Identities
[26/12/2011 12:56:44] - |D| - [56466] - C:\Users\Mitch\AppData\Roaming\Macromedia
[26/12/2011 12:56:44] - |HD| - [0] - C:\Users\Mitch\AppData\Roaming\Media Center Programs
[26/12/2011 12:56:44] - |SD| - [9256900] - C:\Users\Mitch\AppData\Roaming\Microsoft
[09/02/2012 17:00:52] - |HD| - [282] - C:\Users\Mitch\AppData\Roaming\Product_RM
[26/12/2011 13:21:07] - |D| - [1340739] - C:\Users\Mitch\AppData\Roaming\SoftGrid Client
[26/12/2011 14:28:25] - |HD| - [13208] - C:\Users\Mitch\AppData\Roaming\Tific
[26/12/2011 12:59:36] - |HD| - [16204260] - C:\Users\Mitch\AppData\Roaming\Toshiba
[04/02/2012 20:19:23] - |D| - [695] - C:\Users\Mitch\AppData\Roaming\vlc
[26/12/2011 12:56:55] - |HD| - [0] - C:\Users\Mitch\AppData\Roaming\WinBatch
[15/04/2017 20:19:39] - |D| - [5593752] - C:\Users\Mitch\AppData\Roaming\ZHP
[08/09/2015 11:35:29] - |D| - [1618128] - C:\Users\Mitch\AppData\Roaming\ZHP.$quar
[26/12/2011 12:58:02] - |ASH| - [174] - C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
[26/12/2011 12:56:44] - |RD| - [26058] - C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
[26/12/2011 12:56:44] - |RD| - [14660] - C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[26/12/2011 12:58:02] - |RD| - [174] - C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[26/12/2011 12:58:02] - |ASH| - [476] - C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
[06/02/2012 16:16:54] - |D| - [2048] - C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeTorrentViewer
[02/01/2012 13:46:25] - |HD| - [0] - C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
[26/12/2011 12:58:04] - |A| - [1458] - C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[26/12/2011 12:56:44] - |RD| - [580] - C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[26/12/2011 12:58:02] - |RD| - [174] - C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[18/01/2012 15:30:02] - |D| - [1336] - C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Veoh Networks, Inc
[02/01/2012 13:49:22] - |D| - [2974] - C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vivitar Experience Image Manager
[08/05/2012 12:19:44] - |D| - [2178] - C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoola Games
[26/12/2011 12:58:02] - |ASH| - [174] - C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
---------- | [Public]
---------- | C:\ProgramData
[08/09/2015 15:56:57] - |D| - [59744988] - C:\ProgramData\9-lab
[01/08/2011 00:32:52] - |D| - [275704481] - C:\ProgramData\Adobe
[13/07/2009 22:08:56] - |SHD| - [68814947770] - C:\ProgramData\Application Data
[09/09/2015 09:47:10] - |D| - [224539953] - C:\ProgramData\AVAST Software
[13/07/2009 22:08:56] - |SD| - [8159] - C:\ProgramData\Desktop
[19/01/2012 16:26:47] - |D| - [5567819] - C:\ProgramData\DivX
[13/07/2009 22:08:56] - |SHD| - [278] - C:\ProgramData\Documents
[13/07/2009 22:08:56] - |SHD| - [0] - C:\ProgramData\Favorites
[18/01/2012 15:30:05] - |D| - [417032557] - C:\ProgramData\Giraffic
[20/10/2011 10:36:05] - |D| - [544630] - C:\ProgramData\Google
[08/09/2015 10:46:37] - |D| - [11082433] - C:\ProgramData\Malwarebytes
[15/04/2017 20:33:30] - |D| - [0] - C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[02/07/2015 16:39:47] - |D| - [0] - C:\ProgramData\McAfee
[13/07/2009 20:20:08] - |SD| - [2297060808] - C:\ProgramData\Microsoft
[20/10/2011 10:31:34] - |D| - [78211] - C:\ProgramData\Norton
[20/10/2011 10:31:22] - |HD| - [16233035] - C:\ProgramData\NortonInstaller
[19/04/2017 16:46:51] - |RASH| - [8] - C:\ProgramData\ntuser.pol
[09/02/2012 17:00:53] - |HD| - [0] - C:\ProgramData\PC Tools
[16/05/2016 18:28:25] - |D| - [251246] - C:\ProgramData\REGSERVO64
[13/07/2009 22:08:56] - |SHD| - [266041] - C:\ProgramData\Start Menu
[01/08/2011 00:30:28] - |HD| - [119] - C:\ProgramData\Sun
[21/01/2012 16:11:09] - |AHD| - [0] - C:\ProgramData\TEMP
[13/07/2009 22:08:56] - |SHD| - [0] - C:\ProgramData\Templates
[01/08/2011 00:33:38] - |D| - [5700352] - C:\ProgramData\Toshiba
[08/01/2013 17:20:32] - |D| - [38] - C:\ProgramData\Toshiba Book Place
[26/12/2011 15:31:24] - |HD| - [0] - C:\ProgramData\VirtualizedApplications
[12/07/2012 10:00:11] - |D| - [35191005] - C:\ProgramData\WebEx
[20/10/2011 10:47:06] - |D| - [2587738222] - C:\ProgramData\WildTangent
[26/01/2012 14:49:39] - |HD| - [1503] - C:\ProgramData\Yahoo!
---------- | C:\ProgramData\Microsoft\Windows\Start Menu
[13/07/2009 22:01:14] - |A| - [1282] - C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
[13/07/2009 21:49:40] - |ASH| - [442] - C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
[13/07/2009 20:20:08] - |RD| - [260984] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs
[01/08/2011 00:39:58] - |A| - [2067] - C:\ProgramData\Microsoft\Windows\Start Menu\Toshiba Book Place.lnk
[13/07/2009 21:49:40] - |A| - [1266] - C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs
[08/09/2015 15:56:58] - |D| - [963] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\9-lab Removal Tool
[13/07/2009 20:20:08] - |RD| - [43590] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
[13/07/2009 22:32:38] - |RD| - [18363] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[01/08/2011 00:32:56] - |A| - [2441] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[13/05/2016 17:34:11] - |A| - [1048] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
[09/09/2015 09:49:35] - |D| - [1951] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
[09/09/2015 09:30:45] - |D| - [933] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[20/10/2011 10:44:01] - |D| - [997] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel Label@Once
[13/07/2009 21:54:23] - |ASH| - [1748] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
[19/01/2012 16:39:11] - |D| - [10205] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus
[02/01/2012 13:46:19] - |D| - [6513] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow
[13/07/2009 22:32:38] - |RD| - [59259] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
[20/10/2011 10:36:03] - |A| - [2206] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[02/01/2012 13:46:25] - |D| - [6121] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
[13/07/2009 20:20:08] - |RD| - [4370] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
[08/09/2015 10:46:46] - |D| - [3724] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[01/08/2011 00:05:58] - |A| - [1345] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[01/08/2011 00:43:51] - |A| - [2435] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010.lnk
[27/12/2011 16:59:01] - |D| - [14924] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)
[01/08/2011 00:34:28] - |D| - [2278] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[20/10/2011 10:21:47] - |D| - [1022] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Netwaiting
[20/10/2011 10:33:28] - |D| - [1664] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetZero
[16/05/2016 18:28:17] - |D| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REGSERVO
[13/07/2009 21:57:08] - |A| - [1330] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[20/10/2011 10:35:24] - |D| - [1672] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[13/07/2009 20:20:08] - |RD| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
[21/11/2010 00:16:41] - |RHD| - [0] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
[01/08/2011 00:31:28] - |D| - [50664] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TOSHIBA
[13/07/2009 21:57:09] - |A| - [1352] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
[01/08/2011 00:05:50] - |A| - [1326] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[13/07/2009 21:54:59] - |A| - [1210] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
[01/08/2011 00:36:18] - |RD| - [4591] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[01/08/2011 00:35:42] - |A| - [1469] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[01/08/2011 00:35:33] - |A| - [2497] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[01/08/2011 00:36:11] - |A| - [1316] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[01/08/2011 00:36:01] - |A| - [1385] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[13/07/2009 21:57:06] - |A| - [1547] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[13/07/2009 21:57:08] - |A| - [1246] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
[03/02/2017 17:52:16] - |D| - [1105] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
---------- | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
[13/07/2009 21:54:23] - |ASH| - [174] - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
---------- | C:\Program Files (x86)
[01/08/2011 00:32:48] - |D| - [470378450] - C:\Program Files (x86)\Adobe
[08/09/2015 11:32:12] - |D| - [0] - C:\Program Files (x86)\Adware Removal Tool by TSA
[20/10/2011 10:18:51] - |D| - [3598306] - C:\Program Files (x86)\Cisco
[13/07/2009 20:20:08] - |D| - [463511913] - C:\Program Files (x86)\Common Files
[20/10/2011 10:21:46] - |D| - [5240840] - C:\Program Files (x86)\Conexant
[20/10/2011 10:44:01] - |D| - [25215938] - C:\Program Files (x86)\Corel
[13/07/2009 21:54:24] - |ASH| - [174] - C:\Program Files (x86)\desktop.ini
[19/01/2012 16:29:18] - |D| - [104819032] - C:\Program Files (x86)\DivX
[02/01/2012 13:46:18] - |D| - [13975902] - C:\Program Files (x86)\ffdshow
[06/02/2012 16:16:53] - |D| - [4158915] - C:\Program Files (x86)\FreeTorrentViewer
[18/01/2012 15:30:05] - |D| - [9726830] - C:\Program Files (x86)\Giraffic
[20/10/2011 10:35:35] - |D| - [545854400] - C:\Program Files (x86)\Google
[02/01/2012 13:46:24] - |D| - [2548909] - C:\Program Files (x86)\Haali
[01/08/2011 00:30:56] - |HD| - [94320865] - C:\Program Files (x86)\InstallShield Installation Information
[20/10/2011 10:05:57] - |D| - [17978039] - C:\Program Files (x86)\Intel
[13/07/2009 20:20:08] - |D| - [5726046] - C:\Program Files (x86)\Internet Explorer
[01/08/2011 00:30:20] - |D| - [90565055] - C:\Program Files (x86)\Java
[08/09/2015 10:46:37] - |D| - [55140333] - C:\Program Files (x86)\Malwarebytes Anti-Malware
[26/12/2011 13:20:10] - |D| - [13000978] - C:\Program Files (x86)\Microsoft Application Virtualization Client
[01/08/2011 00:43:50] - |D| - [6736828] - C:\Program Files (x86)\Microsoft Office
[01/08/2011 00:34:10] - |D| - [38421083] - C:\Program Files (x86)\Microsoft Silverlight
[01/08/2011 00:35:56] - |D| - [1829877] - C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[28/12/2011 14:35:07] - |HD| - [15715] - C:\Program Files (x86)\Microsoft.NET
[13/07/2009 22:32:38] - |D| - [25757] - C:\Program Files (x86)\MSBuild
[02/01/2012 13:46:50] - |D| - [74014] - C:\Program Files (x86)\MTA
[20/10/2011 10:21:46] - |D| - [6143313] - C:\Program Files (x86)\Netwaiting
[20/10/2011 10:31:34] - |D| - [3586292] - C:\Program Files (x86)\Norton PC Checkup
[20/10/2011 10:31:22] - |D| - [8622003] - C:\Program Files (x86)\NortonInstaller
[01/08/2011 00:39:54] - |D| - [1749892] - C:\Program Files (x86)\PlayReady
[20/10/2011 10:20:50] - |D| - [21429910] - C:\Program Files (x86)\Realtek
[20/10/2011 10:18:27] - |D| - [6179835] - C:\Program Files (x86)\Realtek WLAN Driver
[13/07/2009 22:32:38] - |D| - [36929281] - C:\Program Files (x86)\Reference Assemblies
[02/01/2012 13:46:47] - |D| - [2777102] - C:\Program Files (x86)\TDC13E0
[01/08/2011 00:31:57] - |D| - [196326669] - C:\Program Files (x86)\TOSHIBA
[20/10/2011 10:35:24] - |HD| - [0] - C:\Program Files (x86)\TOSHIBA Corporation
[20/10/2011 10:47:06] - |D| - [283105136] - C:\Program Files (x86)\TOSHIBA Games
[20/10/2011 10:32:57] - |D| - [176048] - C:\Program Files (x86)\Toshiba Online Backup
[13/07/2009 21:57:06] - |HD| - [564154] - C:\Program Files (x86)\Uninstall Information
[18/01/2012 15:29:57] - |D| - [46172460] - C:\Program Files (x86)\Veoh Networks
[20/10/2011 10:47:07] - |D| - [9409955] - C:\Program Files (x86)\WildTangent Games
[13/07/2009 22:32:38] - |D| - [512000] - C:\Program Files (x86)\Windows Defender
[01/08/2011 00:35:00] - |D| - [170778514] - C:\Program Files (x86)\Windows Live
[13/07/2009 20:20:08] - |D| - [6115840] - C:\Program Files (x86)\Windows Mail
[13/07/2009 22:32:38] - |D| - [5008657] - C:\Program Files (x86)\Windows Media Player
[13/07/2009 20:20:08] - |D| - [12062388] - C:\Program Files (x86)\Windows NT
[13/07/2009 22:32:38] - |D| - [4394248] - C:\Program Files (x86)\Windows Photo Viewer
[13/07/2009 22:32:38] - |D| - [189952] - C:\Program Files (x86)\Windows Portable Devices
[13/07/2009 22:32:38] - |D| - [6874184] - C:\Program Files (x86)\Windows Sidebar
[26/01/2012 14:49:37] - |D| - [838761] - C:\Program Files (x86)\Yahoo!
[08/09/2015 10:44:23] - |D| - [17599713] - C:\Program Files (x86)\Zemana AntiMalware
[08/05/2012 12:19:44] - |D| - [931010] - C:\Program Files (x86)\Zoola Games
---------- | C:\Program Files
[08/09/2015 15:56:56] - |D| - [18658370] - C:\Program Files\9-lab
[09/09/2015 09:48:06] - |D| - [1046321339] - C:\Program Files\AVAST Software
[09/09/2015 09:30:42] - |D| - [18005864] - C:\Program Files\CCleaner
[13/07/2009 20:20:08] - |D| - [94321288] - C:\Program Files\Common Files
[20/10/2011 10:15:30] - |D| - [70274856] - C:\Program Files\CONEXANT
[13/07/2009 21:54:24] - |ASH| - [174] - C:\Program Files\desktop.ini
[19/01/2012 16:39:08] - |D| - [5953856] - C:\Program Files\DivX
[13/07/2009 22:32:38] - |D| - [90246164] - C:\Program Files\DVD Maker
[20/10/2011 10:36:28] - |D| - [1030824] - C:\Program Files\Google
[13/07/2009 20:20:08] - |D| - [5967646] - C:\Program Files\Internet Explorer
[13/07/2009 22:32:38] - |D| - [148875826] - C:\Program Files\Microsoft Games
[26/12/2011 13:20:10] - |D| - [1584815] - C:\Program Files\Microsoft Office
[13/07/2009 22:32:38] - |D| - [25757] - C:\Program Files\MSBuild
[01/08/2011 00:10:10] - |D| - [2178436] - C:\Program Files\PlayReady
[13/07/2009 22:32:38] - |D| - [34584745] - C:\Program Files\Reference Assemblies
[20/10/2011 10:19:31] - |D| - [37331569] - C:\Program Files\Synaptics
[01/08/2011 00:30:54] - |D| - [1933101011] - C:\Program Files\Toshiba
[13/07/2009 22:09:26] - |HD| - [0] - C:\Program Files\Uninstall Information
[02/01/2012 13:45:56] - |D| - [50332808] - C:\Program Files\Vivitar Experience Image Manager
[13/07/2009 22:32:38] - |D| - [4016640] - C:\Program Files\Windows Defender
[21/11/2010 00:17:02] - |D| - [9212536] - C:\Program Files\Windows Journal
[01/08/2011 00:34:44] - |D| - [7753535] - C:\Program Files\Windows Live
[13/07/2009 20:20:08] - |D| - [6602240] - C:\Program Files\Windows Mail
[13/07/2009 22:32:38] - |D| - [7665069] - C:\Program Files\Windows Media Player
[13/07/2009 20:20:08] - |D| - [12492468] - C:\Program Files\Windows NT
[13/07/2009 22:32:38] - |D| - [5492504] - C:\Program Files\Windows Photo Viewer
[13/07/2009 22:32:38] - |D| - [244736] - C:\Program Files\Windows Portable Devices
[13/07/2009 22:32:38] - |D| - [8116131] - C:\Program Files\Windows Sidebar
---------- | C:\Program Files (x86)\Common Files
[01/08/2011 00:32:48] - |D| - [18841090] - C:\Program Files (x86)\Common Files\Adobe
[01/08/2011 00:33:21] - |D| - [31116142] - C:\Program Files (x86)\Common Files\Adobe AIR
[03/12/2015 16:34:21] - |D| - [963111] - C:\Program Files (x86)\Common Files\AV
[26/12/2011 13:20:10] - |D| - [99136] - C:\Program Files (x86)\Common Files\DESIGNER
[19/01/2012 16:39:04] - |D| - [24726272] - C:\Program Files (x86)\Common Files\DivX Shared
[01/08/2011 00:30:49] - |D| - [5261706] - C:\Program Files (x86)\Common Files\InstallShield
[20/10/2011 10:08:53] - |D| - [14245009] - C:\Program Files (x86)\Common Files\Intel
[01/08/2011 00:30:28] - |D| - [1252295] - C:\Program Files (x86)\Common Files\Java
[13/07/2009 20:20:08] - |D| - [39193909] - C:\Program Files (x86)\Common Files\microsoft shared
[28/04/2013 16:36:45] - |D| - [651776] - C:\Program Files (x86)\Common Files\MSSoap
[21/01/2012 16:11:10] - |D| - [50303] - C:\Program Files (x86)\Common Files\PC Tools
[20/10/2011 10:07:44] - |D| - [162236] - C:\Program Files (x86)\Common Files\postureAgent
[19/01/2012 16:39:21] - |D| - [4740928] - C:\Program Files (x86)\Common Files\PX Storage Engine
[13/07/2009 20:20:08] - |D| - [2702] - C:\Program Files (x86)\Common Files\Services
[13/07/2009 20:20:08] - |D| - [41103783] - C:\Program Files (x86)\Common Files\SpeechEngines
[13/07/2009 20:20:08] - |D| - [10195955] - C:\Program Files (x86)\Common Files\System
[20/10/2011 11:02:57] - |D| - [3192600] - C:\Program Files (x86)\Common Files\Toshiba Shared
[20/10/2011 10:44:01] - |D| - [8534480] - C:\Program Files (x86)\Common Files\Ulead Systems
[02/04/2012 17:22:26] - |D| - [1123719] - C:\Program Files (x86)\Common Files\WebM Project
[01/08/2011 00:33:59] - |D| - [258054761] - C:\Program Files (x86)\Common Files\Windows Live
---------- | C:\Program Files\Common files
[03/12/2015 16:34:21] - |D| - [963111] - C:\Program Files\Common files\AV
[20/10/2011 10:08:53] - |D| - [15717214] - C:\Program Files\Common files\Intel
[13/07/2009 20:20:08] - |D| - [63583018] - C:\Program Files\Common files\Microsoft Shared
[13/07/2009 20:20:08] - |D| - [2702] - C:\Program Files\Common files\Services
[13/07/2009 20:20:08] - |D| - [608768] - C:\Program Files\Common files\SpeechEngines
[13/07/2009 20:20:08] - |D| - [12145651] - C:\Program Files\Common files\System
[20/10/2011 10:16:16] - |D| - [304472] - C:\Program Files\Common files\Waves Audio Ltd
[02/04/2012 17:22:27] - |D| - [996352] - C:\Program Files\Common files\WebM Project
---------- | Tasks
[MD5.F1A6CD5ADAAB953A6764EA364E17BFB8] - [13/07/2009 22:08:49] - |AH| - [6] - C:\windows\Tasks\SA.DAT
[MD5.F82F0CA6BD7DD454AF4A21A47E8C350C] - [13/07/2009 22:08:49] - |A| - [32628] - C:\windows\Tasks\SCHEDLGU.TXT
[MD5.00000000000000000000000000000000] - [03/12/2015 16:34:22] - |D| - [3860] - C:\windows\System32\Tasks\AVAST Software
[MD5.6A4341978BDCE505CC786FE728644E8C] - [09/09/2015 09:49:05] - |A| - [4180] - C:\windows\System32\Tasks\avast! Emergency Update : C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
[MD5.3B3E3EB66E14C4A359AE144FCF10499F] - [09/09/2015 09:30:45] - |A| - [2790] - C:\windows\System32\Tasks\CCleanerSkipUAC : "C:\Program Files\CCleaner\CCleaner.exe"
[MD5.F485202B5B0AE1A8BDF3DAF1A70E2806] - [20/10/2011 10:35:37] - |A| - [3202] - C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore : C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
[MD5.8EFFB6262442F80BEF9E763AF8E5EF21] - [20/10/2011 10:35:38] - |A| - [3330] - C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA : C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
[MD5.00000000000000000000000000000000] - [13/07/2009 20:20:13] - |D| - [266130] - C:\windows\System32\Tasks\Microsoft
[MD5.00000000000000000000000000000000] - [26/12/2011 13:20:21] - |D| - [4392] - C:\windows\System32\Tasks\OfficeSoftwareProtectionPlatform
[MD5.9F2748EEF770B6B41FB1F829AF0309C0] - [13/05/2016 17:34:12] - |A| - [3890] - C:\windows\System32\Tasks\SafeZone scheduled Autoupdate 1463186051 : C:\Program Files\AVAST Software\SZBrowser\launcher.exe
[MD5.00000000000000000000000000000000] - [13/07/2009 22:09:57] - |D| - [4478] - C:\windows\System32\Tasks\WPD
[MD5.4373602E4B403E709ED33FF9D8046399] - [17/05/2016 17:50:33] - |A| - [3032] - C:\windows\System32\Tasks\{1426D1E5-5A00-4D59-985A-2107F1BEF83C} : C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE
[MD5.9516A6365318001C284BCA25D7A8F49D] - [07/02/2016 12:27:13] - |A| - [2982] - C:\windows\System32\Tasks\{2FB9F27A-DE3A-4CD6-B8B6-B233E63B6955} : C:\Program Files (x86)\Microsoft Office\Options14\MSOO.EXE
[MD5.F1B09D09062AA3EE08655972D34F12EF] - [10/02/2016 16:37:55] - |A| - [3294] - C:\windows\System32\Tasks\{65C76270-92BA-4F63-B82C-13F0D18DD623} : C:\windows\system32\pcalua.exe
[MD5.9516A6365318001C284BCA25D7A8F49D] - [07/02/2016 12:27:22] - |A| - [2982] - C:\windows\System32\Tasks\{A8D2B036-36FC-403B-8061-05969D1469A2} : C:\Program Files (x86)\Microsoft Office\Options14\MSOO.EXE
[MD5.4373602E4B403E709ED33FF9D8046399] - [17/05/2016 17:50:50] - |A| - [3032] - C:\windows\System32\Tasks\{E210F47C-43C1-4A1F-B297-CCB4BE5B7E4D} : C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE
[MD5.00000000000000000000000000000000] - [13/07/2009 20:20:14] - |HD| - [0] - C:\windows\Syswow64\Tasks\Microsoft
---------- | Firewall
[HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules]
"Netlogon-NamedPipe-In"=v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|LPort=445|App=System|Name=@netlogon.dll,-1003|Desc=@netlogon.dll,-1006|EmbedCtxt=@netlogon.dll,-1010|
---------- | Control\Class
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{03F52937-1FD6-44FB-82C6-FE988F1B1D61}] : (kphpwaqu) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{0475BB51-5A02-4EE0-B36C-29040FAD2650}] : (igfx) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{04A83FC2-2AE2-4C88-B45F-E9707B377636}] : (aswHwid) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{1264760F-A5C8-4BFE-B314-D56A7B44A362}] : (DXGKrnl) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{24A0C840-2C3D-4410-8236-8B40816C7B90}] : (aswVmm) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{25DBCE51-6C8F-4A72-8A6D-B54C2B4FC835}] : (WCEUSBS) [] -> @%SystemRoot%\System32\SysClass.Dll,-3026
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{36FC9E60-C465-11CF-8056-444553540000}] : (USB) [] -> @%SystemRoot%\System32\SysClass.Dll,-3025
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4116F60B-25B3-4662-B732-99A6111EDC0B}] : (IPMIDRV) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{43675D81-502A-4A82-9F84-B75F418C5DEA}] : (Media Center Extender) [] -> @%SystemRoot%\system32\McxDriv.dll,-100
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4658EE7E-F050-11D1-B6BD-00C04FA372A7}] : (PnpPrinters) [] -> @%systemroot%\system32\ntprint.dll,-1300
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{48721B56-6795-11D2-B1A8-0080C72E74A2}] : (Dot4) [] -> @%SystemRoot%\system32\sysclass.dll,-3023
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{49CE6AC8-6F86-11D2-B1E5-0080C72E74A2}] : (Dot4Print) [] -> @%SystemRoot%\system32\sysclass.dll,-3024
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}] : (CDROM) [] -> @%SystemRoot%\System32\StorProp.dll,-17001
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E966-E325-11CE-BFC1-08002BE10318}] : (Computer) [] -> @%SystemRoot%\System32\SysClass.dll,-3000
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}] : (DiskDrive) [] -> @%SystemRoot%\System32\StorProp.dll,-17000
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}] : (Display) [] -> @DispCI.dll,-3100
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E969-E325-11CE-BFC1-08002BE10318}] : (fdc) [] -> @%SystemRoot%\System32\SysClass.Dll,-3013
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}] : (hdc) [] -> @%SystemRoot%\System32\SysClass.Dll,-3001
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}] : (Keyboard) [] -> @%SystemRoot%\System32\SysClass.Dll,-3002
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96C-E325-11CE-BFC1-08002BE10318}] : (MEDIA) [] -> @mmci.dll,-3000
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}] : (Modem) [] -> @%SystemRoot%\System32\mdminst.dll,-14100
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96E-E325-11CE-BFC1-08002BE10318}] : (Monitor) [] -> @Montr_CI.dll,-3100
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96F-E325-11CE-BFC1-08002BE10318}] : (Mouse) [] -> @%SystemRoot%\System32\SysClass.Dll,-3004
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E970-E325-11CE-BFC1-08002BE10318}] : (MTD) [] -> @SysClass.Dll,-3021
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E971-E325-11CE-BFC1-08002BE10318}] : (MultiFunction) [] -> @%SystemRoot%\System32\SysClass.Dll,-3014
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}] : (Net) [] -> @NetCfgx.dll,-1502
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E973-E325-11CE-BFC1-08002BE10318}] : (NetClient) [] -> @NetCfgx.dll,-1504
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E974-E325-11CE-BFC1-08002BE10318}] : (NetService) [] -> @NetCfgx.dll,-1505
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E975-E325-11CE-BFC1-08002BE10318}] : (NetTrans) [] -> @NetCfgx.dll,-1503
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E977-E325-11CE-BFC1-08002BE10318}] : (PCMCIA) [] -> @%SystemRoot%\System32\SysClass.Dll,-3010
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E978-E325-11CE-BFC1-08002BE10318}] : (Ports) [] -> @%SystemRoot%\System32\msports.dll,-10000
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E979-E325-11CE-BFC1-08002BE10318}] : (Printer) [] -> @%systemroot%\system32\ntprint.dll,-1004
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E97B-E325-11CE-BFC1-08002BE10318}] : (SCSIAdapter) [] -> @%SystemRoot%\System32\SysClass.Dll,-3005
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E97D-E325-11CE-BFC1-08002BE10318}] : (System) [] -> @%SystemRoot%\System32\SysClass.Dll,-3008
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E97E-E325-11CE-BFC1-08002BE10318}] : (Unknown) [] -> @%SystemRoot%\System32\SysClass.Dll,-3009
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E980-E325-11CE-BFC1-08002BE10318}] : (FloppyDisk) [] -> @%SystemRoot%\System32\SysClass.Dll,-3015
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{50127DC3-0F36-415E-A6CC-4CB3BE910B65}] : (Processor) [] -> @%SystemRoot%\system32\procinst.dll,-100
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{50906CB8-BA12-11D1-BF5D-0000F805F530}] : (MultiPortSerial) [] -> @%SystemRoot%\system32\sysclass.dll,-3022
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5099944A-F6B9-4057-A056-8C550228544C}] : (Memory) [] -> @%SystemRoot%\System32\SysClass.Dll,-3018
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{50DD5230-BA8A-11D1-BF5D-0000F805F530}] : (SmartCardReader) [] -> @StorProp.dll,-17002
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5175D334-C371-4806-B3BA-71FD53C9258D}] : (Sensor) [] -> @%systemroot%\system32\SensorsCpl.dll,-10000
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{522119B9-1B9A-498A-AC52-148B533EFD50}] : (kphpwaqu) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] : (VolumeSnapshot) [] -> @%SystemRoot%\System32\SysClass.Dll,-3011
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{53D29EF7-377C-4D14-864B-EB3A85769359}] : (BiometricDevice) [] -> @%SystemRoot%\System32\SysClass.DLL,-3028
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{54505F9E-EE66-4F1D-A63B-B853A1759385}] : (SymNetS) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{56EBD688-B772-4181-9610-8633FCEE988D}] : (SymIRON) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{5A46010E-C74B-4CB1-A041-D22759FE9F9C}] : (Sftplay) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}] : (1394) [] -> @%SystemRoot%\System32\SysClass.Dll,-3016
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6BDD1FC5-810F-11D0-BEC7-08002BE2092F}] : (Infrared) [] -> @NetCfgx.dll,-1501
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6BDD1FC6-810F-11D0-BEC7-08002BE2092F}] : (Image) [] -> @%systemroot%\system32\sti_ci.dll,-52
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6D807884-7D21-11CF-801C-08002BE10318}] : (TapeDrive) [] -> @%SystemRoot%\System32\SysClass.Dll,-3006
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{6FAE73B7-B735-4B50-A0DA-0DC2484B1F1A}] : (igfx) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] : (Volume) [] -> @%SystemRoot%\System32\SysClass.Dll,-3007
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{72631E54-78A4-11D0-BCF7-00AA00B7B32A}] : (Battery) [] -> @%SystemRoot%\system32\batt.dll,-100
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] : (HIDClass) [] -> @hid.dll,-101
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{7E0006EA-81A8-4780-B0C8-474E2DBF4D63}] : (IDSVia64) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{7E9CDDE7-C6A8-4A7D-8077-1C7656D98FE5}] : (PGEffect) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{7EBEFBC0-3200-11D2-B4C2-00A0C9697D07}] : (61883) [] -> @%SystemRoot%\System32\SysClass.Dll,-3019
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{87C077B2-3D3B-4156-938A-EA51B451D6C6}] : (kphpwaqu) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{8AE85550-832C-4A9B-81BB-2A49DBEE72B4}] : (aswRvrt) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{8BBD94A0-A150-11D4-A878-0040265B73EE}] : (TosSec) [] -> @oem23.inf,%CLASS_NAME%;TosSec Class
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{8ECC055D-047F-11D1-A537-0000F8753ED1}] : (LegacyDriver) [] -> @%SystemRoot%\System32\SysClass.Dll,-3003
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{990A2BD7-E738-46C7-B26F-1CF8FB9F1391}] : (SmartCard) [] -> @sccls.dll,-300
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{997B5D8D-C442-4F2E-BAF3-9C8E671E9E21}] : (SideShow) [] -> @%systemroot%\system32\AuxiliaryDisplayClassInstaller.dll,-10000
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}] : (SDHost) [] -> @%SystemRoot%\System32\SysClass.Dll,-3012
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{BC103702-DD72-406F-9B28-95C868337B59}] : (Transfer Cable) [] -> @%SystemRoot%\System32\migwiz\migres.dll,-20
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{C06FF265-AE09-48F0-812C-16753D7CBA83}] : (AVC) [] -> @%SystemRoot%\System32\SysClass.Dll,-3027
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{C4A06E97-ED42-47B9-83E1-F12299B286A5}] : (aswRdr) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{C777C165-D422-426D-8EBF-6EAF3FB83ADF}] : (aswNdisFlt) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{CE5939AE-EBDE-11D0-B181-0000F8753EC4}] : (MediumChanger) [] -> @%SystemRoot%\System32\StorProp.dll,-17003
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}] : (SBP2) [] -> @%SystemRoot%\System32\SysClass.Dll,-3017
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{D61CA365-5AF4-4486-998B-9DB4734C6CA3}] : (XnaComposite) [] -> @%SystemRoot%\system32\XInput9_1_0.dll,-1000
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}] : (SecurityDevices) [] -> @%SystemRoot%\System32\SysClass.Dll,-3020
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{DB4F6DDD-9C0E-45E4-9597-78DBBAD0F412}] : (SmartCardFilter) [] -> @sccls.dll,-301
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{E0CBF06C-CD8B-4647-BB8A-263B43F0F974}] : (Bluetooth) [] -> @%SystemRoot%\system32\bthci.dll,-4001
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{EEC5AD98-8080-425F-922A-DABF3DE3F69A}] : (WPD) [] -> @wpd_ci.dll,-101
[HKLM\SYSTEM\CurrentControlSet\Control\Class\{FB58BE68-EA9E-4803-847F-2CE814E7B159}] : (kphpwaqu) [] ->
[HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}] : (Script Detection) [@elscore.dll,-2] -> ElsLad.dll (Copyright (c) Microsoft Corporation.)
[HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}] : (Transliteration) [@elscore.dll,-5] -> elstrans.dll (Copyright (c) Microsoft Corporation.)
[HKLM\SYSTEM\CurrentControlSet\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}] : (Language Detection) [@elscore.dll,-1] -> ElsLad.dll (Copyright (c) Microsoft Corporation.)
---------- | Loaded modules (whitelist)
[14/07/2009 15:31:18] - (2.0.0.3) - (TOSHIBA Corporation - TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver) - C:\windows\system32\DRIVERS\TVALZ_O.SYS
[24/06/2009 15:36:48] - (4.2.0.0) - (TOSHIBA Corporation - tos_sps64) - C:\windows\system32\DRIVERS\tos_sps64.sys
[08/09/2015 10:44:10] - (0.0.0.0) - (Zemana Ltd. - ZAM) - C:\windows\System32\drivers\zamguard64.sys
[08/09/2015 10:44:27] - (0.0.0.0) - (Zemana Ltd. - ZAM) - C:\windows\System32\drivers\zam64.sys
[08/11/2010 12:44:40] - (1.0.0.36) - (Atheros Communications, Inc. - Atheros L1c PCI-E Gigabit Ethernet Controller) - C:\windows\system32\DRIVERS\L1C62x64.sys
[03/02/2011 19:59:06] - (15.2.11.1) - (Synaptics Incorporated - Synaptics Touchpad Driver) - C:\windows\system32\DRIVERS\SynTP.sys
[01/08/2011 00:40:14] - (2.0.0.3) - (TOSHIBA Corporation. - TOSHIBA ODD Writing Driver for x64.) - C:\windows\system32\DRIVERS\tdcmdpst.sys
[15/06/2009 13:58:50] - (2.1.0.0) - (TOSHIBA - Generic IO & Memory Access) - C:\windows\system32\DRIVERS\QIOMem.sys
[19/06/2009 19:15:22] - (1.0.0.2) - (TOSHIBA Corporation - TOSHIBA TVALZ Filter Driver for x64) - C:\windows\system32\DRIVERS\TVALZFL.sys
[07/07/2011 15:02:16] - (8.51.2.0) - (Conexant Systems Inc. - 64-bit High Definition Audio Function Driver) - C:\windows\system32\drivers\CHDRT64.sys
[20/10/2011 10:22:53] - (1.0.17.64) - (TOSHIBA Corporation - TOSHIBA Universal Camera Filter Driver) - C:\windows\system32\DRIVERS\pgeffect.sys
[13/07/2009 19:36:07] - (4.3.86.0) - (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. - Macrovision SECURITY Driver) - C:\windows\System32\Drivers\secdrv.SYS
---------- | Services | 0 : Starting up | 1 : System | 2 : Automatic | 3 : Manual | 4 : Disabled | R : Running service | S : Stopped service
R0 - [Kernel Driver] - ACPI (Microsoft ACPI Driver) -> system32\drivers\ACPI.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - amdxata () -> system32\drivers\amdxata.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - aswRvrt (avast! Revert) -> (?) - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - aswVmm (avast! VM Monitor) -> (?) - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - atapi (IDE Channel) -> system32\drivers\atapi.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - CLFS (@%SystemRoot%\system32\clfs.sys,-100) -> System32\CLFS.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - CNG () -> System32\Drivers\cng.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - Compbatt (Microsoft Composite Battery Driver) -> system32\drivers\compbatt.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - Disk (Disk Driver) -> system32\drivers\disk.sys - AcceptPause: False - AcceptStop: True
R0 - [File System Driver] - FileInfo (@%SystemRoot%\system32\drivers\fileinfo.sys,-100) -> system32\drivers\fileinfo.sys - AcceptPause: False - AcceptStop: True
R0 - [File System Driver] - FltMgr (@%SystemRoot%\system32\drivers\fltmgr.sys,-10001) -> system32\drivers\fltmgr.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - fvevol (@%SystemRoot%\system32\drivers\fvevol.sys,-100) -> System32\DRIVERS\fvevol.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - hwpolicy (@%systemroot%\system32\drivers\hwpolicy.sys,-101) -> System32\drivers\hwpolicy.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - iaStor (Intel AHCI Controller) -> system32\DRIVERS\iaStor.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - KSecDD () -> System32\Drivers\ksecdd.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - KSecPkg () -> System32\Drivers\ksecpkg.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - mountmgr (@%SystemRoot%\system32\drivers\mountmgr.sys,-100) -> System32\drivers\mountmgr.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - msahci () -> system32\DRIVERS\msahci.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - msisadrv () -> system32\drivers\msisadrv.sys - AcceptPause: False - AcceptStop: True
R0 - [File System Driver] - Mup (@%systemroot%\system32\drivers\mup.sys,-101) -> System32\Drivers\mup.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - NDIS (@%SystemRoot%\system32\drivers\ndis.sys,-200) -> system32\drivers\ndis.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - partmgr (@%SystemRoot%\system32\drivers\partmgr.sys,-100) -> System32\drivers\partmgr.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - pci (PCI Bus Driver) -> system32\drivers\pci.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - pciide () -> system32\DRIVERS\pciide.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - pcw (Performance Counters for Windows Driver) -> System32\drivers\pcw.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - rdyboost (ReadyBoost) -> System32\drivers\rdyboost.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - spldr (Security Processor Loader Driver) -> (?) - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - Tcpip (@%SystemRoot%\system32\tcpipcfg.dll,-50003) -> System32\drivers\tcpip.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - tos_sps64 (TOSHIBA tos_sps64 Service) -> system32\DRIVERS\tos_sps64.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - TVALZ (TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver) -> system32\DRIVERS\TVALZ_O.SYS - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - vdrvroot (Microsoft Virtual Drive Enumerator Driver) -> system32\drivers\vdrvroot.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - volmgr (Volume Manager Driver) -> system32\drivers\volmgr.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - volmgrx (@%SystemRoot%\system32\drivers\volmgrx.sys,-100) -> System32\drivers\volmgrx.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - volsnap (Storage volumes) -> system32\drivers\volsnap.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - Wd (Microsoft Watchdog Timer Driver) -> system32\drivers\wd.sys - AcceptPause: False - AcceptStop: True
R0 - [Kernel Driver] - Wdf01000 (Kernel Mode Driver Frameworks service) -> system32\drivers\Wdf01000.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - AFD (@%systemroot%\system32\drivers\afd.sys,-1000) -> \SystemRoot\system32\drivers\afd.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - aswKbd (aswKbd) -> \SystemRoot\system32\drivers\aswKbd.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - aswRdr (aswRdr) -> \SystemRoot\system32\drivers\aswRdr2.sys - AcceptPause: False - AcceptStop: True
R1 - [File System Driver] - aswSnx (aswSnx) -> \SystemRoot\system32\drivers\aswSnx.sys - AcceptPause: False - AcceptStop: True
R1 - [File System Driver] - aswSP (aswSP) -> \SystemRoot\system32\drivers\aswSP.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - Beep (Beep) -> (?) - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - blbdrive () -> system32\DRIVERS\blbdrive.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - cdrom (CD-ROM Driver) -> system32\DRIVERS\cdrom.sys - AcceptPause: False - AcceptStop: True
R1 - [File System Driver] - DfsC (@%systemroot%\system32\drivers\dfsc.sys,-101) -> System32\Drivers\dfsc.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - discache (@%systemroot%\system32\drivers\discache.sys,-102) -> System32\drivers\discache.sys - AcceptPause: False - AcceptStop: True
R1 - [File System Driver] - Msfs () -> (?) - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - mssmbios (Microsoft System Management BIOS Driver) -> system32\DRIVERS\mssmbios.sys - AcceptPause: False - AcceptStop: True
R1 - [File System Driver] - NetBIOS (NetBIOS Interface) -> system32\DRIVERS\netbios.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - NetBT (@%SystemRoot%\system32\drivers\netbt.sys,-2) -> System32\DRIVERS\netbt.sys - AcceptPause: False - AcceptStop: True
R1 - [File System Driver] - Npfs () -> (?) - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - nsiproxy (@%SystemRoot%\system32\drivers\nsiproxy.sys,-2) -> system32\drivers\nsiproxy.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - Null () -> (?) - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - Psched (@%SystemRoot%\System32\drivers\pacer.sys,-101) -> system32\DRIVERS\pacer.sys - AcceptPause: False - AcceptStop: True
R1 - [File System Driver] - rdbss (@%systemroot%\system32\wkssvc.dll,-1000) -> system32\DRIVERS\rdbss.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - RDPCDD (@%systemroot%\system32\DRIVERS\RDPCDD.sys,-100) -> System32\DRIVERS\RDPCDD.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - RDPENCDD (@%systemroot%\system32\drivers\RDPENCDD.sys,-101) -> system32\drivers\rdpencdd.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - RDPREFMP (@%systemroot%\system32\drivers\RdpRefMp.sys,-101) -> system32\drivers\rdprefmp.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - tdx (@%SystemRoot%\system32\tcpipcfg.dll,-50004) -> system32\DRIVERS\tdx.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - TermDD (Terminal Device Driver) -> system32\DRIVERS\termdd.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - VgaSave () -> \SystemRoot\System32\drivers\vga.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - vwififlt (Virtual WiFi Filter Driver) -> system32\DRIVERS\vwififlt.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - Wanarpv6 (@%systemroot%\system32\rascfg.dll,-32012) -> system32\DRIVERS\wanarp.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - WfpLwf (WFP Lightweight Filter) -> system32\DRIVERS\wfplwf.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - ZAM (ZAM Helper Driver) -> \??\C:\windows\System32\drivers\zam64.sys - AcceptPause: False - AcceptStop: True
R1 - [Kernel Driver] - ZAM_Guard (ZAM Guard Driver) -> \??\C:\windows\System32\drivers\zamguard64.sys - AcceptPause: False - AcceptStop: True
R2 - [Kernel Driver] - aswHwid (avast! HardwareID) -> \SystemRoot\system32\drivers\aswHwid.sys - AcceptPause: False - AcceptStop: True
R2 - [File System Driver] - aswMonFlt (aswMonFlt) -> \SystemRoot\system32\drivers\aswMonFlt.sys - AcceptPause: False - AcceptStop: True
S2 - [Kernel Driver] - aswStm (aswStm) -> \SystemRoot\system32\drivers\aswStm.sys - AcceptPause: False - AcceptStop: False
R2 - [Kernel Driver] - lltdio (Link-Layer Topology Discovery Mapper I/O Driver) -> system32\DRIVERS\lltdio.sys - AcceptPause: False - AcceptStop: True
R2 - [File System Driver] - luafv (@%systemroot%\system32\drivers\luafv.sys,-100) -> \SystemRoot\system32\drivers\luafv.sys - AcceptPause: False - AcceptStop: True
R2 - [Kernel Driver] - PEAUTH (PEAUTH) -> system32\drivers\peauth.sys - AcceptPause: False - AcceptStop: True
R2 - [Kernel Driver] - rspndr (Link-Layer Topology Discovery Responder) -> system32\DRIVERS\rspndr.sys - AcceptPause: False - AcceptStop: True
R2 - [Kernel Driver] - secdrv (Security Driver) -> (?) - AcceptPause: False - AcceptStop: True
R2 - [Kernel Driver] - tcpipreg (TCP/IP Registry Compatibility) -> System32\drivers\tcpipreg.sys - AcceptPause: False - AcceptStop: True
R2 - [Kernel Driver] - TVALZFL (TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver) -> system32\DRIVERS\TVALZFL.sys - AcceptPause: False - AcceptStop: True
---------- | System files (Microsoft Files whitelisted)
[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - [10/06/2009 13:36:24] - (.Copyright © 2006 Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) - [479.58 Ko] - (1.6.6.4) - C:\windows\System32\Drivers\adp94xx.sys
[MD5.597F78224EE9224EA1A13D6350CED962] - [13/07/2009 14:59:32] - (.Copyright © 2006 Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) - [331.58 Ko] - (1.6.6.1) - C:\windows\System32\Drivers\adpahci.sys
[MD5.E109549C90F62FB570B9540C4B148E54] - [13/07/2009 14:59:33] - (.Copyright © 2003 Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) - [178.58 Ko] - (7.2.0.0) - C:\windows\System32\Drivers\adpu320.sys
[MD5.5812713A477A3AD7363C7438CA2EE038] - [13/07/2009 16:19:47] - (.Copyright (C) Acer Laboratories Inc. 2000 - ALi mini IDE Driver.) - [15.08 Ko] - (1.2.0.0) - C:\windows\System32\Drivers\aliide.sys
[MD5.1FF8B4431C353CE385C875F194924C0C] - [13/07/2009 16:19:49] - (.Copyright (C) AMD 2003 - AMD IDE Driver.) - [15.08 Ko] - (6.1.7600.16385) - C:\windows\System32\Drivers\amdide.sys
[MD5.D4121AE6D0C0E7E13AA221AA57EF2D49] - [01/08/2011 00:11:51] - (.Copyright © 2008-2010 AMD, Inc. - AHCI 1.2 Device Driver.) - [105.38 Ko] - (1.1.2.5) - C:\windows\System32\Drivers\amdsata.sys
[MD5.F67F933E79241ED32FF46A4F29B5120B] - [10/06/2009 13:37:35] - (.2008 Advanced Micro Devices, Inc. - AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform.) - [189.58 Ko] - (3.6.1540.127) - C:\windows\System32\Drivers\amdsbs.sys
[MD5.540DAF1CEA6094886D72126FD7C33048] - [01/08/2011 00:11:51] - (.Copyright © 2008-2010 AMD, Inc. - Storage Filter Driver.) - [26.38 Ko] - (1.1.2.5) - C:\windows\System32\Drivers\amdxata.sys
[MD5.C484F8CEB1717C540242531DB7845C4E] - [13/07/2009 14:59:33] - (.Copyright 2007 Adaptec, Inc. - Adaptec RAID Storport Driver.) - [85.58 Ko] - (5.2.0.10384) - C:\windows\System32\Drivers\arc.sys
[MD5.019AF6924AEFE7839F61C830227FE79C] - [13/07/2009 14:59:33] - (.Copyright 2008 Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) - [95.56 Ko] - (5.2.0.16119) - C:\windows\System32\Drivers\arcsas.sys
[MD5.A629E4799D4CD6361D1B5D573EA5C2CD] - [09/09/2015 09:48:38] - (.Copyright (c) 2014 AVAST Software - avast! HWID.) - [36.77 Ko] - (12.1.3076.0) - C:\windows\System32\Drivers\aswHwid.sys
[MD5.97F952A9050CAD88681F5F0F46B8D5A5] - [13/05/2016 10:00:49] - (.Copyright (c) 2014 AVAST Software - avast! Keyboard Filter Driver.) - [36.27 Ko] - (12.1.3076.0) - C:\windows\System32\Drivers\aswKbd.sys
[MD5.9C6C17C495E960E52EDE5D038EE92AE1] - [09/09/2015 09:48:39] - (.Copyright (c) 2014 AVAST Software - avast! File System Minifilter for Windows 2003/Vista.) - [105.77 Ko] - (12.1.3076.0) - C:\windows\System32\Drivers\aswMonFlt.sys
[MD5.8F492911129B1B32818BF894DC0C2C73] - [09/09/2015 09:48:38] - (.Copyright (c) 2014 AVAST Software - avast! WFP Redirect Driver.) - [100.65 Ko] - (12.1.3076.0) - C:\windows\System32\Drivers\aswRdr2.sys
[MD5.4ABDD84A67378E866BC15DDC9916BA71] - [09/09/2015 09:48:39] - (.Copyright (c) 2014 AVAST Software - avast! Revert.) - [72.8 Ko] - (12.1.3076.0) - C:\windows\System32\Drivers\aswRvrt.sys
[MD5.409CDD1400B404F655EEC1B5850FD3BE] - [09/09/2015 09:48:36] - (.Copyright (c) 2014 AVAST Software - avast! Virtualization Driver.) - [1045.8 Ko] - (12.1.3076.0) - C:\windows\System32\Drivers\aswSnx.sys
[MD5.CDB1BE967AFF65D8395B6DF2EA8CBCCF] - [09/09/2015 09:48:39] - (.Copyright (c) 2014 AVAST Software - avast! self protection module.) - [462.49 Ko] - (12.1.3076.7) - C:\windows\System32\Drivers\aswsp.sys
[MD5.F6B5E463A0BB934C26FB319EDC726F65] - [09/09/2015 09:48:41] - (.Copyright (c) 2014 AVAST Software - Stream Filter.) - [159.09 Ko] - (12.1.3076.0) - C:\windows\System32\Drivers\aswStm.sys
[MD5.FE0EE5CA72BC0D41DCAAFCA70B78274B] - [09/09/2015 09:48:41] - (.Copyright (c) 2014 AVAST Software - avast! VM Monitor.) - [285.84 Ko] - (12.1.3076.11) - C:\windows\System32\Drivers\aswvmm.sys
[MD5.B5ACE6968304A3900EEB1EBFD9622DF2] - [10/06/2009 13:34:23] - (.Copyright 2000-2008, Broadcom Corporation. - Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver..) - [264.5 Ko] - (10.100.4.0) - C:\windows\System32\Drivers\b57nd60a.sys
[MD5.F09EEE9EDC320B5E1501F749FDE686C8] - [13/07/2009 18:19:59] - (.Copyright (C) Brother Industries, Ltd. 2001-2003 - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) - [18 Ko] - (1.10.0.2) - C:\windows\System32\Drivers\BrFiltLo.sys
[MD5.B114D3098E9BDB8BEA8B053685831BE6] - [13/07/2009 18:20:21] - (.Copyright (C) Brother Industries, Ltd. 2001 - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) - [8.5 Ko] - (1.4.0.1) - C:\windows\System32\Drivers\BrFiltUp.sys
[MD5.43BEA8D483BF1870F018E2D02E06A5BD] - [13/07/2009 18:19:06] - (.Copyright (C) Brother Industries Ltd.1997-2006 - Brotehr Serial I/F Driver (WDM).) - [280 Ko] - (1.0.1.6) - C:\windows\System32\Drivers\BrSerId.sys
[MD5.A6ECA2151B08A09CACECA35C07F05B42] - [13/07/2009 18:20:11] - (.Copyright (C) Brother Industries Ltd.1997-2003 - Brother Serial driver (WDM version).) - [46 Ko] - (1.0.0.20) - C:\windows\System32\Drivers\BrSerWdm.sys
[MD5.B79968002C277E869CF38BD22CD61524] - [13/07/2009 18:20:26] - (.Copyright(C)Brother Industries Ltd.1997-2006 - Brother USB MDM Driver.) - [14.63 Ko] - (1.0.0.12) - C:\windows\System32\Drivers\BrUsbMdm.sys
[MD5.A87528880231C54E75EA7A44943B38BF] - [13/07/2009 18:20:15] - (.Copyright(C)Brother Industries Ltd.1997-2006 - Brother USB Serial Driver.) - [14.38 Ko] - (1.0.1.3) - C:\windows\System32\Drivers\BrUsbSer.sys
[MD5.3E5B191307609F7514148C6832BB0842] - [10/06/2009 13:34:28] - (.(c) COPYRIGHT 2001-2008 Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) - [457.5 Ko] - (4.8.2.0) - C:\windows\System32\Drivers\bxvbda.sys
[MD5.20506F12AFAD3DB588D007EA9325FBBC] - [07/07/2011 15:02:16] - (.© Conexant Systems Inc. - 64-bit High Definition Audio Function Driver.) - [1539.63 Ko] - (8.51.2.0) - C:\windows\System32\Drivers\CHDRT64.sys
[MD5.E19D3F095812725D88F9001985B94EDD] - [13/07/2009 16:19:48] - (.Copyright (C) CMD Technology, Inc. 1999-2000 - CMD PCI IDE Bus Driver.) - [17.08 Ko] - (2.0.7.0) - C:\windows\System32\Drivers\cmdide.sys
[MD5.0E5DA5369A0FCAEA12456DD852545184] - [10/06/2009 13:36:49] - (.Copyright © 2003-2009 Emulex - Storport Miniport Driver for LightPulse HBAs.) - [518.06 Ko] - (7.2.10.211) - C:\windows\System32\Drivers\elxstor.sys
[MD5.DC5D737F51BE844D8C82C695EB17372F] - [10/06/2009 13:34:33] - (.(c) COPYRIGHT 2001-2008 Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) - [3209 Ko] - (4.8.13.0) - C:\windows\System32\Drivers\evbda.sys
[MD5.915E4E1E21CBFC4CB2415CD34C72800C] - [26/12/2011 12:57:17] - (.-.) - [0.01 Ko] - (0.0.0.0) - C:\windows\System32\Drivers\fbd.sys
[MD5.F2523EF6460FC42405B12248338AB2F0] - [13/07/2009 15:53:43] - (.Copyright ©2007-2009 Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) - [30.5 Ko] - (1.31.27127.0) - C:\windows\System32\Drivers\hcw85cir.sys
[MD5.A6518DCC42F7A6E999BB3BEA8FD87567] - [19/10/2010 16:34:26] - (.Copyright © 2006-2010, Intel Corporation. - Intel(R) Management Engine Interface.) - [55.02 Ko] - (7.0.0.1144) - C:\windows\System32\Drivers\HECIx64.sys
[MD5.39D2ABCD392F3D8A6DCE7B60AE7B8EFC] - [20/11/2010 20:23:47] - (.Copyright (c) 2004-2010 Hewlett-Packard Development Company, L.P. - Smart Array SAS/SATA Controller Media Driver.) - [76.88 Ko] - (6.12.6.64) - C:\windows\System32\Drivers\HpSAMD.sys
[MD5.D469B77687E12FE43E344806740B624D] - [20/10/2011 10:11:10] - (.Copyright(C) Intel Corporation 1994-2011 - Intel Rapid Storage Technology driver - x64.) - [429.02 Ko] - (10.1.2.1004) - C:\windows\System32\Drivers\iaStor.sys
[MD5.AAAF44DB3BD0B9D1FB6969B23ECC8366] - [01/08/2011 00:11:50] - (.Copyright(C) Intel Corporation 1994-2008 - Intel Matrix Storage Manager driver - x64.) - [400.88 Ko] - (8.6.2.1014) - C:\windows\System32\Drivers\iaStorV.sys
[MD5.370C2A8629B30F910F740387795DDC6F] - [04/04/2011 20:10:14] - (.Copyright (c) 1998-2006 Intel Corporation. - Intel Graphics Kernel Mode Driver.) - [11975.22 Ko] - (8.15.10.2353) - C:\windows\System32\Drivers\igdkmd64.sys
[MD5.5C18831C61933628F5BB0EA2675B9D21] - [13/07/2009 14:59:33] - (.Copyright © 2002-05 Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) - [43.08 Ko] - (5.4.22.0) - C:\windows\System32\Drivers\iirsp.sys
[MD5.FC727061C0F47C8059E88E05D5C8E381] - [15/10/2010 01:28:16] - (.Intel(R) Corporation. - Intel(R) Display Audio Driver.) - [310 Ko] - (6.14.0.3074) - C:\windows\System32\Drivers\IntcDAud.sys
[MD5.CD91D1BD200D9F39682A08E987F0DBE2] - [02/01/2012 13:46:49] - (.Copyright (C) 2007 Jeilin Corporation - Universal Serial Bus Camera Driver.) - [78.98 Ko] - (6.0.6000.16386) - C:\windows\System32\Drivers\jl2005c.sys
[MD5.EBED8B3FF4A823C1A6EEBEED7B29353F] - [08/11/2010 12:44:40] - (.2001-2010 Atheros Communications, Inc. - Atheros L1c PCI-E Gigabit Ethernet Controller.) - [75.11 Ko] - (1.0.0.36) - C:\windows\System32\Drivers\L1C62x64.sys
[MD5.1A93E54EB0ECE102495A51266DCDB6A6] - [13/07/2009 14:59:34] - (.Copyright © LSI Corporation 2008 - LSI Fusion-MPT FC Driver (StorPort).) - [112.06 Ko] - (1.28.3.52) - C:\windows\System32\Drivers\lsi_fc.sys
[MD5.1047184A9FDC8BDBFF857175875EE810] - [13/07/2009 14:59:33] - (.Copyright © LSI Corporation 2008 - LSI Fusion-MPT SAS Driver (StorPort).) - [104.06 Ko] - (1.28.3.52) - C:\windows\System32\Drivers\lsi_sas.sys
[MD5.30F5C0DE1EE8B5BC9306C1F0E4A75F93] - [13/07/2009 14:59:34] - (.Copyright © LSI Corporation 2009 - LSI SAS Gen2 Driver (StorPort).) - [64.06 Ko] - (2.0.2.71) - C:\windows\System32\Drivers\lsi_sas2.sys
[MD5.0504EACAFF0D3C8AED161C4B0D369D4A] - [13/07/2009 14:59:33] - (.Copyright © LSI Corporation 2008 - LSI Fusion-MPT SCSI Driver (StorPort).) - [113.06 Ko] - (1.28.3.67) - C:\windows\System32\Drivers\lsi_scsi.sys
[MD5.A8D28D5B3E2A528D1EF0E338E44F2820] - [08/09/2015 10:46:37] - (.© Malwarebytes Corporation. - Malwarebytes Anti-Malware.) - [25.21 Ko] - (0.1.15.0) - C:\windows\System32\Drivers\mbam.sys
[MD5.47701ECA633574E122687693B5C5D35C] - [08/09/2015 10:46:37] - (.© Malwarebytes. - Malwarebytes Chameleon Protection Driver.) - [106.71 Ko] - (1.1.21.0) - C:\windows\System32\Drivers\mbamchameleon.sys
[MD5.89DECC6E34AE28029BFC9C4EF186FC46] - [08/09/2015 10:47:01] - (.© Malwarebytes. - Malwarebytes Anti-Malware.) - [190.21 Ko] - (0.3.0.4) - C:\windows\System32\Drivers\MBAMSwissArmy.sys
[MD5.A55805F747C6EDB6A9080D7C633BD0F4] - [10/06/2009 13:37:14] - (.Copyright © LSI Corporation - MEGASAS RAID Controller Driver for Windows 7\Server 2008 R2 for x64.) - [34.56 Ko] - (4.5.1.64) - C:\windows\System32\Drivers\megasas.sys
[MD5.BAF74CE0072480C3B6B7C13B2A94D6B3] - [13/07/2009 14:59:33] - (.Copyright (C) 2007 LSI Corporation. - LSI MegaRAID Software RAID Driver.) - [278.06 Ko] - (13.5.409.2009) - C:\windows\System32\Drivers\MegaSR.sys
[MD5.AE757332EA130E94E646621CC695B52A] - [08/09/2015 10:46:37] - (.© Malwarebytes Corporation. - Malwarebytes Web Access Control.) - [62.21 Ko] - (1.0.6.0) - C:\windows\System32\Drivers\mwac.sys
[MD5.77889813BE4D166CDAB78DDBA990DA92] - [13/07/2009 14:59:33] - (.(C) Copyright IBM Corp. 1994, 2002. - IBM ServeRAID Controller Driver.) - [50.06 Ko] - (7.10.0.0) - C:\windows\System32\Drivers\nfrd960.sys
[MD5.0A92CB65770442ED0DC44834632F66AD] - [01/08/2011 00:11:50] - (.Copyright(C) 2001-2010 NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) - [144.88 Ko] - (10.6.0.18) - C:\windows\System32\Drivers\nvraid.sys
[MD5.DAB0E87525C10052BF65F06152F37E4A] - [01/08/2011 00:11:50] - (.Copyright(C) 2001-2010 NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) - [162.38 Ko] - (10.6.0.18) - C:\windows\System32\Drivers\nvstor.sys
[MD5.91111CEBBDE8015E822C46120ED9537C] - [20/10/2011 10:22:53] - (.Copyright (c) TOSHIBA Corporation. - TOSHIBA Universal Camera Filter Driver.) - [37.2 Ko] - (1.0.17.64) - C:\windows\System32\Drivers\PGEffect.sys
[MD5.C8FCB4899F8B70CC34E0D9876A80963C] - [15/06/2009 13:58:50] - (.Copyright(C) 2009-2016 TOSHIBA. - Generic IO & Memory Access.) - [12.5 Ko] - (2.1.0.0) - C:\windows\System32\Drivers\QIOMem.sys
[MD5.A53A15A11EBFD21077463EE2C7AFEEF0] - [10/06/2009 13:37:36] - (.Copyright © QLogic Corporation 1996-2009 - QLogic Fibre Channel Stor Miniport Driver.) - [1489.08 Ko] - (9.1.8.6) - C:\windows\System32\Drivers\ql2300.sys
[MD5.4F6D12B51DE1AAEFF7DC58C4D75423C8] - [13/07/2009 14:59:34] - (.© QLogic Corporation. - QLogic iSCSI Storport Miniport Driver.) - [125.58 Ko] - (2.1.3.20) - C:\windows\System32\Drivers\ql40xx.sys
[MD5.80E356E8BA267DB92DCA373CB4EE11C9] - [20/10/2011 10:20:50] - (.Realtek Semiconductor Corp. - Realtek Turbo Mode Filter Driver for 39.) - [17.6 Ko] - (1.0.2.0) - C:\windows\System32\Drivers\rtcrfilt64.sys
[MD5.945AB249D12CBE044782430C6013AA1A] - [20/10/2011 10:18:27] - (.Copyright (C) 2010 Realtek Semiconductor Corporation - Realtek RTL8187B NDIS Driver.) - [439.5 Ko] - (62.1182.331.2010) - C:\windows\System32\Drivers\rtl8187B.sys
[MD5.F79E887762D9A0C3FDE5D188DCA5BB26] - [20/10/2011 10:18:27] - (.Copyright (C) 2010 Realtek Semiconductor Corporation - Realtek RTL8187S PCIE NDIS Driverr.) - [432 Ko] - (6.9110.401.2010) - C:\windows\System32\Drivers\rtl8187Se.sys
[MD5.64FDF4FE366CA42DA2B7D9D424B6E39B] - [20/10/2011 10:18:27] - (.Copyright (C) 2006 Realtek Semiconductor Corporation - Realtek RTL81892CE NDIS Driverr.) - [1083.1 Ko] - (1005.12.105.2011) - C:\windows\System32\Drivers\rtl8192ce.sys
[MD5.2882E3DE7FA60CEDC208A0D9C506C9E1] - [20/10/2011 10:18:27] - (.Copyright (C) 2006 Realtek Semiconductor Corporation - Realtek RTL81892SE NDIS Driverr.) - [1192.6 Ko] - (2019.2.1217.2010) - C:\windows\System32\Drivers\rtl8192se.sys
[MD5.689E5A7993643E216CB553930990DE23] - [20/10/2011 10:18:27] - (.Copyright (C) 2006 Realtek Semiconductor Corporation - Realtek RTL819xP NDIS Driverr.) - [612.1 Ko] - (2002.0.1222.2010) - C:\windows\System32\Drivers\rtl819xp.sys
[MD5.135A64530D7699AD48F29D73A658DD11] - [20/10/2011 10:20:50] - (.Copyright (C) Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/Vista/Win7.) - [245.1 Ko] - (6.1.7600.30127) - C:\windows\System32\Drivers\RtsUStor.sys
[MD5.E5DC911D0FEB72CAFF2BBDD6E7C3672F] - [20/10/2011 10:20:50] - (.Copyright (C) Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/Vista/Win7.) - [300.1 Ko] - (6.1.7600.10008) - C:\windows\System32\Drivers\rtsuvstor.sys
[MD5.3EA8A16169C26AFBEB544E0E48421186] - [13/07/2009 19:36:07] - (.© 2006 Macrovision Corporation - Macrovision SECURITY Driver.) - [22.5 Ko] - (4.3.86.0) - C:\windows\System32\Drivers\secdrv.sys
[MD5.843CAF1E5FDE1FFD5FF768F23A51E2E1] - [10/06/2009 13:37:40] - (.Copyright (c) SiS Corp. 2000-2010 - SiS RAID Stor Miniport Driver.) - [42.56 Ko] - (5.1.1039.2600) - C:\windows\System32\Drivers\sisraid2.sys
[MD5.6A6C106D42E9FFFF8B9FCB4F754F6DA4] - [13/07/2009 14:59:33] - (.Copyright (c) SiS Corp. 2007-2013 - SiS AHCI Stor-Miniport Driver.) - [78.58 Ko] - (5.1.1039.3600) - C:\windows\System32\Drivers\sisraid4.sys
[MD5.1D8F61346A123CC5CDE7E2AABB7DFEE0] - [30/08/2016 16:15:58] - (.-.) - [43.9 Ko] - (8.0.4624.2183) - C:\windows\System32\Drivers\staport.sys
[MD5.F3817967ED533D08327DC73BC4D5542A] - [13/07/2009 14:59:33] - (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) - [24.08 Ko] - (5.0.1.1) - C:\windows\System32\Drivers\stexstor.sys
[MD5.F5B46DF59FEAA48A442AED7EEB754D4B] - [03/02/2011 19:59:06] - (.Copyright (C) Synaptics Incorporated 1996-2011 - Synaptics Touchpad Driver.) - [1380.55 Ko] - (15.2.11.1) - C:\windows\System32\Drivers\SynTP.sys
[MD5.FD542B661BD22FA69CA789AD0AC58C29] - [01/08/2011 00:40:14] - (.Copyright (C) 2007-2009 TOSHIBA Corporation. - TOSHIBA ODD Writing Driver for x64..) - [27.13 Ko] - (2.0.0.3) - C:\windows\System32\Drivers\tdcmdpst.sys
[MD5.09FF7B0B1B5C3D225495CB6F5A9B39F8] - [24/06/2009 15:36:48] - (.Copyright (C) TOSHIBA Corporation 2000-2009 - tos_sps64.) - [471.08 Ko] - (4.2.0.0) - C:\windows\System32\Drivers\tos_sps64.sys
[MD5.9C7191F4B2E49BFF47A6C1144B5923FA] - [19/06/2009 19:15:22] - (.Copyright (C) 2008-2009 TOSHIBA Corporation - TOSHIBA TVALZ Filter Driver for x64.) - [14.13 Ko] - (1.0.0.2) - C:\windows\System32\Drivers\TVALZFL.sys
[MD5.550B567F9364D8F7684C3FB3EA665A72] - [14/07/2009 15:31:18] - (.Copyright (C) 2006-2009 TOSHIBA Corporation - TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver.) - [26.21 Ko] - (2.0.0.3) - C:\windows\System32\Drivers\TVALZ_O.SYS
[MD5.E5689D93FFE4E5D66C0178761240DD54] - [13/07/2009 16:19:50] - (.Copyright (C) VIA Technologies, Inc. 2000-2007 - VIA Generic PCI IDE Bus Driver.) - [17.08 Ko] - (6.0.6000.170) - C:\windows\System32\Drivers\viaide.sys
[MD5.5E2016EA6EBACA03C04FEAC5F330D997] - [10/06/2009 13:37:58] - (.Copyright (C) VIA Technologies 1992-2007 - VIA RAID DRIVER FOR AMD-X86-64.) - [158.08 Ko] - (6.0.6000.6210) - C:\windows\System32\Drivers\vsmraid.sys
[MD5.0C4540311E11664B245A263E1154CEF8] - [13/07/2009 15:04:21] - (.Copyright Conexant Systems, Inc. 2008 - HSF_HWAZL WDM driver.) - [286 Ko] - (7.80.2.0) - C:\windows\System32\Drivers\VSTAZL6.SYS
[MD5.18E40C245DBFAF36FD0134A7EF2DF396] - [13/07/2009 15:04:21] - (.Copyright Conexant Systems, Inc. 2008 - HSF_CNXT driver.) - [723.5 Ko] - (7.80.2.0) - C:\windows\System32\Drivers\VSTCNXT6.SYS
[MD5.02071D207A9858FBE3A48CBFD59C4A04] - [13/07/2009 15:04:21] - (.Copyright Conexant Systems, Inc. 2008 - HSF_DP driver.) - [1450.5 Ko] - (7.80.2.0) - C:\windows\System32\Drivers\VSTDPV6.SYS
[MD5.21E13F2CB269DEFEAE5E1D09887D47BB] - [08/09/2015 10:44:27] - (.Zemana Ltd. - ZAM.) - [198.91 Ko] - (0.0.0.0) - C:\windows\System32\Drivers\zam64.sys
[MD5.21E13F2CB269DEFEAE5E1D09887D47BB] - [08/09/2015 10:44:10] - (.Zemana Ltd. - ZAM.) - [198.91 Ko] - (0.0.0.0) - C:\windows\System32\Drivers\zamguard64.sys
---------- | Uninstall
[HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\ActiveTouchMeetingClient] : (WebEx.-.Cisco WebEx LLC) -> C:\PROGRA~3\WebEx\atcliun.exe
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\AddressBook] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Branding] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\cAudioFilterAgent] : (.-.Conexant Systems) -> C:\Program Files\CONEXANT\cAudioFilterAgent\SETUP64.EXE -U -IcAudioFilterAgent -SM=cAudioFilterAgent64.exe,16
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\CCleaner] : (CCleaner.-.Piriform) -> "C:\Program Files\CCleaner\uninst.exe"
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\cMA3Preset] : (.-.Conexant Systems) -> C:\Program Files\CONEXANT\cMA3Preset\SETUP64.EXE -U -IcMA3Preset ,16
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\CNXT_AUDIO_HDA] : (Conexant HD Audio.-.Conexant) -> C:\Program Files\CONEXANT\CNXT_AUDIO_HDA\UIU64a.exe -U -G -ITE7Pebwa.inf
##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\DXM_Runtime] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}] : (.-.) -> C:\Program Files\TOSHIBA\TVAP\setup.exe
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MaxxAudio] : (.-.Conexant Systems) -> C:\Program Files\Conexant\MaxxAudio\SETUP64.EXE -U -IMaxxAudio
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MaxxGadget] : (.-.Conexant Systems) -> C:\Program Files\Conexant\MaxxGadget\SETUP64.EXE -U -IMaxxGadget ,16
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\MPlayer2] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\REGSERVO_is1] : (REGSERVO.-.TuneUp System Software Pvt Ltd.) -> "C:\Program Files\REGSERVO\unins000.exe"
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\SAII] : (.-.Conexant Systems) -> C:\Program Files\Conexant\SAII\SETUP64.EXE -U -ISAII -SM=SmartAudio.EXE,1801
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\SynTPDeinstKey] : (Synaptics Pointing Device Driver.-.Synaptics Incorporated) -> rundll32.exe "%ProgramFiles%\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{027BF2A8-9B37-AE37-C35E-1D6839B09261}] : (.-.) ->
##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{066CFFF8-12BF-4390-A673-75F95EFF188E}] : (TOSHIBA Value Added Package.-.TOSHIBA Corporation) ->
##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{1C8C049A-145F-4A6E-8290-B5C245EBE39D}] : (TOSHIBA Bulletin Board.-.TOSHIBA Corporation) -> MsiExec.exe /X{1C8C049A-145F-4A6E-8290-B5C245EBE39D}
##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{24811C12-F4A9-4D0F-8494-A7B8FE46123C}] : (TOSHIBA ReelTime.-.TOSHIBA Corporation) -> MsiExec.exe /X{24811C12-F4A9-4D0F-8494-A7B8FE46123C}
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{5DA0E02F-970B-424B-BF41-513A5018E4C0}] : (TOSHIBA Disc Creator.-.TOSHIBA Corporation) -> MsiExec.exe /X{5DA0E02F-970B-424B-BF41-513A5018E4C0}
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{6D3C4544-EA5F-F1E0-BEFF-C5B631789FB1}] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}] : (TOSHIBA PC Health Monitor.-.TOSHIBA Corporation) -> MsiExec.exe /X{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{9E063853-2003-09E8-0E26-A600FF9F51B9}] : (.-.) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{C2F94B5E-201A-4754-8F2F-4395E1D90DA3}] : (TOSHIBA eco Utility.-.TOSHIBA Corporation) -> MsiExec.exe /X{C2F94B5E-201A-4754-8F2F-4395E1D90DA3}
##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{C4FFA951-9678-4D51-84B4-AFD15D3C45AD}] : (TOSHIBA Hardware Setup.-.TOSHIBA) ->
##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{CBD6B23D-41D5-4A46-8019-6208516C9712}] : (TOSHIBA Supervisor Password.-.TOSHIBA) ->
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{D4322448-B6AF-4316-B859-D8A0E84DCB38}] : (TOSHIBA HDD/SSD Alert.-.TOSHIBA Corporation) -> MsiExec.exe /X{D4322448-B6AF-4316-B859-D8A0E84DCB38}
[HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{E97273D6-1BFC-5317-EB2E-926B029C4002}] : (.-.) ->
##########[{Hidden}][HKLM\SOFTWARE\Microsoft\windows\CurrentVersion\Uninstall\{F67FA545-D8E5-4209-86B1-AEE045D1003F}] : (TOSHIBA Face Recognition.-.TOSHIBA Corporation) -> MsiExec.exe /X{F67FA545-D8E5-4209-86B1-AEE045D1003F}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\9-lab Removal Tool] : (9-lab Removal Tool.-.) -> "C:\Program Files\9-lab\Removal Tool\uninst.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\AddressBook] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Adobe AIR] : (Adobe AIR.-.Adobe Systems Incorporated) -> c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX] : (Adobe Flash Player 18 ActiveX.-.Adobe Systems Incorporated) -> C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_18_0_0_232_ActiveX.exe -maintain activex
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Adobe Flash Player NPAPI] : (Adobe Flash Player 18 NPAPI.-.Adobe Systems Incorporated) -> C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_18_0_0_232_Plugin.exe -maintain plugin
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Avast] : (Avast Free Antivirus.-.AVAST Software) -> C:\Program Files\AVAST Software\Avast\Setup\Instup.exe /control_panel
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Connection Manager] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DirectDrawEx] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\DivX Setup] : (DivX Setup.-.DivX, LLC) -> C:\ProgramData\DivX\Setup\DivXSetup.exe /uninstall
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\ffdshow_is1] : (ffdshow [rev 2527] [2008-12-19].-.) -> "C:\Program Files (x86)\ffdshow\unins000.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Fontcore] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\FreeTorrentViewer] : (FreeTorrentViewer.-.Free Torrent Viewer) -> C:\Program Files (x86)\FreeTorrentViewer\uninst.exe
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Giraffic] : (Veoh Giraffic Video Accelerator.-.Giraffic) -> C:\Program Files (x86)\Giraffic\GirafficUninstall.exe
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Google Chrome] : (Google Chrome.-.Google Inc.) -> "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\setup.exe" --uninstall --system-level --verbose-logging
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\HaaliMkx] : (Haali Media Splitter.-.) -> "C:\Program Files (x86)\Haali\MatroskaSplitter\uninstall.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE40] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE4Data] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IE5BAKEX] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\IEData] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield Uninstall Information] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}] : (TOSHIBA Value Added Package.-.TOSHIBA Corporation) -> C:\Program Files\TOSHIBA\TVAP\Setup.exe
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{1C8C049A-145F-4A6E-8290-B5C245EBE39D}] : (TOSHIBA Bulletin Board.-.TOSHIBA Corporation) -> "C:\Program Files (x86)\InstallShield Installation Information\{1C8C049A-145F-4A6E-8290-B5C245EBE39D}\setup.exe" -runfromtemp -l0x0409 -removeonly
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{24811C12-F4A9-4D0F-8494-A7B8FE46123C}] : (TOSHIBA ReelTime.-.TOSHIBA Corporation) -> "C:\Program Files (x86)\InstallShield Installation Information\{24811C12-F4A9-4D0F-8494-A7B8FE46123C}\setup.exe" -runfromtemp -l0x0409 -removeonly
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}] : (TOSHIBA Web Camera Application.-.TOSHIBA Corporation) -> "C:\Program Files (x86)\InstallShield Installation Information\{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}\setup.exe" -runfromtemp -l0x0409 -removeonly
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{C4FFA951-9678-4D51-84B4-AFD15D3C45AD}] : (TOSHIBA Hardware Setup.-.TOSHIBA) -> C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{C4FFA951-9678-4D51-84B4-AFD15D3C45AD} /l1033
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{CBD6B23D-41D5-4A46-8019-6208516C9712}] : (TOSHIBA Supervisor Password.-.TOSHIBA) -> C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{CBD6B23D-41D5-4A46-8019-6208516C9712} /l1033
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}] : (TOSHIBA Face Recognition.-.TOSHIBA Corporation) -> "C:\Program Files (x86)\InstallShield Installation Information\{F67FA545-D8E5-4209-86B1-AEE045D1003F}\setup.exe" -runfromtemp -l0x0409 -removeonly
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Malwarebytes Anti-Malware_is1] : (Malwarebytes Anti-Malware version 2.1.8.1057.-.Malwarebytes Corporation) -> "C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MixiDJ V34 Toolbar] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MixiDJ_V34 Toolbar] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\MobileOptionPack] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\NortonPCCheckup] : (Toshiba Laptop Checkup.-.Symantec Corporation) -> C:\Program Files (x86)\NortonInstaller\{170fa89a-6886-4c9e-b17b-12bccdd80788}\NortonPCCheckup\LicenseType\2.0.13.11\InstStub.exe /X
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SafeZone 1.48.2066.114] : (SafeZone Stable 1.48.2066.114.-.Avast Software) -> "C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\SchedulingAgent] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\TDC13E0_2009_0603_1515_is1] : (Uninstall Dual Mode Camera (TDC13E0).-.) -> "C:\Program Files (x86)\TDC13E0\unins000.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Veoh Web Player Beta] : (Veoh Web Player.-.Veoh Networks, Inc.) -> "C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\uninst.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Veoh Web Player Toolbar] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Vivitar Experience Image Manager] : (Vivitar Experience Image Manager.-.) -> C:\Program Files\Vivitar Experience Image Manager\uninstaller.exe
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\webmmf] : (WebM Media Foundation Components.-.WebM Project) -> C:\Program Files (x86)\Common Files\WebM Project\webmmf\uninstall_webmmf.exe
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WIC] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangent toshiba Master Uninstall] : (WildTangent Games.-.WildTangent) -> "C:\Program Files (x86)\TOSHIBA Games\Uninstall.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGameProvider-toshiba-genres] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\TOSHIBA Games\Game Explorer Categories - genres\Uninstall.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGameProvider-toshiba-main] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\TOSHIBA Games\Game Explorer Categories - main\Uninstall.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-toshiba-clubpenguin] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\TOSHIBA Games\Web Link - Club Penguin\Uninstall.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-toshiba-darkorbit] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\TOSHIBA Games\Web Link - Dark Orbit\Uninstall.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-toshiba-seafight] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\TOSHIBA Games\Web Link - Seafight\Uninstall.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-toshiba-shaiya] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\TOSHIBA Games\Web Link - Shaiya\Uninstall.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WildTangentGDF-toshiba-worldofwarcraft] : (.-.WildTangent, Inc.) -> "C:\Program Files (x86)\TOSHIBA Games\Web Link - World of Warcraft\Uninstall.exe"
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-1bd9480c-a72e-4acf-9df8-d55787d9bcd7] : (Polar Bowler.-.WildTangent) -> "C:\Program Files (x86)\TOSHIBA Games\Polar Bowler\uninstall\uninstaller.exe"
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-2b98a26a-9857-4cda-b8c0-eee3bb490993] : (Chuzzle Deluxe.-.WildTangent) -> "C:\Program Files (x86)\TOSHIBA Games\Chuzzle Deluxe\uninstall\uninstaller.exe"
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-2c05a9e4-d186-474f-bd85-2496b970ba27] : (Penguins!.-.WildTangent) -> "C:\Program Files (x86)\TOSHIBA Games\Penguins!\uninstall\uninstaller.exe"
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-449bd985-3c9d-415e-91db-c4c8da29a06b] : (Bejeweled 3.-.WildTangent) -> "C:\Program Files (x86)\TOSHIBA Games\Bejeweled 3\uninstall\uninstaller.exe"
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-52f1d0ea-61e5-4e73-9487-ae54e69b2437] : (Virtual Villagers 5 - New Believers.-.WildTangent) -> "C:\Program Files (x86)\TOSHIBA Games\Virtual Villagers 5 - New Believers\uninstall\uninstaller.exe"
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-54d4bc45-6230-4afa-82ed-66eaac5d1226] : (Zuma's Revenge.-.WildTangent) -> "C:\Program Files (x86)\TOSHIBA Games\Zumas Revenge\uninstall\uninstaller.exe"
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-64342a07-e20d-4fb5-9bd4-5c83fc3e1740] : (Tom Clancy's Splinter Cell.-.WildTangent) -> "C:\Program Files (x86)\TOSHIBA Games\Tom Clancys Splinter Cell\uninstall\uninstaller.exe"
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-77bd5c54-5d8d-4416-9bba-1ba4a88ce1b7] : (FATE - The Traitor Soul.-.WildTangent) -> "C:\Program Files (x86)\TOSHIBA Games\FATE - The Traitor Soul\uninstall\uninstaller.exe"
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-acdb0c5a-477e-4756-b925-430ed43ca90f] : (Fishdom (TM) 2.-.WildTangent) -> "C:\Program Files (x86)\TOSHIBA Games\Fishdom (TM) 2\uninstall\uninstaller.exe"
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\WTA-e1c833ce-2952-47e7-8161-c2ec26e43ff2] : (Plants vs. Zombies - Game of the Year.-.WildTangent) -> "C:\Program Files (x86)\TOSHIBA Games\Plants vs Zombies - Game of the Year\uninstall\uninstaller.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Yahoo! Software Update] : (Yahoo! Software Update.-.) -> C:\PROGRA~2\Yahoo!\SOFTWA~1\UNINST~1.EXE
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\Zoola Games] : (Zoola Games.-.) -> C:\Program Files (x86)\Zoola Games\uninstall.exe
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{066CFFF8-12BF-4390-A673-75F95EFF188E}] : (TOSHIBA Value Added Package.-.TOSHIBA Corporation) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{0D795777-9D60-4692-8386-F2B3F2B5E5BF}] : (Label@Once 1.0.-.Corel) -> MsiExec.exe /I{0D795777-9D60-4692-8386-F2B3F2B5E5BF}
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}] : (Google Toolbar for Internet Explorer.-.Google Inc.) -> MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{1C8C049A-145F-4A6E-8290-B5C245EBE39D}] : (.-.TOSHIBA Corporation) ->
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{24811C12-F4A9-4D0F-8494-A7B8FE46123C}] : (.-.TOSHIBA Corporation) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83216025FF}] : (Java(TM) 6 Update 25.-.Oracle) -> MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216025FF}
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App] : (Update Installer for WildTangent Games App.-.WildTangent) -> "C:\Program Files (x86)\WildTangent Games\App\Uninstall.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3108C217-BE83-42E4-AE9E-A56A2A92E549}] : (Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver.-.Atheros Communications Inc.) -> "C:\Program Files (x86)\InstallShield Installation Information\{3108C217-BE83-42E4-AE9E-A56A2A92E549}\setup.exe" -runfromtemp -l0x0009 -removeonly
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}] : (Intel(R) Rapid Storage Technology.-.Intel Corporation) -> C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\Uninstall\setup.exe -uninstall
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4494ACC0-18AE-4342-A96A-864748ABF37C}] : (.-.) ->
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}] : (Java Auto Updater.-.Sun Microsystems, Inc.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{51C7AD07-C3F6-4635-8E8A-231306D810FE}] : (Cisco LEAP Module.-.Cisco Systems, Inc.) -> MsiExec.exe /I{51C7AD07-C3F6-4635-8E8A-231306D810FE}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{59DB31A9-BCB0-4985-ACA6-F6477C7BE367}] : (Strongvault Online Backup.-.Strongvault) -> MsiExec.exe /X{59DB31A9-BCB0-4985-ACA6-F6477C7BE367}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5AF550B4-BB67-4E7E-82F1-2C4300279050}] : (TOSHIBARegistration.-.TOSHIBA) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{5AF550B4-BB67-4E7E-82F1-2C4300279050}\setup.exe" -l0x9 -removeonly
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5B01BCB7-A5D3-476F-AF11-E515BA206591}] : (TOSHIBA Wireless LAN Indicator.-.TOSHIBA CORPORATION) -> MsiExec.exe /X{5B01BCB7-A5D3-476F-AF11-E515BA206591}
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}] : (.-.Strongvault Online Backup) -> MsiExec.exe /I{5E33D30D-D896-4D92-B033-5F45819B2937}
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}] : (Google Update Helper.-.Google Inc.) -> MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{62BBB2F0-E220-4821-A564-730807D2C34D}] : (Realtek USB 2.0 Reader Driver.-.Realtek Semiconductor Corp.) -> "C:\Program Files (x86)\InstallShield Installation Information\{62BBB2F0-E220-4821-A564-730807D2C34D}\setup.exe" -runfromtemp -removeonly
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}] : (Cisco EAP-FAST Module.-.Cisco Systems, Inc.) -> MsiExec.exe /I{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}] : (Intel(R) Management Engine Components.-.Intel Corporation) -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\Uninstall\setup.exe -uninstall
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{654F7484-88C5-46DC-AB32-C66BCB0E2102}] : (TOSHIBA Sleep Utility.-.TOSHIBA Corporation) -> C:\Program Files (x86)\InstallShield Installation Information\{654F7484-88C5-46DC-AB32-C66BCB0E2102}\Setup.exe -runfromtemp -removeonly
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}] : (TOSHIBA Resolution+ Plug-in for Windows Media Player.-.TOSHIBA Corporation) -> "C:\Program Files (x86)\InstallShield Installation Information\{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}\setup.exe" -runfromtemp -l0x0409 -removeonly
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}] : (TOSHIBA Web Camera Application.-.TOSHIBA Corporation) -> MsiExec.exe /I{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-toshiba] : (WildTangent Games App (Toshiba Games).-.WildTangent) -> "C:\Program Files (x86)\WildTangent Games\Touchpoints\toshiba\Uninstall.exe"
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{74B8998B-2B1B-4414-AD5D-17E7E9B5FF0A}] : (Netwaiting.-.Conexant Systems, Inc) -> MsiExec.exe /I{74B8998B-2B1B-4414-AD5D-17E7E9B5FF0A}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{7B63B2922B174135AFC0E1377DD81EC2}] : (.-.) ->
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1] : (Zemana AntiMalware.-.Zemana Ltd.) -> "C:\Program Files (x86)\Zemana AntiMalware\unins000.exe"
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{933B4015-4618-4716-A828-5289FC03165F}] : (VC80CRTRedist - 8.0.50727.6195.-.DivX, Inc) -> MsiExec.exe /I{933B4015-4618-4716-A828-5289FC03165F}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}] : (TOSHIBA Application Installer.-.TOSHIBA) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}\setup.exe" -l0x9 -removeonly
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{9D3D8C60-A55F-4fed-B2B9-173001290E16}] : (Realtek WLAN Driver.-.REALTEK Semiconductor Corp.) -> C:\Program Files (x86)\InstallShield Installation Information\{9D3D8C60-A55F-4fed-B2B9-173001290E16}\Install.exe -uninst -l0x9
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{A14962A7-2B7D-456E-BFCD-F54E3A88D41F}] : (Toshiba Book Place.-.K-NFB Reading Technology, Inc.) -> MsiExec.exe /X{A14962A7-2B7D-456E-BFCD-F54E3A88D41F}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC6569FA-6919-442A-8552-073BE69E247A}] : (TOSHIBA Service Station.-.TOSHIBA) -> C:\Program Files (x86)\InstallShield Installation Information\{AC6569FA-6919-442A-8552-073BE69E247A}\setup.exe -runfromtemp -l0x0009 -removeonly
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}] : (Adobe Reader X MUI.-.Adobe Systems Incorporated) -> MsiExec.exe /I{AC76BA86-7AD7-FFFF-7B44-AA0000000001}
##########[{Hidden}][HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}] : (Adobe AIR.-.Adobe Systems Incorporated) -> MsiExec.exe /I{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}] : (TOSHIBA Recovery Media Creator.-.TOSHIBA CORPORATION) -> C:\Program Files (x86)\InstallShield Installation Information\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}\Setup.exe -runfromtemp -removeonly
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}] : (TOSHIBA Assist.-.TOSHIBA CORPORATION) -> C:\Program Files (x86)\InstallShield Installation Information\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}\setup.exe -runfromtemp -removeonly
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}] : (Toshiba Online Backup.-.Toshiba) -> MsiExec.exe /X{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{C7A4F26F-F9B0-41B2-8659-99181108CDE3}] : (TOSHIBA Media Controller.-.TOSHIBA CORPORATION) -> C:\Program Files (x86)\InstallShield Installation Information\{C7A4F26F-F9B0-41B2-8659-99181108CDE3}\setup.exe -runfromtemp -removeonly
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{DA84ECBF-4B79-47F2-B34C-95C38484C058}] : (Skype Launcher.-.TOSHIBA Corporation) -> C:\Program Files (x86)\InstallShield Installation Information\{DA84ECBF-4B79-47F2-B34C-95C38484C058}\setup.exe -runfromtemp -l0x0009 -removeonly
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{E69992ED-A7F6-406C-9280-1C156417BC49}] : (TOSHIBA Quality Application.-.TOSHIBA) -> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{E69992ED-A7F6-406C-9280-1C156417BC49}\setup.exe" -l0x9 -removeonly
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{ED3CBA78-488F-4E8C-B33F-8E3BF4DDB4D2}] : (Toshiba App Place.-.Toshiba) -> MsiExec.exe /I{ED3CBA78-488F-4E8C-B33F-8E3BF4DDB4D2}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}] : (Cisco PEAP Module.-.Cisco Systems, Inc.) -> MsiExec.exe /I{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}] : (Intel(R) Processor Graphics.-.Intel Corporation) -> C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\Uninstall\setup.exe -uninstall
[HKLM\SOFTWARE\WOW6432Node\Microsoft\windows\CurrentVersion\Uninstall\{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}] : (TOSHIBA Media Controller Plug-in.-.TOSHIBA CORPORATION) -> MsiExec.exe /X{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}
---------- | Installer
[HKCR\Installer\Products\080E7FFA4791FB54390101EDA1F1E50D] : Adobe AIR
[HKCR\Installer\Products\1098C3F63DBED074788FCA12F0E6E520] : TOSHIBA Web Camera Application -> C:\windows\Installer\{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\159AFF4C876915D4484BFA1DD5C354DA] : TOSHIBA Hardware Setup -> C:\Windows\Installer\{C4FFA951-9678-4D51-84B4-AFD15D3C45AD}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\18555481990E8AB4CBB63FB4F26006C0] : Google Toolbar for Internet Explorer
[HKCR\Installer\Products\1EDCB75C9BC7D7643BABE7119961DC1C] : Toshiba Online Backup -> C:\windows\Installer\{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}\Icon.ico
[HKCR\Installer\Products\21C118429A4FF0D448497A8BEF6421C3] : TOSHIBA ReelTime -> C:\Windows\Installer\{24811C12-F4A9-4D0F-8494-A7B8FE46123C}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\4EA42A62D9304AC4784BF238120652FF] : Java(TM) 6 Update 25
[HKCR\Installer\Products\5104B339816461748A822598CF3061F5] : VC80CRTRedist - 8.0.50727.6195
[HKCR\Installer\Products\52744B0D6663D294EB6F85A741DBB99D] : MSVCRT_amd64
[HKCR\Installer\Products\545AF76F5E8D9024681BEA0E541D00F3] : TOSHIBA Face Recognition -> C:\windows\Installer\{F67FA545-D8E5-4209-86B1-AEE045D1003F}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\5D6775DE4B957B64FA18F5D2497D6C04] : Cisco PEAP Module
[HKCR\Installer\Products\6116D6C8427B0184F8D20D746E7B6DE8] : Mesh Runtime
[HKCR\Installer\Products\68AB67CA7DA7FFFFB744AA0000000010] : Adobe Reader X MUI -> C:\Windows\Installer\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}\SC_Reader.ico
[HKCR\Installer\Products\70DA7C156F3C5364E8A83231608D01EF] : Cisco LEAP Module
[HKCR\Installer\Products\75FDF62FE3848C249A9CEE1EDE2B650E] : TOSHIBA Media Controller Plug-in -> C:\Windows\Installer\{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\777597D006D9296438682F3B2F5B5EFB] : Label@Once 1.0 -> C:\windows\Installer\{0D795777-9D60-4692-8386-F2B3F2B5E5BF}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\7810FB462D3FB89499AE61A39FEAE69C] : Cisco EAP-FAST Module
[HKCR\Installer\Products\7A26941AD7B2E654FBDC5FE4A3884DF1] : Toshiba Book Place -> C:\Windows\Installer\{A14962A7-2B7D-456E-BFCD-F54E3A88D41F}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\7BCB10B53D5AF674FA115E51AB025619] : TOSHIBA Wireless LAN Indicator -> C:\windows\Installer\{5B01BCB7-A5D3-476F-AF11-E515BA206591}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\7BD4C90EC03660F46A13E87A329932FA] : D3DX10
[HKCR\Installer\Products\7E0BA6F1DDC839B4A832AAE92BEFCF4E] : Junk Mail filter update
[HKCR\Installer\Products\8442234DFA6B61348B958D0A8ED4BC83] : TOSHIBA HDD/SSD Alert -> C:\Windows\Installer\{D4322448-B6AF-4316-B859-D8A0E84DCB38}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\87ABC3DEF884C8E43BF3E8B34FDD4B2D] : Toshiba App Place -> C:\windows\Installer\{ED3CBA78-488F-4E8C-B33F-8E3BF4DDB4D2}\Icon
[HKCR\Installer\Products\8FFFC660FB2109346A37579FE5FF81E8] : TOSHIBA Value Added Package -> C:\windows\Installer\{066CFFF8-12BF-4390-A673-75F95EFF188E}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\93BAD29AC2E44034A96BCB446EB8552E] : Google Update Helper
[HKCR\Installer\Products\9F0DCED98E3D0B843A09C10FF9453E4A] : TOSHIBA PC Health Monitor -> C:\windows\Installer\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\A089CE062ADB6BC44A720BA745894BAC] : Google Update Helper
[HKCR\Installer\Products\A6C64DD86500CEF47BA082BB611A1FF1] : MSVCRT
[HKCR\Installer\Products\A940C8C1F541E6A428095B2C54BE3ED9] : TOSHIBA Bulletin Board -> C:\Windows\Installer\{1C8C049A-145F-4A6E-8290-B5C245EBE39D}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\B8998B47B1B24144DAD5717E9E5BFFA0] : Netwaiting -> C:\windows\Installer\{74B8998B-2B1B-4414-AD5D-17E7E9B5FF0A}\_6FEFF9B68218417F98F549.exe
[HKCR\Installer\Products\C186FCC1302C3B94384F5AF4F0494461] : CleanWaterAction Reminder by We-Care.com v5.0.5.1 -> C:\windows\Installer\{1CCF681C-C203-49B3-83F4-A54F0F944416}\icon.ico
[HKCR\Installer\Products\D03D33E5698D29D40B33F55418B99273] : Strongvault Online Backup -> C:\windows\Installer\{5E33D30D-D896-4D92-B033-5F45819B2937}\SOS_APP_ICON
[HKCR\Installer\Products\D32B6DBC5D1464A40891268015C67921] : TOSHIBA Supervisor Password -> C:\Windows\Installer\{CBD6B23D-41D5-4A46-8019-6208516C9712}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\DAAE5ACC4F29A7B45BEE4192C466BA16] : PlayReady PC Runtime x86
[HKCR\Installer\Products\E5B49F2CA1024574F8F234591E9DD03A] : TOSHIBA eco Utility -> C:\windows\Installer\{C2F94B5E-201A-4754-8F2F-4395E1D90DA3}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\F20E0AD5B079B424FB1415A305814E0C] : TOSHIBA Disc Creator -> C:\Windows\Installer\{5DA0E02F-970B-424B-BF41-513A5018E4C0}\ARPPRODUCTICON.exe
[HKCR\Installer\Products\F4339ACB9C6B56F4A937CAA523A9D440] : PlayReady PC Runtime amd64
[HKCR\Installer\Products\F60730A4A66673047777F5728467D401] : Java Auto Updater
---------- | ADS
@C:\ProgramData\Temp:373E1720
@C:\ProgramData\Temp
1B5B4F1
---------- | Drives
Disk: 0 Size=477G
Pos MBRndx Type/Name Size Active Hide Start Sector Sectors
--- ------ ---------- ---- ------ ---- ------------ ------------
0 0 27-UNKNWN 1.5G Yes No 2,048 3,072,000
1 1 07-NTFS 461G No No 3,074,048 943,235,072
2 2 17-NTFS 15G No Yes 946,309,120 30,464,000
---------- | MBR
Windows Version: Windows 7 Home Premium Edition
Windows Information: Service Pack 1 (build 7601), 64-bit
Base Board Manufacturer: Intel Corp.
BIOS Manufacturer: INSYDE
System Manufacturer: TOSHIBA
System Product Name: Satellite L755
Logical Drives Mask: 0x0001003c
Analysis of file "C:\QuickDiag\MBR.bin":
Windows 2008 MBR code detected
64 bits not supported by MBR.exe, Dump : C:\QuickDiag\MBR.Bin
---------- | 20 LastEventLog
A new media server was not initialized because RegisterRunningDevice() encountered error '0x80070005'. Restart your computer, and then restart the WMPNetworkSvc service.
------------
A new media server was not initialized because RegisterRunningDevice() encountered error '0x80070005'. Restart your computer, and then restart the WMPNetworkSvc service.
------------
A timeout was reached (30000 milliseconds) while waiting for the Microsoft .NET Framework NGEN v4.0.30319_X64 service to connect.
------------
----------( EOF)---------- - 3179 | 16:54:28