• Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Solved Virus/malware or something else? Keyboard issue

Status
Not open for further replies.
The scans for the fix and ClearLNK are below.

RogueKiller bluescreened at the same point as before - details below.

====================================================================================
Fix result of Farbar Recovery Scan Tool (x64) Version: 04-03-2017
Ran by goldfish (05-03-2017 10:24:42) Run:1
Running from C:\Users\goldfish\Desktop
Loaded Profiles: goldfish (Available Profiles: goldfish)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CreateRestorePoint:
Closeprocesses:
Emptytemp:
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\...\MountPoints2: {3966f36d-41b6-11e0-8b3f-c44619b2e2e4} - D:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\...\MountPoints2: {cfdc1e4e-78d4-11e0-aa4f-c44619b2e2e4} - D:\.\Setup.exe AUTORUN=1
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{927587AB-1894-493E-8E72-6063314BF69A}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{EC19D428-B36F-4D8F-B458-DB4400362D30}: [DhcpNameServer] 172.20.10.1
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?bcutc=sp-014-756
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?bcutc=sp-014-756&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?bcutc=sp-014-756&q={searchTerms}
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://uk-mg5.mail.yahoo.com/neo/launch?.rand=872fenf2dujii
SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-014-756&q={searchTerms}
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-014-756&q={searchTerms}
SearchScopes: HKU\S-1-5-21-928801702-3077407482-3869533313-1000 -> DefaultScope {67B4F6F6-DEA2-42F9-84A7-6785674F4D19} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SVEC
SearchScopes: HKU\S-1-5-21-928801702-3077407482-3869533313-1000 -> {1686262A-C27D-4A79-8D82-C55F4D8BB35A} URL = hxxp://uk.shopping.com/?linkin_id=8056359
SearchScopes: HKU\S-1-5-21-928801702-3077407482-3869533313-1000 -> {67B4F6F6-DEA2-42F9-84A7-6785674F4D19} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SVEC
SearchScopes: HKU\S-1-5-21-928801702-3077407482-3869533313-1000 -> {8FD01E4A-8F30-4C90-8E35-DEF880420C67} URL = hxxp://rover.ebay.com/rover/1/710-42480-16445-5/4?satitle={searchTerms}
SearchScopes: HKU\S-1-5-21-928801702-3077407482-3869533313-1000 -> {96B8ABCB-AC35-45F0-886C-1C2B912B5FFD} URL = hxxp://www.zinio.com/search/index.jsp?s={searchTerms}&rf=sonyie8search
SearchScopes: HKU\S-1-5-21-928801702-3077407482-3869533313-1000 -> {B2EC8D7B-5F99-4D85-94B8-E3BF03379046} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-928801702-3077407482-3869533313-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-014-756&q={searchTerms}
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: HKLM-x32 {76496E5E-244A-424F-B5A5-B677051BD958} hxxp://www.genavsystems.com/ftu/2096/FLIGHTOFFICE.CAB
DPF: HKLM-x32 {BEA7310D-06C4-4339-A784-DC3804819809} hxxp://www.tescophoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-20] (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14] (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-01-01] (Skype Technologies)
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
FF Homepage: Prism\Profiles\1nquevq8.default -> hxxp://127.0.0.1:888/
FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\fcotwa47.default -> Bing
FF NetworkProxy: Mozilla\Firefox\Profiles\fcotwa47.default -> type", 0
FF Extension: (Bing Search Engine) - C:\Users\goldfish\AppData\Roaming\Mozilla\Firefox\Profiles\fcotwa47.default\Extensions\bingsearch.full@microsoft.com [2017-03-03] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG Secure Search\FireFoxExt\18.9.0.230 => not found
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\avg-secure-search.xml [2015-12-15]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin HKU\S-1-5-21-928801702-3077407482-3869533313-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\goldfish\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-22] (Amazon.com, Inc.)
CHR StartupUrls: Default -> "hxxps://login.yahoo.com/?.src=ym&.intl=us&.lang=en-US&.done=https%3a//mail.yahoo.com","hxxps://accounts.google.com/ServiceLogin?service=mail&continue=hxxps://mail.google.com/mail/#identifier","hxxps://www.facebook.com/"
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
S2 ADExchange; no ImagePath
S2 HDD & SSD access service; no ImagePath
S3 TBS; %SystemRoot%\System32\tbssvc.dll [X]
S2 WMPNetworkSvc; "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe" [X]
S3 WsDrvInst; no ImagePath
S3 pccsmcfd; no ImagePath
S3 dbx; system32\DRIVERS\dbx.sys [X]
2017-02-26 22:24 - 2017-02-26 22:24 - 00000000 _____ C:\Users\goldfish\AppData\Local\{C960B433-5DA9-48AB-83A8-605A368C6C7E}
2017-02-20 20:04 - 2017-02-20 20:04 - 00029153 _____ C:\ProgramData\agent.1487621032.bdinstall.bin
2017-02-20 19:10 - 2017-02-20 19:10 - 00000000 ____D C:\Users\goldfish\AppData\Roaming\QuickScan
2017-02-20 19:06 - 2017-02-20 19:06 - 00048200 _____ C:\ProgramData\agent.1487617558.bdinstall.bin
2017-02-20 19:06 - 2017-02-20 19:06 - 00000000 ____D C:\ProgramData\BDLogging
2017-02-20 19:05 - 2017-02-20 19:06 - 00000000 ____D C:\ProgramData\Bitdefender Agent
2017-02-08 19:32 - 2017-02-21 11:48 - 00992488 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgsnx.sys.148767792642001
C:\Windows\system32\Drivers\avgsnx.sys
2017-02-21 23:14 - 2015-10-26 22:44 - 00000000 ____D C:\ProgramData\Avg
2017-02-21 23:13 - 2015-10-26 22:33 - 00000000 ____D C:\Users\goldfish\AppData\Local\AvgSetupLog
2017-02-21 23:08 - 2012-02-19 11:40 - 00000000 ____D C:\Users\goldfish\AppData\Roaming\AVG
2017-02-21 11:42 - 2015-05-30 11:41 - 00000000 ____D C:\Users\goldfish\AppData\Local\Avg
MSCONFIG\Services: !SASCORE => 2
MSCONFIG\Services: ACDaemon => 3
MSCONFIG\Services: btwdins => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: ServiceLayer => 3
MSCONFIG\Services: uCamMonitor => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\Windows\pss\Bluetooth.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^goldfish^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: AmazonMP3DownloaderHelper => C:\Users\goldfish\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
MSCONFIG\startupreg: Apoint => %ProgramFiles%\Apoint\Apoint.exe
MSCONFIG\startupreg: ApplePhotoStreams => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: avgnt => "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
MSCONFIG\startupreg: BrStsInd00 => C:\Program Files (x86)\BrownyInd\Brother\BrIndicator.exe /AUTORUN
MSCONFIG\startupreg: BrStsMon00 => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
MSCONFIG\startupreg: CCleaner => "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
MSCONFIG\startupreg: CitrixReceiver => "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk"
MSCONFIG\startupreg: ConnectionCenter => "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
MSCONFIG\startupreg: DriveUtilitiesHelper => C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe
MSCONFIG\startupreg: Dropbox => "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
MSCONFIG\startupreg: iCloudDrive => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
MSCONFIG\startupreg: iCloudServices => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: MSC => "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
MSCONFIG\startupreg: PC Suite Tray => "C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
MSCONFIG\startupreg: Redirector => "C:\Program Files (x86)\Citrix\ICA Client\redirector.exe" /startup
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Java\jre6\bin\jusched.exe"
MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
MSCONFIG\startupreg: WDAppManager => C:\Program Files (x86)\Western Digital\WD App Manager\AppManagerLauncher.exe
MSCONFIG\startupreg: Windows Mobile Device Center => %windir%\WindowsMobile\wmdc.exe
C:\Windows\system32\Drivers\etc\hosts
hosts:
AlternateDataStreams: C:\ProgramData\TEMP:0B4227B4 [268]
C:\ProgramData\TEMP:0B4227B4
Task: C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe
C:\ProgramData\AVG January 2013 Campaign
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: {02BEB9D0-7890-4F25-AF0D-BF58A97B79E6} - System32\Tasks\{12FCE0CC-9445-4AA9-8D95-E4F80F6C6440} => C:\Program Files (x86)\B737 CBT\install.exe [2000-03-30] (Macromedia, Inc.)
Task: {06C6A861-269E-4E42-9795-B94F8F690B25} - System32\Tasks\{2E0B2CC6-E47D-46B5-A5D7-B8DBE4924FFE} => pcalua.exe -a "C:\Program Files\SUPERAntiSpyware\Uninstall.exe"
Task: {0E364092-14AD-4480-B09D-7C5DD704AD73} - System32\Tasks\{5A1F6414-9B70-4221-A069-2C3136C8F3BC} => Chrome.exe hxxps://ui.skype.com/ui/0/7.29.80.102/en/abandoninstall?page=tsProgressBar
Task: {0EA45EDA-39CC-4ADB-A6D9-4BAF33D5FA30} - System32\Tasks\SONY\VAIO Gate\StartExecuteProxy => C:\Program Files\Sony\VAIO Gate\ExecutionProxy.exe [2010-10-25] (Sony Corporation)
Task: {1268C5BA-AB72-49DD-8BEE-AA1346A5E26A} - System32\Tasks\SONY\VAIO Power Management\VPM Logon Start => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-19] (Sony Corporation)
Task: {1ABF9405-23CC-4197-BE3D-1DAF5349D2AD} - System32\Tasks\{2093FCAC-5EB6-4537-A8F9-03FC034783F2} => C:\Program Files (x86)\iTunes\iTunes.exe
Task: {1B6F7527-6051-4588-9CC3-26DBBA3F5906} - System32\Tasks\SONY\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2010-10-25] (Sony Corporation)
Task: {1DFE7133-E445-4A03-8AC0-F74053E51AD2} - System32\Tasks\TunnelBear => C:\Program Files (x86)\TunnelBear\TBear.Client.exe
Task: {2B73086E-33A6-44C4-87DA-29D189E2786E} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2011-02-16] (Sony Corporation)
Task: {36251C2B-C530-4941-AF8D-09CCF2332640} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-02-15] (Adobe Systems Incorporated)
Task: {411ABCC0-9D14-474C-903F-AF8565D5BC4B} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update 5 => C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe [2011-04-20] (Sony Corporation)
Task: {47B7819F-92DD-43AC-9FF0-5CBB64863D3C} - System32\Tasks\{96C12997-A4BC-4A31-982B-4770E5B9F850} => C:\Program Files (x86)\B737 CBT\install.exe [2000-03-30] (Macromedia, Inc.)
Task: {5221FD53-7E3D-4540-84E1-5FE536E23F55} - System32\Tasks\{E2A5F6B9-C55D-4083-94E2-C7D27EDDC5EE} => pcalua.exe -a "C:\Program Files (x86)\Sony Corporation\VAIO Partners\uninstall.exe" -c -prepareUninstall
Task: {5C46E2A4-DEB2-414F-A340-38C9780099FC} - System32\Tasks\{9C2AC3BE-3FFF-46A1-A323-14AB69C2DAB0} => pcalua.exe -a C:\Users\goldfish\Desktop\setup.exe -d C:\Users\goldfish\Desktop
Task: {6512F9BC-6D3C-470B-8BA9-43E008628A6E} - System32\Tasks\{9A2D62CF-9308-4BCD-AE33-79916B90C09B} => pcalua.exe -a F:\setup.exe -d F:\
Task: {70557BF9-78EC-4476-A384-73A5E50B6AF7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-07] (Google Inc.)
Task: {768AD431-53A2-4F5A-BC74-932F41B28F00} - System32\Tasks\{93FCEB53-8810-4B44-9077-E63EEC818449} => C:\Program Files (x86)\B737 CBT\install.exe [2000-03-30] (Macromedia, Inc.)
Task: {91F065EA-BDE3-4099-89D8-B581A51BD4FA} - System32\Tasks\{926AC40F-1299-447B-AEF6-54EFD36B56DA} => C:\Program Files (x86)\B737 CBT\install.exe [2000-03-30] (Macromedia, Inc.)
Task: {9DC9BC20-0D4B-4598-9C66-0F592842E6DB} - System32\Tasks\{92A54289-B4FD-4AED-801A-802259F7E495} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2017-02-08] (Skype Technologies S.A.)
Task: {A324975A-EFC0-454C-8124-7A26F20C9E52} - System32\Tasks\SONY\SUS-BCF\Level4Daily => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2009-11-20] (Sony Corporation)
Task: {A69AFC5B-57F5-4600-A5F6-F777C0CF3DF1} - System32\Tasks\{97EC3147-E1A9-4701-B32D-CE6CD97B78EC} => C:\Program Files (x86)\B737 CBT\install.exe [2000-03-30] (Macromedia, Inc.)
Task: {B1DF4585-6B0E-49E9-B6F3-5BE3466BF754} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {B1E5F863-1AEB-49C1-812E-B8527F2CCA92} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-07] (Google Inc.)
Task: {B33446C5-DD85-45C5-ADA6-44C81406E9FC} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => %SystemRoot%\ehome\mcupdate.exe
Task: {C956B962-51DE-45C7-A315-B1146AEB98A1} - System32\Tasks\{E1FE020E-4198-444A-883E-2A2DF6C27E01} => pcalua.exe -a "C:\Program Files (x86)\Sony\Marketing Tools\Uninstaller.exe" -c /bootstrap
Task: {CB60D4A6-73F1-4DA8-9A34-05310F59783E} - System32\Tasks\Sony Corporation\VAIO Update\Launch Application => C:\Program Files\Sony\VAIO Update 5\ShellExeProxy.exe
Task: {CE928646-2D82-4350-8674-BCB03E35528E} - System32\Tasks\{81432782-934F-47AD-9717-49765EBAB508} => pcalua.exe -a C:\ProgramData\Installations\{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}\Nokia_PC_Suite_eng_web[1].exe
Task: {D7D6F1EF-7E7F-4AE7-8533-2937A6126C0B} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe [2013-01-17] ()
Task: {DCFC64A1-29B0-4A44-AAA4-B2237C97138D} - System32\Tasks\{D35BEE58-0154-4836-AE23-AA6300E98B3B} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&amp;ver=4.2.0.187.259&amp;LastError=12002
Task: {DDC020A3-0340-45AD-8E21-A677F2C9B4F9} - System32\Tasks\Games\UpdateCheck_S-1-5-21-928801702-3077407482-3869533313-1000
Task: {DE506D78-8716-41A5-A982-BBD96130BB2C} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => %SystemRoot%\ehome\ehrec.exe
Task: {E10E381B-C0E3-481C-98BA-A7E64260B292} - System32\Tasks\{CE7BA935-73B5-4BD7-9385-01F9719511C3} => C:\Program Files (x86)\B737 CBT\install.exe [2000-03-30] (Macromedia, Inc.)
Task: {EF840724-63CF-4693-A308-CB19C44B02DE} - System32\Tasks\{4B63717F-6C21-438B-B556-4FD5C933CCE5} => Firefox.exe hxxp://ui.skype.com/ui/0/7.16.0.102/en/abandoninstall?page=tsProgressBar
Task: {F3A59D10-47AD-4A35-ACC0-FBDA91E1639C} - System32\Tasks\{7A33B700-5810-48F2-9DEB-84DBBFB81049} => pcalua.exe -a C:\Users\goldfish\Desktop\freecol-0.9.5-installer.exe -d C:\Users\goldfish\Desktop
Task: {F64247EC-2515-4E5B-85EC-1809CF0D7BE7} - System32\Tasks\0915wtUpdateInfo => C:\ProgramData\Avg_Update_0915wt\0915wt_{B87CCAC6-8764-480D-A2EC-6EEC605C96A9}.exe
Task: {F87E4381-891C-48AC-B7FB-337A3E3EE276} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCOneClick.exe [2011-02-16] (Sony Corporation)
C:\ProgramData\Avg_Update_0915wt\0915wt_{B87CCAC6-8764-480D-A2EC-6EEC605C96A9}.exe
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state On
CMD: ipconfig /flushdns
reboot:
end

*****************

Restore point was successfully created.
Processes closed successfully.
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3966f36d-41b6-11e0-8b3f-c44619b2e2e4} => key removed successfully
HKCR\CLSID\{3966f36d-41b6-11e0-8b3f-c44619b2e2e4} => key not found.
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cfdc1e4e-78d4-11e0-aa4f-c44619b2e2e4} => key removed successfully
HKCR\CLSID\{cfdc1e4e-78d4-11e0-aa4f-c44619b2e2e4} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avg => key removed successfully
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer => value removed successfully
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}\\DhcpNameServer => value removed successfully
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{927587AB-1894-493E-8E72-6063314BF69A}\\DhcpNameServer => value removed successfully
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{EC19D428-B36F-4D8F-B458-DB4400362D30}\\DhcpNameServer => value removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => key removed successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key removed successfully
HKCR\Wow6432Node\CLSID\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key not found.
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1686262A-C27D-4A79-8D82-C55F4D8BB35A} => key removed successfully
HKCR\CLSID\{1686262A-C27D-4A79-8D82-C55F4D8BB35A} => key not found.
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67B4F6F6-DEA2-42F9-84A7-6785674F4D19} => key removed successfully
HKCR\CLSID\{67B4F6F6-DEA2-42F9-84A7-6785674F4D19} => key not found.
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8FD01E4A-8F30-4C90-8E35-DEF880420C67} => key removed successfully
HKCR\CLSID\{8FD01E4A-8F30-4C90-8E35-DEF880420C67} => key not found.
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{96B8ABCB-AC35-45F0-886C-1C2B912B5FFD} => key removed successfully
HKCR\CLSID\{96B8ABCB-AC35-45F0-886C-1C2B912B5FFD} => key not found.
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B2EC8D7B-5F99-4D85-94B8-E3BF03379046} => key removed successfully
HKCR\CLSID\{B2EC8D7B-5F99-4D85-94B8-E3BF03379046} => key not found.
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key removed successfully
HKCR\CLSID\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{17492023-C23A-453E-A040-C7C580BBF700} => key removed successfully
HKCR\Wow6432Node\CLSID\{17492023-C23A-453E-A040-C7C580BBF700} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{76496E5E-244A-424F-B5A5-B677051BD958} => key removed successfully
HKCR\Wow6432Node\CLSID\{76496E5E-244A-424F-B5A5-B677051BD958} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{BEA7310D-06C4-4339-A784-DC3804819809} => key removed successfully
HKCR\Wow6432Node\CLSID\{BEA7310D-06C4-4339-A784-DC3804819809} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000} => key removed successfully
HKCR\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000} => key not found.
HKCR\PROTOCOLS\Handler\linkscanner => key not found.
HKCR\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Handler\osf => key not found.
HKCR\Wow6432Node\CLSID\{D924BDC6-C83A-4BD5-90D0-095128A113D1} => key not found.
HKCR\PROTOCOLS\Handler\skype-ie-addon-data => key not found.
HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Handler\skype-ie-addon-data => key not found.
HKCR\Wow6432Node\CLSID\{91774881-D725-4E58-B298-07617B9B86A8} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Handler\skype4com => key not found.
HKCR\Wow6432Node\CLSID\{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica => key not found.
HKCR\Wow6432Node\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica; charset=euc-jp => key not found.
HKCR\Wow6432Node\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica; charset=ISO-8859-1 => key not found.
HKCR\Wow6432Node\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica; charset=MS936 => key not found.
HKCR\Wow6432Node\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica; charset=MS949 => key not found.
HKCR\Wow6432Node\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica; charset=MS950 => key not found.
HKCR\Wow6432Node\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica; charset=UTF-8 => key not found.
HKCR\Wow6432Node\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica; charset=UTF8 => key not found.
HKCR\Wow6432Node\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica;charset=euc-jp => key not found.
HKCR\Wow6432Node\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica;charset=ISO-8859-1 => key not found.
HKCR\Wow6432Node\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica;charset=MS936 => key not found.
HKCR\Wow6432Node\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica;charset=MS949 => key not found.
HKCR\Wow6432Node\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica;charset=MS950 => key not found.
HKCR\Wow6432Node\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica;charset=UTF-8 => key not found.
HKCR\Wow6432Node\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-ica;charset=UTF8 => key not found.
HKCR\Wow6432Node\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\ica => key not found.
HKCR\Wow6432Node\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC} => key not found.
Firefox "homepage" removed successfully
Firefox SearchEngineOrder.3 removed successfully
Firefox Proxy settings were reset.
C:\Users\goldfish\AppData\Roaming\Mozilla\Firefox\Profiles\fcotwa47.default\Extensions\bingsearch.full@microsoft.com => not found.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\avg@toolbar => value removed successfully
C:\Program Files (x86)\mozilla firefox\browser\searchplugins\avg-secure-search.xml => moved successfully
HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE => key removed successfully
HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE => key removed successfully
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin => key removed successfully
C:\Users\goldfish\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll => not found.
Chrome StartupUrls => removed successfully
HKLM\SOFTWARE\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk => key removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj => key removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk => key removed successfully
HKLM\System\CurrentControlSet\Services\ADExchange => key removed successfully
ADExchange => service removed successfully
HKLM\System\CurrentControlSet\Services\HDD & SSD access service => key removed successfully
HDD & SSD access service => service removed successfully
HKLM\System\CurrentControlSet\Services\TBS => key removed successfully
TBS => service removed successfully
HKLM\System\CurrentControlSet\Services\WMPNetworkSvc => key removed successfully
WMPNetworkSvc => service removed successfully
HKLM\System\CurrentControlSet\Services\WsDrvInst => key removed successfully
WsDrvInst => service removed successfully
HKLM\System\CurrentControlSet\Services\pccsmcfd => key removed successfully
pccsmcfd => service removed successfully
HKLM\System\CurrentControlSet\Services\dbx => key removed successfully
dbx => service removed successfully
"C:\Users\goldfish\AppData\Local\{C960B433-5DA9-48AB-83A8-605A368C6C7E}" => not found.
C:\ProgramData\agent.1487621032.bdinstall.bin => moved successfully
"C:\Users\goldfish\AppData\Roaming\QuickScan" => not found.
C:\ProgramData\agent.1487617558.bdinstall.bin => moved successfully
C:\ProgramData\BDLogging => moved successfully
C:\ProgramData\Bitdefender Agent => moved successfully
C:\Windows\system32\Drivers\avgsnx.sys.148767792642001 => moved successfully
"C:\Windows\system32\Drivers\avgsnx.sys" => not found.
C:\ProgramData\Avg => moved successfully
"C:\Users\goldfish\AppData\Local\AvgSetupLog" => not found.
"C:\Users\goldfish\AppData\Roaming\AVG" => not found.
"C:\Users\goldfish\AppData\Local\Avg" => not found.
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\!SASCORE => key removed successfully
HKLM\System\CurrentControlSet\Services\!SASCORE => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\ACDaemon => key removed successfully
HKLM\System\CurrentControlSet\Services\ACDaemon => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\btwdins => key removed successfully
HKLM\System\CurrentControlSet\Services\btwdins => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdate => key removed successfully
HKLM\System\CurrentControlSet\Services\gupdate => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdatem => key removed successfully
HKLM\System\CurrentControlSet\Services\gupdatem => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\ServiceLayer => key removed successfully
HKLM\System\CurrentControlSet\Services\ServiceLayer => key not found.
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\uCamMonitor => key removed successfully
HKLM\System\CurrentControlSet\Services\uCamMonitor => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => key removed successfully
C:\Windows\pss\Bluetooth.lnk.CommonStartup => moved successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^goldfish^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => key not found.
C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup => moved successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AmazonMP3DownloaderHelper => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Apoint => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\ApplePhotoStreams => key not found.
HKLM\System\CurrentControlSet\Services\ApplePhotoStreams => key not found.
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\APSDaemon => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\avgnt => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BrStsInd00 => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BrStsMon00 => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CCleaner => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CitrixReceiver => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ConnectionCenter => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DriveUtilitiesHelper => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Dropbox => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\iCloudDrive => key not found.
HKLM\System\CurrentControlSet\Services\iCloudDrive => key not found.
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\iCloudServices => key not found.
HKLM\System\CurrentControlSet\Services\iCloudServices => key not found.
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\iTunesHelper => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSC => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PC Suite Tray => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Redirector => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RtHDVCpl => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SUPERAntiSpyware => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WDAppManager => key removed successfully
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Windows Mobile Device Center => key removed successfully
C:\Windows\system32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
C:\ProgramData\TEMP => ":0B4227B4" ADS removed successfully.
"C:\ProgramData\TEMP:0B4227B4" => not found.
C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => moved successfully
C:\ProgramData\AVG January 2013 Campaign => moved successfully
C:\Windows\Tasks\Adobe Flash Player Updater.job => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{02BEB9D0-7890-4F25-AF0D-BF58A97B79E6} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02BEB9D0-7890-4F25-AF0D-BF58A97B79E6} => key removed successfully
C:\Windows\System32\Tasks\{12FCE0CC-9445-4AA9-8D95-E4F80F6C6440} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{12FCE0CC-9445-4AA9-8D95-E4F80F6C6440} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{06C6A861-269E-4E42-9795-B94F8F690B25} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{06C6A861-269E-4E42-9795-B94F8F690B25} => key removed successfully
C:\Windows\System32\Tasks\{2E0B2CC6-E47D-46B5-A5D7-B8DBE4924FFE} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2E0B2CC6-E47D-46B5-A5D7-B8DBE4924FFE} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0E364092-14AD-4480-B09D-7C5DD704AD73} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0E364092-14AD-4480-B09D-7C5DD704AD73} => key removed successfully
C:\Windows\System32\Tasks\{5A1F6414-9B70-4221-A069-2C3136C8F3BC} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5A1F6414-9B70-4221-A069-2C3136C8F3BC} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{0EA45EDA-39CC-4ADB-A6D9-4BAF33D5FA30} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0EA45EDA-39CC-4ADB-A6D9-4BAF33D5FA30} => key removed successfully
C:\Windows\System32\Tasks\SONY\VAIO Gate\StartExecuteProxy => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SONY\VAIO Gate\StartExecuteProxy => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1268C5BA-AB72-49DD-8BEE-AA1346A5E26A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1268C5BA-AB72-49DD-8BEE-AA1346A5E26A} => key removed successfully
C:\Windows\System32\Tasks\SONY\VAIO Power Management\VPM Logon Start => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SONY\VAIO Power Management\VPM Logon Start => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1ABF9405-23CC-4197-BE3D-1DAF5349D2AD} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1ABF9405-23CC-4197-BE3D-1DAF5349D2AD} => key removed successfully
C:\Windows\System32\Tasks\{2093FCAC-5EB6-4537-A8F9-03FC034783F2} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2093FCAC-5EB6-4537-A8F9-03FC034783F2} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1B6F7527-6051-4588-9CC3-26DBBA3F5906} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B6F7527-6051-4588-9CC3-26DBBA3F5906} => key removed successfully
C:\Windows\System32\Tasks\SONY\VAIO Gate\VAIO Gate => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SONY\VAIO Gate\VAIO Gate => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1DFE7133-E445-4A03-8AC0-F74053E51AD2} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1DFE7133-E445-4A03-8AC0-F74053E51AD2} => key removed successfully
C:\Windows\System32\Tasks\TunnelBear => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\TunnelBear => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2B73086E-33A6-44C4-87DA-29D189E2786E} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2B73086E-33A6-44C4-87DA-29D189E2786E} => key removed successfully
C:\Windows\System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sony Corporation\VAIO Care\VAIO Care => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{36251C2B-C530-4941-AF8D-09CCF2332640} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{36251C2B-C530-4941-AF8D-09CCF2332640} => key removed successfully
C:\Windows\System32\Tasks\Adobe Flash Player Updater => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{411ABCC0-9D14-474C-903F-AF8565D5BC4B} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{411ABCC0-9D14-474C-903F-AF8565D5BC4B} => key removed successfully
C:\Windows\System32\Tasks\Sony Corporation\VAIO Update\VAIO Update 5 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sony Corporation\VAIO Update\VAIO Update 5 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{47B7819F-92DD-43AC-9FF0-5CBB64863D3C} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47B7819F-92DD-43AC-9FF0-5CBB64863D3C} => key removed successfully
C:\Windows\System32\Tasks\{96C12997-A4BC-4A31-982B-4770E5B9F850} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{96C12997-A4BC-4A31-982B-4770E5B9F850} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5221FD53-7E3D-4540-84E1-5FE536E23F55} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5221FD53-7E3D-4540-84E1-5FE536E23F55} => key removed successfully
C:\Windows\System32\Tasks\{E2A5F6B9-C55D-4083-94E2-C7D27EDDC5EE} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E2A5F6B9-C55D-4083-94E2-C7D27EDDC5EE} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5C46E2A4-DEB2-414F-A340-38C9780099FC} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5C46E2A4-DEB2-414F-A340-38C9780099FC} => key removed successfully
C:\Windows\System32\Tasks\{9C2AC3BE-3FFF-46A1-A323-14AB69C2DAB0} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{9C2AC3BE-3FFF-46A1-A323-14AB69C2DAB0} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6512F9BC-6D3C-470B-8BA9-43E008628A6E} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6512F9BC-6D3C-470B-8BA9-43E008628A6E} => key removed successfully
C:\Windows\System32\Tasks\{9A2D62CF-9308-4BCD-AE33-79916B90C09B} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{9A2D62CF-9308-4BCD-AE33-79916B90C09B} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{70557BF9-78EC-4476-A384-73A5E50B6AF7} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70557BF9-78EC-4476-A384-73A5E50B6AF7} => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{768AD431-53A2-4F5A-BC74-932F41B28F00} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{768AD431-53A2-4F5A-BC74-932F41B28F00} => key removed successfully
C:\Windows\System32\Tasks\{93FCEB53-8810-4B44-9077-E63EEC818449} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{93FCEB53-8810-4B44-9077-E63EEC818449} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{91F065EA-BDE3-4099-89D8-B581A51BD4FA} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{91F065EA-BDE3-4099-89D8-B581A51BD4FA} => key removed successfully
C:\Windows\System32\Tasks\{926AC40F-1299-447B-AEF6-54EFD36B56DA} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{926AC40F-1299-447B-AEF6-54EFD36B56DA} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9DC9BC20-0D4B-4598-9C66-0F592842E6DB} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9DC9BC20-0D4B-4598-9C66-0F592842E6DB} => key removed successfully
C:\Windows\System32\Tasks\{92A54289-B4FD-4AED-801A-802259F7E495} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{92A54289-B4FD-4AED-801A-802259F7E495} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A324975A-EFC0-454C-8124-7A26F20C9E52} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A324975A-EFC0-454C-8124-7A26F20C9E52} => key removed successfully
C:\Windows\System32\Tasks\SONY\SUS-BCF\Level4Daily => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SONY\SUS-BCF\Level4Daily => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A69AFC5B-57F5-4600-A5F6-F777C0CF3DF1} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A69AFC5B-57F5-4600-A5F6-F777C0CF3DF1} => key removed successfully
C:\Windows\System32\Tasks\{97EC3147-E1A9-4701-B32D-CE6CD97B78EC} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{97EC3147-E1A9-4701-B32D-CE6CD97B78EC} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B1DF4585-6B0E-49E9-B6F3-5BE3466BF754} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B1DF4585-6B0E-49E9-B6F3-5BE3466BF754} => key removed successfully
C:\Windows\System32\Tasks\Adobe Acrobat Update Task => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Acrobat Update Task => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B1E5F863-1AEB-49C1-812E-B8527F2CCA92} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B1E5F863-1AEB-49C1-812E-B8527F2CCA92} => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B33446C5-DD85-45C5-ADA6-44C81406E9FC} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B33446C5-DD85-45C5-ADA6-44C81406E9FC} => key removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\mcupdate_scheduled => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C956B962-51DE-45C7-A315-B1146AEB98A1} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C956B962-51DE-45C7-A315-B1146AEB98A1} => key removed successfully
C:\Windows\System32\Tasks\{E1FE020E-4198-444A-883E-2A2DF6C27E01} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E1FE020E-4198-444A-883E-2A2DF6C27E01} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CB60D4A6-73F1-4DA8-9A34-05310F59783E} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CB60D4A6-73F1-4DA8-9A34-05310F59783E} => key removed successfully
C:\Windows\System32\Tasks\Sony Corporation\VAIO Update\Launch Application => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sony Corporation\VAIO Update\Launch Application => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CE928646-2D82-4350-8674-BCB03E35528E} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE928646-2D82-4350-8674-BCB03E35528E} => key removed successfully
C:\Windows\System32\Tasks\{81432782-934F-47AD-9717-49765EBAB508} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{81432782-934F-47AD-9717-49765EBAB508} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D7D6F1EF-7E7F-4AE7-8533-2937A6126C0B} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D7D6F1EF-7E7F-4AE7-8533-2937A6126C0B} => key removed successfully
C:\Windows\System32\Tasks\ROC_REG_JAN_DELETE => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ROC_REG_JAN_DELETE => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DCFC64A1-29B0-4A44-AAA4-B2237C97138D} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DCFC64A1-29B0-4A44-AAA4-B2237C97138D} => key removed successfully
C:\Windows\System32\Tasks\{D35BEE58-0154-4836-AE23-AA6300E98B3B} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D35BEE58-0154-4836-AE23-AA6300E98B3B} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DDC020A3-0340-45AD-8E21-A677F2C9B4F9} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DDC020A3-0340-45AD-8E21-A677F2C9B4F9} => key removed successfully
C:\Windows\System32\Tasks\Games\UpdateCheck_S-1-5-21-928801702-3077407482-3869533313-1000 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Games\UpdateCheck_S-1-5-21-928801702-3077407482-3869533313-1000 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DE506D78-8716-41A5-A982-BBD96130BB2C} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DE506D78-8716-41A5-A982-BBD96130BB2C} => key removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\StartRecording => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\StartRecording => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E10E381B-C0E3-481C-98BA-A7E64260B292} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E10E381B-C0E3-481C-98BA-A7E64260B292} => key removed successfully
C:\Windows\System32\Tasks\{CE7BA935-73B5-4BD7-9385-01F9719511C3} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CE7BA935-73B5-4BD7-9385-01F9719511C3} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EF840724-63CF-4693-A308-CB19C44B02DE} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EF840724-63CF-4693-A308-CB19C44B02DE} => key removed successfully
C:\Windows\System32\Tasks\{4B63717F-6C21-438B-B556-4FD5C933CCE5} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4B63717F-6C21-438B-B556-4FD5C933CCE5} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3A59D10-47AD-4A35-ACC0-FBDA91E1639C} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3A59D10-47AD-4A35-ACC0-FBDA91E1639C} => key removed successfully
C:\Windows\System32\Tasks\{7A33B700-5810-48F2-9DEB-84DBBFB81049} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7A33B700-5810-48F2-9DEB-84DBBFB81049} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F64247EC-2515-4E5B-85EC-1809CF0D7BE7} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F64247EC-2515-4E5B-85EC-1809CF0D7BE7} => key removed successfully
C:\Windows\System32\Tasks\0915wtUpdateInfo => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\0915wtUpdateInfo => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F87E4381-891C-48AC-B7FB-337A3E3EE276} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F87E4381-891C-48AC-B7FB-337A3E3EE276} => key removed successfully
C:\Windows\System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sony Corporation\VAIO Care\VCOneClick => key removed successfully
"C:\ProgramData\Avg_Update_0915wt\0915wt_{B87CCAC6-8764-480D-A2EC-6EEC605C96A9}.exe" => not found.

========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully


========= End of RemoveProxy: =========


========= netsh advfirewall reset =========

Ok.


========= End of CMD: =========


========= netsh advfirewall set allprofiles state On =========

Ok.


========= End of CMD: =========


========= ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 4751748 B
Java, Flash, Steam htmlcache => 523 B
Windows/system/drivers => 3072070 B
Edge => 0 B
Chrome => 82128751 B
Firefox => 70352562 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 66228 B
Public => 0 B
ProgramData => 0 B
systemprofile => 157729 B
systemprofile32 => 90203 B
LocalService => 99476 B
NetworkService => 48997044 B
goldfish => 26233878 B

RecycleBin => 0 B
EmptyTemp: => 233 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 10:26:50 ====

====================================================================================

ClearLNK by Alex Dragokas ver. 2.9.0.11

OS: x64 Windows 7 Home Premium, 6.1.7601, Service Pack: 1
Time: 05.03.2017 - 10:34
Language: OS: EN (0x409). Display: EN (0x409). Non-Unicode: en-GB (0x809)
Elevated: Yes
User: goldfish (group: Administrator)

_____________________________ Begin of Log ______________________________
.
[SKIP] 1 "C:\Windows\pss\Bluetooth.lnk" (shortcut was not found)
[SKIP] 2 "C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk" (shortcut was not found)
[SKIP] 3 "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk" (shortcut was not found)
[SKIP] 4 "C:\Windows\pss\Bluetooth.lnk" (shortcut was not found)
[SKIP] 5 "C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk" (shortcut was not found)
.
______________________________ Statistics _______________________________
Cure ran per today: 1 times.

Total processed: 5

Omitted: 5
______________________________ End of Log _______________________________CRC32: C9EFE33B

====================================================================================

upload_2017-3-5_11-58-29.png



upload_2017-3-5_12-5-8.png

Message after Windows restarts:

Problem signature:
Problem Event Name: BlueScreen
OS Version: 6.1.7601.2.1.0.768.3
Locale ID: 2057

Additional information about the problem:
BCCode: 50
BCP1: FFFFFA8019F82DA0
BCP2: 0000000000000001
BCP3: FFFFF880045E3CE0
BCP4: 0000000000000002
OS Version: 6_1_7601
Service Pack: 1_0
Product: 768_1

Files that help describe the problem:
C:\Windows\Minidump\030517-23103-01.dmp
C:\Users\goldfish\AppData\Local\Temp\WER-133505-0.sysdata.xml

Read our privacy statement online:
http://go.microsoft.com/fwlink/?linkid=104288&clcid=0x0409

If the online privacy statement is not available, please read our privacy statement offline:
C:\Windows\system32\en-US\erofflps.txt
 
Last edited:
There had been zero threats found by RogueKiller at the point that the laptop bluescreened, which was 1 - 1.5 hours into the scan.

Also, since running the above tools I get this error when I open Google Chrome. Maybe it's because I replaced my actual name with "goldfish" in the logs? Or maybe the OS is not correctly set (this is the data that chrome requests to send when the error is generated).


upload_2017-3-5_16-29-42.png


upload_2017-3-5_16-27-27.png
 
Last edited:
The Ninite installer froze partway through and wouldn't cancel either, but it seems to have installed okay (and no error when I log in).

The ZHPDiag log is below.

The file C:\Windows\Minidump\030517-23103-01.dmp
is not found with everything, and when I manually go to the directory using Windows Explorer it is empty. This happened when I had the error previously too - couldn't find the file.

upload_2017-3-5_18-46-20.png


====================================================================================

~ ZHPDiag v2017.3.4.39 By Nicolas Coolman (2017/03/04)
~ Run by goldfish (Administrator) (2017/03/05 18:31:05)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ State version: Version OK
~ Mode: Scan
~ Report: C:\Users\goldfish\Desktop\ZHPDiag.txt
~ Report: C:\Users\goldfish\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ System startup: Normal (Normal boot)
Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601) =>.Microsoft Corporation

---\\ Internet Browsers (2) - 1s
~ MSIE: Internet Explorer v11.0.9600.18537
~ OBIE: Avira Scout v17.1.2924.2344

---\\ Windows Product Information (4) - 3s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ System protection software (1) - 11s
Avira Antivirus v15.0.25.154 (Protection)

---\\ Surveillance software (2) - 15s
~ Adobe Flash Player 24 NPAPI (Surveillance)
~ Adobe Acrobat Reader DC (Surveillance)

---\\ Information on the system (6) - 0s
~ Operating System: Intel64 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 6142.052 MB (67% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 180 GB (38%) free of 464 GB : OK =>.Disk Space

---\\ Connection to the system mode (3) - 0s
~ Computer Name: goldfish-VAIO
~ User Name: goldfish
~ Logged in as Administrator

---\\ Enumeration of the disk units (1) - 0s
~ Drive C: has 180 GB free of 464 GB (System)

---\\ State of the Windows Security Center (11) - 0s
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Search Generic System Files (24) - 2s
[MD5.38AE1B3C38FAEF56FE4907922F0385BA] - 29/08/2016 - (.Microsoft Corporation - Windows Explorer.) -- C:\Windows\Explorer.exe [3229696] =>.Microsoft Corporation
[MD5.DD81D91FF3B0763C392422865C9AC12E] - 14/07/2009 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe [45568] =>.Microsoft Corporation
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - 14/07/2009 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\Windows\System32\Wininit.exe [129024] =>.Microsoft Corporation
[MD5.105954F9BEAD700A6DF4B5B489FCCB4B] - 12/11/2016 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\Windows\System32\wininet.dll [2920960] =>.Microsoft Corporation
[MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - 17/07/2014 - (.Microsoft Corporation - Windows Logon Application.) -- C:\Windows\System32\Winlogon.exe [455168] =>.Microsoft Corporation
[MD5.067FA52BFB59A56110A12312EF9AF243] - 20/11/2010 - (.Microsoft Corporation - Software Licensing Library.) -- C:\Windows\System32\sppcomapi.dll [232448] =>.Microsoft Corporation
[MD5.492D07D79E7024CA310867B526D9636D] - 03/03/2011 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\System32\dnsapi.dll [357888] =>.Microsoft Corporation
[MD5.B40420876B9288E0A1C8CCA8A84E5DC9] - 03/03/2011 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\Syswow64\dnsapi.dll [270336] =>.Microsoft Corporation
[MD5.9A4A1EEE802BF2F878EE8EAB407B21B7] - 13/10/2015 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [497664] =>.Microsoft Corporation
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - 14/07/2009 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [24128] =>.Microsoft Windows®
[MD5.B8BD2BB284668C84865658C77574381A] - 13/07/2009 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [92160] =>.Microsoft Corporation
[MD5.F036CE71586E93D94DAB220D7BDF4416] - 20/11/2010 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [147456] =>.Microsoft Corporation
[MD5.9B38580063D281A99E68EF5813022A5F] - 08/09/2016 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [106496] =>.Microsoft Corporation
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - 20/11/2010 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [122368] =>.Microsoft Corporation
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - 13/07/2009 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\Windows\System32\drivers\i8042prt.sys [105472] =>.Microsoft Corporation
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - 14/07/2009 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [116224] =>.Microsoft Corporation
[MD5.632E8A00090E4F85F304E152C92C7F2C] - 05/01/2017 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [159744] =>.Microsoft Corporation
[MD5.E47D571FEC2C76E867935109AB2A770C] - 11/05/2016 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [262144] =>.Microsoft Corporation
[MD5.47B2D0B31BDC3EBE6090228E2BA3764D] - 11/01/2016 - (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\drivers\ntfs.sys [1684416] =>.Microsoft Windows®
[MD5.0086431C29C35BE1DBC43F52CC273887] - 14/07/2009 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\Windows\System32\drivers\Parport.sys [97280] =>.Microsoft Corporation
[MD5.471815800AE33E6F1C32FB1B97C490CA] - 20/11/2010 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [129536] =>.Microsoft Corporation
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - 14/07/2009 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [93184] =>.Microsoft Corporation
[MD5.AA77EB517D2F07A947294F260E3ACA83] - 13/10/2015 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [118272] =>.Microsoft Corporation
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - 20/11/2010 - (.Microsoft Corporation - Volume Shadow Copy Driver.) -- C:\Windows\System32\drivers\volsnap.sys [295808] =>.Microsoft Windows®

---\\ Non Microsoft non disabled Windows Services (45) - 6s
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated - Adobe® Flash® Player Update Service 24.0 r0.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated®
O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\system32\atiesrxx.exe =>.AMD
O23 - Service: Avira Mail Protection (AntiVirMailService) . (.Avira Operations GmbH & Co. KG - Antivirus MailScanner WFP Service.) - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe =>.Avira Operations GmbH & Co. KG®
O23 - Service: Avira Scheduler (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - C:\Program Files (x86)\Avira\Antivirus\sched.exe =>.Avira Operations GmbH & Co. KG®
O23 - Service: Avira Real-Time Protection (AntiVirService) . (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - C:\Program Files (x86)\Avira\Antivirus\avguard.exe =>.Avira Operations GmbH & Co. KG®
O23 - Service: Avira Web Protection (AntiVirWebService) . (.Avira Operations GmbH & Co. KG - AntiVir WebGuard WFP Service.) - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe =>.Avira Operations GmbH & Co. KG®
O23 - Service: Apple Mobile Device Service (Apple Mobile Device Service) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe =>.Apple Inc.®
O23 - Service: ATPL Digital v6 update service (ATPLupd) . (...) - C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\updatescripts\srvany.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) . (.Avira Operations GmbH & Co. KG - Avira Service Host.) - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe =>.Avira Operations GmbH & Co. KG®
O23 - Service: Avira Phantom VPN (AviraPhantomVPN) . (.Avira Operations GmbH & Co. KG - Avira.VpnService.) - C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe =>.Avira Operations GmbH & Co. KG®
O23 - Service: BGS (BGS) . (.Apache Software Foundation - Apache HTTP Server.) - C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\bin\Apache.exe =>.Apache Software Foundation
O23 - Service: Bonjour Service (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.®
O23 - Service: BrYNSvc (BrYNSvc) . (.Brother Industries, Ltd. - BrYNCSvc.) - C:\Program Files (x86)\Browny02\BrYNSvc.exe =>.Brother Industries, Ltd.
O23 - Service: Dropbox Update Service (dbupdate) (dbupdate) . (.Dropbox, Inc. - Dropbox Update.) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe =>.Dropbox, Inc®
O23 - Service: Dropbox Update Service (dbupdatem) (dbupdatem) . (.Dropbox, Inc. - Dropbox Update.) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe =>.Dropbox, Inc®
O23 - Service: DbxSvc (DbxSvc) . (.Dropbox, Inc. - Dropbox Service.) - C:\Windows\system32\DbxSvc.exe =>.Dropbox, Inc.
O23 - Service: FLEXnet Licensing Service (FLEXnet Licensing Service) . (.Flexera Software, Inc. - Activation Licensing Service.) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe =>.Flexera Software, Inc. ®
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation - IAStorDataSvc.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe =>.Intel Corporation®
O23 - Service: InstallDriver Table Manager (IDriverT) . (.Macrovision Corporation - IDriverT Module.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe =>.Macrovision Corporation
O23 - Service: iPod Service (iPod Service) . (.Apple Inc. - iPodService Module (64-bit).) - C:\Program Files\iPod\bin\iPodService.exe =>.Apple Inc.®
O23 - Service: IviRegMgr (IviRegMgr) . (.InterVideo - RegMgr Module.) - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe =>.Intervideo, Inc.®
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation®
O23 - Service: Maxtor Service (Maxtor Sync Service) . (.Seagate Technology LLC - Sync Windows Services.) - C:\Program Files (x86)\Maxtor\Sync\SyncServices.exe {25B1DD7CD102F294C6B4A039166590E7} =>.Seagate Technology LLC
O23 - Service: PMBDeviceInfoProvider (PMBDeviceInfoProvider) . (.Sony Corporation - Device Information Provider.) - C:\Program Files (x86)\SONY\PMB\PMBDeviceInfoProvider.exe =>.Sony Corporation®
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) . (.Protexis Inc. - PsiService PsiService.) - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe =>.Protexis Inc.®
O23 - Service: Roxio UPnP Renderer 10 (Roxio UPnP Renderer 10) . (.Sonic Solutions - Roxio UPnP PRenderer Service.) - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe =>.Sonic Solutions®
O23 - Service: Roxio Upnp Server 10 (Roxio Upnp Server 10) . (.Sonic Solutions - RoxioUpnpService10 Module.) - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe =>.Sonic Solutions®
O23 - Service: VAIO Care Performance Service (SampleCollector) . (.Sony Corporation - VAIO Care Performance Service.) - C:\Program Files\Sony\VAIO Care\VCPerfService.exe =>.Sony Corporation of America®
O23 - Service: Scout Update Service (scupdate) (scupdate) . (.Avira Operations GmbH & Co. KG - Avira Scout Update.) - C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe =>.Avira Operations GmbH & Co. KG®
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl®
O23 - Service: VAIO Media plus Content Importer (SOHCImp) . (.Sony Corporation - VAIO Media plus Content Importer.) - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe =>.Sony Corporation®
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) . (.Sony Corporation - VAIO Media plus Digital Media Server.) - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe =>.Sony Corporation®
O23 - Service: VAIO Media plus Device Searcher (SOHDs) . (.Sony Corporation - VAIO Media plus Device Searcher.) - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe =>.Sony Corporation®
O23 - Service: VAIO Entertainment Common Service (SpfService) . (.Sony Corporation - VAIO Entertainment Common Service.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe =>.Sony Corporation®
O23 - Service: Intel(R) Management & Security Application User Notificatio (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe =>.Intel Corporation®
O23 - Service: VAIO Entertainment TV Device Arbitration Service (VAIO Entertainment TV Device Arbitration Service) . (.Sony Corporation - Hardware Resource Manager.) - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe =>.Sony Corporation®
O23 - Service: VAIO Event Service (VAIO Event Service) . (.Sony Corporation - VAIO Event Service (Service Module).) - C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe =>.Sony Corporation®
O23 - Service: VAIO Content Folder Watcher (VCFw) . (.Sony Corporation - VAIO Content Folder Watcher.) - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe =>.Sony Corporation®
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) . (.Sony Corporation - VcmXml Helper Interface.) - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe =>.Sony Corporation®
O23 - Service: VCService (VCService) . (.Sony Corporation - VAIOCare.) - C:\Program Files\Sony\VAIO Care\VCService.exe =>.Sony Corporation®
O23 - Service: VSNService (VSNService) . (.Sony Corporation - VAIO Smart Network Service.) - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe =>.Sony Corporation
O23 - Service: VUAgent (VUAgent) . (.Sony Corporation - VUAgent.exe.) - C:\Program Files\Sony\VAIO Update Common\VUAgent.exe =>.Sony Corporation®
O23 - Service: WD Drive Manager (WDDriveService) . (.Western Digital Technologies, Inc. - WD Drive Service.) - C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe =>.Western Digital Technologies, Inc.®
O23 - Service: Wondershare Application Framework Service (WsAppService) . (.Wondershare - Wondershare AppService.) - C:\Program Files (x86)\Wondershare\WAF\2.3.0.5\WsAppService.exe =>.Wondershare

---\\ Services not Microsoft (SR=Run, SS=Stop) (50) - 48s
SR - Auto [19/12/2016] [ 82640] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
SS - Auto [15/02/2017] [ 270936] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated®
SR - Auto [08/10/2010] [ 202752] (AMD External Events Utility) . (.AMD.) - C:\Windows\system32\atiesrxx.exe =>.AMD
SS - Auto [15/02/2017] [ 1115552] Avira Mail Protection (AntiVirMailService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe =>.Avira Operations GmbH & Co. KG®
SR - Auto [15/02/2017] [ 487424] Avira Scheduler (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Antivirus\sched.exe =>.Avira Operations GmbH & Co. KG®
SR - Auto [15/02/2017] [ 487424] Avira Real-Time Protection (AntiVirService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Antivirus\avguard.exe =>.Avira Operations GmbH & Co. KG®
SS - Auto [15/02/2017] [ 1519144] Avira Web Protection (AntiVirWebService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe =>.Avira Operations GmbH & Co. KG®
SR - Auto [22/09/2016] [ 83768] Apple Mobile Device Service (Apple Mobile Device Service) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe =>.Apple Inc.®
SR - Auto [18/04/2003] [ 8192] ATPL Digital v6 update service (ATPLupd) . (...) - C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\updatescripts\srvany.exe
SR - Auto [29/12/2016] [ 372272] Avira Service Host (Avira.ServiceHost) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe =>.Avira Operations GmbH & Co. KG®
SS - Auto [10/02/2017] [ 310152] Avira Phantom VPN (AviraPhantomVPN) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe =>.Avira Operations GmbH & Co. KG®
SR - Auto [18/10/2010] [ 20550] BGS (BGS) . (.Apache Software Foundation.) - C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\bin\Apache.exe =>.Apache Software Foundation
SR - Auto [12/08/2015] [ 462096] Bonjour Service (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.®
SR - Auto [26/10/2012] [ 282112] BrYNSvc (BrYNSvc) . (.Brother Industries, Ltd..) - C:\Program Files (x86)\Browny02\BrYNSvc.exe =>.Brother Industries, Ltd.
SS - Auto [22/02/2017] [ 143144] Dropbox Update Service (dbupdate) (dbupdate) . (.Dropbox, Inc..) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe =>.Dropbox, Inc®
SS - Auto [22/02/2017] [ 143144] Dropbox Update Service (dbupdatem) (dbupdatem) . (.Dropbox, Inc..) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe =>.Dropbox, Inc®
SR - Auto [09/02/2017] [ 46408] DbxSvc (DbxSvc) . (.Dropbox, Inc..) - C:\Windows\system32\DbxSvc.exe =>.Dropbox, Inc®
SR - Auto [13/03/2016] [ 1044816] FLEXnet Licensing Service (FLEXnet Licensing Service) . (.Flexera Software, Inc..) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe =>.Flexera Software, Inc. ®
SR - Auto [20/11/2009] [ 13336] Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe =>.Intel Corporation®
SR - Auto [03/04/2005] [ 69632] InstallDriver Table Manager (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe =>.Macrovision Corporation
SR - Auto [19/01/2017] [ 651576] iPod Service (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe =>.Apple Inc.®
SR - Auto [04/01/2007] [ 112152] IviRegMgr (IviRegMgr) . (.InterVideo.) - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe =>.Intervideo, Inc.®
SR - Auto [14/12/2009] [ 268824] Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation®
SR - Auto [28/09/2007] [ 156976] Maxtor Service (Maxtor Sync Service) . (.Seagate Technology LLC.) - C:\Program Files (x86)\Maxtor\Sync\SyncServices.exe {25B1DD7CD102F294C6B4A039166590E7} =>.Seagate Technology LLC
SS - Demand [20/01/2017] [ 4355024] Malwarebytes Service (MBAMService) . (.Malwarebytes.) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation®
SR - Auto [24/10/2009] [ 360224] PMBDeviceInfoProvider (PMBDeviceInfoProvider) . (.Sony Corporation.) - C:\Program Files (x86)\SONY\PMB\PMBDeviceInfoProvider.exe =>.Sony Corporation®
SR - Auto [24/07/2007] [ 185632] Protexis Licensing V2 (PSI_SVC_2) . (.Protexis Inc..) - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe =>.Protexis Inc.®
SS - Auto [31/08/2009] [ 313840] Roxio UPnP Renderer 10 (Roxio UPnP Renderer 10) . (.Sonic Solutions.) - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe =>.Sonic Solutions®
SS - Auto [31/08/2009] [ 362992] Roxio Upnp Server 10 (Roxio Upnp Server 10) . (.Sonic Solutions.) - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe =>.Sonic Solutions®
SR - Auto [29/01/2011] [ 259192] VAIO Care Performance Service (SampleCollector) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Care\VCPerfService.exe =>.Sony Corporation of America®
SS - Auto [21/02/2017] [ 116312] Scout Update Service (scupdate) (scupdate) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe =>.Avira Operations GmbH & Co. KG®
SS - Demand [21/02/2017] [ 116312] Scout Update Service (scupdatem) (scupdatem) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe =>.Avira Operations GmbH & Co. KG®
SS - Auto [16/01/2017] [ 317400] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl®
SR - Auto [16/01/2017] [ 317400] VAIO Media plus Content Importer (SOHCImp) . (.Sony Corporation.) - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe =>.Sony Corporation®
SR - Auto [16/01/2017] [ 317400] VAIO Media plus Digital Media Server (SOHDms) . (.Sony Corporation.) - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe =>.Sony Corporation®
SR - Auto [16/01/2017] [ 317400] VAIO Media plus Device Searcher (SOHDs) . (.Sony Corporation.) - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe =>.Sony Corporation®
SR - Auto [16/01/2017] [ 317400] VAIO Entertainment Common Service (SpfService) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe =>.Sony Corporation®
SR - Auto [16/01/2017] [ 317400] Intel(R) Management & Security Application User Notificatio (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe =>.Intel Corporation®
SR - Auto [16/01/2017] [ 317400] VAIO Entertainment TV Device Arbitration Service (VAIO Entertainment TV Device Arbitration Service) . (.Sony Corporation.) - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe =>.Sony Corporation®
SR - Auto [16/01/2017] [ 317400] VAIO Event Service (VAIO Event Service) . (.Sony Corporation.) - C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe =>.Sony Corporation®
SS - Demand [16/01/2017] [ 317400] VAIO Power Management (VAIO Power Management) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Power Management\SPMService.exe =>.Sony Corporation®
SR - Auto [16/01/2017] [ 317400] VAIO Content Folder Watcher (VCFw) . (.Sony Corporation.) - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe =>.Sony Corporation®
SR - Demand [16/01/2017] [ 317400] VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) . (.Sony Corporation.) - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe =>.Sony Corporation®
SS - Demand [16/01/2017] [ 317400] VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) . (.Sony Corporation.) - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe =>.Sony Corporation®
SR - Auto [16/01/2017] [ 317400] VAIO Content Metadata XML Interface (VcmXmlIfHelper) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe =>.Sony Corporation®
SR - Auto [16/01/2017] [ 317400] VCService (VCService) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Care\VCService.exe =>.Sony Corporation®
SR - Auto [16/01/2017] [ 317400] VSNService (VSNService) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe =>.Sony Corporation
SR - Auto [16/01/2017] [ 317400] VUAgent (VUAgent) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Update Common\VUAgent.exe =>.Sony Corporation®
SR - Auto [16/01/2017] [ 317400] WD Drive Manager (WDDriveService) . (.Western Digital Technologies, Inc..) - C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe =>.Western Digital Technologies, Inc.®
SR - Auto [16/01/2017] [ 317400] Wondershare Application Framework Service (WsAppService) . (.Wondershare.) - C:\Program Files (x86)\Wondershare\WAF\2.3.0.5\WsAppService.exe =>.Wondershare

---\\ Task Planned Automatically (25) - 7s
[MD5.4EA38FE58411907624030BF31C5AD5AD] [APT] [ATPL Update maintenance] (...) -- C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\htdocs\scripts\removelock.bat [317400] (.Activate.)
[MD5.370EE0B2DF7E416C23EAD422A9CA159E] [APT] [AviraScoutUpdateTaskMachineCore] (.Avira Operations GmbH & Co. KG.) -- C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe [317400] (.Activate.) =>.Avira Operations GmbH & Co. KG®
[MD5.370EE0B2DF7E416C23EAD422A9CA159E] [APT] [AviraScoutUpdateTaskMachineUA] (.Avira Operations GmbH & Co. KG.) -- C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe [317400] (.Activate.) =>.Avira Operations GmbH & Co. KG®
[MD5.3B2336A8281ABE998D156B580D6FAC4F] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [317400] (.Activate.) =>.Piriform Ltd®
[MD5.A1F58FFF448E4099297D6EE0641D4D0E] [APT] [DropboxUpdateTaskMachineCore] (.Dropbox, Inc..) -- C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [317400] (.Activate.) =>.Dropbox, Inc®
[MD5.A1F58FFF448E4099297D6EE0641D4D0E] [APT] [DropboxUpdateTaskMachineUA] (.Dropbox, Inc..) -- C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [317400] (.Activate.) =>.Dropbox, Inc®
[MD5.988A613C7D9B39E8684B5B4CF2CDA65F] [APT] [G2MUpdateTask-S-1-5-21-928801702-3077407482-3869533313-1000] (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\goldfish\AppData\Local\Citrix\GoToMeeting\6441\g2mupdate.exe [317400] (.Activate.) =>.Citrix Online®
[MD5.988A613C7D9B39E8684B5B4CF2CDA65F] [APT] [G2MUploadTask-S-1-5-21-928801702-3077407482-3869533313-1000] (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Users\goldfish\AppData\Local\Citrix\GoToMeeting\6441\g2mupload.exe [317400] (.Activate.) =>.Citrix Online®
[MD5.23985274780D27117C470AA259B79B30] [APT] [Apple\AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [317400] (.Activate.) =>.Apple Inc.®
O39 - APT: ATPL Update maintenance - (...) -- C:\Windows\Tasks\ATPL Update maintenance.job [317400]
O39 - APT: AviraScoutUpdateTaskMachineCore - (.Avira Operations GmbH & Co. KG.) -- C:\Windows\Tasks\AviraScoutUpdateTaskMachineCore.job [317400] =>.Avira Operations GmbH & Co. KG®
O39 - APT: AviraScoutUpdateTaskMachineUA - (.Avira Operations GmbH & Co. KG.) -- C:\Windows\Tasks\AviraScoutUpdateTaskMachineUA.job [317400] =>.Avira Operations GmbH & Co. KG®
O39 - APT: DropboxUpdateTaskMachineCore - (.Dropbox, Inc..) -- C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job [317400] =>.Dropbox, Inc®
O39 - APT: DropboxUpdateTaskMachineUA - (.Dropbox, Inc..) -- C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job [317400] =>.Dropbox, Inc®
O39 - APT: G2MUpdateTask-S-1-5-21-928801702-3077407482-3869533313-1000 - (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-928801702-3077407482-3869533313-1000.job [317400] =>.Citrix Online®
O39 - APT: G2MUploadTask-S-1-5-21-928801702-3077407482-3869533313-1000 - (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Windows\Tasks\G2MUploadTask-S-1-5-21-928801702-3077407482-3869533313-1000.job [317400] =>.Citrix Online®
O39 - APT: ATPL Update maintenance - (...) -- C:\Windows\System32\Tasks\ATPL Update maintenance [317400]
O39 - APT: AviraScoutUpdateTaskMachineCore - (.Avira Operations GmbH & Co. KG.) -- C:\Windows\System32\Tasks\AviraScoutUpdateTaskMachineCore [317400] =>.Avira Operations GmbH & Co. KG®
O39 - APT: AviraScoutUpdateTaskMachineUA - (.Avira Operations GmbH & Co. KG.) -- C:\Windows\System32\Tasks\AviraScoutUpdateTaskMachineUA [317400] =>.Avira Operations GmbH & Co. KG®
O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\Windows\System32\Tasks\CCleanerSkipUAC [317400] =>.Piriform Ltd®
O39 - APT: Unknown - (.Microsoft Corporation.) -- C:\Windows\System32\Tasks\CreateChoiceProcessTask [317400] =>.Microsoft Corporation
O39 - APT: DropboxUpdateTaskMachineCore - (.Dropbox, Inc..) -- C:\Windows\System32\Tasks\DropboxUpdateTaskMachineCore [317400] =>.Dropbox, Inc®
O39 - APT: DropboxUpdateTaskMachineUA - (.Dropbox, Inc..) -- C:\Windows\System32\Tasks\DropboxUpdateTaskMachineUA [317400] =>.Dropbox, Inc®
O39 - APT: G2MUpdateTask-S-1-5-21-928801702-3077407482-3869533313-1000 - (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-928801702-3077407482-3869533313-1000 [317400] =>.Citrix Online®
O39 - APT: G2MUploadTask-S-1-5-21-928801702-3077407482-3869533313-1000 - (.Citrix Online, a division of Citrix Systems, Inc..) -- C:\Windows\System32\Tasks\G2MUploadTask-S-1-5-21-928801702-3077407482-3869533313-1000 [317400] =>.Citrix Online®

---\\ Auto loading programs from Registry and folders (8) - 0s
O4 - HKCU\..\Run: [CCleaner] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Program Files (x86)\Avira\Antivirus\avgnt.exe =>.Avira Operations GmbH & Co. KG®
O4 - HKLM\..\Wow6432Node\Run: [Avira SystrayStartTrigger] . (.Avira Operations GmbH & Co. KG - Avira Connect.) -- C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe =>.Avira Operations GmbH & Co. KG®
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Desktop Gadgets.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Desktop Gadgets.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-928801702-3077407482-3869533313-1000\..\Run: [CCleaner] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®

---\\ Process running (52) - 3s
[MD5.00000000000000000000000000000000] - (.AMD - AMD External Events Service Module.) -- C:\Windows\system32\atiesrxx.exe [0] [PID.996] =>.AMD
[MD5.00000000000000000000000000000000] - (.AMD - AMD External Events Client Module.) -- C:\Windows\system32\atieclxx.exe [0] [PID.1292] =>.AMD
[MD5.58FD213E044D88825E411A1A0A6AEE64] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) -- C:\Program Files (x86)\Avira\Antivirus\sched.exe [487424] [PID.1496] =>.Avira Operations GmbH & Co. KG®
[MD5.B932E0EE190778D840F1442DFC0F9612] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [82640] [PID.1556] =>.Adobe Systems, Incorporated®
[MD5.58FD213E044D88825E411A1A0A6AEE64] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) -- C:\Program Files (x86)\Avira\Antivirus\avguard.exe [487424] [PID.1612] =>.Avira Operations GmbH & Co. KG®
[MD5.7D811EA7A2AAA49B0446D42CBC1CD338] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768] [PID.1968] =>.Apple Inc.®
[MD5.1E0029B9936F42C86138EADB5C27439E] - (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [909744] [PID.2112] =>.Avira Operations GmbH & Co. KG®
[MD5.4635935FC972C582632BF45C26BFCB0E] - (...) -- C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\updatescripts\srvany.exe [8192] [PID.2164]
[MD5.2D23F723CD072EA0677BADB604B24CCF] - (.The PHP Group - CLI.) -- C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\php\php.exe [28739] [PID.2192] =>.The PHP Group
[MD5.020EC70045C677B40FEA89C3FE483137] - (.Apache Software Foundation - Apache HTTP Server.) -- C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\bin\Apache.exe [20550] [PID.2704] =>.Apache Software Foundation
[MD5.B5C2F92EE1106DFE7BB1CCE4D35B6037] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [462096] [PID.2760] =>.Apple Inc.®
[MD5.0E03E300CB28F30843F40069563CE2AD] - (.Brother Industries, Ltd. - BrYNCSvc.) -- C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112] [PID.2784] =>.Brother Industries, Ltd.
[MD5.020EC70045C677B40FEA89C3FE483137] - (.Apache Software Foundation - Apache HTTP Server.) -- C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\bin\Apache.exe [20550] [PID.2932] =>.Apache Software Foundation
[MD5.A1F58FFF448E4099297D6EE0641D4D0E] - (.Dropbox, Inc. - Dropbox Update.) -- C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144] [PID.3604] =>.Dropbox, Inc®
[MD5.00000000000000000000000000000000] - (.Dropbox, Inc. - Dropbox Service.) -- C:\Windows\system32\DbxSvc.exe [0] [PID.3612] =>.Dropbox, Inc.
[MD5.73081CF28F0AE20A52CA4F67CEE6E6B0] - (.Flexera Software, Inc. - Activation Licensing Service.) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1044816] [PID.3868] =>.Flexera Software, Inc. ®
[MD5.1CF03C69B49ACB70C722DF92755C0C8C] - (.Macrovision Corporation - IDriverT Module.) -- C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632] [PID.3940] =>.Macrovision Corporation
[MD5.97C9EBB84A761D48DC17E0E6B913C164] - (.Apple Inc. - iPodService Module (64-bit).) -- C:\Program Files\iPod\bin\iPodService.exe [651576] [PID.3824] =>.Apple Inc.®
[MD5.213822072085B5BBAD9AF30AB577D817] - (.InterVideo - RegMgr Module.) -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe [112152] [PID.3844] =>.Intervideo, Inc.®
[MD5.5460828F8951D310B42B442877603B8D] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [268824] [PID.152] =>.Intel Corporation®
[MD5.3E6C47A46BDDE1B6B084012B5B69C069] - (.Seagate Technology LLC - Sync Windows Services.) -- C:\Program Files (x86)\Maxtor\Sync\SyncServices.exe [156976] [PID.1464] {25B1DD7CD102F294C6B4A039166590E7} =>.Seagate Technology LLC
[MD5.627FA58ADC043704F9D14CA44340956F] - (.Sony Corporation - Device Information Provider.) -- C:\Program Files (x86)\SONY\PMB\PMBDeviceInfoProvider.exe [360224] [PID.4296] =>.Sony Corporation®
[MD5.A6A7AD767BF5141665F5C675F671B3E1] - (.Protexis Inc. - PsiService PsiService.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [185632] [PID.4320] =>.Protexis Inc.®
[MD5.65CC4779A29C3E82B987BD4961790DFF] - (.Sony Corporation - VAIO Media plus Digital Media Server.) -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe [423280] [PID.4428] =>.Sony Corporation®
[MD5.F47D75CEE1844EEF4A9EA6EE768828FB] - (.Sony Corporation - VAIO Media plus Device Searcher.) -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [67952] [PID.4456] =>.Sony Corporation®
[MD5.9E89C2D6945389270DE067CE51FF7425] - (.Intel Corporation - User Notification Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2320920] [PID.4520] =>.Intel Corporation®
[MD5.8E68E4AA2D7ABBF7C9159D9D2A38AE0F] - (.Sony Corporation - Hardware Resource Manager.) -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [74496] [PID.4596] =>.Sony Corporation®
[MD5.6B31C9CB94927DBEEB62E15275F4CC54] - (.Sony Corporation - VAIO Event Service (Service Module).) -- C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe [205168] [PID.4668] =>.Sony Corporation®
[MD5.6888526AEB8DDABDE6F778FD40FC0693] - (.Sony Corporation - VAIO Content Folder Watcher.) -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [864000] [PID.4704] =>.Sony Corporation®
[MD5.C8E3BA694CC5EACEC4C01660ACE40D56] - (.Sony Corporation - VcmXml Helper Interface.) -- C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [101152] [PID.4740] =>.Sony Corporation®
[MD5.D347D3ABE070AA09C22FC37121555D52] - (.Sony Corporation - VAIOCare.) -- C:\Program Files\Sony\VAIO Care\VCService.exe [44736] [PID.4792] =>.Sony Corporation®
[MD5.047F22BDFDAE6DF6F1E47E747A1237A2] - (.Sony Corporation - VAIO Smart Network Service.) -- C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [845312] [PID.4856] =>.Sony Corporation
[MD5.D62D16E057BE87F5B84A54D1B83822C4] - (.Sony Corporation - VUAgent.exe.) -- C:\Program Files\Sony\VAIO Update Common\VUAgent.exe [1429608] [PID.4936] =>.Sony Corporation®
[MD5.E84CF717E854D02DF30BD1BCC612BEAC] - (.Western Digital Technologies, Inc. - WD Drive Service.) -- C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [308088] [PID.5020] =>.Western Digital Technologies, Inc.®
[MD5.357CABBF155AFD1D3926E62539D2A3A7] - (.Microsoft Corp. - Microsoft® Windows Live ID Service.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2292480] [PID.5112] =>.Microsoft Corporation®
[MD5.3E2F9D42647CDC1024511839762ABC0C] - (.Sony Corporation - VAIO Smart Network.) -- C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe [2367376] [PID.3812] =>.Sony Corporation®
[MD5.7CD368DFF5D7D4BA9F8F46F31EA8877D] - (.Sony Corporation - VAIO Event Service(Service Sub Module).) -- C:\Program Files (x86)\SONY\VAIO Event Service\VESMgrSub.exe [112488] [PID.1192] =>.Sony Corporation®
[MD5.04F75064637D7409519DD52B61E8BB43] - (.Wondershare - Wondershare AppService.) -- C:\Program Files (x86)\Wondershare\WAF\2.3.0.5\WsAppService.exe [415232] [PID.4904] =>.Wondershare
[MD5.D790CAFEFF0291D0AF8C76F5A1EE2E4E] - (.Microsoft Corp. - Microsoft® Windows Live ID Service Monitor.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE [223488] [PID.5200] =>.Microsoft Corporation®
[MD5.2AEE4D1D7E668F1CCF97EDE93509B0EE] - (.Avira Operations GmbH & Co. KG - Avira Service Host.) -- C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [372272] [PID.5688] =>.Avira Operations GmbH & Co. KG®
[MD5.CC800D2D9FD467542BAC7C186C4774AD] - (.Intel Corporation - IAStorDataSvc.) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [13336] [PID.5796] =>.Intel Corporation®
[MD5.C3E69DB0A4E59564230E053232F39AC7] - (.Sony Corporation - VAIO Media plus Content Importer.) -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [108400] [PID.6044] =>.Sony Corporation®
[MD5.B8047E776E50FC2384801083A77900E0] - (.Sony Corporation - VAIO Entertainment Common Service.) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [303872] [PID.2016] =>.Sony Corporation®
[MD5.2508D922074C96B4E7C25D011550EFCA] - (.Avira Operations GmbH & Co. KG - AntiVir shadow copy service.) -- C:\Program Files (x86)\Avira\Antivirus\avshadow.exe [1063016] [PID.5964] =>.Avira Operations GmbH & Co. KG®
[MD5.F0672B2368E859284A4C44AE2CCA4C72] - (.Sony Corporation - VCM Intelligent Analyzing Manager.) -- C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [549168] [PID.1304] =>.Sony Corporation®
[MD5.F48D4468C499D04ACA7B9E6656F5FE69] - (.Avira Operations GmbH & Co. KG - Avira.) -- C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe [159536] [PID.6968] =>.Avira Operations GmbH & Co. KG®
[MD5.735099A055C50FE534D4781D67FD6B83] - (.Sony Corporation - VAIO Care Performance Service.) -- C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192] [PID.7332] =>.Sony Corporation of America®
[MD5.4D96F6F7508BDF46771262EEEA505F98] - (.Sony of America Corporation - VaioCare Window Listener Application.) -- C:\Program Files\Sony\VAIO Care\listener.exe [81016] [PID.7176] =>.Sony Corporation of America®
[MD5.5E8B711CFA94692414D41F01DB04BE64] - (.Google Inc. - Google Update Setup.) -- C:\Windows\Installer\MSI314F.tmp [50403944] [PID.7280] =>.Google Inc®
[MD5.A8FD9222E4D72596BB37DA8BE95C0BA4] - (.Google Inc. - Google Installer.) -- C:\Program Files (x86)\GUM5198.tmp\GoogleUpdate.exe [153752] [PID.8076] =>.Google Inc®
[MD5.DD7423ABBE2913E70D50E9318AD57EE4] - (.Google Inc. - Google Installer.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] [PID.6884] =>.Google Inc®
[MD5.043AA33C9487A2046734C29E53A7DA47] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\goldfish\Desktop\ZHPDiag3.exe [2707968] [PID.4252] =>.Nicolas Coolman

---\\ Google Chrome, Start,Search,Extensions (20) - 0s
G0 - GCSP: Preferences [User Data\Default][HomePage] http://accounts.google.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://accounts.youtube.com =>.Youtube
G0 - GCSP: Preferences [User Data\Default][HomePage] http://apis.google.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://clients5.google.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://docs.google.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://fonts.gstatic.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://lh3.googleusercontent.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.gstatic.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.co.uk =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.gstatic.com =>.Google Inc.
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://login.yahoo.com/ =>.Yahoo! Inc.
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://accounts.google.com/ =>.Google Inc.
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.facebook.com =>.Facebook
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc. =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] Google Chrome manifest =>.Google Inc. =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.

---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (11) - 4s
M0 - MFSP: prefs.js [goldfish - fcotwa47.default] http://www.google.com/ =>.Google Inc.
M1 - SPR:Search Page Redirection - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
P2 - EXT FILE: (.Firefox Hotfix - Firefox Hotfix: avoid updates that wou.) -- C:\Users\goldfish\AppData\Roaming\Mozilla\Firefox\Profiles\fcotwa47.default\extensions\firefox-hotfix@mozilla.org.xpi =>.Firefox Hotfix
P2 - EXT FILE: (.Gareth Hunt - Add, modify and filter HTTP request he.) -- C:\Users\goldfish\AppData\Roaming\Mozilla\Firefox\Profiles\fcotwa47.default\extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}.xpi
P2 - EXT FILE: (.Google (avast) - Google Search from avast.) -- C:\Users\goldfish\AppData\Roaming\Mozilla\Firefox\Profiles\fcotwa47.default\searchplugins\google-avast.xml =>.Google (avast)
P2 - EXT: (.Skype Technologies S.A. - Skype Click to Call.) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} =>.Skype Technologies S.A.
P2 - EXT: (...) -- C:\Users\goldfish\AppData\Roaming\Mozilla\Extensions\prism@developer.mozilla.org
P2 - EXT: (...) -- C:\Users\goldfish\AppData\Roaming\Mozilla\Firefox\Profiles\fcotwa47.default\extensions\abs@avira.com =>.Avira Software
P2 - EXT: (.Microsoft Corporation - Bing Search Engine.) -- C:\Users\goldfish\AppData\Roaming\Mozilla\Firefox\Profiles\fcotwa47.default\extensions\bingsearch.full@microsoft.com =>.Microsoft Corporation
P2 - EXT: (.Avira - Avira SafeSearch Plus.) -- C:\Users\goldfish\AppData\Roaming\Mozilla\Firefox\Profiles\fcotwa47.default\extensions\safesearchplus2@avira.com =>.Avira
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_221.dll =>.Adobe Systems Incorporated

---\\ Internet Explorer Extensions, Start, Search (20) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk-mg5.mail.yahoo.com/ =>.Yahoo! Inc.
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ =>.Google Inc.
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = about:newtab =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = about:newtab =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ =>.Google Inc.
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKEY_USERS\S-1-5-21-928801702-3077407482-3869533313-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ =>.Google Inc.
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphan =>.Microsoft Internet Explorer

---\\ Internet Explorer, Proxy Management (6) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 0
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies []

---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation

---\\ Hosts file redirection (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (1)

---\\ Browser Helper Object (BHO) (6) - 1s
O2 - BHO: Skype for Business Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} (.Orphan.)
O2 - BHO: Windows Live ID Sign-in Helper [64Bits] - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll =>.Microsoft Corporation®
O2 - BHO: SkypeIEPluginBHO [64Bits] - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Skype Technologies S.A. - Skype Click to Call for Internet Explorer.) -- C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll =>.Skype Technologies SA®
O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files\Microsoft Office 15\root\office15\urlredir.dll =>.Microsoft Corporation®
O2 - BHO: Microsoft SkyDrive Pro Browser Helper [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} (.Orphan.)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (...) -- C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (.not file.)

---\\ Global shortcuts Startup (153) - 29s
O4 - GS\Desktop [Administrator]: C901 Budget.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\C901 Budget 20161106.xlsx
O4 - GS\Desktop [Administrator]: C902 Banking.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\C902 Banking 20160721.xlsx
O4 - GS\Desktop [Administrator]: Contact List.lnk . (...) C:\Users\goldfish\Documents\_Flying\Contacts\CONTACT LIST.txt
O4 - GS\Desktop [Administrator]: DIARY.lnk . (.goldfish goldfish - .) C:\Users\goldfish\Documents\DIARY.doc
O4 - GS\Desktop [Administrator]: DiskCheckup.lnk . (.PassMark (TM) Software - www.passmark.com - DiskCheckup.) C:\Program Files (x86)\DiskCheckup\DiskCheckup.exe {38E7FA0DB1A398F805BB85A69171DC9D}
O4 - GS\Desktop [Administrator]: Dropbox.lnk . (.Dropbox, Inc. - Dropbox.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe /home =>.Dropbox, Inc®
O4 - GS\Desktop [Administrator]: Four Six Four.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\Four Six Four.xlsx
O4 - GS\Desktop [Administrator]: GoToMeeting Quick Connect.lnk . (.Citrix Online, a division of Citrix Systems, Inc. - GoToMeeting.) C:\Users\goldfish\AppData\Local\Citrix\GoToMeeting\6291\g2mstart.exe /Mode Terse /Action Join /Trigger Shortcut /Product G2M /FreeTrialUrl http://s.gotomeeting.com/ =>.Citrix Online, a division of Citrix Systems, Inc.
O4 - GS\Desktop [Administrator]: mccPILOTCAL.lnk . (.MCC bvba - .) C:\Users\goldfish\AppData\Roaming\MCC Pilotlog\mccPILOTCAL.exe
O4 - GS\Desktop [Administrator]: mccPILOTLOG.lnk . (.MCC bvba - .) C:\Program Files (x86)\MCC Pilotlog\mccPILOTLOG.exe
O4 - GS\Desktop [Administrator]: Outlook 2013.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office 15\root\office15\OUTLOOK.EXE =>.Microsoft Corporation
O4 - GS\Desktop [Administrator]: Roxio Easy Media Creator 10 LJ.lnk . (.Copyright (C) 2000-2007 - Roxio Creator.) C:\Program Files (x86)\Common Files\Roxio Shared\10.0\Roxio Central36\Main\Roxio_Central36.exe =>.Sonic Solutions®
O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\goldfish\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Administrator]: Avira Scout.lnk . (.Avira Operations GmbH & Co. KG - Avira Scout.) C:\Program Files (x86)\Avira\Scout\Application\scout.exe =>.Avira Operations GmbH & Co. KG®
O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Administrator]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Administrator]: Microsoft Outlook.lnk . (.Microsoft Corporation - Microsoft Outlook.) C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE /recycle =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Administrator]: Wickr Me.lnk . (...) C:\Program Files (x86)\Wickr Inc\Wickr Me\Wickr Me.exe {045D55AD7640E014A9B074ACF4E03319}
O4 - GS\sendTo [Administrator]: Dropbox.lnk . (...) C:\Users\goldfish\Dropbox
O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrator]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\TaskBar [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Administrator]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: Wickr Me.lnk . (...) C:\Program Files (x86)\Wickr Inc\Wickr Me\Wickr Me.exe {045D55AD7640E014A9B074ACF4E03319}
O4 - GS\Programs [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [Administrator]: Windows Install Clean Up.lnk . (.Microsoft Corporation - Windows Installer Clean Up Application.) C:\Program Files (x86)\Windows Installer Clean Up\msicuu.exe =>.Microsoft Corporation
O4 - GS\Desktop [goldfish]: C901 Budget.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\C901 Budget 20161106.xlsx
O4 - GS\Desktop [goldfish]: C902 Banking.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\C902 Banking 20160721.xlsx
O4 - GS\Desktop [goldfish]: Contact List.lnk . (...) C:\Users\goldfish\Documents\_Flying\Contacts\CONTACT LIST.txt
O4 - GS\Desktop [goldfish]: DIARY.lnk . (.goldfish goldfish - .) C:\Users\goldfish\Documents\DIARY.doc
O4 - GS\Desktop [goldfish]: DiskCheckup.lnk . (.PassMark (TM) Software - www.passmark.com - DiskCheckup.) C:\Program Files (x86)\DiskCheckup\DiskCheckup.exe {38E7FA0DB1A398F805BB85A69171DC9D}
O4 - GS\Desktop [goldfish]: Dropbox.lnk . (.Dropbox, Inc. - Dropbox.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe /home =>.Dropbox, Inc®
O4 - GS\Desktop [goldfish]: Four Six Four.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\Four Six Four.xlsx
O4 - GS\Desktop [goldfish]: GoToMeeting Quick Connect.lnk . (.Citrix Online, a division of Citrix Systems, Inc. - GoToMeeting.) C:\Users\goldfish\AppData\Local\Citrix\GoToMeeting\6291\g2mstart.exe /Mode Terse /Action Join /Trigger Shortcut /Product G2M /FreeTrialUrl http://s.gotomeeting.com/ =>.Citrix Online, a division of Citrix Systems, Inc.
O4 - GS\Desktop [goldfish]: mccPILOTCAL.lnk . (.MCC bvba - .) C:\Users\goldfish\AppData\Roaming\MCC Pilotlog\mccPILOTCAL.exe
O4 - GS\Desktop [goldfish]: mccPILOTLOG.lnk . (.MCC bvba - .) C:\Program Files (x86)\MCC Pilotlog\mccPILOTLOG.exe
O4 - GS\Desktop [goldfish]: Outlook 2013.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office 15\root\office15\OUTLOOK.EXE =>.Microsoft Corporation
O4 - GS\Desktop [goldfish]: Roxio Easy Media Creator 10 LJ.lnk . (.Copyright (C) 2000-2007 - Roxio Creator.) C:\Program Files (x86)\Common Files\Roxio Shared\10.0\Roxio Central36\Main\Roxio_Central36.exe =>.Sonic Solutions®
O4 - GS\Desktop [goldfish]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\goldfish\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [goldfish]: Avira Scout.lnk . (.Avira Operations GmbH & Co. KG - Avira Scout.) C:\Program Files (x86)\Avira\Scout\Application\scout.exe =>.Avira Operations GmbH & Co. KG®
O4 - GS\Quicklaunch [goldfish]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [goldfish]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [goldfish]: Microsoft Outlook.lnk . (.Microsoft Corporation - Microsoft Outlook.) C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE /recycle =>.Microsoft Corporation®
O4 - GS\Quicklaunch [goldfish]: Wickr Me.lnk . (...) C:\Program Files (x86)\Wickr Inc\Wickr Me\Wickr Me.exe {045D55AD7640E014A9B074ACF4E03319}
O4 - GS\sendTo [goldfish]: Dropbox.lnk . (...) C:\Users\goldfish\Dropbox
O4 - GS\sendTo [goldfish]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [goldfish]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\TaskBar [goldfish]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [goldfish]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [goldfish]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\TaskBar [goldfish]: Wickr Me.lnk . (...) C:\Program Files (x86)\Wickr Inc\Wickr Me\Wickr Me.exe {045D55AD7640E014A9B074ACF4E03319}
O4 - GS\Programs [goldfish]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [goldfish]: Windows Install Clean Up.lnk . (.Microsoft Corporation - Windows Installer Clean Up Application.) C:\Program Files (x86)\Windows Installer Clean Up\msicuu.exe =>.Microsoft Corporation
O4 - GS\Desktop [Guest]: C901 Budget.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\C901 Budget 20161106.xlsx
O4 - GS\Desktop [Guest]: C902 Banking.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\C902 Banking 20160721.xlsx
O4 - GS\Desktop [Guest]: Contact List.lnk . (...) C:\Users\goldfish\Documents\_Flying\Contacts\CONTACT LIST.txt
O4 - GS\Desktop [Guest]: DIARY.lnk . (.goldfish goldfish - .) C:\Users\goldfish\Documents\DIARY.doc
O4 - GS\Desktop [Guest]: DiskCheckup.lnk . (.PassMark (TM) Software - www.passmark.com - DiskCheckup.) C:\Program Files (x86)\DiskCheckup\DiskCheckup.exe {38E7FA0DB1A398F805BB85A69171DC9D}
O4 - GS\Desktop [Guest]: Dropbox.lnk . (.Dropbox, Inc. - Dropbox.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe /home =>.Dropbox, Inc®
O4 - GS\Desktop [Guest]: Four Six Four.xlsx.lnk . (.goldfish - .) C:\Users\goldfish\Documents\Four Six Four.xlsx
O4 - GS\Desktop [Guest]: GoToMeeting Quick Connect.lnk . (.Citrix Online, a division of Citrix Systems, Inc. - GoToMeeting.) C:\Users\goldfish\AppData\Local\Citrix\GoToMeeting\6291\g2mstart.exe /Mode Terse /Action Join /Trigger Shortcut /Product G2M /FreeTrialUrl http://s.gotomeeting.com/ =>.Citrix Online, a division of Citrix Systems, Inc.
O4 - GS\Desktop [Guest]: mccPILOTCAL.lnk . (.MCC bvba - .) C:\Users\goldfish\AppData\Roaming\MCC Pilotlog\mccPILOTCAL.exe
O4 - GS\Desktop [Guest]: mccPILOTLOG.lnk . (.MCC bvba - .) C:\Program Files (x86)\MCC Pilotlog\mccPILOTLOG.exe
O4 - GS\Desktop [Guest]: Outlook 2013.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office 15\root\office15\OUTLOOK.EXE =>.Microsoft Corporation
O4 - GS\Desktop [Guest]: Roxio Easy Media Creator 10 LJ.lnk . (.Copyright (C) 2000-2007 - Roxio Creator.) C:\Program Files (x86)\Common Files\Roxio Shared\10.0\Roxio Central36\Main\Roxio_Central36.exe =>.Sonic Solutions®
O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\goldfish\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Guest]: Avira Scout.lnk . (.Avira Operations GmbH & Co. KG - Avira Scout.) C:\Program Files (x86)\Avira\Scout\Application\scout.exe =>.Avira Operations GmbH & Co. KG®
O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Guest]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Guest]: Microsoft Outlook.lnk . (.Microsoft Corporation - Microsoft Outlook.) C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE /recycle =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Guest]: Wickr Me.lnk . (...) C:\Program Files (x86)\Wickr Inc\Wickr Me\Wickr Me.exe {045D55AD7640E014A9B074ACF4E03319}
O4 - GS\sendTo [Guest]: Dropbox.lnk . (...) C:\Users\goldfish\Dropbox
O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Guest]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\TaskBar [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Guest]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: Wickr Me.lnk . (...) C:\Program Files (x86)\Wickr Inc\Wickr Me\Wickr Me.exe {045D55AD7640E014A9B074ACF4E03319}
O4 - GS\Programs [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [Guest]: Windows Install Clean Up.lnk . (.Microsoft Corporation - Windows Installer Clean Up Application.) C:\Program Files (x86)\Windows Installer Clean Up\msicuu.exe =>.Microsoft Corporation
O4 - GS\CommonDesktop [Public]: 3 Malwarebytes.lnk . (.Malwarebytes - Malwarebytes.) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe =>.Malwarebytes Corporation®
O4 - GS\CommonDesktop [Public]: 4 SUPERAntiSpyware Free Edition.lnk . (.SUPERAntiSpyware - SUPERAntiSpyware Application.) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe =>.SUPERAntiSpyware.com®
O4 - GS\CommonDesktop [Public]: ATPL Digital.lnk . (.Bristol.gs - ATPL Digital.) C:\Program Files (x86)\Bristol.gs\ATPL Digital\AtplDigital.exe
O4 - GS\CommonDesktop [Public]: Avira Connect.lnk . (.Avira Operations GmbH & Co. KG - Avira.) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe /showMiniGui =>.Avira Operations GmbH & Co. KG®
O4 - GS\CommonDesktop [Public]: Avira Phantom VPN.lnk . (.Avira Operations GmbH & Co. KG - Avira.WebAppHost.) C:\Program Files (x86)\Avira\VPN\Avira.WebAppHost.exe =>.Avira Operations GmbH & Co. KG®
O4 - GS\CommonDesktop [Public]: Avira Scout.lnk . (.Avira Operations GmbH & Co. KG - Avira Scout.) C:\Program Files (x86)\Avira\Scout\Application\scout.exe =>.Avira Operations GmbH & Co. KG®
O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Ltd - CCleaner.) C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - GS\CommonDesktop [Public]: Family Tree Maker 2006.lnk . (.MyFamily.com, Inc. - Family Tree Maker executable.) C:\Program Files (x86)\Family Tree Maker 2006\FTW.exe
O4 - GS\CommonDesktop [Public]: Free iTunes Backup Extractor.lnk . (.Apex Co. Ltd. - Jihosoft iTunes Extractor.) C:\Program Files (x86)\Jihosoft\Free iTunes Backup Extractor\iTunes Backup Extractor.exe =>.HONGKONG JIHO CO., LIMITED®
O4 - GS\CommonDesktop [Public]: iTunes.lnk . (.Apple Inc. - .) C:\Program Files (x86)\iTunes\iTunes.exe =>.Apple Inc.
O4 - GS\CommonDesktop [Public]: Maxtor Manager.lnk . (.Macrovision Corporation - InstallShield.) C:\Windows\Installer\{ED01D958-AEDC-40C8-93FD-0C08E8AA9530}\NewShortcut2_60EEB642E9E045A2A676B9D8FE17C4A9.exe =>.Macrovision Corporation
O4 - GS\CommonDesktop [Public]: RANT XL.lnk . (...) C:\Program Files (x86)\RANTXL\Rant.exe
O4 - GS\CommonDesktop [Public]: Removal Tool.lnk . (.9-lab LLC - 9-lab Malware Removal Tool.) C:\Program Files\9-lab\Removal Tool\rmtool.exe =>.9-Lab®
O4 - GS\CommonDesktop [Public]: RogueKiller.lnk . (...) C:\Program Files\RogueKiller\RogueKiller64.exe =>.Adlice®
O4 - GS\CommonDesktop [Public]: Run ATP Digital 6.lnk . (.Mozilla Foundation - .) C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\client\prism.exe -webapp BGS =>.Mozilla Foundation
O4 - GS\CommonDesktop [Public]: SeaTools for Windows.lnk . (...) C:\Windows\Installer\{98613C99-1399-416C-A07C-1EE1C585D872}\Icon98613C992.exe
O4 - GS\CommonDesktop [Public]: Skype.lnk . (...) C:\Windows\Installer\{FC965A47-4839-40CA-B618-18F486F042C6}\SkypeIcon.exe =>.Skype Technologies
O4 - GS\CommonDesktop [Public]: WD Backup.lnk . (.Western Digital Technologies, Inc. - WD App Manager.) C:\Program Files (x86)\Western Digital\WD App Manager\WDAppManager.exe -launchbackupdefault =>.WESTERN DIGITAL TECHNOLOGIES®
O4 - GS\CommonDesktop [Public]: Wickr Me.lnk . (...) C:\Program Files (x86)\Wickr Inc\Wickr Me\Wickr Me.exe {045D55AD7640E014A9B074ACF4E03319}
O4 - GS\CommonDesktop [Public]: ZoomBrowser EX.lnk . (.Copyright © 2002-2006 CISRA - Zb Module.) C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\ZoomBrowser.exe
O4 - GS\Programs [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [Public]: Windows Install Clean Up.lnk . (.Microsoft Corporation - Windows Installer Clean Up Application.) C:\Program Files (x86)\Windows Installer Clean Up\msicuu.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Command Prompt.lnk . (.Microsoft Corporation - Windows Command Processor.) C:\Windows\system32\cmd.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe -extoff =>.Microsoft Corporation®
O4 - GS\SystemTools [Public]: Private Character Editor.lnk . (.Microsoft Corporation - Private Character Editor.) C:\Windows\system32\eudcedit.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Bluetooth File Transfer Wizard.lnk . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Windows Calculator.) C:\Windows\system32\calc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - Display Switch.) C:\Windows\system32\displayswitch.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Math Input Panel Accessory.) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - Windows Mobility Center.) C:\Windows\system32\mblctr.exe /open =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\Windows\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\Windows\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Windows Sound Recorder.) C:\Windows\system32\SoundRecorder.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - Sticky Notes.) C:\Windows\system32\StikyNot.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) C:\Windows\System32\mobsync.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Welcome Center.lnk . (.Microsoft Corporation - Windows host process (Rundll32).) C:\Windows\system32\rundll32.exe %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) C:\Windows\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - Microsoft® Disk Defragmenter.) C:\Windows\system32\dfrgui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - Disk Space Cleanup Manager for Windows.) C:\Windows\system32\cleanmgr.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - Resource and Performance Monitor.) C:\Windows\system32\perfmon.exe /res =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - System Information.) C:\Windows\system32\msinfo32.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - Microsoft® Windows System Restore.) C:\Windows\system32\rstrui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) C:\Windows\system32\taskschd.msc /s =>..Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - Windows Easy Transfer Post Migration Applic.) C:\Windows\system32\migwiz\postmig.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - Windows Easy Transfer Application.) C:\Windows\system32\migwiz\migwiz.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Acrobat Reader DC.lnk . (.Flexera Software LLC - InstallShield.) C:\Windows\Installer\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\SC_Reader.ico =>.Flexera Software LLC
O4 - GS\ProgramsCommon [Public]: Apple Software Update.lnk . (...) C:\Windows\Installer\{56EC47AA-5813-4FF6-8E75-544026FBEA83}\AppleSoftwareUpdateIco.exe =>.Apple Inc.
O4 - GS\ProgramsCommon [Public]: Citrix Receiver.lnk . (.Citrix Systems, Inc. - Citrix Receiver.) C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfService.exe -showAppPicker {1DCED972D082A6A82CA2A99FBCEA3A95} =>.Citrix Systems, Inc.
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\ProgramsCommon [Public]: Media Gallery.lnk . (.Sony Corporation - Media Gallery.) C:\Program Files (x86)\SONY\Media Gallery\VRLP.exe =>.Sony Corporation®
O4 - GS\ProgramsCommon [Public]: Movie Maker.lnk . (.Microsoft Corporation - Movie Maker.) C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Photo Gallery.lnk . (.Microsoft Corporation - Photo Gallery.) C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: PMB.lnk . (.Sony Corporation - Browser.) C:\Program Files (x86)\SONY\PMB\PMBBrowser.exe =>.Sony Corporation
O4 - GS\ProgramsCommon [Public]: VAIO Care.lnk . (.Sony Corporation - VAIOCare.) C:\Program Files\Sony\VAIO Care\VAIOCare.exe =>.Sony Corporation®
O4 - GS\ProgramsCommon [Public]: VAIO Control Center.lnk . (.Sony Corporation - VAIO Control Center.) C:\Program Files (x86)\SONY\VAIO Control Center\VAIO Control Center.exe /VCC =>.Sony Corporation®
O4 - GS\ProgramsCommon [Public]: VAIO Data Restore Tool.lnk . (.Sony Corporation - Restore Data.) C:\Program Files (x86)\Sony\VAIO Data Restore Tool\Restore.exe =>.Sony Corporation®
O4 - GS\ProgramsCommon [Public]: VAIO Documentation.lnk . (...) C:\Documentation\Documentation
O4 - GS\ProgramsCommon [Public]: VAIO Gate.lnk . (.Sony Corporation - .) C:\Program Files (x86)\Sony\VAIO Gate\VAIO Gate.exe =>.Sony Corporation
O4 - GS\ProgramsCommon [Public]: VAIO Media plus.lnk . (.Sony Corporation - VAIO Media plus.) C:\Program Files (x86)\SONY\VAIO Media plus\VMp.exe =>.Sony Corporation®
O4 - GS\ProgramsCommon [Public]: VAIO Premium Partners.lnk . (...) C:\Program Files (x86)\Sony Corporation\VAIO Partners\VAIOPartners.exe
O4 - GS\ProgramsCommon [Public]: VAIO Recovery Center.lnk . (.Copyright 2002 - 2009 Sony Corporation - VAIO Recovery Center.) C:\Program Files (x86)\SONY\VAIO RECOVERY\VAIORecv.exe =>.Sony Corporation of America®
O4 - GS\ProgramsCommon [Public]: VAIO Transfer Support.lnk . (.Sony Corporation - VAIO Transfer Support.) C:\Program Files (x86)\SONY\VAIO Transfer Support\VAIOTransfer.exe =>.Sony Corporation®
O4 - GS\ProgramsCommon [Public]: VAIO Update.lnk . (.Sony Corporation - .) C:\Program Files (x86)\Sony\VAIO Update 5\VAIOUpdt.exe =>.Sony Corporation
O4 - GS\ProgramsCommon [Public]: Windows Anytime Upgrade.lnk . (.Microsoft Corporation - Windows Anytime Upgrade User Interface.) C:\Windows\system32\WindowsAnytimeUpgradeUI.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows DVD Maker.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\DVD Maker\DVDMaker.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Mobile Device Center.lnk . (.Microsoft Corporation - Windows Mobile Device Center.) C:\Windows\Installer\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}\wmdc.exe /show =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: XPS Viewer.lnk . (.Microsoft Corporation - XPS Viewer.) C:\Windows\system32\xpsrchvw.exe =>.Microsoft Corporation

---\\ Lop.com/Domain Hijackers (5) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = lan =>.Local Domain
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}: DhcpNameServer = 192.168.1.1 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{1EFB8A60-ADE3-4852-AA62-C8616E1EABDA}: DhcpDomain = lan =>.Local Domain
O17 - HKLM\System\CCS\Services\Tcpip\..\{927587AB-1894-493E-8E72-6063314BF69A}: DhcpDomain = lan =>.Local Domain

---\\ Extra protocols (42) - 3s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-help [64Bits] - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll =>.Microsoft Corporation®
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: osf [64Bits] - {D924BDC6-C83A-4BD5-90D0-095128A113D1} . (.Microsoft Corporation - Microsoft Office 2013 component.) -- C:\Program Files\Microsoft Office 15\root\office15\msosb.dll =>.Microsoft Corporation®
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: skype-ie-addon-data [64Bits] - {91774881-D725-4E58-B298-07617B9B86A8} . (.Skype Technologies S.A. - Skype Click to Call for Internet Explorer.) -- C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll =>.Skype Technologies SA®
O18 - Handler: skype4com [64Bits] - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} . (.Skype Technologies - Skype4COM.) -- C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll =>.Skype Software Sarl®
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Photo Gallery Album Download Protocol Handl.) -- C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll =>.Microsoft Corporation®
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-ica [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) -- C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O18 - Filter: application/x-ica; charset=euc-jp [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) -- C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O18 - Filter: application/x-ica; charset=ISO-8859-1 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) -- C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O18 - Filter: application/x-ica; charset=MS936 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) -- C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O18 - Filter: application/x-ica; charset=MS949 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) -- C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O18 - Filter: application/x-ica; charset=MS950 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) -- C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O18 - Filter: application/x-ica; charset=UTF-8 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) -- C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O18 - Filter: application/x-ica; charset=UTF8 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) -- C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O18 - Filter: application/x-ica;charset=euc-jp [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) -- C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O18 - Filter: application/x-ica;charset=ISO-8859-1 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) -- C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O18 - Filter: application/x-ica;charset=MS936 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) -- C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O18 - Filter: application/x-ica;charset=MS949 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) -- C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O18 - Filter: application/x-ica;charset=MS950 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) -- C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O18 - Filter: application/x-ica;charset=UTF-8 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) -- C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O18 - Filter: application/x-ica;charset=UTF8 [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) -- C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: ica [64Bits] - {CFB6322E-CC85-4d1b-82C7-893888A236BC} . (.Citrix Systems, Inc. - Citrix Receiver ICAMimeFilter DLL.) -- C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O18 - Filter: text/xml [64Bits] - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL =>.Microsoft Corporation®

---\\ Software installed (188) - 53s
O42 - Logiciel: 9-lab Removal Tool - (..) [HKLM][64Bits] -- 9-lab Removal Tool =>.9-Lab®
O42 - Logiciel: Adobe Acrobat Reader DC - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1033-7B44-AC0F074E4100} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Flash Player 24 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Flash Player 24 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-0804-1033-1959-001824211354} =>.Adobe Systems Incorporated
O42 - Logiciel: Alps Pointing-device for VAIO - (.ALPS ELECTRIC CO., LTD..) [HKLM][64Bits] -- {9F72EF8B-AEC9-4CA5-B483-143980AFD6FD} =>.Alps Electric Co., LTD.®
O42 - Logiciel: Apple Application Support (32-bit) - (.Apple Inc..) [HKLM][64Bits] -- {9BA1A894-B42F-4805-BC8C-349C905A3930} =>.Apple Inc.
O42 - Logiciel: Apple Application Support (64-bit) - (.Apple Inc..) [HKLM][64Bits] -- {7EAC8A42-9FAC-4F6B-AABF-C08C9F2E0F13} =>.Apple Inc.
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM][64Bits] -- {55BB2110-FB43-49B3-93F4-945A0CFB0A6C} =>.Apple Inc.
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM][64Bits] -- {56EC47AA-5813-4FF6-8E75-544026FBEA83} =>.Apple Inc.
O42 - Logiciel: ArcSoft Magic-i Visual Effects 2 - (.ArcSoft.) [HKLM][64Bits] -- {7BB90344-0647-468E-925A-7F69F7983421} =>.ArcSoft
O42 - Logiciel: ArcSoft WebCam Companion 3 - (.ArcSoft.) [HKLM][64Bits] -- {DE8AAC73-6D8D-483E-96EA-CAEDDADB9079} =>.ArcSoft
O42 - Logiciel: ATI Catalyst Install Manager - (.ATI Technologies, Inc..) [HKLM][64Bits] -- {5BC83141-83DD-07BE-C940-04B385540F04} =>.ATI Technologies, Inc.
O42 - Logiciel: ATP DIGITAL 6 - (.ATP DIGITAL.) [HKLM][64Bits] -- {0C264625-303E-4458-93BB-B95CA9CB0209}
O42 - Logiciel: Avira Antivirus v15.0.25.154 - (.Avira Operations GmbH & Co. KG.) [HKLM][64Bits] -- Avira Antivirus =>.Avira Operations GmbH & Co. KG®
O42 - Logiciel: Avira Connect v1.2.77.41287 - (.Avira Operations GmbH & Co. KG.) [HKLM][64Bits] -- {7774002B-60B3-4146-BF82-5BF767D468B8} =>.Avira Operations GmbH & Co. KG
O42 - Logiciel: Avira Connect v1.2.77.41287 - (.Avira Operations GmbH & Co. KG.) [HKLM][64Bits] -- {845380e2-f0b5-4584-bc40-cc54345b3c06} =>.Avira Operations GmbH & Co. KG®
O42 - Logiciel: Avira Phantom VPN v2.6.1.20906 - (.Avira Operations GmbH & Co. KG.) [HKLM][64Bits] -- Avira Phantom VPN =>.Avira Operations GmbH & Co. KG®
O42 - Logiciel: Avira Scout v17.1.2924.2344 - (.Avira Operations GmbH & Co. KG.) [HKLM][64Bits] -- Avira Scout =>.Avira Operations GmbH & Co. KG®
O42 - Logiciel: Aware System Update - (.Airbox Aerospace Ltd.) [HKCU][64Bits] -- b9355229a2e7c67c
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM][64Bits] -- {56DDDFB8-7F79-4480-89D5-25E1F52AB28F} =>.Apple Inc.
O42 - Logiciel: Canon MOV Decoder - (.Canon Inc..) [HKLM][64Bits] -- Canon MOV Decoder =>.Canon Inc.®
O42 - Logiciel: Canon MOV Encoder - (.Canon Inc..) [HKLM][64Bits] -- Canon MOV Encoder =>.Canon Inc.®
O42 - Logiciel: Canon MovieEdit Task for ZoomBrowser EX - (.Canon Inc..) [HKLM][64Bits] -- MovieEditTask =>.Canon Inc.®
O42 - Logiciel: Canon Utilities CameraWindow - (.Canon Inc..) [HKLM][64Bits] -- CameraWindowLauncher =>.Canon Inc.®
O42 - Logiciel: Canon Utilities CameraWindow DC - (.Canon Inc..) [HKLM][64Bits] -- CameraWindowDC =>.Canon Inc.®
O42 - Logiciel: Canon Utilities CameraWindow DC 8 - (.Canon Inc..) [HKLM][64Bits] -- CameraWindowDC8 =>.Canon Inc.®
O42 - Logiciel: Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX - (.Canon Inc..) [HKLM][64Bits] -- CameraWindowDVC6 =>.Canon Inc.®
O42 - Logiciel: Canon Utilities MyCamera - (.Canon Inc..) [HKLM][64Bits] -- MyCamera =>.Canon Inc.®
O42 - Logiciel: Canon Utilities MyCamera DC - (.Canon Inc..) [HKLM][64Bits] -- MyCameraDC =>.Canon Inc.®
O42 - Logiciel: Canon Utilities PhotoStitch - (.Canon Inc..) [HKLM][64Bits] -- PhotoStitch =>.Canon Inc.®
O42 - Logiciel: Canon Utilities RemoteCapture Task for ZoomBrowser EX - (.Canon Inc..) [HKLM][64Bits] -- RemoteCaptureTask =>.Canon Inc.®
O42 - Logiciel: Canon Utilities ZoomBrowser EX - (.Canon Inc..) [HKLM][64Bits] -- ZoomBrowser EX =>.Canon Inc.®
O42 - Logiciel: Canon ZoomBrowser EX Memory Card Utility - (.Canon Inc..) [HKLM][64Bits] -- ZoomBrowser EX Memory Card Utility =>.Canon Inc.®
O42 - Logiciel: Catalyst Control Center - Branding - (.ATI.) [HKLM][64Bits] -- {C5529BC1-C2BF-44E8-B62A-01913D70081C} =>.ATI
O42 - Logiciel: Catalyst Control Center Core Implementation - (.ATI.) [HKLM][64Bits] -- {5736590B-36C7-4881-5EBE-F9B390F00774} =>.ATI
O42 - Logiciel: Catalyst Control Center Graphics Full Existing - (.ATI.) [HKLM][64Bits] -- {88001121-87E2-2104-F9F5-ECC15DFCA1E0} =>.ATI
O42 - Logiciel: Catalyst Control Center Graphics Full New - (.ATI.) [HKLM][64Bits] -- {A8D53A4E-77A1-E23E-A396-6D9C86A2F273} =>.ATI
O42 - Logiciel: Catalyst Control Center Graphics Light - (.ATI.) [HKLM][64Bits] -- {265F0D95-A883-7162-0458-B78085B6B693} =>.ATI
O42 - Logiciel: Catalyst Control Center Graphics Previews Common - (.ATI.) [HKLM][64Bits] -- {D49989B0-7BC2-F7F1-8017-3257F617347A} =>.ATI
O42 - Logiciel: Catalyst Control Center Graphics Previews Vista - (.ATI.) [HKLM][64Bits] -- {C2E171F6-9B58-4CE1-7B8B-B69FA04EBAB8} =>.ATI
O42 - Logiciel: Catalyst Control Center InstallProxy - (.ATI Technologies, Inc..) [HKLM][64Bits] -- {935B5086-C002-0FBC-0723-5741D2478EE7} =>.ATI Technologies, Inc.
O42 - Logiciel: Catalyst Control Center InstallProxy - (.ATI Technologies, Inc..) [HKLM][64Bits] -- {F7E8DD1D-9BFD-38BB-86A5-BEF313B00C51} =>.ATI Technologies, Inc.
O42 - Logiciel: Catalyst Control Center Localization All - (.ATI.) [HKLM][64Bits] -- {F5CC9A13-6C57-4948-75A8-3A2C92A3183B} =>.ATI
O42 - Logiciel: ccc-core-static - (.ATI.) [HKLM][64Bits] -- {F1B95046-E9DA-CFEC-42A8-C8224646AA32} =>.ATI
O42 - Logiciel: ccc-utility64 - (.ATI.) [HKLM][64Bits] -- {259FD439-13B0-0136-D0A0-FA89BB05831D} =>.ATI
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>.Piriform Ltd®
O42 - Logiciel: Chinese Traditional Fonts Support For Adobe Reader 9 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-2448-0000-900000000003} =>.Adobe Systems Incorporated
O42 - Logiciel: Citrix Authentication Manager - (.Citrix Systems, Inc..) [HKLM][64Bits] -- {CA55005D-94AC-4596-9646-679D6CC0D620} =>.Citrix Systems, Inc.
O42 - Logiciel: Citrix Receiver - (.Citrix Systems, Inc..) [HKLM][64Bits] -- CitrixOnlinePluginPackWeb {05F124BF6C987707E8DAADA96A6C948B} =>.Citrix Systems, Inc.
O42 - Logiciel: Citrix Receiver (HDX Flash Redirection) - (.Citrix Systems, Inc..) [HKLM][64Bits] -- {C4E28723-0663-4012-9BDC-E21A14C1316C} =>.Citrix Systems, Inc.
O42 - Logiciel: Citrix Receiver Inside - (.Citrix Systems, Inc..) [HKLM][64Bits] -- {D9EE360A-7C19-47EC-93C7-97DEFF64804B} =>.Citrix Systems, Inc.
O42 - Logiciel: Citrix Receiver Updater - (.Citrix Systems, Inc..) [HKLM][64Bits] -- {5E8AC853-65BB-4C99-A09E-19B81851E14C} =>.Citrix Systems, Inc.
O42 - Logiciel: Citrix Receiver(Aero) - (.Citrix Systems, Inc..) [HKLM][64Bits] -- {012C59CF-074A-43DA-8085-B6E636733B59} =>.Citrix Systems, Inc.
O42 - Logiciel: Citrix Receiver(DV) - (.Citrix Systems, Inc..) [HKLM][64Bits] -- {ADE8A83D-BB70-4FB5-BA19-26C47EA31894} =>.Citrix Systems, Inc.
O42 - Logiciel: Citrix Receiver(USB) - (.Citrix Systems, Inc..) [HKLM][64Bits] -- {0E1C5B43-1837-4F98-A96B-79A8A0A5955F} =>.Citrix Systems, Inc.
O42 - Logiciel: Click to Disc MergeModules x64 - (.Sony Corporation.) [HKLM][64Bits] -- {393A9268-A428-4F5A-9B20-BD753309A98E} =>.Sony Corporation
O42 - Logiciel: Corel WinDVD - (.Corel Inc..) [HKLM][64Bits] -- {5C1F18D2-F6B7-4242-B803-B5A78648185D} =>.Corel Inc.
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF} =>.Microsoft
O42 - Logiciel: DiskCheckup v3.1 - (.PassMark Software.) [HKLM][64Bits] -- DiskCheckup_is1 =>.PassMark Software
O42 - Logiciel: Dropbox - (.Dropbox, Inc..) [HKLM][64Bits] -- Dropbox =>.Dropbox, Inc®
O42 - Logiciel: Dropbox Update Helper - (.Dropbox, Inc..) [HKLM][64Bits] -- {099218A5-A723-43DC-8DB5-6173656A1E94} =>.Dropbox, Inc.
O42 - Logiciel: Family Tree Maker 2006 - (..) [HKLM][64Bits] -- {F2F4C144-7D1A-47C4-9D53-395A57B0CD64}
O42 - Logiciel: Free iTunes Backup Extractor version 5.4.0.2 - (.HONGKONG JIHO CO., LIMITED.) [HKLM][64Bits] -- {F891E77B-EB1C-4035-BCC4-4DEF91EDD69E}_is1
O42 - Logiciel: Gleim FAA Test Prep 2010 WebDeploy - (.Gleim.) [HKLM][64Bits] -- FAATPWSUEW49 {2A700F66256B25560000A7B9B691F8ED}
O42 - Logiciel: Google Earth Plug-in - (.Google.) [HKLM][64Bits] -- {57BB4801-61C8-4E74-9672-2160728A461E} =>.Google
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: GoToMeeting 8.0.0.6441 - (.CitrixOnline.) [HKCU][64Bits] -- GoToMeeting =>.Citrix Online®
O42 - Logiciel: HL-1110 series - (.Brother Industries, Ltd..) [HKLM][64Bits] -- {4F2442B7-A89E-42A4-8F0E-6937499855CA} =>.Macrovision Corporation®
O42 - Logiciel: iCloud - (.Apple Inc..) [HKLM][64Bits] -- {709A2D23-C25E-47B5-9268-CB6FEE648504} =>.Apple Inc.
O42 - Logiciel: Intel(R) Control Center - (.Intel Corporation.) [HKLM][64Bits] -- {F8A9085D-4C7A-41a9-8A77-C8998A96C421} =>.Intel Corporation®
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A} =>.Intel Corporation®
O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {3E29EE6C-963A-4aae-86C1-DC237C4A49FC} =>.Intel Corporation®
O42 - Logiciel: Intel(R) Turbo Boost Technology Driver - (.Intel Corporation.) [HKLM][64Bits] -- {D6C630BF-8DBB-4042-8562-DC9A52CB6E7E} =>.Intel Corporation®
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM][64Bits] -- {9D0D2A8B-7E7B-4D88-8D50-24286ED6A5EB} =>.Apple Inc.
O42 - Logiciel: Java Auto Updater - (.Sun Microsystems, Inc..) [HKLM][64Bits] -- {4A03706F-666A-4037-7777-5F2748764D10} =>.Sun Microsystems, Inc.
O42 - Logiciel: Malwarebytes version 3.0.6.1469 - (.Malwarebytes.) [HKLM][64Bits] -- {35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1 =>.Malwarebytes Corporation®
O42 - Logiciel: Maxtor Manager - (.Seagate Technology.) [HKLM][64Bits] -- {ED01D958-AEDC-40C8-93FD-0C08E8AA9530} =>.Seagate Technology
O42 - Logiciel: Maxtor Manager - (.Seagate Technology.) [HKLM][64Bits] -- InstallShield_{ED01D958-AEDC-40C8-93FD-0C08E8AA9530} {25B1DD7CD102F294C6B4A039166590E7} =>.Seagate Technology
O42 - Logiciel: mccPILOTLOG - (.MCC bvba.) [HKLM][64Bits] -- {BAA273F2-67DC-4D05-8C1C-5DEE893EAF1E}
O42 - Logiciel: Media Gallery - (.Sony Corporation.) [HKLM][64Bits] -- {2110ECBD-BF15-4673-8852-8C68DDEB26AC} =>.Sony Corporation
O42 - Logiciel: Media Gallery - (.Sony Corporation.) [HKLM][64Bits] -- {DD88F979-FA58-41AC-980C-A6E1A82B61D9} =>.Sony Corporation®
O42 - Logiciel: Microsoft Application Error Reporting - (.Microsoft Corporation.) [HKLM][64Bits] -- {95120000-00B9-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Flight Simulator X - (.Microsoft Game Studios.) [HKLM][64Bits] -- {9527A496-5DF9-412A-ADC7-168BA5379CA6} =>.Microsoft Game Studios
O42 - Logiciel: Microsoft Flight Simulator X - (.Microsoft Game Studios.) [HKLM][64Bits] -- InstallShield_{9527A496-5DF9-412A-ADC7-168BA5379CA6} =>.Microsoft Game Studios
O42 - Logiciel: Microsoft Flight Simulator X Demo - (.Microsoft Game Studios.) [HKLM][64Bits] -- {B98A34C0-A6A2-4087-B272-557C1C6D0A07} =>.Microsoft Game Studios
O42 - Logiciel: Microsoft Flight Simulator X Demo - (.Microsoft Game Studios.) [HKLM][64Bits] -- InstallShield_{B98A34C0-A6A2-4087-B272-557C1C6D0A07} =>.Microsoft Game Studios
O42 - Logiciel: Microsoft Flight Simulator X: Acceleration - (.Microsoft Game Studios.) [HKLM][64Bits] -- {A9729B90-D37B-4A69-B66A-7436AC1F7274} =>.Microsoft Game Studios
O42 - Logiciel: Microsoft Flight Simulator X: Acceleration - (.Microsoft Game Studios.) [HKLM][64Bits] -- FlightSim_{A9729B90-D37B-4A69-B66A-7436AC1F7274} =>.Microsoft Game Studios
O42 - Logiciel: Microsoft Outlook 2013 - en-us - (.Microsoft Corporation.) [HKLM][64Bits] -- OutlookRetail - en-us =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation
O42 - Logiciel: MSVC80_x64_v2 - (.Nokia.) [HKLM][64Bits] -- {4D668D4F-FAA2-4726-834C-31F4614F312E} =>.Nokia
O42 - Logiciel: MSVC80_x86_v2 - (.Nokia.) [HKLM][64Bits] -- {6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6} =>.Nokia
O42 - Logiciel: MSVC90_x64 - (.Nokia.) [HKLM][64Bits] -- {AB071C8B-873C-459F-ACA9-9EBE03C3E89B} =>.Nokia
O42 - Logiciel: MSVC90_x86 - (.Nokia.) [HKLM][64Bits] -- {AF111648-99A1-453E-81DD-80DBBF6DAD0D} =>.Nokia
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} =>.Microsoft
O42 - Logiciel: MSVCRT110 - (.Microsoft.) [HKLM][64Bits] -- {8E14DDC8-EA60-4E18-B3E3-1937104D5BDA} =>.Microsoft
O42 - Logiciel: MSVCRT110_amd64 - (.Microsoft.) [HKLM][64Bits] -- {E9FA781F-3E80-4399-825A-AD3E11C28C77} =>.Microsoft
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM][64Bits] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71} =>.Microsoft Corporation
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM][64Bits] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC} =>.Microsoft Corporation
O42 - Logiciel: MSXML 4.0 SP2 Parser and SDK - (.Microsoft Corporation.) [HKLM][64Bits] -- {716E0306-8318-4364-8B8F-0CC4E9376BAC} =>.Microsoft Corporation
O42 - Logiciel: MusicStation - (.Omnifone.) [HKLM][64Bits] -- {AB259D46-F851-41B0-9AFA-AED8998AD68A} =>.Omnifone
O42 - Logiciel: Office 15 Click-to-Run Extensibility Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008C-0000-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Office 15 Click-to-Run Licensing Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008F-0000-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Office 15 Click-to-Run Localization Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008C-0409-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Online Plug-in - (.Citrix Systems, Inc..) [HKLM][64Bits] -- {F390D923-76F1-458E-8218-8C0C156CDCFD} =>.Citrix Systems, Inc.
O42 - Logiciel: PMB - (.Sony Corporation.) [HKLM][64Bits] -- {B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C} =>.Sony Corporation
O42 - Logiciel: PMB VAIO Edition Guide - (.Sony Corporation.) [HKLM][64Bits] -- {339F9B4D-00CB-4C1C-BED8-EC86A9AB602A} =>.Sony Corporation
O42 - Logiciel: PMB VAIO Edition plug-in (Click to Disc) - (.Sony Corporation.) [HKLM][64Bits] -- {4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF} =>.Sony Corporation
O42 - Logiciel: PMB VAIO Edition plug-in (Click to Disc) - (.Sony Corporation.) [HKLM][64Bits] -- InstallShield_{4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF} =>.Sony Corporation
O42 - Logiciel: PMB VAIO Edition plug-in (VAIO Image Optimizer) - (.Sony Corporation.) [HKLM][64Bits] -- {1873FFC1-FDCB-47E1-B7C7-F418211E3530} =>.Sony Corporation
O42 - Logiciel: PMB VAIO Edition plug-in (VAIO Image Optimizer) - (.Sony Corporation.) [HKLM][64Bits] -- InstallShield_{1873FFC1-FDCB-47E1-B7C7-F418211E3530} =>.Sony Corporation
O42 - Logiciel: PMB VAIO Edition plug-in (VAIO Movie Story) - (.Sony Corporation.) [HKLM][64Bits] -- {B25563A0-41F4-4A81-A6C1-6DBC0911B1F3} =>.Sony Corporation
O42 - Logiciel: PMB VAIO Edition plug-in (VAIO Movie Story) - (.Sony Corporation.) [HKLM][64Bits] -- InstallShield_{B25563A0-41F4-4A81-A6C1-6DBC0911B1F3} =>.Sony Corporation
O42 - Logiciel: PMDG 737 8900 NGX Base Package FSX - (.PMDG Simulations, LLC..) [HKLM][64Bits] -- {20708FD5-E94D-4097-A21E-E28564CDBC06} =>.PMDG Simulations, LLC.
O42 - Logiciel: QuickTime 7 - (.Apple Inc..) [HKLM][64Bits] -- {FF59BD75-466A-4D5A-AD23-AAD87C5FD44C} =>Riskware.QuickTime
O42 - Logiciel: Radio Aids Navigation Tutor XL Release 4 - (.Oddsoft Limited.) [HKLM][64Bits] -- Radio Aids Navigation Tutor XL_is1
O42 - Logiciel: RANT XL V 6.13 - (.Oddsoft Limited.) [HKLM][64Bits] -- Radio Aids Navigation Tutor XL Release 4_is1
O42 - Logiciel: Realtek HDMI Audio Driver for ATI - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {5449FB4F-1802-4D5B-A6D8-087DB1142147} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp.
O42 - Logiciel: RogueKiller version 12.9.9.0 - (.Adlice Software.) [HKLM][64Bits] -- 8B3D7924-ED89-486B-8322-E8594065D5CB_is1 =>.Adlice®
O42 - Logiciel: Roxio Central Audio - (.Roxio.) [HKLM][64Bits] -- {73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83} =>.Roxio
O42 - Logiciel: Roxio Central Copy - (.Roxio.) [HKLM][64Bits] -- {B6A26DE5-F2B5-4D58-9570-4FC760E00FCD} =>.Roxio
O42 - Logiciel: Roxio Central Core - (.Roxio.) [HKLM][64Bits] -- {ED439A64-F018-4DD4-8BA5-328D85AB09AB} =>.Roxio
O42 - Logiciel: Roxio Central Data - (.Roxio.) [HKLM][64Bits] -- {08E81ABD-79F7-49C2-881F-FD6CB0975693} =>.Roxio
O42 - Logiciel: Roxio Central Tools - (.Roxio.) [HKLM][64Bits] -- {1F54DAFA-9261-4A62-B59D-6C9F26B48FE4} =>.Roxio
O42 - Logiciel: Roxio Easy Media Creator 10 LJ - (.Roxio.) [HKLM][64Bits] -- {537BF16E-7412-448C-95D8-846E85A1D817} =>.Sonic Solutions®
O42 - Logiciel: Roxio Easy Media Creator Home - (.Roxio.) [HKLM][64Bits] -- {FE51662F-D8F6-43B5-99D9-D4894AF00F83} =>.Roxio
O42 - Logiciel: SeaTools for Windows - (.Seagate Technology.) [HKLM][64Bits] -- {98613C99-1399-416C-A07C-1EE1C585D872} =>.Seagate Technology
O42 - Logiciel: Self-service Plug-in - (.Citrix Systems, Inc..) [HKLM][64Bits] -- {47117FCA-0D00-4B6D-9D68-00B763629463} =>.Citrix Systems, Inc.
O42 - Logiciel: Setting Utility Series - (.Sony Corporation.) [HKLM][64Bits] -- {A7DA438C-2E43-4C20-BFDA-C1F4A6208558} =>.Sony Corporation®
O42 - Logiciel: Setup_msm_VCMS_x64 - (.Sony Corporation.) [HKLM][64Bits] -- {1C6B6716-84AC-412A-A296-247D41EBB7FB} =>.Sony Corporation
O42 - Logiciel: Setup_msm_VOFS_x64 - (.Sony Corporation.) [HKLM][64Bits] -- {C69A835B-67A5-4542-AD24-FE36E3140BA9} =>.Sony Corporation
O42 - Logiciel: Setup_VEP_x64_Contain_SSDB - (.Sony Corporation.) [HKLM][64Bits] -- {7ECD4ACB-E1B6-425B-B8AA-5761A59B77E0} =>.Sony Corporation
O42 - Logiciel: Skype Click to Call - (.Skype Technologies S.A..) [HKLM][64Bits] -- {B6CF2967-C81E-40C0-9815-C05774FEF120} =>.Skype Technologies S.A.
O42 - Logiciel: Skype™ 7.32 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {FC965A47-4839-40CA-B618-18F486F042C6} =>.Skype Technologies S.A.
O42 - Logiciel: SOHLib Merge Module - (.Sony Corporation.) [HKLM][64Bits] -- {4A221E47-E361-45C3-886A-7B2D7AD0E5AA} =>.Sony Corporation
O42 - Logiciel: Sony Home Network Library - (.Sony Corporation.) [HKLM][64Bits] -- {9B163B82-3B46-4CE5-BF01-A53E550A8E58} =>.Sony Corporation
O42 - Logiciel: SUPERAntiSpyware - (.SUPERAntiSpyware.com.) [HKLM][64Bits] -- {CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA} =>.SUPERAntiSpyware.com®
O42 - Logiciel: VAIO - PMB VAIO Edition Guide - (.Sony Corporation.) [HKLM][64Bits] -- InstallShield_{339F9B4D-00CB-4C1C-BED8-EC86A9AB602A} =>.Sony Corporation
O42 - Logiciel: VAIO BD Menu Data - (.Sony Corporation.) [HKLM][64Bits] -- {DF0415CC-0563-407F-B560-9B7F277122C5} =>.Macrovision Corporation®
O42 - Logiciel: VAIO Care - (.Sony Corporation.) [HKLM][64Bits] -- {36C5BBF0-E5BF-4DE1-B684-7E90B0C93FB5} =>.Sony Corporation®
O42 - Logiciel: VAIO Care - (.Sony Corporation.) [HKLM][64Bits] -- {D531F5A4-18F6-4130-B9A4-9179D6E349FC} =>.Sony Corporation
O42 - Logiciel: VAIO Content Metadata Intelligent Analyzing Manager - (.Sony Corporation.) [HKLM][64Bits] -- {A1255354-11F3-4D25-95CC-C9B1C2320761} =>.Sony Corporation
O42 - Logiciel: VAIO Content Metadata Intelligent Analyzing Manager - (.Sony Corporation.) [HKLM][64Bits] -- {B1DADBEB-7F82-4B29-84D6-5F14A020F0A0} =>.Sony Corporation
O42 - Logiciel: VAIO Content Metadata Intelligent Network Service Manager - (.Sony Corporation.) [HKLM][64Bits] -- {725D5BA4-E9FA-452B-8CF5-D7E5F8055C71} =>.Sony Corporation
O42 - Logiciel: VAIO Content Metadata Manager Settings - (.Sony Corporation.) [HKLM][64Bits] -- {8FE3CF66-4484-4D39-B47D-DEBBA173619D} =>.Sony Corporation
O42 - Logiciel: VAIO Content Metadata XML Interface Library - (.Sony Corporation.) [HKLM][64Bits] -- {97C58294-36D8-4594-8A49-7AB4AE096504} =>.Sony Corporation
O42 - Logiciel: VAIO Content Monitoring Settings - (.Sony Corporation.) [HKLM][64Bits] -- {06C05B90-2127-4933-8ABA-61833BDE13FA} =>.Sony Corporation
O42 - Logiciel: VAIO Control Center - (.Sony Corporation.) [HKLM][64Bits] -- {72042FA6-5609-489F-A8EA-3C2DD650F667} =>.Sony Corporation®
O42 - Logiciel: VAIO Data Restore Tool - (.Sony Corporation.) [HKLM][64Bits] -- {34DC654E-6E43-4BFA-9E00-6C16CFA7B9F0} =>.Sony Corporation
O42 - Logiciel: VAIO Data Restore Tool - (.Sony Corporation.) [HKLM][64Bits] -- {57B955CE-B5D3-495D-AF1B-FAEE0540BFEF} =>.Sony Corporation®
O42 - Logiciel: VAIO DVD Menu Data - (.Sony Corporation.) [HKLM][64Bits] -- {596BED91-A1D8-4DF1-8CD1-1C777F7588AC} =>.Macrovision Corporation®
O42 - Logiciel: VAIO Entertainment Platform - (.Sony Corporation.) [HKLM][64Bits] -- {0489D044-6386-4BDF-9F98-577D60CF79DD} =>.Sony Corporation
O42 - Logiciel: VAIO Event Service - (.Sony Corporation.) [HKLM][64Bits] -- {C7477742-DDB4-43E5-AC8D-0259E1E661B1} =>.Sony Corporation®
O42 - Logiciel: VAIO Gate - (.Sony Corporation.) [HKLM][64Bits] -- {A7C30414-2382-4086-B0D6-01A88ABA21C3} =>.Sony Corporation®
O42 - Logiciel: VAIO Gate Default - (.Sony Corporation.) [HKLM][64Bits] -- {B7546697-2A80-4256-A24B-1C33163F535B} =>.Sony Corporation®
O42 - Logiciel: VAIO Hardware Diagnostics - (.Sony Corporation.) [HKLM][64Bits] -- {9DA53D22-D922-494C-B1D7-51CD9BCB9E4A} =>.Sony Corporation
O42 - Logiciel: VAIO Marketing Tools - (.Sony Corporation.) [HKLM][64Bits] -- MarketingTools =>.Sony Corporation
O42 - Logiciel: VAIO Media plus - (.Sony Corporation.) [HKLM][64Bits] -- {8DE50158-80AA-4FF2-9E9F-0A7C46F71FCD} =>.Sony Corporation®
O42 - Logiciel: VAIO Media plus Opening Movie - (.Sony Corporation.) [HKLM][64Bits] -- {9238E8A4-BEBA-43A3-B926-769BDBF194C5} =>.Sony Corporation®
O42 - Logiciel: VAIO Movie Story MergeModules x64 - (.Sony Corporation.) [HKLM][64Bits] -- {C37B6246-7D4A-4E5C-BFB4-11C8660BDC99} =>.Sony Corporation
O42 - Logiciel: VAIO Original Function Settings - (.Sony Corporation.) [HKLM][64Bits] -- {04EAE65A-CDCF-480F-B754-5C3A9364239C} =>.Sony Corporation
O42 - Logiciel: VAIO Personalization Manager - (.Sony Corporation.) [HKLM][64Bits] -- {DBB823F3-E8BD-4578-9D16-42AF176FD777} =>.Sony Corporation
O42 - Logiciel: VAIO Power Management - (.Sony Corporation.) [HKLM][64Bits] -- {803E4FA5-A940-4420-B89D-A8BC2E160247} =>.Sony Corporation®
O42 - Logiciel: VAIO Premium Partners - (.Sony Europe.) [HKLM][64Bits] -- VAIO Premium Partners =>.Sony Europe
O42 - Logiciel: VAIO Quick Web Access - (.Sony Corporation.) [HKLM][64Bits] -- {5A92468F-3ED8-4F96-A9E1-4F176C80EC29} =>.Sony Corporation
O42 - Logiciel: VAIO Quick Web Access - (.Sony Corporation.) [HKLM][64Bits] -- splashtop =>.Sony Corporation
O42 - Logiciel: VAIO screensaver - (.Sony Europe.) [HKLM][64Bits] -- VAIO screensaver =>.Sony Europe
O42 - Logiciel: VAIO Smart Network - (.Sony Corporation.) [HKLM][64Bits] -- {0899D75A-C2FC-42EA-A702-5B9A5F24EAD5} =>.Sony Corporation
O42 - Logiciel: VAIO Transfer Support - (.Sony Corporation.) [HKLM][64Bits] -- {5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF} =>.Sony Corporation®
O42 - Logiciel: VAIO Update - (.Sony Corporation.) [HKLM][64Bits] -- {5BEE8F1F-BD32-4553-8107-500439E43BD7} =>.Sony Corporation®
O42 - Logiciel: VAIO Update Merge Module x64 - (.Sony Corporation.) [HKLM][64Bits] -- {11D25EF7-85FC-4B58-8278-485939C8637F} =>.Sony Corporation
O42 - Logiciel: VAIO Wallpaper Contents - (.Sony Corporation.) [HKLM][64Bits] -- {D60F97EC-EF06-4E1E-B0D1-C2CBABA62FA3} =>.Sony Corporation®
O42 - Logiciel: Visual Studio 2008 x64 Redistributables - (.AVG Technologies.) [HKLM][64Bits] -- {FCDBEA60-79F0-4FAE-BBA8-55A26C609A49} =>.AVG Technologies
O42 - Logiciel: Visual Studio 2010 x64 Redistributables - (.AVG Technologies.) [HKLM][64Bits] -- {21B133D6-5979-47F0-BE1C-F6A6B304693F} =>.AVG Technologies
O42 - Logiciel: Visual Studio 2012 x64 Redistributables - (.AVG Technologies.) [HKLM][64Bits] -- {8C775E70-A791-4DA8-BCC3-6AB7136F4484} =>.AVG Technologies
O42 - Logiciel: Visual Studio 2012 x86 Redistributables - (.AVG Technologies CZ, s.r.o..) [HKLM][64Bits] -- {98EFF19A-30AB-4E4B-B943-F06B1C63EBF8} =>.AVG Technologies CZ, s.r.o.
O42 - Logiciel: WD Backup - (.Western Digital Technologies, Inc.) [HKLM][64Bits] -- {4AACAFC7-951A-4215-B430-3DFCFF2E6CED} =>.Western Digital Technologies, Inc
O42 - Logiciel: WD Backup - (.Western Digital Technologies, Inc..) [HKLM][64Bits] -- {a8c9535a-ecd9-4172-a330-0cb5ff9dbed9} =>.WESTERN DIGITAL TECHNOLOGIES®
O42 - Logiciel: WD Drive Utilities - (.Western Digital Technologies, Inc..) [HKLM][64Bits] -- {48996CDD-DD81-4197-93FE-0971E73C5CA7} =>.Western Digital Technologies, Inc.
O42 - Logiciel: WD Drive Utilities - (.Western Digital Technologies, Inc..) [HKLM][64Bits] -- {eab1fb93-61fb-48de-b815-b4e9b68d2ef1} =>.Western Digital Technologies, Inc.®
O42 - Logiciel: Wickr Me - (.Wickr Inc..) [HKLM][64Bits] -- {7668652D-F198-4E7B-8FF4-5E2DC13D9AD7}
O42 - Logiciel: WIDCOMM Bluetooth Software - (.Broadcom Corporation.) [HKLM][64Bits] -- {9E9D49A4-1DF4-4138-B7DB-5D87A893088E} =>.Broadcom Corporation
O42 - Logiciel: Windows Driver Package - Broadcom Bluetooth (09/09/2009 6.2.0.9405) - (.Broadcom.) [HKLM][64Bits] -- 930E4792BDAEAFB62A9514EE7578775658A5D07C =>.Microsoft Windows Component Publisher®
O42 - Logiciel: Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) - (.Broadcom.) [HKLM][64Bits] -- 3BA80AB4C7E9F8497C115C844953A3D4BEB84D21 =>.Microsoft Windows Component Publisher®
O42 - Logiciel: Windows Installer Clean Up - (.Microsoft Corporation.) [HKLM][64Bits] -- {121634B0-2F4A-11D3-ADA3-00C04F52DD53} =>.Microsoft Corporation
O42 - Logiciel: Windows Mobile Device Center - (.Microsoft Corporation.) [HKLM][64Bits] -- {626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B} =>.Microsoft Corporation

---\\ HKCU & HKLM Software Keys (154) - 53s
HKLM\SOFTWARE\Wow6432Node\Adobe =>.Adobe
HKLM\SOFTWARE\Wow6432Node\Adware Removal Tool by TSA =>.TSA Softwares
HKLM\SOFTWARE\Wow6432Node\Amazon =>.Amazon
HKLM\SOFTWARE\Wow6432Node\America Online =>.America Online
HKLM\SOFTWARE\Wow6432Node\Apple Computer, Inc. =>.Apple Computer, Inc.
HKLM\SOFTWARE\Wow6432Node\Apple Inc. =>.Apple Inc.
HKLM\SOFTWARE\Wow6432Node\ArcSoft =>.ArcSoft
HKLM\SOFTWARE\Wow6432Node\ATI =>.ATI
HKLM\SOFTWARE\Wow6432Node\ATI Technologies =>.ATI Technologies
HKLM\SOFTWARE\Wow6432Node\ATP DIGITAL
HKLM\SOFTWARE\Wow6432Node\AVG =>.AVG Software
HKLM\SOFTWARE\Wow6432Node\Avg Secure Update =>.AVG Software
HKLM\SOFTWARE\Wow6432Node\Avira =>.Avira
HKLM\SOFTWARE\Wow6432Node\BinarySense =>.BinarySense
HKLM\SOFTWARE\Wow6432Node\Brother =>.Brother
HKLM\SOFTWARE\Wow6432Node\Brother Industries, Ltd. =>.Brother Industries, Ltd.
HKLM\SOFTWARE\Wow6432Node\Canon =>.Canon
HKLM\SOFTWARE\Wow6432Node\Canon_Inc_IC =>.Canon Inc.
HKLM\SOFTWARE\Wow6432Node\Caphyon =>.Caphyon
HKLM\SOFTWARE\Wow6432Node\CDDB =>.Cddb Software
HKLM\SOFTWARE\Wow6432Node\Citrix =>.Citrix
HKLM\SOFTWARE\Wow6432Node\Corel =>.Corel
HKLM\SOFTWARE\Wow6432Node\Debug =>.Legitimate
HKLM\SOFTWARE\Wow6432Node\Dropbox =>.Dropbox
HKLM\SOFTWARE\Wow6432Node\DropboxUpdate =>.Dropbox Inc.
HKLM\SOFTWARE\Wow6432Node\ej-technologies =>.ej-technologies
HKLM\SOFTWARE\Wow6432Node\Freemake =>.Freemake
HKLM\SOFTWARE\Wow6432Node\Google =>.Google
HKLM\SOFTWARE\Wow6432Node\GuidGuid13
HKLM\SOFTWARE\Wow6432Node\illiminable =>.illiminable
HKLM\SOFTWARE\Wow6432Node\IM Providers =>.IM Providers
HKLM\SOFTWARE\Wow6432Node\InstallShield =>.InstallShield
HKLM\SOFTWARE\Wow6432Node\Intel =>.Intel
HKLM\SOFTWARE\Wow6432Node\JavaSoft =>.JavaSoft
HKLM\SOFTWARE\Wow6432Node\JreMetrics =>.JreMetrics
HKLM\SOFTWARE\Wow6432Node\Licenses =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\Wow6432Node\Macrovision =>.Macrovision
HKLM\SOFTWARE\Wow6432Node\Maxtor =>.Maxtor
HKLM\SOFTWARE\Wow6432Node\McAfee =>.McAfee Inc.
HKLM\SOFTWARE\Wow6432Node\McAfee.com =>.McAfee Inc.
HKLM\SOFTWARE\Wow6432Node\McAfeeInstaller =>.McAfee Inc.
HKLM\SOFTWARE\Wow6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\MyFamily.com
HKLM\SOFTWARE\Wow6432Node\NewHouse
HKLM\SOFTWARE\Wow6432Node\Nokia =>.Nokia
HKLM\SOFTWARE\Wow6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\Wow6432Node\Oddsoft
HKLM\SOFTWARE\Wow6432Node\Piriform =>.Piriform
HKLM\SOFTWARE\Wow6432Node\PMDG Simulations, LLC. =>.PMDG Simulations, LLC.
HKLM\SOFTWARE\Wow6432Node\PocketSoft
HKLM\SOFTWARE\Wow6432Node\Realtek =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp. =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\Roxio =>.Roxio
HKLM\SOFTWARE\Wow6432Node\Skype =>.Skype
HKLM\SOFTWARE\Wow6432Node\Sonic =>.Sonic
HKLM\SOFTWARE\Wow6432Node\Sony =>.Sony
HKLM\SOFTWARE\Wow6432Node\Sony Corporation =>.Sony Corporation
HKLM\SOFTWARE\Wow6432Node\SourceCodeControlProvider =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\VideoLAN =>.VideoLAN
HKLM\SOFTWARE\Wow6432Node\Volatile =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\WafCX =>.WafCX
HKLM\SOFTWARE\Wow6432Node\Western Digital =>.Western Digital
HKLM\SOFTWARE\Wow6432Node\Wickr
HKLM\SOFTWARE\Wow6432Node\Windows =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\Wondershare =>.Wondershare
HKLM\SOFTWARE\Wow6432Node\X-AVCSD =>.Avira Software
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\9-lab =>.9-lab
HKCU\SOFTWARE\Adobe =>.Adobe
HKCU\SOFTWARE\Alps =>.ALPS
HKCU\SOFTWARE\Amazon =>.Amazon
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\Apple Computer, Inc. =>.Apple Computer, Inc.
HKCU\SOFTWARE\Apple Inc. =>.Apple Inc.
HKCU\SOFTWARE\ArcSoft =>.ArcSoft
HKCU\SOFTWARE\ATI =>.ATI
HKCU\SOFTWARE\Aurigma =>.Aurigma
HKCU\SOFTWARE\Avg =>.AVG Software
HKCU\SOFTWARE\Avg Secure Update =>.AVG Software
HKCU\SOFTWARE\AVG Web TuneUp =>.AVG Web TuneUp
HKCU\SOFTWARE\Avira =>.Avira
HKCU\SOFTWARE\BinarySense =>.BinarySense
HKCU\SOFTWARE\Brother =>.Brother
HKCU\SOFTWARE\Canon =>.Canon
HKCU\SOFTWARE\Canon_Inc_IC =>.Canon Inc.
HKCU\SOFTWARE\CDDB =>.Cddb Software
HKCU\SOFTWARE\Citrix =>.Citrix
HKCU\SOFTWARE\Corel =>.Corel
HKCU\SOFTWARE\DatCard
HKCU\SOFTWARE\Dropbox =>.Dropbox
HKCU\SOFTWARE\DropboxUpdate =>.Dropbox Inc.
HKCU\SOFTWARE\EasyBits =>.EasyBits
HKCU\SOFTWARE\ej-technologies =>.ej-technologies
HKCU\SOFTWARE\Evaer
HKCU\SOFTWARE\Evernote =>.Evernote
HKCU\SOFTWARE\FLEXlm License Manager =>.FlexNet
HKCU\SOFTWARE\Freemake =>.Freemake
HKCU\SOFTWARE\G4FON Software
HKCU\SOFTWARE\GARMIN International =>.Garmin Ltd
HKCU\SOFTWARE\Geek Uninstaller =>.Geek Uninstaller
HKCU\SOFTWARE\Gleim
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\IM Providers =>.IM Providers
HKCU\SOFTWARE\Imobie =>.iMobie Inc
HKCU\SOFTWARE\JavaSoft =>.JavaSoft
HKCU\SOFTWARE\JEDI-VCL =>.JEDI Project
HKCU\SOFTWARE\Jihosoft =>.Jihosoft
HKCU\SOFTWARE\Lake =>.Lake Sofware
HKCU\SOFTWARE\LANGAGENT =>.LangAgent
HKCU\SOFTWARE\LAV =>.LAV Inc
HKCU\SOFTWARE\Licenses =>.Microsoft Corporation
HKCU\SOFTWARE\Local AppWizard-Generated Applications =>.ZWCAD
HKCU\SOFTWARE\Macromedia =>.Macromedia
HKCU\SOFTWARE\Malwarebytes =>.Malwarebytes
HKCU\SOFTWARE\Maxtor =>.Maxtor
HKCU\SOFTWARE\MCAFEE =>.McAfee Inc.
HKCU\SOFTWARE\Mozilla =>.Mozilla
HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKCU\SOFTWARE\MyFamily.com
HKCU\SOFTWARE\Netscape =>.Netscape
HKCU\SOFTWARE\Northcode Inc =>.Northcode Inc
HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKCU\SOFTWARE\Oddsoft
HKCU\SOFTWARE\Piriform =>.Piriform
HKCU\SOFTWARE\ProtectedStorage
HKCU\SOFTWARE\QtProject =>.QtProject
HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKCU\SOFTWARE\Roxio =>.Roxio
HKCU\SOFTWARE\RtkPCEE3sMsg
HKCU\SOFTWARE\Settings =>.Samsung Electronics
HKCU\SOFTWARE\Skype =>.Skype
HKCU\SOFTWARE\SkypeApps =>.Skype Technologies
HKCU\SOFTWARE\Sonic =>.Sonic
HKCU\SOFTWARE\Sony Corporation =>.Sony Corporation
HKCU\SOFTWARE\SpecItems
HKCU\SOFTWARE\SUPERAntiSpyware.com =>.SUPERAntiSpyware.com
HKCU\SOFTWARE\Sysinternals =>.Sysinternals
HKCU\SOFTWARE\Trolltech =>.Trolltech
HKCU\SOFTWARE\VFRGenX - Volume 1: South England and South Wales
HKCU\SOFTWARE\Western Digital =>.Western Digital
HKCU\SOFTWARE\Wickr
HKCU\SOFTWARE\Widcomm =>.Widcomm
HKCU\SOFTWARE\Wondershare =>.Wondershare
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\アプリケーション ウィザードで生成されたローカル アプリケーション
HKCU\SOFTWARE\AppDataLow\Google =>.Google
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKCU\SOFTWARE\AppDataLow\Software\Avg =>.AVG Software
HKCU\SOFTWARE\AppDataLow\Software\Citrix =>.Citrix
HKCU\SOFTWARE\AppDataLow\Software\Google =>.Google

---\\ Contents of the Common Files folders (387) - 65s
O43 - CFD: 04/03/2017 - [] D -- C:\Program Files\9-lab =>.9-Lab®
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files\Apoint =>.Alps Electric Co., LTD.®
O43 - CFD: 19/05/2010 - [] D -- C:\Program Files\ATI =>.ATI Technologies, Inc®
O43 - CFD: 26/09/2015 - [] D -- C:\Program Files\Bonjour =>.Apple Inc.
O43 - CFD: 04/03/2017 - [] D -- C:\Program Files\CCleaner =>.Piriform Ltd
O43 - CFD: 25/09/2016 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 24/10/2010 - [] D -- C:\Program Files\DIFX =>.Microsoft Corporation
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files\DVD Maker =>.Aone Software
O43 - CFD: 25/09/2010 - [0] D -- C:\Program Files\Google =>.Google
O43 - CFD: 13/12/2016 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 01/02/2017 - [] D -- C:\Program Files\iPod =>.Apple Inc.®
O43 - CFD: 01/02/2017 - [] D -- C:\Program Files\iTunes =>.Apple Inc.
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files\Java =>.Oracle
O43 - CFD: 26/02/2017 - [] D -- C:\Program Files\Malwarebytes =>.Malwarebytes
O43 - CFD: 24/11/2013 - [0] D -- C:\Program Files\McAfee =>.McAfee
O43 - CFD: 20/05/2010 - [] D -- C:\Program Files\Microsoft Games =>.Microsoft Corporation
O43 - CFD: 30/03/2014 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 01/03/2017 - [] D -- C:\Program Files\Microsoft Office 15 =>.Microsoft Corporation
O43 - CFD: 13/10/2016 - [] D -- C:\Program Files\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files\Microsoft SQL Server Compact Edition =>.Microsoft Corporation
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files\Microsoft Synchronization Services =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files\Realtek =>.Realtek
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 03/03/2017 - [] D -- C:\Program Files\RogueKiller =>.Adlice
O43 - CFD: 21/11/2011 - [] D -- C:\Program Files\Sony =>.Sony Corporation®
O43 - CFD: 26/02/2017 - [] D -- C:\Program Files\SUPERAntiSpyware =>.SUPERAntiSpyware
O43 - CFD: 27/10/2016 - [] D -- C:\Program Files\tinyumbrella
O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 19/05/2010 - [] D -- C:\Program Files\WIDCOMM =>.Broadcom Corporation®
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 25/09/2010 - [] D -- C:\Program Files\Windows Live =>.Microsoft Corporation
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 25/02/2012 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 03/07/2011 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 03/07/2011 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 09/02/2017 - [0] D -- C:\Program Files (x86)\7-Zip =>.Igor Pavlov
O43 - CFD: 09/02/2017 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Systems, Incorporated®
O43 - CFD: 04/03/2017 - [] D -- C:\Program Files (x86)\Adware Removal Tool by TSA =>.TSA Softwares
O43 - CFD: 13/03/2016 - [0] D -- C:\Program Files (x86)\Amazon =>.Amazon
O43 - CFD: 23/03/2016 - [] D -- C:\Program Files (x86)\Apple Software Update =>.Apple Inc.
O43 - CFD: 19/10/2014 - [] D -- C:\Program Files (x86)\ArcSoft =>.ArcSoft
O43 - CFD: 04/12/2010 - [] D -- C:\Program Files (x86)\ATI Technologies =>.ATI Technologies
O43 - CFD: 26/07/2011 - [] D -- C:\Program Files (x86)\ATP DIGITAL
O43 - CFD: 26/02/2017 - [] D -- C:\Program Files (x86)\Avira =>.Avira Software
O43 - CFD: 26/09/2016 - [] D -- C:\Program Files (x86)\B737 CBT
O43 - CFD: 26/09/2015 - [] D -- C:\Program Files (x86)\Bonjour =>.Apple Inc.
O43 - CFD: 11/12/2010 - [] D -- C:\Program Files (x86)\Bristol.gs
O43 - CFD: 12/09/2016 - [] D -- C:\Program Files (x86)\Brother =>.Brother
O43 - CFD: 14/09/2014 - [] D -- C:\Program Files (x86)\Browny02 =>.Brother Industries, Ltd.
O43 - CFD: 14/09/2014 - [] D -- C:\Program Files (x86)\BrownyInd =>.Brother Industries, Ltd.
O43 - CFD: 18/12/2010 - [] D -- C:\Program Files (x86)\Canon =>.Canon
O43 - CFD: 23/02/2017 - [0] D -- C:\Program Files (x86)\Chat Undetected
O43 - CFD: 29/10/2013 - [] D -- C:\Program Files (x86)\Citrix =>.Citrix
O43 - CFD: 09/02/2017 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files (x86)\Corel =>.Corel Corporation
O43 - CFD: 07/12/2012 - [] D -- C:\Program Files (x86)\DiskCheckup {38E7FA0DB1A398F805BB85A69171DC9D}
O43 - CFD: 25/09/2010 - [] D -- C:\Program Files (x86)\Downloaded Installations =>.Microsoft Corporation
O43 - CFD: 28/02/2017 - [] D -- C:\Program Files (x86)\Dropbox =>.Dropbox, Inc®
O43 - CFD: 08/02/2017 - [] D -- C:\Program Files (x86)\FAATP2010 {138C6B1CEA71EBA363F25979E2DB9AAE}
O43 - CFD: 26/09/2010 - [] D -- C:\Program Files (x86)\Family Tree Maker 2006
O43 - CFD: 09/11/2010 - [] D -- C:\Program Files (x86)\Freeciv-2.2.2-gtk2
O43 - CFD: 12/03/2012 - [] D -- C:\Program Files (x86)\Freeciv-2.2.3-gtk2
O43 - CFD: 09/11/2010 - [] D -- C:\Program Files (x86)\freecol
O43 - CFD: 13/03/2016 - [] D -- C:\Program Files (x86)\Freemake =>.Freemake
O43 - CFD: 25/10/2015 - [] D -- C:\Program Files (x86)\G4FON Software
O43 - CFD: 05/03/2017 - [] D -- C:\Program Files (x86)\Google =>.Google Inc®
O43 - CFD: 05/03/2017 - [] D -- C:\Program Files (x86)\GUM1B92.tmp =>.Google Inc®
O43 - CFD: 05/03/2017 - [] D -- C:\Program Files (x86)\GUM5198.tmp =>.Google Inc®
O43 - CFD: 20/03/2016 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield Software
O43 - CFD: 23/09/2010 - [] D -- C:\Program Files (x86)\Intel =>.Intel Corporation
O43 - CFD: 13/12/2016 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 27/10/2016 - [] D -- C:\Program Files (x86)\iTunes =>.Apple Inc.
O43 - CFD: 09/04/2016 - [] D -- C:\Program Files (x86)\Jihosoft =>.HONGKONG JIHO CO., LIMITED®
O43 - CFD: 02/10/2010 - [] D -- C:\Program Files (x86)\Maxtor {25B1DD7CD102F294C6B4A039166590E7} =>.Maxtor
O43 - CFD: 26/11/2013 - [] D -- C:\Program Files (x86)\McAfee =>.McAfee
O43 - CFD: 01/01/2016 - [] D -- C:\Program Files (x86)\MCC Pilotlog
O43 - CFD: 30/03/2014 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services =>.Microsoft Corporation
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files (x86)\Microsoft Games =>.Microsoft Corporation
O43 - CFD: 08/03/2015 - [] D -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 13/10/2016 - [] D -- C:\Program Files (x86)\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition =>.Microsoft Corporation
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files (x86)\Microsoft Synchronization Services =>.Microsoft Corporation
O43 - CFD: 30/03/2014 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 26/02/2017 - [] D -- C:\Program Files (x86)\Mozilla Firefox =>.Mozilla
O43 - CFD: 09/02/2017 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service =>.Mozilla
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 25/09/2010 - [0] D -- C:\Program Files (x86)\MSXML 4.0 =>.Microsoft Corporation
O43 - CFD: 31/12/2011 - [] D -- C:\Program Files (x86)\MusicStation =>.MusicStation
O43 - CFD: 20/03/2016 - [] D -- C:\Program Files (x86)\PMDG Operations Center
O43 - CFD: 24/02/2016 - [] D -- C:\Program Files (x86)\RANTXL
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files (x86)\Realtek =>.Realtek
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files (x86)\Roxio =>.Roxio
O43 - CFD: 07/12/2012 - [] D -- C:\Program Files (x86)\Seagate =>.Seagate
O43 - CFD: 09/02/2017 - [] RD -- C:\Program Files (x86)\Skype =>.Skype
O43 - CFD: 31/12/2011 - [] D -- C:\Program Files (x86)\SONY =>.Sony Corporation®
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files (x86)\Sony Corporation =>.Sony Corporation
O43 - CFD: 16/12/2015 - [] D -- C:\Program Files (x86)\SpeedFan =>.Almico Software
O43 - CFD: 02/01/2012 - [0] D -- C:\Program Files (x86)\T-Mobile
O43 - CFD: 13/09/2010 - [0] HD -- C:\Program Files (x86)\Temp =>.Microsoft Corporation
O43 - CFD: 27/10/2016 - [] D -- C:\Program Files (x86)\Tenorshare ReiBoot
O43 - CFD: 27/10/2016 - [] D -- C:\Program Files (x86)\tinyumbrella
O43 - CFD: 27/10/2016 - [] D -- C:\Program Files (x86)\tinyumbrellaNEW
O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files (x86)\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 04/03/2017 - [] D -- C:\Program Files (x86)\VAIO screensavers
O43 - CFD: 05/02/2012 - [] D -- C:\Program Files (x86)\Virgin Mobile Broadband
O43 - CFD: 01/10/2016 - [] D -- C:\Program Files (x86)\Western Digital =>.Western Digital Technologies, Inc.®
O43 - CFD: 14/02/2017 - [] D -- C:\Program Files (x86)\Wickr Inc {045D55AD7640E014A9B074ACF4E03319}
O43 - CFD: 14/07/2013 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 30/03/2014 - [] D -- C:\Program Files (x86)\Windows Installer Clean Up =>.Microsoft Corporation
O43 - CFD: 24/09/2016 - [] D -- C:\Program Files (x86)\Windows Live =>.Microsoft Corporation
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 03/07/2011 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 03/07/2011 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 27/10/2016 - [] D -- C:\Program Files (x86)\Wondershare =>.Wondershare
O43 - CFD: 04/03/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\9-lab Removal Tool
O43 - CFD: 23/10/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 13/03/2016 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon =>.Amazon
O43 - CFD: 13/09/2010 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft Magic-i Visual Effects 2 =>.ArcSoft
O43 - CFD: 13/09/2010 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft WebCam Companion 3 =>.Labtec
O43 - CFD: 26/07/2011 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ATPL Digital v6
O43 - CFD: 28/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira =>.Avira Software
O43 - CFD: 11/12/2010 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bristol.gs
O43 - CFD: 14/09/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother =>.Brother
O43 - CFD: 18/12/2010 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities =>.Canon Inc.
O43 - CFD: 04/12/2010 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center =>.Advanced Micro Devices Inc
O43 - CFD: 04/03/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd
O43 - CFD: 13/09/2010 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel =>.Corel Corporation
O43 - CFD: 09/02/2017 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diamond DA40D G1000 Trainer v6.14
O43 - CFD: 07/12/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DiskCheckup
O43 - CFD: 28/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox =>.Dropbox
O43 - CFD: 26/09/2010 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Family Tree Maker 2006
O43 - CFD: 09/04/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free iTunes Backup Extractor
O43 - CFD: 09/11/2010 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeCol
O43 - CFD: 25/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G4FON Software
O43 - CFD: 20/03/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 17/10/2010 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gleim Publications
O43 - CFD: 02/05/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud =>.Apple Inc.
O43 - CFD: 19/05/2010 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel =>.Intel Corporation
O43 - CFD: 01/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes =>.Apple Inc.
O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 26/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes =>.Malwarebytes
O43 - CFD: 02/10/2010 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxtor =>.Maxtor
O43 - CFD: 04/02/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games =>.Microsoft Corporation
O43 - CFD: 30/03/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 08/03/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 =>.Microsoft Corporation
O43 - CFD: 13/10/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 25/09/2010 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PMB =>.Sony Corporation
O43 - CFD: 15/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PMDG Simulations
O43 - CFD: 21/06/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RANT XL
O43 - CFD: 03/03/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller =>.Adlice
O43 - CFD: 28/10/2011 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio Easy Media Creator 10 LJ =>.Roxio
O43 - CFD: 07/12/2012 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate =>.Seagate
O43 - CFD: 28/12/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype =>.Skype
O43 - CFD: 13/09/2010 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony =>.Sony
O43 - CFD: 08/04/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 21/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware =>.SUPERAntiSpyware
O43 - CFD: 10/07/2011 - [] HD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Care
O43 - CFD: 01/10/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital =>.Western Digital
O43 - CFD: 14/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wickr Me
O43 - CFD: 04/03/2017 - [] D -- C:\ProgramData\9-lab =>.9-lab
O43 - CFD: 25/12/2015 - [] D -- C:\ProgramData\Adobe =>.Adobe
O43 - CFD: 26/01/2014 - [] D -- C:\ProgramData\Apple =>.Apple Inc.
O43 - CFD: 04/02/2012 - [] D -- C:\ProgramData\Apple Computer =>.Apple Inc.
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 21/02/2017 - [] D -- C:\ProgramData\ArcSoft =>.ArcSoft
O43 - CFD: 04/12/2010 - [] D -- C:\ProgramData\ATI =>.ATI
O43 - CFD: 26/02/2017 - [] D -- C:\ProgramData\Avira =>.Avira Software
O43 - CFD: 14/09/2014 - [] D -- C:\ProgramData\Brother =>.Brother
O43 - CFD: 29/10/2013 - [] D -- C:\ProgramData\Citrix =>.Citrix
O43 - CFD: 18/02/2012 - [] HD -- C:\ProgramData\Common Files =>.Microsoft Corporation
O43 - CFD: 12/01/2014 - [] D -- C:\ProgramData\Corel =>.Corel Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 22/02/2017 - [] D -- C:\ProgramData\Dropbox =>.Dropbox
O43 - CFD: 13/09/2010 - [] D -- C:\ProgramData\Evernote =>.EverNote Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Favorites =>.Microsoft Corporation
O43 - CFD: 20/03/2016 - [] D -- C:\ProgramData\FLEXnet =>.Flexera Software
O43 - CFD: 13/03/2016 - [0] D -- C:\ProgramData\Freemake =>.Freemake
O43 - CFD: 13/03/2016 - [] D -- C:\ProgramData\Installations =>.Unknow
O43 - CFD: 26/02/2017 - [] D -- C:\ProgramData\Malwarebytes =>.Malwarebytes
O43 - CFD: 26/09/2010 - [] D -- C:\ProgramData\Maxtor =>.Maxtor
O43 - CFD: 26/11/2013 - [] D -- C:\ProgramData\McAfee =>.McAfee
O43 - CFD: 20/03/2016 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 13/12/2016 - [] D -- C:\ProgramData\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 10/05/2012 - [] D -- C:\ProgramData\Mozilla =>.Mozilla Corporation
O43 - CFD: 09/02/2017 - [] D -- C:\ProgramData\Oracle =>.Oracle
O43 - CFD: 21/02/2017 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 11/12/2010 - [] D -- C:\ProgramData\pbTPLVyBrsWMQuu
O43 - CFD: 24/10/2010 - [] D -- C:\ProgramData\PC Suite =>.Nokia Inc.
O43 - CFD: 15/11/2015 - [0] D -- C:\ProgramData\PhotoStitch
O43 - CFD: 01/03/2017 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
O43 - CFD: 05/03/2017 - [] D -- C:\ProgramData\RogueKiller =>.Adlice
O43 - CFD: 21/10/2016 - [0] D -- C:\ProgramData\Roxio =>.Roxio
O43 - CFD: 13/09/2010 - [] D -- C:\ProgramData\SiteAdvisor =>.McAfee Inc.
O43 - CFD: 09/02/2017 - [] D -- C:\ProgramData\Skype =>.Skype
O43 - CFD: 15/08/2011 - [] D -- C:\ProgramData\Skype Extras =>.Skype
O43 - CFD: 17/04/2011 - [] D -- C:\ProgramData\Sonic =>.Sonic
O43 - CFD: 25/02/2017 - [] D -- C:\ProgramData\Sony Corporation =>.Sony Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation
O43 - CFD: 17/10/2010 - [] D -- C:\ProgramData\Sun =>.Oracle
O43 - CFD: 11/10/2016 - [] D -- C:\ProgramData\SUPERAntiSpyware.com =>.SUPERAntiSpyware.com
O43 - CFD: 14/02/2017 - [] D -- C:\ProgramData\SUPERSetup
O43 - CFD: 07/12/2012 - [0] AD -- C:\ProgramData\TEMP =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation
O43 - CFD: 13/09/2010 - [] D -- C:\ProgramData\Uninstall =>.Unknow
O43 - CFD: 01/10/2016 - [] D -- C:\ProgramData\Western Digital =>.Western Digital
O43 - CFD: 27/10/2016 - [] D -- C:\ProgramData\Wondershare =>.Wondershare
O43 - CFD: 18/12/2010 - [0] D -- C:\ProgramData\ZoomBrowser =>.Canon Inc.
O43 - CFD: 04/02/2012 - [] D -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001} =>.GEAR Software, Inc.
O43 - CFD: 25/12/2015 - [] D -- C:\Program Files (x86)\Common Files\Adobe =>.Adobe
O43 - CFD: 27/10/2016 - [] D -- C:\Program Files (x86)\Common Files\Apple =>.Apple Inc.
O43 - CFD: 19/10/2014 - [] D -- C:\Program Files (x86)\Common Files\ArcSoft =>.ArcSoft
O43 - CFD: 18/12/2010 - [] D -- C:\Program Files (x86)\Common Files\Canon =>.Canon
O43 - CFD: 29/10/2013 - [] D -- C:\Program Files (x86)\Common Files\Citrix =>.Citrix
O43 - CFD: 22/07/2015 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER =>.Designer
O43 - CFD: 10/06/2011 - [] D -- C:\Program Files (x86)\Common Files\InstallShield =>.InstallShield
O43 - CFD: 30/10/2012 - [] D -- C:\Program Files (x86)\Common Files\Intel Corporation =>.Intel Corporation
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files (x86)\Common Files\InterVideo =>.InterVideo
O43 - CFD: 11/12/2011 - [] D -- C:\Program Files (x86)\Common Files\Java =>.Oracle
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files (x86)\Common Files\Macrovision Shared =>.Rovi Corporation
O43 - CFD: 05/02/2012 - [] D -- C:\Program Files (x86)\Common Files\McAfee =>.McAfee
O43 - CFD: 24/09/2016 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared =>.Microsoft Corporation
O43 - CFD: 19/05/2010 - [] D -- C:\Program Files (x86)\Common Files\postureAgent =>.Microsoft Corporation
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files (x86)\Common Files\Protexis =>.Protexis Inc.
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files (x86)\Common Files\PX Storage Engine =>.Sonic Solutions
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files (x86)\Common Files\Roxio Shared =>.Roxio
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 09/02/2017 - [] D -- C:\Program Files (x86)\Common Files\Skype =>.Skype
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files (x86)\Common Files\Sonic Shared =>.Sonic
O43 - CFD: 15/07/2011 - [] D -- C:\Program Files (x86)\Common Files\Sony Shared =>.Sony Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines =>.Microsoft Corporation
O43 - CFD: 15/03/2016 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 01/10/2016 - [] D -- C:\Program Files (x86)\Common Files\Western Digital =>.Western Digital
O43 - CFD: 13/09/2010 - [] D -- C:\Program Files (x86)\Common Files\Windows Live =>.Microsoft Corporation
O43 - CFD: 07/12/2012 - [] D -- C:\Program Files (x86)\Common Files\Wise Installation Wizard =>.Seagate
O43 - CFD: 09/04/2016 - [] D -- C:\Program Files (x86)\Common Files\Wondershare =>.Wondershare
O43 - CFD: 25/09/2010 - [0] SHD -- C:\Users\goldfish\AppData\Roaming\.#
O43 - CFD: 11/03/2012 - [] D -- C:\Users\goldfish\AppData\Roaming\.freeciv
O43 - CFD: 04/03/2017 - [] D -- C:\Users\goldfish\AppData\Roaming\9-lab =>.9-lab
O43 - CFD: 16/03/2013 - [] D -- C:\Users\goldfish\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 13/03/2016 - [0] D -- C:\Users\goldfish\AppData\Roaming\Amazon =>.Amazon
O43 - CFD: 24/02/2017 - [] D -- C:\Users\goldfish\AppData\Roaming\Apple Computer =>.Apple Inc.
O43 - CFD: 19/10/2014 - [] D -- C:\Users\goldfish\AppData\Roaming\ArcSoft =>.ArcSoft
O43 - CFD: 23/09/2010 - [] D -- C:\Users\goldfish\AppData\Roaming\ATI =>.ATI
O43 - CFD: 20/02/2017 - [] D -- C:\Users\goldfish\AppData\Roaming\Avira =>.Avira Software
O43 - CFD: 11/12/2010 - [] D -- C:\Users\goldfish\AppData\Roaming\Bristol.gs
O43 - CFD: 28/11/2015 - [] RD -- C:\Users\goldfish\AppData\Roaming\Brother =>.Brother
O43 - CFD: 11/09/2011 - [] D -- C:\Users\goldfish\AppData\Roaming\Bytemobile
O43 - CFD: 18/12/2010 - [0] D -- C:\Users\goldfish\AppData\Roaming\CameraWindowDC
O43 - CFD: 09/06/2012 - [] D -- C:\Users\goldfish\AppData\Roaming\Canon =>.Canon
O43 - CFD: 10/04/2011 - [] D -- C:\Users\goldfish\AppData\Roaming\CANON INC =>.Canon Inc.
O43 - CFD: 18/12/2010 - [] D -- C:\Users\goldfish\AppData\Roaming\Corel =>.Corel Corporation
O43 - CFD: 22/02/2017 - [] D -- C:\Users\goldfish\AppData\Roaming\Dropbox =>.Dropbox
O43 - CFD: 23/02/2013 - [] D -- C:\Users\goldfish\AppData\Roaming\Evaer
O43 - CFD: 09/05/2012 - [] D -- C:\Users\goldfish\AppData\Roaming\FastStone =>.FastStone Soft
O43 - CFD: 05/03/2017 - [] D -- C:\Users\goldfish\AppData\Roaming\Geek Uninstaller =>.Geek Uninstaller
O43 - CFD: 17/10/2010 - [] D -- C:\Users\goldfish\AppData\Roaming\Gleim
O43 - CFD: 29/10/2013 - [] D -- C:\Users\goldfish\AppData\Roaming\ICAClient =>.Citrix
O43 - CFD: 23/09/2010 - [] D -- C:\Users\goldfish\AppData\Roaming\Identities =>.Microsoft Corporation
O43 - CFD: 09/04/2016 - [] D -- C:\Users\goldfish\AppData\Roaming\iMobie =>.iMobie Inc
O43 - CFD: 25/09/2010 - [] D -- C:\Users\goldfish\AppData\Roaming\InstallShield =>.InstallShield
O43 - CFD: 23/09/2010 - [] D -- C:\Users\goldfish\AppData\Roaming\Intel Corporation =>.Intel Corporation
O43 - CFD: 09/04/2016 - [] D -- C:\Users\goldfish\AppData\Roaming\JihoiTunesExtractor
O43 - CFD: 25/09/2010 - [] D -- C:\Users\goldfish\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 15/03/2016 - [] D -- C:\Users\goldfish\AppData\Roaming\MCC Pilotlog
O43 - CFD: 20/05/2010 - [0] D -- C:\Users\goldfish\AppData\Roaming\Media Center Programs =>.Microsoft Corporation
O43 - CFD: 12/09/2016 - [] SD -- C:\Users\goldfish\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 11/06/2011 - [] D -- C:\Users\goldfish\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 26/09/2010 - [] D -- C:\Users\goldfish\AppData\Roaming\MyFamily.com
O43 - CFD: 24/10/2010 - [] D -- C:\Users\goldfish\AppData\Roaming\Nokia =>.Nokia
O43 - CFD: 24/10/2010 - [] D -- C:\Users\goldfish\AppData\Roaming\PC Suite =>.Nokia Inc.
O43 - CFD: 13/03/2016 - [] D -- C:\Users\goldfish\AppData\Roaming\PMDG =>.PMDG Simulations, LLC
O43 - CFD: 26/07/2011 - [] D -- C:\Users\goldfish\AppData\Roaming\Prism
O43 - CFD: 19/10/2014 - [] D -- C:\Users\goldfish\AppData\Roaming\PTGui
O43 - CFD: 20/02/2017 - [0] D -- C:\Users\goldfish\AppData\Roaming\QuickScan =>.Bitdefender
O43 - CFD: 18/12/2010 - [] D -- C:\Users\goldfish\AppData\Roaming\Roxio =>.Roxio
O43 - CFD: 04/03/2017 - [] D -- C:\Users\goldfish\AppData\Roaming\Skype =>.Skype
O43 - CFD: 01/09/2011 - [] D -- C:\Users\goldfish\AppData\Roaming\skypePM =>.Skype Technologies
O43 - CFD: 25/09/2010 - [] D -- C:\Users\goldfish\AppData\Roaming\Sony Corporation =>.Sony Corporation
O43 - CFD: 14/02/2017 - [] D -- C:\Users\goldfish\AppData\Roaming\SUPERAntiSpyware.com =>.SUPERAntiSpyware.com
O43 - CFD: 11/09/2011 - [] D -- C:\Users\goldfish\AppData\Roaming\T-Mobile
O43 - CFD: 07/05/2011 - [] D -- C:\Users\goldfish\AppData\Roaming\Temp =>.Microsoft Corporation
O43 - CFD: 27/10/2016 - [] D -- C:\Users\goldfish\AppData\Roaming\Tenorshare =>.Tenorshare
O43 - CFD: 09/06/2013 - [] D -- C:\Users\goldfish\AppData\Roaming\vlc =>.VideoLan Team
O43 - CFD: 01/10/2016 - [] D -- C:\Users\goldfish\AppData\Roaming\Western Digital =>.Western Digital
O43 - CFD: 27/10/2016 - [] D -- C:\Users\goldfish\AppData\Roaming\Wondershare =>.Wondershare
O43 - CFD: 05/03/2017 - [] D -- C:\Users\goldfish\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 24/09/2016 - [0] D -- C:\Users\goldfish\AppData\Roaming\ZoomBrowser EX =>.Canon Inc.
O43 - CFD: 24/02/2017 - [] D -- C:\Users\goldfish\AppData\Local\748A0AB9-F073-4E14-BCD2-A692572E4A9D.aplzod
O43 - CFD: 09/02/2017 - [] D -- C:\Users\goldfish\AppData\Local\Adobe =>.Adobe
O43 - CFD: 15/03/2016 - [] D -- C:\Users\goldfish\AppData\Local\Apple =>.Apple Inc.
O43 - CFD: 15/04/2012 - [] D -- C:\Users\goldfish\AppData\Local\Apple Computer =>.Apple Inc.
O43 - CFD: 25/02/2017 - [] D -- C:\Users\goldfish\AppData\Local\Apple Inc =>.Apple Inc.
O43 - CFD: 23/09/2010 - [0] SHD -- C:\Users\goldfish\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 16/06/2012 - [] D -- C:\Users\goldfish\AppData\Local\Apps =>.Microsoft Corporation
O43 - CFD: 19/10/2014 - [] D -- C:\Users\goldfish\AppData\Local\ArcSoft =>.ArcSoft
O43 - CFD: 23/09/2010 - [] D -- C:\Users\goldfish\AppData\Local\ATI =>.ATI
O43 - CFD: 21/02/2017 - [] D -- C:\Users\goldfish\AppData\Local\Avg =>.AVG Software
O43 - CFD: 21/02/2017 - [] D -- C:\Users\goldfish\AppData\Local\Avira =>.Avira Software
O43 - CFD: 21/02/2017 - [0] D -- C:\Users\goldfish\AppData\Local\AviraSpeedup =>.Avira Software
O43 - CFD: 11/12/2010 - [] D -- C:\Users\goldfish\AppData\Local\Bristol.gs
O43 - CFD: 23/09/2010 - [] D -- C:\Users\goldfish\AppData\Local\Broadcom =>.Broadcom
O43 - CFD: 28/12/2015 - [] D -- C:\Users\goldfish\AppData\Local\CEF =>.CEF
O43 - CFD: 14/02/2017 - [] D -- C:\Users\goldfish\AppData\Local\Citrix =>.Citrix
O43 - CFD: 13/08/2015 - [0] D -- C:\Users\goldfish\AppData\Local\Deployment =>.Microsoft Corporation
O43 - CFD: 20/02/2017 - [] D -- C:\Users\goldfish\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 30/12/2012 - [] D -- C:\Users\goldfish\AppData\Local\Downloaded Installations =>.Microsoft Corporation
O43 - CFD: 22/02/2017 - [] D -- C:\Users\goldfish\AppData\Local\Dropbox =>.Dropbox
O43 - CFD: 21/02/2017 - [] D -- C:\Users\goldfish\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation
O43 - CFD: 12/06/2015 - [0] SHD -- C:\Users\goldfish\AppData\Local\EmieBrowserModeList =>.Enterprise mode Site List Mgr
O43 - CFD: 12/06/2015 - [0] SHD -- C:\Users\goldfish\AppData\Local\EmieSiteList =>.Enterprise mode Site List Mgr
O43 - CFD: 12/06/2015 - [0] SHD -- C:\Users\goldfish\AppData\Local\EmieUserList =>.Enterprise mode Site List Mgr
O43 - CFD: 11/06/2011 - [] D -- C:\Users\goldfish\AppData\Local\Evernote =>.EverNote Corporation
O43 - CFD: 05/03/2017 - [] D -- C:\Users\goldfish\AppData\Local\Google =>.Google
O43 - CFD: 12/06/2015 - [] D -- C:\Users\goldfish\AppData\Local\GWX =>.GWX
O43 - CFD: 23/09/2010 - [0] SHD -- C:\Users\goldfish\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 15/06/2014 - [0] D -- C:\Users\goldfish\AppData\Local\HockeyCrashes
O43 - CFD: 19/12/2010 - [] D -- C:\Users\goldfish\AppData\Local\IsolatedStorage =>.id Software
O43 - CFD: 03/09/2012 - [] D -- C:\Users\goldfish\AppData\Local\Macromedia =>.Macromedia
O43 - CFD: 30/10/2016 - [] D -- C:\Users\goldfish\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 20/03/2016 - [] D -- C:\Users\goldfish\AppData\Local\Microsoft Game Studios =>.Microsoft Corporation
O43 - CFD: 08/03/2015 - [] D -- C:\Users\goldfish\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 04/03/2017 - [0] DC -- C:\Users\goldfish\AppData\Local\MigWiz =>.MigWiz
O43 - CFD: 02/10/2013 - [] D -- C:\Users\goldfish\AppData\Local\Mozilla =>.Mozilla Corporation
O43 - CFD: 26/07/2011 - [] D -- C:\Users\goldfish\AppData\Local\Prism
O43 - CFD: 24/12/2013 - [] D -- C:\Users\goldfish\AppData\Local\Program Files
O43 - CFD: 06/11/2010 - [] D -- C:\Users\goldfish\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 28/12/2015 - [0] D -- C:\Users\goldfish\AppData\Local\Skype =>.Skype
O43 - CFD: 13/11/2010 - [] D -- C:\Users\goldfish\AppData\Local\Sony Corporation =>.Sony Corporation
O43 - CFD: 31/12/2011 - [] D -- C:\Users\goldfish\AppData\Local\Sony_Corporation
O43 - CFD: 05/03/2017 - [] D -- C:\Users\goldfish\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 23/09/2010 - [0] SHD -- C:\Users\goldfish\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 17/10/2010 - [] D -- C:\Users\goldfish\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 01/10/2016 - [] D -- C:\Users\goldfish\AppData\Local\Western Digital =>.Western Digital
O43 - CFD: 14/02/2017 - [] D -- C:\Users\goldfish\AppData\Local\Wickr, LLC
O43 - CFD: 24/09/2016 - [] D -- C:\Users\goldfish\AppData\Local\Windows Live =>.Microsoft Corporation
O43 - CFD: 09/04/2016 - [] D -- C:\Users\goldfish\AppData\Local\Wondershare =>.Wondershare
O43 - CFD: 09/04/2016 - [] D -- C:\Users\goldfish\AppData\Local\微软公司
O43 - CFD: 06/11/2010 - [0] D -- C:\Users\goldfish\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] RD -- C:\Users\goldfish\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 23/09/2016 - [] RD -- C:\Users\goldfish\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 16/06/2012 - [] D -- C:\Users\goldfish\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Airbox Aerospace Ltd
O43 - CFD: 24/12/2013 - [] D -- C:\Users\goldfish\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon =>.Amazon
O43 - CFD: 21/02/2017 - [0] D -- C:\Users\goldfish\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Avira =>.Avira Software
O43 - CFD: 25/09/2016 - [] D -- C:\Users\goldfish\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 30/11/2014 - [0] D -- C:\Users\goldfish\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hugin =>.Hugin
O43 - CFD: 14/07/2009 - [] RD -- C:\Users\goldfish\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 01/01/2016 - [] D -- C:\Users\goldfish\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MCC Pilotlog
O43 - CFD: 05/02/2012 - [] D -- C:\Users\goldfish\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Playsims
O43 - CFD: 04/03/2017 - [] RD -- C:\Users\goldfish\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 30/01/2012 - [] D -- C:\Users\goldfish\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UK2000 Scenery
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 11/04/2012 - [0] D -- C:\Users\Default\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 11/04/2012 - [0] D -- C:\Users\Default User\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 06/11/2010 - [0] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 25/09/2016 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Avg =>.AVG Software
O43 - CFD: 25/02/2017 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Avira =>.Avira Software
O43 - CFD: 28/02/2017 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Dropbox =>.Dropbox
O43 - CFD: 23/04/2011 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Google =>.Google
O43 - CFD: 06/11/2010 - [0] -- C:\Windows\System32\Config\systemprofile\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 21/02/2017 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 10/06/2011 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 06/11/2010 - [0] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 26/11/2011 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Apple Computer =>.Apple Inc.
O43 - CFD: 20/02/2017 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Avira =>.Avira Software
O43 - CFD: 11/09/2011 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Bytemobile
O43 - CFD: 28/02/2017 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Dropbox =>.Dropbox
O43 - CFD: 10/06/2011 - [] SD -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 26/11/2011 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\PC Suite =>.Nokia Inc.
O43 - CFD: 26/09/2010 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\SACore =>.SACore
O43 - CFD: 13/09/2010 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Sony Corporation =>.Sony Corporation

---\\ ShellIconOverlayIdentifiers (SIOI) (12) - 3s
O106 - SIOI: DropboxExt1 Class [ DropboxExt01] - {FB314ED9-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt7 Class [ DropboxExt02] - {FB314EDF-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt9 Class [ DropboxExt03] - {FB314EE1-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt3 Class [ DropboxExt04] - {FB314EDB-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt2 Class [ DropboxExt05] - {FB314EDA-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt4 Class [ DropboxExt06] - {FB314EDC-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt5 Class [ DropboxExt07] - {FB314EDD-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt8 Class [ DropboxExt08] - {FB314EE0-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt10 Class [ DropboxExt09] - {FB314EE2-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
O106 - SIOI: DropboxExt6 Class [ DropboxExt10] - {FB314EDE-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll =>.Dropbox, Inc®
O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation

---\\ System Drivers List (92) - 17s
O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\drivers\adpu320.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [317400] =>.Microsoft Windows®
O58 - SDL:2011/03/11 06:41:12 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [317400] =>.Microsoft Windows®
O58 - SDL:2011/03/11 06:41:12 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/11/04 09:59:59 A . (.Alps Electric Co., Ltd. - Alps Touch Pad Driver.) -- C:\Windows\System32\drivers\Apfiltr.sys [317400] =>.Alps Electric Co., LTD.®
O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/05/26 13:32:04 A . (.ArcSoft, Inc. - For X64.) -- C:\Windows\System32\drivers\ArcSoftKsUFilter.sys [317400] =>.ArcSoft, Inc.®
O58 - SDL:2009/11/12 20:06:44 A . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driv.) -- C:\Windows\System32\drivers\athrx.sys [317400] =>.Atheros Communications, Inc.
O58 - SDL:2010/10/08 06:55:08 A . (.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\System32\drivers\atikmdag.sys [317400] =>.ATI Technologies Inc.
O58 - SDL:2010/10/08 06:55:08 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\Windows\System32\drivers\atikmpag.sys [317400] =>.Advanced Micro Devices, Inc.
O58 - SDL:2017/02/15 16:55:52 A . (.Avira Operations GmbH & Co. KG - Avira Minifilter Driver.) -- C:\Windows\System32\drivers\avgntflt.sys [317400] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2017/02/15 16:55:52 A . (.Avira Operations GmbH & Co. KG - Avira Driver for Security Enhancement.) -- C:\Windows\System32\drivers\avipbb.sys [317400] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2017/02/15 16:55:52 A . (.Avira Operations GmbH & Co. KG - Avira Manager Driver.) -- C:\Windows\System32\drivers\avkmgr.sys [317400] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2017/02/15 16:55:52 A . (.Avira Operations GmbH & Co. KG - Avira WFP Network Driver.) -- C:\Windows\System32\drivers\avnetflt.sys [317400] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2017/02/15 16:55:52 A . (.Avira Operations GmbH & Co. KG - Avira USB Filter Driver.) -- C:\Windows\System32\drivers\avusbflt.sys [317400] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2009/06/10 20:34:23 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60a.sys [317400] =>.Broadcom Corporation
O58 - SDL:2009/06/10 20:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [317400] =>.Brother Industries, Ltd.
O58 - SDL:2009/06/10 20:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [317400] =>.Brother Industries, Ltd.
O58 - SDL:2009/07/14 01:19:07 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [317400] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 20:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [317400] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 20:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [317400] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 20:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [317400] =>.Brother Industries Ltd.
O58 - SDL:2009/11/18 04:30:21 A . (.Broadcom Corporation. - Widcomm Bluetooth USB Filter for Windows XP.) -- C:\Windows\System32\drivers\btusbflt.sys [317400] =>.Broadcom Corporation®
O58 - SDL:2009/11/18 04:30:32 A . (.Broadcom Corporation. - Bluetooth Audio Device.) -- C:\Windows\System32\drivers\btwaudio.sys [317400] =>.Broadcom Corporation®
O58 - SDL:2009/11/18 04:30:32 A . (.Broadcom Corporation. - Broadcom Bluetooth AVDT Service.) -- C:\Windows\System32\drivers\btwavdt.sys [317400] =>.Broadcom Corporation®
O58 - SDL:2009/11/18 04:23:46 A . (.Broadcom Corporation. - Broadcom Bluetooth L2CAP Service.) -- C:\Windows\System32\drivers\btwl2cap.sys [317400] =>.Broadcom Corporation®
O58 - SDL:2009/11/18 04:30:44 A . (.Broadcom Corporation. - Bluetooth Remote Control HID Minidriver.) -- C:\Windows\System32\drivers\btwrchid.sys [317400] =>.Broadcom Corporation®
O58 - SDL:2009/06/10 20:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [317400] =>.Broadcom Corporation
O58 - SDL:2009/05/15 10:00:00 N . (.Sonic Solutions - CDR4 64-bit CD and DVD Place Holder Driver.) -- C:\Windows\System32\drivers\cdr4_xp.sys [317400] =>.Sonic Solutions®
O58 - SDL:2009/05/15 10:00:00 N . (.Sonic Solutions - CDRAL 64-bit Place Holder Driver (see PxHel.) -- C:\Windows\System32\drivers\cdralw2k.sys [317400] =>.Sonic Solutions®
O58 - SDL:2009/07/14 01:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [317400] =>.Microsoft Windows®
O58 - SDL:2013/09/24 07:10:34 A . (.Citrix Systems, Inc. - Citrix USB Filter Driver.) -- C:\Windows\System32\drivers\ctxusbm.sys [317400] {1DCED972D082A6A82CA2A99FBCEA3A95} =>.Citrix Systems, Inc.
O58 - SDL:2017/02/21 18:49:04 A . (.Dropbox, Inc. - Dropbox Filter Driver.) -- C:\Windows\System32\drivers\dbx-canary.sys [317400] =>.Microsoft Windows Hardware Compatibility Publisher®
O58 - SDL:2017/02/21 18:49:04 A . (.Dropbox, Inc. - Dropbox Filter Driver.) -- C:\Windows\System32\drivers\dbx-dev.sys [317400] =>.Microsoft Windows Hardware Compatibility Publisher®
O58 - SDL:2017/02/09 08:33:38 A . (.Dropbox, Inc. - Dropbox Filter Driver.) -- C:\Windows\System32\drivers\dbx-stable.sys [317400] =>.Microsoft Windows Hardware Compatibility Publisher®
O58 - SDL:2009/07/14 01:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/06/10 20:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [317400] =>.Broadcom Corporation
O58 - SDL:2011/03/01 20:44:55 A . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\Windows\System32\drivers\ewusbfake.sys [317400] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2011/03/01 20:44:55 A . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\Windows\System32\drivers\ewusbmdm.sys [317400] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2017/03/03 22:55:56 A . (.Malwarebytes - Malwarebytes Anti-Ransomware Protection.) -- C:\Windows\System32\drivers\farflt.sys [317400] =>.Malwarebytes Corporation®
O58 - SDL:2012/08/21 12:01:20 A . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\System32\drivers\GEARAspiWDM.sys [317400] =>.GEAR Software Inc.®
O58 - SDL:2009/06/10 20:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [317400] =>.Hauppauge Computer Works, Inc.
O58 - SDL:2009/12/14 20:06:07 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\drivers\HECIx64.sys [317400] =>.Intel Corporation®
O58 - SDL:2014/06/15 16:12:37 A . (.Hola Networks Ltd. - Hola Network Monitor Driver.) -- C:\Windows\System32\drivers\hola_mon_drv.sys [317400] {08D34F3F819F7FB1B4FAB09F4F5B5D39} =>.Hola Networks Ltd.
O58 - SDL:2010/11/20 13:33:35 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/11/20 22:09:48 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStor.sys [317400] =>.Intel Corporation®
O58 - SDL:2011/03/11 06:41:26 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/12/16 20:03:04 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd64.sys [317400] =>.Intel Corporation
O58 - SDL:2009/07/14 01:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/11/13 20:08:21 A . (.Intel Corporation - Intel(R) Turbo Boost Technology Driver.) -- C:\Windows\System32\drivers\Impcd.sys [317400] =>.Intel Corporation
O58 - SDL:2009/12/16 20:03:59 A . (.Intel(R) Corporation - Intel(R) Display HD Audio driver.) -- C:\Windows\System32\drivers\IntcDAud.sys [317400] =>.Intel(R) Corporation
O58 - SDL:2009/11/17 09:44:54 A . (.TCT International Mobile Ltd - USB Modem/Serial Device Driver.) -- C:\Windows\System32\drivers\jrdusbser.sys [317400] =>.TCT International Mobile Ltd
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [317400] =>.Microsoft Windows®
O58 - SDL:2017/01/20 07:47:44 A . (.Authors - .) -- C:\Windows\System32\drivers\mbae64.sys [317400] =>.Malwarebytes Corporation®
O58 - SDL:2017/03/03 22:55:55 A . (.Malwarebytes - Malwarebytes Real-Time Protection.) -- C:\Windows\System32\drivers\mbam.sys [317400] =>.Malwarebytes Corporation®
O58 - SDL:2017/02/26 18:30:58 A . (.Malwarebytes - Malwarebytes Chameleon.) -- C:\Windows\System32\drivers\MBAMChameleon.sys [317400] =>.Malwarebytes Corporation®
O58 - SDL:2017/03/03 22:55:53 A . (.Malwarebytes - Malwarebytes SwissArmy.) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys [317400] =>.Malwarebytes Corporation®
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [317400] =>.Microsoft Windows®
O58 - SDL:2017/02/26 21:57:34 A . (.Malwarebytes - Malwarebytes Web Protection.) -- C:\Windows\System32\drivers\mwac.sys [317400] =>.Malwarebytes Corporation®
O58 - SDL:2013/08/06 15:13:30 A . (.Apple Inc. - Apple Mobile Device Ethernet.) -- C:\Windows\System32\drivers\netaapl64.sys [317400] =>.Apple Inc.
O58 - SDL:2009/07/14 01:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [317400] =>.Microsoft Windows®
O58 - SDL:2011/03/11 06:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [317400] =>.Microsoft Windows®
O58 - SDL:2011/03/11 06:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/05/20 10:00:00 N . (.Sonic Solutions - Px Engine Device Driver for 64-bit Windows.) -- C:\Windows\System32\drivers\PxHlpa64.sys [317400] =>.Sonic Solutions®
O58 - SDL:2009/07/14 01:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [317400] =>.Microsoft Windows®
O58 - SDL:2007/04/17 10:51:50 A . (.InterVideo - regi driver.) -- C:\Windows\System32\drivers\regi.sys [317400] =>.Intervideo, Inc.®
O58 - SDL:2009/11/06 20:27:30 A . (.REDC - RICOH MS Driver.) -- C:\Windows\System32\drivers\rimssne64.sys [317400] =>.REDC
O58 - SDL:2009/09/15 20:09:08 A . (.REDC - RICOH PCIe SD/MMC Driver.) -- C:\Windows\System32\drivers\risdsne64.sys [317400] =>.REDC
O58 - SDL:2009/12/16 02:49:48 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RtHDMIVX.sys [317400] =>.Realtek Semiconductor Corp®
O58 - SDL:2009/12/16 05:08:00 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RTKVHD64.sys [317400] =>.Realtek Semiconductor Corp®
O58 - SDL:2009/06/10 20:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [317400] =>.Macrovision Corporation, Macrovision Europe Limited,
O58 - SDL:2009/08/19 20:09:21 A . (.Sony Corporation - Sony Firmware Extension Parser driver.) -- C:\Windows\System32\drivers\SFEP.sys [317400] =>.Sony Corporation
O58 - SDL:2009/07/14 01:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [317400] =>.Microsoft Windows®
O58 - SDL:2014/03/24 10:43:26 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver.) -- C:\Windows\System32\drivers\tap0901.sys [317400] =>.OpenVPN Technologies, Inc.®
O58 - SDL:2017/03/05 10:39:28 A . (.Authors - .) -- C:\Windows\System32\drivers\TrueSight.sys [317400] =>.Adlice®
O58 - SDL:2015/06/10 22:08:36 A . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\drivers\usbaapl64.sys [317400] =>.Apple, Inc.
O58 - SDL:2009/07/14 01:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [317400] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [317400] =>.Microsoft Windows®
O58 - SDL:2015/04/29 23:01:06 A . (.Western Digital Technologies - WD SCSI Architecture Model (SAM) driver.) -- C:\Windows\System32\drivers\wdcsam64.sys [317400] =>.Microsoft Windows Hardware Compatibility Publisher®
O58 - SDL:2016/01/14 10:10:44 A . (.Western Digital Technologies - WD SCSI Architecture Model (SAM) driver.) -- C:\Windows\System32\drivers\wdcsam64_prewin8.sys [317400] =>.Microsoft Windows Hardware Compatibility Publisher®
O58 - SDL:2009/11/12 20:16:19 A . (.Authors - .) -- C:\Windows\System32\drivers\yk62x64.sys [317400]

---\\ Last modified or created user files (2) - 138s
O61 - LFC: 2017/03/04 22:26:20 A . (.Copyright © 2015.) -- C:\Users\goldfish\Desktop\Antivirus EXEs\Adware Removal Tool by TSA.exe [752296] {317DD1C55F51AC2756D9C93C060C6FA5}
O61 - LFC: 2017/03/05 10:22:51 A . (.Alex Dragokas.) -- C:\Users\goldfish\Desktop\laptop issue\clearlnk_2.9.0.11.exe [462976]

---\\ File Associations Shell Spawning (10) - 1s
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S

---\\ Start Menu Internet (12) - 0s
O68 - StartMenuInternet: <Avira Scout> <Avira Scout>[HKLM\..\Shell\open\Command] (.Avira Operations GmbH & Co. KG - Avira Scout.) -- C:\Program Files (x86)\Avira\Scout\Application\scout.exe =>.Avira Operations GmbH & Co. KG®
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O68 - StartMenuInternet: <Avira Scout> <Avira Scout>[HKLM\..\InstallInfo\ShowIconsCommand] (.Avira Operations GmbH & Co. KG - Avira Scout.) -- C:\Program Files (x86)\Avira\Scout\Application\scout.exe =>.Avira Operations GmbH & Co. KG
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: <Avira Scout> <Avira Scout>[HKLM\..\InstallInfo\ReinstallCommand] (.Avira Operations GmbH & Co. KG - Avira Scout.) -- C:\Program Files (x86)\Avira\Scout\Application\scout.exe =>.Avira Operations GmbH & Co. KG
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: <Avira Scout> <Avira Scout>[HKLM\..\InstallInfo\HideIconsCommand] (.Avira Operations GmbH & Co. KG - Avira Scout.) -- C:\Program Files (x86)\Avira\Scout\Application\scout.exe =>.Avira Operations GmbH & Co. KG
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

---\\ Search Browser Infection (5) - 11s
O69 - SBI: SearchScopes [HKCU] {67B4F6F6-DEA2-42F9-84A7-6785674F4D19} [DefaultScope] - (Google) - http://www.google.com/ =>.Google Inc.
O69 - SBI: SearchScopes [HKCU] {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} - (Google) - http://www.google.com/ =>.Google Inc.
O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKLM] {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} - (Google) - http://www.google.com/ =>.Google Inc.
O69 - SBI: SearchScopes [HKLM] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - http://www.google.com/ =>.Google Inc.

---\\ Search Svchost Services (32) - 0s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\Windows\System32\aelupsvc.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\Windows\system32\srvsvc.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\Windows\System32\gpsvc.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\ikeext.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\Windows\System32\Audiosrv.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\Windows\System32\rasauto.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\Windows\System32\Sens.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remote Desktop Session Host Server Remote C.) -- C:\Windows\System32\termsrv.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\system32\wuaueng.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\Windows\System32\qmgr.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\Windows\system32\seclogon.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\Windows\System32\appinfo.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\Windows\system32\iscsiexe.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) -- C:\Windows\system32\mmcss.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\Windows\System32\browser.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\Windows\system32\schedsvc.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\Windows\system32\kmsvc.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\Windows\System32\wercplsupport.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\Windows\system32\themeservice.dll [317400] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\Windows\System32\bdesvc.dll [317400] =>.Microsoft Corporation

---\\ Additional Scan (O88) (7) - 0s
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} =>.Superfluous.Orphan
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} =>.Superfluous.Orphan
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} =>.Superfluous.Orphan
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} =>.Superfluous.Orphan
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} =>.Superfluous.Orphan
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C} =>Riskware.QuickTime
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C} =>Riskware.QuickTime

---\\ Summary of the elements found (1) - 0s
https://nicolascoolman.eu/2017/01/15/riskware-quicktime/ =>Riskware.QuickTime

~ Unselected Options: O82,
~ End of the scan, 94527 items in 07mn38s (1490)(0)
 
The Ninite installer froze partway through and wouldn't cancel either, but it seems to have installed okay (and no error when I log in).

Sweet.

The file C:\Windows\Minidump\030517-23103-01.dmp
is not found with everything, and when I manually go to the directory using Windows Explorer it is empty. This happened when I had the error previously too - couldn't find the file.

Ccleaner settings, Uncheck the option that deletes the dump files.

upload_2017-3-5_13-14-26.png
 
You have any idea what this is?

C:\Users\goldfish\AppData\Local\微软公司

Also, on a side note you will need to replace your user name in order for these fixes to work.
 
Sure, apologies, I'm quite conscious of security when posting publicly. Should I re-run the fixlist.txt with "goldfish" replaced with my name? Then run RogueKiller again? RogueKiller takes a long time so if there is anything else I should run first, please let me know.

I'm not sure what that file is. I lived in Hong Kong so might have some Chinese-language things on my laptop, but it was a long time ago and I don't speak Chinese myself so shouldn't be much. (Google translate says it is "Microsoft Corporation if that helps?)
 
No, lets not run the fixlist again, for the most part everything listed was removed.

Would you like the Chinese stuff removed from your machine, or leave it?

I would like you to run RogueKiller again, cause I am curious as to why it is BSOD. So run it, allow it to crash (if it does) then analyze the dump file and post it. It will take some time to go over this latest log.

Also, is this a business machine? Or your personal?

Have any idea what this file is??

C:\Users\goldfish\AppData\Roaming\.#
 
Okay, I'll run RogueKiller again. It's my personal machine but right now I don't have a job so I am doing some freelancing from home.
It's fine to remove the Chinese language things.
No idea what that file is!
 
ZHP Fix
4bd9Ugb.png

  • Disable your antivirus prior to this fix!
  • Download ZHP-Fix from here.
  • Install it.
  • Click Suivant 5 Times.
  • Then Installer.
  • Then Terminer.
  • Then right clcick the ZHP Fix icon Run as admin.
  • Copy the entire content of the code box below, the next step will grab it from your clipboard.
  • Then click on import.
  • Then click GO.
  • Allow completion.
  • A log file will appear on your desktop.
  • Post it here in your next reply.

Notice!! The Chinese items are listed in the fix, you may remove them if you wish. The two above mentioned fodlers are listed in the fix as well...



Code:
Script ZhpFix
SysRestore
EmptyFlash
ProxyFix
EmptyCLSID
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated - Adobe® Flash® Player Update Service 24.0 r0.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated®
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Desktop Gadgets.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Desktop Gadgets.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.facebook.com =>.Facebook
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://login.yahoo.com/ =>.Yahoo! Inc.
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk-mg5.mail.yahoo.com/ =>.Yahoo! Inc.
O42 - Logiciel: Chinese Traditional Fonts Support For Adobe Reader 9 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-2448-0000-900000000003} =>.Adobe Systems Incorporated
HKLM\SOFTWARE\Wow6432Node\America Online =>.America Online
HKLM\SOFTWARE\Wow6432Node\AVG =>.AVG Software
HKLM\SOFTWARE\Wow6432Node\Avg Secure Update =>.AVG Software
HKLM\SOFTWARE\Wow6432Node\McAfee =>.McAfee Inc.
HKLM\SOFTWARE\Wow6432Node\McAfee.com =>.McAfee Inc.
HKLM\SOFTWARE\Wow6432Node\McAfeeInstaller =>.McAfee Inc.
HKCU\SOFTWARE\Avg =>.AVG Software
C:\Windows\System32\drivers\hola_mon_drv.sys
HKCU\SOFTWARE\Avg Secure Update =>.AVG Software
HKCU\SOFTWARE\AVG Web TuneUp =>.AVG Web TuneUp
HKCU\SOFTWARE\MCAFEE =>.McAfee Inc.
HKCU\SOFTWARE\アプリケーション ウィザードで生成されたローカル アプリケーション
HKCU\SOFTWARE\AppDataLow\Software\Avg =>.AVG Software
O43 - CFD: 24/11/2013 - [0] D -- C:\Program Files\McAfee =>.McAfee
O43 - CFD: 09/04/2016 - [] D -- C:\Program Files (x86)\Jihosoft =>.HONGKONG JIHO CO., LIMITED®
O43 - CFD: 26/11/2013 - [] D -- C:\Program Files (x86)\McAfee =>.McAfee
O43 - CFD: 26/11/2013 - [] D -- C:\ProgramData\McAfee =>.McAfee
O43 - CFD: 11/12/2010 - [] D -- C:\ProgramData\pbTPLVyBrsWMQuu
O43 - CFD: 13/09/2010 - [] D -- C:\ProgramData\SiteAdvisor =>.McAfee Inc.
O43 - CFD: 05/02/2012 - [] D -- C:\Program Files (x86)\Common Files\McAfee =>.McAfee
O43 - CFD: 25/09/2010 - [0] SHD -- C:\Users\goldfish\AppData\Roaming\.#
O43 - CFD: 20/02/2017 - [0] D -- C:\Users\goldfish\AppData\Roaming\QuickScan =>.Bitdefender
O43 - CFD: 11/09/2011 - [] D -- C:\Users\goldfish\AppData\Roaming\T-Mobile
O43 - CFD: 21/02/2017 - [] D -- C:\Users\goldfish\AppData\Local\Avg =>.AVG Software
O43 - CFD: 12/06/2015 - [] D -- C:\Users\goldfish\AppData\Local\GWX =>.GWX
O43 - CFD: 25/09/2016 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Avg =>.AVG Software
O58 - SDL:2014/06/15 16:12:37 A . (.Hola Networks Ltd. - Hola Network Monitor Driver.) -- C:\Windows\System32\drivers\hola_mon_drv.sys [317400] {08D34F3F819F7FB1B4FAB09F4F5B5D39} =>.Hola Networks Ltd.
O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} =>.Superfluous.Orphan
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} =>.Superfluous.Orphan
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} =>.Superfluous.Orphan
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} =>.Superfluous.Orphan
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} =>.Superfluous.Orphan
EmptyTemp


ADS SCAN.

Download ADS to your desktop.
Right Click Run As Administrator.
Click on Listing.
ads-png.1083

A file named Services_List Will appear on your desktop.
Please copy the content of that, and paste it in your next reply.
 
I am also curious as to why there is Chinese writing for Microsoft.
When your machine was is installed in English.....:cautious:

Code:
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)

I'd like you to check the content of that folder as well for me please. Search 微软公司 with the everything search engine, screen shot the content of that folder or at least let me know what resides within.
 
Blue-screened again (same details as last time other than a slightly different filename). The output of the analysis is below and the .dmp file is attached.

========================================================================================================

Instant Online Crash Analysis, brought to you by OSR Open Systems Resources, Inc.
collapse.gif
Primary Analysis

Crash Dump Analysis provided by OSR Open Systems Resources, Inc. (http://www.osr.com)
Online Crash Dump Analysis Service
See http://www.osronline.com for more information
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.23572.amd64fre.win7sp1_ldr.161011-0600
Machine Name:
Kernel base = 0xfffff800`05666000 PsLoadedModuleList = 0xfffff800`058a8730
Debug session time: Sun Mar 5 16:03:27.992 2017 (UTC - 5:00)
System Uptime: 0 days 2:58:11.491
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffffa8019ee0040, memory referenced.
Arg2: 0000000000000001, value 0 = read operation, 1 = write operation.
Arg3: fffff88004433ce0, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)

Debugging Details:
------------------


Could not read faulting driver name
TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\modclass.ini, error 2

WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80005912100
GetUlongFromAddress: unable to read from fffff800059121c8
fffffa8019ee0040 Nonpaged pool

FAULTING_IP:
rimssne64+13ce0
fffff880`04433ce0 488911 mov qword ptr [rcx],rdx

MM_INTERNAL_CODE: 2

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT

BUGCHECK_STR: 0x50

PROCESS_NAME: RogueKiller64.

CURRENT_IRQL: 0

TRAP_FRAME: fffff8800cad4380 -- (.trap 0xfffff8800cad4380)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa8019ee0040 rbx=0000000000000000 rcx=fffffa8019ee0040
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88004433ce0 rsp=fffff8800cad4518 rbp=fffffa80082d01a0
r8=0000000000000000 r9=0000000000000004 r10=0000000000000000
r11=fffff8800cad4608 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
rimssne64+0x13ce0:
fffff880`04433ce0 488911 mov qword ptr [rcx],rdx ds:fffffa80`19ee0040=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER: from fffff80005751cb2 to fffff800056d6400

STACK_TEXT:
fffff880`0cad4218 fffff800`05751cb2 : 00000000`00000050 fffffa80`19ee0040 00000000`00000001 fffff880`0cad4380 : nt!KeBugCheckEx
fffff880`0cad4220 fffff800`056d452e : 00000000`00000001 fffffa80`19ee0040 fffffa81`00150000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x3a306
fffff880`0cad4380 fffff880`04433ce0 : fffff880`0442db55 00000000`00000000 00000000`00000000 fffffa80`0bd57aa0 : nt!KiPageFault+0x16e
fffff880`0cad4518 fffff880`0442db55 : 00000000`00000000 00000000`00000000 fffffa80`0bd57aa0 fffff880`012b12ec : rimssne64+0x13ce0
fffff880`0cad4520 00000000`00000000 : 00000000`00000000 fffffa80`0bd57aa0 fffff880`012b12ec fffffa80`09d64320 : rimssne64+0xdb55


STACK_COMMAND: kb

FOLLOWUP_IP:
rimssne64+13ce0
fffff880`04433ce0 488911 mov qword ptr [rcx],rdx

SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: rimssne64+13ce0

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: rimssne64

IMAGE_NAME: rimssne64.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 4ad84fca

FAILURE_BUCKET_ID: X64_0x50_rimssne64+13ce0

BUCKET_ID: X64_0x50_rimssne64+13ce0

Followup: MachineOwner
---------



This free analysis is provided by OSR Open Systems Resources, Inc.
Want a deeper understanding of crash dump analysis? Check out our Windows Kernel Debugging and Crash Dump Analysis Seminar (opens in new tab/window)
collapse.gif
Crash Code Links

View the MSDN page for PAGE_FAULT_IN_NONPAGED_AREA
Search Google for PAGE_FAULT_IN_NONPAGED_AREA
Bugchecks Explained: PAGE_FAULT_IN_NONPAGED_AREA


collapse.gif
Information About Address 0xfffffa8019ee0040

Supplied dump is a mini-dump. Memory analysis commands unavailable.


collapse.gif
Loaded Module List

start end module name
fffff800`00bb2000 fffff800`00bbc000 kdcom kdcom.dll
fffff800`0561d000 fffff800`05666000 hal hal.dll
fffff800`05666000 fffff800`05c4c000 nt ntkrnlmp.exe
fffff880`00c00000 fffff880`00c75000 CI CI.dll
fffff880`00c75000 fffff880`00c9b000 tunnel tunnel.sys
fffff880`00cac000 fffff880`00d2a000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll
fffff880`00d2a000 fffff880`00d3e000 PSHED PSHED.dll
fffff880`00d3e000 fffff880`00d9d000 CLFS CLFS.SYS
fffff880`00d9d000 fffff880`00df9000 volmgrx volmgrx.sys
fffff880`00e00000 fffff880`00e0d000 vdrvroot vdrvroot.sys
fffff880`00e0d000 fffff880`00e22000 partmgr partmgr.sys
fffff880`00e22000 fffff880`00e2b000 compbatt compbatt.sys
fffff880`00e2b000 fffff880`00e37000 BATTC BATTC.SYS
fffff880`00e37000 fffff880`00e4c000 volmgr volmgr.sys
fffff880`00e4c000 fffff880`00e66000 mountmgr mountmgr.sys
fffff880`00e66000 fffff880`00e8e000 avipbb avipbb.sys
fffff880`00e91000 fffff880`00f53000 Wdf01000 Wdf01000.sys
fffff880`00f53000 fffff880`00f63000 WDFLDR WDFLDR.SYS
fffff880`00f63000 fffff880`00fba000 ACPI ACPI.sys
fffff880`00fba000 fffff880`00fc3000 WMILIB WMILIB.SYS
fffff880`00fc3000 fffff880`00fcd000 msisadrv msisadrv.sys
fffff880`00fcd000 fffff880`01000000 pci pci.sys
fffff880`01000000 fffff880`0104c000 volsnap volsnap.sys
fffff880`01067000 fffff880`0126f000 iaStor iaStor.sys
fffff880`0126f000 fffff880`01278000 atapi atapi.sys
fffff880`01278000 fffff880`012a2000 ataport ataport.SYS
fffff880`012a2000 fffff880`012ad000 amdxata amdxata.sys
fffff880`012ad000 fffff880`012f9000 fltmgr fltmgr.sys
fffff880`012f9000 fffff880`0130d000 fileinfo fileinfo.sys
fffff880`0130d000 fffff880`01318e00 PxHlpa64 PxHlpa64.sys
fffff880`01319000 fffff880`01377000 msrpc msrpc.sys
fffff880`01377000 fffff880`013ec000 cng cng.sys
fffff880`01405000 fffff880`015ae000 Ntfs Ntfs.sys
fffff880`015ae000 fffff880`015c9000 ksecdd ksecdd.sys
fffff880`015c9000 fffff880`015da000 pcw pcw.sys
fffff880`015da000 fffff880`015e4000 Fs_Rec Fs_Rec.sys
fffff880`015e4000 fffff880`015ee000 avkmgr avkmgr.sys
fffff880`01600000 fffff880`01661000 NETIO NETIO.SYS
fffff880`01661000 fffff880`0168c000 ksecpkg ksecpkg.sys
fffff880`0168c000 fffff880`016d5000 fwpkclnt fwpkclnt.sys
fffff880`016d6000 fffff880`017c9000 ndis ndis.sys
fffff880`017c9000 fffff880`017d8000 avusbflt avusbflt.sys
fffff880`017d8000 fffff880`017e0000 spldr spldr.sys
fffff880`017e0000 fffff880`017ff000 dfsc dfsc.sys
fffff880`01801000 fffff880`019fd000 tcpip tcpip.sys
fffff880`01a00000 fffff880`01a0b000 mssmbios mssmbios.sys
fffff880`01a0b000 fffff880`01a196a0 mbae64 mbae64.sys
fffff880`01a1a000 fffff880`01a29000 discache discache.sys
fffff880`01a29000 fffff880`01a3a000 blbdrive blbdrive.sys
fffff880`01a41000 fffff880`01a7b000 rdyboost rdyboost.sys
fffff880`01a7b000 fffff880`01a8d000 mup mup.sys
fffff880`01a8d000 fffff880`01a96000 hwpolicy hwpolicy.sys
fffff880`01a96000 fffff880`01ad0000 fvevol fvevol.sys
fffff880`01ad0000 fffff880`01ae6000 disk disk.sys
fffff880`01ae6000 fffff880`01b16000 CLASSPNP CLASSPNP.SYS
fffff880`01b24000 fffff880`01b4a000 pacer pacer.sys
fffff880`01b4a000 fffff880`01b60000 vwififlt vwififlt.sys
fffff880`01b60000 fffff880`01b7b000 wanarp wanarp.sys
fffff880`01b7b000 fffff880`01b8f000 termdd termdd.sys
fffff880`01b8f000 fffff880`01b99000 SASKUTIL64 SASKUTIL64.SYS
fffff880`01b99000 fffff880`01ba3000 SASDIFSV64 SASDIFSV64.SYS
fffff880`01ba3000 fffff880`01bf4000 rdbss rdbss.sys
fffff880`01bf4000 fffff880`01c00000 nsiproxy nsiproxy.sys
fffff880`02e00000 fffff880`02e44000 Apfiltr Apfiltr.sys
fffff880`02e44000 fffff880`02e53000 mouclass mouclass.sys
fffff880`02e53000 fffff880`02e78180 Impcd Impcd.sys
fffff880`02e79000 fffff880`02e8f000 intelppm intelppm.sys
fffff880`02e8f000 fffff880`02ec5000 atikmpag atikmpag.sys
fffff880`02ec5000 fffff880`02ee9000 HDAudBus HDAudBus.sys
fffff880`02ee9000 fffff880`02efa000 HECIx64 HECIx64.sys
fffff880`02efa000 fffff880`02f0c000 usbehci usbehci.sys
fffff880`02f0c000 fffff880`02f63000 USBPORT USBPORT.SYS
fffff880`02f63000 fffff880`02fc8000 yk62x64 yk62x64.sys
fffff880`02fc8000 fffff880`02fe6000 i8042prt i8042prt.sys
fffff880`02fe6000 fffff880`02ff6000 CompositeBus CompositeBus.sys
fffff880`04000000 fffff880`04089000 afd afd.sys
fffff880`04089000 fffff880`04092000 wfplwf wfplwf.sys
fffff880`04092000 fffff880`040a1000 netbios netbios.sys
fffff880`040a1000 fffff880`042a9000 dump_iaStor dump_iaStor.sys
fffff880`042bf000 fffff880`042e9000 cdrom cdrom.sys
fffff880`042e9000 fffff880`042f2000 Null Null.SYS
fffff880`042f2000 fffff880`042f9000 Beep Beep.SYS
fffff880`042f9000 fffff880`0430ef00 ctxusbm ctxusbm.sys
fffff880`0430f000 fffff880`0431d000 vga vga.sys
fffff880`0431d000 fffff880`04342000 VIDEOPRT VIDEOPRT.SYS
fffff880`04342000 fffff880`04352000 watchdog watchdog.sys
fffff880`04352000 fffff880`0435b000 RDPCDD RDPCDD.sys
fffff880`0435b000 fffff880`04364000 rdpencdd rdpencdd.sys
fffff880`04364000 fffff880`0436d000 rdprefmp rdprefmp.sys
fffff880`0436d000 fffff880`04378000 Msfs Msfs.SYS
fffff880`04378000 fffff880`04389000 Npfs Npfs.SYS
fffff880`04389000 fffff880`043ab000 tdx tdx.sys
fffff880`043ab000 fffff880`043b8000 TDI TDI.SYS
fffff880`043b8000 fffff880`043fd000 netbt netbt.sys
fffff880`04400000 fffff880`04420000 sdbus sdbus.sys
fffff880`04420000 fffff880`04440000 rimssne64 rimssne64.sys
fffff880`04440000 fffff880`04458000 risdsne64 risdsne64.sys
fffff880`04458000 fffff880`0445ec00 GEARAspiWDM GEARAspiWDM.sys
fffff880`04461000 fffff880`045de000 athrx athrx.sys
fffff880`045de000 fffff880`045eb000 vwifibus vwifibus.sys
fffff880`045eb000 fffff880`045fa000 kbdclass kbdclass.sys
fffff880`045fa000 fffff880`045fcc80 SFEP SFEP.sys
fffff880`04600000 fffff880`0461a000 rassstp rassstp.sys
fffff880`0461a000 fffff880`0461b480 swenum swenum.sys
fffff880`0461c000 fffff880`0465f000 ks ks.sys
fffff880`0465f000 fffff880`04671000 umbus umbus.sys
fffff880`04695000 fffff880`046dc000 msiscsi msiscsi.sys
fffff880`046dc000 fffff880`04740000 storport storport.sys
fffff880`04740000 fffff880`04756000 AgileVpn AgileVpn.sys
fffff880`04756000 fffff880`0477a000 rasl2tp rasl2tp.sys
fffff880`0477a000 fffff880`04786000 ndistapi ndistapi.sys
fffff880`04786000 fffff880`047b5000 ndiswan ndiswan.sys
fffff880`047b5000 fffff880`047d0000 raspppoe raspppoe.sys
fffff880`047d0000 fffff880`047f1000 raspptp raspptp.sys
fffff880`04a00000 fffff880`04a46000 dxgmms1 dxgmms1.sys
fffff880`04a46000 fffff880`04a4a500 CmBatt CmBatt.sys
fffff880`04a51000 fffff880`050fd000 atikmdag atikmdag.sys
fffff880`050fd000 fffff880`051f2000 dxgkrnl dxgkrnl.sys
fffff880`0544c000 fffff880`054a6000 usbhub usbhub.sys
fffff880`054a6000 fffff880`054bb000 NDProxy NDProxy.SYS
fffff880`054bb000 fffff880`054ed700 RtHDMIVX RtHDMIVX.sys
fffff880`054ee000 fffff880`0552b000 portcls portcls.sys
fffff880`0552b000 fffff880`0554d000 drmk drmk.sys
fffff880`0554d000 fffff880`05552200 ksthunk ksthunk.sys
fffff880`05553000 fffff880`0556b000 rspndr rspndr.sys
fffff880`06000000 fffff880`06023000 luafv luafv.sys
fffff880`06023000 fffff880`06054000 avgntflt avgntflt.sys
fffff880`06054000 fffff880`06082000 MBAMChameleon MBAMChameleon.sys
fffff880`06082000 fffff880`06097000 lltdio lltdio.sys
fffff880`06097000 fffff880`060ea000 nwifi nwifi.sys
fffff880`060ea000 fffff880`060fd000 ndisuio ndisuio.sys
fffff880`060fd000 fffff880`06317900 RTKVHD64 RTKVHD64.sys
fffff880`06318000 fffff880`06324000 Dxapi Dxapi.sys
fffff880`06324000 fffff880`06341000 usbccgp usbccgp.sys
fffff880`06341000 fffff880`06342e80 USBD USBD.SYS
fffff880`06343000 fffff880`06351000 hidusb hidusb.sys
fffff880`06351000 fffff880`0636a000 HIDCLASS HIDCLASS.SYS
fffff880`0636a000 fffff880`06372080 HIDPARSE HIDPARSE.SYS
fffff880`06373000 fffff880`06381000 kbdhid kbdhid.sys
fffff880`06381000 fffff880`063ae400 usbvideo usbvideo.sys
fffff880`063af000 fffff880`063b9000 ArcSoftKsUFilter ArcSoftKsUFilter.sys
fffff880`063b9000 fffff880`063c6000 mouhid mouhid.sys
fffff880`063c6000 fffff880`063d4000 crashdmp crashdmp.sys
fffff880`063d4000 fffff880`063e7000 dump_dumpfve dump_dumpfve.sys
fffff880`063e7000 fffff880`063f5000 monitor monitor.sys
fffff880`07000000 fffff880`0702d000 mrxsmb mrxsmb.sys
fffff880`0702d000 fffff880`0707b000 mrxsmb10 mrxsmb10.sys
fffff880`0707b000 fffff880`0709f000 mrxsmb20 mrxsmb20.sys
fffff880`0709f000 fffff880`070b4000 avnetflt avnetflt.sys
fffff880`070d4000 fffff880`0719d000 HTTP HTTP.sys
fffff880`0719d000 fffff880`071a7000 vwifimp vwifimp.sys
fffff880`071a7000 fffff880`071c4000 bowser bowser.sys
fffff880`071c4000 fffff880`071dc000 mpsdrv mpsdrv.sys
fffff880`0a020000 fffff880`0a0ca000 peauth peauth.sys
fffff880`0a0ca000 fffff880`0a0d2000 regi regi.sys
fffff880`0a0d2000 fffff880`0a0dc000 speedfan speedfan.sys
fffff880`0a0dc000 fffff880`0a10d000 srvnet srvnet.sys
fffff880`0a10d000 fffff880`0a11f000 tcpipreg tcpipreg.sys
fffff880`0a11f000 fffff880`0a187000 srv2 srv2.sys
fffff880`0b24c000 fffff880`0b2e3000 srv srv.sys
fffff880`0b319000 fffff880`0b332000 WudfPf WudfPf.sys
fffff880`0b332000 fffff880`0b368000 WUDFRd WUDFRd.sys
fffff880`0b3d9000 fffff880`0b3e4000 asyncmac asyncmac.sys
fffff880`0b3e4000 fffff880`0b3ef000 TrueSight TrueSight.sys
fffff960`00040000 fffff960`00367000 win32k win32k.sys
fffff960`00520000 fffff960`0052a000 TSDDD TSDDD.dll
fffff960`00750000 fffff960`00777000 cdd cdd.dll

Unloaded modules:
fffff880`0b368000 fffff880`0b3d9000 spsys.sys
fffff880`0b368000 fffff880`0b3d9000 spsys.sys
fffff880`0b2e3000 fffff880`0b319000 WUDFRd.sys
fffff880`01b16000 fffff880`01b24000 crashdmp.sys
fffff880`040a4000 fffff880`042ac000 dump_iaStor.
fffff880`042ac000 fffff880`042bf000 dump_dumpfve









spsys.sys
spsys.sys
WUDFRd.sys
crashdmp.sys
dump_iaStor.
dump_dumpfve
GenuineIntel
RogueKiller64.
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\compbatt.sys
\SystemRoot\system32\drivers\BATTC.SYS
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\iaStor.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\PxHlpa64.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\System32\Drivers\avusbflt.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\drivers\disk.sys
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\system32\drivers\cdrom.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\system32\DRIVERS\ctxusbm.sys
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
\??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\mssmbios.sys
\??\C:\Windows\system32\drivers\mbae64.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\drivers\blbdrive.sys
\SystemRoot\system32\DRIVERS\avkmgr.sys
\SystemRoot\system32\DRIVERS\avipbb.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\atikmpag.sys
\SystemRoot\system32\DRIVERS\atikmdag.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\HECIx64.sys
\SystemRoot\system32\drivers\usbehci.sys
\SystemRoot\system32\drivers\USBPORT.SYS
\SystemRoot\system32\DRIVERS\athrx.sys
\SystemRoot\system32\DRIVERS\vwifibus.sys
\SystemRoot\system32\drivers\sdbus.sys
\SystemRoot\system32\drivers\rimssne64.sys
\SystemRoot\system32\drivers\risdsne64.sys
\SystemRoot\system32\DRIVERS\yk62x64.sys
\SystemRoot\system32\DRIVERS\i8042prt.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\Apfiltr.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\drivers\SFEP.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\system32\drivers\Impcd.sys
\SystemRoot\system32\drivers\intelppm.sys
\SystemRoot\system32\drivers\CmBatt.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\msiscsi.sys
\SystemRoot\system32\DRIVERS\storport.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\drivers\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\RtHDMIVX.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\drivers\RTKVHD64.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\system32\DRIVERS\ArcSoftKsUFilter.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_iaStor.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\DRIVERS\avgntflt.sys
\SystemRoot\system32\drivers\MBAMChameleon.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\DRIVERS\avnetflt.sys
\SystemRoot\system32\drivers\peauth.sys
\??\C:\Windows\system32\drivers\regi.sys
\??\C:\Windows\SysWOW64\speedfan.sys
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\system32\DRIVERS\WUDFRd.sys
\SystemRoot\system32\DRIVERS\asyncmac.sys
\??\C:\Windows\System32\drivers\TrueSight.sys
7601.23572.amd64fre.win7sp1_ldr.161011-0600
3c3e5c62-2003-41e1-9573-877f8019
A_A^A]A\_
x ATAUAVH
A^A]A\
fffffff
fffffff
fffffff
fffffff
fffffff
fffffff
H;D$8u
H;D$8t
ffffff
fffffff
TRGDDumpBlob
American Megatrends Inc.
R0300Y8
07/20/2010
Sony Corporation
VPCEB2C5E
C606A5TA

Sony Corporation

Sony Corporation
GenuineIntel
Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
L1 Cache
L2 Cache
L3 Cache
0000062381B
FNC-EXTB
9EHN32cZhM4a7y4LhtkIKfmSEv9Iafmxab9Id3kxabAS73kJLj
Reserved
6.0.3.1195
SODIMM1
Bank 0
SODIMM2
Bank 1
Component Information
Configuration Data
Identifier
Intel64 Family 6 Model 37 Stepping 5
ProcessorNameString
Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
Update Signature
Update Status
VendorIdentifier
GenuineIntel
GenuntelineI
GenuntelineI
Intel(R) Core(TMIntel(R) Core(TM
) i5 CPU M) i5 CPU M
520 @ 2.40GHz
520 @ 2.40GHz
HPET8
MCFG<
SLICv
avusbflt
SIeLR<
SCALR8
SIeLR8
Wdf01000
msisadrv
vdrvroot
avusbflt
HDAudBus
vwifibus
ApfiltrService
intelppm
CompositeBus
monitor
PEAUTH
 

Attachments

  • 030517-25599-01.dmp
    267.5 KB · Views: 29
Also RogueKiller had identified the following before the BlueScreen:
upload_2017-3-5_21-32-0.png


Here's the results of searching for .# (Searched for it using Everything then opened it.)

upload_2017-3-5_21-23-59.png


Here's the results for pbTPLVyBrsWMQuu (Searched for it using Everything then opened it.)
upload_2017-3-5_21-24-52.png


Here's the results for the Chinese language search. I think this was from a while back when I was trying various options to retrieve deleted content from my phone - I don't need any of it.
upload_2017-3-5_21-27-11.png

upload_2017-3-5_21-27-45.png

upload_2017-3-5_21-28-0.png

Contents of user.config file:
<?xml version="1.0" encoding="utf-8"?>
<configuration>
<configSections>
<sectionGroup name="userSettings" type="System.Configuration.UserSettingsGroup, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" >
<section name="DataRecovery.Properties.Settings" type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" allowExeDefinition="MachineToLocalUser" requirePermission="false" />
</sectionGroup>
</configSections>
<userSettings>
<DataRecovery.Properties.Settings>
<setting name="Culture" serializeAs="String">
<value>en-US</value>
</setting>
</DataRecovery.Properties.Settings>
</userSettings>
</configuration>
 
Here are the results of the fix and scan:

Rapport de ZHPFix 2015.10.19.9 par Nicolas Coolman, Update du 19/10/2015
Fichier d'export Registre :
Run by goldfish at 05/03/2017 21:38:38
High Elevated Privileges : OK
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)

Recycle Bin emptied (00mn 04s)

========== Software ==========
REMOVES: Chinese Traditional Fonts Support For Adobe Reader 9

========== Registry keys ==========
REMOVES: Service: AdobeARMservice
REMOVES: Service: AdobeFlashPlayerUpdateSvc
REMOVES: HKLM\SOFTWARE\Wow6432Node\America Online
REMOVES: HKLM\SOFTWARE\Wow6432Node\AVG
REMOVES: HKLM\SOFTWARE\Wow6432Node\Avg Secure Update
REMOVES: HKLM\SOFTWARE\Wow6432Node\McAfee
REMOVES: HKLM\SOFTWARE\Wow6432Node\McAfee.com
REMOVES: HKLM\SOFTWARE\Wow6432Node\McAfeeInstaller
REMOVES: HKCU\SOFTWARE\Avg
REMOVES: HKCU\SOFTWARE\Avg Secure Update
REMOVES: HKCU\SOFTWARE\AVG Web TuneUp
REMOVES: HKCU\SOFTWARE\MCAFEE
REMOVES: HKCU\SOFTWARE\???????? ??????????????? ????????
REMOVES: HKCU\SOFTWARE\AppDataLow\Software\Avg
REMOVES:* HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}
REMOVES: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}
REMOVES: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}
REMOVES:* HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}
REMOVES: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}

========== Registry values ==========
ProxyFix : Proxy configuration successfully removed
REMOVES ProxyServer Value
REMOVES ProxyEnable Value
REMOVES EnableHttp1_1 Value
REMOVES ProxyHttp1.1 Value
REMOVES ProxyOverride Value
REMOVES RunValue: Sidebar

========== Elements of the registry data ==========
REMOVES: R0 - Main,Start Page = KCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page

========== Preferences browser ==========
NOW Chrome File: C:\Users\goldfish\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
ABSENT Chrome Site: http://www.facebook.com
NOW Chrome File: C:\Users\goldfish\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
ABSENT Chrome Site: http://login.yahoo.com/

========== Folders ==========
No folders empty CLSID Local user
REMOVES: C:\Program Files\McAfee
REMOVES: C:\Program Files (x86)\Jihosoft
REMOVES: C:\Program Files (x86)\McAfee
REMOVES: C:\ProgramData\McAfee
REMOVES: C:\ProgramData\pbTPLVyBrsWMQuu
REMOVES: C:\ProgramData\SiteAdvisor
REMOVES: C:\Program Files (x86)\Common Files\McAfee
REMOVES: C:\Windows\System32\Config\systemprofile\AppData\Local\Avg
Deletes temporary Windows (110)

========== Files ==========
REMOVES Flash Cookies (0) (0 octets)
REMOVES: c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe
REMOVES: c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe
REMOVES: c:\program files\windows sidebar\sidebar.exe
REMOVES Reboot: c:\program files\windows sidebar\sidebar.exe
REMOVES: C:\Windows\System32\drivers\hola_mon_drv.sys
Deletes temporary Windows (246) (70,496,775 octets)

========== System restore ==========
The system successfully created restore point


========== Summary ==========
19 : Registry keys
7 : Registry values
1 : Elements of the registry data
10 : Folders
7 : Files
1 : Software
4 : Preferences browser
1 : System restore


End of clean in 02mn 26s

========== Path to file report ==========
C:\Users\goldfish\AppData\Roaming\ZHP\ZHPFix[R1].txt - 05/03/2017 21:38:43 [3596]


=============================================================================
---------- ADS | Services Listing

R0 - ACPI (Microsoft ACPI Driver) -> system32\drivers\ACPI.sys
R0 - amdxata () -> system32\drivers\amdxata.sys
R0 - atapi (IDE Channel) -> system32\drivers\atapi.sys
R0 - avusbflt (avusbflt) -> System32\Drivers\avusbflt.sys
R0 - CLFS (@%SystemRoot%\system32\clfs.sys,-100) -> System32\CLFS.sys
R0 - CNG () -> System32\Drivers\cng.sys
R0 - Compbatt (Microsoft Composite Battery Driver) -> system32\drivers\compbatt.sys
R0 - Disk (Disk Driver) -> system32\drivers\disk.sys
R0 - FileInfo (@%SystemRoot%\system32\drivers\fileinfo.sys,-100) -> system32\drivers\fileinfo.sys
R0 - FltMgr (@%SystemRoot%\system32\drivers\fltmgr.sys,-10001) -> system32\drivers\fltmgr.sys
S0 - Fs_Rec () -> (?)
R0 - fvevol (@%SystemRoot%\system32\drivers\fvevol.sys,-100) -> System32\DRIVERS\fvevol.sys
R0 - hwpolicy (@%systemroot%\system32\drivers\hwpolicy.sys,-101) -> System32\drivers\hwpolicy.sys
R0 - iaStor (Intel AHCI Controller) -> system32\drivers\iaStor.sys
R0 - KSecDD () -> System32\Drivers\ksecdd.sys
R0 - KSecPkg () -> System32\Drivers\ksecpkg.sys
R0 - mountmgr (@%SystemRoot%\system32\drivers\mountmgr.sys,-100) -> System32\drivers\mountmgr.sys
R0 - msisadrv () -> system32\drivers\msisadrv.sys
R0 - Mup (@%systemroot%\system32\drivers\mup.sys,-101) -> System32\Drivers\mup.sys
R0 - NDIS (@%SystemRoot%\system32\drivers\ndis.sys,-200) -> system32\drivers\ndis.sys
R0 - partmgr (@%SystemRoot%\system32\drivers\partmgr.sys,-100) -> System32\drivers\partmgr.sys
R0 - pci (PCI Bus Driver) -> system32\drivers\pci.sys
R0 - pcw (Performance Counters for Windows Driver) -> System32\drivers\pcw.sys
R0 - PxHlpa64 (PxHlpa64) -> System32\Drivers\PxHlpa64.sys
R0 - rdyboost (ReadyBoost) -> System32\drivers\rdyboost.sys
R0 - spldr (Security Processor Loader Driver) -> (?)
R0 - Tcpip (@%SystemRoot%\system32\tcpipcfg.dll,-50003) -> System32\drivers\tcpip.sys
R0 - vdrvroot (Microsoft Virtual Drive Enumerator Driver) -> system32\drivers\vdrvroot.sys
R0 - volmgr (Volume Manager Driver) -> system32\drivers\volmgr.sys
R0 - volmgrx (@%SystemRoot%\system32\drivers\volmgrx.sys,-100) -> System32\drivers\volmgrx.sys
R0 - volsnap (Storage volumes) -> system32\drivers\volsnap.sys
R0 - Wdf01000 (@%SystemRoot%\system32\drivers\Wdf01000.sys,-1000) -> system32\drivers\Wdf01000.sys
R1 - AFD (@%systemroot%\system32\drivers\afd.sys,-1000) -> \SystemRoot\system32\drivers\afd.sys
R1 - avipbb (avipbb) -> system32\DRIVERS\avipbb.sys
R1 - avkmgr (avkmgr) -> system32\DRIVERS\avkmgr.sys
R1 - Beep (Beep) -> (?)
R1 - blbdrive () -> \SystemRoot\system32\drivers\blbdrive.sys
R1 - cdrom (CD-ROM Driver) -> \SystemRoot\system32\drivers\cdrom.sys
R1 - ctxusbm (Citrix USB Monitor Driver) -> system32\DRIVERS\ctxusbm.sys
R1 - DfsC (@%systemroot%\system32\drivers\dfsc.sys,-101) -> System32\Drivers\dfsc.sys
R1 - discache (@%systemroot%\system32\drivers\discache.sys,-102) -> System32\drivers\discache.sys
R1 - ESProtectionDriver (Malwarebytes Anti-Exploit) -> \??\C:\Windows\system32\drivers\mbae64.sys
R1 - Msfs () -> (?)
R1 - mssmbios (Microsoft System Management BIOS Driver) -> \SystemRoot\system32\drivers\mssmbios.sys
R1 - NetBIOS (NetBIOS Interface) -> system32\DRIVERS\netbios.sys
R1 - NetBT (NetBT) -> System32\DRIVERS\netbt.sys
R1 - Npfs () -> (?)
R1 - nsiproxy (@%SystemRoot%\system32\drivers\nsiproxy.sys,-2) -> system32\drivers\nsiproxy.sys
R1 - Null () -> (?)
R1 - Psched (@%SystemRoot%\System32\drivers\pacer.sys,-101) -> system32\DRIVERS\pacer.sys
R1 - rdbss (@%systemroot%\system32\wkssvc.dll,-1000) -> system32\DRIVERS\rdbss.sys
R1 - RDPCDD (@%systemroot%\system32\DRIVERS\RDPCDD.sys,-100) -> System32\DRIVERS\RDPCDD.sys
R1 - RDPENCDD (@%systemroot%\system32\drivers\RDPENCDD.sys,-101) -> system32\drivers\rdpencdd.sys
R1 - RDPREFMP (@%systemroot%\system32\drivers\RdpRefMp.sys,-101) -> system32\drivers\rdprefmp.sys
R1 - SASDIFSV (SASDIFSV) -> \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
R1 - SASKUTIL (SASKUTIL) -> \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
R1 - tdx (@%SystemRoot%\system32\tcpipcfg.dll,-50004) -> system32\DRIVERS\tdx.sys
R1 - TermDD (Terminal Device Driver) -> \SystemRoot\system32\drivers\termdd.sys
R1 - VgaSave () -> \SystemRoot\System32\drivers\vga.sys
R1 - vwififlt (Virtual WiFi Filter Driver) -> system32\DRIVERS\vwififlt.sys
R1 - Wanarpv6 (@%systemroot%\system32\rascfg.dll,-32012) -> system32\DRIVERS\wanarp.sys
R1 - WfpLwf (WFP Lightweight Filter) -> system32\DRIVERS\wfplwf.sys
R2 - AMD External Events Utility () -> %SystemRoot%\system32\atiesrxx.exe
S2 - AntiVirMailService (Avira Mail Protection) -> "C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe"
R2 - AntiVirSchedulerService (Avira Scheduler) -> "C:\Program Files (x86)\Avira\Antivirus\sched.exe"
R2 - AntiVirService (Avira Real-Time Protection) -> "C:\Program Files (x86)\Avira\Antivirus\avguard.exe"
S2 - AntiVirWebService (Avira Web Protection) -> "C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe"
R2 - Apple Mobile Device Service (Apple Mobile Device Service) -> "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
R2 - ATPLupd (ATPL Digital v6 update service) -> "C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\updatescripts\srvany.exe"
R2 - AudioEndpointBuilder (@%SystemRoot%\system32\audiosrv.dll,-204) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
R2 - AudioSrv (@%SystemRoot%\system32\audiosrv.dll,-200) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
R2 - avgntflt (avgntflt) -> system32\DRIVERS\avgntflt.sys
R2 - Avira.ServiceHost (Avira Service Host) -> "C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe"
R2 - AviraPhantomVPN (Avira Phantom VPN) -> "C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe"
R2 - avnetflt (avnetflt) -> system32\DRIVERS\avnetflt.sys
R2 - BFE (@%SystemRoot%\system32\bfe.dll,-1001) -> %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork
R2 - BGS (BGS) -> "C:\Program Files (x86)\ATP DIGITAL\ATP DIGITAL 6\server\bin\Apache.exe" -k runservice
R2 - BITS (@%SystemRoot%\system32\qmgr.dll,-1000) -> %SystemRoot%\System32\svchost.exe -k netsvcs
R2 - Bonjour Service (Bonjour Service) -> "C:\Program Files\Bonjour\mDNSResponder.exe"
R2 - BrYNSvc (BrYNSvc) -> "C:\Program Files (x86)\Browny02\BrYNSvc.exe"
R2 - bthserv (Bluetooth Support Service) -> %SystemRoot%\system32\svchost.exe -k bthsvcs
R2 - ClickToRunSvc (Microsoft Office ClickToRun Service) -> "C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
S2 - clr_optimization_v4.0.30319_32 (Microsoft .NET Framework NGEN v4.0.30319_X86) -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
S2 - clr_optimization_v4.0.30319_64 (Microsoft .NET Framework NGEN v4.0.30319_X64) -> C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
R2 - CryptSvc (@%SystemRoot%\system32\cryptsvc.dll,-1001) -> %SystemRoot%\system32\svchost.exe -k NetworkService
S2 - dbupdate (Dropbox Update Service (dbupdate)) -> "C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /svc
S2 - dbupdatem (Dropbox Update Service (dbupdatem)) -> "C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /medsvc
R2 - DbxSvc (DbxSvc) -> %SystemRoot%\system32\DbxSvc.exe
R2 - DcomLaunch (@oleres.dll,-5012) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch
R2 - Dhcp (@%SystemRoot%\system32\dhcpcore.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
R2 - DiagTrack (@%SystemRoot%\system32\UtcResources.dll,-3001) -> %SystemRoot%\System32\svchost.exe -k utcsvc
R2 - Dnscache (@%SystemRoot%\System32\dnsapi.dll,-101) -> %SystemRoot%\system32\svchost.exe -k NetworkService
R2 - DPS (@%systemroot%\system32\dps.dll,-500) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork
R2 - EFS (@%SystemRoot%\system32\efssvc.dll,-100) -> %SystemRoot%\System32\lsass.exe
R2 - eventlog (@%SystemRoot%\system32\wevtsvc.dll,-200) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
R2 - EventSystem (@comres.dll,-2450) -> %SystemRoot%\system32\svchost.exe -k LocalService
R2 - Everything (Everything) -> "C:\Program Files\Everything\Everything.exe" -svc
R2 - FLEXnet Licensing Service (FLEXnet Licensing Service) -> "C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"
R2 - FontCache (@%systemroot%\system32\FntCache.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalService
R2 - gpsvc (@gpapi.dll,-112) -> %windir%\system32\svchost.exe -k GPSvcGroup
R2 - IAStorDataMgrSvc (Intel(R) Rapid Storage Technology) -> "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
R2 - IDriverT (InstallDriver Table Manager) -> "C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
S2 - IEEtwCollectorService (@%SystemRoot%\system32\ieetwcollectorres.dll,-1000) -> %SystemRoot%\system32\IEEtwCollector.exe /V
R2 - IKEEXT (@%SystemRoot%\system32\ikeext.dll,-501) -> %systemroot%\system32\svchost.exe -k netsvcs
R2 - iphlpsvc (@%SystemRoot%\system32\iphlpsvc.dll,-500) -> %SystemRoot%\System32\svchost.exe -k NetSvcs
R2 - iPod Service (iPod Service) -> "C:\Program Files\iPod\bin\iPodService.exe"
R2 - IviRegMgr (IviRegMgr) -> "C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe"
R2 - LanmanServer (@%systemroot%\system32\srvsvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs
R2 - LanmanWorkstation (@%systemroot%\system32\wkssvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k NetworkService
R2 - lltdio (Link-Layer Topology Discovery Mapper I/O Driver) -> system32\DRIVERS\lltdio.sys
R2 - lmhosts (@%SystemRoot%\system32\lmhsvc.dll,-101) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
R2 - LMS (Intel(R) Management and Security Application Local Management Service) -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
R2 - luafv (@%systemroot%\system32\drivers\luafv.sys,-100) -> \SystemRoot\system32\drivers\luafv.sys
R2 - Maxtor Sync Service (Maxtor Service) -> "C:\Program Files (x86)\Maxtor\Sync\SyncServices.exe"
R2 - MBAMChameleon (MBAMChameleon) -> \SystemRoot\system32\drivers\MBAMChameleon.sys
R2 - MMCSS (@%systemroot%\system32\mmcss.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs
R2 - MpsSvc (@%SystemRoot%\system32\FirewallAPI.dll,-23090) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork
R2 - MSiSCSI (@%SystemRoot%\system32\iscsidsc.dll,-5000) -> %systemroot%\system32\svchost.exe -k netsvcs
S2 - NetMsmqActivator (@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195) -> "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator
S2 - NetPipeActivator (@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197) -> C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
S2 - NetTcpActivator (@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199) -> C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
R2 - NetTcpPortSharing (@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8201) -> C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
R2 - NlaSvc (@%SystemRoot%\System32\nlasvc.dll,-1) -> %SystemRoot%\System32\svchost.exe -k NetworkService
R2 - nsi (@%SystemRoot%\system32\nsisvc.dll,-200) -> %systemroot%\system32\svchost.exe -k LocalService
R2 - PcaSvc (@%SystemRoot%\system32\pcasvc.dll,-1) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
R2 - PEAUTH (PEAUTH) -> system32\drivers\peauth.sys
R2 - PerfHost (@%systemroot%\sysWow64\perfhost.exe,-2) -> %SystemRoot%\SysWow64\perfhost.exe
R2 - PlugPlay (@%SystemRoot%\system32\umpnpmgr.dll,-100) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch
R2 - PMBDeviceInfoProvider (PMBDeviceInfoProvider) -> "C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe"
R2 - Power (@%SystemRoot%\system32\umpo.dll,-100) -> %SystemRoot%\system32\svchost.exe -k DcomLaunch
R2 - ProfSvc (@%systemroot%\system32\profsvc.dll,-300) -> %systemroot%\system32\svchost.exe -k netsvcs
R2 - PSI_SVC_2 (Protexis Licensing V2) -> "C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
R2 - RapiMgr (@%windir%\WindowsMobile\rapimgr.dll,-104) -> %SystemRoot%\system32\svchost.exe -k WindowsMobile
R2 - regi (regi) -> \??\C:\Windows\system32\drivers\regi.sys
R2 - rimspci () -> \SystemRoot\system32\drivers\rimssne64.sys
R2 - risdsnpe () -> \SystemRoot\system32\drivers\risdsne64.sys
S2 - Roxio UPnP Renderer 10 (Roxio UPnP Renderer 10) -> "C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe"
S2 - Roxio Upnp Server 10 (Roxio Upnp Server 10) -> "C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe"
R2 - RpcEptMapper (@%windir%\system32\RpcEpMap.dll,-1001) -> %SystemRoot%\system32\svchost.exe -k RPCSS
R2 - RpcSs (@oleres.dll,-5010) -> %SystemRoot%\system32\svchost.exe -k rpcss
R2 - rspndr (Link-Layer Topology Discovery Responder) -> system32\DRIVERS\rspndr.sys
R2 - SampleCollector (VAIO Care Performance Service) -> "C:\Program Files\Sony\VAIO Care\VCPerfService.exe" "/service" "/sstates" "/sampleinterval=5000" "/procinterval=5" "/dllinterval=120" "/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1" "/counter=\Network Interface(*)\Bytes Total/sec:1" "/expandcounter=\Processor Information(*)\Processor Frequency:1" "/expandcounter=\Processor(*)\% Idle Time:1" "/expandcounter=\Processor(*)\% C1 Time:1" "/expandcounter=\Processor(*)\% C2 Time:1" "/expandcounter=\Processor(*)\% C3 Time:1" "/expandcounter=\Processor(*)\% Processor Time:1" "/directory=C:\ProgramData\Sony Corporation\VAIO Care\inteldata"
R2 - SamSs (@%SystemRoot%\system32\samsrv.dll,-1) -> %SystemRoot%\system32\lsass.exe
R2 - Schedule (@%SystemRoot%\system32\schedsvc.dll,-100) -> %systemroot%\system32\svchost.exe -k netsvcs
S2 - scupdate (Scout Update Service (scupdate)) -> "C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe" /svc
R2 - SENS (@%SystemRoot%\system32\Sens.dll,-200) -> %SystemRoot%\system32\svchost.exe -k netsvcs
R2 - ShellHWDetection (@%SystemRoot%\System32\shsvcs.dll,-12288) -> %SystemRoot%\System32\svchost.exe -k netsvcs
S2 - SkypeUpdate (Skype Updater) -> "C:\Program Files (x86)\Skype\Updater\Updater.exe"
R2 - SOHCImp (VAIO Media plus Content Importer) -> "C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe"
R2 - SOHDms (VAIO Media plus Digital Media Server) -> "C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe"
R2 - SOHDs (VAIO Media plus Device Searcher) -> "C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe"
R2 - speedfan (speedfan) -> \??\C:\Windows\SysWOW64\speedfan.sys
R2 - SpfService (VAIO Entertainment Common Service) -> "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe"
R2 - Spooler (@%systemroot%\system32\spoolsv.exe,-1) -> %SystemRoot%\System32\spoolsv.exe
S2 - sppsvc (Software Protection) -> %SystemRoot%\system32\sppsvc.exe
R2 - stisvc (@%SystemRoot%\system32\wiaservc.dll,-9) -> %SystemRoot%\system32\svchost.exe -k imgsvc
R2 - SysMain (@%SystemRoot%\system32\sysmain.dll,-1000) -> %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted
R2 - tcpipreg (TCP/IP Registry Compatibility) -> System32\drivers\tcpipreg.sys
R2 - Themes (@%SystemRoot%\System32\themeservice.dll,-8192) -> %SystemRoot%\System32\svchost.exe -k netsvcs
R2 - TrkWks (@%SystemRoot%\system32\trkwks.dll,-1) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
R2 - UNS (Intel(R) Management & Security Application User Notification Service) -> "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
R2 - UxSms (@%SystemRoot%\system32\dwm.exe,-2000) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
R2 - VAIO Entertainment TV Device Arbitration Service (VAIO Entertainment TV Device Arbitration Service) -> "C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe"
R2 - VAIO Event Service (VAIO Event Service) -> "C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe"
R2 - VCFw (VAIO Content Folder Watcher) -> "C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe"
R2 - VcmXmlIfHelper (VAIO Content Metadata XML Interface) -> "C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe"
R2 - VCService (VCService) -> "C:\Program Files\Sony\VAIO Care\VCService.exe"
R2 - VSNService (VSNService) -> "C:\Program Files\Sony\VAIO Smart Network\VSNService.exe"
R2 - VUAgent (VUAgent) -> "C:\Program Files\Sony\VAIO Update Common\VUAgent.exe"
R2 - WcesComm (@%windir%\WindowsMobile\wcescomm.dll,-40079) -> %SystemRoot%\system32\svchost.exe -k WindowsMobile
R2 - WDDriveService (WD Drive Manager) -> "C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe"
R2 - WinDefend (@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103) -> %SystemRoot%\System32\svchost.exe -k secsvcs
R2 - Winmgmt (@%Systemroot%\system32\wbem\wmisvc.dll,-205) -> %systemroot%\system32\svchost.exe -k netsvcs
R2 - Wlansvc (@%SystemRoot%\System32\wlansvc.dll,-257) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
R2 - wlidsvc (Windows Live ID Sign-in Assistant) -> "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
R2 - WsAppService (Wondershare Application Framework Service) -> C:\Program Files (x86)\Wondershare\WAF\2.3.0.5\WsAppService.exe
R2 - wscsvc (@%SystemRoot%\System32\wscsvc.dll,-200) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
R2 - WSearch (Windows Search) -> %systemroot%\system32\SearchIndexer.exe /Embedding
R2 - wuauserv (Windows Update) -> %systemroot%\system32\svchost.exe -k netsvcs
S3 - 1394ohci (1394 OHCI Compliant Host Controller) -> \SystemRoot\system32\drivers\1394ohci.sys
S3 - AcpiPmi (ACPI Power Meter Driver) -> \SystemRoot\system32\drivers\acpipmi.sys
S3 - adp94xx () -> \SystemRoot\system32\drivers\adp94xx.sys
S3 - adpahci () -> \SystemRoot\system32\drivers\adpahci.sys
S3 - adpu320 () -> \SystemRoot\system32\drivers\adpu320.sys
R3 - AeLookupSvc (@%SystemRoot%\system32\aelupsvc.dll,-1) -> %systemroot%\system32\svchost.exe -k netsvcs
S3 - agp440 (Intel AGP Bus Filter) -> \SystemRoot\system32\drivers\agp440.sys
S3 - ALG (@%SystemRoot%\system32\Alg.exe,-112) -> %SystemRoot%\System32\alg.exe
S3 - aliide () -> \SystemRoot\system32\drivers\aliide.sys
S3 - amdide () -> \SystemRoot\system32\drivers\amdide.sys
S3 - AmdK8 (AMD K8 Processor Driver) -> \SystemRoot\system32\drivers\amdk8.sys
R3 - amdkmdag () -> system32\DRIVERS\atikmdag.sys
R3 - amdkmdap () -> system32\DRIVERS\atikmpag.sys
S3 - AmdPPM (AMD Processor Driver) -> \SystemRoot\system32\drivers\amdppm.sys
S3 - amdsata () -> \SystemRoot\system32\drivers\amdsata.sys
S3 - amdsbs () -> \SystemRoot\system32\drivers\amdsbs.sys
R3 - ApfiltrService (Alps Pointing-device Filter Driver) -> system32\DRIVERS\Apfiltr.sys
S3 - AppID (@%systemroot%\system32\appidsvc.dll,-102) -> \SystemRoot\system32\drivers\appid.sys
S3 - AppIDSvc (@%systemroot%\system32\appidsvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
R3 - Appinfo (@%systemroot%\system32\appinfo.dll,-100) -> %SystemRoot%\system32\svchost.exe -k netsvcs
S3 - arc () -> \SystemRoot\system32\drivers\arc.sys
S3 - arcsas () -> \SystemRoot\system32\drivers\arcsas.sys
R3 - ArcSoftKsUFilter (ArcSoft Magic-I Visual Effect) -> system32\DRIVERS\ArcSoftKsUFilter.sys
S3 - aspnet_state (ASP.NET State Service) -> %SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
S3 - AsyncMac (@%systemroot%\system32\rascfg.dll,-32000) -> system32\DRIVERS\asyncmac.sys
R3 - athr (Atheros Extensible Wireless LAN device driver) -> system32\DRIVERS\athrx.sys
S3 - atikmdag () -> system32\DRIVERS\atikmdag.sys
S3 - AxInstSV (@%SystemRoot%\system32\AxInstSV.dll,-103) -> %SystemRoot%\system32\svchost.exe -k AxInstSVGroup
S3 - b06bdrv (Broadcom NetXtreme II VBD) -> \SystemRoot\system32\drivers\bxvbda.sys
S3 - b57nd60a (Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0) -> system32\DRIVERS\b57nd60a.sys
S3 - BDESVC (@%SystemRoot%\system32\bdesvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k netsvcs
R3 - bowser (@%systemroot%\system32\browser.dll,-102) -> system32\DRIVERS\bowser.sys
S3 - BrFiltLo (Brother USB Mass-Storage Lower Filter Driver) -> \SystemRoot\system32\drivers\BrFiltLo.sys
S3 - BrFiltUp (Brother USB Mass-Storage Upper Filter Driver) -> \SystemRoot\system32\drivers\BrFiltUp.sys
S3 - Browser (@%systemroot%\system32\browser.dll,-100) -> %SystemRoot%\System32\svchost.exe -k netsvcs
S3 - Brserid (Brother MFC Serial Port Interface Driver (WDM)) -> \SystemRoot\System32\Drivers\Brserid.sys
S3 - BrSerWdm (Brother WDM Serial driver) -> \SystemRoot\System32\Drivers\BrSerWdm.sys
S3 - BrUsbMdm (Brother MFC USB Fax Only Modem) -> \SystemRoot\System32\Drivers\BrUsbMdm.sys
S3 - BrUsbSer (Brother MFC USB Serial WDM Driver) -> \SystemRoot\System32\Drivers\BrUsbSer.sys
S3 - BthEnum (Bluetooth Enumerator Service) -> system32\DRIVERS\BthEnum.sys
S3 - BTHMODEM (Bluetooth Serial Communications Driver) -> system32\DRIVERS\bthmodem.sys
S3 - BthPan (Bluetooth Device (Personal Area Network)) -> system32\DRIVERS\bthpan.sys
S3 - BTHPORT (Bluetooth Port Driver) -> System32\Drivers\BTHport.sys
S3 - BTHUSB (Bluetooth Radio USB Driver) -> System32\Drivers\BTHUSB.sys
S3 - btusbflt (Bluetooth USB Filter) -> system32\drivers\btusbflt.sys
S3 - btwaudio (Bluetooth Audio Device Service) -> system32\drivers\btwaudio.sys
S3 - btwavdt (Bluetooth AVDT) -> system32\drivers\btwavdt.sys
S3 - btwl2cap (Bluetooth L2CAP Service) -> system32\DRIVERS\btwl2cap.sys
S3 - btwrchid () -> system32\DRIVERS\btwrchid.sys
S3 - catchme () -> \??\C:\Users\CATHER~1\AppData\Local\Temp\catchme.sys
S3 - CertPropSvc (@%SystemRoot%\System32\certprop.dll,-11) -> %SystemRoot%\system32\svchost.exe -k netsvcs
S3 - circlass (Consumer IR Devices) -> \SystemRoot\system32\drivers\circlass.sys
R3 - CmBatt (Microsoft ACPI Control Method Battery Driver) -> \SystemRoot\system32\drivers\CmBatt.sys
S3 - cmdide () -> \SystemRoot\system32\drivers\cmdide.sys
R3 - CompositeBus (Composite Bus Enumerator Driver) -> \SystemRoot\system32\drivers\CompositeBus.sys
S3 - COMSysApp (@comres.dll,-947) -> %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
S3 - defragsvc (@%SystemRoot%\system32\defragsvc.dll,-101) -> %SystemRoot%\system32\svchost.exe -k defragsvc
S3 - dot3svc (@%systemroot%\system32\dot3svc.dll,-1102) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
S3 - drmkaud (Microsoft Trusted Audio Drivers) -> \SystemRoot\system32\drivers\drmkaud.sys
R3 - DXGKrnl (LDDM Graphics Subsystem) -> \SystemRoot\System32\drivers\dxgkrnl.sys
R3 - EapHost (@%systemroot%\system32\eapsvc.dll,-1) -> %SystemRoot%\System32\svchost.exe -k netsvcs
S3 - ebdrv (Broadcom NetXtreme II 10 GigE VBD) -> \SystemRoot\system32\drivers\evbda.sys
S3 - elxstor () -> \SystemRoot\system32\drivers\elxstor.sys
S3 - ErrDev (Microsoft Hardware Error Device Driver) -> \SystemRoot\system32\drivers\errdev.sys
S3 - exfat (exFAT File System Driver) -> (?)
S3 - fastfat (FAT12/16/32 File System Driver) -> (?)
S3 - Fax (@%systemroot%\system32\fxsresm.dll,-118) -> %systemroot%\system32\fxssvc.exe
S3 - fdc (Floppy Disk Controller Driver) -> \SystemRoot\system32\drivers\fdc.sys
R3 - fdPHost (@%systemroot%\system32\fdPHost.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalService
R3 - FDResPub (@%systemroot%\system32\fdrespub.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
S3 - Filetrace (@%SystemRoot%\system32\drivers\filetrace.sys,-10001) -> system32\drivers\filetrace.sys
S3 - flpydisk (Floppy Disk Driver) -> \SystemRoot\system32\drivers\flpydisk.sys
S3 - FontCache3.0.0.0 (@%SystemRoot%\system32\PresentationHost.exe,-3309) -> %systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
S3 - FsDepends (@%SystemRoot%\system32\drivers\fsdepends.sys,-10001) -> System32\drivers\FsDepends.sys
S3 - gagp30kx (Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms) -> \SystemRoot\system32\drivers\gagp30kx.sys
R3 - GEARAspiWDM (GEAR ASPI Filter Driver) -> system32\DRIVERS\GEARAspiWDM.sys
S3 - hcw85cir (Hauppauge Consumer Infrared Receiver) -> \SystemRoot\system32\drivers\hcw85cir.sys
S3 - HdAudAddService (Microsoft 1.1 UAA Function Driver for High Definition Audio Service) -> \SystemRoot\system32\drivers\HdAudio.sys
R3 - HDAudBus (Microsoft UAA Bus Driver for High Definition Audio) -> \SystemRoot\system32\drivers\HDAudBus.sys
R3 - HECIx64 (Intel(R) Management Engine Interface) -> system32\DRIVERS\HECIx64.sys
S3 - HidBatt (HID UPS Battery Driver) -> \SystemRoot\system32\drivers\HidBatt.sys
S3 - HidBth (Microsoft Bluetooth HID Miniport) -> \SystemRoot\system32\drivers\hidbth.sys
S3 - HidIr (Microsoft Infrared HID Driver) -> \SystemRoot\system32\drivers\hidir.sys
R3 - hidserv (@%SystemRoot%\System32\hidserv.dll,-101) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
R3 - HidUsb (Microsoft HID Class Driver) -> system32\DRIVERS\hidusb.sys
S3 - hkmsvc (@%SystemRoot%\system32\kmsvc.dll,-6) -> %SystemRoot%\System32\svchost.exe -k netsvcs
R3 - HomeGroupListener (@%SystemRoot%\System32\ListSvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
R3 - HomeGroupProvider (@%SystemRoot%\System32\provsvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
S3 - HpSAMD () -> \SystemRoot\system32\drivers\HpSAMD.sys
R3 - HTTP (@%SystemRoot%\system32\drivers\http.sys,-1) -> system32\drivers\HTTP.sys
S3 - hwdatacard (Huawei DataCard USB Modem and USB Serial) -> system32\DRIVERS\ewusbmdm.sys
S3 - hwusbfake (Huawei DataCard USB Fake) -> system32\DRIVERS\ewusbfake.sys
R3 - i8042prt (i8042 Keyboard and PS/2 Mouse Port Driver) -> system32\DRIVERS\i8042prt.sys
S3 - iaStorV (Intel RAID Controller Windows 7) -> \SystemRoot\system32\drivers\iaStorV.sys
S3 - idsvc (@%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8193) -> "%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe"
S3 - igfx () -> system32\DRIVERS\igdkmd64.sys
S3 - iirsp () -> \SystemRoot\system32\drivers\iirsp.sys
R3 - Impcd () -> \SystemRoot\system32\drivers\Impcd.sys
R3 - IntcAzAudAddService (Service for Realtek HD Audio (WDM)) -> system32\drivers\RTKVHD64.sys
S3 - IntcDAud (Intel(R) Display Audio) -> system32\DRIVERS\IntcDAud.sys
S3 - intelide () -> \SystemRoot\system32\drivers\intelide.sys
R3 - intelppm (Intel Processor Driver) -> \SystemRoot\system32\drivers\intelppm.sys
S3 - IPBusEnum (@%systemroot%\system32\IPBusEnum.dll,-102) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
S3 - IpFilterDriver (@%systemroot%\system32\rascfg.dll,-32013) -> system32\DRIVERS\ipfltdrv.sys
S3 - IPMIDRV () -> \SystemRoot\system32\drivers\IPMIDrv.sys
S3 - IPNAT (IP Network Address Translator) -> System32\drivers\ipnat.sys
S3 - IRENUM (@%SystemRoot%\system32\drivers\irenum.sys,-100) -> system32\drivers\irenum.sys
S3 - isapnp () -> \SystemRoot\system32\drivers\isapnp.sys
R3 - iScsiPrt (iScsiPort Driver) -> system32\DRIVERS\msiscsi.sys
S3 - jrdusbser (Mobile Connector Device for Legacy Serial Communication) -> system32\DRIVERS\jrdusbser.sys
R3 - kbdclass (Keyboard Class Driver) -> system32\DRIVERS\kbdclass.sys
R3 - kbdhid (Keyboard HID Driver) -> system32\DRIVERS\kbdhid.sys
R3 - KeyIso (@keyiso.dll,-100) -> %SystemRoot%\system32\lsass.exe
R3 - ksthunk (Kernel Streaming Thunks) -> \SystemRoot\system32\drivers\ksthunk.sys
S3 - KtmRm (@comres.dll,-2946) -> %SystemRoot%\System32\svchost.exe -k NetworkServiceAndNoImpersonation
S3 - lltdsvc (@%SystemRoot%\system32\lltdres.dll,-1) -> %SystemRoot%\System32\svchost.exe -k LocalService
S3 - LSI_FC () -> \SystemRoot\system32\drivers\lsi_fc.sys
S3 - LSI_SAS () -> \SystemRoot\system32\drivers\lsi_sas.sys
S3 - LSI_SAS2 () -> \SystemRoot\system32\drivers\lsi_sas2.sys
S3 - LSI_SCSI () -> \SystemRoot\system32\drivers\lsi_scsi.sys
S3 - MBAMFarflt () -> \??\C:\Windows\system32\drivers\farflt.sys
S3 - MBAMProtection () -> \??\C:\Windows\system32\drivers\mbam.sys
S3 - MBAMService (Malwarebytes Service) -> "C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe"
S3 - MBAMSwissArmy (MBAMSwissArmy) -> \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
S3 - megasas () -> \SystemRoot\system32\drivers\megasas.sys
S3 - MegaSR () -> \SystemRoot\system32\drivers\MegaSR.sys
S3 - Modem () -> system32\drivers\modem.sys
R3 - monitor (Microsoft Monitor Class Function Driver Service) -> system32\DRIVERS\monitor.sys
R3 - mouclass (Mouse Class Driver) -> system32\DRIVERS\mouclass.sys
R3 - mouhid (Mouse HID Driver) -> system32\DRIVERS\mouhid.sys
S3 - mpio (Microsoft Multi-Path Bus Driver) -> \SystemRoot\system32\drivers\mpio.sys
R3 - mpsdrv (@%SystemRoot%\system32\FirewallAPI.dll,-23092) -> System32\drivers\mpsdrv.sys
S3 - MRxDAV (@%systemroot%\system32\webclnt.dll,-104) -> \SystemRoot\system32\drivers\mrxdav.sys
R3 - mrxsmb (@%systemroot%\system32\wkssvc.dll,-1002) -> system32\DRIVERS\mrxsmb.sys
R3 - mrxsmb10 (@%systemroot%\system32\wkssvc.dll,-1004) -> system32\DRIVERS\mrxsmb10.sys
R3 - mrxsmb20 (@%systemroot%\system32\wkssvc.dll,-1006) -> system32\DRIVERS\mrxsmb20.sys
S3 - msahci () -> \SystemRoot\system32\drivers\msahci.sys
S3 - msdsm (Microsoft Multi-Path Device Specific Module) -> \SystemRoot\system32\drivers\msdsm.sys
S3 - MSDTC (@comres.dll,-2797) -> %SystemRoot%\System32\msdtc.exe
S3 - mshidkmdf (@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100) -> \SystemRoot\System32\drivers\mshidkmdf.sys
R3 - msiserver (@%SystemRoot%\system32\msimsg.dll,-27) -> %systemroot%\system32\msiexec.exe /V
S3 - MSKSSRV (Microsoft Streaming Service Proxy) -> system32\drivers\MSKSSRV.sys
S3 - MSPCLOCK (Microsoft Streaming Clock Proxy) -> system32\drivers\MSPCLOCK.sys
S3 - MSPQM (Microsoft Streaming Quality Manager Proxy) -> system32\drivers\MSPQM.sys
S3 - MsRPC () -> (?)
S3 - MSTEE (Microsoft Streaming Tee/Sink-to-Sink Converter) -> system32\drivers\MSTEE.sys
S3 - MTConfig (Microsoft Input Configuration Driver) -> \SystemRoot\system32\drivers\MTConfig.sys
S3 - napagent (@%SystemRoot%\system32\qagentrt.dll,-6) -> %SystemRoot%\System32\svchost.exe -k NetworkService
R3 - NativeWifiP (NativeWiFi Filter) -> system32\DRIVERS\nwifi.sys
S3 - NdisCap (NDIS Capture LightWeight Filter) -> system32\DRIVERS\ndiscap.sys
R3 - NdisTapi (@%systemroot%\system32\rascfg.dll,-32001) -> system32\DRIVERS\ndistapi.sys
R3 - Ndisuio (NDIS Usermode I/O Protocol) -> system32\DRIVERS\ndisuio.sys
R3 - NdisWan (@%systemroot%\system32\rascfg.dll,-32002) -> system32\DRIVERS\ndiswan.sys
R3 - NDProxy (NDIS Proxy) -> (?)
S3 - Netaapl (Apple Mobile Device Ethernet Service) -> system32\DRIVERS\netaapl64.sys
S3 - Netlogon (@%SystemRoot%\System32\netlogon.dll,-102) -> %systemroot%\system32\lsass.exe
R3 - Netman (@%SystemRoot%\system32\netman.dll,-109) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
R3 - netprofm (@%SystemRoot%\system32\netprofm.dll,-202) -> %SystemRoot%\System32\svchost.exe -k LocalService
S3 - nfrd960 () -> \SystemRoot\system32\drivers\nfrd960.sys
R3 - Ntfs () -> (?)
S3 - nvraid () -> \SystemRoot\system32\drivers\nvraid.sys
S3 - nvstor () -> \SystemRoot\system32\drivers\nvstor.sys
S3 - nv_agp (NVIDIA nForce AGP Bus Filter) -> \SystemRoot\system32\drivers\nv_agp.sys
S3 - ohci1394 (1394 OHCI Compliant Host Controller (Legacy)) -> \SystemRoot\system32\drivers\ohci1394.sys
S3 - ose (Office Source Engine) -> "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
S3 - osppsvc (Office Software Protection Platform) -> "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
R3 - p2pimsvc (@%SystemRoot%\system32\pnrpsvc.dll,-8004) -> %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet
R3 - p2psvc (@%SystemRoot%\system32\p2psvc.dll,-8006) -> %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet
S3 - Parport (Parallel port driver) -> \SystemRoot\system32\drivers\parport.sys
S3 - pciide () -> \SystemRoot\system32\drivers\pciide.sys
S3 - pcmcia () -> \SystemRoot\system32\drivers\pcmcia.sys
S3 - pla (@%systemroot%\system32\pla.dll,-500) -> %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork
S3 - PNRPAutoReg (@%SystemRoot%\system32\pnrpauto.dll,-8002) -> %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet
R3 - PNRPsvc (@%SystemRoot%\system32\pnrpsvc.dll,-8000) -> %SystemRoot%\System32\svchost.exe -k LocalServicePeerNet
S3 - PolicyAgent (@%SystemRoot%\System32\polstore.dll,-5010) -> %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted
R3 - PptpMiniport (@%systemroot%\system32\rascfg.dll,-32006) -> system32\DRIVERS\raspptp.sys
S3 - Processor (Processor Driver) -> \SystemRoot\system32\drivers\processr.sys
S3 - ProtectedStorage (@%systemroot%\system32\psbase.dll,-300) -> %SystemRoot%\system32\lsass.exe
S3 - ql2300 () -> \SystemRoot\system32\drivers\ql2300.sys
S3 - ql40xx () -> \SystemRoot\system32\drivers\ql40xx.sys
S3 - QWAVE (@%SystemRoot%\system32\qwave.dll,-1) -> %windir%\system32\svchost.exe -k LocalServiceAndNoImpersonation
S3 - QWAVEdrv (@%SystemRoot%\system32\drivers\qwavedrv.sys,-1) -> \SystemRoot\system32\drivers\qwavedrv.sys
S3 - RasAcd (Remote Access Auto Connection Driver) -> System32\DRIVERS\rasacd.sys
R3 - RasAgileVpn (WAN Miniport (IKEv2)) -> system32\DRIVERS\AgileVpn.sys
S3 - RasAuto (@%Systemroot%\system32\rasauto.dll,-200) -> %SystemRoot%\System32\svchost.exe -k netsvcs
R3 - Rasl2tp (@%systemroot%\system32\rascfg.dll,-32005) -> system32\DRIVERS\rasl2tp.sys
S3 - RasMan (@%Systemroot%\system32\rasmans.dll,-200) -> %SystemRoot%\System32\svchost.exe -k netsvcs
R3 - RasPppoe (@%systemroot%\system32\rascfg.dll,-32007) -> system32\DRIVERS\raspppoe.sys
R3 - RasSstp (@%systemroot%\system32\sstpsvc.dll,-202) -> system32\DRIVERS\rassstp.sys
S3 - rdpbus (Remote Desktop Device Redirector Bus Driver) -> \SystemRoot\system32\drivers\rdpbus.sys
S3 - RdpVideoMiniport (Remote Desktop Video Miniport Driver) -> System32\drivers\rdpvideominiport.sys
S3 - RDPWD (RDP Winstation Driver) -> (?)
S3 - RemoteRegistry (@regsvc.dll,-1) -> %SystemRoot%\system32\svchost.exe -k regsvc
S3 - RFCOMM (Bluetooth Device (RFCOMM Protocol TDI)) -> system32\DRIVERS\rfcomm.sys
S3 - RpcLocator (@%systemroot%\system32\Locator.exe,-2) -> %SystemRoot%\system32\locator.exe
R3 - RTHDMIAzAudService (Service for HDMI) -> system32\drivers\RtHDMIVX.sys
S3 - sbp2port (SBP-2 Transport/Protocol Bus Driver) -> \SystemRoot\system32\drivers\sbp2port.sys
S3 - SCardSvr (@%SystemRoot%\System32\SCardSvr.dll,-1) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
S3 - scfilter (@%SystemRoot%\System32\drivers\scfilter.sys,-11) -> System32\DRIVERS\scfilter.sys
S3 - SCPolicySvc (@%SystemRoot%\System32\certprop.dll,-13) -> %SystemRoot%\system32\svchost.exe -k netsvcs
S3 - scupdatem (Scout Update Service (scupdatem)) -> "C:\Program Files (x86)\Avira\Scout Update\ScoutUpdate.exe" /medsvc
R3 - sdbus () -> \SystemRoot\system32\drivers\sdbus.sys
S3 - SDRSVC (@%SystemRoot%\system32\sdrsvc.dll,-107) -> %SystemRoot%\system32\svchost.exe -k SDRSVC
S3 - seclogon (@%SystemRoot%\system32\seclogon.dll,-7001) -> %windir%\system32\svchost.exe -k netsvcs
S3 - SensrSvc (@%SystemRoot%\System32\sensrsvc.dll,-1000) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
S3 - Serenum (Serenum Filter Driver) -> \SystemRoot\system32\drivers\serenum.sys
S3 - Serial () -> \SystemRoot\system32\drivers\serial.sys
S3 - sermouse (Serial Mouse Driver) -> \SystemRoot\system32\drivers\sermouse.sys
S3 - SessionEnv (@%SystemRoot%\System32\SessEnv.dll,-1026) -> %SystemRoot%\System32\svchost.exe -k netsvcs
R3 - SFEP (Sony Firmware Extension Parser) -> \SystemRoot\system32\drivers\SFEP.sys
S3 - sffdisk (SFF Storage Class Driver) -> \SystemRoot\system32\drivers\sffdisk.sys
S3 - sffp_mmc (SFF Storage Protocol Driver for MMC) -> \SystemRoot\system32\drivers\sffp_mmc.sys
S3 - sffp_sd (SFF Storage Protocol Driver for SDBus) -> \SystemRoot\system32\drivers\sffp_sd.sys
S3 - sfloppy (High-Capacity Floppy Disk Drive) -> \SystemRoot\system32\drivers\sfloppy.sys
S3 - SharedAccess (@%SystemRoot%\system32\ipnathlp.dll,-106) -> %SystemRoot%\System32\svchost.exe -k netsvcs
S3 - SiSRaid2 () -> \SystemRoot\system32\drivers\SiSRaid2.sys
S3 - SiSRaid4 () -> \SystemRoot\system32\drivers\sisraid4.sys
S3 - Smb (@%SystemRoot%\system32\tcpipcfg.dll,-50005) -> system32\DRIVERS\smb.sys
S3 - SNMPTRAP (@%SystemRoot%\system32\snmptrap.exe,-3) -> %SystemRoot%\System32\snmptrap.exe
S3 - sppuinotify (@%SystemRoot%\system32\sppuinotify.dll,-103) -> %SystemRoot%\system32\svchost.exe -k LocalService
R3 - srv (@%systemroot%\system32\srvsvc.dll,-102) -> System32\DRIVERS\srv.sys
R3 - srv2 (@%systemroot%\system32\srvsvc.dll,-104) -> System32\DRIVERS\srv2.sys
R3 - srvnet () -> System32\DRIVERS\srvnet.sys
R3 - SSDPSRV (@%systemroot%\system32\ssdpsrv.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
S3 - SstpSvc (@%SystemRoot%\system32\sstpsvc.dll,-200) -> %SystemRoot%\system32\svchost.exe -k LocalService
S3 - stexstor () -> \SystemRoot\system32\drivers\stexstor.sys
R3 - swenum (Software Bus Driver) -> \SystemRoot\system32\drivers\swenum.sys
R3 - swprv (@%SystemRoot%\System32\swprv.dll,-103) -> %SystemRoot%\System32\svchost.exe -k swprv
R3 - TabletInputService (@%SystemRoot%\system32\TabSvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
S3 - tap0901 (TAP-Windows Adapter V9) -> system32\DRIVERS\tap0901.sys
S3 - TapiSrv (@%SystemRoot%\system32\tapisrv.dll,-10100) -> %SystemRoot%\System32\svchost.exe -k NetworkService
S3 - TCPIP6 (Microsoft IPv6 Protocol Driver) -> system32\DRIVERS\tcpip.sys
S3 - TDPIPE (TDPIPE) -> system32\drivers\tdpipe.sys
S3 - TDTCP (TDTCP) -> system32\drivers\tdtcp.sys
R3 - TermService (@%SystemRoot%\System32\termsrv.dll,-268) -> %SystemRoot%\System32\svchost.exe -k NetworkService
S3 - THREADORDER (@%systemroot%\system32\mmcss.dll,-102) -> %SystemRoot%\system32\svchost.exe -k LocalService
S3 - TrueSight () -> \??\C:\Windows\System32\drivers\TrueSight.sys
S3 - TrustedInstaller (@%SystemRoot%\servicing\TrustedInstaller.exe,-100) -> %SystemRoot%\servicing\TrustedInstaller.exe
S3 - tssecsrv (@%SystemRoot%\System32\DRIVERS\tssecsrv.sys,-101) -> System32\DRIVERS\tssecsrv.sys
S3 - TsUsbFlt () -> system32\drivers\tsusbflt.sys
R3 - tunnel (Microsoft Tunnel Miniport Adapter Driver) -> system32\DRIVERS\tunnel.sys
S3 - uagp35 (Microsoft AGPv3.5 Filter) -> \SystemRoot\system32\drivers\uagp35.sys
S3 - UI0Detect (@%SystemRoot%\system32\ui0detect.exe,-101) -> %SystemRoot%\system32\UI0Detect.exe
S3 - uliagpkx (Uli AGP Bus Filter) -> \SystemRoot\system32\drivers\uliagpkx.sys
R3 - umbus (UMBus Enumerator Driver) -> system32\DRIVERS\umbus.sys
S3 - UmPass (Microsoft UMPass Driver) -> \SystemRoot\system32\drivers\umpass.sys
S3 - upnphost (@%systemroot%\system32\upnphost.dll,-213) -> %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
S3 - USBAAPL64 (Apple Mobile USB Driver) -> System32\Drivers\usbaapl64.sys
S3 - usbaudio (USB Audio Driver (WDM)) -> system32\drivers\usbaudio.sys
R3 - usbccgp (Microsoft USB Generic Parent Driver) -> system32\DRIVERS\usbccgp.sys
S3 - usbcir (eHome Infrared Receiver (USBCIR)) -> \SystemRoot\system32\drivers\usbcir.sys
R3 - usbehci (Microsoft USB 2.0 Enhanced Host Controller Miniport Driver) -> \SystemRoot\system32\drivers\usbehci.sys
R3 - usbhub (Microsoft USB Standard Hub Driver) -> \SystemRoot\system32\drivers\usbhub.sys
S3 - usbohci (Microsoft USB Open Host Controller Miniport Driver) -> \SystemRoot\system32\drivers\usbohci.sys
S3 - usbprint (Microsoft USB PRINTER Class) -> system32\DRIVERS\usbprint.sys
S3 - usbser (USB Modem Driver) -> system32\drivers\usbser.sys
S3 - USBSTOR (USB Mass Storage Driver) -> system32\DRIVERS\USBSTOR.SYS
S3 - usbuhci (Microsoft USB Universal Host Controller Miniport Driver) -> \SystemRoot\system32\drivers\usbuhci.sys
R3 - usbvideo (USB Video Device (WDM)) -> \SystemRoot\System32\Drivers\usbvideo.sys
S3 - VAIO Power Management (VAIO Power Management) -> "C:\Program Files\Sony\VAIO Power Management\SPMService.exe"
S3 - VaultSvc (@%SystemRoot%\system32\vaultsvc.dll,-1003) -> %SystemRoot%\system32\lsass.exe
R3 - VcmIAlzMgr (VAIO Content Metadata Intelligent Analyzing Manager) -> "C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe"
S3 - VcmINSMgr (VAIO Content Metadata Intelligent Network Service Manager) -> "C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe"
S3 - vds (@%SystemRoot%\system32\vds.exe,-100) -> %SystemRoot%\System32\vds.exe
S3 - vga () -> system32\DRIVERS\vgapnp.sys
S3 - vhdmp () -> \SystemRoot\system32\drivers\vhdmp.sys
S3 - viaide () -> \SystemRoot\system32\drivers\viaide.sys
S3 - vsmraid () -> \SystemRoot\system32\drivers\vsmraid.sys
R3 - VSS (@%systemroot%\system32\vssvc.exe,-102) -> %systemroot%\system32\vssvc.exe
R3 - vwifibus (Virtual WiFi Bus Driver) -> system32\DRIVERS\vwifibus.sys
R3 - vwifimp (Microsoft Virtual WiFi Miniport Service) -> system32\DRIVERS\vwifimp.sys
S3 - W32Time (@%SystemRoot%\system32\w32time.dll,-200) -> %SystemRoot%\system32\svchost.exe -k LocalService
S3 - WacomPen (Wacom Serial Pen HID Driver) -> \SystemRoot\system32\drivers\wacompen.sys
S3 - WANARP (@%systemroot%\system32\rascfg.dll,-32011) -> system32\DRIVERS\wanarp.sys
S3 - WatAdminSvc (@%SystemRoot%\system32\Wat\WatUX.exe,-601) -> %SystemRoot%\system32\Wat\WatAdminSvc.exe
S3 - wbengine (@%systemroot%\system32\wbengine.exe,-104) -> "%systemroot%\system32\wbengine.exe"
S3 - WbioSrvc (@%systemroot%\system32\wbiosrvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k WbioSvcGroup
S3 - wcncsvc (@%SystemRoot%\system32\wcncsvc.dll,-3) -> %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation
S3 - WcsPlugInService (@%SystemRoot%\system32\WcsPlugInService.dll,-200) -> %SystemRoot%\system32\svchost.exe -k wcssvc
S3 - Wd () -> \SystemRoot\system32\drivers\wd.sys
S3 - WD Backup Drive Helper (WD Backup Drive Helper) -> C:\Windows\SysWOW64\dllhost.exe /Processid:{4AB831D3-8315-414C-8A7A-303105288D0B}
S3 - WD Backup Snapshot (WD Backup Snapshot) -> C:\Windows\SysWOW64\dllhost.exe /Processid:{302480DF-3AC5-4400-BE7B-DD77AF93B6DD}
S3 - WDC_SAM (WD SCSI Pass Thru driver) -> system32\DRIVERS\wdcsam64_prewin8.sys
R3 - WdiServiceHost (@%systemroot%\system32\wdi.dll,-502) -> %SystemRoot%\System32\svchost.exe -k LocalService
R3 - WdiSystemHost (@%systemroot%\system32\wdi.dll,-500) -> %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
S3 - WebClient (@%systemroot%\system32\webclnt.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalService
S3 - Wecsvc (@%SystemRoot%\system32\wecsvc.dll,-200) -> %SystemRoot%\system32\svchost.exe -k NetworkService
S3 - wercplsupport (@%SystemRoot%\System32\wercplsupport.dll,-101) -> %SystemRoot%\System32\svchost.exe -k netsvcs
S3 - WerSvc (@%SystemRoot%\System32\wersvc.dll,-100) -> %SystemRoot%\System32\svchost.exe -k WerSvcGroup
S3 - WIMMount (WIMMount) -> system32\drivers\wimmount.sys
R3 - WinHttpAutoProxySvc (@%SystemRoot%\system32\winhttp.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalService
S3 - WinRM (@%Systemroot%\system32\wsmsvc.dll,-101) -> %SystemRoot%\System32\svchost.exe -k NetworkService
S3 - Winsock () -> (?)
S3 - WinUsb (WinUsb Driver) -> system32\DRIVERS\WinUsb.sys
S3 - WmiAcpi (Microsoft Windows Management Interface for ACPI) -> \SystemRoot\system32\drivers\wmiacpi.sys
S3 - wmiApSrv (@%Systemroot%\system32\wbem\wmiapsrv.exe,-110) -> %systemroot%\system32\wbem\WmiApSrv.exe
S3 - WPCSvc (@%SystemRoot%\system32\wpcsvc.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted
R3 - WPDBusEnum (@%SystemRoot%\system32\wpdbusenum.dll,-100) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
R3 - WudfPf (@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000) -> system32\drivers\WudfPf.sys
R3 - WUDFRd () -> system32\DRIVERS\WUDFRd.sys
R3 - wudfsvc (@%SystemRoot%\system32\wudfsvc.dll,-1000) -> %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted
S3 - WwanSvc (@%SystemRoot%\System32\wwansvc.dll,-257) -> %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork
R3 - yukonw7 (NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller) -> system32\DRIVERS\yk62x64.sys
S4 - cdfs (CD/DVD File System Reader) -> system32\DRIVERS\cdfs.sys
S4 - clr_optimization_v2.0.50727_32 (Microsoft .NET Framework NGEN v2.0.50727_X86) -> %systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
S4 - clr_optimization_v2.0.50727_64 (Microsoft .NET Framework NGEN v2.0.50727_X64) -> %systemroot%\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
S4 - crcdisk (Crcdisk Filter Driver) -> \SystemRoot\system32\drivers\crcdisk.sys
S4 - RemoteAccess (@%Systemroot%\system32\mprdim.dll,-200) -> %SystemRoot%\System32\svchost.exe -k netsvcs
S4 - secdrv (Security Driver) -> (?)
S4 - udfs (udfs) -> system32\DRIVERS\udfs.sys
S4 - ws2ifsl (Windows Socket 2.0 Non-IFS Service Provider Support Environment) -> \SystemRoot\system32\drivers\ws2ifsl.sys
 
I was trying various options to retrieve deleted content from my phone - I don't need any of it.

Search the Chinese character again, and then edit select all -- then right click selected items delete them.

As far as the BSOD --- IMAGE_NAME: rimssne64.sys Do you use it?
If not then search rimssne64.sys with everything search engine and rename it to rimssne64.bak

At least long enough to run RK .

Search for and delete the items below with everything search engine.


Code:
speedfan.sys
DiagTrack
GWX
catchme.sys


Run Check Disk


Run chkdsk /f /r from elevated command prompt.




After the checkdisk....

ListChkdskResult.png
Scan with ListChkDskResult

Please download ListChkDskResult by SleepyDude and save it to your desktop.
  • Right-click on
    ListChkdskResult.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • A message about checking Windows Event Log will pop-up. Click OK.
  • Wait patiently until a notepad window will open. This won't take long.
  • The displayed logfile will be also saved to your desktop as ListChkDskResult.txt.
Please include the content of this file in your next reply.

After the checkdisk we will look at installing some fresh drivers for your machine, here is your support site.


(Also, I'll be away for a day or so, but will follow any upcoming instructions as soon as I'm back.)


Thanks for letting me know. :thumbsup:




 
Okay I had some time tonight after all for the first few scans:
- Chinese characters: deleted the folder
- rimssne64.sys: I have two memory sticks that I sometimes use, not sure which one this relates to. There were 3 files found. I've renamed two of them, but the last one gives an error - see below. I tried renaming it in Windows Explorer but that still didn't work. I was able to run RK anyway, see below.
- speedfan.sys: deleted
- DiagTrack: lots of matches (see further below) - which ones do I delete? (Or was this deleted as part of the cleanup we've done already?)
- GWX: it's a folder - just checking that's correct before I delete it?
- catchme.sys: not found (maybe deleted as part of the cleanup we've done already?)

RogueKiller:
- It worked! so clearly it was one of the two files I renamed (not the one I couldn't rename) that was causing the issue. It found one threat. The report is below.

upload_2017-3-6_16-37-37.png


upload_2017-3-6_16-38-23.png



upload_2017-3-6_16-40-19.png


upload_2017-3-6_16-42-30.png

======================================================================================
RogueKiller V12.9.9.0 (x64) [Feb 27 2017] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : goldfish [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Delete -- Date : 03/06/2017 22:00:56 (Duration : 01:09:25)

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 0 ¤¤¤

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 1 ¤¤¤
[PUM.HomePage][Chrome:Config] Default [SecurePrefs] : session.startup_urls [https://login.yahoo.com/?.src=ym&.intl=us&.lang=en-US&.done=https://mail.yahoo.com|https://accounts.google.com/ServiceLogin?service=mail&continue=https://mail.google.com/mail/#identifier|https://www.facebook.com/] -> Deleted

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST9500325AS +++++
--- User ---
[MBR] 8c79ebb857ed6d866c134c6224d99d0d
[BSP] cb581fdaad25f96eadca901c7ef4b8fb : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 11942 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 24459264 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 24664064 | Size: 464896 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: Ricoh SD/MMC Disk Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! ([32] The request is not supported. )
Error reading LL2 MBR! ([32] The request is not supported. )
 

Attachments

  • upload_2017-3-6_16-36-42.png
    upload_2017-3-6_16-36-42.png
    12.6 KB · Views: 4
  • upload_2017-3-6_16-42-46.png
    upload_2017-3-6_16-42-46.png
    6.2 KB · Views: 9
Last edited:
- rimssne64.sys: I have two memory sticks that I sometimes use


If you go to use them and they do not function then rename the file .sys again.

- DiagTrack: lots of matches (see further below) - which ones do I delete? (Or was this deleted as part of the cleanup we've done already?)

All of them edit select all then hold shift and click delete
If something will not go then grab Unlocker to delete them, just be weary of the extra crap that comes with it.
Once installed do the same with everything search engine.
Search Diag track then edit select all right click selected items then choose Unlocker in the right click menu.


W0TQwL9.png


- GWX: it's a folder - just checking that's correct before I delete it?

Yes, it is the Get windows 10 crap that windows tries to force on people. We will move further when the check disk log is posted.

Security Check Scan.

  • Download Security Check to your desktop.
  • Right click it run as administrator.
  • When the program completes, the tool will automatically open a log file.
  • Please post that log here in your next post.
 
Status
Not open for further replies.