~ ZHPDiag v2017.10.14.182 By Nicolas Coolman (2017/10/14)
~ Run by Owner (Administrator) (2017/10/15 10:09:30)
~ Web:
https://www.nicolascoolman.com
~ Blog:
https://nicolascoolman.eu/
~ Facebook:
https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Legal
~ State version: Version OK
~ Mode: Scan
~ Report: C:\Users\Owner\Desktop\ZHPDiag.txt
~ Report: C:\Users\Owner\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ System startup: Normal (Normal boot)
Windows 10 Home, 64-bit (Build 15063) =>.Microsoft Corporation
---\\ Internet Browsers (3) - 0s
~ GCIE: Google Chrome v61.0.3163.100
~ MSIE: Microsoft Edge v40
~ MSIE: Internet Explorer v11.608.15063.0
---\\ Windows Product Information (3) - 4s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK
---\\ System protection software (2) - 1s
McAfee LiveSafe – Internet Security v14.0.1076 (Protection)
Windows Defender (Deactivate)
---\\ Surveillance software (1) - 2s
~ Adobe Reader X MUI (Surveillance)
---\\ Information on the system (6) - 0s
~ Operating System: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 6174.452 MB (61% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 218 GB (76%) free of 285 GB : OK =>.Disk Space
---\\ Connection to the system mode (3) - 0s
~ Computer Name: LADY
~ User Name: Owner
~ Logged in as Administrator
---\\ Enumeration of the disk units (2) - 0s
~ Drive C: has 218 GB free of 285 GB (System)
~ Drive D: has 407 GB free of 407 GB
---\\ State of the Windows Security Center (7) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
---\\ Search Generic System Files (24) - 2s
[MD5.3AF6D6F752EDE013ED15DFD2D44F8EF9] - 24/09/2017 - (.Microsoft Corporation - Windows Explorer.) -- C:\WINDOWS\Explorer.exe [4848960] =>.Microsoft Windows®
[MD5.ECB702B8C5650381C0784F1EEABB97BC] - 18/03/2017 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\WINDOWS\System32\rundll32.exe [68608] =>.Microsoft Corporation
[MD5.0242626678C83AE788C655C1990A3CC3] - 24/09/2017 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\WINDOWS\System32\Wininit.exe [318232] =>.Microsoft Windows Publisher®
[MD5.9AA7516745C98B81FC10227FF2652391] - 24/09/2017 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\WINDOWS\System32\wininet.dll [3307008] =>.Microsoft Corporation
[MD5.9CDA170849A4F66F4D68B3DBB3AC8394] - 24/09/2017 - (.Microsoft Corporation - Windows Logon Application.) -- C:\WINDOWS\System32\Winlogon.exe [706560] =>.Microsoft Corporation
[MD5.50CDF68A8EA8A2A9165CD573FA6C42D8] - 18/03/2017 - (.Microsoft Corporation - Software Licensing Library.) -- C:\WINDOWS\System32\sppcomapi.dll [414208] =>.Microsoft Corporation
[MD5.0F9FA6A2D4EAE50393DCE473759A9845] - 18/03/2017 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\WINDOWS\System32\dnsapi.dll [661224] =>.Microsoft Windows®
[MD5.3F969D5ADEAB3284ABD500B37D74A8F8] - 18/03/2017 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\WINDOWS\Syswow64\dnsapi.dll [508344] =>.Microsoft Windows®
[MD5.5A6D591D56791BA63CE73FCAD60D89A1] - 24/09/2017 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\WINDOWS\System32\drivers\AFD.sys [610720] =>.Microsoft Windows®
[MD5.01733BEEE02E51F712330D5909BD701C] - 18/03/2017 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [29088] =>.Microsoft Windows®
[MD5.B6E5AD7C83A5254DEE9D86023C0E5A81] - 18/03/2017 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [93184] =>.Microsoft Corporation
[MD5.ABE77AD954BC3D72F559CF0C381E50BC] - 18/03/2017 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [160256] =>.Microsoft Corporation
[MD5.185A4519B7764F4DEF714D890A7A9FD2] - 18/03/2017 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\DfsC.sys [150528] =>.Microsoft Corporation
[MD5.02B9639D9997E95CDF2F4C4F3BDCC73D] - 11/07/2017 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [86528] =>.Microsoft Corporation
[MD5.C6C8315E3262FAE460529C6DA2951682] - 18/03/2017 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [115200] =>.Microsoft Corporation
[MD5.DCC05E5EAA580C97F13B434FAFACED85] - 18/03/2017 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [214528] =>.Microsoft Corporation
[MD5.F2AD1B72C5A6475FB5FF332E1980DF88] - 18/03/2017 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [467352] =>.Microsoft Windows®
[MD5.BAD3C424788BC071C3EC82CFCDA954D2] - 24/09/2017 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [305152] =>.Microsoft Corporation
[MD5.075F8C81457804BB79DD33FE69A96C57] - 24/09/2017 - (.Microsoft Corporation - NT File System Driver.) -- C:\WINDOWS\System32\drivers\ntfs.sys [2327456] =>.Microsoft Windows®
[MD5.2CC6C325B271C7CA60F374F8F868CB45] - 18/03/2017 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\WINDOWS\System32\drivers\Parport.sys [97792] =>.Microsoft Corporation
[MD5.5279EC98F6218D29EADDFECCC0D80E9A] - 18/03/2017 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [107008] =>.Microsoft Corporation
[MD5.53A01D3FDB701AC5D9DDE4140227E3D9] - 18/03/2017 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [183296] =>.Microsoft Corporation
[MD5.D74756DD1518D28A09CDA99696273FA4] - 24/09/2017 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [119712] =>.Microsoft Windows®
[MD5.E3429DBBEA3965BB96E24B16EF4A2551] - 18/03/2017 - (.Microsoft Corporation - Volume Shadow Copy driver.) -- C:\WINDOWS\System32\drivers\volsnap.sys [397216] =>.Microsoft Windows®
---\\ Non Microsoft non disabled Windows Services (21) - 2s
O23 - Service: ASLDR Service (ASLDRService) . (.ASUSTek Computer Inc. - ASLDR Service.) - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe =>.ASUSTeK Computer Inc.®
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) . (.ASUS - ASUS InstantOn Program.) - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe =>.ASUSTeK Computer Inc.®
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) . (.ASUS - GFNEXSrv.) - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe =>.ASUSTeK Computer Inc.®
O23 - Service: McAfee Home Network (HomeNetSvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
O23 - Service: IconMan_R (IconMan_R) . (.Realsil Microelectronics Inc. - Realtek Card Reader Patch Tool..) - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe =>.Realtek Semiconductor Corp®
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation - igfxCUIService Module.) - C:\WINDOWS\System32\igfxCUIService.exe =>.Intel Corporation
O23 - Service: Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe =>.Intel® Upgrade Service®
O23 - Service: Intel(R) ME Service (Intel(R) ME Service) . (.Intel Corporation - Intel(R) ME Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe =>.Intel Corporation®
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe =>.Intel Corporation®
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation®
O23 - Service: McAfee AP Service (McAPExe) . (.McAfee, Inc. - McAfee Access Protection.) - C:\Program Files\McAfee\MSC\McAPExe.exe =>.McAfee, Inc.®
O23 - Service: McAfee CSP Service (mccspsvc) . (.McAfee, Inc. - McAfee CSP Service Host.) - C:\Program Files\Common Files\McAfee\CSP\1.5.495.0\McCSPServiceHost.exe =>.McAfee, Inc.®
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
O23 - Service: McAfee Platform Services (mcpltsvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
O23 - Service: McAfee Proxy Service (McProxy) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
O23 - Service: McAfee Service Controller (mfemms) . (.McAfee, Inc. - McAfee Management Service.) - C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe =>.McAfee, Inc.®
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) . (.McAfee, Inc. - McAfee Process Validation Service.) - C:\windows\system32\mfevtps.exe =>.McAfee, Inc.
O23 - Service: McAfee Anti-Spam Service (MSK80Service) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
O23 - Service: TeamViewer 10 (TeamViewer) . (.TeamViewer GmbH - TeamViewer 10.) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe =>.TeamViewer®
O23 - Service: Intel(R) Management and Security Application User Notificat (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe =>.Intel Corporation®
---\\ Services not Microsoft (SR=Run, SS=Stop) (36) - 26s
SS - Disabl [07/03/2017] [ 194632] Ask Update Service (APNMCP) . (.APN LLC..) - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe =>PUP.Optional.APNToolBar =>PUP.Optional.APNToolBar
SS - Disabl [07/09/2013] [ 55624] Apple Mobile Device (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe =>.Apple Inc.®
SR - Auto [05/10/2012] [ 110976] ASLDR Service (ASLDRService) . (.ASUSTek Computer Inc..) - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe =>.ASUSTeK Computer Inc.®
SR - Auto [13/04/2012] [ 277120] ASUS InstantOn Service (ASUS InstantOn) . (.ASUS.) - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe =>.ASUSTeK Computer Inc.®
SS - Disabl [19/12/2012] [ 72192] Asus WebStorage Windows Service (Asus WebStorage Windows Service) . (.Copyright © 2012.) - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe =>.ASUSTeK
SR - Auto [21/11/2011] [ 96896] ATKGFNEX Service (ATKGFNEXSrv) . (.ASUS.) - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe =>.ASUSTeK Computer Inc.®
SS - Disabl [31/08/2011] [ 462184] Bonjour Service (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.®
SS - Demand [03/05/2016] [ 299488] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe =>.Intel(R) pGFX®
SS - Demand [29/05/2015] [ 1432912] FlexNet Licensing Service 64 (FlexNet Licensing Service 64) . (.Flexera Software LLC..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe =>.Flexera Software LLC®
SS - Disabl [12/10/2010] [ 206072] GamesAppService (GamesAppService) . (.WildTangent, Inc..) - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe =>.WildTangent Inc®
SS - Disabl [28/12/2015] [ 144200] Google Update Service (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Disabl [28/12/2015] [ 144200] Google Update Service (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SR - Auto [06/05/2015] [ 340744] McAfee Home Network (HomeNetSvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
SS - Demand [24/04/2012] [ 169752] Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe =>.Intel Corporation®
SR - Auto [12/09/2012] [ 2466448] IconMan_R (IconMan_R) . (.Realsil Microelectronics Inc..) - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe =>.Realtek Semiconductor Corp®
SR - Auto [03/05/2016] [ 337888] Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation.) - C:\WINDOWS\System32\igfxCUIService.exe =>.Intel(R) pGFX®
SR - Auto [20/04/2012] [ 635104] Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe =>.Intel® Upgrade Service®
SR - Auto [27/06/2012] [ 129856] Intel(R) ME Service (Intel(R) ME Service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe =>.Intel Corporation®
SS - Disabl [02/11/2013] [ 641352] iPod Service (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe =>.Apple Inc.®
SR - Auto [25/06/2012] [ 166720] Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe =>.Intel Corporation®
SR - Auto [17/07/2012] [ 277824] Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation®
SR - Auto [13/05/2015] [ 754280] McAfee AP Service (McAPExe) . (.McAfee, Inc..) - C:\Program Files\McAfee\MSC\McAPExe.exe =>.McAfee, Inc.®
SS - Demand [21/12/2012] [ 334760] McAfee Activation Service (McAWFwk) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe =>.McAfee, Inc.®
SR - Auto [04/06/2015] [ 207344] McAfee CSP Service (mccspsvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\CSP\1.5.495.0\McCSPServiceHost.exe =>.McAfee, Inc.®
SR - Auto [06/05/2015] [ 340744] McAfee Personal Firewall Service (McMPFSvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
SR - Auto [06/05/2015] [ 340744] McAfee VirusScan Announcer (McNaiAnn) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
SS - Demand [05/05/2015] [ 609592] McAfee Scanner (McODS) . (.McAfee, Inc..) - C:\Program Files\mcafee\VirusScan\mcods.exe =>.McAfee, Inc.®
SS - Disabl [06/05/2015] [ 340744] McAfee OOBE Service2 (McOobeSv2) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
SR - Auto [06/05/2015] [ 340744] McAfee Platform Services (mcpltsvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
SR - Auto [06/05/2015] [ 340744] McAfee Proxy Service (McProxy) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
SR - Demand [29/06/2015] [ 232656] McAfee Firewall Core Service (mfefire) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe =>.McAfee, Inc.®
SR - Auto [06/07/2015] [ 373704] McAfee Service Controller (mfemms) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe =>.McAfee, Inc.®
SR - Auto [29/06/2015] [ 254792] McAfee Validation Trust Protection Service (mfevtp) . (.McAfee, Inc..) - C:\windows\system32\mfevtps.exe =>.McAfee, Inc.®
SR - Auto [06/05/2015] [ 340744] McAfee Anti-Spam Service (MSK80Service) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
SR - Auto [20/05/2015] [ 5491984] TeamViewer 10 (TeamViewer) . (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe =>.TeamViewer®
SR - Auto [17/07/2012] [ 365376] Intel(R) Management and Security Application User Notificat (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe =>.Intel Corporation®
---\\ Task Planned Automatically (Register) (94) - 26s
O38 - TASK: {05C35C43-30B0-478C-A045-7452BCE45E4E} [64Bits][\Microsoft\Windows\Defrag\ScheduledDefrag] - (.Microsoft Corp. - Disk Defragmenter Module.) -- C:\WINDOWS\system32\defrag.exe [185856] =>.Microsoft Corp.
O38 - TASK: {0C518199-F01B-42CF-9CB7-16710B002812} [64Bits][\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask] - (.Microsoft Corporation - MDMAgent.) -- C:\WINDOWS\system32\MDMAgent.exe [68096] =>.Microsoft Corporation
O38 - TASK: {0CC2C164-C391-4AE1-AC44-61014D23FC1F} [64Bits][\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization] - (.Microsoft Corp. - Disk Defragmenter Module.) -- C:\WINDOWS\system32\defrag.exe [185856] =>.Microsoft Corp.
O38 - TASK: {15EFA216-3731-4837-8673-1900B63B835C} [64Bits][\ASUS USB Charger Plus] - (.ASUSTek Computer Inc. - ASUS USB Charger Plus.) -- C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [1124032] =>.ASUSTeK Computer Inc.®
O38 - TASK: {186E3FCA-A925-48F1-88BF-0AD9D9289626} [64Bits][\Microsoft\Windows\Autochk\Proxy] - (.Microsoft Corporation - Autochk Proxy DLL.) -- C:\Windows\System32\acproxy.dll [13312] =>.Microsoft Corporation
O38 - TASK: {1F22D99D-93CA-4064-A299-22E8455A602E} [64Bits][\Microsoft\Windows\Windows Media Sharing\UpdateLibrary] - (.Microsoft Corporation - Windows Media Player Network Sharing Servic.) -- C:\Program Files\Windows Media Player\wmpnscfg.exe [70144] =>.Microsoft Corporation
O38 - TASK: {240478A4-B7D2-43B1-AF21-626C77E72C1F} [64Bits][\Microsoft\Windows\DiskFootprint\Diagnostics] - (.Microsoft Corporation - DiskSnapshot.exe.) -- C:\WINDOWS\system32\disksnapshot.exe [82944] =>.Microsoft Corporation
O38 - TASK: {2532DB2F-A598-4946-BA1F-6EBE9D19C34C} [64Bits][\Microsoft\Windows\Location\WindowsActionDialog] - (.Microsoft Corporation - Windows Action Dialog Broker.) -- C:\WINDOWS\System32\WindowsActionDialog.exe [59392] =>.Microsoft Corporation
O38 - TASK: {28D3F09B-BB5A-4D20-9576-2DF545A0DCA8} [64Bits][\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval] - (.Microsoft Corporation - MusNotificationBroker.) -- C:\WINDOWS\System32\MusNotification.exe [293376] =>.Microsoft Corporation
O38 - TASK: {2FE5C5AA-AEA6-44E8-8EE0-97507F9A20E1} [64Bits][\G2MUploadTask-S-1-5-21-1241052491-2989075707-2494370071-1001] - (.Citrix Online, a division of Citrix Systems, Inc. - GoToMeeting.) -- C:\Users\Owner\AppData\Local\Citrix\GoToMeeting\5573\g2mupload.exe [41536] =>.Citrix Online®
O38 - TASK: {33C04DDB-DE68-4033-8570-ADDDBFF99E1B} [64Bits][\Microsoft\Windows\NlaSvc\WiFiTask] - (.Microsoft Corporation - Wireless Background Task.) -- C:\WINDOWS\System32\WiFiTask.exe [459168] =>.Microsoft Windows®
O38 - TASK: {3619A588-C82A-437E-AAB3-F0AE62D9596A} [64Bits][\Microsoft\Windows\UPnP\UPnPHostConfig] - (.Microsoft Corporation - Service Control Manager Configuration Tool.) -- C:\Windows\System32\sc.exe [68608] =>.Microsoft Corporation
O38 - TASK: {3AEEF4D4-C4A8-42A1-8A1E-80CA054C2E9C} [64Bits][\Microsoft\Windows\SystemRestore\SR] - (.Microsoft Corporation - Microsoft® Windows System Protection backgr.) -- C:\WINDOWS\system32\srtasks.exe [57856] =>.Microsoft Corporation
O38 - TASK: {3BEF8B7D-CC52-4BB4-8185-F7CA05412D63} [64Bits][\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector] - (.Microsoft Corporation - Windows Disk Failure Diagnostic Module.) -- C:\Windows\System32\dfdts.dll [45568] =>.Microsoft Corporation
O38 - TASK: {3E757B5E-55B1-4F43-820F-3CA89C3FB296} [64Bits][\Microsoft\Windows\WindowsUpdate\Scheduled Start] - (.Microsoft Corporation. - This task is used to start the Windows Upda.) -- wuauserv [0] =>.Microsoft Corporation.
O38 - TASK: {3EA82649-A360-4898-A6FB-C273024D1364} [64Bits][\Microsoft\Windows\Shell\FamilySafetyMonitor] - (.Microsoft Corporation - Family Safety Monitor.) -- C:\WINDOWS\System32\wpcmon.exe [1763376] =>.Microsoft Windows®
O38 - TASK: {3F451604-93EA-4AA6-A7AD-5F7EFE9D0BDA} [64Bits][\ASUS Splendid ACMON] - (.ASUS - ACMON.) -- C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [54488] =>.ASUSTeK Computer Inc.®
O38 - TASK: {4051EB0B-2917-432F-B9F9-431C7E3C9181} [64Bits][\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask] - (.Microsoft Corporation - Windows Remote Assistance COM Server.) -- C:\Windows\System32\raserver.exe [128512] =>.Microsoft Corporation
O38 - TASK: {43505C32-2EE7-4325-95D4-A8CC0544DEF9} [64Bits][\User_Feed_Synchronization-{C12BC12E-5262-4B9E-B66C-421CE6825189}] - (.Microsoft Corporation - Microsoft Feeds Synchronization.) -- C:\Windows\System32\msfeedssync.exe [15360] =>.Microsoft Corporation
O38 - TASK: {4A5D4628-E32A-4422-9B01-D37DD4C1CE75} [64Bits][\Microsoft\Windows\WwanSvc\NotificationTask] - (.Microsoft Corporation - Wireless Background Task.) -- C:\WINDOWS\System32\WiFiTask.exe [459168] =>.Microsoft Windows®
O38 - TASK: {4B6926D3-D490-4D93-82CE-D109F1D1BC80} [64Bits][\Microsoft\Windows\WindowsUpdate\sih] - (.Microsoft Corporation - SIH Client.) -- C:\WINDOWS\System32\sihclient.exe [229888] =>.Microsoft Corporation
O38 - TASK: {4C3288FD-E718-4485-AEAE-8DE7CEA84C52} [64Bits][\Microsoft\Office\Office Subscription Maintenance] - (.Microsoft Corporation - Office Subscription Licensing Heartbeat.) -- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [1163552] =>.Microsoft Corporation®
O38 - TASK: {5010C4B7-1314-4A40-8FDA-19E7BB61FBA8} [64Bits][\Microsoft\Windows\Sysmain\WsSwapAssessmentTask] - (.Microsoft Corporation - Superfetch Service Host.) -- C:\Windows\System32\sysmain.dll [972800] =>.Microsoft Corporation
O38 - TASK: {52C4776E-11B1-402C-A230-0A0306A146C4} [64Bits][\Microsoft\Windows\Customer Experience Improvement Program\Consolidator] - (.Microsoft Corporation - Windows SQM Consolidator.) -- C:\WINDOWS\System32\wsqmcons.exe [77824] =>.Microsoft Corporation
O38 - TASK: {53F0FF65-7596-45C8-ACB1-469873ACF549} [64Bits][\G2MUpdateTask-S-1-5-21-1241052491-2989075707-2494370071-1001] - (.Citrix Online, a division of Citrix Systems, Inc. - GoToMeeting.) -- C:\Users\Owner\AppData\Local\Citrix\GoToMeeting\5573\g2mupdate.exe [41536] =>.Citrix Online®
O38 - TASK: {597C1C01-CCB6-4917-942F-E1C96EEE91BC} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Policy Install] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [34304] =>.Microsoft Corporation
O38 - TASK: {5BC5A21F-4785-41A6-B4B1-62FB9B08FABD} [64Bits][\Microsoft\Windows\Workplace Join\Automatic-Device-Join] - (.Microsoft Corporation - DSREG commandline tool.) -- C:\WINDOWS\System32\dsregcmd.exe [659968] =>.Microsoft Corporation
O38 - TASK: {5C326114-085E-444C-9B7A-D3E2E59C549E} [64Bits][\Microsoft\Windows\Device Information\Device] - (.Microsoft Corporation - Device Census.) -- C:\WINDOWS\system32\devicecensus.exe [34720] =>.Microsoft Windows®
O38 - TASK: {5D81326C-D6EC-49A0-AAB5-D8A874E06E83} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Reboot] - (.Microsoft Corporation - MusNotificationBroker.) -- C:\WINDOWS\System32\MusNotification.exe [293376] =>.Microsoft Corporation
O38 - TASK: {5EEE9DE4-B1C4-49A0-B7A2-17931A764B94} [64Bits][\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display] - (.Microsoft Corporation - MusNotificationBroker.) -- C:\windows\system32\MusNotification.exe [293376] =>.Microsoft Corporation
O38 - TASK: {61BD468E-F5F2-4D36-8B7A-8521069DF8E9} [64Bits][\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup] - (.Microsoft Corporation - AppX Deployment Client DLL.) -- C:\Windows\System32\AppxDeploymentClient.dll [654976] =>.Microsoft Windows®
O38 - TASK: {6772AC65-7600-4DF2-9BD5-F17292FAAE4B} [64Bits][\Microsoft\Windows\Speech\SpeechModelDownloadTask] - (.Microsoft Corporation - Speech Model Download Executable.) -- C:\Windows\System32\speech_onecore\Common\SpeechModelDownload.exe [162816] =>.Microsoft Corporation
O38 - TASK: {68D8DFDD-4439-42AA-B976-4DEFAAAE637D} [64Bits][\OneDrive Standalone Update Task] - (.Microsoft Corporation - .) -- C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {6B77FE8F-9ABB-49E1-9ED4-23EF2D783AAC} [64Bits][\Microsoft\Windows\MUI\Mcbuilder] - (.Microsoft Corporation - Resource cache builder tool.) -- C:\Windows\System32\mcbuilder.exe [347648] =>.Microsoft Corporation
O38 - TASK: {70B68569-0DB9-4459-869B-6D44CB422E27} [64Bits][\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network] - (.Microsoft Corporation. - This task is used to start the Windows Upda.) -- wuauserv [0] =>.Microsoft Corporation.
O38 - TASK: {70E0A093-79B7-461E-A9C7-B67CD7B1511E} [64Bits][\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload] - (.Microsoft Corporation - Microsoft Feedback SIUF Deployment Manager.) -- C:\WINDOWS\system32\dmclient.exe [89600] =>.Microsoft Corporation
O38 - TASK: {7508389C-FF71-4BE4-AD8A-5F56FB645036} [64Bits][\Microsoft\Windows\ApplicationData\CleanupTemporaryState] - (.Microsoft Corporation - Windows Application Data API Server.) -- C:\Windows\System32\Windows.Storage.ApplicationData.dll [328616] =>.Microsoft Windows®
O38 - TASK: {78F76D6D-0B70-46A9-8DEB-4FCB650A6627} [64Bits][\Microsoft\Windows\SharedPC\Account Cleanup] - (.Microsoft Corporation - SharedPC.AccountManager.) -- C:\WINDOWS\System32\Windows.SharedPC.AccountManager.dll [192512] =>.Microsoft Corporation
O38 - TASK: {799AC654-A37D-49AA-B0F3-433D7D5EBBD9} [64Bits][\Microsoft\Windows\WCM\WiFiTask] - (.Microsoft Corporation - Wireless Background Task.) -- C:\WINDOWS\System32\WiFiTask.exe [459168] =>.Microsoft Windows®
O38 - TASK: {79C5CC18-9BA2-4BAE-8B38-7AF9D3EE968C} [64Bits][\Microsoft\XblGameSave\XblGameSaveTaskLogon] - (.Microsoft Corporation - XblGameSave Standby Task.) -- C:\WINDOWS\System32\XblGameSaveTask.exe [31744] =>.Microsoft Corporation
O38 - TASK: {81710EDD-8B00-4260-A8FD-5B04E5B729CA} [64Bits][\Microsoft\Office\OfficeTelemetryAgentLogOn] - (.Microsoft Corporation - Office Telemetry Agent.) -- C:\Program Files\Microsoft Office 15\root\office15\msoia.exe [289496] =>.Microsoft Corporation®
O38 - TASK: {829C695F-E874-432A-9A9F-7862D04236B9} [64Bits][\Microsoft\Windows\ApplicationData\DsSvcCleanup] - (.Microsoft Corporation - Data Sharing Service Maintenance Driver.) -- C:\WINDOWS\system32\dstokenclean.exe [12800] =>.Microsoft Corporation
O38 - TASK: {87488988-70F6-44C5-A1BD-E328BE17C205} [64Bits][\Microsoft\Windows\AppID\PolicyConverter] - (.Microsoft Corporation - AppID Policy Converter Task.) -- C:\WINDOWS\system32\appidpolicyconverter.exe [159744] =>.Microsoft Corporation
O38 - TASK: {88209412-5377-4AA1-B01E-F5D5A6F39E21} [64Bits][\Microsoft\Windows\SpacePort\SpaceAgentTask] - (.Microsoft Corporation - Storage Spaces Settings.) -- C:\WINDOWS\system32\SpaceAgent.exe [129536] =>.Microsoft Corporation
O38 - TASK: {88E18EB0-E633-47C9-8FE5-84CEAB8F5EF7} [64Bits][\microsoft\windows\applicationdata\appuriverifierdaily] - (.Microsoft Corporation - App Uri Handlers Registration Verifier.) -- C:\WINDOWS\system32\AppHostRegistrationVerifier.exe [105472] =>.Microsoft Corporation
O38 - TASK: {896ED842-4861-49E9-A2C1-0AE31689F876} [64Bits][\Microsoft\Windows\Clip\License Validation] - (.Microsoft Corporation - Client License Platform migration tool.) -- C:\WINDOWS\System32\ClipUp.exe [1347640] =>.Microsoft Windows Publisher®
O38 - TASK: {8C5D1608-0748-4414-AF40-A403264AAF6B} [64Bits][\Microsoft\Windows\Subscription\EnableLicenseAcquisition] - (.Microsoft Corporation - Acquire License From Store.) -- C:\WINDOWS\System32\ClipRenew.exe [137112] =>.Microsoft Windows®
O38 - TASK: {8D5B2911-B38B-4561-8EAA-AFBC641F0206} [64Bits][\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver] - (.Microsoft Corporation - Windows Disk Diagnostic User Resolver.) -- C:\WINDOWS\system32\DFDWiz.exe [51200] =>.Microsoft Corporation
O38 - TASK: {8EE52AD7-9F81-40D3-AE0C-9F5DB09BC56F} [64Bits][\Microsoft\Windows\DiskCleanup\SilentCleanup] - (.Microsoft Corporation - Disk Space Cleanup Manager for Windows.) -- C:\WINDOWS\system32\cleanmgr.exe [217088] =>.Microsoft Corporation
O38 - TASK: {8F1E601B-9AA0-4F88-B4B0-17D1B287EDF7} [64Bits][\Microsoft\Windows\MUI\Lpksetup] - (.Microsoft Corporation - Language Pack Installer.) -- C:\WINDOWS\System32\lpksetup.exe [743424] =>.Microsoft Corporation
O38 - TASK: {8F478E0D-04D7-4C8B-BBFC-401134210E53} [64Bits][\HPCustParticipation HP DeskJet 3630 series] - (.HP Inc. - HP Product Improvement Study.) -- C:\Program Files\HP\HP DeskJet 3630 series\Bin\HPCustPartic.exe [6438544] =>.Hewlett Packard®
O38 - TASK: {907C764F-9FE0-4E46-9F7B-92EC1FE1DFEC} [64Bits][\ASUS InstantOn Config] - (.ASUS - ASUS InstantOn.) -- C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe [1196416] =>.ASUSTeK Computer Inc.®
O38 - TASK: {9340B747-1A69-4B61-895C-97326AD9FA69} [64Bits][\Microsoft\Office\OfficeTelemetryAgentFallBack] - (.Microsoft Corporation - Office Telemetry Agent.) -- C:\Program Files\Microsoft Office 15\root\office15\msoia.exe [289496] =>.Microsoft Corporation®
O38 - TASK: {936FF605-A684-4476-8E62-E051A903B3D3} [64Bits][\Microsoft\Windows\Time Zone\SynchronizeTimeZone] - (.Microsoft Corporation - TimeZone Sync Task.) -- C:\WINDOWS\system32\tzsync.exe [60928] =>.Microsoft Corporation
O38 - TASK: {938954E2-DAFB-4BCD-8740-6AC11EBFE13C} [64Bits][\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck] - (.Microsoft Corporation - AppID Certificate Store Verification Task.) -- C:\WINDOWS\system32\appidcertstorecheck.exe [19456] =>.Microsoft Corporation
O38 - TASK: {95F7441D-F4DE-4103-8791-34DEA0DB80C0} [64Bits][\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange] - (.Microsoft Corporation - Base Filtering Engine.) -- C:\Windows\System32\bfe.dll [815616] =>.Microsoft Corporation
O38 - TASK: {9A6E511E-0793-480B-9C71-BE6506CF4C66} [64Bits][\Microsoft\Office\Office Automatic Updates] - (.Microsoft Corporation - Microsoft Office Click-to-Run Client.) -- C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [979208] =>.Microsoft Corporation®
O38 - TASK: {9CF304F4-4D08-4DBB-A568-102240A2160B} [64Bits][\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser] - (.Microsoft Corporation - Mobile Broadband Account Experience Parser.) -- C:\WINDOWS\System32\MbaeParserTask.exe [112640] =>.Microsoft Corporation
O38 - TASK: {A10D15E4-477A-446A-A68B-7DB9680F2CA2} [64Bits][\ASUS Splendid ColorU] - (.ASUSTeK Computer Inc. - ASUS Color Engine.) -- C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe [176240] =>.ASUSTeK Computer Inc.®
O38 - TASK: {A77767EA-5260-432E-9139-6F99E5030D77} [64Bits][\Microsoft\Office\Office ClickToRun Service Monitor] - (.Microsoft Corporation - Microsoft Office Click-to-Run Client.) -- C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [979208] =>.Microsoft Corporation®
O38 - TASK: {A8048B05-A259-4ECE-B90D-2C3AD0193661} [64Bits][\McAfeeLogon] - (.McAfee, Inc. - McAfee.) -- C:\Program Files\Common Files\mcafee\platform\McUICnt.exe [719784] =>.McAfee, Inc.®
O38 - TASK: {B0B01AAA-FF6C-4441-B75E-44A24B0B37CD} [64Bits][\Microsoft\Windows\DUSM\dusmtask] - (.Microsoft Corporation - DUSM Task.) -- C:\WINDOWS\System32\dusmtask.exe [35840] =>.Microsoft Corporation
O38 - TASK: {B5EA650A-8EE9-4BA5-BAA0-2A8ACE00500D} [64Bits][\Microsoft\Windows\SpacePort\SpaceManagerTask] - (.Microsoft Corporation - Storage Spaces Manager.) -- C:\WINDOWS\system32\spaceman.exe [34816] =>.Microsoft Corporation
O38 - TASK: {B757F292-9A9D-47A9-B393-3552AA6BFAAE} [64Bits][\Microsoft\Windows\UNP\RunCampaignManager] - (.Microsoft Corporation - UNP CampaignManager.) -- C:\WINDOWS\System32\UNP\UNPCampaignManager.exe [1039712] =>.Microsoft Windows®
O38 - TASK: {BCC432F2-7A57-4195-881F-9013CF46F613} [64Bits][\Microsoft\Windows\MUI\LPRemove] - (.Microsoft Corporation - MUI Language pack cleanup.) -- C:\WINDOWS\system32\lpremove.exe [66560] =>.Microsoft Corporation
O38 - TASK: {BD69C6ED-AD55-467C-B787-533200C3B376} [64Bits][\Microsoft\XblGameSave\XblGameSaveTask] - (.Microsoft Corporation - XblGameSave Standby Task.) -- C:\WINDOWS\System32\XblGameSaveTask.exe [31744] =>.Microsoft Corporation
O38 - TASK: {BEAF8A6C-47E0-4E84-840B-3A61426B5AAD} [64Bits][\Microsoft\Windows\Application Experience\StartupAppTask] - (.Microsoft Corporation - Startup scan task DLL.) -- C:\Windows\System32\Startupscan.dll [19968] =>.Microsoft Corporation
O38 - TASK: {BF063809-A257-4320-A05E-61F967FD99F6} [64Bits][\GoogleUpdateTaskMachineUA] - (.Google Inc. - Google Installer.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc®
O38 - TASK: {C05E2FFD-7D0D-4F6B-952B-A3318F829D19} [64Bits][\Microsoft\Windows\Management\Provisioning\Cellular] - (.Microsoft Corporation - Provisioning package runtime processing too.) -- C:\WINDOWS\system32\ProvTool.exe [68608] =>.Microsoft Corporation
O38 - TASK: {C0B2A3C7-43E2-4C76-9ADB-E74B08AC7E7F} [64Bits][\Microsoft\Windows\Subscription\LicenseAcquisition] - (.Microsoft Corporation - Acquire License From Store.) -- C:\WINDOWS\System32\ClipRenew.exe [137112] =>.Microsoft Windows®
O38 - TASK: {C162FF56-952F-4ABA-AE13-AA8CB0F4C087} [64Bits][\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers] - (.Microsoft Corporation - Driver Installation Module.) -- C:\WINDOWS\System32\drvinst.exe [158720] =>.Microsoft Corporation
O38 - TASK: {C3E614E0-6925-4296-BE8C-3A65E1B687B9} [64Bits][\Apple\AppleSoftwareUpdate] - (.Apple Inc. - Apple Software Update.) -- C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [561984] =>.Apple Inc.®
O38 - TASK: {C42799B6-75B2-42CF-8197-3BE332E05553} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Schedule Scan] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [34304] =>.Microsoft Corporation
O38 - TASK: {C97B639A-C1BF-4E0C-ACFD-CF5B27B65B3C} [64Bits][\Microsoft\Windows\Windows Error Reporting\QueueReporting] - (.Microsoft Corporation - Windows Problem Reporting.) -- C:\WINDOWS\system32\wermgr.exe [182688] =>.Microsoft Windows®
O38 - TASK: {CDC553D2-B5AD-4AF3-BB6D-5AA47466C1F9} [64Bits][\Microsoft\Windows\Management\Provisioning\Logon] - (.Microsoft Corporation - Provisioning package runtime processing too.) -- C:\WINDOWS\system32\ProvTool.exe [68608] =>.Microsoft Corporation
O38 - TASK: {CFE9501D-B60F-45DB-B48F-19C572F7F30E} [64Bits][\microsoft\windows\applicationdata\appuriverifierinstall] - (.Microsoft Corporation - App Uri Handlers Registration Verifier.) -- C:\WINDOWS\system32\AppHostRegistrationVerifier.exe [105472] =>.Microsoft Corporation
O38 - TASK: {D2C50CE0-7E9B-4F0D-A2A4-95AC59829444} [64Bits][\Microsoft\Windows\Bluetooth\UninstallDeviceTask] - (.Microsoft Corporation - Bluetooth Uninstall Device Task.) -- C:\Windows\System32\BthUdTask.exe [40448] =>.Microsoft Corporation
O38 - TASK: {D4AEEABF-2FD8-45BF-8128-76AEF0ADD074} [64Bits][\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot] - (.Microsoft Corporation - MusNotificationBroker.) -- C:\windows\system32\MusNotification.exe [293376] =>.Microsoft Corporation
O38 - TASK: {D5EBF28C-A33D-4CBA-8355-0F457EE12498} [64Bits][\Microsoft\Windows\Application Experience\ProgramDataUpdater] - (.Microsoft Corporation - Microsoft Compatibility Telemetry.) -- C:\WINDOWS\system32\compattelrunner.exe [96672] =>.Microsoft Windows®
O38 - TASK: {D6202415-B38A-4BCC-A4D1-39B70755FFE6} [64Bits][\OneDrive Standalone Update Task-S-1-5-21-1241052491-2989075707-2494370071-1001] - (.Microsoft Corporation - Standalone Updater.) -- C:\Users\Owner\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe [2797776] =>.Microsoft Corporation®
O38 - TASK: {DC25F9B2-B5E4-4FD3-81F9-E09AF39A0731} [64Bits][\GoogleUpdateTaskMachineCore] - (.Google Inc. - Google Installer.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc®
O38 - TASK: {DDF20D4F-3224-469E-80F6-6FC7C9A86B22} [64Bits][\{27316D6C-1273-4606-B7EC-7559CE8CED58}] - (.Google Inc. - Google Chrome.) -- c:\program files (x86)\google\chrome\application\chrome.exe [1451352] =>.Google Inc®
O38 - TASK: {DE280E27-41E3-43DD-8D0C-7D14FBD3A6ED} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Refresh Settings] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [34304] =>.Microsoft Corporation
O38 - TASK: {DEA1FD8A-5ED8-46CB-9D4B-73E2892FB0E5} [64Bits][\ASUS P4G] - (.ASUS - Power4Gear Hybrid.) -- C:\Program Files\ASUS\P4G\BatteryLife.exe [1018240] =>.ASUSTeK Computer Inc.®
O38 - TASK: {DFCA820C-7457-47FB-8E5E-E20A7BD0E335} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Resume On Boot] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [34304] =>.Microsoft Corporation
O38 - TASK: {E0DFD5EB-E6A1-4020-B9F0-1AD24A3B59B3} [64Bits][\AsusVibeSchedule] - (.ASUSTeK - AsusVibe Application.) -- C:\Program Files (x86)\Asus\AsusVibe\AsusVibeLauncher.exe [1957040] ASUSTeK =>ASUSTeK
O38 - TASK: {E11183CC-FCAC-479E-B422-6A72654C14EA} [64Bits][\Microsoft\Windows\Location\Notifications] - (.Microsoft Corporation - Location Notification.) -- C:\WINDOWS\System32\LocationNotificationWindows.exe [66560] =>.Microsoft Corporation
O38 - TASK: {E6C98639-63D7-4817-82D5-F5F67D85273B} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Maintenance Install] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [34304] =>.Microsoft Corporation
O38 - TASK: {EA5FE701-133D-424A-87D0-E08D8E57C9A5} [64Bits][\ASUS Live Update] - (.ASUSTeK Computer Inc. - ASUS Live Update.) -- C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [1559936] =>.ASUSTeK Computer Inc.®
O38 - TASK: {EC11A6F7-343D-49E9-A974-A3716157F2C1} [64Bits][\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser] - (.Microsoft Corporation - Microsoft Compatibility Telemetry.) -- C:\WINDOWS\system32\compattelrunner.exe [96672] =>.Microsoft Windows®
O38 - TASK: {F09A7632-C051-4582-A500-E9B4C80336AC} [64Bits][\McAfee Remediation (Prepare)] - (.McAfee, Inc. - McAfee Remediation Manager.) -- C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [3949168] =>.McAfee, Inc.®
O38 - TASK: {F2A78F1D-FB42-4EFD-B52C-D747E19998E1} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Combined Scan Download Install] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [34304] =>.Microsoft Corporation
O38 - TASK: {F88E01C2-99E3-4AF6-BFAA-7ACC8EF521D4} [64Bits][\Microsoft\Windows\Feedback\Siuf\DmClient] - (.Microsoft Corporation - Microsoft Feedback SIUF Deployment Manager.) -- C:\WINDOWS\system32\dmclient.exe [89600] =>.Microsoft Corporation
O38 - TASK: {F9015704-44A7-4962-B811-A4C0206CF851} [64Bits][\Microsoft\Windows\WindowsUpdate\sihboot] - (.Microsoft Corporation - SIH Client.) -- C:\WINDOWS\System32\sihclient.exe [229888] =>.Microsoft Corporation
---\\ Auto loading programs from Registry and folders (19) - 3s
O4 - HKLM\..\Run: [SecurityHealth] . (.Microsoft Corporation - Windows Defender notification icon.) -- C:\Program Files\Windows Defender\MSASCuiL.exe =>.Microsoft Windows®
O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Realtek HD Audio Manager.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp®
O4 - HKLM\..\Run: [RtHDVBg] . (.Realtek Semiconductor - HD Audio Background Process.) -- C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe =>.Realtek Semiconductor Corp®
O4 - HKCU\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows®
O4 - HKCU\..\Run: [Lync] . (.Microsoft Corporation - Skype for Business.) -- C:\Program Files\Microsoft Office 15\root\office15\lync.exe =>.Microsoft Corporation®
O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\Owner\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - HKLM\..\Wow6432Node\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe =>.Adobe Systems, Incorporated®
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems, Incorporated®
O4 - HKLM\..\Wow6432Node\Run: [ASUSPRP] . (.ASUSTek Computer Inc. - ASUS Product Register Program.) -- C:\Program Files (x86)\ASUS\APRP\APRP.EXE =>.ASUSTek Computer Inc.
O4 - HKLM\..\Wow6432Node\Run: [ASUSWebStorage] . (.ASUS Cloud Corporation - ASUS WebStorage Panel.) -- C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe =>.ASUS Cloud Corporation®
O4 - HKLM\..\Wow6432Node\Run: [RemoteControl10] . (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe =>.CyberLink®
O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe =>.Apple Inc.®
O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe =>.Apple Inc.®
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle America, Inc.®
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows®
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows®
O4 - HKUS\S-1-5-21-1241052491-2989075707-2494370071-1001\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows®
O4 - HKUS\S-1-5-21-1241052491-2989075707-2494370071-1001\..\Run: [Lync] . (.Microsoft Corporation - Skype for Business.) -- C:\Program Files\Microsoft Office 15\root\office15\lync.exe =>.Microsoft Corporation®
O4 - HKUS\S-1-5-21-1241052491-2989075707-2494370071-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\Owner\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
---\\ Google Chrome, Start,Search,Extensions (20) - 0s
G0 - GCSP: Preferences [User Data\Default][HomePage]
http://apis.google.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage]
http://clients5.google.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage]
http://fonts.gstatic.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage]
http://id.google.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage]
http://lh3.googleusercontent.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage]
http://ogs.google.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage]
http://pchelpforum.net
G0 - GCSP: Preferences [User Data\Default][HomePage]
http://ssl.gstatic.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage]
http://www.google.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage]
http://www.gstatic.com =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] =>.Google Inc. {Slides}
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] =>.Google Inc. {Docs}
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf]
http://drive.google.com/ =>.Google Inc. {Drive}
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo]
http://www.youtube.com =>.Youtube {Youtube}
G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf]
http://www.google.com/ =>.Google Inc. {Hidden Chrome extensions}
G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] =>.Google Inc. {Sheets}
G2 - GCE: Preference [User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] =>.Google Inc. {Docs hors connexion}
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] =>.Google Inc. {Wallet}
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia]
http://mail.google.com/ =>.Google Inc. {Gmail}
G2 - GCE: Preference [User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.
---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (3) - 4s
P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (.Apple Inc..) -- C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll =>.Apple Inc.
P2 - FPN: [HKLM] [@mcafee.com/MSC,version=10] - (.McAfee Total Protection MIME Plugin.) -- c:\Program Files (x86)\McAfee\msc\npMcSnFFPl.dll =>.McAfee Total Protection MIME Plugin
P2 - FPN: [HKLM] [@WildTangent.com/GamesAppPresenceDetector,Version=1.0] - (.WildTangent.) -- C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll =>.WildTangent
---\\ Internet Explorer Extensions, Start, Search (16) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://asus13.msn.com =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Browser.) (11.00.15063.608 (WinBuild.160101.0800)) -- C:\Windows\SysWOW64\ieframe.dll =>.Microsoft Corporation
---\\ Internet Explorer, Proxy Management (6) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft
---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
F2 - REG:system.ini: UserInit=
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=
---\\ Hosts file redirection (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)
---\\ Browser Helper Object (BHO) (3) - 1s
O2 - BHO: Skype for Business Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} . (.Microsoft Corporation - Skype for Business.) -- C:\Program Files\Microsoft Office 15\root\office15\ochelper.dll =>.Microsoft Corporation®
O2 - BHO: Search App by Ask BHO [64Bits] - {4F524A2D-5350-4500-76A7-7A786E7484D7} . (...) -- "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll" (.not file.) =>PUP.Optional.BrowserTabSearch
O2 - BHO: Microsoft SkyDrive Pro Browser Helper [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} . (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office 15\root\office15\grooveex.dll =>.Microsoft Corporation®
---\\ Internet Explorer Toolbars (1) - 0s
O3 - Toolbar: (no name) - [HKLM]{4F524A2D-5350-4500-76A7-7A786E7484D7} (.Orphan.)
---\\ Global shortcuts Startup (69) - 12s
O4 - GS\Desktop [Administrator]: Owner Gibson - Nimbels Strategy - Shortcut.lnk . (...) C:\Users\Owner\Documents\zoom\2017-09-10 14.20.54 Owner gibson's zoom meeting 331521913\Owner Gibson - Nimbels Strategy.mp4
O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Owner\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Administrator]: Zoom.lnk . (.Zoom Video Communications, Inc. - Zoom Meetings.) C:\Users\Owner\AppData\Roaming\Zoom\bin\Zoom.exe =>.Zoom Video Communications, Inc.®
O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Administrator]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\sendTo [Administrator]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrator]: TeamViewer.lnk . (.TeamViewer GmbH - TeamViewer 10.) C:\Program Files (x86)\TeamViewer\TeamViewer.exe --sendto =>.TeamViewer®
O4 - GS\TaskBar [Administrator]: ASUS Install.lnk . (.ASUSTek Computer INC. - AsInsWiz.) C:\eSupport\eDriver\AsInsWiz.exe =>.ASUSTeK Computer Inc.®
O4 - GS\TaskBar [Administrator]: eManual.Lnk . (.ASUSTek Computer Inc. - EManual Application.) C:\eSupport\Manual\eManual.exe =>.ASUSTeK Computer Inc.®
O4 - GS\Startup [Administrator]: OneNote 2007 Screen Clipper and Launcher.lnk . (.Microsoft Corporation - Microsoft Office OneNote Quick Launcher.) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE /tsr =>.Microsoft Corporation®
O4 - GS\Programs [Administrator]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Owner\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Owner]: Owner Gibson - Nimbels Strategy - Shortcut.lnk . (...) C:\Users\Owner\Documents\zoom\2017-09-10 14.20.54 Owner gibson's zoom meeting 331521913\Owner Gibson - Nimbels Strategy.mp4
O4 - GS\Desktop [Owner]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Owner\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Owner]: Zoom.lnk . (.Zoom Video Communications, Inc. - Zoom Meetings.) C:\Users\Owner\AppData\Roaming\Zoom\bin\Zoom.exe =>.Zoom Video Communications, Inc.®
O4 - GS\Quicklaunch [Owner]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Owner]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\sendTo [Owner]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\sendTo [Owner]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Owner]: TeamViewer.lnk . (.TeamViewer GmbH - TeamViewer 10.) C:\Program Files (x86)\TeamViewer\TeamViewer.exe --sendto =>.TeamViewer®
O4 - GS\TaskBar [Owner]: ASUS Install.lnk . (.ASUSTek Computer INC. - AsInsWiz.) C:\eSupport\eDriver\AsInsWiz.exe =>.ASUSTeK Computer Inc.®
O4 - GS\TaskBar [Owner]: eManual.Lnk . (.ASUSTek Computer Inc. - EManual Application.) C:\eSupport\Manual\eManual.exe =>.ASUSTeK Computer Inc.®
O4 - GS\Startup [Owner]: OneNote 2007 Screen Clipper and Launcher.lnk . (.Microsoft Corporation - Microsoft Office OneNote Quick Launcher.) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE /tsr =>.Microsoft Corporation®
O4 - GS\Programs [Owner]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Owner\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Guest]: Owner Gibson - Nimbels Strategy - Shortcut.lnk . (...) C:\Users\Owner\Documents\zoom\2017-09-10 14.20.54 Owner gibson's zoom meeting 331521913\Owner Gibson - Nimbels Strategy.mp4
O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Owner\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Guest]: Zoom.lnk . (.Zoom Video Communications, Inc. - Zoom Meetings.) C:\Users\Owner\AppData\Roaming\Zoom\bin\Zoom.exe =>.Zoom Video Communications, Inc.®
O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Guest]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\sendTo [Guest]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Guest]: TeamViewer.lnk . (.TeamViewer GmbH - TeamViewer 10.) C:\Program Files (x86)\TeamViewer\TeamViewer.exe --sendto =>.TeamViewer®
O4 - GS\TaskBar [Guest]: ASUS Install.lnk . (.ASUSTek Computer INC. - AsInsWiz.) C:\eSupport\eDriver\AsInsWiz.exe =>.ASUSTeK Computer Inc.®
O4 - GS\TaskBar [Guest]: eManual.Lnk . (.ASUSTek Computer Inc. - EManual Application.) C:\eSupport\Manual\eManual.exe =>.ASUSTeK Computer Inc.®
O4 - GS\Startup [Guest]: OneNote 2007 Screen Clipper and Launcher.lnk . (.Microsoft Corporation - Microsoft Office OneNote Quick Launcher.) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE /tsr =>.Microsoft Corporation®
O4 - GS\Programs [Guest]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Owner\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\CommonDesktop [Public]: FlexSim 7.5.lnk . (.Flexsim Corporation - .) C:\Program Files (x86)\FlexSim7.5\program\flexsim.exe
O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\CommonDesktop [Public]: HP DeskJet 3630 series.lnk . (.HP Inc. - .) C:\Program Files (x86)\HP\HP DeskJet 3630 series\Bin\HP DeskJet 3630 series.exe -Start UDCDevicePage =>.HP Inc.
O4 - GS\CommonDesktop [Public]: HP Photo Creations.lnk . (.Visan / RocketLife - PhotoProduct.exe.) C:\Program Files (x86)\HP Photo Creations\PhotoProduct.exe =>.Visan Industries®
O4 - GS\CommonDesktop [Public]: iTunes.lnk . (.Apple Inc. - iTunes.) C:\Program Files (x86)\iTunes\iTunes.exe =>.Apple Inc.®
O4 - GS\CommonDesktop [Public]: Shop for Supplies - HP DeskJet 3630 series.lnk . (.HP Inc. - .) C:\Program Files (x86)\HP\HP DeskJet 3630 series\Bin\hpqDTSS.exe =>.HP Inc.
O4 - GS\CommonDesktop [Public]: TeamViewer 10.lnk . (.TeamViewer GmbH - TeamViewer 10.) C:\Program Files (x86)\TeamViewer\TeamViewer.exe =>.TeamViewer®
O4 - GS\CommonDesktop [Public]: Waves MAXXAudio.lnk . (.Waves Audio Ltd. - .) C:\Program Files (x86)\Realtek\Audio\HDA\MaxxAudioControl64.exe =>.Waves Audio Ltd.
O4 - GS\Programs [Public]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Owner\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\Accessories [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\WINDOWS\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Quick Assist.lnk . (.Microsoft Corporation - Quick Assist.) C:\WINDOWS\system32\quickassist.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\WINDOWS\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Steps Recorder.) C:\WINDOWS\system32\psr.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: XPS Viewer.lnk . (.Microsoft Corporation - XPS Viewer.) C:\WINDOWS\system32\xpsrchvw.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) C:\WINDOWS\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Adobe Reader X.lnk . (...) C:\windows\Installer\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}\SC_Reader.ico =>.Adobe Inc.
O4 - GS\ProgramsCommon [Public]: Apple Software Update.lnk . (...) C:\Windows\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\AppleSoftwareUpdateIco.exe =>.Apple Inc.
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\WINDOWS\System32\Control.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: MiracastView.lnk . (.Microsoft Corporation - MiracastView.) C:\WINDOWS\MiracastView\MiracastView.exe =>.Microsoft Windows®
O4 - GS\ProgramsCommon [Public]: Movie Maker.lnk . (.Microsoft Corporation - Movie Maker.) C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Photo Gallery.lnk . (.Microsoft Corporation - Photo Gallery.) C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: PrintDialog.lnk . (.Microsoft Corporation - Print Dialog.) C:\WINDOWS\PrintDialog\PrintDialog.exe =>.Microsoft Windows®
O4 - GS\ProgramsCommon [Public]: TeamViewer 10.lnk . (.TeamViewer GmbH - TeamViewer 10.) C:\Program Files (x86)\TeamViewer\TeamViewer.exe =>.TeamViewer®
O4 - GS\ProgramsCommon [Public]: WildTangent Games App - asus.lnk . (.WildTangent - WildTangent Games App.) C:\Program Files (x86)\WildTangent Games\App\GameConsole-wt.exe /src gamesmenu /dp asus =>.WildTangent Inc®
O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
---\\ Lop.com/Domain Hijackers (4) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.5.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{a904134b-6078-4031-9289-5472adcba676}: DhcpNameServer = 192.168.5.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{a9ea9500-b3ac-4445-8b3d-70204043ace5}: DhcpNameServer = 192.168.72.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{e61c9154-b92f-403e-b1c7-c602aad8694f}: DhcpNameServer = 192.168.5.1 =>.Local IP Adress
---\\ Extra protocols (27) - 1s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\SysWOW64\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-help [64Bits] - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll =>.Microsoft Corporation®
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation
O18 - Handler: osf [64Bits] - {D924BDC6-C83A-4BD5-90D0-095128A113D1} . (.Microsoft Corporation - Microsoft Office 2013 component.) -- C:\Program Files\Microsoft Office 15\root\office15\msosb.dll =>.Microsoft Corporation®
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\SysWOW64\tbauth.dll =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: windows.tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\SysWOW64\tbauth.dll =>.Microsoft Corporation
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Photo Gallery Album Download Protocol Handl.) -- C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll =>.Microsoft Corporation®
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-mfe-ipt [64Bits] - {3EF5086B-5478-4598-A054-786C45D75692} . (.McAfee, Inc. - McAfee MSC IE plugin DLL.) -- c:\Program Files (x86)\McAfee\msc\McSnIePl.dll =>.McAfee, Inc.®
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL =>.Microsoft Corporation®
---\\ ASIC (ActiveSetup Installed Components) (6) - 4s
O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Microsoft Windows Media Player Setup Utilit.) -- C:\Windows\System32\unregmp2.exe =>.Microsoft Corporation
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll =>.Microsoft Corporation®
O40 - ASIC: Google Chrome [64Bits] - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (.Google Inc. - Google Chrome Installer.) -- C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.100\Installer\chrmstp.exe =>.Google Inc®
---\\ Software installed (72) - 12s
O42 - Logiciel: Adobe Reader X MUI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-FFFF-7B44-AA0000000001} =>.Adobe Systems Incorporated
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM][64Bits] -- {46F044A5-CE8B-4196-984E-5BD6525E361D} =>.Apple Inc.
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM][64Bits] -- {2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C} =>.Apple Inc.
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM][64Bits] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} =>.Apple Inc.
O42 - Logiciel: ASUS InstantOn - (.ASUS.) [HKLM][64Bits] -- {749F674B-2674-47E8-879C-5626A06B2A91} =>.ASUS
O42 - Logiciel: ASUS LifeFrame3 - (.ASUS.) [HKLM][64Bits] -- {1DBD1F12-ED93-49C0-A7CC-56CBDE488158} =>.ASUS
O42 - Logiciel: ASUS Live Update - (.ASUS.) [HKLM][64Bits] -- {FA540E67-095C-4A1B-97BA-4D547DEC9AF4} =>.ASUS
O42 - Logiciel: ASUS Power4Gear Hybrid - (.ASUS.) [HKLM][64Bits] -- {9B6239BF-4E85-4590-8D72-51E30DB1A9AA} =>.ASUS
O42 - Logiciel: ASUS Screen Saver - (.ASUS.) [HKLM][64Bits] -- {0FBEEDF8-30FA-4FA3-B31F-C9C7E7E8DFA2} =>.ASUS
O42 - Logiciel: ASUS Splendid Video Enhancement Technology - (.ASUS.) [HKLM][64Bits] -- {0969AF05-4FF6-4C00-9406-43599238DE0D} =>.ASUS
O42 - Logiciel: ASUS USB Charger Plus - (.ASUS.) [HKLM][64Bits] -- {A859E3E5-C62F-4BFA-AF1D-2B95E03166AF} =>.ASUS
O42 - Logiciel: ASUS WebStorage Sync Agent - (.ASUS Cloud Corporation.) [HKLM][64Bits] -- ASUS WebStorage =>.ASUS Cloud Corporation
O42 - Logiciel: ASUSDVD - (.CyberLink Corp..) [HKLM][64Bits] -- {DEC235ED-58A4-4517-A278-C41E8DAEAB3B} =>.CyberLink®
O42 - Logiciel: ASUSDVD - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B} =>.CyberLink®
O42 - Logiciel: AsusVibe2.0 - (.ASUSTEK.) [HKLM][64Bits] -- Asus Vibe2.0 =>.ASUSTeK
O42 - Logiciel: ATK Package - (.ASUS.) [HKLM][64Bits] -- {AB5C933E-5C7D-4D30-B314-9C83A49B94BE} =>.ASUS
O42 - Logiciel: Azteca - (.WildTangent.) [HKLM][64Bits] -- WTA-f16d00eb-f7b1-482f-bd1f-4433db7f046d =>.WildTangent Inc®
O42 - Logiciel: Bejeweled 3 - (.WildTangent.) [HKLM][64Bits] -- WTA-c70ce12c-fa71-4526-9e49-dc34f23d11e5 =>.WildTangent Inc®
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM][64Bits] -- {6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D} =>.Apple Inc.
O42 - Logiciel: Citrix Online Launcher - (.Citrix.) [HKLM][64Bits] -- {09DA5EE2-7E46-4DC4-96F9-BFEE50D40659} =>.Citrix
O42 - Logiciel: Cut the Rope - (.WildTangent.) [HKLM][64Bits] -- WTA-37b0c899-be55-4990-ace2-377368f019b1 =>.WildTangent Inc®
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF} =>.Microsoft
O42 - Logiciel: FlexSim 7.5.4 - (.FlexSim Software Products Inc..) [HKLM][64Bits] -- {7663DDB1-2788-4481-9861-C779473E47FB}
O42 - Logiciel: FlexSim 7.5.4 - (.FlexSim Software Products, Inc..) [HKLM][64Bits] -- {8d9d3193-a71a-419c-bb7b-6855761902da} {21EFCFA675BA77F4AB2C64E476433DB7}
O42 - Logiciel: FlexSim 7.5.4 AStar Module 1.1.0 - (.FlexSim Software Products Inc..) [HKLM][64Bits] -- {124DDD12-0BD0-464E-B753-4BC53D27770A}
O42 - Logiciel: FlexSim 7.5.4 Conveyor Module 1.0.6 - (.FlexSim Software Products Inc..) [HKLM][64Bits] -- {BD185B6B-E748-45E9-A5FF-31B0048F7436}
O42 - Logiciel: Galería de fotos - (.Microsoft Corporation.) [HKLM][64Bits] -- {8F7FECEC-088F-431D-A5FB-2B59E1E69943} =>.Microsoft Corporation
O42 - Logiciel: Galerie de photos - (.Microsoft Corporation.) [HKLM][64Bits] -- {446CC8CE-0E90-44F7-ADD0-774B243EF090} =>.Microsoft Corporation
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome =>.Google Inc®
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: GoToMeeting 8.8.0.7297 - (.LogMeIn, Inc..) [HKCU][64Bits] -- GoToMeeting =>.LogMeIn, Inc.®
O42 - Logiciel: HP DeskJet 3630 series Basic Device Software - (.HP Inc..) [HKLM][64Bits] -- {5BF43ABB-30E8-4728-93C2-C4A0DCE7A27B} =>.HP Inc.
O42 - Logiciel: HP DeskJet 3630 series Help - (.Hewlett Packard.) [HKLM][64Bits] -- {5F074370-FEB0-4477-820F-A59DF28A933E} =>.Hewlett Packard
O42 - Logiciel: HP Dropbox Plugin - (.HP.) [HKLM][64Bits] -- {D12BC084-97D6-438A-AA7C-5962608D17A0} =>.HP
O42 - Logiciel: HP Google Drive Plugin - (.HP.) [HKLM][64Bits] -- {BFA42100-DB54-467A-BB87-CF70732B4065} =>.HP
O42 - Logiciel: HP Photo Creations - (.HP.) [HKLM][64Bits] -- HP Photo Creations =>.Visan Industries®
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A} =>.Intel Corporation®
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} =>.Intel Corporation - pGFX®
O42 - Logiciel: Intel(R) SDK for OpenCL - CPU Only Runtime Package - (.Intel Corporation.) [HKLM][64Bits] -- {FCB3772C-B7D0-4933-B1A9-3707EBACC573} =>.Intel Corporation
O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {F4404AFD-2EF3-40C1-8C09-29E5F3B6972B} =>.Intel Corporation
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM][64Bits] -- {D601CEAD-2E4F-4BBB-85CC-C29A4CE6A3C0} =>.Apple Inc.
O42 - Logiciel: Java 7 Update 65 - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F03217065FF} =>.Oracle
O42 - Logiciel: Java Auto Updater - (.Oracle, Inc..) [HKLM][64Bits] -- {4A03706F-666A-4037-7777-5F2748764D10} =>.Oracle, Inc.
O42 - Logiciel: McAfee LiveSafe – Internet Security - (.McAfee, Inc..) [HKLM][64Bits] -- MSC =>.McAfee, Inc.®
O42 - Logiciel: Microsoft Application Error Reporting - (.Microsoft Corporation.) [HKLM][64Bits] -- {95120000-00B9-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft OneDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- OneDriveSetup.exe =>.Microsoft Corporation®
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} =>.Microsoft
O42 - Logiciel: MSVCRT110 - (.Microsoft.) [HKLM][64Bits] -- {8E14DDC8-EA60-4E18-B3E3-1937104D5BDA} =>.Microsoft
O42 - Logiciel: MSVCRT110_amd64 - (.Microsoft.) [HKLM][64Bits] -- {E9FA781F-3E80-4399-825A-AD3E11C28C77} =>.Microsoft
O42 - Logiciel: MyBitCast 2.0 - (.ASUS.) [HKLM][64Bits] -- MyBitCast =>.ASUS
O42 - Logiciel: Office 15 Click-to-Run Extensibility Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008C-0000-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Office 15 Click-to-Run Licensing Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008F-0000-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Office 15 Click-to-Run Localization Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008C-0409-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Peggle - (.WildTangent.) [HKLM][64Bits] -- WTA-76b0a447-ce1e-45e2-ba52-842c2abfca88 =>.WildTangent Inc®
O42 - Logiciel: Penguins! - (.WildTangent.) [HKLM][64Bits] -- WTA-2b878b41-62cf-48f5-a545-808b72d8a96c =>.WildTangent Inc®
O42 - Logiciel: Product Improvement Study for HP DeskJet 3630 series - (.HP Inc..) [HKLM][64Bits] -- {1ECB5ABB-63BB-4E26-AEE0-6021F0502DB2} =>.HP Inc.
O42 - Logiciel: Qualcomm Atheros Client Installation Program - (.Qualcomm Atheros.) [HKLM][64Bits] -- {28006915-2739-4EBE-B5E8-49B25D32EB33} =>.Qualcomm Atheros
O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Realtek PCIE Card Reader - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {C1594429-8296-4652-BF54-9DBE4932A44C} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Search App by Ask - (.APN, LLC.) [HKLM][64Bits] -- {4F524A2D-5350-4500-76A7-A758B70C2E03} =>PUP.Optional.BrowserTabSearch
O42 - Logiciel: Shared C Run-time for x64 - (.McAfee.) [HKLM][64Bits] -- {EF79C448-6946-4D71-8134-03407888C054} =>.McAfee
O42 - Logiciel: Tales of Lagoona - (.WildTangent.) [HKLM][64Bits] -- WTA-21e86661-8d6c-4fd1-af68-34c97e81c2e1 =>.WildTangent Inc®
O42 - Logiciel: TeamViewer 10 - (.TeamViewer.) [HKLM][64Bits] -- TeamViewer =>.TeamViewer®
O42 - Logiciel: Update Installer for WildTangent Games App - (.WildTangent.) [HKLM][64Bits] -- {2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App =>.WildTangent Inc®
O42 - Logiciel: WildTangent Games - (.WildTangent.) [HKLM][64Bits] -- WildTangent wildgames Master Uninstall =>.WildTangent Inc®
O42 - Logiciel: WildTangent Games App - (.WildTangent.) [HKLM][64Bits] -- {70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-asus =>.WildTangent Inc®
O42 - Logiciel: Windows 10 Update and Privacy Settings - (.Microsoft Corporation.) [HKLM][64Bits] -- {4DFCD818-036A-4229-A67D-CF17DC461D92} =>.Microsoft Corporation
O42 - Logiciel: WinFlash - (.ASUS.) [HKLM][64Bits] -- {8F21291E-0444-4B1D-B9F9-4370A73E346D} =>.ASUS
O42 - Logiciel: Zoom - (.Zoom Video Communications, Inc..) [HKCU][64Bits] -- ZoomUMX =>.Zoom Video Communications, Inc.®
O42 - Logiciel: 影像中心 - (.Microsoft Corporation.) [HKLM][64Bits] -- {631C4E4F-6FDC-4CC0-A067-E9876A9BA7FD} =>.Microsoft Corporation
O42 - Logiciel: 照片库 - (.Microsoft Corporation.) [HKLM][64Bits] -- {017E337D-D709-437C-83DB-71F82AA78BF6} =>.Microsoft Corporation
---\\ HKCU & HKLM Software Keys (67) - 12s
HKLM\SOFTWARE\Wow6432Node\Adobe =>.Adobe
HKLM\SOFTWARE\Wow6432Node\Apple Computer, Inc. =>.Apple Computer, Inc.
HKLM\SOFTWARE\Wow6432Node\Apple Inc. =>.Apple Inc.
HKLM\SOFTWARE\Wow6432Node\ASIO =>.Steinberg Media Technologies
HKLM\SOFTWARE\Wow6432Node\AskPartnerNetwork =>PUP.Optional.APNToolBar
HKLM\SOFTWARE\Wow6432Node\AsLdr =>.ASUSTeK
HKLM\SOFTWARE\Wow6432Node\ASUS =>.ASUS
HKLM\SOFTWARE\Wow6432Node\Atheros =>.Qualcomm Atheros
HKLM\SOFTWARE\Wow6432Node\CyberLink =>.CyberLink Corporation
HKLM\SOFTWARE\Wow6432Node\ECAREME =>.Ecareme
HKLM\SOFTWARE\Wow6432Node\Google =>.Google
HKLM\SOFTWARE\Wow6432Node\Hewlett-Packard =>.Hewlett-Packard
HKLM\SOFTWARE\Wow6432Node\IM Providers =>.IM Providers
HKLM\SOFTWARE\Wow6432Node\Intel =>.Intel
HKLM\SOFTWARE\Wow6432Node\JavaSoft =>.JavaSoft
HKLM\SOFTWARE\Wow6432Node\JreMetrics =>.JreMetrics
HKLM\SOFTWARE\Wow6432Node\Khronos =>.Khronos
HKLM\SOFTWARE\Wow6432Node\Lake =>.Lake Sofware
HKLM\SOFTWARE\Wow6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\Wow6432Node\McAfee =>.McAfee Inc.
HKLM\SOFTWARE\Wow6432Node\McAfee.com =>.McAfee Inc.
HKLM\SOFTWARE\Wow6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\Network Associates =>.Network Associates
HKLM\SOFTWARE\Wow6432Node\Nuance =>.Nuance
HKLM\SOFTWARE\Wow6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\Wow6432Node\Qualcomm Atheros =>.Qualcomm Atheros
HKLM\SOFTWARE\Wow6432Node\Realtek =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp. =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\RocketLife =>.RocketLife
HKLM\SOFTWARE\Wow6432Node\Skype =>.Skype
HKLM\SOFTWARE\Wow6432Node\SuppHelpDir =>.Toshiba Corporation
HKLM\SOFTWARE\Wow6432Node\TeamViewer =>.TeamViewer
HKLM\SOFTWARE\Wow6432Node\Visan =>.Visan Software
HKLM\SOFTWARE\Wow6432Node\WildTangent =>.WildTangent
HKLM\SOFTWARE\Wow6432Node\WOW6432Node =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\Adobe =>.Adobe
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\Apple Computer, Inc. =>.Apple Computer, Inc.
HKCU\SOFTWARE\Apple Inc. =>.Apple Inc.
HKCU\SOFTWARE\AskPartnerNetwork =>PUP.Optional.APNToolBar
HKCU\SOFTWARE\ASUS =>.ASUS
HKCU\SOFTWARE\Citrix =>.Citrix
HKCU\SOFTWARE\CyberLink =>.CyberLink Corporation
HKCU\SOFTWARE\ECAREME =>.Ecareme
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard
HKCU\SOFTWARE\HP =>.HP
HKCU\SOFTWARE\IM Providers =>.IM Providers
HKCU\SOFTWARE\Intel =>.Intel
HKCU\SOFTWARE\JavaSoft =>.JavaSoft
HKCU\SOFTWARE\LogMeInInc =>.LogMeIn Entreprise
HKCU\SOFTWARE\Macromedia =>.Macromedia
HKCU\SOFTWARE\McAfee =>.McAfee Inc.
HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKCU\SOFTWARE\Netscape =>.Netscape
HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\TeamViewer =>.TeamViewer
HKCU\SOFTWARE\Visan =>.Visan Software
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\ZoomUMX
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKCU\SOFTWARE\AppDataLow\Software\JavaSoft =>.JavaSoft
---\\ Contents of the Common Files folders (205) - 15s
O43 - CFD: 23/09/2013 - [] D -- C:\Program Files\ASUS =>.ASUSTeK Computer Inc.®
O43 - CFD: 02/01/2014 - [] AD -- C:\Program Files\Bonjour =>.Apple Inc.
O43 - CFD: 15/10/2017 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 30/07/2016 - [] D -- C:\Program Files\DIFX =>.Microsoft Corporation
O43 - CFD: 29/05/2015 - [] AD -- C:\Program Files\FlexSim7.5
O43 - CFD: 03/11/2016 - [] D -- C:\Program Files\HP =>.Hewlett-Packard
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files\Intel =>.Intel Corporation
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 02/01/2014 - [] D -- C:\Program Files\iPod =>.Apple Inc.®
O43 - CFD: 02/01/2014 - [] D -- C:\Program Files\iTunes =>.Apple Inc.
O43 - CFD: 15/10/2017 - [] AD -- C:\Program Files\mcafee =>.McAfee
O43 - CFD: 01/05/2013 - [] D -- C:\Program Files\mcafee.com =>.McAfee Inc.
O43 - CFD: 25/12/2013 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 14/10/2017 - [] AD -- C:\Program Files\Microsoft Office 15 =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files\Realtek =>.Realtek
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 02/07/2017 - [] AD -- C:\Program Files\UNP =>.Microsoft Corporation
O43 - CFD: 11/07/2017 - [] RD -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files\Windows Security =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] SHD -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 15/10/2017 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 01/05/2013 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Systems, Incorporated®
O43 - CFD: 02/01/2014 - [] AD -- C:\Program Files (x86)\Apple Software Update =>.Apple Inc.
O43 - CFD: 15/10/2017 - [] D -- C:\Program Files (x86)\AskPartnerNetwork =>PUP.Optional.APNToolBar
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files (x86)\ASUS =>.ASUSTeK Computer Inc.®
O43 - CFD: 02/01/2014 - [] AD -- C:\Program Files (x86)\Bonjour =>.Apple Inc.
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 23/09/2013 - [] D -- C:\Program Files (x86)\CyberLink =>.CyberLink Corporation
O43 - CFD: 28/12/2015 - [] D -- C:\Program Files (x86)\Google =>.Google Inc®
O43 - CFD: 03/11/2016 - [] D -- C:\Program Files (x86)\HP =>.Hewlett-Packard
O43 - CFD: 03/11/2016 - [] D -- C:\Program Files (x86)\HP Photo Creations =>.Visan Industries®
O43 - CFD: 23/09/2013 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield
O43 - CFD: 13/04/2015 - [] D -- C:\Program Files (x86)\Intel =>.Intel Corporation
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 02/01/2014 - [] AD -- C:\Program Files (x86)\iTunes =>.Apple Inc.
O43 - CFD: 18/07/2014 - [] D -- C:\Program Files (x86)\Java =>.Oracle
O43 - CFD: 14/10/2017 - [] D -- C:\Program Files (x86)\McAfee =>.McAfee
O43 - CFD: 01/05/2013 - [] D -- C:\Program Files (x86)\mcafee.com =>.McAfee Inc.
O43 - CFD: 29/07/2016 - [] AD -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 01/05/2013 - [] D -- C:\Program Files (x86)\Microsoft SkyDrive =>.Microsoft Corporation
O43 - CFD: 01/05/2013 - [] AD -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition =>.Microsoft Corporation
O43 - CFD: 02/02/2015 - [] D -- C:\Program Files (x86)\Microsoft Works =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 23/09/2013 - [] AD -- C:\Program Files (x86)\Qualcomm Atheros =>.Qualcomm Atheros
O43 - CFD: 23/09/2013 - [] D -- C:\Program Files (x86)\Realtek =>.Realtek
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 18/01/2016 - [] AD -- C:\Program Files (x86)\TeamViewer =>.TeamViewer GmbH
O43 - CFD: 23/09/2013 - [0] HD -- C:\Program Files (x86)\Temp =>.Microsoft Corporation
O43 - CFD: 01/05/2013 - [] AD -- C:\Program Files (x86)\WildGames =>.WildTangent Inc®
O43 - CFD: 01/05/2013 - [] D -- C:\Program Files (x86)\WildTangent Games =>.WildTangent Games
O43 - CFD: 11/07/2017 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 01/05/2013 - [] AD -- C:\Program Files (x86)\Windows Live =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] SHD -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files (x86)\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 11/07/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 24/09/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS =>.ASUS
O43 - CFD: 24/09/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUSDVD =>.ASUSTeK
O43 - CFD: 24/09/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlexSim 7.5
O43 - CFD: 24/09/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP =>.Hewlett-Packard
O43 - CFD: 24/09/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel =>.Intel Corporation
O43 - CFD: 24/09/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes =>.Apple Inc.
O43 - CFD: 24/09/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java =>.Oracle
O43 - CFD: 18/03/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 15/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee =>.McAfee
O43 - CFD: 24/09/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 02/01/2014 - [] D -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 =>.GEAR Software, Inc.
O43 - CFD: 19/06/2014 - [] D -- C:\ProgramData\Adobe =>.Adobe
O43 - CFD: 02/01/2014 - [] D -- C:\ProgramData\Apple =>.Apple Inc.
O43 - CFD: 02/01/2014 - [] D -- C:\ProgramData\Apple Computer =>.Apple Inc.
O43 - CFD: 24/09/2017 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 01/05/2013 - [] D -- C:\ProgramData\ASUS WebStorage =>.ASUSTeK
O43 - CFD: 01/05/2013 - [] D -- C:\ProgramData\ASUSLogos =>.ASUSTeK
O43 - CFD: 23/09/2013 - [] D -- C:\ProgramData\ASUSVibe =>.ASUSTeK
O43 - CFD: 16/07/2016 - [0] D -- C:\ProgramData\Comms =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 29/05/2015 - [] D -- C:\ProgramData\FLEXnet =>.Flexera Software
O43 - CFD: 29/05/2015 - [] D -- C:\ProgramData\Flexsim
O43 - CFD: 04/12/2016 - [] AD -- C:\ProgramData\HP =>.Hewlett-Packard
O43 - CFD: 03/11/2016 - [] AD -- C:\ProgramData\HP Photo Creations =>.HP Photo Creations
O43 - CFD: 23/09/2013 - [] D -- C:\ProgramData\Intel =>.Intel Corporation
O43 - CFD: 08/09/2017 - [] D -- C:\ProgramData\McAfee =>.McAfee
O43 - CFD: 24/09/2017 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 17/07/2017 - [] D -- C:\ProgramData\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 06/10/2017 - [] D -- C:\ProgramData\Microsoft OneDrive =>.Microsoft Corporation
O43 - CFD: 01/05/2013 - [] D -- C:\ProgramData\Microsoft SkyDrive =>.Microsoft Corporation
O43 - CFD: 18/07/2014 - [0] D -- C:\ProgramData\Oracle =>.Oracle
O43 - CFD: 23/09/2013 - [] AD -- C:\ProgramData\P4G =>.Portables4Gamers
O43 - CFD: 17/01/2016 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 05/12/2015 - [] D -- C:\ProgramData\PRICache =>.Microsoft Corporation
O43 - CFD: 23/09/2013 - [] D -- C:\ProgramData\Qualcomm Atheros =>.Qualcomm Atheros
O43 - CFD: 14/10/2017 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [] D -- C:\ProgramData\SetupTPDriver =>.ASUSTeK
O43 - CFD: 18/03/2017 - [0] D -- C:\ProgramData\SoftwareDistribution =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation
O43 - CFD: 18/07/2014 - [] D -- C:\ProgramData\Sun =>.Oracle
O43 - CFD: 23/09/2013 - [] D -- C:\ProgramData\Temp =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation
O43 - CFD: 25/12/2013 - [] D -- C:\ProgramData\USBChargerPlus =>.ASUSTeK
O43 - CFD: 24/09/2017 - [] D -- C:\ProgramData\USOPrivate =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [] D -- C:\ProgramData\USOShared =>.Microsoft Corporation
O43 - CFD: 03/11/2016 - [] D -- C:\ProgramData\Visan =>.Visan Industries
O43 - CFD: 01/05/2013 - [] D -- C:\ProgramData\WildTangent =>.WildTangent
O43 - CFD: 18/03/2017 - [] D -- C:\ProgramData\WindowsHolographicDevices =>.Microsoft Corporation
O43 - CFD: 01/05/2013 - [] AD -- C:\Program Files (x86)\Common Files\Adobe =>.Adobe
O43 - CFD: 02/01/2014 - [] D -- C:\Program Files (x86)\Common Files\Apple =>.Apple Inc.
O43 - CFD: 04/09/2015 - [] AD -- C:\Program Files (x86)\Common Files\DESIGNER =>.Designer
O43 - CFD: 23/09/2013 - [] D -- C:\Program Files (x86)\Common Files\InstallShield =>.InstallShield
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files (x86)\Common Files\Intel =>.Intel Corporation
O43 - CFD: 18/07/2014 - [] D -- C:\Program Files (x86)\Common Files\Java =>.Oracle
O43 - CFD: 01/05/2013 - [] D -- C:\Program Files (x86)\Common Files\mcafee =>.McAfee
O43 - CFD: 24/09/2017 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared =>.Microsoft Corporation
O43 - CFD: 23/09/2013 - [] D -- C:\Program Files (x86)\Common Files\postureAgent =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 01/05/2013 - [] D -- C:\Program Files (x86)\Common Files\Windows Live =>.Microsoft Corporation
O43 - CFD: 19/06/2014 - [] D -- C:\Users\Owner\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 29/05/2015 - [] D -- C:\Users\Owner\AppData\Roaming\Apple Computer =>.Apple Inc.
O43 - CFD: 25/12/2013 - [] D -- C:\Users\Owner\AppData\Roaming\ASUS WebStorage =>.ASUSTeK
O43 - CFD: 29/05/2015 - [] D -- C:\Users\Owner\AppData\Roaming\Flexsim
O43 - CFD: 03/11/2016 - [] D -- C:\Users\Owner\AppData\Roaming\HP_Easy_Start =>.Hewlett-Packard
O43 - CFD: 14/04/2015 - [] D -- C:\Users\Owner\AppData\Roaming\Identities =>.Microsoft Corporation
O43 - CFD: 25/12/2013 - [] D -- C:\Users\Owner\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 24/09/2017 - [] SD -- C:\Users\Owner\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 17/08/2016 - [] D -- C:\Users\Owner\AppData\Roaming\Skype =>.Skype
O43 - CFD: 14/10/2017 - [] D -- C:\Users\Owner\AppData\Roaming\TeamViewer =>.TeamViewer GmbH
O43 - CFD: 15/10/2017 - [] D -- C:\Users\Owner\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 09/09/2017 - [] D -- C:\Users\Owner\AppData\Roaming\Zoom =>.ZOOM
O43 - CFD: 05/12/2015 - [0] D -- C:\Users\Owner\AppData\Local\ActiveSync =>.Microsoft Corporation
O43 - CFD: 19/06/2014 - [] D -- C:\Users\Owner\AppData\Local\Adobe =>.Adobe
O43 - CFD: 02/01/2014 - [] D -- C:\Users\Owner\AppData\Local\Apple =>.Apple Inc.
O43 - CFD: 29/05/2015 - [] D -- C:\Users\Owner\AppData\Local\Apple Computer =>.Apple Inc.
O43 - CFD: 24/09/2017 - [0] SHD -- C:\Users\Owner\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 15/10/2017 - [] D -- C:\Users\Owner\AppData\Local\AskPartnerNetwork =>PUP.Optional.APNToolBar
O43 - CFD: 25/12/2013 - [] D -- C:\Users\Owner\AppData\Local\ASUS =>.ASUS
O43 - CFD: 12/04/2016 - [] D -- C:\Users\Owner\AppData\Local\Citrix =>.Citrix
O43 - CFD: 05/12/2015 - [] D -- C:\Users\Owner\AppData\Local\Comms =>.Microsoft Corporation
O43 - CFD: 06/10/2017 - [] D -- C:\Users\Owner\AppData\Local\ConnectedDevicesPlatform =>.Microsoft Corporation
O43 - CFD: 01/09/2014 - [0] D -- C:\Users\Owner\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 04/09/2015 - [0] SHD -- C:\Users\Owner\AppData\Local\EmieBrowserModeList =>.Enterprise mode Site List Mgr
O43 - CFD: 04/09/2015 - [0] SHD -- C:\Users\Owner\AppData\Local\EmieSiteList =>.Enterprise mode Site List Mgr
O43 - CFD: 04/09/2015 - [0] SHD -- C:\Users\Owner\AppData\Local\EmieUserList =>.Enterprise mode Site List Mgr
O43 - CFD: 29/05/2015 - [] D -- C:\Users\Owner\AppData\Local\flexsim
O43 - CFD: 06/11/2016 - [] D -- C:\Users\Owner\AppData\Local\Google =>.Google
O43 - CFD: 17/07/2017 - [] D -- C:\Users\Owner\AppData\Local\GoToMeeting
O43 - CFD: 03/06/2015 - [] D -- C:\Users\Owner\AppData\Local\GWX =>.GWX
O43 - CFD: 24/09/2017 - [0] SHD -- C:\Users\Owner\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 03/11/2016 - [] D -- C:\Users\Owner\AppData\Local\HP =>.Hewlett-Packard
O43 - CFD: 24/09/2017 - [] D -- C:\Users\Owner\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 25/12/2013 - [0] D -- C:\Users\Owner\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 06/12/2015 - [] D -- C:\Users\Owner\AppData\Local\MicrosoftEdge =>.Microsoft Corporation
O43 - CFD: 05/12/2015 - [0] D -- C:\Users\Owner\AppData\Local\NetworkTiles =>.NetworkTiles
O43 - CFD: 09/10/2017 - [] D -- C:\Users\Owner\AppData\Local\Packages =>.Microsoft Corporation
O43 - CFD: 05/12/2015 - [] D -- C:\Users\Owner\AppData\Local\Publishers =>.Microsoft Corporation
O43 - CFD: 15/10/2017 - [] D -- C:\Users\Owner\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [0] SHD -- C:\Users\Owner\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 05/12/2015 - [] D -- C:\Users\Owner\AppData\Local\TileDataLayer =>.Microsoft Corporation
O43 - CFD: 02/07/2017 - [] D -- C:\Users\Owner\AppData\Local\UNP =>.Microsoft Corporation
O43 - CFD: 19/06/2014 - [] D -- C:\Users\Owner\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 15/10/2017 - [] D -- C:\Users\Owner\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 11/07/2017 - [] RD -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 05/10/2017 - [] RD -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 05/10/2017 - [] RD -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 18/03/2017 - [] D -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 05/10/2017 - [] RD -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [] RD -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] RD -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [] D -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom =>.ZOOM
O43 - CFD: 24/09/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 09/10/2016 - [0] D -- C:\Users\Default\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 09/10/2016 - [0] D -- C:\Users\Default User\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 18/03/2017 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [0] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\DBG =>.DBG
O43 - CFD: 09/10/2017 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 24/09/2017 - [] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Apple Computer =>.Apple Inc.
---\\ ShellIconOverlayIdentifiers (SIOI) (12) - 1s
O106 - SIOI: ErrorOverlayHandler Class [ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6966.0824_1\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SharedOverlayHandler Class [ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6966.0824_1\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SharedSyncingOverlayHandler Class [ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6966.0824_1\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: UpToDateOverlayHandler Class [ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6966.0824_1\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SyncingOverlayHandler Class [ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6966.0824_1\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: ReadOnlyOverlayHandler Class [ OneDrive6] - {9AA2F32D-362A-42D9-9328-24A483E2CCC3}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6966.0824_1\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: UpToDateOverlayHandler Class [ SkyDrive1] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6966.0824_1\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SyncingOverlayHandler Class [ SkyDrive2] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6966.0824_1\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: ErrorOverlayHandler Class [ SkyDrive3] - {BBACC218-34EA-4666-9D7A-C78F2274A524}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Owner\AppData\Local\Microsoft\OneDrive\17.3.6966.0824_1\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) [ SkyDrivePro1 (ErrorConflict)] - {8BA85C75-763B-4103-94EB-9470F12FE0F7}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office 15\root\office15\grooveex.dll =>.Microsoft Corporation®
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) [ SkyDrivePro2 (SyncInProgress)] - {CD55129A-B1A1-438E-A425-CEBC7DC684EE}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office 15\root\office15\grooveex.dll =>.Microsoft Corporation®
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 3 (InSync) [ SkyDrivePro3 (InSync)] - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office 15\root\office15\grooveex.dll =>.Microsoft Corporation®
---\\ Image File Execution Options (18) - 1s
O50 - IFEO:C:\Windows\System32\cscript.exe - (.Microsoft Corporation - Microsoft ® Console Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\dllhost.exe - (.Microsoft Corporation - COM Surrogate.) [DisableExceptionChainValidation\\3] =>.Microsoft Windows®
O50 - IFEO:C:\WINDOWS\System32\drvinst.exe - (.Microsoft Corporation - Driver Installation Module.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\ie4uinit.exe - (.Microsoft Corporation - IE Per-User Initialization Utility.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - IE 7.0 Unattended Install Utility.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mmc.exe - (.Microsoft Corporation - Microsoft Management Console.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\MRT.exe - (.Microsoft Corporation - Microsoft Windows Malicious Software Remova.) [CFGOptions\\1] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Microsoft (R) HTML Application host.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Windows Presentation Foundation Host.) [MitigationOptions\\1118481] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\PrintIsolationHost.exe - (.Microsoft Corporation - PrintIsolationHost.) [MitigationOptions\\2097152] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\rundll32.exe - (.Microsoft Corporation - Windows host process (Rundll32).) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\\4294967296] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\searchprotocolhost.exe - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Spooler SubSystem App.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Spooler SubSystem App.) [MitigationOptions\\2097152] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Host Process for Windows Services.) [MinimumStackCommitInBytes\\32768] =>.Microsoft Windows Publisher®
O50 - IFEO:C:\Windows\System32\wscript.exe - (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
---\\ System Drivers List (78) - 20s
O58 - SDL:2017/03/18 16:56:25 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107424] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135512] =>.Microsoft Windows®
O58 - SDL:2012/09/18 15:51:54 A . (.ASUSTek Computer Inc. - ASUS Charger driver.) -- C:\WINDOWS\System32\drivers\AiCharger.sys [17152] =>.ASUSTeK Computer Inc.®
O58 - SDL:2017/03/18 16:56:25 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [83352] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259488] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [27040] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [132000] =>.Microsoft Windows®
O58 - SDL:2015/05/13 06:44:24 A . (.ASUS - HID driver for ASUS Wireless Radio Control.) -- C:\WINDOWS\System32\drivers\AsHIDSwitch64.sys [19976] =>.Microsoft Windows Hardware Compatibility Publisher®
O58 - SDL:2015/12/14 14:45:00 A . (.ASUS Corporation - Asus TP Filter Driver(X64).) -- C:\WINDOWS\System32\drivers\AsusTP.sys [101368] =>.ASUSTeK Computer Inc.®
O58 - SDL:2017/03/18 16:56:19 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\drivers\athw8x.sys [4233728] =>.Qualcomm Atheros Communications, Inc.
O58 - SDL:2017/03/18 16:56:25 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [9728] =>.Windows (R) Win 7 DDK provider
O58 - SDL:2017/03/18 16:56:23 A . (.QLogic Corporation - QLogic Gigabit Ethernet VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [533920] =>.Microsoft Windows®
O58 - SDL:2015/07/02 15:33:00 A . (.McAfee, Inc. - McAfee Personal Firewall IDS Plugin.) -- C:\WINDOWS\System32\drivers\cfwids.sys [77536] =>.McAfee, Inc.®
O58 - SDL:2017/03/18 16:56:25 A . (.Chelsio Communications - Chelsio iSCSI Crash Dump Driver.) -- C:\WINDOWS\System32\drivers\cht4dx64.sys [102816] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.Chelsio Communications - Chelsio iSCSI VMiniport Driver.) -- C:\WINDOWS\System32\drivers\cht4sx64.sys [347032] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.Chelsio Communications - Virtual Bus Driver for Chelsio ® T4 Chipset.) -- C:\WINDOWS\System32\drivers\cht4vx64.sys [2104224] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:28 A . (.Intel Corporation - Intel(R) Gigabit Adapter NDIS 6.x driver.) -- C:\WINDOWS\System32\drivers\e1i63x64.sys [524800] =>.Intel Corporation
O58 - SDL:2017/03/18 16:56:23 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3419040] =>.Microsoft Windows®
O58 - SDL:2012/08/21 14:01:20 A . (.GEAR Software Inc. - CD DVD Filter.) -- C:\WINDOWS\System32\drivers\GEARAspiWDM.sys [33240] =>.GEAR Software Inc.®
O58 - SDL:2012/07/02 18:16:02 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\HECIx64.sys [62784] =>.Intel Corporation®
O58 - SDL:2015/04/27 08:02:58 A . (.McAfee, Inc. - McAfee HIP IPS Driver.) -- C:\WINDOWS\System32\drivers\HipShieldK.sys [198448] =>.McAfee, Inc.®
O58 - SDL:2017/03/18 16:56:25 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64416] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:28 A . (.Intel(R) Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iagpio.sys [33280] =>.Intel(R) Corporation
O58 - SDL:2017/03/18 16:56:28 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) -- C:\WINDOWS\System32\drivers\iai2c.sys [81408] =>.Intel(R) Corporation
O58 - SDL:2017/03/18 16:56:28 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [70656] =>.Intel Corporation
O58 - SDL:2017/03/18 16:56:28 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [85504] =>.Intel Corporation
O58 - SDL:2017/03/18 16:56:28 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [165376] =>.Intel Corporation
O58 - SDL:2017/03/18 16:56:28 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [168448] =>.Intel Corporation
O58 - SDL:2017/03/18 16:56:23 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] =>.Intel Corporation - Client Components Group®
O58 - SDL:2017/03/18 16:56:19 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [113152] =>.Intel Corporation
O58 - SDL:2012/09/14 01:15:10 A . (.Intel Corporation - Intel Rapid Storage Technology driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorA.sys [647736] =>.Intel Corporation - Intel® Rapid Storage Technology®
O58 - SDL:2017/03/18 16:56:26 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [673184] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:26 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412064] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [526240] =>.Microsoft Windows®
O58 - SDL:2016/05/03 23:30:46 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\igdkmd64.sys [3811288] =>.Intel(R) pGFX®
O58 - SDL:2015/08/21 12:50:48 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\WINDOWS\System32\drivers\IntcDAud.sys [463112] =>.Intel Corporation - Client Components Group®
O58 - SDL:2015/12/01 15:46:03 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\intelaud.sys [50160] =>.Intel(R) Wireless Display®
O58 - SDL:2015/12/01 15:46:03 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\iwdbus.sys [38896] =>.Intel(R) Wireless Display®
O58 - SDL:2012/08/01 23:22:48 A . (. - Keyboard Filter Driver.) -- C:\WINDOWS\System32\drivers\kbfiltr.sys [14992] =>.Dritek System
O58 - SDL:2017/03/18 16:56:25 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [108960] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [123808] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [103328] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82848] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59808] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\MegaSas2i.sys [64416] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575904] =>.Microsoft Windows®
O58 - SDL:2015/07/02 15:33:00 A . (.McAfee, Inc. - McAfee Arbitrary Access Control Driver.) -- C:\WINDOWS\System32\drivers\mfeaack.sys [412440] =>.McAfee, Inc.®
O58 - SDL:2015/07/02 15:33:00 A . (.McAfee, Inc. - Anti-Virus File System Filter Driver.) -- C:\WINDOWS\System32\drivers\mfeavfk.sys [347800] =>.McAfee, Inc.®
O58 - SDL:2015/03/26 12:46:36 A . (. - McAfee Driver Cleaning Driver.) -- C:\WINDOWS\System32\drivers\mfeclnrk.sys [11720] =>.McAfee, Inc.®
O58 - SDL:2015/04/08 07:44:52 A . (.McAfee, Inc. - McAfee Disk Filter Driver.) -- C:\WINDOWS\System32\drivers\mfedisk.sys [101872] =>.McAfee, Inc.®
O58 - SDL:2015/07/02 15:33:00 A . (.McAfee, Inc. - McAfee ELAM Driver.) -- C:\WINDOWS\System32\drivers\mfeelamk.sys [80920] =>.Microsoft Windows Early Launch Anti-malware Publisher®
O58 - SDL:2015/07/02 15:33:00 A . (.McAfee, Inc. - McAfee Core Firewall Engine Driver.) -- C:\WINDOWS\System32\drivers\mfefirek.sys [496888] =>.McAfee, Inc.®
O58 - SDL:2015/07/02 15:33:00 A . (.McAfee, Inc. - McAfee Link Driver.) -- C:\WINDOWS\System32\drivers\mfehidk.sys [875928] =>.McAfee, Inc.®
O58 - SDL:2015/03/26 12:45:54 A . (.McAfee, Inc. - Event Driver.) -- C:\WINDOWS\System32\drivers\mfencbdc.sys [483240] =>.McAfee, Inc.®
O58 - SDL:2015/03/26 12:46:00 A . (.McAfee, Inc. - Detection driver.) -- C:\WINDOWS\System32\drivers\mfencrk.sys [100720] =>.McAfee, Inc.®
O58 - SDL:2015/07/02 15:33:00 A . (.McAfee, Inc. - Anti-Virus Mini-Firewall Driver.) -- C:\WINDOWS\System32\drivers\mfewfpk.sys [344704] =>.McAfee, Inc.®
O58 - SDL:2017/03/18 16:56:25 A . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [842656] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63904] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [108960] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:20 A . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\WINDOWS\System32\drivers\Netwbw02.sys [3485696] =>.Intel Corporation
O58 - SDL:2017/03/18 16:56:25 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150432] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [166304] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [58784] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [61848] =>.Microsoft Windows®
O58 - SDL:2015/07/08 00:25:38 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.40 64-bit Dr.) -- C:\WINDOWS\System32\drivers\rt640x64.sys [895256] =>.Realtek Semiconductor Corp®
O58 - SDL:2013/06/04 09:36:08 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\WINDOWS\System32\drivers\RTKVHD64.sys [3441992] =>.Realtek Semiconductor Corp®
O58 - SDL:2015/07/08 09:27:46 A . (.Realtek Semiconductor Corp. - Realtek Pcie CardReader Driver for 2K/XP/Vi.) -- C:\WINDOWS\System32\drivers\RtsBaStor.sys [321792] =>.Realtek Semiconductor Corp®
O58 - SDL:2017/03/18 16:56:26 A . (...) -- C:\WINDOWS\System32\drivers\SDFRd.sys [31128] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44960] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81824] =>.Microsoft Windows®
O58 - SDL:2016/09/05 06:47:06 A . (.Samsung Electronics Co., Ltd. - SAMSUNG USB Composite Device Driver.) -- C:\WINDOWS\System32\drivers\ssudbus.sys [131712] =>.Samsung Electronics CO., LTD.®
O58 - SDL:2016/09/05 06:47:12 A . (.Samsung Electronics Co., Ltd. - SAMSUNG Android Modem Device Driver.) -- C:\WINDOWS\System32\drivers\ssudmdm.sys [165504] =>.Samsung Electronics CO., LTD.®
O58 - SDL:2017/03/18 16:56:25 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31136] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166816] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305568] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [32160] =>.Microsoft Windows®
O58 - SDL:2017/03/18 16:56:25 A . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [64920] =>.Microsoft Windows®
O58 - SDL:2012/11/19 02:57:58 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\athw8x.sys [3728384] =>.Qualcomm Atheros Communications, Inc.
---\\ Last modified or created user files (1) - 26s
O61 - LFC: 2017/10/15 10:06:47 A . (..) -- C:\Users\Owner\AppData\Roaming\sp_data.sys [74]
---\\ File Associations Shell Spawning (10) - 0s
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\WINDOWS\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\WINDOWS\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.EXE =>.Microsoft Corporation®
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (...) -- %1" %*
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S
---\\ Start Menu Internet (8) - 0s
O68 - StartMenuInternet: <Google Chrome> <Google Chrome> [64Bits][HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer> [64Bits][HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O68 - StartMenuInternet: <Google Chrome> <Google Chrome> [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer> [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: <Google Chrome> <Google Chrome> [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer> [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: <Google Chrome> <Google Chrome> [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer> [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
---\\ Search Browser Infection (2) - 0s
O69 - SBI: SearchScopes [HKCU] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] [NTURL] - () -
http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) -
http://www.bing.com/ =>.Bing.com
---\\ Search Svchost Services (47) - 2s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\WINDOWS\System32\certprop.dll [189952] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\WINDOWS\System32\certprop.dll [189952] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\WINDOWS\System32\srvsvc.dll [303104] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\WINDOWS\System32\gpsvc.dll [1269248] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\WINDOWS\System32\ikeext.dll [934912] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\WINDOWS\System32\iphlpsvc.dll [996864] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\WINDOWS\system32\seclogon.dll [31232] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\WINDOWS\System32\appinfo.dll [138752] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\WINDOWS\System32\iscsiexe.dll [150016] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\WINDOWS\System32\eapsvc.dll [108032] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\WINDOWS\System32\schedsvc.dll [877568] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\System32\wbem\WMIsvc.dll [221696] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\WINDOWS\System32\browser.dll [133120] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\WINDOWS\System32\profsvc.dll [413184] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\WINDOWS\System32\sessenv.dll [385536] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\WINDOWS\System32\wercplsupport.dll [93184] =>.Microsoft Corporation
O83 - Search Svchost Services: shpamsvc (shpamsvc) . (.Microsoft Corporation - SharedPC.AccountManager.) -- C:\WINDOWS\System32\Windows.SharedPC.AccountManager.dll [192512] =>.Microsoft Corporation
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\WINDOWS\System32\XblGameSave.dll [1135104] =>.Microsoft Corporation
O83 - Search Svchost Services: NaturalAuthentication (NaturalAuthentication) . (.Microsoft Corporation - Natural Authentication Service.) -- C:\WINDOWS\System32\NaturalAuth.dll [723968] =>.Microsoft Corporation
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Microsoft® Account Service.) -- C:\WINDOWS\System32\wlidsvc.dll [2153984] =>.Microsoft Corporation
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\WINDOWS\System32\usermgr.dll [877568] =>.Microsoft Corporation
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\WINDOWS\System32\XblAuthManager.dll [1015296] =>.Microsoft Corporation
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - Windows Managent Service DLL.) -- C:\WINDOWS\System32\Windows.Internal.Management.dll [536064] =>.Microsoft Corporation
O83 - Search Svchost Services: xbgm (xbgm) . (.Microsoft Corporation - Xbox Game Monitoring Service.) -- C:\WINDOWS\System32\xbgmsvc.dll [301216] =>.Microsoft Windows Publisher®
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\WINDOWS\System32\themeservice.dll [69632] =>.Microsoft Corporation
O83 - Search Svchost Services: TokenBroker (TokenBroker) . (.Microsoft Corporation - Token Broker.) -- C:\WINDOWS\System32\TokenBroker.dll [1052160] =>.Microsoft Corporation
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Geolocation Service.) -- C:\WINDOWS\System32\lfsvc.dll [43520] =>.Microsoft Corporation
O83 - Search Svchost Services: Irmon (Irmon) . (.Microsoft Corporation - Infrared Monitor.) -- C:\WINDOWS\System32\irmon.dll [24576] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\WINDOWS\System32\rasauto.dll [104448] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINDOWS\System32\rasmans.dll [874496] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\WINDOWS\System32\mprdim.dll [490496] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\WINDOWS\System32\sens.dll [69632] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\WINDOWS\System32\ipnathlp.dll [537600] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\WINDOWS\System32\tapisrv.dll [306688] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\WINDOWS\System32\wuaueng.dll [2445824] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\WINDOWS\System32\qmgr.dll [1159680] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\WINDOWS\System32\shsvcs.dll [612864] =>.Microsoft Corporation
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\WINDOWS\System32\dmwappushsvc.dll [55296] =>.Microsoft Corporation
O83 - Search Svchost Services: wisvc (wisvc) . (.Microsoft Corporation - Flight Settings.) -- C:\WINDOWS\System32\flightsettings.dll [699904] =>.Microsoft Corporation
O83 - Search Svchost Services: WpnService (WpnService) . (.Microsoft Corporation - Windows Push Notification System Service.) -- C:\WINDOWS\System32\WpnService.dll [276480] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\WINDOWS\System32\bdesvc.dll [385536] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\WINDOWS\System32\XboxNetApiSvc.dll [1067008] =>.Microsoft Corporation
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Update Session Orchestrator Core.) -- C:\WINDOWS\System32\usocore.dll [681984] =>.Microsoft Corporation
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Network Setup Service.) -- C:\WINDOWS\System32\NetSetupSvc.dll [261632] =>.Microsoft Corporation
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Device Setup Manager.) -- C:\WINDOWS\System32\DeviceSetupManager.dll [233984] =>.Microsoft Corporation
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Microsoft Network Connectivity Assistant Se.) -- C:\WINDOWS\System32\ncasvc.dll [167424] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxGipSvc (XboxGipSvc) . (.Microsoft Corporation - Xbox Gip Management Service.) -- C:\WINDOWS\System32\XboxGipSvc.dll [18944] =>.Microsoft Corporation
---\\ Product Upgrade Codes (1) - 2s
O90 - PUC: "D2A425F405350054677A7A857BC0E230" . (.Search App by Ask.) -- C:\WINDOWS\Installer\{4F524A2D-5350-4500-76A7-A758B70C2E03}\ToolbarIcon.exe =>PUP.Optional.BrowserTabSearch
---\\ Additional Scan (O88) (12) - 0s
HKLM\SYSTEM\CurrentControlSet\Services\APNMCP =>PUP.Optional.APNToolBar
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe =>PUP.Optional.APNToolBar
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4F524A2D-5350-4500-76A7-7A786E7484D7} =>PUP.Optional.BrowserTabSearch
HKLM\Software\WOW6432Node\Classes\CLSID\{4F524A2D-5350-4500-76A7-7A786E7484D7} =>PUP.Optional.BrowserTabSearch
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4F524A2D-5350-4500-76A7-7A786E7484D7} =>PUP.Optional.BrowserTabSearch
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4F524A2D-5350-4500-76A7-7A786E7484D7} =>PUP.Optional.BrowserTabSearch
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4F524A2D-5350-4500-76A7-A758B70C2E03} =>PUP.Optional.BrowserTabSearch
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4F524A2D-5350-4500-76A7-A758B70C2E03} =>PUP.Optional.BrowserTabSearch
C:\Users\Owner\AppData\Local\AskPartnerNetwork =>PUP.Optional.APNToolBar
C:\WINDOWS\Installer\{4F524A2D-5350-4500-76A7-A758B70C2E03}\ToolbarIcon.exe =>PUP.Optional.BrowserTabSearch
HKLM\Software\Classes\Installer\Products\D2A425F405350054677A7A857BC0E230 =>PUP.Optional.BrowserTabSearch
HKLM\Software\Classes\Installer\Features\D2A425F405350054677A7A857BC0E230 =>PUP.Optional.BrowserTabSearch
---\\ Summary of the elements found (3) - 0s
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.APNToolBar
https://www.nicolascoolman.com/fr/pup-browsertabsearch/ =>PUP.Optional.BrowserTabSearch
https://nicolascoolman.eu/2017/02/23/adware-bandoo/ =>Adware.Bandoo
~ Unselected Options:
~ End of the scan, 37249 items in 06mn11s (1010)(0)