ZHP Diag
~ ZHPDiag v2016.12.11.240 By Nicolas Coolman (2016/12/11)
~ Run by OWNER (Administrator) (2016/12/11 19:00:32)
~ Web:
https://www.nicolascoolman.com
~ Blog:
https://www.anti-malware.top
~ Facebook:
https://www.facebook.com/nicolascoolman1
~ State version:
~ Mode: Scan
~ Report: C:\Users\OWNER\Desktop\ZHPDiag.txt
~ Report: C:\Users\OWNER\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Deactivate
~ System startup: Sans échec avec prise en charge du réseau (Fail-safe with network boot)
Windows 7 Ultimate, 64-bit Service Pack 1 (Build 7601) =>.Microsoft Corporation
---\\ Internet Browsers (3) - 0s
~ GCIE: Google Chrome v56.0.2924.21
~ MFIE: Mozilla Firefox 50.0.2 (x86 en-US)
~ MSIE: Internet Explorer v10.0.9200.17609
---\\ Windows Product Information (4) - 4s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
---\\ Surveillance software (1) - 1s
~ Adobe Flash Player 22 NPAPI (Surveillance)
---\\ Information on the system (6) - 0s
~ Operating System: AMD64 Family 21 Model 2 Stepping 0, AuthenticAMD
~ Operating System: 64-bit
~ Boot mode: Sans échec avec prise en charge du réseau (Fail-safe with network boot)
Total RAM: 8345.236 MB (86% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 108 GB (22%) free of 476 GB : OK =>.Disk Space
---\\ Connection to the system mode (3) - 0s
~ Computer Name: OWNER-PC
~ User Name: OWNER
~ Logged in as Administrator
---\\ Enumeration of the disk units (1) - 0s
~ Drive C: has 108 GB free of 476 GB (System)
---\\ State of the Windows Security Center (11) - 0s
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
---\\ Search Generic System Files (25) - 2s
[MD5.AC4C51EB24AA95B77F705AB159189E24] - 20/11/2010 - (.Microsoft Corporation - Windows Explorer.) -- C:\Windows\Explorer.exe [2872320] =>.Microsoft Corporation
[MD5.DD81D91FF3B0763C392422865C9AC12E] - 13/07/2009 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe [45568] =>.Microsoft Corporation
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - 13/07/2009 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\Windows\System32\Wininit.exe [129024] =>.Microsoft Corporation
[MD5.F34A9FB73E8EF1CC099BCAA5D1E3B716] - 16/12/2015 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\Windows\System32\wininet.dll [2238976] =>.Microsoft Corporation
[MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - 16/07/2014 - (.Microsoft Corporation - Windows Logon Application.) -- C:\Windows\System32\Winlogon.exe [455168] =>.Microsoft Corporation
[MD5.067FA52BFB59A56110A12312EF9AF243] - 20/11/2010 - (.Microsoft Corporation - Software Licensing Library.) -- C:\Windows\System32\sppcomapi.dll [232448] =>.Microsoft Corporation
[MD5.492D07D79E7024CA310867B526D9636D] - 02/03/2011 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\System32\dnsapi.dll [357888] =>.Microsoft Corporation
[MD5.B40420876B9288E0A1C8CCA8A84E5DC9] - 02/03/2011 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\Syswow64\dnsapi.dll [270336] =>Hijacker.DNS.Hosts
[MD5.9A4A1EEE802BF2F878EE8EAB407B21B7] - 13/10/2015 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [497664] =>.Microsoft Corporation
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - 13/07/2009 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [24128] =>.Microsoft Windowsョ
[MD5.B8BD2BB284668C84865658C77574381A] - 13/07/2009 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [92160] =>.Microsoft Corporation
[MD5.F036CE71586E93D94DAB220D7BDF4416] - 20/11/2010 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [147456] =>.Microsoft Corporation
[MD5.9B38580063D281A99E68EF5813022A5F] - 08/09/2016 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [106496] =>.Microsoft Corporation
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - 20/11/2010 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [122368] =>.Microsoft Corporation
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - 13/07/2009 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\Windows\System32\drivers\i8042prt.sys [105472] =>.Microsoft Corporation
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - 13/07/2009 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [116224] =>.Microsoft Corporation
[MD5.25F918BB5D57C99FFEB0255143D0DF9A] - 10/10/2016 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [159744] =>.Microsoft Corporation
[MD5.E47D571FEC2C76E867935109AB2A770C] - 11/05/2016 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [262144] =>.Microsoft Corporation
[MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - 12/04/2013 - (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\drivers\ntfs.sys [1656680] =>.Microsoft Windowsョ
[MD5.0086431C29C35BE1DBC43F52CC273887] - 13/07/2009 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\Windows\System32\drivers\Parport.sys [97280] =>.Microsoft Corporation
[MD5.471815800AE33E6F1C32FB1B97C490CA] - 20/11/2010 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [129536] =>.Microsoft Corporation
[MD5.1B6163C503398B23FF8B939C67747683] - 20/11/2010 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [165888] =>.Microsoft Corporation
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - 13/07/2009 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [93184] =>.Microsoft Corporation
[MD5.AA77EB517D2F07A947294F260E3ACA83] - 13/10/2015 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [118272] =>.Microsoft Corporation
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - 20/11/2010 - (.Microsoft Corporation - Volume Shadow Copy Driver.) -- C:\Windows\System32\drivers\volsnap.sys [295808] =>.Microsoft Windowsョ
---\\ Services not Microsoft (SR=Run, SS=Stop) (16) - 14s
SS - Disabl [10/08/2016] [ 270016] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporatedョ
SS - Disabl [16/09/2016] [ 287112] (AMD External Events Utility) . (.AMD.) - C:\Windows\system32\atiesrxx.exe =>.Advanced Micro Devices, Inc.ョ
SS - Disabl [12/10/2015] [ 351944] AMD FUEL Service (AMD FUEL Service) . (.Advanced Micro Devices, Inc..) - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe =>.Advanced Micro Devices, Inc.ョ
SS - Disabl [16/06/2015] [ 433784] BlueStacks Android Service (BstHdAndroidSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-Service.exe =>.Bluestack Systems, Inc.ョ
SS - Disabl [16/06/2015] [ 413304] BlueStacks Log Rotator Service (BstHdLogRotatorSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe =>.Bluestack Systems, Inc.ョ
SS - Disabl [21/07/2015] [ 831096] BlueStacks Updater Service;gadgetDataDir=C:\ProgramData\Blu (BstHdUpdaterSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe =>.Bluestack Systems, Inc.ョ
SS - Disabl [28/08/2015] [ 144200] Google Update Service (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Incョ
SS - Disabl [28/08/2015] [ 144200] Google Update Service (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Incョ
SS - Disabl [05/04/2016] [ 2550280] LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) . (.LogMeIn Inc..) - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe =>.LogMeIn, Inc.ョ
SS - Disabl [31/07/2014] [ 127752] HitmanPro Scheduler (HitmanProScheduler) . (.SurfRight B.V..) - C:\Program Files\HitmanPro\hmpsched.exe =>.SurfRight B.V.ョ
SS - Disabl [05/04/2016] [ 417552] LMIGuardianSvc (LMIGuardianSvc) . (.LogMeIn, Inc..) - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe =>.LogMeIn, Inc.ョ
SS - Disabl [30/11/2016] [ 172488] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporationョ
SS - Disabl [07/07/2014] [ 70768] Nalpeiron Licensing Service (nlsX86cc) . (.Nalpeiron Ltd..) - C:\Windows\SysWOW64\nlssrv32.exe =>.Nalpeiron Incョ
SS - Disabl [09/01/2015] [ 4374072] SoftEther VPN Client (SEVPNCLIENT) . (.SoftEther VPN Project at University of Tsukuba, Japan.) - C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe =>.SoftEther K.K.ョ
SS - Disabl [23/05/2016] [ 324224] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarlョ
SS - Disabl [23/05/2016] [ 324224] Steam Client Service (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe =>.Valveョ
---\\ Task Planned Automatically (21) - 3s
O39 - APT: Unknown - (.Adobe Inc..) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [324224] =>.Adobe Inc.
O39 - APT: Unknown - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [324224] =>.Google Inc.
O39 - APT: Unknown - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [324224] =>.Google Inc.
O39 - APT: Unknown - (.Adobe Inc..) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [324224] =>.Adobe Inc.
O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\AMD Updater [324224]
O39 - APT: Unknown - (.IObit.) -- C:\Windows\System32\Tasks\CCleanerSkipUAC [324224] =>.IObit
O39 - APT: Unknown - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [324224] =>.Google Inc.
O39 - APT: Unknown - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [324224] =>.Google Inc.
O39 - APT: Unknown - (.Microsoft Corporation.) -- C:\Windows\System32\Tasks\SidebarExecute [324224] =>.Microsoft Corporation
O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{0A419879-A9D4-4082-814A-F36FDE0CA71F} [324224]
O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{155BAE76-F0D7-4B0B-8CA4-8169F3350BAD} [324224]
O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{31789F64-6B41-4888-B118-06F62E982B47} [324224]
O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{33802990-D4AF-4FCD-B413-352904CD37E1} [324224]
O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{395B8B54-1DCC-4D89-B5C5-B83AA920524C} [324224]
O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{4818B540-D086-4B0E-9692-4777D5FFB6E1} [324224]
O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{79417B52-B97C-4187-A43F-ED27EE3514F7} [324224]
O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{798C79DE-8C69-49BE-BC05-9F1D0406861C} [324224]
O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{79D623CB-126D-446F-BC10-F0EAF1AFF3DE} [324224]
O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{7DD725DA-3F70-4955-BC2C-5EFE6E6B081A} [324224]
O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{87025ECC-BC61-4DE0-B1C6-EF8ADB1E4B54} [324224]
O39 - APT: Unknown - (...) -- C:\Windows\System32\Tasks\{91C7824F-6C42-4D5F-8E4A-8B6BB406F230} [324224]
---\\ Auto loading programs from Registry and folders (5) - 1s
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe =>.Microsoft Corporationョ
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Desktop Gadgets.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Desktop Gadgets.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
---\\ Process running (3) - 0s
[MD5.D6F38FD2B90CD7DC139279BB73DD0C7B] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [510920] [PID.1916] =>.Mozilla Corporationョ
[MD5.D6F38FD2B90CD7DC139279BB73DD0C7B] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [510920] [PID.1228] =>.Mozilla Corporationョ
[MD5.CE599CBFD706CC4850BB0F4928940900] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\OWNER\Desktop\ZHPDiag3.exe [2576896] [PID.1116] =>.Nicolas Coolman
---\\ Google Chrome, Start,Search,Extensions (5) - 0s
G0 - GCSP: Secure Preferences [User Data\Default][HomePage]
http://www.google.com =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [bohapeiooecafommnlaiccilacgmkaoc] Sad Panda
G2 - GCE: Preference [User Data\Default] [cfhdojbkjhnklbpkdaibdccddilifddb] __MSG_name__ =>.AdblocPlus Plugin
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.
---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (5) - 2s
M0 - MFSP: prefs.js [OWNER - v88yth1x.default-1396169490810]
http://www.google.com =>.Google Inc.
P2 - EXT FILE: (.Sadpanda 2 - Login to ExH with no problems!.) -- C:\Users\OWNER\AppData\Roaming\Mozilla\Firefox\Profiles\v88yth1x.default-1396169490810\extensions\jid1-7NbXi2AqS1oUFw@jetpack.xpi
P2 - EXT FILE: (.NoScript - Extra protection for your Firefox: NoS.) -- C:\Users\OWNER\AppData\Roaming\Mozilla\Firefox\Profiles\v88yth1x.default-1396169490810\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi =>.NoScript
P2 - FPN: [HKCU] [@unity3d.com/UnityPlayer,version=1.0] - (.Unity Technologies ApS.) -- C:\Users\OWNER\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll =>.Unity Technologies ApS
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll =>.Adobe Systems Incorporated
---\\ Internet Explorer Extensions, Start, Search (17) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ =>.Google Inc.
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = preserve =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKEY_USERS\S-1-5-21-2941685042-3306150061-3194319401-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = preserve =>.Microsoft Corporation
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphan =>.Microsoft Internet Explorer
---\\ Internet Explorer, Proxy Management (7) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation
---\\ Hosts file redirection (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)
---\\ Browser Helper Object (BHO) (2) - 0s
O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (.Orphan.)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} (.Orphan.)
---\\ Global shortcuts Startup (92) - 7s
O4 - GS\Desktop [Administrator]: Discord.lnk . (.Hammer & Chisel, Inc. - Discord.) C:\Users\OWNER\AppData\Local\Discord\app-0.0.296\Discord.exe =>.Hammer & Chisel Inc.ョ
O4 - GS\Desktop [Administrator]: WhoCrashed.lnk . (.Resplendence Software Projects - WhoCrashed.) C:\Users\Default\Desktop\WhoCrashed\WhoCrashedEx.exe =>.Daniel Terhellョ
O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\OWNER\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Administrator]: バンダイナムコオンラインランチャー.lnk . (.Copyright (C) 2012-2015 BANDAI NAMCO Online Inc. - BNOStarter.) C:\Users\OWNER\Desktop\BNO\bno_starter.exe {1121C3C7331D8AA37B3F1272B14448A5C35F}
O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Incョ
O4 - GS\Quicklaunch [Administrator]: HxD.lnk . (.Maël Hörz - HxD Hex Editor.) C:\Program Files (x86)\HxD\HxD.exe =>.Maël Hörz
O4 - GS\Quicklaunch [Administrator]: JDownloader 2.lnk . (.AppWork GmbH - JDownloader 2 Launcher.) C:\Users\OWNER\Desktop\Extra\DL Manager\JDownloader2.exe =>.Appwork GmbHョ
O4 - GS\Quicklaunch [Administrator]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporationョ
O4 - GS\Quicklaunch [Administrator]: Vuze.lnk . (.Azureus Software, Inc - .) C:\Program Files (x86)\Vuze\Azureus.exe =>.Azureus Software, Inc
O4 - GS\sendTo [Administrator]: ATLAS Translation Editor.lnk . (.FUJITSU LIMITED - Translation Editor.) C:\Program Files (x86)\ATLAS V14\Atledit.exe {22C4558DE9DE4208230E72015BE7086A} =>.FUJITSU LIMITED
O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrator]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarlョ
O4 - GS\TaskBar [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporationョ
O4 - GS\TaskBar [Administrator]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporationョ
O4 - GS\TaskBar [Administrator]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\Programs [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporationョ
O4 - GS\Programs [Administrator]: TeamSpeak 3 Client.lnk . (.TeamSpeak Systems GmbH - TeamSpeak 3 Client.) C:\Users\OWNER\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe =>.TeamSpeak Systems GmbHョ
O4 - GS\Programs [Administrator]: バンダイナムコオンラインランチャー.lnk . (.Copyright (C) 2012-2015 BANDAI NAMCO Online Inc. - BNOStarter.) C:\Users\OWNER\Desktop\BNO\bno_starter.exe {1121C3C7331D8AA37B3F1272B14448A5C35F}
O4 - GS\Desktop [Guest]: Discord.lnk . (.Hammer & Chisel, Inc. - Discord.) C:\Users\OWNER\AppData\Local\Discord\app-0.0.296\Discord.exe =>.Hammer & Chisel Inc.ョ
O4 - GS\Desktop [Guest]: WhoCrashed.lnk . (.Resplendence Software Projects - WhoCrashed.) C:\Users\Default\Desktop\WhoCrashed\WhoCrashedEx.exe =>.Daniel Terhellョ
O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\OWNER\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Guest]: バンダイナムコオンラインランチャー.lnk . (.Copyright (C) 2012-2015 BANDAI NAMCO Online Inc. - BNOStarter.) C:\Users\OWNER\Desktop\BNO\bno_starter.exe {1121C3C7331D8AA37B3F1272B14448A5C35F}
O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Incョ
O4 - GS\Quicklaunch [Guest]: HxD.lnk . (.Maël Hörz - HxD Hex Editor.) C:\Program Files (x86)\HxD\HxD.exe =>.Maël Hörz
O4 - GS\Quicklaunch [Guest]: JDownloader 2.lnk . (.AppWork GmbH - JDownloader 2 Launcher.) C:\Users\OWNER\Desktop\Extra\DL Manager\JDownloader2.exe =>.Appwork GmbHョ
O4 - GS\Quicklaunch [Guest]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporationョ
O4 - GS\Quicklaunch [Guest]: Vuze.lnk . (.Azureus Software, Inc - .) C:\Program Files (x86)\Vuze\Azureus.exe =>.Azureus Software, Inc
O4 - GS\sendTo [Guest]: ATLAS Translation Editor.lnk . (.FUJITSU LIMITED - Translation Editor.) C:\Program Files (x86)\ATLAS V14\Atledit.exe {22C4558DE9DE4208230E72015BE7086A} =>.FUJITSU LIMITED
O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Guest]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarlョ
O4 - GS\TaskBar [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporationョ
O4 - GS\TaskBar [Guest]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporationョ
O4 - GS\TaskBar [Guest]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\Programs [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporationョ
O4 - GS\Programs [Guest]: TeamSpeak 3 Client.lnk . (.TeamSpeak Systems GmbH - TeamSpeak 3 Client.) C:\Users\OWNER\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe =>.TeamSpeak Systems GmbHョ
O4 - GS\Programs [Guest]: バンダイナムコオンラインランチャー.lnk . (.Copyright (C) 2012-2015 BANDAI NAMCO Online Inc. - BNOStarter.) C:\Users\OWNER\Desktop\BNO\bno_starter.exe {1121C3C7331D8AA37B3F1272B14448A5C35F}
O4 - GS\Desktop [OWNER]: Discord.lnk . (.Hammer & Chisel, Inc. - Discord.) C:\Users\OWNER\AppData\Local\Discord\app-0.0.296\Discord.exe =>.Hammer & Chisel Inc.ョ
O4 - GS\Desktop [OWNER]: WhoCrashed.lnk . (.Resplendence Software Projects - WhoCrashed.) C:\Users\Default\Desktop\WhoCrashed\WhoCrashedEx.exe =>.Daniel Terhellョ
O4 - GS\Desktop [OWNER]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\OWNER\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [OWNER]: バンダイナムコオンラインランチャー.lnk . (.Copyright (C) 2012-2015 BANDAI NAMCO Online Inc. - BNOStarter.) C:\Users\OWNER\Desktop\BNO\bno_starter.exe {1121C3C7331D8AA37B3F1272B14448A5C35F}
O4 - GS\Quicklaunch [OWNER]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Incョ
O4 - GS\Quicklaunch [OWNER]: HxD.lnk . (.Maël Hörz - HxD Hex Editor.) C:\Program Files (x86)\HxD\HxD.exe =>.Maël Hörz
O4 - GS\Quicklaunch [OWNER]: JDownloader 2.lnk . (.AppWork GmbH - JDownloader 2 Launcher.) C:\Users\OWNER\Desktop\Extra\DL Manager\JDownloader2.exe =>.Appwork GmbHョ
O4 - GS\Quicklaunch [OWNER]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporationョ
O4 - GS\Quicklaunch [OWNER]: Vuze.lnk . (.Azureus Software, Inc - .) C:\Program Files (x86)\Vuze\Azureus.exe =>.Azureus Software, Inc
O4 - GS\sendTo [OWNER]: ATLAS Translation Editor.lnk . (.FUJITSU LIMITED - Translation Editor.) C:\Program Files (x86)\ATLAS V14\Atledit.exe {22C4558DE9DE4208230E72015BE7086A} =>.FUJITSU LIMITED
O4 - GS\sendTo [OWNER]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [OWNER]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarlョ
O4 - GS\TaskBar [OWNER]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporationョ
O4 - GS\TaskBar [OWNER]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporationョ
O4 - GS\TaskBar [OWNER]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\Programs [OWNER]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporationョ
O4 - GS\Programs [OWNER]: TeamSpeak 3 Client.lnk . (.TeamSpeak Systems GmbH - TeamSpeak 3 Client.) C:\Users\OWNER\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe =>.TeamSpeak Systems GmbHョ
O4 - GS\Programs [OWNER]: バンダイナムコオンラインランチャー.lnk . (.Copyright (C) 2012-2015 BANDAI NAMCO Online Inc. - BNOStarter.) C:\Users\OWNER\Desktop\BNO\bno_starter.exe {1121C3C7331D8AA37B3F1272B14448A5C35F}
O4 - GS\Programs [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporationョ
O4 - GS\Programs [Public]: TeamSpeak 3 Client.lnk . (.TeamSpeak Systems GmbH - TeamSpeak 3 Client.) C:\Users\OWNER\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe =>.TeamSpeak Systems GmbHョ
O4 - GS\Programs [Public]: バンダイナムコオンラインランチャー.lnk . (.Copyright (C) 2012-2015 BANDAI NAMCO Online Inc. - BNOStarter.) C:\Users\OWNER\Desktop\BNO\bno_starter.exe {1121C3C7331D8AA37B3F1272B14448A5C35F}
O4 - GS\Accessories [Public]: Command Prompt.lnk . (.Microsoft Corporation - Windows Command Processor.) C:\Windows\system32\cmd.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe -extoff =>.Microsoft Corporationョ
O4 - GS\SystemTools [Public]: Private Character Editor.lnk . (.Microsoft Corporation - Private Character Editor.) C:\Windows\system32\eudcedit.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Windows Calculator.) C:\Windows\system32\calc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - Display Switch.) C:\Windows\system32\displayswitch.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Math Input Panel Accessory.) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - Windows Mobility Center.) C:\Windows\system32\mblctr.exe /open =>.Microsoft Corporation
O4 - GS\Accessories [Public]: NetworkProjection.lnk . (.Microsoft Corporation - Connect to a Network Projector.) C:\Windows\system32\NetProj.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\Windows\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\Windows\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Windows Sound Recorder.) C:\Windows\system32\SoundRecorder.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - Sticky Notes.) C:\Windows\system32\StikyNot.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) C:\Windows\System32\mobsync.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Welcome Center.lnk . (.Microsoft Corporation - Windows host process (Rundll32).) C:\Windows\system32\rundll32.exe %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) C:\Windows\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - Microsoft® Disk Defragmenter.) C:\Windows\system32\dfrgui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - Disk Space Cleanup Manager for Windows.) C:\Windows\system32\cleanmgr.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - Resource and Performance Monitor.) C:\Windows\system32\perfmon.exe /res =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - System Information.) C:\Windows\system32\msinfo32.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - Microsoft® Windows System Restore.) C:\Windows\system32\rstrui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) C:\Windows\system32\taskschd.msc /s =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - Windows Easy Transfer Post Migration Applic.) C:\Windows\system32\migwiz\postmig.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - Windows Easy Transfer Application.) C:\Windows\system32\migwiz\migwiz.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Incョ
O4 - GS\ProgramsCommon [Public]: Media Center.lnk . (.Microsoft Corporation - Windows Media Center.) C:\Windows\ehome\ehshell.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Sidebar.lnk . (.Microsoft Corporation - Windows Desktop Gadgets.) C:\Program Files (x86)\Windows Sidebar\sidebar.exe /showgadgets =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Vuze.lnk . (.Azureus Software, Inc - .) C:\Program Files (x86)\Vuze\Azureus.exe =>.Azureus Software, Inc
O4 - GS\ProgramsCommon [Public]: Windows DVD Maker.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\DVD Maker\DVDMaker.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: XPS Viewer.lnk . (.Microsoft Corporation - XPS Viewer.) C:\Windows\system32\xpsrchvw.exe =>.Microsoft Corporation
---\\ Lop.com/Domain Hijackers (4) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\..\{26F54C70-E6A9-4026-AAE6-12027642A3E0}: DhcpNameServer = 192.168.1.254 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{2B0F3536-45DB-43BD-8D5D-6D24B03F4ECD}: DhcpNameServer = 192.168.1.254 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{26F54C70-E6A9-4026-AAE6-12027642A3E0}: DhcpDomain = attlocal.net
O17 - HKLM\System\CCS\Services\Tcpip\..\{2B0F3536-45DB-43BD-8D5D-6D24B03F4ECD}: DhcpDomain = attlocal.net
---\\ Extra protocols (20) - 0s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporationョ
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporationョ
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporationョ
---\\ Software installed (85) - 20s
O42 - Logiciel: _inmm.dll 2.38 - (..) [HKLM][64Bits] -- _inmm
O42 - Logiciel: 7-Zip 9.20 - (.Igor Pavlov.) [HKLM][64Bits] -- 7-Zip =>.Igor Pavlov
O42 - Logiciel: Adobe Flash Player 21 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX =>.Adobe Systems Incorporatedョ
O42 - Logiciel: Adobe Flash Player 22 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporatedョ
O42 - Logiciel: Aeria Ignite - (.Aeria Games & Entertainment.) [HKLM][64Bits] -- {FE2D627E-D7E0-46EA-93A6-8583420285FA} =>.Aeria Games & Entertainment
O42 - Logiciel: Aeria Ignite - (.Aeria Games & Entertainment.) [HKLM][64Bits] -- Aeria Ignite 1.13.3296 =>.Aeria Games & Entertainment
O42 - Logiciel: Apowersoft Online Launcher version 1.4.4 - (.APOWERSOFT LIMITED.) [HKCU][64Bits] -- {20BF67A8-D81A-4489-8225-FABAA0896E2D}_is1 =>.APOWERSOFT LIMITED
O42 - Logiciel: ATLAS Translation Standard V14.0 Trial Version - (.FUJITSU LIMITED.) [HKLM][64Bits] -- {6652750B-AA69-49B7-9D09-C0A28B6FFC9F} =>.FUJITSU LIMITED
O42 - Logiciel: AutoHotkey 1.0.48.05 - (.Chris Mallett.) [HKLM][64Bits] -- AutoHotkey
O42 - Logiciel: BlueStacks App Player - (.BlueStack Systems, Inc..) [HKLM][64Bits] -- BlueStacks App Player =>.Bluestack Systems, Inc.ョ
O42 - Logiciel: BlueStacks Notification Center - (.BlueStack Systems, Inc..) [HKLM][64Bits] -- {4FCF716C-CEB4-499D-AFB8-A5375105EC2A} =>.BlueStack Systems, Inc.
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>.Piriform Ltdョ
O42 - Logiciel: ChuSingura46+1 S - (.インレ.) [HKLM][64Bits] -- Steam App 464780 =>.Valveョ
O42 - Logiciel: CPUID CPU-Z 1.71 - (..) [HKLM][64Bits] -- CPUID CPU-Z_is1
O42 - Logiciel: Creatures of Darkness - (.Screaming Bee.) [HKLM][64Bits] -- {573F9269-A022-4C6F-97BD-CF1316A76369} =>.Screaming Bee
O42 - Logiciel: Cybertroopers Virtual-ON version PC - (.Installer by TheArcadeStriker - Game by SEGA.) [HKLM][64Bits] -- {379E152B-4215-44D7-ADBC-DC280791A042}_is1
O42 - Logiciel: Deep Space Voices - (.Screaming Bee.) [HKLM][64Bits] -- {67CEC218-B250-4B4C-B23F-A597EC8DB153} =>.Screaming Bee
O42 - Logiciel: Dies irae -Amantes amentes- - (.株式会社グリーンウッド.) [HKLM][64Bits] -- {91F5A357-7173-408C-85B7-FAAC69B5AD22}
O42 - Logiciel: Dies irae -Amantes amentes- - (.株式会社グリーンウッド.) [HKLM][64Bits] -- InstallShield_{91F5A357-7173-408C-85B7-FAAC69B5AD22}
O42 - Logiciel: Discord - (.Hammer & Chisel, Inc..) [HKCU][64Bits] -- Discord =>.Hammer & Chisel Inc.ョ
O42 - Logiciel: Etron USB3.0 Host Controller - (.Etron Technology.) [HKLM][64Bits] -- {DFBB738C-71D8-4DC5-B8D2-D65C37680E27} =>.Etron Technology
O42 - Logiciel: Etron USB3.0 Host Controller - (.Etron Technology.) [HKLM][64Bits] -- InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27} =>.Etron Technology
O42 - Logiciel: Fantasy Voice Pack - (.Screaming Bee.) [HKLM][64Bits] -- {5F4C3E1F-87FC-41BD-B219-E4156BBD8AE5} =>.Screaming Bee
O42 - Logiciel: FINAL FANTASY XIV - A Realm Reborn - (.SQUARE ENIX CO., LTD..) [HKLM][64Bits] -- {2B41E132-07DF-4925-A3D3-F2D1765CCDFE} =>.SQUARE ENIX CO., LTD.
O42 - Logiciel: Fraps - (.Beepa.) [HKLM][64Bits] -- Fraps
O42 - Logiciel: Galactic Voices - (.Screaming Bee.) [HKLM][64Bits] -- {891D8FC9-726D-46F2-ADC0-E060A6EB1DC3} =>.Screaming Bee
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome =>.Google Incョ
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: HitmanPro 3.7 - (.SurfRight B.V..) [HKLM][64Bits] -- HitmanPro37 =>.SurfRight B.V.
O42 - Logiciel: HxD Hex Editor version 1.7.7.0 - (.Ma・ Hz.) [HKLM][64Bits] -- HxD Hex Editor_is1
O42 - Logiciel: Java 7 Update 79 (64-bit) - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F06417079FF} =>.Oracle
O42 - Logiciel: K-Lite Mega Codec Pack 10.0.5 - (.KLite Inc.) [HKLM][64Bits] -- KLiteCodecPack_is1 =>.KLite Inc
O42 - Logiciel: LogMeIn Hamachi - (.LogMeIn, Inc..) [HKLM][64Bits] -- {446B150E-993B-4D5B-BA82-3C496B5F62D5} =>.LogMeIn, Inc.
O42 - Logiciel: LogMeIn Hamachi - (.LogMeIn, Inc..) [HKLM][64Bits] -- LogMeIn Hamachi =>.LogMeIn, Inc.
O42 - Logiciel: Male Voice Pack - (.Screaming Bee.) [HKLM][64Bits] -- {71DD9C2C-3C7A-4B8D-AA36-C5C528A0CD69} =>.Screaming Bee
O42 - Logiciel: MeCab 0.98 - (.Taku Kudo.) [HKLM][64Bits] -- MeCab_is1
O42 - Logiciel: Microsoft Games for Windows - LIVE - (.Microsoft Corporation.) [HKLM][64Bits] -- {A1C962E2-2426-49C6-A38B-9A07E40D607C} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM][64Bits] -- {2AA3C13E-0531-41B8-AE48-AE28C940A809} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Security Client =>.Microsoft Corporationョ
O42 - Logiciel: MorphVOX Pro - (.Screaming Bee.) [HKLM][64Bits] -- {1DDBB040-3BEB-4057-90BB-B38B5E081D1B} =>.Screaming Bee
O42 - Logiciel: Mozilla Firefox 50.0.2 (x86 en-US) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 50.0.2 (x86 en-US) =>.Mozilla Corporationョ
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService =>.Mozilla
O42 - Logiciel: Mudfish Cloud VPN v4.4.3 - (.Mudfish Networks.) [HKLM][64Bits] -- Mudfish Cloud VPN
O42 - Logiciel: Personality Voices - (.Screaming Bee.) [HKLM][64Bits] -- {4B886E97-AF5B-46F0-9F48-6BE03149D972} =>.Screaming Bee
O42 - Logiciel: PHANTASY STAR ONLINE 2 - (.SEGA.) [HKLM][64Bits] --
http://pso2.jp/appid/release_is1 {5F4DF13A2D7701135FA8FAB4934015A9} =>.SEGA
O42 - Logiciel: puush - (.Dean Herbert.) [HKLM][64Bits] -- {C3592426-531E-4110-911D-BFECE2CE284B} =>.Dean Herbert
O42 - Logiciel: Python 2.7.12 - (.Python Software Foundation.) [HKLM][64Bits] -- {9DA28CE5-0AA5-429E-86D8-686ED898C665} =>.Python Software Foundation
O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} =>.Realtek Semiconductor Corpョ
O42 - Logiciel: RGSS-RTP 1.03 - (.Enterbrain Inc..) [HKLM][64Bits] -- RGSS-RTP
O42 - Logiciel: RPG Maker VX RTP - (.Enterbrain.) [HKLM][64Bits] -- RPG Maker VX RTP_is1 =>.Enterbrain
O42 - Logiciel: Sci-Fi Voice Pack - (.Screaming Bee.) [HKLM][64Bits] -- {BC038C91-D3C6-4E43-8439-B65976FE7937} =>.Screaming Bee
O42 - Logiciel: sdrt(5.0, 64bit) - (.パルティオソフト株式会社.) [HKLM][64Bits] -- {63A3DBCF-FB40-4398-9AE5-94EE6206CE12}
O42 - Logiciel: Skype™ 7.26 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {FC965A47-4839-40CA-B618-18F486F042C6} =>.Skype Technologies S.A.
O42 - Logiciel: SoftEther VPN Client - (.SoftEther VPN Project.) [HKLM][64Bits] -- softether_sevpnclient =>.SoftEther K.K.ョ
O42 - Logiciel: Soulworker Patcher - (.MiyuPatcher.) [HKCU][64Bits] -- 4f8fec11a5e6e736
O42 - Logiciel: SpeedFan (remove only) - (.Almico Software.) [HKLM][64Bits] -- SpeedFan =>.Almico Software
O42 - Logiciel: Steam - (.Valve Corporation.) [HKLM][64Bits] -- {048298C9-A4D3-490B-9FF9-AB023A9238F3} =>.Valve Corporation
O42 - Logiciel: TeamSpeak 3 Client - (.TeamSpeak Systems GmbH.) [HKCU][64Bits] -- TeamSpeak 3 Client =>.TeamSpeak Systems GmbH
O42 - Logiciel: Ultimate Knight ƒEƒBƒ“ƒ_ƒ€XP - (..) [HKLM][64Bits] -- {D5C424A1-5C0A-426C-BB0B-D75907243EC3}
O42 - Logiciel: Unity Web Player - (.Unity Technologies ApS.) [HKCU][64Bits] -- UnityWebPlayer =>.Unity Technologies ApS
O42 - Logiciel: Unity Web Player (x64) (All users) - (.Unity Technologies ApS.) [HKLM][64Bits] -- UnityWebPlayer =>.Unity Technologies ApS
O42 - Logiciel: VirtualCloneDrive - (.Elaborate Bytes.) [HKLM][64Bits] -- VirtualCloneDrive =>.Elaborate Bytes
O42 - Logiciel: Visual Studio 2012 x64 Redistributables - (.AVG Technologies.) [HKLM][64Bits] -- {8C775E70-A791-4DA8-BCC3-6AB7136F4484} =>.AVG Technologies
O42 - Logiciel: Visual Studio 2012 x86 Redistributables - (.AVG Technologies CZ, s.r.o..) [HKLM][64Bits] -- {98EFF19A-30AB-4E4B-B943-F06B1C63EBF8} =>.AVG Technologies CZ, s.r.o.
O42 - Logiciel: VLC media player 1.1.11 - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
O42 - Logiciel: Vulkan Run Time Libraries 1.0.17.0 - (.LunarG, Inc..) [HKLM][64Bits] -- VulkanRT1.0.17.0 =>.LunarG, Inc.ョ
O42 - Logiciel: Vulkan Run Time Libraries 1.0.26.0 - (.LunarG, Inc..) [HKLM][64Bits] -- VulkanRT1.0.26.0 =>.LunarG, Inc.ョ
O42 - Logiciel: Vulkan Run Time Libraries 1.0.3.1 - (.LunarG, Inc..) [HKLM][64Bits] -- VulkanRT1.0.3.1 =>.LunarG, Inc.
O42 - Logiciel: Vuze - (.Azureus Software, Inc..) [HKLM][64Bits] -- 8461-7759-5462-8226 =>.Azureus Software, Inc.ョ
O42 - Logiciel: WhoCrashed 5.53 - (.Resplendence Software Projects Sp..) [HKLM][64Bits] -- WhoCrashed_is1 =>.Resplendence Software Projects Sp.
O42 - Logiciel: WinRAR 5.31 beta 1 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver =>.win.rar GmbHョ
O42 - Logiciel: XSplit Gamecaster - (.SplitmediaLabs.) [HKLM][64Bits] -- {4EDB1851-7427-4324-AAAA-9E3852C73DAE} =>.SplitMediaLabs
O42 - Logiciel: いろとりどりのセカイ - (.FAVORITE.) [HKLM][64Bits] -- {3DC8D5BA-E704-402F-88F0-E22BF4C41F6F}
O42 - Logiciel: ソウルワーカー - (.NHN PlayArt Corp..) [HKLM][64Bits] -- ソウルワーカー
O42 - Logiciel: バンダイナムコオンラインランチャー - (.株式会社バンダイナムコオンライン.) [HKLM][64Bits] -- bno_starter {1121C3C7331D8AA37B3F1272B14448A5C35F}
O42 - Logiciel: ユニオリズム・カルテット A3-DAYS - (.CLIPCRAFT.) [HKLM][64Bits] -- UQA3
O42 - Logiciel: 機動戦士ガンダムオンライン - (.株式会社バンダイナムコオンライン.) [HKLM][64Bits] -- Olive_is1
O42 - Logiciel: 神咒神威神楽 曙之光 - (.株式会社グリーンウッド.) [HKLM][64Bits] -- {E836AF82-7D3E-415F-BB09-0A124EF73909}
O42 - Logiciel: 神咒神威神楽 曙之光 - (.株式会社グリーンウッド.) [HKLM][64Bits] -- InstallShield_{E836AF82-7D3E-415F-BB09-0A124EF73909}
O42 - Logiciel: 相州戦神館學園 八命陣 - (.株式会社グリーンウッド.) [HKLM][64Bits] -- {BC30387C-AA5F-427F-A64D-E4F27374C7CA}
O42 - Logiciel: 相州戦神館學園 万仙陣 - (.株式会社グリーンウッド.) [HKLM][64Bits] -- {47CE86AC-FC80-4C08-A389-41CF2AE1519A}
O42 - Logiciel: 大迷宮&大迷惑 - (.(c)Liar-soft/HOBIBOX.) [HKLM][64Bits] -- {12BB3C50-4D4F-4D1F-8217-527477FEC813}
O42 - Logiciel: 凍京NECRO - (.Nitroplus.) [HKLM][64Bits] -- {96448B65-910B-41D9-8CC9-3E6BBC6B299D}
O42 - Logiciel: セイバーフィッシュ- - (..) [HKLM][64Bits] -- JHPCIPOOIKKLILEOCNJDPHJGFPICMGJCIGIPGPICLFICPAILIBICNPICOJIDEJIDJDIDGJJCECCN
---\\ HKCU & HKLM Software Keys (178) - 20s
HKLM\SOFTWARE\Wow6432Node\7-Zip =>.Igor Pavlov
HKLM\SOFTWARE\Wow6432Node\Adware Removal Tool by TSA
HKLM\SOFTWARE\Wow6432Node\AMD =>.AMD
HKLM\SOFTWARE\Wow6432Node\ATI =>.ATI
HKLM\SOFTWARE\Wow6432Node\ATI Technologies =>.ATI Technologies
HKLM\SOFTWARE\Wow6432Node\AutoHotkey
HKLM\SOFTWARE\Wow6432Node\AVG SafeGuard toolbar
HKLM\SOFTWARE\Wow6432Node\AVG Web TuneUp =>.AVG Web TuneUp
HKLM\SOFTWARE\Wow6432Node\Avnex
HKLM\SOFTWARE\Wow6432Node\Bethesda Softworks =>.Bethesda Softworks
HKLM\SOFTWARE\Wow6432Node\BlueStacks =>.BlueStack Systems, Inc.
HKLM\SOFTWARE\Wow6432Node\Caphyon =>.Caphyon
HKLM\SOFTWARE\Wow6432Node\DT Soft =>.DT Soft Ltd
HKLM\SOFTWARE\Wow6432Node\Elaborate Bytes =>.Elaborate Bytes
HKLM\SOFTWARE\Wow6432Node\Enterbrain =>.Enterbrain
HKLM\SOFTWARE\Wow6432Node\FAVORITE
HKLM\SOFTWARE\Wow6432Node\FFOnline
HKLM\SOFTWARE\Wow6432Node\Fraps =>.Beepa
HKLM\SOFTWARE\Wow6432Node\Fujitsu =>.Fujitsu
HKLM\SOFTWARE\Wow6432Node\g3n-h@ckm@n =>.g3n-h@ckm@n
HKLM\SOFTWARE\Wow6432Node\GGS =>.GGS
HKLM\SOFTWARE\Wow6432Node\GNU =>.GNU
HKLM\SOFTWARE\Wow6432Node\GOG.com =>.GOG.com
HKLM\SOFTWARE\Wow6432Node\Google =>.Google
HKLM\SOFTWARE\Wow6432Node\HanPurple
HKLM\SOFTWARE\Wow6432Node\IM Providers =>.IM Providers
HKLM\SOFTWARE\Wow6432Node\Intel =>.Intel
HKLM\SOFTWARE\Wow6432Node\irori
HKLM\SOFTWARE\Wow6432Node\Key
HKLM\SOFTWARE\Wow6432Node\Khronos =>.Khronos
HKLM\SOFTWARE\Wow6432Node\KLCodecPack =>.KLite Inc
HKLM\SOFTWARE\Wow6432Node\LAV =>.LAV Inc
HKLM\SOFTWARE\Wow6432Node\light =>.Light
HKLM\SOFTWARE\Wow6432Node\LogMeIn Hamachi =>.LogMeIn Entreprise
HKLM\SOFTWARE\Wow6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\Wow6432Node\Malwarebytes Anti-Rootkit =>.Malwarebytes
HKLM\SOFTWARE\Wow6432Node\McAfee.com =>.McAfee Inc.
HKLM\SOFTWARE\Wow6432Node\MeCab
HKLM\SOFTWARE\Wow6432Node\MimarSinan =>.Mimar Sinan
HKLM\SOFTWARE\Wow6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\Nalpeiron =>.Nalpeiron
HKLM\SOFTWARE\Wow6432Node\Nitroplus
HKLM\SOFTWARE\Wow6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\Wow6432Node\onOne Software =>.onOne Software
HKLM\SOFTWARE\Wow6432Node\Paltiosoft
HKLM\SOFTWARE\Wow6432Node\Playcoo
HKLM\SOFTWARE\Wow6432Node\Realtek =>.Realtek
HKLM\SOFTWARE\Wow6432Node\SAGAPLANETS
HKLM\SOFTWARE\Wow6432Node\Screaming Bee =>.Screaming Bee
HKLM\SOFTWARE\Wow6432Node\Sega2
HKLM\SOFTWARE\Wow6432Node\Skype =>.Skype
HKLM\SOFTWARE\Wow6432Node\SoftDenchi
HKLM\SOFTWARE\Wow6432Node\SoftEther Project =>.SoftEther Project
HKLM\SOFTWARE\Wow6432Node\SpeedFan =>.Almico Software
HKLM\SOFTWARE\Wow6432Node\SplitmediaLabs =>.SplitMediaLabs
HKLM\SOFTWARE\Wow6432Node\SquareEnix =>.SquareEnix
HKLM\SOFTWARE\Wow6432Node\StepMania 5
HKLM\SOFTWARE\Wow6432Node\ukwxp
HKLM\SOFTWARE\Wow6432Node\Valve =>.Valve
HKLM\SOFTWARE\Wow6432Node\VideoLAN =>.VideoLAN
HKLM\SOFTWARE\Wow6432Node\Volatile =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\WafCX =>.WafCX
HKLM\SOFTWARE\Wow6432Node\Wondershare =>.Wondershare
HKLM\SOFTWARE\Wow6432Node\Wow6432Node =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\wtu =>.WTU
HKLM\SOFTWARE\Wow6432Node\Wuji
HKLM\SOFTWARE\Wow6432Node\げーせん18
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\7-Zip =>.Igor Pavlov
HKCU\SOFTWARE\Aeria Games =>.Aeria Games
HKCU\SOFTWARE\AhnLab =>.AhnLab Inc.
HKCU\SOFTWARE\AIDA
HKCU\SOFTWARE\AI_RecycleBin =>.Legitimate
HKCU\SOFTWARE\AMD =>.AMD
HKCU\SOFTWARE\AMD Driver Downloader
HKCU\SOFTWARE\Apowersoft =>.Apowersoft
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\Apple Computer, Inc. =>.Apple Computer, Inc.
HKCU\SOFTWARE\Apple Inc. =>.Apple Inc.
HKCU\SOFTWARE\ATI =>.ATI
HKCU\SOFTWARE\AutoHotkey
HKCU\SOFTWARE\Avg =>.AVG Software
HKCU\SOFTWARE\AVG SafeGuard toolbar
HKCU\SOFTWARE\AVG SafePrice =>.AVG Software
HKCU\SOFTWARE\Avg Secure Update =>.AVG Software
HKCU\SOFTWARE\AVG Web TuneUp =>.AVG Web TuneUp
HKCU\SOFTWARE\Azureus
HKCU\SOFTWARE\BitComet =>.BitComet (P2P)
HKCU\SOFTWARE\BNO
HKCU\SOFTWARE\Burda
HKCU\SOFTWARE\CLIPCRAFT
HKCU\SOFTWARE\DefaultCompany =>.Unity
HKCU\SOFTWARE\DT Soft =>.DT Soft Ltd
HKCU\SOFTWARE\ej-technologies =>.ej-technologies
HKCU\SOFTWARE\Elaborate Bytes =>.Elaborate Bytes
HKCU\SOFTWARE\Enterbrain =>.Enterbrain
HKCU\SOFTWARE\Football News App
HKCU\SOFTWARE\Fraps3 =>.Beepa
HKCU\SOFTWARE\Fujitsu =>.Fujitsu
HKCU\SOFTWARE\g3n-h@ckm@n =>.g3n-h@ckm@n
HKCU\SOFTWARE\Gabest =>.Gabest
HKCU\SOFTWARE\GGS =>.GGS
HKCU\SOFTWARE\GNU =>.GNU
HKCU\SOFTWARE\GOG.com =>.GOG.com
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\HADASHI
HKCU\SOFTWARE\HANPURPLE
HKCU\SOFTWARE\HmelyoffLabs =>.Hmelyoff Labs
HKCU\SOFTWARE\Icaros =>.Icaros
HKCU\SOFTWARE\illusion
HKCU\SOFTWARE\IM Providers =>.IM Providers
HKCU\SOFTWARE\INCAInternet =>.INCAInternet
HKCU\SOFTWARE\Inre
HKCU\SOFTWARE\irori
HKCU\SOFTWARE\JavaSoft =>.JavaSoft
HKCU\SOFTWARE\KanColleTool
HKCU\SOFTWARE\KID
HKCU\SOFTWARE\KISS
HKCU\SOFTWARE\Lagarith =>.Lagarith
HKCU\SOFTWARE\Liar
HKCU\SOFTWARE\light =>.Light
HKCU\SOFTWARE\Macromedia =>.Macromedia
HKCU\SOFTWARE\madshi =>.madshi.net
HKCU\SOFTWARE\Magnet =>.Magnet
HKCU\SOFTWARE\Malwarebytes Anti-Rootkit =>.Malwarebytes
HKCU\SOFTWARE\MCAFEE =>.McAfee Inc.
HKCU\SOFTWARE\MeCab
HKCU\SOFTWARE\MediaInfo =>.Jérôme Martinez
HKCU\SOFTWARE\Mozilla =>.Mozilla
HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKCU\SOFTWARE\Mumble =>.Mumble
HKCU\SOFTWARE\Nitroplus
HKCU\SOFTWARE\Piriform =>.Piriform
HKCU\SOFTWARE\puush
HKCU\SOFTWARE\Python =>.Python
HKCU\SOFTWARE\QtProject =>.QtProject
HKCU\SOFTWARE\Raptr =>.Raptr
HKCU\SOFTWARE\Resplendence Sp =>.Resplendence Software
HKCU\SOFTWARE\RightBrainGames
HKCU\SOFTWARE\Section Studios, Inc.
HKCU\SOFTWARE\SETTEC
HKCU\SOFTWARE\SimonTatham =>.Simon Tatham
HKCU\SOFTWARE\Skype =>.Skype
HKCU\SOFTWARE\SoftEther Project =>.SoftEther Project
HKCU\SOFTWARE\SpeedFan =>.Almico Software
HKCU\SOFTWARE\SplitmediaLabs =>.SplitMediaLabs
HKCU\SOFTWARE\sshelper6
HKCU\SOFTWARE\StepMania 5
HKCU\SOFTWARE\TeamPsykskallar =>.Team Psykskallar
HKCU\SOFTWARE\TeamSpeak 3 Client =>.TeamSpeak
HKCU\SOFTWARE\TesSafe
HKCU\SOFTWARE\Trolltech =>.Trolltech
HKCU\SOFTWARE\unicorn-a
HKCU\SOFTWARE\Unity =>.Unity
HKCU\SOFTWARE\University of Tsukuba =>.University of Tsukuba
HKCU\SOFTWARE\Valve =>.Valve
HKCU\SOFTWARE\Vebanaul
HKCU\SOFTWARE\WinRAR =>.WinRAR
HKCU\SOFTWARE\WinRAR SFX =>.RarLab
HKCU\SOFTWARE\Wintertree =>.Wintertree Software
HKCU\SOFTWARE\Wondershare =>.Wondershare
HKCU\SOFTWARE\WordPad+
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\WuJi
HKCU\SOFTWARE\YandereDev
HKCU\SOFTWARE\Yanderu Software
HKCU\SOFTWARE\ZebHelpProcess Helper =>.Nicolas Coolman
HKCU\SOFTWARE\Zemana =>.Zemana
HKCU\SOFTWARE\アトリエかぐや
HKCU\SOFTWARE\アプリケーション ウィザードで生成されたローカル アプリケーション
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKCU\SOFTWARE\AppDataLow\Software\JavaSoft =>.JavaSoft
HKCU\SOFTWARE\AppDataLow\Software\Unity =>.Unity
---\\ Contents of the Common Files folders (338) - 51s
O43 - CFD: 16/11/2016 - [] D -- C:\Program Files\AMD =>.AMD
O43 - CFD: 25/10/2014 - [] D -- C:\Program Files\ATI =>.ATI
O43 - CFD: 20/12/2014 - [] D -- C:\Program Files\ATI Technologies =>.ATI Technologies
O43 - CFD: 18/11/2016 - [] D -- C:\Program Files\CCleaner =>.Piriform
O43 - CFD: 11/12/2016 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 25/10/2014 - [] D -- C:\Program Files\CPUID =>.CPUID Inc
O43 - CFD: 02/02/2013 - [] D -- C:\Program Files\DVD Maker =>.Aone Software
O43 - CFD: 04/05/2016 - [] D -- C:\Program Files\HitmanPro =>.EIDOS hitman Game
O43 - CFD: 13/01/2016 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 19/11/2016 - [] D -- C:\Program Files\Java =>.Oracle
O43 - CFD: 13/07/2009 - [] D -- C:\Program Files\Microsoft Games =>.Microsoft Corporation
O43 - CFD: 10/12/2016 - [] D -- C:\Program Files\Microsoft Security Client =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 26/07/2016 - [] D -- C:\Program Files\SoftDenchi
O43 - CFD: 10/12/2016 - [] D -- C:\Program Files\SoftEther VPN Client =>.SoftEther
O43 - CFD: 13/07/2009 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 22/11/2014 - [] D -- C:\Program Files\Unity =>.Unity
O43 - CFD: 07/11/2016 - [] D -- C:\Program Files\Vuze =>.Vuze (P2P)
O43 - CFD: 16/07/2013 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 11/05/2016 - [] D -- C:\Program Files\Windows Journal =>.Microsoft Corporation
O43 - CFD: 02/02/2013 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 13/10/2016 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 02/02/2013 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 02/02/2013 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 02/02/2013 - [] D -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 04/05/2016 - [] D -- C:\Program Files\WinRAR =>.win.rar GmbHョ
O43 - CFD: 26/05/2015 - [] D -- C:\Program Files (x86)\7-Zip =>.Igor Pavlov
O43 - CFD: 11/12/2016 - [] D -- C:\Program Files (x86)\Adware Removal Tool by TSA
O43 - CFD: 03/06/2014 - [] D -- C:\Program Files (x86)\Aeria Games =>.Aeria Games and Entertainmentョ
O43 - CFD: 16/11/2016 - [] D -- C:\Program Files (x86)\AMD =>.AMD
O43 - CFD: 20/12/2014 - [] D -- C:\Program Files (x86)\AMD AVT =>.Advanced Micro Devices Inc
O43 - CFD: 06/09/2008 - [] D -- C:\Program Files (x86)\ATLAS V14 {22C4558DE9DE4208230E72015BE7086A}
O43 - CFD: 02/02/2015 - [] D -- C:\Program Files (x86)\AutoHotkey =>.Chicony Multimedia
O43 - CFD: 25/07/2015 - [] D -- C:\Program Files (x86)\BlueStacks =>.BlueStack Systems, Inc.
O43 - CFD: 11/12/2016 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 08/05/2013 - [] D -- C:\Program Files (x86)\DAEMON Tools Lite =>.DAEMON Tools
O43 - CFD: 02/02/2013 - [] D -- C:\Program Files (x86)\Elaborate Bytes =>.Elaborate Bytes
O43 - CFD: 22/12/2013 - [] D -- C:\Program Files (x86)\Enterbrain =>.Enterbrain
O43 - CFD: 25/10/2014 - [] D -- C:\Program Files (x86)\Etron Technology =>.Etron Technology
O43 - CFD: 12/05/2013 - [] D -- C:\Program Files (x86)\FAVORITE
O43 - CFD: 16/10/2015 - [] D -- C:\Program Files (x86)\Google =>.Google Incョ
O43 - CFD: 27/08/2016 - [] D -- C:\Program Files (x86)\HxD
O43 - CFD: 26/07/2016 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield Software
O43 - CFD: 13/01/2016 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 08/10/2013 - [] D -- C:\Program Files (x86)\K-Lite Codec Pack =>.KLite Inc
O43 - CFD: 13/10/2016 - [] D -- C:\Program Files (x86)\Liar
O43 - CFD: 05/12/2016 - [] D -- C:\Program Files (x86)\light =>.Light
O43 - CFD: 04/05/2016 - [] D -- C:\Program Files (x86)\LogMeIn Hamachi =>.LogMeIn Entreprise
O43 - CFD: 06/09/2015 - [] D -- C:\Program Files (x86)\MeCab
O43 - CFD: 10/12/2016 - [] D -- C:\Program Files (x86)\Microsoft Security Client =>.Microsoft Corporation
O43 - CFD: 21/03/2013 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 30/11/2016 - [] D -- C:\Program Files (x86)\Mozilla Firefox =>.Mozilla
O43 - CFD: 30/11/2016 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service =>.Mozilla
O43 - CFD: 13/07/2009 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 10/12/2016 - [] D -- C:\Program Files (x86)\Mudfish Cloud VPN
O43 - CFD: 26/07/2016 - [] D -- C:\Program Files (x86)\Nitroplus
O43 - CFD: 29/11/2014 - [] D -- C:\Program Files (x86)\puush =>.Dean Herbertョ
O43 - CFD: 29/08/2014 - [] D -- C:\Program Files (x86)\Realtek =>.Realtek
O43 - CFD: 13/07/2009 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 11/05/2013 - [] D -- C:\Program Files (x86)\SAGAPLANETS
O43 - CFD: 13/04/2016 - [] D -- C:\Program Files (x86)\Screaming Bee =>.Screaming Bee
O43 - CFD: 09/05/2015 - [] D -- C:\Program Files (x86)\SEGA {5F4DF13A2D7701135FA8FAB4934015A9} =>.SEGA
O43 - CFD: 03/08/2016 - [] RD -- C:\Program Files (x86)\Skype =>.Skype
O43 - CFD: 26/07/2016 - [] D -- C:\Program Files (x86)\SoftDenchi
O43 - CFD: 12/09/2016 - [] D -- C:\Program Files (x86)\softhouse-seal
O43 - CFD: 09/12/2016 - [] D -- C:\Program Files (x86)\SpeedFan =>.Almico Software
O43 - CFD: 17/08/2013 - [] D -- C:\Program Files (x86)\SquareEnix =>.SQUARE ENIX CO., LTD.ョ
O43 - CFD: 09/12/2016 - [] D -- C:\Program Files (x86)\Steam =>.SteamApps
O43 - CFD: 23/02/2013 - [0] D -- C:\Program Files (x86)\Temp =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] HD -- C:\Program Files (x86)\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 13/08/2013 - [] D -- C:\Program Files (x86)\VideoLAN =>.VideoLAN
O43 - CFD: 16/11/2016 - [] D -- C:\Program Files (x86)\VulkanRT =>.LunarG, Inc
O43 - CFD: 16/07/2013 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 02/02/2013 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 13/10/2016 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 02/02/2013 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 02/02/2013 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 02/02/2013 - [] D -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 27/08/2016 - [] D -- C:\Program Files (x86)\_inmm
O43 - CFD: 04/09/2015 - [] D -- C:\Program Files (x86)\セイバーフィッシュ
O43 - CFD: 26/05/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip =>.Igor Pavlov
O43 - CFD: 30/01/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 02/02/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 03/06/2014 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AeriaGames =>.AeriaGames
O43 - CFD: 16/11/2016 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Settings =>.Samsung Electronics
O43 - CFD: 06/09/2008 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ATLAS V14.0 Trial Version
O43 - CFD: 02/02/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoHotkey =>.Chicony Multimedia
O43 - CFD: 16/04/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks =>.BlueStack Systems, Inc.
O43 - CFD: 18/11/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform
O43 - CFD: 25/10/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID =>.CPUID Inc
O43 - CFD: 27/08/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cybertroopers Virtual-ON
O43 - CFD: 08/05/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite =>.DAEMON Tools
O43 - CFD: 02/02/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes =>.Elaborate Bytes
O43 - CFD: 31/07/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ever17
O43 - CFD: 12/05/2013 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FAVORITE
O43 - CFD: 24/01/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps =>.Fraps Games
O43 - CFD: 05/12/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 31/07/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro =>.EIDOS hitman Game
O43 - CFD: 27/08/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor
O43 - CFD: 19/11/2016 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java =>.Oracle
O43 - CFD: 08/10/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack =>.KLite Inc
O43 - CFD: 09/12/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\light =>.Light
O43 - CFD: 06/04/2016 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi =>.LogMeIn Entreprise
O43 - CFD: 13/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 06/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MeCab
O43 - CFD: 13/04/2013 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows - LIVE =>.Microsoft Corporation
O43 - CFD: 14/04/2016 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCWest =>.NCWest
O43 - CFD: 26/07/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitroplus
O43 - CFD: 28/07/2014 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\onOne Software =>.onOne Software
O43 - CFD: 31/01/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PHANTASY STAR ONLINE 2
O43 - CFD: 29/11/2014 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\puush
O43 - CFD: 27/12/2013 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razor 1911
O43 - CFD: 22/12/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RGSS-RTP Standard
O43 - CFD: 30/01/2016 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype =>.Skype
O43 - CFD: 09/01/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftEther VPN Client =>.SoftEther
O43 - CFD: 25/10/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan =>.Almico Software
O43 - CFD: 17/08/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SQUARE ENIX =>.Square Enix
O43 - CFD: 04/05/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 08/06/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam =>.SteamApps
O43 - CFD: 27/04/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StepMania 5
O43 - CFD: 13/07/2009 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC =>.Wacom Technology
O43 - CFD: 13/08/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLAN
O43 - CFD: 05/04/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vulkan 1.0.3.1 =>.Kronos Group
O43 - CFD: 09/12/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WhoCrashed =>.Resplendence Software
O43 - CFD: 27/01/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 20/07/2015 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XSplit =>.SplitMedia Labs
O43 - CFD: 30/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\セイバーフィッシュ
O43 - CFD: 31/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ソウルワーカー
O43 - CFD: 26/07/2016 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ソフト電池
O43 - CFD: 25/04/2014 - [] D -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 =>.GEAR Software, Inc.
O43 - CFD: 03/06/2014 - [] D -- C:\ProgramData\Aeria Games =>.Aeria Games
O43 - CFD: 02/08/2015 - [] D -- C:\ProgramData\AMD =>.AMD
O43 - CFD: 13/04/2016 - [] D -- C:\ProgramData\Apple =>.Apple Inc.
O43 - CFD: 25/04/2014 - [] D -- C:\ProgramData\Apple Computer =>.Apple Inc.
O43 - CFD: 13/07/2009 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 11/11/2015 - [] D -- C:\ProgramData\ASign
O43 - CFD: 11/12/2015 - [] D -- C:\ProgramData\ATI =>.ATI
O43 - CFD: 16/04/2015 - [] D -- C:\ProgramData\BlueStacks =>.BlueStack Systems, Inc.
O43 - CFD: 18/11/2016 - [] D -- C:\ProgramData\BlueStacksSetup =>.BlueStack Systems, Inc.
O43 - CFD: 19/01/2016 - [] D -- C:\ProgramData\boost_interprocess =>.boost.org
O43 - CFD: 02/10/2015 - [] D -- C:\ProgramData\Damned
O43 - CFD: 13/07/2009 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- C:\ProgramData\Favorites =>.Microsoft Corporation
O43 - CFD: 25/10/2014 - [] D -- C:\ProgramData\FNET =>.FNet Corporation
O43 - CFD: 27/08/2013 - [] D -- C:\ProgramData\Gibraltar
O43 - CFD: 21/11/2013 - [] D -- C:\ProgramData\HitmanPro =>.EIDOS hitman Game
O43 - CFD: 02/10/2013 - [] D -- C:\ProgramData\LogMeIn =>.LogMeIn
O43 - CFD: 11/12/2013 - [] D -- C:\ProgramData\Malwarebytes =>.Malwarebytes
O43 - CFD: 25/10/2014 - [] D -- C:\ProgramData\McAfee =>.McAfee
O43 - CFD: 03/12/2016 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 09/02/2013 - [] D -- C:\ProgramData\Mozilla =>.Mozilla Corporation
O43 - CFD: 28/07/2014 - [] D -- C:\ProgramData\onOne Software =>.onOne Software
O43 - CFD: 18/08/2014 - [] D -- C:\ProgramData\ONScripter-EN
O43 - CFD: 26/07/2016 - [] D -- C:\ProgramData\paltiosoft
O43 - CFD: 09/06/2014 - [] D -- C:\ProgramData\Screaming Bee =>.Screaming Bee
O43 - CFD: 03/08/2016 - [] D -- C:\ProgramData\Skype =>.Skype
O43 - CFD: 19/04/2015 - [] D -- C:\ProgramData\SplitMediaLabs =>.SplitMediaLabs
O43 - CFD: 27/08/2013 - [] D -- C:\ProgramData\Stardock =>.Stardock
O43 - CFD: 13/07/2009 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation
O43 - CFD: 19/09/2013 - [] D -- C:\ProgramData\Steam =>.SteamApps
O43 - CFD: 13/07/2009 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation
O43 - CFD: 12/09/2015 - [] D -- C:\ProgramData\Umineko4final
O43 - CFD: 01/04/2016 - [] D -- C:\ProgramData\WindSolutions =>.WindSolutions
O43 - CFD: 01/04/2016 - [] D -- C:\ProgramData\wondershare =>.Wondershare
O43 - CFD: 28/07/2014 - [] D -- C:\Program Files (x86)\Common Files\Adobe =>.Adobe
O43 - CFD: 25/10/2014 - [] D -- C:\Program Files (x86)\Common Files\ATI Technologies =>.ATI Technologies
O43 - CFD: 21/05/2013 - [] D -- C:\Program Files (x86)\Common Files\Enterbrain =>.Enterbrain
O43 - CFD: 21/03/2013 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared =>.Microsoft Corporation
O43 - CFD: 09/06/2014 - [] D -- C:\Program Files (x86)\Common Files\Screaming Bee =>.Screaming Bee
O43 - CFD: 13/07/2009 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 27/04/2016 - [] D -- C:\Program Files (x86)\Common Files\Skype =>.Skype
O43 - CFD: 13/07/2009 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines =>.Microsoft Corporation
O43 - CFD: 06/10/2016 - [] D -- C:\Program Files (x86)\Common Files\Steam =>.SteamApps
O43 - CFD: 02/02/2013 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 03/07/2014 - [] D -- C:\Users\OWNER\AppData\Roaming\17173
O43 - CFD: 28/07/2014 - [] D -- C:\Users\OWNER\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 16/04/2015 - [] D -- C:\Users\OWNER\AppData\Roaming\AMD =>.AMD
O43 - CFD: 28/07/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\AnnkakeSpa
O43 - CFD: 19/05/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Apowersoft =>.Apowersoft
O43 - CFD: 01/04/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Apple Computer =>.Apple Inc.
O43 - CFD: 25/10/2014 - [] D -- C:\Users\OWNER\AppData\Roaming\ATI =>.ATI
O43 - CFD: 23/12/2015 - [] D -- C:\Users\OWNER\AppData\Roaming\Audacity =>.The Audacity Team
O43 - CFD: 09/11/2015 - [] D -- C:\Users\OWNER\AppData\Roaming\Avnex
O43 - CFD: 01/12/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Azureus =>.Azureus Software (P2P)
O43 - CFD: 15/10/2015 - [] D -- C:\Users\OWNER\AppData\Roaming\BitComet =>.BitComet (P2P)
O43 - CFD: 11/12/2015 - [] D -- C:\Users\OWNER\AppData\Roaming\CW
O43 - CFD: 11/12/2015 - [] D -- C:\Users\OWNER\AppData\Roaming\CWPatcher
O43 - CFD: 18/11/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\DAEMON Tools Lite =>.DAEMON Tools
O43 - CFD: 25/10/2014 - [] D -- C:\Users\OWNER\AppData\Roaming\Dropbox =>.Dropbox
O43 - CFD: 05/12/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\FALCOM
O43 - CFD: 10/05/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Frontwing
O43 - CFD: 06/09/2008 - [] D -- C:\Users\OWNER\AppData\Roaming\Fujitsu =>.Fujitsu
O43 - CFD: 14/11/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\grabacr.net
O43 - CFD: 30/01/2013 - [] D -- C:\Users\OWNER\AppData\Roaming\Identities =>.Microsoft Corporation
O43 - CFD: 22/06/2014 - [] D -- C:\Users\OWNER\AppData\Roaming\library_dir =>.library_dir
O43 - CFD: 13/10/2015 - [] D -- C:\Users\OWNER\AppData\Roaming\light =>.Light
O43 - CFD: 30/01/2013 - [] D -- C:\Users\OWNER\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 27/08/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Mael
O43 - CFD: 13/07/2009 - [0] D -- C:\Users\OWNER\AppData\Roaming\Media Center Programs =>.Microsoft Corporation
O43 - CFD: 12/08/2015 - [] SD -- C:\Users\OWNER\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 04/02/2013 - [] D -- C:\Users\OWNER\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 20/09/2015 - [] D -- C:\Users\OWNER\AppData\Roaming\Mumble =>.Mumble
O43 - CFD: 26/07/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Nitroplus
O43 - CFD: 28/07/2014 - [] D -- C:\Users\OWNER\AppData\Roaming\onOne Software =>.onOne Software
O43 - CFD: 18/04/2014 - [] D -- C:\Users\OWNER\AppData\Roaming\ONScripter-EN
O43 - CFD: 27/04/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\puush
O43 - CFD: 23/02/2013 - [] D -- C:\Users\OWNER\AppData\Roaming\RealReader
O43 - CFD: 10/01/2015 - [] D -- C:\Users\OWNER\AppData\Roaming\REngLauncher
O43 - CFD: 11/06/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\savedata
O43 - CFD: 09/06/2014 - [] D -- C:\Users\OWNER\AppData\Roaming\Screaming Bee =>.Screaming Bee
O43 - CFD: 30/01/2013 - [] D -- C:\Users\OWNER\AppData\Roaming\SEGA =>.SEGA
O43 - CFD: 19/11/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Sikuli
O43 - CFD: 13/10/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Skype =>.Skype
O43 - CFD: 25/10/2014 - [] D -- C:\Users\OWNER\AppData\Roaming\Skype_old
O43 - CFD: 14/11/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Smooth and Flat
O43 - CFD: 19/04/2015 - [] D -- C:\Users\OWNER\AppData\Roaming\SplitmediaLabs =>.SplitMediaLabs
O43 - CFD: 27/08/2013 - [] D -- C:\Users\OWNER\AppData\Roaming\Stardock =>.Stardock
O43 - CFD: 16/07/2015 - [] D -- C:\Users\OWNER\AppData\Roaming\Steam =>.SteamApps
O43 - CFD: 29/07/2015 - [] D -- C:\Users\OWNER\AppData\Roaming\Tera_Awesomium
O43 - CFD: 12/11/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\TS3Client =>.TeamSpeak
O43 - CFD: 23/12/2013 - [] D -- C:\Users\OWNER\AppData\Roaming\uMod
O43 - CFD: 22/08/2013 - [] D -- C:\Users\OWNER\AppData\Roaming\Unity =>.Unity
O43 - CFD: 30/08/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\vlc =>.VideoLAN
O43 - CFD: 31/01/2013 - [] D -- C:\Users\OWNER\AppData\Roaming\WinRAR =>.WinRAR
O43 - CFD: 11/12/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 10/07/2014 - [] D -- C:\Users\OWNER\AppData\Local\AAA_Internet_Publishing,_
O43 - CFD: 03/06/2014 - [] D -- C:\Users\OWNER\AppData\Local\Aeria Games =>.Aeria Games
O43 - CFD: 16/11/2016 - [] D -- C:\Users\OWNER\AppData\Local\AMD =>.AMD
O43 - CFD: 19/05/2016 - [] D -- C:\Users\OWNER\AppData\Local\Apowersoft =>.Apowersoft
O43 - CFD: 25/04/2014 - [] D -- C:\Users\OWNER\AppData\Local\Apple =>.Apple Inc.
O43 - CFD: 25/04/2014 - [] D -- C:\Users\OWNER\AppData\Local\Apple Computer =>.Apple Inc.
O43 - CFD: 30/01/2013 - [0] SHD -- C:\Users\OWNER\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 10/01/2015 - [] D -- C:\Users\OWNER\AppData\Local\Apps =>.Microsoft Corporation
O43 - CFD: 26/05/2015 - [] D -- C:\Users\OWNER\AppData\Local\AreaZero
O43 - CFD: 25/10/2014 - [] D -- C:\Users\OWNER\AppData\Local\ATI =>.ATI
O43 - CFD: 10/12/2016 - [] D -- C:\Users\OWNER\AppData\Local\Avg =>.AVG Software
O43 - CFD: 29/08/2016 - [] D -- C:\Users\OWNER\AppData\Local\BANDAI NAMCO GAMES =>.BANDAI NAMCO Games
O43 - CFD: 06/12/2015 - [] D -- C:\Users\OWNER\AppData\Local\BISHOP
O43 - CFD: 16/04/2015 - [] D -- C:\Users\OWNER\AppData\Local\Bluestacks =>.BlueStack Systems, Inc.
O43 - CFD: 07/08/2015 - [] D -- C:\Users\OWNER\AppData\Local\BNSUpdater
O43 - CFD: 23/07/2015 - [] D -- C:\Users\OWNER\AppData\Local\CEF =>.CEF
O43 - CFD: 10/12/2016 - [0] D -- C:\Users\OWNER\AppData\Local\Deployment =>.Microsoft Corporation
O43 - CFD: 24/07/2016 - [0] D -- C:\Users\OWNER\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 23/02/2013 - [] D -- C:\Users\OWNER\AppData\Local\Digital_Distribution
O43 - CFD: 13/10/2016 - [] D -- C:\Users\OWNER\AppData\Local\Discord =>.GitHub
O43 - CFD: 10/01/2015 - [] D -- C:\Users\OWNER\AppData\Local\Downloaded Installations =>.Microsoft Corporation
O43 - CFD: 10/12/2016 - [] D -- C:\Users\OWNER\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation
O43 - CFD: 23/02/2013 - [] D -- C:\Users\OWNER\AppData\Local\FreeOCR
O43 - CFD: 06/09/2008 - [] D -- C:\Users\OWNER\AppData\Local\Fujitsu =>.Fujitsu
O43 - CFD: 27/08/2013 - [] D -- C:\Users\OWNER\AppData\Local\GameStop =>.GameStop
O43 - CFD: 30/10/2016 - [] D -- C:\Users\OWNER\AppData\Local\Google =>.Google
O43 - CFD: 14/11/2016 - [] D -- C:\Users\OWNER\AppData\Local\grabacr.net
O43 - CFD: 30/01/2013 - [0] SHD -- C:\Users\OWNER\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 08/05/2013 - [] D -- C:\Users\OWNER\AppData\Local\INISet
O43 - CFD: 23/02/2013 - [] D -- C:\Users\OWNER\AppData\Local\IsolatedStorage =>.id Software
O43 - CFD: 14/11/2016 - [] D -- C:\Users\OWNER\AppData\Local\KanColleTool
O43 - CFD: 02/10/2013 - [] D -- C:\Users\OWNER\AppData\Local\LogMeIn =>.LogMeIn
O43 - CFD: 18/11/2016 - [] D -- C:\Users\OWNER\AppData\Local\LogMeIn Hamachi =>.LogMeIn Entreprise
O43 - CFD: 04/02/2013 - [] D -- C:\Users\OWNER\AppData\Local\Macromedia =>.Macromedia
O43 - CFD: 05/06/2016 - [] D -- C:\Users\OWNER\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 16/07/2013 - [] D -- C:\Users\OWNER\AppData\Local\Microsoft Games =>.Microsoft Corporation
O43 - CFD: 30/09/2013 - [] D -- C:\Users\OWNER\AppData\Local\Mozilla =>.Mozilla Corporation
O43 - CFD: 18/03/2013 - [] D -- C:\Users\OWNER\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 09/06/2014 - [] D -- C:\Users\OWNER\AppData\Local\SkypeFx
O43 - CFD: 14/11/2016 - [] D -- C:\Users\OWNER\AppData\Local\Smooth and Flat
O43 - CFD: 14/11/2016 - [] D -- C:\Users\OWNER\AppData\Local\Smooth_and_Flat
O43 - CFD: 25/04/2015 - [] D -- C:\Users\OWNER\AppData\Local\SplitMediaLabs =>.SplitMediaLabs
O43 - CFD: 11/01/2016 - [] D -- C:\Users\OWNER\AppData\Local\SquirrelTemp =>.Squirrels
O43 - CFD: 20/02/2015 - [] D -- C:\Users\OWNER\AppData\Local\Steam =>.SteamApps
O43 - CFD: 09/12/2016 - [] D -- C:\Users\OWNER\AppData\Local\SWPatcher
O43 - CFD: 08/11/2014 - [] D -- C:\Users\OWNER\AppData\Local\SyndicatedLife
O43 - CFD: 11/11/2016 - [] D -- C:\Users\OWNER\AppData\Local\TeamSpeak 3 Client =>.TeamSpeak
O43 - CFD: 11/12/2016 - [] D -- C:\Users\OWNER\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 30/01/2013 - [0] SHD -- C:\Users\OWNER\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 21/12/2015 - [] D -- C:\Users\OWNER\AppData\Local\UWKProcess
O43 - CFD: 15/10/2015 - [] D -- C:\Users\OWNER\AppData\Local\Vebanaul
O43 - CFD: 03/07/2014 - [] D -- C:\Users\OWNER\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 10/05/2013 - [] D -- C:\Users\OWNER\AppData\Local\WindomXP
O43 - CFD: 08/05/2013 - [] D -- C:\Users\OWNER\AppData\Local\wxpfree
O43 - CFD: 11/12/2016 - [] D -- C:\Users\OWNER\AppData\Local\Zemana =>.Zemana
O43 - CFD: 18/03/2013 - [0] D -- C:\Users\OWNER\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 19/09/2013 - [] RD -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 14/10/2015 - [] RD -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 12/10/2015 - [0] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AeriaGames =>.AeriaGames
O43 - CFD: 13/10/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
O43 - CFD: 01/10/2016 - [0] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CINEMATOGRAPH
O43 - CFD: 20/11/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CLIPCRAFT
O43 - CFD: 31/07/2016 - [0] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ever17
O43 - CFD: 01/10/2016 - [0] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\frontwing
O43 - CFD: 31/08/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hammer & Chisel, Inc =>.Hammer & Chisel, Inc
O43 - CFD: 30/11/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader =>.JDownloader
O43 - CFD: 06/11/2015 - [] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\KISS
O43 - CFD: 13/10/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Liar
O43 - CFD: 13/07/2009 - [] RD -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 07/12/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MiyuPatcher
O43 - CFD: 30/11/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mudfish Cloud VPN
O43 - CFD: 18/03/2015 - [0] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Portion
O43 - CFD: 19/11/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 2.7 =>.Python
O43 - CFD: 22/12/2013 - [0] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RGSS-RTP Standard
O43 - CFD: 09/06/2014 - [0] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Screaming Bee =>.Screaming Bee
O43 - CFD: 25/10/2014 - [0] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan =>.Almico Software
O43 - CFD: 11/12/2016 - [] RD -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 05/12/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam =>.SteamApps
O43 - CFD: 23/07/2013 - [0] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StepMania 5
O43 - CFD: 27/01/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 08/08/2016 - [0] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\あざらしそふと
O43 - CFD: 01/05/2014 - [] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AtelierR
O43 - CFD: 04/03/2013 - [] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AtelierW
O43 - CFD: 28/02/2016 - [] D -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LTR
O43 - CFD: 13/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 10/12/2016 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Avg =>.AVG Software
O43 - CFD: 30/01/2013 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Google =>.Google
O43 - CFD: 13/07/2009 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 25/04/2014 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Apple Computer =>.Apple Inc.
O43 - CFD: 17/04/2015 - [] SD -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 27/06/2014 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\NetworkTunnel
O43 - CFD: 16/04/2013 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Paltiosoft
---\\ ShellIconOverlayIdentifiers (SIOI) (2) - 0s
O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
---\\ System Drivers List (65) - 61s
O58 - SDL:2009/07/13 17:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2009/07/13 17:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2009/07/13 17:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\drivers\adpu320.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2009/07/13 17:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2016/09/16 11:40:04 A . (.Advanced Micro Devices - AMD ACP Binaries.) -- C:\Windows\System32\drivers\amdacpksd.sys [324224] =>.Advanced Micro Devices, Inc.ョ
O58 - SDL:2010/02/18 09:18:24 A . (.Advanced Micro Devices - AMD IO Driver.) -- C:\Windows\System32\drivers\amdiox64.sys [324224] =>.Advanced Micro Devices, Inc.ョ
O58 - SDL:2010/11/20 05:32:46 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2009/07/13 17:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2010/11/20 05:32:47 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2009/07/13 17:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2009/07/13 17:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2016/03/29 21:00:36 A . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) -- C:\Windows\System32\drivers\AtihdW76.sys [324224] =>.Advanced Micro Devices
O58 - SDL:2016/09/16 11:37:36 A . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\System32\drivers\atikmdag.sys [324224] =>.Advanced Micro Devices, Inc.
O58 - SDL:2016/09/16 11:41:30 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\Windows\System32\drivers\atikmpag.sys [324224] =>.Advanced Micro Devices, Inc.ョ
O58 - SDL:2009/06/10 12:34:23 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60a.sys [324224] =>.Broadcom Corporation
O58 - SDL:2009/06/10 12:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [324224] =>.Brother Industries, Ltd.
O58 - SDL:2009/06/10 12:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [324224] =>.Brother Industries, Ltd.
O58 - SDL:2009/07/13 17:19:07 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [324224] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 12:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [324224] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 12:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [324224] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 12:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [324224] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 12:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [324224] =>.Broadcom Corporation
O58 - SDL:2009/07/13 17:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2010/12/16 14:58:14 A . (.Elaborate Bytes AG - ElbyCD Windows x64 I/O driver.) -- C:\Windows\System32\drivers\ElbyCDIO.sys [324224] =>.Elaborate Bytes AGョ
O58 - SDL:2009/07/13 17:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2011/07/29 10:40:56 A . (.Etron Technology Inc - Etron eXtensible Hub Driver..) -- C:\Windows\System32\drivers\EtronHub3.sys [324224] =>.Etron Technology Inc
O58 - SDL:2011/07/29 10:40:58 A . (.Etron Technology Inc - Etron eXtensible Host Controller Driver..) -- C:\Windows\System32\drivers\EtronXHCI.sys [324224] =>.Etron Technology Inc
O58 - SDL:2009/06/10 12:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [324224] =>.Broadcom Corporation
O58 - SDL:2009/03/18 15:35:42 AH . (.LogMeIn, Inc. - Hamachi Virtual Network Interface Driver.) -- C:\Windows\System32\drivers\hamachi.sys [324224] =>.LogMeIn, Inc.ョ
O58 - SDL:2009/06/10 12:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [324224] =>.Hauppauge Computer Works, Inc.
O58 - SDL:2010/11/20 05:33:35 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2010/11/20 05:33:38 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2009/07/13 17:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2011/08/10 23:54:26 A . (.Atheros Communications, Inc. - Atheros Ar81xx series PCI-E Gigabit Etherne.) -- C:\Windows\System32\drivers\L1C60x64.sys [324224] =>.Atheros Communications Inc.ョ
O58 - SDL:2009/07/13 17:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2009/07/13 17:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2009/07/13 17:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2009/07/13 17:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2015/10/01 01:23:59 A . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\drivers\mbamchameleon.sys [324224] =>.Malwarebytes Corporationョ
O58 - SDL:2016/12/10 22:15:39 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys [324224] =>.Malwarebytes Corporationョ
O58 - SDL:2009/07/13 17:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2009/07/13 17:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2015/01/09 01:08:32 A . (.SoftEther VPN Project at University of Tsukuba, Japan - SoftEther VPN.) -- C:\Windows\System32\drivers\Neo_0038.sys [324224] =>.SoftEther K.K.ョ
O58 - SDL:2009/07/13 17:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2010/11/20 05:33:48 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2010/11/20 05:33:48 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2009/07/13 17:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2009/07/13 17:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2011/04/22 01:17:04 A . (.Realtek - Realtek 8136/8168/8169 NDIS 6.20 64-bit Dri.) -- C:\Windows\System32\drivers\Rt64win7.sys [324224] =>.Realtek Semiconductor Corpョ
O58 - SDL:2010/07/01 13:21:50 A . (.Screaming Bee LLC - Screaming Bee Audio Driver.) -- C:\Windows\System32\drivers\ScreamingBAudio64.sys [324224] =>.Screaming Bee LLCョ
O58 - SDL:2009/06/10 12:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [324224] =>.Macrovision Corporation, Macrovision Europe Limited,
O58 - SDL:2009/07/13 17:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2009/07/13 17:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2013/05/08 21:33:40 A . (.Authors - .) -- C:\Windows\System32\drivers\sptd.sys [324224]
O58 - SDL:2009/07/13 17:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2013/09/23 14:39:28 A . (.The OpenVPN Project - TAP-Win32 Virtual Network Driver.) -- C:\Windows\System32\drivers\tap0901.sys [324224] =>.The OpenVPN Project
O58 - SDL:2016/04/01 14:02:35 A . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\drivers\usbaapl64.sys [324224] =>.Apple, Inc.
O58 - SDL:2011/01/15 08:21:04 A . (.Elaborate Bytes AG - VirtualCloneCD Driver.) -- C:\Windows\System32\drivers\VClone.sys [324224] =>.Elaborate Bytes AG
O58 - SDL:2009/07/13 17:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2013/04/18 14:34:22 A . (.Headsoft - VJoy Virtual Joystick Driver.) -- C:\Windows\System32\drivers\vjoy.sys [324224] {11218A7D74F838907AA32D509C5D68E08411} =>.Headsoft
O58 - SDL:2009/07/13 17:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [324224] =>.Microsoft Windowsョ
O58 - SDL:2014/07/02 19:49:08 A . (.SplitmediaLabs Limited - XSplit Stream Audio.) -- C:\Windows\System32\drivers\xspltspk.sys [324224] =>.Splitmedialabs Limitedョ
O58 - SDL:2016/12/11 01:47:41 A . (.Zemana Ltd. - ZAM.) -- C:\Windows\System32\drivers\zam64.sys [324224] =>.Zemana Ltd.ョ
O58 - SDL:2016/12/11 01:47:39 A . (.Zemana Ltd. - ZAM.) -- C:\Windows\System32\drivers\zamguard64.sys [324224] =>.Zemana Ltd.ョ
O58 - SDL:2016/04/05 15:18:28 AH . (.LogMeIn, Inc. - Hamachi Virtual Network Interface Driver.) -- C:\Windows\System32\hamachi.sys [324224] =>.LogMeIn, Inc.ョ
---\\ Last modified or created user files (13) - 91s
O61 - LFC: 2016/12/11 00:13:04 A . (.Copyright © 2015.) -- C:\Users\OWNER\Desktop\Adware Removal Tool by TSA.exe [752296] {317DD1C55F51AC2756D9C93C060C6FA5}
O61 - LFC: 2016/12/11 06:07:09 A . (..) -- C:\Users\OWNER\Desktop\zoek.exe [1309184]
O61 - LFC: 2016/12/07 12:08:23 A . (.© Microsoft Corporation. All rights reserved..) -- C:\Users\OWNER\Desktop\Launchers\SW\setup(1).exe [591240]
O61 - LFC: 2016/12/05 11:49:22 A . (.Java(TM) Native Access (JNA).) -- C:\Users\OWNER\Desktop\Extra\DL Manager\tmp\jna\jna8308253101283634884.dll [198144]
O61 - LFC: 2016/12/05 11:49:29 A . (..) -- C:\Users\OWNER\Desktop\Extra\DL Manager\tmp\7zip\SevenZipJBinding-FKPz9\lib7-Zip-JBinding.dll [4078962]
O61 - LFC: 2016/12/05 11:49:29 A . (..) -- C:\Users\OWNER\Desktop\Extra\DL Manager\tmp\7zip\SevenZipJBinding-FKPz9\libgcc_s_sjlj-1.dll [566439]
O61 - LFC: 2016/12/07 12:12:13 N . (.Dino Chiesa.) -- C:\Users\OWNER\AppData\Local\Apps\2.0\1KJ40ETR.D9N\H889L8M7.9GB\swpa..tion_57a59494e3651860_0002.0004_dc2358626ec28004\Ionic.Zip.Patched.dll [462848]
O61 - LFC: 2016/12/07 12:12:14 A . (.MadMilkman.) -- C:\Users\OWNER\AppData\Local\Apps\2.0\1KJ40ETR.D9N\H889L8M7.9GB\swpa..tion_57a59494e3651860_0002.0004_dc2358626ec28004\MadMilkman.Ini.dll [40960]
O61 - LFC: 2016/12/07 12:12:13 A . (..) -- C:\Users\OWNER\AppData\Local\Apps\2.0\1KJ40ETR.D9N\H889L8M7.9GB\swpa..tion_57a59494e3651860_0002.0004_dc2358626ec28004\patchw32.dll [252832] {78BB344EC2C9E38268CEEA6C93F9B725}
O61 - LFC: 2016/12/07 12:12:14 N . (.Copyright © 2016.) -- C:\Users\OWNER\AppData\Local\Apps\2.0\1KJ40ETR.D9N\H889L8M7.9GB\swpa..tion_57a59494e3651860_0002.0004_dc2358626ec28004\SWPatcher.exe [583048]
O61 - LFC: 2016/12/07 12:12:13 A . (..) -- C:\Users\OWNER\AppData\Local\Apps\2.0\1KJ40ETR.D9N\H889L8M7.9GB\swpa...exe_57a59494e3651860_0002.0004_en_b2b5d0881c8cd648\patchw32.dll [252832] {78BB344EC2C9E38268CEEA6C93F9B725}
O61 - LFC: 2016/12/07 12:12:14 A . (.MadMilkman.) -- C:\Users\OWNER\AppData\Local\Apps\2.0\1KJ40ETR.D9N\H889L8M7.9GB\madm...ini_4e0b5157a7ffbb74_0001.0000_none_a972c2f079e1e421\MadMilkman.Ini.dll [40960]
O61 - LFC: 2016/12/07 15:52:36 A . (..) -- C:\Users\OWNER\AppData\Local\AMD\DxCache\23c63d5d8344258f4b6f9c30f232a03e87378e3449650438..bin [4194304]
---\\ File Associations Shell Spawning (11) - 0s
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporationョ
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporationョ
---\\ Start Menu Internet (12) - 0s
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporationョ
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Incョ
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporationョ
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
---\\ Search Browser Infection (10) - 11s
O69 - SBI: SearchScopes [HKCU] {012E1000-F331-11DB-8314-0800200C9A66} - (Google) -
http://www.google.com/ =>.Google Inc.
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) -
http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKCU] {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} - (Google) -
http://www.google.com/ =>.Google Inc.
O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (@ieframe.dll,-12512) -
http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKLM] {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} - (Google) -
http://www.google.com/ =>.Google Inc.
O69 - SBI: SearchScopes [HKLM] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} [DefaultScope] - (Google) -
http://www.google.com/ =>.Google Inc.
O69 - SBI: SearchScopes [HKUS\.DEFAULT] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) -
http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKUS\.DEFAULT] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) -
http://www.google.com/ =>.Google Inc.
O69 - SBI: SearchScopes [HKUS\S-1-5-18] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) -
http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKUS\S-1-5-18] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) -
http://www.google.com/ =>.Google Inc.
---\\ Search Svchost Services (33) - 1s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\Windows\System32\aelupsvc.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\Windows\system32\srvsvc.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\Windows\System32\gpsvc.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\ikeext.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\Windows\System32\Audiosrv.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\Windows\System32\rasauto.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\Windows\System32\Sens.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remote Desktop Session Host Server Remote C.) -- C:\Windows\System32\termsrv.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\system32\wuaueng.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\Windows\System32\qmgr.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\Windows\system32\seclogon.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\Windows\System32\appinfo.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\Windows\system32\iscsiexe.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) -- C:\Windows\system32\mmcss.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\Windows\System32\browser.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\Windows\system32\schedsvc.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\Windows\system32\kmsvc.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\Windows\System32\wercplsupport.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\Windows\system32\themeservice.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\Windows\System32\bdesvc.dll [324224] =>.Microsoft Corporation
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Software installation Service.) -- C:\Windows\System32\appmgmts.dll [324224] =>.Microsoft Corporation
---\\ Additional Scan (O88) (2) - 0s
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} =>.Superfluous.Orphan
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} =>.Superfluous.Orphan
---\\ Summary of the elements found (1) - 0s
https://www.nicolascoolman.com/fr/repaquetage-et_infections/ =>Hijacker.DNS.Hosts
~ End of the scan, 34545 items in 00h05mn26s (1091)