Solved Frst & addition logs for networking problem

  • Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.
Status
Not open for further replies.
Rogue Killer Scan.

Download RogueKiller -- (Portable) -- from one of the following links and save it to your Desktop:

Link 1
Link 2

  • Close all other the running programs
  • Disable ALL Antivirus -- Antimalware -- Applications.
  • Right Click Rogue Killer and Run as Administrator.
  • Click the Start Scan button.
  • Allow the scan to run -- it can take ten minutes or more.
  • Once the scan is complete check All items for removal.
  • upload_2017-2-23_10-55-54-png.1658

  • After All items are checked then press Remove Selected.
  • Wait until the Status box shows Deleting Finished.
  • Click on open report -- then open txt
  • Copy the content of the report and paste it here in your next reply.

JRT Scan.


Please download Junkware Removal Tool and save it on your desktop.


  • Shut down your anti-virus, anti-spyware, and firewall software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click it and select Run as administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log is saved to your desktop and will automatically open.
  • Please post the JRT log.

Adware Cleaner Scan.

Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Scan button.
  • When the scan has finished click on Clean button.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

ZHP Diag Scan


Download ZHP Diag to your desktop.


1. Right Click Run as Admin.

2. Click the Options button.

Click on Check All
Then Click Validate
Then click close.

upload_2017-4-26_17-16-39-png.2074





2. Click the Scanner button.


upload_2017-2-23_3-32-26-png.1647



When complete please push the report button.
A notepad will open... copy and paste the report in your next reply.
 
  • Like
Reactions: maxim123
rogue killer log:

Code:
RogueKiller V12.11.9.0 (x64) [Aug  3 2017] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 10 (10.0.15063) 64 bits version
Started in : Normal mode
User : Max [Administrator]
Started from : C:\Users\USER\Desktop\RogueKiller_portable64.exe
Mode : Delete -- Date : 08/08/2017 16:18:22 (Duration : 01:00:01)

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 5 ¤¤¤
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Simplitec -> Deleted
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-900945925-988278395-3478122750-1001\Software\OCS -> Deleted
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-900945925-988278395-3478122750-1001\Software\OCS -> Deleted
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-900945925-988278395-3478122750-1001\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve  -> Replaced (http://search.msn.com/spbasic.htm)
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-900945925-988278395-3478122750-1001\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve  -> Replaced (http://search.msn.com/spbasic.htm)

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 9 ¤¤¤
[PUP.Gen1][Folder] C:\ProgramData\SecTaskMan -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\c_AdaptiveSleepService4B841E02.file -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\c_cmw_srv32FCDCA0 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\c_cmw_srv32FCDCA0.memory -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\c_CxAudMsg6416D826DB.file -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\c_CyberGhostvice.exe31B21831.file -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\c_hydra2AD91A7F.memory -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\c_jhi_service771495DA.memory -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\c_SwitchBoard4CDCE3EF.file -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\c_USBGuard38719CF2.file -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\c_uTorrent3A4E74DE -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\c_uTorrent3A4E74DE.memory -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_000041091A0000000000000000F01FEC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_000041091A0000000000000000F01FEC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_000041091A0090400000000000F01FEC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_000041091A0090400000000000F01FEC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109511090400000000000F01FEC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109511090400000000000F01FEC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109610000000000000000F01FEC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109610000000000000000F01FEC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109610090400000000000F01FEC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109610090400000000000F01FEC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109611090400100000000F01FEC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109611090400100000000F01FEC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109A20000000100000000F01FEC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109A20000000100000000F01FEC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109A20090400100000000F01FEC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109A20090400100000000F01FEC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109B10000000000000000F01FEC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109B10000000000000000F01FEC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109B10090400000000000F01FEC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109B10090400000000000F01FEC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109C20090400000000000F01FEC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109C20090400000000000F01FEC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109E60090400000000000F01FEC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109E60090400000000000F01FEC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109F10090400000000000F01FEC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109F10090400000000000F01FEC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109F100A0C00000000000F01FEC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109F100A0C00000000000F01FEC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109F100C0400000000000F01FEC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_00004109F100C0400000000000F01FEC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_0001A13E9A9C4C0B426EEA7611F572C7 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_0001A13E9A9C4C0B426EEA7611F572C7.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_008FFDCA5106CEEBA872B7A108192537 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_008FFDCA5106CEEBA872B7A108192537.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_0AA7CFB2C445A3E47869763FEB56B59E -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_0AA7CFB2C445A3E47869763FEB56B59E.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_0AB19942EE0FDA44C98CE55CA0CE6F7B -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_0AB19942EE0FDA44C98CE55CA0CE6F7B.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_0B47DCE45212CFD422DAEF7A386E1D91 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_0B47DCE45212CFD422DAEF7A386E1D91.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_0F41CAD81467FD729E26997B9B45E7F0 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_0F41CAD81467FD729E26997B9B45E7F0.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_1007C6B46D7C017319E3B52CF3EC196E -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_1007C6B46D7C017319E3B52CF3EC196E.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_121E2D80A6F7BE3479DF26B944094330 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_121E2D80A6F7BE3479DF26B944094330.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_12342rg -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_12346db -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_12350vi4 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_1303E36A22506C811FF8E78E903713F5 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_1303E36A22506C811FF8E78E903713F5.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_1926E8D15D0BCE53481466615F760A7F -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_1926E8D15D0BCE53481466615F760A7F.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_1af2a8da7e60d0b429d7e6453b3d0182 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_1af2a8da7e60d0b429d7e6453b3d0182.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_1AF8D3E72906A96459B586CFA4C276AC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_1AF8D3E72906A96459B586CFA4C276AC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_1D5E3C0FEDA1E123187686FED06E995A -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_1D5E3C0FEDA1E123187686FED06E995A.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_1F764691F11C67F458B88521DA8CB349 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_1F764691F11C67F458B88521DA8CB349.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_21EE4A31AE32173319EEFE3BD6FDFFE3 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_21EE4A31AE32173319EEFE3BD6FDFFE3.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_22BEFC8F7E2A1793E9ADB411DEFE1C58 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_22BEFC8F7E2A1793E9ADB411DEFE1C58.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_24C995FA5E2A15247BEE94522B869B7B -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_24C995FA5E2A15247BEE94522B869B7B.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_24C995FA5E2A15247BEE94522B869EEB -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_24C995FA5E2A15247BEE94522B869EEB.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_254AB8D5462131D74ECE2863CEB538EF -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_254AB8D5462131D74ECE2863CEB538EF.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_296D7E10587DF347A5550F10262DA6C1 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_296D7E10587DF347A5550F10262DA6C1.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_2B7A37F2E05E6A93A9CBFE984E6CE263 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_2B7A37F2E05E6A93A9CBFE984E6CE263.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_2DB859CBCAD52683BBA11CEB700934D8 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_2DB859CBCAD52683BBA11CEB700934D8.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_2DE806C4B53591126316E9F6D7BD06F0 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_2DE806C4B53591126316E9F6D7BD06F0.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_2DF774AAB7432371D5C8FA53FAB17930 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_2DF774AAB7432371D5C8FA53FAB17930.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_30847AC12BC530C4DBEB60E1CD18CCF7 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_30847AC12BC530C4DBEB60E1CD18CCF7.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_31036807400771152751500050713758 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_31036807400771152751500050713758.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_326483007394D7D4DB9D3215D3C105BA -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_326483007394D7D4DB9D3215D3C105BA.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_3595CFBB9BC22395D174254EAA9937B7 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_3595CFBB9BC22395D174254EAA9937B7.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_37074588665C59840950BE9EE83A7F7C -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_37074588665C59840950BE9EE83A7F7C.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_387D1E04FDD3002122E8573109A51532 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_387D1E04FDD3002122E8573109A51532.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_39103BDF0ADFAAD3CAAC7AE5FE5E6370 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_39103BDF0ADFAAD3CAAC7AE5FE5E6370.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_392827CF2645CC3DA5E77C9210ACEA1B -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_392827CF2645CC3DA5E77C9210ACEA1B.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_3E11D6804AC9FEBDB284A5E2FF5D1354 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_3E11D6804AC9FEBDB284A5E2FF5D1354.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_3e43b73803c7c394f8a6b2f0402e19c2 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_3e43b73803c7c394f8a6b2f0402e19c2.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_4079A0F0303F187F3F2FA67F46531B39 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_4079A0F0303F187F3F2FA67F46531B39.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_4426EAF8040EBE3500FEA8488EE5AE67 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_4426EAF8040EBE3500FEA8488EE5AE67.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_4A93B2C607E517A567F8069ADACF6A9F -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_4A93B2C607E517A567F8069ADACF6A9F.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_4DFB82C37C09831378FE14D81CE65989 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_4DFB82C37C09831378FE14D81CE65989.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_4EA42A62D9304AC4784BF2381208540F -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_4EA42A62D9304AC4784BF2381208540F.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_4F8DD925BE7B982ECEE8FEAF81B6CCE1 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_4F8DD925BE7B982ECEE8FEAF81B6CCE1.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_51E9E3D0A7EDB003691F4BFA219B4688 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_51E9E3D0A7EDB003691F4BFA219B4688.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_5372DAECD74FC9E4882B1DBDCA7FFBFF -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_5372DAECD74FC9E4882B1DBDCA7FFBFF.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_55E3652ACEB38283D8765E8E9B8E6B57 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_55E3652ACEB38283D8765E8E9B8E6B57.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_5CF1B82A749393D9F75E3ABC811E3685 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_5CF1B82A749393D9F75E3ABC811E3685.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_609AB94FAD38A5F3B542308CEDA29363 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_609AB94FAD38A5F3B542308CEDA29363.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_61A79338FD41374A83995903AEFD5221 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_61A79338FD41374A83995903AEFD5221.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_62DBF9290209B993A9A757D1160F9B24 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_62DBF9290209B993A9A757D1160F9B24.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_67D6ECF5CD5FBA732B8B22BAC8DE1B4D -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_67D6ECF5CD5FBA732B8B22BAC8DE1B4D.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_6993899A5E1FB47D479DEB8AB8A7BF7B -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_6993899A5E1FB47D479DEB8AB8A7BF7B.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_6A00348D1F2717753B1BF87C1148BA83 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_6A00348D1F2717753B1BF87C1148BA83.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_6A4E5613ED5D0B6458795DE5B228B648 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_6A4E5613ED5D0B6458795DE5B228B648.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_6BAE1C0D1F2919EE402C9574EE515039 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_6BAE1C0D1F2919EE402C9574EE515039.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_6E8D947A316B3EB3F8F540C548BE2AB9 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_6E8D947A316B3EB3F8F540C548BE2AB9.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_6F12F344E3E8E7524EF3F77BFB72261C -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_6F12F344E3E8E7524EF3F77BFB72261C.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_71460E5BCA4A52243BE6E7439C61617E -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_71460E5BCA4A52243BE6E7439C61617E.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_730867CA97078564CA42827956E0A0EB -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_730867CA97078564CA42827956E0A0EB.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_73AC5E2C268C96A4CAD6424F052AC061 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_73AC5E2C268C96A4CAD6424F052AC061.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_76B0D5EBA1D098AF9455317D6574F851 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_76B0D5EBA1D098AF9455317D6574F851.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_77231D65F9AF248286D2DD2789795358 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_77231D65F9AF248286D2DD2789795358.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_77EAAEFBF7DB43542B68C9C54B96E71B -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_77EAAEFBF7DB43542B68C9C54B96E71B.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_7B67BF31A06942E93DB2D48729ADE164 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_7B67BF31A06942E93DB2D48729ADE164.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_7B81B2B417473A244E240E5442E5A584 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_7B81B2B417473A244E240E5442E5A584.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_7C2DF039620DD791494EBC9571EC4702 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_7C2DF039620DD791494EBC9571EC4702.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_804B31A4240A31609BE55507CF13D4AF -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_804B31A4240A31609BE55507CF13D4AF.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_8085EAAFAFD005641F623ECD8E5CA2CE -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_8085EAAFAFD005641F623ECD8E5CA2CE.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_84A1F513388D432BC79751785347CA1C -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_84A1F513388D432BC79751785347CA1C.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_8877C0D8915D56B7636F0D2D21691F37 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_8877C0D8915D56B7636F0D2D21691F37.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_908C5009A79454DFBC69673A33E8539B -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_908C5009A79454DFBC69673A33E8539B.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_91785D291CBB3CC40AB8659C8E48CCC2 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_91785D291CBB3CC40AB8659C8E48CCC2.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_96C80F6315435E069F89D90B92C9AF28 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_96C80F6315435E069F89D90B92C9AF28.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_970B582FA9A724174BE31CD748AA6B78 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_970B582FA9A724174BE31CD748AA6B78.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_98255F75624265EE9253343B089B20EB -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_98255F75624265EE9253343B089B20EB.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_9eab5ec6ac3d99b498a1d16c1c815acf -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_9eab5ec6ac3d99b498a1d16c1c815acf.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_9EFF84BA812547C2A976CF5422FE6F5F -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_9EFF84BA812547C2A976CF5422FE6F5F.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_A089CE062ADB6BC44A720BA745894BAC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_A089CE062ADB6BC44A720BA745894BAC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_A16AAE7520DC43FD809352945FA733C4 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_A16AAE7520DC43FD809352945FA733C4.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_A5AD5B36B774D8346A0A1178784A7CB1 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_A5AD5B36B774D8346A0A1178784A7CB1.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_A70BEE519BF3C4AFE8FF967782BCE1C5 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_A70BEE519BF3C4AFE8FF967782BCE1C5.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_AAC664A5170FFE9D7A99FE3655D2EB07 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_AAC664A5170FFE9D7A99FE3655D2EB07.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_ABD864F9EA8C9D53643FBC09F33A6D80 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_ABD864F9EA8C9D53643FBC09F33A6D80.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_B5A81845CEE0B3B515471D47AB5DCA4D -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_B5A81845CEE0B3B515471D47AB5DCA4D.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_B8CF35CA81EEC9F3B9950639D7B081C2 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_B8CF35CA81EEC9F3B9950639D7B081C2.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_BCA1BC2A2A49AB231AE5D70813F95798 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_BCA1BC2A2A49AB231AE5D70813F95798.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_BD3A0501343A6108089D4377D59CC7C3 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_BD3A0501343A6108089D4377D59CC7C3.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_BDD4CD7DD0E397F62485A46461456B98 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_BDD4CD7DD0E397F62485A46461456B98.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_C1C069EBDAB76ED3B8A16261EF358254 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_C1C069EBDAB76ED3B8A16261EF358254.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_c1c4f01781cc94c4c8fb1542c0981a2a -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_c1c4f01781cc94c4c8fb1542c0981a2a.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_C700036D047AFEFD2509C0BEAE94E5C0 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_C700036D047AFEFD2509C0BEAE94E5C0.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_C7E8F3786E01F944DBE7F5ABC7E8C1B9 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_C7E8F3786E01F944DBE7F5ABC7E8C1B9.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_CFD2C1F142D260E3CB8B271543DA9F98 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_CFD2C1F142D260E3CB8B271543DA9F98.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_D20352A90C039D93DBF6126ECE614057 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_D20352A90C039D93DBF6126ECE614057.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_D2B2239FF44095189D0AC79E4F230906 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_D2B2239FF44095189D0AC79E4F230906.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_D2E6A39FF04EFD2B63510C209F107178 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_D2E6A39FF04EFD2B63510C209F107178.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_E8E2425A91A0CE509E96BEB5D26F3C4A -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_E8E2425A91A0CE509E96BEB5D26F3C4A.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_EA4E63A47BBC7D4396DAB18E0CB25839 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_EA4E63A47BBC7D4396DAB18E0CB25839.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_ECE71497D9AD3B941B9C38AAE3EAA60E -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_ECE71497D9AD3B941B9C38AAE3EAA60E.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_EDDFC45970FA9FA2690007E697D824AB -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_EDDFC45970FA9FA2690007E697D824AB.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_EFEE0228DC83E77358593193D847A0EC -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_EFEE0228DC83E77358593193D847A0EC.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_F02864575993F2261FB861FB01F71921 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_F02864575993F2261FB861FB01F71921.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_F0679767ED2736F8275A87DD9589575C -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_F0679767ED2736F8275A87DD9589575C.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_F0D6692ABB34D6119C7C9416F2FB0DEA -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_F0D6692ABB34D6119C7C9416F2FB0DEA.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_F2ADA5F02B0C6DA4F87FD7AFD9B6C4AB -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_F2ADA5F02B0C6DA4F87FD7AFD9B6C4AB.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_F60730A4A66673047777F5728467D401 -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_F60730A4A66673047777F5728467D401.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_F90E4FA5B9C5FAA37B1345D4D38C12DD -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\icm_F90E4FA5B9C5FAA37B1345D4D38C12DD.dll -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\ItemsState.ini -> Deleted
[PUP.Gen1][File] C:\ProgramData\SecTaskMan\WSBROW~1.DLL.q_Quarantine_FC80_q.ini -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\simplitec -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\simplitec\KMPFaster\cache\StartUp -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\simplitec\KMPFaster\cache -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\checkdetails\BrowserCleanerModule.result -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\simplitec\KMPFaster\checkdetails -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\driverupdate\driverupdate.log -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\simplitec\KMPFaster\driverupdate -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\ExceptionHandlerDll\Exception.exlog -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\ExceptionHandlerDll\Trace.log -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\simplitec\KMPFaster\ExceptionHandlerDll -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\gahelper.xml -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\newsfeed\data.xml -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\simplitec\KMPFaster\newsfeed -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\simplitec\KMPFaster\RegCleanerDll\Backups -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\RegCleanerDll\BlackList.cfg -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\RegCleanerDll\Log\2016-07-15 17-04-46 RegCleanerDll.log -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\simplitec\KMPFaster\RegCleanerDll\Log -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\RegCleanerDll\RegCleanerDll.cfg -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\simplitec\KMPFaster\RegCleanerDll -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\remote_devices.db -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\Rn5b3260.dat -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\Rn5c3260.dat -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\Rn5f3260.dat -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\Rn5s3260.dat -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\scheduler_ignore.dat -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\services\services.xml -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\simplitec\KMPFaster\services -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\Setup Log 2016-03-27 #002.log -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\simplitec_Power_Suite.ini -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\simplitec\KMPFaster\softwareproducts -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\03d09322094210491b780c5b420e5e0f.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\04ae9dd25be5d353d2eda9bc33119964.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\0985a20e6d19305d2bc17f8e4e7babfe.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\0d6da56b05a7e5cb6a155b6acd80aaa0.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\12ce7fb45c16798f338602fef1c4466f.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\13a775b7d0b48c4d6df5604cb8a04d68.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\1a776a77155aed50f0a782dcac8750d1.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\2e125e8daee00d323bcda6106a3221a9.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\42ac26a0c73fa832da33883f7cdfe0c1.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\51b933fbf4bdc6441c10f4adef24ec7e.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\56280b07e7992bc450b69631cc30a087.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\5ae56c073b93d1ddc9ec7cfc2b0f7a68.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\5f9210aa02e9a09760dc3617b3bff3b3.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\7229983d0f41f104dbb408bb28f89050.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\a41e71864e4b2e47efae6e6d27f4b959.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\b255368d4b0ae9842909dc00617b6df3.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\bb8d3d5c7f2e9f6f34e16f5f1265e824.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\e53765858d39e3a737f7a85d2a13d994.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\e858d147660ddb9dc60897935936ffd6.png -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\startup.log -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\startup\startup.xml -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\simplitec\KMPFaster\startup -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\usertips_DE.xml -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\usertips_EN.xml -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\usertips_ES.xml -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\usertips_FR.xml -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\usertips_IT.xml -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\usertips_KO.xml -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\usertips_NL.xml -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\usertips_PL.xml -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\usertips_PT.xml -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\usertips_RU.xml -> Deleted
[PUP.Gen1][File] C:\ProgramData\simplitec\KMPFaster\winsettings.dat -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\simplitec\KMPFaster -> Deleted
[PUP.HackTool][Folder] C:\Windows\AutoKMS -> Deleted
[PUP.HackTool][File] C:\Windows\AutoKMS\AutoKMS.ini -> Deleted
[PUP.HackTool][File] C:\Windows\AutoKMS\AutoKMS.log -> Deleted
[PUP.HackTool][File] C:\Windows\AutoKMS\Uninstall-Autokms-Tasks.cmd -> Deleted
[PUP.DownloadAssistant][Folder] C:\Users\USER\AppData\Roaming\DVDVideoSoft -> Deleted
[PUP.DownloadAssistant][File] C:\Users\USER\AppData\Roaming\DVDVideoSoft\common.cfg -> Deleted
[PUP.DownloadAssistant][File] C:\Users\USER\AppData\Roaming\DVDVideoSoft\FreeYTVDownloader.cfg -> Deleted
[PUP.DownloadAssistant][File] C:\Users\USER\AppData\Roaming\DVDVideoSoft\freeytvdownloader_userlist.txt -> Deleted
[PUP.Gen1][Folder] C:\Users\USER\AppData\Roaming\Easeware -> Deleted
[PUP.Gen1][Folder] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\4ceyoqwo.qfr -> Deleted
[PUP.Gen1][File] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\Drivers.data -> Deleted
[PUP.Gen1][Folder] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\emwiv0zy.gq4 -> Deleted
[PUP.Gen1][Folder] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\fsljrdvr.yyt -> Deleted
[PUP.Gen1][Folder] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\hjsepx5w.drk -> Deleted
[PUP.Gen1][Folder] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\mlklmjnm.imk -> Deleted
[PUP.Gen1][Folder] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\o2dqmah5.5gh -> Deleted
[PUP.Gen1][Folder] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\s4njha42.nog -> Deleted
[PUP.Gen1][File] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\sgfdshea.thw\acpivpc.cat -> Deleted
[PUP.Gen1][File] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\sgfdshea.thw\acpivpc.inf -> Deleted
[PUP.Gen1][File] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\sgfdshea.thw\acpivpc.sys -> Deleted
[PUP.Gen1][Folder] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\sgfdshea.thw -> Deleted
[PUP.Gen1][Folder] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\stzg4yoe.roi -> Deleted
[PUP.Gen1][File] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\z33uuxte.bqs\intcdaud.cat -> Deleted
[PUP.Gen1][File] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\z33uuxte.bqs\intcdaud.inf -> Deleted
[PUP.Gen1][File] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\z33uuxte.bqs\intcdaud.sys -> Deleted
[PUP.Gen1][Folder] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\z33uuxte.bqs -> Deleted
[PUP.Gen1][Folder] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\zszafuz1.25w -> Deleted
[PUP.Gen1][Folder] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers\ztwxlgbk.cca -> Deleted
[PUP.Gen1][Folder] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\drivers -> Deleted
[PUP.Gen1][File] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy\settings.dat -> Deleted
[PUP.Gen1][Folder] C:\Users\USER\AppData\Roaming\Easeware\DriverEasy -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\SecTaskMan -> ERROR [3]
[PUP.Gen1][Folder] C:\ProgramData\simplitec -> ERROR [3]
[PUP.HackTool][Folder] C:\Program Files\KMSpico -> Deleted
[PUP.Gen1][Folder] C:\Program Files (x86)\simplitec -> Deleted

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 1 ¤¤¤
[PUM.SearchEngine][Firefox:Config] z94n8t79.default : user_pref("browser.search.defaultenginename", "Coolrom Search Engine"); -> Deleted

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST500LT012-1DG142 +++++
--- User ---
[MBR] 5d43a0b57305f7e812c5c5626882d2d7
[BSP] a7f419dda298f4e53c24e5d515cc1d5d : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 119163 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 244049920 | Size: 836 MB
2 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 245764033 | Size: 356935 MB
User = LL1 ... OK
User = LL2 ... OK
 
JRT scan

Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Pro x64
Ran by Max (Administrator) on Tue 08/08/2017 at 17:24:45.73
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 2

Successfully deleted: C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\z94n8t79.default\searchplugins\youtube-video-search.xml (File)
Successfully deleted: C:\WINDOWS\wininit.ini (File)



Registry: 1

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 08/08/2017 at 17:29:18.24
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
adware cleaner log:

Code:
# AdwCleaner 7.0.1.0 - Logfile created on Tue Aug 08 12:18:01 2017
# Updated on 2017/05/08 by Malwarebytes
# Running on Windows 10 Pro (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

No malicious folders deleted.

***** [ Files ] *****

No malicious files deleted.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks deleted.

***** [ Registry ] *****

No malicious registry entries deleted.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries deleted.

*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[C0].txt - [5637 B] - [2017/2/18 15:57:30]
C:/AdwCleaner/AdwCleaner[C1].txt - [1924 B] - [2017/8/3 12:16:42]
C:/AdwCleaner/AdwCleaner[S0].txt - [5054 B] - [2017/2/18 10:49:52]
C:/AdwCleaner/AdwCleaner[S1].txt - [5126 B] - [2017/2/18 15:39:49]
C:/AdwCleaner/AdwCleaner[S2].txt - [1866 B] - [2017/8/3 11:58:50]
C:/AdwCleaner/AdwCleaner[S3].txt - [1282 B] - [2017/8/8 12:16:14]


########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt ##########
 
zhp diag scan log:
[the link you gave didn't open, so I downloaded from majorgeeks]

~ ZHPDiag v2017.8.4.134 By Nicolas Coolman (2017/08/04)
~ Run by Max (Administrator) (2017/08/08 18:22:20)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Legal
~ State version: Version OK
~ Mode: Scan
~ Report: C:\Users\USER\Desktop\ZHPDiag.txt
~ Report: C:\Users\USER\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ System startup: Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 15063) =>.Microsoft Corporation

---\\ Internet Browsers (4) - 0s
~ GCIE: Google Chrome v60.0.3112.90
~ MFIE: Mozilla Firefox 39.0 (x86 en-US)
~ MSIE: Microsoft Edge v40
~ MSIE: Internet Explorer v11.483.15063.0

---\\ Windows Product Information (3) - 3s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK

---\\ System protection software (1) - 2s
Windows Defender (Activate) (Protection)

---\\ System optimization software (1) - 3s
~ Tweaking.com - Windows Repair v4.0.1 (Optimize)

---\\ Surveillance software (1) - 3s
~ Adobe Flash Player 26 PPAPI (Surveillance)

---\\ Information on the system (6) - 0s
~ Operating System: Intel64 Family 6 Model 69 Stepping 1, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 4088.172 MB (42% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 55 GB (46%) free of 119 GB : OK =>.Disk Space

---\\ Connection to the system mode (3) - 0s
~ Computer Name: ADMIN
~ User Name: Max
~ Logged in as Administrator

---\\ Enumeration of the disk units (2) - 0s
~ Drive C: has 55 GB free of 119 GB (System)
~ Drive D: has 3 GB free of 356 GB

---\\ State of the Windows Security Center (7) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Search Generic System Files (24) - 3s
[MD5.CA3BF0F15BA4F24D511BFEE725CC89BD] - 20/06/2017 - (.Microsoft Corporation - Windows Explorer.) -- C:\WINDOWS\Explorer.exe [4847424] =>.Microsoft Windows®
[MD5.ECB702B8C5650381C0784F1EEABB97BC] - 19/03/2017 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\WINDOWS\System32\rundll32.exe [68608] =>.Microsoft Corporation
[MD5.B2DB5876B6F68D32E470F691C7088F3F] - 07/07/2017 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\WINDOWS\System32\Wininit.exe [318232] =>.Microsoft Windows Publisher®
[MD5.BC776B6B434641AF71ED0CC00BC859AA] - 07/07/2017 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\WINDOWS\System32\wininet.dll [3307008] =>.Microsoft Corporation
[MD5.31E3287EF6D97C5864A301CEA75BBBA1] - 07/07/2017 - (.Microsoft Corporation - Windows Logon Application.) -- C:\WINDOWS\System32\Winlogon.exe [706560] =>.Microsoft Corporation
[MD5.50CDF68A8EA8A2A9165CD573FA6C42D8] - 19/03/2017 - (.Microsoft Corporation - Software Licensing Library.) -- C:\WINDOWS\System32\sppcomapi.dll [414208] =>.Microsoft Corporation
[MD5.0F9FA6A2D4EAE50393DCE473759A9845] - 19/03/2017 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\WINDOWS\System32\dnsapi.dll [661224] =>.Microsoft Windows®
[MD5.3F969D5ADEAB3284ABD500B37D74A8F8] - 19/03/2017 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\WINDOWS\Syswow64\dnsapi.dll [508344] =>.Microsoft Windows®
[MD5.AC1928C2F7505BD556C552F153B062AB] - 19/03/2017 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\WINDOWS\System32\drivers\AFD.sys [610712] =>.Microsoft Windows®
[MD5.01733BEEE02E51F712330D5909BD701C] - 19/03/2017 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [29088] =>.Microsoft Windows®
[MD5.B6E5AD7C83A5254DEE9D86023C0E5A81] - 19/03/2017 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [93184] =>.Microsoft Corporation
[MD5.ABE77AD954BC3D72F559CF0C381E50BC] - 19/03/2017 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [160256] =>.Microsoft Corporation
[MD5.185A4519B7764F4DEF714D890A7A9FD2] - 19/03/2017 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\DfsC.sys [150528] =>.Microsoft Corporation
[MD5.02B9639D9997E95CDF2F4C4F3BDCC73D] - 20/06/2017 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [86528] =>.Microsoft Corporation
[MD5.C6C8315E3262FAE460529C6DA2951682] - 19/03/2017 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [115200] =>.Microsoft Corporation
[MD5.DCC05E5EAA580C97F13B434FAFACED85] - 19/03/2017 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [214528] =>.Microsoft Corporation
[MD5.F2AD1B72C5A6475FB5FF332E1980DF88] - 19/03/2017 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [467352] =>.Microsoft Windows®
[MD5.30C2F67EC84EB11B22011620107E0325] - 19/03/2017 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [305152] =>.Microsoft Corporation
[MD5.8D72D5038C5F91AFEF1B160FE524C2D9] - 20/06/2017 - (.Microsoft Corporation - NT File System Driver.) -- C:\WINDOWS\System32\drivers\ntfs.sys [2327456] =>.Microsoft Windows®
[MD5.2CC6C325B271C7CA60F374F8F868CB45] - 19/03/2017 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\WINDOWS\System32\drivers\Parport.sys [97792] =>.Microsoft Corporation
[MD5.5279EC98F6218D29EADDFECCC0D80E9A] - 19/03/2017 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [107008] =>.Microsoft Corporation
[MD5.53A01D3FDB701AC5D9DDE4140227E3D9] - 19/03/2017 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [183296] =>.Microsoft Corporation
[MD5.892AB2637603A5E9507C39E61101C3C3] - 03/06/2017 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [119712] =>.Microsoft Windows®
[MD5.E3429DBBEA3965BB96E24B16EF4A2551] - 19/03/2017 - (.Microsoft Corporation - Volume Shadow Copy driver.) -- C:\WINDOWS\System32\drivers\volsnap.sys [397216] =>.Microsoft Windows®

---\\ Non Microsoft non disabled Windows Services (12) - 3s
O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\WINDOWS\system32\atiesrxx.exe =>.AMD
O23 - Service: C:\WINDOWS\system32\CxAudMsg64.exe,-100 (CxAudMsg) . (.Conexant Systems Inc. - Conexant Audio Message Service.) - C:\WINDOWS\system32\CxAudMsg64.exe =>.Conexant Systems Inc.
O23 - Service: Elan Service (ETDService) . (.ELAN Microelectronics Corp. - Elan Service.) - C:\Program Files\Elantech\ETDService.exe =>.ELAN Microelectronics Corporation®
O23 - Service: Google Update Service (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) . (.Intel Corporation - igfxCUIService Module.) - C:\WINDOWS\system32\igfxCUIService.exe =>.Intel Corporation
O23 - Service: System Interface Foundation Service (ImControllerService) . (.Lenovo Group Limited - Lenovo.Modern.ImController.) - C:\Program Files\lenovo\ImController\Service\Lenovo.Modern.ImController.exe =>.Lenovo®
O23 - Service: Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe =>.Intel(R) Corporation
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe =>.Intel Corporation - Intel® Management Engine Firmware®
O23 - Service: Conexant SmartAudio service (SAService) . (...) - C:\Windows\System32\SASrv.exe (.not file.)
O23 - Service: Sandboxie Service (SbieSvc) . (.Sandboxie Holdings, LLC - Sandboxie Service.) - d:\Program Files\Sandboxie\SbieSvc.exe =>.Invincea, Inc.®
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl®
O23 - Service: Power Control [2014/08/18 01:23:32] ({C5F942FD-1110-4664-86CE-0C6BDA305235}) . (.CyberLink Corp. - .) - C:\Program Files (x86)\CyberLink\PowerDVD14\Common\NavFilter\000.fcl =>.CyberLink Corp.®

---\\ Services not Microsoft (SR=Run, SS=Stop) (20) - 35s
SS - Demand [11/07/2017] [ 272384] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated®
SR - Auto [04/05/2017] [ 551832] (AMD External Events Utility) . (.AMD.) - C:\WINDOWS\system32\atiesrxx.exe =>.Advanced Micro Devices, Inc.®
SS - Demand [12/06/2017] [ 301496] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe =>.Intel(R) pGFX®
SR - Auto [25/07/2013] [ 206552] C:\WINDOWS\system32\CxAudMsg64.exe,-100 (CxAudMsg) . (.Conexant Systems Inc..) - C:\WINDOWS\system32\CxAudMsg64.exe =>.Conexant Systems, Inc.®
SR - Auto [24/08/2015] [ 135072] Elan Service (ETDService) . (.ELAN Microelectronics Corp..) - C:\Program Files\Elantech\ETDService.exe =>.ELAN Microelectronics Corporation®
SS - Demand [27/02/2016] [ 1045256] FLEXnet Licensing Service (FLEXnet Licensing Service) . (.Acresso Software Inc..) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe =>.Acresso Software Inc.®
SS - Auto [03/10/2015] [ 144200] Google Update Service (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [03/10/2015] [ 144200] Google Update Service (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SR - Auto [12/06/2017] [ 373688] Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) . (.Intel Corporation.) - C:\WINDOWS\system32\igfxCUIService.exe =>.Intel(R) pGFX®
SR - Auto [05/06/2017] [ 57160] System Interface Foundation Service (ImControllerService) . (.Lenovo Group Limited.) - C:\Program Files\lenovo\ImController\Service\Lenovo.Modern.ImController.exe =>.Lenovo®
SR - Auto [27/08/2013] [ 747520] Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe =>.Intel(R) Corporation
SS - Demand [27/08/2013] [ 828376] Intel(R) Capability Licensing Service TCP IP Interface (Intel(R) Capability Licensing Service TCP IP Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe =>.Intel® Trusted Connect Service®
SR - Auto [17/09/2013] [ 169432] Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe =>.Intel Corporation - Intel® Management Engine Firmware®
SS - Demand [17/09/2013] [ 169432] Malwarebytes Service (MBAMService) . (.Malwarebytes.) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation®
SS - Demand [17/09/2013] [ 169432] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation®
SS - Disabl [17/09/2013] [ 169432] RosettaStoneDaemon (RosettaStoneDaemon) . (.Rosetta Stone Ltd..) - C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe =>.Rosetta Stone Ltd®
SR - Auto [17/09/2013] [ 169432] Sandboxie Service (SbieSvc) . (.Sandboxie Holdings, LLC.) - d:\Program Files\Sandboxie\SbieSvc.exe =>.Invincea, Inc.®
SS - Auto [17/09/2013] [ 169432] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl®
SS - Demand [17/09/2013] [ 169432] SwitchBoard (SwitchBoard) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe =>.Adobe Systems Incorporated
SS - Auto [17/09/2013] [ 169432] Power Control [2014/08/18 01:23:32] ({C5F942FD-1110-4664-86CE-0C6BDA305235}) . (.CyberLink Corp..) - C:\Program Files (x86)\CyberLink\PowerDVD14\Common\NavFilter\000.fcl =>.CyberLink Corp.®

---\\ Task Planned Automatically (19) - 17s
[MD5.68DDCB629A7F2C5A3D2392F8177A3CD0] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [7658200] (.Activate.) =>.Piriform Ltd®
[MD5.053EEEE1ABAE53F044F1E386E22AE525] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] (.Activate.) =>.Google Inc®
[MD5.053EEEE1ABAE53F044F1E386E22AE525] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] (.Activate.) =>.Google Inc®
[MD5.8E65EBE8511CD0757BBB17C7670F6563] [APT] [Tweaking.com - Windows Repair Tray Icon] (.Tweaking.com.) -- C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [218336] (.Activate.) =>.Tweaking LLC®
[MD5.8FE11A6B735F7C904E1DC0EF7EA79B78] [APT] [{1E6113B1-6320-42D6-98F3-9B2BBA5E0C28}] (.Mozilla Corporation.) -- d:\program files (x86)\mozilla firefox\firefox.exe [392136] (.Activate.) =>.Mozilla Corporation®
[MD5.8A268094274301F2673D0D656BF763E5] [APT] [Lenovo\ImController\TimeBasedEvents\06484341-7f04-42cc-ab7a-e55cbeb6bc9f] (.Lenovo Group Limited.) -- C:\Program Files\lenovo\ImController\Service\Lenovo.Modern.ImController.exe [57160] (.Activate.) =>.Lenovo®
[MD5.8A268094274301F2673D0D656BF763E5] [APT] [Lenovo\ImController\TimeBasedEvents\08483c54-0d53-407b-96a4-579aa11dfc78] (.Lenovo Group Limited.) -- C:\Program Files\lenovo\ImController\Service\Lenovo.Modern.ImController.exe [57160] (.Activate.) =>.Lenovo®
[MD5.8A268094274301F2673D0D656BF763E5] [APT] [Lenovo\ImController\TimeBasedEvents\110323a4-c849-4dae-9628-a720238a215e] (.Lenovo Group Limited.) -- C:\Program Files\lenovo\ImController\Service\Lenovo.Modern.ImController.exe [57160] (.Activate.) =>.Lenovo®
[MD5.8A268094274301F2673D0D656BF763E5] [APT] [Lenovo\ImController\TimeBasedEvents\5115b37c-ad53-4808-937c-4d8f4eedbddb] (.Lenovo Group Limited.) -- C:\Program Files\lenovo\ImController\Service\Lenovo.Modern.ImController.exe [57160] (.Activate.) =>.Lenovo®
O39 - APT: Unknown - (.Legitimate.) -- C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job [214]
O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\WINDOWS\System32\Tasks\CCleanerSkipUAC [2846] =>.Piriform Ltd®
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore [3120] =>.Google Inc®
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA [3344] =>.Google Inc®
O39 - APT: Unknown - (...) -- C:\WINDOWS\System32\Tasks\shutdown [2478]
O39 - APT: Tweaking.com - Windows Repair Tray Icon - (.Tweaking.com.) -- C:\WINDOWS\System32\Tasks\Tweaking.com - Windows Repair Tray Icon [3758] =>.Tweaking LLC®
O39 - APT: {1E6113B1-6320-42D6-98F3-9B2BBA5E0C28} - (.Mozilla Corporation.) -- C:\WINDOWS\System32\Tasks\{1E6113B1-6320-42D6-98F3-9B2BBA5E0C28} [2240] =>.Mozilla Corporation®
HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Nero
HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\shutdown
HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Tweaking.com - Windows Repair Tray Icon

---\\ Auto loading programs from Registry and folders (9) - 1s
O4 - HKLM\..\Run: [SecurityHealth] . (.Microsoft Corporation - Windows Defender notification icon.) -- C:\Program Files\Windows Defender\MSASCuiL.exe =>.Microsoft Windows®
O4 - HKLM\..\Run: [cAudioFilterAgent] . (.Conexant Systems, Inc. - Conexant High Definition Audio Filter Agent.) -- C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe =>.Conexant Systems, Inc.®
O4 - HKLM\..\Run: [SmartAudio] . (.Conexant Systems, Inc. - SmartAudio CPL (32bit).) -- C:\Program Files\CONEXANT\SAII\SACpl.exe =>.Conexant Systems, Inc.®
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe =>.Adobe Systems Incorporated®
O4 - HKCU\..\Run: [SandboxieControl] . (.Sandboxie Holdings, LLC - Sandboxie Control.) -- d:\Program Files\Sandboxie\SbieCtrl.exe =>.Invincea, Inc.®
O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- D:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc.
O4 - HKLM\..\Wow6432Node\Run: [KeyScrambler] . (.QFX Software Corporation - KeyScrambler.) -- d:\Program Files (x86)\KeyScrambler\keyscrambler.exe =>.QFX Software Corporation®
O4 - HKUS\S-1-5-21-900945925-988278395-3478122750-1001\..\Run: [SandboxieControl] . (.Sandboxie Holdings, LLC - Sandboxie Control.) -- d:\Program Files\Sandboxie\SbieCtrl.exe =>.Invincea, Inc.®
O4 - HKUS\S-1-5-21-900945925-988278395-3478122750-1001\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- D:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc.

---\\ Process running (24) - 4s
[MD5.00000000000000000000000000000000] - (.Intel Corporation - igfxCUIService Module.) -- C:\WINDOWS\system32\igfxCUIService.exe [0] [PID.1744] =>.Intel Corporation
[MD5.00000000000000000000000000000000] - (.AMD - AMD External Events Service Module.) -- C:\WINDOWS\system32\atiesrxx.exe [0] [PID.1936] =>.AMD
[MD5.00000000000000000000000000000000] - (.AMD - AMD External Events Client Module.) -- C:\WINDOWS\system32\atieclxx.exe [0] [PID.2168] =>.AMD
[MD5.F17F3D35E94CFB0D7B85BAE2B1DD3A9E] - (.Sandboxie Holdings, LLC - Sandboxie Service.) -- d:\Program Files\Sandboxie\SbieSvc.exe [198792] [PID.2552] =>.Invincea, Inc.®
[MD5.00000000000000000000000000000000] - (.Conexant Systems Inc. - Conexant Audio Message Service.) -- C:\WINDOWS\system32\CxAudMsg64.exe [0] [PID.3576] =>.Conexant Systems Inc.
[MD5.2C101AA0A186C079C4044F1FD0D1E5E5] - (.ELAN Microelectronics Corp. - Elan Service.) -- C:\Program Files\Elantech\ETDService.exe [135072] [PID.3632] =>.ELAN Microelectronics Corporation®
[MD5.8A268094274301F2673D0D656BF763E5] - (.Lenovo Group Limited - Lenovo.Modern.ImController.) -- C:\Program Files\lenovo\ImController\Service\Lenovo.Modern.ImController.exe [57160] [PID.3640] =>.Lenovo®
[MD5.DAE6C3099D291EED8922A65C29ABCF52] - (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520] [PID.3696] =>.Intel(R) Corporation
[MD5.FA732C734521F9B74149272636D1D4EA] - (.ELAN Microelectronics Corp. - ETD Control Center.) -- C:\Program Files\Elantech\ETDCtrl.exe [3743648] [PID.532] =>.ELAN Microelectronics Corporation®
[MD5.AF5DB228216629E05A5EB3A20BEF2693] - (.ELAN Microelectronics Corp. - ETD Control Center Helper.) -- C:\Program Files\Elantech\ETDCtrlHelper.exe [2654624] [PID.6528] =>.ELAN Microelectronics Corporation®
[MD5.3A9F29C46129C094B5FA09BBD42AFFB0] - (.ELAN Microelectronics Corp. - ETDIntelligent.) -- C:\Program Files\Elantech\ETDIntelligent.exe [2267552] [PID.6560] =>.ELAN Microelectronics Corporation®
[MD5.00000000000000000000000000000000] - (.Intel Corporation - igfxEM Module.) -- C:\WINDOWS\system32\igfxEM.exe [0] [PID.6864] =>.Intel Corporation
[MD5.00000000000000000000000000000000] - (.Intel Corporation - igfxHK Module.) -- C:\WINDOWS\system32\igfxHK.exe [0] [PID.6892] =>.Intel Corporation
[MD5.FFBFE1175531CD582D89796835CBB598] - (.Conexant Systems, Inc. - Conexant High Definition Audio Filter Agent.) -- C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe [935104] [PID.7192] =>.Conexant Systems, Inc.®
[MD5.3B292B4214F7CCB2076262CA0D235B70] - (.Tonec Inc. - Internet Download Manager (IDM).) -- D:\Program Files (x86)\Internet Download Manager\IDMan.exe [4001848] [PID.7340] =>.Tonec Inc.
[MD5.21C640C0579CCE82AD8EB14FF28C0DD8] - (.QFX Software Corporation - KeyScrambler.) -- D:\Program Files (x86)\KeyScrambler\KeyScrambler.exe [509216] [PID.7572] =>.QFX Software Corporation®
[MD5.B289C20C10B241F6016FECD92B267098] - (.Tonec Inc. - Internet Download Manager agent for click m.) -- D:\Program Files (x86)\Internet Download Manager\IEMonitor.exe [275512] [PID.7660] =>.Tonec Inc.®
[MD5.26FBEC366638A0162F442D26CC51B026] - (.QFX Software Corporation - KeyScrambler.) -- D:\Program Files (x86)\KeyScrambler\x64\KeyScrambler.exe [563488] [PID.7728] =>.QFX Software Corporation®
[MD5.52069AEB42D3D0F97CBCA1085EBF55E6] - (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432] [PID.8012] =>.Intel Corporation - Intel® Management Engine Firmware®
[MD5.8E65EBE8511CD0757BBB17C7670F6563] - (.Tweaking.com - Tweaking.com - Windows Repair Tray Icon.) -- C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [218336] [PID.6344] =>.Tweaking LLC®
[MD5.C9E3BD3977709EF215AD82AE5A838EF1] - (.Lenovo Group Limited - Lenovo.Modern.ImController.PluginHost.) -- C:\Program Files\lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe [36680] [PID.7484] =>.Lenovo®
[MD5.C9E3BD3977709EF215AD82AE5A838EF1] - (.Lenovo Group Limited - Lenovo.Modern.ImController.PluginHost.) -- C:\Program Files\lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe [36680] [PID.8008] =>.Lenovo®
[MD5.797F95CDD6C99A10CAFDC959F3CF1212] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\USER\AppData\Roaming\ZHP\ZHPDiag3.exe [2806656] [PID.8480] =>.Nicolas Coolman
[MD5.C9E3BD3977709EF215AD82AE5A838EF1] - (.Lenovo Group Limited - Lenovo.Modern.ImController.PluginHost.) -- C:\Program Files\lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe [36680] [PID.1072] =>.Lenovo®

---\\ Google Chrome, Start,Search,Extensions (12) - 0s
G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.gstatic.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.com.np =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] http://drive.google.com/ =>.Google Inc. {Drive}
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] http://www.youtube.com =>.Youtube {Youtube}
G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] http://www.google.com/ =>.Google Inc. {Hidden Chrome extensions}
G2 - GCE: Preference [User Data\Default] [kgejglhpjiefppelpmljglcjbhoiplfn]
G2 - GCE: Preference [User Data\Default] [kkmlkkjojmombglmlpbpapmhcaljjkde] Zhongwen Chinese Popup Dictionary
G2 - GCE: Preference [User Data\Default] [mdkfiefeoimmobmhdimachkfcpkgahlc]
G2 - GCE: Preference [User Data\Default] [melfcogdhodeocnkdiplgdpkllopbhan] http://ttsreader.com/
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] =>.Google Inc. {Wallet}
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] http://mail.google.com/ =>.Google Inc. {Gmail}
G2 - GCE: Preference [User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.

---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (13) - 7s
P2 - EXT FILE: (.Activate Reader View - The Reader View is a feature that stri.) -- C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\z94n8t79.default\extensions\@activatereaderview.xpi
P2 - EXT FILE: (.http://coolrom.com/contact.php - Coolrom Search Engine.) -- C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\z94n8t79.default\extensions\{0fc22c4c-93ed-48ea-ad12-dc8039cf3795}.xpi
P2 - EXT FILE: (.Adblock Plus - Ads were yesterday!.) -- C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\z94n8t79.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi =>.Adblock Plus
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\aushelper@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT: (.Mozilla & Android Open Source Project - ADB Helper.) -- C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\z94n8t79.default\extensions\adbhelper@mozilla.org =>.Mozilla & Android Open Source Project
P2 - EXT: (.Justin Kovalchuk - Perapera Chinese.) -- C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\z94n8t79.default\extensions\chineseperakun@gmail.com =>.Justin Kovalchuk
P2 - EXT: (.Internet Download Manager, Tonec Inc. - IDM integration.) -- C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\z94n8t79.default\extensions\mozilla_cc2@internetdownloadmanager.com =>.Internet Download Manager, Tonec Inc.
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_137.dll =>.Adobe Systems Incorporated
P2 - FPN: [HKLM] [@google.com/npPicasa3,version=3.0.0] - (.Google, Inc..) -- C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll =>.Google, Inc.

---\\ Internet Explorer Extensions, Start, Search (19) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com =>.Google Inc.
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKEY_USERS\S-1-5-21-900945925-988278395-3478122750-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/ =>.Microsoft Corporation
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphan =>.Microsoft Internet Explorer

---\\ Internet Explorer, Proxy Management (6) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=

---\\ Hosts file redirection (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (24)

---\\ Browser Helper Object (BHO) (2) - 1s
O2 - BHO: IDM Helper [64Bits] - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- d:\Program Files (x86)\Internet Download Manager\IDMIECC.dll =>.Tonec Inc.®
O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- D:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL =>.Microsoft Corporation®

---\\ Global shortcuts Startup (131) - 12s
O4 - GS\Desktop [Administrator]: Anki.lnk . (...) D:\Program Files (x86)\Anki\anki.exe
O4 - GS\Desktop [Administrator]: Basic Patterns of Chinese Grammar_ A Student's Guide - Qin Xue Herzberg - Shortcut.lnk . (...) D:\Downloads\Basic Patterns of Chinese Grammar by Qin Xue Herzberg\Basic Patterns of Chinese Grammar_ A Student's Guide - Qin Xue Herzberg.pdf
O4 - GS\Desktop [Administrator]: Format Factory.lnk . (.Free Time - FormatFactory.) C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe =>.Free Time
O4 - GS\Desktop [Administrator]: HTTrack Website Copier.lnk . (.HTTrack - WinHTTrack Website Copier, Copy Websites to.) D:\Program Files\WinHTTrack\WinHTTrack.exe =>.Open Source Developer, Xavier Roche®
O4 - GS\Desktop [Administrator]: JDownloader 2.lnk . (.AppWork GmbH - JDownloader 2 Launcher.) D:\Program Files (x86)\jdownloader 2\JDownloader v2.0\JDownloader2.exe =>.Appwork GmbH®
O4 - GS\Desktop [Administrator]: Journal - Shortcut.lnk . (...) D:\documents\Journal
O4 - GS\Desktop [Administrator]: Modern Mandarin Chinese Grammar A Practical Guide - Shortcut.lnk . (...) D:\Downloads\Chinese Language Learning Pack\05.Grammar, Workbooks, Usage\Modern Mandarin Chinese Grammar A Practical Guide.pdf
O4 - GS\Desktop [Administrator]: mp3DirectCut.lnk . (.Martin Pesch - mp3DirectCut - Direct MP3 editor and record.) D:\Program Files (x86)\mp3DirectCut\mp3DirectCut.exe =>.Martin Pesch
O4 - GS\Desktop [Administrator]: PeerBlock.lnk . (.PeerBlock, LLC - PeerBlock.) D:\Program Files\PeerBlock\peerblock.exe =>.PeerBlock, LLC®
O4 - GS\Desktop [Administrator]: procexp64 - Shortcut.lnk . (.Sysinternals - www.sysinternals.com - Sysinternals Process Explorer.) D:\softwares\procexp64.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Administrator]: Sandboxed Web Browser.lnk . (.Sandboxie Holdings, LLC - Sandboxie Start.) D:\Program Files\Sandboxie\Start.exe default_browser =>.Invincea, Inc.®
O4 - GS\Desktop [Administrator]: Subtitle Edit.lnk . (.Nikse - Subtitle Edit.) C:\Program Files\Subtitle Edit\SubtitleEdit.exe =>.Nikse
O4 - GS\Desktop [Administrator]: The Secrets Kyusho - Pressure Point Fighting (2012) - Shortcut.lnk . (...) D:\Downloads\The Secrets Kyusho - Pressure Point Fighting (2012).pdf
O4 - GS\Desktop [Administrator]: Tweaking.com - Windows Repair.lnk . (.Tweaking.com - Tweaking.com - Windows Repair.) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\Repair_Windows.exe =>.Tweaking LLC®
O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\USER\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Administrator]: JDownloader 2.lnk . (.AppWork GmbH - JDownloader 2 Launcher.) D:\Program Files (x86)\jdownloader 2\JDownloader v2.0\JDownloader2.exe =>.Appwork GmbH®
O4 - GS\Quicklaunch [Administrator]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Administrator]: Sandboxed Web Browser.lnk . (.Sandboxie Holdings, LLC - Sandboxie Start.) D:\Program Files\Sandboxie\Start.exe default_browser =>.Invincea, Inc.®
O4 - GS\sendTo [Administrator]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrator]: Format Factory.lnk . (.Free Time - FormatFactory.) C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe =>.Free Time
O4 - GS\sendTo [Administrator]: Sandboxie - DefaultBox.lnk . (.Sandboxie Holdings, LLC - Sandboxie Start.) D:\Program Files\Sandboxie\Start.exe /box:DefaultBox =>.Invincea, Inc.®
O4 - GS\sendTo [Administrator]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\TaskBar [Administrator]: MetaTrader (2).lnk . (.MetaQuotes Software Corp. - MetaTrader.) D:\Program Files (x86)\MetaTrader - EXNESS\terminal.exe {00A74246F26ADF987743017FED54891570} =>.MetaQuotes Software Corp.
O4 - GS\TaskBar [Administrator]: MetaTrader.lnk . (.MetaQuotes Software Corp. - MetaTrader.) D:\Program Files (x86)\InstaTrader\terminal.exe {00A74246F26ADF987743017FED54891570} =>.MetaQuotes Software Corp.
O4 - GS\TaskBar [Administrator]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) D:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Administrator]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\Programs [Administrator]: AMD Radeon Settings.lnk . (.Advanced Micro Devices, Inc. - .) C:\Program Files (x86)\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.
O4 - GS\Programs [Administrator]: Anki.lnk . (...) D:\Program Files (x86)\Anki\anki.exe
O4 - GS\Programs [Administrator]: Optional Features.lnk . (.Microsoft Corporation - Features On Demand Helper.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Desktop [Guest]: Anki.lnk . (...) D:\Program Files (x86)\Anki\anki.exe
O4 - GS\Desktop [Guest]: Basic Patterns of Chinese Grammar_ A Student's Guide - Qin Xue Herzberg - Shortcut.lnk . (...) D:\Downloads\Basic Patterns of Chinese Grammar by Qin Xue Herzberg\Basic Patterns of Chinese Grammar_ A Student's Guide - Qin Xue Herzberg.pdf
O4 - GS\Desktop [Guest]: Format Factory.lnk . (.Free Time - FormatFactory.) C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe =>.Free Time
O4 - GS\Desktop [Guest]: HTTrack Website Copier.lnk . (.HTTrack - WinHTTrack Website Copier, Copy Websites to.) D:\Program Files\WinHTTrack\WinHTTrack.exe =>.Open Source Developer, Xavier Roche®
O4 - GS\Desktop [Guest]: JDownloader 2.lnk . (.AppWork GmbH - JDownloader 2 Launcher.) D:\Program Files (x86)\jdownloader 2\JDownloader v2.0\JDownloader2.exe =>.Appwork GmbH®
O4 - GS\Desktop [Guest]: Journal - Shortcut.lnk . (...) D:\documents\Journal
O4 - GS\Desktop [Guest]: Modern Mandarin Chinese Grammar A Practical Guide - Shortcut.lnk . (...) D:\Downloads\Chinese Language Learning Pack\05.Grammar, Workbooks, Usage\Modern Mandarin Chinese Grammar A Practical Guide.pdf
O4 - GS\Desktop [Guest]: mp3DirectCut.lnk . (.Martin Pesch - mp3DirectCut - Direct MP3 editor and record.) D:\Program Files (x86)\mp3DirectCut\mp3DirectCut.exe =>.Martin Pesch
O4 - GS\Desktop [Guest]: PeerBlock.lnk . (.PeerBlock, LLC - PeerBlock.) D:\Program Files\PeerBlock\peerblock.exe =>.PeerBlock, LLC®
O4 - GS\Desktop [Guest]: procexp64 - Shortcut.lnk . (.Sysinternals - www.sysinternals.com - Sysinternals Process Explorer.) D:\softwares\procexp64.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Guest]: Sandboxed Web Browser.lnk . (.Sandboxie Holdings, LLC - Sandboxie Start.) D:\Program Files\Sandboxie\Start.exe default_browser =>.Invincea, Inc.®
O4 - GS\Desktop [Guest]: Subtitle Edit.lnk . (.Nikse - Subtitle Edit.) C:\Program Files\Subtitle Edit\SubtitleEdit.exe =>.Nikse
O4 - GS\Desktop [Guest]: The Secrets Kyusho - Pressure Point Fighting (2012) - Shortcut.lnk . (...) D:\Downloads\The Secrets Kyusho - Pressure Point Fighting (2012).pdf
O4 - GS\Desktop [Guest]: Tweaking.com - Windows Repair.lnk . (.Tweaking.com - Tweaking.com - Windows Repair.) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\Repair_Windows.exe =>.Tweaking LLC®
O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\USER\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Guest]: JDownloader 2.lnk . (.AppWork GmbH - JDownloader 2 Launcher.) D:\Program Files (x86)\jdownloader 2\JDownloader v2.0\JDownloader2.exe =>.Appwork GmbH®
O4 - GS\Quicklaunch [Guest]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Guest]: Sandboxed Web Browser.lnk . (.Sandboxie Holdings, LLC - Sandboxie Start.) D:\Program Files\Sandboxie\Start.exe default_browser =>.Invincea, Inc.®
O4 - GS\sendTo [Guest]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Guest]: Format Factory.lnk . (.Free Time - FormatFactory.) C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe =>.Free Time
O4 - GS\sendTo [Guest]: Sandboxie - DefaultBox.lnk . (.Sandboxie Holdings, LLC - Sandboxie Start.) D:\Program Files\Sandboxie\Start.exe /box:DefaultBox =>.Invincea, Inc.®
O4 - GS\sendTo [Guest]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\TaskBar [Guest]: MetaTrader (2).lnk . (.MetaQuotes Software Corp. - MetaTrader.) D:\Program Files (x86)\MetaTrader - EXNESS\terminal.exe {00A74246F26ADF987743017FED54891570} =>.MetaQuotes Software Corp.
O4 - GS\TaskBar [Guest]: MetaTrader.lnk . (.MetaQuotes Software Corp. - MetaTrader.) D:\Program Files (x86)\InstaTrader\terminal.exe {00A74246F26ADF987743017FED54891570} =>.MetaQuotes Software Corp.
O4 - GS\TaskBar [Guest]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) D:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Guest]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\Programs [Guest]: AMD Radeon Settings.lnk . (.Advanced Micro Devices, Inc. - .) C:\Program Files (x86)\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.
O4 - GS\Programs [Guest]: Anki.lnk . (...) D:\Program Files (x86)\Anki\anki.exe
O4 - GS\Programs [Guest]: Optional Features.lnk . (.Microsoft Corporation - Features On Demand Helper.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Desktop [Max]: Anki.lnk . (...) D:\Program Files (x86)\Anki\anki.exe
O4 - GS\Desktop [Max]: Basic Patterns of Chinese Grammar_ A Student's Guide - Qin Xue Herzberg - Shortcut.lnk . (...) D:\Downloads\Basic Patterns of Chinese Grammar by Qin Xue Herzberg\Basic Patterns of Chinese Grammar_ A Student's Guide - Qin Xue Herzberg.pdf
O4 - GS\Desktop [Max]: Format Factory.lnk . (.Free Time - FormatFactory.) C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe =>.Free Time
O4 - GS\Desktop [Max]: HTTrack Website Copier.lnk . (.HTTrack - WinHTTrack Website Copier, Copy Websites to.) D:\Program Files\WinHTTrack\WinHTTrack.exe =>.Open Source Developer, Xavier Roche®
O4 - GS\Desktop [Max]: JDownloader 2.lnk . (.AppWork GmbH - JDownloader 2 Launcher.) D:\Program Files (x86)\jdownloader 2\JDownloader v2.0\JDownloader2.exe =>.Appwork GmbH®
O4 - GS\Desktop [Max]: Journal - Shortcut.lnk . (...) D:\documents\Journal
O4 - GS\Desktop [Max]: Modern Mandarin Chinese Grammar A Practical Guide - Shortcut.lnk . (...) D:\Downloads\Chinese Language Learning Pack\05.Grammar, Workbooks, Usage\Modern Mandarin Chinese Grammar A Practical Guide.pdf
O4 - GS\Desktop [Max]: mp3DirectCut.lnk . (.Martin Pesch - mp3DirectCut - Direct MP3 editor and record.) D:\Program Files (x86)\mp3DirectCut\mp3DirectCut.exe =>.Martin Pesch
O4 - GS\Desktop [Max]: PeerBlock.lnk . (.PeerBlock, LLC - PeerBlock.) D:\Program Files\PeerBlock\peerblock.exe =>.PeerBlock, LLC®
O4 - GS\Desktop [Max]: procexp64 - Shortcut.lnk . (.Sysinternals - www.sysinternals.com - Sysinternals Process Explorer.) D:\softwares\procexp64.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Max]: Sandboxed Web Browser.lnk . (.Sandboxie Holdings, LLC - Sandboxie Start.) D:\Program Files\Sandboxie\Start.exe default_browser =>.Invincea, Inc.®
O4 - GS\Desktop [Max]: Subtitle Edit.lnk . (.Nikse - Subtitle Edit.) C:\Program Files\Subtitle Edit\SubtitleEdit.exe =>.Nikse
O4 - GS\Desktop [Max]: The Secrets Kyusho - Pressure Point Fighting (2012) - Shortcut.lnk . (...) D:\Downloads\The Secrets Kyusho - Pressure Point Fighting (2012).pdf
O4 - GS\Desktop [Max]: Tweaking.com - Windows Repair.lnk . (.Tweaking.com - Tweaking.com - Windows Repair.) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\Repair_Windows.exe =>.Tweaking LLC®
O4 - GS\Desktop [Max]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\USER\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Max]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Max]: JDownloader 2.lnk . (.AppWork GmbH - JDownloader 2 Launcher.) D:\Program Files (x86)\jdownloader 2\JDownloader v2.0\JDownloader2.exe =>.Appwork GmbH®
O4 - GS\Quicklaunch [Max]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Max]: Sandboxed Web Browser.lnk . (.Sandboxie Holdings, LLC - Sandboxie Start.) D:\Program Files\Sandboxie\Start.exe default_browser =>.Invincea, Inc.®
O4 - GS\sendTo [Max]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\sendTo [Max]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Max]: Format Factory.lnk . (.Free Time - FormatFactory.) C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe =>.Free Time
O4 - GS\sendTo [Max]: Sandboxie - DefaultBox.lnk . (.Sandboxie Holdings, LLC - Sandboxie Start.) D:\Program Files\Sandboxie\Start.exe /box:DefaultBox =>.Invincea, Inc.®
O4 - GS\sendTo [Max]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\TaskBar [Max]: MetaTrader (2).lnk . (.MetaQuotes Software Corp. - MetaTrader.) D:\Program Files (x86)\MetaTrader - EXNESS\terminal.exe {00A74246F26ADF987743017FED54891570} =>.MetaQuotes Software Corp.
O4 - GS\TaskBar [Max]: MetaTrader.lnk . (.MetaQuotes Software Corp. - MetaTrader.) D:\Program Files (x86)\InstaTrader\terminal.exe {00A74246F26ADF987743017FED54891570} =>.MetaQuotes Software Corp.
O4 - GS\TaskBar [Max]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) D:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Max]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Max]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\Programs [Max]: AMD Radeon Settings.lnk . (.Advanced Micro Devices, Inc. - .) C:\Program Files (x86)\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.
O4 - GS\Programs [Max]: Anki.lnk . (...) D:\Program Files (x86)\Anki\anki.exe
O4 - GS\Programs [Max]: Optional Features.lnk . (.Microsoft Corporation - Features On Demand Helper.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\CommonDesktop [Public]: Audacity.lnk . (.The Audacity Team - Audacity®, the Free, Cross-Platform Sound E.) D:\Program Files (x86)\Audacity\audacity.exe =>.James Crook®
O4 - GS\CommonDesktop [Public]: calibre - E-book management.lnk . (...) D:\Program Files (x86)\Calibre2\calibre.exe
O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Ltd - CCleaner.) C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - GS\CommonDesktop [Public]: CyberLink PowerDVD 14.lnk . (.CyberLink Corp. - CyberLink PowerDVD14.) C:\Program Files (x86)\CyberLink\PowerDVD14\PDVDLP.exe =>.CyberLink Corp.®
O4 - GS\CommonDesktop [Public]: DCXTrader.lnk . (...) D:\Program Files (x86)\Ese Software\DCX Trader\DCXTrader.exe
O4 - GS\CommonDesktop [Public]: Malwarebytes.lnk . (.Malwarebytes - Malwarebytes.) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe =>.Malwarebytes Corporation®
O4 - GS\CommonDesktop [Public]: MetaTrader - EXNESS.lnk . (.MetaQuotes Software Corp. - MetaTrader.) D:\Program Files (x86)\MetaTrader - EXNESS\terminal.exe {00A74246F26ADF987743017FED54891570} =>.MetaQuotes Software Corp.
O4 - GS\CommonDesktop [Public]: Network Recording Player.lnk . (.Cisco WebEx LLC - NBR Player Execute Module.) D:\programdata\WebEx\WebEx\500\nbrplay.exe =>.Cisco WebEx LLC®
O4 - GS\CommonDesktop [Public]: PrimoPDF - Drop Files Here to Convert!.lnk . (.Nitro PDF - PrimoPDF.) C:\Program Files (x86)\Nitro PDF\PrimoPDF\PrimoPDF.exe =>.Nitro PDF Software®
O4 - GS\CommonDesktop [Public]: Skype.lnk . (...) C:\Windows\Installer\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}\SkypeIcon.exe =>.Skype Technologies
O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) D:\Program Files (x86)\VideoLAN\VLC\vlc.exe =>.VideoLAN®
O4 - GS\CommonDesktop [Public]: Wise Data Recovery.lnk . (.WiseCleaner.com - Wise Data Recovery.) D:\Program Files (x86)\Wise\Wise Data Recovery\WiseDataRecovery.exe =>.Lespeed Technology Ltd.®
O4 - GS\Programs [Public]: AMD Radeon Settings.lnk . (.Advanced Micro Devices, Inc. - .) C:\Program Files (x86)\AMD\CNext\CNext\RadeonSettings.exe =>.Advanced Micro Devices, Inc.
O4 - GS\Programs [Public]: Anki.lnk . (...) D:\Program Files (x86)\Anki\anki.exe
O4 - GS\Programs [Public]: Optional Features.lnk . (.Microsoft Corporation - Features On Demand Helper.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\WINDOWS\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Quick Assist.lnk . (.Microsoft Corporation - Quick Assist.) C:\WINDOWS\system32\quickassist.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\WINDOWS\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Steps Recorder.) C:\WINDOWS\system32\psr.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: XPS Viewer.lnk . (.Microsoft Corporation - XPS Viewer.) C:\WINDOWS\system32\xpsrchvw.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) C:\WINDOWS\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Audacity.lnk . (.The Audacity Team - Audacity®, the Free, Cross-Platform Sound E.) D:\Program Files (x86)\Audacity\audacity.exe =>.James Crook®
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\WINDOWS\System32\Control.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: MiracastView.lnk . (.Microsoft Corporation - MiracastView.) C:\WINDOWS\MiracastView\MiracastView.exe =>.Microsoft Windows®
O4 - GS\ProgramsCommon [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\ProgramsCommon [Public]: PrintDialog.lnk . (.Microsoft Corporation - Print Dialog.) C:\WINDOWS\PrintDialog\PrintDialog.exe =>.Microsoft Windows®
O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation

---\\ Lop.com/Domain Hijackers (5) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{01068155-a52c-4740-b306-07578124303c}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{29e036c1-4265-4952-8012-f43a55ab4933}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{3ee4e1e4-47d5-4352-aec3-6f70569b12df}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{F6C362E6-31CF-4394-9851-E5D33DF654FC}: DhcpNameServer = 192.168.30.1 =>.Local IP Adress

---\\ Extra protocols (24) - 1s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\SysWOW64\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-help [64Bits] - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll =>.Microsoft Corporation®
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\SysWOW64\tbauth.dll =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: windows.tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\SysWOW64\tbauth.dll =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: text/xml [64Bits] - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL =>.Microsoft Corporation®

---\\ CLSID Tasks (Register) (1) - 3s
O40 - TASK: {BF728E4A-B1B4-406C-A6B2-1A4888A56396} - (...) -- C:\WINDOWS\system32\osppc.dll (.not file.) [0] (.Orphan.) =>.Superfluous.Orphan

---\\ Software installed (68) - 28s
O42 - Logiciel: 7-Zip 9.20 - (.Igor Pavlov.) [HKLM][64Bits] -- 7-Zip =>.Igor Pavlov
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {8C9AA2C1-D07A-48E8-9DD8-471A072947F4} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe AIR =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Flash Player 26 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Flash Player 26 PPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player PPAPI =>.Adobe Systems Incorporated®
O42 - Logiciel: Anki - (.Damien Elmes.) [HKLM][64Bits] -- Anki =>.Damien Elmes
O42 - Logiciel: Audacity 2.1.3 - (.Audacity Team.) [HKLM][64Bits] -- Audacity®_is1 =>.Audacity Team
O42 - Logiciel: AutoHotkey 1.1.26.01 - (.Lexikos.) [HKLM][64Bits] -- AutoHotkey =>.Lexikos
O42 - Logiciel: Bulk Rename Utility 2.7.1.3 - (.TGRMN Software.) [HKLM][64Bits] -- Bulk Rename Utility_is1 =>.TGRMN Software
O42 - Logiciel: calibre - (.Kovid Goyal.) [HKLM][64Bits] -- {A253C2A7-FD66-43AA-9EA7-D30E5041F391} =>.Kovid Goyal
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>.Piriform Ltd®
O42 - Logiciel: Conexant HD Audio - (.Conexant.) [HKLM][64Bits] -- CNXT_AUDIO_HDA =>.Conexant Systems, Inc.®
O42 - Logiciel: DCX Trader 1.8.15 - (..) [HKLM][64Bits] -- DCX_Deploy_0
O42 - Logiciel: Dolby Digital Plus Home Theater - (.Dolby Laboratories Inc.) [HKLM][64Bits] -- {7E3D8FA1-6092-469A-955B-68FC4A2C67CA} =>.Dolby Laboratories Inc
O42 - Logiciel: Foxit Reader - (.Foxit Software Inc..) [HKLM][64Bits] -- Foxit Reader_is1 =>.Foxit Software Incorporated®
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome =>.Google Inc®
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: InstaTrader - (.MetaQuotes Software Corp..) [HKLM][64Bits] -- InstaTrader =>.MetaQuotes Software Corp.®
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} =>.Intel(R) pGFX®
O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {B5E06417-A4AC-4225-B36E-7E34C91616E7} =>.Intel Corporation
O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM][64Bits] -- Internet Download Manager =>.Tonec Inc.®
O42 - Logiciel: IP Camera Adapter - (.Pavel Khlebovich.) [HKLM][64Bits] -- {6D140BFF-7CC5-4BFE-AD6D-47035FFE5F14} =>.Pavel Khlebovich
O42 - Logiciel: Java 8 Update 144 - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F32180144F0} =>.Oracle Corporation
O42 - Logiciel: Java Auto Updater - (.Oracle Corporation.) [HKLM][64Bits] -- {4A03706F-666A-4037-7777-5F2748764D10} =>.Oracle Corporation
O42 - Logiciel: JDownloader 2 - (.AppWork GmbH.) [HKLM][64Bits] -- jdownloader2 =>.Appwork GmbH®
O42 - Logiciel: KeyScrambler - (.QFX Software Corporation.) [HKLM][64Bits] -- KeyScrambler =>.QFX Software Corporation
O42 - Logiciel: K-Lite Codec Pack 11.4.0 Basic - (.KLite Inc.) [HKLM][64Bits] -- KLiteCodecPack_is1 =>.KLite Inc
O42 - Logiciel: Lenovo EasyCamera - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Lenovo pointing device - (.ELAN Microelectronic Corp..) [HKLM][64Bits] -- Elantech =>.ELAN Microelectronics Corporation®
O42 - Logiciel: Lenovo System Interface Foundation Driver - (.Lenovo.) [HKLM][64Bits] -- {C2E5CA37-C862-4A69-AC6D-24F450A20C16} =>.Lenovo
O42 - Logiciel: Malwarebytes version 3.1.2.1733 - (.Malwarebytes.) [HKLM][64Bits] -- {35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1 =>.Malwarebytes Corporation®
O42 - Logiciel: MetaTrader - EXNESS - (.MetaQuotes Software Corp..) [HKLM][64Bits] -- MetaTrader - EXNESS =>.MetaQuotes Software Corp.®
O42 - Logiciel: Microsoft Excel 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- Office14.EXCEL =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Word 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- Office14.WORD =>.Microsoft Corporation®
O42 - Logiciel: Microsoft XNA Framework Redistributable 4.0 - (.Microsoft Corporation.) [HKLM][64Bits] -- {2BFC7AA0-544C-4E3A-8796-67F3BE655BE9} =>.Microsoft Corporation
O42 - Logiciel: Mozilla Firefox 39.0 (x86 en-US) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 39.0 (x86 en-US) =>.Mozilla Corporation®
O42 - Logiciel: Mozilla Firefox 47.0.1 (x86 en-US) - (.Mozilla.) [HKCU][64Bits] -- Mozilla Firefox 47.0.1 (x86 en-US) =>.Mozilla Corporation®
O42 - Logiciel: Mozilla Firefox 54.0.1 (x86 en-US) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 54.0.1 (x86 en-US) =>.Mozilla Corporation®
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService =>.Mozilla
O42 - Logiciel: MusicBee 3.0 - (.Steven Mayall.) [HKLM][64Bits] -- MusicBee =>.Steven Mayall
O42 - Logiciel: Network Recording Player - (.Cisco WebEx LLC.) [HKLM][64Bits] -- {79417ECE-DA9D-49B3-B1C9-83AA3EAE6AE0} =>.Cisco WebEx LLC
O42 - Logiciel: NVIDIA Install Application - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer =>.NVIDIA Corporation
O42 - Logiciel: OpenAL - (.Open Audio Library.) [HKLM][64Bits] -- OpenAL =>.Creative Labs Inc®
O42 - Logiciel: PeerBlock 1.2 (r693) - (.PeerBlock, LLC.) [HKLM][64Bits] -- {015C5B35-B678-451C-9AEE-821E8D69621C}_is1 =>.PeerBlock, LLC
O42 - Logiciel: PrimoPDF -- brought to you by Nitro PDF Software - (.Nitro PDF Software.) [HKLM][64Bits] -- PrimoPDF =>.Nitro PDF Software
O42 - Logiciel: PX Profile Update - (.AMD.) [HKLM][64Bits] -- {954CFDDE-AF07-2AF9-9600-706E798D42BA} =>.AMD
O42 - Logiciel: Raptr - (.Raptr, Inc.) [HKLM][64Bits] -- Raptr =>.Raptr, Inc
O42 - Logiciel: Rosetta Stone Language Training - (.Rosetta Stone, Ltd.) [HKLM][64Bits] -- {00384623-4937-4D7D-BDD9-23513D1C50AB}
O42 - Logiciel: Rosetta Stone Ltd Services - (.Rosetta Stone Ltd..) [HKLM][64Bits] -- {3165E4A6-D5DE-46B0-8597-D55E2B826B84} =>.Rosetta Stone Ltd.
O42 - Logiciel: Sandboxie 5.20 (64-bit) - (.Sandboxie Holdings, LLC.) [HKLM][64Bits] -- Sandboxie =>.Invincea, Inc.®
O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM][64Bits] -- {873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B} =>.Microsoft Corporation
O42 - Logiciel: Skype™ 7.1 - (..) [HKLM][64Bits] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}
O42 - Logiciel: Subtitle Edit 3.4.6 - (.Nikse.) [HKLM][64Bits] -- SubtitleEdit_is1 =>.Nikse
O42 - Logiciel: Subtitle Edit 3.5.3 - (.Nikse.) [HKLM][64Bits] -- SubtitleEdit_is1 =>.Nikse
O42 - Logiciel: Tweaking.com - Windows Repair - (.Tweaking.com.) [HKLM][64Bits] -- Tweaking.com - Windows Repair =>.Tweaking.com
O42 - Logiciel: USB Vibration Joystick - (..) [HKLM][64Bits] -- {4999B2F1-3E74-409A-B8B5-E94448AA9EA6}
O42 - Logiciel: Virtual DJ Home - Atomix Productions - (.Atomix Production.) [HKLM][64Bits] -- Virtual DJ Home - Atomix Productions =>.Atomix Production
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
O42 - Logiciel: Vulkan Run Time Libraries 1.0.3.1 - (.LunarG, Inc..) [HKLM][64Bits] -- VulkanRT1.0.3.1 =>.LunarG, Inc.
O42 - Logiciel: Vulkan Run Time Libraries 1.0.39.1 - (.LunarG, Inc..) [HKLM][64Bits] -- VulkanRT1.0.39.1 =>.LunarG, Inc.®
O42 - Logiciel: Windows 10 Update and Privacy Settings - (.Microsoft Corporation.) [HKLM][64Bits] -- {293F2009-0145-450B-B4AA-063D43FB368C} =>.Microsoft Corporation
O42 - Logiciel: Windows Driver Package - Lenovo (ACPIVPC) System (02/17/2013 9.52.0.776) - (.Lenovo.) [HKLM][64Bits] -- 35DD26BE48DAF4A9F35F969F3CB1E3E1435E661E =>.Lenovo (Beijing) Limited®
O42 - Logiciel: Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.28 - (.Lenovo.) [HKLM][64Bits] -- 6BCA401E9CBEED970D75F55FA5320F60D11984E9 =>.Lenovo (Beijing) Limited®
O42 - Logiciel: WinHTTrack Website Copier 3.48-22 (x64) - (.HTTrack.) [HKLM][64Bits] -- WinHTTrack Website Copier_is1 =>.Open Source Developer, Xavier Roche®
O42 - Logiciel: WinRAR 4.01 (32-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver =>.win.rar GmbH
O42 - Logiciel: WinRAR 5.40 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver =>.win.rar GmbH®
O42 - Logiciel: Wise Data Recovery 3.82 - (.WiseCleaner.com, Inc..) [HKLM][64Bits] -- Wise Data Recovery_is1 =>.WiseCleaner.com, Inc.

---\\ HKCU & HKLM Software Keys (197) - 28s
HKLM\SOFTWARE\Wow6432Node\7-Zip =>.Igor Pavlov
HKLM\SOFTWARE\Wow6432Node\ACD Systems =>.ACD Systems
HKLM\SOFTWARE\Wow6432Node\Adobe =>.Adobe
HKLM\SOFTWARE\Wow6432Node\Anki =>.Damien Elmes
HKLM\SOFTWARE\Wow6432Node\Anvisoft =>.Anvisoft
HKLM\SOFTWARE\Wow6432Node\Apple Computer, Inc. =>.Apple Computer, Inc.
HKLM\SOFTWARE\Wow6432Node\Apple Inc. =>.Apple Inc.
HKLM\SOFTWARE\Wow6432Node\ATI =>.ATI
HKLM\SOFTWARE\Wow6432Node\ATI Technologies =>.ATI Technologies
HKLM\SOFTWARE\Wow6432Node\Belarc =>.Belarc
HKLM\SOFTWARE\Wow6432Node\calibre =>.Kovid Goyal
HKLM\SOFTWARE\Wow6432Node\CDDB =>.Cddb Software
HKLM\SOFTWARE\Wow6432Node\Conexant =>.Conexant
HKLM\SOFTWARE\Wow6432Node\CyberLink =>.CyberLink Corporation
HKLM\SOFTWARE\Wow6432Node\DigitalWave =>.DigitalWave Corporation
HKLM\SOFTWARE\Wow6432Node\DivXNetworks =>.DivXNetworks
HKLM\SOFTWARE\Wow6432Node\EA GAMES =>.EA Games
HKLM\SOFTWARE\Wow6432Node\Ese Software
HKLM\SOFTWARE\Wow6432Node\Eset =>.ESET
HKLM\SOFTWARE\Wow6432Node\FarStone =>.FarStone
HKLM\SOFTWARE\Wow6432Node\Foxit Software =>.Foxit Software
HKLM\SOFTWARE\Wow6432Node\Free YouTube Downloader =>.DawnArk, Inc
HKLM\SOFTWARE\Wow6432Node\GNU =>.GNU
HKLM\SOFTWARE\Wow6432Node\GOG.com =>.GOG.com
HKLM\SOFTWARE\Wow6432Node\Google =>.Google
HKLM\SOFTWARE\Wow6432Node\HaaliMkx =>.Haali Media
HKLM\SOFTWARE\Wow6432Node\HideAllIP
HKLM\SOFTWARE\Wow6432Node\HitmanPro =>.EIDOS hitman Game
HKLM\SOFTWARE\Wow6432Node\IM Providers =>.IM Providers
HKLM\SOFTWARE\Wow6432Node\InstallShield =>.InstallShield
HKLM\SOFTWARE\Wow6432Node\Intel =>.Intel
HKLM\SOFTWARE\Wow6432Node\Internet Download Manager =>.Tonec Inc
HKLM\SOFTWARE\Wow6432Node\InterVideo =>.InterVideo
HKLM\SOFTWARE\Wow6432Node\iSkysoft =>.iSkysoft Software
HKLM\SOFTWARE\Wow6432Node\JavaSoft =>.JavaSoft
HKLM\SOFTWARE\Wow6432Node\JreMetrics =>.JreMetrics
HKLM\SOFTWARE\Wow6432Node\Khronos =>.Khronos
HKLM\SOFTWARE\Wow6432Node\KLCodecPack =>.KLite Inc
HKLM\SOFTWARE\Wow6432Node\Lake =>.Lake Sofware
HKLM\SOFTWARE\Wow6432Node\LAV =>.LAV Inc
HKLM\SOFTWARE\Wow6432Node\Lenovo =>.Lenovo
HKLM\SOFTWARE\Wow6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\Wow6432Node\Macrovision =>.Macrovision
HKLM\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware =>.Malwarebytes' Anti-Malware
HKLM\SOFTWARE\Wow6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\MusicBee
HKLM\SOFTWARE\Wow6432Node\Nalpeiron =>.Nalpeiron
HKLM\SOFTWARE\Wow6432Node\Naver
HKLM\SOFTWARE\Wow6432Node\Nero =>.Ahead Corporation
HKLM\SOFTWARE\Wow6432Node\Nuance =>.Nuance
HKLM\SOFTWARE\Wow6432Node\Nullsoft =>.Nullsoft
HKLM\SOFTWARE\Wow6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\Wow6432Node\Opera Software =>.Opera Software
HKLM\SOFTWARE\Wow6432Node\QFX Software =>.QFX Software
HKLM\SOFTWARE\Wow6432Node\QuickTimeLite
HKLM\SOFTWARE\Wow6432Node\R-TT =>.Unknown
HKLM\SOFTWARE\Wow6432Node\Raptr =>.Raptr
HKLM\SOFTWARE\Wow6432Node\Realtek =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp. =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\Riot Games =>.Riot Games
HKLM\SOFTWARE\Wow6432Node\RtWLan =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\Skype =>.Skype
HKLM\SOFTWARE\Wow6432Node\SuppHelpDir =>.Toshiba Corporation
HKLM\SOFTWARE\Wow6432Node\TeamViewer =>.TeamViewer
HKLM\SOFTWARE\Wow6432Node\TrendMicro =>.TrendMicro
HKLM\SOFTWARE\Wow6432Node\Valve =>.Valve
HKLM\SOFTWARE\Wow6432Node\VideoLAN =>.VideoLAN
HKLM\SOFTWARE\Wow6432Node\Vimicro Corporation =>.Vimicro Corporation
HKLM\SOFTWARE\Wow6432Node\VirtualDJ =>.Atomix Production
HKLM\SOFTWARE\Wow6432Node\Volatile =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\WafCX =>.WafCX
HKLM\SOFTWARE\Wow6432Node\WebEx =>.Cisco Systems, Inc.
HKLM\SOFTWARE\Wow6432Node\WinRAR =>.WinRAR
HKLM\SOFTWARE\Wow6432Node\Wondershare =>.Wondershare
HKLM\SOFTWARE\Wow6432Node\WOW6432Node =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\4kdownload.com =>.4kdownload.com
HKCU\SOFTWARE\7-Zip =>.Igor Pavlov
HKCU\SOFTWARE\ACD Systems =>.ACD Systems
HKCU\SOFTWARE\Adobe =>.Adobe
HKCU\SOFTWARE\AMD =>.AMD
HKCU\SOFTWARE\AMPLITUDE Studios =>.Amplitude Studios
HKCU\SOFTWARE\Ankama =>.Ankama
HKCU\SOFTWARE\Aplicaciones generadas con el Asistente para aplicaciones local
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\Apple Computer, Inc. =>.Apple Computer, Inc.
HKCU\SOFTWARE\AppWork =>.Appwork GmbH
HKCU\SOFTWARE\ATI =>.ATI
HKCU\SOFTWARE\BlueStacks =>.BlueStack Systems, Inc.
HKCU\SOFTWARE\Boneloaf
HKCU\SOFTWARE\BugSplat =>.Bugsplat Game
HKCU\SOFTWARE\calibre =>.Kovid Goyal
HKCU\SOFTWARE\Chromium =>.Chromium
HKCU\SOFTWARE\cks =>.Legitimate
HKCU\SOFTWARE\ComfortSoftware =>.Comfort Software
HKCU\SOFTWARE\Conexant =>.Conexant
HKCU\SOFTWARE\Cyberlink =>.CyberLink Corporation
HKCU\SOFTWARE\Daedalic Entertainment GmbH =>.Daedalic Entertainment GmbH
HKCU\SOFTWARE\DAUM =>.DAUM
HKCU\SOFTWARE\DivXNetworks =>.DivXNetworks
HKCU\SOFTWARE\DownloadManager =>.DownloadManager
HKCU\SOFTWARE\ej-technologies =>.ej-technologies
HKCU\SOFTWARE\Elantech =>.Elantech Inc.
HKCU\SOFTWARE\EMU =>.Games Software
HKCU\SOFTWARE\epsxe =>.ePSXe
HKCU\SOFTWARE\ESET =>.ESET
HKCU\SOFTWARE\EXP
HKCU\SOFTWARE\Forex Software =>.REX Game Studios, LLC
HKCU\SOFTWARE\Foxit Software =>.Foxit Software
HKCU\SOFTWARE\FreeTime =>.FreeTime Inc
HKCU\SOFTWARE\FSCR Master
HKCU\SOFTWARE\Fugazo
HKCU\SOFTWARE\Gabest =>.Gabest
HKCU\SOFTWARE\Geek Uninstaller =>.Geek Uninstaller
HKCU\SOFTWARE\Genymobile =>.Genymobile
HKCU\SOFTWARE\GNU =>.GNU
HKCU\SOFTWARE\GOG.com =>.GOG.com
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\GreenTree Applications =>.Superfluous.GreenTreeApp
HKCU\SOFTWARE\Haali =>.Haali Media
HKCU\SOFTWARE\HideAllIP
HKCU\SOFTWARE\Icaros =>.Icaros
HKCU\SOFTWARE\IM Providers =>.IM Providers
HKCU\SOFTWARE\Intel =>.Intel
HKCU\SOFTWARE\IP Webcam
HKCU\SOFTWARE\iSkysoft =>.iSkysoft Software
HKCU\SOFTWARE\JavaSoft =>.JavaSoft
HKCU\SOFTWARE\Katauri Interactive
HKCU\SOFTWARE\Kingsoft =>.Kingosoft Technology Ltd
HKCU\SOFTWARE\KoeiTecmo
HKCU\SOFTWARE\Lake =>.Lake Sofware
HKCU\SOFTWARE\Leapdroid =>.Leapdroid
HKCU\SOFTWARE\Lenovo =>.Lenovo
HKCU\SOFTWARE\Logitech =>.Logitech
HKCU\SOFTWARE\Macromedia =>.Macromedia
HKCU\SOFTWARE\madshi =>.madshi.net
HKCU\SOFTWARE\Magix =>.Magix
HKCU\SOFTWARE\Malwarebytes =>.Malwarebytes
HKCU\SOFTWARE\MediaInfo =>.Jérôme Martinez
HKCU\SOFTWARE\Memsource
HKCU\SOFTWARE\MetaQuotes Software =>.MetaQuotes Software
HKCU\SOFTWARE\MGS
HKCU\SOFTWARE\Microgaming
HKCU\SOFTWARE\Mirage =>.Mirage Game
HKCU\SOFTWARE\Mozilla =>.Mozilla
HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKCU\SOFTWARE\MPC-HC =>.MPC-HC Team
HKCU\SOFTWARE\Naver
HKCU\SOFTWARE\Nero =>.Ahead Corporation
HKCU\SOFTWARE\Netscape =>.Netscape
HKCU\SOFTWARE\Nitro =>.Nitro
HKCU\SOFTWARE\Obsidian Entertainment =>.Obsidian Entertainment
HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKCU\SOFTWARE\Opera Software =>.Opera Software
HKCU\SOFTWARE\OTELNP
HKCU\SOFTWARE\PCSX2
HKCU\SOFTWARE\Piriform =>.Piriform
HKCU\SOFTWARE\QFX Software =>.QFX Software
HKCU\SOFTWARE\QtProject =>.QtProject
HKCU\SOFTWARE\R-TT =>.Unknown
HKCU\SOFTWARE\RAD Game Tools =>.RAD Game Tools
HKCU\SOFTWARE\Raptr =>.Raptr
HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\RLZer
HKCU\SOFTWARE\SDR Free Ebook Converter
HKCU\SOFTWARE\SKS =>.SKS Software
HKCU\SOFTWARE\Skype =>.Skype
HKCU\SOFTWARE\SYNCJM =>.SYNCJM
HKCU\SOFTWARE\Sysinternals =>.Sysinternals
HKCU\SOFTWARE\SysProgs =>.SysProgs
HKCU\SOFTWARE\TeamViewer =>.TeamViewer
HKCU\SOFTWARE\Tencent =>.Superfluous.Tencent
HKCU\SOFTWARE\TGRMN Software =>.TGRMN Software
HKCU\SOFTWARE\The Creative Assembly =>.The Creative Assembly
HKCU\SOFTWARE\ThsDict.ini
HKCU\SOFTWARE\ThsDict.ini2
HKCU\SOFTWARE\Trolltech =>.Trolltech
HKCU\SOFTWARE\Unity =>.Unity
HKCU\SOFTWARE\Valve =>.Valve
HKCU\SOFTWARE\VirtualDJ =>.Atomix Production
HKCU\SOFTWARE\Vision Thing
HKCU\SOFTWARE\Webex =>.Cisco Systems, Inc.
HKCU\SOFTWARE\Winamp =>.Nullsoft Inc.
HKCU\SOFTWARE\WinHTTrack Website Copier =>.Xavier Roche
HKCU\SOFTWARE\WinRAR =>.WinRAR
HKCU\SOFTWARE\WinRAR SFX =>.RarLab
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\WsAudioDevice_383
HKCU\SOFTWARE\Yahoo =>.Yahoo! Inc.
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\Ó¦ÓóÌÐòÏòµ¼Éú³ÉµÄ±¾µØÓ¦ÓóÌÐò
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKCU\SOFTWARE\AppDataLow\Software\JavaSoft =>.JavaSoft
HKCU\SOFTWARE\AppDataLow\Software\Yahoo =>.Yahoo! Inc.

---\\ Contents of the Common Files folders (384) - 42s
O43 - CFD: 18/08/2014 - [] D -- C:\Program Files\Adobe =>.Adobe Systems Incorporated®
O43 - CFD: 25/03/2015 - [] D -- C:\Program Files\Adware-Removal-Tool =>.Pawan Kumar®
O43 - CFD: 05/06/2017 - [] AD -- C:\Program Files\AMD =>.Advanced Micro Devices, Inc.®
O43 - CFD: 11/05/2015 - [] D -- C:\Program Files\ATI =>.ATI
O43 - CFD: 05/06/2017 - [] AD -- C:\Program Files\ATI Technologies =>.ATI Technologies
O43 - CFD: 03/08/2017 - [] D -- C:\Program Files\AutoHotkey =>.Chicony Multimedia
O43 - CFD: 26/06/2017 - [] AD -- C:\Program Files\CCleaner =>.Piriform Ltd
O43 - CFD: 04/06/2017 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] D -- C:\Program Files\CONEXANT =>.Conexant Systems, Inc.®
O43 - CFD: 07/12/2014 - [] D -- C:\Program Files\DIFX =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] AD -- C:\Program Files\Dolby Digital Plus =>.Dolby Laboratories Inc
O43 - CFD: 04/06/2017 - [] D -- C:\Program Files\Elantech =>.ELAN Microelectronics Corporation®
O43 - CFD: 04/06/2017 - [] D -- C:\Program Files\Intel =>.Intel Corporation
O43 - CFD: 05/06/2017 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 25/10/2016 - [0] D -- C:\Program Files\Leapdroid =>.Leapdroid
O43 - CFD: 03/08/2017 - [] D -- C:\Program Files\lenovo =>.Lenovo
O43 - CFD: 01/06/2017 - [] D -- C:\Program Files\Malwarebytes =>.Malwarebytes
O43 - CFD: 09/11/2016 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 05/06/2017 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 18/08/2014 - [] D -- C:\Program Files\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 05/06/2017 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 03/08/2017 - [] D -- C:\Program Files\Subtitle Edit =>.Nikse
O43 - CFD: 04/06/2017 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 31/05/2017 - [] AD -- C:\Program Files\UNP =>.Microsoft Corporation
O43 - CFD: 12/07/2017 - [] RD -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [] D -- C:\Program Files\Windows Defender Advanced Threat Protection =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [] D -- C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 12/07/2017 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [] D -- C:\Program Files\Windows Security =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [] SHD -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 08/08/2017 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [] D -- C:\Program Files\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 03/08/2017 - [] D -- C:\Program Files\WinRAR =>.win.rar GmbH®
O43 - CFD: 10/08/2015 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Systems Incorporated®
O43 - CFD: 04/06/2017 - [] AD -- C:\Program Files (x86)\AMD =>.Advanced Micro Devices, Inc.®
O43 - CFD: 09/08/2015 - [] D -- C:\Program Files (x86)\AMD AVT =>.Advanced Micro Devices Inc
O43 - CFD: 09/08/2015 - [] AD -- C:\Program Files (x86)\ATI Technologies =>.ATI Technologies
O43 - CFD: 30/03/2015 - [0] D -- C:\Program Files (x86)\Belarc =>.Belarc, Inc.
O43 - CFD: 03/08/2017 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 18/08/2014 - [] D -- C:\Program Files (x86)\Cooler_PC
O43 - CFD: 18/08/2014 - [] D -- C:\Program Files (x86)\CyberLink =>.CyberLink Corporation
O43 - CFD: 12/10/2016 - [] D -- C:\Program Files (x86)\FreeCodecPack =>.Free Codec Pack
O43 - CFD: 17/08/2014 - [] D -- C:\Program Files (x86)\FreeTime =>.FreeTime
O43 - CFD: 03/10/2015 - [] D -- C:\Program Files (x86)\Google =>.Google Inc®
O43 - CFD: 03/08/2017 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield
O43 - CFD: 07/12/2014 - [] D -- C:\Program Files (x86)\Intel =>.Intel Corporation
O43 - CFD: 26/06/2017 - [] D -- C:\Program Files (x86)\Internet Download Manager =>.Tonec Inc
O43 - CFD: 05/06/2017 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 03/08/2017 - [] D -- C:\Program Files (x86)\Java =>.Oracle
O43 - CFD: 17/08/2014 - [] D -- C:\Program Files (x86)\K-Lite Codec Pack =>.KLite Inc
O43 - CFD: 03/08/2017 - [] D -- C:\Program Files (x86)\Lenovo =>.Lenovo
O43 - CFD: 02/06/2016 - [0] D -- C:\Program Files (x86)\Microsoft =>.Microsoft Corporation
O43 - CFD: 09/11/2016 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services =>.Microsoft Corporation
O43 - CFD: 09/11/2016 - [] D -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition =>.Microsoft Corporation
O43 - CFD: 09/11/2016 - [] D -- C:\Program Files (x86)\Microsoft Synchronization Services =>.Microsoft Corporation
O43 - CFD: 06/05/2015 - [] D -- C:\Program Files (x86)\Microsoft XNA =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 03/08/2017 - [] AD -- C:\Program Files (x86)\Mozilla Firefox =>.Mozilla
O43 - CFD: 03/08/2017 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service =>.Mozilla
O43 - CFD: 05/06/2017 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 17/08/2014 - [] D -- C:\Program Files (x86)\MSXML 4.0 =>.Microsoft Corporation
O43 - CFD: 09/04/2015 - [] D -- C:\Program Files (x86)\Nitro PDF =>.Nitro PDF Software®
O43 - CFD: 18/08/2014 - [] D -- C:\Program Files (x86)\NSIS Uninstall Information =>.MSIS
O43 - CFD: 06/02/2017 - [] D -- C:\Program Files (x86)\OpenAL =>.Open Audio Library
O43 - CFD: 17/02/2015 - [] D -- C:\Program Files (x86)\OTELNP
O43 - CFD: 17/08/2014 - [] D -- C:\Program Files (x86)\QT Lite
O43 - CFD: 17/08/2014 - [] D -- C:\Program Files (x86)\R-Studio =>.R-Tools Technology Inc.®
O43 - CFD: 22/06/2016 - [0] D -- C:\Program Files (x86)\Raptr =>.Raptr
O43 - CFD: 25/07/2016 - [] D -- C:\Program Files (x86)\Raptr Inc =>.Raptr Inc.
O43 - CFD: 09/08/2015 - [] D -- C:\Program Files (x86)\Realtek =>.Realtek
O43 - CFD: 14/02/2015 - [] D -- C:\Program Files (x86)\REALTEK PCIE Wireless LAN Driver =>.Realtek Semiconductor Corp.
O43 - CFD: 05/06/2017 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 27/02/2016 - [] D -- C:\Program Files (x86)\Rosetta Stone =>.Rosetta Stone Ltd®
O43 - CFD: 27/02/2016 - [] AD -- C:\Program Files (x86)\RosettaStoneLtdServices =>.Rosetta Stone Ltd®
O43 - CFD: 25/10/2016 - [] RD -- C:\Program Files (x86)\Skype =>.Skype
O43 - CFD: 07/08/2017 - [] D -- C:\Program Files (x86)\Tweaking.com =>.Tweaking LLC®
O43 - CFD: 07/08/2017 - [0] HD -- C:\Program Files (x86)\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 17/08/2014 - [] D -- C:\Program Files (x86)\USB Disk Security =>.FlashPeak Inc
O43 - CFD: 03/08/2017 - [] D -- C:\Program Files (x86)\USB Vibration =>.InstallShield Software Corporation®
O43 - CFD: 23/02/2015 - [] D -- C:\Program Files (x86)\Vimicro =>.Vimicro
O43 - CFD: 29/03/2015 - [] D -- C:\Program Files (x86)\Virtual Router =>.CodePlex
O43 - CFD: 05/06/2017 - [] D -- C:\Program Files (x86)\VulkanRT =>.LunarG, Inc
O43 - CFD: 12/07/2017 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 12/07/2017 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [] SHD -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [] D -- C:\Program Files (x86)\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip =>.Igor Pavlov
O43 - CFD: 19/03/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 12/07/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 12/07/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS6
O43 - CFD: 25/07/2016 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Gaming Evolved =>.AMD Gaming Evolved
O43 - CFD: 05/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Problem Report Wizard
O43 - CFD: 05/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings =>.Advanced Micro Devices Inc
O43 - CFD: 03/08/2017 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvisoft =>.Anvisoft
O43 - CFD: 03/08/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoHotkey =>.Chicony Multimedia
O43 - CFD: 04/09/2015 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BufferZone
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bulk Rename Utility
O43 - CFD: 03/08/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management =>.Kovid Goyal
O43 - CFD: 26/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conexant =>.Conexant
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 14 =>.CyberLink Corporation
O43 - CFD: 09/08/2015 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolphin =>.Dolphin DevTeam
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ese Software
O43 - CFD: 14/06/2017 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InstaTrader
O43 - CFD: 04/06/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel =>.Intel Corporation
O43 - CFD: 26/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager =>.Tonec Inc
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IP Camera Adapter =>.DeskShare Inc
O43 - CFD: 03/08/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java =>.Oracle
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack =>.KLite Inc
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeyScrambler =>.QFX Software
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo =>.Lenovo
O43 - CFD: 19/03/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes =>.Malwarebytes
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MetaTrader - EXNESS
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Network Recording Player
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewFeature1
O43 - CFD: 17/08/2014 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3 =>.Google Inc.
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrimoPDF
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QT Lite
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Raptr =>.Raptr
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rosetta Stone =>.Rosetta Stone
O43 - CFD: 07/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie =>.Sandboxie
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype =>.Skype
O43 - CFD: 19/03/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 03/08/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Subtitle Edit =>.Nikse
O43 - CFD: 19/03/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 07/08/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com =>.Tweaking.com
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\USB Disk Security =>.FlashPeak Inc
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vimicro USB PC Camera (ZC0301PLH)
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virtual DJ =>.Atomix Production
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vulkan 1.0.3.1 =>.Kronos Group
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinCDEmu
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinHTTrack =>.HTTrack
O43 - CFD: 03/08/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Data Recovery =>.WiseCleaner.com, Inc
O43 - CFD: 17/08/2014 - [] D -- C:\ProgramData\ACD Systems =>.ACD Systems Ltd
O43 - CFD: 23/03/2015 - [] D -- C:\ProgramData\Adobe =>.Adobe
O43 - CFD: 05/06/2017 - [] D -- C:\ProgramData\AMD =>.AMD
O43 - CFD: 04/03/2016 - [] D -- C:\ProgramData\Anvisoft =>.Anvisoft
O43 - CFD: 17/08/2014 - [] D -- C:\ProgramData\Apple Computer =>.Apple Inc.
O43 - CFD: 04/06/2017 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 22/06/2016 - [] D -- C:\ProgramData\ATI =>.ATI
O43 - CFD: 07/08/2016 - [0] D -- C:\ProgramData\BlueStacksSetup =>.BlueStack Systems, Inc.
O43 - CFD: 16/07/2016 - [0] D -- C:\ProgramData\Comms =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\Conexant =>.Conexant
O43 - CFD: 19/03/2015 - [] D -- C:\ProgramData\CyberLink =>.CyberLink Corporation
O43 - CFD: 04/06/2017 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 07/12/2014 - [] D -- C:\ProgramData\Downloaded Installations =>.Microsoft Corporation
O43 - CFD: 03/06/2015 - [] D -- C:\ProgramData\Energy Manager =>.Lenovo
O43 - CFD: 27/02/2016 - [] D -- C:\ProgramData\FLEXnet =>.Flexera Software
O43 - CFD: 05/06/2016 - [] D -- C:\ProgramData\Foxit ContentPlatform =>.Foxit Corporation
O43 - CFD: 12/07/2017 - [0] D -- C:\ProgramData\Foxit Software =>.Foxit Software
O43 - CFD: 01/11/2015 - [] D -- C:\ProgramData\Fugazo =>.Games Software
O43 - CFD: 26/03/2015 - [] D -- C:\ProgramData\HitmanPro =>.EIDOS hitman Game
O43 - CFD: 26/06/2017 - [0] D -- C:\ProgramData\IDM =>.IDM
O43 - CFD: 18/08/2014 - [] D -- C:\ProgramData\install_clap =>.Microsoft Corporation
O43 - CFD: 07/12/2014 - [] D -- C:\ProgramData\Intel =>.Intel Corporation
O43 - CFD: 12/12/2016 - [] D -- C:\ProgramData\iSkysoft =>.iSkySoft
O43 - CFD: 12/10/2016 - [] D -- C:\ProgramData\iSkysoft Application Common Data
O43 - CFD: 12/12/2016 - [] D -- C:\ProgramData\iSkysoft iTube Studio
O43 - CFD: 03/04/2015 - [] D -- C:\ProgramData\KONAMI =>.Konami
O43 - CFD: 11/03/2017 - [] D -- C:\ProgramData\Lenovo =>.Lenovo
O43 - CFD: 03/08/2017 - [] D -- C:\ProgramData\MAGIX =>.Magix
O43 - CFD: 01/06/2017 - [] D -- C:\ProgramData\Malwarebytes =>.Malwarebytes
O43 - CFD: 24/03/2015 - [] D -- C:\ProgramData\MetaQuotes
O43 - CFD: 07/10/2016 - [] D -- C:\ProgramData\mgs
O43 - CFD: 04/07/2017 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 13/03/2017 - [] D -- C:\ProgramData\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 17/08/2014 - [] D -- C:\ProgramData\Microsoft Toolkit =>.Microsoft Corporation
O43 - CFD: 17/08/2014 - [] D -- C:\ProgramData\Mozilla =>.Mozilla Corporation
O43 - CFD: 25/04/2016 - [] D -- C:\ProgramData\Nero =>.Ahead Corporation
O43 - CFD: 17/08/2014 - [] D -- C:\ProgramData\Nitro =>.Nitro
O43 - CFD: 28/03/2015 - [] D -- C:\ProgramData\Office Genuine Advantage =>.Microsoft Corporation
O43 - CFD: 03/07/2015 - [] D -- C:\ProgramData\Oracle =>.Oracle
O43 - CFD: 03/08/2017 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 17/08/2014 - [] D -- C:\ProgramData\PDVD =>.PDVD
O43 - CFD: 25/03/2015 - [] D -- C:\ProgramData\QFX Software =>.QFX Software
O43 - CFD: 07/12/2014 - [] D -- C:\ProgramData\Qualcomm Atheros =>.Qualcomm Atheros
O43 - CFD: 31/07/2015 - [] D -- C:\ProgramData\Realtek =>.Realtek
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\regid.1986-12.com.adobe =>.Adobe Inc.
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
O43 - CFD: 25/03/2015 - [] D -- C:\ProgramData\RELOADED
O43 - CFD: 31/08/2015 - [] D -- C:\ProgramData\Riot Games =>.Riot Games
O43 - CFD: 08/08/2017 - [] D -- C:\ProgramData\RogueKiller =>.Adlice Software
O43 - CFD: 27/02/2016 - [] D -- C:\ProgramData\Rosetta Stone =>.Rosetta Stone
O43 - CFD: 27/02/2016 - [] D -- C:\ProgramData\Rosetta Stone Backups
O43 - CFD: 27/02/2016 - [] D -- C:\ProgramData\RosettaStoneLtdServices
O43 - CFD: 24/02/2015 - [] D -- C:\ProgramData\Skype =>.Skype
O43 - CFD: 19/03/2017 - [0] D -- C:\ProgramData\SoftwareDistribution =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation
O43 - CFD: 03/06/2015 - [] D -- C:\ProgramData\Steam =>.Steam Games
O43 - CFD: 03/08/2017 - [] D -- C:\ProgramData\Sun =>.Oracle
O43 - CFD: 18/08/2014 - [] D -- C:\ProgramData\SUPPORTDIR =>.Microsoft Corporation
O43 - CFD: 02/02/2015 - [] D -- C:\ProgramData\Synaptics =>.Synaptics
O43 - CFD: 02/11/2015 - [] AD -- C:\ProgramData\Temp =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\USOPrivate =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] D -- C:\ProgramData\USOShared =>.Microsoft Corporation
O43 - CFD: 17/08/2014 - [] D -- C:\ProgramData\VS Revo Group =>.VS Revo Group
O43 - CFD: 19/03/2017 - [] D -- C:\ProgramData\WindowsHolographicDevices =>.Microsoft Corporation
O43 - CFD: 27/05/2015 - [] D -- C:\ProgramData\X360CE =>.Microsoft Corporation
O43 - CFD: 23/03/2015 - [] D -- C:\Program Files (x86)\Common Files\Adobe =>.Adobe
O43 - CFD: 03/08/2017 - [] AD -- C:\Program Files (x86)\Common Files\Adobe AIR =>.Adobe Inc.
O43 - CFD: 04/03/2016 - [] D -- C:\Program Files (x86)\Common Files\Anvisoft =>.Anvisoft
O43 - CFD: 07/12/2014 - [] D -- C:\Program Files (x86)\Common Files\Atheros =>.Qualcomm Atheros
O43 - CFD: 11/05/2015 - [] D -- C:\Program Files (x86)\Common Files\ATI Technologies =>.ATI Technologies
O43 - CFD: 09/11/2016 - [] AD -- C:\Program Files (x86)\Common Files\DESIGNER =>.Designer
O43 - CFD: 09/03/2015 - [] HD -- C:\Program Files (x86)\Common Files\EAInstaller =>.Electronic Arts, Inc.
O43 - CFD: 22/02/2016 - [] D -- C:\Program Files (x86)\Common Files\InstallShield =>.InstallShield
O43 - CFD: 04/06/2017 - [] D -- C:\Program Files (x86)\Common Files\Intel =>.Intel Corporation
O43 - CFD: 03/08/2017 - [] D -- C:\Program Files (x86)\Common Files\Java =>.Oracle
O43 - CFD: 22/05/2015 - [] D -- C:\Program Files (x86)\Common Files\Macrovision Shared =>.Rovi Corporation
O43 - CFD: 04/06/2017 - [] AD -- C:\Program Files (x86)\Common Files\Microsoft Shared =>.Microsoft Corporation
O43 - CFD: 25/04/2016 - [] D -- C:\Program Files (x86)\Common Files\Nero =>.Ahead Corporation
O43 - CFD: 07/12/2014 - [] D -- C:\Program Files (x86)\Common Files\postureAgent =>.Microsoft Corporation
O43 - CFD: 17/08/2014 - [] D -- C:\Program Files (x86)\Common Files\PX Storage Engine =>.Sonic Solutions
O43 - CFD: 19/03/2017 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 14/02/2015 - [] AD -- C:\Program Files (x86)\Common Files\Skype =>.Skype
O43 - CFD: 04/06/2017 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 17/08/2014 - [] D -- C:\Users\USER\AppData\Roaming\ACD Systems =>.ACD Systems Ltd
O43 - CFD: 08/04/2015 - [] D -- C:\Users\USER\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 11/02/2015 - [] D -- C:\Users\USER\AppData\Roaming\Adobe.ExMan
O43 - CFD: 25/08/2015 - [] D -- C:\Users\USER\AppData\Roaming\AMD =>.AMD
O43 - CFD: 07/12/2014 - [] D -- C:\Users\USER\AppData\Roaming\ATI =>.ATI
O43 - CFD: 27/07/2017 - [] D -- C:\Users\USER\AppData\Roaming\audacity =>.Audacity
O43 - CFD: 08/07/2017 - [] D -- C:\Users\USER\AppData\Roaming\calibre =>.Kovid Goyal
O43 - CFD: 27/02/2016 - [] D -- C:\Users\USER\AppData\Roaming\com.rosettastone.languagetraining
O43 - CFD: 19/03/2015 - [] D -- C:\Users\USER\AppData\Roaming\CyberLink =>.CyberLink Corporation
O43 - CFD: 17/02/2017 - [] D -- C:\Users\USER\AppData\Roaming\discordptb
O43 - CFD: 08/08/2017 - [] D -- C:\Users\USER\AppData\Roaming\DMCache =>.DMCache
O43 - CFD: 17/09/2016 - [] D -- C:\Users\USER\AppData\Roaming\dvdcss =>.VideoLan Team
O43 - CFD: 17/04/2015 - [] D -- C:\Users\USER\AppData\Roaming\Ebook Converter =>.ebook Converter
O43 - CFD: 22/02/2016 - [] D -- C:\Users\USER\AppData\Roaming\FarStone =>.FarStone
O43 - CFD: 13/06/2015 - [0] D -- C:\Users\USER\AppData\Roaming\fltk.org =>.fltk.org
O43 - CFD: 29/07/2017 - [] D -- C:\Users\USER\AppData\Roaming\Foxit AgentInformation =>.Foxit Corporation
O43 - CFD: 29/07/2017 - [] D -- C:\Users\USER\AppData\Roaming\Foxit Software =>.Foxit Software
O43 - CFD: 01/11/2015 - [] D -- C:\Users\USER\AppData\Roaming\Fugazo =>.Games Software
O43 - CFD: 03/08/2017 - [] D -- C:\Users\USER\AppData\Roaming\Geek Uninstaller =>.Geek Uninstaller
O43 - CFD: 02/04/2015 - [] D -- C:\Users\USER\AppData\Roaming\Identities =>.Microsoft Corporation
O43 - CFD: 03/08/2017 - [] D -- C:\Users\USER\AppData\Roaming\IDM =>.IDM
O43 - CFD: 24/03/2015 - [] D -- C:\Users\USER\AppData\Roaming\Kalypso Media =>.Kalypso Media
O43 - CFD: 25/10/2016 - [] AD -- C:\Users\USER\AppData\Roaming\Leapdroid =>.Leapdroid
O43 - CFD: 22/06/2016 - [] D -- C:\Users\USER\AppData\Roaming\library_dir =>.library_dir
O43 - CFD: 02/11/2016 - [] D -- C:\Users\USER\AppData\Roaming\LolClient =>.LolClient
O43 - CFD: 08/07/2017 - [] D -- C:\Users\USER\AppData\Roaming\LSC =>.LSC
O43 - CFD: 17/08/2014 - [] D -- C:\Users\USER\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 03/08/2017 - [] D -- C:\Users\USER\AppData\Roaming\MAGIX =>.Magix
O43 - CFD: 04/05/2015 - [] D -- C:\Users\USER\AppData\Roaming\MetaQuotes
O43 - CFD: 07/07/2017 - [] SD -- C:\Users\USER\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 05/06/2015 - [] D -- C:\Users\USER\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 26/06/2017 - [0] D -- C:\Users\USER\AppData\Roaming\MPC-HC =>.MPC-HC Team
O43 - CFD: 28/07/2017 - [] D -- C:\Users\USER\AppData\Roaming\MusicBee
O43 - CFD: 02/02/2015 - [] D -- C:\Users\USER\AppData\Roaming\My Bluetooth =>.Legitimate
O43 - CFD: 17/08/2014 - [] D -- C:\Users\USER\AppData\Roaming\Nero =>.Ahead Corporation
O43 - CFD: 17/08/2014 - [] D -- C:\Users\USER\AppData\Roaming\Nitro =>.Nitro
O43 - CFD: 09/10/2015 - [] D -- C:\Users\USER\AppData\Roaming\OfficeRecovery
O43 - CFD: 11/07/2016 - [0] D -- C:\Users\USER\AppData\Roaming\Opera Software =>.Opera Software
O43 - CFD: 21/02/2015 - [] D -- C:\Users\USER\AppData\Roaming\PhotoScape =>.Mooii Tech Software
O43 - CFD: 03/08/2017 - [] D -- C:\Users\USER\AppData\Roaming\PrimoPDF
O43 - CFD: 19/02/2017 - [] D -- C:\Users\USER\AppData\Roaming\ProgReporter
O43 - CFD: 25/03/2015 - [] D -- C:\Users\USER\AppData\Roaming\QFX Software =>.QFX Software
O43 - CFD: 17/08/2014 - [] D -- C:\Users\USER\AppData\Roaming\R-TT
O43 - CFD: 15/07/2016 - [] D -- C:\Users\USER\AppData\Roaming\Raptr =>.Raptr
O43 - CFD: 03/08/2017 - [] D -- C:\Users\USER\AppData\Roaming\Samsung =>.Samsung Electronics
O43 - CFD: 09/02/2017 - [] D -- C:\Users\USER\AppData\Roaming\Skype =>.Skype
O43 - CFD: 21/02/2015 - [] D -- C:\Users\USER\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
O43 - CFD: 10/05/2015 - [] D -- C:\Users\USER\AppData\Roaming\Steam =>.Steam Games
O43 - CFD: 03/08/2017 - [] D -- C:\Users\USER\AppData\Roaming\Subtitle Edit =>.Nikse
O43 - CFD: 03/08/2017 - [] D -- C:\Users\USER\AppData\Roaming\Sun =>.Oracle
O43 - CFD: 17/08/2014 - [] D -- C:\Users\USER\AppData\Roaming\TeamViewer =>.TeamViewer GmbH
O43 - CFD: 02/06/2016 - [] D -- C:\Users\USER\AppData\Roaming\The Creative Assembly =>.The Creative Assembly
O43 - CFD: 30/10/2015 - [] D -- C:\Users\USER\AppData\Roaming\Vitzo =>.Vitzo Ltd
O43 - CFD: 08/08/2017 - [] D -- C:\Users\USER\AppData\Roaming\vlc =>.VideoLan Team
O43 - CFD: 25/03/2015 - [] D -- C:\Users\USER\AppData\Roaming\WinRAR =>.WinRAR
O43 - CFD: 28/06/2016 - [] D -- C:\Users\USER\AppData\Roaming\Wise Data Recovery =>.WiseCleaner.com, Inc
O43 - CFD: 08/08/2016 - [] D -- C:\Users\USER\AppData\Roaming\yiwanzhushou
O43 - CFD: 08/08/2017 - [] D -- C:\Users\USER\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 12/10/2016 - [] D -- C:\Users\USER\AppData\Local\4kdownload.com =>.4kdownload.com
O43 - CFD: 16/07/2016 - [0] D -- C:\Users\USER\AppData\Local\ActiveSync =>.Microsoft Corporation
O43 - CFD: 06/03/2017 - [] D -- C:\Users\USER\AppData\Local\Adobe =>.Adobe
O43 - CFD: 05/06/2017 - [] D -- C:\Users\USER\AppData\Local\AMD =>.AMD
O43 - CFD: 05/06/2015 - [] D -- C:\Users\USER\AppData\Local\Ankama =>.Ankama
O43 - CFD: 04/06/2017 - [0] SHD -- C:\Users\USER\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 07/12/2014 - [] D -- C:\Users\USER\AppData\Local\ATI =>.ATI
O43 - CFD: 28/04/2017 - [] D -- C:\Users\USER\AppData\Local\Audacity =>.Audacity
O43 - CFD: 07/08/2016 - [] D -- C:\Users\USER\AppData\Local\Bluestacks =>.BlueStack Systems, Inc.
O43 - CFD: 02/02/2015 - [] D -- C:\Users\USER\AppData\Local\BMExplorer =>.BMExplorer
O43 - CFD: 18/04/2015 - [0] D -- C:\Users\USER\AppData\Local\calibre-cache =>.Kovid Goyal
O43 - CFD: 17/08/2014 - [] D -- C:\Users\USER\AppData\Local\Chris_Pietschmann_(http__
O43 - CFD: 21/08/2015 - [] D -- C:\Users\USER\AppData\Local\Comms =>.Microsoft Corporation
O43 - CFD: 02/04/2015 - [] D -- C:\Users\USER\AppData\Local\Conexant =>.Conexant
O43 - CFD: 10/02/2017 - [] D -- C:\Users\USER\AppData\Local\ConnectedDevicesPlatform =>.Microsoft Corporation
O43 - CFD: 25/04/2016 - [0] D -- C:\Users\USER\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 18/08/2014 - [] D -- C:\Users\USER\AppData\Local\CyberLink =>.CyberLink Corporation
O43 - CFD: 17/08/2014 - [] D -- C:\Users\USER\AppData\Local\Cyberlink SoftDMA =>.CyberLink Corporation
O43 - CFD: 29/03/2016 - [0] D -- C:\Users\USER\AppData\Local\Daedalic Entertainment GmbH =>.Daedalic Entertainment GmbH
O43 - CFD: 03/06/2015 - [] D -- C:\Users\USER\AppData\Local\Darksiders2
O43 - CFD: 04/06/2017 - [0] D -- C:\Users\USER\AppData\Local\DBG =>.DBG
O43 - CFD: 10/07/2017 - [0] D -- C:\Users\USER\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 18/08/2014 - [] D -- C:\Users\USER\AppData\Local\Downloaded Installations =>.Microsoft Corporation
O43 - CFD: 15/01/2017 - [0] D -- C:\Users\USER\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation
O43 - CFD: 17/02/2015 - [] SHD -- C:\Users\USER\AppData\Local\EmieBrowserModeList =>.Enterprise mode Site List Mgr
O43 - CFD: 06/09/2015 - [0] SHD -- C:\Users\USER\AppData\Local\EmieSiteList =>.Enterprise mode Site List Mgr
O43 - CFD: 06/09/2015 - [0] SHD -- C:\Users\USER\AppData\Local\EmieUserList =>.Enterprise mode Site List Mgr
O43 - CFD: 10/05/2015 - [] D -- C:\Users\USER\AppData\Local\EMU =>.Games Software
O43 - CFD: 17/04/2015 - [] D -- C:\Users\USER\AppData\Local\ERW
O43 - CFD: 29/04/2015 - [] D -- C:\Users\USER\AppData\Local\Foxit Reader =>.Foxit Corporation
O43 - CFD: 09/08/2016 - [] D -- C:\Users\USER\AppData\Local\Genymobile =>.Genymobile
O43 - CFD: 25/11/2016 - [] D -- C:\Users\USER\AppData\Local\Google =>.Google
O43 - CFD: 02/06/2015 - [] D -- C:\Users\USER\AppData\Local\GWX =>.GWX
O43 - CFD: 04/06/2017 - [0] SHD -- C:\Users\USER\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 02/02/2015 - [] D -- C:\Users\USER\AppData\Local\Intel_Corporation =>.Intel Corporation
O43 - CFD: 30/01/2016 - [] D -- C:\Users\USER\AppData\Local\joeglens.wordpress.com
O43 - CFD: 08/08/2016 - [] D -- C:\Users\USER\AppData\Local\Leapdroid =>.Leapdroid
O43 - CFD: 30/09/2016 - [] D -- C:\Users\USER\AppData\Local\Lenovo =>.Lenovo
O43 - CFD: 25/03/2015 - [] D -- C:\Users\USER\AppData\Local\Macromedia =>.Macromedia
O43 - CFD: 17/08/2014 - [] D -- C:\Users\USER\AppData\Local\MediaServer =>.MediaServer
O43 - CFD: 07/08/2017 - [] D -- C:\Users\USER\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 30/12/2016 - [] D -- C:\Users\USER\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] D -- C:\Users\USER\AppData\Local\MicrosoftEdge =>.Microsoft Corporation
O43 - CFD: 28/03/2015 - [] D -- C:\Users\USER\AppData\Local\Mozilla =>.Mozilla Corporation
O43 - CFD: 10/02/2017 - [] D -- C:\Users\USER\AppData\Local\My Games =>.My Games
O43 - CFD: 17/08/2014 - [] D -- C:\Users\USER\AppData\Local\Nero =>.Ahead Corporation
O43 - CFD: 20/08/2015 - [0] D -- C:\Users\USER\AppData\Local\NetworkTiles =>.NetworkTiles
O43 - CFD: 11/07/2016 - [0] D -- C:\Users\USER\AppData\Local\Opera Software =>.Opera Software
O43 - CFD: 04/06/2017 - [] D -- C:\Users\USER\AppData\Local\Packages =>.Microsoft Corporation
O43 - CFD: 10/08/2015 - [0] D -- C:\Users\USER\AppData\Local\PeerDistRepub =>.Microsoft Corporation
O43 - CFD: 17/08/2014 - [] D -- C:\Users\USER\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 09/08/2015 - [] D -- C:\Users\USER\AppData\Local\Publishers =>.Microsoft Corporation
O43 - CFD: 27/07/2017 - [] D -- C:\Users\USER\AppData\Local\Recovery =>.Recovery Labs
O43 - CFD: 02/06/2016 - [] D -- C:\Users\USER\AppData\Local\SKIDROW =>.SKIDROW
O43 - CFD: 17/08/2014 - [] D -- C:\Users\USER\AppData\Local\Skype =>.Skype
O43 - CFD: 19/10/2015 - [] D -- C:\Users\USER\AppData\Local\Skyrim =>.Skyrim Games
O43 - CFD: 17/02/2017 - [] D -- C:\Users\USER\AppData\Local\SquirrelTemp =>.Squirrels
O43 - CFD: 08/08/2017 - [] D -- C:\Users\USER\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [0] SHD -- C:\Users\USER\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 09/08/2015 - [] D -- C:\Users\USER\AppData\Local\TileDataLayer =>.Microsoft Corporation
O43 - CFD: 01/06/2017 - [] D -- C:\Users\USER\AppData\Local\UNP =>.Microsoft Corporation
O43 - CFD: 20/09/2016 - [] D -- C:\Users\USER\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 17/08/2014 - [] D -- C:\Users\USER\AppData\Local\VS Revo Group =>.VS Revo Group
O43 - CFD: 08/08/2017 - [] D -- C:\Users\USER\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 17/08/2014 - [0] D -- C:\Users\USER\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [] RD -- C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] RD -- C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 12/07/2017 - [] RD -- C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 04/06/2017 - [] D -- C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory =>.FormatFactory
O43 - CFD: 17/02/2017 - [0] D -- C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hammer & Chisel, Inc =>.Hammer & Chisel, Inc
O43 - CFD: 26/06/2017 - [] D -- C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager =>.Tonec Inc
O43 - CFD: 29/07/2017 - [] D -- C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader =>.JDownloader
O43 - CFD: 19/03/2017 - [] D -- C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [] D -- C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MusicBee
O43 - CFD: 04/06/2017 - [] D -- C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OTELNP
O43 - CFD: 04/06/2017 - [] D -- C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\R-Studio
O43 - CFD: 12/07/2017 - [] RD -- C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [] RD -- C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 16/04/2015 - [0] D -- C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Virtual DJ =>.Atomix Production
O43 - CFD: 19/03/2017 - [] RD -- C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell =>.Microsoft Corporation
O43 - CFD: 03/08/2017 - [] D -- C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 04/06/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 19/03/2017 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 04/06/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 07/08/2017 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 22/07/2017 - [] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Foxit Software =>.Foxit Software

---\\ Image File Execution Options (17) - 1s
O50 - IFEO:C:\Windows\System32\cscript.exe - (.Microsoft Corporation - Microsoft ® Console Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\dllhost.exe - (.Microsoft Corporation - COM Surrogate.) [DisableExceptionChainValidation\\3] =>.Microsoft Windows®
O50 - IFEO:C:\WINDOWS\System32\drvinst.exe - (.Microsoft Corporation - Driver Installation Module.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\ie4uinit.exe - (.Microsoft Corporation - IE Per-User Initialization Utility.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - IE 7.0 Unattended Install Utility.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mmc.exe - (.Microsoft Corporation - Microsoft Management Console.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Microsoft (R) HTML Application host.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Windows Presentation Foundation Host.) [MitigationOptions\\1118481] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\PrintIsolationHost.exe - (.Microsoft Corporation - PrintIsolationHost.) [MitigationOptions\\2097152] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\rundll32.exe - (.Microsoft Corporation - Windows host process (Rundll32).) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\\4294967296] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\searchprotocolhost.exe - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Spooler SubSystem App.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Spooler SubSystem App.) [MitigationOptions\\2097152] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Host Process for Windows Services.) [MinimumStackCommitInBytes\\32768] =>.Microsoft Windows Publisher®
O50 - IFEO:C:\Windows\System32\wscript.exe - (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation

---\\ System Drivers List (85) - 18s
O58 - SDL:2017/06/03 13:35:44 A . (.Malwarebytes - Malwarebytes SwissArmy.) -- C:\WINDOWS\System32\drivers\110C1792.sys [252832] =>.Malwarebytes Corporation®
O58 - SDL:2017/03/19 02:41:25 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107424] =>.Microsoft Windows®
O58 - SDL:2017/06/03 13:36:48 A . (.Malwarebytes - Malwarebytes SwissArmy.) -- C:\WINDOWS\System32\drivers\59E9189A.sys [252832] =>.Malwarebytes Corporation®
O58 - SDL:2014/12/07 14:36:36 A . (.Lenovo Corporation - ACPI Virtual Power Controller Driver.) -- C:\WINDOWS\System32\drivers\AcpiVpc.sys [35600] =>.Lenovo (Beijing) Limited®
O58 - SDL:2017/03/19 02:41:25 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135512] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [83352] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259488] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [27040] =>.Microsoft Windows®
O58 - SDL:2015/02/09 14:24:24 A . (.AnviSoft.com - Anvi Folder Protect Filter Driver.) -- C:\WINDOWS\System32\drivers\AnviFPFltd.sys [28568] =>.Anvei Technology Co., LTD®
O58 - SDL:2017/03/19 02:41:25 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [132000] =>.Microsoft Windows®
O58 - SDL:2016/08/04 02:48:20 A . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\atikmdag.sys [26706464] =>.Microsoft Windows Hardware Compatibility Publisher®
O58 - SDL:2016/08/04 02:48:16 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\WINDOWS\System32\drivers\atikmpag.sys [518176] =>.Microsoft Windows Hardware Compatibility Publisher®
O58 - SDL:2015/09/28 23:53:15 A . (.Sysprogs OU - WinCDEmu virtual CDROM bus.) -- C:\WINDOWS\System32\drivers\BazisVirtualCDBus.sys [172376] =>.Sysprogs OU®
O58 - SDL:2017/03/19 02:41:25 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [9728] =>.Windows (R) Win 7 DDK provider
O58 - SDL:2017/03/19 02:41:23 A . (.QLogic Corporation - QLogic Gigabit Ethernet VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [533920] =>.Microsoft Windows®
O58 - SDL:2015/10/08 13:49:26 A . (.Conexant Systems Inc. - 64-bit High Definition Audio Function Drive.) -- C:\WINDOWS\System32\drivers\CHDRT64.sys [1561728] =>.Conexant Systems, Inc.®
O58 - SDL:2017/03/19 02:41:25 A . (.Chelsio Communications - Chelsio iSCSI Crash Dump Driver.) -- C:\WINDOWS\System32\drivers\cht4dx64.sys [102816] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.Chelsio Communications - Chelsio iSCSI VMiniport Driver.) -- C:\WINDOWS\System32\drivers\cht4sx64.sys [347032] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.Chelsio Communications - Virtual Bus Driver for Chelsio ® T4 Chipset.) -- C:\WINDOWS\System32\drivers\cht4vx64.sys [2104224] =>.Microsoft Windows®
O58 - SDL:2015/08/24 21:55:05 A . (.ELAN Microelectronics Corp. - ETD Kernel Center.) -- C:\WINDOWS\System32\drivers\ETD.sys [467032] =>.ELAN MICROELECTRONICS CORPORATION®
O58 - SDL:2017/03/19 02:41:23 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3419040] =>.Microsoft Windows®
O58 - SDL:2017/06/01 14:19:40 A . (.Malwarebytes - Malwarebytes Anti-Ransomware Protection.) -- C:\WINDOWS\System32\drivers\farflt.sys [113592] =>.Malwarebytes Corporation®
O58 - SDL:2008/10/29 08:47:02 A . (.FarStone Inc. - FarStone Bus Enumerator.) -- C:\WINDOWS\System32\drivers\FCDABUS.SYS [24592] =>.Farstone Technology Inc®
O58 - SDL:2009/12/23 17:33:50 A . (.FarStone Inc. - FarStone SCSI Miniport.) -- C:\WINDOWS\System32\drivers\FVXSCSI.SYS [118360] {02AFB82ABDED8F860823C142D94AB36B} =>.FarStone Inc.
O58 - SDL:2017/03/19 02:41:25 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64416] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:28 A . (.Intel(R) Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iagpio.sys [33280] =>.Intel(R) Corporation
O58 - SDL:2017/03/19 02:41:28 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) -- C:\WINDOWS\System32\drivers\iai2c.sys [81408] =>.Intel(R) Corporation
O58 - SDL:2017/03/19 02:41:28 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [70656] =>.Intel Corporation
O58 - SDL:2017/03/19 02:41:28 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [85504] =>.Intel Corporation
O58 - SDL:2017/03/19 02:41:28 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [165376] =>.Intel Corporation
O58 - SDL:2017/03/19 02:41:28 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [168448] =>.Intel Corporation
O58 - SDL:2017/03/19 02:41:23 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] =>.Intel Corporation - Client Components Group®
O58 - SDL:2017/03/19 02:41:19 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [113152] =>.Intel Corporation
O58 - SDL:2017/03/19 02:41:26 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [673184] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:26 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412064] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [526240] =>.Microsoft Windows®
O58 - SDL:2017/06/08 22:00:14 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\WINDOWS\System32\drivers\idmwfp.sys [223432] =>.Tonec Inc.®
O58 - SDL:2017/06/12 01:56:24 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\igdkmd64.sys [7970232] =>.Intel(R) pGFX®
O58 - SDL:2016/08/21 21:45:38 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\WINDOWS\System32\drivers\IntcDAud.sys [481768] =>.Intel(R) OWR®
O58 - SDL:2013/10/29 06:53:35 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\intelaud.sys [39320] =>.Intel Wireless Display®
O58 - SDL:2013/10/29 06:53:35 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\iwdbus.sys [27032] =>.Intel Wireless Display®
O58 - SDL:2015/06/03 19:28:30 A . (.QFX Software Corporation - KeyScrambler Keyboard Encryption Driver.) -- C:\WINDOWS\System32\drivers\keyscrambler.sys [224208] =>.QFX Software Corporation®
O58 - SDL:2017/03/19 02:41:25 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [108960] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [123808] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [103328] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82848] =>.Microsoft Windows®
O58 - SDL:2017/05/31 11:09:14 A . (...) -- C:\WINDOWS\System32\drivers\mbae64.sys [77376] =>.Malwarebytes Corporation®
O58 - SDL:2017/06/01 14:19:31 A . (.Malwarebytes - Malwarebytes Real-Time Protection.) -- C:\WINDOWS\System32\drivers\mbam.sys [44960] =>.Malwarebytes Corporation®
O58 - SDL:2017/06/01 14:19:48 A . (.Malwarebytes - Malwarebytes Chameleon.) -- C:\WINDOWS\System32\drivers\MBAMChameleon.sys [188312] =>.Malwarebytes Corporation®
O58 - SDL:2017/07/03 18:59:10 A . (.Malwarebytes - Malwarebytes SwissArmy.) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [252832] =>.Malwarebytes Corporation®
O58 - SDL:2017/03/19 02:41:25 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59808] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\MegaSas2i.sys [64416] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575904] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [842656] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63904] =>.Microsoft Windows®
O58 - SDL:2017/06/01 14:21:39 A . (.Malwarebytes - Malwarebytes Web Protection.) -- C:\WINDOWS\System32\drivers\mwac.sys [93600] =>.Malwarebytes Corporation®
O58 - SDL:2017/03/19 02:41:25 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [108960] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150432] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [166304] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [58784] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [61848] =>.Microsoft Windows®
O58 - SDL:2015/08/09 13:04:05 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.40 64-bit Dr.) -- C:\WINDOWS\System32\drivers\rt640x64.sys [886528] =>.Realtek Semiconductor Corp®
O58 - SDL:2015/06/04 11:41:30 A . (.Realtek Semiconductor Corporation - Realtek Bluetooth Filter Driver.) -- C:\WINDOWS\System32\drivers\RtkBtfilter.sys [615728] =>.Realtek Semiconductor Corp®
O58 - SDL:2015/08/10 18:22:26 A . (.Realsil Semiconductor Corporation - RTS USB READER Driver.) -- C:\WINDOWS\System32\drivers\RtsUer.sys [410880] =>.Realtek Semiconductor Corp®
O58 - SDL:2015/08/10 18:22:12 A . (.Realtek Semiconductor Corp. - Realtek UVC Driver for Vista/Win7/Win8/Win8.) -- C:\WINDOWS\System32\drivers\rtsuvc.sys [3068160] =>.Realtek Semiconductor Corp®
O58 - SDL:2013/08/08 14:12:54 A . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/V.) -- C:\WINDOWS\System32\drivers\RtsUVStor.sys [329944] =>.Realtek Semiconductor Corp®
O58 - SDL:2017/03/19 02:41:20 A . (.Realtek Semiconductor Corporation - Realtek PCIE NDIS Driver 47528 20362.) -- C:\WINDOWS\System32\drivers\rtwlane.sys [6320640] =>.Realtek Semiconductor Corporation
O58 - SDL:2017/03/19 02:41:26 A . (...) -- C:\WINDOWS\System32\drivers\SDFRd.sys [31128] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44960] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81824] =>.Microsoft Windows®
O58 - SDL:2016/09/05 05:47:06 A . (.Samsung Electronics Co., Ltd. - SAMSUNG USB Composite Device Driver.) -- C:\WINDOWS\System32\drivers\ssudbus.sys [131712] =>.Samsung Electronics CO., LTD.®
O58 - SDL:2016/09/05 05:47:12 A . (.Samsung Electronics Co., Ltd. - SAMSUNG Android Modem Device Driver.) -- C:\WINDOWS\System32\drivers\ssudmdm.sys [165504] =>.Samsung Electronics CO., LTD.®
O58 - SDL:2017/03/19 02:41:25 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31136] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:42:24 A . (. - WDM CODEC Class Device Driver 2.0.) -- C:\WINDOWS\System32\drivers\stream.sys [75776] =>.Microsoft Corporation
O58 - SDL:2016/04/21 14:55:04 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\WINDOWS\System32\drivers\tap0901.sys [27136] =>.The OpenVPN Project
O58 - SDL:2017/02/09 16:40:18 A . (.Anchorfree Inc. - Anchorfree HSS VPN Adapter.) -- C:\WINDOWS\System32\drivers\taphss6.sys [42064] =>.AnchorFree Inc®
O58 - SDL:2013/09/17 01:05:12 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\TeeDriverx64.sys [99288] =>.Intel Corporation - Intel® Management Engine Firmware®
O58 - SDL:2017/08/08 16:18:24 A . (...) -- C:\WINDOWS\System32\drivers\TrueSight.sys [28272] =>.Adlice®
O58 - SDL:2015/09/08 11:47:40 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Host-Only Network Adapt.) -- C:\WINDOWS\System32\drivers\VBoxNetAdp6.sys [117768] =>.Oracle Corporation®
O58 - SDL:2015/09/08 11:47:40 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Lightweight Filter Driv.) -- C:\WINDOWS\System32\drivers\VBoxNetLwf.sys [146072] =>.Oracle Corporation®
O58 - SDL:2017/03/19 02:41:25 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166816] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305568] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [32160] =>.Microsoft Windows®
O58 - SDL:2017/03/19 02:41:25 A . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [64920] =>.Microsoft Windows®
O58 - SDL:2013/11/12 22:50:22 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\athwbx.sys [3880448] =>.Qualcomm Atheros Communications, Inc.

---\\ Last modified or created user files (3) - 115s
O61 - LFC: 2017/08/03 22:33:28 A . (..) -- C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\z94n8t79.default\extensions\adbhelper@mozilla.org\win32\adb.exe [1489920]
O61 - LFC: 2017/08/03 22:33:28 A . (..) -- C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\z94n8t79.default\extensions\adbhelper@mozilla.org\win32\fastboot.exe [806912]
O61 - LFC: 2017/08/03 15:23:57 A . (..) -- C:\Users\USER\Desktop\rsthosts_2.0.exe [353632]

---\\ File Associations Shell Spawning (11) - 0s
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- D:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®

---\\ Start Menu Internet (16) - 0s
O68 - StartMenuInternet: <Firefox-E7CF176E110C211B> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- d:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O68 - StartMenuInternet: <Firefox-E7CF176E110C211B> <Mozilla Firefox>[HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- d:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: <Firefox-E7CF176E110C211B> <Mozilla Firefox>[HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- d:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: <Firefox-E7CF176E110C211B> <Mozilla Firefox>[HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- d:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

---\\ Search Browser Infection (5) - 16s
O69 - SBI: SearchScopes [HKCU] {012E1000-F331-11DB-8314-0800200C9A66} - (Google) - http://www.google.com/ =>.Google Inc.
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKCU] {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} - (Google) - http://www.google.com/ =>.Google Inc.
O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKLM] {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} - (Google) - http://www.google.com/ =>.Google Inc.

---\\ Search Svchost Services (47) - 1s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\WINDOWS\System32\certprop.dll [189952] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\WINDOWS\System32\certprop.dll [189952] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\WINDOWS\system32\srvsvc.dll [303616] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\WINDOWS\System32\gpsvc.dll [1269248] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\WINDOWS\System32\ikeext.dll [934912] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\WINDOWS\System32\iphlpsvc.dll [996864] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\WINDOWS\system32\seclogon.dll [31232] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\WINDOWS\System32\appinfo.dll [138752] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\WINDOWS\system32\iscsiexe.dll [150016] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\WINDOWS\System32\eapsvc.dll [108032] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\WINDOWS\system32\schedsvc.dll [877568] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [221696] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\WINDOWS\system32\profsvc.dll [413696] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [385536] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\WINDOWS\System32\wercplsupport.dll [91648] =>.Microsoft Corporation
O83 - Search Svchost Services: shpamsvc (shpamsvc) . (.Microsoft Corporation - SharedPC.AccountManager.) -- C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll [192512] =>.Microsoft Corporation
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\WINDOWS\System32\XblGameSave.dll [1135104] =>.Microsoft Corporation
O83 - Search Svchost Services: NaturalAuthentication (NaturalAuthentication) . (.Microsoft Corporation - Natural Authentication Service.) -- C:\WINDOWS\System32\NaturalAuth.dll [723968] =>.Microsoft Corporation
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Microsoft® Account Service.) -- C:\WINDOWS\system32\wlidsvc.dll [2155008] =>.Microsoft Corporation
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\WINDOWS\System32\usermgr.dll [877568] =>.Microsoft Corporation
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\WINDOWS\System32\XblAuthManager.dll [1013248] =>.Microsoft Corporation
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - Windows Managent Service DLL.) -- C:\Windows\System32\Windows.Internal.Management.dll [536064] =>.Microsoft Corporation
O83 - Search Svchost Services: xbgm (xbgm) . (.Microsoft Corporation - Xbox Game Monitoring Service.) -- C:\WINDOWS\System32\xbgmsvc.dll [301216] =>.Microsoft Windows Publisher®
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\WINDOWS\system32\themeservice.dll [69632] =>.Microsoft Corporation
O83 - Search Svchost Services: TokenBroker (TokenBroker) . (.Microsoft Corporation - Token Broker.) -- C:\Windows\System32\TokenBroker.dll [1054208] =>.Microsoft Corporation
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Geolocation Service.) -- C:\WINDOWS\System32\lfsvc.dll [43520] =>.Microsoft Corporation
O83 - Search Svchost Services: Irmon (Irmon) . (.Microsoft Corporation - Infrared Monitor.) -- C:\WINDOWS\System32\irmon.dll [24576] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\WINDOWS\System32\rasauto.dll [104448] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINDOWS\System32\rasmans.dll [873472] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [490496] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\WINDOWS\System32\sens.dll [69632] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\WINDOWS\System32\ipnathlp.dll [537600] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [306688] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\WINDOWS\system32\wuaueng.dll [2444288] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\WINDOWS\System32\qmgr.dll [1159680] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [612864] =>.Microsoft Corporation
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\WINDOWS\system32\dmwappushsvc.dll [55296] =>.Microsoft Corporation
O83 - Search Svchost Services: wisvc (wisvc) . (.Microsoft Corporation - Flight Settings.) -- C:\WINDOWS\system32\flightsettings.dll [699904] =>.Microsoft Corporation
O83 - Search Svchost Services: WpnService (WpnService) . (.Microsoft Corporation - Windows Push Notification System Service.) -- C:\WINDOWS\system32\WpnService.dll [276480] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\WINDOWS\System32\bdesvc.dll [385536] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\WINDOWS\system32\XboxNetApiSvc.dll [1067008] =>.Microsoft Corporation
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Update Session Orchestrator Core.) -- C:\WINDOWS\system32\usocore.dll [681984] =>.Microsoft Corporation
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Network Setup Service.) -- C:\WINDOWS\System32\NetSetupSvc.dll [261632] =>.Microsoft Corporation
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Device Setup Manager.) -- C:\WINDOWS\System32\DeviceSetupManager.dll [233984] =>.Microsoft Corporation
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Microsoft Network Connectivity Assistant Se.) -- C:\WINDOWS\System32\ncasvc.dll [167424] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxGipSvc (XboxGipSvc) . (.Microsoft Corporation - Xbox Gip Management Service.) -- C:\WINDOWS\System32\XboxGipSvc.dll [18944] =>.Microsoft Corporation
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Software installation Service.) -- C:\Windows\System32\appmgmts.dll [196096] =>.Microsoft Corporation

---\\ Additional Scan (O88) (1) - 1s
~ No malicious or unnecessary items found.

---\\ Summary of the elements found (2) - 0s
https://www.anti-malware.top/2016/09/10/superfluous-greentreeapp/ =>.Superfluous.GreenTreeApp
https://nicolascoolman.eu/2017/02/23/tencentadressbar/ =>.Superfluous.Tencent

~ Unselected Options:
~ End of the scan, 41194 items in 06mn13s (1281)(0)
 
ZHP Diag Fix.


ZHP Fix
4bd9Ugb.png

  • Disable your antivirus prior to this fix!
  • Download ZHP-Fix from here.
  • UnZip it to your desktop -- Tool Here if needed.... 7-Zip
  • Install it.
  • Click Suivant 5 Times.
  • Then Installer.
  • Then Terminer.
  • Then right clcick the ZHP Fix icon Run as admin.
  • Copy the entire content of the code box below, the next step will grab it from your clipboard.
  • Then click on import.
  • Then click GO.
  • If you see any Prompts like the one below, select Oui. = Yes in French.
  • upload_2017-5-24_21-17-40-png.2248

  • Allow completion.
  • A log file will appear on your desktop.
  • Post it here in your next reply.
Code:
Script ZhpFix
SysRestore
EmptyFlash
ProxyFix
EmptyCLSID
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl®
SS - Demand [11/07/2017] [ 272384] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated®
SS - Demand [17/09/2013] [ 169432] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation®
SS - Auto [17/09/2013] [ 169432] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl®
[MD5.8E65EBE8511CD0757BBB17C7670F6563] [APT] [Tweaking.com - Windows Repair Tray Icon] (.Tweaking.com.) -- C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [218336] (.Activate.) =>.Tweaking LLC®
O39 - APT: Unknown - (...) -- C:\WINDOWS\System32\Tasks\shutdown [2478]
O39 - APT: Tweaking.com - Windows Repair Tray Icon - (.Tweaking.com.) -- C:\WINDOWS\System32\Tasks\Tweaking.com - Windows Repair Tray Icon [3758] =>.Tweaking LLC®
O39 - APT: {1E6113B1-6320-42D6-98F3-9B2BBA5E0C28} - (.Mozilla Corporation.) -- C:\WINDOWS\System32\Tasks\{1E6113B1-6320-42D6-98F3-9B2BBA5E0C28} [2240] =>.Mozilla Corporation®
HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\shutdown
HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Tweaking.com - Windows Repair Tray Icon
G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.gstatic.com =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.
P2 - EXT FILE: (.http://coolrom.com/contact.php - Coolrom Search Engine.) -- C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\z94n8t79.default\extensions\{0fc22c4c-93ed-48ea-ad12-dc8039cf3795}.xpi
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphan =>.Microsoft Internet Explorer
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
O40 - TASK: {BF728E4A-B1B4-406C-A6B2-1A4888A56396} - (...) -- C:\WINDOWS\system32\osppc.dll (.not file.) [0] (.Orphan.) =>.Superfluous.Orphan
O42 - Logiciel: Mozilla Firefox 39.0 (x86 en-US) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 39.0 (x86 en-US) =>.Mozilla Corporation®
O42 - Logiciel: Mozilla Firefox 47.0.1 (x86 en-US) - (.Mozilla.) [HKCU][64Bits] -- Mozilla Firefox 47.0.1 (x86 en-US) =>.Mozilla Corporation®
HKLM\SOFTWARE\Wow6432Node\Eset =>.ESET
HKLM\SOFTWARE\Wow6432Node\Free YouTube Downloader =>.DawnArk, Inc
HKLM\SOFTWARE\Wow6432Node\Wondershare =>.Wondershare
HKCU\SOFTWARE\BlueStacks =>.BlueStack Systems, Inc.
HKCU\SOFTWARE\Boneloaf
HKCU\SOFTWARE\Chromium =>.Chromium
HKCU\SOFTWARE\epsxe =>.ePSXe
HKCU\SOFTWARE\ESET =>.ESET
HKCU\SOFTWARE\RLZer
HKCU\SOFTWARE\Tencent =>.Superfluous.Tencent
HKCU\SOFTWARE\ThsDict.ini
HKCU\SOFTWARE\ThsDict.ini2
HKCU\SOFTWARE\Vision Thing
HKCU\SOFTWARE\Yahoo =>.Yahoo! Inc.
HKCU\SOFTWARE\AppDataLow\Software\Yahoo =>.Yahoo! Inc.
HKCU\SOFTWARE\Ó¦ÓóÌÐòÏòµ¼Éú³ÉµÄ±¾µØÓ¦ÓóÌÐò
C:\Program Files\Leapdroid
C:\Program Files (x86)\Belarc
C:\Program Files (x86)\NSIS Uninstall Information
C:\ProgramData\BlueStacksSetup
C:\Users\USER\AppData\Roaming\My Bluetooth
C:\Users\USER\AppData\Roaming\yiwanzhushou
C:\Users\USER\AppData\Local\Bluestacks
C:\Users\USER\AppData\Local\Chris_Pietschmann_(http__
C:\Users\USER\AppData\Local\GWX
O58 - SDL:2016/04/21 14:55:04 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\WINDOWS\System32\drivers\tap0901.sys [27136] =>.The OpenVPN Project
O58 - SDL:2017/02/09 16:40:18 A . (.Anchorfree Inc. - Anchorfree HSS VPN Adapter.) -- C:\WINDOWS\System32\drivers\taphss6.sys [42064] =>.AnchorFree Inc®
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\WINDOWS\system32\dmwappushsvc.dll [55296] =>.Microsoft Corporation
HKCU\SOFTWARE\GreenTree Applications =>.Superfluous.GreenTreeApp
EmptyTemp
 
  • Like
Reactions: maxim123
Hi, here is the zhpfix log:

Code:
Rapport de ZHPFix 2015.10.19.9 par Nicolas Coolman, Update du 19/10/2015
Fichier d'export Registre :
Run by Max at 8/9/2017 10:51:15 AM
High Elevated Privileges : OK
Windows 8 Business Edition, 64-bit Service Pack 1 (15063)

Recycle Bin emptied (02mn AMs)

========== Software ==========
ABSENT Uninstall Process: d:\program files (x86)\mozilla firefox\uninstall\helper.exe

========== Registry keys ==========
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 39.0 (x86 en-US)]
REMOVES Logiciel Key: [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 47.0.1 (x86 en-US)]
REMOVES: Service: SkypeUpdate
REMOVES: HKLM\SOFTWARE\Wow6432Node\Eset
REMOVES: HKLM\SOFTWARE\Wow6432Node\Free YouTube Downloader
REMOVES: HKLM\SOFTWARE\Wow6432Node\Wondershare
REMOVES: HKCU\SOFTWARE\BlueStacks
REMOVES: HKCU\SOFTWARE\Boneloaf
REMOVES: HKCU\SOFTWARE\Chromium
REMOVES: HKCU\SOFTWARE\epsxe
REMOVES: HKCU\SOFTWARE\ESET
REMOVES: HKCU\SOFTWARE\RLZer
REMOVES: HKCU\SOFTWARE\Tencent
REMOVES: HKCU\SOFTWARE\ThsDict.ini
REMOVES: HKCU\SOFTWARE\ThsDict.ini2
REMOVES: HKCU\SOFTWARE\Vision Thing
REMOVES: HKCU\SOFTWARE\Yahoo
REMOVES: HKCU\SOFTWARE\AppDataLow\Software\Yahoo
REMOVES: HKCU\SOFTWARE\Ó¦ÓóÌÐòÏòµ¼Éú³ÉµÄ±¾µØÓ¦ÓóÌÐò
REMOVES: Services Svchost: dmwappushservice
REMOVES: HKCU\SOFTWARE\GreenTree Applications

========== Registry values ==========
ProxyFix : Proxy configuration successfully removed
REMOVES ProxyServer Value
REMOVES ProxyEnable Value
REMOVES EnableHttp1_1 Value
REMOVES ProxyHttp1.1 Value
REMOVES ProxyOverride Value
REMOVES: URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497}

========== Elements of the registry data ==========
REMOVES: R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable
REMOVES: R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy
REMOVES: R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1
REMOVES: R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1

========== Folders ==========
No folders empty CLSID Local user
REMOVES: c:\program files\leapdroid
REMOVES: c:\program files (x86)\belarc
REMOVES: c:\program files (x86)\nsis uninstall information
REMOVES: c:\programdata\bluestackssetup
REMOVES: c:\users\user\appdata\roaming\my bluetooth
REMOVES: c:\users\user\appdata\roaming\yiwanzhushou
REMOVES: c:\users\user\appdata\local\bluestacks
REMOVES: c:\users\user\appdata\local\chris_pietschmann_(http__
REMOVES: c:\users\user\appdata\local\gwx
Deletes temporary Windows (218)

========== Files ==========
REMOVES Flash Cookies (0) (0 octets)
REMOVES: c:\program files (x86)\skype\updater\updater.exe
REMOVES Reboot: c:\windows\system32\tasks\shutdown
REMOVES Reboot: c:\windows\system32\tasks\{1e6113b1-6320-42d6-98f3-9b2bba5e0c28}
REMOVES Reboot: c:\windows\system32\drivers\tap0901.sys
REMOVES Reboot: c:\windows\system32\drivers\taphss6.sys
Deletes temporary Windows (6509) (628,620,600 octets)

========== Scheduled task ==========
REMOVES: Tweaking.com - Windows Repair Tray Icon

========== System restore ==========
No System Restore Point created

========== Other ==========
NON-TREATY O40 - TASK: {BF728E4A-B1B4-406C-A6B2-1A4888A56396} - (...) -- C:\WINDOWS\system32\osppc.dll (.not file.) [0] (.Orphan.)


========== Summary ==========
21 : Registry keys
7 : Registry values
4 : Elements of the registry data
11 : Folders
7 : Files
1 : Software
1 : Scheduled task
1 : System restore
1 : Other


End of clean in 44mn AMs

========== Path to file report ==========
C:\Users\USER\AppData\Roaming\ZHP\ZHPFix[R1].txt - 8/9/2017 10:51:17 AM [3705]

It tried to uninstall firefox, which I cancelled. Do I have to uninstall the firefox? Also, I haven't run chkdsk, do I have to run it (you told me to ask before I do it)?
 
9-Lab Scan.



  • Download 9-Lab Removal Tool.
  • CLICK HERE to determine whether you're running 32-bit or 64-bit for Windows.
  • Disable your antivirus prior to this scan.
  • Install the program onto your computer, then right click the icon run as administrator.
  • Update the program and then run a Quick scan!
  • Make sure the program updates, might be better to install it update reboot and check for updates again.
  • You need to make sure the database updates!!!
  • Upon Scan Completion Click on Show Results.
  • Then Click On Clean
  • Then Click on Save Log.
  • Save it to your desktop, copy and paste the contents of the log here in your next reply.
 
got it:

Code:
9-lab Removal Tool 1.0.0.39 BETA
9-lab.com

Database version: 177.51574

Windows 8 (Version 6.2, Build 0, 64-bit Edition)
Internet Explorer 9.11.15063.0
Max :: ADMIN

8/13/2017 9:35:45 PM
9lab-log-2017-08-13 (21-35-45).txt

Scan type: Quick
Objects scanned: 31865
Time Elapsed: 19 m 25 s

Registry Keys detected: 5
Adware.RPL.Gen.vl [HKEY_CLASSES_ROOT\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}]
Adware.RPL.Gen.vl [HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}]
Adware.RPL.Gen.vl [HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}]
Adware.RPL.Gen.vl [HKEY_CLASSES_ROOT\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}]
Adware.RMPL.Shopper.vl [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\{DAF8B7E5-449D-4180-8281-10E536E597F2}]


Registry Values detected: 1
Adware.RPL.5Hex.vl [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run startcn]


ActiveX detected: 47
[C2E55F19B9E71DF7A0287C1AF87643C7] PUP.FPL.Gen.tv [{51A00247-40A8-4845-9F17-7DBFCC9A8783} c:\program files (x86)\freecodecpack\haali\avi.x64.dll]
[08E4448B797FB3B601D59917242BB0EE] PUP.FPL.Gen.tv [{53D9DE0B-FC61-4650-9773-74D13CC7E582} c:\program files (x86)\freecodecpack\haali\mkx.x64.dll]
[CE694B77C2DF4E862EA7AD11E6D01A5F] PUP.FPL.Gen.tv [{55DA30FC-F16B-49FC-BAA5-AE59FC65F82D} c:\program files (x86)\freecodecpack\haali\splitter.x64.ax]
[CE694B77C2DF4E862EA7AD11E6D01A5F] PUP.FPL.Gen.tv [{564FD788-86C9-4444-971E-CC4A243DA150} c:\program files (x86)\freecodecpack\haali\splitter.x64.ax]
[08E4448B797FB3B601D59917242BB0EE] PUP.FPL.Gen.tv [{64F2005C-6CF5-4652-B94F-600360B15B27} c:\program files (x86)\freecodecpack\haali\mkx.x64.dll]
[5BB2B619940BC10ABDBE9EF4D02EFC9E] PUP.FPL.Gen.tv [{760A8F35-97E7-479D-AAF5-DA9EFF95D751} c:\program files (x86)\freecodecpack\haali\dxr.x64.dll]
[CE694B77C2DF4E862EA7AD11E6D01A5F] PUP.FPL.Gen.tv [{7B63A013-DC2C-462E-9292-CAF8C867100F} c:\program files (x86)\freecodecpack\haali\splitter.x64.ax]
[CE694B77C2DF4E862EA7AD11E6D01A5F] PUP.FPL.Gen.tv [{895322C5-84A1-450C-8478-C57793CAE86F} c:\program files (x86)\freecodecpack\haali\splitter.x64.ax]
[5BB2B619940BC10ABDBE9EF4D02EFC9E] PUP.FPL.Gen.tv [{8E8B4A31-408B-4929-86A4-A9FA9F01BA43} c:\program files (x86)\freecodecpack\haali\dxr.x64.dll]
[CE694B77C2DF4E862EA7AD11E6D01A5F] PUP.FPL.Gen.tv [{8F43B7D9-9D6B-4F48-BE18-4D787C795EEA} c:\program files (x86)\freecodecpack\haali\splitter.x64.ax]
[CE694B77C2DF4E862EA7AD11E6D01A5F] PUP.FPL.Gen.tv [{90C7D10E-CE9A-479B-A238-1A0F2396DE43} c:\program files (x86)\freecodecpack\haali\splitter.x64.ax]
[CE694B77C2DF4E862EA7AD11E6D01A5F] PUP.FPL.Gen.tv [{A28F324B-DDC5-4999-AA25-D3A7E25EF7A8} c:\program files (x86)\freecodecpack\haali\splitter.x64.ax]
[5BB2B619940BC10ABDBE9EF4D02EFC9E] PUP.FPL.Gen.tv [{A36C253D-CEE4-4BCA-9CC2-E03CF6BBB054} c:\program files (x86)\freecodecpack\haali\dxr.x64.dll]
[75E6D6DFAC96118358D684E3EAEED39A] PUP.FPL.Gen.tv [{B3DE7EDC-0CD4-4D07-B1C5-92219CD475CC} c:\program files (x86)\freecodecpack\haali\mp4.x64.dll]
[F13B6D469F3E7B705A9A9DB87AC668FE] PUP.FPL.Gen.tv [{B841F346-4835-4DE8-AA5E-2E7CD2D4C435} c:\program files (x86)\freecodecpack\haali\ts.x64.dll]
[08E4448B797FB3B601D59917242BB0EE] PUP.FPL.Gen.tv [{BD4FB4BE-809D-487B-ADD6-F7D164247E52} c:\program files (x86)\freecodecpack\haali\mkx.x64.dll]
[C45CC534B4E6BD8B5632FBEF3AC41182] PUP.FPL.Gen.tv [{DB43B405-43AA-4F01-82D8-D84D47E6019C} c:\program files (x86)\freecodecpack\haali\ogm.x64.dll]
[CE694B77C2DF4E862EA7AD11E6D01A5F] PUP.FPL.Gen.tv [{F13D3732-96BD-4108-AFEB-E85F68FF64DC} c:\program files (x86)\freecodecpack\haali\splitter.x64.ax]
[193F78604E232181DB7B882492E569B9] PUP.FPL.Gen.tv [{0180E49C-13BF-46DB-9AFD-9F52292E1C22} c:\program files (x86)\freecodecpack\vsfilter.dll]
[193F78604E232181DB7B882492E569B9] PUP.FPL.Gen.tv [{485CACED-6741-457A-84A2-41FD70C28E3E} c:\program files (x86)\freecodecpack\vsfilter.dll]
[6660C895F0EFBD2E52D1BA6A6CF59EE5] PUP.FPL.Gen.tv [{51A00247-40A8-4845-9F17-7DBFCC9A8783} c:\program files (x86)\freecodecpack\haali\avi.dll]
[193F78604E232181DB7B882492E569B9] PUP.FPL.Gen.tv [{525F116F-04AD-40A2-AE2F-A0C4E1AFEF98} c:\program files (x86)\freecodecpack\vsfilter.dll]
[6B9FE322B9DD432C20EFBA1A317162CB] PUP.FPL.Gen.tv [{53D9DE0B-FC61-4650-9773-74D13CC7E582} c:\program files (x86)\freecodecpack\haali\mkx.dll]
[2B9406C107139FC080035F17AE7DFE9A] PUP.FPL.Gen.tv [{55DA30FC-F16B-49FC-BAA5-AE59FC65F82D} c:\program files (x86)\freecodecpack\haali\splitter.ax]
[2B9406C107139FC080035F17AE7DFE9A] PUP.FPL.Gen.tv [{564FD788-86C9-4444-971E-CC4A243DA150} c:\program files (x86)\freecodecpack\haali\splitter.ax]
[193F78604E232181DB7B882492E569B9] PUP.FPL.Gen.tv [{60765CF5-01C2-4EE7-A44B-C791CF25FEA0} c:\program files (x86)\freecodecpack\vsfilter.dll]
[6B9FE322B9DD432C20EFBA1A317162CB] PUP.FPL.Gen.tv [{64F2005C-6CF5-4652-B94F-600360B15B27} c:\program files (x86)\freecodecpack\haali\mkx.dll]
[EE393AD971B476C86C696A30BBE0C31A] PUP.FPL.Gen.tv [{760A8F35-97E7-479D-AAF5-DA9EFF95D751} c:\program files (x86)\freecodecpack\haali\dxr.dll]
[2B9406C107139FC080035F17AE7DFE9A] PUP.FPL.Gen.tv [{7B63A013-DC2C-462E-9292-CAF8C867100F} c:\program files (x86)\freecodecpack\haali\splitter.ax]
[2B9406C107139FC080035F17AE7DFE9A] PUP.FPL.Gen.tv [{895322C5-84A1-450C-8478-C57793CAE86F} c:\program files (x86)\freecodecpack\haali\splitter.ax]
[EE393AD971B476C86C696A30BBE0C31A] PUP.FPL.Gen.tv [{8E8B4A31-408B-4929-86A4-A9FA9F01BA43} c:\program files (x86)\freecodecpack\haali\dxr.dll]
[2B9406C107139FC080035F17AE7DFE9A] PUP.FPL.Gen.tv [{8F43B7D9-9D6B-4F48-BE18-4D787C795EEA} c:\program files (x86)\freecodecpack\haali\splitter.ax]
[2B9406C107139FC080035F17AE7DFE9A] PUP.FPL.Gen.tv [{90C7D10E-CE9A-479B-A238-1A0F2396DE43} c:\program files (x86)\freecodecpack\haali\splitter.ax]
[193F78604E232181DB7B882492E569B9] PUP.FPL.Gen.tv [{93A22E7A-5091-45EF-BA61-6DA26156A5D0} c:\program files (x86)\freecodecpack\vsfilter.dll]
[193F78604E232181DB7B882492E569B9] PUP.FPL.Gen.tv [{9852A670-F845-491B-9BE6-EBD841B8A613} c:\program files (x86)\freecodecpack\vsfilter.dll]
[2B9406C107139FC080035F17AE7DFE9A] PUP.FPL.Gen.tv [{A28F324B-DDC5-4999-AA25-D3A7E25EF7A8} c:\program files (x86)\freecodecpack\haali\splitter.ax]
[EE393AD971B476C86C696A30BBE0C31A] PUP.FPL.Gen.tv [{A36C253D-CEE4-4BCA-9CC2-E03CF6BBB054} c:\program files (x86)\freecodecpack\haali\dxr.dll]
[193F78604E232181DB7B882492E569B9] PUP.FPL.Gen.tv [{A8B25C0E-0894-4531-B668-AB1599FAF7F6} c:\program files (x86)\freecodecpack\vsfilter.dll]
[193F78604E232181DB7B882492E569B9] PUP.FPL.Gen.tv [{ACE4747B-35BD-4E97-9DD7-1D4245B0695C} c:\program files (x86)\freecodecpack\vsfilter.dll]
[D688D4E791197587517E75CEFAD80673] PUP.FPL.Gen.tv [{B3DE7EDC-0CD4-4D07-B1C5-92219CD475CC} c:\program files (x86)\freecodecpack\haali\mp4.dll]
[BA0345ECADAA2B9A00FF7EF1B7D3FBB9] PUP.FPL.Gen.tv [{B841F346-4835-4DE8-AA5E-2E7CD2D4C435} c:\program files (x86)\freecodecpack\haali\ts.dll]
[6B9FE322B9DD432C20EFBA1A317162CB] PUP.FPL.Gen.tv [{BD4FB4BE-809D-487B-ADD6-F7D164247E52} c:\program files (x86)\freecodecpack\haali\mkx.dll]
[193F78604E232181DB7B882492E569B9] PUP.FPL.Gen.tv [{C2D6D98F-09CA-4524-AF64-1049B5665C9C} c:\program files (x86)\freecodecpack\vsfilter.dll]
[193F78604E232181DB7B882492E569B9] PUP.FPL.Gen.tv [{CE77C59C-CFD2-429F-868C-8B04D23F94CA} c:\program files (x86)\freecodecpack\vsfilter.dll]
[E873C53772A4AE5165C2C84C17FE67E5] PUP.FPL.Gen.tv [{DB43B405-43AA-4F01-82D8-D84D47E6019C} c:\program files (x86)\freecodecpack\haali\ogm.dll]
[2B9406C107139FC080035F17AE7DFE9A] PUP.FPL.Gen.tv [{F13D3732-96BD-4108-AFEB-E85F68FF64DC} c:\program files (x86)\freecodecpack\haali\splitter.ax]
[193F78604E232181DB7B882492E569B9] PUP.FPL.Gen.tv [{F544E0F5-CA3C-47EA-A64D-35FCF1602396} c:\program files (x86)\freecodecpack\vsfilter.dll]


Files detected: 121
[6425F4478E3F714860715B3033755D4F] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\Haali\avs.dll]
[3A62FBF76A3738372329EE36AABD7B80] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\Haali\avss.dll]
[7D471B3960FB58E738A44B8A82E2CEF3] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\Haali\cue2xml.js]
[1AFDB1A41CE37F22C93717F44F7BE5A9] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\Haali\dsmux.exe]
[C44533AD159EC52ED0ECFDF84875E00D] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\Haali\dsmux.x64.exe]
[3755FC10292CE34B9717B52DC9D82112] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\Haali\gdsmux.exe]
[4FABD1DE723E6F3B2491AC70DFAB04F6] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\Haali\gdsmux.x64.exe]
[7E5137972C4F79ABD600E57AB4865308] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\Haali\mkunicode.dll]
[E68B896159A647B12A4D943531E14575] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\Haali\mkunicode.x64.dll]
[D7DE01EB541D2C4D924F4F7A069097FB] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\Haali\mkv2vfr.exe]
[A8C730EEB5E2C86FACC3C955EE409169] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\Haali\mkv2vfr.x64.exe]
[985D235316866DCFFC0BFE4D700CD655] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\Haali\mkzlib.dll]
[51FABCC45A765A3B49BC63C4E06197F9] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\Haali\mkzlib.x64.dll]
[625DB1B882A34E19A7694BEA453A6158] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\LAV\avcodec-lav-56.dll]
[C9170F248588F8A3CCA2E902E2F06ED2] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\LAV\avfilter-lav-5.dll]
[F0CA2CF574ADAAD678C8D999DF6FA142] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\LAV\avformat-lav-56.dll]
[9F43D17F6386176ACAEA3CAA16A1F55D] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\LAV\avresample-lav-2.dll]
[77BC4BAFBE905F70E261C10E7083B188] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\LAV\avutil-lav-54.dll]
[E4BB1DD9199A17678C959B160D60E654] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\LAV\IntelQuickSyncDecoder.dll]
[D29BF3FE1466D5F65A53584427F7EA3E] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\LAV\LAVFilters.Dependencies.manifest]
[6804D04D32D30E57051E36E89C3316AE] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\LAV\libbluray.dll]
[2E912AB10299139429A3A39079BE3CD4] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\LAV\README.txt]
[7CB2896F18FD76CDE4D53E2B08EE4FA5] PUP.FPL.Gen.tv [C:\Program Files (x86)\FreeCodecPack\LAV\swscale-lav-3.dll]
[D41D8CD98F00B204E9800998ECF8427E] Adware.FPL.Gen.dd [c:\users\user\appdata\roaming\LolClient\#airversion\21.0.0.176]
[273B1E29A14DCF627C8FFE4CA14E99AE] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\Downloading.dat]
[134C6468BF35F792243A59AE2CAE572D] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\Downloading.dat.bak]
[24B86AA9AB90A9DB640B1B7CE72EB041] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\MediaLib.xml]
[74BCC9C72CA2E59F467B46D0D2B9F409] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\SiteLogo\www.youtube.com.ico.jpg]
[AF886B11DEFA1C28842803478EF96DFF] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{02417829-2F84-4323-A684-AF35ABAD9271}.jpg]
[6498298E444ED9215AEDFEE06A092553] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{0340159C-6B93-4A26-A00F-BF10B29519B6}.jpg]
[9A69DB3653079E6BA290ABCA4928BCB6] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{04A1D463-D4F8-44B6-AD84-55DAB515DBF4}.jpg]
[2271359DF0E0BB56851D1E2F74AA0A43] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{0524FAA4-50E1-47FC-BF55-83ED439DD220}.jpg]
[7FBCCBDC4B011942798B81C034933D0F] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{0BDD00FE-1212-4069-A50D-B007D8891F54}.jpg]
[1F7485F419EA2A4F7081CA4CEDCAFB53] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{0C21D373-8C35-431B-AE85-FD85B98A3C65}.jpg]
[C305C2CA28E220A766C916276F54785D] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{0C6EFE35-5F56-4B52-8759-10913D90D36A}.jpg]
[769AC3D5CC9A9240B860B91DDD55C71A] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{0D081949-BCC4-4FD1-B56F-66991DFB68B5}.jpg]
[49AF060ABBF5D401629223F2DD32AD62] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{0DA766E2-94E4-4823-AD00-48EFCB4E5470}.jpg]
[668C356E3B274623A57A1E7350869168] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{165D3871-B0C2-4608-9D91-B12B952D88FC}.jpg]
[02D88BEED1AA46911099D50B894D5A34] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{16B5FA59-B454-4CF3-A871-7F1B4CDF2F38}.jpg]
[DD9690BECC561666AC2E447C45BF626A] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{16CF0FAA-EA2D-4BF1-82AE-D64B5598928C}.jpg]
[5B818310FD1D3079C2E7307115137396] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{16F8E2CD-E45F-4E9E-90E1-AA3ABE3B1B1B}.jpg]
[0F304E041AC6F730A1844CF19AA16CA1] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{176EFDD2-8D1F-4DC3-8050-73A65BDDD7A8}.jpg]
[13C0F21C6F5781738D31C90EEF9F61C3] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{1B6036EE-1670-40D5-8531-5656E2D93EA4}.jpg]
[BCEB750A2CE4C44BF33E53984D0F4EDF] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{1BCDAFB7-4995-4EDB-A24C-275913474BC3}.jpg]
[665027AD827C920B1AF882EAA013B521] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{1E52215D-4707-4CB4-ABC4-4770C98F39B1}.jpg]
[87CB082D6EBBC4E4757C9641C36211B4] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{20532BB7-B6B7-486D-8F6B-254214EBDC8E}.jpg]
[F51561C02B3CAF226F072DCA34F27BA5] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{24B91BFD-3C26-4576-A07F-1873AB6815E0}.jpg]
[D5A0B8FACC187A01552E88AA62E5574E] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{26E2ADE3-8D7F-4A9F-9D47-785E9B4BEAA4}.jpg]
[7CDE42707F34A9E6BD97EEB5E25623FB] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{29832EB5-90DB-4907-85F8-80667310AD07}.jpg]
[33F5E0868BB3C8CACF97F4A208B68A80] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{30CE22F4-C269-41CF-8002-02815AA6B728}.jpg]
[EE4387076D69C65D97F6706D9FAFC4F0] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{329AC101-3D15-42DE-9C3B-89A3776D4E6D}.jpg]
[EDCB755597E553B0060E43DA51C2783B] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{3754CB7B-589D-44F9-B357-32E6DB0E4406}.jpg]
[F3D717FCD8EC7B82B092A973230D14F5] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{3890C691-094C-4C13-AB45-DD381F50F5B8}.jpg]
[7A51FFC6589E6372385DE680A8417839] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{39E48416-BB68-4D03-A5C0-BF6374EF829B}.jpg]
[E9EFA82CD33DD082A85395BB674E7A7C] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{3A3FF36A-064B-444B-9B82-F7A9EA057E36}.jpg]
[66B66B1C274C0F0366B8C315E2345E3E] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{3E3026AE-C4D9-4C4D-B663-F1AC6429CC99}.jpg]
[9A62DE37B772FBADEDE60B8EC4385389] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{4E34239B-E4A9-4C05-9E11-81AF1F1F6D71}.jpg]
[CA16F5EDC022E59C0116E595FBC14B8E] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{50BC047D-9FC3-4039-805C-2FE9BF186CC5}.jpg]
[CCBCAFFC0056476CD2640859EE572E1D] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{537E956A-004C-4EA6-BF3D-C84342A64FA6}.jpg]
[02D88BEED1AA46911099D50B894D5A34] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{54BE0380-1991-427D-B3CA-F988BA1B5691}.jpg]
[CB79A279EF2D3800A3F0354317D618F3] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{55917A52-52FF-4FDC-9A5A-53A596FF39C0}.jpg]
[74794B25635219CF9231E0D4E33074BA] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{57AA9C96-EE3A-452D-8E07-B97437514134}.jpg]
[893139EDE188FF5E8C97E285AE542B30] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{587C8050-DC15-4AB0-BA1F-B9C3436CCF34}.jpg]
[A78432308BAD508CB37D2FB043EC08FE] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{5A856837-000B-4E0D-9490-29F50BB1AF8E}.jpg]
[3921E787A11D14DDE6E3240049D9D618] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{5B2125E9-63D8-4FFC-8EA7-C036097E0B14}.jpg]
[38162886FAD643207722304C2403D22F] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{5CC09F12-89A1-4792-9EC1-3F8BF9437C90}.jpg]
[F7B9C20E1017D1C6BA28888E918B8F32] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{5D17CCAE-6CE0-4113-9256-6389F79420F9}.jpg]
[8E32FF26E0064188A9F2AA36CAA96580] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{5DDF73EC-F97C-4089-8F73-9CAE3960C569}.jpg]
[D01884F642112803DBDFD2BDFCA1FF76] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{5E64ADA3-C232-46B8-A6FB-775F02672CEB}.jpg]
[202D0BEAF8FFCEC7DBA8C62B058AB409] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{62E641E9-3A48-4284-A5A8-2E28795AA92C}.jpg]
[EC2F6E2FE45BD96C53FEC7FD9BB54574] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{6B2BAB4A-497C-47E0-9084-AB68AEE63763}.jpg]
[54B67079DDD81D5328588AC2FE2BC56D] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{6FC7A6B7-FA35-4999-A9CD-78E87D93F5E9}.jpg]
[5BA5F6B5B443C63446B66BD2035DC125] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{77FC7098-CE3C-427D-89CB-A74D9765623A}.jpg]
[2C8AC56A05BA0093D300B2AF02B3B9CA] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{796FAB6B-25BC-4080-B625-3069B2F5A1EB}.jpg]
[F7F88363B654499C62F006A3ADF332FC] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{7C43343A-95B3-44FD-B3A5-EAB1E7B4C1D2}.jpg]
[489B5B8930D62687996619D5B8339A45] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{82855F70-22C6-4442-AB36-21DA6D248AE8}.jpg]
[D0A4734E8CC8902C35A1E8801CD8AD6E] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{8432087D-4579-4090-9AC2-1A239F834801}.jpg]
[299B491CA94FD816480B289DD4A68F4F] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{84AB8371-487C-4BE1-B118-289AC3A52894}.jpg]
[A36F5D57ECDE48F37F7F11CFB7BCFE20] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{862866BE-B3AD-4909-B790-4BACD7639A5C}.jpg]
[5885F31C37211502DC9C6435DBB7B3B2] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{87431175-6042-4D13-85A2-08A0DCCE44B0}.jpg]
[2B6C9F217DAE8AF5987997F36AA20F46] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{8A9E67B3-4B71-4352-83A0-40D6B29A2AFC}.jpg]
[97D145B4075F9A2DF377CCFDA7030CE9] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{8DF7A331-0C2A-4B15-AF91-6BB4901D1BEB}.jpg]
[3C567D6951E9FC5259CA1E09DC0D830E] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{9A2F823B-9881-4B38-ADA3-4631FE51ADE3}.jpg]
[29E02158367825A7FF3E32CC7407FA02] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{9BD53B34-031E-469E-875F-468A65C41F32}.jpg]
[EF36AA58354411775F4804201BECA455] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{A4743DE5-7590-4C12-9401-5ED0A812447A}.jpg]
[6DA29F38BE2AFD53D2D3685AC45982BC] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{A4F9E3B2-769B-4113-B965-9D7F3768458D}.jpg]
[26AEBD83E572EF6B1CA411C749059EC5] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{A64D0A9E-13DD-4905-854A-30F488E5A00B}.jpg]
[A57CCE8AF44B3695EB246ECB9006B2B0] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{A677D93D-B29C-4EAB-A96D-FE543A1FAD44}.jpg]
[F3D717FCD8EC7B82B092A973230D14F5] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{A9DC5B30-89CC-41B4-BEBF-0C8A28D58C42}.jpg]
[03B2E9793E92CF3CA577FAC46B9BD7E3] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{ABC8478F-3EB4-45F1-A80A-10DBE4BE154B}.jpg]
[F7D086BE07D926DCB0FC3D00EC7F8BF2] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{ACC5058F-D532-41DB-B622-86D9DE182C86}.jpg]
[0F304E041AC6F730A1844CF19AA16CA1] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{AE97F6D9-9761-4129-86FC-3C3841CA1A61}.jpg]
[D447D73513842DC0F2A8A210618FCB76] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{B0543709-D178-4912-85D1-8C3D8BB00AD4}.jpg]
[4AEFB77F0483EDF4F0BE4D8DB7048D86] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{B69B470D-3851-467F-AACC-DDD98910C6DE}.jpg]
[C0353B27BCB854B3BE04889D8BCBAD46] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{B75B147A-EEBC-4E5D-94BA-74EF753A747D}.jpg]
[893139EDE188FF5E8C97E285AE542B30] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{BA564DA7-9D24-42AA-97B7-BD21D1FC3D48}.jpg]
[0FC23778F099D7E6AB1956E185AB2A34] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{BD7D4579-6029-4DA0-8AB0-989CDC3536D0}.jpg]
[D1D4BB42D14AC05A19C8EF079F90FFD1] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{BF007232-A3EA-4B32-A399-64D7EF2A050C}.jpg]
[15428D081972054939898ACBC596965B] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{BF119D18-05D0-401F-8A98-EC12917FF2DA}.jpg]
[409DC9589EBAFF2D3902564B5603DF7B] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{C43D2AED-3989-4037-8AEB-BB022B1FABDE}.jpg]
[A15A0D832DF5BF87351C7BD1EEF49683] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{C78B5158-C804-4705-92AE-009C975BA5CF}.jpg]
[0A1CB4797BCD2B15C100795F17D1159B] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{C7CEB200-B858-43E5-B7B0-AFE4A0E0DFDB}.jpg]
[CC716C86CEE4AA6C46BE6A577451B0E0] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{CB62D162-F0FA-4DFE-9A79-332363ADF2A5}.jpg]
[81376C7AC0CFDA95A65A10488D3037A9] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{CF76B6D9-04FB-4F59-92B7-DCEE0D33A116}.jpg]
[F26F9F65AC1B93F9544378BEAA115E8E] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{D538CB7A-7092-49E1-89F3-EA0402E053BD}.jpg]
[7EFB7134310DCDF656825A0C2A5962ED] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{D5ADE971-C6FC-469D-9239-D59393A20B04}.jpg]
[212513FA65623DE2243D497EA23BED9A] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{E00CBAD2-E7A3-401A-B54E-8E71F6DBF470}.jpg]
[CFE2BBB6447D3467CC5DB28D361AFA22] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{E0CB3FB7-E5C8-403E-85A8-0CAC06D29573}.jpg]
[807E865E8DBAA0BFAC9F86306A4DA6D4] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{EDB23419-3F51-49A2-B781-E8676D9D7D0C}.jpg]
[A57CCE8AF44B3695EB246ECB9006B2B0] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{F6E10739-B5D7-4D2D-BC08-3127F2A1395F}.jpg]
[016C3FB36104CCC60323D95A4F9C1E84] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{F996D897-79C7-42A3-8B90-56EC72DB6282}.jpg]
[B7C992205FB529551C79CF3BF81AA5A5] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{FA7A49AB-CAC7-4277-827D-171CACF0E3F9}.jpg]
[D0549A1AFD9880A95FFD7D5396A33D88] Adware.FMPL.MultiPlug.vl [C:\ProgramData\iSkysoft Application Common Data\Download\TempThumbDir\{FBFEEC9A-2507-49B6-A611-B5C8E8B10275}.jpg]
[CC7AA7B42CF418FC3D926913490048F8] Malware.Win32.Gen.cld [c:\windows\zoek-delete.exe]
[790ADEBBB3AD5D8DB42D798FEDB98440] PUP.Downloader.vl!c [c:\users\user\appdata\roaming\Microsoft\Windows\Start Menu\Programs\JDownloader\JDownloader 2 Uninstaller.lnk]
[C9DD226E1A8A47BACA133207EE5F50C7] PUP.Downloader.vl!c [c:\users\user\appdata\roaming\Microsoft\Windows\Start Menu\Programs\JDownloader\JDownloader 2 Update & Rescue.lnk]
[F9E0142C3E96CC2D670BA38F6D1503F9] Adware.Win32.Gen.vl!i [C:\Program Files (x86)\Cooler_PC\YTD Video Downloader\Uninstall.exe]
[66EFAD004292BB337E18548B90BC112A] Adware.Win32.Gen.vl!i [C:\Program Files (x86)\Cooler_PC\YTD Video Downloader\ytd.exe]
[687DCB2CA77ECA83497086335C9710F9] PUP.Win32.Ask.vl!n [C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\Ask\ApnIC.dll]
[817E86B7C18A015223A405E79DB836E9] Adware.Win32.Toolbar.vl!n [C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\Ask\ApnStub.exe]
[D848EF0636EA49D340F074F939DB817B] Trojan.Win32.Gen.bot!i [C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\Baidu-TB-ASBar.exe]
 
Hello maxim123, Malnutrition has asked me to assist you whilst he is so busy working long hours atm. From what Ive seen just looking through the thread so far is that the PC is pretty tidy, and we will probably move this thread to where other specialists may assist you. Before we do can I ask the following?
  1. I see you have upgraded to Windows 10 Creators Update, did the issues logging into your router begin then?
  2. Have you tried connecting your PC via lan cable to your router before logging in through your browser, if not can you?
  3. Have you tried different browsers to log into your router?
  4. Can you please give us the make and model of your router?
  5. When you type 192.168.1.1 into the browsers url bar and hit go, what do you get?

Sorry to ask so many questions but this is necessary to narrow down our diagnosis.:)
 
  • Like
Reactions: maxim123
Hello maxim123, Malnutrition has asked me to assist you whilst he is so busy working long hours atm. From what Ive seen just looking through the thread so far is that the PC is pretty tidy, and we will probably move this thread to where other specialists may assist you. Before we do can I ask the following?
  1. I see you have upgraded to Windows 10 Creators Update, did the issues logging into your router begin then?
  2. Have you tried connecting your PC via lan cable to your router before logging in through your browser, if not can you?
  3. Have you tried different browsers to log into your router?
  4. Can you please give us the make and model of your router?
  5. When you type 192.168.1.1 into the browsers url bar and hit go, what do you get?

Sorry to ask so many questions but this is necessary to narrow down our diagnosis.:)

Hi, I tried entering the admin panel again today and it worked :) I don't know which step of the advice Malnutrition gave me did this magic but it is working now (not sure if it is permanent or just temporary though)

- 1 - No, the router worked perfectly at the time of the upgrade to windows 10 and it only stopped working 6 or so months back. When the problem started, it would work for some time if I reset the router but a few days before I created this thread, that method stopped working.
- 2 - I always have my lan cable connected to the pc and only rarely use wifi in my laptop.
- 3- every browsers - I have 3 (IE/ Microsoft Edge, FF and GC)
-4 - TPLINK ( I need to check which type it is, I am currently on wifi )
-5 - it would simply not load at all. It won't go anywhere, just loading for a while then problem loading the page error.

Thank You and @Malnutrition thank you a lot :)
 
  • Like
Reactions: jmarket
Hi maxim123, glad your router is now accessible. Malnutrition has certainly removed some unwanted stuff from your PC. I will now close this thread but should you need further help with this issue in the future please contact a staff member who can assist with re opening this thread:)
 
Status
Not open for further replies.