cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2018.6.22.140 By Nicolas Coolman (2018/06/22)
~ Run by moh (Administrator) (2018/06/24 22:12:36)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Legal
~ State version: Version OK
~ Mode: Scan
~ Report: C:\Users\moh\Desktop\ZHPDiag.txt
~ Report: C:\Users\moh\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Deactivate
~ System startup: Normal (Normal boot)
Windows 7 Professional, 64-bit Service Pack 1 (Build 7601) =>.Microsoft Corporation

---\\ Internet Browsers (4) - 1s
~ GCIE: Google Chrome v67.0.3396.87
~ MFIE: Mozilla Firefox 60.0.2 (x64 ar)
~ MFIE: Opera 42.0.2393.137
~ MSIE: Internet Explorer v11.0.9600.19035

---\\ Windows Product Information (4) - 3s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ Surveillance software (4) - 5s
~ Adobe Flash Player 30 ActiveX (Surveillance)
~ Adobe Flash Player 30 NPAPI (Surveillance)
~ Adobe Flash Player 30 PPAPI (Surveillance)
~ Adobe Acrobat Reader DC (Surveillance)

---\\ System optimization software (1) - 5s
~ CCleaner v5.41 (Optimisation)

---\\ Sharing software PeerToPeer (1) - 5s
~ µTorrent v3.5.3.44358 (P2P)

---\\ Informations on the system (6) - 0s
~ Operating System: Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 4193.528 MB (3% free) : ATTENTION =>Warning RAM
System Restore: Activé (Enable)
System drive C: has 28 GB (36%) free of 76 GB : OK =>.Disk Space

---\\ Connection to the system mode (3) - 0s
~ Computer Name: MOH-PC
~ User Name: moh
~ Logged in as Administrator

---\\ Enumeration of the disk units (3) - 0s
~ Drive C: has 28 GB free of 76 GB (System)
~ Drive D: has 57 GB free of 199 GB
~ Drive E: has 199 GB free of 199 GB

---\\ State of the Windows Security Center (11) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Search Generic System Files (26) - 4s
[MD5.38AE1B3C38FAEF56FE4907922F0385BA] - 29/08/2016 - (.Microsoft Corporation - مستكشف Windows.) -- C:\Windows\Explorer.exe [3229696] =>.Microsoft Corporation
[MD5.C36BB659F08F046B139C8D1B980BF1AC] - 30/03/2017 - (.Microsoft Corporation - عملية مضيف Windows (Rundll32)‎.) -- C:\Windows\System32\rundll32.exe [46080] =>.Microsoft Corporation
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - 14/07/2009 - (.Microsoft Corporation - ‎‎تطبيق بدء تشغيل Windows.) -- C:\Windows\System32\Wininit.exe [129024] =>.Microsoft Corporation
[MD5.AD083DE5E3FE4E54F1C3EEA3E2AC6372] - 25/05/2018 - (.Microsoft Corporation - ملحقات الإنترنت لـ Win32.) -- C:\Windows\System32\wininet.dll [3241472] =>.Microsoft Corporation
[MD5.11D6A262B617130F7C16E308C12E0D41] - 01/01/2018 - (.Microsoft Corporation - تطبيق تسجيل دخول Windows.) -- C:\Windows\System32\Winlogon.exe [455680] =>.Microsoft Corporation
[MD5.067FA52BFB59A56110A12312EF9AF243] - 21/11/2010 - (.Microsoft Corporation - مكتبة تراخيص البرامج.) -- C:\Windows\System32\sppcomapi.dll [232448] =>.Microsoft Corporation
[MD5.492D07D79E7024CA310867B526D9636D] - 03/03/2011 - (.Microsoft Corporation - مكتبة الارتباط الديناميكي لواجهة برمجة تطبي.) -- C:\Windows\System32\dnsapi.dll [357888] =>.Microsoft Corporation
[MD5.B40420876B9288E0A1C8CCA8A84E5DC9] - 03/03/2011 - (.Microsoft Corporation - مكتبة الارتباط الديناميكي لواجهة برمجة تطبي.) -- C:\Windows\Syswow64\dnsapi.dll [270336] =>.Microsoft Corporation
[MD5.0D57D091E06BB1E58E72E5D08479FDDF] - 07/02/2011 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [20480] =>.Microsoft Corporation
[MD5.0DC2A9882540DEA4A55B08785E09D8FC] - 04/04/2017 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [496128] =>.Microsoft Corporation
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - 14/07/2009 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [24128] =>.Microsoft Corporation
[MD5.B8BD2BB284668C84865658C77574381A] - 13/07/2009 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [92160] =>.Microsoft Corporation
[MD5.F036CE71586E93D94DAB220D7BDF4416] - 21/11/2010 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [147456] =>.Microsoft Corporation
[MD5.7D2D2284833760A82308CF09F7618E8B] - 01/01/2018 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [106496] =>.Microsoft Corporation
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - 21/11/2010 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [122368] =>.Microsoft Corporation
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - 13/07/2009 - (.Microsoft Corporation - برنامج تشغيل منفذ i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [105472] =>.Microsoft Corporation
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - 14/07/2009 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [116224] =>.Microsoft Corporation
[MD5.B07AD0FD4026F7E3A146485B728B9CAF] - 29/05/2018 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [160256] =>.Microsoft Corporation
[MD5.734837208CAFD6E0959A7A0333C95C9D] - 11/08/2017 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [262656] =>.Microsoft Corporation
[MD5.8422AFBD1C2D30FFC913309D7F1A366D] - 15/05/2018 - (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\drivers\ntfs.sys [1681088] =>.Microsoft Corporation
[MD5.0086431C29C35BE1DBC43F52CC273887] - 14/07/2009 - (.Microsoft Corporation - برنامج تشغيل المنفذ المتوازي.) -- C:\Windows\System32\drivers\Parport.sys [97280] =>.Microsoft Corporation
[MD5.471815800AE33E6F1C32FB1B97C490CA] - 21/11/2010 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [129536] =>.Microsoft Corporation
[MD5.1B6163C503398B23FF8B939C67747683] - 21/11/2010 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [165888] =>.Microsoft Corporation
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - 14/07/2009 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [93184] =>.Microsoft Corporation
[MD5.4DD986720F7CB7A8A5D1226793097B9A] - 29/07/2017 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [117248] =>.Microsoft Corporation
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - 21/11/2010 - (.Microsoft Corporation - برنامج تشغيل خدمة ملفات الظل الاحتياطية لوح.) -- C:\Windows\System32\drivers\volsnap.sys [295808] =>.Microsoft Corporation

---\\ No disabled Windows Services (54) - 5s
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
O23 - Service: Adobe Flash Player Feedback Service (AdobeFlashPlayerFeedbackSvc) . (.Adobe Systems Incorporated - Adobe® Flash® Player Feedback Service 30.0.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerFeedbackService.exe =>.Adobe Systems Incorporated®
O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\System32\atiesrxx.exe =>.AMD
O23 - Service: C:\Windows\System32\audiosrv.dll (AudioEndpointBuilder) . (.Microsoft Corporation - خدمة صوت Windows.) - C:\Windows\System32\Audiosrv.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\audiosrv.dll (AudioSrv) . (.Microsoft Corporation - خدمة صوت Windows.) - C:\Windows\System32\Audiosrv.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\bfe.dll (BFE) . (.Microsoft Corporation - Base Filtering Engine.) - C:\Windows\System32\bfe.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\qmgr.dll (BITS) . (.Microsoft Corporation - خدمة النقل الذكي في الخلفية.) - C:\Windows\System32\qmgr.dll =>.Microsoft Corporation
O23 - Service: ByteFence Anti-Malware Service (ByteFenceService) . (...) - C:\Program Files\ByteFence\ByteFenceService.exe (.not file.) =>.SUP.ByteFence
O23 - Service: Microsoft .NET Framework NGEN v4.0.30319_X86 (clr_optimization_v4.0.30319_32) . (.Microsoft Corporation - .NET Runtime Optimization Service.) - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe =>.Microsoft Dynamic Code Publisher®
O23 - Service: Microsoft .NET Framework NGEN v4.0.30319_X64 (clr_optimization_v4.0.30319_64) . (.Microsoft Corporation - .NET Runtime Optimization Service.) - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe =>.Microsoft Dynamic Code Publisher®
O23 - Service: C:\Windows\System32\cryptsvc.dll (CryptSvc) . (.Microsoft Corporation - خدمات تشفيرية.) - C:\Windows\System32\cryptsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\cscsvc.dll (CscService) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمة CSC.) - C:\Windows\System32\cscsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\dhcpcore.dll (Dhcp) . (.Microsoft Corporation - خدمة عميل DHCP.) - C:\Windows\System32\dhcpcore.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\UtcResources.dll (DiagTrack) . (.Microsoft Corporation - Microsoft Windows Diagnostics Tracking.) - C:\Windows\System32\diagtrack.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\dnsapi.dll (Dnscache) . (.Microsoft Corporation - خدمة محلل التخزين المؤقت لـ DNS.) - C:\Windows\System32\dnsrslvr.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\efssvc.dll (EFS) . (.Microsoft Corporation - Local Security Authority Process.) - C:\Windows\System32\lsass.exe =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wevtsvc.dll (eventlog) . (.Microsoft Corporation - Host Process for Windows Services.) - C:\Windows\System32\svchost.exe =>.Microsoft Corporation
O23 - Service: @comres.dll,-2450 (EventSystem) . (.Microsoft Corporation - COM+.) - C:\Windows\System32\es.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\FntCache.dll (FontCache) . (.Microsoft Corporation - Windows Font Cache Service.) - C:\Windows\System32\FntCache.dll =>.Microsoft Corporation
O23 - Service: @gpapi.dll,-112 (gpsvc) . (.Microsoft Corporation - عميل نهج المجموعة.) - C:\Windows\System32\gpsvc.dll =>.Microsoft Corporation
O23 - Service: خدمة Google Update (gupdate) (gupdate) . (.Google Inc. - مثبِّت Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
O23 - Service: C:\Windows\System32\ikeext.dll (IKEEXT) . (.Microsoft Corporation - IKE extension.) - C:\Windows\System32\ikeext.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\iphlpsvc.dll (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) - C:\Windows\System32\iphlpsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\srvsvc.dll (LanmanServer) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمة الخادم.) - C:\Windows\System32\srvsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wkssvc.dll (LanmanWorkstation) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمة محطة العمل.) - C:\Windows\System32\wkssvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\lmhsvc.dll (lmhosts) . (.Microsoft Corporation - TCPIP NetBios Transport Services DLL.) - C:\Windows\System32\lmhsvc.dll =>.Microsoft Corporation
O23 - Service: McAfee SiteAdvisor Service (McAfee SiteAdvisor Service) . (.McAfee, Inc. - McAfee WebAdvisor.) - C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe =>.McAfee, Inc.
O23 - Service: C:\Windows\System32\mmcss.dll (MMCSS) . (.Microsoft Corporation - خدمة جدولة فئات تعدد الوسائط.) - C:\Windows\System32\mmcss.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\FirewallAPI.dll (MpsSvc) . (.Microsoft Corporation - خدمة حماية Microsoft.) - C:\Windows\System32\mpssvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\nlasvc.dll (NlaSvc) . (.Microsoft Corporation - Network Location Awareness 2.) - C:\Windows\System32\nlasvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\nsisvc.dll (nsi) . (.Microsoft Corporation - Network Store Interface RPC server.) - C:\Windows\System32\nsisvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\pcasvc.dll (PcaSvc) . (.Microsoft Corporation - خدمة مساعد توافق البرامج.) - C:\Windows\System32\pcasvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\umpnpmgr.dll (PlugPlay) . (.Microsoft Corporation - خدمة 'التوصيل والتشغيل' لوضع المستخدم.) - C:\Windows\System32\umpnpmgr.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\umpo.dll (Power) . (.Microsoft Corporation - User-mode Power Service.) - C:\Windows\System32\umpo.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\profsvc.dll (ProfSvc) . (.Microsoft Corporation - ProfSvc.) - C:\Windows\System32\profsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\system32\RpcEpMap.dll (RpcEptMapper) . (.Microsoft Corporation - معين نقطة نهاية RPC.) - C:\Windows\System32\RpcEpMap.dll =>.Microsoft Corporation
O23 - Service: @oleres.dll,-5010 (RpcSs) . (.Microsoft Corporation - Distributed COM Services.) - C:\Windows\System32\rpcss.dll =>.Microsoft Corporation
O23 - Service: rtop (rtop) . (.Byte Technologies LLC. - ByteFence Real-time Protection Service.) - C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe =>.SUP.ByteFence
O23 - Service: C:\Windows\System32\schedsvc.dll (Schedule) . (.Microsoft Corporation - خدمة جدولة المهام.) - C:\Windows\System32\schedsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\Sens.dll (SENS) . (.Microsoft Corporation - خدمة الإعلام بأحداث النظام (SENS).) - C:\Windows\System32\Sens.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\shsvcs.dll (ShellHWDetection) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمات Windows Sh.) - C:\Windows\System32\shsvcs.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\spoolsv.exe,-1 (Spooler) . (.Microsoft Corporation - Spooler SubSystem App.) - C:\Windows\System32\spoolsv.exe =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\sppsvc.exe,-101 (sppsvc) . (.Microsoft Corporation - ‎‎خدمة النظام الأساسي لحماية البرامج لـ Mic.) - C:\Windows\System32\sppsvc.exe =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wiaservc.dll (stisvc) . (.Microsoft Corporation - خدمة أجهزة الصور الثابتة.) - C:\Windows\System32\wiaservc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\sysmain.dll (SysMain) . (.Microsoft Corporation - مضيف خدمة الإحضار المسبق.) - C:\Windows\System32\sysmain.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\themeservice.dll (Themes) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمات نُسق Windo.) - C:\Windows\System32\themeservice.dll =>.Microsoft Corporation
O23 - Service: UC Browser Service (UCBrowserSvc) . (...) - C:\Program Files (x86)\UCBrowser\Application\UCService.exe =>.TAOBAO (CHINA) SOFTWARE CO.,LTD.®
O23 - Service: (Update service) . (...) - C:\Program Files (x86)\Popcorn Time\Updater.exe =>.SUP.PopcornTime
O23 - Service: C:\Windows\System32\dwm.exe,-2000 (UxSms) . (.Microsoft Corporation - Microsoft User Experience Session Managemen.) - C:\Windows\System32\uxsms.dll =>.Microsoft Corporation
O23 - Service: @%ProgramFiles%\Windows Defender\MsMpRes.dll,-103 (WinDefend) . (.Microsoft Corporation - Service Module.) - C:\Program Files\Windows Defender\MpSvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wbem\wmisvc.dll (Winmgmt) . (.Microsoft Corporation - WMI.) - C:\Windows\System32\wbem\WMIsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wscsvc.dll (wscsvc) . (.Microsoft Corporation - خدمة مركز أمان Windows.) - C:\Windows\System32\wscsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\SearchIndexer.exe,-103 (WSearch) . (.Microsoft Corporation - Microsoft Windows Search Indexer.) - C:\Windows\System32\SearchIndexer.exe =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation - عامل Windows Update.) - C:\Windows\System32\wuaueng.dll =>.Microsoft Corporation

---\\ Services not Microsoft (SR=Run, SS=Stop) (12) - 31s
SR - Auto [09/02/2018] [ 83984] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
SR - Auto [24/05/2018] [ 479744] Adobe Flash Player Feedback Service (AdobeFlashPlayerFeedbackSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerFeedbackService.exe =>.Adobe Systems Incorporated®
SS - Demand [08/06/2018] [ 335872] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated®
SR - Auto [04/08/2015] [ 246784] (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe =>.AMD
SS - Auto [23/06/2018] [ 153168] خدمة Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [23/06/2018] [ 153168] خدمة Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SStart Pending - Auto [29/05/2018] [ 604824] McAfee SiteAdvisor Service (McAfee SiteAdvisor Service) . (.McAfee, Inc..) - C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe =>.McAfee, Inc.
SS - Demand [07/06/2018] [ 194512] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation®
SR - Auto [11/04/2018] [ 297288] rtop (rtop) . (.Byte Technologies LLC..) - C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe =>.SUP.ByteFence
SS - Demand [08/06/2018] [ 593920] SystemUpdate64 (SystemUpdate64) . (.SystemaRev.) - C:\Program Files\SystemaRev\RevServicesX\SystemUpdate64x.exe =>Trojan.Agent
SR - Auto [02/01/2018] [ 656784] UC Browser Service (UCBrowserSvc) . (...) - C:\Program Files (x86)\UCBrowser\Application\UCService.exe =>.TAOBAO (CHINA) SOFTWARE CO.,LTD.®
SS - Auto [17/10/2017] [ 339968] (Update service) . (...) - C:\Program Files (x86)\Popcorn Time\Updater.exe =>.SUP.PopcornTime

---\\ Task Planned Automatically (Register) (6) - 7s
O38 - TASK: {42A7D9BF-F919-408D-9EF9-3FAD913B40E9} [64Bits][\GoogleUpdateTaskMachineUA] - (.Google Inc. - مثبِّت Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168] =>.Google Inc.
O38 - TASK: {B8D81AE4-B942-4CDB-B31F-C7FDAF7D584D} [64Bits][\CCleaner Update] - (.Piriform Ltd - CCleaner emergency updater.) -- C:\Program Files (x86)\CCleaner\CCUpdate.exe [520736] =>.Piriform Ltd
O38 - TASK: {E7EBB357-08BF-4976-BC52-865F8D4AB30A} [64Bits][\GoogleUpdateTaskMachineCore] - (.Google Inc. - مثبِّت Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168] =>.Google Inc.
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [/ua ./ua] =>.Google Inc.
C:\Windows\System32\Tasks\CCleaner Update - (.Piriform Ltd.) -- C:\Program Files (x86)\CCleaner\CCUpdate.exe [] =>.Piriform Ltd
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [/c] =>.Google Inc.

---\\ Auto loading programs from Registry and folders (12) - 17s
O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - إدارة صوت Realtek HD.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp.®
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe =>.Intel Corporation
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe =>.Intel Corporation
O4 - HKLM\..\Run: [Everything] . (.Copyright (C) 2016 David Carpenter - Everything.) -- C:\Program Files\Everything\Everything.exe =>.David Carpenter®
O4 - HKLM\..\Run: [JServicesManager] . (...) -- C:\Program Files\SystemaRev\RevServicesX\app.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files (x86)\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc.
O4 - HKLM\..\Wow6432Node\Run: [JServicesManager] . (...) -- C:\Program Files\SystemaRev\RevServicesX\app.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - ‎‎MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - ‎‎MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-3846459619-3345045358-488364244-1000\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files (x86)\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - HKUS\S-1-5-21-3846459619-3345045358-488364244-1000\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc.

---\\ Process running (28) - 3s
[MD5.606C8F129FE18D6E3EA2FD542D43D72D] - (.AMD - AMD External Events Service Module.) -- C:\Windows\System32\atiesrxx.exe [246784] [PID.860] =>.AMD
[MD5.CC4356B8859E98ACC8E2A1E7FCAE8315] - (.AMD - AMD External Events Client Module.) -- C:\Windows\System32\atieclxx.exe [672768] [PID.1148] =>.AMD
[MD5.CA805DA983594B01F3554464B2E5158F] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [83984] [PID.1548] =>.Adobe Systems, Incorporated®
[MD5.2DC8B4245A7A130BE605B995893603E7] - (.Adobe Systems Incorporated - Adobe® Flash® Player Feedback Service 30.0.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerFeedbackService.exe [479744] [PID.1568] =>.Adobe Systems Incorporated®
[MD5.AA2D6757674D3D7DD8D85E1B5B86F41F] - (.McAfee, Inc. - McAfee WebAdvisor.) -- C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [604824] [PID.1680] =>.McAfee, Inc.
[MD5.1E3684D287D5F141087610D5F3120F11] - (.Byte Technologies LLC. - ByteFence Real-time Protection Service.) -- C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe [297288] [PID.1744] =>.SUP.ByteFence
[MD5.502FDD4B1960E8F4F81F1F3E5D3BE27F] - (...) -- C:\Program Files (x86)\UCBrowser\Application\UCService.exe [656784] [PID.1920] =>.TAOBAO (CHINA) SOFTWARE CO.,LTD.®
[MD5.70C0F95C6F72FD14AB72A37449AA56FD] - (.Byte Technologies LLC. - ByteFence Real-time Protection Background P.) -- C:\Program Files\ByteFence\rtop\bin\rtop_bg.exe [613192] [PID.1532] =>.SUP.ByteFence
[MD5.FDCE23B84DFF75CD965C7B95ECA79F7F] - (.Realtek Semiconductor - إدارة صوت Realtek HD.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18388928] [PID.2432] =>.Realtek Semiconductor Corp.®
[MD5.2C9DB41BE3DBB47427B6D64114893AB4] - (.Copyright (C) 2016 David Carpenter - Everything.) -- C:\Program Files\Everything\Everything.exe [2197608] [PID.2468] =>.David Carpenter®
[MD5.4FF98ED6FD417530A3AF197872077EE8] - (...) -- C:\Program Files\SystemaRev\RevServicesX\app.exe [3823616] [PID.2528]
[MD5.DB9D9C1921CCD94A40C04A37BE79BE44] - (.Piriform Ltd - CCleaner.) -- C:\Program Files (x86)\CCleaner\CCleaner64.exe [17074688] [PID.2564] =>.Piriform Ltd®
[MD5.3C6C68C39F831D2BBE5891DD09B106F8] - (.Facebook - FacebookGameroom.) -- C:\Users\moh\AppData\Local\Facebook\Games\FacebookGameroom.exe [568696] [PID.2688] =>.Facebook, Inc.®
[MD5.6C718849D436A7CCEBED72538F8BD04B] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe [288848] [PID.3056] =>.Google Inc®
[MD5.D2F56E366F1CB26866A6F43BD53B46C3] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe [366160] [PID.3064] =>.Google Inc®
[MD5.B289C20C10B241F6016FECD92B267098] - (.Tonec Inc. - Internet Download Manager agent for click m.) -- C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe [275512] [PID.2524] =>.Tonec Inc.®
[MD5.81D188A849C8768E8F3694EB1C0E6086] - (...) -- C:\Program Files (x86)\ClockworkMod\Universal Adb Driver\adb.exe [819200] [PID.3960]
[MD5.DA54361834E1671CC7A35849F9CAAAFB] - (.The CefSharp Authors - Facebook Gameroom Browser.) -- C:\Users\moh\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe [43896] [PID.2408] =>.Facebook, Inc.®
[MD5.178F860D7BF66F6FD5A275437F2C60CA] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [442832] [PID.4868] =>.Mozilla Corporation®
[MD5.178F860D7BF66F6FD5A275437F2C60CA] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [442832] [PID.5388] =>.Mozilla Corporation®
[MD5.178F860D7BF66F6FD5A275437F2C60CA] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [442832] [PID.5768] =>.Mozilla Corporation®
[MD5.178F860D7BF66F6FD5A275437F2C60CA] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [442832] [PID.4660] =>.Mozilla Corporation®
[MD5.178F860D7BF66F6FD5A275437F2C60CA] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [442832] [PID.708] =>.Mozilla Corporation®
[MD5.01B855DCAE1CA057877E9D1147A01969] - (.MPC-HC Team - MPC-HC.) -- C:\Program Files (x86)\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe [6082560] [PID.3224] =>.MPC-HC Team
[MD5.178F860D7BF66F6FD5A275437F2C60CA] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [442832] [PID.2796] =>.Mozilla Corporation®
[MD5.10972633D5C179C507EF30FB89D0EEA8] - (.Alexander Roshal - WinRAR archiver.) -- C:\Program Files (x86)\WinRAR\WinRAR.exe [1521880] [PID.3756] =>.win.rar GmbH®
[MD5.56BF36D8E283B8CA868D0CE4E676AF39] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3948600] [PID.5532] =>.Tonec Inc.
[MD5.8B8C86F77C353E1F1584CA4A7192754A] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\moh\Downloads\Programs\ZHPDiag3.exe [3144576] [PID.5772] =>.Nicolas Coolman

---\\ Google Chrome, Start,Search,Extensions (29) - 1s
G0 - GCSP: Preferences [User Data\Default][HomePage] http://cimaclub.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://go.mobtrks.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://go.onclasrv.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://s7.addthis.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.vigilgrup.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://billing.clockworkmod.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://billing.vysor.io
G0 - GCSP: Preferences [User Data\Default][HomePage] http://fonts.googleapis.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://mail.google.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.google-analytics.com =>.Google Inc.
G2 - GCE: Preference [moh][User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] =>.Google Inc. {Slides}
G2 - GCE: Preference [moh][User Data\Default] [aohghmighlieiainnegkcijnfilokake] =>.Google Inc. {Docs}
G2 - GCE: Preference [moh][User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] http://drive.google.com/ =>.Google Inc. {Drive}
G2 - GCE: Preference [moh][User Data\Default] [bbfneagfdkkcpjojiigmahjplnbppkff] =>.profiappsplus {Deadpool}
G2 - GCE: Preference [moh][User Data\Default] [bfbmjmiodbnnpllbbbfblcplfjjepjdn] Stefan vd =>.stefanvd.net
G2 - GCE: Preference [moh][User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] http://www.youtube.com =>.Youtube {Youtube}
G2 - GCE: Preference [moh][User Data\Default] [eeajicmampllnpkmfimkhefbndkfeloo] Group Invite All =>.Jagjeet Singh
G2 - GCE: Preference [moh][User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] =>.Google Inc. {Sheets}
G2 - GCE: Preference [moh][User Data\Default] [gbchcmhmhahfdphkhkmpfmihenigjmpp] =>.Google Inc. {Bureau à distance}
G2 - GCE: Preference [moh][User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] =>.Google Inc. {Docs hors connexion}
G2 - GCE: Preference [moh][User Data\Default] [gidgenkbbabolejbgbpnhbimgjbffefm] Vysor =>.Vysor
G2 - GCE: Preference [moh][User Data\Default] [lgfehfbnofiffladdncogfobimealokp] Ask Web Search =>Toolbar.Ask
G2 - GCE: Preference [moh][User Data\Default] [lneaknkopdijkpnocmklfnjbeapigfbh] http://maps.google.com =>.Google Inc.
G2 - GCE: Preference [moh][User Data\Default] [ngpampappnmepgilojfohadhhmbhlaek] IDM Integration Module =>.IDM Computer Solutions, Inc.
G2 - GCE: Preference [moh][User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] =>.Google Inc. {Wallet}
G2 - GCE: Preference [moh][User Data\Default] [ohahllgiabjaoigichmmfljhkcfikeof]
G2 - GCE: Preference [moh][User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] http://mail.google.com/ =>.Google Inc. {Gmail}
G2 - GCE: Preference [moh][User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\SystemTable =>.SUP.BrowserExtension

---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (11) - 8s
P2 - EXT FILE: (.العربية Language Pack", - Language pack for Firefox for ar".) -- C:\Users\moh\AppData\Roaming\Mozilla\Firefox\Profiles\xcymw95z.default-1526329100750\extensions\langpack-ar@firefox.mozilla.org.xpi
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\browser\features\activity-stream@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\browser\features\aushelper@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\browser\features\followonsearch@mozilla.com.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\browser\features\formautofill@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\browser\features\onboarding@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (...) -- C:\Program Files\Mozilla Firefox\browser\features\{A5FD4672-4D73-4F90-A1C0-2ABD39DB2565}.xpi =>PUP.Optional.YouTubeAdBlock
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_30_0_0_104.dll =>.Adobe Systems Incorporated

---\\ Opera, Plugins,Start,Search (1) - 0s
B2 - EXT: [IDM Integration Module] C:\Users\moh\AppData\Roaming\Opera Software\Opera Stable\Extensions\ngpampappnmepgilojfohadhhmbhlaek =>.IDM Integration Module

---\\ Internet Explorer Extensions, Start, Search (15) - 1s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:NewsFeed =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - مستعرض الإنترنت.) (11.00.9600.19036 (winblue_ltsb_escrow.180524-1802)) -- C:\Windows\System32\ieframe.dll =>.Microsoft Corporation

---\\ INTERNET EXPLORER, trusted site and sensitive site (4) - 0s
~ IE Restricted Site Good: localhost
~ IE Restricted Site Good: webcompanion.com
~ Microsoft Internet Explorer Restricted Site(s) Domains: 2(Good) / 0(Bad)
~ Microsoft Internet Explorer Restricted Site(s) EscDomains: 0(Good) / 0(Bad)

---\\ Internet Explorer, Proxy Management (5) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation

---\\ Hosts file redirection (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (43)

---\\ Browser Helper Object (BHO) (6) - 0s
O2 - BHO: IDM Helper [64Bits] - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll =>.Tonec Inc.®
O2 - BHO: SnagIt Toolbar Loader [64Bits] - {00C6482D-C502-44C8-8409-FCE54AD9C208} . (.TechSmith Corporation - SnagIt Browser Helper Object for Internet E.) -- C:\Program Files (x86)\TechSmith\SnagIt 9\DLLx64\SnagItBHO64.dll =>.TechSmith Corporation®
O2 - BHO: Groove GFS Browser Helper [64Bits] - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O2 - BHO: McAfee WebAdvisor [64Bits] - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} . (.McAfee, Inc. - WebAdvisor.) -- c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll =>.McAfee, Inc.
O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL =>.Microsoft Corporation®
O2 - BHO: YoutubeAdBlock [64Bits] - {C0D38E5A-7CF8-4105-8FE8-31B81443A114} (.Orphan.) =>PUP.Optional.YouTubeAdBlock

---\\ Global shortcuts Startup (160) - 17s
O4 - GS\Desktop [Administrator]: Coollector.lnk . (.Coollector (C) 2017 - Coollector Movie Database.) C:\Program Files (x86)\Coollector\Coollector.exe
O4 - GS\Desktop [Administrator]: Facebook Gameroom.lnk . (.Facebook - FacebookGameroom.) C:\Users\moh\AppData\Local\Facebook\Games\FacebookGameroom.exe =>.Facebook, Inc.®
O4 - GS\Desktop [Administrator]: Format Factory.lnk . (.Free Time Co., Ltd. - FormatFactory.) C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe =>.Free Time Co., Ltd.®
O4 - GS\Desktop [Administrator]: Hein 4.5.2.lnk . (.Hero Hero - Hero Hero.) C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\Hein.exe =>.Hero Hero
O4 - GS\Desktop [Administrator]: Hein Recovery 1.8.lnk . (.Hero Hero - Hero Family.) C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\Hein Recovery.exe =>.Hero Hero
O4 - GS\Desktop [Administrator]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc.
O4 - GS\Desktop [Administrator]: Media Player Classic.lnk . (.MPC-HC Team - MPC-HC.) C:\Program Files (x86)\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe =>.MPC-HC Team
O4 - GS\Desktop [Administrator]: Microsoft PowerPoint 2010.lnk . (...) C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\pptico.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Administrator]: My Drivers.lnk . (.Huntersoft - .) C:\Program Files (x86)\My Drivers\MyDrivers.exe =>.Huntersoft
O4 - GS\Desktop [Administrator]: Uninstall Tool.lnk . (.CrystalIDEA Software - .) C:\Program Files (x86)\Uninstall Tool\UninstallToolExec.exe =>.CrystalIdea Software
O4 - GS\Desktop [Administrator]: Viber.lnk . (.Viber Media S.à r.l. - Viber.) C:\Users\moh\AppData\Local\Viber\Viber.exe {243C767E33053FAAE0F0131C103D7A17}
O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\moh\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Administrator]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\moh\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\Desktop [Administrator]: البحث في كل شيء.lnk . (...) C:\Program Files (x86)\Everything\Everything.exe
O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Administrator]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Administrator]: Opera Browser.lnk . (.Opera Software - .) C:\Program Files (x86)\Opera\launcher.exe =>.Opera Software
O4 - GS\Quicklaunch [Administrator]: QQPlayer.lnk . (...) C:\Program Files (x86)\Tencent\QQPlayer\QQPlayer.exe =>.SUP.Tencent
O4 - GS\Quicklaunch [Administrator]: Samsung Kies 3.lnk . (.Samsung - Kies.) C:\Program Files (x86)\Samsung\Kies3\Kies3.exe =>.Samsung Electronics CO., LTD.®
O4 - GS\Quicklaunch [Administrator]: SnagIt 9.lnk . (.TechSmith Corporation - SnagIt 9.) C:\Program Files (x86)\TechSmith\SnagIt 9\SnagIt32.exe =>.TechSmith Corporation®
O4 - GS\Quicklaunch [Administrator]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\moh\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrator]: Format Factory.lnk . (.Free Time Co., Ltd. - FormatFactory.) C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe =>.Free Time Co., Ltd.®
O4 - GS\TaskBar [Administrator]: EmbratoriaG10.lnk . (...) C:\Users\moh\Desktop\Embratoria_G10\EmbratoriaG10.exe
O4 - GS\TaskBar [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Administrator]: Hein 4.5.2.lnk . (.Hero Hero - Hero Hero.) C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\Hein.exe =>.Hero Hero
O4 - GS\TaskBar [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Administrator]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Administrator]: Opera Browser.lnk . (.Opera Software - .) C:\Program Files (x86)\Opera\launcher.exe =>.Opera Software
O4 - GS\TaskBar [Administrator]: Windows Explorer.lnk . (.Microsoft Corporation - مستكشف Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: Windows Media Player.lnk . (.Microsoft Corporation - ‎‎Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Startup [Administrator]: Facebook Gameroom.lnk . (.Facebook - FacebookGameroom.) C:\Users\moh\AppData\Local\Facebook\Games\FacebookGameroom.exe fbgames://windows_startup/ =>.Facebook, Inc.®
O4 - GS\Programs [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Guest]: Coollector.lnk . (.Coollector (C) 2017 - Coollector Movie Database.) C:\Program Files (x86)\Coollector\Coollector.exe
O4 - GS\Desktop [Guest]: Facebook Gameroom.lnk . (.Facebook - FacebookGameroom.) C:\Users\moh\AppData\Local\Facebook\Games\FacebookGameroom.exe =>.Facebook, Inc.®
O4 - GS\Desktop [Guest]: Format Factory.lnk . (.Free Time Co., Ltd. - FormatFactory.) C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe =>.Free Time Co., Ltd.®
O4 - GS\Desktop [Guest]: Hein 4.5.2.lnk . (.Hero Hero - Hero Hero.) C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\Hein.exe =>.Hero Hero
O4 - GS\Desktop [Guest]: Hein Recovery 1.8.lnk . (.Hero Hero - Hero Family.) C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\Hein Recovery.exe =>.Hero Hero
O4 - GS\Desktop [Guest]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc.
O4 - GS\Desktop [Guest]: Media Player Classic.lnk . (.MPC-HC Team - MPC-HC.) C:\Program Files (x86)\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe =>.MPC-HC Team
O4 - GS\Desktop [Guest]: Microsoft PowerPoint 2010.lnk . (...) C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\pptico.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Guest]: My Drivers.lnk . (.Huntersoft - .) C:\Program Files (x86)\My Drivers\MyDrivers.exe =>.Huntersoft
O4 - GS\Desktop [Guest]: Uninstall Tool.lnk . (.CrystalIDEA Software - .) C:\Program Files (x86)\Uninstall Tool\UninstallToolExec.exe =>.CrystalIdea Software
O4 - GS\Desktop [Guest]: Viber.lnk . (.Viber Media S.à r.l. - Viber.) C:\Users\moh\AppData\Local\Viber\Viber.exe {243C767E33053FAAE0F0131C103D7A17}
O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\moh\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Guest]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\moh\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\Desktop [Guest]: البحث في كل شيء.lnk . (...) C:\Program Files (x86)\Everything\Everything.exe
O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Guest]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Guest]: Opera Browser.lnk . (.Opera Software - .) C:\Program Files (x86)\Opera\launcher.exe =>.Opera Software
O4 - GS\Quicklaunch [Guest]: QQPlayer.lnk . (...) C:\Program Files (x86)\Tencent\QQPlayer\QQPlayer.exe =>.SUP.Tencent
O4 - GS\Quicklaunch [Guest]: Samsung Kies 3.lnk . (.Samsung - Kies.) C:\Program Files (x86)\Samsung\Kies3\Kies3.exe =>.Samsung Electronics CO., LTD.®
O4 - GS\Quicklaunch [Guest]: SnagIt 9.lnk . (.TechSmith Corporation - SnagIt 9.) C:\Program Files (x86)\TechSmith\SnagIt 9\SnagIt32.exe =>.TechSmith Corporation®
O4 - GS\Quicklaunch [Guest]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\moh\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Guest]: Format Factory.lnk . (.Free Time Co., Ltd. - FormatFactory.) C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe =>.Free Time Co., Ltd.®
O4 - GS\TaskBar [Guest]: EmbratoriaG10.lnk . (...) C:\Users\moh\Desktop\Embratoria_G10\EmbratoriaG10.exe
O4 - GS\TaskBar [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Guest]: Hein 4.5.2.lnk . (.Hero Hero - Hero Hero.) C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\Hein.exe =>.Hero Hero
O4 - GS\TaskBar [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Guest]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Guest]: Opera Browser.lnk . (.Opera Software - .) C:\Program Files (x86)\Opera\launcher.exe =>.Opera Software
O4 - GS\TaskBar [Guest]: Windows Explorer.lnk . (.Microsoft Corporation - مستكشف Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: Windows Media Player.lnk . (.Microsoft Corporation - ‎‎Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Startup [Guest]: Facebook Gameroom.lnk . (.Facebook - FacebookGameroom.) C:\Users\moh\AppData\Local\Facebook\Games\FacebookGameroom.exe fbgames://windows_startup/ =>.Facebook, Inc.®
O4 - GS\Programs [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Desktop [moh]: Coollector.lnk . (.Coollector (C) 2017 - Coollector Movie Database.) C:\Program Files (x86)\Coollector\Coollector.exe
O4 - GS\Desktop [moh]: Facebook Gameroom.lnk . (.Facebook - FacebookGameroom.) C:\Users\moh\AppData\Local\Facebook\Games\FacebookGameroom.exe =>.Facebook, Inc.®
O4 - GS\Desktop [moh]: Format Factory.lnk . (.Free Time Co., Ltd. - FormatFactory.) C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe =>.Free Time Co., Ltd.®
O4 - GS\Desktop [moh]: Hein 4.5.2.lnk . (.Hero Hero - Hero Hero.) C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\Hein.exe =>.Hero Hero
O4 - GS\Desktop [moh]: Hein Recovery 1.8.lnk . (.Hero Hero - Hero Family.) C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\Hein Recovery.exe =>.Hero Hero
O4 - GS\Desktop [moh]: Internet Download Manager.lnk . (.Tonec Inc. - Internet Download Manager (IDM).) C:\Program Files (x86)\Internet Download Manager\IDMan.exe =>.Tonec Inc.
O4 - GS\Desktop [moh]: Media Player Classic.lnk . (.MPC-HC Team - MPC-HC.) C:\Program Files (x86)\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe =>.MPC-HC Team
O4 - GS\Desktop [moh]: Microsoft PowerPoint 2010.lnk . (...) C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\pptico.exe =>.Microsoft Corporation®
O4 - GS\Desktop [moh]: My Drivers.lnk . (.Huntersoft - .) C:\Program Files (x86)\My Drivers\MyDrivers.exe =>.Huntersoft
O4 - GS\Desktop [moh]: Uninstall Tool.lnk . (.CrystalIDEA Software - .) C:\Program Files (x86)\Uninstall Tool\UninstallToolExec.exe =>.CrystalIdea Software
O4 - GS\Desktop [moh]: Viber.lnk . (.Viber Media S.à r.l. - Viber.) C:\Users\moh\AppData\Local\Viber\Viber.exe {243C767E33053FAAE0F0131C103D7A17}
O4 - GS\Desktop [moh]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\moh\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [moh]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\moh\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\Desktop [moh]: البحث في كل شيء.lnk . (...) C:\Program Files (x86)\Everything\Everything.exe
O4 - GS\Quicklaunch [moh]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [moh]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [moh]: Opera Browser.lnk . (.Opera Software - .) C:\Program Files (x86)\Opera\launcher.exe =>.Opera Software
O4 - GS\Quicklaunch [moh]: QQPlayer.lnk . (...) C:\Program Files (x86)\Tencent\QQPlayer\QQPlayer.exe =>.SUP.Tencent
O4 - GS\Quicklaunch [moh]: Samsung Kies 3.lnk . (.Samsung - Kies.) C:\Program Files (x86)\Samsung\Kies3\Kies3.exe =>.Samsung Electronics CO., LTD.®
O4 - GS\Quicklaunch [moh]: SnagIt 9.lnk . (.TechSmith Corporation - SnagIt 9.) C:\Program Files (x86)\TechSmith\SnagIt 9\SnagIt32.exe =>.TechSmith Corporation®
O4 - GS\Quicklaunch [moh]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\moh\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [moh]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [moh]: Format Factory.lnk . (.Free Time Co., Ltd. - FormatFactory.) C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe =>.Free Time Co., Ltd.®
O4 - GS\TaskBar [moh]: EmbratoriaG10.lnk . (...) C:\Users\moh\Desktop\Embratoria_G10\EmbratoriaG10.exe
O4 - GS\TaskBar [moh]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [moh]: Hein 4.5.2.lnk . (.Hero Hero - Hero Hero.) C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\Hein.exe =>.Hero Hero
O4 - GS\TaskBar [moh]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [moh]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [moh]: Opera Browser.lnk . (.Opera Software - .) C:\Program Files (x86)\Opera\launcher.exe =>.Opera Software
O4 - GS\TaskBar [moh]: Windows Explorer.lnk . (.Microsoft Corporation - مستكشف Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\TaskBar [moh]: Windows Media Player.lnk . (.Microsoft Corporation - ‎‎Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Startup [moh]: Facebook Gameroom.lnk . (.Facebook - FacebookGameroom.) C:\Users\moh\AppData\Local\Facebook\Games\FacebookGameroom.exe fbgames://windows_startup/ =>.Facebook, Inc.®
O4 - GS\Programs [moh]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\CommonDesktop [Public]: Acrobat Reader DC.lnk . (.Adobe Systems Incorporated - Adobe Acrobat Reader DC.) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe =>.Adobe Systems, Incorporated®
O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Ltd - CCleaner.) C:\Program Files (x86)\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - GS\CommonDesktop [Public]: Firefox.lnk . (.Mozilla Corporation - .) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation
O4 - GS\CommonDesktop [Public]: Focus Magic.lnk . (.Acclaim Software Ltd - Image Restoration Program.) C:\Program Files (x86)\Focus Magic\FocusMagic.exe
O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\CommonDesktop [Public]: Microsoft Word 2010.lnk . (...) C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\wordicon.exe =>.Microsoft Corporation®
O4 - GS\CommonDesktop [Public]: MiniTool Partition Wizard.lnk . (.MiniTool Solution Ltd. - .) C:\Program Files (x86)\MiniTool Partition Wizard 10\partitionwizard.exe =>.MiniTool Solution Ltd.
O4 - GS\CommonDesktop [Public]: Opera Browser.lnk . (.Opera Software - .) C:\Program Files (x86)\Opera\launcher.exe =>.Opera Software
O4 - GS\CommonDesktop [Public]: Popcorn Time.lnk . (...) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe =>.SUP.PopcornTime
O4 - GS\CommonDesktop [Public]: Recuva.lnk . (.Piriform Ltd - .) C:\Program Files (x86)\Recuva\recuva64.exe =>.Piriform Ltd
O4 - GS\CommonDesktop [Public]: Samsung Kies 3.lnk . (.Samsung - Kies.) C:\Program Files (x86)\Samsung\Kies3\Kies3.exe =>.Samsung Electronics CO., LTD.®
O4 - GS\CommonDesktop [Public]: SDFormatter.lnk . (.TRENDY Corporation - Format Tool for SD Card [Normal Area Only].) C:\Program Files (x86)\SDA\SD Formatter\SDFormatter.exe =>.TRENDY Co.®
O4 - GS\CommonDesktop [Public]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe =>.Skype Software Sarl®
O4 - GS\CommonDesktop [Public]: SnagIt 9 Editor.lnk . (.TechSmith Corporation - SnagIt Editor 9.) C:\Program Files (x86)\TechSmith\SnagIt 9\SnagItEditor.exe =>.TechSmith Corporation®
O4 - GS\CommonDesktop [Public]: SnagIt 9.lnk . (.TechSmith Corporation - SnagIt 9.) C:\Program Files (x86)\TechSmith\SnagIt 9\SnagIt32.exe =>.TechSmith Corporation®
O4 - GS\CommonDesktop [Public]: UltraISO.lnk . (.EZB Systems, Inc. - UltraISO Premium.) C:\Program Files (x86)\UltraISO\UltraISO.exe =>.SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD.®
O4 - GS\CommonDesktop [Public]: USB Disk Security.lnk . (.Zbshareware Lab - USB Disk Security.) C:\Program Files (x86)\USB Disk Security\USBGuard.exe =>.Lanzhou Itanium Software Technology Co., Ltd.®
O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - .) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe =>.VideoLAN
O4 - GS\CommonDesktop [Public]: Web Navigation.lnk . (...) C:\Program Files (x86)\USB Disk Security\linkzb.exe =>.Lanzhou Itanium Software Technology Co., Ltd.®
O4 - GS\Programs [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Accessories [Public]: Command Prompt.lnk . (.Microsoft Corporation - Windows Command Processor.) C:\Windows\system32\cmd.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - ‎‎المفكرة.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Explorer.lnk . (.Microsoft Corporation - مستكشف Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe -extoff =>.Microsoft Corporation®
O4 - GS\SystemTools [Public]: Private Character Editor.lnk . (.Microsoft Corporation - ‎‎محرر الأحرف الخاصة.) C:\Windows\system32\eudcedit.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - ‎‎حاسبة Windows.) C:\Windows\system32\calc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - ‎‎تبديل شاشة العرض.) C:\Windows\system32\displayswitch.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - ‎‎ملحق لوحة إدخال العمليات الرياضية.) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - ‎‎‫مركز إعدادات الكمبيوتر المحمول لـ Window.) C:\Windows\system32\mblctr.exe /open =>.Microsoft Corporation
O4 - GS\Accessories [Public]: NetworkProjection.lnk . (.Microsoft Corporation - Connect to a Network Projector.) C:\Windows\system32\NetProj.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - ‎‎الرسام.) C:\Windows\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - ‎‎الاتصال بسطح المكتب البعيد.) C:\Windows\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - ‎‎أداة القطع.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - ‎‎مسجل صوت Windows.) C:\Windows\system32\SoundRecorder.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - ‎‎Sticky Notes.) C:\Windows\system32\StikyNot.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) C:\Windows\System32\mobsync.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Welcome Center.lnk . (.Microsoft Corporation - عملية مضيف Windows (Rundll32)‎.) C:\Windows\system32\rundll32.exe %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut =>..Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - ‎‎تطبيق المفكرة لـ Windows.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - ‎‎مخطط توزيع الأحرف.) C:\Windows\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - ‎‎Microsoft® Disk Defragmenter.) C:\Windows\system32\dfrgui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - ‎‎إدارة تنظيف مساحة القرص لـ Windows.) C:\Windows\system32\cleanmgr.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - ‎‎مراقبة الأداء والموارد.) C:\Windows\system32\perfmon.exe /res =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - ‎‎معلومات النظام.) C:\Windows\system32\msinfo32.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - ‎‎Microsoft® Windows System Restore.) C:\Windows\system32\rstrui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) C:\Windows\system32\taskschd.msc /s =>..Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - ‎‎تطبيق ما بعد عملية الترحيل لأداة النقل ال.) C:\Windows\system32\migwiz\postmig.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - ‎‎تطبيق أداة النقل السريع في Windows.) C:\Windows\system32\migwiz\migwiz.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Acrobat Reader DC.lnk . (.Flexera Software LLC - InstallShield.) C:\Windows\Installer\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\SC_Reader.ico =>.Flexera Software LLC
O4 - GS\ProgramsCommon [Public]: Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\ProgramsCommon [Public]: HowToRemove.lnk . (...) C:\Users\moh\AppData\Local\{E7BBD1E7-C313-BD5F-AE8B-98B78AE3642F}\HowToRemove\HowToRemove.html
O4 - GS\ProgramsCommon [Public]: Media Center.lnk . (.Microsoft Corporation - Windows Media Center.) C:\Windows\ehome\ehshell.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\ProgramsCommon [Public]: Opera Browser.lnk . (.Opera Software - .) C:\Program Files (x86)\Opera\launcher.exe =>.Opera Software
O4 - GS\ProgramsCommon [Public]: Opera.lnk . (.Opera Software - Opera Internet Browser.) C:\Program Files\Opera\launcher.exe =>.Opera Software AS®
O4 - GS\ProgramsCommon [Public]: Sidebar.lnk . (.Microsoft Corporation - ‎‎الأدوات الذكية على سطح المكتب لـ Windows.) C:\Program Files (x86)\Windows Sidebar\sidebar.exe /showgadgets =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Anytime Upgrade.lnk . (.Microsoft Corporation - Windows Anytime Upgrade User Interface.) C:\Windows\system32\WindowsAnytimeUpgradeUI.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows DVD Maker.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\DVD Maker\DVDMaker.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - ‎‎Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: XPS Viewer.lnk . (.Microsoft Corporation - ‎‎عارض XPS.) C:\Windows\system32\xpsrchvw.exe =>.Microsoft Corporation

---\\ Lop.com/Domain Hijackers (2) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{572710F0-6032-40EF-841E-6687AA65BB05}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress

---\\ Extra protocols (22) - 1s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - عارض Microsoft (R) HTML.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - ملحقات OLE32 لـ Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - عنصر تحكم ActiveX للفيديو المتدفق.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - ملحقات OLE32 لـ Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - ملحقات OLE32 لـ Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - ملحقات OLE32 لـ Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - ملحقات OLE32 لـ Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - عارض Microsoft (R) HTML.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - ملحقات OLE32 لـ Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - عارض Microsoft (R) HTML.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - ملحقات OLE32 لـ Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - عارض Microsoft (R) HTML.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: sacore [64Bits] - {5513F07E-936B-4E52-9B00-067394E91CC5} . (.McAfee, Inc. - WebAdvisor.) -- c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll =>.McAfee, Inc.
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - عنصر تحكم ActiveX للفيديو المتدفق.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - عارض Microsoft (R) HTML.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: text/xml [64Bits] - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL =>.Microsoft Corporation®

---\\ AppInit_DLLs Registry value Autorun (1) - 0s
O20 - Winlogon : UserInit . (.Microsoft Corporation - ‎‎تطبيق تسجيل دخول Userinit.) - C:\Windows\system32\userinit.exe =>.Microsoft Corporation

---\\ ASIC (ActiveSetup Installed Components) (10) - 1s
O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - خادم تسجيل (C)‏Microsoft.) -- C:\Windows\System32\regsvr32.exe =>.Microsoft Corporation
O40 - ASIC: Internet Explorer [64Bits] - {2D46B6DC-2207-486B-B523-A557E6D54B47} . (.Microsoft Corporation - ‎‎الأداة المساعدة للتهيئة لكل مستخدم لـ IE.) -- C:\Windows\system32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - ‎‎بريد Windows.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Enable TLS1.1 and 1.2 [64Bits] - {66C64F22-FC60-4E6C-A6B5-F0D580E680CE} . (.Microsoft Corporation - ‎‎الأداة المساعدة للتهيئة لكل مستخدم لـ IE.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - ‎‎الأداة المساعدة لإعداد Microsoft Windows.) -- C:\Windows\System32\unregmp2.exe =>.Microsoft Corporation
O40 - ASIC: Disable SSL3 [64Bits] - {7D715857-A67C-4C2F-A929-038448584D63} . (.Microsoft Corporation - ‎‎الأداة المساعدة للتهيئة لكل مستخدم لـ IE.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - ‎‎الأداة المساعدة للتهيئة لكل مستخدم لـ IE.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll =>.Microsoft Corporation®
O40 - ASIC: Google Chrome [64Bits] - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (.Google Inc. - Google Chrome Installer.) -- C:\Program Files (x86)\Google\Chrome\Application\67.0.3396.87\Installer\chrmstp.exe =>.Google Inc®

---\\ Software installed (241) - 27s
O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU][64Bits] -- uTorrent =>.BitTorrent Inc®
O42 - Logiciel: Adobe Acrobat Reader DC - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1033-7B44-AC0F074E4100} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Flash Player 30 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Flash Player 30 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Flash Player 30 PPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player PPAPI =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-0804-1033-1959-001824265200} =>.Adobe Systems Incorporated
O42 - Logiciel: AMD Accelerated Video Transcoding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {003B37AE-21F5-5BC5-F5EB-CD60A8928696} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: AMD Catalyst Install Manager - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: AMD Drag and Drop Transcoding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {35D00343-3BFA-46A1-C6DD-FFD770501E0B} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: Catalyst Control Center - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {6E0D26C1-4265-1D02-4D19-D0A8F6A463F8} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: Catalyst Control Center - Branding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {E2F0AF23-FE2F-4222-9A43-55E63CC41EF1} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: Catalyst Control Center Graphics Previews Common - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {E649AC39-69C0-C6FE-0A54-4752DB5D1FD2} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: Catalyst Control Center InstallProxy - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {5A883D2B-D279-0D01-6E62-B810AFD8CC62} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: Catalyst Control Center Localization All - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {E21A8F3C-1ACB-46B1-CE72-E9CF09549DED} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Chinese Standard - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {9809124C-0C4C-2367-7889-1E16D8EF1AAF} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Chinese Traditional - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {C1E2D27F-B363-588E-8859-9EF7F4EBF418} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Czech - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {E2F52AC2-B925-C18F-E1AE-42FBD46ECAC7} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Danish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {7DD62206-7B6C-E32E-BD11-B49B3B089D16} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Dutch - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {13464292-6666-B2DB-1B0C-A3FE14DAD1F9} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help English - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {E06F7C95-4D68-63D9-2231-AA5F8E186FCB} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Finnish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {E9463114-898C-7C2A-2C47-E9ABC63F5D43} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help French - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {338CD56F-1CDC-CF32-33F6-DED2DF92284E} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help German - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {DA675EE2-4C04-9699-0EE2-7EF9FE7AB870} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Greek - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {A6E1EE9D-01DD-82FD-BDBC-193BCEF9FD5C} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Hungarian - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {46458556-5C46-79A9-A6FF-81DF1F8B2729} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Italian - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {FF10AC4D-3349-99DA-3E58-5197CEA1D833} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Japanese - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {AB13F192-49FC-A065-F15C-746B10CC43C8} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Korean - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {67A4760F-9804-CCF6-C319-27840ED77924} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Norwegian - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {519D68B8-A768-4CDC-E4C9-B115D49CED93} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Polish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {51D383BC-D988-8C1E-FAA1-BC5260A32A87} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Portuguese - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {9739158D-EDED-D628-9865-1460B5A7FAE3} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Russian - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {AE548812-D611-608D-61C6-7E40F28573A2} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Spanish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {BC63AEF9-1367-9F7C-5926-52E56450EDCD} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Swedish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {D76AC809-CCC1-6198-4970-A63FA5CF7DCB} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Thai - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {6BE5E4A9-D88B-532D-26E6-883C32BF098A} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCC Help Turkish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {FFEC93FF-C162-C0C3-B5E7-01214B0E5F2D} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: ccc-utility64 - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {653B9326-BD45-53BE-681A-A49CAAEE8A3C} =>.Advanced Micro Devices, Inc.
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>.Piriform Ltd®
O42 - Logiciel: CloudNet - (.EpicNet Inc..) [HKCU][64Bits] -- CloudNet =>Adware.MSIL
O42 - Logiciel: Coollector - (..) [HKLM][64Bits] -- Coollector
O42 - Logiciel: Definition Update for Microsoft Office 2010 (KB3115475) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{C6943CC4-79E1-4B29-BFF7-8C4049C7DF61} =>.Microsoft Corporation®
O42 - Logiciel: DriverDoc - (.Solvusoft Corporation.) [HKLM][64Bits] -- {4D0A0750-B034-4DF8-97DE-26F1212AC2FF} =>.SUP.Solvusoft
O42 - Logiciel: DriverDoc - (.Solvusoft Corporation.) [HKLM][64Bits] -- DriverDoc =>.SUP.Solvusoft
O42 - Logiciel: DriverPack Notifier - (.DriverPack Solution.) [HKLM][64Bits] -- DriverPack Notifier =>.DriverPack Solution
O42 - Logiciel: Everything 1.4.1.877 (x64) - (.David Carpenter.) [HKLM][64Bits] -- Everything =>.David Carpenter
O42 - Logiciel: Facebook Gameroom 1.20.6599.20957 - (.Facebook.) [HKLM][64Bits] -- {5B20BC8B-3651-4A73-9571-61AF4C6965C8} =>.Facebook
O42 - Logiciel: Focus Magic 4.02b - (.Acclaim Software Ltd.) [HKLM][64Bits] -- Focus Magic_is1
O42 - Logiciel: FormatFactory 4.3.0.0 - (.Free Time.) [HKLM][64Bits] -- FormatFactory =>.Free Time
O42 - Logiciel: Google Chrome - (.Google Inc‎.‎.) [HKLM][64Bits] -- Google Chrome =>.Google Inc®
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} =>.Intel Corporation - Software and Firmware Products®
O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM][64Bits] -- Internet Download Manager =>.Tonec Inc.®
O42 - Logiciel: Internet Download Manager Registration 6.19 Build 9 - (.Softwares Registrations.) [HKLM][64Bits] -- Internet Download Manager Registration 6.19 Build 9 =>.Tonec Inc.®
O42 - Logiciel: K-Lite Mega Codec Pack 10.5.5 - (.KLite Inc.) [HKLM][64Bits] -- KLiteCodecPack_is1 =>.KLite Inc
O42 - Logiciel: McAfee WebAdvisor - (.McAfee, Inc..) [HKLM][64Bits] -- {35ED3F83-4BDC-4c44-8EC6-6A8301C7413A} =>.McAfee, Inc.
O42 - Logiciel: Microsoft .NET Framework 4.7.1 - (.Microsoft Corporation.) [HKLM][64Bits] -- {92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033 =>.Microsoft Corporation®
O42 - Logiciel: Microsoft .NET Framework 4.7.1 - (.Microsoft Corporation.) [HKLM][64Bits] -- {E0C7523C-686B-3EE6-8FB1-CB4339E30EDD} =>.Microsoft Corporation
O42 - Logiciel: Microsoft .NET Framework 4.7.1 (ARA) - (.Microsoft Corporation.) [HKLM][64Bits] -- {784887CA-0B0A-392E-9500-7860E0324DA9} =>.Microsoft Corporation
O42 - Logiciel: Microsoft .NET Framework 4.7.1 (العربية) - (.Microsoft Corporation.) [HKLM][64Bits] -- {92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1025 =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Office Access MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-0015-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Excel MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-0016-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Groove MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-00BA-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office InfoPath MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-0044-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Office 64-bit Components 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-002A-0000-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office OneNote MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-00A1-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Outlook MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-001A-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office PowerPoint MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-0018-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Professional Plus 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Professional Plus 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- Office14.PROPLUS =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Office Proof (Arabic) 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-001F-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proof (English) 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-001F-0409-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proof (French) 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-001F-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proofing (Arabic) 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-002C-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Publisher MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-0019-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Shared 64-bit MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-002A-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Shared MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-006E-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Word MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90140000-001B-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 - (.Microsoft Corporation.) [HKLM][64Bits] -- {1D8E6291-B0D5-35EC-8441-6616F567A0F7} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 - (.Microsoft Corporation.) [HKLM][64Bits] -- {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 - (.Microsoft Corporation.) [HKLM][64Bits] -- {577ff5ba-39aa-4d8c-a3a9-f95012763438} =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40660 - (.Microsoft Corporation.) [HKLM][64Bits] -- {7DAD0258-515C-3DD4-8964-BD714199E0F7} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40660 - (.Microsoft Corporation.) [HKLM][64Bits] -- {E30D8B21-D82D-3211-82CC-0F0A5D1495E8} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 - (.Microsoft Corporation.) [HKLM][64Bits] -- {e2803110-78b3-4664-a479-3611a381656a} =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24215 - (.Microsoft Corporation.) [HKLM][64Bits] -- {69BCE4AC-9572-3271-A2FB-9423BDA36A43} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24215 - (.Microsoft Corporation.) [HKLM][64Bits] -- {BBF2AC74-720C-3CB3-8291-5E34039232FA} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual Studio 2010 Tools for Office Runtime (x64) - (.Microsoft Corporation.) [HKLM][64Bits] -- {9495AEB4-AB97-39DE-8C42-806EEF75ECA7} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual Studio 2010 Tools for Office Runtime (x64) - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Visual Studio 2010 Tools for Office Runtime (x64) =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - - (.Microsoft Corporation.) [HKLM][64Bits] -- {0C1C05E9-8109-36AE-8BCE-F5A9C16C2883} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual Studio 2010 Tools لحزمة اللغة لـ Office Runtime‏ (x64)‏ - - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - ARA =>.Microsoft Corporation®
O42 - Logiciel: MiniTool Partition Wizard Free 10.2.2 - (.MiniTool Solution Ltd..) [HKLM][64Bits] -- {05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1 =>.MiniTool Solution Ltd®
O42 - Logiciel: Mozilla Firefox 60.0.2 (x64 ar) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 60.0.2 (x64 ar) =>.Mozilla Corporation®
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService =>.Mozilla
O42 - Logiciel: My Drivers 5.1 - (.Huntersoft.) [HKLM][64Bits] -- My Drivers_is1 =>.Huntersoft
O42 - Logiciel: Notepad++ - (.Notepad++ Team.) [HKLM][64Bits] -- Notepad++ =>.Notepad++ Team
O42 - Logiciel: One System Care - (.One System Care.) [HKLM][64Bits] -- OneSystemCare_is1 =>PUP.Optional.OneSystemCare
O42 - Logiciel: Opera Stable 42.0.2393.137 - (.Opera Software.) [HKLM][64Bits] -- Opera 42.0.2393.137 =>.Opera Software AS®
O42 - Logiciel: Opera Stable 51.0.2830.55 - (.Opera Software.) [HKLM][64Bits] -- Opera 51.0.2830.55 =>.Opera Software AS®
O42 - Logiciel: Opera Stable 53.0.2907.99 - (.Opera Software.) [HKLM][64Bits] -- Opera 53.0.2907.99 =>.Opera Software AS®
O42 - Logiciel: Oracle VM VirtualBox 5.2.6 - (.Oracle Corporation.) [HKLM][64Bits] -- {E4157798-7F79-4E27-84A0-A6BF96607F47} =>.Oracle Corporation
O42 - Logiciel: PlayReady PC Runtime amd64 - (.Microsoft Corporation.) [HKLM][64Bits] -- {BCA9334F-B6C9-4F65-9A73-AC5A329A4D04} =>.Microsoft Corporation
O42 - Logiciel: Popcorn Time - (.Popcorn Time.) [HKLM][64Bits] -- Popcorn Time_is1 =>.SUP.PopcornTime
O42 - Logiciel: QQ??3.7 - (.????(??)????.) [HKCU][64Bits] -- QQPlayer
O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} =>.Realtek Semiconductor Corp.®
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp.®
O42 - Logiciel: Recuva - (.Piriform.) [HKLM][64Bits] -- Recuva =>.Piriform Ltd®
O42 - Logiciel: RevServicesX - (.SystemaRev.) [HKLM][64Bits] -- {4A0D29CD-7A99-4F5F-B81B-115A5BB25EC4} =>Trojan.Agent
O42 - Logiciel: Samsung Kies3 - (.Samsung Electronics Co., Ltd..) [HKLM][64Bits] -- {88547073-C566-4895-9005-EBE98EA3F7C7} =>.Samsung Electronics Co., Ltd.
O42 - Logiciel: Samsung Kies3 - (.Samsung Electronics Co., Ltd..) [HKLM][64Bits] -- InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7} =>.Samsung Electronics Co., Ltd.
O42 - Logiciel: SDFormatter - (.SD Association.) [HKLM][64Bits] -- {179324FF-7B16-4BA8-9836-055CAAEE4F08} =>.SD Association
O42 - Logiciel: Security Update for Microsoft Access 2010 (KB3114416) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{2E827501-7656-4E2D-9721-4D826A7E3BE1} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Excel 2010 (KB4022209) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{1E401549-7949-450F-A905-F55D0E556F08} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft InfoPath 2010 (KB3114414) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B3F75577-16EF-48AA-9259-2AF290C973FD} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft InfoPath 2010 (KB3114414) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{B3F75577-16EF-48AA-9259-2AF290C973FD} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2553313) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{473DA037-A808-4DF4-9F37-548928C3CDA1} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2553313) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{473DA037-A808-4DF4-9F37-548928C3CDA1} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2850016) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{7AC3F78E-ECA0-45F4-A9CC-3E885DA23662} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2880971) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{5EE42B42-1159-435C-898A-2A3298453B20} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2881029) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{433890E5-7858-4D14-8FD3-CCD28015472F} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2956063) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{0567725C-77BA-47C1-BE23-FFC218C8F953} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2956076) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-006E-0401-0000-0000000FF1CE}_Office14.PROPLUS_{3482A8CE-9BE4-4FE8-BFCA-99075952C7B8} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB3085528) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{9429D223-4B64-4038-B63D-3F239216F6E5} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB3114874) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{185B3518-235A-48F6-929E-35A2703D6133} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB3115197) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B555A082-6EFC-4557-9AA4-6B975B1F4D41} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB3115248) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{EB272A58-A562-4497-8ADB-8FEDFEF7D61C} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB3118389) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{350F12B5-B76D-4723-8D04-6BE4F483BF5A} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB3191908) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{D196C74E-1419-4DC9-981F-45B6A6504D69} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB3203468) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001F-0401-0000-0000000FF1CE}_Office14.PROPLUS_{F63A5E34-3E66-4E59-8314-1CAA9D7B12C6} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB3203468) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{548F42CA-61CC-4A49-9963-50124AC7B81D} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB3203468) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{C1954E2B-1672-4E5C-B564-F8CB2D08345B} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB3213626) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-006E-0401-0000-0000000FF1CE}_Office14.PROPLUS_{0ADF396A-B2DE-4908-8237-F6D783383CB2} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB3213631) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{5553566A-EC2B-4B4C-9576-8A46B0629BE0} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB4011274) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{12CCDD07-3E70-48C5-8BD1-A75395DF7283} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB4011274) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-006E-0401-0000-0000000FF1CE}_Office14.PROPLUS_{12CCDD07-3E70-48C5-8BD1-A75395DF7283} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB4011275) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{E00B9391-2729-4F55-BF33-EE79229E6392} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB4011610) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-006E-0401-0000-0000000FF1CE}_Office14.PROPLUS_{A0F718C3-2599-4420-BD1F-18AFB72E2E79} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB4022137) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{452E3CF4-2A10-4958-93AA-2616F6978E91} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB4022199) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{7836E989-C7F3-4AAC-9E56-AD32BE4EF6D8} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft OneNote 2010 (KB3114885) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{67E31350-8E55-4143-9F7A-4E703B49FD45} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft OneNote 2010 (KB3114885) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{67E31350-8E55-4143-9F7A-4E703B49FD45} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft OneNote 2010 (KB3114885) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-00A1-0401-0000-0000000FF1CE}_Office14.PROPLUS_{455DF650-8C67-4F65-9C84-556A2D90B7DE} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Outlook 2010 (KB4011711) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001A-0401-0000-0000000FF1CE}_Office14.PROPLUS_{7C7AB504-B331-4E4B-A62B-B34ECDE03046} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Outlook 2010 (KB4022205) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{A7F76828-2921-47BE-AF85-72084CCDA50A} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Publisher 2010 (KB4011186) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{9253C6B0-7BC1-4D42-A7A2-B6AFF95FDB4E} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Visio 2010 (KB3114872) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{14044761-B4DB-4690-BA5C-E79CC538C58E} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Visio Viewer 2010 (KB2999465) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{D54D39CD-37D6-42EF-AD2E-2222515782F1} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Word 2010 (KB2965313) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001A-0401-0000-0000000FF1CE}_Office14.PROPLUS_{2DAE6AAC-5584-49A2-BF7A-B556D16C687D} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Word 2010 (KB2965313) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001B-0401-0000-0000000FF1CE}_Office14.PROPLUS_{2DAE6AAC-5584-49A2-BF7A-B556D16C687D} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Microsoft Word 2010 (KB4022141) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{9CD51E71-9A55-4F28-9A76-FE2D340D8D43} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0015-0401-0000-0000000FF1CE}_Office14.PROPLUS_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0016-0401-0000-0000000FF1CE}_Office14.PROPLUS_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0018-0401-0000-0000000FF1CE}_Office14.PROPLUS_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0019-0401-0000-0000000FF1CE}_Office14.PROPLUS_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001A-0401-0000-0000000FF1CE}_Office14.PROPLUS_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001B-0401-0000-0000000FF1CE}_Office14.PROPLUS_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001F-0401-0000-0000000FF1CE}_Office14.PROPLUS_{00694B53-36C7-472D-9CB1-37BAE02F0E78} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{09A9DF49-DA06-4093-A2FD-F339211E39EA} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{ECC1D579-DC17-4B90-929C-B4A0BB35F7B3} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{E4D76E88-C65F-4003-9C71-EC4306679D17} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-002A-0401-1000-0000000FF1CE}_Office14.PROPLUS_{A94EBBF1-30E0-43A6-930B-E6E144631140} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-002C-0401-0000-0000000FF1CE}_Office14.PROPLUS_{ED827D4A-C39C-4B80-8209-3519EFDC7754} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0044-0401-0000-0000000FF1CE}_Office14.PROPLUS_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-006E-0401-0000-0000000FF1CE}_Office14.PROPLUS_{29A7BE00-F052-4298-A37C-0AB095772ABC} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-00A1-0401-0000-0000000FF1CE}_Office14.PROPLUS_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-00BA-0401-0000-0000000FF1CE}_Office14.PROPLUS_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Skype النسخة 8.23 - (.Skype Technologies S.A..) [HKLM][64Bits] -- Skype_is1 =>.Skype Software Sarl®
O42 - Logiciel: SnagIt 9 - (.TechSmith Corporation.) [HKLM][64Bits] -- {2FADA80A-5D89-4CC8-9ED7-445527754A83} =>.TechSmith Corporation
O42 - Logiciel: TechPowerUp GPU-Z - (.TechPowerUp.) [HKLM][64Bits] -- TechPowerUp GPU-Z =>.TechPowerUp
O42 - Logiciel: UC Browser - (.UCWeb Inc..) [HKLM][64Bits] -- UCBrowser =>.SUP.UCBrowser
O42 - Logiciel: UltraISO Premium V9.61 - (.ZBShareware Labs.) [HKLM][64Bits] -- UltraISO_is1 =>.ZBShareware Labs
O42 - Logiciel: Uninstall Tool - (.CrystalIDEA Software, Inc..) [HKLM][64Bits] -- Uninstall Tool_is1 =>.CrystalBit Solutions®
O42 - Logiciel: Universal Adb Driver - (.ClockworkMod.) [HKLM][64Bits] -- {C0E08D8D-6076-4117-B644-2AF34F35B757} =>.ClockworkMod
O42 - Logiciel: Universal Adb Driver - (.ClockworkMod.) [HKLM][64Bits] -- {D9C4202E-6D51-4B06-A8F1-22316E654BCA} =>.ClockworkMod
O42 - Logiciel: Update for Microsoft .NET Framework 4.7.1 (KB4054852) - (.Microsoft Corporation.) [HKLM][64Bits] -- {92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB4054852 =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft .NET Framework 4.7.1 (KB4054981) - (.Microsoft Corporation.) [HKLM][64Bits] -- {92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB4054981 =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft .NET Framework 4.7.1 (KB4074880) - (.Microsoft Corporation.) [HKLM][64Bits] -- {92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB4074880 =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft .NET Framework 4.7.1 (KB4096234) - (.Microsoft Corporation.) [HKLM][64Bits] -- {92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB4096234 =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft .NET Framework 4.7.1 (KB4096418) - (.Microsoft Corporation.) [HKLM][64Bits] -- {92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB4096418 =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Excel 2010 (KB2956084) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0016-0401-0000-0000000FF1CE}_Office14.PROPLUS_{CE1F2B8C-9E3D-4977-ABF0-0258784FE17F} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Excel 2010 (KB2956084) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0018-0401-0000-0000000FF1CE}_Office14.PROPLUS_{CE1F2B8C-9E3D-4977-ABF0-0258784FE17F} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Excel 2010 (KB2956084) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001B-0401-0000-0000000FF1CE}_Office14.PROPLUS_{CE1F2B8C-9E3D-4977-ABF0-0258784FE17F} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Filter Pack 2.0 (KB2999508) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{9DCB10B2-8E20-4678-B85B-DDB48895B885} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Filter Pack 2.0 (KB2999508) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{9DCB10B2-8E20-4678-B85B-DDB48895B885} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553140) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{8BEEA2FC-D416-428A-B52A-A3ED45921151} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553140) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-006E-0401-0000-0000000FF1CE}_Office14.PROPLUS_{8BEEA2FC-D416-428A-B52A-A3ED45921151} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0015-0401-0000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0016-0401-0000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0018-0401-0000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0019-0401-0000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001A-0401-0000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001B-0401-0000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001F-0401-0000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-002A-0401-1000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-002C-0401-0000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0044-0401-0000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-006E-0401-0000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-00A1-0401-0000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-00BA-0401-0000-0000000FF1CE}_Office14.PROPLUS_{7CA28304-D86F-4ACA-97FA-D126E0D02416} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553388) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{AEB4E79E-26B6-42F3-9980-096443C534BE} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2589318) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{091CB6F9-4347-4084-A572-7C320DA7D686} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{287A1E92-9E41-4BC1-8920-B3D0E9220800} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2589386) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{A4F91D60-654C-4892-BFD3-0D41ADA649B6} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{9D69691D-823D-4C3E-9B12-563A3F520366} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2791057) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{43EBBFDD-8FB7-4FCC-9780-EB40277987A2} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{BA610006-2C39-4419-9834-CF61AB24810A} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2881030) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{D6C976E4-E88C-4048-9A6B-39400D2933C7} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2883019) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{D1C4AD0B-CC79-41D2-8D6A-571E7B30658C} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB3054873) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{9C9636BD-37A7-43F7-BB00-5C7606B42D27} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB3054886) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{A786FC51-D7D5-4499-A230-D1EBEA64932C} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB3054886) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A786FC51-D7D5-4499-A230-D1EBEA64932C} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB3055047) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B29C45D3-4B2D-4FC2-B072-81E3528E4EE1} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB3128031) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{E686AD78-72BA-4602-A10E-EA0FD975350F} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Outlook 2010 (KB2760779) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B8BF0BCB-30FA-4BCA-BB01-2243B6295CC8} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Outlook Social Connector 2010 (KB2553308) 32-Bit Editi - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{E7C8C158-9575-4120-AF5E-5CCEF2DD6761} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft PowerPoint 2010 (KB2965234) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{2A4445D6-05E1-49DD-B85B-200DFA24B21F} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft PowerPoint 2010 (KB2965234) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0018-0401-0000-0000000FF1CE}_Office14.PROPLUS_{8FEB9723-BD01-47D2-ABCE-CA9501E5F1B7} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F9F5A080-AF38-4966-9A6B-C43DCA465035} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F9F5A080-AF38-4966-9A6B-C43DCA465035} =>.Microsoft Corporation®
O42 - Logiciel: USB Disk Security - (.Zbshareware Lab.) [HKLM][64Bits] -- USB Disk Security_is1 =>.Zbshareware Lab
O42 - Logiciel: Viber - (.Viber Media Inc..) [HKCU][64Bits] -- {9574df79-44de-4a4a-8146-38d4900e15d0} =>.Viber Media S.à r.l.®
O42 - Logiciel: Viber - (.Viber Media Inc..) [HKLM][64Bits] -- {09674AFF-C692-4D7F-BE2A-85647529D745} =>.Viber Media Inc.
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
O42 - Logiciel: WinRAR 5.50 (32-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver =>.win.rar GmbH®
O42 - Logiciel: YoutubeAdBlock - (.Company Inc..) [HKLM][64Bits] -- E3605470-291B-44EB-8648-745EE356599A =>PUP.Optional.YouTubeAdBlock
O42 - Logiciel: حزمة برامج تشغيل Windows - Condor (gnusbnet) Net (11/11/2013 1.2.0.0) - (.Condor.) [HKLM][64Bits] -- 350179D4FEEF8D83146365E4FD7427A21F5D955A =>.Microsoft Windows®
O42 - Logiciel: حزمة برامج تشغيل Windows - Condor Communication Equipment Co.,Ltd. (gnusbse - (.Condor Communication Equipment Co.,Ltd..) [HKLM][64Bits] -- 760ECD7B4391C69CC34B300D57CAAE1D7BF4D16B =>.Microsoft Windows®
O42 - Logiciel: حزمة برامج تشغيل Windows - Condor Communication Equipment Co.,Ltd. (gnusbse - (.Condor Communication Equipment Co.,Ltd..) [HKLM][64Bits] -- FD4B3DDA263F0DD0154678E963EE8341AB29EAFE =>.Microsoft Windows®
O42 - Logiciel: حزمة برامج تشغيل Windows - Condor Corporation Net (11/11/2013 1.2.0.0) - (.Condor Corporation.) [HKLM][64Bits] -- E304C591E3B27BA4FEDE756A7033259C81448FE5 =>.Microsoft Windows®
O42 - Logiciel: حزمة برامج تشغيل Windows - MediaTek Inc. (usbser) Ports (01/05/2012 2.0000 - (.MediaTek Inc..) [HKLM][64Bits] -- 49D9ABA9270C5BDFD7AE1BEB607D36B26BB90235 =>.Microsoft Windows®
O42 - Logiciel: حزمة برامج تشغيل Windows - MediaTek Inc. (usbser) Ports (12/24/2011 2.0000 - (.MediaTek Inc..) [HKLM][64Bits] -- D0E6296D177F42BB31C0200E49412003DB6C4633 =>.Microsoft Windows®
O42 - Logiciel: حزمة برامج تشغيل Windows - Microsoft (WUDFRd) WPD (11/11/2013 1.2.0.0) - (.Microsoft.) [HKLM][64Bits] -- 0DB207BF709605C62C08D44DD3A953D00A924560 =>.Microsoft Windows®
O42 - Logiciel: حزمة برامج تشغيل Windows - SPA Condor Electronics (WinUSB) AndroidUsbDevice - (.SPA Condor Electronics.) [HKLM][64Bits] -- EA52A0024D67167EA2BC865080C775727661BB60 =>.Microsoft Windows®

---\\ HKCU & HKLM Software Keys (294) - 27s
HKU\.DEFAULT\Software\ByteFence =>.SUP.ByteFence
HKU\S-1-5-18\Software\ByteFence =>.SUP.ByteFence
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\Software\BSD =>.SUP.DriverUpdatePlus
HKCU\Software\Lavasoft\Web Companion =>PUP.Optional.LavasoftWebCompanion
HKCU\Software\UCBrowserPID =>.SUP.UCBrowser
HKCU\Software\csastats =>Adware.InstallCore
HKCU\Software\undefined =>.SUP.Downloader
HKCU\Software\ProductSetup =>Adware.InstallCore
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com =>PUP.Optional.LavasoftWebCompanion
HKLM\SOFTWARE\Wow6432Node\Lavasoft\Web Companion =>PUP.Optional.LavasoftWebCompanion
HKLM\SOFTWARE\Wow6432Node\UCBrowserPID =>.SUP.UCBrowser
HKLM\SOFTWARE\Lavasoft\Web Companion =>PUP.Optional.LavasoftWebCompanion
HKLM\SOFTWARE\UCBrowserPID =>.SUP.UCBrowser
HKLM\System\CurrentControlSet\Services\EventLog\Reason\ReasonByteFence =>.SUP.ByteFence
HKLM\SOFTWARE\Acclaim Software Ltd =>.Acclaim Software Ltd
HKLM\SOFTWARE\Adobe =>.Adobe
HKLM\SOFTWARE\AMD =>.AMD
HKLM\SOFTWARE\ATI =>.ATI
HKLM\SOFTWARE\ATI Technologies =>.ATI Technologies
HKLM\SOFTWARE\AVAST Software =>.AVAST Software
HKLM\SOFTWARE\AVG =>.AVG Software
HKLM\SOFTWARE\BSD =>.Berkeley
HKLM\SOFTWARE\ByteFence =>.SUP.ByteFence
HKLM\SOFTWARE\Caphyon =>.Caphyon
HKLM\SOFTWARE\Coollector
HKLM\SOFTWARE\CyberLink =>.CyberLink Corporation
HKLM\SOFTWARE\drpsu =>.Driver PackSolution
HKLM\SOFTWARE\EasyBoot Systems =>.EasyBoot Systems
HKLM\SOFTWARE\GNU =>.GNU
HKLM\SOFTWARE\Google =>.Google
HKLM\SOFTWARE\GRETECH =>.Gretech
HKLM\SOFTWARE\Intel =>.Intel
HKLM\SOFTWARE\Internet Download Manager =>.Tonec Inc
HKLM\SOFTWARE\InterVideo =>.InterVideo
HKLM\SOFTWARE\JavaSoft =>.JavaSoft
HKLM\SOFTWARE\JreMetrics =>.JreMetrics
HKLM\SOFTWARE\Khronos =>.Khronos
HKLM\SOFTWARE\KLCodecPack =>.KLite Inc
HKLM\SOFTWARE\LAV =>.LAV Inc
HKLM\SOFTWARE\Lavasoft =>.Lavasoft
HKLM\SOFTWARE\Macromedia =>.Macromedia
HKLM\SOFTWARE\McAfee =>.McAfee Inc.
HKLM\SOFTWARE\MimarSinan =>.Mimar Sinan
HKLM\SOFTWARE\Mozilla =>.Mozilla
HKLM\SOFTWARE\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\Notepad++ =>.Don Ho
HKLM\SOFTWARE\Nuance =>.Nuance
HKLM\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\Opera Software =>.Opera Software
HKLM\SOFTWARE\Oracle =>.Oracle
HKLM\SOFTWARE\Piriform =>.Piriform
HKLM\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Samsung =>.Samsung Electronics
HKLM\SOFTWARE\SiteAdvisor =>.McAfee Inc.
HKLM\SOFTWARE\Skype =>.Skype
HKLM\SOFTWARE\Solvusoft =>.SUP.Solvusoft
HKLM\SOFTWARE\SRS Labs =>.SRS Labs
HKLM\SOFTWARE\TechSmith =>.TechSmith
HKLM\SOFTWARE\Tencent =>.SUP.Tencent
HKLM\SOFTWARE\UCBrowser =>.UCWeb Inc.
HKLM\SOFTWARE\UCBrowserPID =>.UCWeb Inc.
HKLM\SOFTWARE\Volatile =>.Microsoft Corporation
HKLM\SOFTWARE\WinRAR =>.WinRAR
HKLM\SOFTWARE\zbshareware =>.Zbshareware
HKLM\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\Acclaim Software Ltd =>.Acclaim Software Ltd
HKLM\SOFTWARE\WOW6432Node\Adobe =>.Adobe
HKLM\SOFTWARE\WOW6432Node\AMD =>.AMD
HKLM\SOFTWARE\WOW6432Node\ATI =>.ATI
HKLM\SOFTWARE\WOW6432Node\ATI Technologies =>.ATI Technologies
HKLM\SOFTWARE\WOW6432Node\AVAST Software =>.AVAST Software
HKLM\SOFTWARE\WOW6432Node\AVG =>.AVG Software
HKLM\SOFTWARE\WOW6432Node\BSD =>.Berkeley
HKLM\SOFTWARE\WOW6432Node\ByteFence =>.SUP.ByteFence
HKLM\SOFTWARE\WOW6432Node\Caphyon =>.Caphyon
HKLM\SOFTWARE\WOW6432Node\Coollector
HKLM\SOFTWARE\WOW6432Node\CyberLink =>.CyberLink Corporation
HKLM\SOFTWARE\WOW6432Node\drpsu =>.Driver PackSolution
HKLM\SOFTWARE\WOW6432Node\EasyBoot Systems =>.EasyBoot Systems
HKLM\SOFTWARE\WOW6432Node\GNU =>.GNU
HKLM\SOFTWARE\WOW6432Node\Google =>.Google
HKLM\SOFTWARE\WOW6432Node\GRETECH =>.Gretech
HKLM\SOFTWARE\WOW6432Node\Intel =>.Intel
HKLM\SOFTWARE\WOW6432Node\Internet Download Manager =>.Tonec Inc
HKLM\SOFTWARE\WOW6432Node\InterVideo =>.InterVideo
HKLM\SOFTWARE\WOW6432Node\JavaSoft =>.JavaSoft
HKLM\SOFTWARE\WOW6432Node\JreMetrics =>.JreMetrics
HKLM\SOFTWARE\WOW6432Node\Khronos =>.Khronos
HKLM\SOFTWARE\WOW6432Node\KLCodecPack =>.KLite Inc
HKLM\SOFTWARE\WOW6432Node\LAV =>.LAV Inc
HKLM\SOFTWARE\WOW6432Node\Lavasoft =>.Lavasoft
HKLM\SOFTWARE\WOW6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\WOW6432Node\McAfee =>.McAfee Inc.
HKLM\SOFTWARE\WOW6432Node\MimarSinan =>.Mimar Sinan
HKLM\SOFTWARE\WOW6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\WOW6432Node\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\WOW6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\WOW6432Node\Notepad++ =>.Don Ho
HKLM\SOFTWARE\WOW6432Node\Nuance =>.Nuance
HKLM\SOFTWARE\WOW6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\WOW6432Node\Opera Software =>.Opera Software
HKLM\SOFTWARE\WOW6432Node\Oracle =>.Oracle
HKLM\SOFTWARE\WOW6432Node\Piriform =>.Piriform
HKLM\SOFTWARE\WOW6432Node\Realtek =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\WOW6432Node\Samsung =>.Samsung Electronics
HKLM\SOFTWARE\WOW6432Node\SiteAdvisor =>.McAfee Inc.
HKLM\SOFTWARE\WOW6432Node\Skype =>.Skype
HKLM\SOFTWARE\WOW6432Node\Solvusoft =>.SUP.Solvusoft
HKLM\SOFTWARE\WOW6432Node\SRS Labs =>.SRS Labs
HKLM\SOFTWARE\WOW6432Node\TechSmith =>.TechSmith
HKLM\SOFTWARE\WOW6432Node\Tencent =>.SUP.Tencent
HKLM\SOFTWARE\WOW6432Node\UCBrowser =>.UCWeb Inc.
HKLM\SOFTWARE\WOW6432Node\UCBrowserPID =>.UCWeb Inc.
HKLM\SOFTWARE\WOW6432Node\Volatile =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\WinRAR =>.WinRAR
HKLM\SOFTWARE\WOW6432Node\zbshareware =>.Zbshareware
HKLM\SOFTWARE\WOW6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\Acclaim Software Ltd =>.Acclaim Software Ltd
HKCU\SOFTWARE\Active@ File Preview
HKCU\SOFTWARE\Adobe =>.Adobe
HKCU\SOFTWARE\AMD =>.AMD
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\ATI =>.ATI
HKCU\SOFTWARE\AVG =>.AVG Software
HKCU\SOFTWARE\BitTorrent =>.BitTorrent (P2P)
HKCU\SOFTWARE\Browser Cleanup =>.Avast Software s.r.o
HKCU\SOFTWARE\BSD =>.Berkeley
HKCU\SOFTWARE\ByteFence =>.SUP.ByteFence
HKCU\SOFTWARE\CatalinaGroup =>.SUP.CatalinaMarketing
HKCU\SOFTWARE\Chromium =>.Chromium
HKCU\SOFTWARE\ClockworkMod =>.ClockworkMod
HKCU\SOFTWARE\Coollector
HKCU\SOFTWARE\CoreAAC =>.Core Codec
HKCU\SOFTWARE\Crystal Reality =>.Games Software
HKCU\SOFTWARE\CrystalIdea Software =>.CrystalIdea Software
HKCU\SOFTWARE\CyberLink =>.CyberLink Corporation
HKCU\SOFTWARE\DMGR1.25
HKCU\SOFTWARE\DownloadManager =>.DownloadManager
HKCU\SOFTWARE\DRP
HKCU\SOFTWARE\drpsu =>.Driver PackSolution
HKCU\SOFTWARE\DSP-worx =>.Microsoft Corporation
HKCU\SOFTWARE\DuoDianApp =>.DuoDianApp
HKCU\SOFTWARE\EasyBoot Systems =>.EasyBoot Systems
HKCU\SOFTWARE\EpicNet Inc. =>Adware.MSIL
HKCU\SOFTWARE\Facebook =>.Facebook
HKCU\SOFTWARE\FreeTime =>.FreeTime Inc
HKCU\SOFTWARE\Gabest =>.Gabest
HKCU\SOFTWARE\GNU =>.GNU
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\GRETECH =>.Gretech
HKCU\SOFTWARE\Icaros =>.Icaros
HKCU\SOFTWARE\IM Providers =>.IM Providers
HKCU\SOFTWARE\Intel =>.Intel
HKCU\SOFTWARE\KGB Archiver
HKCU\SOFTWARE\KMPlayer =>.KMPlayer
HKCU\SOFTWARE\LAV =>.LAV Inc
HKCU\SOFTWARE\Lavasoft =>.Lavasoft
HKCU\SOFTWARE\Macromedia =>.Macromedia
HKCU\SOFTWARE\madshi =>.madshi.net
HKCU\SOFTWARE\MediaInfo =>.Jérôme Martinez
HKCU\SOFTWARE\Michael Herf =>.Michael Herf
HKCU\SOFTWARE\MiniTool Solution Ltd. =>.MiniTool Solution Ltd.
HKCU\SOFTWARE\Mozilla =>.Mozilla
HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKCU\SOFTWARE\MPC-HC =>.MPC-HC Team
HKCU\SOFTWARE\MTK =>.MTK
HKCU\SOFTWARE\Netscape =>.Netscape
HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKCU\SOFTWARE\One System Care =>PUP.Optional.OneSystemCare
HKCU\SOFTWARE\Opera Software =>.Opera Software
HKCU\SOFTWARE\Oracle =>.Oracle
HKCU\SOFTWARE\Piriform =>.Piriform
HKCU\SOFTWARE\Popcorn Time =>.SUP.PopcornTime
HKCU\SOFTWARE\PopcornTime =>.SUP.PopcornTime
HKCU\SOFTWARE\ProtectedStorage =>.Microsoft Corporation
HKCU\SOFTWARE\QtProject =>.QtProject
HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKCU\SOFTWARE\Samsung =>.Samsung Electronics
HKCU\SOFTWARE\Skype =>.Skype
HKCU\SOFTWARE\skypeapp-35af0675f20e =>.Skype Technologies
HKCU\SOFTWARE\Solvusoft =>.SUP.Solvusoft
HKCU\SOFTWARE\Space Sciences Laboratory, U.C. Berkeley =>.Space Sciences Laboratory, U.C.
HKCU\SOFTWARE\Sysinternals =>.Sysinternals
HKCU\SOFTWARE\System Healer =>.SUP.SystemHealer
HKCU\SOFTWARE\techPowerUp =>.TechPowerUp
HKCU\SOFTWARE\TechSmith =>.TechSmith
HKCU\SOFTWARE\Tencent =>.SUP.Tencent
HKCU\SOFTWARE\Trolltech =>.Trolltech
HKCU\SOFTWARE\UCBrowser =>.UCWeb Inc.
HKCU\SOFTWARE\UCBrowserPID =>.UCWeb Inc.
HKCU\SOFTWARE\USB Disk Security =>.ZBShareware Labs
HKCU\SOFTWARE\Viber =>.Viber
HKCU\SOFTWARE\WidModule
HKCU\SOFTWARE\WindowsUpdater
HKCU\SOFTWARE\WinRAR =>.WinRAR
HKCU\SOFTWARE\WinRAR SFX =>.RarLab
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\Yahoo =>.Yahoo! Inc.
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKCU\SOFTWARE\AppDataLow\Software\JavaSoft =>.JavaSoft
HKU\.DEFAULT\SOFTWARE\ATI =>.ATI
HKU\.DEFAULT\SOFTWARE\Browser Cleanup =>.Avast Software s.r.o
HKU\.DEFAULT\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKU\.DEFAULT\SOFTWARE\Opera Software =>.Opera Software
HKU\.DEFAULT\SOFTWARE\Piriform =>.Piriform
HKU\.DEFAULT\SOFTWARE\TechSmith =>.TechSmith
HKU\.DEFAULT\SOFTWARE\UCBrowser =>.UCWeb Inc.
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Acclaim Software Ltd =>.Acclaim Software Ltd
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Active@ File Preview
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Adobe =>.Adobe
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\AMD =>.AMD
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\ATI =>.ATI
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\AVG =>.AVG Software
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\BitTorrent =>.BitTorrent (P2P)
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Browser Cleanup =>.Avast Software s.r.o
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\BSD =>.Berkeley
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\ByteFence =>.SUP.ByteFence
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\CatalinaGroup =>.SUP.CatalinaMarketing
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Chromium =>.Chromium
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\ClockworkMod =>.ClockworkMod
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Coollector
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\CoreAAC =>.Core Codec
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Crystal Reality =>.Games Software
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\CrystalIdea Software =>.CrystalIdea Software
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\csastats
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\CyberLink =>.CyberLink Corporation
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\DMGR1.25
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\DownloadManager =>.DownloadManager
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\DRP
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\drpsu =>.Driver PackSolution
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\DSP-worx =>.Microsoft Corporation
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\DuoDianApp =>.DuoDianApp
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\EasyBoot Systems =>.EasyBoot Systems
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\EpicNet Inc. =>Adware.MSIL
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Facebook =>.Facebook
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\FreeTime =>.FreeTime Inc
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Gabest =>.Gabest
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\GNU =>.GNU
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Google =>.Google
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\GRETECH =>.Gretech
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Icaros =>.Icaros
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\IM Providers =>.IM Providers
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Intel =>.Intel
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\KGB Archiver
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\KMPlayer =>.KMPlayer
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\LAV =>.LAV Inc
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Lavasoft =>.Lavasoft
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Macromedia =>.Macromedia
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\madshi =>.madshi.net
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\MediaInfo =>.Jérôme Martinez
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Michael Herf =>.Michael Herf
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\MiniTool Solution Ltd. =>.MiniTool Solution Ltd.
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Mozilla =>.Mozilla
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\MPC-HC =>.MPC-HC Team
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\MTK =>.MTK
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Netscape =>.Netscape
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\One System Care =>PUP.Optional.OneSystemCare
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Opera Software =>.Opera Software
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Oracle =>.Oracle
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Piriform =>.Piriform
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Popcorn Time =>.SUP.PopcornTime
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\PopcornTime =>.SUP.PopcornTime
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\ProductSetup
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\ProtectedStorage =>.Microsoft Corporation
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\QtProject =>.QtProject
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Samsung =>.Samsung Electronics
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Skype =>.Skype
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\skypeapp-35af0675f20e =>.Skype Technologies
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Solvusoft =>.SUP.Solvusoft
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Space Sciences Laboratory, U.C. Berkeley =>.Space Sciences Laboratory, U.C.
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Sysinternals =>.Sysinternals
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\System Healer =>.SUP.SystemHealer
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\techPowerUp =>.TechPowerUp
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\TechSmith =>.TechSmith
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Tencent =>.SUP.Tencent
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Trolltech =>.Trolltech
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\UCBrowser =>.UCWeb Inc.
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\UCBrowserPID =>.UCWeb Inc.
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\undefined
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\USB Disk Security =>.ZBShareware Labs
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Viber =>.Viber
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\WidModule
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\WindowsUpdater
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\WinRAR =>.WinRAR
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\WinRAR SFX =>.RarLab
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\Yahoo =>.Yahoo! Inc.
HKU\S-1-5-21-3846459619-3345045358-488364244-1000\SOFTWARE\ZHP =>.Nicolas Coolman

---\\ Contents of the Common Files folders (307) - 14s
O43 - CFD: 04/05/2018 - [] D -- C:\Program Files\AMD =>.AMD
O43 - CFD: 04/05/2018 - [] D -- C:\Program Files\ATI =>.Advanced Micro Devices, Inc.®
O43 - CFD: 04/05/2018 - [] D -- C:\Program Files\ATI Technologies =>.ATI Technologies
O43 - CFD: 06/04/2018 - [] D -- C:\Program Files\ByteFence =>.SUP.ByteFence
O43 - CFD: 17/06/2018 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 27/04/2018 - [] D -- C:\Program Files\DIFX =>.Microsoft Corporation
O43 - CFD: 01/01/2018 - [] D -- C:\Program Files\DVD Maker =>.Aone Software
O43 - CFD: 10/06/2018 - [] D -- C:\Program Files\Everything =>.Everything
O43 - CFD: 18/06/2018 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 30/12/2017 - [] D -- C:\Program Files\LSoft Technologies =>.Lsoft technologies
O43 - CFD: 23/02/2018 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 30/12/2017 - [] D -- C:\Program Files\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 31/12/2017 - [] D -- C:\Program Files\MiniTool Partition Wizard 10 =>.MiniTool Solution Ltd
O43 - CFD: 07/06/2018 - [] D -- C:\Program Files\Mozilla Firefox =>.Mozilla
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 04/05/2018 - [] D -- C:\Program Files\My Drivers
O43 - CFD: 10/06/2018 - [0] D -- C:\Program Files\My Program
O43 - CFD: 15/06/2018 - [] D -- C:\Program Files\Opera =>.Opera Software
O43 - CFD: 22/03/2018 - [] D -- C:\Program Files\Oracle =>.Oracle
O43 - CFD: 07/02/2018 - [] D -- C:\Program Files\PlayReady =>.Microsoft Corporation
O43 - CFD: 30/12/2017 - [] D -- C:\Program Files\Realtek =>.Realtek
O43 - CFD: 13/06/2018 - [] D -- C:\Program Files\Recuva =>.Piriform
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 17/06/2018 - [] D -- C:\Program Files\Sawmenger XP
O43 - CFD: 10/06/2018 - [] D -- C:\Program Files\SystemaRev =>Trojan.Agent
O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 15/06/2018 - [] D -- C:\Program Files\Uninstall Tool =>.CrystalBit Solutions®
O43 - CFD: 01/01/2018 - [] D -- C:\Program Files\VideoLAN =>.VideoLan Team
O43 - CFD: 31/12/2017 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 31/12/2017 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 01/01/2018 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 31/12/2017 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 21/11/2010 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 31/12/2017 - [] D -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 28/02/2018 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Systems, Incorporated®
O43 - CFD: 04/05/2018 - [] D -- C:\Program Files (x86)\AMD AVT =>.Advanced Micro Devices Inc
O43 - CFD: 04/05/2018 - [] D -- C:\Program Files (x86)\ATI Technologies =>.ATI Technologies
O43 - CFD: 08/05/2018 - [] D -- C:\Program Files (x86)\CCleaner =>.Piriform Ltd
O43 - CFD: 24/01/2018 - [] D -- C:\Program Files (x86)\ClockworkMod =>.ClockworkMod
O43 - CFD: 19/06/2018 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 05/01/2018 - [] D -- C:\Program Files (x86)\Coollector
O43 - CFD: 04/05/2018 - [] D -- C:\Program Files (x86)\DriverPack Notifier =>.DriverPack Solution
O43 - CFD: 10/06/2018 - [] D -- C:\Program Files (x86)\EgDGbQEiU
O43 - CFD: 06/04/2018 - [] D -- C:\Program Files (x86)\Focus Magic
O43 - CFD: 01/01/2018 - [] D -- C:\Program Files (x86)\FreeTime =>.FreeTime
O43 - CFD: 23/06/2018 - [] D -- C:\Program Files (x86)\Google =>.Google Inc®
O43 - CFD: 01/01/2018 - [] D -- C:\Program Files (x86)\GPU-Z =>.TechPowerUp Ltd®
O43 - CFD: 01/01/2018 - [] D -- C:\Program Files (x86)\GRETECH =>.Gretech
O43 - CFD: 10/06/2018 - [] D -- C:\Program Files (x86)\ijcQGTqqPStU2
O43 - CFD: 04/05/2018 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield
O43 - CFD: 30/12/2017 - [] D -- C:\Program Files (x86)\Intel =>.Intel Corporation
O43 - CFD: 24/06/2018 - [] D -- C:\Program Files (x86)\Internet Download Manager =>.Tonec Inc
O43 - CFD: 18/06/2018 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 10/06/2018 - [] D -- C:\Program Files (x86)\iRmKFyAZyPUn
O43 - CFD: 05/02/2018 - [] D -- C:\Program Files (x86)\K-Lite Codec Pack =>.KLite Inc
O43 - CFD: 10/06/2018 - [] D -- C:\Program Files (x86)\lJFUJMGEHIE
O43 - CFD: 03/06/2018 - [] D -- C:\Program Files (x86)\McAfee =>.McAfee
O43 - CFD: 19/06/2018 - [] D -- C:\Program Files (x86)\Microsoft =>.Microsoft Corporation
O43 - CFD: 23/02/2018 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services =>.Microsoft Corporation
O43 - CFD: 23/02/2018 - [] D -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 30/12/2017 - [] D -- C:\Program Files (x86)\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 23/02/2018 - [] D -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition =>.Microsoft Corporation
O43 - CFD: 23/02/2018 - [] D -- C:\Program Files (x86)\Microsoft Sync Framework =>.Microsoft Corporation
O43 - CFD: 23/02/2018 - [] D -- C:\Program Files (x86)\Microsoft Synchronization Services =>.Microsoft Corporation
O43 - CFD: 23/02/2018 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio 8 =>.Microsoft Corporation
O43 - CFD: 23/02/2018 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 08/06/2018 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service =>.Mozilla
O43 - CFD: 23/02/2018 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 30/01/2018 - [] D -- C:\Program Files (x86)\NirSoft =>.NirSoft
O43 - CFD: 01/01/2018 - [] D -- C:\Program Files (x86)\Notepad++ =>.Don Ho
O43 - CFD: 05/06/2018 - [0] D -- C:\Program Files (x86)\Nox =>.FFmpeg Project
O43 - CFD: 23/06/2018 - [] D -- C:\Program Files (x86)\OneSystemCare =>PUP.Optional.OneSystemCare
O43 - CFD: 10/06/2018 - [] D -- C:\Program Files (x86)\OxoywZINBbQwrioRGrR
O43 - CFD: 15/03/2018 - [] D -- C:\Program Files (x86)\Popcorn Time =>.SUP.PopcornTime
O43 - CFD: 04/05/2018 - [] D -- C:\Program Files (x86)\Realtek =>.Realtek
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 28/02/2018 - [] D -- C:\Program Files (x86)\Samsung =>.Samsung Electronics
O43 - CFD: 30/12/2017 - [] D -- C:\Program Files (x86)\SDA =>.TRENDY Co.®
O43 - CFD: 19/06/2018 - [] RD -- C:\Program Files (x86)\Skype =>.Skype
O43 - CFD: 11/03/2018 - [] D -- C:\Program Files (x86)\Solvusoft =>.SUP.Solvusoft
O43 - CFD: 23/02/2018 - [] D -- C:\Program Files (x86)\TechSmith =>.TechSmith
O43 - CFD: 08/04/2018 - [] D -- C:\Program Files (x86)\UCBrowser =>.TAOBAO (CHINA) SOFTWARE CO.,LTD.®
O43 - CFD: 17/05/2018 - [] D -- C:\Program Files (x86)\UltraISO =>.EZB Systems
O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files (x86)\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 01/03/2018 - [] D -- C:\Program Files (x86)\USB Disk Security =>.FlashPeak Inc
O43 - CFD: 01/01/2018 - [] D -- C:\Program Files (x86)\USB Vibration
O43 - CFD: 10/06/2018 - [] D -- C:\Program Files (x86)\wCCFxMJCsZmzC
O43 - CFD: 31/12/2017 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 31/12/2017 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 01/01/2018 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 31/12/2017 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 31/12/2017 - [] D -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 30/12/2017 - [] D -- C:\Program Files (x86)\WinRAR =>.win.rar GmbH®
O43 - CFD: 31/12/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 30/12/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 04/05/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center =>.Advanced Micro Devices Inc
O43 - CFD: 27/01/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd
O43 - CFD: 05/01/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coollector
O43 - CFD: 06/04/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Focus Magic
O43 - CFD: 21/11/2010 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 26/05/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager =>.Tonec Inc
O43 - CFD: 05/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack =>.KLite Inc
O43 - CFD: 31/12/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft =>.Lavasoft
O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 23/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 30/12/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 31/12/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniTool Partition Wizard 10 =>.MiniTool Solution Ltd
O43 - CFD: 04/05/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My Drivers 5
O43 - CFD: 01/01/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ =>.Don Ho
O43 - CFD: 11/06/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care =>PUP.Optional.OneSystemCare
O43 - CFD: 22/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox =>.Oracle
O43 - CFD: 15/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Popcorn Time =>.SUP.PopcornTime
O43 - CFD: 30/12/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva =>.Piriform
O43 - CFD: 28/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung =>.Samsung Electronics
O43 - CFD: 30/12/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SDFormatter =>.SD Association
O43 - CFD: 23/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint =>.Microsoft Corporation
O43 - CFD: 19/06/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype =>.Skype
O43 - CFD: 04/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SnagIt 9 =>.TechSmith
O43 - CFD: 16/02/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft =>.SUP.Solvusoft
O43 - CFD: 06/04/2018 - [0] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 17/05/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO =>.EZB Systems
O43 - CFD: 15/06/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uninstall Tool
O43 - CFD: 01/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\USB Disk Security =>.FlashPeak Inc
O43 - CFD: 01/01/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team
O43 - CFD: 30/12/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 10/06/2018 - [] D -- C:\ProgramData\23aa6461-67c2-4c67-b567-a488a7e052c4
O43 - CFD: 11/06/2018 - [0] D -- C:\ProgramData\47765288-ac79-4c5b-b2c6-5c276ae6fc9c
O43 - CFD: 10/06/2018 - [] D -- C:\ProgramData\55e0cb0e-c21b-4f2d-ac71-2f3455b1b89f
O43 - CFD: 10/06/2018 - [] D -- C:\ProgramData\93f8d562-c26c-4cd2-b33f-096da5934c09
O43 - CFD: 28/02/2018 - [] D -- C:\ProgramData\Adobe =>.Adobe
O43 - CFD: 04/05/2018 - [] D -- C:\ProgramData\AMD =>.AMD
O43 - CFD: 01/01/2018 - [] D -- C:\ProgramData\APN =>Toolbar.Ask
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 04/05/2018 - [] D -- C:\ProgramData\ATI =>.ATI
O43 - CFD: 20/05/2018 - [] D -- C:\ProgramData\Audyssey Labs =>.Audyssey Labs
O43 - CFD: 23/06/2018 - [] D -- C:\ProgramData\AVG =>.AVG Software
O43 - CFD: 22/03/2018 - [] D -- C:\ProgramData\BOINC =>.Space Sciences Laboratory, U.C.
O43 - CFD: 16/02/2018 - [] D -- C:\ProgramData\BSD =>.Berkeley
O43 - CFD: 22/03/2018 - [] D -- C:\ProgramData\ByteFence =>.SUP.ByteFence
O43 - CFD: 17/06/2018 - [] HD -- C:\ProgramData\Common Files =>.Microsoft Corporation
O43 - CFD: 05/01/2018 - [] D -- C:\ProgramData\DeskShare =>.Deskshare
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 01/01/2018 - [] D -- C:\ProgramData\DivX =>.DivX
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Favorites =>.Microsoft Corporation
O43 - CFD: 17/05/2018 - [0] D -- C:\ProgramData\IDM =>.IDM
O43 - CFD: 04/05/2018 - [0] D -- C:\ProgramData\inf
O43 - CFD: 13/06/2018 - [] D -- C:\ProgramData\Isolated Storage =>.Microsoft Corporation
O43 - CFD: 22/03/2018 - [] D -- C:\ProgramData\McAfee =>.McAfee
O43 - CFD: 23/02/2018 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 18/06/2018 - [] D -- C:\ProgramData\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 05/03/2018 - [] D -- C:\ProgramData\Oracle =>.Oracle
O43 - CFD: 02/06/2018 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 28/02/2018 - [] D -- C:\ProgramData\Samsung =>.Samsung Electronics
O43 - CFD: 19/06/2018 - [] D -- C:\ProgramData\Skype =>.Skype
O43 - CFD: 16/02/2018 - [] D -- C:\ProgramData\Solvusoft =>.SUP.Solvusoft
O43 - CFD: 27/04/2018 - [] D -- C:\ProgramData\SP_FT_Logs
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation
O43 - CFD: 23/02/2018 - [] D -- C:\ProgramData\TechSmith =>.TechSmith
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation
O43 - CFD: 10/06/2018 - [] D -- C:\ProgramData\XjOPTLXDzAynQaVB
O43 - CFD: 06/04/2018 - [] HD -- C:\ProgramData\{0897014C-63E3-47DF-8A5F-4399CC5D61B9}
O43 - CFD: 06/04/2018 - [] D -- C:\ProgramData\{B6AE73CD-3CEC-F90B-BA2A-67492068EC87}
O43 - CFD: 30/12/2017 - [] SHD -- C:\ProgramData\سطح المكتب
O43 - CFD: 30/12/2017 - [] SHD -- C:\ProgramData\قائمة ابدأ
O43 - CFD: 28/02/2018 - [] D -- C:\Program Files (x86)\Common Files\Adobe =>.Adobe
O43 - CFD: 04/05/2018 - [] D -- C:\Program Files (x86)\Common Files\ATI Technologies =>.ATI Technologies
O43 - CFD: 24/02/2018 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER =>.Designer
O43 - CFD: 17/05/2018 - [] D -- C:\Program Files (x86)\Common Files\EZB Systems =>.EZB Systems
O43 - CFD: 22/03/2018 - [] D -- C:\Program Files (x86)\Common Files\McAfee =>.McAfee
O43 - CFD: 10/05/2018 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines =>.Microsoft Corporation
O43 - CFD: 24/02/2018 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 04/03/2018 - [] D -- C:\Program Files (x86)\Common Files\Wise Installation Wizard =>.Seagate
O43 - CFD: 28/02/2018 - [] D -- C:\Users\moh\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 23/05/2018 - [] D -- C:\Users\moh\AppData\Roaming\AMD =>.AMD
O43 - CFD: 23/06/2018 - [] D -- C:\Users\moh\AppData\Roaming\Appԁata
O43 - CFD: 04/05/2018 - [] D -- C:\Users\moh\AppData\Roaming\ATI =>.ATI
O43 - CFD: 22/03/2018 - [] D -- C:\Users\moh\AppData\Roaming\BOINC =>.Space Sciences Laboratory, U.C.
O43 - CFD: 01/01/2018 - [0] D -- C:\Users\moh\AppData\Roaming\COWON =>.COWON
O43 - CFD: 15/06/2018 - [] D -- C:\Users\moh\AppData\Roaming\CrystalIdea Software =>.CrystalIdea Software
O43 - CFD: 24/06/2018 - [] D -- C:\Users\moh\AppData\Roaming\DMCache =>.DMCache
O43 - CFD: 04/05/2018 - [] AD -- C:\Users\moh\AppData\Roaming\DriverPack Notifier =>.DriverPack Solution
O43 - CFD: 04/05/2018 - [] D -- C:\Users\moh\AppData\Roaming\DRPNano =>.DriverPack Solution
O43 - CFD: 20/05/2018 - [] D -- C:\Users\moh\AppData\Roaming\DRPNPS
O43 - CFD: 04/05/2018 - [] D -- C:\Users\moh\AppData\Roaming\DRPSu =>.Driver PackSolution
O43 - CFD: 10/06/2018 - [] D -- C:\Users\moh\AppData\Roaming\EpicNet Inc =>Adware.MSIL
O43 - CFD: 24/06/2018 - [] D -- C:\Users\moh\AppData\Roaming\Everything =>.Everything
O43 - CFD: 08/04/2018 - [] D -- C:\Users\moh\AppData\Roaming\facebook-nativefier-f52d2f
O43 - CFD: 30/12/2017 - [] D -- C:\Users\moh\AppData\Roaming\Google =>.Google
O43 - CFD: 30/12/2017 - [] D -- C:\Users\moh\AppData\Roaming\Identities =>.Microsoft Corporation
O43 - CFD: 23/06/2018 - [] D -- C:\Users\moh\AppData\Roaming\IDM =>.IDM
O43 - CFD: 23/06/2018 - [] SHD -- C:\Users\moh\AppData\Roaming\Latas
O43 - CFD: 30/12/2017 - [] D -- C:\Users\moh\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 21/11/2010 - [0] D -- C:\Users\moh\AppData\Roaming\Media Center Programs =>.Microsoft Corporation
O43 - CFD: 19/06/2018 - [] SD -- C:\Users\moh\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 30/12/2017 - [] D -- C:\Users\moh\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 24/06/2018 - [] D -- C:\Users\moh\AppData\Roaming\MPC-HC =>.MPC-HC Team
O43 - CFD: 02/01/2018 - [] D -- C:\Users\moh\AppData\Roaming\MyTotalTV =>.MyTotalTV
O43 - CFD: 01/01/2018 - [] D -- C:\Users\moh\AppData\Roaming\Notepad++ =>.Don Ho
O43 - CFD: 10/06/2018 - [] D -- C:\Users\moh\AppData\Roaming\One System Care =>PUP.Optional.OneSystemCare
O43 - CFD: 10/06/2018 - [] D -- C:\Users\moh\AppData\Roaming\OneSystemCare =>PUP.Optional.OneSystemCare
O43 - CFD: 30/12/2017 - [] D -- C:\Users\moh\AppData\Roaming\Opera Software =>.Opera Software
O43 - CFD: 22/03/2018 - [] D -- C:\Users\moh\AppData\Roaming\PowerISO =>.PowerISO Computing
O43 - CFD: 23/06/2018 - [] SHD -- C:\Users\moh\AppData\Roaming\Pr
O43 - CFD: 28/02/2018 - [] D -- C:\Users\moh\AppData\Roaming\Samsung =>.Samsung Electronics
O43 - CFD: 19/06/2018 - [] D -- C:\Users\moh\AppData\Roaming\Skype =>.Skype
O43 - CFD: 16/02/2018 - [] D -- C:\Users\moh\AppData\Roaming\Solvusoft =>.SUP.Solvusoft
O43 - CFD: 27/02/2018 - [] D -- C:\Users\moh\AppData\Roaming\Sun =>.Oracle
O43 - CFD: 10/06/2018 - [] D -- C:\Users\moh\AppData\Roaming\SystemaRev
O43 - CFD: 09/01/2018 - [] D -- C:\Users\moh\AppData\Roaming\TechSmith =>.TechSmith
O43 - CFD: 03/01/2018 - [] D -- C:\Users\moh\AppData\Roaming\Tencent =>.SUP.Tencent
O43 - CFD: 08/04/2018 - [] D -- C:\Users\moh\AppData\Roaming\uTorrent
O43 - CFD: 17/06/2018 - [] D -- C:\Users\moh\AppData\Roaming\ViberPC =>.Viber
O43 - CFD: 27/02/2018 - [] D -- C:\Users\moh\AppData\Roaming\VidMasta
O43 - CFD: 24/06/2018 - [] D -- C:\Users\moh\AppData\Roaming\vlc =>.VideoLan Team
O43 - CFD: 10/06/2018 - [] D -- C:\Users\moh\AppData\Roaming\WidModule
O43 - CFD: 30/12/2017 - [] D -- C:\Users\moh\AppData\Roaming\WinRAR =>.WinRAR
O43 - CFD: 11/01/2018 - [] D -- C:\Users\moh\AppData\Roaming\Yahoo Messenger =>.Yahoo! Inc.
O43 - CFD: 30/12/2017 - [] D -- C:\Users\moh\AppData\Roaming\Zbshareware Lab =>.Zbshareware Lab
O43 - CFD: 24/06/2018 - [] D -- C:\Users\moh\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 28/02/2018 - [] D -- C:\Users\moh\AppData\Local\Adobe =>.Adobe
O43 - CFD: 30/12/2017 - [] SHD -- C:\Users\moh\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 31/12/2017 - [] D -- C:\Users\moh\AppData\Local\Apps =>.Microsoft Corporation
O43 - CFD: 04/05/2018 - [] D -- C:\Users\moh\AppData\Local\ATI =>.ATI
O43 - CFD: 23/06/2018 - [] D -- C:\Users\moh\AppData\Local\Avg =>.AVG Software
O43 - CFD: 05/03/2018 - [] D -- C:\Users\moh\AppData\Local\Bluestacks =>.BlueStack Systems, Inc.
O43 - CFD: 19/03/2018 - [] D -- C:\Users\moh\AppData\Local\CatalinaGroup =>.SUP.CatalinaMarketing
O43 - CFD: 31/12/2017 - [] D -- C:\Users\moh\AppData\Local\CEF =>.CEF
O43 - CFD: 23/02/2018 - [0] D -- C:\Users\moh\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 05/01/2018 - [] D -- C:\Users\moh\AppData\Local\DeskShare Data =>.DeskShare Inc
O43 - CFD: 28/02/2018 - [] D -- C:\Users\moh\AppData\Local\Downloaded Installations =>.Microsoft Corporation
O43 - CFD: 23/06/2018 - [] D -- C:\Users\moh\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation
O43 - CFD: 08/04/2018 - [] D -- C:\Users\moh\AppData\Local\Embratoria =>.Embratoria
O43 - CFD: 24/06/2018 - [] D -- C:\Users\moh\AppData\Local\Everything =>.Everything
O43 - CFD: 13/02/2018 - [] D -- C:\Users\moh\AppData\Local\Facebook =>.Facebook
O43 - CFD: 01/01/2018 - [0] D -- C:\Users\moh\AppData\Local\FluxSoftware =>.Stereopsis
O43 - CFD: 07/04/2018 - [] D -- C:\Users\moh\AppData\Local\fontconfig =>.Portable Apps
O43 - CFD: 30/12/2017 - [] D -- C:\Users\moh\AppData\Local\Geckofx =>.Geckofx
O43 - CFD: 30/12/2017 - [] D -- C:\Users\moh\AppData\Local\Google =>.Google
O43 - CFD: 30/12/2017 - [] SHD -- C:\Users\moh\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 16/02/2018 - [] D -- C:\Users\moh\AppData\Local\IIIQF =>.Scrabblo
O43 - CFD: 31/12/2017 - [] D -- C:\Users\moh\AppData\Local\Macromedia =>.Macromedia
O43 - CFD: 27/04/2018 - [] D -- C:\Users\moh\AppData\Local\Mediatek =>.Mediatek
O43 - CFD: 13/05/2018 - [] D -- C:\Users\moh\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 23/02/2018 - [0] D -- C:\Users\moh\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 30/12/2017 - [] D -- C:\Users\moh\AppData\Local\Mozilla =>.Mozilla Corporation
O43 - CFD: 05/06/2018 - [] D -- C:\Users\moh\AppData\Local\Nox =>.FFmpeg Project
O43 - CFD: 30/12/2017 - [] D -- C:\Users\moh\AppData\Local\Opera Software =>.Opera Software
O43 - CFD: 04/01/2018 - [] D -- C:\Users\moh\AppData\Local\Package Cache =>.Microsoft Corporation
O43 - CFD: 08/04/2018 - [] D -- C:\Users\moh\AppData\Local\Pokofura
O43 - CFD: 23/02/2018 - [] D -- C:\Users\moh\AppData\Local\PopcornTime =>.SUP.PopcornTime
O43 - CFD: 30/12/2017 - [] D -- C:\Users\moh\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 19/02/2018 - [0] D -- C:\Users\moh\AppData\Local\Skype =>.Skype
O43 - CFD: 05/01/2018 - [] D -- C:\Users\moh\AppData\Local\Spoon =>.Spoon
O43 - CFD: 05/01/2018 - [] D -- C:\Users\moh\AppData\Local\SquirrelTemp =>.Squirrels
O43 - CFD: 27/02/2018 - [] D -- C:\Users\moh\AppData\Local\Sun =>.Oracle
O43 - CFD: 02/02/2018 - [] D -- C:\Users\moh\AppData\Local\TechSmith =>.TechSmith
O43 - CFD: 24/06/2018 - [] D -- C:\Users\moh\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 30/12/2017 - [] SHD -- C:\Users\moh\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 11/06/2018 - [] D -- C:\Users\moh\AppData\Local\Viber =>.Viber
O43 - CFD: 27/01/2018 - [] D -- C:\Users\moh\AppData\Local\Viber Media S.à r.l =>.Viber Media S.à r.l
O43 - CFD: 30/12/2017 - [0] D -- C:\Users\moh\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 11/01/2018 - [] D -- C:\Users\moh\AppData\Local\yahoomessenger =>.Yahoo! Inc.
O43 - CFD: 24/06/2018 - [] D -- C:\Users\moh\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 06/04/2018 - [] D -- C:\Users\moh\AppData\Local\{E7BBD1E7-C313-BD5F-AE8B-98B78AE3642F}
O43 - CFD: 30/12/2017 - [0] D -- C:\Users\moh\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 18/02/2018 - [] D -- C:\Users\moh\AppData\LocalLow\Adobe =>.Adobe
O43 - CFD: 31/12/2017 - [] SHD -- C:\Users\moh\AppData\LocalLow\Microsoft =>.Microsoft Corporation
O43 - CFD: 24/06/2018 - [] D -- C:\Users\moh\AppData\LocalLow\Mozilla =>.Mozilla Corporation
O43 - CFD: 01/01/2018 - [] D -- C:\Users\moh\AppData\LocalLow\Oracle =>.Oracle
O43 - CFD: 01/01/2018 - [] D -- C:\Users\moh\AppData\LocalLow\Sun =>.Oracle
O43 - CFD: 20/05/2018 - [] D -- C:\Users\moh\AppData\LocalLow\Temp =>.Microsoft Corporation
O43 - CFD: 23/06/2018 - [] D -- C:\Users\moh\Desktop\Embratoria_G10
O43 - CFD: 27/04/2018 - [] RD -- C:\Users\moh\Desktop\SP_Flash_Tool_v5.1343.01
O43 - CFD: 20/05/2018 - [] D -- C:\Users\moh\Desktop\شهادة التعليم المتوسط
O43 - CFD: 13/05/2018 - [] D -- C:\Users\moh\Desktop\مجلد جديد ‫‬
O43 - CFD: 14/07/2009 - [] RD -- C:\Users\moh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 21/02/2018 - [] RD -- C:\Users\moh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 27/01/2018 - [] D -- C:\Users\moh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd
O43 - CFD: 10/04/2018 - [] D -- C:\Users\moh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory =>.FormatFactory
O43 - CFD: 26/05/2018 - [] D -- C:\Users\moh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager =>.Tonec Inc
O43 - CFD: 14/07/2009 - [] RD -- C:\Users\moh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 30/01/2018 - [0] D -- C:\Users\moh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft Mail PassView =>.Kirill Gavrilov
O43 - CFD: 01/01/2018 - [0] D -- C:\Users\moh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++ =>.Don Ho
O43 - CFD: 21/02/2018 - [] RD -- C:\Users\moh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 01/01/2018 - [] D -- C:\Users\moh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z =>.TechPowerUp
O43 - CFD: 01/01/2018 - [] D -- C:\Users\moh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tencent =>.SUP.Tencent
O43 - CFD: 04/01/2018 - [] D -- C:\Users\moh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Viber =>.Viber
O43 - CFD: 30/12/2017 - [] D -- C:\Users\moh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 05/01/2018 - [] D -- C:\Users\moh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yahoo! Inc =>.Yahoo! Inc.
O43 - CFD: 23/03/2018 - [] D -- C:\Users\moh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\كل شيء
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 24/02/2018 - [0] D -- C:\Users\Default\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 17/06/2018 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Avg =>.AVG Software
O43 - CFD: 14/07/2009 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 31/12/2017 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 19/03/2018 - [] SD -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 16/02/2018 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Solvusoft =>.SUP.Solvusoft

---\\ ShellIconOverlayIdentifiers (SIOI) (9) - 0s
O106 - SIOI: [ IDM Shell Extension] - {CDC95B92-E27C-4745-A8C5-64A52A78855D}. (.Tonec Inc. - Internet Download Manager module.) -- C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll =>.Tonec Inc.®
O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - مكتبة DLL الخاصة بملحق Shell للتخزين المحسّ.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O106 - SIOI: Groove Explorer Icon Overlay 1 (GFS Unread Stub) [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] - {99FD978C-D287-4F50-827F-B2C658EDA8E7}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Groove Explorer Icon Overlay 2 (GFS Stub) [Groove Explorer Icon Overlay 2 (GFS Stub)] - {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] - {920E6DB1-9907-4370-B3A0-BAFC03D81399}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Groove Explorer Icon Overlay 3 (GFS Folder) [Groove Explorer Icon Overlay 3 (GFS Folder)] - {16F3DD56-1AF5-4347-846D-7C10C4192619}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Groove Explorer Icon Overlay 4 (GFS Unread Mark) [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] - {2916C86E-86A6-43FE-8112-43ABE6BF8DCC}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: [Offline Files] - {4E77131D-3629-431c-9818-C5679DC83E81}. (.Microsoft Corporation - واجهة مستخدم ذاكرة التخزين المؤقت من جانب ا.) -- C:\Windows\System32\cscui.dll =>.Microsoft Corporation
O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - امتداد Shell الخاص بالمشاركة.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation

---\\ Search Context Menu Handlers (SCMH) (39) - 1s
O108 - CMH1: ANotepad++64 [64Bits] - {B298D29A-A6ED-11DE-BA8C-A68E55D89593} . (. - ShellHandler for Notepad++ (64 bit).) -- C:\Program Files (x86)\Notepad++\NppShell_05.dll =>.Don Ho
O108 - CMH1: BriefcaseMenu [64Bits] - {85BBD920-42A0-1069-A2E4-08002B30309D} . (.Microsoft Corporation - حقيبة ملفات Windows.) -- C:\Windows\System32\syncui.dll =>.Microsoft Corporation
O108 - CMH1: Open With [64Bits] - {09799AFB-AD67-11d1-ABCD-00C04FC30936} . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لـ Windows Shell.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH1: Open With EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لـ Windows Shell.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH1: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - امتداد Shell الخاص بالمشاركة.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH1: SnagItMainShellExt [64Bits] - {CF74B903-3389-469c-B3B6-0204D204FCBD} . (.TechSmith Corporation - SnagIt Shell Extension DLL.) -- C:\Program Files (x86)\TechSmith\SnagIt 9\DLLx64\SnagItShellExt64.dll =>.TechSmith Corporation®
O108 - CMH1: WinRAR [64Bits] - {B41DB860-64E4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files (x86)\WinRAR\RarExt64.dll =>.win.rar GmbH®
O108 - CMH1: WinRAR32 [64Bits] - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Orphan.)
O108 - CMH1: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O108 - CMH2: Compatibility [64Bits] - {1d27f844-3a1f-4410-85ac-14651078412d} . (.Microsoft Corporation - مكتبة ملحق Shell لعلامة تبويب التوافق.) -- C:\Windows\System32\acppage.dll =>.Microsoft Corporation
O108 - CMH2: OpenContainingFolderMenu [64Bits] - {37ea3a21-7493-4208-a011-7f9ea79ce9f5} . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لـ Windows Shell.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH3: CopyAsPathMenu [64Bits] - {f3d06e7c-1e45-4a26-847e-f9fcdee59be0} . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لـ Windows Shell.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH3: SendTo [64Bits] - {7BA4C740-9E81-11CF-99D3-00AA004AE837} . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لـ Windows Shell.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH3: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O108 - CMH4: EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لـ Windows Shell.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH4: Offline Files [64Bits] - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Microsoft Corporation - واجهة مستخدم ذاكرة التخزين المؤقت من جانب ا.) -- C:\Windows\System32\cscui.dll =>.Microsoft Corporation
O108 - CMH4: PowerISO [64Bits] - {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} . (.Orphan.)
O108 - CMH4: RecuvaShellExt [64Bits] - {435E5DF5-2510-463C-B223-BDA47006D002} . (.Piriform Ltd - Recuva shell extensions.) -- C:\Program Files\Recuva\RecuvaShell64.dll =>.Piriform Ltd®
O108 - CMH4: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - امتداد Shell الخاص بالمشاركة.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH4: SnagItMainShellExt [64Bits] - {CF74B903-3389-469c-B3B6-0204D204FCBD} . (.TechSmith Corporation - SnagIt Shell Extension DLL.) -- C:\Program Files (x86)\TechSmith\SnagIt 9\DLLx64\SnagItShellExt64.dll =>.TechSmith Corporation®
O108 - CMH4: UltraISO [64Bits] - {AD392E40-428C-459F-961E-9B147782D099} . (.EZB Systems, Inc. - ISOShell.) -- C:\Program Files (x86)\UltraISO\isoshl64.dll =>.SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD.®
O108 - CMH4: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O108 - CMH5: ACE [64Bits] - {5E2121EE-0300-11D4-8D3B-444553540000} . (.Advanced Micro Devices, Inc. - AMD Desktop Control Panel.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll =>.Advanced Micro Devices, Inc.
O108 - CMH5: Gadgets [64Bits] - {6B9228DA-9C15-419e-856C-19E768A13BDC} . (.Microsoft Corporation - Sidebar droptarget.) -- C:\Program Files\Windows Sidebar\sbdrop.dll =>.Microsoft Corporation
O108 - CMH5: New [64Bits] - {D969A300-E7FF-11d0-A93B-00A0C90F2719} . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لـ Windows Shell.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH5: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - امتداد Shell الخاص بالمشاركة.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH5: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O108 - CMH6: BriefcaseMenu [64Bits] - {85BBD920-42A0-1069-A2E4-08002B30309D} . (.Microsoft Corporation - حقيبة ملفات Windows.) -- C:\Windows\System32\syncui.dll =>.Microsoft Corporation
O108 - CMH6: Library Location [64Bits] - {3dad6c5d-2167-4cae-9914-f99e41c12cfa} . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لـ Windows Shell.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH6: Offline Files [64Bits] - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Microsoft Corporation - واجهة مستخدم ذاكرة التخزين المؤقت من جانب ا.) -- C:\Windows\System32\cscui.dll =>.Microsoft Corporation
O108 - CMH6: PowerISO [64Bits] - {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} . (.Orphan.)
O108 - CMH6: RecuvaShellExt [64Bits] - {435E5DF5-2510-463C-B223-BDA47006D002} . (.Piriform Ltd - Recuva shell extensions.) -- C:\Program Files\Recuva\RecuvaShell64.dll =>.Piriform Ltd®
O108 - CMH6: UltraISO [64Bits] - {AD392E40-428C-459F-961E-9B147782D099} . (.EZB Systems, Inc. - ISOShell.) -- C:\Program Files (x86)\UltraISO\isoshl64.dll =>.SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD.®
O108 - CMH6: WinRAR [64Bits] - {B41DB860-64E4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files (x86)\WinRAR\RarExt64.dll =>.win.rar GmbH®
O108 - CMH6: WinRAR32 [64Bits] - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Orphan.)
O108 - CMH6: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O108 - CMH7: EnhancedStorageShell [64Bits] - {2854F705-3548-414C-A113-93E27C808C85} . (.Microsoft Corporation - مكتبة DLL الخاصة بملحق Shell للتخزين المحسّ.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O108 - CMH7: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - امتداد Shell الخاص بالمشاركة.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH7: UltraISO [64Bits] - {AD392E40-428C-459F-961E-9B147782D099} . (.EZB Systems, Inc. - ISOShell.) -- C:\Program Files (x86)\UltraISO\isoshl64.dll =>.SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD.®

---\\ Image File Execution Options (4) - 1s
O50 - IFEO:C:\Windows\System32\ie4uinit.exe - (.Microsoft Corporation - ‎‎الأداة المساعدة للتهيئة لكل مستخدم لـ IE.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - ‎‎أداة التثبيت المساعدة غير المراقبة لـ IE.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - ‎‎مضيف تطبيق Microsoft (R) HTML.) [MitigationOptions\\256] =>.Microsoft Corporation

---\\ System Drivers List (59) - 7s
O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [491088] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [339536] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\drivers\adpu320.sys [182864] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [15440] =>.Microsoft Windows®
O58 - SDL:2015/08/04 06:25:44 A . (.Advanced Micro Devices - AMD ACP Binaries.) -- C:\Windows\System32\drivers\amdacpksd.sys [297672] =>.Advanced Micro Devices, Inc.®
O58 - SDL:2011/03/11 06:41:12 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [107904] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [194128] =>.Microsoft Windows®
O58 - SDL:2011/03/11 06:41:12 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [27008] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [87632] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [97856] =>.Microsoft Windows®
O58 - SDL:2016/04/01 02:31:20 A . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) -- C:\Windows\System32\drivers\AtihdW76.sys [104976] =>.Microsoft Windows Hardware Compatibility Publisher®
O58 - SDL:2015/08/04 06:23:28 A . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\System32\drivers\atikmdag.sys [21622784] =>.Advanced Micro Devices, Inc.
O58 - SDL:2015/08/04 01:42:28 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\Windows\System32\drivers\atikmpag.sys [665088] =>.Advanced Micro Devices, Inc.
O58 - SDL:2009/06/10 20:34:23 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60a.sys [270848] =>.Broadcom Corporation
O58 - SDL:2009/06/10 20:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [18432] =>.Brother Industries, Ltd.
O58 - SDL:2009/06/10 20:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [8704] =>.Brother Industries, Ltd.
O58 - SDL:2009/07/14 01:19:07 A . (.Brother Industries Ltd. - برنامج تشغيل I/F التسلسلي لـ Brotehr (WDM)‎.) -- C:\Windows\System32\drivers\BrSerId.sys [286720] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 20:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [47104] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 20:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [14976] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 20:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [14720] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 20:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [468480] =>.Broadcom Corporation
O58 - SDL:2017/07/04 16:34:16 A . (.CrystalIdea Software - Uninstall Tool 3 Driver.) -- C:\Windows\System32\drivers\CisUtMonitor.sys [54192] =>.Software Security Systems ChTUP®
O58 - SDL:2009/07/14 01:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [17488] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [530496] =>.Microsoft Windows®
O58 - SDL:2009/06/10 20:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3286016] =>.Broadcom Corporation
O58 - SDL:2009/06/10 20:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [31232] =>.Hauppauge Computer Works, Inc.
O58 - SDL:2010/11/21 03:23:47 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [78720] =>.Microsoft Windows®
O58 - SDL:2011/03/11 06:41:26 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [410496] =>.Microsoft Windows®
O58 - SDL:2018/03/01 14:36:14 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\drivers\idmwfp.sys [226032] =>.Tonec Inc.®
O58 - SDL:2012/11/15 00:57:04 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd64.sys [10629408] =>.Intel Corporation
O58 - SDL:2009/07/14 01:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [44112] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [114752] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [106560] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [65600] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [115776] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [35392] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [284736] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [51264] =>.Microsoft Windows®
O58 - SDL:2014/01/12 09:05:46 A . (. - Serial Port Enumerator.) -- C:\Windows\System32\drivers\nuvserenum.sys [23552]
O58 - SDL:2014/01/12 09:05:46 A . (.Nuvoton Technology Corp. - Nuvoton Serial Device Driver (WDM).) -- C:\Windows\System32\drivers\nuvserial.sys [86016] =>.Nuvoton Technology Corp.
O58 - SDL:2011/03/11 06:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [148352] =>.Microsoft Windows®
O58 - SDL:2011/03/11 06:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [166272] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1524816] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [128592] =>.Microsoft Windows®
O58 - SDL:2018/05/20 17:29:02 A . (.Realtek - Realtek 8136/8168/8169 NDIS 6.20 64-bit Dri.) -- C:\Windows\System32\drivers\Rt64win7.sys [988104] =>.Realtek Semiconductor Corp.®
O58 - SDL:2018/02/12 23:13:36 A . (.Realtek Semiconductor Corporation - Realtek 10/100/1000 X64 Driver.) -- C:\Windows\System32\drivers\Rtenic64.sys [549824] =>.Realtek Semiconductor Corp.®
O58 - SDL:2018/05/16 19:55:30 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RTKVHD64.sys [6228416] =>.Realtek Semiconductor Corp.®
O58 - SDL:2009/06/10 20:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] =>.Rovi Corporation
O58 - SDL:2009/07/14 01:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [43584] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [80464] =>.Microsoft Windows®
O58 - SDL:2017/05/18 22:17:28 A . (.Samsung Electronics Co., Ltd. - SAMSUNG USB Composite Device Driver.) -- C:\Windows\System32\drivers\ssudbus.sys [131984] =>.Samsung Electronics Co., Ltd.®
O58 - SDL:2017/05/18 22:17:30 A . (.Samsung Electronics Co., Ltd. - SAMSUNG Android Modem Device Driver.) -- C:\Windows\System32\drivers\ssudmdm.sys [166288] =>.Samsung Electronics Co., Ltd.®
O58 - SDL:2009/07/14 01:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [24656] =>.Microsoft Windows®
O58 - SDL:2016/08/16 03:18:34 A . (.MBB - USB Modem/Serial Device Driver.) -- C:\Windows\System32\drivers\usb2ser.sys [159936] =>.NGO®
O58 - SDL:2018/01/15 15:59:36 A . (.Oracle Corporation - VirtualBox Support Driver.) -- C:\Windows\System32\drivers\VBoxDrv.sys [972192] =>.Oracle Corporation®
O58 - SDL:2009/07/14 01:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [17488] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [161872] =>.Microsoft Windows®
O58 - SDL:2013/09/30 15:26:50 A . (...) -- C:\Windows\System32\pwdrvio.sys [19152] =>.MiniTool Solution Ltd®
O58 - SDL:2013/09/30 15:26:48 A . (...) -- C:\Windows\System32\pwdspio.sys [12504] =>.MiniTool Solution Ltd®

---\\ Last modified or created user files (19) - 424s
O61 - LFC: 2018/05/30 08:00:06 A . (..) -- C:\ProgramData\23aa6461-67c2-4c67-b567-a488a7e052c4\SystemConsole.exe [1720320]
O61 - LFC: 2018/05/29 14:08:16 A . (..) -- C:\ProgramData\55e0cb0e-c21b-4f2d-ac71-2f3455b1b89f\RescueMonitor.exe [1254400]
O61 - LFC: 2018/05/30 11:56:08 A . (..) -- C:\ProgramData\93f8d562-c26c-4cd2-b33f-096da5934c09\OneSystemCare.exe [521864] {20D7BAECA5D2F968547FB6FE78BE0C2D} =>PUP.Optional.OneSystemCare
O61 - LFC: 2018/06/01 15:50:20 A . (..) -- C:\Users\moh\AppData\Local\Viber\imageformats\qsvg.dll [471112] {243C767E33053FAAE0F0131C103D7A17}
O61 - LFC: 2018/06/01 15:49:01 A . (..) -- C:\Users\moh\AppData\Local\Viber\libEGL.dll [19016] {243C767E33053FAAE0F0131C103D7A17}
O61 - LFC: 2018/06/01 15:49:02 A . (..) -- C:\Users\moh\AppData\Local\Viber\libGLESV2.dll [2102856] {243C767E33053FAAE0F0131C103D7A17}
O61 - LFC: 2018/06/01 15:49:08 A . (..) -- C:\Users\moh\AppData\Local\Viber\opengl32sw.dll [16002120] {243C767E33053FAAE0F0131C103D7A17}
O61 - LFC: 2018/06/01 15:49:10 A . (..) -- C:\Users\moh\AppData\Local\Viber\qrencode.dll [47688] {243C767E33053FAAE0F0131C103D7A17}
O61 - LFC: 2018/06/01 15:49:59 A . (.Viber Media S.à r.l..) -- C:\Users\moh\AppData\Local\Viber\Viber.exe [40255560] {243C767E33053FAAE0F0131C103D7A17}
O61 - LFC: 2018/06/01 15:49:55 A . (..) -- C:\Users\moh\AppData\Local\Viber\ViberRTC.dll [8936008] {243C767E33053FAAE0F0131C103D7A17}
O61 - LFC: 2018/06/11 01:38:58 A . (..) -- C:\Users\moh\AppData\Roaming\ViberPC\9.0.0.8\9.0.0.8\updater.exe [617032] {243C767E33053FAAE0F0131C103D7A17}
O61 - LFC: 2018/06/11 01:38:58 A . (..) -- C:\Users\moh\Application Data\ViberPC\9.0.0.8\9.0.0.8\updater.exe [617032] {243C767E33053FAAE0F0131C103D7A17}
O61 - LFC: 2018/06/10 20:25:09 A . (..) -- C:\Users\moh\Desktop\Embratoria_G10\BeinSave\BeinSave_10-06-2018-20-24-51.dll [5536018]
O61 - LFC: 2018/06/12 16:01:24 A . (..) -- C:\Users\moh\Desktop\Embratoria_G10\EmbratoriaG10.exe [572416]
O61 - LFC: 2018/06/06 16:30:48 A . (.Embratoria Copyright © 2018.) -- C:\Users\moh\Desktop\Embratoria_G10\Fix_Errors.exe [278016]
O61 - LFC: 2018/06/13 22:16:48 A . (..) -- C:\Users\moh\Desktop\Embratoria_G10\LibsG10.exe [6876160]
O61 - LFC: 2018/06/04 13:20:20 A . (.Copyright Embratoria tv © 2018.) -- C:\Users\moh\Desktop\Embratoria_G10\Restore_G7-G10.exe [323072]
O61 - LFC: 2018/06/20 13:06:15 A . (..) -- C:\Users\moh\Desktop\Embratoria_G10\Tools\Silverlight.exe [0]
O61 - LFC: 2018/06/23 23:42:11 A . (.Softwares Registrations.) -- C:\Users\moh\Downloads\Programs\Registration.exe [1837302]

---\\ File Associations Shell Spawning (10) - 1s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - ‎‎مشغل الأداة الإضافية لعارض الأحداث.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (...) -- C:\Windows\System32\WScript.exe "%1" %* =>.Default.Value
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - ‎‎محرر التسجيل.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S =>.Default.Value

---\\ Start Menu Internet (24) - 0s
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (...) -- C:\Users\moh\AppData\Local\Chromium\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (...) -- iexplore.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\Launcher.exe =>.Opera Software AS®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (...) -- C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe (.not file.) =>.SUP.UCBrowser
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Users\moh\AppData\Local\Chromium\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - ‎‎الأداة المساعدة للتهيئة لكل مستخدم لـ IE.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\launcher.exe =>.Opera Software
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe (.not file.)
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Users\moh\AppData\Local\Chromium\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - ‎‎الأداة المساعدة للتهيئة لكل مستخدم لـ IE.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\launcher.exe =>.Opera Software
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe (.not file.)
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Users\moh\AppData\Local\Chromium\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - ‎‎الأداة المساعدة للتهيئة لكل مستخدم لـ IE.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Opera Software - Opera Internet Browser.) -- C:\Program Files\Opera\launcher.exe =>.Opera Software
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe (.not file.)

---\\ Search Browser Infection (3) - 7s
O69 - SBI: SearchScopes [HKCU] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKCU] [64Bits]{C0C3A6C6-03BC-4195-8FCB-AEA091301353} - (Yahoo!) - http://maktoob.search.yahoo.com/ =>.Yahoo! Inc.
O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com

---\\ Search Svchost Services (33) - 1s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\Windows\System32\aelupsvc.dll [72192] =>.Microsoft Corporation
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - خدمة نشر شهادة البطاقة الذكية لـ Microsoft.) -- C:\Windows\System32\certprop.dll [80384] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - خدمة نشر شهادة البطاقة الذكية لـ Microsoft.) -- C:\Windows\System32\certprop.dll [80384] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمة الخادم.) -- C:\Windows\System32\srvsvc.dll [236032] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - عميل نهج المجموعة.) -- C:\Windows\System32\gpsvc.dll [794624] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\IKEEXT.DLL [863232] =>.Microsoft Corporation
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - خدمة صوت Windows.) -- C:\Windows\System32\audiosrv.dll [680448] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - إدارة الطلب التلقائي للوصول عن بُعد.) -- C:\Windows\System32\rasauto.dll [99328] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [344064] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [97792] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - خدمة الإعلام بأحداث النظام (SENS).) -- C:\Windows\System32\Sens.dll [64512] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [359424] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [316928] =>.Microsoft Corporation
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remote Desktop Session Host Server Remote C.) -- C:\Windows\System32\termsrv.dll [683520] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - عامل Windows Update.) -- C:\Windows\System32\wuaueng.dll [2651648] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - خدمة النقل الذكي في الخلفية.) -- C:\Windows\System32\qmgr.dll [849920] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمات Windows Sh.) -- C:\Windows\System32\shsvcs.dll [370688] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [569344] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي الخاصة بخدمة تسجي.) -- C:\Windows\System32\seclogon.dll [30720] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - خدمة معلومات التطبيقات.) -- C:\Windows\System32\appinfo.dll [70144] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - خدمة اكتشاف iSCSI.) -- C:\Windows\System32\iscsiexe.dll [156672] =>.Microsoft Corporation
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - خدمة جدولة فئات تعدد الوسائط.) -- C:\Windows\System32\mmcss.dll [67584] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [242688] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - خدمة تكوين سطح المكتب البعيد.) -- C:\Windows\System32\SessEnv.dll [121856] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمة مستعرض الكم.) -- C:\Windows\System32\browser.dll [136704] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [111104] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - خدمة جدولة المهام.) -- C:\Windows\System32\schedsvc.dll [1110528] =>.Microsoft Corporation
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\Windows\System32\KMSVC.DLL [90624] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - تقارير المشاكل وحلولها.) -- C:\Windows\System32\wercplsupport.dll [84480] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [210432] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - مكتبة الارتباط الديناميكي لخدمات نُسق Windo.) -- C:\Windows\System32\themeservice.dll [44544] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - خدمة BDE.) -- C:\Windows\System32\bdesvc.dll [100864] =>.Microsoft Corporation
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - خدمة تثبت البرامج.) -- C:\Windows\System32\appmgmts.dll [193536] =>.Microsoft Corporation

---\\ Firewall Active Exception List (39) - 7s
O87 - FAEL: "{5B8F044C-EB3A-4013-A62A-AB2067B7DC5D}" [In-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\moh\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O87 - FAEL: "{1DF95E00-1662-4121-A482-5A77338E322F}" [In-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\moh\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O87 - FAEL: "{9990EAD4-0CEA-4C2E-9E78-5A74419D2F35}" [In-None-P6-TRUE] .(...) -- C:\Users\moh\Desktop\EmbratoriaG7.1.2\libs.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{7B537AF7-7EAA-432D-978C-2C0984CC3C82}" [In-None-P17-TRUE] .(...) -- C:\Users\moh\Desktop\EmbratoriaG7.1.2\libs.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{1B29CA29-EED1-4F93-BB06-8984C192CCCF}" [In-None-P6-TRUE] .(...) -- C:\Users\moh\AppData\Local\Mozilla Firefox\firefox.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{6EA10253-C956-42E9-A922-512FE175D242}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Deskshare\IP Camera Viewer 3\IP Camera Viewer.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{F8F6ED96-0223-4195-AE2B-3162337DC839}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Deskshare\IP Camera Viewer 3\IP Camera Viewer.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{43BB133A-1BDD-43E0-84EA-2A87992715DE}" [In-None-P6-TRUE] .(...) -- C:\Users\moh\AppData\Local\Temp\Rar$EXa2476.40729\HeroConnect UpdateV1.1\libsONE.exe (.not file.) =>.Temporary file not necessary
O87 - FAEL: "{D54658CB-B954-429E-BAED-4B55293116F8}" [In-None-P17-TRUE] .(...) -- C:\Users\moh\AppData\Local\Temp\Rar$EXa2476.40729\HeroConnect UpdateV1.1\libsONE.exe (.not file.) =>.Temporary file not necessary
O87 - FAEL: "TCP Query User{54705267-4ED8-412A-90DA-DA3A9F2D6089}C:\windows\syswow64\javaw.exe" [In-None-P6-TRUE] .(...) -- C:\windows\syswow64\javaw.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "UDP Query User{7C68C9EC-5993-46D5-B32B-EAFF23C61ABB}C:\windows\syswow64\javaw.exe" [In-None-P17-TRUE] .(...) -- C:\windows\syswow64\javaw.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{D76B4CF2-4142-4F1A-8C2B-0CC786D8C9C0}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\BlueStacks\HD-Player.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{D23BAF91-E8D3-472C-8272-56CB6709AF11}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Opera\42.0.2393.137\opera.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{D1B59F4C-7785-4B83-A0E7-889DE8FBD873}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{A99254DA-B1A2-44EC-8C82-118690217248}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{8D7408F1-2286-4B01-A1D6-AEA77EF4E0E6}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\UCBrowser\Application\Downloader\download\MiniThunderPlatform.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{253FF018-AF08-4094-B089-A28679521792}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Nox\bin\Nox.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{56C0B95E-5A42-4636-87BC-AA48E4D2D8B3}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Bignox\BigNoxVM\RT\NoxVMHandle.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{DC0B6161-DD53-410B-95FA-F8405A920D77}" [In-None-P17-TRUE] .(...) -- C:\Users\moh\AppData\Local\Chromium\Application\chrome.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{5D5E911E-C28D-4D9B-9F58-AE580C7B5DCF}" [In-None-P6-TRUE] .(...) -- C:\Users\moh\Desktop\HeroConnect UpdateV1.1\libsONE.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{B59D0D83-8609-4289-B0E5-DC9E05150371}" [In-None-P17-TRUE] .(...) -- C:\Users\moh\Desktop\HeroConnect UpdateV1.1\libsONE.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{EE6C917C-554C-4415-AADC-C43CC6818DB3}" [In-None-P6-TRUE] .(...) -- C:\Users\moh\Desktop\Hero Connect H2\libsONE.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{FAE4622E-DCBC-4DAD-9562-64C966D3FB2C}" [In-None-P17-TRUE] .(...) -- C:\Users\moh\Desktop\Hero Connect H2\libsONE.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "TCP Query User{A10BBEF7-A069-4782-98D3-1F62EC13165A}C:\users\moh\desktop\sp_flash_tool_v5.1343.01\flash_tool.exe" [In-None-P6-TRUE] .(...) -- C:\users\moh\desktop\sp_flash_tool_v5.1343.01\flash_tool.exe
O87 - FAEL: "UDP Query User{AC0BB1EE-62D6-4087-9B62-15CDC67DD573}C:\users\moh\desktop\sp_flash_tool_v5.1343.01\flash_tool.exe" [In-None-P17-TRUE] .(...) -- C:\users\moh\desktop\sp_flash_tool_v5.1343.01\flash_tool.exe
O87 - FAEL: "{9208DDAC-4B51-407C-9A45-62BCD0A6CA1C}" [In-None-P6-TRUE] .(...) -- C:\Program Files\DriversCloud.com\DriversCloud.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{0F71B567-BD65-48BF-9746-4394F3F33AC6}" [In-None-P17-TRUE] .(...) -- C:\Program Files\DriversCloud.com\DriversCloud.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{10988B27-7EFC-4229-9896-74EA32F79256}" [In-None-P17-TRUE] .(...) -- C:\Users\moh\AppData\Local\Temp\7ZipSfx.001\bin\tools\aria2c.exe (.not file.) =>.Temporary file not necessary
O87 - FAEL: "{E0DDC403-B72A-4A3C-9BE3-2A0095609FF0}" [In-None-P17-TRUE] .(...) -- C:\Users\moh\AppData\Local\Temp\7ZipSfx.002\bin\tools\aria2c.exe (.not file.) =>.Temporary file not necessary
O87 - FAEL: "TCP Query User{B13A6534-EB80-406A-9E36-59AB62890130}C:\users\moh\desktop\embratoria_g10\libsg10.exe" [In-None-P6-TRUE] .(...) -- C:\users\moh\desktop\embratoria_g10\libsg10.exe
O87 - FAEL: "UDP Query User{9B0F4916-2242-4841-BCBF-B347331C784F}C:\users\moh\desktop\embratoria_g10\libsg10.exe" [In-None-P17-TRUE] .(...) -- C:\users\moh\desktop\embratoria_g10\libsg10.exe
O87 - FAEL: "TCP Query User{2194E1B9-D04B-4226-9521-52581F9CF801}C:\users\moh\desktop\embratoria_g10\libsg10_updated.exe" [In-None-P6-TRUE] .(...) -- C:\users\moh\desktop\embratoria_g10\libsg10_updated.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "UDP Query User{81EC0506-DF1C-42F4-BD94-DAEF11FD50FB}C:\users\moh\desktop\embratoria_g10\libsg10_updated.exe" [In-None-P17-TRUE] .(...) -- C:\users\moh\desktop\embratoria_g10\libsg10_updated.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{2C07A63D-AB8C-4444-927E-A5B68A299C33}" [In-None-P17-TRUE] .(...) -- C:\Program Files\SystemaRev\RevServicesX\app.exe
O87 - FAEL: "{E7829323-B91D-45A4-9FD1-4143C641BF4D}" [In-None-P6-TRUE] .(...) -- C:\Users\moh\AppData\Local\Temp\Rar$EXa5696.44770\libs.exe (.not file.) =>.Temporary file not necessary
O87 - FAEL: "{CE6A75AC-6AC0-4AC3-A48C-65B87EFCC861}" [In-None-P17-TRUE] .(...) -- C:\Users\moh\AppData\Local\Temp\Rar$EXa5696.44770\libs.exe (.not file.) =>.Temporary file not necessary
O87 - FAEL: "TCP Query User{B659C6B7-D8A5-4E2C-9951-9442655A3F34}C:\users\moh\desktop\embratoria_g10\libsg10.exe" [In-None-P6-TRUE] .(...) -- C:\users\moh\desktop\embratoria_g10\libsg10.exe
O87 - FAEL: "UDP Query User{8F9410C5-9A6B-49A5-AC62-07E7BDB6339C}C:\users\moh\desktop\embratoria_g10\libsg10.exe" [In-None-P17-TRUE] .(...) -- C:\users\moh\desktop\embratoria_g10\libsg10.exe
O87 - FAEL: "{4BEBDEB5-870C-4F1A-ADDD-1BFC08FE0079}" [In-None-P17-TRUE] .(...) -- C:\Users\moh\AppData\Local\Temp\7ZipSfx.002\bin\tools\aria2c.exe (.not file.) =>.Temporary file not necessary

---\\ Product Upgrade Codes (76) - 2s
O90 - PUC: "00004109110000000000000000F01FEC" [HKLM] . (.Microsoft Office Professional Plus 2010.) =>.Microsoft Corporation
O90 - PUC: "000041091A0010400000000000F01FEC" [HKLM] . (.Microsoft Office OneNote MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109440010400000000000F01FEC" [HKLM] . (.Microsoft Office InfoPath MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109510010400000000000F01FEC" [HKLM] . (.Microsoft Office Access MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109610010400000000000F01FEC" [HKLM] . (.Microsoft Office Excel MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109810010400000000000F01FEC" [HKLM] . (.Microsoft Office PowerPoint MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109910010400000000000F01FEC" [HKLM] . (.Microsoft Office Publisher MUI (Arabic) 2010.) =>.bl.org
O90 - PUC: "00004109A10010400000000000F01FEC" [HKLM] . (.Microsoft Office Outlook MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109A20000000100000000F01FEC" [HKLM] . (.Microsoft Office Office 64-bit Components 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109A20010400100000000F01FEC" [HKLM] . (.Microsoft Office Shared 64-bit MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109AB0010400000000000F01FEC" [HKLM] . (.Microsoft Office Groove MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109B10010400000000000F01FEC" [HKLM] . (.Microsoft Office Word MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109C20010400000000000F01FEC" [HKLM] . (.Microsoft Office Proofing (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109E60010400000000000F01FEC" [HKLM] . (.Microsoft Office Shared MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109F10010400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109F10090400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (English) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109F100C0400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (French) 2010.) =>.Microsoft Corporation
O90 - PUC: "0570A0D4430B8FD479ED621F12A22CFF" [HKLM] . (.DriverDoc.) =>.Legitimate
O90 - PUC: "12B8D03ED28D112328CCF0A0D541598E" [HKLM] . (.Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40660.) =>.Microsoft Corporation
O90 - PUC: "1926E8D15D0BCE53481466615F760A7F" [HKLM] . (.Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219.) =>.bl.org
O90 - PUC: "1C62D0E6562420D1D4910D8A6F4A368F" [HKLM] . (.Catalyst Control Center.) -- C:\Windows\Installer\{6E0D26C1-4265-1D02-4D19-D0A8F6A463F8}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "1D5E3C0FEDA1E123187686FED06E995A" [HKLM] . (.Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219.) =>.bl.org
O90 - PUC: "218845EA116DD806166CE7042F58372A" [HKLM] . (.CCC Help Russian.) -- C:\Windows\Installer\{AE548812-D611-608D-61C6-7E40F28573A2}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "291F31BACF94560A1FC547B601CC348C" [HKLM] . (.CCC Help Japanese.) -- C:\Windows\Installer\{AB13F192-49FC-A065-F15C-746B10CC43C8}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "292464316666BD2BB1C03AEF41AD1D9F" [HKLM] . (.CCC Help Dutch.) -- C:\Windows\Installer\{13464292-6666-B2DB-1B0C-A3FE14DAD1F9}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "2CA25F2E529BF81C1EEA24BF4DE6AC7C" [HKLM] . (.CCC Help Czech.) -- C:\Windows\Installer\{E2F52AC2-B925-C18F-E1AE-42FBD46ECAC7}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "2EE576AD40C49969E02EE79FEFA78B07" [HKLM] . (.CCC Help German.) -- C:\Windows\Installer\{DA675EE2-4C04-9699-0EE2-7EF9FE7AB870}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "32FA0F2EF2EF2224A934556EC34CE11F" [HKLM] . (.Catalyst Control Center - Branding.) -- C:\Windows\Installer\{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "34300D53AFB31A646CDDFF7D0705E1B0" [HKLM] . (.AMD Drag and Drop Transcoding.) -- C:\Windows\Installer\{35D00343-3BFA-46A1-C6DD-FFD770501E0B}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "37074588665C59840950BE9EE83A7F7C" [HKLM] . (.Samsung Kies3.) -- C:\Windows\Installer\{88547073-C566-4895-9005-EBE98EA3F7C7}\ARPPRODUCTICON.exe =>.Samsung Electronics
O90 - PUC: "4113649EC898A2C7C2749EBA6CF3D534" [HKLM] . (.CCC Help Finnish.) -- C:\Windows\Installer\{E9463114-898C-7C2A-2C47-E9ABC63F5D43}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "47CA2FBBC0273BC32819E543302923AF" [HKLM] . (.Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24215.) =>.Microsoft Corporation
O90 - PUC: "4BEA594979BAED93C82408E6FE57CE7A" [HKLM] . (.Microsoft Visual Studio 2010 Tools for Office Runtime (x64).) =>.Microsoft Corporation
O90 - PUC: "59C7F60E86D49D362213AAF5E881F6BC" [HKLM] . (.CCC Help English.) -- C:\Windows\Installer\{E06F7C95-4D68-63D9-2231-AA5F8E186FCB}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "60226DD7C6B7E23EDB114BB9B380D961" [HKLM] . (.CCC Help Danish.) -- C:\Windows\Installer\{7DD62206-7B6C-E32E-BD11-B49B3B089D16}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "6239B35654DBEB3586A14AC9AAEEA8C3" [HKLM] . (.ccc-utility64.) -- C:\Windows\Installer\{653B9326-BD45-53BE-681A-A49CAAEE8A3C}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "6558546464C59A976AFF18FDF1B87292" [HKLM] . (.CCC Help Hungarian.) -- C:\Windows\Installer\{46458556-5C46-79A9-A6FF-81DF1F8B2729}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "68AB67CA408033019195008142622500" [HKLM] . (.Adobe Refresh Manager.) -- C:\Windows\Installer\{AC76BA86-0804-1033-1959-001824265200}\ARPPRODUCTICON.exe =>.Western Digital Technologies
O90 - PUC: "68AB67CA7DA73301B744CAF070E41400" [HKLM] . (.Adobe Acrobat Reader DC.) -- C:\Windows\Installer\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\SC_Reader.ico =>.Adobe Inc.
O90 - PUC: "6B5D0BA99774F4C8AC191AEFBD657DCE" [HKLM] . (.AMD Catalyst Install Manager.) -- C:\Windows\Installer\{9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC}\ARPPRODUCTICON.exe =>.Western Digital Technologies
O90 - PUC: "8520DAD7C5154DD39846DB1714990E7F" [HKLM] . (.Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40660.) =>.Microsoft Corporation
O90 - PUC: "8977514E97F772E4480A6AFB6906F774" [HKLM] . (.Oracle VM VirtualBox 5.2.6.) -- C:\Windows\Installer\{E4157798-7F79-4E27-84A0-A6BF96607F47}\IconVirtualBox =>.Oracle
O90 - PUC: "8B86D915867ACDC44E9C1B514DC9DE39" [HKLM] . (.CCC Help Norwegian.) -- C:\Windows\Installer\{519D68B8-A768-4CDC-E4C9-B115D49CED93}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "908CA67D1CCC891694076AF35AFCD7BC" [HKLM] . (.CCC Help Swedish.) -- C:\Windows\Installer\{D76AC809-CCC1-6198-4970-A63FA5CF7DCB}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "93CA946E0C96EF6CA0457425BDD5F12D" [HKLM] . (.Catalyst Control Center Graphics Previews Common.) -- C:\Windows\Installer\{E649AC39-69C0-C6FE-0A54-4752DB5D1FD2}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "9A4E5EB6B88DD235626E88C323FB90A8" [HKLM] . (.CCC Help Thai.) -- C:\Windows\Installer\{6BE5E4A9-D88B-532D-26E6-883C32BF098A}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "9E50C1C09018EA63B8EC5F9A1CC68238" [HKLM] . (.Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - ARA.) =>.Microsoft Corporation
O90 - PUC: "9FEA36CB7631C7F99562255E4605DEDC" [HKLM] . (.CCC Help Spanish.) -- C:\Windows\Installer\{BC63AEF9-1367-9F7C-5926-52E56450EDCD}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "A089CE062ADB6BC44A720BA745894BAC" [HKLM] . (.Google Update Helper.) =>.Google Inc.
O90 - PUC: "A08ADAF298D58CC4E97D44557257A438" [HKLM] . (.SnagIt 9.) =>.TechSmith
O90 - PUC: "AC788487A0B0E293590087060E23D49A" [HKLM] . (.Microsoft .NET Framework 4.7.1 (ARA).) =>.Microsoft Corporation
O90 - PUC: "B2D388A5972D10D0E6268B01FA8DCC26" [HKLM] . (.Catalyst Control Center InstallProxy.) -- C:\Windows\Installer\{5A883D2B-D279-0D01-6E62-B810AFD8CC62}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "C3257C0EB6866EE3F81BBC34933EE0DD" [HKLM] . (.Microsoft .NET Framework 4.7.1.) =>.Microsoft Corporation
O90 - PUC: "C3F8A12EBCA11B64EC279EFC9045D9DE" [HKLM] . (.Catalyst Control Center Localization All.) -- C:\Windows\Installer\{E21A8F3C-1ACB-46B1-CE72-E9CF09549DED}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "C4219089C4C076328798E1618DFEA1FA" [HKLM] . (.CCC Help Chinese Standard.) -- C:\Windows\Installer\{9809124C-0C4C-2367-7889-1E16D8EF1AAF}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "CA4ECB96275917232ABF4932DB3AA634" [HKLM] . (.Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24215.) =>.Microsoft Corporation
O90 - PUC: "CB383D15889DE1C8AF1ACB25063AA278" [HKLM] . (.CCC Help Polish.) -- C:\Windows\Installer\{51D383BC-D988-8C1E-FAA1-BC5260A32A87}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "D4CA01FF9433AD99E3851579EC1A8D33" [HKLM] . (.CCC Help Italian.) -- C:\Windows\Installer\{FF10AC4D-3349-99DA-3E58-5197CEA1D833}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "D7314F9862C648A4DB8BE2A5B47BE100" [HKLM] . (.Microsoft Silverlight.) -- C:\Windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ARPIcon =>.Microsoft Corporation
O90 - PUC: "D8519379DEDE826D895641065B7AAF3E" [HKLM] . (.CCC Help Portuguese.) -- C:\Windows\Installer\{9739158D-EDED-D628-9865-1460B5A7FAE3}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "D8D80E0C670671146B44A23FF4537B75" [HKLM] . (.Universal Adb Driver.) =>.Universal Adb
O90 - PUC: "D9EE1E6ADD10DF28DBCB91B3EC9FDFC5" [HKLM] . (.CCC Help Greek.) -- C:\Windows\Installer\{A6E1EE9D-01DD-82FD-BDBC-193BCEF9FD5C}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "DC92D0A499A7F5F48BB111A5B52BE54C" [HKLM] . (.RevServicesX.) =>Trojan.Agent
O90 - PUC: "EA73B3005F125CB55FBEDC068A296869" [HKLM] . (.AMD Accelerated Video Transcoding.) -- C:\Windows\Installer\{003B37AE-21F5-5BC5-F5EB-CD60A8928696}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "F0674A7640896FCC3C917248E07D9742" [HKLM] . (.CCC Help Korean.) -- C:\Windows\Installer\{67A4760F-9804-CCF6-C319-27840ED77924}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "F4339ACB9C6B56F4A937CAA523A9D440" [HKLM] . (.PlayReady PC Runtime amd64.) =>.Microsoft Corporation
O90 - PUC: "F65DC833CDC123FC336FED2DFD2982E4" [HKLM] . (.CCC Help French.) -- C:\Windows\Installer\{338CD56F-1CDC-CF32-33F6-DED2DF92284E}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "F72D2E1C363BE8858895E97F4FBE4F81" [HKLM] . (.CCC Help Chinese Traditional.) -- C:\Windows\Installer\{C1E2D27F-B363-588E-8859-9EF7F4EBF418}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "FF39CEFF261C3C0C5B7E1012B4E0F5D2" [HKLM] . (.CCC Help Turkish.) -- C:\Windows\Installer\{FFEC93FF-C162-C0C3-B5E7-01214B0E5F2D}\ARPPRODUCTICON.exe =>.Advanced Micro Devices Inc
O90 - PUC: "FF42397161B78AB4896350C5AAEEF480" [HKLM] . (.SDFormatter.) -- C:\Windows\Installer\{179324FF-7B16-4BA8-9836-055CAAEE4F08}\ARPPRODUCTICON.exe =>.SD Association
O90 - PUC: "B8CB02B5156337A4591716FAC496568C" [HKCU] . (.Facebook Gameroom 1.20.6599.20957.) -- %APPDATA%\Microsoft\Installer\{5B20BC8B-3651-4A73-9571-61AF4C6965C8}\icon.ico =>.Facebook
O90 - PUC: "E2024C9D15D660B48A1F2213E656B4AC" [HKCU] . (.Universal Adb Driver.) =>.Universal Adb
O90 - PUC: "FFA47690296CF7D4EBA2584657927D54" [HKCU] . (.Viber.) =>.Viber
O90 - PUC: "B8CB02B5156337A4591716FAC496568C" [HKU] . (.Facebook Gameroom 1.20.6599.20957.) -- %APPDATA%\Microsoft\Installer\{5B20BC8B-3651-4A73-9571-61AF4C6965C8}\icon.ico =>.Facebook
O90 - PUC: "E2024C9D15D660B48A1F2213E656B4AC" [HKU] . (.Universal Adb Driver.) =>.Universal Adb
O90 - PUC: "FFA47690296CF7D4EBA2584657927D54" [HKU] . (.Viber.) =>.Viber

---\\ Windows Installer Scan (46) - 19s
[MD5.92A8FD273230C6586F62B3E8276870DF] [WIS][2018/02/28 16:42:10] (.Samsung Electronics Co., Ltd..) -- C:\Windows\Installer\11b9a75.msi [38928384] =>.Samsung Electronics Co., Ltd.
[MD5.672A3BA455E067F0B365EAF4C2F278F4] [WIS][2016/10/07 07:38:09] (.ClockworkMod.) -- C:\Windows\Installer\12e55e.msi [9208320] =>.ClockworkMod
[MD5.50EA7A4D9481B12A97070942F474D918] [WIS][2018/05/17 01:27:28] (.Google Inc. - Google Update Helper.) -- C:\Windows\Installer\18db6d9.msi [40960] =>.Google Inc.
[MD5.7CF98FD765D5D6D2329F8A2E65EC050A] [WIS][2013/04/16 16:24:54] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22ae71.msi [627712] =>.Advanced Micro Devices, Inc.
[MD5.FF25A0CED186885284196286F715BC0B] [WIS][2013/04/16 16:31:06] (.Advanced Micro Devices, Inc. - AMD Catalyst Install Manager Installer (64 .) -- C:\Windows\Installer\22ae79.msi [8338944] =>.Advanced Micro Devices, Inc.
[MD5.207C9DDEC7FBF993B9FA5C183EB29E71] [WIS][2013/04/22 19:31:54] (.Advanced Micro Devices, Inc. - Branding.) -- C:\Windows\Installer\22ae80.msi [507392] =>.Advanced Micro Devices, Inc.
[MD5.4B427F9771F39829EFF2BEF719684D8B] [WIS][2013/04/16 16:26:22] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22ae87.msi [1889792] =>.Advanced Micro Devices, Inc.
[MD5.82EC590443C92D5173D5844288B4AC52] [WIS][2013/04/16 16:22:20] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22ae8e.msi [790528] =>.Advanced Micro Devices, Inc.
[MD5.767A17A70D5DA592D4E970BCD04FA66E] [WIS][2013/04/16 16:22:26] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22ae95.msi [755712] =>.Advanced Micro Devices, Inc.
[MD5.D8480B0D393B115F5E0AA11F3B05F2BD] [WIS][2013/04/16 16:22:32] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22ae9c.msi [779264] =>.Advanced Micro Devices, Inc.
[MD5.CE9E45C6B4D0A9092D7997EBD50384D0] [WIS][2013/04/16 16:22:40] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22aea3.msi [893440] =>.Advanced Micro Devices, Inc.
[MD5.6D30F7199359AD913675DC45F81CCFF0] [WIS][2013/04/16 16:22:46] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22aeaa.msi [736256] =>.Advanced Micro Devices, Inc.
[MD5.78059CE1E34BC80FDCA07642CEE75608] [WIS][2013/04/16 16:22:52] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22aeb1.msi [766976] =>.Advanced Micro Devices, Inc.
[MD5.5785061F4DBA850C39FB8061627383A6] [WIS][2013/04/16 16:22:58] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22aeb8.msi [761344] =>.Advanced Micro Devices, Inc.
[MD5.1169621C95744773917AF4101BFECF68] [WIS][2013/04/16 16:23:06] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22aebf.msi [772608] =>.Advanced Micro Devices, Inc.
[MD5.5E90565A502AC0F8BF37684DF00B1A8E] [WIS][2013/04/16 16:23:12] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22aec6.msi [788992] =>.Advanced Micro Devices, Inc.
[MD5.30D1494FCDC144513F13DCDC7AD4621E] [WIS][2013/04/16 16:23:18] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22aecd.msi [763904] =>.Advanced Micro Devices, Inc.
[MD5.6BBDDE7DC0877E2DD91117BD1BEAEAD2] [WIS][2013/04/16 16:23:26] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22aed4.msi [812544] =>.Advanced Micro Devices, Inc.
[MD5.86B1336124129E747D365ABC74BF5AB8] [WIS][2013/04/16 16:23:32] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22aedb.msi [793600] =>.Advanced Micro Devices, Inc.
[MD5.4B4B99AB98A6692F87F66E200C351A83] [WIS][2013/04/16 16:23:38] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22aee2.msi [753152] =>.Advanced Micro Devices, Inc.
[MD5.C261857181768AE1EA9335F9AEF48032] [WIS][2013/04/16 16:23:44] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22aee9.msi [745472] =>.Advanced Micro Devices, Inc.
[MD5.36E1134D6F49E77D4A221CAD0622502E] [WIS][2013/04/16 16:23:50] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22aef0.msi [780288] =>.Advanced Micro Devices, Inc.
[MD5.B265EF6172D98F7AB0EB99586AED5A31] [WIS][2013/04/16 16:23:58] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22aef7.msi [763904] =>.Advanced Micro Devices, Inc.
[MD5.BA0BB6616FF68934C192C7E03C1B7FD5] [WIS][2013/04/16 16:24:04] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22aefe.msi [872448] =>.Advanced Micro Devices, Inc.
[MD5.4743F161EF8E9851774A9CBBFC622EEA] [WIS][2013/04/16 16:24:10] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22af05.msi [752128] =>.Advanced Micro Devices, Inc.
[MD5.9E8A35A25F37DE63B3E3907E3CBEB731] [WIS][2013/04/16 16:24:18] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22af0c.msi [845824] =>.Advanced Micro Devices, Inc.
[MD5.A067346BECAAFA699BDD83CFEAD1260E] [WIS][2013/04/16 16:24:24] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22af13.msi [770560] =>.Advanced Micro Devices, Inc.
[MD5.DE8AA746CE1439DE9B8C458D8837826E] [WIS][2013/04/16 16:24:30] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22af1a.msi [760320] =>.Advanced Micro Devices, Inc.
[MD5.0C7D06CB65DCC2F8AC705C12325DCF0D] [WIS][2013/04/16 16:24:36] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22af21.msi [769536] =>.Advanced Micro Devices, Inc.
[MD5.134C93F052510E837470355C7F155681] [WIS][2013/04/16 16:24:46] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22af28.msi [869888] =>.Advanced Micro Devices, Inc.
[MD5.919F0281687D5519BAF04564AAB7ED48] [WIS][2013/04/16 16:25:06] (.Advanced Micro Devices, Inc. - Catalyst Control Center Utility 64.) -- C:\Windows\Installer\22af2f.msi [394752] =>.Advanced Micro Devices, Inc.
[MD5.ED2EB54B3E3EE6903CCDD038B2CC5C73] [WIS][2013/04/22 19:33:38] (.Advanced Micro Devices, Inc. - Catalyst Control Center.) -- C:\Windows\Installer\22af37.msi [13896192] =>.Advanced Micro Devices, Inc.
[MD5.9C63B6786B797DBC010A579E659241A4] [WIS][2013/04/16 16:37:30] (.Advanced Micro Devices, Inc. - Drag & Drop Transcoding.) -- C:\Windows\Installer\22af3f.msi [1487360] =>.Advanced Micro Devices, Inc.
[MD5.7E4BBC4428BA8E1970AA6B85E98B9D22] [WIS][2013/04/16 16:31:38] (.Advanced Micro Devices, Inc. - AMD Accelerated Video Transcoding INstallat.) -- C:\Windows\Installer\22af4c.msi [3553792] =>.Advanced Micro Devices, Inc.
[MD5.A0B1CC7C5C26044738798BA2E5E8C217] [WIS][2018/02/16 12:24:41] (.ClockworkMod.) -- C:\Windows\Installer\4605da.msi [17060864] =>.ClockworkMod
[MD5.9E153093A0AF0EDEE01C59A32E773C1B] [WIS][2018/06/08 03:16:58] (.SystemaRev - RevServicesX.) -- C:\Windows\Installer\5eb38d.msi [1794560] =>Trojan.Agent
[MD5.1C31DBDE092AEAFB2262B0B0F7313206] [WIS][2018/03/04 10:00:16] (.TechSmith Corporation - SnagIt.) -- C:\Windows\Installer\7e3eb3.msi [22375936] =>.TechSmith Corporation
[MD5.B5F699B6FE449BA1A58F5E2A301CE3B1] [WIS][2017/12/30 17:04:26] (.SD Association.) -- C:\Windows\Installer\9fa47c.msi [6295040] =>.SD Association
[MD5.112401693D088EB4F8DA9CA26867B54C] [WIS][2018/01/25 19:43:00] (.Facebook - Facebook Gameroom 1.20.6599.20957.) -- C:\Windows\Installer\a8d8c2.msi [52086784] =>.Facebook
[MD5.7F9BBDB60B98B6AB6A09446AFADA65CB] [WIS][2018/02/28 15:09:08] (.Adobe Systems Incorporated - Adobe ARM Installer.) -- C:\Windows\Installer\ccc810.msi [884736] =>.Adobe Systems Incorporated
[MD5.23B97F4BEDD554D3F629B60637AFC936] [WIS][2015/03/17 08:42:22] (.Adobe Systems Incorporated.) -- C:\Windows\Installer\e7e754.msi [2792960] =>.Adobe Systems Incorporated
[MD5.38DE187C53ECF739F66EC0AAC0D7EC65] [WIS][2016/09/13 17:50:24] (.Viber Media Inc. - Viber.) -- C:\Windows\Installer\ed737f.msi [106778624] =>.Viber Media Inc.
[MD5.E7DA5BF3A13B5299AE23DF94F8423FC6] [WIS][2018/01/25 02:05:44] (.Oracle Corporation - Oracle VM VirtualBox 5.2.6 installation pac.) -- C:\Windows\Installer\f573b7.msi [32104448] =>.Oracle Corporation
[MD5.04B537B3AB3D8FD3121C2F07CB853532] [WIS][2018/02/23 13:25:32] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\1b64fad.msp [103350272] =>.Adobe Systems, Incorporated
[MD5.E05CA6506E1D5ECE25152018D3FF00CE] [WIS][2018/05/12 06:05:37] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\cdb2ad.msp [7094272] =>.Adobe Systems, Incorporated
[MD5.B5B294D6E8CF1D6C89EC5F6CC580C8CE] [WIS][2017/04/05 02:14:23] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\e7e755.msp [92508160] =>.Adobe Systems, Incorporated

---\\ Search Tracing Registry Key (4) - 1s
HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASAPI32 =>.SUP.ByteFence
HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASMANCS =>.SUP.ByteFence
HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32 =>.SUP.ByteFence
HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS =>.SUP.ByteFence

---\\ FEATURE CONTROLE. (158) - 0s
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL]:WindowsAnytimeUpgradeUI.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_AJAX_CONNECTIONEVENTS]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:infopath.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:CCleaner64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_ISO_2022_JP_SNIFFING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPfewgsrv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGuiIT.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGUI.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLgPad.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLOGON.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:Scale_for_R3.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NAVIGATION_SOUNDS]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:ieuser.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK]:YahooMusicEngine.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:devenv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:dexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:helppane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS]:msfeedssync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HIGH_CONTRAST_BACKGROUND_IMAGES]:sidebar.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PROLOG]:msiexec.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:wm.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:cs.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:waol.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IVIEWOBJECTDRAW_DMLT9_WITH_GDI]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPARAMS]:helppane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS]:wlmail.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:outlook.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:sidebar.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_NINPUT_LEGACYMODE]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING]:communicator.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msimn.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:winmail.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SPELLCHECKING]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_STATUS_BAR_THROTTLING]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:winmail.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:msimn.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:outlook.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:infopath.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:winword.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:excel.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:powerpnt.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD]:msn.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBSOCKET]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XDOMAINREQUEST]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XMLHTTP]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:mshta.exe =>.Legitimate

---\\ Additional Scan (O88) (83) - 8s
C:\ProgramData\23aa6461-67c2-4c67-b567-a488a7e052c4 =>Heuristic.Suspect
C:\ProgramData\47765288-ac79-4c5b-b2c6-5c276ae6fc9c =>Heuristic.Suspect
C:\ProgramData\55e0cb0e-c21b-4f2d-ac71-2f3455b1b89f =>Heuristic.Suspect
C:\ProgramData\93f8d562-c26c-4cd2-b33f-096da5934c09 =>Heuristic.Suspect
HKLM\SYSTEM\CurrentControlSet\Services\ByteFenceService =>.SUP.ByteFence
HKLM\SYSTEM\CurrentControlSet\Services\Update service =>.SUP.PopcornTime
C:\Program Files (x86)\Popcorn Time\Updater.exe =>.SUP.PopcornTime
HKLM\SYSTEM\CurrentControlSet\Services\SystemUpdate64 =>Trojan.Agent
C:\Program Files\SystemaRev\RevServicesX\SystemUpdate64x.exe =>Trojan.Agent
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lgfehfbnofiffladdncogfobimealokp =>Toolbar.Ask
C:\Program Files\Mozilla Firefox\browser\features\{A5FD4672-4D73-4F90-A1C0-2ABD39DB2565}.xpi =>PUP.Optional.YouTubeAdBlock
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0D38E5A-7CF8-4105-8FE8-31B81443A114} =>PUP.Optional.YouTubeAdBlock
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4A0D29CD-7A99-4F5F-B81B-115A5BB25EC4} =>Trojan.Agent
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DriverDoc =>.SUP.Solvusoft
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E3605470-291B-44EB-8648-745EE356599A =>PUP.Optional.YouTubeAdBlock
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1 =>PUP.Optional.OneSystemCare
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Popcorn Time_is1 =>.SUP.PopcornTime
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UCBrowser =>.SUP.UCBrowser
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4D0A0750-B034-4DF8-97DE-26F1212AC2FF} =>.SUP.Solvusoft
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DriverDoc =>.SUP.Solvusoft
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\E3605470-291B-44EB-8648-745EE356599A =>PUP.Optional.YouTubeAdBlock
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\OneSystemCare_is1 =>PUP.Optional.OneSystemCare
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Popcorn Time_is1 =>.SUP.PopcornTime
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\UCBrowser =>.SUP.UCBrowser
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4D0A0750-B034-4DF8-97DE-26F1212AC2FF} =>.SUP.Solvusoft
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CloudNet =>Adware.MSIL
C:\Program Files\SystemaRev =>Trojan.Agent
C:\Program Files (x86)\OneSystemCare =>PUP.Optional.OneSystemCare
C:\Program Files (x86)\Popcorn Time =>.SUP.PopcornTime
C:\Program Files (x86)\Solvusoft =>.SUP.Solvusoft
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care =>PUP.Optional.OneSystemCare
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Popcorn Time =>.SUP.PopcornTime
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solvusoft =>.SUP.Solvusoft
C:\ProgramData\APN =>Toolbar.Ask
C:\ProgramData\ByteFence =>.SUP.ByteFence
C:\ProgramData\Solvusoft =>.SUP.Solvusoft
C:\Users\moh\AppData\Roaming\EpicNet Inc =>Adware.MSIL
C:\Users\moh\AppData\Roaming\One System Care =>PUP.Optional.OneSystemCare
C:\Users\moh\AppData\Roaming\OneSystemCare =>PUP.Optional.OneSystemCare
C:\Users\moh\AppData\Roaming\Solvusoft =>.SUP.Solvusoft
C:\Users\moh\AppData\Roaming\Tencent =>.SUP.Tencent
C:\Users\moh\AppData\Local\CatalinaGroup =>.SUP.CatalinaMarketing
C:\Users\moh\AppData\Local\PopcornTime =>.SUP.PopcornTime
C:\Users\moh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tencent =>.SUP.Tencent
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32 =>.SUP.Orphan
HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} =>.SUP.Orphan
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\PowerISO =>.SUP.Orphan
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\PowerISO =>.SUP.Orphan
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32 =>.SUP.Orphan
C:\ProgramData\93f8d562-c26c-4cd2-b33f-096da5934c09\OneSystemCare.exe =>PUP.Optional.OneSystemCare
[HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{164AA651-276F-4029-BA3D-A7E63D530886} =>.SUP.PopcornTime
[HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{E92F5623-875A-4A06-9324-2BED1C3509F8} =>.SUP.PopcornTime
C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe =>.SUP.PopcornTime
[HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{164F1791-2D2B-4CE1-928B-C280FC7B1C80} =>.SUP.PopcornTime
[HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{E1BCA704-AABF-41EA-87EA-11FB369DE5CF} =>.SUP.PopcornTime
[HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{97ED57BD-5E1F-4007-A736-A2FF1182C5EA} =>Adware.MSIL
HKLM\SOFTWARE\Wow6432Node\Classes\Installer\Products\DC92D0A499A7F5F48BB111A5B52BE54C =>Trojan.Agent
HKLM\SOFTWARE\Wow6432Node\Classes\Installer\Features\DC92D0A499A7F5F48BB111A5B52BE54C =>Trojan.Agent
C:\Windows\Installer\5eb38d.msi =>Trojan.Agent
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFenceService_RASAPI32 =>.SUP.ByteFence
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFenceService_RASMANCS =>.SUP.ByteFence
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFence_RASAPI32 =>.SUP.ByteFence
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFence_RASMANCS =>.SUP.ByteFence
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\002 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\003 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\004 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\006 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\009 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\011 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\012 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\014 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\015 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\016 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\017 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\018 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\019 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\020 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\021 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\022 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\023 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\024 =>.SUP.Temporary.Chrome
C:\Users\moh\AppData\Local\Google\Chrome\User Data\Default\File System\025 =>.SUP.Temporary.Chrome
NoIntegrityChecks is set. Check for possible unsigned driver with ZHPFix IntegrityChecksFix command. =>Riskware.Unsigned.Drivers

---\\ Summary of the elements found (22) - 0s
https://nicolascoolman.eu/2017/01/28/heuristic-suspect/ =>Heuristic.Suspect
https://nicolascoolman.eu/2017/03/13/superfluous-bytefence/ =>.SUP.ByteFence
https://nicolascoolman.eu/2017/02/26/superfluous-popcorntime/ =>.SUP.PopcornTime
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Trojan.Agent
https://nicolascoolman.eu/2017/02/28/toolbar-ask/ =>Toolbar.Ask
https://nicolascoolman.eu/2017/10/05/sup-browserextension/ =>.SUP.BrowserExtension
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.YouTubeAdBlock
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>BitTorrent (P2P)
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Solvusoft
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.OneSystemCare
https://nicolascoolman.eu/2017/03/04/superfluous-ucbrowser/ =>.SUP.UCBrowser
https://nicolascoolman.eu/2017/09/13/adware-msil/ =>Adware.MSIL
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.DriverUpdatePlus
https://nicolascoolman.eu/2017/03/12/superfluous-lavasoftwebcompanion/ =>PUP.Optional.LavasoftWebCompanion
https://nicolascoolman.eu/2017/09/19/adware-installcore-3/ =>Adware.InstallCore
https://nicolascoolman.eu/2017/12/22/sup-downloader/ =>.SUP.Downloader
https://nicolascoolman.eu/2017/02/23/tencentadressbar/ =>.SUP.Tencent
https://nicolascoolman.eu/2017/09/16/sup-catalinamarketing/ =>.SUP.CatalinaMarketing
https://nicolascoolman.eu/2017/10/03/sup-systemhealer/ =>.SUP.SystemHealer
https://nicolascoolman.eu/2017/09/12/origine-lignes-orphelines/ =>.SUP.Orphan
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Temporary.Chrome
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Riskware.Unsigned.Drivers

~ Unselected Options: O82,
~ End of the scan, 20223 items in 10mn37s (2027)(0)

Publicité


Signaler le contenu de ce document

Publicité