cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2018.9.14.172 By Nicolas Coolman (2018/09/14)
~ Run by moez (Administrator) (2018/09/18 22:15:56)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Illegal
~ State version: Version OK
~ Mode: Scan
~ Report: C:\Users\moez\Desktop\ZHPDiag.txt
~ Report: C:\Users\moez\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Deactivate
~ System startup: Normal (Normal boot)
Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601) =>.Microsoft Corporation

---\\ Internet Browsers (4) - 2s
~ GCIE: Google Chrome v68.0.3440.106
~ MFIE: Mozilla Firefox 61.0.1 (x64 en-US)
~ MFIE: Opera 42.0.2393.137
~ MSIE: Internet Explorer v10.0.9200.16521

---\\ Windows Product Information (4) - 3s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : KO
Windows Activation Technologies : KO

---\\ System protection software (1) - 6s
Kaspersky Secure Connection v18.0.0.405 (Protection)

---\\ Surveillance software (3) - 6s
~ Adobe Flash Player 31 NPAPI (Surveillance)
~ Adobe Flash Player 31 PPAPI (Surveillance)
~ Adobe Acrobat Reader DC (Surveillance)

---\\ System optimization software (1) - 6s
~ CCleaner v5.21 (Optimisation)

---\\ Sharing software PeerToPeer (1) - 6s
~ µTorrent v3.5.4.44520 (P2P)

---\\ Informations on the system (6) - 0s
~ Operating System: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 4086.36 MB (19% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 1 GB (0%) free of 153 GB : ATTENTION =>Warning Disk Space

---\\ Connection to the system mode (3) - 0s
~ Computer Name: MOEZ-PC
~ User Name: moez
~ Logged in as Administrator

---\\ Enumeration of the disk units (4) - 0s
~ Drive C: has 1 GB free of 153 GB (System)
~ Drive D: has 11 GB free of 233 GB
~ Drive E: has 20 GB free of 217 GB
~ Drive F: has 21 GB free of 319 GB

---\\ State of the Windows Security Center (10) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Search Generic System Files (24) - 3s
[MD5.AC4C51EB24AA95B77F705AB159189E24] - 21/11/2010 - (.Microsoft Corporation - Windows Explorer.) -- C:\Windows\Explorer.exe [2872320] =>.Microsoft Corporation
[MD5.DD81D91FF3B0763C392422865C9AC12E] - 14/07/2009 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe [45568] =>.Microsoft Corporation
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - 14/07/2009 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\Windows\System32\Wininit.exe [129024] =>.Microsoft Corporation
[MD5.69F1D418B4C4EC23033D598E4CBC6B73] - 23/03/2017 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\Windows\System32\wininet.dll [2240512] =>.Microsoft Corporation
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - 21/11/2010 - (.Microsoft Corporation - Windows Logon Application.) -- C:\Windows\System32\Winlogon.exe [390656] =>.Microsoft Corporation
[MD5.067FA52BFB59A56110A12312EF9AF243] - 21/11/2010 - (.Microsoft Corporation - Software Licensing Library.) -- C:\Windows\System32\sppcomapi.dll [232448] =>.Microsoft Corporation
[MD5.A52B6CC24063CC83C78C0E6F24DEEC01] - 21/11/2010 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\System32\dnsapi.dll [357888] =>.Microsoft Corporation
[MD5.59DF156711A76BCB993253EC6C9BBF41] - 21/11/2010 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\Syswow64\dnsapi.dll [270336] =>.Microsoft Corporation
[MD5.D31DC7A16DEA4A9BAF179F3D6FBDB38C] - 21/11/2010 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [499712] =>.Microsoft Corporation
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - 14/07/2009 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [24128] =>.Microsoft Corporation
[MD5.B8BD2BB284668C84865658C77574381A] - 14/07/2009 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [92160] =>.Microsoft Corporation
[MD5.F036CE71586E93D94DAB220D7BDF4416] - 21/11/2010 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [147456] =>.Microsoft Corporation
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - 21/11/2010 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [102400] =>.Microsoft Corporation
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - 21/11/2010 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [122368] =>.Microsoft Corporation
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - 14/07/2009 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\Windows\System32\drivers\i8042prt.sys [105472] =>.Microsoft Corporation
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - 14/07/2009 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [116224] =>.Microsoft Corporation
[MD5.FAF015B07E3A2874A790A39B7D2C579F] - 21/11/2010 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [158208] =>.Microsoft Corporation
[MD5.09594D1089C523423B32A4229263F068] - 21/11/2010 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [261632] =>.Microsoft Corporation
[MD5.05D78AA5CB5F3F5C31160BDB955D0B7C] - 21/11/2010 - (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\drivers\ntfs.sys [1659776] =>.Microsoft Corporation
[MD5.0086431C29C35BE1DBC43F52CC273887] - 14/07/2009 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\Windows\System32\drivers\Parport.sys [97280] =>.Microsoft Corporation
[MD5.471815800AE33E6F1C32FB1B97C490CA] - 21/11/2010 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [129536] =>.Microsoft Corporation
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - 14/07/2009 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [93184] =>.Microsoft Corporation
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - 21/11/2010 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [119296] =>.Microsoft Corporation
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - 21/11/2010 - (.Microsoft Corporation - Volume Shadow Copy Driver.) -- C:\Windows\System32\drivers\volsnap.sys [295808] =>.Microsoft Corporation

---\\ No disabled Windows Services (69) - 11s
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
O23 - Service: ASP.NET State Service (aspnet_state) . (.Microsoft Corporation - Microsoft ASP.NET State Server.) - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe =>.Microsoft Corporation®
O23 - Service: C:\Windows\System32\audiosrv.dll (AudioEndpointBuilder) . (.Microsoft Corporation - Windows Audio Service.) - C:\Windows\System32\Audiosrv.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\audiosrv.dll (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) - C:\Windows\System32\Audiosrv.dll =>.Microsoft Corporation
O23 - Service: Kaspersky Anti-Virus Service 19.0.0 (AVP19.0.0) . (.AO Kaspersky Lab - Kaspersky Anti-Virus.) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avp.exe =>.Kaspersky Lab®
O23 - Service: C:\Windows\System32\bfe.dll (BFE) . (.Microsoft Corporation - Base Filtering Engine.) - C:\Windows\System32\bfe.dll =>.Microsoft Corporation
O23 - Service: Bonjour Service (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.®
O23 - Service: Microsoft .NET Framework NGEN v4.0.30319_X86 (clr_optimization_v4.0.30319_32) . (.Microsoft Corporation - .NET Runtime Optimization Service.) - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe {33000000FA34E0481131F81E070001000000FA} =>.Microsoft Corporation
O23 - Service: Microsoft .NET Framework NGEN v4.0.30319_X64 (clr_optimization_v4.0.30319_64) . (.Microsoft Corporation - .NET Runtime Optimization Service.) - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe {33000000FA34E0481131F81E070001000000FA} =>.Microsoft Corporation
O23 - Service: CodeMeter Runtime Server (CodeMeter.exe) . (.WIBU-SYSTEMS AG - CodeMeter Runtime Server.) - C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe =>.WIBU-SYSTEMS AG®
O23 - Service: Connect2 Hotspot Service (connect2hotspot) . (.Lenovo - Connect2 Service.) - C:\Program Files (x86)\Lenovo\Connect2\Connect2.Service.exe =>.LENOVO®
O23 - Service: C:\Windows\System32\cryptsvc.dll (CryptSvc) . (.Microsoft Corporation - Cryptographic Services.) - C:\Windows\System32\cryptsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\dhcpcore.dll (Dhcp) . (.Microsoft Corporation - DHCP Client Service.) - C:\Windows\System32\dhcpcore.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\dnsapi.dll (Dnscache) . (.Microsoft Corporation - DNS Caching Resolver Service.) - C:\Windows\System32\dnsrslvr.dll =>.Microsoft Corporation
O23 - Service: egGetSvc (egGetSvc) . (.Copyright (C) EagleGet 2014~2015 - EGMonitor.) - C:\Program Files (x86)\EagleGet\EGMonitor.exe =>.Beijing Pu Technology Limited®
O23 - Service: Energy Server Service WILLAMETTE (ESRV_SVC_WILLAMETTE) . (.Copyright (C) 2016 Intel Corporation. All rights rese - Intel(R) System Usage Report.) - C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe =>.Intel(R) Software Development Products®
O23 - Service: C:\Windows\System32\wevtsvc.dll (eventlog) . (.Microsoft Corporation - Host Process for Windows Services.) - C:\Windows\System32\svchost.exe =>.Microsoft Corporation
O23 - Service: @comres.dll,-2450 (EventSystem) . (.Microsoft Corporation - COM+.) - C:\Windows\System32\es.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\FntCache.dll (FontCache) . (.Microsoft Corporation - Windows Font Cache Service.) - C:\Windows\System32\FntCache.dll =>.Microsoft Corporation
O23 - Service: @gpapi.dll,-112 (gpsvc) . (.Microsoft Corporation - Group Policy Client.) - C:\Windows\System32\gpsvc.dll =>.Microsoft Corporation
O23 - Service: خدمة Google Update (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
O23 - Service: HP LaserJet Service (HP LaserJet Service) . (.HP - HP LaserJet Service.) - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe =>.HP
O23 - Service: HP SI Service (HPSIService) . (.HP - HP Smart-Install Service.) - C:\Windows\system32\HPSIsvc.exe =>.HP
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation - igfxCUIService Module.) - C:\Windows\System32\igfxCUIService.exe =>.Intel Corporation
O23 - Service: C:\Windows\System32\ikeext.dll (IKEEXT) . (.Microsoft Corporation - IKE extension.) - C:\Windows\System32\ikeext.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\IPBusEnum.dll (IPBusEnum) . (.Microsoft Corporation - PnP-X IP Bus Enumerator DLL.) - C:\Windows\System32\ipbusenum.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\iphlpsvc.dll (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) - C:\Windows\System32\iphlpsvc.dll =>.Microsoft Corporation
O23 - Service: Kaspersky Secure Connection خدمة 2.0.0 (KSDE2.0.0) . (.AO Kaspersky Lab - Kaspersky Secure Connection.) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0 (1)\ksde.exe =>.Kaspersky Lab®
O23 - Service: C:\Windows\System32\srvsvc.dll (LanmanServer) . (.Microsoft Corporation - Server Service DLL.) - C:\Windows\System32\srvsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wkssvc.dll (LanmanWorkstation) . (.Microsoft Corporation - Workstation Service DLL.) - C:\Windows\System32\wkssvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\lmhsvc.dll (lmhosts) . (.Microsoft Corporation - TCPIP NetBios Transport Services DLL.) - C:\Windows\System32\lmhsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\mmcss.dll (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) - C:\Windows\System32\mmcss.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\FirewallAPI.dll (MpsSvc) . (.Microsoft Corporation - Microsoft Protection Service.) - C:\Windows\System32\mpssvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\iscsidsc.dll (MSiSCSI) . (.Microsoft Corporation - iSCSI Discovery service.) - C:\Windows\System32\iscsiexe.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\nlasvc.dll (NlaSvc) . (.Microsoft Corporation - Network Location Awareness 2.) - C:\Windows\System32\nlasvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\nsisvc.dll (nsi) . (.Microsoft Corporation - Network Store Interface RPC server.) - C:\Windows\System32\nsisvc.dll =>.Microsoft Corporation
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) . (.NVIDIA Corporation - NVIDIA Container.) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation®
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) . (.NVIDIA Corporation - NVIDIA Container.) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe =>.NVIDIA Corporation®
O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) . (.NVIDIA Corporation - NVIDIA Container.) - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe =>.NVIDIA Corporation®
O23 - Service: C:\Windows\System32\pcasvc.dll (PcaSvc) . (.Microsoft Corporation - Program Compatibility Assistant Service.) - C:\Windows\System32\pcasvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\umpnpmgr.dll (PlugPlay) . (.Microsoft Corporation - User-mode Plug-and-Play Service.) - C:\Windows\System32\umpnpmgr.dll =>.Microsoft Corporation
O23 - Service: PnkBstrA (PnkBstrA) . (...) - C:\Windows\System32\PnkBstrA.exe (.not file.) =>.PunkBuster Games
O23 - Service: C:\Windows\System32\umpo.dll (Power) . (.Microsoft Corporation - User-mode Power Service.) - C:\Windows\System32\umpo.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\profsvc.dll (ProfSvc) . (.Microsoft Corporation - ProfSvc.) - C:\Windows\System32\profsvc.dll =>.Microsoft Corporation
O23 - Service: QMEmulatorService (QMEmulatorService) . (.Tencent - 腾讯手游助手.) - e:\Program Files\TxGameAssistant\AppMarket\QMEmulatorService.exe =>.SUP.Tencent
O23 - Service: C:\Windows\system32\RpcEpMap.dll (RpcEptMapper) . (.Microsoft Corporation - RPC Endpoint Mapper.) - C:\Windows\System32\RpcEpMap.dll =>.Microsoft Corporation
O23 - Service: @oleres.dll,-5010 (RpcSs) . (.Microsoft Corporation - Distributed COM Services.) - C:\Windows\System32\rpcss.dll =>.Microsoft Corporation
O23 - Service: Realtek Audio Service (RtkAudioService) . (.Realtek Semiconductor - Realtek Audio Service.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe =>.Realtek Semiconductor Corp®
O23 - Service: C:\Windows\System32\schedsvc.dll (Schedule) . (.Microsoft Corporation - Task Scheduler Service.) - C:\Windows\System32\schedsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\Sens.dll (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) - C:\Windows\System32\Sens.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\shsvcs.dll (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) - C:\Windows\System32\shsvcs.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\spoolsv.exe,-1 (Spooler) . (.Microsoft Corporation - Spooler SubSystem App.) - C:\Windows\System32\spoolsv.exe =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\sppsvc.exe,-101 (sppsvc) . (.Microsoft Corporation - Microsoft Software Protection Platform Serv.) - C:\Windows\System32\sppsvc.exe =>.Microsoft Corporation
O23 - Service: SQL Server VSS Writer (SQLWriter) . (.Microsoft Corporation - SQL Server VSS Writer - 64 Bit.) - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe =>.Microsoft Corporation®
O23 - Service: C:\Windows\System32\wiaservc.dll (stisvc) . (.Microsoft Corporation - Still Image Devices Service.) - C:\Windows\System32\wiaservc.dll =>.Microsoft Corporation
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) . (.Synaptics Incorporated - 64-bit Synaptics Pointing Enhance Service.) - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe =>.Synaptics Incorporated®
O23 - Service: C:\Windows\System32\sysmain.dll (SysMain) . (.Microsoft Corporation - Superfetch Service Host.) - C:\Windows\System32\sysmain.dll =>.Microsoft Corporation
O23 - Service: Intel(R) System Usage Report Service SystemUsageReportSvc_W (SystemUsageReportSvc_WILLAMETTE) . (.Copyright (C) 2016 Intel Corporation. All rights rese - Intel(R) System Usage Report.) - C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe =>.Intel(R) Software Development Products®
O23 - Service: C:\Windows\System32\themeservice.dll (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) - C:\Windows\System32\themeservice.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\dwm.exe,-2000 (UxSms) . (.Microsoft Corporation - Microsoft User Experience Session Managemen.) - C:\Windows\System32\uxsms.dll =>.Microsoft Corporation
O23 - Service: VMware Authorization Service (VMAuthdService) . (.VMware, Inc. - VMware Authorization Service.) - E:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe =>.VMware, Inc.®
O23 - Service: VMware DHCP Service (VMnetDHCP) . (.VMware, Inc. - VMware VMnet DHCP service.) - C:\Windows\SysWOW64\vmnetdhcp.exe =>.VMware, Inc.®
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) . (.VMware, Inc. - VMware USB Arbitration Service.) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe =>.VMware, Inc.®
O23 - Service: VMware NAT Service (VMware NAT Service) . (.VMware, Inc. - VMware NAT Service.) - C:\Windows\SysWOW64\vmnat.exe =>.VMware, Inc.®
O23 - Service: C:\Windows\System32\wbem\wmisvc.dll (Winmgmt) . (.Microsoft Corporation - WMI.) - C:\Windows\System32\wbem\WMIsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wlansvc.dll (Wlansvc) . (.Microsoft Corporation - Windows WLAN AutoConfig Service DLL.) - C:\Windows\System32\wlansvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wscsvc.dll (wscsvc) . (.Microsoft Corporation - Windows Security Center Service.) - C:\Windows\System32\wscsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\SearchIndexer.exe,-103 (WSearch) . (.Microsoft Corporation - Microsoft Windows Search Indexer.) - C:\Windows\System32\SearchIndexer.exe =>.Microsoft Corporation
O23 - Service: Windows Driver Foundation - User-mode Driver Framework (wudfsvc) . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) - C:\Windows\System32\WUDFSvc.dll =>.Microsoft Corporation

---\\ Services not Microsoft (SR=Run, SS=Stop) (34) - 37s
SR - Auto [21/03/2018] [ 83984] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
SS - Demand [12/09/2018] [ 335872] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated®
SR - Auto [28/02/2018] [ 619640] Kaspersky Anti-Virus Service 19.0.0 (AVP19.0.0) . (.AO Kaspersky Lab.) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avp.exe =>.Kaspersky Lab®
SR - Auto [12/08/2015] [ 462096] Bonjour Service (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.®
SR - Auto [19/07/2012] [ 2568120] CodeMeter Runtime Server (CodeMeter.exe) . (.WIBU-SYSTEMS AG.) - C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe =>.WIBU-SYSTEMS AG®
SR - Auto [20/10/2016] [ 101032] Connect2 Hotspot Service (connect2hotspot) . (.Lenovo.) - C:\Program Files (x86)\Lenovo\Connect2\Connect2.Service.exe =>.LENOVO®
SS - Demand [04/06/2015] [ 280680] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe =>.Intel Corporation - pGFX®
SR - Auto [17/05/2018] [ 255992] egGetSvc (egGetSvc) . (.Copyright (C) EagleGet 2014~2015.) - C:\Program Files (x86)\EagleGet\EGMonitor.exe =>.Beijing Pu Technology Limited®
SR - Auto [08/06/2016] [ 416408] Energy Server Service WILLAMETTE (ESRV_SVC_WILLAMETTE) . (.Copyright (C) 2016 Intel Corporation. All rights rese.) - C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe =>.Intel(R) Software Development Products®
SR - Auto [27/07/2016] [ 154440] خدمة Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [27/07/2016] [ 154440] خدمة Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SR - Auto [21/01/2011] [ 145920] HP LaserJet Service (HP LaserJet Service) . (.HP.) - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe =>.HP
SR - Auto [24/11/2010] [ 127800] HP SI Service (HPSIService) . (.HP.) - C:\Windows\system32\HPSIsvc.exe =>.Hewlett-Packard Company®
SS - Demand [24/04/2012] [ 169752] Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe =>.Intel Corporation®
SR - Auto [04/06/2015] [ 319080] Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation.) - C:\Windows\System32\igfxCUIService.exe =>.Intel Corporation - pGFX®
SS - Demand [22/01/2018] [ 673080] خدمة iPod (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe =>.Apple Inc.®
SS - Demand [31/08/2018] [ 416560] klvssbridge64_19.0.0 (klvssbridge64_19.0.0) . (.AO Kaspersky Lab.) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\vssbridge64.exe =>.Kaspersky Lab®
SR - Auto [24/01/2017] [ 354672] Kaspersky Secure Connection خدمة 2.0.0 (KSDE2.0.0) . (.AO Kaspersky Lab.) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0 (1)\ksde.exe =>.Kaspersky Lab®
SS - Demand [28/07/2018] [ 194512] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation®
SR - Auto [14/03/2018] [ 522688] NVIDIA LocalSystem Container (NvContainerLocalSystem) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation®
SS - Demand [14/03/2018] [ 522688] NVIDIA NetworkService Container (NvContainerNetworkService) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation®
SR - Auto [16/03/2018] [ 464272] NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe =>.NVIDIA Corporation®
SR - Auto [14/03/2018] [ 469952] NVIDIA Telemetry Container (NvTelemetryContainer) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe =>.NVIDIA Corporation®
SR - Auto [21/06/2018] [ 342776] QMEmulatorService (QMEmulatorService) . (.Tencent.) - e:\Program Files\TxGameAssistant\AppMarket\QMEmulatorService.exe =>.SUP.Tencent
SR - Auto [07/10/2015] [ 307456] Realtek Audio Service (RtkAudioService) . (.Realtek Semiconductor.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe =>.Realtek Semiconductor Corp®
SS - Demand [23/07/2016] [ 837312] Steam Client Service (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe =>.Valve®
SR - Auto [02/07/2015] [ 237736] SynTPEnh Caller Service (SynTPEnhService) . (.Synaptics Incorporated.) - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe =>.Synaptics Incorporated®
SR - Auto [08/06/2016] [ 117400] Intel(R) System Usage Report Service SystemUsageReportSvc_W (SystemUsageReportSvc_WILLAMETTE) . (.Copyright (C) 2016 Intel Corporation. All rights rese.) - C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe =>.Intel(R) Software Development Products®
SS - Demand [08/06/2016] [ 416408] User Energy Server Service WILLAMETTE (USER_ESRV_SVC_WILLAMETTE) . (.Copyright (C) 2016 Intel Corporation. All rights rese.) - C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe =>.Intel(R) Software Development Products®
SS - Demand [11/09/2017] [ 33224] SHAREit Hotspot Service (uSHAREitSvc) . (.SHAREit Technologies Co.Ltd.) - C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.Service.exe =>.SHAREit Technologies Co.Ltd®
SR - Auto [06/09/2016] [ 97864] VMware Authorization Service (VMAuthdService) . (.VMware, Inc..) - E:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe =>.VMware, Inc.®
SR - Auto [06/09/2016] [ 366664] VMware DHCP Service (VMnetDHCP) . (.VMware, Inc..) - C:\Windows\SysWOW64\vmnetdhcp.exe =>.VMware, Inc.®
SR - Auto [06/09/2016] [ 916040] VMware USB Arbitration Service (VMUSBArbService) . (.VMware, Inc..) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe =>.VMware, Inc.®
SR - Auto [06/09/2016] [ 400968] VMware NAT Service (VMware NAT Service) . (.VMware, Inc..) - C:\Windows\SysWOW64\vmnat.exe =>.VMware, Inc.®

---\\ Task Planned Automatically (Register) (52) - 12s
O38 - TASK: {1674388E-BBBD-4A2C-965E-591FED5C7640} [64Bits][\elbyExecuteWithUAC] - (.Copyright (C) 2008 Elaborate Bytes AG - ElbyCDIO install helper process.) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ExecuteWithUAC.exe [77824]
O38 - TASK: {1BF2F06E-5737-474D-8156-03B11BA8698E} [64Bits][\GoogleUpdateTaskMachineUA] - (.Google Inc. - Google Installer.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440] =>.Google Inc.
O38 - TASK: {2E8FD1D0-58BA-4513-9DD8-EBF0C9567DC1} [64Bits][\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] - (.NVIDIA Corporation - NVIDIA telemetry monitor.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [510912] =>.NVIDIA Corporation
O38 - TASK: {2EB77A9A-C733-4932-ACED-0139D7A11DB0} [64Bits][\HPLJCustParticipation] - (.Hewlett Packard - HPUTSCH.) -- C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe [42808] =>.Hewlett Packard
O38 - TASK: {354DF94F-9454-4722-BF7E-8FEC3534F846} [64Bits][\CCleanerSkipUAC] - (.Piriform Ltd - CCleaner.) -- E:\Program Files (x86)\cc\CCleaner.exe [6854360] =>.Piriform Ltd
O38 - TASK: {3C0F49C9-0870-40D9-8F45-FFBADFDFCD2E} [64Bits][\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe [469952] =>.NVIDIA Corporation
O38 - TASK: {3C6FFD3E-DD04-4353-AEDC-2873B3FFE84A} [64Bits][\klcp_update] - (.KLite Inc - Setup/Uninstall.) -- C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1179648] =>.KLite Inc
O38 - TASK: {3E703708-83BD-47FF-AEFA-67DC083DCD34} [64Bits][\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] - (.NVIDIA Corporation - NVIDIA crash and telemetry reporter.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [757184] =>.NVIDIA Corporation
O38 - TASK: {4BA147D3-CA1B-4836-A2FB-0103F1EADC95} [64Bits][\{B039DE40-B7CA-4229-B0A3-E66B4325AC75}] - (.Echobit LLC - Evolve Setup.) -- C:\Users\moez\Documents\EGDownloads\New folder (4)\zero\New folder\EvolveSetup.exe [3258328] =>.Echobit LLC
O38 - TASK: {61B22C90-D9A9-48D5-A3CB-569D91E1D108} [64Bits][\Opera scheduled Autoupdate 1497547862] - (.Opera Software - Opera Internet Browser.) -- E:\Program Files (x86)\opera\launcher.exe [1139800] =>.Opera Software
O38 - TASK: {6A644A49-1992-45AB-8557-48A83F8FA6E0} [64Bits][\Intel\Intel Telemetry 2] - (.Intel Corporation - Intel(R) Product Improvement Program.) -- C:\Program Files\Intel\Telemetry 2.0\lrio.exe [1741576] =>.Intel Corporation
O38 - TASK: {7CEB8BC7-2B81-46AD-8BA7-4052FECA3EEE} [64Bits][\Opera scheduled Autoupdate 1520535652] - (.Opera Software - Opera Internet Browser.) -- E:\Program Files (x86)\opera\launcher.exe [1139800] =>.Opera Software
O38 - TASK: {926C8299-BEFB-41A8-8191-FDC1C6F13521} [64Bits][\Adobe Acrobat Update Task] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1187864] =>.Adobe Systems Incorporated
O38 - TASK: {A8EC700B-D81D-4203-8970-7F91E54615B9} [64Bits][\{AA2139A8-50FB-4EAE-B611-E32ED2453FEC}] - (.TeamExtreme - Minecraft 1.10 Installation.) -- F:\New folder (11)\Minecraft 1.9.0.exe [231306556] =>.TeamExtreme
O38 - TASK: {AF5C363D-D0D8-4AF9-91F1-DC9F1943A0C5} [64Bits][\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] - (.NVIDIA Corporation - NVIDIA GeForce Experience.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2069952] =>.NVIDIA Corporation
O38 - TASK: {B26BF62A-F4AD-4358-BB59-D75D55F87376} [64Bits][\{3B7CD587-2EC5-49D5-8D52-32B6DF4CCD09}] - (.InstallShield Software Corporation - InstallShield® unInstaller.) -- C:\Windows\IsUninst.exe [327168] =>.InstallShield Software Corporation
O38 - TASK: {BA91011E-5289-463C-AD7D-831AB0137D6F} [64Bits][\GoogleUpdateTaskMachineCore] - (.Google Inc. - Google Installer.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440] =>.Google Inc.
O38 - TASK: {C6D28AC1-F9A8-49B0-BE2E-7BA15638797E} [64Bits][\Adobe Flash Player PPAPI Notifier] - (.Adobe Systems Incorporated - Adobe® Flash® Player Installer/Uninstaller.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_108_pepper.exe [1454592] =>.Adobe Systems Incorporated
O38 - TASK: {C9841F00-78B5-4C77-8D72-E124A06B5F93} [64Bits][\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] - (.NVIDIA Corporation - NVIDIA nodejs launcher.) -- C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [976832] =>.NVIDIA Corporation
O38 - TASK: {CDCBDB69-C767-46F9-A218-C390894F5641} [64Bits][\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] - (.NVIDIA Corporation - NVIDIA driver profile updater.) -- C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [662464] =>.NVIDIA Corporation
O38 - TASK: {D518506E-0CA7-4897-8190-BB31D4A52C19} [64Bits][\Adobe Flash Player NPAPI Notifier] - (.Adobe Systems Incorporated - Adobe® Flash® Player Installer/Uninstaller.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_108_Plugin.exe [1454080] =>.Adobe Systems Incorporated
O38 - TASK: {D9F2F3AB-734C-4D28-BD52-F7A3BAD22527} [64Bits][\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}] - (.AO Kaspersky Lab - Kaspersky Upgrade Launcher.) -- C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [791232] =>.AO Kaspersky Lab
O38 - TASK: {DB72C326-012D-483E-B1B2-35C232835571} [64Bits][\Java Platform SE Auto Updater] - (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [588704] =>.Oracle Corporation
O38 - TASK: {EC6EA8AE-4A71-4348-8AA5-61D2E42B2AA6} [64Bits][\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [522688] =>.NVIDIA Corporation
O38 - TASK: {F20C4097-9F51-4F35-ACAD-C7993A755DBF} [64Bits][\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] - (.NVIDIA Corporation - NVIDIA driver profile updater.) -- C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [662464] =>.NVIDIA Corporation
O38 - TASK: {FC97C804-F6C7-41FC-B73B-C62049C5C6C8} [64Bits][\Adobe Flash Player Updater] - (.Adobe Systems Incorporated - Adobe® Flash® Player Update Service 31.0 r0.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335872] =>.Adobe Systems Incorporated
C:\Windows\System32\Tasks\elbyExecuteWithUAC - (.Copyright (C) 2008 Elaborate Bytes AG.) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ExecuteWithUAC.exe [/e]
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [/ua ./ua] =>.Google Inc.
C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [] =>.NVIDIA Corporation
C:\Windows\System32\Tasks\HPLJCustParticipation - (.Hewlett Packard.) -- C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe [] =>.Hewlett Packard
C:\Windows\System32\Tasks\CCleanerSkipUAC - (.Piriform Ltd.) -- E:\Program Files (x86)\cc\CCleaner.exe [$(Arg0)] =>.Piriform Ltd
C:\Windows\System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe [-d "C:\Program Files (x86)\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\] =>.NVIDIA Corporation
C:\Windows\System32\Tasks\klcp_update - (.KLite Inc.) -- C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [/verysilent ./verysilent] =>.KLite Inc
C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [] =>.NVIDIA Corporation
C:\Windows\System32\Tasks\{B039DE40-B7CA-4229-B0A3-E66B4325AC75} - (.Echobit LLC.) -- C:\Users\moez\Documents\EGDownloads\New folder (4)\zero\New folder\EvolveSetup.exe [C:\Users\moez\Documents\EGDownloads\New folder (4)\zero\New folder\EvolveSetup.exe] =>.Echobit LLC
C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1497547862 - (.Opera Software.) -- E:\Program Files (x86)\opera\launcher.exe [--scheduledautoupdate .--scheduledautoupdate] =>.Opera Software
C:\Windows\System32\Tasks\Intel\Intel Telemetry 2 - (.Intel Corporation.) -- C:\Program Files\Intel\Telemetry 2.0\lrio.exe [] =>.Intel Corporation
C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1520535652 - (.Opera Software.) -- E:\Program Files (x86)\opera\launcher.exe [--scheduledautoupdate .--scheduledautoupdate] =>.Opera Software
C:\Windows\System32\Tasks\Adobe Acrobat Update Task - (.Adobe Systems Incorporated.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [] =>.Adobe Systems Incorporated
C:\Windows\System32\Tasks\{AA2139A8-50FB-4EAE-B611-E32ED2453FEC} - (.TeamExtreme.) -- F:\New folder (11)\Minecraft 1.9.0.exe [F:\New folder (11)\Minecraft 1.9.0.exe] =>.TeamExtreme
C:\Windows\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [] =>.NVIDIA Corporation
C:\Windows\System32\Tasks\{3B7CD587-2EC5-49D5-8D52-32B6DF4CCD09} - (.InstallShield Software Corporation.) -- C:\Windows\IsUninst.exe [C:\Windows\IsUninst.exe] =>.InstallShield Software Corporation
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [/c] =>.Google Inc.
C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_108_pepper.exe [-check pepperplugin.-check] =>.Adobe Systems Incorporated
C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [--launcher=TaskScheduler] =>.NVIDIA Corporation
C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [] =>.NVIDIA Corporation
C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_108_Plugin.exe [-check plugin.-check] =>.Adobe Systems Incorporated
C:\Windows\System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} - (.AO Kaspersky Lab.) -- C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [/waitUpgrade] =>.AO Kaspersky Lab
C:\Windows\System32\Tasks\Java Platform SE Auto Updater - (.Oracle Corporation.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [] =>.Oracle Corporation
C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [-d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContain] =>.NVIDIA Corporation
C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [] =>.NVIDIA Corporation
C:\Windows\System32\Tasks\Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [] =>.Adobe Systems Incorporated

---\\ Auto loading programs from Registry and folders (12) - 1s
O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Realtek HD Audio Manager.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp®
O4 - HKCU\..\Run: [EagleGet] . (.EagleGet.com - EagleGet Free Downloader.) -- C:\Program Files (x86)\EagleGet\EagleGet.exe =>.Beijing Pu Technology Limited®
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] . (.Microsoft Corporation - Sticky Notes.) -- C:\Windows\System32\StikyNot.exe =>.Microsoft Corporation
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_30DD00273E030B8888A423FD94401938] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - HKCU\..\Run: [BitTorrent] . (.BitTorrent Inc. - BitTorrent.) -- C:\Users\moez\AppData\Roaming\BitTorrent\BitTorrent.exe =>.BitTorrent Inc®
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle America, Inc.®
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-318700280-1262799068-3410121159-1000\..\Run: [EagleGet] . (.EagleGet.com - EagleGet Free Downloader.) -- C:\Program Files (x86)\EagleGet\EagleGet.exe =>.Beijing Pu Technology Limited®
O4 - HKUS\S-1-5-21-318700280-1262799068-3410121159-1000\..\Run: [RESTART_STICKY_NOTES] . (.Microsoft Corporation - Sticky Notes.) -- C:\Windows\System32\StikyNot.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-318700280-1262799068-3410121159-1000\..\Run: [GoogleChromeAutoLaunch_30DD00273E030B8888A423FD94401938] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - HKUS\S-1-5-21-318700280-1262799068-3410121159-1000\..\Run: [BitTorrent] . (.BitTorrent Inc. - BitTorrent.) -- C:\Users\moez\AppData\Roaming\BitTorrent\BitTorrent.exe =>.BitTorrent Inc®

---\\ Process running (56) - 5s
[MD5.9AD9E0731AD2A89B0DEC4EE2A72AF70D] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [464272] [PID.536] =>.NVIDIA Corporation®
[MD5.3051E3530952CD960C9A5A5AF4725049] - (.Intel Corporation - igfxCUIService Module.) -- C:\Windows\System32\igfxCUIService.exe [319080] [PID.1268] =>.Intel Corporation
[MD5.7E45C7B61C4A3865608418BF4077DF82] - (.Realtek Semiconductor - Realtek Audio Service.) -- C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [307456] [PID.1308] =>.Realtek Semiconductor Corp®
[MD5.1E9965D9AB360142D11B3E08818B02F7] - (.Realtek Semiconductor - HD Audio Background Process.) -- C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744] [PID.1348] =>.Realtek Semiconductor Corp®
[MD5.9AD9E0731AD2A89B0DEC4EE2A72AF70D] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [464272] [PID.1644] =>.NVIDIA Corporation®
[MD5.AE86FE2A70C377C0F1AD5B20E66F4C2F] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [83984] [PID.2012] =>.Adobe Systems, Incorporated®
[MD5.E5D432E9BCEB5CB71B71258F1046DD67] - (.AO Kaspersky Lab - Kaspersky Anti-Virus.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avp.exe [619640] [PID.1180] =>.Kaspersky Lab®
[MD5.B5C2F92EE1106DFE7BB1CCE4D35B6037] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [462096] [PID.2004] =>.Apple Inc.®
[MD5.2EF52E3C5AEEA56D179421AFAE3FA54B] - (.Node.js - NVIDIA Web Helper Service.) -- C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe [15997376] [PID.2464] =>.NVIDIA Corporation®
[MD5.6C718849D436A7CCEBED72538F8BD04B] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe [288848] [PID.2504] =>.Google Inc®
[MD5.D2F56E366F1CB26866A6F43BD53B46C3] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe [366160] [PID.2516] =>.Google Inc®
[MD5.200185E99AA0922D1D12A6BF4345E65D] - (.Realtek Semiconductor - Realtek HD Audio Manager.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16407296] [PID.2832] =>.Realtek Semiconductor Corp®
[MD5.51CF0E38751B0351D67CBB53910B8556] - (.EagleGet.com - EagleGet Free Downloader.) -- C:\Program Files (x86)\EagleGet\EagleGet.exe [2102264] [PID.2844] =>.Beijing Pu Technology Limited®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.2864] =>.Google Inc®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.2052] =>.Google Inc®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.1332] =>.Google Inc®
[MD5.34E9BF9CAEBF49B8AAF1FF45AB5AE577] - (.HP - HP Smart-Install Service.) -- C:\Windows\system32\HPSIsvc.exe [127800] [PID.2780] =>.HP
[MD5.7021BCD337B4A88CF3A63AA4F0C5D05D] - (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [588704] [PID.3016] =>.Oracle America, Inc.®
[MD5.74AABA63DC9557F16D37402BECCDAC15] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [522688] [PID.2392] =>.NVIDIA Corporation®
[MD5.4DFCEB68ADDF290C541D4BD36BBB1AB5] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [469952] [PID.3348] =>.NVIDIA Corporation®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.3552] =>.Google Inc®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.3588] =>.Google Inc®
[MD5.3A2BDD76E7D2A5F40A7174793D1BA794] - (...) -- C:\Windows\SysWOW64\PnkBstrA.exe [75136] [PID.3840] =>.Even Balance, Inc.®
[MD5.5DA665A9DFAEAB9F16AB40717D7C988C] - (.AO Kaspersky Lab - Kaspersky Anti-Virus.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avpui.exe [338224] [PID.4048] =>.Kaspersky Lab®
[MD5.C1345EB0C9A974657563BB38F71CB9E1] - (.Synaptics Incorporated - 64-bit Synaptics Pointing Enhance Service.) -- C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [237736] [PID.4188] =>.Synaptics Incorporated®
[MD5.35AA4B404689D5CC233D6ED2A3A7E0AE] - (.Synaptics Incorporated - Synaptics TouchPad 64-bit Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3936936] [PID.4304] =>.Synaptics Incorporated®
[MD5.6CF22C519FC54D73786A176872CB66EF] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\PROGRAM FILES\SYNAPTICS\SynTP\SYNTPHELPER.EXE [201384] [PID.4456] =>.Synaptics Incorporated®
[MD5.BFEBD30F175D558498A23D5379E98123] - (.VMware, Inc. - VMware VMnet DHCP service.) -- C:\Windows\SysWOW64\vmnetdhcp.exe [366664] [PID.4396] =>.VMware, Inc.®
[MD5.7A39E2125C1523A2AF0F7063310694C7] - (.VMware, Inc. - VMware NAT Service.) -- C:\Windows\SysWOW64\vmnat.exe [400968] [PID.3996] =>.VMware, Inc.®
[MD5.0375A6AAAC9D617E192BBA8CF2808956] - (.VMware, Inc. - VMware Authorization Service.) -- E:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe [97864] [PID.5020] =>.VMware, Inc.®
[MD5.D46F765ABFBBEE6A23B7D61603916B4F] - (.VMware, Inc. - VMware USB Arbitration Service.) -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [916040] [PID.4540] =>.VMware, Inc.®
[MD5.360959BBD4F451E1AB811F4304232766] - (.WIBU-SYSTEMS AG - CodeMeter Runtime Server.) -- C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe [2568120] [PID.880] =>.WIBU-SYSTEMS AG®
[MD5.F9800ACC5925012F5B6F20BAD8310934] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe [469952] [PID.5248] =>.NVIDIA Corporation®
[MD5.C6F8B8139F93FE4853E0615838D60C89] - (.Copyright (C) 2016 Intel Corporation. All rights rese - Intel(R) System Usage Report.) -- C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv.exe [458904] [PID.3144] =>.Intel(R) Software Development Products®
[MD5.F4D8F67474DDA4FEF3935393AAA0173F] - (.Copyright (C) 2016 Intel Corporation. All rights rese - Intel(R) System Usage Report.) -- C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [416408] [PID.6880] =>.Intel(R) Software Development Products®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.576] =>.Google Inc®
[MD5.6E854C771DC0F1AAA920E2D57B20F88E] - (.PandoraTV - The KMPlayer.) -- E:\Program Files (x86)\KMPlayer\KMPlayer.exe [14165224] [PID.8560] =>.Pandora TV Co., Ltd.®
[MD5.153112F0FAA6BCC9F25A5F4ACC74D7EC] - (.Alexander Roshal - WinRAR archiver.) -- C:\Program Files (x86)\WinRAR\WinRAR.exe [1463288] [PID.7924] =>.win.rar GmbH®
[MD5.E39ED1EA1A5039C86FB94B0CBC619D2B] - (.Tencent - 腾讯手游助手.) -- e:\Program Files\TxGameAssistant\AppMarket\QMEmulatorService.exe [342776] [PID.6804] =>.SUP.Tencent
[MD5.BCF388E5F0EE38ABA9B897047103EE87] - (.Tencent - Tencent Gaming Buddy.) -- E:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe [2688760] [PID.1240] =>.SUP.Tencent
[MD5.5408D299C908F667F3E356ADFBFF48A3] - (...) -- E:\Program Files\TxGameAssistant\AppMarket\QQExternal.exe [65272] [PID.6104] =>.SUP.Tencent
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.6556] =>.Google Inc®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.13008] =>.Google Inc®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.11004] =>.Google Inc®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.8268] =>.Google Inc®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.10624] =>.Google Inc®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.5696] =>.Google Inc®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.4824] =>.Google Inc®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.4948] =>.Google Inc®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.12284] =>.Google Inc®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.11356] =>.Google Inc®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.9832] =>.Google Inc®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.8376] =>.Google Inc®
[MD5.EA6158EBC0CA8095DA44CD0C39203F62] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\moez\Desktop\ZHPDiag3(2).exe [3165568] [PID.9808] =>.Nicolas Coolman
[MD5.E5D432E9BCEB5CB71B71258F1046DD67] - (.AO Kaspersky Lab - Kaspersky Anti-Virus.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avp.exe [619640] [PID.8200] =>.Kaspersky Lab®
[MD5.67590595FC7F03C0BC697AB409621A36] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1577816] [PID.3724] =>.Google Inc®

---\\ Google Chrome, Start,Search,Extensions (29) - 3s
G0 - GCSP: Preferences [User Data\Default][HomePage] http://captive.apple.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://detectportal.firefox.com
G0 - GCSP: Preferences [User Data\Default][HomePage] http://g.cn
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.airport.us
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.com.sg =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.thinkdifferent.us
G0 - GCSP: Preferences [User Data\Default][HomePage] http://accounts.google.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://api.zcdn.de
G0 - GCSP: Preferences [User Data\Default][HomePage] http://crm.zenguard.biz
G0 - GCSP: Preferences [User Data\Default][HomePage] http://play.google.com =>.Google Inc.
G2 - GCE: Preference [moez][User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] =>.Google Inc. {Slides}
G2 - GCE: Preference [moez][User Data\Default] [amkpcclbbgegoafihnpgomddadjhcadd] =>.Kaspersky Protection
G2 - GCE: Preference [moez][User Data\Default] [aohghmighlieiainnegkcijnfilokake] =>.Google Inc. {Docs}
G2 - GCE: Preference [moez][User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] http://drive.google.com/ =>.Google Inc. {Drive}
G2 - GCE: Preference [moez][User Data\Default] [bihmplhobchoageeokmgbdihknkjbknd] =>.northghost.com {Free Proxy}
G2 - GCE: Preference [moez][User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] http://www.youtube.com =>.Youtube {Youtube}
G2 - GCE: Preference [moez][User Data\Default] [fdcgdnkidjaadafnichfpabhfomcebme] ZenMate =>.zenmate.com
G2 - GCE: Preference [moez][User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] =>.Google Inc. {Sheets}
G2 - GCE: Preference [moez][User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] =>.Google Inc. {Docs hors connexion}
G2 - GCE: Preference [moez][User Data\Default] [icpklikeghomkemdellmmkoifgfbakio]
G2 - GCE: Preference [moez][User Data\Default] [jabopobgcpjmedljpbcaablpmlmfcogm] WhatFont =>.chengyinliu.com
G2 - GCE: Preference [moez][User Data\Default] [kaebhgioafceeldhgjmendlfhbfjefmo] EagleGet Free Downloader =>.EagleGet.com
G2 - GCE: Preference [moez][User Data\Default] [khnadcdfjbjgojiilfdebbpiepokangj] Tools for Instagram
G2 - GCE: Preference [moez][User Data\Default] [lpcaedmchfhocbbapmcbpinfpgnhiddi] Google Keep Chrome Extension =>.Google Inc.
G2 - GCE: Preference [moez][User Data\Default] [nlbejmccbhkncgokjcmghpfloaajcffj] =>.hotspotshield.com
G2 - GCE: Preference [moez][User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] =>.Google Inc. {Wallet}
G2 - GCE: Preference [moez][User Data\Default] [omdakjcmkglenbhjadbccaookpfjihpa] TunnelBear VPN
G2 - GCE: Preference [moez][User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] http://mail.google.com/ =>.Google Inc. {Gmail}
G2 - GCE: Preference [moez][User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.

---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (12) - 14s
P2 - EXT FILE: (.Microsoft Corporation - The plugin allows you to have a better expe.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npMeetingJoinPluginOC.dll =>.Microsoft Corporation®
P2 - EXT FILE: (.Browsec VPN - Free and Unlimited VPN - .) -- C:\Users\moez\AppData\Roaming\Mozilla\Firefox\Profiles\pmc722jt.default-1507078032606\extensions\browsec@browsec.com.xpi
P2 - EXT FILE: (.Wappalyzer - Identify web technologies.) -- C:\Users\moez\AppData\Roaming\Mozilla\Firefox\Profiles\pmc722jt.default-1507078032606\extensions\wappalyzer@crunchlabz.com.xpi =>.Wappalyzer
P2 - EXT FILE: (.Flagfox - .) -- C:\Users\moez\AppData\Roaming\Mozilla\Firefox\Profiles\pmc722jt.default-1507078032606\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi =>.Flagfox
P2 - EXT FILE: (.NoScript - .) -- C:\Users\moez\AppData\Roaming\Mozilla\Firefox\Profiles\pmc722jt.default-1507078032606\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi =>.NoScript
P2 - EXT FILE: (.Yahoo! Search Engine - yahoo-search-engine.) -- C:\Users\moez\AppData\Roaming\Mozilla\Firefox\Profiles\pmc722jt.default-1507078032606\searchplugins\yahoo-lavasoft-ff59.xml =>.Yahoo! Search Engine
P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\vb@yandex.ru
P2 - EXT: (.Yandex - Yandex Elements.) -- C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\yasearch@yandex.ru =>.Yandex
P2 - EXT: (.Yandex - Yandex Elements.) -- C:\Users\moez\AppData\Roaming\Mozilla\Firefox\Profiles\pmc722jt.default-1507078032606\extensions\yasearch@yandex.ru =>.Yandex
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_108.dll =>.Adobe Systems Incorporated
P2 - FPN: [HKLM] [@java.com/DTPlugin,version=11.151.2] - (.Oracle Corp..) -- C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll =>.Oracle Corp.
P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=11.151.2] - (.Oracle Corp..) -- C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll =>.Oracle Corp.

---\\ Opera, Plugins,Start,Search (11) - 2s
B2 - EXT: [Ghostery] C:\Users\moez\AppData\Roaming\Opera Software\Opera Stable\Extensions\bbkekonodcdmedgffkkbgmnnekbainbg =>.Ghostery
B2 - EXT: [zenguard] C:\Users\moez\AppData\Roaming\Opera Software\Opera Stable\Extensions\cnhbkkedmelfmalgjpkngiaoifpdfcnl
B2 - EXT: [glinchiney] C:\Users\moez\AppData\Roaming\Opera Software\Opera Stable\Extensions\colooklfiganllfdabmgaonfbjpeoied
B2 - EXT: [__MSG_extensionNameChrome__] C:\Users\moez\AppData\Roaming\Opera Software\Opera Stable\Extensions\ebpielhlnnpkiddeeacoephkilopgblc
B2 - EXT: [dotvpncom] C:\Users\moez\AppData\Roaming\Opera Software\Opera Stable\Extensions\hiegahbgoabbpoieploedhfnobmpgbeg
B2 - EXT: [richtr] C:\Users\moez\AppData\Roaming\Opera Software\Opera Stable\Extensions\ibnombjmjocaccigcefonnipcnlaeaed =>.richtr
B2 - EXT: [dr34polw] C:\Users\moez\AppData\Roaming\Opera Software\Opera Stable\Extensions\ipiopppcaojnchgoepoemlbdccogeije
B2 - EXT: [esolutionsnordicab] C:\Users\moez\AppData\Roaming\Opera Software\Opera Stable\Extensions\jikibpedldihacokaanimbcjipghbloo
B2 - EXT: [EagleGet Free Downloader] C:\Users\moez\AppData\Roaming\Opera Software\Opera Stable\Extensions\kaebhgioafceeldhgjmendlfhbfjefmo
B2 - EXT: [__MSG_extName__] C:\Users\moez\AppData\Roaming\Opera Software\Opera Stable\Extensions\mchdgimobfnilobnllpdnompfjkkfdmi
B2 - EXT: [rayronvictor] C:\Users\moez\AppData\Roaming\Opera Software\Opera Stable\Extensions\nhddjiapfjkfbooicpajnllkinjnncao

---\\ Internet Explorer Extensions, Start, Search (15) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Browser.) (10.00.9200.16521 (win8_gdr_soc_ie.130216-2100)) -- C:\Windows\System32\ieframe.dll =>.Microsoft Corporation

---\\ INTERNET EXPLORER, trusted site and sensitive site (4) - 0s
~ IE Restricted Site Good: localhost
IE Restricted Site Good: webcompanion.com =>PUP.Optional.LavasoftWebCompanion
~ Microsoft Internet Explorer Restricted Site(s) Domains: 2(Good) / 0(Bad)
~ Microsoft Internet Explorer Restricted Site(s) EscDomains: 0(Good) / 0(Bad)

---\\ Internet Explorer, Proxy Management (6) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\\ Line Analysis, IniFiles, Auto loading programs (3) - 1s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation

---\\ Hosts file redirection (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (9)

---\\ Browser Helper Object (BHO) (6) - 2s
O2 - BHO: Lync Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} . (.Microsoft Corporation - Microsoft Lync.) -- E:\Program Files (x86)\office\Office15\OCHelper.dll =>.Microsoft Corporation®
O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_171\bin\ssv.dll =>.Oracle America, Inc.®
O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- E:\Program Files (x86)\office\Office15\URLREDIR.DLL =>.Microsoft Corporation®
O2 - BHO: Microsoft SkyDrive Pro Browser Helper [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} . (.Microsoft Corporation - Microsoft SkyDrive Pro Extensions.) -- E:\Program Files (x86)\office\Office15\GROOVEEX.DLL =>.Microsoft Corporation®
O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_171\bin\jp2ssv.dll =>.Oracle America, Inc.®
O2 - BHO: ScriptInjectionPluginBrowserHelperObject [64Bits] - {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} . (.AO Kaspersky Lab - Kaspersky Protection plugins.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\ieext\ie_plugin.dll =>.Kaspersky Lab®

---\\ Internet Explorer Toolbars (1) - 1s
O3 - Toolbar: 0x9D473F092E71CD469E0662E734A05F68 - [HKCU]{093F479D-712E-46CD-9E06-62E734A05F68} . (...) -- (.not file.)

---\\ Global shortcuts Startup (258) - 46s
O4 - GS\Desktop [Administrator]: Adobe Bridge CC (64bit).lnk . (.Adobe Systems Incorporated - Adobe Bridge CC.) E:\Program Files (x86)\adobe\Adobe Bridge CC (64 Bit)\Bridge.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [Administrator]: Adobe Illustrator CC 2015.lnk . (.Adobe Systems Inc. - Adobe Illustrator CC 2015.) E:\Program Files (x86)\adobe\Adobe Illustrator CC 2015\Support Files\Contents\Windows\Illustrator.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [Administrator]: Adobe Photoshop CC (64 Bit).lnk . (.Adobe Systems, Incorporated - Adobe Photoshop CC.) E:\Program Files (x86)\adobe\Adobe Photoshop CC (64 Bit)\Photoshop.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [Administrator]: Adobe Photoshop CC.lnk . (.Adobe Systems, Incorporated - Adobe Photoshop CC.) E:\Program Files (x86)\adobe\Adobe Photoshop CC\Photoshop.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [Administrator]: BitTorrent.lnk . (.BitTorrent Inc. - BitTorrent.) C:\Users\moez\AppData\Roaming\BitTorrent\BitTorrent.exe =>.BitTorrent Inc®
O4 - GS\Desktop [Administrator]: BotanicalName.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""BotanicalName"", ""app_url"": """", ""app_pkg"": ""sireetechno.co.in.botanicalname""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Administrator]: Botany Dictionary.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""Botany Dictionary"", ""app_url"": """", ""app_pkg"": ""com.believe.additional.botanydictionary""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Administrator]: Catalog.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""Catalog"", ""app_url"": """", ""app_pkg"": ""lt.farmis.apps.farmiscatalog""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Administrator]: Downloads.lnk . (...) C:\Users\moez\Downloads
O4 - GS\Desktop [Administrator]: GardenAnswers.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""GardenAnswers"", ""app_url"": """", ""app_pkg"": ""com.teamsoa.gardenanswers""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Administrator]: InDesign - 64.lnk . (.Adobe Systems Incorporated - Adobe InDesign CC.) E:\Program Files (x86)\adobe\Adobe InDesign CC (64 bit)\InDesign.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [Administrator]: InDesign.lnk . (.Adobe Systems Incorporated - Adobe InDesign CC.) E:\Program Files (x86)\adobe\Adobe InDesign CC\InDesign.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [Administrator]: KMPlayer.lnk . (.PandoraTV - The KMPlayer.) E:\Program Files (x86)\KMPlayer\KMPlayer.exe =>.Pandora TV Co., Ltd.®
O4 - GS\Desktop [Administrator]: Microsoft Office Excel 2007.lnk . (...) C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Administrator]: Minecraft.lnk . (.Titan Launcher - 1.12.2 Minecraft Launcher.) C:\Users\moez\AppData\Roaming\.minecraft\minecraft launcher\Minecraft Launcher.exe =>.Titan Launcher
O4 - GS\Desktop [Administrator]: mpc-hc64 - Shortcut (2).lnk . (.MPC-HC Team - MPC-HC (x64).) C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe =>.MPC-HC Team
O4 - GS\Desktop [Administrator]: mpc-hc64 - Shortcut.lnk . (.MPC-HC Team - MPC-HC (x64).) C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe =>.MPC-HC Team
O4 - GS\Desktop [Administrator]: Nmap - Zenmap GUI.lnk . (...) E:\Program Files (x86)\Nmap\zenmap.exe
O4 - GS\Desktop [Administrator]: PictureThis.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""PictureThis"", ""app_url"": """", ""app_pkg"": ""cn.danatech.xingseus""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Administrator]: Plantifier.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""Plantifier"", ""app_url"": """", ""app_pkg"": ""air.be.trendsco.plantifier""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Administrator]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) E:\Program Files (x86)\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Desktop [Administrator]: Tencent Gaming Buddy.lnk . (.Tencent - Tencent Gaming Buddy.) E:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe -from AppMarketDesktopLink =>.SUP.Tencent
O4 - GS\Desktop [Administrator]: TreeLogy.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""TreeLogy"", ""app_url"": """", ""app_pkg"": ""com.payinekereg.treelogy""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Administrator]: Vegetable Doctor.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""Vegetable Doctor"", ""app_url"": """", ""app_pkg"": ""com.bugwood.vegetabledoctor""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Administrator]: Viber.lnk . (.Viber Media S.à r.l. - Viber.) C:\Users\moez\AppData\Local\Viber\Viber.exe =>.Viber Media S.à r.l.®
O4 - GS\Desktop [Administrator]: WhatsApp.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""WhatsApp"", ""app_url"": """", ""app_pkg"": ""com.whatsapp""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Administrator]: Ygopro.lnk . (.YGOPRO - YGOPRO Automatic Dueling System.) C:\Users\moez\Documents\EGDownloads\New folder (4)\zero\New folder\New folder (3)\ygopro-percy\ygopro_vs.exe
O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (...) C:\Users\moez\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Administrator]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\moez\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\Desktop [Administrator]: الهندسة الزراعية.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""الهندسة الزراعية"", ""app_url"": """", ""app_pkg"": ""agro.info""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Administrator]: بلانت نت.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""بلانت نت"", ""app_url"": """", ""app_pkg"": ""org.plantnet""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Administrator]: بلانتكس.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""بلانتكس"", ""app_url"": """", ""app_pkg"": ""com.peat.GartenBank""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Administrator]: طرق زراعة الخضراوات والفواكه.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""طرق زراعة الخضراوات والفواكه"", ""app_url"": """", ""app_pkg"": ""join.konbrand.Agriculture""}" =>.BlueStack Systems, Inc.®
O4 - GS\Quicklaunch [Administrator]: Bigasoft Total Video Converter.lnk . (.Bigasoft Corporation - Total Video Converter.) E:\Program Files (x86)\Bigasoft\Total Video Converter 4\videoconverter.exe =>.Bigasoft Corporation
O4 - GS\Quicklaunch [Administrator]: BitTorrent.lnk . (.BitTorrent Inc. - BitTorrent.) C:\Users\moez\AppData\Roaming\BitTorrent\BitTorrent.exe =>.BitTorrent Inc®
O4 - GS\Quicklaunch [Administrator]: EagleGet.lnk . (.EagleGet.com - EagleGet Free Downloader.) C:\Program Files (x86)\EagleGet\EagleGet.exe =>.Beijing Pu Technology Limited®
O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Administrator]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Administrator]: QmEye.lnk . (.版权所有 (C) 2012 - PCClient Microsoft 基础类应用程序.) E:\Program Files (x86)\QmEye\QmEye.exe
O4 - GS\Quicklaunch [Administrator]: Tencent Gaming Buddy.lnk . (.Tencent - Tencent Gaming Buddy.) E:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe -from AppMarketDesktopLink =>.SUP.Tencent
O4 - GS\Quicklaunch [Administrator]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\moez\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [Administrator]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrator]: Viber.lnk . (.Viber Media S.à r.l. - Viber.) C:\Users\moez\AppData\Local\Viber\Viber.exe ShareFiles =>.Viber Media S.à r.l.®
O4 - GS\TaskBar [Administrator]: Adobe Photoshop CC.lnk . (.Adobe Systems, Incorporated - Adobe Photoshop CC.) E:\Program Files (x86)\adobe\Adobe Photoshop CC\Photoshop.exe =>.Adobe Systems Incorporated®
O4 - GS\TaskBar [Administrator]: Calculator.lnk . (.Microsoft Corporation - Windows Calculator.) C:\Windows\system32\calc.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: EagleGet (2).lnk . (.EagleGet.com - EagleGet Free Downloader.) C:\Program Files (x86)\EagleGet\EagleGet.exe =>.Beijing Pu Technology Limited®
O4 - GS\TaskBar [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Administrator]: KMPlayer.exe.lnk . (.PandoraTV - The KMPlayer.) E:\Program Files (x86)\KMPlayer\KMPlayer.exe =>.Pandora TV Co., Ltd.®
O4 - GS\TaskBar [Administrator]: mpc-hc64 - Shortcut.lnk . (.MPC-HC Team - MPC-HC (x64).) C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe =>.MPC-HC Team
O4 - GS\TaskBar [Administrator]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: On-Screen Keyboard (2).lnk . (.Microsoft Corporation - Accessibility On-Screen Keyboard.) C:\Windows\system32\osk.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: On-Screen Keyboard (3).lnk . (.Microsoft Corporation - Accessibility On-Screen Keyboard.) C:\Windows\system32\osk.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: On-Screen Keyboard.lnk . (.Microsoft Corporation - Accessibility On-Screen Keyboard.) C:\Windows\system32\osk.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: Opera Browser.lnk . (.Opera Software - Opera Internet Browser.) E:\Program Files (x86)\opera\launcher.exe =>.Opera Software AS®
O4 - GS\TaskBar [Administrator]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: Sticky Notes.lnk . (.Microsoft Corporation - Sticky Notes.) C:\Windows\system32\StikyNot.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: Tencent Gaming Buddy.lnk . (.Tencent - Tencent Gaming Buddy.) E:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe -from AppMarketDesktopLink =>.SUP.Tencent
O4 - GS\TaskBar [Administrator]: The KMPlayer.lnk . (.PandoraTV - The KMPlayer.) E:\KMPlayer\KMPlayer.exe =>.Pandora TV Co., Ltd.®
O4 - GS\TaskBar [Administrator]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: WinRAR.lnk . (.Alexander Roshal - WinRAR archiver.) C:\Program Files (x86)\WinRAR\WinRAR.exe =>.win.rar GmbH®
O4 - GS\Programs [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Guest]: Adobe Bridge CC (64bit).lnk . (.Adobe Systems Incorporated - Adobe Bridge CC.) E:\Program Files (x86)\adobe\Adobe Bridge CC (64 Bit)\Bridge.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [Guest]: Adobe Illustrator CC 2015.lnk . (.Adobe Systems Inc. - Adobe Illustrator CC 2015.) E:\Program Files (x86)\adobe\Adobe Illustrator CC 2015\Support Files\Contents\Windows\Illustrator.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [Guest]: Adobe Photoshop CC (64 Bit).lnk . (.Adobe Systems, Incorporated - Adobe Photoshop CC.) E:\Program Files (x86)\adobe\Adobe Photoshop CC (64 Bit)\Photoshop.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [Guest]: Adobe Photoshop CC.lnk . (.Adobe Systems, Incorporated - Adobe Photoshop CC.) E:\Program Files (x86)\adobe\Adobe Photoshop CC\Photoshop.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [Guest]: BitTorrent.lnk . (.BitTorrent Inc. - BitTorrent.) C:\Users\moez\AppData\Roaming\BitTorrent\BitTorrent.exe =>.BitTorrent Inc®
O4 - GS\Desktop [Guest]: BotanicalName.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""BotanicalName"", ""app_url"": """", ""app_pkg"": ""sireetechno.co.in.botanicalname""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Guest]: Botany Dictionary.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""Botany Dictionary"", ""app_url"": """", ""app_pkg"": ""com.believe.additional.botanydictionary""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Guest]: Catalog.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""Catalog"", ""app_url"": """", ""app_pkg"": ""lt.farmis.apps.farmiscatalog""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Guest]: Downloads.lnk . (...) C:\Users\moez\Downloads
O4 - GS\Desktop [Guest]: GardenAnswers.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""GardenAnswers"", ""app_url"": """", ""app_pkg"": ""com.teamsoa.gardenanswers""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Guest]: InDesign - 64.lnk . (.Adobe Systems Incorporated - Adobe InDesign CC.) E:\Program Files (x86)\adobe\Adobe InDesign CC (64 bit)\InDesign.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [Guest]: InDesign.lnk . (.Adobe Systems Incorporated - Adobe InDesign CC.) E:\Program Files (x86)\adobe\Adobe InDesign CC\InDesign.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [Guest]: KMPlayer.lnk . (.PandoraTV - The KMPlayer.) E:\Program Files (x86)\KMPlayer\KMPlayer.exe =>.Pandora TV Co., Ltd.®
O4 - GS\Desktop [Guest]: Microsoft Office Excel 2007.lnk . (...) C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Guest]: Minecraft.lnk . (.Titan Launcher - 1.12.2 Minecraft Launcher.) C:\Users\moez\AppData\Roaming\.minecraft\minecraft launcher\Minecraft Launcher.exe =>.Titan Launcher
O4 - GS\Desktop [Guest]: mpc-hc64 - Shortcut (2).lnk . (.MPC-HC Team - MPC-HC (x64).) C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe =>.MPC-HC Team
O4 - GS\Desktop [Guest]: mpc-hc64 - Shortcut.lnk . (.MPC-HC Team - MPC-HC (x64).) C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe =>.MPC-HC Team
O4 - GS\Desktop [Guest]: Nmap - Zenmap GUI.lnk . (...) E:\Program Files (x86)\Nmap\zenmap.exe
O4 - GS\Desktop [Guest]: PictureThis.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""PictureThis"", ""app_url"": """", ""app_pkg"": ""cn.danatech.xingseus""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Guest]: Plantifier.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""Plantifier"", ""app_url"": """", ""app_pkg"": ""air.be.trendsco.plantifier""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Guest]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) E:\Program Files (x86)\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Desktop [Guest]: Tencent Gaming Buddy.lnk . (.Tencent - Tencent Gaming Buddy.) E:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe -from AppMarketDesktopLink =>.SUP.Tencent
O4 - GS\Desktop [Guest]: TreeLogy.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""TreeLogy"", ""app_url"": """", ""app_pkg"": ""com.payinekereg.treelogy""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Guest]: Vegetable Doctor.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""Vegetable Doctor"", ""app_url"": """", ""app_pkg"": ""com.bugwood.vegetabledoctor""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Guest]: Viber.lnk . (.Viber Media S.à r.l. - Viber.) C:\Users\moez\AppData\Local\Viber\Viber.exe =>.Viber Media S.à r.l.®
O4 - GS\Desktop [Guest]: WhatsApp.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""WhatsApp"", ""app_url"": """", ""app_pkg"": ""com.whatsapp""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Guest]: Ygopro.lnk . (.YGOPRO - YGOPRO Automatic Dueling System.) C:\Users\moez\Documents\EGDownloads\New folder (4)\zero\New folder\New folder (3)\ygopro-percy\ygopro_vs.exe
O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (...) C:\Users\moez\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Guest]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\moez\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\Desktop [Guest]: الهندسة الزراعية.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""الهندسة الزراعية"", ""app_url"": """", ""app_pkg"": ""agro.info""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Guest]: بلانت نت.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""بلانت نت"", ""app_url"": """", ""app_pkg"": ""org.plantnet""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Guest]: بلانتكس.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""بلانتكس"", ""app_url"": """", ""app_pkg"": ""com.peat.GartenBank""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [Guest]: طرق زراعة الخضراوات والفواكه.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""طرق زراعة الخضراوات والفواكه"", ""app_url"": """", ""app_pkg"": ""join.konbrand.Agriculture""}" =>.BlueStack Systems, Inc.®
O4 - GS\Quicklaunch [Guest]: Bigasoft Total Video Converter.lnk . (.Bigasoft Corporation - Total Video Converter.) E:\Program Files (x86)\Bigasoft\Total Video Converter 4\videoconverter.exe =>.Bigasoft Corporation
O4 - GS\Quicklaunch [Guest]: BitTorrent.lnk . (.BitTorrent Inc. - BitTorrent.) C:\Users\moez\AppData\Roaming\BitTorrent\BitTorrent.exe =>.BitTorrent Inc®
O4 - GS\Quicklaunch [Guest]: EagleGet.lnk . (.EagleGet.com - EagleGet Free Downloader.) C:\Program Files (x86)\EagleGet\EagleGet.exe =>.Beijing Pu Technology Limited®
O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Guest]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Guest]: QmEye.lnk . (.版权所有 (C) 2012 - PCClient Microsoft 基础类应用程序.) E:\Program Files (x86)\QmEye\QmEye.exe
O4 - GS\Quicklaunch [Guest]: Tencent Gaming Buddy.lnk . (.Tencent - Tencent Gaming Buddy.) E:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe -from AppMarketDesktopLink =>.SUP.Tencent
O4 - GS\Quicklaunch [Guest]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\moez\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [Guest]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Guest]: Viber.lnk . (.Viber Media S.à r.l. - Viber.) C:\Users\moez\AppData\Local\Viber\Viber.exe ShareFiles =>.Viber Media S.à r.l.®
O4 - GS\TaskBar [Guest]: Adobe Photoshop CC.lnk . (.Adobe Systems, Incorporated - Adobe Photoshop CC.) E:\Program Files (x86)\adobe\Adobe Photoshop CC\Photoshop.exe =>.Adobe Systems Incorporated®
O4 - GS\TaskBar [Guest]: Calculator.lnk . (.Microsoft Corporation - Windows Calculator.) C:\Windows\system32\calc.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: EagleGet (2).lnk . (.EagleGet.com - EagleGet Free Downloader.) C:\Program Files (x86)\EagleGet\EagleGet.exe =>.Beijing Pu Technology Limited®
O4 - GS\TaskBar [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Guest]: KMPlayer.exe.lnk . (.PandoraTV - The KMPlayer.) E:\Program Files (x86)\KMPlayer\KMPlayer.exe =>.Pandora TV Co., Ltd.®
O4 - GS\TaskBar [Guest]: mpc-hc64 - Shortcut.lnk . (.MPC-HC Team - MPC-HC (x64).) C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe =>.MPC-HC Team
O4 - GS\TaskBar [Guest]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: On-Screen Keyboard (2).lnk . (.Microsoft Corporation - Accessibility On-Screen Keyboard.) C:\Windows\system32\osk.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: On-Screen Keyboard (3).lnk . (.Microsoft Corporation - Accessibility On-Screen Keyboard.) C:\Windows\system32\osk.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: On-Screen Keyboard.lnk . (.Microsoft Corporation - Accessibility On-Screen Keyboard.) C:\Windows\system32\osk.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: Opera Browser.lnk . (.Opera Software - Opera Internet Browser.) E:\Program Files (x86)\opera\launcher.exe =>.Opera Software AS®
O4 - GS\TaskBar [Guest]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: Sticky Notes.lnk . (.Microsoft Corporation - Sticky Notes.) C:\Windows\system32\StikyNot.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: Tencent Gaming Buddy.lnk . (.Tencent - Tencent Gaming Buddy.) E:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe -from AppMarketDesktopLink =>.SUP.Tencent
O4 - GS\TaskBar [Guest]: The KMPlayer.lnk . (.PandoraTV - The KMPlayer.) E:\KMPlayer\KMPlayer.exe =>.Pandora TV Co., Ltd.®
O4 - GS\TaskBar [Guest]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: WinRAR.lnk . (.Alexander Roshal - WinRAR archiver.) C:\Program Files (x86)\WinRAR\WinRAR.exe =>.win.rar GmbH®
O4 - GS\Programs [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Desktop [moez]: Adobe Bridge CC (64bit).lnk . (.Adobe Systems Incorporated - Adobe Bridge CC.) E:\Program Files (x86)\adobe\Adobe Bridge CC (64 Bit)\Bridge.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [moez]: Adobe Illustrator CC 2015.lnk . (.Adobe Systems Inc. - Adobe Illustrator CC 2015.) E:\Program Files (x86)\adobe\Adobe Illustrator CC 2015\Support Files\Contents\Windows\Illustrator.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [moez]: Adobe Photoshop CC (64 Bit).lnk . (.Adobe Systems, Incorporated - Adobe Photoshop CC.) E:\Program Files (x86)\adobe\Adobe Photoshop CC (64 Bit)\Photoshop.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [moez]: Adobe Photoshop CC.lnk . (.Adobe Systems, Incorporated - Adobe Photoshop CC.) E:\Program Files (x86)\adobe\Adobe Photoshop CC\Photoshop.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [moez]: BitTorrent.lnk . (.BitTorrent Inc. - BitTorrent.) C:\Users\moez\AppData\Roaming\BitTorrent\BitTorrent.exe =>.BitTorrent Inc®
O4 - GS\Desktop [moez]: BotanicalName.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""BotanicalName"", ""app_url"": """", ""app_pkg"": ""sireetechno.co.in.botanicalname""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [moez]: Botany Dictionary.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""Botany Dictionary"", ""app_url"": """", ""app_pkg"": ""com.believe.additional.botanydictionary""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [moez]: Catalog.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""Catalog"", ""app_url"": """", ""app_pkg"": ""lt.farmis.apps.farmiscatalog""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [moez]: Downloads.lnk . (...) C:\Users\moez\Downloads
O4 - GS\Desktop [moez]: GardenAnswers.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""GardenAnswers"", ""app_url"": """", ""app_pkg"": ""com.teamsoa.gardenanswers""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [moez]: InDesign - 64.lnk . (.Adobe Systems Incorporated - Adobe InDesign CC.) E:\Program Files (x86)\adobe\Adobe InDesign CC (64 bit)\InDesign.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [moez]: InDesign.lnk . (.Adobe Systems Incorporated - Adobe InDesign CC.) E:\Program Files (x86)\adobe\Adobe InDesign CC\InDesign.exe =>.Adobe Systems Incorporated®
O4 - GS\Desktop [moez]: KMPlayer.lnk . (.PandoraTV - The KMPlayer.) E:\Program Files (x86)\KMPlayer\KMPlayer.exe =>.Pandora TV Co., Ltd.®
O4 - GS\Desktop [moez]: Microsoft Office Excel 2007.lnk . (...) C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe =>.Microsoft Corporation®
O4 - GS\Desktop [moez]: Minecraft.lnk . (.Titan Launcher - 1.12.2 Minecraft Launcher.) C:\Users\moez\AppData\Roaming\.minecraft\minecraft launcher\Minecraft Launcher.exe =>.Titan Launcher
O4 - GS\Desktop [moez]: mpc-hc64 - Shortcut (2).lnk . (.MPC-HC Team - MPC-HC (x64).) C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe =>.MPC-HC Team
O4 - GS\Desktop [moez]: mpc-hc64 - Shortcut.lnk . (.MPC-HC Team - MPC-HC (x64).) C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe =>.MPC-HC Team
O4 - GS\Desktop [moez]: Nmap - Zenmap GUI.lnk . (...) E:\Program Files (x86)\Nmap\zenmap.exe
O4 - GS\Desktop [moez]: PictureThis.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""PictureThis"", ""app_url"": """", ""app_pkg"": ""cn.danatech.xingseus""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [moez]: Plantifier.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""Plantifier"", ""app_url"": """", ""app_pkg"": ""air.be.trendsco.plantifier""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [moez]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) E:\Program Files (x86)\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Desktop [moez]: Tencent Gaming Buddy.lnk . (.Tencent - Tencent Gaming Buddy.) E:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe -from AppMarketDesktopLink =>.SUP.Tencent
O4 - GS\Desktop [moez]: TreeLogy.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""TreeLogy"", ""app_url"": """", ""app_pkg"": ""com.payinekereg.treelogy""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [moez]: Vegetable Doctor.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""Vegetable Doctor"", ""app_url"": """", ""app_pkg"": ""com.bugwood.vegetabledoctor""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [moez]: Viber.lnk . (.Viber Media S.à r.l. - Viber.) C:\Users\moez\AppData\Local\Viber\Viber.exe =>.Viber Media S.à r.l.®
O4 - GS\Desktop [moez]: WhatsApp.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""WhatsApp"", ""app_url"": """", ""app_pkg"": ""com.whatsapp""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [moez]: Ygopro.lnk . (.YGOPRO - YGOPRO Automatic Dueling System.) C:\Users\moez\Documents\EGDownloads\New folder (4)\zero\New folder\New folder (3)\ygopro-percy\ygopro_vs.exe
O4 - GS\Desktop [moez]: ZHPDiag.lnk . (...) C:\Users\moez\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [moez]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\moez\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\Desktop [moez]: الهندسة الزراعية.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""الهندسة الزراعية"", ""app_url"": """", ""app_pkg"": ""agro.info""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [moez]: بلانت نت.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""بلانت نت"", ""app_url"": """", ""app_pkg"": ""org.plantnet""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [moez]: بلانتكس.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""بلانتكس"", ""app_url"": """", ""app_pkg"": ""com.peat.GartenBank""}" =>.BlueStack Systems, Inc.®
O4 - GS\Desktop [moez]: طرق زراعة الخضراوات والفواكه.lnk . (.BlueStack Systems, Inc. - BlueStacks App Runner.) C:\Program Files (x86)\BlueStacks\HD-RunApp.exe -json "{""app_icon_url"": """", ""app_name"": ""طرق زراعة الخضراوات والفواكه"", ""app_url"": """", ""app_pkg"": ""join.konbrand.Agriculture""}" =>.BlueStack Systems, Inc.®
O4 - GS\Quicklaunch [moez]: Bigasoft Total Video Converter.lnk . (.Bigasoft Corporation - Total Video Converter.) E:\Program Files (x86)\Bigasoft\Total Video Converter 4\videoconverter.exe =>.Bigasoft Corporation
O4 - GS\Quicklaunch [moez]: BitTorrent.lnk . (.BitTorrent Inc. - BitTorrent.) C:\Users\moez\AppData\Roaming\BitTorrent\BitTorrent.exe =>.BitTorrent Inc®
O4 - GS\Quicklaunch [moez]: EagleGet.lnk . (.EagleGet.com - EagleGet Free Downloader.) C:\Program Files (x86)\EagleGet\EagleGet.exe =>.Beijing Pu Technology Limited®
O4 - GS\Quicklaunch [moez]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [moez]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [moez]: QmEye.lnk . (.版权所有 (C) 2012 - PCClient Microsoft 基础类应用程序.) E:\Program Files (x86)\QmEye\QmEye.exe
O4 - GS\Quicklaunch [moez]: Tencent Gaming Buddy.lnk . (.Tencent - Tencent Gaming Buddy.) E:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe -from AppMarketDesktopLink =>.SUP.Tencent
O4 - GS\Quicklaunch [moez]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\moez\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [moez]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\sendTo [moez]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [moez]: Viber.lnk . (.Viber Media S.à r.l. - Viber.) C:\Users\moez\AppData\Local\Viber\Viber.exe ShareFiles =>.Viber Media S.à r.l.®
O4 - GS\TaskBar [moez]: Adobe Photoshop CC.lnk . (.Adobe Systems, Incorporated - Adobe Photoshop CC.) E:\Program Files (x86)\adobe\Adobe Photoshop CC\Photoshop.exe =>.Adobe Systems Incorporated®
O4 - GS\TaskBar [moez]: Calculator.lnk . (.Microsoft Corporation - Windows Calculator.) C:\Windows\system32\calc.exe =>.Microsoft Corporation
O4 - GS\TaskBar [moez]: EagleGet (2).lnk . (.EagleGet.com - EagleGet Free Downloader.) C:\Program Files (x86)\EagleGet\EagleGet.exe =>.Beijing Pu Technology Limited®
O4 - GS\TaskBar [moez]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [moez]: KMPlayer.exe.lnk . (.PandoraTV - The KMPlayer.) E:\Program Files (x86)\KMPlayer\KMPlayer.exe =>.Pandora TV Co., Ltd.®
O4 - GS\TaskBar [moez]: mpc-hc64 - Shortcut.lnk . (.MPC-HC Team - MPC-HC (x64).) C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe =>.MPC-HC Team
O4 - GS\TaskBar [moez]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\TaskBar [moez]: On-Screen Keyboard (2).lnk . (.Microsoft Corporation - Accessibility On-Screen Keyboard.) C:\Windows\system32\osk.exe =>.Microsoft Corporation
O4 - GS\TaskBar [moez]: On-Screen Keyboard (3).lnk . (.Microsoft Corporation - Accessibility On-Screen Keyboard.) C:\Windows\system32\osk.exe =>.Microsoft Corporation
O4 - GS\TaskBar [moez]: On-Screen Keyboard.lnk . (.Microsoft Corporation - Accessibility On-Screen Keyboard.) C:\Windows\system32\osk.exe =>.Microsoft Corporation
O4 - GS\TaskBar [moez]: Opera Browser.lnk . (.Opera Software - Opera Internet Browser.) E:\Program Files (x86)\opera\launcher.exe =>.Opera Software AS®
O4 - GS\TaskBar [moez]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\TaskBar [moez]: Sticky Notes.lnk . (.Microsoft Corporation - Sticky Notes.) C:\Windows\system32\StikyNot.exe =>.Microsoft Corporation
O4 - GS\TaskBar [moez]: Tencent Gaming Buddy.lnk . (.Tencent - Tencent Gaming Buddy.) E:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe -from AppMarketDesktopLink =>.SUP.Tencent
O4 - GS\TaskBar [moez]: The KMPlayer.lnk . (.PandoraTV - The KMPlayer.) E:\KMPlayer\KMPlayer.exe =>.Pandora TV Co., Ltd.®
O4 - GS\TaskBar [moez]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\TaskBar [moez]: WinRAR.lnk . (.Alexander Roshal - WinRAR archiver.) C:\Program Files (x86)\WinRAR\WinRAR.exe =>.win.rar GmbH®
O4 - GS\Programs [moez]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\CommonDesktop [Public]: Acrobat Reader DC.lnk . (.Adobe Systems Incorporated - Adobe Acrobat Reader DC.) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe =>.Adobe Systems, Incorporated®
O4 - GS\CommonDesktop [Public]: Adobe Application Manager.lnk . (.Adobe Systems Incorporated - Adobe Application Manager.) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\PDapp.exe --appletID=CCM_UI --appletVersion=1.0 --workflow=CCM_workflow_launch =>.Adobe Systems Incorporated®
O4 - GS\CommonDesktop [Public]: Arabic Rappelz.lnk . (.GALALAB - Rappelz Launcher.) E:\Game Power 7\Arabic Rappelz\Launcher.exe {0D09BE38011F73AC9E11DAC466C7D6C9} =>.GALALAB
O4 - GS\CommonDesktop [Public]: Bigasoft Total Video Converter.lnk . (.Bigasoft Corporation - Total Video Converter.) E:\Program Files (x86)\Bigasoft\Total Video Converter 4\videoconverter.exe =>.Bigasoft Corporation
O4 - GS\CommonDesktop [Public]: BlueStacks.lnk . (.BlueStack Systems, Inc. - BlueStacks 3.) F:\New folder\BlueStacks\Client\BlueStacks.exe =>.BlueStack Systems, Inc.
O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Ltd - CCleaner.) E:\Program Files (x86)\cc\CCleaner64.exe =>.Piriform Ltd®
O4 - GS\CommonDesktop [Public]: Connect2.lnk . (.Lenovo - Connect2.) C:\Program Files (x86)\Lenovo\Connect2\Connect2.exe =>.LENOVO®
O4 - GS\CommonDesktop [Public]: EagleGet.lnk . (.EagleGet.com - EagleGet Free Downloader.) C:\Program Files (x86)\EagleGet\EagleGet.exe =>.Beijing Pu Technology Limited®
O4 - GS\CommonDesktop [Public]: Firefox.lnk . (.Mozilla Corporation - Firefox.) E:\Program Files (x86)\firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\CommonDesktop [Public]: GeForce Experience.lnk . (.NVIDIA Corporation - NVIDIA GeForce Experience.) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe =>.NVIDIA Corporation®
O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\CommonDesktop [Public]: Google Earth Pro.lnk . (.Google - Google Earth.) C:\Program Files (x86)\Google\Google Earth Pro\client\googleearth.exe =>.Google Inc®
O4 - GS\CommonDesktop [Public]: Intel(R) Driver Update Utility 2.6.lnk . (.Intel - Intel Driver Update Utility.) C:\Program Files (x86)\Intel Driver Update Utility\DriverUpdateUI.exe =>.Intel(R) Driver Update Utility®
O4 - GS\CommonDesktop [Public]: Intel(R) HD Graphics Control Panel.lnk . (.Intel Corporation - GFXUIEX Module.) C:\Windows\system32\GfxUIEx.exe =>.Intel Corporation
O4 - GS\CommonDesktop [Public]: iTunes.lnk . (.Apple Inc. - iTunes.) E:\iTunes\iTunes.exe =>.Apple Inc.®
O4 - GS\CommonDesktop [Public]: Kaspersky Free.lnk . (.AO Kaspersky Lab - Kaspersky Anti-Virus.) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\avpui.exe =>.Kaspersky Lab®
O4 - GS\CommonDesktop [Public]: Kaspersky Secure Connection.lnk . (.AO Kaspersky Lab - Kaspersky Secure Connection.) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0 (1)\ksdeui.exe -navigate ksde://mainwindow =>.Kaspersky Lab®
O4 - GS\CommonDesktop [Public]: Nidhogg.lnk . (.Messhof LLC - Nidhogg.) E:\game\Nidhogg\Nidhogg.exe =>.Messhof LLC
O4 - GS\CommonDesktop [Public]: Opera.lnk . (.Opera Software - Opera Internet Browser.) E:\Program Files (x86)\opera\launcher.exe =>.Opera Software AS®
O4 - GS\CommonDesktop [Public]: Recuva.lnk . (.Piriform Ltd - .) C:\Program Files (x86)\Recuva\recuva64.exe =>.Piriform Ltd
O4 - GS\CommonDesktop [Public]: SHAREit.lnk . (.SHAREit Technologies Co.Ltd - SHAREit.) C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.exe =>.SHAREit Technologies Co.Ltd®
O4 - GS\CommonDesktop [Public]: Steam.lnk . (.Valve Corporation - Steam Client Bootstrapper.) E:\Program Files (x86)\Steam\Steam.exe =>.Valve®
O4 - GS\CommonDesktop [Public]: Virtual CloneDrive.lnk . (.Elaborate Bytes AG - VirtualCloneDrive Preferences.) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDPrefs.exe =>.Elaborate Bytes AG
O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) E:\Program Files (x86)\VideoLAN\VLC\vlc.exe =>.VideoLAN®
O4 - GS\CommonDesktop [Public]: VMware Workstation 12 Player.lnk . (.VMware, Inc. - VMware Player.) E:\Program Files (x86)\VMware\VMware Player\vmplayer.exe =>.VMware, Inc.®
O4 - GS\Programs [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Accessories [Public]: Command Prompt.lnk . (.Microsoft Corporation - Windows Command Processor.) C:\Windows\system32\cmd.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe -extoff =>.Microsoft Corporation®
O4 - GS\SystemTools [Public]: Private Character Editor.lnk . (.Microsoft Corporation - Private Character Editor.) C:\Windows\system32\eudcedit.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Bluetooth File Transfer Wizard.lnk . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Windows Calculator.) C:\Windows\system32\calc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - Display Switch.) C:\Windows\system32\displayswitch.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Math Input Panel Accessory.) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - Windows Mobility Center.) C:\Windows\system32\mblctr.exe /open =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\Windows\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\Windows\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Windows Sound Recorder.) C:\Windows\system32\SoundRecorder.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - Sticky Notes.) C:\Windows\system32\StikyNot.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) C:\Windows\System32\mobsync.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Welcome Center.lnk . (.Microsoft Corporation - Windows host process (Rundll32).) C:\Windows\system32\rundll32.exe %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut =>..Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) C:\Windows\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - Microsoft® Disk Defragmenter.) C:\Windows\system32\dfrgui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - Disk Space Cleanup Manager for Windows.) C:\Windows\system32\cleanmgr.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - Resource and Performance Monitor.) C:\Windows\system32\perfmon.exe /res =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - System Information.) C:\Windows\system32\msinfo32.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - Microsoft® Windows System Restore.) C:\Windows\system32\rstrui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) C:\Windows\system32\taskschd.msc /s =>..Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - Windows Easy Transfer Post Migration Applic.) C:\Windows\system32\migwiz\postmig.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - Windows Easy Transfer Application.) C:\Windows\system32\migwiz\migwiz.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Acrobat Reader DC.lnk . (.Flexera Software LLC - InstallShield.) C:\Windows\Installer\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\SC_Reader.ico =>.Flexera Software LLC
O4 - GS\ProgramsCommon [Public]: Adobe Application Manager.lnk . (.Adobe Systems Incorporated - Adobe Application Manager.) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\PDapp.exe --appletID=CCM_UI --appletVersion=1.0 --workflow=CCM_workflow_launch =>.Adobe Systems Incorporated®
O4 - GS\ProgramsCommon [Public]: Adobe Bridge CC (64bit).lnk . (.Adobe Systems Incorporated - Adobe Bridge CC.) E:\Program Files (x86)\adobe\Adobe Bridge CC (64 Bit)\Bridge.exe =>.Adobe Systems Incorporated®
O4 - GS\ProgramsCommon [Public]: Adobe Photoshop CC (64 Bit).lnk . (.Adobe Systems, Incorporated - Adobe Photoshop CC.) E:\Program Files (x86)\adobe\Adobe Photoshop CC (64 Bit)\Photoshop.exe =>.Adobe Systems Incorporated®
O4 - GS\ProgramsCommon [Public]: Adobe Photoshop CC.lnk . (.Adobe Systems, Incorporated - Adobe Photoshop CC.) E:\Program Files (x86)\adobe\Adobe Photoshop CC\Photoshop.exe =>.Adobe Systems Incorporated®
O4 - GS\ProgramsCommon [Public]: Adobe Update Management Tool.lnk . (.PainteR - Update Management Tool.) E:\Program Files (x86)\Update Management Tool\umt.exe =>.PainteR
O4 - GS\ProgramsCommon [Public]: Apple Software Update.lnk . (...) C:\Windows\Installer\{19589375-5C58-4AFA-842F-8B34744CCEAD}\AppleSoftwareUpdateIco.exe =>.Apple Inc.
O4 - GS\ProgramsCommon [Public]: Firefox.lnk . (.Mozilla Corporation - Firefox.) E:\Program Files (x86)\firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\ProgramsCommon [Public]: Media Center.lnk . (.Microsoft Corporation - Windows Media Center.) C:\Windows\ehome\ehshell.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Nidhogg.lnk . (.Messhof LLC - Nidhogg.) E:\game\Nidhogg\Nidhogg.exe =>.Messhof LLC
O4 - GS\ProgramsCommon [Public]: Opera Browser.lnk . (.Opera Software - Opera Internet Browser.) E:\Program Files (x86)\opera\launcher.exe =>.Opera Software AS®
O4 - GS\ProgramsCommon [Public]: Opera.lnk . (.Opera Software - Opera Internet Browser.) E:\Program Files (x86)\opera\launcher.exe =>.Opera Software AS®
O4 - GS\ProgramsCommon [Public]: Sidebar.lnk . (.Microsoft Corporation - Windows Desktop Gadgets.) C:\Program Files (x86)\Windows Sidebar\sidebar.exe /showgadgets =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Anytime Upgrade.lnk . (.Microsoft Corporation - Windows Anytime Upgrade User Interface.) C:\Windows\system32\WindowsAnytimeUpgradeUI.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows DVD Maker.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\DVD Maker\DVDMaker.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: XPS Viewer.lnk . (.Microsoft Corporation - XPS Viewer.) C:\Windows\system32\xpsrchvw.exe =>.Microsoft Corporation

---\\ Lop.com/Domain Hijackers (10) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = domain.name
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 5.63.4.2 8.8.8.8 =>.France Google Cloud
O17 - HKLM\System\CCS\Services\Tcpip\..\{45A9FF9C-CDDB-475D-98D5-24028D86814A}: DhcpNameServer = 5.63.4.2 8.8.8.8 =>.France Google Cloud
O17 - HKLM\System\CCS\Services\Tcpip\..\{48B3CAEF-0021-4F02-BD37-6858DB93EF69}: DhcpNameServer = 192.168.1.1 0.0.0.0 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{76529DC7-40CC-4CFD-8435-3C13C05E5442}: DhcpNameServer = 8.8.8.8 =>.France Google Cloud
O17 - HKLM\System\CCS\Services\Tcpip\..\{98985B8E-1651-447E-9BAB-D72DCAA42CC5}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABAB562B-2682-4940-BCCE-F87FAF02DAEC}: DhcpNameServer = 172.20.10.1 =>.Private IP
O17 - HKLM\System\CCS\Services\Tcpip\..\{C6216AF7-C83A-462F-B255-23AB4DCBB97C}: DhcpNameServer = 8.8.8.8 =>.France Google Cloud
O17 - HKLM\System\CCS\Services\Tcpip\..\{45A9FF9C-CDDB-475D-98D5-24028D86814A}: DhcpDomain = domain.name
O17 - HKLM\System\CCS\Services\Tcpip\..\{98985B8E-1651-447E-9BAB-D72DCAA42CC5}: DhcpDomain = wimax

---\\ Extra protocols (24) - 1s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: gopher [64Bits] - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-help [64Bits] - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll =>.Microsoft Corporation®
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: osf [64Bits] - {D924BDC6-C83A-4BD5-90D0-095128A113D1} . (.Microsoft Corporation - Microsoft Office 2013 component.) -- E:\Program Files (x86)\office\Office15\MSOSB.DLL =>.Microsoft Corporation®
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL =>.Microsoft Corporation®

---\\ AppInit_DLLs Registry value Autorun (2) - 0s
O20 - AppInit_DLLs: . (.NVIDIA Corporation - NVIDIA shim initialization dll, Version 391.) - C:\Windows\System32\nvinitx.dll =>.NVIDIA Corporation
O20 - Winlogon : UserInit . (.Microsoft Corporation - Userinit Logon Application.) - C:\Windows\system32\userinit.exe =>.Microsoft Corporation

---\\ ASIC (ActiveSetup Installed Components) (8) - 2s
O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Microsoft Windows Media Player Setup Utilit.) -- C:\Windows\System32\unregmp2.exe =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - Microsoft(C) Register Server.) -- C:\Windows\System32\regsvr32.exe =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Microsoft Windows Media Player Setup Utilit.) -- C:\Windows\System32\unregmp2.exe =>.Microsoft Corporation
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll =>.Microsoft Corporation®
O40 - ASIC: Google Chrome [64Bits] - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (.Google Inc. - Google Chrome Installer.) -- C:\Program Files (x86)\Google\Chrome\Application\68.0.3440.106\Installer\chrmstp.exe =>.Google Inc®

---\\ Software installed (222) - 28s
O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU][64Bits] -- uTorrent =>.BitTorrent Inc®
O42 - Logiciel: 7-Zip 18.01 (x64) - (.Igor Pavlov.) [HKLM][64Bits] -- 7-Zip =>.Igor Pavlov
O42 - Logiciel: Adobe Acrobat Reader DC - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1033-7B44-AC0F074E4100} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Bridge CC (64 Bit) - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {359F8007-6486-429C-A8C5-D67F6897C88C} =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Flash Player 31 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Flash Player 31 PPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player PPAPI =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Illustrator CC 2015 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {5680D629-B263-49CC-821E-3CEBD4507B51} =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Photoshop CC - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {2D99B50E-431D-4AA8-85C1-172A6F8BCF09} =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-0804-1033-1959-001824272646} =>.Adobe Systems Incorporated
O42 - Logiciel: Advanced Calendar 2.0.0.1000176 - (.MEIXIAN XIE.) [HKLM][64Bits] -- {D9BAB2C9-5236-48c3-AF02-67E799F09BBD} =>.MEIXIAN XIE
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM][64Bits] -- {19589375-5C58-4AFA-842F-8B34744CCEAD} =>.Apple Inc.
O42 - Logiciel: Arabic Rappelz - (.Game Power 7.) [HKLM][64Bits] -- Arabic Rappelz
O42 - Logiciel: Bigasoft Total Video Converter 4.6.0.5589 - (.Bigasoft Corporation.) [HKLM][64Bits] -- {A72CE741-1F32-4D79-BFFB-A714375C678D}_is1 =>.Bigasoft Corporation
O42 - Logiciel: BitTorrent - (.BitTorrent Inc..) [HKCU][64Bits] -- BitTorrent =>.BitTorrent Inc®
O42 - Logiciel: BlueStacks App Player - (.BlueStack Systems, Inc..) [HKLM][64Bits] -- BlueStacks =>.BlueStack Systems, Inc.®
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM][64Bits] -- {56DDDFB8-7F79-4480-89D5-25E1F52AB28F} =>.Apple Inc.
O42 - Logiciel: Canon MF4400 Series - (.Canon Inc..) [HKLM][64Bits] -- {4129CA8E-7E75-4eee-BAE5-AA7707AA7708} =>.Canon Inc.
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>.Piriform Ltd®
O42 - Logiciel: Connect2 - (.Lenovo.) [HKLM][64Bits] -- Connect2_is1 =>.LENOVO®
O42 - Logiciel: DisplayDriverAnalyzer - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer =>.NVIDIA Corporation
O42 - Logiciel: EagleGet version 2.0.4.50 - (.EagleGet.) [HKLM][64Bits] -- {F6D8142A-B30B-454B-9EE0-08A7B997DFE4}_is1 =>.EagleGet
O42 - Logiciel: Entity Framework Tools for Visual Studio 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {08AEF86A-1956-4846-B906-B01350E96E30} =>.Microsoft Corporation
O42 - Logiciel: Epic Games Launcher Prerequisites (x64) - (.Epic Games, Inc..) [HKLM][64Bits] -- {66C5838F-B854-4A55-89E6-A6138747A4DF} =>.Epic Games, Inc.
O42 - Logiciel: Google Chrome - (.Google Inc‎.‎.) [HKLM][64Bits] -- Google Chrome =>.Google Inc®
O42 - Logiciel: Google Earth Pro - (.Google.) [HKLM][64Bits] -- {DE706580-82C7-4B1A-ABA4-EA48AC15B045} =>.Google
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: HP LaserJet Professional CP1020 Series - (.Hewlett-Packard.) [HKLM][64Bits] -- HP LaserJet Professional CP1020 Series =>.Hewlett-Packard
O42 - Logiciel: HP LaserJet Professional P1100-P1560-P1600 Series - (.Hewlett-Packard.) [HKLM][64Bits] -- HP LaserJet Professional P1100-P1560-P1600 Series =>.Hewlett-Packard Company®
O42 - Logiciel: HPLJUT - (.HP.) [HKLM][64Bits] -- {229D6185-BD7E-494B-A73B-C5215BE0690E} =>.HP
O42 - Logiciel: hppcp1025LaserJetService - (.Hewlett-Packard.) [HKLM][64Bits] -- {F31BF057-0D5E-485E-ADFD-560314A27912} =>.Hewlett-Packard
O42 - Logiciel: hppLaserJetService - (.Hewlett-Packard.) [HKLM][64Bits] -- {5093AE98-D510-4BEB-BAC1-7FC8ECE35B98} =>.Hewlett-Packard
O42 - Logiciel: IIS 8.0 Express - (.Microsoft Corporation.) [HKLM][64Bits] -- {7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7} =>.Microsoft Corporation
O42 - Logiciel: IIS Express Application Compatibility Database for x64 - (.Microsoft Corporation.) [HKLM][64Bits] -- {9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb =>.Microsoft Corporation
O42 - Logiciel: IIS Express Application Compatibility Database for x86 - (.Microsoft Corporation.) [HKLM][64Bits] -- {fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb =>.Microsoft Corporation
O42 - Logiciel: Intel(R) C++ Redistributables for Windows* on Intel(R) 64 - (.Intel Corporation.) [HKLM][64Bits] -- {D2437C5C-2D8C-40D2-8059-689AD7239FA3} =>.Intel Corporation
O42 - Logiciel: Intel(R) Driver Update Utility 2.6 - (.Intel.) [HKLM][64Bits] -- {2B710CA5-99F0-4D29-962C-29A7CFF7A989} =>.Intel
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} =>.Intel Corporation - pGFX®
O42 - Logiciel: Intel(R) Product Improvement Program - (.Intel.) [HKLM][64Bits] -- {B9FD2F32-B6ED-477A-98A3-380720F1B553} =>.Intel
O42 - Logiciel: Intel® Driver Update Utility - (.Intel.) [HKLM][64Bits] -- {3e714701-b89c-4cf2-bf3b-41b2c105ffdc} =>.Intel(R) Driver Update Utility®
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM][64Bits] -- {9879F618-79BB-4524-823F-18A6C342F6A2} =>.Apple Inc.
O42 - Logiciel: Java 8 Update 171 (64-bit) - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F64180171F0} =>.Oracle Corporation
O42 - Logiciel: Java Auto Updater - (.Oracle Corporation.) [HKLM][64Bits] -- {4A03706F-666A-4037-7777-5F2748764D10} =>.Oracle Corporation
O42 - Logiciel: Kaspersky Free - (.Kaspersky Lab.) [HKLM][64Bits] -- {718613F4-492D-4272-ACC3-D04A8EF0F883} =>.Kaspersky Lab
O42 - Logiciel: Kaspersky Free - (.Kaspersky Lab.) [HKLM][64Bits] -- InstallWIX_{718613F4-492D-4272-ACC3-D04A8EF0F883} =>.Kaspersky Lab
O42 - Logiciel: Kaspersky Secure Connection - (.Kaspersky Lab.) [HKLM][64Bits] -- {F33C0717-8E04-4EB5-90C8-47221287DB4F} =>.Kaspersky Lab
O42 - Logiciel: Kaspersky Secure Connection - (.Kaspersky Lab.) [HKLM][64Bits] -- InstallWIX_{F33C0717-8E04-4EB5-90C8-47221287DB4F} =>.Kaspersky Lab
O42 - Logiciel: K-Lite Codec Pack 14.1.5 Full - (.KLCP.) [HKLM][64Bits] -- KLiteCodecPack_is1 =>.KLCP
O42 - Logiciel: KMPlayer (remove only) - (.PandoraTV.) [HKLM][64Bits] -- The KMPlayer =>.PandoraTV
O42 - Logiciel: Launcher Prerequisites (x64) - (.Epic Games, Inc..) [HKLM][64Bits] -- {c6c5a357-c7ca-4a5f-9789-3bb1af579253} =>.Epic Games Inc.®
O42 - Logiciel: Microsoft .NET Framework 4 Multi-Targeting Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft .NET Framework 4.5 Multi-Targeting Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {56E962F0-4FB0-3C67-88DB-9EAA6EEFC493} =>.Microsoft Corporation
O42 - Logiciel: Microsoft .NET Framework 4.5 SDK - (.Microsoft Corporation.) [HKLM][64Bits] -- {4AE57014-05C4-4864-A13D-86517A7E1BA4} =>.Microsoft Corporation
O42 - Logiciel: Microsoft .NET Framework 4.5.1 Multi-Targeting Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {6A0C6700-EA93-372C-8871-DCCF13D160A4} =>.Microsoft Corporation
O42 - Logiciel: Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) - (.Microsoft Corporation.) [HKLM][64Bits] -- {D3517C62-68A5-37CF-92F7-93C029A89681} =>.Microsoft Corporation
O42 - Logiciel: Microsoft .NET Framework 4.5.1 SDK - (.Microsoft Corporation.) [HKLM][64Bits] -- {19A5926D-66E1-46FC-854D-163AA10A52D3} =>.Microsoft Corporation
O42 - Logiciel: Microsoft .NET Framework 4.6 - (.Microsoft Corporation.) [HKLM][64Bits] -- {92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033 =>.Microsoft Corporation®
O42 - Logiciel: Microsoft .NET Framework 4.6 - (.Microsoft Corporation.) [HKLM][64Bits] -- {94A631D5-B30A-3DD8-B65C-1117C09DA73E} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Access MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0015-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft DCF MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0090-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Excel MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0016-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Exchange Web Services Managed API 2.0 - (.Microsoft Corporation.) [HKLM][64Bits] -- {6EE9E2DF-2CD7-4952-A649-95DEA8697BD8} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Groove MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00BA-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Help Viewer 2.1 - (.Microsoft Corporation.) [HKLM][64Bits] -- {0398BFBC-991B-3275-9463-D2BF91B3C80B} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Help Viewer 2.1 - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Help Viewer 2.1 =>.Microsoft Corporation
O42 - Logiciel: Microsoft Identity Extensions - (.Microsoft Corporation.) [HKLM][64Bits] -- {F99F24BF-0B90-463E-9658-3FD2EFC3C992} =>.Microsoft Corporation
O42 - Logiciel: Microsoft InfoPath MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0044-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Lync MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-012B-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office 32-bit Components 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00C1-0000-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Access MUI (Arabic) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-0015-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Enterprise 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-0030-0000-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Enterprise 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- ENTERPRISE =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Office Excel MUI (Arabic) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-0016-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Groove MUI (English) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-00BA-0409-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Groove Setup Metadata MUI (Arabic) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-0114-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office InfoPath MUI (Arabic) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-0044-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Office 64-bit Components 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-002A-0000-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office OneNote MUI (Arabic) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-00A1-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office OSM MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00E1-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office OSM UX MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00E2-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Outlook MUI (Arabic) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-001A-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office PowerPoint MUI (Arabic) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-0018-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Professional Plus 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {91150000-0011-0000-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Professional Plus 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- Office15.PROPLUSR =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Office Proof (Arabic) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-001F-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proof (English) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-001F-0409-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proof (French) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-001F-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proofing (Arabic) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-002C-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proofing (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-002C-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proofing Tools 2013 - English - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001F-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proofing Tools 2013 - اللغة العربية - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001F-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Publisher MUI (Arabic) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-0019-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Shared 32-bit MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00C1-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Shared 64-bit MUI (Arabic) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-002A-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Shared 64-bit MUI (English) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-002A-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Shared MUI (Arabic) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-006E-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Shared MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-006E-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Shared MUI (English) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-006E-0409-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Word MUI (Arabic) 2007 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90120000-001B-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft OneNote MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00A1-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Outlook MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001A-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft PowerPoint MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0018-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Publisher MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0019-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Silverlight 5 SDK - (.Microsoft Corporation.) [HKLM][64Bits] -- {E1FBB3D4-ADB0-4949-B101-855DA061C735} =>.Microsoft Corporation
O42 - Logiciel: Microsoft SQL Server 2012 Command Line Utilities - (.Microsoft Corporation.) [HKLM][64Bits] -- {58FED865-4F13-408D-A5BF-996019C4B936} =>.Microsoft Corporation
O42 - Logiciel: Microsoft SQL Server 2012 Data-Tier App Framework - (.Microsoft Corporation.) [HKLM][64Bits] -- {1B876496-B3A2-4D22-9B12-B608A3FD4B8B} =>.Microsoft Corporation
O42 - Logiciel: Microsoft SQL Server 2012 Data-Tier App Framework (x64) - (.Microsoft Corporation.) [HKLM][64Bits] -- {A6BA243E-85A3-4635-A269-32949C98AC7F} =>.Microsoft Corporation
O42 - Logiciel: Microsoft SQL Server 2012 Express LocalDB - (.Microsoft Corporation.) [HKLM][64Bits] -- {6C026A91-640F-4A23-8B68-05D589CC6F18} =>.Microsoft Corporation
O42 - Logiciel: Microsoft SQL Server 2012 Management Objects - (.Microsoft Corporation.) [HKLM][64Bits] -- {2F7DBBE6-8EBC-495C-9041-46A772F4E311} =>.Microsoft Corporation
O42 - Logiciel: Microsoft SQL Server 2012 Management Objects (x64) - (.Microsoft Corporation.) [HKLM][64Bits] -- {43A5C316-9521-49C3-B9B6-FCE5E1005DF0} =>.Microsoft Corporation
O42 - Logiciel: Microsoft SQL Server 2012 Native Client - (.Microsoft Corporation.) [HKLM][64Bits] -- {D411E9C9-CE62-4DBF-9D92-4CB22B750ED5} =>.Microsoft Corporation
O42 - Logiciel: Microsoft SQL Server 2012 Transact-SQL ScriptDom - (.Microsoft Corporation.) [HKLM][64Bits] -- {54C5041B-0E91-4E92-8417-AAA12493C790} =>.Microsoft Corporation
O42 - Logiciel: Microsoft SQL Server 2012 T-SQL Language Service - (.Microsoft Corporation.) [HKLM][64Bits] -- {04DD7AF4-A6D3-4E30-9BB9-3B3670719234} =>.Microsoft Corporation
O42 - Logiciel: Microsoft SQL Server Compact 4.0 SP1 x64 ENU - (.Microsoft Corporation.) [HKLM][64Bits] -- {78909610-D229-459C-A936-25D92283D3FD} =>.Microsoft Corporation
O42 - Logiciel: Microsoft SQL Server Data Tools - enu (12.0.30919.1) - (.Microsoft Corporation.) [HKLM][64Bits] -- {0D7FCBFB-F478-4D32-901C-83F0BF5A3501} =>.Microsoft Corporation
O42 - Logiciel: Microsoft SQL Server Data Tools Build Utilities - enu (12.0.30919.1) - (.Microsoft Corporation.) [HKLM][64Bits] -- {6781FF9B-E87D-4A03-9373-A55A288B83FA} =>.Microsoft Corporation
O42 - Logiciel: Microsoft SQL Server System CLR Types - (.Microsoft Corporation.) [HKLM][64Bits] -- {A47FD1BF-A815-4A76-BE65-53A15BD5D25D} =>.Microsoft Corporation
O42 - Logiciel: Microsoft SQL Server System CLR Types (x64) - (.Microsoft Corporation.) [HKLM][64Bits] -- {4701DEDE-1888-49E0-BAE5-857875924CA2} =>.Microsoft Corporation
O42 - Logiciel: Microsoft System CLR Types for SQL Server 2012 - (.Microsoft Corporation.) [HKLM][64Bits] -- {070C38AC-05CE-43DF-9A20-141332F6AB2B} =>.Microsoft Corporation
O42 - Logiciel: Microsoft System CLR Types for SQL Server 2012 (x64) - (.Microsoft Corporation.) [HKLM][64Bits] -- {05FF8209-C4F1-4C77-BC28-791653156D20} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM][64Bits] -- {710f4c1c-cc18-4c49-8cbf-51240c89a1a2} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM][64Bits] -- {837b34e3-7c30-493c-8f6a-2b0f04e2912c} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable (x64) - (.Microsoft Corporation.) [HKLM][64Bits] -- {6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable (x64) - (.Microsoft Corporation.) [HKLM][64Bits] -- {ad8a2fa1-06e7-4b0d-927d-6e54b3d31028} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 - (.Microsoft Corporation.) [HKLM][64Bits] -- {350AA351-21FA-3270-8B7A-835434E766AD} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM][64Bits] -- {4B6C7001-C7D6-3710-913E-5BC23FCE91E6} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 - (.Microsoft Corporation.) [HKLM][64Bits] -- {5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM][64Bits] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 - (.Microsoft Corporation.) [HKLM][64Bits] -- {9BE518E6-ECC6-35A9-88E4-87755C07200F} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 - (.Microsoft Corporation.) [HKLM][64Bits] -- {1D8E6291-B0D5-35EC-8441-6616F567A0F7} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 - (.Microsoft Corporation.) [HKLM][64Bits] -- {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 - (.Microsoft Corporation.) [HKLM][64Bits] -- {ca67548a-5ebe-413a-b50c-4b9ceb6d66c6} =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 - (.Microsoft Corporation.) [HKLM][64Bits] -- {95716cce-fc71-413f-8ad5-56c2892d4b3a} =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 - (.Microsoft Corporation.) [HKLM][64Bits] -- {33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 - (.Microsoft Corporation.) [HKLM][64Bits] -- {37B8F9C7-03FB-3253-8781-2517C99D7C00} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 - (.Microsoft Corporation.) [HKLM][64Bits] -- {CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 - (.Microsoft Corporation.) [HKLM][64Bits] -- {B175520C-86A2-35A7-8619-86DC379688B9} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 - (.Microsoft Corporation.) [HKLM][64Bits] -- {BD95A8CD-1D9F-35AD-981A-3E7925026EBB} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 - (.Microsoft Corporation.) [HKLM][64Bits] -- {050d4fc8-5d48-4b8f-8972-47c82c46020f} =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 - (.Microsoft Corporation.) [HKLM][64Bits] -- {f65db027-aff3-4070-886a-0d87064aabb1} =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 - (.Microsoft Corporation.) [HKLM][64Bits] -- {929FBD26-9020-399B-9A7A-751D61F0B942} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 - (.Microsoft Corporation.) [HKLM][64Bits] -- {A749D8E6-B613-3BE3-8F5F-045C84EBA29B} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 - (.Microsoft Corporation.) [HKLM][64Bits] -- {F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 - (.Microsoft Corporation.) [HKLM][64Bits] -- {13A4EE12-23EA-3371-91EE-EFB36DDFFF3E} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 - (.Microsoft Corporation.) [HKLM][64Bits] -- {d992c12e-cab2-426f-bde3-fb8c53950b0d} =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 - (.Microsoft Corporation.) [HKLM][64Bits] -- {462f63a8-6347-4894-a1b3-dbfe3a4c981d} =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.24215 - (.Microsoft Corporation.) [HKLM][64Bits] -- {EF1EC6A9-17DE-3DA9-B040-686A1E8A8B04} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.24215 - (.Microsoft Corporation.) [HKLM][64Bits] -- {50A2BC33-C9CD-3BF1-A8FF-53C10A0B183C} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24212 - (.Microsoft Corporation.) [HKLM][64Bits] -- {844ECB74-9B63-3D5C-958C-30BD23F19EE4} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24212 - (.Microsoft Corporation.) [HKLM][64Bits] -- {37B55901-995A-3650-80B1-BBFD047E2911} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual Studio 2010 Tools for Office Runtime (x64) - (.Microsoft Corporation.) [HKLM][64Bits] -- {B47797F6-4C28-3F32-83DC-2784335CA487} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual Studio 2010 Tools for Office Runtime (x64) - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Visual Studio 2010 Tools for Office Runtime (x64) =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Web Deploy 3.5 - (.Microsoft Corporation.) [HKLM][64Bits] -- {3674F088-9B90-473A-AAC3-20A00D8D810C} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Word MUI (Arabic) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001B-0401-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Minecraft1.10 - (.Microsoft Corporation.) [HKLM][64Bits] -- Minecraft1.10 =>.Microsoft Corporation
O42 - Logiciel: Mozilla Firefox 61.0.1 (x64 en-US) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 61.0.1 (x64 en-US) =>.Mozilla Corporation®
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService =>.Mozilla
O42 - Logiciel: Nidhogg - (..) [HKLM][64Bits] -- TmlkaG9nZw==_is1
O42 - Logiciel: Nmap 7.25BETA2 - (.Fyodor.) [HKLM][64Bits] -- Nmap =>.Fyodor
O42 - Logiciel: Notepad++ (32-bit x86) - (.Notepad++ Team.) [HKLM][64Bits] -- Notepad++ =>.Notepad++ Team
O42 - Logiciel: NVIDIA Ansel - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Backend - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvBackend =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Control Panel 391.24 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Display Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Display Container LS - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainerLS =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Display Session Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplaySessionContainer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Display Watchdog Plugin - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayPluginWatchdog =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA GeForce Experience 3.13.1.30 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Graphics Driver 391.24 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Install Application - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA LocalSystem Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.LocalSystem =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Message Bus for NvContainer - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.MessageBus =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA NetworkService Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NetworkService =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA NodeJS - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Optimus Update 31.1.10.0 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA PhysX System Software 9.17.0524 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Session Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.Session =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA ShadowPlay 3.13.1.30 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay =>.NVIDIA Corporation
O42 - Logiciel: Nvidia Share - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_OSC =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA SHIELD Streaming - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA SHIELD Wireless Controller Driver - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Telemetry Client - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Telemetry Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetryContainer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA TelemetryApi helper for NvContainer - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.ContainerTelemetryApiHelper =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Update 31.1.10.0 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Update Core - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA User Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.User =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Virtual Audio 4.04.0 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Virtual Host Controller - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvvHci =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Watchdog Plugin for NvContainer - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvPlugin.Watchdog =>.NVIDIA Corporation
O42 - Logiciel: Open XML SDK 2.5 for Microsoft Office - (.Microsoft Corporation.) [HKLM][64Bits] -- {3EA16E23-14D2-466A-8268-D7CD40DC46B6} =>.Microsoft Corporation
O42 - Logiciel: Opera Stable 42.0.2393.137 - (.Opera Software.) [HKLM][64Bits] -- Opera 42.0.2393.137 =>.Opera Software AS®
O42 - Logiciel: Opera Stable 55.0.2994.61 - (.Opera Software.) [HKLM][64Bits] -- Opera 55.0.2994.61 =>.Opera Software AS®
O42 - Logiciel: Outils de vérification linguistique 2013 de Microsoft Office - Français - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001F-040C-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: PDF Settings CC - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {1FBAE18D-4DE4-47AA-83EC-D1B046F262DC} =>.Adobe Systems Incorporated
O42 - Logiciel: Prerequisites for SSDT - (.Microsoft Corporation.) [HKLM][64Bits] -- {35C1D9D6-87C0-46A3-B1B4-EDBCC063221C} =>.Microsoft Corporation
O42 - Logiciel: QmEye version V2.4.11.3 - (..) [HKLM][64Bits] -- {B63D1468-3E9E-44A7-9F63-8017DE27C6CF}_is1
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Recuva - (.Piriform.) [HKLM][64Bits] -- Recuva =>.Piriform Ltd®
O42 - Logiciel: RtkClassFilter - (.REALTEK Semiconductor Corp.) [HKLM][64Bits] -- {8220FCF2-A57F-4236-BFCC-C6C2268E851E} =>.REALTEK Semiconductor Corp
O42 - Logiciel: RtkClassFilter - (.REALTEK Semiconductor Corp.) [HKLM][64Bits] -- InstallShield_{8220FCF2-A57F-4236-BFCC-C6C2268E851E} =>.REALTEK Semiconductor Corp
O42 - Logiciel: SHAREit - (.SHAREit Technologies Co.Ltd.) [HKLM][64Bits] -- www.ushareit.com_is1 =>.SHAREit Technologies Co.Ltd
O42 - Logiciel: SharePoint Client Components - (.Microsoft Corporation.) [HKLM][64Bits] -- {95150001-1163-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Steam - (.Valve Corporation.) [HKLM][64Bits] -- Steam =>.Valve®
O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey =>.Synaptics Incorporated
O42 - Logiciel: Teeworlds - (.Teeworlds Team.) [HKLM][64Bits] -- Steam App 380840 =>.Valve®
O42 - Logiciel: Tencent Gaming Buddy - (.Tencent Technology Company.) [HKLM][64Bits] -- MobileGamePC =>.SUP.Tencent
O42 - Logiciel: Update for Microsoft Office Word 2007 (KB974631) - (..) [HKLM][64Bits] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{1D53FB73-9826-4541-B2E0-A239C6EBA718}
O42 - Logiciel: Update for Microsoft Office Word 2007 (KB974631) - (..) [HKLM][64Bits] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{34726474-50D6-49FC-B8AC-35411459D27A}
O42 - Logiciel: Viber - (.Viber Media Inc..) [HKCU][64Bits] -- {d924dc86-33fe-49b3-9439-8b0e69ec7216} =>.Viber Media S.à r.l.®
O42 - Logiciel: Viber - (.Viber Media Inc..) [HKLM][64Bits] -- {01B68243-D530-42B0-97D4-DB4DDF236E2F} =>.Viber Media Inc.
O42 - Logiciel: VirtualCloneDrive - (.Elaborate Bytes.) [HKLM][64Bits] -- VirtualCloneDrive =>.Elaborate Bytes
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
O42 - Logiciel: VMware Player - (.VMware, Inc..) [HKLM][64Bits] -- {BC00AC33-2B00-443D-8FC2-3656D94AEA0A} =>.VMware, Inc.
O42 - Logiciel: Vulkan Run Time Libraries 1.0.65.1 - (.LunarG, Inc..) [HKLM][64Bits] -- VulkanRT1.0.65.1 =>.LunarG, Inc.®
O42 - Logiciel: WCF RIA Services V1.0 SP2 - (.Microsoft Corporation.) [HKLM][64Bits] -- {5D8DD6A8-C4D7-4554-93F9-F1CC28C72600} =>.Microsoft Corporation
O42 - Logiciel: Windows Driver Package - Realtek Semiconductor Corp. RtkBtFilter Bluetooth - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- EA90D42054890B3938D0BEF1E8A316D20C6D6003 =>.Microsoft Windows®
O42 - Logiciel: WinRAR 5.30 (32-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver =>.win.rar GmbH®
O42 - Logiciel: ZeroTier One Virtual Network Port - (.ZeroTier.) [HKLM][64Bits] -- {4AFE4740-C680-40FE-B6B0-0C15EB0176F1} =>.ZeroTier
O42 - Logiciel: دعم تطبيقات Apple‏ (32 بت) - (.Apple Inc..) [HKLM][64Bits] -- {543F829B-4591-4B2F-AF63-6E6E6AE59EB2} =>.Apple Inc.
O42 - Logiciel: دعم تطبيقات Apple‏ (64 بت) - (.Apple Inc..) [HKLM][64Bits] -- {0ECA3BB5-4410-414B-B226-241FF1C12CD0} =>.Apple Inc.

---\\ HKCU & HKLM Software Keys (372) - 28s
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\Software\BSD =>.SUP.DriverUpdatePlus
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drp.su =>.SUP.DriverPack
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com =>PUP.Optional.LavasoftWebCompanion
HKCU\Software\Lavasoft\Web Companion =>PUP.Optional.LavasoftWebCompanion
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drp.su =>.SUP.DriverPack
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com =>PUP.Optional.LavasoftWebCompanion
HKLM\SOFTWARE\Wow6432Node\Lavasoft\Web Companion =>PUP.Optional.LavasoftWebCompanion
HKLM\SOFTWARE\Lavasoft\Web Companion =>PUP.Optional.LavasoftWebCompanion
HKLM\SOFTWARE\Activision =>.Activision
HKLM\SOFTWARE\Adobe =>.Adobe
HKLM\SOFTWARE\AGEIA Technologies =>.AGEIA Technologies
HKLM\SOFTWARE\Apple Inc. =>.Apple Inc.
HKLM\SOFTWARE\Auslogics =>.Auslogics
HKLM\SOFTWARE\Autodesk =>.Autodesk
HKLM\SOFTWARE\AVAST Software =>.AVAST Software
HKLM\SOFTWARE\AVG =>.AVG Software
HKLM\SOFTWARE\Baidu =>.Baidu
HKLM\SOFTWARE\Bigasoft =>.Bigasoft Corporation
HKLM\SOFTWARE\BlueStacks =>.BlueStack Systems, Inc.
HKLM\SOFTWARE\BlueStacksGP =>.BlueStack Systems, Inc.
HKLM\SOFTWARE\BSD =>.Berkeley
HKLM\SOFTWARE\Canon =>.Canon
HKLM\SOFTWARE\Cela.C.M
HKLM\SOFTWARE\CloudOPTInfo =>.Baidu Technology
HKLM\SOFTWARE\Core Design =>.Core Design
HKLM\SOFTWARE\drpsu =>.SUP.DriverPack
HKLM\SOFTWARE\EagleGet =>.EagleGet
HKLM\SOFTWARE\EasyAntiCheat =>.EasyAntiCheat
HKLM\SOFTWARE\Elaborate Bytes =>.Elaborate Bytes
HKLM\SOFTWARE\Firefly Studios =>.Firefly Studios
HKLM\SOFTWARE\Fraps =>.Beepa
HKLM\SOFTWARE\Google =>.Google
HKLM\SOFTWARE\HaaliMkx =>.Haali Media
HKLM\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard
HKLM\SOFTWARE\HewlettPackard =>.Hewlett-Packard
HKLM\SOFTWARE\HP =>.HP
HKLM\SOFTWARE\Huawei technologies =>.Huawei Technologies
HKLM\SOFTWARE\Icaros =>.Icaros
HKLM\SOFTWARE\Intel =>.Intel
HKLM\SOFTWARE\InterVideo =>.InterVideo
HKLM\SOFTWARE\JavaSoft =>.JavaSoft
HKLM\SOFTWARE\JreMetrics =>.JreMetrics
HKLM\SOFTWARE\KasperskyLab =>.Kaspersky Labs
HKLM\SOFTWARE\Khronos =>.Khronos
HKLM\SOFTWARE\KLCodecPack =>.KLite Inc
HKLM\SOFTWARE\KMPlayer =>.KMPlayer
HKLM\SOFTWARE\LAV =>.LAV Inc
HKLM\SOFTWARE\Lavasoft =>.Lavasoft
HKLM\SOFTWARE\Lenovo =>.Lenovo
HKLM\SOFTWARE\LogMeInRescueCallingCard =>.LogMeIn Entreprise
HKLM\SOFTWARE\Macromedia =>.Macromedia
HKLM\SOFTWARE\Mozilla =>.Mozilla
HKLM\SOFTWARE\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\nFlavor =>.nFlavor
HKLM\SOFTWARE\Notepad++ =>.Don Ho
HKLM\SOFTWARE\Nuance =>.Nuance
HKLM\SOFTWARE\NuGet =>.Microsoft Corporation
HKLM\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation
HKLM\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\Opera Software =>.Opera Software
HKLM\SOFTWARE\Pixologic =>.Pixologic
HKLM\SOFTWARE\PowerPivot =>.PowerPivot
HKLM\SOFTWARE\SHAREit Technologies =>..SUP.SHAREit
HKLM\SOFTWARE\SoftEther Project =>.SoftEther Project
HKLM\SOFTWARE\TechSmith =>.TechSmith
HKLM\SOFTWARE\Tencent =>.SUP.Tencent
HKLM\SOFTWARE\ThinPrint =>.ThinPrint
HKLM\SOFTWARE\TOSHIBA =>.Toshiba Corporation
HKLM\SOFTWARE\Valve =>.Valve
HKLM\SOFTWARE\VideoLAN =>.VideoLAN
HKLM\SOFTWARE\VMware, Inc. =>.VMware, Inc.
HKLM\SOFTWARE\WIBU-SYSTEMS =>.Wibu-Systems
HKLM\SOFTWARE\WiMax
HKLM\SOFTWARE\WinRAR =>.WinRAR
HKLM\SOFTWARE\ZeroTier =>.ZeroTier
HKLM\SOFTWARE\Even Balance =>.Even Balance Inc
HKLM\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\Activision =>.Activision
HKLM\SOFTWARE\WOW6432Node\Adobe =>.Adobe
HKLM\SOFTWARE\WOW6432Node\AGEIA Technologies =>.AGEIA Technologies
HKLM\SOFTWARE\WOW6432Node\Apple Inc. =>.Apple Inc.
HKLM\SOFTWARE\WOW6432Node\Auslogics =>.Auslogics
HKLM\SOFTWARE\WOW6432Node\Autodesk =>.Autodesk
HKLM\SOFTWARE\WOW6432Node\AVAST Software =>.AVAST Software
HKLM\SOFTWARE\WOW6432Node\AVG =>.AVG Software
HKLM\SOFTWARE\WOW6432Node\Baidu =>.Baidu
HKLM\SOFTWARE\WOW6432Node\Bigasoft =>.Bigasoft Corporation
HKLM\SOFTWARE\WOW6432Node\BlueStacks =>.BlueStack Systems, Inc.
HKLM\SOFTWARE\WOW6432Node\BlueStacksGP =>.BlueStack Systems, Inc.
HKLM\SOFTWARE\WOW6432Node\BSD =>.Berkeley
HKLM\SOFTWARE\WOW6432Node\Canon =>.Canon
HKLM\SOFTWARE\WOW6432Node\Cela.C.M
HKLM\SOFTWARE\WOW6432Node\CloudOPTInfo =>.Baidu Technology
HKLM\SOFTWARE\WOW6432Node\Core Design =>.Core Design
HKLM\SOFTWARE\WOW6432Node\drpsu =>.SUP.DriverPack
HKLM\SOFTWARE\WOW6432Node\EagleGet =>.EagleGet
HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat =>.EasyAntiCheat
HKLM\SOFTWARE\WOW6432Node\Elaborate Bytes =>.Elaborate Bytes
HKLM\SOFTWARE\WOW6432Node\Firefly Studios =>.Firefly Studios
HKLM\SOFTWARE\WOW6432Node\Fraps =>.Beepa
HKLM\SOFTWARE\WOW6432Node\Google =>.Google
HKLM\SOFTWARE\WOW6432Node\HaaliMkx =>.Haali Media
HKLM\SOFTWARE\WOW6432Node\Hewlett-Packard =>.Hewlett-Packard
HKLM\SOFTWARE\WOW6432Node\HewlettPackard =>.Hewlett-Packard
HKLM\SOFTWARE\WOW6432Node\HP =>.HP
HKLM\SOFTWARE\WOW6432Node\Huawei technologies =>.Huawei Technologies
HKLM\SOFTWARE\WOW6432Node\Icaros =>.Icaros
HKLM\SOFTWARE\WOW6432Node\Intel =>.Intel
HKLM\SOFTWARE\WOW6432Node\InterVideo =>.InterVideo
HKLM\SOFTWARE\WOW6432Node\JavaSoft =>.JavaSoft
HKLM\SOFTWARE\WOW6432Node\JreMetrics =>.JreMetrics
HKLM\SOFTWARE\WOW6432Node\KasperskyLab =>.Kaspersky Labs
HKLM\SOFTWARE\WOW6432Node\Khronos =>.Khronos
HKLM\SOFTWARE\WOW6432Node\KLCodecPack =>.KLite Inc
HKLM\SOFTWARE\WOW6432Node\KMPlayer =>.KMPlayer
HKLM\SOFTWARE\WOW6432Node\LAV =>.LAV Inc
HKLM\SOFTWARE\WOW6432Node\Lavasoft =>.Lavasoft
HKLM\SOFTWARE\WOW6432Node\Lenovo =>.Lenovo
HKLM\SOFTWARE\WOW6432Node\LogMeInRescueCallingCard =>.LogMeIn Entreprise
HKLM\SOFTWARE\WOW6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\WOW6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\WOW6432Node\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\WOW6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\WOW6432Node\nFlavor =>.nFlavor
HKLM\SOFTWARE\WOW6432Node\Notepad++ =>.Don Ho
HKLM\SOFTWARE\WOW6432Node\Nuance =>.Nuance
HKLM\SOFTWARE\WOW6432Node\NuGet =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\NVIDIA Corporation =>.nVidia Corporation
HKLM\SOFTWARE\WOW6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\WOW6432Node\Opera Software =>.Opera Software
HKLM\SOFTWARE\WOW6432Node\Pixologic =>.Pixologic
HKLM\SOFTWARE\WOW6432Node\PowerPivot =>.PowerPivot
HKLM\SOFTWARE\WOW6432Node\SHAREit Technologies =>..SUP.SHAREit
HKLM\SOFTWARE\WOW6432Node\SoftEther Project =>.SoftEther Project
HKLM\SOFTWARE\WOW6432Node\TechSmith =>.TechSmith
HKLM\SOFTWARE\WOW6432Node\Tencent =>.SUP.Tencent
HKLM\SOFTWARE\WOW6432Node\ThinPrint =>.ThinPrint
HKLM\SOFTWARE\WOW6432Node\TOSHIBA =>.Toshiba Corporation
HKLM\SOFTWARE\WOW6432Node\Valve =>.Valve
HKLM\SOFTWARE\WOW6432Node\VideoLAN =>.VideoLAN
HKLM\SOFTWARE\WOW6432Node\VMware, Inc. =>.VMware, Inc.
HKLM\SOFTWARE\WOW6432Node\WIBU-SYSTEMS =>.Wibu-Systems
HKLM\SOFTWARE\WOW6432Node\WiMax
HKLM\SOFTWARE\WOW6432Node\WinRAR =>.WinRAR
HKLM\SOFTWARE\WOW6432Node\ZeroTier =>.ZeroTier
HKLM\SOFTWARE\WOW6432Node\Even Balance =>.Even Balance Inc
HKLM\SOFTWARE\WOW6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\7-Zip =>.Igor Pavlov
HKCU\SOFTWARE\Adobe =>.Adobe
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\Apple Computer, Inc. =>.Apple Computer, Inc.
HKCU\SOFTWARE\Apple Inc. =>.Apple Inc.
HKCU\SOFTWARE\Autodesk =>.Autodesk
HKCU\SOFTWARE\AutoKeybot
HKCU\SOFTWARE\Avg =>.AVG Software
HKCU\SOFTWARE\Baidu =>.Baidu
HKCU\SOFTWARE\Bennett Foddy
HKCU\SOFTWARE\Bigasoft =>.Bigasoft Corporation
HKCU\SOFTWARE\BitTorrent =>.BitTorrent (P2P)
HKCU\SOFTWARE\Blizzard Entertainment =>.Blizzard Entertainment
HKCU\SOFTWARE\Boneloaf
HKCU\SOFTWARE\BreakPoint =>.BreakPoint
HKCU\SOFTWARE\BreakPoint License Manager
HKCU\SOFTWARE\Browser Cleanup =>.Avast Software s.r.o
HKCU\SOFTWARE\BSD =>.Berkeley
HKCU\SOFTWARE\Bugsplat =>.Bugsplat Game
HKCU\SOFTWARE\CampoSanto
HKCU\SOFTWARE\Canon =>.Canon
HKCU\SOFTWARE\Chromium =>.Chromium
HKCU\SOFTWARE\Core Design =>.Core Design
HKCU\SOFTWARE\Corel =>.Corel
HKCU\SOFTWARE\DownloadManager =>.DownloadManager
HKCU\SOFTWARE\DriverToolkit =>.SUP.DriverToolkit
HKCU\SOFTWARE\drpsu =>.SUP.DriverPack
HKCU\SOFTWARE\EagleGet =>.EagleGet
HKCU\SOFTWARE\Echobit =>.Echobit
HKCU\SOFTWARE\Elaborate Bytes =>.Elaborate Bytes
HKCU\SOFTWARE\Epic Games =>.Epic Games
HKCU\SOFTWARE\Gabest =>.Gabest
HKCU\SOFTWARE\giveawayoftheday.com =>.giveawayoftheday.com
HKCU\SOFTWARE\GNU =>.GNU
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\Haali =>.Haali Media
HKCU\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard
HKCU\SOFTWARE\HP =>.HP
HKCU\SOFTWARE\Icaros =>.Icaros
HKCU\SOFTWARE\IM Providers =>.IM Providers
HKCU\SOFTWARE\INCAInternet =>.INCAInternet
HKCU\SOFTWARE\Informer Technologies, Inc. =>.Informer Technologies, Inc.
HKCU\SOFTWARE\Intel =>.Intel
HKCU\SOFTWARE\JavaSoft =>.JavaSoft
HKCU\SOFTWARE\JEDI-VCL =>.JEDI Project
HKCU\SOFTWARE\JVSG
HKCU\SOFTWARE\KasperskyLab =>.Kaspersky Labs
HKCU\SOFTWARE\KasperskyLabSetup =>.Kaspersky Labs
HKCU\SOFTWARE\KMPlayer =>.KMPlayer
HKCU\SOFTWARE\L2j Community Network =>.L2j Community Network
HKCU\SOFTWARE\Lavalys =>.Lavalys
HKCU\SOFTWARE\Lavasoft =>.Lavasoft
HKCU\SOFTWARE\Lenovo =>.Lenovo
HKCU\SOFTWARE\Macromedia =>.Macromedia
HKCU\SOFTWARE\madshi =>.madshi.net
HKCU\SOFTWARE\MainConcept =>.MainConcept AG
HKCU\SOFTWARE\Marvell =>.Marvell
HKCU\SOFTWARE\MediaChance =>.Mediachance
HKCU\SOFTWARE\MediaInfo =>.Jérôme Martinez
HKCU\SOFTWARE\MMBPlayer
HKCU\SOFTWARE\MONOGRAM =>.MOO Software
HKCU\SOFTWARE\Mootools =>.Legitimate
HKCU\SOFTWARE\Motion Analysis =>.Motion Analysis
HKCU\SOFTWARE\Mozilla =>.Mozilla
HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKCU\SOFTWARE\MPC-HC =>.MPC-HC Team
HKCU\SOFTWARE\MurGee.com =>.MurGee.com
HKCU\SOFTWARE\Netscape =>.Netscape
HKCU\SOFTWARE\Nmap =>.Fyodor
HKCU\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation
HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKCU\SOFTWARE\Opera Software =>.Opera Software
HKCU\SOFTWARE\PCTuneUp =>.NNJ Corporation
HKCU\SOFTWARE\Piriform =>.Piriform
HKCU\SOFTWARE\Playdead =>.Playdead
HKCU\SOFTWARE\PortableApps.com =>.PortableApps.com
HKCU\SOFTWARE\QtProject =>.QtProject
HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKCU\SOFTWARE\RobotSoft
HKCU\SOFTWARE\SecuROM =>.SecuROM
HKCU\SOFTWARE\SHAREit Technologies =>..SUP.SHAREit
HKCU\SOFTWARE\SKS =>.SKS Software
HKCU\SOFTWARE\SoftEther Corporation =>.SoftEther Corporation
HKCU\SOFTWARE\SoftEther Project =>.SoftEther Project
HKCU\SOFTWARE\Synaptics =>.Synaptics
HKCU\SOFTWARE\TechSmith =>.TechSmith
HKCU\SOFTWARE\Tencent =>.SUP.Tencent
HKCU\SOFTWARE\TheGameBakers
HKCU\SOFTWARE\TOSHIBA =>.Toshiba Corporation
HKCU\SOFTWARE\Transcend
HKCU\SOFTWARE\Transcend Elite
HKCU\SOFTWARE\Trolltech =>.Trolltech
HKCU\SOFTWARE\Unity =>.Unity
HKCU\SOFTWARE\user32.dll
HKCU\SOFTWARE\Valve =>.Valve
HKCU\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation
HKCU\SOFTWARE\Viber =>.Viber
HKCU\SOFTWARE\Viber Media S.à r.l
HKCU\SOFTWARE\Wargaming.net =>.Wargaming.net
HKCU\SOFTWARE\Winamp =>.Nullsoft Inc.
HKCU\SOFTWARE\WinRAR =>.WinRAR
HKCU\SOFTWARE\WinRAR SFX =>.RarLab
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\ZebHelpProcess Helper =>.Nicolas Coolman
HKCU\SOFTWARE\ZebraNetworkSystems
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKU\.DEFAULT\SOFTWARE\Apple Inc. =>.Apple Inc.
HKU\.DEFAULT\SOFTWARE\Autodesk =>.Autodesk
HKU\.DEFAULT\SOFTWARE\CyberGhost =>.CyberGhost S.R.L
HKU\.DEFAULT\SOFTWARE\Epic Games =>.Epic Games
HKU\.DEFAULT\SOFTWARE\KasperskyLabSetup =>.Kaspersky Labs
HKU\.DEFAULT\SOFTWARE\Netscape =>.Netscape
HKU\.DEFAULT\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation
HKU\.DEFAULT\SOFTWARE\Opera Software =>.Opera Software
HKU\.DEFAULT\SOFTWARE\Piriform =>.Piriform
HKU\.DEFAULT\SOFTWARE\Protexis64
HKU\.DEFAULT\SOFTWARE\Synaptics =>.Synaptics
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\7-Zip =>.Igor Pavlov
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Adobe =>.Adobe
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Apple Computer, Inc. =>.Apple Computer, Inc.
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Apple Inc. =>.Apple Inc.
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Autodesk =>.Autodesk
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\AutoKeybot
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Avg =>.AVG Software
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Baidu =>.Baidu
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Bennett Foddy
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Bigasoft =>.Bigasoft Corporation
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\BitTorrent =>.BitTorrent (P2P)
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Blizzard Entertainment =>.Blizzard Entertainment
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Boneloaf
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\BreakPoint =>.BreakPoint
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\BreakPoint License Manager
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Browser Cleanup =>.Avast Software s.r.o
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\BSD =>.Berkeley
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Bugsplat =>.Bugsplat Game
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\CampoSanto
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Canon =>.Canon
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Chromium =>.Chromium
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Core Design =>.Core Design
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Corel =>.Corel
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\DownloadManager =>.DownloadManager
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\DriverToolkit =>.SUP.DriverToolkit
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\drpsu =>.SUP.DriverPack
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\EagleGet =>.EagleGet
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Echobit =>.Echobit
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Elaborate Bytes =>.Elaborate Bytes
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Epic Games =>.Epic Games
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Gabest =>.Gabest
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\giveawayoftheday.com =>.giveawayoftheday.com
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\GNU =>.GNU
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Google =>.Google
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Haali =>.Haali Media
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\HP =>.HP
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Icaros =>.Icaros
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\IM Providers =>.IM Providers
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\INCAInternet =>.INCAInternet
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Informer Technologies, Inc. =>.Informer Technologies, Inc.
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Intel =>.Intel
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\JavaSoft =>.JavaSoft
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\JEDI-VCL =>.JEDI Project
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\JVSG
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\KasperskyLab =>.Kaspersky Labs
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\KasperskyLabSetup =>.Kaspersky Labs
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\KMPlayer =>.KMPlayer
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\L2j Community Network =>.L2j Community Network
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Lavalys =>.Lavalys
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Lavasoft =>.Lavasoft
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Lenovo =>.Lenovo
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Macromedia =>.Macromedia
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\madshi =>.madshi.net
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\MainConcept =>.MainConcept AG
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Marvell =>.Marvell
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\MediaChance =>.Mediachance
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\MediaInfo =>.Jérôme Martinez
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\MMBPlayer
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\MONOGRAM =>.MOO Software
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Mootools =>.Legitimate
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Motion Analysis =>.Motion Analysis
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Mozilla =>.Mozilla
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\MPC-HC =>.MPC-HC Team
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\MurGee.com =>.MurGee.com
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Netscape =>.Netscape
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Nmap =>.Fyodor
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Opera Software =>.Opera Software
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\PCTuneUp =>.NNJ Corporation
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Piriform =>.Piriform
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Playdead =>.Playdead
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\PortableApps.com =>.PortableApps.com
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\QtProject =>.QtProject
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\RobotSoft
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\SecuROM =>.SecuROM
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\SHAREit Technologies =>..SUP.SHAREit
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\SKS =>.SKS Software
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\SoftEther Corporation =>.SoftEther Corporation
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\SoftEther Project =>.SoftEther Project
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Synaptics =>.Synaptics
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\TechSmith =>.TechSmith
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Tencent =>.SUP.Tencent
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\TheGameBakers
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\TOSHIBA =>.Toshiba Corporation
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Transcend
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Transcend Elite
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Trolltech =>.Trolltech
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Unity =>.Unity
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\user32.dll
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Valve =>.Valve
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Viber =>.Viber
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Viber Media S.à r.l
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Wargaming.net =>.Wargaming.net
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Winamp =>.Nullsoft Inc.
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\WinRAR =>.WinRAR
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\WinRAR SFX =>.RarLab
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\ZebHelpProcess Helper =>.Nicolas Coolman
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\ZebraNetworkSystems
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\SOFTWARE\ZHP =>.Nicolas Coolman

---\\ Contents of the Common Files folders (417) - 42s
O43 - CFD: 02/03/2018 - [] D -- C:\Program Files\Bonjour =>.Apple Inc.
O43 - CFD: 23/01/2017 - [] D -- C:\Program Files\Canon =>.Canon
O43 - CFD: 12/09/2018 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 17/06/2017 - [0] D -- C:\Program Files\CyberGhost 6 =>.CyberGhost S.R.L
O43 - CFD: 08/05/2018 - [] D -- C:\Program Files\DIFX =>.Microsoft Corporation
O43 - CFD: 27/07/2015 - [] D -- C:\Program Files\DVD Maker =>.Aone Software
O43 - CFD: 14/09/2018 - [0] D -- C:\Program Files\Easeware =>.Easeware
O43 - CFD: 28/05/2017 - [] D -- C:\Program Files\Echobit =>.Echobit
O43 - CFD: 16/10/2016 - [] D -- C:\Program Files\HP =>.Hewlett-Packard
O43 - CFD: 24/03/2017 - [] D -- C:\Program Files\IIS =>.Microsoft Corporation
O43 - CFD: 24/03/2017 - [] D -- C:\Program Files\IIS Express =>.Microsoft Corporation®
O43 - CFD: 27/07/2016 - [] D -- C:\Program Files\Intel =>.Intel Corporation
O43 - CFD: 23/03/2017 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 02/03/2018 - [] D -- C:\Program Files\iPod =>.Apple Inc.®
O43 - CFD: 21/04/2018 - [] D -- C:\Program Files\Java =>.Oracle
O43 - CFD: 03/08/2016 - [] D -- C:\Program Files\Microsoft Analysis Services =>.Microsoft Corporation
O43 - CFD: 12/04/2011 - [] D -- C:\Program Files\Microsoft Games =>.Microsoft Corporation
O43 - CFD: 24/03/2017 - [] D -- C:\Program Files\Microsoft Identity Extensions =>.Microsoft Corporation
O43 - CFD: 04/10/2016 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 29/10/2017 - [] D -- C:\Program Files\Microsoft SQL Server =>.Microsoft Corporation
O43 - CFD: 23/03/2017 - [] D -- C:\Program Files\Microsoft SQL Server Compact Edition =>.Microsoft Corporation
O43 - CFD: 04/10/2016 - [] D -- C:\Program Files\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 29/10/2017 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 27/09/2016 - [] D -- C:\Program Files\Npcap
O43 - CFD: 25/04/2018 - [] D -- C:\Program Files\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 26/07/2016 - [] D -- C:\Program Files\Realtek =>.Realtek
O43 - CFD: 28/09/2016 - [0] D -- C:\Program Files\Reason
O43 - CFD: 21/04/2018 - [] D -- C:\Program Files\Recuva =>.Piriform
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 24/03/2017 - [] D -- C:\Program Files\SharePoint Client Components =>.Microsoft Corporation
O43 - CFD: 28/05/2017 - [] D -- C:\Program Files\SoftEther VPN Bridge =>.SoftEther K.K.®
O43 - CFD: 28/05/2017 - [] D -- C:\Program Files\SoftEther VPN Server =>.SoftEther K.K.®
O43 - CFD: 26/07/2016 - [] D -- C:\Program Files\Synaptics =>.Synaptics Incorporated®
O43 - CFD: 29/10/2017 - [] D -- C:\Program Files\TOSHIBA =>.Toshiba Corporation
O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 31/07/2016 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 24/03/2017 - [] D -- C:\Program Files\Windows Identity Foundation =>.Microsoft Corporation
O43 - CFD: 31/07/2016 - [] D -- C:\Program Files\Windows Journal =>.Microsoft Corporation
O43 - CFD: 31/07/2016 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 31/07/2016 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 31/07/2016 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 21/11/2010 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 31/07/2016 - [] D -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 26/07/2016 - [0] D -- C:\Program Files (x86)\360 =>.Qihu 360 Software
O43 - CFD: 30/10/2016 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Systems, Incorporated®
O43 - CFD: 11/01/2018 - [0] D -- C:\Program Files (x86)\Autodesk =>.Autodesk
O43 - CFD: 03/11/2017 - [] D -- C:\Program Files (x86)\AVG =>.AVG Software
O43 - CFD: 14/09/2018 - [] D -- C:\Program Files (x86)\baidu =>.Baidu
O43 - CFD: 16/03/2018 - [] D -- C:\Program Files (x86)\BlueStacks =>.BlueStack Systems, Inc.
O43 - CFD: 02/03/2018 - [] D -- C:\Program Files (x86)\Bonjour =>.Apple Inc.
O43 - CFD: 11/06/2018 - [] D -- C:\Program Files (x86)\CalendarTool =>.Meixian Xie
O43 - CFD: 10/04/2017 - [] D -- C:\Program Files (x86)\Cela.C.M
O43 - CFD: 09/04/2017 - [] D -- C:\Program Files (x86)\Cisco =>.Cisco Systems, Inc.
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\CodeMeter =>.Legitimate
O43 - CFD: 21/04/2018 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 27/07/2016 - [] D -- C:\Program Files (x86)\DriverPack Notifier =>.SUP.DriverPack
O43 - CFD: 11/06/2018 - [] D -- C:\Program Files (x86)\EagleGet =>.Beijing Pu Technology Limited®
O43 - CFD: 03/08/2016 - [] D -- C:\Program Files (x86)\Elaborate Bytes =>.Elaborate Bytes
O43 - CFD: 19/05/2017 - [] D -- C:\Program Files (x86)\Google =>.Google Inc®
O43 - CFD: 17/06/2017 - [] D -- C:\Program Files (x86)\Hewlett-Packard =>.Hewlett-Packard
O43 - CFD: 16/10/2016 - [] D -- C:\Program Files (x86)\HP =>.Hewlett-Packard
O43 - CFD: 24/03/2017 - [] D -- C:\Program Files (x86)\IIS =>.Microsoft Corporation
O43 - CFD: 24/03/2017 - [] D -- C:\Program Files (x86)\IIS Express =>.Microsoft Corporation®
O43 - CFD: 08/05/2018 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield
O43 - CFD: 27/07/2016 - [] D -- C:\Program Files (x86)\Intel =>.Intel Corporation
O43 - CFD: 27/07/2016 - [] D -- C:\Program Files (x86)\Intel Driver Update Utility =>.Intel Corporation
O43 - CFD: 23/03/2017 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 23/05/2018 - [] D -- C:\Program Files (x86)\K-Lite Codec Pack =>.KLite Inc
O43 - CFD: 31/08/2018 - [] D -- C:\Program Files (x86)\Kaspersky Lab =>.Kaspersky Lab
O43 - CFD: 19/11/2016 - [] D -- C:\Program Files (x86)\Lenovo =>.Lenovo
O43 - CFD: 24/03/2017 - [] D -- C:\Program Files (x86)\Microsoft =>.Microsoft Corporation
O43 - CFD: 03/08/2016 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services =>.Microsoft Corporation
O43 - CFD: 23/03/2017 - [] D -- C:\Program Files (x86)\Microsoft Help Viewer =>.Microsoft Corporation
O43 - CFD: 03/08/2016 - [] D -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 29/10/2017 - [] D -- C:\Program Files (x86)\Microsoft SDKs =>.Microsoft Corporation
O43 - CFD: 24/03/2017 - [] D -- C:\Program Files (x86)\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 29/10/2017 - [] D -- C:\Program Files (x86)\Microsoft SQL Server =>.Microsoft Corporation
O43 - CFD: 23/03/2017 - [] D -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition =>.Microsoft Corporation
O43 - CFD: 29/10/2017 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio =>.Microsoft Corporation
O43 - CFD: 04/10/2016 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio 8 =>.Microsoft Corporation
O43 - CFD: 04/10/2016 - [] D -- C:\Program Files (x86)\Microsoft Works =>.Microsoft Corporation
O43 - CFD: 23/03/2017 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 08/03/2018 - [] D -- C:\Program Files (x86)\Mozilla Firefox =>.Mozilla
O43 - CFD: 30/07/2018 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service =>.Mozilla
O43 - CFD: 29/10/2017 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 23/10/2016 - [0] D -- C:\Program Files (x86)\Nitro PDF =>.SUP.Empty
O43 - CFD: 28/05/2017 - [] D -- C:\Program Files (x86)\No-IP =>.No-IP
O43 - CFD: 26/04/2018 - [] D -- C:\Program Files (x86)\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 24/03/2017 - [] D -- C:\Program Files (x86)\Open XML SDK =>.Microsoft Corporation
O43 - CFD: 10/09/2016 - [] D -- C:\Program Files (x86)\Opera =>.Opera Software
O43 - CFD: 08/05/2018 - [] D -- C:\Program Files (x86)\REALTEK =>.Realtek
O43 - CFD: 10/04/2017 - [] D -- C:\Program Files (x86)\Realtek Wireless LAN Adapter Software =>.Realtek Semiconductor Corp.
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 10/02/2017 - [] D -- C:\Program Files (x86)\SHAREit Technologies =>.SHAREit Technologies Co.Ltd®
O43 - CFD: 27/07/2016 - [] D -- C:\Program Files (x86)\Toshiba =>.Toshiba Corporation
O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files (x86)\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 22/03/2018 - [] D -- C:\Program Files (x86)\VulkanRT =>.LunarG, Inc
O43 - CFD: 31/07/2016 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 24/03/2017 - [] D -- C:\Program Files (x86)\Windows Identity Foundation =>.Microsoft Corporation
O43 - CFD: 23/03/2017 - [] D -- C:\Program Files (x86)\Windows Kits =>.Microsoft Corporation
O43 - CFD: 31/07/2016 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 31/07/2016 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 31/07/2016 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 31/07/2016 - [] D -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 26/07/2016 - [] D -- C:\Program Files (x86)\WinRAR =>.win.rar GmbH®
O43 - CFD: 28/05/2017 - [0] D -- C:\Program Files (x86)\ZebraNetworkSystems
O43 - CFD: 29/05/2017 - [] D -- C:\Program Files (x86)\ZeroTier =>.ZeroTier
O43 - CFD: 22/08/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip =>.Igor Pavlov
O43 - CFD: 30/10/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 02/09/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Arabic Rappelz
O43 - CFD: 30/01/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon =>.Canon
O43 - CFD: 03/08/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd
O43 - CFD: 19/11/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Connect2
O43 - CFD: 26/08/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Design =>.Core Design
O43 - CFD: 11/06/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EagleGet =>.EagleGet
O43 - CFD: 03/08/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes =>.Elaborate Bytes
O43 - CFD: 30/10/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 19/05/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro =>.Google Inc.
O43 - CFD: 16/10/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP =>.Hewlett-Packard
O43 - CFD: 27/07/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver Update Utility =>.Intel Corporation
O43 - CFD: 02/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes =>.Apple Inc.
O43 - CFD: 21/04/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java =>.Oracle
O43 - CFD: 23/05/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack =>.KLite Inc
O43 - CFD: 31/08/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Free =>.Kaspersky Labs
O43 - CFD: 05/05/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection =>.Kaspersky Lab
O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 04/10/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 04/10/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 =>.Microsoft Corporation
O43 - CFD: 24/03/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 24/03/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 5 SDK =>.Microsoft Corporation
O43 - CFD: 27/07/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ =>.Don Ho
O43 - CFD: 22/12/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 11/01/2018 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pixologic =>.Pixologic
O43 - CFD: 02/03/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QmEye
O43 - CFD: 23/05/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva =>.Piriform
O43 - CFD: 14/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SHAREit =>.Lenovo Group Limited
O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 13/09/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam =>.Steam Games
O43 - CFD: 12/04/2011 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC =>.Wacom Technology
O43 - CFD: 17/09/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tencent Software =>.SUP.Tencent
O43 - CFD: 06/07/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TOSHIBA =>.Toshiba Corporation
O43 - CFD: 12/08/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team
O43 - CFD: 23/10/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware =>.VMware
O43 - CFD: 26/07/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 10/04/2017 - [] D -- C:\ProgramData\Adobe =>.Adobe
O43 - CFD: 27/07/2016 - [0] D -- C:\ProgramData\ALM =>.ALM
O43 - CFD: 02/03/2018 - [] D -- C:\ProgramData\Apple =>.Apple Inc.
O43 - CFD: 02/03/2018 - [] D -- C:\ProgramData\Apple Computer =>.Apple Inc.
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 10/08/2016 - [] D -- C:\ProgramData\Auslogics =>.Auslogics
O43 - CFD: 28/10/2017 - [] D -- C:\ProgramData\Autodesk =>.Autodesk
O43 - CFD: 14/09/2018 - [] D -- C:\ProgramData\AVAST Software =>.AVAST Software
O43 - CFD: 03/11/2017 - [] D -- C:\ProgramData\Avg =>.AVG Software
O43 - CFD: 11/06/2018 - [] D -- C:\ProgramData\Baidu =>.Baidu
O43 - CFD: 27/05/2017 - [] D -- C:\ProgramData\Battle.net =>.Games Software
O43 - CFD: 28/04/2018 - [0] D -- C:\ProgramData\BlueStacksSetup =>.BlueStack Systems, Inc.
O43 - CFD: 08/08/2016 - [] D -- C:\ProgramData\BSD =>.Berkeley
O43 - CFD: 10/04/2017 - [] D -- C:\ProgramData\Caphyon =>.Caphyon
O43 - CFD: 24/05/2017 - [] HD -- C:\ProgramData\Common Files =>.Microsoft Corporation
O43 - CFD: 28/05/2017 - [] D -- C:\ProgramData\COMODO =>.Comodo Group.
O43 - CFD: 11/01/2018 - [] D -- C:\ProgramData\Corel =>.Corel Corporation
O43 - CFD: 01/08/2016 - [0] D -- C:\ProgramData\CorelDRAW Graphics Suite X7 x64
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 15/09/2018 - [] D -- C:\ProgramData\Doctor Web =>.Doctor Web Ltd
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 09/04/2017 - [] D -- C:\ProgramData\Driver-Soft =>.Driver-Soft
O43 - CFD: 05/10/2017 - [] D -- C:\ProgramData\DriverGenius =>.Bluesquad
O43 - CFD: 11/06/2018 - [] D -- C:\ProgramData\EagleGet =>.EagleGet
O43 - CFD: 28/05/2017 - [] D -- C:\ProgramData\Echobit =>.Echobit
O43 - CFD: 13/09/2018 - [] D -- C:\ProgramData\Epic =>.Epic
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Favorites =>.Microsoft Corporation
O43 - CFD: 28/10/2017 - [] D -- C:\ProgramData\FLEXnet =>.Flexera Software
O43 - CFD: 17/06/2017 - [] D -- C:\ProgramData\Hewlett-Packard =>.Hewlett-Packard
O43 - CFD: 25/08/2017 - [] D -- C:\ProgramData\Hi-Rez Studios =>.Hi-Rez Studios
O43 - CFD: 16/10/2016 - [] D -- C:\ProgramData\HP =>.Hewlett-Packard
O43 - CFD: 21/04/2017 - [0] D -- C:\ProgramData\IDM =>.IDM
O43 - CFD: 10/04/2017 - [] D -- C:\ProgramData\Intel =>.Intel Corporation
O43 - CFD: 27/07/2016 - [] D -- C:\ProgramData\IntelDLM =>.Intel Corporation
O43 - CFD: 21/11/2016 - [0] D -- C:\ProgramData\Isolated Storage =>.Microsoft Corporation
O43 - CFD: 18/09/2018 - [] D -- C:\ProgramData\Kaspersky Lab =>.Kaspersky Lab
O43 - CFD: 10/02/2017 - [0] D -- C:\ProgramData\Lenovo =>.Lenovo
O43 - CFD: 01/06/2017 - [] D -- C:\ProgramData\LogMeIn =>.LogMeIn
O43 - CFD: 29/10/2017 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 20/12/2016 - [] D -- C:\ProgramData\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 24/03/2017 - [] D -- C:\ProgramData\Microsoft Visual Studio =>.Microsoft Corporation
O43 - CFD: 18/09/2018 - [] D -- C:\ProgramData\NVIDIA =>.nVidia Corporation
O43 - CFD: 25/04/2018 - [] D -- C:\ProgramData\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 08/06/2017 - [] D -- C:\ProgramData\Oracle =>.Oracle
O43 - CFD: 31/05/2018 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 01/08/2016 - [] D -- C:\ProgramData\Protexis64 =>.Protexis Inc.
O43 - CFD: 29/07/2016 - [] D -- C:\ProgramData\regid.1986-12.com.adobe =>.Adobe Inc.
O43 - CFD: 29/10/2017 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
O43 - CFD: 31/10/2016 - [] D -- C:\ProgramData\RELOADED
O43 - CFD: 10/04/2017 - [] D -- C:\ProgramData\Sprint
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation
O43 - CFD: 10/04/2017 - [] D -- C:\ProgramData\Steam =>.Steam Games
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation
O43 - CFD: 15/09/2018 - [] D -- C:\ProgramData\Tencent =>.SUP.Tencent
O43 - CFD: 06/07/2017 - [] D -- C:\ProgramData\TOSHIBA =>.Toshiba Corporation
O43 - CFD: 16/09/2018 - [] D -- C:\ProgramData\VMware =>.VMware
O43 - CFD: 17/09/2018 - [] D -- C:\ProgramData\X360CE =>.Microsoft Corporation
O43 - CFD: 29/05/2017 - [] D -- C:\ProgramData\ZeroTier =>.ZeroTier
O43 - CFD: 04/08/2016 - [] D -- C:\Program Files (x86)\Common Files\Adobe =>.Adobe
O43 - CFD: 28/07/2016 - [] D -- C:\Program Files (x86)\Common Files\Adobe AIR =>.Adobe Inc.
O43 - CFD: 13/09/2018 - [] D -- C:\Program Files (x86)\Common Files\Apple =>.Apple Inc.
O43 - CFD: 11/01/2018 - [] D -- C:\Program Files (x86)\Common Files\Autodesk Shared =>.Autodesk
O43 - CFD: 26/07/2016 - [0] D -- C:\Program Files (x86)\Common Files\AV =>.Avast
O43 - CFD: 04/10/2016 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER =>.Designer
O43 - CFD: 11/06/2018 - [] D -- C:\Program Files (x86)\Common Files\EagleGet =>.EagleGet
O43 - CFD: 01/08/2016 - [] D -- C:\Program Files (x86)\Common Files\Intel =>.Intel Corporation
O43 - CFD: 21/04/2018 - [] D -- C:\Program Files (x86)\Common Files\Java =>.Oracle
O43 - CFD: 29/10/2017 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared =>.Microsoft Corporation
O43 - CFD: 21/01/2018 - [] D -- C:\Program Files (x86)\Common Files\Oracle =>.Oracle
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines =>.Microsoft Corporation
O43 - CFD: 13/09/2016 - [] D -- C:\Program Files (x86)\Common Files\Steam =>.Steam Games
O43 - CFD: 04/10/2016 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 23/10/2016 - [] D -- C:\Program Files (x86)\Common Files\ThinPrint =>.ThinPrint
O43 - CFD: 23/10/2016 - [] D -- C:\Program Files (x86)\Common Files\VMware =>.VMware
O43 - CFD: 13/03/2018 - [] D -- C:\Users\moez\AppData\Roaming\.minecraft =>.Microsoft Corporation
O43 - CFD: 15/10/2016 - [] D -- C:\Users\moez\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 17/09/2018 - [] D -- C:\Users\moez\AppData\Roaming\AndroidTbox
O43 - CFD: 02/03/2018 - [] D -- C:\Users\moez\AppData\Roaming\Apple Computer =>.Apple Inc.
O43 - CFD: 28/10/2017 - [] D -- C:\Users\moez\AppData\Roaming\Autodesk =>.Autodesk
O43 - CFD: 11/06/2018 - [] D -- C:\Users\moez\AppData\Roaming\Baidu =>.Baidu
O43 - CFD: 27/05/2017 - [] D -- C:\Users\moez\AppData\Roaming\Battle.net =>.Games Software
O43 - CFD: 04/12/2016 - [] D -- C:\Users\moez\AppData\Roaming\Bigasoft Total Video Converter 4 =>.Bigasoft Corporation
O43 - CFD: 17/09/2018 - [] D -- C:\Users\moez\AppData\Roaming\BitTorrent
O43 - CFD: 21/12/2016 - [] D -- C:\Users\moez\AppData\Roaming\Braid
O43 - CFD: 10/04/2017 - [] D -- C:\Users\moez\AppData\Roaming\Bytemobile =>.Bytemobile
O43 - CFD: 16/09/2018 - [] D -- C:\Users\moez\AppData\Roaming\CalendarTool =>.Meixian Xie
O43 - CFD: 28/05/2017 - [] D -- C:\Users\moez\AppData\Roaming\COMODO =>.Comodo Group.
O43 - CFD: 01/08/2016 - [] D -- C:\Users\moez\AppData\Roaming\Corel =>.Corel Corporation
O43 - CFD: 14/01/2018 - [] D -- C:\Users\moez\AppData\Roaming\DMCache =>.DMCache
O43 - CFD: 26/07/2016 - [0] D -- C:\Users\moez\AppData\Roaming\doctor
O43 - CFD: 02/09/2018 - [] AD -- C:\Users\moez\AppData\Roaming\DriverPack Notifier =>.SUP.DriverPack
O43 - CFD: 26/07/2016 - [] D -- C:\Users\moez\AppData\Roaming\DRPNano =>.SUP.DriverPack
O43 - CFD: 26/07/2016 - [] D -- C:\Users\moez\AppData\Roaming\DRPNPS =>.SUP.DriverPack
O43 - CFD: 26/07/2016 - [] D -- C:\Users\moez\AppData\Roaming\DRPSu =>.SUP.DriverPack
O43 - CFD: 26/09/2016 - [] D -- C:\Users\moez\AppData\Roaming\dvdcss =>.VideoLan Team
O43 - CFD: 12/06/2018 - [] D -- C:\Users\moez\AppData\Roaming\EagleGet =>.EagleGet
O43 - CFD: 09/04/2017 - [] D -- C:\Users\moez\AppData\Roaming\Easeware =>.Easeware
O43 - CFD: 27/03/2017 - [] D -- C:\Users\moez\AppData\Roaming\Endpoint Dynamics =>.Endpoint Dynamics
O43 - CFD: 23/10/2016 - [0] D -- C:\Users\moez\AppData\Roaming\EurekaLog =>.EurekaLog
O43 - CFD: 28/05/2017 - [] D -- C:\Users\moez\AppData\Roaming\GameRanger =>.GameRanger
O43 - CFD: 16/10/2016 - [] D -- C:\Users\moez\AppData\Roaming\Hewlett-Packard =>.Hewlett-Packard
O43 - CFD: 16/10/2016 - [] D -- C:\Users\moez\AppData\Roaming\HP =>.Hewlett-Packard
O43 - CFD: 05/10/2017 - [0] D -- C:\Users\moez\AppData\Roaming\hpqLog =>.Hewlett-Packard
O43 - CFD: 26/07/2016 - [] D -- C:\Users\moez\AppData\Roaming\Identities =>.Microsoft Corporation
O43 - CFD: 10/01/2018 - [] D -- C:\Users\moez\AppData\Roaming\IDM =>.IDM
O43 - CFD: 08/06/2017 - [] D -- C:\Users\moez\AppData\Roaming\java =>.Oracle
O43 - CFD: 29/10/2017 - [] D -- C:\Users\moez\AppData\Roaming\JVSG
O43 - CFD: 27/07/2016 - [] D -- C:\Users\moez\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 12/04/2011 - [0] D -- C:\Users\moez\AppData\Roaming\Media Center Programs =>.Microsoft Corporation
O43 - CFD: 08/05/2017 - [] SD -- C:\Users\moez\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 23/12/2017 - [] D -- C:\Users\moez\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 31/10/2017 - [] D -- C:\Users\moez\AppData\Roaming\MPC-HC =>.MPC-HC Team
O43 - CFD: 29/05/2017 - [] D -- C:\Users\moez\AppData\Roaming\netvirt
O43 - CFD: 17/09/2018 - [] D -- C:\Users\moez\AppData\Roaming\Nidhogg
O43 - CFD: 05/08/2018 - [] D -- C:\Users\moez\AppData\Roaming\Notepad++ =>.Don Ho
O43 - CFD: 23/03/2017 - [] D -- C:\Users\moez\AppData\Roaming\NuGet =>.Microsoft Corporation
O43 - CFD: 13/01/2018 - [] D -- C:\Users\moez\AppData\Roaming\NVIDIA =>.nVidia Corporation
O43 - CFD: 15/06/2017 - [] D -- C:\Users\moez\AppData\Roaming\Opera Software =>.Opera Software
O43 - CFD: 09/10/2016 - [] D -- C:\Users\moez\AppData\Roaming\PrimoPDF
O43 - CFD: 20/11/2016 - [] D -- C:\Users\moez\AppData\Roaming\RobotSoft
O43 - CFD: 10/04/2017 - [] D -- C:\Users\moez\AppData\Roaming\Sierra Wireless =>.Sierra Wireless Inc
O43 - CFD: 27/07/2016 - [] D -- C:\Users\moez\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
O43 - CFD: 29/07/2016 - [] D -- C:\Users\moez\AppData\Roaming\Steam =>.Steam Games
O43 - CFD: 27/09/2016 - [] D -- C:\Users\moez\AppData\Roaming\Subversion =>.Games Software
O43 - CFD: 27/07/2016 - [] D -- C:\Users\moez\AppData\Roaming\Sun =>.Oracle
O43 - CFD: 02/01/2018 - [] D -- C:\Users\moez\AppData\Roaming\TechSmith =>.TechSmith
O43 - CFD: 27/05/2017 - [] D -- C:\Users\moez\AppData\Roaming\Teeworlds =>.Teeworlds
O43 - CFD: 17/09/2018 - [] D -- C:\Users\moez\AppData\Roaming\Tencent =>.SUP.Tencent
O43 - CFD: 25/03/2017 - [] D -- C:\Users\moez\AppData\Roaming\Transcend Elite =>.Transcend
O43 - CFD: 29/05/2017 - [] D -- C:\Users\moez\AppData\Roaming\Tunngle =>.Tunngle.net
O43 - CFD: 10/02/2017 - [] D -- C:\Users\moez\AppData\Roaming\Umeng
O43 - CFD: 12/09/2018 - [] D -- C:\Users\moez\AppData\Roaming\uTorrent
O43 - CFD: 10/06/2018 - [] D -- C:\Users\moez\AppData\Roaming\ViberPC =>.Viber
O43 - CFD: 29/10/2017 - [] D -- C:\Users\moez\AppData\Roaming\Visual Studio Setup =>.Pinnacle Systems, Inc.
O43 - CFD: 12/09/2018 - [] D -- C:\Users\moez\AppData\Roaming\vlc =>.VideoLan Team
O43 - CFD: 04/07/2018 - [] D -- C:\Users\moez\AppData\Roaming\VMware =>.VMware
O43 - CFD: 24/03/2017 - [] D -- C:\Users\moez\AppData\Roaming\vstelemetry =>.Legitimate
O43 - CFD: 27/07/2016 - [] D -- C:\Users\moez\AppData\Roaming\WinBatch =>.winbatch.com
O43 - CFD: 26/07/2016 - [] D -- C:\Users\moez\AppData\Roaming\WinRAR =>.WinRAR
O43 - CFD: 28/05/2017 - [] D -- C:\Users\moez\AppData\Roaming\ZebraNetworkSystems
O43 - CFD: 18/09/2018 - [] D -- C:\Users\moez\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 27/07/2016 - [] D -- C:\Users\moez\AppData\Local\1BN_Software_&_IT_Solutio
O43 - CFD: 28/03/2018 - [] D -- C:\Users\moez\AppData\Local\Adobe =>.Adobe
O43 - CFD: 02/03/2018 - [] D -- C:\Users\moez\AppData\Local\Apple =>.Apple Inc.
O43 - CFD: 02/03/2018 - [] D -- C:\Users\moez\AppData\Local\Apple Computer =>.Apple Inc.
O43 - CFD: 26/07/2016 - [0] SHD -- C:\Users\moez\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 29/11/2016 - [] D -- C:\Users\moez\AppData\Local\Apps =>.Microsoft Corporation
O43 - CFD: 28/10/2017 - [] D -- C:\Users\moez\AppData\Local\Autodesk =>.Autodesk
O43 - CFD: 14/09/2018 - [] D -- C:\Users\moez\AppData\Local\AVAST Software =>.AVAST Software
O43 - CFD: 05/10/2017 - [] D -- C:\Users\moez\AppData\Local\Avg =>.AVG Software
O43 - CFD: 03/11/2017 - [] D -- C:\Users\moez\AppData\Local\AvgSetupLog =>.AVG Software
O43 - CFD: 21/11/2016 - [] D -- C:\Users\moez\AppData\Local\BlueEye
O43 - CFD: 16/03/2018 - [] D -- C:\Users\moez\AppData\Local\BlueStacks =>.BlueStack Systems, Inc.
O43 - CFD: 27/09/2017 - [] D -- C:\Users\moez\AppData\Local\cache =>.Legitimate
O43 - CFD: 29/01/2017 - [] D -- C:\Users\moez\AppData\Local\CAPCOM =>.CAPCOM
O43 - CFD: 04/08/2016 - [] D -- C:\Users\moez\AppData\Local\CEF =>.CEF
O43 - CFD: 22/12/2016 - [] D -- C:\Users\moez\AppData\Local\Chromium =>.Chromium
O43 - CFD: 18/09/2018 - [] D -- C:\Users\moez\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 30/03/2017 - [0] D -- C:\Users\moez\AppData\Local\Deployment =>.Microsoft Corporation
O43 - CFD: 05/10/2016 - [0] D -- C:\Users\moez\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 24/10/2016 - [0] D -- C:\Users\moez\AppData\Local\DriverToolkit =>.SUP.DriverToolkit
O43 - CFD: 28/05/2017 - [] D -- C:\Users\moez\AppData\Local\Echobit =>.Echobit
O43 - CFD: 03/08/2018 - [0] D -- C:\Users\moez\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation
O43 - CFD: 03/11/2016 - [] D -- C:\Users\moez\AppData\Local\Google =>.Google
O43 - CFD: 16/10/2016 - [] D -- C:\Users\moez\AppData\Local\Hewlett-Packard =>.Hewlett-Packard
O43 - CFD: 02/01/2017 - [] D -- C:\Users\moez\AppData\Local\HirezLauncherUI =>.Hi-Rez Studios
O43 - CFD: 26/07/2016 - [0] SHD -- C:\Users\moez\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 31/07/2016 - [] D -- C:\Users\moez\AppData\Local\Intel =>.Intel Corporation
O43 - CFD: 10/02/2017 - [] D -- C:\Users\moez\AppData\Local\Lenovo =>.Lenovo
O43 - CFD: 28/05/2017 - [] D -- C:\Users\moez\AppData\Local\LogMeIn =>.LogMeIn
O43 - CFD: 18/06/2017 - [] D -- C:\Users\moez\AppData\Local\Macromedia =>.Macromedia
O43 - CFD: 31/07/2016 - [] D -- C:\Users\moez\AppData\Local\mHotspot
O43 - CFD: 02/01/2018 - [] D -- C:\Users\moez\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 08/06/2017 - [] D -- C:\Users\moez\AppData\Local\Microsoft Games =>.Microsoft Corporation
O43 - CFD: 03/08/2016 - [0] D -- C:\Users\moez\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 29/10/2017 - [] D -- C:\Users\moez\AppData\Local\Microsoft_Corporation =>.Microsoft Corporation
O43 - CFD: 27/07/2016 - [] D -- C:\Users\moez\AppData\Local\Mozilla =>.Mozilla Corporation
O43 - CFD: 23/03/2018 - [] D -- C:\Users\moez\AppData\Local\NVIDIA =>.nVidia Corporation
O43 - CFD: 08/01/2018 - [] D -- C:\Users\moez\AppData\Local\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 15/06/2017 - [] D -- C:\Users\moez\AppData\Local\Opera Software =>.Opera Software
O43 - CFD: 29/01/2017 - [] D -- C:\Users\moez\AppData\Local\Package Cache =>.Microsoft Corporation
O43 - CFD: 26/07/2016 - [] D -- C:\Users\moez\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 02/06/2017 - [] D -- C:\Users\moez\AppData\Local\PunkBuster =>.PunkBuster Games
O43 - CFD: 24/03/2017 - [] D -- C:\Users\moez\AppData\Local\ServiceHub
O43 - CFD: 19/11/2016 - [] D -- C:\Users\moez\AppData\Local\SHAREit =>.Lenovo Group Limited
O43 - CFD: 10/02/2017 - [] D -- C:\Users\moez\AppData\Local\SHAREit Technologies
O43 - CFD: 02/01/2017 - [] D -- C:\Users\moez\AppData\Local\Steam =>.Steam Games
O43 - CFD: 02/01/2018 - [] D -- C:\Users\moez\AppData\Local\TechSmith =>.TechSmith
O43 - CFD: 18/09/2018 - [] D -- C:\Users\moez\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 26/07/2016 - [0] SHD -- C:\Users\moez\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 06/07/2017 - [] D -- C:\Users\moez\AppData\Local\TOSHIBA =>.Toshiba Corporation
O43 - CFD: 31/05/2018 - [] D -- C:\Users\moez\AppData\Local\UnrealEngine =>.Unreal Software
O43 - CFD: 10/06/2018 - [] D -- C:\Users\moez\AppData\Local\Viber =>.Viber
O43 - CFD: 03/07/2017 - [] D -- C:\Users\moez\AppData\Local\Viber Media S.à r.l =>.Viber Media S.à r.l
O43 - CFD: 26/07/2016 - [0] D -- C:\Users\moez\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 28/05/2017 - [] D -- C:\Users\moez\AppData\Local\Vitalwerks =>.Vitalwerks
O43 - CFD: 04/07/2018 - [] D -- C:\Users\moez\AppData\Local\VMware =>.VMware
O43 - CFD: 29/05/2017 - [] D -- C:\Users\moez\AppData\Local\ZeroTier =>.ZeroTier
O43 - CFD: 18/09/2018 - [] D -- C:\Users\moez\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 26/07/2016 - [0] D -- C:\Users\moez\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 04/08/2016 - [] D -- C:\Users\moez\AppData\LocalLow\Adobe =>.Adobe
O43 - CFD: 02/01/2018 - [] D -- C:\Users\moez\AppData\LocalLow\Bennett Foddy
O43 - CFD: 23/12/2016 - [] D -- C:\Users\moez\AppData\LocalLow\CampoSanto
O43 - CFD: 19/05/2017 - [] D -- C:\Users\moez\AppData\LocalLow\Google =>.Google
O43 - CFD: 18/06/2017 - [] SD -- C:\Users\moez\AppData\LocalLow\Microsoft =>.Microsoft Corporation
O43 - CFD: 08/08/2018 - [0] D -- C:\Users\moez\AppData\LocalLow\Mozilla =>.Mozilla Corporation
O43 - CFD: 21/04/2018 - [] D -- C:\Users\moez\AppData\LocalLow\Oracle =>.Oracle
O43 - CFD: 11/10/2016 - [] D -- C:\Users\moez\AppData\LocalLow\Playdead =>.Playdead
O43 - CFD: 31/08/2016 - [] D -- C:\Users\moez\AppData\LocalLow\SKS
O43 - CFD: 27/07/2016 - [] D -- C:\Users\moez\AppData\LocalLow\Sun =>.Oracle
O43 - CFD: 17/09/2018 - [0] SD -- C:\Users\moez\AppData\LocalLow\Temp =>.Microsoft Corporation
O43 - CFD: 22/12/2016 - [] D -- C:\Users\moez\AppData\LocalLow\TheGameBakers
O43 - CFD: 15/06/2018 - [] D -- C:\Users\moez\Desktop\cam
O43 - CFD: 27/12/2016 - [] RD -- C:\Users\moez\Desktop\libyanadb
O43 - CFD: 09/10/2016 - [] D -- C:\Users\moez\Desktop\New folder
O43 - CFD: 15/10/2016 - [] D -- C:\Users\moez\Desktop\New folder (10)
O43 - CFD: 16/10/2016 - [] D -- C:\Users\moez\Desktop\New folder (11)
O43 - CFD: 28/11/2016 - [] D -- C:\Users\moez\Desktop\New folder (15)
O43 - CFD: 29/11/2016 - [] D -- C:\Users\moez\Desktop\New folder (16)
O43 - CFD: 16/10/2017 - [] D -- C:\Users\moez\Desktop\New folder (17)
O43 - CFD: 24/12/2017 - [] D -- C:\Users\moez\Desktop\New folder (18)
O43 - CFD: 19/02/2018 - [0] D -- C:\Users\moez\Desktop\New folder (2)
O43 - CFD: 30/05/2017 - [] D -- C:\Users\moez\Desktop\New folder (26)
O43 - CFD: 11/09/2016 - [] D -- C:\Users\moez\Desktop\New folder (3)
O43 - CFD: 05/12/2017 - [] D -- C:\Users\moez\Desktop\New folder (6)
O43 - CFD: 09/10/2016 - [] D -- C:\Users\moez\Desktop\New folder (7)
O43 - CFD: 16/10/2016 - [] D -- C:\Users\moez\Desktop\New folder (9)
O43 - CFD: 24/05/2017 - [] D -- C:\Users\moez\Desktop\smartcard
O43 - CFD: 17/05/2017 - [] D -- C:\Users\moez\Desktop\web
O43 - CFD: 17/03/2018 - [] D -- C:\Users\moez\Desktop\zxzxzxx
O43 - CFD: 30/04/2017 - [] D -- C:\Users\moez\Desktop\طباعة
O43 - CFD: 09/01/2018 - [] D -- C:\Users\moez\Desktop\معز
O43 - CFD: 14/07/2009 - [] RD -- C:\Users\moez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 26/07/2016 - [] RD -- C:\Users\moez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 04/12/2016 - [0] D -- C:\Users\moez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AoaoPhoto Digital Studio =>.AoaoPhoto Digital Studio
O43 - CFD: 04/12/2016 - [] D -- C:\Users\moez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bigasoft =>.Bigasoft Corporation
O43 - CFD: 26/12/2017 - [] D -- C:\Users\moez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] RD -- C:\Users\moez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 09/06/2017 - [] D -- C:\Users\moez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft =>.Microsoft Corporation
O43 - CFD: 27/09/2016 - [] D -- C:\Users\moez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nmap =>.Fyodor
O43 - CFD: 26/07/2016 - [] RD -- C:\Users\moez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 27/05/2017 - [] D -- C:\Users\moez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam =>.Steam Games
O43 - CFD: 20/04/2018 - [] D -- C:\Users\moez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer =>.The KMPlayer Team
O43 - CFD: 29/01/2017 - [] D -- C:\Users\moez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Viber =>.Viber
O43 - CFD: 26/07/2016 - [] D -- C:\Users\moez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Avg =>.AVG Software
O43 - CFD: 02/11/2017 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\AvgSetupLog =>.AVG Software
O43 - CFD: 16/09/2018 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 01/06/2017 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\LogMeIn =>.LogMeIn
O43 - CFD: 14/07/2009 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 10/04/2017 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Bytemobile =>.Bytemobile
O43 - CFD: 11/06/2018 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\CalendarTool =>.Meixian Xie
O43 - CFD: 11/10/2017 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 29/10/2017 - [] SD -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 30/08/2018 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Opera Software =>.Opera Software
O43 - CFD: 15/09/2018 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Tencent =>.SUP.Tencent
O43 - CFD: 16/09/2018 - [0] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\VMware =>.VMware
O43 - CFD: 28/05/2017 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\ZebraNetworkSystems

---\\ ShellIconOverlayIdentifiers (SIOI) (5) - 2s
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) [ SkyDrivePro1 (ErrorConflict)] - {8BA85C75-763B-4103-94EB-9470F12FE0F7}. (.Microsoft Corporation - Microsoft SkyDrive Pro Extensions.) -- E:\Program Files (x86)\office\Office15\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) [ SkyDrivePro2 (SyncInProgress)] - {CD55129A-B1A1-438E-A425-CEBC7DC684EE}. (.Microsoft Corporation - Microsoft SkyDrive Pro Extensions.) -- E:\Program Files (x86)\office\Office15\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 3 (InSync) [ SkyDrivePro3 (InSync)] - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1}. (.Microsoft Corporation - Microsoft SkyDrive Pro Extensions.) -- E:\Program Files (x86)\office\Office15\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation

---\\ Search Context Menu Handlers (SCMH) (44) - 3s
O108 - CMH1: 7-Zip [64Bits] - {23170F69-40C1-278A-1000-000100020000} . (.Igor Pavlov - 7-Zip Shell Extension.) -- E:\Program Files (x86)\7-Zip\7-zip.dll =>.Igor Pavlov
O108 - CMH1: ANotepad++64 [64Bits] - {B298D29A-A6ED-11DE-BA8C-A68E55D89593} . (. - ShellHandler for Notepad++ (64 bit).) -- E:\Program Files (x86)\Notepad++\NppShell_06.dll =>.Notepad++®
O108 - CMH1: BriefcaseMenu [64Bits] - {85BBD920-42A0-1069-A2E4-08002B30309D} . (.Microsoft Corporation - Windows Briefcase.) -- C:\Windows\System32\syncui.dll =>.Microsoft Corporation
O108 - CMH1: Kaspersky Anti-Virus 19.0.0 [64Bits] - {755D388B-420B-4692-A974-84AAF0E577D3} . (.AO Kaspersky Lab - Shell Extension.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\shellex.dll =>.Kaspersky Lab®
O108 - CMH1: Open With [64Bits] - {09799AFB-AD67-11d1-ABCD-00C04FC30936} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH1: Open With EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH1: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH1: VirtualCloneDrive [64Bits] - {B7056B8E-4F99-44f8-8CBD-282390FE5428} . (.Elaborate Bytes AG - CloseTray.) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell1.dll =>.Elaborate Bytes AG®
O108 - CMH1: WinRAR [64Bits] - {B41DB860-64E4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files (x86)\WinRAR\RarExt64.dll =>.win.rar GmbH®
O108 - CMH1: WinRAR32 [64Bits] - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Orphan.)
O108 - CMH1: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Orphan.)
O108 - CMH2: Compatibility [64Bits] - {1d27f844-3a1f-4410-85ac-14651078412d} . (.Microsoft Corporation - Compatibility Tab Shell Extension Library.) -- C:\Windows\System32\acppage.dll =>.Microsoft Corporation
O108 - CMH2: NvAppShExt [64Bits] - {A929C4CE-FD36-4270-B4F5-34ECAC5BD63C} . (.NVIDIA Corporation - NVIDIA Shell Extensions.) -- C:\Windows\system32\nv3dappshext.dll =>.NVIDIA Corporation
O108 - CMH2: OpenContainingFolderMenu [64Bits] - {37ea3a21-7493-4208-a011-7f9ea79ce9f5} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH2: OpenGLShExt [64Bits] - {E97DEC16-A50D-49bb-AE24-CF682282E08D} . (.NVIDIA Corporation - NVIDIA Shell Extensions.) -- C:\Windows\system32\nv3dappshext.dll =>.NVIDIA Corporation
O108 - CMH3: CopyAsPathMenu [64Bits] - {f3d06e7c-1e45-4a26-847e-f9fcdee59be0} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH3: SendTo [64Bits] - {7BA4C740-9E81-11CF-99D3-00AA004AE837} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH3: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Orphan.)
O108 - CMH4: 7-Zip [64Bits] - {23170F69-40C1-278A-1000-000100020000} . (.Igor Pavlov - 7-Zip Shell Extension.) -- E:\Program Files (x86)\7-Zip\7-zip.dll =>.Igor Pavlov
O108 - CMH4: EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH4: Kaspersky Anti-Virus 19.0.0 [64Bits] - {755D388B-420B-4692-A974-84AAF0E577D3} . (.AO Kaspersky Lab - Shell Extension.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\shellex.dll =>.Kaspersky Lab®
O108 - CMH4: RecuvaShellExt [64Bits] - {435E5DF5-2510-463C-B223-BDA47006D002} . (.Piriform Ltd - Recuva shell extensions.) -- C:\Program Files\Recuva\RecuvaShell64.dll =>.Piriform Ltd®
O108 - CMH4: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH4: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Orphan.)
O108 - CMH5: Gadgets [64Bits] - {6B9228DA-9C15-419e-856C-19E768A13BDC} . (.Microsoft Corporation - Sidebar droptarget.) -- C:\Program Files\Windows Sidebar\sbdrop.dll =>.Microsoft Corporation
O108 - CMH5: igfxDTCM [64Bits] - {9B5F5829-A529-4B12-814A-E81BCB8D93FC} . (.Intel Corporation - igfxDTCM Module.) -- C:\Windows\system32\igfxDTCM.dll =>.Intel Corporation
O108 - CMH5: New [64Bits] - {D969A300-E7FF-11d0-A93B-00A0C90F2719} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH5: NvCplDesktopContext [64Bits] - {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} . (.NVIDIA Corporation - NVIDIA Display Shell Extension.) -- C:\Windows\System32\nvshext.dll =>.NVIDIA Corporation
O108 - CMH5: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH5: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Orphan.)
O108 - CMH6: 7-Zip [64Bits] - {23170F69-40C1-278A-1000-000100020000} . (.Igor Pavlov - 7-Zip Shell Extension.) -- E:\Program Files (x86)\7-Zip\7-zip.dll =>.Igor Pavlov
O108 - CMH6: BriefcaseMenu [64Bits] - {85BBD920-42A0-1069-A2E4-08002B30309D} . (.Microsoft Corporation - Windows Briefcase.) -- C:\Windows\System32\syncui.dll =>.Microsoft Corporation
O108 - CMH6: Kaspersky Anti-Virus 19.0.0 [64Bits] - {755D388B-420B-4692-A974-84AAF0E577D3} . (.AO Kaspersky Lab - Shell Extension.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\shellex.dll =>.Kaspersky Lab®
O108 - CMH6: Library Location [64Bits] - {3dad6c5d-2167-4cae-9914-f99e41c12cfa} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH6: RecuvaShellExt [64Bits] - {435E5DF5-2510-463C-B223-BDA47006D002} . (.Piriform Ltd - Recuva shell extensions.) -- C:\Program Files\Recuva\RecuvaShell64.dll =>.Piriform Ltd®
O108 - CMH6: WinRAR [64Bits] - {B41DB860-64E4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files (x86)\WinRAR\RarExt64.dll =>.win.rar GmbH®
O108 - CMH6: WinRAR32 [64Bits] - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Orphan.)
O108 - CMH6: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Orphan.)
O108 - CMH7: EnhancedStorageShell [64Bits] - {2854F705-3548-414C-A113-93E27C808C85} . (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O108 - CMH7: Kaspersky Anti-Virus 19.0.0 [64Bits] - {755D388B-420B-4692-A974-84AAF0E577D3} . (.AO Kaspersky Lab - Shell Extension.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\shellex.dll =>.Kaspersky Lab®
O108 - CMH7: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH7: VirtualCloneDrive [64Bits] - {B7056B8E-4F99-44f8-8CBD-282390FE5428} . (.Elaborate Bytes AG - CloseTray.) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell1.dll =>.Elaborate Bytes AG®
O108 - CMH7: VMDiskMenuHandler [64Bits] - {271DC252-6FE1-4D59-9053-E4CF50AB99DE} . (.Orphan.)
O108 - CMH7: VMDiskMenuHandler64 [64Bits] - {E4D28EDC-8C0B-43EE-9E7D-C8A8682334DC} . (.VMware, Inc. - VMware Workstation.) -- E:\Program Files (x86)\VMware\VMware Player\x64\vmdkShellExt64.dll =>.VMware, Inc.®

---\\ Image File Execution Options (4) - 1s
O50 - IFEO:C:\Windows\System32\ie4uinit.exe - (.Microsoft Corporation - IE Per-User Initialization Utility.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - IE 7.0 Unattended Install Utility.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Microsoft (R) HTML Application host.) [MitigationOptions\\256] =>.Microsoft Corporation

---\\ ShareTools MSconfig StartupReg (24) - 4s
O53 - SMSR:HKLM\...\startupreg\AdobeAAMUpdater-1.0 [Key] [64Bits] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe =>.Adobe Systems Incorporated
O53 - SMSR:HKLM\...\startupreg\AdobeCEPServiceManager [Key] [64Bits] . (.Adobe Systems Incorporated - Adobe CEP Service Manager.) -- C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe =>.Adobe Systems Incorporated
O53 - SMSR:HKLM\...\startupreg\ADSKAppManager [Key] [64Bits] . (...) -- C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\AvgUi [Key] [64Bits] . (...) -- C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\BitTorrent [Key] [64Bits] . (.BitTorrent Inc. - BitTorrent.) -- C:\Users\moez\AppData\Roaming\BitTorrent\BitTorrent.exe =>BitTorrent (P2P)
O53 - SMSR:HKLM\...\startupreg\CCleaner Monitoring [Key] [64Bits] . (.Piriform Ltd - CCleaner.) -- E:\Program Files (x86)\cc\CCleaner64.exe =>.Piriform Ltd
O53 - SMSR:HKLM\...\startupreg\CyberGhost [Key] [64Bits] . (...) -- .
O53 - SMSR:HKLM\...\startupreg\EagleGet [Key] [64Bits] . (.EagleGet.com - EagleGet Free Downloader.) -- E:\Program Files (x86)\EagleGet\EagleGet.exe =>.EagleGet.com
O53 - SMSR:HKLM\...\startupreg\EvolveClient [Key] [64Bits] . (...) -- C:\Program Files\Echobit\Evolve\EvolveClient.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\GoogleChromeAutoLaunch_30DD00273E030B8888A423FD94401938 [Key] [64Bits] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O53 - SMSR:HKLM\...\startupreg\GrooveMonitor [Key] [64Bits] . (.Microsoft Corporation - GrooveMonitor Utility.) -- E:\Program Files (x86)\Microsoft Office2\Office12\GrooveMonitor.exe =>.Microsoft Corporation
O53 - SMSR:HKLM\...\startupreg\HP CP1020 System Tray [Key] [64Bits] . (.HP - HP System Tray Status.) -- C:\Program Files\HP\HP LaserJet Professional CP1020 Series\HPCP1020STRAY.EXE =>.HP
O53 - SMSR:HKLM\...\startupreg\IDMan [Key] [64Bits] . (...) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\iTunesHelper [Key] [64Bits] . (.Apple Inc. - iTunesHelper.) -- E:\iTunes\iTunesHelper.exe =>.Apple Inc.
O53 - SMSR:HKLM\...\startupreg\LogMeIn Hamachi Ui [Key] [64Bits] . (...) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\MurGee.com Auto Keyboard [Key] [64Bits] . (...) -- E:\Program Files (x86)\Auto Keyboard\AutoKeyboard.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\ShadowPlay [Key] [64Bits] . (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe =>.Microsoft Corporation
O53 - SMSR:HKLM\...\startupreg\Steam [Key] [64Bits] . (.Valve Corporation - Steam Client Bootstrapper.) -- e:\Program Files (x86)\Steam\Steam.exe =>.Valve Corporation
O53 - SMSR:HKLM\...\startupreg\SunJavaUpdateSched [Key] [64Bits] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle Corporation
O53 - SMSR:HKLM\...\startupreg\SynTPEnh [Key] [64Bits] . (.Synaptics Incorporated - Synaptics TouchPad 64-bit Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe =>.Synaptics Incorporated
O53 - SMSR:HKLM\...\startupreg\TecoResident [Key] [64Bits] . (...) -- C:\Program Files\TOSHIBA\Teco\TecoResident.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\Viber [Key] [64Bits] . (.Viber Media S.à r.l. - Viber.) -- C:\Users\moez\AppData\Local\Viber\Viber.exe
O53 - SMSR:HKLM\...\startupreg\VirtualCloneDrive [Key] [64Bits] . (.Elaborate Bytes AG - Virtual CloneDrive Daemon.) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe =>.Elaborate Bytes AG
O53 - SMSR:HKLM\...\startupreg\Web Companion [Key] [64Bits] . (...) -- C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe (.not file.)

---\\ System Drivers List (350) - 49s
O58 - SDL:2009/07/14 02:06:38 A . (.Microsoft Corporation - 1394 Bus Device Driver.) -- C:\Windows\System32\drivers\1394bus.sys [68096] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - 1394 OpenHCI Driver.) -- C:\Windows\System32\drivers\1394ohci.sys [229888] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - ACPI Driver for NT.) -- C:\Windows\System32\drivers\acpi.sys [334208] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - ACPI Power Metering Driver.) -- C:\Windows\System32\drivers\acpipmi.sys [12800] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [491088] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [339536] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\drivers\adpu320.sys [182864] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:24:08 A . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\afd.sys [499712] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:10:24 A . (.Microsoft Corporation - RAS Agile Vpn Miniport Call Manager.) -- C:\Windows\System32\drivers\agilevpn.sys [60416] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:52:21 A . (.Microsoft Corporation - 440 NT AGP Filter.) -- C:\Windows\System32\drivers\AGP440.sys [61008] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [15440] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Microsoft Corporation - AMD IDE Driver.) -- C:\Windows\System32\drivers\amdide.sys [15440] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:19:25 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\amdk8.sys [64512] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:19:25 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\amdppm.sys [60928] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [107904] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [194128] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:23:47 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [27008] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:24:25 A . (.Microsoft Corporation - AppID Driver.) -- C:\Windows\System32\drivers\appid.sys [61440] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [87632] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [97856] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:10:13 A . (.Microsoft Corporation - MS Remote Access serial network driver.) -- C:\Windows\System32\drivers\asyncmac.sys [23040] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:52:21 A . (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [24128] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - ATAPI Driver Extension.) -- C:\Windows\System32\drivers\ataport.sys [155520] =>.Microsoft Windows®
O58 - SDL:2013/06/29 00:49:20 A . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driv.) -- C:\Windows\System32\drivers\athurx.sys [1930240] =>.Atheros Communications, Inc.
O58 - SDL:2009/06/10 22:34:23 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60a.sys [270848] =>.Broadcom Corporation
O58 - SDL:2009/07/14 03:52:21 A . (.Microsoft Corporation - Battery Class Driver.) -- C:\Windows\System32\drivers\battc.sys [28240] =>.Microsoft Windows®
O58 - SDL:2010/06/18 10:05:34 A . (.Beceem communications pvt ltd. - Beceem Communications Inc. WiMAX driver.) -- C:\Windows\System32\drivers\BcmBusCtr_64.sys [62464] =>.Beceem communications pvt ltd.
O58 - SDL:2009/07/14 02:00:13 A . (.Microsoft Corporation - BEEP Driver.) -- C:\Windows\System32\drivers\beep.sys [6656] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:35:59 A . (.Microsoft Corporation - BLB Drive Driver.) -- C:\Windows\System32\drivers\blbdrive.sys [45056] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:23:50 A . (.Microsoft Corporation - NT Lan Manager Datagram Receiver Driver.) -- C:\Windows\System32\drivers\bowser.sys [90624] =>.Microsoft Corporation
O58 - SDL:2009/06/10 22:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [18432] =>.Brother Industries, Ltd.
O58 - SDL:2009/06/10 22:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [8704] =>.Brother Industries, Ltd.
O58 - SDL:2009/07/14 03:01:48 A . (.Microsoft Corporation - MAC Bridge Driver.) -- C:\Windows\System32\drivers\bridge.sys [95232] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:19:07 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [286720] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [47104] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [14976] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [14720] =>.Brother Industries Ltd.
O58 - SDL:2009/07/14 02:06:53 A . (.Microsoft Corporation - Bluetooth Bus Extender.) -- C:\Windows\System32\drivers\bthenum.sys [41984] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:06:52 A . (.Microsoft Corporation - Bluetooth Communications Driver.) -- C:\Windows\System32\drivers\bthmodem.sys [72192] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:07:00 A . (.Microsoft Corporation - Bluetooth Personal Area Networking.) -- C:\Windows\System32\drivers\bthpan.sys [118784] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - Bluetooth Bus Driver.) -- C:\Windows\System32\drivers\bthport.sys [552448] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - Bluetooth Miniport Driver.) -- C:\Windows\System32\drivers\BTHUSB.SYS [80384] =>.Microsoft Corporation
O58 - SDL:2009/06/10 22:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [468480] =>.Broadcom Corporation
O58 - SDL:2009/07/14 01:19:47 A . (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\cdfs.sys [92160] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\cdrom.sys [147456] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:06:34 A . (.Microsoft Corporation - Consumer IR Class Driver for eHome.) -- C:\Windows\System32\drivers\circlass.sys [45568] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:24 A . (.Microsoft Corporation - SCSI Class System Dll.) -- C:\Windows\System32\drivers\Classpnp.sys [179072] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:31:03 A . (.Microsoft Corporation - Control Method Battery Driver.) -- C:\Windows\System32\drivers\CmBatt.sys [17664] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [17488] =>.Microsoft Windows®
O58 - SDL:2018/01/27 11:10:16 A . (.AO Kaspersky Lab - Cryptographic Module Driver x64 (56 bit).) -- C:\Windows\System32\drivers\cm_km.sys [243400] =>.Kaspersky Lab®
O58 - SDL:2010/11/21 05:24:08 A . (.Microsoft Corporation - Kernel Cryptography, Next Generation.) -- C:\Windows\System32\drivers\cng.sys [459248] {6115346400000000000C} =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:52:31 A . (.Microsoft Corporation - Composite Battery Driver.) -- C:\Windows\System32\drivers\compbatt.sys [21584] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - Multi-Transport Composite Bus Enumerator.) -- C:\Windows\System32\drivers\CompositeBus.sys [38912] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:47:48 A . (.Microsoft Corporation - Crash Dump Driver.) -- C:\Windows\System32\drivers\crashdmp.sys [39504] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:47:48 A . (.Microsoft Corporation - Disk Block Verification Filter Driver.) -- C:\Windows\System32\drivers\crcdisk.sys [24144] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:24:32 A . (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\dfsc.sys [102400] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:37:18 A . (.Microsoft Corporation - System Indexer/Cache Driver.) -- C:\Windows\System32\drivers\discache.sys [40448] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:47:48 A . (.Microsoft Corporation - PnP Disk Driver.) -- C:\Windows\System32\drivers\disk.sys [73280] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:24:16 A . (.Microsoft Corporation - Crash Dump Disk Driver.) -- C:\Windows\System32\drivers\Diskdump.sys [27520] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:01:25 A . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\Windows\System32\drivers\drmk.sys [116224] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:06:16 A . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\Windows\System32\drivers\drmkaud.sys [5632] =>.Microsoft Corporation
O58 - SDL:2010/06/18 10:05:44 A . (.Beceem communications pvt ltd. - Beceem Communications Inc. WiMAX driver.) -- C:\Windows\System32\drivers\drxvi314_64.sys [363136] =>.Beceem communications pvt ltd.
O58 - SDL:2009/07/14 03:47:48 A . (.Microsoft Corporation - ATAPI Dump Driver.) -- C:\Windows\System32\drivers\Dumpata.sys [28736] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:43:14 A . (.Microsoft Corporation - Bitlocker Drive Encryption Crashdump Filter.) -- C:\Windows\System32\drivers\dumpfve.sys [55128] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:38:28 A . (.Microsoft Corporation - DirectX API Driver.) -- C:\Windows\System32\drivers\dxapi.sys [16896] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:38:28 A . (.Microsoft Corporation - DirectX Graphics Driver.) -- C:\Windows\System32\drivers\dxg.sys [98816] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:32 A . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\Windows\System32\drivers\dxgkrnl.sys [982912] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:24:32 A . (.Microsoft Corporation - DirectX Graphics MMS.) -- C:\Windows\System32\drivers\dxgmms1.sys [258048] =>.Microsoft Corporation
O58 - SDL:2018/02/05 20:52:36 A . (. - eagleGet Network Filter.) -- C:\Windows\System32\drivers\eagleGet.sys [79024]
O58 - SDL:2009/12/18 00:25:17 A . (.Elaborate Bytes AG - ElbyCD Windows x64 I/O driver.) -- C:\Windows\System32\drivers\ElbyCDIO.sys [34472] =>.Elaborate Bytes AG®
O58 - SDL:2009/07/14 03:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [530496] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:31:04 A . (.Microsoft Corporation - Error Device Driver.) -- C:\Windows\System32\drivers\errdev.sys [9728] =>.Microsoft Corporation
O58 - SDL:2009/06/10 22:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3286016] =>.Broadcom Corporation
O58 - SDL:2017/05/29 04:21:07 A . (.Echobit, LLC - Evolve Virtual Miniport Driver.) -- C:\Windows\System32\drivers\evolve.sys [21656] =>.Echobit, LLC®
O58 - SDL:2009/07/14 01:23:29 A . (.Microsoft Corporation - Microsoft Extended FAT File System.) -- C:\Windows\System32\drivers\exfat.sys [195072] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:23:29 A . (.Microsoft Corporation - Fast FAT File System Driver.) -- C:\Windows\System32\drivers\fastfat.sys [204800] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:00:54 A . (.Microsoft Corporation - Floppy Disk Controller Driver.) -- C:\Windows\System32\drivers\fdc.sys [29696] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:47:48 A . (.Microsoft Corporation - FileInfo Filter Driver.) -- C:\Windows\System32\drivers\fileinfo.sys [70224] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:25:40 A . (.Microsoft Corporation - File Trace Filter Driver.) -- C:\Windows\System32\drivers\filetrace.sys [34304] =>.Microsoft Corporation
O58 - SDL:2009/09/09 11:23:46 A . (.Intel Corporation - BIOS Update Driver.) -- C:\Windows\System32\drivers\flashud.sys [51712] =>.Intel Corporation
O58 - SDL:2009/07/14 02:00:54 A . (.Microsoft Corporation - Floppy Driver.) -- C:\Windows\System32\drivers\flpydisk.sys [24576] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:00 A . (.Microsoft Corporation - Microsoft Filesystem Filter Manager.) -- C:\Windows\System32\drivers\fltMgr.sys [289664] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:47:49 A . (.Microsoft Corporation - File System Dependency Manager Mini Filter.) -- C:\Windows\System32\drivers\fsdepends.sys [55376] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:47:48 A . (.Microsoft Corporation - File System Recognizer Driver.) -- C:\Windows\System32\drivers\fs_rec.sys [23104] =>.Microsoft Windows®
O58 - SDL:2015/05/21 22:46:14 A . (...) -- C:\Windows\System32\drivers\fusion.sys [19840] =>.Umar Yaqoob Batoo®
O58 - SDL:2010/11/21 05:24:39 A . (.Microsoft Corporation - BitLocker Drive Encryption Driver.) -- C:\Windows\System32\drivers\fvevol.sys [223248] {6115346400000000000C} =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:08 A . (.Microsoft Corporation - FWP/IPsec Kernel-Mode API.) -- C:\Windows\System32\drivers\FWPKCLNT.SYS [288640] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:47:48 A . (.Microsoft Corporation - MS Generic AGPv3.0 Filter for K8/9 Processo.) -- C:\Windows\System32\drivers\GAGP30KX.SYS [65088] =>.Microsoft Windows®
O58 - SDL:2017/05/22 16:21:10 AH . (.LogMeIn, Inc. - Hamachi Virtual Network Interface Driver.) -- C:\Windows\System32\drivers\hamachi.sys [35648] =>.LogMeIn, Inc.®
O58 - SDL:2016/09/06 18:48:58 A . (.VMware, Inc. - VMware USB monitor.) -- C:\Windows\System32\drivers\hcmon.sys [83008] =>.VMware, Inc.®
O58 - SDL:2009/06/10 22:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [31232] =>.Hauppauge Computer Works, Inc.
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\hdaudbus.sys [122368] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - High Definition Audio Function Driver.) -- C:\Windows\System32\drivers\HdAudio.sys [350208] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:31:06 A . (.Microsoft Corporation - Hid Battery Driver.) -- C:\Windows\System32\drivers\hidbatt.sys [26624] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:06:52 A . (.Microsoft Corporation - Bluetooth Miniport Driver for HID Devices.) -- C:\Windows\System32\drivers\hidbth.sys [100864] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - Hid Class Library.) -- C:\Windows\System32\drivers\hidclass.sys [76800] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:06:23 A . (.Microsoft Corporation - Infrared Miniport Driver for Input Devices.) -- C:\Windows\System32\drivers\hidir.sys [46592] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:06:17 A . (.Microsoft Corporation - Hid Parsing Library.) -- C:\Windows\System32\drivers\hidparse.sys [32896] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - USB Miniport Driver for Input Devices.) -- C:\Windows\System32\drivers\hidusb.sys [30208] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [78720] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:23:55 A . (.Microsoft Corporation - HTTP Protocol Stack.) -- C:\Windows\System32\drivers\http.sys [753664] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:24 A . (.Microsoft Corporation - Hardware Policy Driver.) -- C:\Windows\System32\drivers\hwpolicy.sys [14720] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:19:57 A . (.Microsoft Corporation - i8042 Port Driver.) -- C:\Windows\System32\drivers\i8042prt.sys [105472] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [410496] =>.Microsoft Windows®
O58 - SDL:2010/08/18 00:28:32 A . (.Intel Corporation - Intel(R) Watchdog Timer Driver (Intel(R) WD.) -- C:\Windows\System32\drivers\ICCWDT.sys [26136] =>.Intel Corporation®
O58 - SDL:2015/05/25 03:20:58 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd64.sys [3788728] =>.Intel Corporation - pGFX®
O58 - SDL:2009/07/14 03:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [44112] =>.Microsoft Windows®
O58 - SDL:2014/09/09 04:13:28 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\Windows\System32\drivers\IntcDAud.sys [454416] =>.Intel Corporation - Client Components Group®
O58 - SDL:2009/07/14 03:48:04 A . (.Microsoft Corporation - Intel PCI IDE Driver.) -- C:\Windows\System32\drivers\intelide.sys [16960] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:19:25 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\intelppm.sys [62464] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:27 A . (.Microsoft Corporation - IP FILTER DRIVER.) -- C:\Windows\System32\drivers\ipfltdrv.sys [82944] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:48 A . (.Microsoft Corporation - WMI IPMI DRIVER.) -- C:\Windows\System32\drivers\IPMIDrv.sys [78848] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:10:03 A . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\ipnat.sys [116224] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:09:02 A . (.Microsoft Corporation - IRDA Protocol Driver.) -- C:\Windows\System32\drivers\irda.sys [120320] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:08:59 A . (.Microsoft Corporation - Infra-Red Bus Enumerator.) -- C:\Windows\System32\drivers\irenum.sys [17920] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:48:04 A . (.Microsoft Corporation - PNP ISA Bus Driver.) -- C:\Windows\System32\drivers\isapnp.sys [20544] =>.Microsoft Windows®
O58 - SDL:2013/12/10 14:15:46 A . (.Intel Corporation - Intel(R) USB 3.0 eXtensible Host Controller.) -- C:\Windows\System32\drivers\iusb3xhc.sys [795632] =>.Intel Corporation - Software and Firmware Products®
O58 - SDL:2009/07/14 03:48:04 A . (.Microsoft Corporation - Keyboard Class Driver.) -- C:\Windows\System32\drivers\kbdclass.sys [50768] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - HID Keyboard Filter Driver.) -- C:\Windows\System32\drivers\kbdhid.sys [33280] =>.Microsoft Corporation
O58 - SDL:2018/02/20 11:53:38 A . (.AO Kaspersky Lab - Updatable component loader [fre_wnet_x64].) -- C:\Windows\System32\drivers\kl1.sys [528576] =>.Kaspersky Lab®
O58 - SDL:2017/12/27 10:10:46 A . (.AO Kaspersky Lab - Backup Disk Filter [fre_wnet_x64].) -- C:\Windows\System32\drivers\klbackupdisk.sys [72904] =>.Kaspersky Lab®
O58 - SDL:2018/02/02 03:45:36 A . (.AO Kaspersky Lab - Backup File Filter [fre_wlh_x64].) -- C:\Windows\System32\drivers\klbackupflt.sys [122056] =>.Kaspersky Lab®
O58 - SDL:2018/09/01 01:04:54 A . (.AO Kaspersky Lab - Virtual Disk [fre_win7_x64].) -- C:\Windows\System32\drivers\kldisk.sys [87752] =>.Kaspersky Lab®
O58 - SDL:2018/09/01 01:01:32 A . (.AO Kaspersky Lab - Filter Core [fre_wlh_x64].) -- C:\Windows\System32\drivers\klflt.sys [219328] =>.Kaspersky Lab®
O58 - SDL:2018/09/01 01:01:07 A . (.AO Kaspersky Lab - klhk [fre_win7_x64].) -- C:\Windows\System32\drivers\klhk.sys [1193160] =>.Kaspersky Lab®
O58 - SDL:2018/09/01 01:01:36 A . (.AO Kaspersky Lab - Core System Interceptors [fre_wlh_x64].) -- C:\Windows\System32\drivers\klif.sys [1127104] =>.Kaspersky Lab®
O58 - SDL:2018/02/12 04:17:12 A . (.AO Kaspersky Lab - Packet Network Filter [fre_wlh_x64].) -- C:\Windows\System32\drivers\klim6.sys [56520] =>.Kaspersky Lab®
O58 - SDL:2018/01/15 05:16:12 A . (.AO Kaspersky Lab - Keyboard Device Filter [fre_wlh_x64].) -- C:\Windows\System32\drivers\klkbdflt.sys [58056] =>.Kaspersky Lab®
O58 - SDL:2017/12/11 11:49:14 A . (.AO Kaspersky Lab - Mouse Device Filter [fre_wlh_x64].) -- C:\Windows\System32\drivers\klmouflt.sys [83496] =>.Kaspersky Lab®
O58 - SDL:2017/05/30 18:51:40 A . (.AO Kaspersky Lab - Format Recognizer [fre_wnet_x64].) -- C:\Windows\System32\drivers\klpd.sys [50648] =>.Kaspersky Lab®
O58 - SDL:2016/06/07 01:31:06 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\Windows\System32\drivers\kltap.sys [52152] =>.AnchorFree Inc®
O58 - SDL:2017/11/07 23:56:12 A . (.AO Kaspersky Lab - Legacy Network Filter [fre_wnet_x64].) -- C:\Windows\System32\drivers\kltdi.sys [81632] =>.Kaspersky Lab®
O58 - SDL:2018/09/01 01:01:46 A . (.AO Kaspersky Lab - WFP Network Connection Filter Driver [fre_w.) -- C:\Windows\System32\drivers\klwtp.sys [161592] =>.Microsoft Windows Hardware Compatibility Publisher®
O58 - SDL:2018/02/24 05:17:48 A . (.AO Kaspersky Lab - Network Processor [fre_wnet_x64].) -- C:\Windows\System32\drivers\kneps.sys [203968] =>.Kaspersky Lab®
O58 - SDL:2010/11/21 05:24:16 A . (.Microsoft Corporation - Kernel CSA Library.) -- C:\Windows\System32\drivers\ks.sys [243712] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:08 A . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\drivers\ksecdd.sys [95616] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:24:08 A . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\drivers\ksecpkg.sys [152960] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:00:19 A . (.Microsoft Corporation - Kernel Streaming WOW Thunk Service.) -- C:\Windows\System32\drivers\ksthunk.sys [20992] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:08:51 A . (.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) -- C:\Windows\System32\drivers\lltdio.sys [60928] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:09:10 A . (.Microsoft Corporation - Loopback Network Driver.) -- C:\Windows\System32\drivers\loop.sys [7680] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [114752] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [106560] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [65600] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [115776] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:26:13 A . (.Microsoft Corporation - LUA File Virtualization Filter Driver.) -- C:\Windows\System32\drivers\luafv.sys [113152] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:01:06 A . (.Microsoft Corporation - Medium changer class driver.) -- C:\Windows\System32\drivers\mcd.sys [22016] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [35392] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [284736] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:10:48 A . (.Microsoft Corporation - Modem Device Driver.) -- C:\Windows\System32\drivers\modem.sys [40448] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:38:52 A . (.Microsoft Corporation - Monitor Driver.) -- C:\Windows\System32\drivers\monitor.sys [30208] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:48:27 A . (.Microsoft Corporation - Mouse Class Driver.) -- C:\Windows\System32\drivers\mouclass.sys [49216] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:00:20 A . (.Microsoft Corporation - HID Mouse Filter Driver.) -- C:\Windows\System32\drivers\mouhid.sys [31232] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:53 A . (.Microsoft Corporation - Mount Point Manager.) -- C:\Windows\System32\drivers\mountmgr.sys [94592] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - MultiPath Support Bus-Driver.) -- C:\Windows\System32\drivers\mpio.sys [155008] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:08:25 A . (.Microsoft Corporation - Microsoft Protection Service Driver.) -- C:\Windows\System32\drivers\mpsdrv.sys [77312] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:36 A . (.Microsoft Corporation - Windows NT WebDav Minirdr.) -- C:\Windows\System32\drivers\mrxdav.sys [140800] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:03 A . (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\mrxsmb.sys [158208] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:03 A . (.Microsoft Corporation - Longhorn SMB Downlevel SubRdr.) -- C:\Windows\System32\drivers\mrxsmb10.sys [287744] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:15 A . (.Microsoft Corporation - Longhorn SMB 2.0 Redirector.) -- C:\Windows\System32\drivers\mrxsmb20.sys [128000] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - MS AHCI 1.0 Standard Driver.) -- C:\Windows\System32\drivers\msahci.sys [31104] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - Microsoft Device Specific Module.) -- C:\Windows\System32\drivers\msdsm.sys [140672] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:19:47 A . (.Microsoft Corporation - Mailslot driver.) -- C:\Windows\System32\drivers\msfs.sys [26112] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:06:24 A . (.Microsoft Corporation - Pass-through HID to KMDF Filter Driver.) -- C:\Windows\System32\drivers\mshidkmdf.sys [8192] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:48:27 A . (.Microsoft Corporation - ISA Driver.) -- C:\Windows\System32\drivers\msisadrv.sys [15424] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:23:48 A . (.Microsoft Corporation - Microsoft iSCSI Initiator Driver.) -- C:\Windows\System32\drivers\msiscsi.sys [273792] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:00:18 A . (.Microsoft Corporation - MS KS Server.) -- C:\Windows\System32\drivers\mskssrv.sys [11136] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:00:17 A . (.Microsoft Corporation - MS Proxy Clock.) -- C:\Windows\System32\drivers\mspclock.sys [7168] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:00:17 A . (.Microsoft Corporation - MS Proxy Quality Manager.) -- C:\Windows\System32\drivers\mspqm.sys [6784] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:15 A . (.Microsoft Corporation - Kernel Remote Procedure Call Provider.) -- C:\Windows\System32\drivers\msrpc.sys [366976] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:27 A . (.Microsoft Corporation - System Management BIOS Driver.) -- C:\Windows\System32\drivers\mssmbios.sys [32320] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:00:17 A . (.Microsoft Corporation - WDM Tee/Communication Transform Filter.) -- C:\Windows\System32\drivers\mstee.sys [8064] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:02:08 A . (.Microsoft Corporation - Microsoft Multi-Touch HID Driver.) -- C:\Windows\System32\drivers\MTConfig.sys [15360] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:48:27 A . (.Microsoft Corporation - Multiple UNC Provider Driver.) -- C:\Windows\System32\drivers\mup.sys [60496] =>.Microsoft Windows®
O58 - SDL:2012/11/28 04:18:03 A . (.Marvell Semiconductor, Inc. - USB EWS Device Driver.) -- C:\Windows\System32\drivers\mvusbews.sys [20480] =>.Marvell Semiconductor, Inc.
O58 - SDL:2010/11/21 05:23:55 A . (.Microsoft Corporation - NDIS 6.20 driver.) -- C:\Windows\System32\drivers\ndis.sys [951680] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:08:13 A . (.Microsoft Corporation - NDIS Packet Capture Filter Driver.) -- C:\Windows\System32\drivers\ndiscap.sys [35328] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:10:00 A . (.Microsoft Corporation - NDIS 3.0 connection wrapper driver.) -- C:\Windows\System32\drivers\ndistapi.sys [24064] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:32 A . (.Microsoft Corporation - NDIS User mode I/O driver.) -- C:\Windows\System32\drivers\ndisuio.sys [56832] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:08 A . (.Microsoft Corporation - MS PPP Framing Driver (Strong Encryption).) -- C:\Windows\System32\drivers\ndiswan.sys [164352] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:14 A . (.Microsoft Corporation - NDIS Proxy.) -- C:\Windows\System32\drivers\ndproxy.sys [57856] =>.Microsoft Corporation
O58 - SDL:2017/10/13 13:57:52 A . (.Apple Inc. - Apple Mobile Device Ethernet.) -- C:\Windows\System32\drivers\netaapl64.sys [23040] =>.Apple Inc.
O58 - SDL:2009/07/14 02:09:26 A . (.Microsoft Corporation - NetBIOS interface driver.) -- C:\Windows\System32\drivers\netbios.sys [44544] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:51 A . (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netbt.sys [261632] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:26 A . (.Microsoft Corporation - Network I/O Subsystem.) -- C:\Windows\System32\drivers\netio.sys [376192] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [51264] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:19:48 A . (.Microsoft Corporation - NPFS Driver.) -- C:\Windows\System32\drivers\npfs.sys [44032] =>.Microsoft Corporation
O58 - SDL:2009/09/01 21:10:00 A . (.NeoRouter Inc. - NeoRouter Virtual Network Driver.) -- C:\Windows\System32\drivers\nrtap.sys [29696] =>.NeoRouter Inc.
O58 - SDL:2009/07/14 01:21:02 A . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\drivers\nsiproxy.sys [24576] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:55 A . (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\drivers\ntfs.sys [1659776] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:19:38 A . (.Microsoft Corporation - NULL Driver.) -- C:\Windows\System32\drivers\null.sys [6144] =>.Microsoft Corporation
O58 - SDL:2018/03/16 20:02:26 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\Windows\System32\drivers\nvlddmkm.sys [17353576] =>.NVIDIA Corporation®
O58 - SDL:2018/03/16 20:03:02 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\Windows\System32\drivers\nvpciflt.sys [48384] =>.NVIDIA Corporation®
O58 - SDL:2010/11/21 05:23:47 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [148352] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:23:47 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [166272] =>.Microsoft Windows®
O58 - SDL:2017/12/15 04:03:48 A . (.NVIDIA Corporation - NVIDIA Virtual Audio Driver.) -- C:\Windows\System32\drivers\nvvad64v.sys [59240] =>.NVIDIA Corporation®
O58 - SDL:2018/01/04 03:39:57 A . (.NVIDIA Corporation - Virtual USB Host Controller driver.) -- C:\Windows\System32\drivers\nvvhci.sys [57792] =>.NVIDIA Corporation®
O58 - SDL:2009/07/14 03:48:26 A . (.Microsoft Corporation - NForce NT AGP Filter.) -- C:\Windows\System32\drivers\NV_AGP.SYS [122960] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:07:23 A . (.Microsoft Corporation - NativeWiFi Miniport Driver.) -- C:\Windows\System32\drivers\nwifi.sys [318976] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:06:45 A . (.Microsoft Corporation - 1394 OpenHCI Port Driver.) -- C:\Windows\System32\drivers\ohci1394.sys [72832] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:08 A . (.Microsoft Corporation - QoS Packet Scheduler.) -- C:\Windows\System32\drivers\pacer.sys [131584] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:00:41 A . (.Microsoft Corporation - Parallel Port Driver.) -- C:\Windows\System32\drivers\parport.sys [97280] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:26 A . (.Microsoft Corporation - Partition Management Driver.) -- C:\Windows\System32\drivers\partmgr.sys [75136] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - NT Plug and Play PCI Enumerator.) -- C:\Windows\System32\drivers\pci.sys [184704] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:45 A . (.Microsoft Corporation - Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\pciide.sys [12352] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:46 A . (.Microsoft Corporation - PCI IDE Bus Driver Extension.) -- C:\Windows\System32\drivers\pciidex.sys [48720] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:45 A . (.Microsoft Corporation - PCMCIA Bus Driver.) -- C:\Windows\System32\drivers\pcmcia.sys [220752] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:45 A . (.Microsoft Corporation - Performance Counters for Windows Driver.) -- C:\Windows\System32\drivers\pcw.sys [50768] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:01:19 A . (.Microsoft Corporation - Protected Environment Authentication and Au.) -- C:\Windows\System32\drivers\PEAuth.sys [651264] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:06:29 A . (.Microsoft Corporation - Port Class (Class Driver for Port/Miniport.) -- C:\Windows\System32\drivers\portcls.sys [230400] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:19:25 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\processr.sys [60416] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1524816] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [128592] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:09:48 A . (.Microsoft Corporation - Microsoft Quality Windows Audio Video Exper.) -- C:\Windows\System32\drivers\qwavedrv.sys [46592] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:10:09 A . (.Microsoft Corporation - RAS Automatic Connection Driver.) -- C:\Windows\System32\drivers\rasacd.sys [14848] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:33 A . (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\rasl2tp.sys [129536] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:10:17 A . (.Microsoft Corporation - RAS PPPoE mini-port/call-manager driver.) -- C:\Windows\System32\drivers\raspppoe.sys [92672] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:33 A . (.Microsoft Corporation - Peer-to-Peer Tunneling Protocol.) -- C:\Windows\System32\drivers\raspptp.sys [111104] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:10:25 A . (.Microsoft Corporation - RAS SSTP Miniport Call Manager.) -- C:\Windows\System32\drivers\rassstp.sys [83968] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:08 A . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) -- C:\Windows\System32\drivers\rdbss.sys [309248] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:17:46 A . (.Microsoft Corporation - Microsoft RDP Bus Device driver.) -- C:\Windows\System32\drivers\rdpbus.sys [24064] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:16:34 A . (.Microsoft Corporation - RDP Miniport.) -- C:\Windows\System32\drivers\RDPCDD.sys [7680] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:16:34 A . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\drivers\RDPENCDD.sys [7680] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:16:35 A . (.Microsoft Corporation - RDP Reflector Driver Miniport.) -- C:\Windows\System32\drivers\RDPREFMP.sys [8192] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:29 A . (.Microsoft Corporation - RDP Terminal Stack Driver.) -- C:\Windows\System32\drivers\rdpwd.sys [210944] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:33 A . (.Microsoft Corporation - ReadyBoost Driver.) -- C:\Windows\System32\drivers\rdyboost.sys [213888] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:06:56 A . (.Microsoft Corporation - Bluetooth RFCOMM Driver.) -- C:\Windows\System32\drivers\rfcomm.sys [158720] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:15 A . (.Microsoft Corporation - Reliable Multicast Transport.) -- C:\Windows\System32\drivers\rmcast.sys [146432] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:09:48 A . (.Microsoft Corporation - Remote NDIS Miniport.) -- C:\Windows\System32\drivers\RNDISMP.sys [41472] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:09:48 A . (.Microsoft Corporation - Remote NDIS Miniport.) -- C:\Windows\System32\drivers\rndismp6.sys [35840] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:09:47 A . (.Microsoft Corporation - Remote NDIS Miniport.) -- C:\Windows\System32\drivers\rndismpx.sys [41472] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:10:47 A . (.Microsoft Corporation - Legacy Non-Pnp Modem Device Driver.) -- C:\Windows\System32\drivers\rootmdm.sys [11264] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:08:51 A . (.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) -- C:\Windows\System32\drivers\rspndr.sys [76800] =>.Microsoft Corporation
O58 - SDL:2015/08/24 09:11:06 A . (.Realtek - Realtek 8136/8168/8169 NDIS 6.20 64-bit Dri.) -- C:\Windows\System32\drivers\Rt64win7.sys [987888] =>.Realtek Semiconductor Corp®
O58 - SDL:2012/01/05 13:42:32 A . (.Realtek Microelectronics - Filter Driver for the Realtek Bluetooth Chi.) -- C:\Windows\System32\drivers\RtkBtfilter.sys [21096] =>.Realtek Semiconductor Corp®
O58 - SDL:2015/10/07 04:41:40 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RTKVHD64.sys [4613888] =>.Realtek Semiconductor Corp®
O58 - SDL:2015/06/01 16:44:54 A . (.Realtek Semiconductor Corp. - Realtek Pcie CardReader Driver for 2K/XP/Vi.) -- C:\Windows\System32\drivers\RtsP2Stor.sys [301784] =>.Realtek Semiconductor Corp®
O58 - SDL:2012/08/14 11:20:56 A . (.Realtek Semiconductor Corporation - Realtek PCIE NDIS Driverr.) -- C:\Windows\System32\drivers\rtwlane.sys [1148048] =>.Realtek Semiconductor Corp®
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - SBP-2 Protocol Driver.) -- C:\Windows\System32\drivers\sbp2port.sys [103808] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:24:09 A . (.Microsoft Corporation - Microsoft Smart Card Reader Filter Driver.) -- C:\Windows\System32\drivers\scfilter.sys [29696] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:00 A . (.Microsoft Corporation - SCSI Port Driver.) -- C:\Windows\System32\drivers\scsiport.sys [171392] =>.Microsoft Windows®
O58 - SDL:2009/06/10 22:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] =>.Rovi Corporation
O58 - SDL:2017/05/28 21:47:41 A . (.SoftEther Corporation - SoftEther VPN.) -- C:\Windows\System32\drivers\see.sys [50208] =>.SoftEther Corporation®
O58 - SDL:2015/06/04 13:33:50 A . (...) -- C:\Windows\System32\drivers\semav6msr64.sys [21984] =>.Intel(R) Code Signing External®
O58 - SDL:2009/07/14 02:00:33 A . (.Microsoft Corporation - Serial Port Enumerator.) -- C:\Windows\System32\drivers\serenum.sys [23552] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:00:40 A . (.Microsoft Corporation - Serial Device Driver.) -- C:\Windows\System32\drivers\serial.sys [94208] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:00:20 A . (.Microsoft Corporation - Serial Mouse Filter Driver.) -- C:\Windows\System32\drivers\sermouse.sys [26624] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:01:01 A . (.Microsoft Corporation - Small Form Factor Disk Driver.) -- C:\Windows\System32\drivers\sffdisk.sys [14336] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:01:03 A . (.Microsoft Corporation - Small Form Factor MMC Protocol Driver.) -- C:\Windows\System32\drivers\sffp_mmc.sys [13824] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - Small Form Factor SD Protocol Driver.) -- C:\Windows\System32\drivers\sffp_sd.sys [14336] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:01:02 A . (.Microsoft Corporation - SCSI Floppy Driver.) -- C:\Windows\System32\drivers\sfloppy.sys [16896] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [43584] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [80464] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:09:09 A . (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [93184] =>.Microsoft Corporation
O58 - SDL:2015/07/02 00:33:46 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\Windows\System32\drivers\Smb_driver_AMDASF_Aux.sys [33448] =>.Synaptics Incorporated®
O58 - SDL:2015/07/02 00:33:46 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\Windows\System32\drivers\Smb_driver_Intel.sys [33960] =>.Synaptics Incorporated®
O58 - SDL:2015/07/02 00:33:46 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\Windows\System32\drivers\Smb_driver_Intel_Aux.sys [33960] =>.Synaptics Incorporated®
O58 - SDL:2009/07/14 02:00:35 A . (.Microsoft Corporation - Smart Card Driver Library.) -- C:\Windows\System32\drivers\smclib.sys [20992] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:45:55 A . (.Microsoft Corporation - loader for security processor.) -- C:\Windows\System32\drivers\spldr.sys [19008] =>.Microsoft Windows®
O58 - SDL:2009/06/10 22:48:43 A . (.Microsoft Corporation - security processor.) -- C:\Windows\System32\drivers\spsys.sys [426496] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:50 A . (.Microsoft Corporation - Server driver.) -- C:\Windows\System32\drivers\srv.sys [468992] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:51 A . (.Microsoft Corporation - Smb 2.0 Server driver.) -- C:\Windows\System32\drivers\srv2.sys [413184] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:54 A . (.Microsoft Corporation - Server Network driver.) -- C:\Windows\System32\drivers\srvnet.sys [167936] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [24656] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:24:00 A . (.Microsoft Corporation - Microsoft Storage Port Driver.) -- C:\Windows\System32\drivers\storport.sys [189824] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:06:18 A . (.Microsoft Corporation - WDM CODEC Class Device Driver 2.0.) -- C:\Windows\System32\drivers\stream.sys [68864] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:45:55 A . (.Microsoft Corporation - Plug and Play Software Device Enumerator.) -- C:\Windows\System32\drivers\swenum.sys [12496] =>.Microsoft Windows®
O58 - SDL:2015/07/02 00:33:42 A . (.Synaptics Incorporated - Synaptics Touchpad Win64 Driver.) -- C:\Windows\System32\drivers\SynTP.sys [607400] =>.Synaptics Incorporated®
O58 - SDL:2015/03/07 21:27:18 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver.) -- C:\Windows\System32\drivers\tap0901.sys [40664] =>.OpenVPN Technologies, Inc.®
O58 - SDL:2015/12/21 17:01:36 A . (.Tunngle.net - TAP-Win32 Virtual Network Driver.) -- C:\Windows\System32\drivers\tap0901t.sys [47736] =>.Tunngle.net GmbH®
O58 - SDL:2009/07/14 02:01:04 A . (.Microsoft Corporation - SCSI Tape Class Driver.) -- C:\Windows\System32\drivers\tape.sys [29184] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:08 A . (.Microsoft Corporation - TCP/IP Driver.) -- C:\Windows\System32\drivers\tcpip.sys [1924480] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:23:52 A . (.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) -- C:\Windows\System32\drivers\tcpipreg.sys [45056] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:01 A . (.Microsoft Corporation - TDI Wrapper.) -- C:\Windows\System32\drivers\tdi.sys [26624] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:16:32 A . (.Microsoft Corporation - Named Pipe Transport Driver.) -- C:\Windows\System32\drivers\tdpipe.sys [15872] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:16:32 A . (.Microsoft Corporation - TCP Transport Driver.) -- C:\Windows\System32\drivers\tdtcp.sys [23552] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:32 A . (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [119296] =>.Microsoft Corporation
O58 - SDL:2015/08/31 21:50:26 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\drivers\TeeDriverx64.sys [179456] =>.Intel Corporation - Embedded Subsystems and IP Blocks Group®
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - Remote Desktop Server Driver.) -- C:\Windows\System32\drivers\termdd.sys [63360] =>.Microsoft Windows®
O58 - SDL:2009/06/29 14:16:20 A . (.TOSHIBA Corporation - TOSHIBA HDD Protection - Shock Sensor Drive.) -- C:\Windows\System32\drivers\Thpevm.sys [14784] =>.TOSHIBA CORPORATION®
O58 - SDL:2014/06/21 14:56:00 A . (.TOSHIBA Corporation - TOSHIBA Bluetooth EC Driver.) -- C:\Windows\System32\drivers\tosrfec.sys [53624] =>.TOSHIBA CORPORATION®
O58 - SDL:2010/11/21 05:23:51 A . (.Microsoft Corporation - TS Security Filter Driver.) -- C:\Windows\System32\drivers\tssecsrv.sys [39424] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:33 A . (.Microsoft Corporation - Remote Desktop USB Hub Filter Driver.) -- C:\Windows\System32\drivers\TsUsbFlt.sys [59392] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - Remote Desktop Generic USB Driver.) -- C:\Windows\System32\drivers\TsUsbGD.sys [31232] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:15 A . (.Microsoft Corporation - Microsoft Tunnel Interface Driver.) -- C:\Windows\System32\drivers\tunnel.sys [125440] =>.Microsoft Corporation
O58 - SDL:2009/07/14 13:31:18 A . (.TOSHIBA Corporation - TOSHIBA ACPI-Based Value Added Logical and.) -- C:\Windows\System32\drivers\TVALZ_O.SYS [26840] =>.TOSHIBA CORPORATION®
O58 - SDL:2009/07/14 03:45:55 A . (.Microsoft Corporation - MS AGPv3.5 Filter.) -- C:\Windows\System32\drivers\UAGP35.SYS [64080] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:23:55 A . (.Microsoft Corporation - UDF File System Driver.) -- C:\Windows\System32\drivers\udfs.sys [328192] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:45:55 A . (.Microsoft Corporation - ULi AGPv3.0 Filter for K8/9 Processor Platf.) -- C:\Windows\System32\drivers\ULIAGPKX.SYS [64592] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - User-Mode Bus Enumerator.) -- C:\Windows\System32\drivers\umbus.sys [48640] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:06:52 A . (.Microsoft Corporation - Generic pass-through driver.) -- C:\Windows\System32\drivers\umpass.sys [9728] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:09:49 A . (.Microsoft Corporation - Remote NDIS USB Driver.) -- C:\Windows\System32\drivers\usb8023.sys [19968] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:09:50 A . (.Microsoft Corporation - Remote NDIS USB Driver.) -- C:\Windows\System32\drivers\usb80236.sys [19968] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:09:50 A . (.Microsoft Corporation - Remote NDIS USB Driver.) -- C:\Windows\System32\drivers\usb8023x.sys [19968] =>.Microsoft Corporation
O58 - SDL:2017/11/27 11:46:14 A . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\drivers\usbaapl64.sys [54784] =>.Apple, Inc.
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - USB Audio Class Driver.) -- C:\Windows\System32\drivers\USBAUDIO.sys [109696] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:11 A . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) -- C:\Windows\System32\drivers\USBCAMD2.sys [32896] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - USB Common Class Generic Parent Driver.) -- C:\Windows\System32\drivers\usbccgp.sys [98816] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:06:37 A . (.Microsoft Corporation - USB Consumer IR Driver for eHome.) -- C:\Windows\System32\drivers\usbcir.sys [100352] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:06:23 A . (.Microsoft Corporation - Universal Serial Bus Driver.) -- C:\Windows\System32\drivers\usbd.sys [7936] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - EHCI eUSB Miniport Driver.) -- C:\Windows\System32\drivers\usbehci.sys [52224] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - Default Hub Driver for USB.) -- C:\Windows\System32\drivers\usbhub.sys [343040] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:06:30 A . (.Microsoft Corporation - OHCI USB Miniport Driver.) -- C:\Windows\System32\drivers\usbohci.sys [25600] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - USB 1.1 & 2.0 Port Driver.) -- C:\Windows\System32\drivers\usbport.sys [325120] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:38:18 A . (.Microsoft Corporation - USB Printer driver.) -- C:\Windows\System32\drivers\usbprint.sys [25088] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:39 A . (.Microsoft Corporation - Windows USB Redirection Policy Manager.) -- C:\Windows\System32\drivers\usbrpm.sys [31744] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:35:32 A . (.Microsoft Corporation - USB Scanner Driver.) -- C:\Windows\System32\drivers\usbscan.sys [41984] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - USB Mass Storage Class Driver.) -- C:\Windows\System32\drivers\USBSTOR.SYS [91648] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:06:27 A . (.Microsoft Corporation - UHCI USB Miniport Driver.) -- C:\Windows\System32\drivers\usbuhci.sys [30720] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - USB Video Class Driver.) -- C:\Windows\System32\drivers\usbvideo.sys [184960] =>.Microsoft Corporation
O58 - SDL:2016/04/28 15:05:50 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Host-Only Network Adapt.) -- C:\Windows\System32\drivers\VBoxNetAdp6.sys [119712] =>.Oracle Corporation®
O58 - SDL:2016/04/28 15:05:50 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Lightweight Filter Driv.) -- C:\Windows\System32\drivers\VBoxNetLwf.sys [192352] =>.Oracle Corporation®
O58 - SDL:2016/04/28 15:05:50 A . (.Oracle Corporation - VirtualBox USB Driver.) -- C:\Windows\System32\drivers\VBoxUSB.sys [135768] =>.Oracle Corporation®
O58 - SDL:2009/07/14 03:45:55 A . (.Microsoft Corporation - Virtual Drive Root Enumerator.) -- C:\Windows\System32\drivers\vdrvroot.sys [36432] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:38:47 A . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\drivers\vga.sys [29184] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:38:47 A . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\drivers\vgapnp.sys [29184] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - VHD Miniport Driver.) -- C:\Windows\System32\drivers\vhdmp.sys [215936] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [17488] =>.Microsoft Windows®
O58 - SDL:2009/07/14 01:38:51 A . (.Microsoft Corporation - Video Port Driver.) -- C:\Windows\System32\drivers\videoprt.sys [129024] =>.Microsoft Corporation
O58 - SDL:2016/09/02 21:27:24 A . (.VMware, Inc. - VMware PCI VMCI Bus Device.) -- C:\Windows\System32\drivers\vmci.sys [106560] =>.VMware, Inc.®
O58 - SDL:2016/09/06 19:13:08 A . (.VMware, Inc. - VMware virtual network driver (64-bit).) -- C:\Windows\System32\drivers\vmnet.sys [45632] =>.VMware, Inc.®
O58 - SDL:2016/09/06 19:13:08 A . (.VMware, Inc. - VMware virtual network adapter driver (64-b.) -- C:\Windows\System32\drivers\vmnetadapter.sys [46144] =>.VMware, Inc.®
O58 - SDL:2016/09/06 19:13:10 A . (.VMware, Inc. - VMware bridge driver (64-bit).) -- C:\Windows\System32\drivers\vmnetbridge.sys [66624] =>.VMware, Inc.®
O58 - SDL:2016/09/06 19:13:10 A . (.VMware, Inc. - VMware network application interface driver.) -- C:\Windows\System32\drivers\vmnetuserif.sys [44096] =>.VMware, Inc.®
O58 - SDL:2016/09/06 18:48:58 A . (.VMware, Inc. - VMware USB driver.) -- C:\Windows\System32\drivers\vmusb.sys [60480] =>.VMware, Inc.®
O58 - SDL:2016/09/06 19:25:10 A . (.VMware, Inc. - VMware kernel driver.) -- C:\Windows\System32\drivers\vmx86.sys [88128] =>.VMware, Inc.®
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\drivers\volmgr.sys [71552] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:24:15 A . (.Microsoft Corporation - Volume Manager Extension Driver.) -- C:\Windows\System32\drivers\volmgrx.sys [363392] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - Volume Shadow Copy Driver.) -- C:\Windows\System32\drivers\volsnap.sys [295808] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [161872] =>.Microsoft Windows®
O58 - SDL:2016/09/02 21:27:24 A . (.VMware, Inc. - VMware vSockets Service.) -- C:\Windows\System32\drivers\vsock.sys [93248] =>.VMware, Inc.®
O58 - SDL:2009/07/14 02:07:21 A . (.Microsoft Corporation - Virtual WiFi Bus Driver.) -- C:\Windows\System32\drivers\vwifibus.sys [24576] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:07:22 A . (.Microsoft Corporation - Virtual WiFi Filter Driver.) -- C:\Windows\System32\drivers\vwififlt.sys [59904] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:07:28 A . (.Microsoft Corporation - Virtual WiFi Miniport Driver.) -- C:\Windows\System32\drivers\vwifimp.sys [17920] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:02:07 A . (.Microsoft Corporation - Wacom Serial Pen Tablet HID Driver.) -- C:\Windows\System32\drivers\wacompen.sys [27776] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:24:11 A . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) -- C:\Windows\System32\drivers\wanarp.sys [88576] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:37:35 A . (.Microsoft Corporation - Watchdog Driver.) -- C:\Windows\System32\drivers\watchdog.sys [42496] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:45:55 A . (.Microsoft Corporation - Microsoft Watchdog Timer Driver.) -- C:\Windows\System32\drivers\wd.sys [21056] =>.Microsoft Windows®
O58 - SDL:2012/07/26 06:55:47 A . (.Microsoft Corporation - Kernel Mode Driver Framework Runtime.) -- C:\Windows\System32\drivers\Wdf01000.sys [785512] =>.Microsoft Windows®
O58 - SDL:2012/07/26 06:55:47 A . (.Microsoft Corporation - Kernel Mode Driver Framework Loader.) -- C:\Windows\System32\drivers\WdfLdr.sys [54376] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:09:26 A . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) -- C:\Windows\System32\drivers\wfplwf.sys [12800] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:45:56 A . (.Microsoft Corporation - Wim file system Driver.) -- C:\Windows\System32\drivers\wimmount.sys [22096] =>.Microsoft Windows®
O58 - SDL:2010/11/21 05:23:47 A . (.Microsoft Corporation - Windows USB Class Driver BETA.) -- C:\Windows\System32\drivers\winusb.sys [41984] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:31:02 A . (.Microsoft Corporation - Windows Management Interface for ACPI.) -- C:\Windows\System32\drivers\wmiacpi.sys [14336] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:45:55 A . (.Microsoft Corporation - WMILIB WMI support library Dll.) -- C:\Windows\System32\drivers\wmilib.sys [16464] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:10:33 A . (.Microsoft Corporation - Winsock2 IFS Layer.) -- C:\Windows\System32\drivers\ws2ifsl.sys [21504] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:50 A . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\drivers\WUDFPf.sys [112128] =>.Microsoft Corporation
O58 - SDL:2010/11/21 05:23:50 A . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\drivers\WUDFRd.sys [172544] =>.Microsoft Corporation
O58 - SDL:2009/07/14 03:52:31 A . (.Microsoft Corporation - Common Log File System Driver.) -- C:\Windows\System32\clfs.sys [367696] =>.Microsoft Windows®
O58 - SDL:2017/05/22 16:21:10 AH . (.LogMeIn, Inc. - Hamachi Virtual Network Interface Driver.) -- C:\Windows\System32\hamachi.sys [35648] =>.LogMeIn, Inc.®
O58 - SDL:2010/11/21 05:24:16 A . (.Microsoft Corporation - Multi-User Win32 Driver.) -- C:\Windows\System32\win32k.sys [3126272] =>.Microsoft Corporation

---\\ Last modified or created user files (2) - 450s
O61 - LFC: 2018/09/15 21:28:58 A . (..) -- C:\Users\moez\Desktop\lnkr4e5g.exe [178295816] {06D1FA3F75BBBE0FB9CD5D15E6E6B852}
O61 - LFC: 2018/09/12 05:10:36 A . (.BitTorrent Inc..) -- C:\Users\moez\Downloads\uTorrent.exe [2963040] {4C2CF9383407889E51D49459} =>BitTorrent (P2P)

---\\ File Associations Shell Spawning (9) - 1s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (...) -- C:\Windows\System32\WScript.exe "%1" %* =>.Default.Value
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S =>.Default.Value

---\\ Start Menu Internet (16) - 0s
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- E:\Program Files (x86)\firefox\firefox.exe =>.Mozilla Corporation®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Opera Software - Opera Internet Browser.) -- E:\Program Files (x86)\opera\Launcher.exe =>.Opera Software AS®
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- E:\Program Files (x86)\firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Opera Software - Opera Internet Browser.) -- E:\Program Files (x86)\opera\launcher.exe =>.Opera Software
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- E:\Program Files (x86)\firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Opera Software - Opera Internet Browser.) -- E:\Program Files (x86)\opera\launcher.exe =>.Opera Software
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- E:\Program Files (x86)\firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Opera Software - Opera Internet Browser.) -- E:\Program Files (x86)\opera\launcher.exe =>.Opera Software

---\\ Search Browser Infection (2) - 8s
O69 - SBI: SearchScopes [HKCU] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com

---\\ Search Svchost Services (32) - 2s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\Windows\System32\aelupsvc.dll [72192] =>.Microsoft Corporation
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [80384] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [80384] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\Windows\System32\srvsvc.dll [236032] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\Windows\System32\gpsvc.dll [777728] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\IKEEXT.DLL [853504] =>.Microsoft Corporation
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\Windows\System32\audiosrv.dll [679424] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\Windows\System32\rasauto.dll [99328] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [344064] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [97792] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\Windows\System32\Sens.dll [64512] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [359424] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [316928] =>.Microsoft Corporation
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remote Desktop Session Host Server Remote C.) -- C:\Windows\System32\termsrv.dll [680960] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\System32\wuaueng.dll [2477536] =>.Microsoft Windows Component Publisher®
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\Windows\System32\qmgr.dll [849920] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [370688] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [569344] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\Windows\System32\seclogon.dll [30720] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\Windows\System32\appinfo.dll [70656] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\Windows\System32\iscsiexe.dll [156672] =>.Microsoft Corporation
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) -- C:\Windows\System32\mmcss.dll [67584] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [242688] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [121856] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\Windows\System32\browser.dll [136192] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [111104] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\Windows\System32\schedsvc.dll [1110016] =>.Microsoft Corporation
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\Windows\System32\KMSVC.DLL [90624] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\Windows\System32\wercplsupport.dll [84480] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [209920] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\Windows\System32\themeservice.dll [44544] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\Windows\System32\bdesvc.dll [100864] =>.Microsoft Corporation

---\\ Firewall Active Exception List (72) - 26s
O87 - FAEL: "{F395F1E3-1792-4420-AA98-33E69CAE77A9}" [In-None-P6-TRUE] .(.Mozilla Corporation - Firefox.) -- E:\Program Files (x86)\firefox\firefox.exe =>.Mozilla Corporation®
O87 - FAEL: "{976CA5BD-A348-4DCE-9487-71C2EE4FC5A7}" [In-None-P17-TRUE] .(.Mozilla Corporation - Firefox.) -- E:\Program Files (x86)\firefox\firefox.exe =>.Mozilla Corporation®
O87 - FAEL: "{8FF16FAA-4FA3-419D-B48B-733659EB6963}" [In-None-P6-TRUE] .(...) -- H:\mHotspot[1].exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{84BA13EA-8E65-4FF1-8536-5F4525AAE49C}" [In-None-P17-TRUE] .(...) -- H:\mHotspot[1].exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "TCP Query User{F6D47A95-7FB8-448C-9155-4DED4D6E43D8}C:\users\moez\appdata\roaming\utorrent\utorrent.exe" [In-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\users\moez\appdata\roaming\utorrent\utorrent.exe =>.BitTorrent Inc®
O87 - FAEL: "UDP Query User{49FE9B4C-2FC7-483F-9FC4-F7307ECBC66D}C:\users\moez\appdata\roaming\utorrent\utorrent.exe" [In-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\users\moez\appdata\roaming\utorrent\utorrent.exe =>.BitTorrent Inc®
O87 - FAEL: "{66C6D9BE-7C82-410A-9EF6-A87A348D1B79}" [In-None-P6-TRUE] .(.Valve Corporation - Steam Client Bootstrapper.) -- E:\Program Files (x86)\Steam\Steam.exe =>.Valve®
O87 - FAEL: "{B91AD09C-AFFE-43A7-9706-03206505A141}" [In-None-P17-TRUE] .(.Valve Corporation - Steam Client Bootstrapper.) -- E:\Program Files (x86)\Steam\Steam.exe =>.Valve®
O87 - FAEL: "{AD87A643-3C17-4FEA-B480-23297B01FA92}" [In-None-P17-TRUE] .(.VMware, Inc. - VMware Authorization Service.) -- E:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe =>.VMware, Inc.®
O87 - FAEL: "{A0632599-3720-4018-9E07-D48C7480159B}" [In-None-P17-TRUE] .(.VMware, Inc. - VMware Authorization Service.) -- E:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe =>.VMware, Inc.®
O87 - FAEL: "{6EE45B4C-69C4-4676-B990-FB139FF89E6F}" [In-None-P6-TRUE] .(.Lenovo - Connect2.) -- C:\Program Files (x86)\Lenovo\Connect2\Connect2.exe =>.LENOVO®
O87 - FAEL: "{2FD9E146-D149-49B2-9D4C-B420117F0278}" [Out-None-P17-TRUE] .(.Lenovo - Connect2.) -- C:\Program Files (x86)\Lenovo\Connect2\Connect2.exe =>.LENOVO®
O87 - FAEL: "{A62B3CCC-A2CE-4D5A-8EF0-B54C842EA1F6}" [In-None-P17-TRUE] .(.Lenovo - Connect2.) -- C:\Program Files (x86)\Lenovo\Connect2\Connect2.exe =>.LENOVO®
O87 - FAEL: "{538C6B2F-0541-4E6B-AC7B-454296B16DF9}" [In-None-P6-TRUE] .(.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation®
O87 - FAEL: "{C401CA18-3D0F-4114-81D3-7A1D7A848FB9}" [In-None-P17-TRUE] .(.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation®
O87 - FAEL: "{A40C81C8-5C60-4D40-B310-E041B7F25758}" [In-None-P6-TRUE] .(.NVIDIA Corporation - NVIDIA Streamer Server Component.) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe =>.NVIDIA Corporation®
O87 - FAEL: "{E7725CD7-7EDB-4723-A4BF-9A75A8F8D838}" [In-None-P17-TRUE] .(.NVIDIA Corporation - NVIDIA Streamer Server Component.) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe =>.NVIDIA Corporation®
O87 - FAEL: "{AAEC6C7D-0C1B-4BE6-BE77-3D151B60C7AF}" [In-None-P6-TRUE] .(.BitTorrent Inc. - BitTorrent.) -- C:\Users\moez\AppData\Roaming\BitTorrent\BitTorrent.exe =>.BitTorrent Inc®
O87 - FAEL: "{3CCC841E-9A9D-4EE6-AFAA-189610EFD977}" [In-None-P17-TRUE] .(.BitTorrent Inc. - BitTorrent.) -- C:\Users\moez\AppData\Roaming\BitTorrent\BitTorrent.exe =>.BitTorrent Inc®
O87 - FAEL: "{3FF20091-A18F-4B95-947C-CFE387DC25DB}" [In-None-P6-TRUE] .(.SHAREit Technologies Co.Ltd - SHAREit.) -- C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.exe =>.SHAREit Technologies Co.Ltd®
O87 - FAEL: "{287A7F8B-2092-4393-9962-A19EE49B4A04}" [In-None-P17-TRUE] .(.SHAREit Technologies Co.Ltd - SHAREit.) -- C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.exe =>.SHAREit Technologies Co.Ltd®
O87 - FAEL: "TCP Query User{B3EC329F-CAE3-40F9-BD8F-3DC851950603}H:\battlefield 4\bf4.exe" [In-None-P6-TRUE] .(...) -- H:\battlefield 4\bf4.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "UDP Query User{2C306E2F-86F8-4C43-AF31-26DC29120C94}H:\battlefield 4\bf4.exe" [In-None-P17-TRUE] .(...) -- H:\battlefield 4\bf4.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "TCP Query User{4AE91D87-2BCA-4538-9534-C0D7CF3D1A16}E:\program files (x86)\nmap\nmap.exe" [In-None-P6-TRUE] .(.Insecure.Org - Nmap.) -- E:\program files (x86)\nmap\nmap.exe =>.Insecure.Org
O87 - FAEL: "UDP Query User{89520BB3-2632-423C-84E3-3BDB6410EDDB}E:\program files (x86)\nmap\nmap.exe" [In-None-P17-TRUE] .(.Insecure.Org - Nmap.) -- E:\program files (x86)\nmap\nmap.exe =>.Insecure.Org
O87 - FAEL: "{7332BCC2-C729-4591-97D3-C5319BFEF709}" [In-None-P6-TRUE] .(.WIBU-SYSTEMS AG - CodeMeter Runtime Server.) -- C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe =>.WIBU-SYSTEMS AG®
O87 - FAEL: "{F0DCE3EA-7E75-44B8-9F41-ED6A8457A37B}" [In-None-P17-TRUE] .(.WIBU-SYSTEMS AG - CodeMeter Runtime Server.) -- C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe =>.WIBU-SYSTEMS AG®
O87 - FAEL: "{9F4F61C1-8867-4B95-A5FA-5AEFC268FFD6}" [In-None-P6-TRUE] .(...) -- E:\Program Files (x86)\Steam\steamapps\common\Teeworlds\tw\teeworlds.exe =>.Steam Games
O87 - FAEL: "{2EC5727A-0E8B-4837-BE14-CE0F9FFA7FC7}" [In-None-P17-TRUE] .(...) -- E:\Program Files (x86)\Steam\steamapps\common\Teeworlds\tw\teeworlds.exe =>.Steam Games
O87 - FAEL: "{7E5185AE-572A-48D2-BB71-7F5936FF1B08}" [In-None-P6-TRUE] .(.Valve Corporation - Steam Client WebHelper.) -- E:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe =>.Valve®
O87 - FAEL: "{63F79ECD-E9E6-4C31-9DCC-912D914EE797}" [In-None-P17-TRUE] .(.Valve Corporation - Steam Client WebHelper.) -- E:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe =>.Valve®
O87 - FAEL: "{B2E8A394-C1C1-4DCD-AD94-B10A3BD0B838}" [In-None-P6-TRUE] .(.SHAREit Technologies Co.Ltd - SHAREit.) -- C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.exe =>.SHAREit Technologies Co.Ltd®
O87 - FAEL: "{196E2F2D-1E3A-4489-9A31-953180527498}" [In-None-P17-TRUE] .(.SHAREit Technologies Co.Ltd - SHAREit.) -- C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.exe =>.SHAREit Technologies Co.Ltd®
O87 - FAEL: "{255B1545-F86E-4B97-A839-8496B2923AFE}" [In-None-P6-TRUE] .(.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation®
O87 - FAEL: "{3FFF4EC5-F70D-4AF1-8184-6C0E658B1C0E}" [In-None-P17-TRUE] .(.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation®
O87 - FAEL: "{72CF8E70-F85D-440A-B8A5-F589799E6E89}" [In-None-P17-TRUE] .(.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe =>.Apple Inc.®
O87 - FAEL: "{E89919D0-8431-47D3-A2AC-177C48C62B87}" [In-None-P6-TRUE] .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.®
O87 - FAEL: "{1DB535CC-04A5-406A-AB64-E42382DCB2B0}" [In-None-P17-TRUE] .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.®
O87 - FAEL: "{A20E7157-16C6-4607-90C2-D8FEA23DD0D6}" [In-None-P6-TRUE] .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe =>.Apple Inc.®
O87 - FAEL: "{51378D45-1497-4012-A51A-436363C02E17}" [In-None-P17-TRUE] .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe =>.Apple Inc.®
O87 - FAEL: "{A1D22628-34FE-4A79-BB24-FA00AC6A5EB9}" [In-None-P17-TRUE] .(.Apple Inc. - iTunes.) -- E:\iTunes\iTunes.exe =>.Apple Inc.®
O87 - FAEL: "{9918C932-25D5-4409-B0DC-A8DB1ABEAD04}" [Out-None-P17-TRUE] .(...) -- C:\Program Files\Easeware\DriverEasy\DriverEasy.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{3478C4E5-84BC-4A30-A10A-73AC849EB411}" [In-None-P17-TRUE] .(.Opera Software - Opera Internet Browser.) -- E:\Program Files (x86)\opera\42.0.2393.137\opera.exe =>.Opera Software AS®
O87 - FAEL: "{4E097C0E-8771-4F8F-BCC1-9C0F7AF18AF3}" [In-None-P17-TRUE] .(.BlueStack Systems, Inc. - BlueStacks Android Host.) -- C:\Program Files (x86)\BlueStacks\HD-Player.exe =>.BlueStack Systems, Inc.®
O87 - FAEL: "{3CC75762-2E05-4BD4-9BFD-4B1B85801420}" [In-None-P17-TRUE] .(.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation®
O87 - FAEL: "{3B33A871-6330-4A1D-990A-230E4530DC94}" [In-None-P17-TRUE] .(.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation®
O87 - FAEL: "{D4B358CA-B889-4A2B-8656-E9583DFDF59F}" [In-None-P6-TRUE] .(.NVIDIA Corporation - NVIDIA Streamer Server Component.) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe =>.NVIDIA Corporation®
O87 - FAEL: "{9407556F-DF86-4D26-841E-728A237E10B6}" [In-None-P17-TRUE] .(.NVIDIA Corporation - NVIDIA Streamer Server Component.) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe =>.NVIDIA Corporation®
O87 - FAEL: "{7AC50EC0-E62C-4076-8F03-5166127F90E5}" [In-None-P17-TRUE] .(.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O87 - FAEL: "{F1855A8A-5D34-40DB-B47E-81F5211CFC86}" [In-None-P17-TRUE] .(.Opera Software - Opera Internet Browser.) -- E:\Program Files (x86)\opera\55.0.2994.44\opera.exe =>.Opera Software AS®
O87 - FAEL: "{6CE68580-DED1-4537-B184-FF21A88597A2}" [In-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\moez\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O87 - FAEL: "{E44D89EE-751E-4D92-9B1A-8C5D4568B85A}" [In-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\moez\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O87 - FAEL: "{CBE9A487-5F3B-439A-AAE2-AE77E32BF7B1}" [In-None-P6-TRUE] .(...) -- C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{1160E698-F4A6-4D22-B40C-7DA769C95D0E}" [In-None-P17-TRUE] .(...) -- C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{007E43B7-489A-4708-9C8C-1FA2136A34A4}" [In-None-P6-TRUE] .(.Tencent - 腾讯游戏云加速下载引擎(旋风Inside).) -- C:\Users\moez\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe =>.SUP.Tencent
O87 - FAEL: "{94FC931C-9622-4CEB-8116-849F9F32001C}" [In-None-P17-TRUE] .(.Tencent - 腾讯游戏云加速下载引擎(旋风Inside).) -- C:\Users\moez\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe =>.SUP.Tencent
O87 - FAEL: "{0412651A-5EB2-4A6B-9752-7D115BE11640}" [In-None-P6-TRUE] .(.Tencent - 腾讯游戏云加速下载引擎(旋风Inside).) -- C:\Users\moez\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe =>.SUP.Tencent
O87 - FAEL: "{6D39D2C7-A46C-4B53-B909-D1A58B0A1ED6}" [In-None-P17-TRUE] .(.Tencent - 腾讯游戏云加速下载引擎(旋风Inside).) -- C:\Users\moez\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe =>.SUP.Tencent
O87 - FAEL: "{47EEAEC0-FE0E-4CAB-979B-57D6F7B51A15}" [In-None-P6-TRUE] .(.Tencent - 腾讯游戏云加速下载引擎(旋风Inside).) -- C:\Users\moez\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe =>.SUP.Tencent
O87 - FAEL: "{020909CE-CE37-462E-BC01-1FB65117E131}" [In-None-P17-TRUE] .(.Tencent - 腾讯游戏云加速下载引擎(旋风Inside).) -- C:\Users\moez\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe =>.SUP.Tencent
O87 - FAEL: "{5271B608-11F7-4B46-BA32-53A0627FE65F}" [In-None-P17-TRUE] .(.Tencent - Tencent Gaming Buddy.) -- e:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe =>.SUP.Tencent
O87 - FAEL: "{0CEB48E8-CBC8-4222-9CB1-2FFD6B36F259}" [In-None-P17-TRUE] .(...) -- e:\Program Files\TxGameAssistant\AppMarket\TInst.exe =>.SUP.Tencent
O87 - FAEL: "{D1EE5BE8-865E-409D-9B3F-0491364CBEA0}" [In-None-P17-TRUE] .(.腾讯公司 - 腾讯手游助手-crash上报.) -- e:\Program Files\TxGameAssistant\AppMarket\bugreport.exe =>.SUP.Tencent
O87 - FAEL: "{D01676EA-E426-408E-9A11-52C733EB50FE}" [In-None-P17-TRUE] .(...) -- e:\Program Files\TxGameAssistant\AppMarket\QQExternal.exe =>.SUP.Tencent
O87 - FAEL: "{4A610F75-9036-4CCA-A94D-84A2855D056F}" [In-None-P17-TRUE] .(.Tencent - Tencent Gaming Buddy - Install.) -- e:\Program Files\TxGameAssistant\AppMarket\GameDownload.exe =>.SUP.Tencent
O87 - FAEL: "{84EB1DD7-CBB5-4D43-BF21-00DA224CE863}" [In-None-P17-TRUE] .(.Tencent - Tencent Gaming Buddy - Update.) -- e:\Program Files\TxGameAssistant\AppMarket\GF186\TUpdate.exe =>.SUP.Tencent
O87 - FAEL: "{F135F577-8CF4-4EB2-A31D-2861C909DD68}" [In-None-P17-TRUE] .(.Tencent - Tencent Gaming Buddy.) -- e:\Program Files\TxGameAssistant\UI\AndroidEmulator.exe =>.SUP.Tencent
O87 - FAEL: "{2AE26F2B-3CCC-4BC5-9A68-AF0EB26470C7}" [In-None-P17-TRUE] .(...) -- e:\Program Files\TxGameAssistant\UI\adb.exe
O87 - FAEL: "{4FD0546C-0A9B-44E8-AC6D-7ED1AB0CFF57}" [In-None-P17-TRUE] .(...) -- e:\Program Files\TxGameAssistant\UI\TInst.exe =>.SUP.Tencent
O87 - FAEL: "{89FCBB09-8A77-4A40-8A4C-6F9C80459092}" [In-None-P17-TRUE] .(.Tencent - Tencent Gaming Buddy - Crash Report.) -- e:\Program Files\TxGameAssistant\UI\bugreport.exe =>.SUP.Tencent
O87 - FAEL: "{B8BF639A-6DB6-4B11-B21A-5E481BEB68EB}" [In-None-P17-TRUE] .(.Tencent - 腾讯手游助手辅助程序.) -- e:\Program Files\TxGameAssistant\UI\TxGaDcc.exe =>.SUP.Tencent
O87 - FAEL: "{EAA7829A-E4C2-44DF-AFB8-1BBD3B0C0DCD}" [In-None-P17-TRUE] .(.Opera Software - Opera Internet Browser.) -- E:\Program Files (x86)\opera\55.0.2994.61\opera.exe =>.Opera Software AS®

---\\ Product Upgrade Codes (126) - 4s
O90 - PUC: "00002109030000000000000000F01FEC" [HKLM] . (.Microsoft Office Enterprise 2007.) =>.Microsoft Corporation
O90 - PUC: "000021091A0010400000000000F01FEC" [HKLM] . (.Microsoft Office OneNote MUI (Arabic) 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109411010400000000000F01FEC" [HKLM] . (.Microsoft Office Groove Setup Metadata MUI (Arabic) 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109440010400000000000F01FEC" [HKLM] . (.Microsoft Office InfoPath MUI (Arabic) 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109510010400000000000F01FEC" [HKLM] . (.Microsoft Office Access MUI (Arabic) 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109610010400000000000F01FEC" [HKLM] . (.Microsoft Office Excel MUI (Arabic) 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109810010400000000000F01FEC" [HKLM] . (.Microsoft Office PowerPoint MUI (Arabic) 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109910010400000000000F01FEC" [HKLM] . (.Microsoft Office Publisher MUI (Arabic) 2007.) =>.bl.org
O90 - PUC: "00002109A10010400000000000F01FEC" [HKLM] . (.Microsoft Office Outlook MUI (Arabic) 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109A20000000100000000F01FEC" [HKLM] . (.Microsoft Office Office 64-bit Components 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109A20010400100000000F01FEC" [HKLM] . (.Microsoft Office Shared 64-bit MUI (Arabic) 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109A20090400100000000F01FEC" [HKLM] . (.Microsoft Office Shared 64-bit MUI (English) 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109AB0090400000000000F01FEC" [HKLM] . (.Microsoft Office Groove MUI (English) 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109B10010400000000000F01FEC" [HKLM] . (.Microsoft Office Word MUI (Arabic) 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109C20010400000000000F01FEC" [HKLM] . (.Microsoft Office Proofing (Arabic) 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109E60010400000000000F01FEC" [HKLM] . (.Microsoft Office Shared MUI (Arabic) 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109E60090400000000000F01FEC" [HKLM] . (.Microsoft Office Shared MUI (English) 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109F10010400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (Arabic) 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109F10090400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (English) 2007.) =>.Microsoft Corporation
O90 - PUC: "00002109F100C0400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (French) 2007.) =>.Microsoft Corporation
O90 - PUC: "00005109090010400100000000F01FEC" [HKLM] . (.Microsoft DCF MUI (Arabic) 2013.) =>.Microsoft Corporation
O90 - PUC: "000051091A0010400100000000F01FEC" [HKLM] . (.Microsoft OneNote MUI (Arabic) 2013.) =>.Microsoft Corporation
O90 - PUC: "000051091C0000000100000000F01FEC" [HKLM] . (.Microsoft Office 32-bit Components 2013.) =>.Microsoft Corporation
O90 - PUC: "000051091C0010400100000000F01FEC" [HKLM] . (.Microsoft Office Shared 32-bit MUI (Arabic) 2013.) =>.Microsoft Corporation
O90 - PUC: "000051091E0010400100000000F01FEC" [HKLM] . (.Microsoft Office OSM MUI (Arabic) 2013.) =>.Microsoft Corporation
O90 - PUC: "000051092E0010400100000000F01FEC" [HKLM] . (.Microsoft Office OSM UX MUI (Arabic) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109440010400100000000F01FEC" [HKLM] . (.Microsoft InfoPath MUI (Arabic) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109510010400100000000F01FEC" [HKLM] . (.Microsoft Access MUI (Arabic) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109610010400100000000F01FEC" [HKLM] . (.Microsoft Excel MUI (Arabic) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109810010400100000000F01FEC" [HKLM] . (.Microsoft PowerPoint MUI (Arabic) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109910010400100000000F01FEC" [HKLM] . (.Microsoft Publisher MUI (Arabic) 2013.) =>.bl.org
O90 - PUC: "00005109A10010400100000000F01FEC" [HKLM] . (.Microsoft Outlook MUI (Arabic) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109AB0010400100000000F01FEC" [HKLM] . (.Microsoft Groove MUI (Arabic) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109B10010400100000000F01FEC" [HKLM] . (.Microsoft Word MUI (Arabic) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109B21010400100000000F01FEC" [HKLM] . (.Microsoft Lync MUI (Arabic) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109C20010400100000000F01FEC" [HKLM] . (.Microsoft Office Proofing (Arabic) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109E60010400100000000F01FEC" [HKLM] . (.Microsoft Office Shared MUI (Arabic) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109F10010400100000000F01FEC" [HKLM] . (.Microsoft Office Proofing Tools 2013 - اللغة العربية.) -- C:\Windows\Installer\{90150000-001F-0401-1000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "00005109F10090400100000000F01FEC" [HKLM] . (.Microsoft Office Proofing Tools 2013 - English.) -- C:\Windows\Installer\{90150000-001F-0409-1000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "00005109F100C0400100000000F01FEC" [HKLM] . (.Outils de vérification linguistique 2013 de Microsoft Office - Français.) -- C:\Windows\Installer\{90150000-001F-040C-1000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "00005119110000000100000000F01FEC" [HKLM] . (.Microsoft Office Professional Plus 2013.) =>.Microsoft Corporation
O90 - PUC: "0076C0A639AEC2738817CDFC311D064A" [HKLM] . (.Microsoft .NET Framework 4.5.1 Multi-Targeting Pack.) =>.Microsoft Corporation
O90 - PUC: "01690987922DC9549A63529D22383DDF" [HKLM] . (.Microsoft SQL Server Compact 4.0 SP1 x64 ENU.) -- C:\Windows\Installer\{78909610-D229-459C-A936-25D92283D3FD}\ProductIcon =>.Microsoft Corporation
O90 - PUC: "0474EFA4086CEF046B0BC051BE10671F" [HKLM] . (.ZeroTier One Virtual Network Port.) -- C:\Windows\Installer\{4AFE4740-C680-40FE-B6B0-0C15EB0176F1}\ZeroTierIcon.exe =>.Hewlett-Packard
O90 - PUC: "085607ED7C28A1B4BA4AAE84CA510B54" [HKLM] . (.Google Earth Pro.) -- C:\Windows\Installer\{DE706580-82C7-4B1A-ABA4-EA48AC15B045}\MainIcon.ico =>.Google Inc.
O90 - PUC: "0F269E650BF476C388BDE9AAE6FE4C39" [HKLM] . (.Microsoft .NET Framework 4.5 Multi-Targeting Pack.) =>.Microsoft Corporation
O90 - PUC: "10005159361190400100000000F01FEC" [HKLM] . (.SharePoint Client Components.)
O90 - PUC: "1007C6B46D7C017319E3B52CF3EC196E" [HKLM] . (.Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148.) =>.bl.org
O90 - PUC: "10955B73A5990563081BBBDF40E79211" [HKLM] . (.Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24212.) =>.Microsoft Corporation
O90 - PUC: "153AA053AF120723B8A73845437E66DA" [HKLM] . (.Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022.) =>.bl.org
O90 - PUC: "1926E8D15D0BCE53481466615F760A7F" [HKLM] . (.Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219.) =>.bl.org
O90 - PUC: "19A620C6F04632A4B886505D98CCF681" [HKLM] . (.Microsoft SQL Server 2012 Express LocalDB .) -- C:\Windows\Installer\{6C026A91-640F-4A23-8B68-05D589CC6F18}\ARPIco =>.Microsoft Corporation
O90 - PUC: "1af2a8da7e60d0b429d7e6453b3d0182" [HKLM] . (.Microsoft Visual C++ 2005 Redistributable (x64).) =>.bl.org
O90 - PUC: "1D5E3C0FEDA1E123187686FED06E995A" [HKLM] . (.Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219.) =>.bl.org
O90 - PUC: "21EE4A31AE32173319EEFE3BD6FDFFE3" [HKLM] . (.Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005.) =>.Microsoft Corporation
O90 - PUC: "22BEFC8F7E2A1793E9ADB411DEFE1C58" [HKLM] . (.Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005.) =>.Microsoft Corporation
O90 - PUC: "23F2DF9BDE6BA774893A8370021F5B35" [HKLM] . (.Intel(R) Product Improvement Program.) =>.Intel Corporation
O90 - PUC: "26C7153D5A86FC73297F390C928A6918" [HKLM] . (.Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU).) =>.Microsoft Corporation
O90 - PUC: "2FCF0228F75A6324FBCC6C2C62E858E1" [HKLM] . (.RtkClassFilter.) -- C:\Windows\Installer\{8220FCF2-A57F-4236-BFCC-C6C2268E851E}\ARPPRODUCTICON.exe
O90 - PUC: "32E61AE32D41A66428867DDC04CD646B" [HKLM] . (.Open XML SDK 2.5 for Microsoft Office.) =>.Microsoft Corporation
O90 - PUC: "33CA00CB00B2D344F82C63659DA4AEA0" [HKLM] . (.VMware Player.) =>.VMware
O90 - PUC: "33CB2A05DC9C1FB38AFF351CA0B081C3" [HKLM] . (.Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.24215.) =>.Microsoft Corporation
O90 - PUC: "3e43b73803c7c394f8a6b2f0402e19c2" [HKLM] . (.Microsoft Visual C++ 2005 Redistributable.) =>.bl.org
O90 - PUC: "41075EA44C5046841AD36815A7E7B14A" [HKLM] . (.Microsoft .NET Framework 4.5 SDK.) =>.Microsoft Corporation
O90 - PUC: "47BCE44836B9C5D359C803DB321FE94E" [HKLM] . (.Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24212.) =>.Microsoft Corporation
O90 - PUC: "4D3BBF1E0BDA94941B1058D50A167C53" [HKLM] . (.Microsoft Silverlight 5 SDK.) -- C:\Windows\Installer\{E1FBB3D4-ADB0-4949-B101-855DA061C735}\ARPICON =>.Microsoft Corporation
O90 - PUC: "4EA42A62D9304AC4784BF2468110170F" [HKLM] . (.Java 8 Update 171 (64-bit).) -- C:\Program Files\Java\jre1.8.0_171\\bin\javaws.exe =>.Sun Microsystems
O90 - PUC: "4F316817D2942724CA3C0DA4E80F8F38" [HKLM] . (.Kaspersky Free.) -- C:\Windows\Installer\{718613F4-492D-4272-ACC3-D04A8EF0F883}\arp.ico =>.Kaspersky Labs
O90 - PUC: "4FA7DD403D6A03E4B99BB36307172943" [HKLM] . (.Microsoft SQL Server 2012 T-SQL Language Service .) -- C:\Windows\Installer\{04DD7AF4-A6D3-4E30-9BB9-3B3670719234}\ARPIco =>.Microsoft Corporation
O90 - PUC: "568DEF8531F4D8045AFB9906914C9B63" [HKLM] . (.Microsoft SQL Server 2012 Command Line Utilities .) -- C:\Windows\Installer\{58FED865-4F13-408D-A5BF-996019C4B936}\ARPIco =>.Microsoft Corporation
O90 - PUC: "5739859185C5AFA448F2B84347C4ECDA" [HKLM] . (.Apple Software Update.) -- C:\Windows\Installer\{19589375-5C58-4AFA-842F-8B34744CCEAD}\Installer.ico =>.Apple Inc.
O90 - PUC: "5816D922E7DBB4947AB35C12B50E96E0" [HKLM] . (.HPLJUT.) =>.Hewlett-Packard
O90 - PUC: "5AC017B20F9992D469C2927AFC7F9A98" [HKLM] . (.Intel(R) Driver Update Utility 2.6.) -- C:\Windows\Installer\{2B710CA5-99F0-4D29-962C-29A7CFF7A989}\ProductIcon =>.Intel Corporation
O90 - PUC: "5BB3ACE00144B4142B6242F11F1CC20D" [HKLM] . (.دعم تطبيقات Apple‏ (64 بت).) -- C:\Windows\Installer\{0ECA3BB5-4410-414B-B226-241FF1C12CD0}\WinInstall.ico =>.Apple Inc.
O90 - PUC: "5D136A49A03B8DD36BC511710CD97AE3" [HKLM] . (.Microsoft .NET Framework 4.6.) =>.Microsoft Corporation
O90 - PUC: "613C5A3412593C949B6BCF5E1E00D50F" [HKLM] . (.Microsoft SQL Server 2012 Management Objects (x64).) -- C:\Windows\Installer\{43A5C316-9521-49C3-B9B6-FCE5E1005DF0}\ARPIco =>.Microsoft Corporation
O90 - PUC: "62DBF9290209B993A9A757D1160F9B24" [HKLM] . (.Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005.) =>.Microsoft Corporation
O90 - PUC: "67D6ECF5CD5FBA732B8B22BAC8DE1B4D" [HKLM] . (.Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161.) =>.bl.org
O90 - PUC: "68AB67CA408033019195008142726264" [HKLM] . (.Adobe Refresh Manager.) -- C:\Windows\Installer\{AC76BA86-0804-1033-1959-001824272646}\ARPPRODUCTICON.exe =>.Western Digital Technologies
O90 - PUC: "68AB67CA7DA73301B744CAF070E41400" [HKLM] . (.Adobe Acrobat Reader DC.) -- C:\Windows\Installer\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\SC_Reader.ico =>.Adobe Inc.
O90 - PUC: "694678B12A3B22D4B9216B803ADFB4B8" [HKLM] . (.Microsoft SQL Server 2012 Data-Tier App Framework .) -- C:\Windows\Installer\{1B876496-B3A2-4D22-9B12-B608A3FD4B8B}\ARPIco =>.Microsoft Corporation
O90 - PUC: "6D9D1C530C783A641B4BDECB0C3622C1" [HKLM] . (.Prerequisites for SSDT .) -- C:\Windows\Installer\{35C1D9D6-87C0-46A3-B1B4-EDBCC063221C}\ARPIco =>.Legitimate
O90 - PUC: "6E815EB96CCE9A53884E7857C57002F0" [HKLM] . (.Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161.) =>.bl.org
O90 - PUC: "6E8D947A316B3EB3F8F540C548BE2AB9" [HKLM] . (.Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005.) =>.Microsoft Corporation
O90 - PUC: "6EBBD7F2CBE8C5940914647A274F3E11" [HKLM] . (.Microsoft SQL Server 2012 Management Objects .) -- C:\Windows\Installer\{2F7DBBE6-8EBC-495C-9041-46A772F4E311}\ARPIco =>.Microsoft Corporation
O90 - PUC: "6F79774B82C423F338CD724833C54A78" [HKLM] . (.Microsoft Visual Studio 2010 Tools for Office Runtime (x64).) =>.Microsoft Corporation
O90 - PUC: "7170C33F40E85BE4098C74222178BDF4" [HKLM] . (.Kaspersky Secure Connection.) -- C:\Windows\Installer\{F33C0717-8E04-4EB5-90C8-47221287DB4F}\arp.ico =>.Kaspersky Labs
O90 - PUC: "750FB13FE5D0E584DADF6530412A9721" [HKLM] . (.hppcp1025LaserJetService.) =>.Hewlett-Packard
O90 - PUC: "7C9F8B73BF303523781852719CD9C700" [HKLM] . (.Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030.) =>.Microsoft Corporation
O90 - PUC: "816F9789BB97425428F3816A3C246F2A" [HKLM] . (.iTunes.) -- C:\Windows\Installer\{9879F618-79BB-4524-823F-18A6C342F6A2}\Installer.ico =>.Apple Inc.
O90 - PUC: "880F476309B9A374AA3C020AD0D818C0" [HKLM] . (.Microsoft Web Deploy 3.5.) -- C:\Windows\Installer\{3674F088-9B90-473A-AAC3-20A00D8D810C}\MSDeployIcon.exe =>.Microsoft Corporation
O90 - PUC: "89EA3905015DBEB4AB1CF78CCE3EB589" [HKLM] . (.hppLaserJetService.) =>.Hewlett-Packard
O90 - PUC: "8A6DD8D57D4C4554399F1FCC827C6200" [HKLM] . (.WCF RIA Services V1.0 SP2.) -- C:\Windows\Installer\{5D8DD6A8-C4D7-4554-93F9-F1CC28C72600}\icon.ico =>.Microsoft Corporation
O90 - PUC: "8A84FEFC8BFBCAE3B85AEDF4A82A76EC" [HKLM] . (.Microsoft .NET Framework 4 Multi-Targeting Pack.) =>.Microsoft Corporation
O90 - PUC: "8BFDDD6597F70844985D521E5FA22BF8" [HKLM] . (.Bonjour.) -- C:\Windows\Installer\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}\Bonjour.ico =>.Microsoft Corporation
O90 - PUC: "9028FF501F4C77C4CB8297613551D602" [HKLM] . (.Microsoft System CLR Types for SQL Server 2012 (x64).) -- C:\Windows\Installer\{05FF8209-C4F1-4C77-BC28-791653156D20}\ARPIco =>.Microsoft Corporation
O90 - PUC: "9A6CE1FEED719AD30B0486A6E1A8B840" [HKLM] . (.Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.24215.) =>.Microsoft Corporation
O90 - PUC: "9AF16FB7BFDB365489DACF0BAD82CC7C" [HKLM] . (.IIS 8.0 Express.) -- C:\Windows\Installer\{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}\Icon_IisExpress =>.Legitimate
O90 - PUC: "9C9E114D26ECFBD4D929C42BB257E05D" [HKLM] . (.Microsoft SQL Server 2012 Native Client .) -- C:\Windows\Installer\{D411E9C9-CE62-4DBF-9D92-4CB22B750ED5}\ARPIco =>.Microsoft Corporation
O90 - PUC: "9eab5ec6ac3d99b498a1d16c1c815acf" [HKLM] . (.Microsoft Visual C++ 2005 Redistributable (x64).) =>.bl.org
O90 - PUC: "A089CE062ADB6BC44A720BA745894BAC" [HKLM] . (.Google Update Helper.) =>.Google Inc.
O90 - PUC: "A68FEA80659164849B600B31059EE603" [HKLM] . (.Entity Framework Tools for Visual Studio 2013.) -- C:\Windows\Installer\{08AEF86A-1956-4846-B906-B01350E96E30}\setup.ico =>.Microsoft Corporation
O90 - PUC: "B1405C4519E029E44871AA1A42397C09" [HKLM] . (.Microsoft SQL Server 2012 Transact-SQL ScriptDom .) -- C:\Windows\Installer\{54C5041B-0E91-4E92-8417-AAA12493C790}\ARPIco =>.Microsoft Corporation
O90 - PUC: "B928F3451954F2B4FA36E6E6A65EE92B" [HKLM] . (.دعم تطبيقات Apple‏ (32 بت).) -- C:\Windows\Installer\{543F829B-4591-4B2F-AF63-6E6E6AE59EB2}\WinInstall.ico =>.Apple Inc.
O90 - PUC: "B9FF1876D78E30A439375AA582B838AF" [HKLM] . (.Microsoft SQL Server Data Tools Build Utilities - enu (12.0.30919.1).) -- C:\Windows\Installer\{6781FF9B-E87D-4A03-9373-A55A288B83FA}\setup.ico =>.Microsoft Corporation
O90 - PUC: "BFBCF7D0874F23D409C1380FFBA55310" [HKLM] . (.Microsoft SQL Server Data Tools - enu (12.0.30919.1).) -- C:\Windows\Installer\{0D7FCBFB-F478-4D32-901C-83F0BF5A3501}\setup.ico =>.Microsoft Corporation
O90 - PUC: "C025571B2A687A53689168CD7369889B" [HKLM] . (.Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030.) =>.Microsoft Corporation
O90 - PUC: "c1c4f01781cc94c4c8fb1542c0981a2a" [HKLM] . (.Microsoft Visual C++ 2005 Redistributable.) =>.bl.org
O90 - PUC: "C3AEB2FCAE628F23AAB933F1E743AB79" [HKLM] . (.Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030.) =>.Microsoft Corporation
O90 - PUC: "C5C7342DC8D22D04089586A97D32F93A" [HKLM] . (.Intel(R) C++ Redistributables for Windows* on Intel(R) 64.) -- C:\Windows\Installer\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}\ARPPRODUCTICON.exe =>.bl.org
O90 - PUC: "CA83C070EC50FD34A9024131236FBAB2" [HKLM] . (.Microsoft System CLR Types for SQL Server 2012.) -- C:\Windows\Installer\{070C38AC-05CE-43DF-9A20-141332F6AB2B}\ARPIco =>.Microsoft Corporation
O90 - PUC: "CBFB8930B199572349362DFB193B8CB0" [HKLM] . (.Microsoft Help Viewer 2.1.) =>.Microsoft Corporation
O90 - PUC: "CFD2C1F142D260E3CB8B271543DA9F98" [HKLM] . (.Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148.) =>.bl.org
O90 - PUC: "D6295A911E66CF6458D461A31AA0253D" [HKLM] . (.Microsoft .NET Framework 4.5.1 SDK.) =>.Microsoft Corporation
O90 - PUC: "D7314F9862C648A4DB8BE2A5B47BE100" [HKLM] . (.Microsoft Silverlight.) -- c:\Windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ARPIcon =>.Microsoft Corporation
O90 - PUC: "D81EABF14ED4AA7438CE1D0B642F26CD" [HKLM] . (.PDF Settings CC.) =>.Adobe Inc.
O90 - PUC: "DC8A59DBF9D1DA5389A1E3975220E6BB" [HKLM] . (.Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030.) =>.Microsoft Corporation
O90 - PUC: "E342AB6A3A5853642A962349C989CAF7" [HKLM] . (.Microsoft SQL Server 2012 Data-Tier App Framework (x64).) -- C:\Windows\Installer\{A6BA243E-85A3-4635-A269-32949C98AC7F}\ARPIco =>.Microsoft Corporation
O90 - PUC: "EDED107488810E94AB5E58875729C42A" [HKLM] . (.Microsoft SQL Server System CLR Types (x64).) -- C:\Windows\Installer\{4701DEDE-1888-49E0-BAE5-857875924CA2}\ARPIco =>.Microsoft Corporation
O90 - PUC: "F60730A4A66673047777F5728467D401" [HKLM] . (.Java Auto Updater.) =>.Sun Microsystems
O90 - PUC: "F8385C66458B55A4986E6A3178744AFD" [HKLM] . (.Epic Games Launcher Prerequisites (x64).) -- C:\Windows\Installer\{66C5838F-B854-4A55-89E6-A6138747A4DF}\UnrealEngineLauncher.ico =>.Legitimate
O90 - PUC: "FB1DF74A518A67A4EB56351AB55D2DD5" [HKLM] . (.Microsoft SQL Server System CLR Types.) -- C:\Windows\Installer\{A47FD1BF-A815-4A76-BE65-53A15BD5D25D}\ARPIco =>.Microsoft Corporation
O90 - PUC: "FB42F99F09B0E3646985F32DFE3C9C29" [HKLM] . (.Microsoft Identity Extensions.) =>.Microsoft Corporation
O90 - PUC: "FD2E9EE67DC225946A9459ED8A96B78D" [HKLM] . (.Microsoft Exchange Web Services Managed API 2.0.) =>.Microsoft Corporation
O90 - PUC: "34286B10035D0B24794DBDD4FD32E6F2" [HKCU] . (.Viber.) =>.Viber
O90 - PUC: "34286B10035D0B24794DBDD4FD32E6F2" [HKU] . (.Viber.) =>.Viber

---\\ Windows Installer Scan (48) - 90s
[MD5.F22749073181C2CA6DA1E3A6AE556F0C] [WIS][2016/11/18 18:08:50] (.Viber Media Inc. - Viber.) -- C:\Windows\Installer\160777e.msi [70418432] =>.Viber Media Inc.
[MD5.219403B58E38F759271E97217239E615] [WIS][2018/07/11 00:01:24] (.Adobe Systems Incorporated - Adobe ARM Installer.) -- C:\Windows\Installer\23f75157.msi [885760] =>.Adobe Systems Incorporated
[MD5.FC813183B6A793DAB4E530F22FA2F824] [WIS][2016/08/01 18:23:17] (.Intel Corporation.) -- C:\Windows\Installer\242e83.msi [20413440] =>.Intel Corporation
[MD5.1B8A9BD44F0644E3B2708EDCC788D67F] [WIS][2017/05/29 07:31:08] (.ZeroTier - ZeroTier One Virtual Network Port.) -- C:\Windows\Installer\2980e8a.msi [1453568] =>.ZeroTier
[MD5.140B06D8F9F4B596BAB1F7A33AEA6F8E] [WIS][2017/05/19 06:04:24] (.Google - Google Earth Pro.) -- C:\Windows\Installer\2e6f31b.msi [31604736] =>.Google
[MD5.EE3B22D566B9A5797ACDA0F03899BFB6] [WIS][2016/10/23 23:18:14] (.VMware, Inc. - VMware Player.) -- C:\Windows\Installer\34b245.msi [67395584] =>.VMware, Inc.
[MD5.D669362819016F48135A32E282082630] [WIS][2016/06/15 17:34:22] (.Intel - Intel(R) Product Improvement Program.) -- C:\Windows\Installer\3969a3.msi [1060864] =>.Intel
[MD5.0393EEB610186B606787BF8743E12E62] [WIS][2016/06/15 17:34:40] (.Intel - Intel(R) Driver Update Utility 2.6.) -- C:\Windows\Installer\3969ab.msi [5017600] =>.Intel
[MD5.86E2B390629665FBC20E06DFBF01A48F] [WIS][2017/11/06 17:02:18] (.Apple Inc. - [ProductName] Installer.) -- C:\Windows\Installer\4dbc3a.msi [2732032] =>.Apple Inc.
[MD5.24E1B96B703E125A98774CCB8A1ED785] [WIS][2018/01/04 04:29:24] (.Apple Inc. - Apple Software Update Installer.) -- C:\Windows\Installer\4dbc4c.msi [3608576] =>.Apple Inc.
[MD5.770232DBED4BD0E47A2AAD43EA5B6991] [WIS][2018/01/22 14:42:06] (.Apple Inc. - iTunes Installer.) -- C:\Windows\Installer\4dbc54.msi [162029568] =>.Apple Inc.
[MD5.56733A7CCD955F7BCD161521C6F03B93] [WIS][2018/04/27 20:53:41] (.Apple Inc. - Apple Application Support Installer.) -- C:\Windows\Installer\50cff39.msi [48005120] =>.Apple Inc.
[MD5.FB261C151ECD4FCF50CC16EC15680514] [WIS][2018/04/27 20:55:34] (.Apple Inc. - Apple Application Support Installer.) -- C:\Windows\Installer\50d03c2.msi [53149696] =>.Apple Inc.
[MD5.AA00FE52DD17C28976E7300370ABE0F3] [WIS][2017/10/27 13:11:02] (.Kaspersky Lab - Kaspersky Secure Connection.) -- C:\Windows\Installer\541721.msi [9453568] =>.Kaspersky Lab
[MD5.AA30A40A096DC2D468E42BCE6893F4A3] [WIS][2017/05/22 17:42:01] (.LogMeIn, Inc. - LogMeIn Hamachi Installer.) -- C:\Windows\Installer\54477c.msi [10412032] =>.LogMeIn, Inc.
[MD5.D4905DB6A1B45FC6AFBDE5D6A1A9396F] [WIS][2012/12/25 10:50:47] (..) -- C:\Windows\Installer\5a659.msi [508416]
[MD5.F2005417A29475E6E143C2941576850D] [WIS][2012/12/25 10:45:55] (.
- .) -- C:\Windows\Installer\5a661.msi [1192448]
[MD5.93317FF2B58B296E69FB7547A3DCB2C7] [WIS][2014/09/03 18:32:14] (.HP - HPLJUT.) -- C:\Windows\Installer\5a669.msi [747520] =>.HP
[MD5.536A7A1F384F85DE40D8B6E00107598E] [WIS][2018/04/21 18:54:39] (.Oracle Corporation - Java SE Runtime Environment 8 Update 171.) -- C:\Windows\Installer\636a818.msi [39620608] =>.Oracle Corporation
[MD5.EFAFE089C4933ED9F788AD68EEA4FE57] [WIS][2018/04/21 18:54:39] (.Oracle Corporation - Java Auto Updater.) -- C:\Windows\Installer\636a829.msi [761856] =>.Oracle Corporation
[MD5.2D79399C9FEA8C45A9601569E9CDA139] [WIS][2013/06/20 01:12:14] (.Adobe Systems Incorporated - PDF Settings CC.) -- C:\Windows\Installer\9e9c9.msi [2259968] =>.Adobe Systems Incorporated
[MD5.7873ACD3BFA53B19469E6AB5606C80FE] [WIS][2015/11/19 10:56:58] (.Epic Games, Inc. - Epic Games Launcher Prerequisites (x64).) -- C:\Windows\Installer\a9fb914.msi [11919360] =>.Epic Games, Inc.
[MD5.115B3950FE49E504A8B2E9AD159A44B5] [WIS][2012/01/04 17:51:44] (.REALTEK Semiconductor Corp - RtkClassFilter.) -- C:\Windows\Installer\ccd0219.msi [328704] =>.REALTEK Semiconductor Corp
[MD5.781B44266AEBD9CEBC5FED39833583B0] [WIS][2018/08/31 01:33:27] (.Kaspersky Lab - Kaspersky Free.) -- C:\Windows\Installer\cf791c0.msi [13516894] =>.Kaspersky Lab
[MD5.50EA7A4D9481B12A97070942F474D918] [WIS][2018/05/17 17:37:35] (.Google Inc. - Google Update Helper.) -- C:\Windows\Installer\df978ca.msi [40960] =>.Google Inc.
[MD5.23B97F4BEDD554D3F629B60637AFC936] [WIS][2015/03/17 10:42:22] (.Adobe Systems Incorporated.) -- C:\Windows\Installer\faa4f.msi [2792960] =>.Adobe Systems Incorporated
[MD5.E05CA6506E1D5ECE25152018D3FF00CE] [WIS][2018/05/12 08:05:37] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\1087b4.msp [7094272] =>.Adobe Systems, Incorporated
[MD5.F767152C881F505C5BBAC71A825C1263] [WIS][2017/02/21 14:33:51] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\137202c.msp [12845056] =>.Adobe Systems, Incorporated
[MD5.D2F26242D1B928EDD86912216CB6267E] [WIS][2018/09/01 01:01:19] (.Kaspersky Lab.) -- C:\Windows\Installer\16d8c9.msp [17960960] =>.Kaspersky Lab
[MD5.77AB51250501ADDD4D491DECDB6121FD] [WIS][2017/08/28 18:40:46] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\1769944d.msp [2424832] =>.Adobe Systems, Incorporated
[MD5.4D64DE5B41C39FA6192C22CBCD826FBA] [WIS][2016/10/10 09:29:03] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\17a862.msp [36499456] =>.SUP.Obsolete.Adobe
[MD5.2BF0093E60C2D00175DD9F550D900CB7] [WIS][2017/08/07 10:20:05] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\18d78ed.msp [70610944] =>.Adobe Systems, Incorporated
[MD5.2F159BBD3479AEB0C168488067503723] [WIS][2018/07/09 07:47:48] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\23f751ca.msp [27000832] =>.Adobe Systems, Incorporated
[MD5.3617A09ABC822D955214EBE86A991CF3] [WIS][2017/11/29 12:42:28] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\2742f02.msp [1355776] =>.Adobe Systems, Incorporated
[MD5.82F476D2A7125BB7EBF5A2A657BAB293] [WIS][2017/11/13 06:26:16] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\279fa0f.msp [23506944] =>.Adobe Systems, Incorporated
[MD5.0762EDB0E4C8D62A4328C3360BC7AD2C] [WIS][2017/07/11 06:57:12] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\2ae3dc78.msp [1732608] =>.Adobe Systems, Incorporated
[MD5.BCC43969BE02109C8AC7141C7C3CB9CA] [WIS][2017/08/11 12:04:59] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\3ce5c61.msp [2031616] =>.Adobe Systems, Incorporated
[MD5.D65FA317AC2DF76CBE3F765A60BD8809] [WIS][2018/08/13 08:19:45] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\4b20073.msp [1441792] =>.Adobe Systems, Incorporated
[MD5.A58EAEAA86B7D4FA1891CA2EEDDCA3DD] [WIS][2018/02/12 16:26:08] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\557acc8.msp [103362560] =>.Adobe Systems, Incorporated
[MD5.CECF2A7991F74C858965EA972A43CE3F] [WIS][2017/04/10 07:34:32] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\7adb794.msp [57815040] =>.Adobe Systems, Incorporated
[MD5.834919D74149700138C36FB0483F2753] [WIS][2017/12/15 01:10:13] (.Kaspersky Lab.) -- C:\Windows\Installer\7afb098.msp [65536] =>.Kaspersky Lab
[MD5.AC022AC4D63280214DF73D68EFEE1970] [WIS][2018/07/24 14:46:35] (.Kaspersky Lab.) -- C:\Windows\Installer\b064edb.msp [17661952] =>.Kaspersky Lab
[MD5.339631DF934AFC2BE35E2B27A6F7DB06] [WIS][2016/11/03 09:25:06] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\b8df2.msp [1642496] =>.SUP.Obsolete.Adobe
[MD5.A9095FC652E0273E10F1D9481C59067D] [WIS][2018/02/23 15:25:19] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\c69e4.msp [1343488] =>.Adobe Systems, Incorporated
[MD5.72C91237F7C7A0527FA5F0752CF81A66] [WIS][2017/01/19 12:28:55] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\cbd835.msp [1937408] =>.Adobe Systems, Incorporated
[MD5.E3869EFD0836C950E46B02D3CBC67184] [WIS][2017/01/09 05:41:00] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\d01033.msp [25853952] =>.Adobe Systems, Incorporated
[MD5.6162B337E0F3CE536F240ABC3595B585] [WIS][2016/06/30 15:28:39] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\faa50.msp [71077888] =>.SUP.Obsolete.Adobe
[MD5.F9FD1AB516C661D9938213AA661350B7] [WIS][2016/08/02 13:49:06] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\faa67.msp [1511424] =>.SUP.Obsolete.Adobe

---\\ FEATURE CONTROLE. (872) - 1s
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL]:WindowsAnytimeUpgradeUI.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:msoia.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:INFOPATH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:ACCICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSACCESS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:AppSharingHookController64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:infopath.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:HPSFViewer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:HPCF.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_ISO_2022_JP_SNIFFING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPfewgsrv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGuiIT.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGUI.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLgPad.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLOGON.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:Scale_for_R3.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:ieuser.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK]:YahooMusicEngine.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:devenv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:dexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:helppane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS]:msfeedssync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GPU_RENDERING]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HIGH_CONTRAST_BACKGROUND_IMAGES]:sidebar.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:msoia.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:INFOPATH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:ACCICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSACCESS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:AppSharingHookController64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PROLOG]:msiexec.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:wm.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:cs.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:waol.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPARAMS]:helppane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS]:wlmail.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:msoia.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:INFOPATH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:ACCICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSACCESS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:AppSharingHookController64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:msoia.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:INFOPATH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:ACCICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSACCESS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:AppSharingHookController64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:msoia.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:INFOPATH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:ACCICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSACCESS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:AppSharingHookController64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:outlook.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:sidebar.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_NINPUT_LEGACYMODE]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:msoia.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:INFOPATH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:ACCICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSACCESS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:AppSharingHookController64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:msoia.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:INFOPATH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:ACCICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSACCESS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:AppSharingHookController64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING]:communicator.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:msoia.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:INFOPATH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:ACCICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSACCESS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:AppSharingHookController64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msimn.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:winmail.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msoia.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:INFOPATH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:ACCICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSACCESS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:AppSharingHookController64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:msoia.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:INFOPATH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:ACCICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSACCESS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:AppSharingHookController64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:msoia.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:INFOPATH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:ACCICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSACCESS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:AppSharingHookController64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:winmail.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:msimn.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:outlook.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:msoia.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:INFOPATH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:ACCICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSACCESS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:AppSharingHookController64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:infopath.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:winword.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:excel.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:powerpnt.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:msoia.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:INFOPATH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:ACCICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSACCESS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:AppSharingHookController64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:IEContentService.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD]:msn.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:msoia.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:INFOPATH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:ACCICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSACCESS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:AppSharingHookController64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:msoia.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:INFOPATH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:ACCICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSACCESS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:AppSharingHookController64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:ONENOTE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:ehExtHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OSPPREARM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:LICLUA.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:VSTOInstaller.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:msotd.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:msoev.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:msoia.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SELFCERT.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SETLANG.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:GRAPH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSQRY32.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:INFOPATH.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:ACCICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSACCESS.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:GROOVE.EXE =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:AppSharingHookController64.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:UcMapi.exe =>.Legitimate

---\\ Additional Scan (O88) (64) - 27s
C:\Program Files (x86)\DriverPack Notifier =>.SUP.DriverPack
C:\Program Files (x86)\Nitro PDF =>.SUP.Empty
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tencent Software =>.SUP.Tencent
C:\ProgramData\Tencent =>.SUP.Tencent
C:\Users\moez\AppData\Roaming\DriverPack Notifier =>.SUP.DriverPack
C:\Users\moez\AppData\Roaming\DRPNano =>.SUP.DriverPack
C:\Users\moez\AppData\Roaming\DRPNPS =>.SUP.DriverPack
C:\Users\moez\AppData\Roaming\DRPSu =>.SUP.DriverPack
C:\Users\moez\AppData\Roaming\Tencent =>.SUP.Tencent
C:\Users\moez\AppData\Local\DriverToolkit =>.SUP.DriverToolkit
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32 =>.SUP.Orphan
HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} =>.SUP.Orphan
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\XXX Groove GFS Context Menu Handler XXX =>.SUP.Orphan
HKLM\Software\Classes\CLSID\{6C467336-8281-4E60-8204-430CED96822D} =>.SUP.Orphan
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\XXX Groove GFS Context Menu Handler XXX =>.SUP.Orphan
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\XXX Groove GFS Context Menu Handler XXX =>.SUP.Orphan
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\XXX Groove GFS Context Menu Handler XXX =>.SUP.Orphan
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32 =>.SUP.Orphan
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\XXX Groove GFS Context Menu Handler XXX =>.SUP.Orphan
HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\VMDiskMenuHandler =>.SUP.Orphan
HKLM\Software\Classes\CLSID\{271DC252-6FE1-4D59-9053-E4CF50AB99DE} =>.SUP.Orphan
C:\Users\moez\AppData\Roaming\BitTorrent\BitTorrent.exe =>BitTorrent (P2P)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Shared Tools\MSConfig\startupreg\BitTorrent =>BitTorrent (P2P)
C:\Users\moez\Downloads\uTorrent.exe =>BitTorrent (P2P)
C:\Windows\Installer\17a862.msp =>.SUP.Obsolete.Adobe
C:\Windows\Installer\b8df2.msp =>.SUP.Obsolete.Adobe
C:\Windows\Installer\faa50.msp =>.SUP.Obsolete.Adobe
C:\Windows\Installer\faa67.msp =>.SUP.Obsolete.Adobe
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\000 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\001 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\003 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\004 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\005 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\006 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\007 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\008 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\009 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\010 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\011 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\013 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\014 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\015 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\016 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\017 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\018 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\019 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\020 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\022 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\024 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\041 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\045 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\046 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\047 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\048 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\049 =>.SUP.Temporary.Chrome
C:\Users\moez\AppData\Local\Google\Chrome\User Data\Default\File System\050 =>.SUP.Temporary.Chrome
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\Software\BSD =>.SUP.DriverUpdatePlus
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drp.su =>.SUP.DriverPack
HKU\S-1-5-21-318700280-1262799068-3410121159-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com =>PUP.Optional.LavasoftWebCompanion
HKCU\Software\Lavasoft\Web Companion =>PUP.Optional.LavasoftWebCompanion
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drp.su =>.SUP.DriverPack
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com =>PUP.Optional.LavasoftWebCompanion
HKLM\SOFTWARE\Wow6432Node\Lavasoft\Web Companion =>PUP.Optional.LavasoftWebCompanion
HKLM\SOFTWARE\Lavasoft\Web Companion =>PUP.Optional.LavasoftWebCompanion

---\\ Summary of the elements found (10) - 0s
https://nicolascoolman.eu/2017/03/12/superfluous-lavasoftwebcompanion/ =>PUP.Optional.LavasoftWebCompanion
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>BitTorrent (P2P)
https://nicolascoolman.eu/2017/02/23/tencentadressbar/ =>.SUP.Tencent
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.DriverUpdatePlus
https://nicolascoolman.eu/2018/07/04/sup-driverpack/ =>.SUP.DriverPack
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.DriverToolkit
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Empty
https://nicolascoolman.eu/2017/09/12/origine-lignes-orphelines/ =>.SUP.Orphan
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Obsolete.Adobe
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Temporary.Chrome

~ Unselected Options: O82,
~ End of the scan, 13100 items in 15mn08s (3482)(0)

Publicité


Signaler le contenu de ce document

Publicité