OTL logfile created on: 07/08/2018 12:56:10 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\HIGH TECH\Desktop
64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.19078)
Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy

3,90 Gb Total Physical Memory | 1,86 Gb Available Physical Memory | 47,58% Memory free
5,78 Gb Paging File | 3,78 Gb Available in Paging File | 65,45% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 126,61 Gb Total Space | 30,79 Gb Free Space | 24,32% Space Free | Partition Type: NTFS
Drive D: | 146,48 Gb Total Space | 122,35 Gb Free Space | 83,53% Space Free | Partition Type: NTFS
Drive E: | 192,32 Gb Total Space | 176,56 Gb Free Space | 91,80% Space Free | Partition Type: NTFS

Computer Name: HIGHTECH | User Name: HIGH TECH | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - File not found --
PRC - [2018/08/07 12:28:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\HIGH TECH\Desktop\OTL.exe
PRC - [2018/07/25 10:12:16 | 008,730,648 | ---- | M] (AVAST Software) -- C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe
PRC - [2018/07/17 14:44:59 | 010,828,504 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2018/07/17 14:35:49 | 000,435,248 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\afwServ.exe
PRC - [2018/06/29 15:56:18 | 001,871,344 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
PRC - [2018/04/24 07:51:50 | 000,818,128 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
PRC - [2017/12/28 03:48:40 | 004,105,328 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe
PRC - [2017/09/27 18:07:00 | 000,018,264 | ---- | M] (Intel(R) Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe
PRC - [2016/05/20 13:37:34 | 000,275,512 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
PRC - [2015/07/07 15:06:56 | 000,295,736 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
PRC - [2015/07/07 15:06:56 | 000,123,704 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
PRC - [2015/05/25 13:20:18 | 019,782,224 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
PRC - [2015/05/21 14:52:36 | 000,439,096 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
PRC - [2015/04/22 10:28:24 | 000,222,008 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
PRC - [2015/04/01 18:01:32 | 000,107,320 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
PRC - [2014/06/24 15:12:22 | 000,171,480 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2018/07/17 14:36:29 | 000,483,544 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\streamback.dll
MOD - [2018/07/17 14:35:51 | 000,282,840 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
MOD - [2018/03/12 21:40:54 | 067,126,928 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2015/03/17 01:34:22 | 000,010,240 | ---- | M] () -- C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Locale\fr_FR\AcroTray.FRA


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2018/07/17 14:36:16 | 000,322,464 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:[b]64bit:[/b] - [2018/07/17 14:35:58 | 007,780,400 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe -- (aswbIDSAgent)
SRV:[b]64bit:[/b] - [2018/07/17 14:35:49 | 000,435,248 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall)
SRV:[b]64bit:[/b] - [2018/03/10 17:46:10 | 000,840,192 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:[b]64bit:[/b] - [2018/01/02 06:17:04 | 000,116,224 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2017/12/13 06:39:43 | 000,093,008 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\KeyboardFilterSvc.dll -- (MsKeyboardFilter)
SRV:[b]64bit:[/b] - [2017/10/20 16:41:42 | 000,365,040 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\igfxCUIService.exe -- (igfxCUIService2.0.0.0)
SRV:[b]64bit:[/b] - [2017/05/05 12:02:42 | 000,110,416 | ---- | M] (Code Sector) [Auto | Running] -- C:\Program Files\TeraCopy\TeraCopyService.exe -- (TeraCopyService)
SRV:[b]64bit:[/b] - [2017/01/12 17:51:17 | 000,361,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV:[b]64bit:[/b] - [2017/01/12 17:51:17 | 000,119,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:[b]64bit:[/b] - [2016/12/25 00:39:34 | 000,133,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:[b]64bit:[/b] - [2016/08/22 14:34:40 | 001,628,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
SRV:[b]64bit:[/b] - [2016/06/07 21:32:07 | 002,988,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:[b]64bit:[/b] - [2016/02/08 17:53:04 | 001,348,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:[b]64bit:[/b] - [2016/02/03 16:11:56 | 001,673,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:[b]64bit:[/b] - [2015/07/16 19:58:34 | 000,074,752 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:[b]64bit:[/b] - [2015/05/30 20:36:24 | 000,230,400 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2015/05/12 14:19:37 | 000,294,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:[b]64bit:[/b] - [2015/05/07 16:21:51 | 000,522,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)
SRV:[b]64bit:[/b] - [2015/02/21 00:49:18 | 000,780,800 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:[b]64bit:[/b] - [2014/10/29 04:59:51 | 003,460,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:[b]64bit:[/b] - [2014/10/29 03:42:19 | 000,026,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:[b]64bit:[/b] - [2014/10/29 03:42:03 | 000,041,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:[b]64bit:[/b] - [2014/10/29 03:34:51 | 000,067,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:[b]64bit:[/b] - [2014/10/29 03:33:55 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:[b]64bit:[/b] - [2014/10/29 03:30:35 | 000,187,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:[b]64bit:[/b] - [2014/10/29 03:29:22 | 000,121,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:[b]64bit:[/b] - [2014/10/29 02:57:05 | 000,324,608 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\BthHFSrv.dll -- (BthHFSrv)
SRV:[b]64bit:[/b] - [2014/10/29 02:48:20 | 000,166,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:[b]64bit:[/b] - [2014/10/29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:[b]64bit:[/b] - [2014/10/29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:[b]64bit:[/b] - [2014/10/29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:[b]64bit:[/b] - [2014/10/29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:[b]64bit:[/b] - [2014/10/29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:[b]64bit:[/b] - [2014/10/29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:[b]64bit:[/b] - [2014/10/29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:[b]64bit:[/b] - [2014/10/29 02:27:21 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:[b]64bit:[/b] - [2014/10/29 02:22:40 | 000,062,464 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2014/10/29 02:20:03 | 000,262,656 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:[b]64bit:[/b] - [2014/10/29 02:19:20 | 000,550,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2014/10/29 02:16:17 | 000,154,112 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:[b]64bit:[/b] - [2014/10/29 02:13:24 | 000,374,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:[b]64bit:[/b] - [2014/10/29 02:13:02 | 000,260,608 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:[b]64bit:[/b] - [2014/10/29 02:12:36 | 000,407,040 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:[b]64bit:[/b] - [2014/10/29 02:12:22 | 000,270,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:[b]64bit:[/b] - [2014/10/29 02:11:10 | 001,639,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:[b]64bit:[/b] - [2014/10/29 02:05:09 | 000,206,848 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:[b]64bit:[/b] - [2014/10/29 01:48:52 | 000,562,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV - [2018/07/25 10:12:16 | 008,730,648 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe -- (CleanupPSvc)
SRV - [2018/07/10 17:32:17 | 000,335,872 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2018/07/06 13:50:29 | 000,194,512 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2018/05/11 12:50:54 | 002,128,872 | ---- | M] (Adobe Systems, Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe -- (AGSService)
SRV - [2018/05/11 12:50:52 | 002,321,384 | ---- | M] (Adobe Systems, Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe -- (AGMService)
SRV - [2018/04/24 07:51:50 | 000,818,128 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe -- (AdobeUpdateService)
SRV - [2017/12/20 12:05:57 | 001,074,480 | ---- | M] (Flexera Software LLC) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe -- (FlexNet Licensing Service)
SRV - [2017/10/20 16:43:06 | 000,494,056 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2017/09/27 18:07:00 | 000,018,264 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe -- (XTU3SERVICE)
SRV - [2016/06/07 21:32:07 | 002,988,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2015/08/17 02:48:18 | 001,385,640 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysWOW64\esif_uf.exe -- (esifsvc)
SRV - [2015/07/07 15:06:56 | 000,123,704 | ---- | M] (ASUSTek Computer Inc.) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe -- (ASLDRService)
SRV - [2015/05/07 16:05:40 | 000,367,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2015/04/01 18:01:32 | 000,107,320 | ---- | M] (ASUSTek Computer Inc.) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv)
SRV - [2014/10/29 02:51:55 | 000,017,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2014/10/29 02:04:45 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2014/06/24 15:12:22 | 000,171,480 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe -- (ICCS)
SRV - [2013/12/06 11:03:16 | 001,893,304 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\MPI-RT\4.1.3.045\em64t\bin\smpd.exe -- (impi_smpd)
SRV - [2013/12/06 11:03:10 | 000,301,496 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\MPI-RT\4.1.3.045\em64t\bin\hydra_service.exe -- (impi_hydra)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - File not found [File_System | System | Stopped] -- C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp.sys -- (epp)
DRV:[b]64bit:[/b] - [2018/07/25 20:08:42 | 000,467,064 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:[b]64bit:[/b] - [2018/07/17 14:37:32 | 000,211,160 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:[b]64bit:[/b] - [2018/07/17 14:37:31 | 000,381,584 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:[b]64bit:[/b] - [2018/07/17 14:37:31 | 000,159,640 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:[b]64bit:[/b] - [2018/07/17 14:37:31 | 000,085,968 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:[b]64bit:[/b] - [2018/07/17 14:37:31 | 000,046,976 | ---- | M] (AVAST Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:[b]64bit:[/b] - [2018/07/17 14:37:30 | 000,197,160 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswArPot.sys -- (aswArPot)
DRV:[b]64bit:[/b] - [2018/07/17 14:37:29 | 000,111,872 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:[b]64bit:[/b] - [2018/07/17 14:36:07 | 001,027,728 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:[b]64bit:[/b] - [2018/07/17 14:35:50 | 000,647,488 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswNetSec.sys -- (aswNetSec)
DRV:[b]64bit:[/b] - [2018/07/17 14:35:46 | 000,346,664 | ---- | M] (AVAST Software) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\aswbloga.sys -- (aswblog)
DRV:[b]64bit:[/b] - [2018/07/17 14:35:46 | 000,059,592 | ---- | M] (AVAST Software) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\aswbuniva.sys -- (aswbuniv)
DRV:[b]64bit:[/b] - [2018/07/17 14:35:45 | 000,229,392 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswbidsdrivera.sys -- (aswbidsdriver)
DRV:[b]64bit:[/b] - [2018/07/17 14:35:45 | 000,201,328 | ---- | M] (AVAST Software) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\aswbidsha.sys -- (aswbidsh)
DRV:[b]64bit:[/b] - [2018/06/20 19:48:27 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)
DRV:[b]64bit:[/b] - [2018/05/23 06:45:28 | 000,027,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:[b]64bit:[/b] - [2018/05/12 21:51:23 | 000,923,480 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\refs.sys -- (ReFS)
DRV:[b]64bit:[/b] - [2018/05/04 00:02:07 | 000,325,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:[b]64bit:[/b] - [2018/05/04 00:02:07 | 000,187,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)
DRV:[b]64bit:[/b] - [2018/04/06 22:27:09 | 000,376,656 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:[b]64bit:[/b] - [2018/04/05 18:47:55 | 000,087,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)
DRV:[b]64bit:[/b] - [2018/03/08 20:53:08 | 000,065,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpcivsp.sys -- (vpcivsp)
DRV:[b]64bit:[/b] - [2018/02/26 16:45:40 | 000,213,632 | ---- | M] (Oracle Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\VBoxNetLwf.sys -- (VBoxNetLwf)
DRV:[b]64bit:[/b] - [2018/02/26 16:45:32 | 000,203,328 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VBoxNetAdp6.sys -- (VBoxNetAdp)
DRV:[b]64bit:[/b] - [2018/02/21 22:09:43 | 000,022,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\kbldfltr.sys -- (kbldfltr)
DRV:[b]64bit:[/b] - [2018/01/02 08:56:11 | 000,136,536 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:[b]64bit:[/b] - [2018/01/02 06:38:34 | 000,220,160 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Vid.sys -- (Vid)
DRV:[b]64bit:[/b] - [2018/01/02 06:38:29 | 000,130,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmbusr.sys -- (vmbusr)
DRV:[b]64bit:[/b] - [2017/12/29 02:47:16 | 000,226,024 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\idmwfp.sys -- (IDMWFP)
DRV:[b]64bit:[/b] - [2017/11/08 16:55:00 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:[b]64bit:[/b] - [2017/11/07 16:23:40 | 000,053,904 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\aswTap.sys -- (aswTap)
DRV:[b]64bit:[/b] - [2017/10/20 16:41:20 | 007,963,632 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2017/09/19 11:38:16 | 000,129,448 | ---- | M] (Future Technology Devices International Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ftdibus.sys -- (FTDIBUS)
DRV:[b]64bit:[/b] - [2017/08/24 06:19:12 | 000,089,800 | ---- | M] (Future Technology Devices International Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ftser2k.sys -- (FTSER2K)
DRV:[b]64bit:[/b] - [2017/07/08 04:16:36 | 000,086,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:[b]64bit:[/b] - [2017/06/07 05:36:28 | 000,138,296 | ---- | M] (Power Software Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\scdemu.sys -- (SCDEmu)
DRV:[b]64bit:[/b] - [2017/05/15 23:09:32 | 000,057,688 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:[b]64bit:[/b] - [2017/05/08 14:39:40 | 000,038,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ICCWDT.sys -- (ICCWDT)
DRV:[b]64bit:[/b] - [2017/02/10 15:37:28 | 000,046,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:[b]64bit:[/b] - [2017/01/12 17:51:18 | 000,274,776 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:[b]64bit:[/b] - [2017/01/12 17:51:18 | 000,117,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:[b]64bit:[/b] - [2017/01/12 16:03:31 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\storvsp.sys -- (storvsp)
DRV:[b]64bit:[/b] - [2017/01/11 18:28:42 | 000,422,744 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:[b]64bit:[/b] - [2017/01/02 15:01:46 | 000,036,600 | ---- | M] (Riverbed Technology, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (npf)
DRV:[b]64bit:[/b] - [2016/05/12 05:32:26 | 000,481,768 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:[b]64bit:[/b] - [2016/04/21 10:10:04 | 000,027,136 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:[b]64bit:[/b] - [2016/01/26 20:15:40 | 000,072,024 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:[b]64bit:[/b] - [2015/12/07 18:53:18 | 000,051,704 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible)
DRV:[b]64bit:[/b] - [2015/12/07 18:53:18 | 000,039,920 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus)
DRV:[b]64bit:[/b] - [2015/10/11 07:34:30 | 000,468,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:[b]64bit:[/b] - [2015/09/29 13:24:42 | 000,155,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:[b]64bit:[/b] - [2015/08/17 02:48:18 | 000,261,624 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\esif_lf.sys -- (esif_lf)
DRV:[b]64bit:[/b] - [2015/08/17 02:48:18 | 000,053,752 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dptf_cpu.sys -- (dptf_cpu)
DRV:[b]64bit:[/b] - [2015/08/17 02:48:18 | 000,050,696 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dptf_pch.sys -- (dptf_pch)
DRV:[b]64bit:[/b] - [2015/08/10 06:17:52 | 001,462,720 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
DRV:[b]64bit:[/b] - [2015/07/28 20:37:20 | 000,184,608 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TeeDriverW8x64.sys -- (MEIx64)
DRV:[b]64bit:[/b] - [2015/06/26 03:04:04 | 000,088,256 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\IntelPcc.sys -- (IntelHSWPcc)
DRV:[b]64bit:[/b] - [2015/06/07 22:46:36 | 004,291,072 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athwbx.sys -- (athr)
DRV:[b]64bit:[/b] - [2015/06/03 02:47:10 | 000,313,048 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsBaStor.sys -- (RSBASTOR)
DRV:[b]64bit:[/b] - [2015/05/25 13:20:18 | 000,021,816 | ---- | M] (ASUSTek Computer Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AiCharger.sys -- (AiCharger)
DRV:[b]64bit:[/b] - [2015/03/20 02:56:10 | 000,080,384 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:[b]64bit:[/b] - [2015/03/13 05:03:31 | 000,239,424 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2015/03/09 03:02:51 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:[b]64bit:[/b] - [2015/01/15 12:42:42 | 000,881,368 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)
DRV:[b]64bit:[/b] - [2015/01/04 05:14:40 | 000,600,776 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:[b]64bit:[/b] - [2014/10/29 04:57:42 | 000,054,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:[b]64bit:[/b] - [2014/10/29 04:56:04 | 000,027,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2014/10/29 03:46:43 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2014/10/29 03:45:54 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:[b]64bit:[/b] - [2014/10/29 03:45:39 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:[b]64bit:[/b] - [2014/10/29 03:45:16 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:[b]64bit:[/b] - [2014/10/13 03:43:17 | 000,039,744 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:[b]64bit:[/b] - [2014/08/15 01:36:55 | 000,146,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:[b]64bit:[/b] - [2014/07/01 14:49:40 | 000,120,312 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iaLPSS_I2C.sys -- (iaLPSS_I2C)
DRV:[b]64bit:[/b] - [2014/07/01 14:49:40 | 000,035,832 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iaLPSS_GPIO.sys -- (iaLPSS_GPIO)
DRV:[b]64bit:[/b] - [2014/03/13 13:35:24 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\wof.sys -- (Wof)
DRV:[b]64bit:[/b] - [2014/02/22 16:49:49 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:[b]64bit:[/b] - [2013/12/04 19:41:54 | 000,226,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BthLEEnum.sys -- (BthLEEnum)
DRV:[b]64bit:[/b] - [2013/10/26 02:54:32 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:[b]64bit:[/b] - [2013/10/09 06:52:16 | 000,020,280 | ---- | M] (ASUS) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AsHIDSwitch64.sys -- (HIDSwitch)
DRV:[b]64bit:[/b] - [2013/09/30 05:20:56 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:[b]64bit:[/b] - [2013/09/30 05:02:35 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:[b]64bit:[/b] - [2013/08/22 14:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:[b]64bit:[/b] - [2013/08/22 14:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2013/08/22 13:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:[b]64bit:[/b] - [2013/08/22 13:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:[b]64bit:[/b] - [2013/08/22 13:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:[b]64bit:[/b] - [2013/08/22 12:40:18 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pnpmem.sys -- (PNPMEM)
DRV:[b]64bit:[/b] - [2013/08/22 12:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:[b]64bit:[/b] - [2013/08/22 12:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:[b]64bit:[/b] - [2013/08/22 12:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:[b]64bit:[/b] - [2013/08/22 12:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:[b]64bit:[/b] - [2013/08/22 12:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:[b]64bit:[/b] - [2013/08/22 12:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:[b]64bit:[/b] - [2013/08/22 12:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:[b]64bit:[/b] - [2013/08/22 12:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:[b]64bit:[/b] - [2013/08/22 12:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:[b]64bit:[/b] - [2013/08/22 12:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:[b]64bit:[/b] - [2013/08/22 12:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:[b]64bit:[/b] - [2013/08/22 12:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2013/08/22 12:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:[b]64bit:[/b] - [2013/08/22 12:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2013/08/22 12:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:[b]64bit:[/b] - [2013/08/13 00:25:46 | 000,017,624 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:[b]64bit:[/b] - [2013/08/10 01:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:[b]64bit:[/b] - [2013/07/30 19:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:[b]64bit:[/b] - [2013/07/25 20:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:[b]64bit:[/b] - [2013/06/18 15:45:26 | 000,460,288 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\e1i63x64.sys -- (e1iexpress)
DRV:[b]64bit:[/b] - [2012/12/11 10:43:42 | 000,063,568 | ---- | M] (SafeNet, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SNTUSB64.SYS -- (SNTUSB64)
DRV:[b]64bit:[/b] - [2012/08/06 09:17:18 | 000,017,280 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbfiltr.sys -- (kbfiltr)
DRV:[b]64bit:[/b] - [2009/09/17 07:05:02 | 000,145,448 | ---- | M] (SafeNet, Inc.) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\sentinel64.sys -- (Sentinel64)
DRV:[b]64bit:[/b] - [2009/02/19 03:29:46 | 000,071,168 | ---- | M] (Silicon Laboratories) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\silabser.sys -- (silabser)
DRV:[b]64bit:[/b] - [2009/02/19 03:29:46 | 000,023,040 | ---- | M] (Silicon Laboratories, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\silabenm.sys -- (silabenm)
DRV - [2017/09/15 18:22:24 | 000,038,424 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys -- (iocbios2)
DRV - [2015/05/08 10:49:58 | 000,018,048 | ---- | M] (ASUS) [Kernel | Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys -- (ASMMAP64)
DRV - [2015/05/08 10:07:06 | 000,020,096 | ---- | M] (ASUSTek Computer Inc.) [Kernel | System | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys -- (ATKWMIACPIIO)


[color=#E56717]========== Standard Registry (All) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://google.com/
IE - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr-FR,fr;q=0.8,ar-DZ;q=0.5,ar;q=0.3
IE - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = DA 08 26 5F 1F 5F D3 01 [binary data]
IE - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = 53 A3 C3 95 F1 80 D3 01 [binary data]
IE - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = Reg Error: Value error.
IE - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002\..\SearchScopes,DefaultScope = {C0C3A6C6-03BC-4195-8FCB-AEA091301353}
IE - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002\..\SearchScopes\{C0C3A6C6-03BC-4195-8FCB-AEA091301353}: "URL" = https://maktoob.search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10420__171121__yaie&p={searchTerms}
IE - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.countryCode: "DZ"
FF - prefs.js..browser.search.region: "DZ"
FF - user.js - File not found

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_30_0_0_134.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_30_0_0_134.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.181.2: C:\Program Files (x86)\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.181.2: C:\Program Files (x86)\Java\jre1.8.0_181\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.8: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=3.0.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension.17@acrobat.adobe.com: C:\PROGRAM FILES (X86)\ADOBE\ACROBAT DC\ACROBAT\BROWSER\WCFIREFOXEXTN\WEBEXTN\SIGNED_EXTN\ADOBE_ACROBAT-1.0-WINDOWS.XPI [2018/06/29 07:56:26 | 000,470,521 | ---- | M] ()
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 61.0.1\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 61.0.1\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension.17@acrobat.adobe.com: C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2018/06/29 07:56:26 | 000,470,521 | ---- | M] ()
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\mozilla_cc3@internetdownloadmanager.com: C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi [2017/12/29 02:59:54 | 000,078,554 | ---- | M] ()
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 61.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 61.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\HIGH TECH\AppData\Roaming\IDM\idmmzcc5 [2017/11/06 22:34:34 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc2@internetdownloadmanager.com: C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017/12/20 15:58:30 | 000,030,386 | ---- | M] ()

[2013/11/19 20:45:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Extensions
[2017/11/16 22:33:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\SystemExtensionsDev
[2018/07/28 12:51:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\47v5k2fd.default-1515538160535\extensions
[2018/01/09 22:37:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\mfaphtm1.default-1515533724045\browser-extension-data
[2018/01/09 22:37:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\mfaphtm1.default-1515533724045\browser-extension-data\screenshots@mozilla.org
[2018/01/09 22:35:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\xigw8xjb.default\browser-extension-data
[2018/01/09 22:35:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\xigw8xjb.default\browser-extension-data\{b6d09408-a35e-11e7-bc48-f3e9438e081e}
[2018/01/09 22:35:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\xigw8xjb.default\browser-extension-data\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2018/01/09 22:35:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\xigw8xjb.default\browser-extension-data\newtaboverride@agenedia.com
[2018/01/09 22:35:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\xigw8xjb.default\browser-extension-data\s3google@translator
[2018/01/09 22:35:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\xigw8xjb.default\browser-extension-data\screenshots@mozilla.org
[2018/05/30 13:08:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\xigw8xjb.default\extensions
[2018/08/02 16:13:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\yugb9q7e.default-1532763993451\browser-extension-data
[2018/08/07 12:33:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\yugb9q7e.default-1532763993451\browser-extension-data\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2018/08/07 12:16:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\yugb9q7e.default-1532763993451\browser-extension-data\helper@savefrom.net
[2018/08/02 16:13:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\yugb9q7e.default-1532763993451\browser-extension-data\jid1-r1tDuNiNb4SEww@jetpack
[2018/07/28 08:46:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\yugb9q7e.default-1532763993451\browser-extension-data\newtaboverride@agenedia.com
[2018/08/07 12:34:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\yugb9q7e.default-1532763993451\browser-extension-data\s3google@translator
[2018/08/02 16:13:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\yugb9q7e.default-1532763993451\browser-extension-data\sp@avast.com
[2018/07/28 08:46:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\yugb9q7e.default-1532763993451\browser-extension-data\web2pdfextension.17@acrobat.adobe.com
[2018/08/02 16:13:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\yugb9q7e.default-1532763993451\browser-extension-data\wrc@avast.com
[2018/08/03 11:23:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\yugb9q7e.default-1532763993451\extensions
[2018/08/03 11:23:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\Firefox\Profiles\yugb9q7e.default-1532763993451\extensions\staged
[2018/06/28 22:53:50 | 000,747,338 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\47v5k2fd.default-1515538160535\extensions\helper@savefrom.net.xpi
[2018/07/25 21:23:33 | 001,022,878 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\47v5k2fd.default-1515538160535\extensions\jid1-r1tDuNiNb4SEww@jetpack.xpi
[2018/07/22 12:51:37 | 000,055,458 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\47v5k2fd.default-1515538160535\extensions\newtaboverride@agenedia.com.xpi
[2018/04/13 19:30:21 | 000,005,888 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\47v5k2fd.default-1515538160535\extensions\overbitewx@floodgap.com.xpi
[2018/04/13 19:17:28 | 000,380,675 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\47v5k2fd.default-1515538160535\extensions\s3google@translator.xpi
[2018/07/09 22:07:04 | 002,457,020 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\47v5k2fd.default-1515538160535\extensions\sp@avast.com.xpi
[2018/07/09 22:06:35 | 000,789,048 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\47v5k2fd.default-1515538160535\extensions\wrc@avast.com.xpi
[2018/04/13 19:30:16 | 000,010,623 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\47v5k2fd.default-1515538160535\extensions\{7276f3bb-de56-4b5a-b940-88b62731d409}.xpi
[2018/07/18 14:39:43 | 001,228,429 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\47v5k2fd.default-1515538160535\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2017/12/08 15:03:07 | 000,049,005 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\xigw8xjb.default\extensions\newtaboverride@agenedia.com.xpi
[2017/12/22 23:06:50 | 000,372,436 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\xigw8xjb.default\extensions\s3google@translator.xpi
[2018/01/08 18:16:05 | 000,607,400 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\xigw8xjb.default\extensions\sp@avast.com.xpi
[2017/11/14 21:32:28 | 000,707,252 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\xigw8xjb.default\extensions\wrc@avast.com.xpi
[2017/12/12 19:57:21 | 001,044,671 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\xigw8xjb.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2018/01/06 21:34:45 | 000,005,324 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\xigw8xjb.default\features\{b39f8a6b-4845-426d-af54-876d10ba69b2}\disable-js-shared-memory@mozilla.org.xpi
[2018/01/06 21:34:36 | 000,005,507 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\xigw8xjb.default\features\{b39f8a6b-4845-426d-af54-876d10ba69b2}\disable-media-wmf-nv12@mozilla.org.xpi
[2018/08/03 11:23:44 | 000,748,230 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\yugb9q7e.default-1532763993451\extensions\helper@savefrom.net.xpi
[2018/07/22 12:51:37 | 000,055,458 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\yugb9q7e.default-1532763993451\extensions\newtaboverride@agenedia.com.xpi
[2018/04/13 19:30:21 | 000,005,888 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\yugb9q7e.default-1532763993451\extensions\overbitewx@floodgap.com.xpi
[2018/04/13 19:17:28 | 000,380,675 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\yugb9q7e.default-1532763993451\extensions\s3google@translator.xpi
[2018/04/13 19:30:16 | 000,010,623 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\yugb9q7e.default-1532763993451\extensions\{7276f3bb-de56-4b5a-b940-88b62731d409}.xpi
[2018/07/18 14:39:43 | 001,228,429 | ---- | M] () (No name found) -- C:\Users\HIGH TECH\AppData\Roaming\mozilla\firefox\profiles\yugb9q7e.default-1532763993451\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

O1 HOSTS File: ([2018/08/03 15:14:12 | 000,000,093 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 platform.wondershare.com
O2:[b]64bit:[/b] - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
O2:[b]64bit:[/b] - BHO: (Skype for Business Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll (Microsoft Corporation)
O2:[b]64bit:[/b] - BHO: (ExplorerBHO Class) - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
O2:[b]64bit:[/b] - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:[b]64bit:[/b] - BHO: (Adobe Acrobat Create PDF Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll (Adobe Systems Incorporated)
O2:[b]64bit:[/b] - BHO: (ClassicIEBHO Class) - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft)
O2:[b]64bit:[/b] - BHO: (Adobe Acrobat Create PDF from Selection) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll (Adobe Systems Incorporated)
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (Skype for Business Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (ExplorerBHO Class) - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_181\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
O2 - BHO: (Adobe Acrobat Create PDF Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_181\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (ClassicIEBHO Class) - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft)
O2 - BHO: (Adobe Acrobat Create PDF from Selection) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll (Adobe Systems Incorporated)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Adobe Acrobat Create PDF Toolbar) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll (Adobe Systems Incorporated)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Classic Explorer Bar) - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
O3 - HKLM\..\Toolbar: (Adobe Acrobat Create PDF Toolbar) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Classic Explorer Bar) - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
O4:[b]64bit:[/b] - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:[b]64bit:[/b] - HKLM..\Run: [AdobeGCInvoker-1.0] C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe (Adobe Systems, Incorporated)
O4:[b]64bit:[/b] - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvLaunch.exe (AVAST Software)
O4:[b]64bit:[/b] - HKLM..\Run: [Classic Start Menu] C:\Program Files\Classic Shell\ClassicStartMenu.exe (IvoSoft)
O4:[b]64bit:[/b] - HKLM..\Run: [CNAP2 Launcher] C:\Windows\SysNative\spool\drivers\x64\3\CNAP2LAK.EXE (CANON INC.)
O4:[b]64bit:[/b] - HKLM..\Run: [Fences] C:\Program Files (x86)\Stardock\Fences\Fences.exe (Stardock Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\isuspm.exe (Flexera Software, Inc.)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Oracle Corporation)
O4 - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002..\Run: [BitTorrent] C:\Users\HIGH TECH\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc.)
O4 - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002..\Run: [CNAP2 Launcher] C:\Windows\system32\spool\DRIVERS\x64\3\CNAP2LAK.EXE File not found
O4 - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002..\Run: [Fences] c:\program files (x86)\stardock\fences\Fences.exe (Stardock Corporation)
O4 - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002..\Run: [ISUSPM Startup] C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - Startup: C:\Users\HIGH TECH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Envoyer à OneNote.lnk = C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Users\HIGH TECH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Firemin.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O7 - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:[b]64bit:[/b] - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE (Microsoft Corporation)
O8:[b]64bit:[/b] - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8:[b]64bit:[/b] - Extra context menu item: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll (Microsoft Corporation)
O8:[b]64bit:[/b] - Extra context menu item: Télécharger avec IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8:[b]64bit:[/b] - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O9:[b]64bit:[/b] - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIE.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIE.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe (IvoSoft)
O9:[b]64bit:[/b] - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe (IvoSoft)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Domains: localhost ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: webcompanion.com ([]http in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: localhost ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: webcompanion.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-2912233613-2941139974-2034645768-1002\..Trusted Domains: localhost ([]* in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{56ACE47F-43E2-4684-B9C4-26DFA449F07A}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7FA338C1-35D0-4E9A-A7D9-020015E44B68}: NameServer = 77.234.40.79
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AF0B5407-1B03-40B5-BFED-AA477C35E1E1}: DhcpNameServer = 192.168.1.1
O18:[b]64bit:[/b] - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\mso-minsb.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\mso-minsb-roaming.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\osf.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\osf-roaming.16 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-minsb.16 {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-minsb-roaming.16 {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\osf.16 {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\osf-roaming.16 {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Filter\text/xml {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\MSOXMLMF.DLL (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22:[b]64bit:[/b] - SharedTaskScheduler: {1984DD45-52CF-49cd-AB77-18F378FEA264} - FencesShellExt - No CLSID value found.
O27:[b]64bit:[/b] - HKLM IFEO\Acrobat.exe: Debugger - "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"ndows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
File not found
O27:[b]64bit:[/b] - HKLM IFEO\acrodist.exe: Debugger - "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"ndows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) File not found
O27:[b]64bit:[/b] - HKLM IFEO\photoshop.exe: Debugger - "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"ndows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) File not found
O27 - HKLM IFEO\Acrobat.exe: Debugger - "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"ndows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) File not found
O27 - HKLM IFEO\acrodist.exe: Debugger - "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" File not found
O27 - HKLM IFEO\photoshop.exe: Debugger - "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"ftware\Avast Cleanup\autoreactivator.exe" File not found
File not found
O29:[b]64bit:[/b] - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:[b]64bit:[/b] - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2018/04/03 16:05:18 | 2286,113,014 | ---- | M] () - E:\Autodata 3.45.rar -- [ NTFS ]
O33 - MountPoints2\{1060e141-d3b0-11e7-82aa-f0038c027fa2}\Shell - "" = AutoRun
O33 - MountPoints2\{1060e141-d3b0-11e7-82aa-f0038c027fa2}\Shell\AutoRun\command - "" = "H:\iLinker.exe"
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = "G:\autorun.exe"
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = "H:\setup.exe"
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2018/08/07 12:29:24 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2018/08/07 12:28:11 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\HIGH TECH\Desktop\OTL.exe
[2018/08/06 12:49:25 | 000,029,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\aspnet_counters.dll
[2018/08/06 12:49:21 | 000,019,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvcr100_clr0400.dll
[2018/08/06 12:49:18 | 000,030,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aspnet_counters.dll
[2018/08/06 12:49:14 | 000,019,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcr100_clr0400.dll
[2018/08/05 22:45:31 | 000,000,000 | ---D | C] -- C:\Users\HIGH TECH\Desktop\Adobe Acrobat
[2018/08/03 20:42:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2018/08/03 20:40:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils Microsoft Office
[2018/08/01 13:03:19 | 000,000,000 | -H-D | C] -- C:\$WINDOWS.~BT
[2018/08/01 08:11:32 | 000,000,000 | -H-D | C] -- C:\$SysReset
[2018/07/28 16:05:53 | 000,378,072 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2018/07/26 08:21:36 | 000,000,000 | ---D | C] -- C:\ProgramData\AVS4YOU
[2018/07/26 08:21:33 | 000,000,000 | ---D | C] -- C:\Users\HIGH TECH\AppData\Roaming\AVS4YOU
[2018/07/26 08:14:56 | 000,000,000 | ---D | C] -- C:\Users\HIGH TECH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AVS4YOU
[2018/07/26 08:14:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU
[2018/07/26 08:14:21 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3a.dll
[2018/07/26 08:14:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVS4YOU
[2018/07/26 08:14:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVSMedia
[2018/07/25 21:00:25 | 000,000,000 | ---D | C] -- C:\Users\HIGH TECH\Desktop\Nouveau dossier (2)
[2018/07/21 23:14:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Oracle
[2018/07/21 23:14:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2018/07/18 11:46:35 | 000,000,000 | ---D | C] -- C:\Users\HIGH TECH\AppData\Local\CrashDumps
[2018/07/18 11:24:14 | 000,000,000 | ---D | C] -- C:\Users\HIGH TECH\AppData\Local\AVAST Software
[2018/07/12 11:26:44 | 000,835,064 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2018/07/12 11:26:44 | 000,179,704 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2018/07/11 04:28:51 | 005,779,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2018/07/11 04:28:50 | 007,398,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2018/07/11 04:28:48 | 003,119,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ExplorerFrame.dll
[2018/07/11 04:28:48 | 002,712,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ExplorerFrame.dll
[2018/07/11 04:28:48 | 000,012,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-environment-l1-1-0.dll
[2018/07/11 04:28:48 | 000,011,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-utility-l1-1-0.dll
[2018/07/11 04:28:47 | 002,176,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\combase.dll
[2018/07/11 04:28:47 | 001,565,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\combase.dll
[2018/07/11 04:28:47 | 000,998,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ucrtbase.dll
[2018/07/11 04:28:47 | 000,918,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ucrtbase.dll
[2018/07/11 04:28:46 | 000,656,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnsapi.dll
[2018/07/11 04:28:46 | 000,576,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2018/07/11 04:28:45 | 001,676,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2018/07/11 04:28:45 | 001,536,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe
[2018/07/11 04:28:44 | 000,439,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbport.sys
[2018/07/11 04:28:44 | 000,187,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\UCX01000.SYS
[2018/07/11 04:28:43 | 000,325,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBXHCI.SYS
[2018/07/11 04:28:43 | 000,065,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-private-l1-1-0.dll
[2018/07/11 04:28:43 | 000,063,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-private-l1-1-0.dll
[2018/07/11 04:28:43 | 000,019,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-multibyte-l1-1-0.dll
[2018/07/11 04:28:43 | 000,018,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-multibyte-l1-1-0.dll
[2018/07/11 04:28:43 | 000,013,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-time-l1-1-0.dll
[2018/07/11 04:28:43 | 000,012,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-heap-l1-1-0.dll
[2018/07/11 04:28:43 | 000,012,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-conio-l1-1-0.dll
[2018/07/11 04:28:43 | 000,011,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-locale-l1-1-0.dll
[2018/07/11 04:28:43 | 000,011,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-environment-l1-1-0.dll
[2018/07/11 04:28:42 | 000,428,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2018/07/11 04:28:42 | 000,021,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-math-l1-1-0.dll
[2018/07/11 04:28:42 | 000,020,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-math-l1-1-0.dll
[2018/07/11 04:28:42 | 000,013,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-filesystem-l1-1-0.dll
[2018/07/11 04:28:42 | 000,013,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-filesystem-l1-1-0.dll
[2018/07/11 04:28:42 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-conio-l1-1-0.dll
[2018/07/11 04:28:42 | 000,012,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-process-l1-1-0.dll
[2018/07/11 04:28:42 | 000,012,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-utility-l1-1-0.dll
[2018/07/11 04:28:42 | 000,012,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-locale-l1-1-0.dll
[2018/07/11 04:28:42 | 000,011,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-heap-l1-1-0.dll
[2018/07/11 04:28:41 | 000,017,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-string-l1-1-0.dll
[2018/07/11 04:28:41 | 000,017,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-stdio-l1-1-0.dll
[2018/07/11 04:28:41 | 000,017,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-string-l1-1-0.dll
[2018/07/11 04:28:41 | 000,017,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-stdio-l1-1-0.dll
[2018/07/11 04:28:41 | 000,016,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-runtime-l1-1-0.dll
[2018/07/11 04:28:41 | 000,015,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-runtime-l1-1-0.dll
[2018/07/11 04:28:41 | 000,015,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-convert-l1-1-0.dll
[2018/07/11 04:28:41 | 000,015,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-convert-l1-1-0.dll
[2018/07/11 04:28:41 | 000,014,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-time-l1-1-0.dll
[2018/07/11 04:28:41 | 000,012,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-process-l1-1-0.dll
[2018/07/11 04:28:36 | 000,809,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2018/07/11 04:28:36 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\zipfldr.dll
[2018/07/11 04:28:36 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\fxppm.sys
[2018/07/11 04:28:35 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2018/07/11 04:28:35 | 000,794,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2018/07/11 04:28:35 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2018/07/11 04:28:35 | 000,662,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2018/07/11 04:18:21 | 002,860,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aitstatic.exe
[2018/07/11 04:18:21 | 001,602,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appraiser.dll
[2018/07/11 04:18:20 | 000,783,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll
[2018/07/11 04:18:20 | 000,680,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll
[2018/07/11 04:18:20 | 000,612,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\devinv.dll
[2018/07/11 04:18:20 | 000,470,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\centel.dll
[2018/07/11 04:18:20 | 000,443,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\invagent.dll
[2018/07/11 04:18:20 | 000,301,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\acmigration.dll
[2018/07/11 04:18:20 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepic.dll
[2018/07/11 04:18:20 | 000,149,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CompatTelRunner.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2018/08/07 12:28:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\HIGH TECH\Desktop\OTL.exe
[2018/08/07 12:14:04 | 000,000,180 | ---- | M] () -- C:\Windows\SysNative\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
[2018/08/07 12:13:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2018/08/07 12:11:34 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2018/08/06 18:00:52 | 003,234,784 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2018/08/06 17:28:37 | 000,002,034 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Acrobat DC.lnk
[2018/08/05 21:04:23 | 000,000,308 | ---- | M] () -- C:\Users\HIGH TECH\Desktop\1.reg
[2018/08/04 20:56:00 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\last.dump
[2018/08/02 22:33:18 | 001,843,726 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2018/08/02 22:33:18 | 000,806,712 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat
[2018/08/02 22:33:18 | 000,733,138 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2018/08/02 22:33:18 | 000,160,964 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat
[2018/08/02 22:33:18 | 000,140,040 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2018/08/01 13:03:43 | 000,001,908 | ---- | M] () -- C:\Windows\diagwrn.xml
[2018/08/01 13:03:43 | 000,001,908 | ---- | M] () -- C:\Windows\diagerr.xml
[2018/07/28 16:11:59 | 000,001,938 | ---- | M] () -- C:\Users\Public\Desktop\Avast Internet Security.lnk
[2018/07/26 09:31:12 | 007,091,808 | ---- | M] () -- C:\Users\HIGH TECH\Desktop\ARONA_07_17_FR.pdf
[2018/07/26 08:14:29 | 000,001,257 | ---- | M] () -- C:\Users\HIGH TECH\Desktop\AVS Audio Converter.lnk
[2018/07/25 20:08:42 | 000,467,064 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2018/07/25 11:10:25 | 000,001,112 | ---- | M] () -- C:\Users\HIGH TECH\Desktop\BitTorrent.lnk
[2018/07/25 11:10:25 | 000,001,092 | ---- | M] () -- C:\Users\HIGH TECH\Application Data\Microsoft\Internet Explorer\Quick Launch\BitTorrent.lnk
[2018/07/21 23:13:29 | 000,098,680 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2018/07/17 14:37:32 | 000,211,160 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
[2018/07/17 14:37:31 | 000,381,584 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswVmm.sys
[2018/07/17 14:37:31 | 000,378,072 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2018/07/17 14:37:31 | 000,159,640 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2018/07/17 14:37:31 | 000,085,968 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2018/07/17 14:37:31 | 000,046,976 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswHwid.sys
[2018/07/17 14:37:30 | 000,197,160 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswArPot.sys
[2018/07/17 14:37:29 | 000,111,872 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2018/07/17 14:36:07 | 001,027,728 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2018/07/17 14:35:50 | 000,647,488 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswNetSec.sys
[2018/07/17 14:35:46 | 000,346,664 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswbloga.sys
[2018/07/17 14:35:46 | 000,059,592 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswbuniva.sys
[2018/07/17 14:35:45 | 000,229,392 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswbidsdrivera.sys
[2018/07/17 14:35:45 | 000,201,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswbidsha.sys
[2018/07/12 21:52:49 | 000,037,796 | ---- | M] () -- C:\Users\HIGH TECH\Desktop\36976853_281097555973630_1278219508951023616_n.jpg
[2018/07/12 13:22:40 | 000,001,601 | ---- | M] () -- C:\Users\HIGH TECH\.tracker.prefs
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2018/08/06 17:28:37 | 000,002,057 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
[2018/08/06 17:28:37 | 000,002,034 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Acrobat DC.lnk
[2018/08/06 17:28:36 | 000,002,469 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
[2018/08/05 21:04:23 | 000,000,308 | ---- | C] () -- C:\Users\HIGH TECH\Desktop\1.reg
[2018/08/03 20:40:04 | 000,002,430 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
[2018/08/01 13:03:13 | 000,001,908 | ---- | C] () -- C:\Windows\diagwrn.xml
[2018/08/01 13:03:13 | 000,001,908 | ---- | C] () -- C:\Windows\diagerr.xml
[2018/07/26 09:28:28 | 007,091,808 | ---- | C] () -- C:\Users\HIGH TECH\Desktop\ARONA_07_17_FR.pdf
[2018/07/26 08:14:29 | 000,001,257 | ---- | C] () -- C:\Users\HIGH TECH\Desktop\AVS Audio Converter.lnk
[2018/07/12 21:52:47 | 000,037,796 | ---- | C] () -- C:\Users\HIGH TECH\Desktop\36976853_281097555973630_1278219508951023616_n.jpg
[2018/05/29 01:54:24 | 000,129,024 | ---- | C] () -- C:\Windows\SysWow64\AVERM.dll
[2018/05/29 01:54:24 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\AVEQT.dll
[2018/05/12 22:55:23 | 000,095,744 | ---- | C] () -- C:\Windows\womtrust.dll
[2018/05/12 22:55:23 | 000,081,408 | ---- | C] () -- C:\Windows\wontrust.dll
[2018/05/03 13:03:37 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll
[2018/04/24 16:22:54 | 000,729,088 | ---- | C] () -- C:\Windows\Announces.exe
[2018/03/03 21:48:57 | 000,001,601 | ---- | C] () -- C:\Users\HIGH TECH\.tracker.prefs
[2018/02/25 23:21:57 | 000,001,456 | ---- | C] () -- C:\Users\HIGH TECH\AppData\Local\Adobe Enregistrer pour le Web 13.0 Prefs
[2018/02/25 16:25:01 | 000,000,112 | ---- | C] () -- C:\Users\HIGH TECH\AppData\Roaming\Préfs JP2K CS6
[2017/12/29 13:54:11 | 000,107,008 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
[2017/12/29 13:52:46 | 000,046,080 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2017/12/28 22:24:49 | 000,518,144 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2017/12/28 15:50:17 | 000,002,255 | ---- | C] () -- C:\Windows\SysWow64\WimBootCompress.ini
[2017/12/28 11:49:30 | 000,000,103 | ---- | C] () -- C:\Windows\pro.INI
[2017/12/14 17:04:33 | 000,318,479 | ---- | C] () -- C:\Users\HIGH TECH\note1.ndx
[2017/12/14 17:04:33 | 000,040,583 | ---- | C] () -- C:\Users\HIGH TECH\note1.fic
[2017/12/02 23:58:53 | 000,001,525 | ---- | C] () -- C:\Users\HIGH TECH\.youtube-upload-credentials.json
[2017/11/23 11:00:43 | 000,001,024 | -HS- | C] () -- C:\Windows\SysWow64\msi32w16.dat
[2017/11/21 10:21:26 | 000,000,097 | ---- | C] () -- C:\Users\HIGH TECH\AppData\Local\fusioncache.dat
[2017/11/20 21:45:55 | 001,845,512 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2017/11/18 09:19:12 | 000,000,602 | ---- | C] () -- C:\Users\HIGH TECH\mm.cfg
[2017/11/11 20:35:11 | 000,646,656 | ---- | C] () -- C:\Windows\ExcelStudio.exe
[2017/11/07 22:34:57 | 000,004,608 | ---- | C] () -- C:\Windows\SECOH-QAD.exe
[2017/11/07 22:34:57 | 000,003,584 | ---- | C] () -- C:\Windows\SECOH-QAD.dll
[2013/11/18 22:19:56 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2013/11/16 03:20:41 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2018/06/12 09:00:25 | 022,374,248 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2018/06/12 08:57:16 | 019,790,760 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2018/03/03 05:47:56 | 001,005,056 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2018/03/03 05:32:42 | 000,779,776 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2014/10/29 02:16:01 | 000,512,512 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== LOP Check ==========[/color]

[2013/11/18 00:20:03 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\ClassicShell
[2013/11/18 00:20:03 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\ClassicShell
[2017/11/11 22:20:12 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Advanced Chemistry Development
[2018/07/12 13:11:41 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Apowersoft
[2017/11/07 16:31:29 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\AVAST Software
[2018/02/26 17:37:57 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Avast Tuneup
[2018/08/05 21:22:14 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\BitTorrent
[2017/11/15 16:21:19 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\ChemLab
[2018/05/11 00:50:54 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\ClassicShell
[2018/03/04 22:35:13 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\com.prezi.PreziDesktop
[2018/08/07 04:25:49 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\DMCache
[2018/05/30 02:18:17 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\IDM
[2018/03/10 00:13:23 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\ioloGovernor
[2017/11/18 23:47:16 | 000,000,000 | -HSD | M] -- C:\Users\HIGH TECH\AppData\Roaming\Latas
[2018/06/08 02:07:35 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\men-ges-notes-nativefier-19a012
[2018/05/21 13:12:03 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\men_ges_notes
[2017/11/22 11:37:39 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\National Instruments
[2018/06/22 14:58:51 | 000,000,000 | -H-D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Obsidium
[2017/11/10 20:35:05 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Opera Software
[2017/11/18 23:06:53 | 000,000,000 | -HSD | M] -- C:\Users\HIGH TECH\AppData\Roaming\Pr
[2017/12/18 21:15:23 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Regressi
[2018/04/08 00:14:36 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Rizonesoft
[2018/05/12 22:52:06 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Stardock
[2018/08/07 12:29:18 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\TeraCopy
[2017/11/07 20:59:08 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\URSoft
[2017/11/22 20:55:36 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\uTorrent
[2017/12/25 19:44:28 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Xilisoft
[2018/01/08 17:51:12 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\ZHP

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Custom Scans ==========[/color]

[color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color]
[2016/08/27 19:26:03 | 002,411,048 | ---- | M] (Microsoft Corporation) MD5=042216FBB8B0CCC7402C3C77E58E1BC9 -- C:\Windows\SysWOW64\explorer.exe
[2016/08/27 19:26:03 | 002,411,048 | ---- | M] (Microsoft Corporation) MD5=042216FBB8B0CCC7402C3C77E58E1BC9 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.18460_none_4cd924758207ca59\explorer.exe
[2018/01/05 21:05:02 | 000,190,776 | ---- | M] () MD5=091A7746F84619EFBF032A7DB496AC64 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.18231_none_4cfa90b781ee958f\explorer.exe
[2018/01/05 21:04:47 | 000,374,657 | ---- | M] () MD5=1068DC9890F911434C2257B0969E7178 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17031_none_4cfaa3b381ee81a0\explorer.exe
[2018/01/04 16:58:29 | 000,233,035 | ---- | M] () MD5=551F8CA17B9F89A458C4B8603C9BC300 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.18231_none_42a5e6654d8dd394\explorer.exe
[2018/01/05 21:04:43 | 000,367,045 | ---- | M] () MD5=71202252FACDFEF17C29B3ACE9CC8D45 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16441_none_4ceff22781f6788c\explorer.exe
[2018/01/04 16:58:23 | 000,437,160 | ---- | M] () MD5=7685FBC4A4EAAD972CC0D0ED017284FF -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17039_none_42adfbb14d868a5d\explorer.exe
[2018/01/04 16:58:26 | 000,323,910 | ---- | M] () MD5=AD796ED2EB4770B88AF4DBF02941EF42 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_42bfa1f94d79e1bb\explorer.exe
[2018/01/05 21:04:52 | 000,374,488 | ---- | M] () MD5=B90FB0AF6EE4A4D925AEF56B73C75836 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17039_none_4d02a60381e74c58\explorer.exe
[2018/01/04 16:58:18 | 000,430,192 | ---- | M] () MD5=CC7A472A27D682693E27CDCCC3DDC9C1 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16441_none_429b47d54d95b691\explorer.exe
[2016/08/27 20:44:40 | 002,755,504 | ---- | M] (Microsoft Corporation) MD5=ED6B4C95E2A6D67480B9DBB8A8E7D9B4 -- C:\Windows\explorer.exe
[2016/08/27 20:44:40 | 002,755,504 | ---- | M] (Microsoft Corporation) MD5=ED6B4C95E2A6D67480B9DBB8A8E7D9B4 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.18460_none_42847a234da7085e\explorer.exe
[2018/01/05 21:04:57 | 000,259,346 | ---- | M] () MD5=EDD864152678F57FAFFE400F64DC6FD6 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_4d144c4b81daa3b6\explorer.exe
[2018/01/04 16:58:20 | 000,437,693 | ---- | M] () MD5=F531B838ADA5056655A664521624A3EF -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17031_none_42a5f9614d8dbfa5\explorer.exe

[color=#A23BEC]< MD5 for: SERVICES.EXE >[/color]
[2018/01/05 19:04:06 | 000,101,307 | ---- | M] () MD5=66E13F40470CC0DFA280D040BB1486F8 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.3.9600.16384_none_2fd72579d09a45e9\services.exe
[2018/01/05 19:04:07 | 000,073,764 | ---- | M] () MD5=AB48952896280CE4CF1048334F6463DC -- C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.3.9600.17415_none_3023c055d060b271\services.exe
[2015/04/08 23:55:21 | 000,410,128 | ---- | M] (Microsoft Corporation) MD5=E0C7813A97CA7947FF5C18A8F3B61A45 -- C:\Windows\SysNative\services.exe
[2015/04/08 23:55:21 | 000,410,128 | ---- | M] (Microsoft Corporation) MD5=E0C7813A97CA7947FF5C18A8F3B61A45 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.3.9600.17794_none_2fcc465dd0a27017\services.exe

[color=#A23BEC]< MD5 for: SVCHOST.EXE >[/color]
[2018/01/05 22:25:25 | 000,007,517 | ---- | M] () MD5=73AA583D4FB0F05C313B38C091D94804 -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_4a5b1e2820e75323\svchost.exe
[2018/01/05 19:09:58 | 000,007,559 | ---- | M] () MD5=CFE97816CBBEF783FD8634109F1877D2 -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_a679b9abd944c459\svchost.exe
[2014/10/29 04:17:51 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\SysWOW64\svchost.exe
[2014/10/29 04:17:51 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.17415_none_4aa7b90420adbfab\svchost.exe
[2014/10/29 05:11:20 | 000,038,792 | ---- | M] (Microsoft Corporation) MD5=E3A2AD05E24105B35E986CF9CB38EC47 -- C:\Windows\SysNative\svchost.exe
[2014/10/29 05:11:20 | 000,038,792 | ---- | M] (Microsoft Corporation) MD5=E3A2AD05E24105B35E986CF9CB38EC47 -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.17415_none_a6c65487d90b30e1\svchost.exe

[color=#A23BEC]< MD5 for: USERINIT.EXE >[/color]
[2018/01/05 19:33:24 | 000,002,671 | ---- | M] () MD5=061AC3BD7ADC5DCBA6AC0F23895266F8 -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_cce71a20a5a6fe7f\userinit.exe
[2018/01/05 22:33:26 | 000,004,269 | ---- | M] () MD5=1AE98168631581DE1343C3A87A6CBCA9 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_70c87e9ced498d49\userinit.exe
[2014/10/29 02:28:08 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=5C131534A3EA4A461A793FB507A8004F -- C:\Windows\SysNative\userinit.exe
[2014/10/29 02:28:08 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=5C131534A3EA4A461A793FB507A8004F -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.17415_none_cd33b4fca56d6b07\userinit.exe
[2014/10/29 02:05:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\SysWOW64\userinit.exe
[2014/10/29 02:05:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.17415_none_71151978ed0ff9d1\userinit.exe

[color=#A23BEC]< MD5 for: WININIT.EXE >[/color]
[2018/01/05 19:38:52 | 000,019,125 | ---- | M] () MD5=13FD442D1426CE3B6FC42F6A0048BBB5 -- C:\Windows\WinSxS\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.3.9600.17415_none_21fdb3b5d80e199e\wininit.exe
[2018/01/05 19:38:52 | 000,028,040 | ---- | M] () MD5=BA376B69D9C6C33B06892FC9FF0D7A99 -- C:\Windows\WinSxS\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.3.9600.16384_none_21b118d9d847ad16\wininit.exe
[2017/01/14 18:49:25 | 000,146,944 | ---- | M] (Microsoft Corporation) MD5=D9516405E05F24EDCD90B1988FAF3948 -- C:\Windows\SysNative\wininit.exe
[2017/01/14 18:49:25 | 000,146,944 | ---- | M] (Microsoft Corporation) MD5=D9516405E05F24EDCD90B1988FAF3948 -- C:\Windows\WinSxS\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.3.9600.18577_none_21bebfdfd83d0aba\wininit.exe

[color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
[2018/02/19 16:52:42 | 000,077,011 | ---- | M] () MD5=1945647BBEF9AFD5B14466F18427A863 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17415_none_60cdfbfda8aeeef1\winlogon.exe
[2018/02/19 16:52:41 | 000,103,219 | ---- | M] () MD5=30642260E2185DE624D18BFE3F7A9D2B -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17031_none_60b45365a8c2ccdb\winlogon.exe
[2018/01/02 05:32:07 | 000,571,392 | ---- | M] (Microsoft Corporation) MD5=4294D7AD504EA206A4A03DB29311B6C2 -- C:\Windows\SysNative\winlogon.exe
[2018/01/02 05:32:07 | 000,571,392 | ---- | M] (Microsoft Corporation) MD5=4294D7AD504EA206A4A03DB29311B6C2 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.18895_none_60776d6da8efdcb6\winlogon.exe
[2018/02/19 16:52:40 | 000,104,341 | ---- | M] () MD5=528750FF496A411EBE452B96E12E6EDD -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.16384_none_60816121a8e88269\winlogon.exe

[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]

[color=#A23BEC]< %ALLUSERSPROFILE%\Application Data\*. >[/color]

[color=#A23BEC]< %ALLUSERSPROFILE%\Application Data\*.exe /s >[/color]

[color=#A23BEC]< %APPDATA%\*. >[/color]
[2018/08/05 22:39:08 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Adobe
[2017/11/11 22:20:12 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Advanced Chemistry Development
[2018/07/12 13:11:41 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Apowersoft
[2017/11/07 16:31:29 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\AVAST Software
[2018/02/26 17:37:57 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Avast Tuneup
[2018/07/26 08:21:33 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\AVS4YOU
[2018/08/05 21:22:14 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\BitTorrent
[2017/11/15 16:21:19 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\ChemLab
[2018/05/11 00:50:54 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\ClassicShell
[2018/03/04 22:35:13 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\com.prezi.PreziDesktop
[2018/08/07 04:25:49 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\DMCache
[2013/11/18 00:30:09 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Identities
[2018/05/30 02:18:17 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\IDM
[2018/03/10 00:13:23 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\ioloGovernor
[2017/11/18 23:47:16 | 000,000,000 | -HSD | M] -- C:\Users\HIGH TECH\AppData\Roaming\Latas
[2018/01/06 19:45:54 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Lavasoft
[2013/11/19 20:50:11 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Macromedia
[2018/06/08 02:07:35 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\men-ges-notes-nativefier-19a012
[2018/05/21 13:12:03 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\men_ges_notes
[2018/07/06 17:54:08 | 000,000,000 | --SD | M] -- C:\Users\HIGH TECH\AppData\Roaming\Microsoft
[2017/11/16 22:33:55 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Mozilla
[2017/11/22 11:37:39 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\National Instruments
[2017/11/20 21:23:21 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Nero
[2018/06/22 14:58:51 | 000,000,000 | -H-D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Obsidium
[2017/11/10 20:35:05 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Opera Software
[2017/11/18 23:06:53 | 000,000,000 | -HSD | M] -- C:\Users\HIGH TECH\AppData\Roaming\Pr
[2017/12/18 21:15:23 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Regressi
[2018/04/08 00:14:36 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Rizonesoft
[2018/02/26 18:11:48 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Skype
[2018/05/12 22:52:06 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Stardock
[2017/11/11 21:41:22 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Sun
[2018/01/07 18:06:32 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\SUPERAntiSpyware.com
[2018/08/07 12:29:18 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\TeraCopy
[2017/11/07 20:59:08 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\URSoft
[2017/11/22 20:55:36 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\uTorrent
[2018/08/05 17:33:27 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\vlc
[2017/11/06 22:12:37 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\WinRAR
[2017/12/25 19:44:28 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\Xilisoft
[2018/01/08 17:51:12 | 000,000,000 | ---D | M] -- C:\Users\HIGH TECH\AppData\Roaming\ZHP

[color=#A23BEC]< %APPDATA%\*.exe /s >[/color]
[2018/06/22 14:21:19 | 002,154,176 | ---- | M] (BitTorrent Inc.) -- C:\Users\HIGH TECH\AppData\Roaming\BitTorrent\BitTorrent.exe
[2017/12/03 12:02:48 | 002,153,928 | ---- | M] (BitTorrent Inc.) -- C:\Users\HIGH TECH\AppData\Roaming\BitTorrent\updates\7.10.0_43917.exe
[2018/02/27 09:50:00 | 002,151,616 | ---- | M] (BitTorrent Inc.) -- C:\Users\HIGH TECH\AppData\Roaming\BitTorrent\updates\7.10.3_44359.exe
[2018/06/22 14:21:19 | 002,154,176 | ---- | M] (BitTorrent Inc.) -- C:\Users\HIGH TECH\AppData\Roaming\BitTorrent\updates\7.10.3_44495.exe
[2017/12/03 12:03:15 | 000,396,992 | ---- | M] (BitTorrent Inc.) -- C:\Users\HIGH TECH\AppData\Roaming\BitTorrent\updates\7.10.0_43917\bittorrentie.exe
[2018/02/27 10:14:38 | 000,396,992 | ---- | M] (BitTorrent Inc.) -- C:\Users\HIGH TECH\AppData\Roaming\BitTorrent\updates\7.10.3_44359\bittorrentie.exe
[2018/07/05 10:36:23 | 000,398,016 | ---- | M] (BitTorrent Inc.) -- C:\Users\HIGH TECH\AppData\Roaming\BitTorrent\updates\7.10.3_44495\bittorrentie.exe
[2018/06/18 00:04:31 | 000,881,314 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\LBP2900_R150_V330_W64_uk_FR_1._1068\LBP2900_R150_V330_W64_uk_FR_1..exe5
[2018/06/18 00:04:31 | 000,954,148 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\LBP2900_R150_V330_W64_uk_FR_1._1068\LBP2900_R150_V330_W64_uk_FR_1..exe7
[2018/06/18 00:04:31 | 000,870,012 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\LBP2900_R150_V330_W64_uk_FR_1._1068\LBP2900_R150_V330_W64_uk_FR_1..exe6
[2018/06/18 00:04:31 | 000,711,324 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\LBP2900_R150_V330_W64_uk_FR_1._1068\LBP2900_R150_V330_W64_uk_FR_1..exe8
[2018/06/18 00:04:31 | 000,951,484 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\LBP2900_R150_V330_W64_uk_FR_1._1068\LBP2900_R150_V330_W64_uk_FR_1..exe4
[2018/06/18 00:03:42 | 000,365,010 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\LBP2900_R150_V330_W64_uk_FR_1._1068\LBP2900_R150_V330_W64_uk_FR_1..exe
[2018/06/18 00:04:31 | 001,599,339 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\LBP2900_R150_V330_W64_uk_FR_1._1068\LBP2900_R150_V330_W64_uk_FR_1..exe1
[2018/06/18 00:04:30 | 001,098,395 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\LBP2900_R150_V330_W64_uk_FR_1._1068\LBP2900_R150_V330_W64_uk_FR_1..exe2
[2018/06/18 00:04:31 | 000,798,251 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\LBP2900_R150_V330_W64_uk_FR_1._1068\LBP2900_R150_V330_W64_uk_FR_1..exe3
[2017/11/16 18:52:40 | 000,033,333 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\Tracker-4.11.0-windows-install_18\Tracker-4.11.0-windows-install.exe6
[2017/11/16 18:52:38 | 000,012,333 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\Tracker-4.11.0-windows-install_18\Tracker-4.11.0-windows-install.exe7
[2017/11/16 18:52:40 | 000,012,334 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\Tracker-4.11.0-windows-install_18\Tracker-4.11.0-windows-install.exe4
[2017/11/16 18:52:39 | 000,041,794 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\Tracker-4.11.0-windows-install_18\Tracker-4.11.0-windows-install.exe
[2017/11/16 18:52:36 | 000,003,934 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\Tracker-4.11.0-windows-install_18\Tracker-4.11.0-windows-install.exe1
[2017/11/16 18:52:40 | 000,045,932 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\Tracker-4.11.0-windows-install_18\Tracker-4.11.0-windows-install.exe2
[2017/11/16 18:52:40 | 000,016,533 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\Tracker-4.11.0-windows-install_18\Tracker-4.11.0-windows-install.exe3
[2017/11/16 18:52:40 | 000,016,533 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\Tracker-4.11.0-windows-install_18\Tracker-4.11.0-windows-install.exe5
[2017/11/16 19:47:13 | 000,189,122 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\UserBenchMark_19\UserBenchMark.exe5
[2017/11/16 19:47:10 | 000,083,822 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\UserBenchMark_19\UserBenchMark.exe7
[2017/11/16 19:47:13 | 000,255,622 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\UserBenchMark_19\UserBenchMark.exe6
[2017/11/16 19:45:56 | 000,282,310 | ---- | M] (UserBenchmark.com) -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\UserBenchMark_19\UserBenchMark.exe
[2017/11/16 19:47:13 | 000,332,523 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\UserBenchMark_19\UserBenchMark.exe1
[2017/11/16 19:47:08 | 000,264,292 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\UserBenchMark_19\UserBenchMark.exe2
[2017/11/16 19:47:10 | 000,066,521 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\UserBenchMark_19\UserBenchMark.exe3
[2017/11/16 19:47:10 | 000,135,321 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\UserBenchMark_19\UserBenchMark.exe4
[2017/11/16 19:47:13 | 000,181,422 | ---- | M] () -- C:\Users\HIGH TECH\AppData\Roaming\IDM\DwnlData\HIGH TECH\UserBenchMark_19\UserBenchMark.exe8

[color=#A23BEC]< %systemroot%\*. /mp /s >[/color]

[color=#A23BEC]< %systemroot%\Tasks\*.* /s >[/color]
[2018/08/07 12:12:05 | 000,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT

[color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]
[2018/06/12 08:57:16 | 019,790,760 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\system32\shell32.dll

[color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color]

[color=#A23BEC]< %systemroot%\system32\drivers\*.sys /lockedfiles >[/color]

[color=#E56717]========== Files - Unicode (All) ==========[/color]
[2017/12/21 13:21:57 | 031,081,356 | ---- | M] ()(C:\Users\HIGH TECH\Documents\?هل سمعتم عن المدينة القديمة المفقودة... - 1.2.3 viva l'algérie?.mp4) -- C:\Users\HIGH TECH\Documents\‫هل سمعتم عن المدينة القديمة المفقودة... - 1.2.3 viva l'algérie‬.mp4
[2017/12/21 13:18:52 | 031,081,356 | ---- | C] ()(C:\Users\HIGH TECH\Documents\?هل سمعتم عن المدينة القديمة المفقودة... - 1.2.3 viva l'algérie?.mp4) -- C:\Users\HIGH TECH\Documents\‫هل سمعتم عن المدينة القديمة المفقودة... - 1.2.3 viva l'algérie‬.mp4
[2017/12/21 00:16:30 | 004,348,709 | ---- | M] ()(C:\Users\HIGH TECH\Documents\?تلاوات قرآنية - عمرك سمعت قارئ يقرأ بمثل هذه النبرة؟؟؟...?.mp4) -- C:\Users\HIGH TECH\Documents\‫تلاوات قرآنية - عمرك سمعت قارئ يقرأ بمثل هذه النبرة؟؟؟...‬.mp4
[2017/12/21 00:15:45 | 004,348,709 | ---- | C] ()(C:\Users\HIGH TECH\Documents\?تلاوات قرآنية - عمرك سمعت قارئ يقرأ بمثل هذه النبرة؟؟؟...?.mp4) -- C:\Users\HIGH TECH\Documents\‫تلاوات قرآنية - عمرك سمعت قارئ يقرأ بمثل هذه النبرة؟؟؟...‬.mp4
[2017/12/21 00:14:53 | 003,630,441 | ---- | M] ()(C:\Users\HIGH TECH\Documents\?تلاوات قرآنية - صلاة العشاء _ ? مسجد...?.mp4) -- C:\Users\HIGH TECH\Documents\‫تلاوات قرآنية - صلاة العشاء _ ⛥ مسجد...‬.mp4
[2017/12/21 00:14:24 | 003,630,441 | ---- | C] ()(C:\Users\HIGH TECH\Documents\?تلاوات قرآنية - صلاة العشاء _ ? مسجد...?.mp4) -- C:\Users\HIGH TECH\Documents\‫تلاوات قرآنية - صلاة العشاء _ ⛥ مسجد...‬.mp4
[2017/11/18 23:06:54 | 000,000,000 | ---D | M](C:\Users\HIGH TECH\AppData\Roaming\App?ata) -- C:\Users\HIGH TECH\AppData\Roaming\Appԁata
[2017/11/18 23:06:54 | 000,000,000 | ---D | M](C:\Users\HIGH TECH\AppData\Roaming\App?ata) -- C:\Users\HIGH TECH\AppData\Roaming\Appԁata
(C:\Users\HIGH TECH\AppData\Roaming\App?ata) -- C:\Users\HIGH TECH\AppData\Roaming\Appԁata

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:1CE11B51

< End of report >