Advertisement
Guest User

aufa

a guest
Apr 28th, 2017
766
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 111.73 KB | None | 0 0
  1. OTL logfile created on: 29/04/2017 2:54:40 - Run 1
  2. OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\GAVA MEDIA\Desktop
  3. 64bit- Enterprise Edition N (Version = 6.2.9200) - Type = NTWorkstation
  4. Internet Explorer (Version = 9.11.9600.16438)
  5. Locale: 00000421 | Country: Indonesia | Language: IND | Date Format: dd/MM/yyyy
  6.  
  7. 3,89 Gb Total Physical Memory | 2,84 Gb Available Physical Memory | 73,02% Memory free
  8. 4,58 Gb Paging File | 3,49 Gb Available in Paging File | 76,21% Paging File free
  9. Paging file location(s): ?:\pagefile.sys [binary data]
  10.  
  11. %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
  12. Drive C: | 116,67 Gb Total Space | 14,40 Gb Free Space | 12,35% Space Free | Partition Type: NTFS
  13. Drive E: | 175,78 Gb Total Space | 13,22 Gb Free Space | 7,52% Space Free | Partition Type: NTFS
  14. Drive F: | 172,79 Gb Total Space | 11,75 Gb Free Space | 6,80% Space Free | Partition Type: NTFS
  15.  
  16. Computer Name: ASUS | User Name: GAVA MEDIA | Logged in as Administrator.
  17. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
  18. Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
  19.  
  20. [color=#E56717]========== Processes (SafeList) ==========[/color]
  21.  
  22. PRC - C:\Users\GAVA MEDIA\Desktop\OTL.exe (OldTimer Tools)
  23. PRC - C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe (Google Inc.)
  24. PRC - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH)
  25. PRC - C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe (AnchorFree Inc.)
  26. PRC - C:\Program Files\ByteFence\rtop\bin\rtop_bg.exe ()
  27. PRC - C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe ()
  28. PRC - C:\Program Files (x86)\SMADAV\SMΔRTP.exe (Smadsoft)
  29. PRC - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software LLC)
  30. PRC - C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (Tonec Inc.)
  31. PRC - C:\Users\GAVA MEDIA\AppData\Local\TECHP-Browser\prtsvc.exe ()
  32. PRC - C:\Program Files (x86)\ArcGIS\License10.3\bin\ARCGIS.exe (ESRI)
  33. PRC - C:\Program Files (x86)\ArcGIS\License10.3\bin\lmgrd.exe (Flexera Software LLC)
  34. PRC - C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
  35. PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTek Computer Inc.)
  36. PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
  37. PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUSTek Computer Inc.)
  38. PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.)
  39. PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
  40. PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
  41.  
  42.  
  43. [color=#E56717]========== Modules (No Company Name) ==========[/color]
  44.  
  45. MOD - C:\Program Files\ByteFence\rtop\bin\rtop_bg.exe ()
  46. MOD - C:\Program Files (x86)\SMADAV\SM?RTP.exe ()
  47. MOD - C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll ()
  48.  
  49.  
  50. [color=#E56717]========== Services (SafeList) ==========[/color]
  51.  
  52. SRV:[b]64bit:[/b] - (TrueKeyServiceHelper) -- C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe (McAfee, Inc.)
  53. SRV:[b]64bit:[/b] - (TrueKeyScheduler) -- C:\Program Files\TrueKey\McTkSchedulerService.exe (McAfee, Inc.)
  54. SRV:[b]64bit:[/b] - (TrueKey) -- C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe (McAfee, Inc.)
  55. SRV:[b]64bit:[/b] - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\3.11.523\McCHSvc.exe (McAfee, Inc.)
  56. SRV:[b]64bit:[/b] - (rtop) -- C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe ()
  57. SRV:[b]64bit:[/b] - (ByteFenceService) -- C:\Program Files\ByteFence\ByteFenceService.exe (Byte Technologies LLC)
  58. SRV:[b]64bit:[/b] - (workfolderssvc) -- C:\Windows\SysNative\workfolderssvc.dll (Microsoft Corporation)
  59. SRV:[b]64bit:[/b] - (AppReadiness) -- C:\Windows\SysNative\AppReadiness.dll (Microsoft Corporation)
  60. SRV:[b]64bit:[/b] - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)
  61. SRV:[b]64bit:[/b] - (WSService) -- C:\Windows\SysNative\WSService.dll (Microsoft Corporation)
  62. SRV:[b]64bit:[/b] - (AppXSvc) -- C:\Windows\SysNative\AppXDeploymentServer.dll (Microsoft Corporation)
  63. SRV:[b]64bit:[/b] - (wlidsvc) -- C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
  64. SRV:[b]64bit:[/b] - (Wcmsvc) -- C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
  65. SRV:[b]64bit:[/b] - (lfsvc) -- C:\Windows\SysNative\GeofenceMonitorService.dll (Microsoft Corporation)
  66. SRV:[b]64bit:[/b] - (BrokerInfrastructure) -- C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
  67. SRV:[b]64bit:[/b] - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
  68. SRV:[b]64bit:[/b] - (MsKeyboardFilter) -- C:\Windows\SysNative\KeyboardFilterSvc.dll (Microsoft Corporation)
  69. SRV:[b]64bit:[/b] - (WdNisSvc) -- C:\Program Files\Windows Defender\NisSrv.exe (Microsoft Corporation)
  70. SRV:[b]64bit:[/b] - (WinDefend) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
  71. SRV:[b]64bit:[/b] - (PrintNotify) -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
  72. SRV:[b]64bit:[/b] - (WEPHOSTSVC) -- C:\Windows\SysNative\wephostsvc.dll (Microsoft Corporation)
  73. SRV:[b]64bit:[/b] - (EFS) -- C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
  74. SRV:[b]64bit:[/b] - (WiaRpc) -- C:\Windows\SysNative\wiarpc.dll (Microsoft Corporation)
  75. SRV:[b]64bit:[/b] - (svsvc) -- C:\Windows\SysNative\svsvc.dll (Microsoft Corporation)
  76. SRV:[b]64bit:[/b] - (fhsvc) -- C:\Windows\SysNative\fhsvc.dll (Microsoft Corporation)
  77. SRV:[b]64bit:[/b] - (NcaSvc) -- C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
  78. SRV:[b]64bit:[/b] - (vmicvss) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
  79. SRV:[b]64bit:[/b] - (vmictimesync) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
  80. SRV:[b]64bit:[/b] - (vmicshutdown) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
  81. SRV:[b]64bit:[/b] - (vmicrdv) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
  82. SRV:[b]64bit:[/b] - (vmickvpexchange) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
  83. SRV:[b]64bit:[/b] - (vmicheartbeat) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
  84. SRV:[b]64bit:[/b] - (vmicguestinterface) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
  85. SRV:[b]64bit:[/b] - (LSM) -- C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
  86. SRV:[b]64bit:[/b] - (smphost) -- C:\Windows\SysNative\smphost.dll (Microsoft Corporation)
  87. SRV:[b]64bit:[/b] - (Netlogon) -- C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
  88. SRV:[b]64bit:[/b] - (SystemEventsBroker) -- C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
  89. SRV:[b]64bit:[/b] - (ScDeviceEnum) -- C:\Windows\SysNative\ScDeviceEnum.dll (Microsoft Corporation)
  90. SRV:[b]64bit:[/b] - (KeyIso) -- C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
  91. SRV:[b]64bit:[/b] - (TimeBroker) -- C:\Windows\SysNative\TimeBrokerServer.dll (Microsoft Corporation)
  92. SRV:[b]64bit:[/b] - (netprofm) -- C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
  93. SRV:[b]64bit:[/b] - (NcbService) -- C:\Windows\SysNative\ncbservice.dll (Microsoft Corporation)
  94. SRV:[b]64bit:[/b] - (VaultSvc) -- C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
  95. SRV:[b]64bit:[/b] - (DeviceAssociationService) -- C:\Windows\SysNative\das.dll (Microsoft Corporation)
  96. SRV:[b]64bit:[/b] - (AudioEndpointBuilder) -- C:\Windows\SysNative\AudioEndpointBuilder.dll (Microsoft Corporation)
  97. SRV:[b]64bit:[/b] - (DsmSvc) -- C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
  98. SRV:[b]64bit:[/b] - (NcdAutoSetup) -- C:\Windows\SysNative\NcdAutoSetup.dll (Microsoft Corporation)
  99. SRV:[b]64bit:[/b] - (Intel(R) -- C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe (Intel(R) Corporation)
  100. SRV:[b]64bit:[/b] - (Intel(R) -- C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe (Intel(R) Corporation)
  101. SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
  102. SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
  103. SRV - (TeamViewer) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH)
  104. SRV - (hshld) -- C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe (AnchorFree Inc.)
  105. SRV - (uSHAREitSvc) -- C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.Service.exe (SHAREit Technologies Co.Ltd)
  106. SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software LLC)
  107. SRV - (prtsvc) -- C:\Users\GAVA MEDIA\AppData\Local\TECHP-Browser\prtsvc.exe ()
  108. SRV - (ArcGIS License Manager) -- C:\Program Files (x86)\ArcGIS\License10.3\bin\lmgrd.exe (Flexera Software LLC)
  109. SRV - (cphs) -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
  110. SRV - (lfsvc) -- C:\Windows\SysWOW64\GeofenceMonitorService.dll (Microsoft Corporation)
  111. SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUSTek Computer Inc.)
  112. SRV - (PrintNotify) -- C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
  113. SRV - (StorSvc) -- C:\Windows\SysWOW64\StorSvc.dll (Microsoft Corporation)
  114. SRV - (smphost) -- C:\Windows\SysWOW64\smphost.dll (Microsoft Corporation)
  115. SRV - (ICCS) -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Intel Corporation)
  116. SRV - (ATKGFNEXSrv) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
  117. SRV - (Adobe Version Cue CS3) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (Adobe Systems Incorporated)
  118.  
  119.  
  120. [color=#E56717]========== Driver Services (SafeList) ==========[/color]
  121.  
  122. DRV:[b]64bit:[/b] - (MBAMSwissArmy) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys (Malwarebytes)
  123. DRV:[b]64bit:[/b] - (IntelHaxm) -- C:\Windows\SysNative\drivers\IntelHaxm.sys (Intel Corporation)
  124. DRV:[b]64bit:[/b] - (IDMWFP) -- C:\Windows\SysNative\drivers\idmwfp.sys (Tonec Inc.)
  125. DRV:[b]64bit:[/b] - (ssudserd) -- C:\Windows\SysNative\drivers\ssudserd.sys (Samsung Electronics Co., Ltd.)
  126. DRV:[b]64bit:[/b] - (ssudmdm) -- C:\Windows\SysNative\drivers\ssudmdm.sys (Samsung Electronics Co., Ltd.)
  127. DRV:[b]64bit:[/b] - (dg_ssudbus) -- C:\Windows\SysNative\drivers\ssudbus.sys (Samsung Electronics Co., Ltd.)
  128. DRV:[b]64bit:[/b] - (DFX12) -- C:\Windows\SysNative\drivers\dfx12x64.sys (Windows (R) Win 7 DDK provider)
  129. DRV:[b]64bit:[/b] - (XQHDrv) -- C:\Windows\SysNative\drivers\XQHDrv.sys (BigNox Corporation)
  130. DRV:[b]64bit:[/b] - (DFX11_1) -- C:\Windows\SysNative\drivers\dfx11_1x64.sys (Windows (R) Win 7 DDK provider)
  131. DRV:[b]64bit:[/b] - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
  132. DRV:[b]64bit:[/b] - (taphss6) -- C:\Windows\SysNative\drivers\taphss6.sys (Anchorfree Inc.)
  133. DRV:[b]64bit:[/b] - (ATP) -- C:\Windows\SysNative\drivers\AsusTP.sys (ASUS Corporation)
  134. DRV:[b]64bit:[/b] - (IntcDAud) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation)
  135. DRV:[b]64bit:[/b] - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
  136. DRV:[b]64bit:[/b] - (TXEIx64) -- C:\Windows\SysNative\drivers\TXEIx64.sys (Intel Corporation)
  137. DRV:[b]64bit:[/b] - (RTL8168) -- C:\Windows\SysNative\drivers\Rt630x64.sys (Realtek )
  138. DRV:[b]64bit:[/b] - (athr) -- C:\Windows\SysNative\drivers\athwbx.sys (Qualcomm Atheros Communications, Inc.)
  139. DRV:[b]64bit:[/b] - (intaud_WaveExtensible) -- C:\Windows\SysNative\drivers\intelaud.sys (Intel Corporation)
  140. DRV:[b]64bit:[/b] - (iwdbus) -- C:\Windows\SysNative\drivers\iwdbus.sys (Intel Corporation)
  141. DRV:[b]64bit:[/b] - (spaceport) -- C:\Windows\SysNative\drivers\spaceport.sys (Microsoft Corporation)
  142. DRV:[b]64bit:[/b] - (USBXHCI) -- C:\Windows\SysNative\drivers\USBXHCI.SYS (Microsoft Corporation)
  143. DRV:[b]64bit:[/b] - (stornvme) -- C:\Windows\SysNative\drivers\stornvme.sys (Microsoft Corporation)
  144. DRV:[b]64bit:[/b] - (intelpep) -- C:\Windows\SysNative\drivers\intelpep.sys (Microsoft Corporation)
  145. DRV:[b]64bit:[/b] - (USBHUB3) -- C:\Windows\SysNative\drivers\USBHUB3.SYS (Microsoft Corporation)
  146. DRV:[b]64bit:[/b] - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
  147. DRV:[b]64bit:[/b] - (VerifierExt) -- C:\Windows\SysNative\drivers\VerifierExt.sys (Microsoft Corporation)
  148. DRV:[b]64bit:[/b] - (pdc) -- C:\Windows\SysNative\drivers\pdc.sys (Microsoft Corporation)
  149. DRV:[b]64bit:[/b] - (WFPLWFS) -- C:\Windows\SysNative\drivers\wfplwfs.sys (Microsoft Corporation)
  150. DRV:[b]64bit:[/b] - (iaioi2c) -- C:\Windows\SysNative\drivers\iaioi2ce.sys (Intel Corporation)
  151. DRV:[b]64bit:[/b] - (GPIO) -- C:\Windows\SysNative\drivers\iaiogpioe.sys (Intel Corporation)
  152. DRV:[b]64bit:[/b] - (MBI) -- C:\Windows\SysNative\drivers\MBI.sys (Intel Corporation)
  153. DRV:[b]64bit:[/b] - (HIDSwitch) -- C:\Windows\SysNative\drivers\AsHIDSwitch64.sys (ASUS)
  154. DRV:[b]64bit:[/b] - (kbldfltr) -- C:\Windows\SysNative\drivers\kbldfltr.sys (Microsoft Corporation)
  155. DRV:[b]64bit:[/b] - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
  156. DRV:[b]64bit:[/b] - (Vid) -- C:\Windows\SysNative\drivers\Vid.sys (Microsoft Corporation)
  157. DRV:[b]64bit:[/b] - (vmbusr) -- C:\Windows\SysNative\drivers\vmbusr.sys (Microsoft Corporation)
  158. DRV:[b]64bit:[/b] - (tsusbhub) -- C:\Windows\SysNative\drivers\tsusbhub.sys (Microsoft Corporation)
  159. DRV:[b]64bit:[/b] - (storvsp) -- C:\Windows\SysNative\drivers\storvsp.sys (Microsoft Corporation)
  160. DRV:[b]64bit:[/b] - (vpcivsp) -- C:\Windows\SysNative\drivers\vpcivsp.sys (Microsoft Corporation)
  161. DRV:[b]64bit:[/b] - (Synth3dVsc) -- C:\Windows\SysNative\drivers\Synth3dVsc.sys (Microsoft Corporation)
  162. DRV:[b]64bit:[/b] - (terminpt) -- C:\Windows\SysNative\drivers\terminpt.sys (Microsoft Corporation)
  163. DRV:[b]64bit:[/b] - (condrv) -- C:\Windows\SysNative\drivers\condrv.sys (Microsoft Corporation)
  164. DRV:[b]64bit:[/b] - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
  165. DRV:[b]64bit:[/b] - (dam) -- C:\Windows\SysNative\drivers\dam.sys (Microsoft Corporation)
  166. DRV:[b]64bit:[/b] - (acpiex) -- C:\Windows\SysNative\drivers\acpiex.sys (Microsoft Corporation)
  167. DRV:[b]64bit:[/b] - (TPM) -- C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
  168. DRV:[b]64bit:[/b] - (mvumis) -- C:\Windows\SysNative\drivers\mvumis.sys (Marvell Semiconductor, Inc.)
  169. DRV:[b]64bit:[/b] - (GPIOClx0101) -- C:\Windows\SysNative\drivers\msgpioclx.sys (Microsoft Corporation)
  170. DRV:[b]64bit:[/b] - (msgpiowin32) -- C:\Windows\SysNative\drivers\msgpiowin32.sys (Microsoft Corporation)
  171. DRV:[b]64bit:[/b] - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
  172. DRV:[b]64bit:[/b] - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
  173. DRV:[b]64bit:[/b] - (LSI_SSS) -- C:\Windows\SysNative\drivers\lsi_sss.sys (LSI Corporation)
  174. DRV:[b]64bit:[/b] - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
  175. DRV:[b]64bit:[/b] - (LSI_SAS3) -- C:\Windows\SysNative\drivers\lsi_sas3.sys (LSI Corporation)
  176. DRV:[b]64bit:[/b] - (ADP80XX) -- C:\Windows\SysNative\drivers\adp80xx.sys (PMC-Sierra)
  177. DRV:[b]64bit:[/b] - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
  178. DRV:[b]64bit:[/b] - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
  179. DRV:[b]64bit:[/b] - (3ware) -- C:\Windows\SysNative\drivers\3ware.sys (LSI)
  180. DRV:[b]64bit:[/b] - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
  181. DRV:[b]64bit:[/b] - (EhStorTcgDrv) -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys (Microsoft Corporation)
  182. DRV:[b]64bit:[/b] - (EhStorClass) -- C:\Windows\SysNative\drivers\EhStorClass.sys (Microsoft Corporation)
  183. DRV:[b]64bit:[/b] - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
  184. DRV:[b]64bit:[/b] - (VSTXRAID) -- C:\Windows\SysNative\drivers\VSTXRAID.SYS (VIA Corporation)
  185. DRV:[b]64bit:[/b] - (UCX01000) -- C:\Windows\SysNative\drivers\UCX01000.SYS (Microsoft Corporation)
  186. DRV:[b]64bit:[/b] - (UASPStor) -- C:\Windows\SysNative\drivers\uaspstor.sys (Microsoft Corporation)
  187. DRV:[b]64bit:[/b] - (sdstor) -- C:\Windows\SysNative\drivers\sdstor.sys (Microsoft Corporation)
  188. DRV:[b]64bit:[/b] - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology, Inc.)
  189. DRV:[b]64bit:[/b] - (SerCx2) -- C:\Windows\SysNative\drivers\SerCx2.sys (Microsoft Corporation)
  190. DRV:[b]64bit:[/b] - (storahci) -- C:\Windows\SysNative\drivers\storahci.sys (Microsoft Corporation)
  191. DRV:[b]64bit:[/b] - (SpbCx) -- C:\Windows\SysNative\drivers\SpbCx.sys (Microsoft Corporation)
  192. DRV:[b]64bit:[/b] - (SerCx) -- C:\Windows\SysNative\drivers\SerCx.sys (Microsoft Corporation)
  193. DRV:[b]64bit:[/b] - (wpcfltr) -- C:\Windows\SysNative\drivers\wpcfltr.sys (Microsoft Corporation)
  194. DRV:[b]64bit:[/b] - (CLFS) -- C:\Windows\SysNative\drivers\clfs.sys (Microsoft Corporation)
  195. DRV:[b]64bit:[/b] - (ReFS) -- C:\Windows\SysNative\drivers\refs.sys (Microsoft Corporation)
  196. DRV:[b]64bit:[/b] - (UEFI) -- C:\Windows\SysNative\drivers\uefi.sys (Microsoft Corporation)
  197. DRV:[b]64bit:[/b] - (vpci) -- C:\Windows\SysNative\drivers\vpci.sys (Microsoft Corporation)
  198. DRV:[b]64bit:[/b] - (WdFilter) -- C:\Windows\SysNative\drivers\WdFilter.sys (Microsoft Corporation)
  199. DRV:[b]64bit:[/b] - (WdNisDrv) -- C:\Windows\SysNative\drivers\WdNisDrv.sys (Microsoft Corporation)
  200. DRV:[b]64bit:[/b] - (WdBoot) -- C:\Windows\SysNative\drivers\WdBoot.sys (Microsoft Corporation)
  201. DRV:[b]64bit:[/b] - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
  202. DRV:[b]64bit:[/b] - (ahcache) -- C:\Windows\SysNative\drivers\ahcache.sys (Microsoft Corporation)
  203. DRV:[b]64bit:[/b] - (BasicDisplay) -- C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation)
  204. DRV:[b]64bit:[/b] - (BasicRender) -- C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation)
  205. DRV:[b]64bit:[/b] - (HyperVideo) -- C:\Windows\SysNative\drivers\HyperVideo.sys (Microsoft Corporation)
  206. DRV:[b]64bit:[/b] - (mshidumdf) -- C:\Windows\SysNative\drivers\mshidumdf.sys (Microsoft Corporation)
  207. DRV:[b]64bit:[/b] - (acpitime) -- C:\Windows\SysNative\drivers\acpitime.sys (Microsoft Corporation)
  208. DRV:[b]64bit:[/b] - (acpipagr) -- C:\Windows\SysNative\drivers\acpipagr.sys (Microsoft Corporation)
  209. DRV:[b]64bit:[/b] - (BthAvrcpTg) -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys (Microsoft Corporation)
  210. DRV:[b]64bit:[/b] - (kdnic) -- C:\Windows\SysNative\drivers\kdnic.sys (Microsoft Corporation)
  211. DRV:[b]64bit:[/b] - (gencounter) -- C:\Windows\SysNative\drivers\vmgencounter.sys (Microsoft Corporation)
  212. DRV:[b]64bit:[/b] - (npsvctrig) -- C:\Windows\SysNative\drivers\npsvctrig.sys (Microsoft Corporation)
  213. DRV:[b]64bit:[/b] - (usb_rndisx) -- C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
  214. DRV:[b]64bit:[/b] - (bthhfhid) -- C:\Windows\SysNative\drivers\BthhfHid.sys (Microsoft Corporation)
  215. DRV:[b]64bit:[/b] - (hyperkbd) -- C:\Windows\SysNative\drivers\hyperkbd.sys (Microsoft Corporation)
  216. DRV:[b]64bit:[/b] - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
  217. DRV:[b]64bit:[/b] - (BthHFEnum) -- C:\Windows\SysNative\drivers\bthhfenum.sys (Microsoft Corporation)
  218. DRV:[b]64bit:[/b] - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
  219. DRV:[b]64bit:[/b] - (hidi2c) -- C:\Windows\SysNative\drivers\hidi2c.sys (Microsoft Corporation)
  220. DRV:[b]64bit:[/b] - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
  221. DRV:[b]64bit:[/b] - (netvsc) -- C:\Windows\SysNative\drivers\netvsc63.sys (Microsoft Corporation)
  222. DRV:[b]64bit:[/b] - (NdisVirtualBus) -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys (Microsoft Corporation)
  223. DRV:[b]64bit:[/b] - (NdisImPlatform) -- C:\Windows\SysNative\drivers\NdisImPlatform.sys (Microsoft Corporation)
  224. DRV:[b]64bit:[/b] - (MsLldp) -- C:\Windows\SysNative\drivers\mslldp.sys (Microsoft Corporation)
  225. DRV:[b]64bit:[/b] - (Ndu) -- C:\Windows\SysNative\drivers\Ndu.sys (Microsoft Corporation)
  226. DRV:[b]64bit:[/b] - (FxPPM) -- C:\Windows\SysNative\drivers\fxppm.sys (Microsoft Corporation)
  227. DRV:[b]64bit:[/b] - (bcmfn2) -- C:\Windows\SysNative\drivers\bcmfn2.sys (Windows (R) Win 7 DDK provider)
  228. DRV:[b]64bit:[/b] - (iaStorAV) -- C:\Windows\SysNative\drivers\iaStorAV.sys (Intel Corporation)
  229. DRV:[b]64bit:[/b] - (iaLPSSi_GPIO) -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys (Intel Corporation)
  230. DRV:[b]64bit:[/b] - (iaLPSSi_I2C) -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys (Intel Corporation)
  231. DRV:[b]64bit:[/b] - (RSBASTOR) -- C:\Windows\SysNative\drivers\RtsBaStor.sys (Realtek Semiconductor Corp.)
  232. DRV:[b]64bit:[/b] - (netr28ux) -- C:\Windows\SysNative\drivers\netr28ux.sys (Ralink Technology Corp.)
  233. DRV:[b]64bit:[/b] - (kbfiltr) -- C:\Windows\SysNative\drivers\kbfiltr.sys ( )
  234. DRV:[b]64bit:[/b] - (tapoas) -- C:\Windows\SysNative\drivers\tapoas.sys (The OpenVPN Project)
  235. DRV:[b]64bit:[/b] - (tap0901) -- C:\Windows\SysNative\drivers\tap0901.sys (The OpenVPN Project)
  236. DRV:[b]64bit:[/b] - (REN2CAP_DRIVER) -- C:\Windows\SysNative\drivers\ren2cap.sys ()
  237. DRV:[b]64bit:[/b] - (ssadserd) -- C:\Windows\SysNative\drivers\ssadserd.sys (MCCI Corporation)
  238. DRV:[b]64bit:[/b] - (ssadbus) -- C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
  239. DRV - (AFTrafMgr1.2) -- C:\Program Files (x86)\Hotspot Shield\bin\TrafMgr_1_2_64.sys (AnchorFree Inc.)
  240. DRV - (hwinterface) -- C:\Windows\SysWOW64\drivers\hwinterface.sys (Logix4u)
  241. DRV - (XQHDrv) -- C:\Windows\SysWOW64\drivers\XQHDrv.sys (BigNox Corporation)
  242. DRV - (ATKWMIACPIIO) -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys (ASUSTek Computer Inc.)
  243. DRV - (ASMMAP64) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys (ASUS)
  244.  
  245.  
  246. [color=#E56717]========== Standard Registry (All) ==========[/color]
  247.  
  248.  
  249. [color=#E56717]========== Internet Explorer ==========[/color]
  250.  
  251. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
  252. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
  253. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
  254. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
  255. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
  256. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.com
  257. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
  258. IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
  259. IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3C}
  260. IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  261. IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{5e7797ae-5ca1-4b50-95d8-97e746340487}: "URL" = [String data over 1000 bytes]
  262. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
  263. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
  264. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
  265. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
  266. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
  267. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.com
  268. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
  269. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
  270. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://smartsputnik.ru/?ri=1&uid=eac954ae850660e68614d890f9e9b94e&q=
  271. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://smartsputnik.ru/?ri=1&uid=eac954ae850660e68614d890f9e9b94e&q=
  272. IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3C}
  273. IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
  274. IE - HKLM\..\SearchScopes\{5e7797ae-5ca1-4b50-95d8-97e746340487}: "URL" = [String data over 1000 bytes]
  275.  
  276. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
  277. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
  278. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
  279. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.com
  280. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
  281. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://u.msn.com/id-id/?ocid=iehp
  282. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = id-ID
  283. IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 88 67 D6 A1 78 66 D1 01 [binary data]
  284. IE - HKCU\..\URLSearchHook: {0633EE93-D776-472f-A0FF-E1416B8B2E3D} - No CLSID value found
  285. IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
  286. IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3C}
  287. IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" =
  288. IE - HKCU\..\SearchScopes\{5e7797ae-5ca1-4b50-95d8-97e746340487}: "URL" = [String data over 1000 bytes]
  289. IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
  290. IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
  291.  
  292. [color=#E56717]========== FireFox ==========[/color]
  293.  
  294. FF - prefs.js..browser.search.countryCode: "ID"
  295. FF - prefs.js..browser.search.region: "ID"
  296. FF - prefs.js..browser.search.selectedEngine: "Palikan"
  297. FF - prefs.js..browser.startup.homepage: "https://www.malwarebytes.org/restorebrowser//?f=1&a=plk_coinisrs_17_08_ssg01&cd=2XzuyEtN2Y1L1Qzu0A0C0ByDyB0Dzy0B0E0D0BtB0DtDtA0BtN0D0Tzu0StCzzyByBtN1L2XzutAtFtByDtFtCtFyDtBtN1L1Czu1ByCtN1L1G1B1V1N2Y1L1Qzu2StByByD0BtByBzz0CtGyC0EzztBtGyEyCzy0EtGtAtAtC0BtGtAyDtDyByC0FtBtDtBzytByB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0AtAtAyCtCtC0E0DtG0AyC0EtDtGyEzyzzyDtGzy0A0C0FtGzzyE0C0DtC0A0DtC0AzzyBzz2QtN0A0LzutB&cr=2098784095&ir="
  298. FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:52.0.2
  299. FF - prefs.js..keyword.URL: true
  300. FF - user.js - File not found
  301.  
  302. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll File not found
  303. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.11.2: C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
  304. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.11.2: C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation)
  305. FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
  306. FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll ()
  307. FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
  308. FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
  309. FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
  310. FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
  311. FF - HKLM\Software\MozillaPlugins\@qq.com/npAndroidAssistant: C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll (腾讯公司)
  312. FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.)
  313. FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.)
  314. FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
  315.  
  316. 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 52.0.2\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS
  317. 64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 52.0.2\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS
  318. FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\GAVA MEDIA\AppData\Roaming\IDM\idmmzcc5 [2015/07/02 15:15:05 | 000,000,000 | ---D | M]
  319. FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\GAVA MEDIA\AppData\Roaming\IDM\idmmzcc5 [2015/07/02 15:15:05 | 000,000,000 | ---D | M]
  320.  
  321. [2015/07/08 01:06:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\GAVA MEDIA\AppData\Roaming\Mozilla\Extensions
  322. [2017/04/03 17:19:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\GAVA MEDIA\AppData\Roaming\Mozilla\Firefox\Profiles\w82ciju9.default\extensions
  323. [2017/04/03 17:20:00 | 000,007,704 | ---- | M] () (No name found) -- C:\Users\GAVA MEDIA\AppData\Roaming\Mozilla\Firefox\Profiles\w82ciju9.default\features\{5c5c37aa-e42d-4208-a774-d6ef77059080}\aushelper@mozilla.org.xpi
  324. [2017/04/03 17:20:00 | 000,005,527 | ---- | M] () (No name found) -- C:\Users\GAVA MEDIA\AppData\Roaming\Mozilla\Firefox\Profiles\w82ciju9.default\features\{5c5c37aa-e42d-4208-a774-d6ef77059080}\diagnostics@mozilla.org.xpi
  325. [2017/04/03 17:20:01 | 000,008,857 | ---- | M] () (No name found) -- C:\Users\GAVA MEDIA\AppData\Roaming\Mozilla\Firefox\Profiles\w82ciju9.default\features\{5c5c37aa-e42d-4208-a774-d6ef77059080}\disableSHA1rollout@mozilla.org.xpi
  326. [2017/04/03 17:20:01 | 000,007,195 | ---- | M] () (No name found) -- C:\Users\GAVA MEDIA\AppData\Roaming\Mozilla\Firefox\Profiles\w82ciju9.default\features\{5c5c37aa-e42d-4208-a774-d6ef77059080}\e10srollout@mozilla.org.xpi
  327. [2017/04/03 17:20:01 | 000,005,336 | ---- | M] () (No name found) -- C:\Users\GAVA MEDIA\AppData\Roaming\Mozilla\Firefox\Profiles\w82ciju9.default\features\{5c5c37aa-e42d-4208-a774-d6ef77059080}\hsts-priming@mozilla.org.xpi
  328. [2012/10/01 20:43:54 | 000,034,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll
  329. [2009/12/21 18:34:06 | 000,103,864 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll
  330.  
  331. [color=#E56717]========== Chrome ==========[/color]
  332.  
  333. CHR - Extension: No name found = C:\Users\GAVA MEDIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
  334. CHR - Extension: No name found = C:\Users\GAVA MEDIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
  335. CHR - Extension: No name found = C:\Users\GAVA MEDIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
  336. CHR - Extension: No name found = C:\Users\GAVA MEDIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
  337. CHR - Extension: No name found = C:\Users\GAVA MEDIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnibclkcmchpmfgnpnpnhanmfapffcjn\1.5.0_0\
  338. CHR - Extension: No name found = C:\Users\GAVA MEDIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\
  339. CHR - Extension: No name found = C:\Users\GAVA MEDIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
  340. CHR - Extension: No name found = C:\Users\GAVA MEDIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaedmjdfmmahhbjefcbgaolhhanlaolb\2.2.0_0\
  341. CHR - Extension: No name found = C:\Users\GAVA MEDIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\
  342. CHR - Extension: No name found = C:\Users\GAVA MEDIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn\6.21_1\
  343. CHR - Extension: No name found = C:\Users\GAVA MEDIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\kejbdjndbnbjgmefkgdddjlbokphdefk\2.1.26_0\
  344. CHR - Extension: No name found = C:\Users\GAVA MEDIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgfhaplbolbklbifbhiplbcldlbbamfc\2.6.5_0\
  345. CHR - Extension: No name found = C:\Users\GAVA MEDIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\
  346. CHR - Extension: No name found = C:\Users\GAVA MEDIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooebklgpfnbcnpokahmdidgbmlcdepkm\3.1_0\
  347. CHR - Extension: No name found = C:\Users\GAVA MEDIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
  348. CHR - Extension: No name found = C:\Users\GAVA MEDIA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5616.1121.0.3_0\
  349.  
  350. O1 HOSTS File: ([2017/04/29 02:47:36 | 000,002,052 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
  351. O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
  352. O1 - Hosts: 0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
  353. O1 - Hosts: 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
  354. O1 - Hosts: 0.0.0.0 media.opencandy.com
  355. O1 - Hosts: 0.0.0.0 cdn.opencandy.com
  356. O1 - Hosts: 0.0.0.0 tracking.opencandy.com
  357. O1 - Hosts: 0.0.0.0 api.opencandy.com
  358. O1 - Hosts: 0.0.0.0 api.recommendedsw.com
  359. O1 - Hosts: 0.0.0.0 installer.betterinstaller.com
  360. O1 - Hosts: 0.0.0.0 installer.filebulldog.com
  361. O1 - Hosts: 0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
  362. O1 - Hosts: 0.0.0.0 inno.bisrv.com
  363. O1 - Hosts: 0.0.0.0 nsis.bisrv.com
  364. O1 - Hosts: 0.0.0.0 cdn.file2desktop.com
  365. O1 - Hosts: 0.0.0.0 cdn.goateastcach.us
  366. O1 - Hosts: 0.0.0.0 cdn.guttastatdk.us
  367. O1 - Hosts: 0.0.0.0 cdn.inskinmedia.com
  368. O1 - Hosts: 0.0.0.0 cdn.insta.oibundles2.com
  369. O1 - Hosts: 0.0.0.0 cdn.insta.playbryte.com
  370. O1 - Hosts: 0.0.0.0 cdn.llogetfastcach.us
  371. O1 - Hosts: 0.0.0.0 cdn.montiera.com
  372. O1 - Hosts: 0.0.0.0 cdn.msdwnld.com
  373. O1 - Hosts: 0.0.0.0 cdn.mypcbackup.com
  374. O1 - Hosts: 0.0.0.0 cdn.ppdownload.com
  375. O1 - Hosts: 0.0.0.0 cdn.riceateastcach.us
  376. O1 - Hosts: 12 more lines...
  377. O2:[b]64bit:[/b] - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
  378. O2:[b]64bit:[/b] - BHO: (True Key Helper) - {0F4B8786-5502-4803-8EBC-F652A1153BB6} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll (Intel Security)
  379. O2:[b]64bit:[/b] - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
  380. O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre8\bin\ssv.dll (Oracle Corporation)
  381. O2:[b]64bit:[/b] - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
  382. O2:[b]64bit:[/b] - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
  383. O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre8\bin\jp2ssv.dll (Oracle Corporation)
  384. O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
  385. O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
  386. O2 - BHO: (True Key Helper) - {0F4B8786-5502-4803-8EBC-F652A1153BB6} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll (Intel Security)
  387. O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
  388. O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
  389. O2 - BHO: (Ó¦Óñ¦Ò»¼ü°²×°²å¼þ) - {50F4150A-48B2-417A-BE4C-C83F580FB904} - C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll (腾讯公司)
  390. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
  391. O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  392. O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
  393. O2 - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
  394. O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
  395. O3:[b]64bit:[/b] - HKLM\..\Toolbar: (True Key) - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll (Intel Security)
  396. O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  397. O3 - HKLM\..\Toolbar: (True Key) - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll (Intel Security)
  398. O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
  399. O3:[b]64bit:[/b] - HKCU\..\Toolbar\WebBrowser: (True Key) - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll (Intel Security)
  400. O3 - HKCU\..\Toolbar\WebBrowser: (True Key) - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll (Intel Security)
  401. O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
  402. O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
  403. O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
  404. O4 - HKLM..\Run: [] File not found
  405. O4 - HKLM..\Run: [DFX] C:\Program Files (x86)\DFX\DFX.exe ()
  406. O4 - HKLM..\Run: [SMΔRT-Protection] C:\Program Files (x86)\Smadav\SMΔRTP.exe (Smadsoft)
  407. O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Oracle Corporation)
  408. O4 - HKCU..\Run: [Chromium] c:\users\gava media\appdata\local\chromium\application\chrome.exe (The Chromium Authors)
  409. O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
  410. O4 - HKCU..\Run: [DLPDFEditorUpdateChecker] "0\DLPDFEditorUpdateChecker.exe" File not found
  411. O4 - HKCU..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
  412. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
  413. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
  414. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
  415. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
  416. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
  417. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
  418. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
  419. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
  420. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
  421. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
  422. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
  423. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
  424. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
  425. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
  426. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
  427. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
  428. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
  429. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
  430. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
  431. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
  432. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
  433. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
  434. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
  435. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
  436. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
  437. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
  438. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
  439. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
  440. O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
  441. O8:[b]64bit:[/b] - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
  442. O8:[b]64bit:[/b] - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  443. O8:[b]64bit:[/b] - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  444. O8:[b]64bit:[/b] - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  445. O8:[b]64bit:[/b] - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  446. O8:[b]64bit:[/b] - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  447. O8:[b]64bit:[/b] - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  448. O8:[b]64bit:[/b] - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  449. O8:[b]64bit:[/b] - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  450. O8:[b]64bit:[/b] - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
  451. O8:[b]64bit:[/b] - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
  452. O8:[b]64bit:[/b] - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office15\EXCEL.EXE (Microsoft Corporation)
  453. O8:[b]64bit:[/b] - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
  454. O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
  455. O8 - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  456. O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  457. O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  458. O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  459. O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  460. O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  461. O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  462. O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
  463. O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
  464. O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
  465. O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office15\EXCEL.EXE (Microsoft Corporation)
  466. O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
  467. O9:[b]64bit:[/b] - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
  468. O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
  469. O9:[b]64bit:[/b] - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
  470. O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
  471. O9:[b]64bit:[/b] - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
  472. O9:[b]64bit:[/b] - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
  473. O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
  474. O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
  475. O9 - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
  476. O9 - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
  477. O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
  478. O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
  479. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
  480. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
  481. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
  482. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
  483. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  484. O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
  485. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  486. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  487. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  488. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  489. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  490. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  491. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  492. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  493. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  494. O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
  495. O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
  496. O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
  497. O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
  498. O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
  499. O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  500. O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
  501. O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
  502. O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  503. O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  504. O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  505. O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  506. O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  507. O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  508. O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  509. O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  510. O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  511. O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
  512. O13[b]64bit:[/b] - gopher Prefix: missing
  513. O13 - gopher Prefix: missing
  514. O15 - HKCU\..Trusted Domains: hola.org ([]http in Trusted sites)
  515. O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
  516. O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EC52DAC6-2A7A-42D6-9B5D-0D1C66BFF936}: DhcpNameServer = 192.168.0.1
  517. O18:[b]64bit:[/b] - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  518. O18:[b]64bit:[/b] - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  519. O18:[b]64bit:[/b] - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
  520. O18:[b]64bit:[/b] - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  521. O18:[b]64bit:[/b] - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  522. O18:[b]64bit:[/b] - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  523. O18:[b]64bit:[/b] - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  524. O18:[b]64bit:[/b] - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
  525. O18:[b]64bit:[/b] - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  526. O18:[b]64bit:[/b] - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  527. O18:[b]64bit:[/b] - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  528. O18:[b]64bit:[/b] - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
  529. O18:[b]64bit:[/b] - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
  530. O18:[b]64bit:[/b] - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
  531. O18:[b]64bit:[/b] - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
  532. O18:[b]64bit:[/b] - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
  533. O18:[b]64bit:[/b] - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  534. O18:[b]64bit:[/b] - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
  535. O18:[b]64bit:[/b] - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
  536. O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  537. O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  538. O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
  539. O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  540. O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  541. O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  542. O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  543. O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
  544. O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  545. O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  546. O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  547. O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
  548. O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
  549. O18 - Protocol\Handler\ms-help - No CLSID value found
  550. O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
  551. O18 - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
  552. O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  553. O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
  554. O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
  555. O18:[b]64bit:[/b] - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
  556. O18:[b]64bit:[/b] - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
  557. O18:[b]64bit:[/b] - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
  558. O18:[b]64bit:[/b] - Protocol\Filter\text/xml {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL (Microsoft Corporation)
  559. O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
  560. O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
  561. O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
  562. O18 - Protocol\Filter\text/xml {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL (Microsoft Corporation)
  563. O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - File not found
  564. O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
  565. O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found
  566. O20 - HKLM Winlogon: Shell - (explorer.exe) - File not found
  567. O20 - HKLM Winlogon: UserInit - (userinit.exe) - File not found
  568. O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found
  569. O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - File not found
  570. O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
  571. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
  572. O29:[b]64bit:[/b] - HKLM SecurityProviders - (credssp.dll) - File not found
  573. O29 - HKLM SecurityProviders - (credssp.dll) - File not found
  574. O30:[b]64bit:[/b] - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
  575. O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
  576. O31 - SafeBoot: AlternateShell - cmd.exe
  577. O32 - HKLM CDRom: AutoRun - 1
  578. O33 - MountPoints2\{2ac420e2-66d8-11e5-9c39-08626668ee9c}\Shell - "" = AutoRun
  579. O33 - MountPoints2\{2ac420e2-66d8-11e5-9c39-08626668ee9c}\Shell\AutoRun\command - "" = "G:\Setup.exe" /s
  580. O33 - MountPoints2\{7ef3ca40-03c0-11e6-9c87-08626668ee9c}\Shell - "" = AutoRun
  581. O33 - MountPoints2\{7ef3ca40-03c0-11e6-9c87-08626668ee9c}\Shell\AutoRun\command - "" = "H:\Setup.exe" /s
  582. O33 - MountPoints2\{e636ff96-5f75-11e5-9c35-08626668ee9c}\Shell - "" = AutoRun
  583. O33 - MountPoints2\{e636ff96-5f75-11e5-9c35-08626668ee9c}\Shell\AutoRun\command - "" = "G:\Setup.exe" /s
  584. O34 - HKLM BootExecute: (autocheck autochk *)
  585. O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
  586. O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
  587. O35 - HKLM\..comfile [open] -- "%1" %*
  588. O35 - HKLM\..exefile [open] -- "%1" %*
  589. O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
  590. O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
  591. O37 - HKLM\...com [@ = comfile] -- "%1" %*
  592. O37 - HKLM\...exe [@ = exefile] -- "%1" %*
  593. O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
  594. O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
  595.  
  596. [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
  597.  
  598. [2017/04/29 02:51:50 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\GAVA MEDIA\Desktop\OTL.exe
  599. [2017/04/28 20:51:24 | 000,000,000 | ---D | C] -- C:\Users\GAVA MEDIA\Desktop\New folder (4)
  600. [2017/04/26 04:49:17 | 000,000,000 | ---D | C] -- C:\Users\GAVA MEDIA\AppData\Roaming\Google
  601. [2017/04/21 01:24:56 | 000,000,000 | ---D | C] -- C:\Users\GAVA MEDIA\Desktop\auto
  602. [2017/04/19 18:47:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ezkeyword
  603. [2017/04/19 00:08:03 | 000,000,000 | ---D | C] -- C:\Users\GAVA MEDIA\Desktop\IDM 7.1 Full portable
  604. [2017/04/09 00:11:43 | 000,000,000 | ---D | C] -- C:\Users\GAVA MEDIA\Desktop\as
  605. [2017/04/08 07:13:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
  606. [2017/04/07 20:34:10 | 000,223,464 | ---- | C] (Tonec Inc.) -- C:\Windows\SysNative\drivers\idmwfp.sys
  607. [2017/04/03 21:33:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ezkeyword
  608. [2017/04/03 17:30:48 | 000,000,000 | ---D | C] -- C:\Users\GAVA MEDIA\AppData\Roaming\Xiaomi
  609. [2017/04/03 17:12:21 | 000,000,000 | ---D | C] -- C:\Users\GAVA MEDIA\Desktop\MiFlashUnlock_1.1.0317.1_en
  610. [2017/04/03 17:04:06 | 000,000,000 | ---D | C] -- C:\Users\GAVA MEDIA\AppData\Roaming\TeamViewer
  611. [2017/04/03 17:03:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer
  612. [2017/04/01 00:47:07 | 000,000,000 | ---D | C] -- C:\Users\GAVA MEDIA\Desktop\ez
  613. [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
  614. [1 C:\Users\GAVA MEDIA\Desktop\*.tmp files -> C:\Users\GAVA MEDIA\Desktop\*.tmp -> ]
  615.  
  616. [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
  617.  
  618. [2017/04/29 02:51:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\GAVA MEDIA\Desktop\OTL.exe
  619. [2017/04/29 02:48:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
  620. [2017/04/29 02:46:33 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
  621. [2017/04/29 02:46:30 | 3340,861,440 | -HS- | M] () -- C:\hiberfil.sys
  622. [2017/04/29 00:22:44 | 000,192,216 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
  623. [2017/04/27 06:14:28 | 000,001,177 | ---- | M] () -- C:\Users\Public\Desktop\True Key.lnk
  624. [2017/04/27 05:57:20 | 000,000,304 | ---- | M] () -- C:\Windows\tasks\McAfee Remediation (Prepare).job
  625. [2017/04/27 00:52:14 | 000,076,292 | ---- | M] () -- C:\Users\GAVA MEDIA\Desktop\SLIP_SBMPTN_11799923109.jpg
  626. [2017/04/26 18:02:52 | 000,863,592 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
  627. [2017/04/26 18:02:52 | 000,722,476 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
  628. [2017/04/26 18:02:52 | 000,135,592 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
  629. [2017/04/20 23:40:53 | 000,333,146 | ---- | M] () -- C:\Users\GAVA MEDIA\Desktop\kartini-abadi.png
  630. [2017/04/20 10:38:45 | 000,002,209 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
  631. [2017/04/19 18:47:09 | 000,001,041 | ---- | M] () -- C:\Users\GAVA MEDIA\Desktop\ezkeyword.lnk
  632. [2017/04/19 15:26:28 | 000,002,309 | ---- | M] () -- C:\Users\GAVA MEDIA\Desktop\Google Chrome.lnk
  633. [2017/04/19 15:26:28 | 000,002,309 | ---- | M] () -- C:\Users\GAVA MEDIA\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
  634. [2017/04/13 15:30:08 | 000,002,030 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
  635. [2017/04/08 07:13:09 | 000,001,986 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
  636. [2017/04/03 19:00:30 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
  637. [2017/04/03 18:50:32 | 002,493,856 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
  638. [2017/04/03 17:11:47 | 002,104,201 | ---- | M] () -- C:\Users\GAVA MEDIA\Desktop\MiFlashUnlock_1.1.0317.1_en.zip
  639. [2017/04/01 22:36:25 | 031,490,009 | ---- | M] (ciptafile.com ) -- C:\Users\GAVA MEDIA\Desktop\ezkeyword.exe
  640. [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
  641. [1 C:\Users\GAVA MEDIA\Desktop\*.tmp files -> C:\Users\GAVA MEDIA\Desktop\*.tmp -> ]
  642.  
  643. [color=#E56717]========== Files Created - No Company Name ==========[/color]
  644.  
  645. [2017/04/27 06:14:28 | 000,001,177 | ---- | C] () -- C:\Users\Public\Desktop\True Key.lnk
  646. [2017/04/27 00:52:12 | 000,076,292 | ---- | C] () -- C:\Users\GAVA MEDIA\Desktop\SLIP_SBMPTN_11799923109.jpg
  647. [2017/04/20 23:40:53 | 000,333,146 | ---- | C] () -- C:\Users\GAVA MEDIA\Desktop\kartini-abadi.png
  648. [2017/04/19 18:47:09 | 000,001,041 | ---- | C] () -- C:\Users\GAVA MEDIA\Desktop\ezkeyword.lnk
  649. [2017/04/19 00:22:17 | 000,002,209 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
  650. [2017/04/03 19:00:30 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
  651. [2017/04/03 17:11:38 | 002,104,201 | ---- | C] () -- C:\Users\GAVA MEDIA\Desktop\MiFlashUnlock_1.1.0317.1_en.zip
  652. [2017/04/03 17:04:06 | 000,001,065 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
  653. [2016/11/15 12:56:56 | 000,000,047 | ---- | C] () -- C:\Windows\ncStarter.INI
  654. [2016/09/23 23:16:30 | 000,131,072 | RHS- | C] ( ) -- C:\Windows\SysWow64\csrss.exe
  655. [2016/07/17 16:24:30 | 000,000,600 | ---- | C] () -- C:\Users\GAVA MEDIA\AppData\Roaming\winscp.rnd
  656. [2016/07/15 10:48:41 | 000,872,506 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
  657. [2016/02/14 16:51:29 | 000,005,120 | ---- | C] () -- C:\Users\GAVA MEDIA\AppData\Roaming\GiftBag.db
  658. [2016/02/11 18:42:24 | 000,000,017 | ---- | C] () -- C:\Users\GAVA MEDIA\AppData\Local\resmon.resmoncfg
  659. [2016/01/25 21:53:59 | 000,000,008 | RHS- | C] () -- C:\Users\GAVA MEDIA\ntuser.pol
  660. [2016/01/19 11:04:55 | 002,681,364 | ---- | C] () -- C:\Users\GAVA MEDIA\AppData\Roaming\sb328.dat
  661. [2016/01/19 11:04:28 | 000,396,288 | ---- | C] () -- C:\Users\GAVA MEDIA\AppData\Roaming\Setup39967.exe
  662. [2015/12/09 01:52:52 | 000,000,008 | ---- | C] () -- C:\Windows\SysWow64\PROTOCOL.INI
  663. [2015/08/06 16:51:46 | 039,028,974 | ---- | C] () -- C:\Users\GAVA MEDIA\tecsnd1.uha
  664. [2015/08/06 16:51:43 | 062,295,583 | ---- | C] () -- C:\Users\GAVA MEDIA\tecsnd0.uha
  665. [2015/08/06 16:51:43 | 005,016,988 | ---- | C] () -- C:\Users\GAVA MEDIA\tecmisc0.uha
  666. [2015/08/06 16:51:43 | 000,781,154 | ---- | C] () -- C:\Users\GAVA MEDIA\tecmisc1.uha
  667. [2015/08/06 16:51:40 | 053,043,788 | ---- | C] () -- C:\Users\GAVA MEDIA\tecmesh.uha
  668. [2015/08/06 16:51:40 | 007,679,605 | ---- | C] () -- C:\Users\GAVA MEDIA\tecmaps.uha
  669. [2015/08/06 16:51:40 | 005,505,532 | ---- | C] () -- C:\Users\GAVA MEDIA\tecdll.uha
  670. [2015/08/06 16:51:40 | 000,344,042 | ---- | C] () -- C:\Users\GAVA MEDIA\tecmain.uha
  671. [2015/08/06 16:51:39 | 008,842,694 | ---- | C] () -- C:\Users\GAVA MEDIA\tecanim.uha
  672. [2015/08/06 16:51:39 | 000,100,864 | ---- | C] () -- C:\Users\GAVA MEDIA\Tecuha.exe
  673. [2015/08/06 16:51:39 | 000,001,685 | ---- | C] () -- C:\Users\GAVA MEDIA\_Unpak.bat
  674. [2015/08/03 15:11:29 | 000,000,218 | ---- | C] () -- C:\Users\GAVA MEDIA\.recently-used.xbel
  675. [2015/07/18 03:10:42 | 000,000,273 | ---- | C] () -- C:\Users\GAVA MEDIA\AppData\Roaming\WB.CFG
  676. [2015/07/09 02:21:02 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
  677. [2015/07/08 00:45:30 | 000,005,296 | ---- | C] () -- C:\Windows\SysWow64\Wisuahype.ini
  678. [2015/07/08 00:45:30 | 000,003,016 | ---- | C] () -- C:\Windows\SysWow64\WisuahypeOff.ini
  679. [2015/07/08 00:28:04 | 000,000,000 | ---- | C] () -- C:\Windows\prleth.sys
  680. [2015/07/08 00:28:04 | 000,000,000 | ---- | C] () -- C:\Windows\hgfs.sys
  681. [2015/07/02 18:38:22 | 002,463,976 | ---- | C] () -- C:\Windows\SysWow64\NPSWF32.dll
  682. [2015/07/02 16:43:09 | 000,002,828 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
  683. [2015/07/02 16:43:09 | 000,000,008 | RHS- | C] () -- C:\ProgramData\7DFF748DE8.sys
  684. [2015/07/01 15:55:54 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
  685. [2015/07/01 14:50:44 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl
  686. [2015/07/01 14:45:43 | 000,299,520 | ---- | C] () -- C:\Windows\SysWow64\igdmd32.dll
  687. [2015/07/01 14:45:42 | 000,182,272 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
  688. [2015/07/01 14:45:26 | 000,142,848 | ---- | C] () -- C:\Windows\SysWow64\igdail32.dll
  689.  
  690. [color=#E56717]========== ZeroAccess Check ==========[/color]
  691.  
  692. [2015/09/06 20:49:51 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
  693.  
  694. [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
  695.  
  696. [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  697.  
  698. [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
  699.  
  700. [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
  701.  
  702. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
  703. "" = C:\Windows\SysNative\shell32.dll -- [2013/11/15 00:46:31 | 021,196,664 | ---- | M] (Microsoft Corporation)
  704. "ThreadingModel" = Apartment
  705.  
  706. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
  707. "" = %SystemRoot%\system32\shell32.dll -- [2013/11/15 00:46:31 | 018,642,504 | ---- | M] (Microsoft Corporation)
  708. "ThreadingModel" = Apartment
  709.  
  710. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
  711. "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013/08/22 16:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
  712. "ThreadingModel" = Free
  713.  
  714. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
  715. "" = %systemroot%\system32\wbem\fastprox.dll -- [2013/08/22 09:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
  716. "ThreadingModel" = Free
  717.  
  718. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
  719. "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013/08/22 16:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
  720. "ThreadingModel" = Both
  721.  
  722. [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
  723.  
  724. [color=#E56717]========== LOP Check ==========[/color]
  725.  
  726. [2016/11/07 19:39:40 | 000,000,000 | -H-D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\249BD025
  727. [2016/07/15 11:09:56 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\Andy
  728. [2016/02/16 10:11:40 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\api--1-0
  729. [2016/06/09 16:39:04 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\DAEMON Tools Lite
  730. [2017/04/07 19:38:01 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\DMCache
  731. [2016/06/07 03:43:12 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\ESRI
  732. [2017/03/01 16:42:57 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\FileZilla
  733. [2015/08/15 21:00:25 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\gtk-2.0
  734. [2016/12/04 17:58:22 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\Hola
  735. [2016/12/02 07:20:27 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\Hotspot Shield
  736. [2017/04/18 23:54:01 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\IDM
  737. [2016/11/22 04:55:24 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\JetBrains
  738. [2016/01/27 13:53:14 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\kingsoft
  739. [2016/02/21 00:44:13 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\MegaTypers
  740. [2016/01/20 09:03:20 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\mgyun
  741. [2017/01/09 00:38:41 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\MiniLyrics
  742. [2016/03/19 01:02:22 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\MiniUpgrade
  743. [2016/03/20 20:36:30 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\MPC-HC
  744. [2016/11/15 00:10:47 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\Nox
  745. [2017/01/30 01:50:54 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\PhotoScape
  746. [2015/08/11 11:12:21 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\Rovio
  747. [2017/04/29 02:48:29 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\Smadav
  748. [2016/01/26 16:05:39 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\software
  749. [2016/03/19 01:02:07 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\talimama
  750. [2017/04/03 17:04:06 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\TeamViewer
  751. [2016/07/21 14:46:37 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\Tencent
  752. [2016/10/31 05:13:42 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\Umeng
  753. [2016/06/06 21:18:43 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\uTorrent
  754. [2016/06/03 23:03:01 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\WarThunder
  755. [2016/01/27 13:53:45 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\wps
  756. [2017/04/03 17:30:48 | 000,000,000 | ---D | M] -- C:\Users\GAVA MEDIA\AppData\Roaming\Xiaomi
  757.  
  758. [color=#E56717]========== Purity Check ==========[/color]
  759.  
  760.  
  761.  
  762. [color=#E56717]========== Files - Unicode (All) ==========[/color]
  763. (C:\Users\GAVA MEDIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\????) -- C:\Users\GAVA MEDIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
  764. (C:\ProgramData\Microsoft\Windows\Start Menu\Programs\????) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
  765.  
  766. < End of report >
  767.  
  768. OTL Extras logfile created on: 29/04/2017 2:54:40 - Run 1
  769. OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\GAVA MEDIA\Desktop
  770. 64bit- Enterprise Edition N (Version = 6.2.9200) - Type = NTWorkstation
  771. Internet Explorer (Version = 9.11.9600.16438)
  772. Locale: 00000421 | Country: Indonesia | Language: IND | Date Format: dd/MM/yyyy
  773.  
  774. 3,89 Gb Total Physical Memory | 2,84 Gb Available Physical Memory | 73,02% Memory free
  775. 4,58 Gb Paging File | 3,49 Gb Available in Paging File | 76,21% Paging File free
  776. Paging file location(s): ?:\pagefile.sys [binary data]
  777.  
  778. %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
  779. Drive C: | 116,67 Gb Total Space | 14,40 Gb Free Space | 12,35% Space Free | Partition Type: NTFS
  780. Drive E: | 175,78 Gb Total Space | 13,22 Gb Free Space | 7,52% Space Free | Partition Type: NTFS
  781. Drive F: | 172,79 Gb Total Space | 11,75 Gb Free Space | 6,80% Space Free | Partition Type: NTFS
  782.  
  783. Computer Name: ASUS | User Name: GAVA MEDIA | Logged in as Administrator.
  784. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
  785. Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
  786.  
  787. [color=#E56717]========== Extra Registry (SafeList) ==========[/color]
  788.  
  789.  
  790. [color=#E56717]========== File Associations ==========[/color]
  791.  
  792. [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
  793. .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
  794. .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
  795. .reg [@ = regfile] -- regedit.exe "%1"
  796.  
  797. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
  798. .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
  799. .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
  800. .reg [@ = regfile] -- regedit.exe "%1"
  801.  
  802. [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
  803. .html [@ = ChromiumHTM.HJRO7HSOVI2IUMPTO7PJB5GWVU] -- C:\Users\GAVA MEDIA\AppData\Local\Chromium\Application\chrome.exe (The Chromium Authors)
  804.  
  805. [color=#E56717]========== Shell Spawning ==========[/color]
  806.  
  807. [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
  808. batfile [open] -- "%1" %*
  809. cmdfile [open] -- "%1" %*
  810. comfile [open] -- "%1" %*
  811. exefile [open] -- "%1" %*
  812. helpfile [open] -- Reg Error: Key error.
  813. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
  814. htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
  815. http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
  816. https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
  817. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
  818. InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
  819. InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
  820. piffile [open] -- "%1" %*
  821. regfile [open] -- regedit.exe "%1"
  822. regfile [merge] -- Reg Error: Key error.
  823. scrfile [config] -- "%1"
  824. scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
  825. scrfile [open] -- "%1" /S
  826. txtfile [edit] -- Reg Error: Key error.
  827. Unknown [openas] -- %SystemRoot%\SysWow64\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
  828. Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
  829. Directory [ByteFence Folder Scan] -- "C:\Program Files\ByteFence\ByteFenceScan.exe" /scan:"%1" (Byte Technologies LLC)
  830. Directory [cmd] -- cmd.exe /s /k pushd "%V"
  831. Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
  832. Directory [mplayerc64.enqueue] -- "C:\Program Files (x86)\K-Lite Codec Pack 2\MPC-HC64\mpc-hc64.exe" /add "%1" (MPC-HC Team)
  833. Directory [mplayerc64.play] -- "C:\Program Files (x86)\K-Lite Codec Pack 2\MPC-HC64\mpc-hc64.exe" "%1" (MPC-HC Team)
  834. Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
  835. Directory [SHAREit] -- C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.exe /waitfile:%1 (SHAREit Technologies Co.Ltd)
  836. Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
  837. Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
  838. Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft)
  839. Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
  840. Folder [explore] -- Reg Error: Value error.
  841. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
  842. Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
  843. CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
  844.  
  845. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
  846. batfile [open] -- "%1" %*
  847. cmdfile [open] -- "%1" %*
  848. comfile [open] -- "%1" %*
  849. cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
  850. exefile [open] -- "%1" %*
  851. helpfile [open] -- Reg Error: Key error.
  852. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
  853. htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
  854. http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
  855. https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
  856. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
  857. piffile [open] -- "%1" %*
  858. regfile [open] -- regedit.exe "%1"
  859. regfile [merge] -- Reg Error: Key error.
  860. scrfile [config] -- "%1"
  861. scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
  862. scrfile [open] -- "%1" /S
  863. txtfile [edit] -- Reg Error: Key error.
  864. Unknown [openas] -- %SystemRoot%\SysWow64\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
  865. Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
  866. Directory [ByteFence Folder Scan] -- "C:\Program Files\ByteFence\ByteFenceScan.exe" /scan:"%1" (Byte Technologies LLC)
  867. Directory [cmd] -- cmd.exe /s /k pushd "%V"
  868. Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
  869. Directory [mplayerc64.enqueue] -- "C:\Program Files (x86)\K-Lite Codec Pack 2\MPC-HC64\mpc-hc64.exe" /add "%1" (MPC-HC Team)
  870. Directory [mplayerc64.play] -- "C:\Program Files (x86)\K-Lite Codec Pack 2\MPC-HC64\mpc-hc64.exe" "%1" (MPC-HC Team)
  871. Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
  872. Directory [SHAREit] -- C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.exe /waitfile:%1 (SHAREit Technologies Co.Ltd)
  873. Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
  874. Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
  875. Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft)
  876. Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
  877. Folder [explore] -- Reg Error: Value error.
  878. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
  879. Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
  880. CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
  881.  
  882. [color=#E56717]========== Security Center Settings ==========[/color]
  883.  
  884. [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
  885. "cval" = 0
  886.  
  887. [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
  888.  
  889. [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
  890. "VistaSp1" = A6 4E 27 AC 46 9F CE 01 [binary data]
  891. "AntiVirusOverride" = 0
  892. "AntiSpywareOverride" = 0
  893. "FirewallOverride" = 0
  894.  
  895. [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
  896. "UpgradeTime" = [binary data]
  897.  
  898. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
  899.  
  900. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
  901.  
  902. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
  903. "UpgradeTime" = Reg Error: Unknown registry data type -- File not found
  904.  
  905. [color=#E56717]========== Firewall Settings ==========[/color]
  906.  
  907. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
  908. "EnableFirewall" = 1
  909. "DisableNotifications" = 0
  910.  
  911. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
  912. "EnableFirewall" = 1
  913. "DisableNotifications" = 0
  914.  
  915. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
  916. "EnableFirewall" = 1
  917. "DisableNotifications" = 0
  918.  
  919. [color=#E56717]========== Authorized Applications List ==========[/color]
  920.  
  921.  
  922. [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]
  923.  
  924. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
  925. "{182E32F2-4D44-4089-8DA5-F5B574F74AC0}" = lport=3704 | protocol=6 | dir=in | name=adobe version cue cs3 server |
  926. "{280B9725-E658-49E2-A9DC-47F53BCB64A7}" = lport=3703 | protocol=6 | dir=in | name=adobe version cue cs3 server |
  927. "{47C074EC-D026-4D8A-B706-886EBBFA5863}" = lport=50900 | protocol=6 | dir=in | name=adobe version cue cs3 server |
  928. "{9A91BAC8-AADC-4DD4-8634-47771800914C}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
  929. "{B290445F-E5B4-4781-BE28-F25ADDB711AC}" = lport=5353 | protocol=17 | dir=in | app=c:\users\gava media\appdata\local\chromium\application\chrome.exe |
  930. "{CD18F8FB-3D91-44D6-A486-DDDC734B977D}" = lport=50901 | protocol=6 | dir=in | name=adobe version cue cs3 server |
  931. "{DB73515C-C516-43F9-80D8-D0D2CE6A5FD3}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office15\outlook.exe |
  932.  
  933. [color=#E56717]========== Vista Active Application Exception List ==========[/color]
  934.  
  935. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
  936. "{018B7B3F-72E2-49FF-BC9C-94A0FF56C9AC}" = protocol=6 | dir=in | app=c:\program files (x86)\mypublicwifi\mypublicwifi.exe |
  937. "{044CAE66-A987-4BDF-AF43-23F09F99E56C}" = dir=out | app=c:\users\gava media\appdata\local\temp\andy-x64\setup.exe |
  938. "{05B59494-8963-4917-8E26-F99F80BD01BC}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
  939. "{0981FDFD-8718-4373-B1B7-74BB8478E110}" = dir=in | app=c:\program files (x86)\common files\tencent\qqdownload\131\bugreport_xf.exe |
  940. "{09BB3F49-7C44-4D67-8346-851E2FEAAD44}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe |
  941. "{10C74109-91E4-4355-8625-870B15013A66}" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
  942. "{1899C94C-5F4F-452D-83E1-E49281A30BEA}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer_service.exe |
  943. "{18F7F0CB-8DB8-471D-A450-DF7BDDFC3EA2}" = dir=in | app=c:\program files (x86)\common files\tencent\qqdownload\131\tencentdl.exe |
  944. "{28F9F8C2-AE23-4ED9-A86E-D84EF8039B9D}" = protocol=6 | dir=in | name=abrir puertos 27000-27009 |
  945. "{2A5AAA93-CD55-4167-BE54-C75D1AFFA37F}" = dir=out | name=@{microsoft.bingsports_3.0.4.345_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} |
  946. "{2C163E4B-7404-4B10-A982-10C85ADB3774}" = dir=out | app=c:\program files\andy\setupfiles\uninstall.exe |
  947. "{311B1178-D978-456C-B961-14BF9D8DF154}" = dir=out | name=windows_ie_ac_001 |
  948. "{37400CD0-C3A9-459F-9FDE-978CD1E6907D}" = dir=in | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\rosettastoneversion3.exe |
  949. "{3ACAA342-DD38-469F-9BEB-B2CFC570471F}" = dir=in | app=c:\program files (x86)\tencent\qqpcmgr\11.6.17602.210\plugins\checkpcmgrupdate.exe |
  950. "{3C52CEF3-AFFC-41C3-AF1E-4C43D3BCF87C}" = dir=in | name=f5.vpn.client |
  951. "{3D3F77BC-AC26-4344-AC2F-FA2E296339DF}" = dir=in | app=c:\program files\andy\andy.exe |
  952. "{4027DAD1-4690-4BCB-87E4-F278EDDE9865}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer.exe |
  953. "{43D32C04-3571-4F55-BA1D-AA1689E1D7B4}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\lync.exe |
  954. "{46A435FD-B170-4B30-AEF7-3C45C5C5AFD4}" = dir=in | app=c:\program files\andy\setupfiles\uninstall.exe |
  955. "{4A3AA50E-B086-4914-9F86-E598965686BE}" = dir=out | name=@{microsoft.bingmaps_2.1.3230.2048_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
  956. "{4AA00625-946D-43EB-AFFE-BD2E002ED558}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.4.336_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} |
  957. "{4CBB5E7E-22D3-43FF-B0D3-AD5E8D7F1A1A}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\lync.exe |
  958. "{4CF5C462-C198-4BDE-A084-C99AB1AC122C}" = protocol=17 | dir=in | app=c:\program files (x86)\shareit technologies\shareit\shareit.exe |
  959. "{53FCDD00-AB9D-4611-A574-92D29B016316}" = dir=out | name=@{microsoft.bingweather_3.0.4.350_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} |
  960. "{55B99A2E-C70A-4B20-B3F6-3EADA8E8CF6D}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
  961. "{5E10FDE8-4F37-4B25-8570-7B632171A0C0}" = dir=out | name=@{microsoft.bingtravel_3.0.4.336_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} |
  962. "{5FB08332-0A2D-498C-A2BD-7E1C33D72153}" = protocol=6 | dir=in | app=c:\program files (x86)\shareit technologies\shareit\shareit.exe |
  963. "{65B3E550-8F0E-4CAF-A18B-3AE6E07EA450}" = protocol=6 | dir=in | app=c:\users\gava media\desktop\hammerheaddomain\app\firefox\firefox.exe |
  964. "{662E2252-1EAE-46EA-B7B5-82708F07181C}" = dir=out | name=@{microsoft.bingnews_3.0.4.344_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} |
  965. "{66C159BB-227A-42C6-B6A3-D7BF4C587CE2}" = protocol=6 | dir=in | app=c:\program files (x86)\shareit technologies\shareit\shareit.exe |
  966. "{6A2CF76B-96D4-458B-8C0D-CEE5520C0930}" = protocol=17 | dir=in | app=c:\program files (x86)\shareit technologies\shareit\shareit.exe |
  967. "{707D823A-412B-4794-ADD3-AC6E076419E1}" = dir=out | name=f5.vpn.client |
  968. "{70EB8721-183C-4211-92D0-49AED5858518}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
  969. "{727C2449-4F98-4BA2-85A3-75EE2500C8A7}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\adobe\adobe version cue cs3\server\bin\versioncuecs3.exe |
  970. "{73759FD4-C3DC-4E3B-87E3-C9EDDF71BF85}" = dir=in | name=junipernetworks.junospulsevpn |
  971. "{7D7DCFA8-E8B3-400B-9DFD-ECABA61F8873}" = dir=out | name=junipernetworks.junospulsevpn |
  972. "{836DB9ED-1128-443C-8935-98D98E24E187}" = dir=in | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\support\bin\win\rosettastoneltdservices.exe |
  973. "{8381BC2A-6338-4D50-96E4-3F3AB00BFABB}" = dir=out | app=c:\program files\andy\andyconsole.exe |
  974. "{8566E6CE-8413-44D8-9851-B9DF55D55124}" = protocol=17 | dir=in | app=c:\program files (x86)\mypublicwifi\mypublicwifi.exe |
  975. "{86B0CE3B-19E3-4D23-BB1C-77698EC78201}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\adobe\adobe version cue cs3\server\bin\versioncuecs3.exe |
  976. "{96020BB7-32DB-48C1-A54B-EA8F876E256E}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer.exe |
  977. "{9D5E1863-2075-4C42-A162-2BB38840C1D6}" = dir=in | app=c:\program files\andy\handyandy.exe |
  978. "{9FC956DF-BB6C-4F56-A401-1FD397E092C5}" = dir=out | app=c:\program files\andy\andy.exe |
  979. "{A4B8899F-AB69-42A0-89D0-1E86DCE6C601}" = dir=out | app=c:\users\gava media\appdata\local\temp\andy-x64\setup.exe |
  980. "{A610FD37-00BB-4046-9B2B-D1880D734238}" = dir=in | name=sonicwall.mobileconnect |
  981. "{A785D10E-9DDF-4DCF-9626-47F914AEA589}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.21234_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
  982. "{AA9173FB-DF6F-482F-B5DF-BBD60B83DCC5}" = dir=in | app=c:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe |
  983. "{AE74E26C-9DA5-494D-81ED-934D6CB03965}" = protocol=6 | dir=out | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\rosettastoneversion3.exe |
  984. "{B2FED0DD-DE5C-4D7F-9885-0446410AFA55}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
  985. "{B3670AAC-2BBC-40DE-9405-A93809034BD0}" = protocol=17 | dir=in | app=c:\users\gava media\desktop\hammerheaddomain\app\firefox\firefox.exe |
  986. "{B53D282E-F35F-451A-A682-EC1AA3D97734}" = protocol=17 | dir=in | app=c:\program files (x86)\shareit technologies\shareit\shareit.exe |
  987. "{B5AA8671-9715-40E3-9F44-939275B95B3A}" = dir=in | name=checkpoint.vpn |
  988. "{BE2A89A1-BCA4-4438-88E1-E84392E222C5}" = dir=in | app=c:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe |
  989. "{BF69F6F2-20C8-4DB4-8CDF-6ED746044D64}" = dir=out | app=c:\program files\andy\handyandy.exe |
  990. "{C3F12E8C-A794-41E8-A7F0-0E160F54240B}" = dir=in | app=c:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe |
  991. "{C9E9CBAA-FBB5-4525-95D3-0F77FBCCB057}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
  992. "{CB5277D4-29B5-4849-93FD-CC8BC0BA6F71}" = dir=out | name=@{microsoft.bingfinance_3.0.4.344_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} |
  993. "{CB833BCD-5E58-4A45-8F2E-8A241A6459EA}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
  994. "{CCD20E34-B40C-47B1-BC39-A2AA16607B1D}" = protocol=17 | dir=in | app=c:\users\gava media\appdata\roaming\utorrent\utorrent.exe |
  995. "{D00EA503-F556-4412-BFCC-F7A7501EF150}" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
  996. "{DA5D22FA-32A4-4A38-A440-BE4E562C7107}" = protocol=6 | dir=in | app=c:\program files (x86)\shareit technologies\shareit\shareit.exe |
  997. "{DEC73439-31BD-4846-A410-F5FB3F03F965}" = protocol=6 | dir=in | app=c:\users\gava media\appdata\roaming\utorrent\utorrent.exe |
  998. "{E058F791-25B8-4AFD-A4BF-E98C254D0319}" = protocol=6 | dir=in | app=c:\program files\android\android studio\jre\bin\java.exe |
  999. "{E33428A2-0388-46C7-929A-A062A6A963A5}" = dir=in | app=c:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe |
  1000. "{E3B2C8E5-A137-40C7-8692-A75230EAE655}" = dir=out | name=sonicwall.mobileconnect |
  1001. "{E41D8F24-F35A-4B85-BCE9-3371CF4A9B87}" = protocol=17 | dir=in | app=c:\program files\android\android studio\jre\bin\java.exe |
  1002. "{E91D54E8-0A80-46D9-8985-42AC103FA55A}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.21234_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
  1003. "{E98B75B9-2F7B-4311-B4A0-AA606131DD70}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.4.336_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} |
  1004. "{EA36696A-978C-4550-B200-8EFEB8D0A038}" = dir=out | name=checkpoint.vpn |
  1005. "{EB2A700A-6B19-400F-B398-A2DE82485BC2}" = dir=in | app=c:\program files\andy\andyconsole.exe |
  1006. "{ECC0FF1F-3C33-4264-A48D-AECFFB930029}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe |
  1007. "{F4E45B6E-940B-432A-8481-18EA6DA49FB1}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
  1008. "{F831B48C-0463-46C4-A2FB-D5A16D2A48B0}" = dir=in | app=c:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe |
  1009. "{FA5A963F-F19D-4AC5-803D-E942321C02A4}" = protocol=6 | dir=out | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\support\bin\win\rosettastoneltdservices.exe |
  1010. "{FB696780-A938-4E59-8489-2A22A662BDC4}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer_service.exe |
  1011. "TCP Query User{2069F283-FA39-4258-BB75-0555FC8F859D}C:\program files\android\android studio\jre\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\android\android studio\jre\bin\java.exe |
  1012. "TCP Query User{8BB5D66A-3C1F-4DB6-BE77-8D0DA5D165C3}F:\games\warhammer\w40k.exe" = protocol=6 | dir=in | app=f:\games\warhammer\w40k.exe |
  1013. "TCP Query User{C9642FAE-EFB5-4B88-B5E5-82BAB8C64758}C:\users\gava media\desktop\hammerheaddomain\app\firefox\firefox.exe" = protocol=6 | dir=in | app=c:\users\gava media\desktop\hammerheaddomain\app\firefox\firefox.exe |
  1014. "TCP Query User{EF1D3BF2-FDCC-4C47-AAEE-3B2B8FB7CCB8}C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe" = protocol=6 | dir=in | app=c:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe |
  1015. "UDP Query User{3B1E93F7-9809-4500-9D6B-79056A0E7944}C:\program files\android\android studio\jre\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\android\android studio\jre\bin\java.exe |
  1016. "UDP Query User{4B4584CF-6441-417A-BD53-AEE1E37AD085}C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe" = protocol=17 | dir=in | app=c:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe |
  1017. "UDP Query User{8A9EF88A-6960-45A3-98A5-C274850A0657}C:\users\gava media\desktop\hammerheaddomain\app\firefox\firefox.exe" = protocol=17 | dir=in | app=c:\users\gava media\desktop\hammerheaddomain\app\firefox\firefox.exe |
  1018. "UDP Query User{9A923AAC-5CBA-483C-AFAB-7A9360987363}F:\games\warhammer\w40k.exe" = protocol=17 | dir=in | app=f:\games\warhammer\w40k.exe |
  1019.  
  1020. [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
  1021.  
  1022. 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
  1023. "{176E2755-0A17-42C6-88E2-192AB2131278}" = Intel(R) Trusted Execution Engine
  1024. "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
  1025. "{26A24AE4-039D-4CA4-87B4-2F86418011FF}" = Java 8 Update 11 (64-bit)
  1026. "{27276DC1-66AA-4B16-918D-5AB1EEDF09C6}" = Intel® Hardware Accelerated Execution Manager
  1027. "{2D6248C0-4693-4CAB-9922-F05E4015F62A}" = Intel(R) Trusted Execution Engine
  1028. "{37D41A97-6B02-4C30-8753-85107BE1D674}" = Intel® RealSense™ SDK 2014 Runtime (x64): Core
  1029. "{42112AF2-A715-465e-B9B7-02626461E6E8}" = DL PDF Editor 1.7
  1030. "{60092746-6A0F-46A9-B9F1-53B62EC0E0A4}_is1" = OPPO USB Drivers 2.2.6.0
  1031. "{6307E820-0317-4DCE-AAE0-7B6CAD867055}" = Intel(R) Trusted Execution Engine Driver
  1032. "{64A3A4F4-B792-11D6-A78A-00B0D0180110}" = Java SE Development Kit 8 Update 11 (64-bit)
  1033. "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
  1034. "{90150000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2013
  1035. "{90150000-0015-0409-1000-0000000FF1CE}" = Microsoft Access MUI (English) 2013
  1036. "{90150000-0016-0409-1000-0000000FF1CE}" = Microsoft Excel MUI (English) 2013
  1037. "{90150000-0018-0409-1000-0000000FF1CE}" = Microsoft PowerPoint MUI (English) 2013
  1038. "{90150000-0019-0409-1000-0000000FF1CE}" = Microsoft Publisher MUI (English) 2013
  1039. "{90150000-001A-0409-1000-0000000FF1CE}" = Microsoft Outlook MUI (English) 2013
  1040. "{90150000-001B-0409-1000-0000000FF1CE}" = Microsoft Word MUI (English) 2013
  1041. "{90150000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - English
  1042. "{90150000-001F-040C-1000-0000000FF1CE}" = Outils de vérification linguistique 2013 de Microsoft Office - Français
  1043. "{90150000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - Español
  1044. "{90150000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2013
  1045. "{90150000-0044-0409-1000-0000000FF1CE}" = Microsoft InfoPath MUI (English) 2013
  1046. "{90150000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2013
  1047. "{90150000-0090-0409-1000-0000000FF1CE}" = Microsoft DCF MUI (English) 2013
  1048. "{90150000-00A1-0409-1000-0000000FF1CE}" = Microsoft OneNote MUI (English) 2013
  1049. "{90150000-00BA-0409-1000-0000000FF1CE}" = Microsoft Groove MUI (English) 2013
  1050. "{90150000-00C1-0000-1000-0000000FF1CE}" = Microsoft Office 32-bit Components 2013
  1051. "{90150000-00C1-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2013
  1052. "{90150000-00E1-0409-1000-0000000FF1CE}" = Microsoft Office OSM MUI (English) 2013
  1053. "{90150000-00E2-0409-1000-0000000FF1CE}" = Microsoft Office OSM UX MUI (English) 2013
  1054. "{90150000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2013
  1055. "{90150000-0117-0409-1000-0000000FF1CE}" = Microsoft Access Setup Metadata MUI (English) 2013
  1056. "{90150000-012B-0409-1000-0000000FF1CE}" = Microsoft Lync MUI (English) 2013
  1057. "{929FBD26-9020-399B-9A7A-751D61F0B942}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
  1058. "{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
  1059. "2BEE838DC3D664A0CAB23AEA0332BB3877ED0685" = Windows Driver Package - ASUS (ATP) Mouse (01/07/2014 1.0.0.197)
  1060. "CCleaner" = CCleaner
  1061. "McAfee Security Scan" = McAfee Security Scan Plus
  1062. "Mozilla Firefox 52.0.2 (x64 id)" = Mozilla Firefox 52.0.2 (x64 id)
  1063. "Office15.PROPLUS" = Microsoft Office Professional Plus 2013
  1064. "TrueKey" = Intel Security True Key
  1065. "WinRAR archiver" = WinRAR 4.11 (64-bit)
  1066.  
  1067. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
  1068. "{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
  1069. "{0224CACC-994D-45F8-B973-D65056EA9C2F}" = Adobe XMP DVA Panels CS3
  1070. "{0327FA9D-975C-448C-A086-577D57BB25B8}" = Adobe Soundbooth CS3 Codecs
  1071. "{050d4fc8-5d48-4b8f-8972-47c82c46020f}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
  1072. "{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
  1073. "{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
  1074. "{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}" = Adobe After Effects CS3 Presets
  1075. "{1D58229F-C505-45CA-8223-F35F3A34B963}" = Adobe Version Cue CS3 Server
  1076. "{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
  1077. "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Qualcomm Atheros Client Installation Program
  1078. "{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
  1079. "{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}" = Adobe Flash Video Encoder
  1080. "{3421ebee-874e-4668-9a74-fec88239d649}" = Hotspot Shield 6.5.2
  1081. "{35DAA04C-1720-4BE3-A920-A03731EC6A1D}" = Google Earth Pro
  1082. "{4458C442-7376-4CF9-AF58-E8CEA6722363}" = Adobe Setup
  1083. "{485ACF57-F364-440A-8496-E1E81C8FA1AA}" = Adobe Premiere Pro CS3 Third Party Content
  1084. "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
  1085. "{4D3286A6-F6AB-498A-82A4-E4F040529F3D}" = ASUS Smart Gesture
  1086. "{50F102CA-4BE2-41A9-9810-5BB05EB91B9A}" = Adobe Premiere Pro CS3 Functional Content
  1087. "{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
  1088. "{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
  1089. "{54B2EAD9-A110-43F7-B010-2859A1BD2AFE}" = Adobe Encore CS3
  1090. "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
  1091. "{58DCEEE5-532E-44F4-B1D7-A146EF9E9FDA}" = Adobe Premiere Pro CS3
  1092. "{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}" = Realtek Card Reader
  1093. "{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
  1094. "{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
  1095. "{6B52140A-F189-4945-BFFC-DB3F00B8C589}" = Adobe Flash CS3
  1096. "{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
  1097. "{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}" = AHV content for Acrobat and Flash
  1098. "{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
  1099. "{710C34F3-9270-4DF9-AB44-BC8D71DB24F0}" = ArcGIS 10.3 License Manager
  1100. "{7ACFB90E-8FD0-4397-AD3A-5195412623A3}" = Adobe Help Viewer CS3
  1101. "{7C10F5C7-F00F-4BD3-A110-C7D240D2DD25}" = Adobe Dreamweaver CS3
  1102. "{7DFC1012-D346-46CE-B03E-FF79125AE029}" = Adobe Fireworks CS3
  1103. "{80F7CA44-F3A5-4853-8BA6-DDF57CD4F078}" = Rosetta Stone Version 3
  1104. "{83E94EF6-73FC-49AA-9A63-F02AAD7CDD7A}" = Global Mapper 15
  1105. "{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}" = Adobe Video Profiles
  1106. "{8718DC03-D066-4957-94E5-50C3C5042E8E}" = Adobe Creative Suite 3 Master Collection
  1107. "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
  1108. "{884CC64A-405C-4A58-89F4-56C50EE22DCF}" = MOST
  1109. "{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1" = SMADAV version 11.0
  1110. "{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
  1111. "{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
  1112. "{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
  1113. "{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
  1114. "{9A0BC33A-EAA8-4ED4-8D0C-CB9B42B06D7F}" = ArcGIS 10.3 for Desktop
  1115. "{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
  1116. "{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
  1117. "{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
  1118. "{A6B23EFA-6590-482C-A11F-5ACE1B91F5B9}" = Adobe Soundbooth CS3
  1119. "{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package
  1120. "{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
  1121. "{AC76BA86-1033-0000-7760-000000000003}" = Adobe Acrobat 8 Professional
  1122. "{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
  1123. "{AF599C42-A2E5-4251-B7EE-4925B177CBA7}" = Hotspot Shield 6.5.2
  1124. "{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
  1125. "{B671CBFD-4109-4D35-9252-3062D3CCB7B2}" = Adobe SING CS3
  1126. "{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}" = Adobe BridgeTalk Plugin CS3
  1127. "{B8B7A4D8-80E1-4DAE-BD33-7FD535BA3931}" = Adobe Encore CS3 Codecs
  1128. "{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
  1129. "{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}" = Adobe Flash Player 9 ActiveX
  1130. "{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
  1131. "{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
  1132. "{C5BD220A-EFE8-48A5-B70E-9503D535FACE}" = Adobe WAS CS3
  1133. "{CB3F8375-B600-4B9F-83C9-238ED1E583FD}" = Adobe InDesign CS3
  1134. "{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
  1135. "{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
  1136. "{D5A31AB1-345D-47C7-A87B-036A669F6DF1}" = Adobe XMP Panels CS3
  1137. "{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
  1138. "{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
  1139. "{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
  1140. "{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}" = Adobe InDesign CS3 Icon Handler
  1141. "{EB0202F7-016A-410C-ADE4-40F848CCC661}" = Adobe After Effects CS3
  1142. "{EDAAC216-AC73-4152-9654-E12FE5A69F5D}_is1" = CBR Reader
  1143. "{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
  1144. "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
  1145. "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
  1146. "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
  1147. "{FC9E08AA-CD59-4C59-BEF9-87E05B9E37D7}" = Adobe Contribute CS3
  1148. "4K Video Downloader_is1" = 4K Video Downloader 4.1
  1149. "Adobe Flash Player NPAPI" = Adobe Flash Player 25 NPAPI
  1150. "Adobe Flash Player PPAPI" = Adobe Flash Player 24 PPAPI
  1151. "Adobe_4dcfd9b7e901b57f81f667144603236" = Add or Remove Adobe Creative Suite 3 Master Collection
  1152. "ArcGIS 10.3 for Desktop" = ArcGIS 10.3 for Desktop
  1153. "ArcGIS 10.3 License Manager" = ArcGIS 10.3 License Manager
  1154. "ByteFence" = ByteFence Anti-Malware
  1155. "C5A8BC6E-723A-4C0F-96E1-C426D1A4BCA9" = Intel(R) Sideband Fabric Device Driver
  1156. "CDisplay_is1" = CDisplay 1.8
  1157. "DAEMON Tools Lite" = DAEMON Tools Lite
  1158. "DFX" = DFX
  1159. "DjVu Solo 3.1" = DjVu Solo 3.1
  1160. "ezkeyword_is1" = ezkeyword Versi 3.0.0
  1161. "FastStone Photo Resizer" = FastStone Photo Resizer 3.7
  1162. "FileZilla Client" = FileZilla Client 3.14.1
  1163. "GOM Player" = GOM Player
  1164. "Google Chrome" = Google Chrome
  1165. "HotspotShield" = Hotspot Shield 6.5.2
  1166. "Internet Download Manager" = Internet Download Manager
  1167. "KLiteCodecPack_is1" = K-Lite Codec Pack 12.0.1 Full
  1168. "Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.2.1.1043
  1169. "MiniLyrics" = MiniLyrics
  1170. "MozillaMaintenanceService" = Mozilla Maintenance Service
  1171. "OpenOrienteering Mapper 0.5.96" = OpenOrienteering Mapper 0.5.96 x64
  1172. "PhotoScape" = PhotoScape
  1173. "TeamViewer" = TeamViewer 12
  1174. "Universal Maps Downloader_is1" = Universal Maps Downloader 8.9
  1175. "uTorrent" = µTorrent
  1176. "VLC media player" = VLC media player 2.1.1
  1177. "Winamp" = Winamp
  1178. "www.ushareit.com_is1" = SHAREit
  1179.  
  1180. [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]
  1181.  
  1182. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
  1183. "Chromium" = Chromium
  1184.  
  1185. [color=#E56717]========== Last 20 Event Log Errors ==========[/color]
  1186.  
  1187. [ Application Events ]
  1188. Error - 21/04/2017 20:29:02 | Computer Name = ASUS | Source = .NET Runtime | ID = 1026
  1189. Description =
  1190.  
  1191. Error - 21/04/2017 20:29:02 | Computer Name = ASUS | Source = Application Error | ID = 1000
  1192. Description = Faulting application name: EzKeyword.exe, version: 3.0.0.0, time stamp:
  1193. 0x58f1a46f Faulting module name: KERNELBASE.dll, version: 6.3.9600.16408, time stamp:
  1194. 0x523d4548 Exception code: 0xe0434352 Fault offset: 0x00012eec Faulting process id:
  1195. 0x1410 Faulting application start time: 0x01d2bafee37d5021 Faulting application path:
  1196. C:\Program Files (x86)\ezkeyword\EzKeyword.exe Faulting module path: C:\Windows\SYSTEM32\KERNELBASE.dll
  1197. Report
  1198. Id: aebb261f-26f2-11e7-9dbb-08626668ee9c Faulting package full name: Faulting package-relative
  1199. application ID:
  1200.  
  1201. Error - 21/04/2017 20:29:08 | Computer Name = ASUS | Source = Application Error | ID = 1000
  1202. Description = Faulting application name: EzKeyword.exe, version: 3.0.0.0, time stamp:
  1203. 0x58f1a46f Faulting module name: KERNELBASE.dll, version: 6.3.9600.16408, time stamp:
  1204. 0x523d4548 Exception code: 0xc000041d Fault offset: 0x00012eec Faulting process id:
  1205. 0x1410 Faulting application start time: 0x01d2bafee37d5021 Faulting application path:
  1206. C:\Program Files (x86)\ezkeyword\EzKeyword.exe Faulting module path: C:\Windows\SYSTEM32\KERNELBASE.dll
  1207. Report
  1208. Id: b21db933-26f2-11e7-9dbb-08626668ee9c Faulting package full name: Faulting package-relative
  1209. application ID:
  1210.  
  1211. Error - 22/04/2017 2:54:25 | Computer Name = ASUS | Source = .NET Runtime | ID = 1026
  1212. Description =
  1213.  
  1214. Error - 22/04/2017 2:54:25 | Computer Name = ASUS | Source = Application Error | ID = 1000
  1215. Description = Faulting application name: EzKeyword.exe, version: 3.0.0.0, time stamp:
  1216. 0x58f1a46f Faulting module name: KERNELBASE.dll, version: 6.3.9600.16408, time stamp:
  1217. 0x523d4548 Exception code: 0xe0434352 Fault offset: 0x00012eec Faulting process id:
  1218. 0xb58 Faulting application start time: 0x01d2bb004a502338 Faulting application path:
  1219. C:\Program Files (x86)\ezkeyword\EzKeyword.exe Faulting module path: C:\Windows\SYSTEM32\KERNELBASE.dll
  1220. Report
  1221. Id: 85594d0c-2728-11e7-9dbb-08626668ee9c Faulting package full name: Faulting package-relative
  1222. application ID:
  1223.  
  1224. Error - 22/04/2017 2:54:27 | Computer Name = ASUS | Source = Application Error | ID = 1000
  1225. Description = Faulting application name: EzKeyword.exe, version: 3.0.0.0, time stamp:
  1226. 0x58f1a46f Faulting module name: KERNELBASE.dll, version: 6.3.9600.16408, time stamp:
  1227. 0x523d4548 Exception code: 0xc000041d Fault offset: 0x00012eec Faulting process id:
  1228. 0xb58 Faulting application start time: 0x01d2bb004a502338 Faulting application path:
  1229. C:\Program Files (x86)\ezkeyword\EzKeyword.exe Faulting module path: C:\Windows\SYSTEM32\KERNELBASE.dll
  1230. Report
  1231. Id: 86a2557b-2728-11e7-9dbb-08626668ee9c Faulting package full name: Faulting package-relative
  1232. application ID:
  1233.  
  1234. Error - 28/04/2017 4:43:26 | Computer Name = ASUS | Source = Application Error | ID = 1000
  1235. Description = Faulting application name: EXCEL.EXE, version: 15.0.4420.1017, time
  1236. stamp: 0x506741b5 Faulting module name: EXCEL.EXE, version: 15.0.4420.1017, time
  1237. stamp: 0x506741b5 Exception code: 0xc0000005 Fault offset: 0x0000000000d18964 Faulting
  1238. process id: 0x134c Faulting application start time: 0x01d2bff9d762e50b Faulting application
  1239. path: C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE Faulting module path: C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE
  1240. Report
  1241. Id: be48db01-2bee-11e7-9dbe-08626668ee9c Faulting package full name: Faulting package-relative
  1242. application ID:
  1243.  
  1244. Error - 28/04/2017 8:42:23 | Computer Name = ASUS | Source = Application Error | ID = 1000
  1245. Description = Faulting application name: EXCEL.EXE, version: 15.0.4420.1017, time
  1246. stamp: 0x506741b5 Faulting module name: EXCEL.EXE, version: 15.0.4420.1017, time
  1247. stamp: 0x506741b5 Exception code: 0xc0000005 Fault offset: 0x0000000000889493 Faulting
  1248. process id: 0x700 Faulting application start time: 0x01d2c011e03ebd6a Faulting application
  1249. path: C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE Faulting module path: C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE
  1250. Report
  1251. Id: 1fe62f72-2c10-11e7-9dbe-08626668ee9c Faulting package full name: Faulting package-relative
  1252. application ID:
  1253.  
  1254. Error - 28/04/2017 13:35:24 | Computer Name = ASUS | Source = Microsoft-Windows-WMI | ID = 28
  1255. Description = Failed to Initialize WMI Core or Provider SubSystem or Event SubSystem
  1256. with error number 0x80090017. This could be due to a badly installed version of
  1257. WMI, WMI repository upgrade failure, insufficient disk space or insufficient memory.
  1258.  
  1259. Error - 28/04/2017 15:47:18 | Computer Name = ASUS | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
  1260. Description = Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Calendar
  1261. failed with error: -2144927150 See the Microsoft-Windows-TWinUI/Operational log
  1262. for additional information.
  1263.  
  1264.  
  1265. < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement