cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2017.10.2.173 Par Nicolas Coolman (2017/10/02)
~ Démarré par LENOVO (Administrator) (2017/10/13 16:18:03)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Legal
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Users\Public\Documents\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\LENOVO\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Démarrage du système: Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 10586) =>.Microsoft Corporation

---\\ Navigateurs Internet (2) - 0s
~ MSIE: Microsoft Edge v40
~ MSIE: Internet Explorer v11.589.10586.0

---\\ Informations sur les produits Windows (3) - 3s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK

---\\ Logiciels de protection (3) - 28s
Avast Antivirus Gratuit v17.6.2310 (Protection)
SMADAV version 11.3 v11.3 (Protection)
Windows Defender (Deactivate)

---\\ Surveillance de Logiciels (2) - 30s
~ Adobe Flash Player 27 NPAPI (Surveillance)
~ Adobe Acrobat Reader DC - Français (Surveillance)

---\\ Informations sur le système (6) - 0s
~ Operating System: Intel64 Family 6 Model 42 Stepping 7, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 2009.228 MB (14% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 34 GB (12%) free of 267 GB : OK =>.Disk Space

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: LENOVO-PC
~ User Name: LENOVO
~ Logged in as Administrator

---\\ Enumération des unités disques (2) - 0s
~ Drive C: has 34 GB free of 267 GB (System)
~ Drive G: has 55 GB free of 208 GB

---\\ Etat du Centre de Sécurité Windows (7) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Recherche particulière de fichiers génériques (25) - 6s
[MD5.02ADAC7A8D203C70BC0FBB34836DD4E6] - 06/09/2016 - (.Microsoft Corporation - Explorateur Windows.) -- C:\WINDOWS\Explorer.exe [4515256] =>.Microsoft Windows®
[MD5.0DCB89B1F3689BC6262FF30BBD603171] - 29/10/2015 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\WINDOWS\System32\rundll32.exe [59392] =>.Microsoft Corporation
[MD5.C1C81AAF533552B3C4D9F11A5FF97700] - 22/04/2016 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\WINDOWS\System32\Wininit.exe [291360] =>.Microsoft Windows Publisher®
[MD5.7CB38AB0088D91B6E3E24BCA52007B7A] - 06/09/2016 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\WINDOWS\System32\wininet.dll [3078656] =>.Microsoft Corporation
[MD5.5C156EC4E44E30331BCC865A3B61D839] - 22/04/2016 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\WINDOWS\System32\Winlogon.exe [585728] =>.Microsoft Corporation
[MD5.9EEAA1B69DC3FD620AE576CC8F4147DC] - 29/10/2015 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\WINDOWS\System32\sppcomapi.dll [430592] =>.Microsoft Corporation
[MD5.9A3E17CDB177913C2A111C80F3D0DBB4] - 29/03/2016 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\WINDOWS\System32\dnsapi.dll [686976] =>.Microsoft Windows®
[MD5.6A7ACABAE92C837F5C1330188EAE36AE] - 29/03/2016 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\WINDOWS\Syswow64\dnsapi.dll [535080] =>.Microsoft Windows®
[MD5.CE50037751671682D1FDBBE7C9B37F4A] - 30/10/2015 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\WINDOWS\System32\fr-FR\user32.dll.mui [20480] =>.Microsoft Corporation
[MD5.70148EFA9A562E7185B75BBE7D376BF7] - 05/11/2015 - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\WINDOWS\System32\drivers\AFD.sys [578912] =>.Microsoft Windows®
[MD5.492B99D2E3D5D7BFD5F0AE1BE7BD37DD] - 29/10/2015 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [28512] =>.Microsoft Windows®
[MD5.7F9C7226D743B232907ED2537B8A574F] - 29/10/2015 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [92672] =>.Microsoft Corporation
[MD5.82D97776BF982AA143BDC7DFB5054EA8] - 29/10/2015 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [173568] =>.Microsoft Corporation
[MD5.935823F79CBEDB91637B63D37E3A5A36] - 28/03/2016 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\DfsC.sys [148480] =>.Microsoft Corporation
[MD5.84BC034B6BB763733C1949B7B9BAF976] - 29/10/2015 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [79872] =>.Microsoft Corporation
[MD5.53FDD9E69189E546DE4740F8C4D8AB2F] - 29/10/2015 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [114688] =>.Microsoft Corporation
[MD5.9E5E8F2A1996F23B7E9687846AA81B01] - 29/10/2015 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [143360] =>.Microsoft Corporation
[MD5.E7D59C52DE0C19C3179114D028EAA4B7] - 06/09/2016 - (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [430944] =>.Microsoft Windows®
[MD5.C03E926B0E7D66D68994067231DC3246] - 27/05/2016 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [278528] =>.Microsoft Corporation
[MD5.19BD8A88AAC580592668B070AC0727D9] - 29/03/2016 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\WINDOWS\System32\drivers\ntfs.sys [2152280] =>.Microsoft Windows®
[MD5.7D0FC96264C0F8F2C1321E33E8EB646C] - 29/10/2015 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\WINDOWS\System32\drivers\Parport.sys [96768] =>.Microsoft Corporation
[MD5.E3C82823B22463BC38AA4F8ADA852624] - 23/02/2016 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [104960] =>.Microsoft Corporation
[MD5.1DC2CC74B51E4DC4CD5A20C1021E4010] - 30/10/2015 - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [173056] =>.Microsoft Corporation
[MD5.91D3F2A6253EF83EFBD7903028F58C4D] - 05/11/2015 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [118624] =>.Microsoft Windows®
[MD5.E1F91A727A04C9F8199D04FF3BBBF63C] - 29/10/2015 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\WINDOWS\System32\drivers\volsnap.sys [414560] =>.Microsoft Windows®

---\\ Liste des services NT non Microsoft et non désactivés (9) - 25s
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
O23 - Service: Avast Antivirus (avast! Antivirus) . (.AVAST Software - Avast Service.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe =>.AVAST Software s.r.o.®
O23 - Service: CDROM_Eject_H (CDROM_Eject_H) . (...) - C:\Program Files\Camtel CE682\HEject.exe
O23 - Service: Elan Service (ETDService) . (.ELAN Microelectronics Corp. - Elan Service.) - C:\Program Files\Elantech\ETDService.exe =>.ELAN Microelectronics Corporation®
O23 - Service: GoogleChromeUpService (GoogleChromeUpService) . (...) - C:\ProgramData\service.exe (.not file.) =>PUP.Optional.Zusy
O23 - Service: HUAWEIWiMAX (HUAWEIWiMAX) . (...) - C:\Program Files (x86)\WiMAX Connection Manager\Service\HUAWEIWiMAX.exe =>.Huawei Technologies Co.,Ltd
O23 - Service: YAC Service (iSafeService) . (.Elex do Brasil Participações Ltda - iSafeSvc.) - C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe =>.SUP.Elex
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation®
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl®

---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (12) - 95s
SR - Auto [19/07/2017] [ 83032] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
SS - Demand [11/10/2017] [ 272384] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated®
SR - Demand [12/10/2017] [ 7452288] aswbIDSAgent (aswbIDSAgent) . (.AVAST Software s.r.o..) - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe =>.AVAST Software s.r.o.®
SR - Auto [12/10/2017] [ 275208] Avast Antivirus (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe =>.AVAST Software s.r.o.®
SR - Auto [18/11/2013] [ 306176] CDROM_Eject_H (CDROM_Eject_H) . (...) - C:\Program Files\Camtel CE682\HEject.exe
SS - Demand [01/06/2015] [ 290224] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe =>.Intel Corporation - pGFX®
SR - Auto [06/10/2015] [ 144072] Elan Service (ETDService) . (.ELAN Microelectronics Corp..) - C:\Program Files\Elantech\ETDService.exe =>.ELAN Microelectronics Corporation®
SS - Demand [07/10/2009] [ 77824] France Telecom Routing Table Service (FTRTSVC) . (.France Telecom SA.) - C:\Program Files (x86)\Common Files\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe =>.France Telecom SA
SR - Auto [25/09/2013] [ 89088] HUAWEIWiMAX (HUAWEIWiMAX) . (...) - C:\Program Files (x86)\WiMAX Connection Manager\Service\HUAWEIWiMAX.exe =>.Huawei Technologies Co.,Ltd
SS - Auto [01/12/2016] [ 131024] YAC Service (iSafeService) . (.Elex do Brasil Participações Ltda.) - C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe =>.SUP.Elex
SR - Auto [20/12/2010] [ 325656] Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe =>.Intel Corporation®
SS - Auto [09/07/2015] [ 327296] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl®

---\\ Tâches planifiées en automatique (Registre) (158) - 42s
O38 - TASK: {01FA44D0-D945-4962-825B-69C1C32894A8} [64Bits][\RunAsStdUser Task] - (.RunAsStdUser - .) -- C:\Program Files (x86)\iWin Games\iWinGames.exe (.not file.) [0] (.Orphan.) =>PUP.Optional.iWinArcade
O38 - TASK: {027A773E-8EED-4F02-8D3F-C7786DC69C35} [64Bits][\Updater_Online_Application] - (.Microleaves - Online Application Updater 2.6.0 © Microle.) -- C:\Program Files (x86)\Microleaves\Online Application\Online Application Updater.exe [879984] =>.SUP.Microleaves
O38 - TASK: {02D29941-3208-47A6-A68F-6BFFF8A122F0} [64Bits][\Microsoft\Windows\Media Center\PeriodicScanRetry] - (...) -- C:\WINDOWS\ehome\MCUpdate.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {08629A58-75ED-46AA-8646-8C7015698215} [64Bits][\Microsoft\Windows\WindowsUpdate\sihboot] - (.Microsoft Corporation - Client SIH.) -- C:\WINDOWS\System32\sihclient.exe [203264] =>.Microsoft Corporation
O38 - TASK: {088482FA-65B8-4E17-9ABF-1DCD48E8D373} [64Bits][\Microsoft\Windows\Tcpip\IpAddressConflict1] - (.Microsoft Corporation - API cliente de cadre de Diagnostic réseau.) -- C:\Windows\System32\ndfapi.dll [270336] =>.Microsoft Corporation
O38 - TASK: {08867BF6-3AFC-430C-A881-4660A6F54017} [64Bits][\Avast Emergency Update] - (.AVAST Software - Avast Emergency Update.) -- C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2388056] =>.AVAST Software s.r.o.®
O38 - TASK: {09A65862-66EF-45BE-B9F6-46EFB7E454A1} [64Bits][\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance] - (.Microsoft Corporation - Microsoft Malware Protection Command Line U.) -- C:\Program Files\Windows Defender\MpCmdRun.exe [370272] =>.Microsoft Corporation®
O38 - TASK: {09F06BFE-A3C8-40E3-846A-6E6F4000C238} [64Bits][\Microsoft\Windows\Tcpip\IpAddressConflict2] - (.Microsoft Corporation - API cliente de cadre de Diagnostic réseau.) -- C:\Windows\System32\ndfapi.dll [270336] =>.Microsoft Corporation
O38 - TASK: {0C4E406A-F635-48D0-9180-B1FB9DFBE6CF} [64Bits][\{CE26D11F-78DA-4E9E-A8F2-4EE2B4529478}] - (...) -- C:\Users\LENOVO\Downloads\aroundtheworld_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {0CFE2E40-6A97-48C5-9F38-DE82315CF1B0} [64Bits][\Microsoft\Windows\UPnP\UPnPHostConfig] - (.Microsoft Corporation - Outil de configuration du Gestionnaire de c.) -- C:\Windows\System32\sc.exe [68096] =>.Microsoft Corporation
O38 - TASK: {141029C2-1390-4C3A-AD07-B295D00106EC} [64Bits][\Driver Booster SkipUAC (LENOVO)] - (...) -- C:\Program Files (x86)\IObit\Driver Booster\4.2.0\DriverBooster.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {1513F486-8706-4EE2-939F-4B905696833B} [64Bits][\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan] - (.Microsoft Corporation - Microsoft Malware Protection Command Line U.) -- C:\Program Files\Windows Defender\MpCmdRun.exe [370272] =>.Microsoft Corporation®
O38 - TASK: {1991A07A-C0E6-4C3B-A499-6F95A2870B2C} [64Bits][\Microsoft\Windows\Media Center\ReindexSearchRoot] - (...) -- C:\WINDOWS\ehome\ehPrivJob.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {1A438DBA-6F47-44D6-8207-124A92E1597E} [64Bits][\Microsoft\Windows\ApplicationData\CleanupTemporaryState] - (.Microsoft Corporation - Windows Application Data API Server.) -- C:\Windows\System32\Windows.Storage.ApplicationData.dll [337328] =>.Microsoft Windows®
O38 - TASK: {1A5947A8-D846-4CBB-B82A-237EDAD98691} [64Bits][\{E13197BA-522A-4395-9D91-8075E635E099}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {1ABBA4DD-21D4-43E7-81C7-F9C49282C5FA} [64Bits][\{EC268F52-C7B4-4B28-A40D-FCFBDDD6CD15}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {1CCAEE92-289B-4AF8-9D10-41B54CCC3625} [64Bits][\Microsoft\Windows\Media Center\UpdateRecordPath] - (...) -- C:\WINDOWS\ehome\ehPrivJob.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {1F530B71-AF88-49DC-AE00-AAD24E828906} [64Bits][\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask] - (...) -- C:\WINDOWS\ehome\mcupdate.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {2225FD6F-0959-4E6E-B9F7-0B2554C099B8} [64Bits][\Microsoft\Windows\Media Center\PvrScheduleTask] - (...) -- C:\WINDOWS\ehome\mcupdate.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {22DF95EE-A3BC-4A00-8468-0FF46BF970FC} [64Bits][\Microsoft\Windows\Windows Error Reporting\QueueReporting] - (.Microsoft Corporation - Windows Problem Reporting.) -- C:\WINDOWS\system32\wermgr.exe [147808] =>.Microsoft Windows®
O38 - TASK: {2B307AD0-33EA-4DB6-81B3-05FEADBE1140} [64Bits][\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization] - (.Microsoft Corp. - Module de défragmenteur de disque.) -- C:\WINDOWS\system32\defrag.exe [187392] =>.Microsoft Corp.
O38 - TASK: {2BBFDF1D-ED62-41EE-BB05-9F7CA538092D} [64Bits][\Microsoft\Windows\WindowsBackup\Windows Backup Monitor] - (.Microsoft Corporation - Sauvegarde Microsoft® Windows.) -- C:\WINDOWS\System32\sdclt.exe [1226752] =>.Microsoft Corporation
O38 - TASK: {2D83BE47-CAE9-40A6-A859-061A784D79F1} [64Bits][\{5285D5A6-A041-4772-B672-CEBBCCD7F9A7}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {37307B43-41DC-4BBE-BF3B-9B1631BEE311} [64Bits][\Microsoft\Windows\MUI\LPRemove] - (.Microsoft Corporation - MUI Language pack cleanup.) -- C:\WINDOWS\system32\lpremove.exe [68608] =>.Microsoft Corporation
O38 - TASK: {39191456-CABB-44DD-9B65-47D105DE4BB2} [64Bits][\{CDFF73BC-98A4-40F0-BAF8-B0316E5F93EA}] - (...) -- C:\Users\LENOVO\Downloads\dreamdaywedding-112270203-setup.s112270203.c110341560.len.u0c9cddcd3f8fbc2ea4e8e8ef6be01e1cbec1b11d.dl.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {3991D558-31E2-4714-AE27-63F67215F782} [64Bits][\{638C70F6-3679-494A-B300-0F0776904C95}] - (...) -- C:\Program Files (x86)\LiveSupport\LiveSupport.exe (.not file.) [0] (.Orphan.) =>PUP.Optional.LiveSupport
O38 - TASK: {3C705DD5-FF5B-401E-83FE-A02BA5C74399} [64Bits][\Microsoft\Windows\Media Center\PBDADiscoveryW2] - (...) -- C:\WINDOWS\ehome\ehPrivJob.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {3E829439-8226-4A77-9B11-838A83FD52E8} [64Bits][\{1E9A6F55-E08D-4E99-BF17-9FD00F68FBAF}] - (...) -- C:\Users\LENOVO\Documents\Around The World in 80 Days\game.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {41292781-55FC-4D9C-87BD-A0F908545CC0} [64Bits][\Microsoft\Windows\Media Center\OCURActivate] - (...) -- C:\WINDOWS\ehome\ehPrivJob.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {4208A7BF-D622-476E-A1A3-F9EB2719ECD4} [64Bits][\Microsoft\Windows\Management\Provisioning\Logon] - (.Microsoft Corporation - Provisioning package runtime processing too.) -- C:\WINDOWS\system32\ProvTool.exe [56320] =>.Microsoft Corporation
O38 - TASK: {421E80F3-8E9E-4A21-816B-ED275D19DFFF} [64Bits][\Microsoft\Windows\RemovalTools\MRT_ERROR_HB] - (.Microsoft Corporation - Outil de suppression de logiciels malveilla.) -- C:\WINDOWS\system32\MRT.exe [144199024] =>.Microsoft Windows®
O38 - TASK: {43744BF4-03F7-4B73-87FC-2BA232F6D655} [64Bits][\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser] - (.Microsoft Corporation - Tâche de l’analyseur d’expérience de compte.) -- C:\WINDOWS\System32\MbaeParserTask.exe [115712] =>.Microsoft Corporation
O38 - TASK: {4585F16E-E875-4443-A691-1557606B4914} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Maintenance Install] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [19968] =>.Microsoft Corporation
O38 - TASK: {47B2070E-4A1C-4538-8B2D-DE2BEBE2FBED} [64Bits][\{556FDF99-14CF-45D9-B538-3BB18156E702}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {4858AB94-5B05-463D-A994-6C132A5E10BF} [64Bits][\{819FF07D-51C4-40F9-9BCB-2AEA3EF2749F}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {48E4EF46-2962-499E-B496-FD87DEFA9D4D} [64Bits][\Microsoft\Windows\Feedback\Siuf\DmClient] - (.Microsoft Corporation - Microsoft Feedback SIUF Deployment Manager.) -- C:\WINDOWS\system32\dmclient.exe [63488] =>.Microsoft Corporation
O38 - TASK: {4903D8F2-DDE6-4B93-9921-2819C297E2D6} [64Bits][\GoforFilesUpdate] - (.http://www.goforfiles.com/ - .) -- C:\Program Files (x86)\GoforFiles\GFFUpdater.exe (.not file.) [0] (.Orphan.) =>PUP.Optional.YourFileDownloader
O38 - TASK: {4BC5D02D-368A-405A-B471-F9CAB6666731} [64Bits][\Microsoft\Windows\WindowsUpdate\Scheduled Start] - (.Microsoft Corporation - Outil de configuration du Gestionnaire de c.) -- C:\Windows\System32\sc.exe [68096] =>.Microsoft Corporation
O38 - TASK: {4C5A8A03-2384-464F-AEAA-F58928D854D8} [64Bits][\Microsoft\Windows\DiskFootprint\Diagnostics] - (.Microsoft Corporation - DiskSnapshot.exe.) -- C:\WINDOWS\system32\disksnapshot.exe [82432] =>.Microsoft Corporation
O38 - TASK: {4E4954A6-C22F-4537-87FE-9A696B7BF9C4} [64Bits][\Microsoft\Windows\Location\WindowsActionDialog] - (.Microsoft Corporation - Service Broker pour la boîte de dialogue Ac.) -- C:\WINDOWS\System32\WindowsActionDialog.exe [39936] =>.Microsoft Corporation
O38 - TASK: {52362630-34B3-46AA-8508-9857D8B13B4F} [64Bits][\Microsoft\Windows\Sysmain\WsSwapAssessmentTask] - (.Microsoft Corporation - Hôte de service Superfetch.) -- C:\Windows\System32\sysmain.dll [1088512] =>.Microsoft Corporation
O38 - TASK: {53EDBB7E-EDA3-4204-ABE3-FA305856939A} [64Bits][\Microsoft\Windows\Media Center\RegisterSearch] - (...) -- C:\WINDOWS\ehome\ehPrivJob.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {54A4AE1A-EE50-4681-9F70-25DA22B7173A} [64Bits][\{FA1FC01C-D9A2-4E3A-8196-549866F94F0F}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {5584FEB1-0462-42CA-B51B-13B85F135F5D} [64Bits][\{EEC37A3B-AB09-4579-9B49-2F68DCBBDB8D}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {57ED60D2-6B0B-4069-90B4-50B067491212} [64Bits][\Microsoft\Windows\Time Synchronization\SynchronizeTime] - (.Microsoft Corporation - Outil de configuration du Gestionnaire de c.) -- C:\WINDOWS\system32\sc.exe [68096] =>.Microsoft Corporation
O38 - TASK: {5933A242-E43F-4877-B4C7-0DF6BE23EE97} [64Bits][\Microsoft\Windows\WindowsBackup\AutomaticBackup] - (.Microsoft Corporation - Moteur de sauvegarde Microsoft® Windows.) -- C:\Windows\System32\sdengin2.dll [1213440] =>.Microsoft Corporation
O38 - TASK: {5A0411B9-5453-4D32-B35F-1FF11FEE7DCB} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Resume On Boot] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [19968] =>.Microsoft Corporation
O38 - TASK: {5BDEA729-F3AC-40B2-9BDB-23C86C9CF6E6} [64Bits][\Microsoft\Windows\Media Center\mcupdate_scheduled] - (. - Check for Media Center updates..) -- C:\WINDOWS\ehome\mcupdate (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {5E99DB52-C2B2-418A-84E5-B4D6D7384D91} [64Bits][\Ghesoing Host] - (.Glarysoft Ltd - Glary Utilities AutoUpdate.) -- C:\Program Files (x86)\Coesition\xerwut.exe [1022448] =>.Glarysoft LTD®
O38 - TASK: {5F86794D-D906-44E3-A6E6-40A6E4580E80} [64Bits][\Adobe Acrobat Update Task] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1165920] =>.Adobe Systems, Incorporated®
O38 - TASK: {6132659C-6BA7-4F3A-B427-CAE4119590AB} [64Bits][\Microsoft\Windows\Media Center\PvrRecoveryTask] - (...) -- C:\WINDOWS\ehome\mcupdate.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {6189D146-D0F9-49B7-B8F8-A10D99263929} [64Bits][\{372E848F-6076-4630-9028-2978DDF68104}] - (...) -- C:\Program Files (x86)\LiveSupport\LiveSupport.exe (.not file.) [0] (.Orphan.) =>PUP.Optional.LiveSupport
O38 - TASK: {61E97BCB-528E-4B3C-A43A-CDFC978E48E7} [64Bits][\Microsoft\Windows\AppID\PolicyConverter] - (.Microsoft Corporation - AppID Policy Converter Task.) -- C:\WINDOWS\system32\appidpolicyconverter.exe [161280] =>.Microsoft Corporation
O38 - TASK: {64AB42DE-F0EA-4628-8EC6-846C42A0788D} [64Bits][\Microsoft\Windows\Multimedia\Manager] - (...) -- C:\Users\LENOVO\AppData\Roaming\Adobe\Manager.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {64BDC5AE-5FEC-4803-B20B-6F45301E1F9C} [64Bits][\Microsoft\Windows\Media Center\PBDADiscovery] - (...) -- C:\WINDOWS\ehome\ehPrivJob.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {669C5EEB-85F9-409A-A8FF-51492CA1401D} [64Bits][\{BF9BD17E-1ADA-4E54-9897-E889846D3AF0}] - (...) -- C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {673AE9F9-4D27-4A87-8B77-32C776BDEEF5} [64Bits][\Microsoft\Windows\Media Center\StartRecording] - (...) -- C:\WINDOWS\ehome\ehrec (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {6A2B31E0-3CFF-473D-A2D2-2C1FE4674293} [64Bits][\{672E28BE-05EC-4A68-A9F6-0CA51DE4A5EA}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {6B696BCF-C866-41CA-B4E4-3D19FB1E9250} [64Bits][\Microsoft\Windows\SpacePort\SpaceManagerTask] - (.Microsoft Corporation - Storage Spaces Manager.) -- C:\WINDOWS\system32\SpaceMan.exe [34304] =>.Microsoft Corporation
O38 - TASK: {6C0534C5-B986-4714-86BB-776F0B42052C} [64Bits][\Microsoft\Windows\Media Center\ConfigureInternetTimeService] - (...) -- C:\WINDOWS\ehome\ehPrivJob.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {6CC86CDF-94A2-4560-A79F-4EBE5C067446} [64Bits][\Online Application V2G3] - (.WORKGROUP\LENOVO-PC$ - .) -- C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe (.not file.) [0] (.Orphan.) =>.SUP.Microleaves
O38 - TASK: {6D36D3DE-B1F6-404F-8B5B-C594DB2B13E8} [64Bits][\{800998B4-07D8-4CDC-8956-797FB0D04A3D}] - (...) -- C:\Users\LENOVO\Downloads\epicadventures_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {6F069022-3CD8-4D59-B0B4-0A02317FD8F0} [64Bits][\Microsoft\Windows\Windows Defender\Windows Defender Verification] - (.Microsoft Corporation - Microsoft Malware Protection Command Line U.) -- C:\Program Files\Windows Defender\MpCmdRun.exe [370272] =>.Microsoft Corporation®
O38 - TASK: {6F338C7B-DDCE-40C9-BB6F-F092BCA1F77F} [64Bits][\{1A40EF62-E758-4A9C-A095-FBF2D3CD9DEF}] - (...) -- D:\Windows7\11_Camera\Install.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {70F86019-0F19-4552-BDF8-8676699B8424} [64Bits][\{CF866A90-1C10-4442-8A8A-B5A1D7771D9E}] - (...) -- E:\BWASetup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {7324D1A0-5AD8-466A-B90A-DD55254EAF0A} [64Bits][\{7E609438-73F5-4CB0-BB33-378CC81FE8DD}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {73F84A2E-E267-44CD-AE43-26F5FADC07BC} [64Bits][\Microsoft\Windows\WS\License Validation] - (.Microsoft Corporation - Client de gestion de licences du Windows St.) -- C:\Windows\System32\WSClient.dll [185344] =>.Microsoft Corporation
O38 - TASK: {7464E64D-F916-44C4-8B4D-8285C95325A1} [64Bits][\Microsoft\Windows\WCM\WiFiTask] - (.Microsoft Corporation - Tâche sans fil en arrière-plan.) -- C:\WINDOWS\System32\WiFiTask.exe [413536] =>.Microsoft Windows®
O38 - TASK: {74D71BBF-E798-410F-852B-22CF0E4DE205} [64Bits][\{4908A665-3C56-41DF-9103-02180C3C390B}] - (...) -- C:\Users\LENOVO\Documents\paule francine\setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {74F2D99F-2AC6-40CF-8D83-61FD6B085438} [64Bits][\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot] - (.Microsoft Corporation - MusNotificationBroker.) -- C:\windows\system32\MusNotification.exe [189952] =>.Microsoft Corporation
O38 - TASK: {7506EE3F-10D4-4FCF-9DDD-77B8FF1182D4} [64Bits][\Microsoft\Windows\SpacePort\SpaceAgentTask] - (.Microsoft Corporation - Paramètres des espaces de stockage.) -- C:\WINDOWS\system32\SpaceAgent.exe [121344] =>.Microsoft Corporation
O38 - TASK: {7594B08E-18BF-45C9-8880-9794CC9D1DCF} [64Bits][\{C758FF3F-9A0F-4D48-842D-6518E5749396}] - (...) -- C:\Users\LENOVO\Documents\Around The World in 80 Days\game.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {78048FAE-0623-496B-AF26-91FE4C77695D} [64Bits][\Microsoft\Windows\Media Center\SqlLiteRecoveryTask] - (...) -- C:\WINDOWS\ehome\mcupdate.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {797A9B7D-9756-45DA-9FAF-B1B0EA2FB8A3} [64Bits][\DTChk] - (.Search Results, LLC - DT Check.) -- C:\Users\Public\Util\DTChk.exe [197232] =>PUP.Optional.IMBooster
O38 - TASK: {7AE1BCAC-061D-4672-BACB-88BC74CE1D7A} [64Bits][\Microsoft\Windows\Application Experience\ProgramDataUpdater] - (.Microsoft Corporation - Microsoft Compatibility Telemetry.) -- C:\WINDOWS\system32\compattelrunner.exe [50368] =>.Microsoft Corporation®
O38 - TASK: {7BC0D930-20AA-4354-9CD6-D1B2B4B01429} [64Bits][\{CC12C9BA-4908-4C43-9FAD-52F9564F2CA0}] - (...) -- C:\Users\LENOVO\Documents\Around The World in 80 Days\game.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {7BC12C89-A012-46EA-B9EB-052EB5CD4326} [64Bits][\Microsoft\Windows\Windows Media Sharing\UpdateLibrary] - (.Microsoft Corporation - Application de configuration du service Par.) -- C:\Program Files\Windows Media Player\wmpnscfg.exe [71680] =>.Microsoft Corporation
O38 - TASK: {7BD8F44E-530D-41CF-B1D0-B9BB0B0C1C73} [64Bits][\Microsoft\Windows\Time Zone\SynchronizeTimeZone] - (.Microsoft Corporation - TimeZone Sync Task.) -- C:\WINDOWS\system32\tzsync.exe [64000] =>.Microsoft Corporation
O38 - TASK: {808DDCCD-531B-4912-8B5B-82243A5F2D84} [64Bits][\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver] - (.Microsoft Corporation - Outil de résolution des défaillances disque.) -- C:\WINDOWS\system32\DFDWiz.exe [78848] =>.Microsoft Corporation
O38 - TASK: {82EDE977-0B47-4F1B-96C9-FFFA39BA27CC} [64Bits][\User_Feed_Synchronization-{B4BF3F47-E237-4D84-A295-3EF22628AE12}] - (.Microsoft Corporation - Microsoft Feeds Synchronization.) -- C:\Windows\System32\msfeedssync.exe [14336] =>.Microsoft Corporation
O38 - TASK: {85B48615-1F16-4128-A513-3FA544E7A31B} [64Bits][\Microsoft\Windows\Windows Defender\Windows Defender Cleanup] - (.Microsoft Corporation - Microsoft Malware Protection Command Line U.) -- C:\Program Files\Windows Defender\MpCmdRun.exe [370272] =>.Microsoft Corporation®
O38 - TASK: {860F596C-A1D8-4651-B747-D134041D80AD} [64Bits][\Microsoft\Windows\DiskFootprint\StorageSense] - (.Microsoft Corporation - Storage Usage.) -- C:\WINDOWS\system32\StorageUsage.dll [30208] =>.Microsoft Corporation
O38 - TASK: {8713ADC6-927D-4504-921C-62DF411A5AE1} [64Bits][\Microsoft\Windows\Media Center\mcupdate] - (...) -- C:\WINDOWS\ehome\mcupdate (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {89125235-CC35-4E54-92FA-31837F9BA1C4} [64Bits][\{D571BCB5-1B74-4B0B-8B1D-F6822D7C7488}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {89591734-AA0E-4BC8-AC0E-0A76CED3824C} [64Bits][\Microsoft\Windows\Media Center\OCURDiscovery] - (...) -- C:\WINDOWS\ehome\ehPrivJob.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {8967C7AC-6C34-4FFE-8FCC-7AD1F87AF1D9} [64Bits][\{AD50FB38-FB75-4040-8331-76DD2FF74209}] - (...) -- C:\Users\Public\Documents\Desktop\RTMI2.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {89CF964B-C004-40A9-ABBD-D0DB801924FE} [64Bits][\{97EAB407-A309-4C41-B5F6-F24C036D7F72}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {8BF6C715-8BD3-4A58-B74A-CA2F65B4C599} [64Bits][\{02090A92-A1AD-48FF-9DD1-F5B17E5D1298}] - (...) -- C:\Users\LENOVO\Downloads\wedding_setup(1).exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {8C488EAC-FA00-42EB-A2E1-9202769B36F1} [64Bits][\Online Application V2G1] - (.WORKGROUP\LENOVO-PC$ - .) -- C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe (.not file.) [0] (.Orphan.) =>.SUP.Microleaves
O38 - TASK: {8DAE7A60-9C57-4E37-AABF-46D64E432634} [64Bits][\Online Application V2G2] - (.WORKGROUP\LENOVO-PC$ - .) -- C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe (.not file.) [0] (.Orphan.) =>.SUP.Microleaves
O38 - TASK: {8E31BEBC-68F5-4892-BC8A-A83BC5366B30} [64Bits][\{E9ECEEF4-DB37-48A0-ADC6-A5147E171EC9}] - (...) -- C:\Users\LENOVO\Documents\Around The World in 80 Days\game.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {90D79106-3D12-40AF-A9BA-231F2327770C} [64Bits][\Microsoft\Windows\DUSM\dusmtask] - (.Microsoft Corporation - DUSM Task.) -- C:\WINDOWS\System32\dusmtask.exe [27136] =>.Microsoft Corporation
O38 - TASK: {94A821BB-028B-4486-B6BF-074076D450F7} [64Bits][\Adobe Flash Player Updater] - (.Adobe Systems Incorporated - Adobe® Flash® Player Update Service 27.0 r0.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [272384] =>.Adobe Systems Incorporated®
O38 - TASK: {95EA2E99-EAA2-41B4-8BE2-76B871853A80} [64Bits][\Microsoft\Windows\Media Center\ActivateWindowsSearch] - (...) -- C:\WINDOWS\ehome\ehPrivJob.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {97601E9E-9C9C-415D-B81D-9F86ACA7CDC5} [64Bits][\Microsoft\Windows\Defrag\ScheduledDefrag] - (.Microsoft Corp. - Module de défragmenteur de disque.) -- C:\WINDOWS\system32\defrag.exe [187392] =>.Microsoft Corp.
O38 - TASK: {987787A7-E2BB-4B8B-815A-CA49FB457B6E} [64Bits][\{054EBD86-E2DC-4991-BE25-DD844D07C12E}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {9BF4AC5E-F818-4E58-8B02-4EEDD7A0CB8A} [64Bits][\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector] - (.Microsoft Corporation - Module de diagnostics des erreurs de disque.) -- C:\Windows\System32\dfdts.dll [47616] =>.Microsoft Corporation
O38 - TASK: {9F1E53E1-A53E-47D5-8791-FE2B1867E8BE} [64Bits][\Microsoft\Windows Defender\MpIdleTask] - (.Microsoft Corporation - Microsoft Malware Protection Command Line U.) -- c:\program files\windows defender\MpCmdRun.exe [370272] =>.Microsoft Corporation®
O38 - TASK: {9FFB29C5-38ED-47CB-B89B-EA84708EBA65} [64Bits][\Microsoft\Windows\ApplicationData\DsSvcCleanup] - (.Microsoft Corporation - Data Sharing Service Maintenance Driver.) -- C:\WINDOWS\system32\dstokenclean.exe [12800] =>.Microsoft Corporation
O38 - TASK: {A00B5966-A0DF-4368-B092-EF29F7E7F68C} [64Bits][\{6934C0F3-DCBA-46B7-8423-56DA3A8569B1}] - (...) -- C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {A4D1B478-9D9D-489F-98BF-846F21D1EA6C} [64Bits][\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers] - (.Microsoft Corporation - Module d’installation de pilotes.) -- C:\WINDOWS\System32\drvinst.exe [121856] =>.Microsoft Corporation
O38 - TASK: {A4FB0886-6FDB-4AD4-806D-4D0EF0C75DF2} [64Bits][\{107A5D49-A217-4AD3-B06F-42DC1273720D}] - (...) -- C:\Program Files (x86)\KAPITALSIN\Prince of Persia T2T\unins000.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {AA5A1E65-2BF6-48C1-BB5F-0D4C9D68ABF9} [64Bits][\{6A2C3CD5-DB6C-46D6-9D31-3440502A15B4}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {AC2E6D05-1724-4562-9F51-672D042347B8} [64Bits][\{1069C9E5-4994-4C41-B32A-FD4C3EA9AC13}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {ACCB79F2-527D-4242-A863-68F2D03097A8} [64Bits][\Microsoft\Windows\Media Center\PBDADiscoveryW1] - (.Acer Inc. - .) -- C:\WINDOWS\ehome\ehPrivJob.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {AD6251B1-B091-4448-93BF-7A4A32AEDC4C} [64Bits][\{AD1A3099-5200-4176-84B7-97803FCB807B}] - (...) -- C:\Program Files (x86)\Microids\Return to Mysterious Island 2\RTMI2.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {AF8621E4-DD0A-4E22-AEBD-D252114A7D89} [64Bits][\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask] - (.Microsoft Corporation - Serveur COM d’assistance à distance Windows.) -- C:\Windows\System32\raserver.exe [124928] =>.Microsoft Corporation
O38 - TASK: {B15048DA-0ABE-4125-AB1D-87CE2B1D6A5C} [64Bits][\{3A3D9D59-E1A7-4A0F-A302-8D5763BDA6AF}] - (...) -- C:\Users\LENOVO\Documents\Dream Day Wedding Married in Manhattan\Uninstall.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {B3A3FA47-B9F5-4E28-A1FA-78DED82537ED} [64Bits][\{CBF57A23-5146-489C-BE09-EA65F2D9AD51}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {B3CA34A9-D92C-4D1C-9B61-B317738A0F5A} [64Bits][\Microsoft\Windows\Media Center\DispatchRecoveryTasks] - (. - Travail du répartiteur de tâche de récupéra.) -- C:\WINDOWS\ehome\ehPrivJob.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {B3DD4C81-C4AC-4263-806F-E5B540C1B26A} [64Bits][\Microsoft\Windows\DiskCleanup\SilentCleanup] - (.Microsoft Corporation - Gestionnaire de nettoyage de disque pour Wi.) -- C:\WINDOWS\system32\cleanmgr.exe [206848] =>.Microsoft Corporation
O38 - TASK: {B423785A-6B05-4C3D-81DC-B8FC7C07ADD1} [64Bits][\{AB6A4B82-59F3-4B5E-AF76-17DA306A7266}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {B4A5B97B-E0F1-4984-ADA4-432088751E1B} [64Bits][\Microsoft\Windows\NetTrace\GatherNetworkInfo] - (...) -- C:\WINDOWS\system32\gatherNetworkInfo.vbs [75642]
O38 - TASK: {BC8EE91C-2E2B-4F8F-A6EB-35F2ED61AEB7} [64Bits][\smadav] - (.Smadsoft - Smadav USB Antivirus & Additional Protectio.) -- C:\Program Files (x86)\SMADAV\SMΔRTP.exe [1781760] =>.SmadSoft
O38 - TASK: {BF851359-0DE5-47A1-9B7E-6074CC5829EE} [64Bits][\Microsoft\Windows\Media Center\RecordingRestart] - (...) -- C:\WINDOWS\ehome\ehrec (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {C349BB67-3672-4975-AE02-517BAD9318EE} [64Bits][\Microsoft\Windows\WindowsUpdate\sih] - (.Microsoft Corporation - Client SIH.) -- C:\WINDOWS\System32\sihclient.exe [203264] =>.Microsoft Corporation
O38 - TASK: {C4E89737-E6D8-4D86-B15E-50A93654BBC1} [64Bits][\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange] - (.Microsoft Corporation - Moteur de filtrage de base.) -- C:\Windows\System32\bfe.dll [794112] =>.Microsoft Corporation
O38 - TASK: {C6FBF15E-4BC4-4945-A65F-4AA3B1E9565B} [64Bits][\{A81BDA75-B943-4F5E-B4AA-8C5CC9E95755}] - (...) -- C:\Program Files (x86)\LiveSupport\LiveSupport.exe (.not file.) [0] (.Orphan.) =>PUP.Optional.LiveSupport
O38 - TASK: {C7752DC6-148D-4AB0-93E1-D84AEB7AA014} [64Bits][\Microsoft\Windows\Bluetooth\UninstallDeviceTask] - (.Microsoft Corporation - Tâche de désinstallation du périphérique Bl.) -- C:\Windows\System32\BthUdTask.exe [38400] =>.Microsoft Corporation
O38 - TASK: {C7CA3FD3-EF2C-49E0-9E78-61BE9B2B322A} [64Bits][\{37BA39CD-DB50-48B9-8DF5-59B6758F29A4}] - (...) -- D:\Windows7\10_Bluetooth\Setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {C9A3E241-2B26-42F5-9610-D866DBC0A035} [64Bits][\{CEC2FA9F-C356-44F6-9D8A-D1AE9CADA306}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {C9EAE88C-934D-40E2-8A01-B4366041E483} [64Bits][\Microsoft\Windows\Media Center\InstallPlayReady] - (...) -- C:\WINDOWS\ehome\ehPrivJob.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {CA4BE44E-107E-4B2D-91AF-FC3B077B02FC} [64Bits][\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser] - (.Microsoft Corporation - Microsoft Compatibility Telemetry.) -- C:\WINDOWS\system32\compattelrunner.exe [50368] =>.Microsoft Corporation®
O38 - TASK: {CAD021A5-9175-405D-95D7-1F457A986B88} [64Bits][\{125AF75A-BAB0-4F63-8E3E-78AC3E8BA786}] - (...) -- C:\Users\LENOVO\Documents\MES JEUX\fbi_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {D3A63264-E247-4AF3-82C1-D13FB8364585} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Policy Install] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [19968] =>.Microsoft Corporation
O38 - TASK: {D45E034B-B72A-44A1-AA6D-28214E04AE97} [64Bits][\{03023942-FF14-4068-A1A3-5D3E70DA76CE}] - (.Elex do Brasil Participações Ltda - uninstal.) -- C:\Program Files (x86)\Elex-tech\YAC\uninstall.exe [1081152] =>.SUP.Elex
O38 - TASK: {D761F339-030A-4C9D-9474-98154085811A} [64Bits][\{B51F6FBD-B6F5-40BC-B367-EF9F1A951A4A}] - (...) -- C:\Users\LENOVO\Downloads\jojos_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {D8095B54-6359-4DA3-A356-619B01CD7F26} [64Bits][\{1DC780CD-0E2A-48AA-B739-5552B5562D71}] - (...) -- C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {DAAFAEC3-BC03-44D7-A77D-05760FE578AD} [64Bits][\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup] - (.Microsoft Corporation - DLL du client de déploiement d’AppX.) -- C:\Windows\System32\AppxDeploymentClient.dll [436736] =>.Microsoft Corporation
O38 - TASK: {DB39EF46-E147-4BF9-B0A4-84D929258A08} [64Bits][\{96228DF9-7C3C-4A4A-8FF7-87B9281AB612}] - (...) -- C:\Users\LENOVO\Documents\Around The World in 80 Days\game.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {DB458018-DEBA-4577-AB8B-EA1506110FB8} [64Bits][\Microsoft\Windows\Location\Notifications] - (.Microsoft Corporation - Notification d'emplacement.) -- C:\WINDOWS\System32\LocationNotificationWindows.exe [41472] =>.Microsoft Corporation
O38 - TASK: {DBF344B4-B3ED-4384-BDF3-149F77B3A6AB} [64Bits][\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display] - (.Microsoft Corporation - MusNotificationBroker.) -- C:\windows\system32\MusNotification.exe [189952] =>.Microsoft Corporation
O38 - TASK: {DCAEF577-40CF-4D99-AC76-A5673634CFA2} [64Bits][\{DA6DDDE1-B858-400A-9B50-EA26AEDAE44D}] - (...) -- C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {DCB5939D-35AA-473B-8143-7EF9FFECEFE1} [64Bits][\{A87F8FC6-2F96-4E3E-8D5F-3786C27A9370}] - (...) -- C:\Users\LENOVO\Downloads\weddingsalon_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {DE08B8FB-618E-4A57-AA51-2AB8EBE3262A} [64Bits][\Microsoft\Windows\Media Center\ehDRMInit] - (...) -- C:\WINDOWS\ehome\ehPrivJob.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {E009867F-14AB-4644-966D-D4FFF665F13F} [64Bits][\{7BF1054D-4601-4FFA-9259-D69FE7EAA1EF}] - (...) -- C:\Users\LENOVO\Downloads\dreamdaywedding-112270203-setup.s112270203.c110341560.len.u0c9cddcd3f8fbc2ea4e8e8ef6be01e1cbec1b11d.dl.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {E046AACD-58C4-41ED-8BCF-C2B73FF63DE7} [64Bits][\Gkghtknoly] - (.System - Gkghtknoly.) -- msiexec [0]
O38 - TASK: {E179CE08-2908-4440-9100-EB3F02EDE327} [64Bits][\{12495545-6BB4-427D-82F6-C0CFFA7D8FB8}] - (...) -- C:\Program Files (x86)\LiveSupport\LiveSupport.exe (.not file.) [0] (.Orphan.) =>PUP.Optional.LiveSupport
O38 - TASK: {E506F4C9-20BB-40AE-AD65-2304E5EF9B80} [64Bits][\Microsoft\Windows\Clip\License Validation] - (.Microsoft Corporation - Client License Platform migration tool.) -- C:\WINDOWS\System32\ClipUp.exe [1128096] =>.Microsoft Windows Publisher®
O38 - TASK: {E5217668-D921-4907-8CE1-276EABA44515} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Schedule Scan] - (.Microsoft Corporation - UsoClient.) -- C:\WINDOWS\System32\usoclient.exe [19968] =>.Microsoft Corporation
O38 - TASK: {E6BAFEB0-9D01-4B02-A2EA-CE08E2E90C97} [64Bits][\{B8E5FFF5-F405-4707-BBF2-0AF1651413BF}] - (...) -- C:\Users\LENOVO\Documents\Around The World in 80 Days\game.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {E704213D-0C0D-4113-A000-272BF9276CC9} [64Bits][\{54777606-5D90-4F51-A829-1B21749B622F}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {E7D61507-58B7-44DC-8D1E-932F96FC2D62} [64Bits][\Microsoft\Windows\Customer Experience Improvement Program\Consolidator] - (.Microsoft Corporation - Consolidateur SQM Windows.) -- C:\WINDOWS\System32\wsqmcons.exe [228352] =>.Microsoft Corporation
O38 - TASK: {EA5BAD09-FEEE-40BB-B6C4-75DE7E0E746E} [64Bits][\{8DB8B1AA-0589-4576-9523-7A6BC7AD6EF1}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {EF3EC7C4-1CB5-43F1-A074-D1D74BB07D7A} [64Bits][\Microsoft\Windows\Shell\FamilySafetyMonitor] - (.Microsoft Corporation - Moniteur du contrôle parental.) -- C:\WINDOWS\System32\wpcmon.exe [1750440] =>.Microsoft Windows®
O38 - TASK: {EFA75A35-8D5A-45C8-8AA6-8DCEC99A693D} [64Bits][\Milimili] - (.LENOVO-PC\LENOVO - .) -- C:\Program Files (x86)\MIO\MIO.exe [331368] =>.SUP.Tencent
O38 - TASK: {EFB2C913-BFA0-4FB9-8130-48BEE6BD1B12} [64Bits][\Microsoft\Windows\NlaSvc\WiFiTask] - (.Microsoft Corporation - Tâche sans fil en arrière-plan.) -- C:\WINDOWS\System32\WiFiTask.exe [413536] =>.Microsoft Windows®
O38 - TASK: {F1ACB018-4DC0-467A-BF7D-91572AA0D8EF} [64Bits][\Microsoft\Windows\DeviceSettings\Fidght] - (.System - Fidght.) -- msiexec [0]
O38 - TASK: {F2341244-5F02-41C5-BA40-4FBADCD67206} [64Bits][\Microsoft\Windows\Autochk\Proxy] - (.Microsoft Corporation - DLL de proxy Autochk.) -- C:\Windows\System32\acproxy.dll [12800] =>.Microsoft Corporation
O38 - TASK: {F421607F-0909-4693-B494-26ADEC56DBA9} [64Bits][\Microsoft\Windows\Media Center\MediaCenterRecoveryTask] - (...) -- C:\WINDOWS\ehome\mcupdate.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {F4BF89A9-8488-4988-B163-F7F0341D521B} [64Bits][\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck] - (.Microsoft Corporation - AppID Certificate Store Verification Task.) -- C:\WINDOWS\system32\appidcertstorecheck.exe [19456] =>.Microsoft Corporation
O38 - TASK: {F526F6FD-9C18-483D-A6E7-F871D4360FFA} [64Bits][\{F4317822-E6D6-4229-B9C4-95C748865159}] - (...) -- E:\Setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {F775C69D-FE09-4105-8F98-5DC6D956FA4E} [64Bits][\Microsoft\Windows\Workplace Join\Automatic-Device-Join] - (.Microsoft Corporation - Outil de ligne de commande DSREG.) -- C:\WINDOWS\System32\dsregcmd.exe [604672] =>.Microsoft Corporation
O38 - TASK: {F84DC905-B3D1-47B5-B867-3E5BFB0B4415} [64Bits][\WPD\SqmUpload_S-1-5-21-2244098690-1691685554-420185725-1000] - (.Microsoft Corporation - Composants API de l’appareil mobile Windows.) -- C:\Windows\System32\portabledeviceapi.dll [639488] =>.Microsoft Corporation
O38 - TASK: {FA625267-66E0-464A-AE95-8754007E78AD} [64Bits][\Microsoft\Windows\UpdateOrchestrator\Reboot] - (.Microsoft Corporation - MusNotificationBroker.) -- C:\WINDOWS\System32\MusNotification.exe [189952] =>.Microsoft Corporation
O38 - TASK: {FB1868EE-5CA8-4DE9-A8B1-6171EB0EDB5A} [64Bits][\Microsoft\Windows\SystemRestore\SR] - (.Microsoft Corporation - Tâches de fond de la protection du système.) -- C:\WINDOWS\system32\srtasks.exe [58368] =>.Microsoft Corporation
O38 - TASK: {FC52F032-45F0-4B04-99DA-5A5F43CB0392} [64Bits][\Microsoft\Windows\Application Experience\StartupAppTask] - (.Microsoft Corporation - DLL de tâche d’analyse de démarrage.) -- C:\Windows\System32\Startupscan.dll [19456] =>.Microsoft Corporation
O38 - TASK: {FE172F5D-7504-4D02-B6F8-B4BF1C22C5CE} [64Bits][\{8781F340-7865-4AE5-99E8-6909C2E825AB}] - (...) -- C:\Users\LENOVO\Downloads\photomania_setup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan

---\\ Applications lancées au démarrage du système (7) - 1s
O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp®
O4 - HKLM\..\Run: [AvastUI.exe] . (.AVAST Software - AvLaunch component.) -- C:\Program Files\AVAST Software\Avast\AvLaunch.exe =>.AVAST Software s.r.o.®
O4 - HKCU\..\Run: [BitTorrent] . (.BitTorrent Inc. - BitTorrent.) -- C:\Users\LENOVO\AppData\Roaming\BitTorrent\BitTorrent.exe =>.BitTorrent Inc®
O4 - HKLM\..\Wow6432Node\Run: [PWRISOVM.EXE] . (.Power Software Ltd - PowerISO Virtual Drive Manager.) -- C:\Program Files\PowerISO\PWRISOVM.EXE =>.Power Software Limited®
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Corporation®
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Corporation®
O4 - HKUS\S-1-5-21-2244098690-1691685554-420185725-1000\..\Run: [BitTorrent] . (.BitTorrent Inc. - BitTorrent.) -- C:\Users\LENOVO\AppData\Roaming\BitTorrent\BitTorrent.exe =>.BitTorrent Inc®

---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (2) - 2s
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll =>.Adobe Systems Incorporated
P2 - FPN: [HKLM] [@oberon-media.com/ONCAdapter] - (.Oberon Media.) -- C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.14\npapicomadapter.dll =>.Oberon Media

---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (23) - 1s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.startpageing123.com/ =>Hijacker.StartpageIng123
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.startpageing123.com/ =>Hijacker.StartpageIng123
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.startpageing123.com/ =>Hijacker.StartpageIng123
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgijvkxlyip4nye17avlwqjf96savhjpymmx08wy-uoho9epmslgasufgmiagx1siw5jgrgq0hsv9i5q3c2jcfpkjmfx-qd5fhqb6mepsd6j4_8ohvd7gc8junkczciz0ryah6-tk3qjpi421bybyfi1bnoo1plhvwa48ws08vq9mykxpyzrjdi6dgipe&q={searchterms} =>.SUP.Linkury
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.startpageing123.com/ =>Hijacker.StartpageIng123
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgijvkxlyip4nye17avlwqjf96savhjpymmx08wy-uoho9epmslgasufgmiagx1siw5jgrgq0hsv9i5q3c2jcfpkjmfx-qd5fhqb6mepsd6j4_8ohvd7gc8junkczciz0ryah6-tk3qjpi421bybyfi1bnoo1plhvwa48ws08vq9mykxpyzrjdi6dgipe&q={searchterms} =>.SUP.Linkury
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.startpageing123.com/ =>Hijacker.StartpageIng123
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.startpageing123.com/ =>Hijacker.StartpageIng123
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.startpageing123.com/ =>Hijacker.StartpageIng123
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgijvkxlyip4nye17avlwqjf96savhjpymmx08wy-uoho9epmslgasufgmiagx1siw5jgrgq0hsv9i5q3c2jcfpkjmfx-qd5fhqb6mepsd6j4_8ohvd7gc8junkczciz0ryah6-tk3qjpi421bybyfi1bnoo1plhvwa48ws08vq9mykxpyzrjdi6dgipe&q={searchterms} =>.SUP.Linkury
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgijvkxlyip4nye17avlwqjf96savhjpymmx08wy-uoho9epmslgasufgmiagx1siw5jgrgq0hsv9i5q3c2jcfpkjmfx-qd5fhqb6mepsd6j4_8ohvd7gc8junkczciz0ryah6-tk3qjpi421bybyfi1bnoo1plhvwa48ws08vq9mykxpyzrjdi6dgipe&q={searchterms} =>.SUP.Linkury
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.startpageing123.com/ =>Hijacker.StartpageIng123
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.startpageing123.com/ =>Hijacker.StartpageIng123
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.startpageing123.com/ =>Hijacker.StartpageIng123
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKEY_USERS\S-1-5-21-2244098690-1691685554-420185725-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgijvkxlyip4nye17avlwqjf96savhjpymmx08wy-uoho9epmslgasufgmiagx1siw5jgrgq0hsv9i5q3c2jcfpkjmfx-qd5fhqb6mepsd6j4_8ohvd7gc8junkczciz0ryah6-tk3qjpi421bybyfi1bnoo1plhvwa48ws08vq9mykxpyzrjdi6dgipe&q={searchterms} =>.SUP.Linkury
R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.10586.545 (th2_release.160802-1857)) -- C:\Windows\SysWOW64\ieframe.dll =>.Microsoft Corporation
R4 - HKLM\Software\WOW6432Node\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1

---\\ Microsoft Edge, Plugin,Favoris,Démarrage,Recherche,Extension (1) - 0s
E0 - Microsoft Edge: HKU\S-1-5-21-2244098690-1691685554-420185725-1000\HomeButtonPage = http://start.myplaycity.com

---\\ Internet Explorer,Proxy Management (5) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=

---\\ Etude du fichier hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (51)

---\\ Browser Helper Object de navigateur (BHO) (1) - 0s
O2 - BHO: SkypeIEPluginBHO [64Bits] - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll =>.Skype Software Sarl®

---\\ Raccourcis Global Startup (89) - 26s
O4 - GS\Desktop [Administrateur]: BitTorrent.lnk . (.BitTorrent Inc. - BitTorrent.) C:\Users\LENOVO\AppData\Roaming\BitTorrent\BitTorrent.exe =>.BitTorrent Inc®
O4 - GS\Desktop [Administrateur]: CodeBlocks.lnk . (...) C:\Program Files (x86)\CodeBlocks\codeblocks.exe
O4 - GS\Desktop [Administrateur]: Documents - Raccourci.lnk . (...) C:\Users\LENOVO\Documents
O4 - GS\Desktop [Administrateur]: Dream Day Wedding - Married in Manhattan.lnk . (...) C:\Program Files (x86)\MyPlayCity.com\Dream Day Wedding - Married in Manhattan\Dream Day Wedding - Married in Manhattan.exe =>.MyPlayCity Inc®
O4 - GS\Desktop [Administrateur]: Dream Day Wedding - Viva Las Vegas.lnk . (...) C:\Program Files (x86)\MyPlayCity.com\Dream Day Wedding - Viva Las Vegas\Dream Day Wedding - Viva Las Vegas.exe =>.MyPlayCity Inc®
O4 - GS\Desktop [Administrateur]: Dream Day Wedding.lnk . (...) C:\Program Files (x86)\MyPlayCity.com\Dream Day Wedding\Dream Day Wedding.exe
O4 - GS\Desktop [Administrateur]: DYSFONCTIONNEMENT DE L’APPAREIL MANDUCATEUR - Raccourci.lnk . (.Dr Bitha - .) C:\Users\LENOVO\Documents\occluso\DYSFONCTIONNEMENT DE L’APPAREIL MANDUCATEUR.pptx
O4 - GS\Desktop [Administrateur]: Khi3 Calculator.lnk . (...) C:\Users\LENOVO\AppData\Roaming\Microsoft\Installer\{F212B4CD-2950-41D3-BBC9-30CFF511E37D}\_52f12d17.exe
O4 - GS\Desktop [Administrateur]: MyPlayCity Games.lnk . (...) C:\Program Files (x86)\MyPlayCity.com\Dream Day Wedding\MyPlayCity.url
O4 - GS\Desktop [Administrateur]: Play Online Games.lnk . (...) C:\Program Files (x86)\MyPlayCity.com\Dream Day Wedding\PlayOnlineGames.url
O4 - GS\Desktop [Administrateur]: Return to Mysterious Island Demo.lnk . (...) C:\Program Files (x86)\The Adventure Company\Return to Mysterious Island Demo\RtMI.exe
O4 - GS\Desktop [Administrateur]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\LENOVO\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\sendTo [Administrateur]: Destinataire de télécopie.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrateur]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrateur]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\sendTo [Administrateur]: Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrateur]: BitTorrent.lnk . (.BitTorrent Inc. - BitTorrent.) C:\Users\LENOVO\AppData\Roaming\BitTorrent\BitTorrent.exe =>.BitTorrent Inc®
O4 - GS\TaskBar [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Footper\Application\chrome.exe %SNP% =>.Google Inc®
O4 - GS\TaskBar [Administrateur]: Mozilla Firefox.lnk . (...) C:\Program Files (x86)\Firefox\Firefox.exe %SNF%
O4 - GS\TaskBar [Administrateur]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe =>.VideoLAN®
O4 - GS\TaskBar [Administrateur]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Programs [Administrateur]: Documents.lnk . (...) C:\Users\LENOVO\Documents
O4 - GS\Programs [Administrateur]: Fonctionnalités optionnelles.lnk . (.Microsoft Corporation - Assistance des fonctionnalités à la demande.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Programs [Administrateur]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\LENOVO\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\Desktop [LENOVO]: BitTorrent.lnk . (.BitTorrent Inc. - BitTorrent.) C:\Users\LENOVO\AppData\Roaming\BitTorrent\BitTorrent.exe =>.BitTorrent Inc®
O4 - GS\Desktop [LENOVO]: CodeBlocks.lnk . (...) C:\Program Files (x86)\CodeBlocks\codeblocks.exe
O4 - GS\Desktop [LENOVO]: Documents - Raccourci.lnk . (...) C:\Users\LENOVO\Documents
O4 - GS\Desktop [LENOVO]: Dream Day Wedding - Married in Manhattan.lnk . (...) C:\Program Files (x86)\MyPlayCity.com\Dream Day Wedding - Married in Manhattan\Dream Day Wedding - Married in Manhattan.exe =>.MyPlayCity Inc®
O4 - GS\Desktop [LENOVO]: Dream Day Wedding - Viva Las Vegas.lnk . (...) C:\Program Files (x86)\MyPlayCity.com\Dream Day Wedding - Viva Las Vegas\Dream Day Wedding - Viva Las Vegas.exe =>.MyPlayCity Inc®
O4 - GS\Desktop [LENOVO]: Dream Day Wedding.lnk . (...) C:\Program Files (x86)\MyPlayCity.com\Dream Day Wedding\Dream Day Wedding.exe
O4 - GS\Desktop [LENOVO]: DYSFONCTIONNEMENT DE L’APPAREIL MANDUCATEUR - Raccourci.lnk . (.Dr Bitha - .) C:\Users\LENOVO\Documents\occluso\DYSFONCTIONNEMENT DE L’APPAREIL MANDUCATEUR.pptx
O4 - GS\Desktop [LENOVO]: Khi3 Calculator.lnk . (...) C:\Users\LENOVO\AppData\Roaming\Microsoft\Installer\{F212B4CD-2950-41D3-BBC9-30CFF511E37D}\_52f12d17.exe
O4 - GS\Desktop [LENOVO]: MyPlayCity Games.lnk . (...) C:\Program Files (x86)\MyPlayCity.com\Dream Day Wedding\MyPlayCity.url
O4 - GS\Desktop [LENOVO]: Play Online Games.lnk . (...) C:\Program Files (x86)\MyPlayCity.com\Dream Day Wedding\PlayOnlineGames.url
O4 - GS\Desktop [LENOVO]: Return to Mysterious Island Demo.lnk . (...) C:\Program Files (x86)\The Adventure Company\Return to Mysterious Island Demo\RtMI.exe
O4 - GS\Desktop [LENOVO]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\LENOVO\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\sendTo [LENOVO]: Destinataire de télécopie.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [LENOVO]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [LENOVO]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\sendTo [LENOVO]: Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [LENOVO]: BitTorrent.lnk . (.BitTorrent Inc. - BitTorrent.) C:\Users\LENOVO\AppData\Roaming\BitTorrent\BitTorrent.exe =>.BitTorrent Inc®
O4 - GS\TaskBar [LENOVO]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Footper\Application\chrome.exe %SNP% =>.Google Inc®
O4 - GS\TaskBar [LENOVO]: Mozilla Firefox.lnk . (...) C:\Program Files (x86)\Firefox\Firefox.exe %SNF%
O4 - GS\TaskBar [LENOVO]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe =>.VideoLAN®
O4 - GS\TaskBar [LENOVO]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Programs [LENOVO]: Documents.lnk . (...) C:\Users\LENOVO\Documents
O4 - GS\Programs [LENOVO]: Fonctionnalités optionnelles.lnk . (.Microsoft Corporation - Assistance des fonctionnalités à la demande.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Programs [LENOVO]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\LENOVO\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\CommonDesktop [Public]: Acrobat Reader DC.lnk . (.Adobe Systems Incorporated - Adobe Acrobat Reader DC.) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe =>.Adobe Systems, Incorporated®
O4 - GS\CommonDesktop [Public]: Acrobat Reader DC.lnk . (.Adobe Systems Incorporated - Adobe Acrobat Reader DC.) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe =>.Adobe Systems, Incorporated®
O4 - GS\CommonDesktop [Public]: Avast Antivirus Gratuit.lnk . (.AVAST Software - Avast Antivirus.) C:\Program Files\AVAST Software\Avast\avastui.exe =>.AVAST Software s.r.o.®
O4 - GS\CommonDesktop [Public]: Cambridge Advanced Learner's Dictionary - 4th Edition.lnk . (.mozilla.org - cald4.) C:\Program Files (x86)\Cambridge\CALD4\cald4.exe =>.mozilla.org
O4 - GS\CommonDesktop [Public]: Camtel CE682.lnk . (.Copy right(c) 2006. All rights reserved. - .) C:\Program Files\Camtel CE682\App.exe
O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Footper\Application\chrome.exe %SNP% =>.Google Inc®
O4 - GS\CommonDesktop [Public]: PowerISO.lnk . (.Power Software Ltd - PowerISO.) C:\Program Files\PowerISO\PowerISO.exe =>.Power Software Limited®
O4 - GS\CommonDesktop [Public]: Return to Mysterious Island 2.lnk . (.Microïds - .) C:\Program Files (x86)\Meridian4\Return to Mysterious Island 2\RTMI2.exe
O4 - GS\CommonDesktop [Public]: Skype.lnk . (...) C:\Windows\Installer\{6A0549A9-1B96-498C-ACBC-3943001FEB19}\SkypeIcon.exe =>.Skype Technologies
O4 - GS\CommonDesktop [Public]: SMADΔV.lnk . (.Smadsoft - Smadav USB Antivirus & Additional Protectio.) C:\Program Files (x86)\SMADAV\SMΔRTP.exe =>.SmadSoft
O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe =>.VideoLAN®
O4 - GS\CommonDesktop [Public]: WiMAX Connection Manager.lnk . (...) C:\Program Files (x86)\WiMAX Connection Manager\WiMAX Connection Manager.exe
O4 - GS\Programs [Public]: Documents.lnk . (...) C:\Users\LENOVO\Documents
O4 - GS\Programs [Public]: Fonctionnalités optionnelles.lnk . (.Microsoft Corporation - Assistance des fonctionnalités à la demande.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Programs [Public]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\LENOVO\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\Accessories [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe http://www.startpageing123.com/ =>Hijacker.StartpageIng123
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Bloc-notes.) C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Private Character Editor.lnk . (.Microsoft Corporation - Éditeur de caractères privés.) C:\WINDOWS\system32\eudcedit.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - Centre de mobilité Windows.) C:\WINDOWS\system32\mblctr.exe /open =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\WINDOWS\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Connexion Bureau à distance.) C:\WINDOWS\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Outil Capture d’écran.) C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Enregistreur d’actions.) C:\WINDOWS\system32\psr.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - Pense-bête.) C:\WINDOWS\system32\StikyNot.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Application Windows Wordpad.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: XPS Viewer.lnk . (.Microsoft Corporation - Visionneuse XPS.) C:\WINDOWS\system32\xpsrchvw.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Table des caractères.) C:\WINDOWS\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Acrobat Reader DC.lnk . (.Flexera Software LLC - InstallShield.) C:\WINDOWS\Installer\{AC76BA86-7AD7-1036-7B44-AC0F074E4100}\SC_Reader.ico =>.Flexera Software LLC
O4 - GS\ProgramsCommon [Public]: Acrobat Reader DC.lnk . (.Flexera Software LLC - InstallShield.) C:\WINDOWS\Installer\{AC76BA86-7AD7-1036-7B44-AC0F074E4100}\SC_Reader.ico =>.Flexera Software LLC
O4 - GS\ProgramsCommon [Public]: Avast Antivirus Gratuit.lnk . (.AVAST Software - Avast Antivirus.) C:\Program Files\AVAST Software\Avast\avastui.exe =>.AVAST Software s.r.o.®
O4 - GS\ProgramsCommon [Public]: Devices Flow.lnk . (.Microsoft Corporation - Flux des périphériques.) C:\WINDOWS\DevicesFlow\DevicesFlow.exe =>.Microsoft Windows®
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Footper\Application\chrome.exe %SNP% =>.Google Inc®
O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\WINDOWS\System32\Control.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: MiracastView.lnk . (.Microsoft Corporation - MiracastView.) C:\WINDOWS\MiracastView\MiracastView.exe =>.Microsoft Windows®
O4 - GS\ProgramsCommon [Public]: Mozilla Firefox.lnk . (...) C:\Program Files (x86)\Firefox\Firefox.exe %SNF%
O4 - GS\ProgramsCommon [Public]: PrintDialog.lnk . (.Microsoft Corporation - Print Dialog.) C:\WINDOWS\PrintDialog\PrintDialog.exe =>.Microsoft Windows®
O4 - GS\ProgramsCommon [Public]: Search.lnk . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) C:\WINDOWS\system32\rundll32.exe -sta {C90FB8CA-3295-4462-A721-2935E83694BA} =>..Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation

---\\ Modification Domaine/Adresses DNS (4) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 41.205.5.117 41.205.5.121 41.205.5.109
O17 - HKLM\System\CCS\Services\Tcpip\..\{574f8c74-eb27-4a7c-948b-2575219d3870}: DhcpNameServer = 41.205.5.117 41.205.5.121 41.205.5.109
O17 - HKLM\System\CCS\Services\Tcpip\..\{73efe1c3-054f-4676-8de0-37225ba84f14}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{fe4c2460-3f57-4f06-a36d-e55ec291533c}: DhcpNameServer = 192.168.111.1 41.223.30.2 41.223.28.6 =>.Local IP Adress

---\\ Protocole additionnel (26) - 2s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: grooveLocalGWS [64Bits] - {88FED34C-F0CA-4636-A375-3CB6248B04CD} . (.Microsoft Corporation - GrooveSystemServices Module.) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll =>.Microsoft Corporation®
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\SysWOW64\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-help [64Bits] - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll =>.Microsoft Corporation®
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: skypec2c [64Bits] - {91774881-D725-4E58-B298-07617B9B86A8} . (.Microsoft Corporation - Skype Click to Call IE Add-on.) -- C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll =>.Skype Software Sarl®
O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\SysWOW64\tbauth.dll =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: windows.tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\SysWOW64\tbauth.dll =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL =>.Microsoft Corporation®

---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (1) - 0s
O20 - AppInit_DLLs: . (...) - C:\ProgramData\Utatity\Span-Touch.dll (.not file.)

---\\ Enumère les données de BootExecute (1) - 0s
O34 - HKLM BootExecute: (aswBoot.exe /M:cb3689d6d /wow /dir:"C:\Program Files\AVAST Software\Avast") (.AVAST Software - Avast start-up scanner.) -- aswBoot.exe =>.AVAST Software

---\\ ASIC (ActiveSetup Installed Components) (5) - 2s
O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Utilitaire d’installation du Lecteur Window.) -- C:\Windows\System32\unregmp2.exe =>.Microsoft Corporation
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll =>.Microsoft Corporation®

---\\ Logiciels installés (54) - 42s
O42 - Logiciel: Adobe Acrobat Reader DC - Français - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1036-7B44-AC0F074E4100} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Flash Player 27 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-0804-1033-1959-001824225037} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Shockwave Player 12.2 - (.Adobe Systems, Inc..) [HKLM][64Bits] -- Adobe Shockwave Player =>.Adobe Systems, Inc.
O42 - Logiciel: amulesw - (.amules.) [HKLM][64Bits] -- {3CC3DE19-E0B1-4D42-87AB-B5C61FE4BA58}
O42 - Logiciel: ASIO4ALL - (.Michael Tippach.) [HKLM][64Bits] -- ASIO4ALL =>.Michael Tippach
O42 - Logiciel: Atheros Client Installation Program - (.Atheros.) [HKLM][64Bits] -- {D3694B69-6F8C-42D3-8A0A-EB2AB528C02C} =>.Macrovision Corporation®
O42 - Logiciel: Avast Antivirus Gratuit - (.AVAST Software.) [HKLM][64Bits] -- Avast Antivirus =>.AVAST Software s.r.o.®
O42 - Logiciel: BitTorrent - (.BitTorrent Inc..) [HKCU][64Bits] -- BitTorrent =>.BitTorrent Inc®
O42 - Logiciel: Cambridge Advanced Learner's Dictionary - 4th Edition - (..) [HKLM][64Bits] -- NSIS_cald4
O42 - Logiciel: Camtel CE682 - (..) [HKLM][64Bits] -- Camtel CE682_is1
O42 - Logiciel: CodeBlocks - (.The Code::Blocks Team.) [HKCU][64Bits] -- CodeBlocks =>.The Code::Blocks Team
O42 - Logiciel: deskapp - (.deskapp.) [HKLM][64Bits] -- {D751E92C-AB44-45E6-9733-427FE2C37FD8}
O42 - Logiciel: Dream Day Wedding - (.MyPlayCity, Inc..) [HKLM][64Bits] -- Dream Day Wedding_is1 =>.MyPlayCity, Inc.
O42 - Logiciel: Dream Day Wedding - Married in Manhattan - (.MyPlayCity, Inc..) [HKLM][64Bits] -- Dream Day Wedding - Married in Manhattan_is1 =>.MyPlayCity, Inc.
O42 - Logiciel: Dream Day Wedding - Viva Las Vegas - (.MyPlayCity, Inc..) [HKLM][64Bits] -- Dream Day Wedding - Viva Las Vegas_is1 =>.MyPlayCity, Inc.
O42 - Logiciel: ELAN Touchpad 11.15.0.18_X64 - (.ELAN Microelectronic Corp..) [HKLM][64Bits] -- Elantech =>.ELAN Microelectronics Corporation®
O42 - Logiciel: Energy Management - (.Lenovo.) [HKLM][64Bits] -- {D0956C11-0F60-43FE-99AD-524E833471BB} =>.Lenovo
O42 - Logiciel: EnergyCut - (.Lenovo.) [HKLM][64Bits] -- {6E127727-CE4B-40E4-9A7D-9D65CDE0A15C} =>.Macrovision Corporation®
O42 - Logiciel: FastDataX 1.20 - (..) [HKLM][64Bits] -- FastDataX_is1 =>Adware.FastDataX
O42 - Logiciel: Google Update Helper - (.BonanzaDeals.) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>Heuristic.Suspect
O42 - Logiciel: Intel(R) Control Center - (.Intel Corporation.) [HKLM][64Bits] -- {F8A9085D-4C7A-41a9-8A77-C8998A96C421} =>.Intel Corporation®
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A} =>.Intel Corporation®
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} =>.Intel Corporation - pGFX®
O42 - Logiciel: Jojos Fashion Show - World Tour - (.MyPlayCity, Inc..) [HKLM][64Bits] -- Jojos Fashion Show - World Tour_is1 =>.MyPlayCity, Inc.
O42 - Logiciel: Khi3 - Universal Scientific Calculator - (.Joël Ollivier.) [HKLM][64Bits] -- {F212B4CD-2950-41D3-BBC9-30CFF511E37D} =>.Joël Ollivier
O42 - Logiciel: Lenovo EasyCamera - (.Vimicro.) [HKLM][64Bits] -- {ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332} =>.Macrovision Corporation®
O42 - Logiciel: Lenovo OneKey Recovery - (..) [HKLM][64Bits] -- {46F4D124-20E5-4D12-BE52-EC177A7A4B42} =>.CyberLink®
O42 - Logiciel: Microsoft Application Error Reporting - (.Microsoft Corporation.) [HKLM][64Bits] -- {95120000-00B9-0409-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft DVD App Installation for Microsoft.WindowsDVDPlayer_2019.6.13291. - (.Microsoft Corporation.) [HKLM][64Bits] -- {25E80DAA-FD87-DCE5-202C-CC02F6673002} =>.Microsoft Corporation
O42 - Logiciel: Notepad++ - (.Notepad++ Team.) [HKLM][64Bits] -- Notepad++ =>.Notepad++ Team
O42 - Logiciel: NoterSave version 1.0 - (.WeMonetize.) [HKLM][64Bits] -- NoterSave_is1 =>.SUP.Tuto4PC
O42 - Logiciel: Online Application - (.Microleaves.) [HKLM][64Bits] -- {5266F634-7B7D-4537-BDDC-98DD6CFCBAA1} =>.SUP.Microleaves
O42 - Logiciel: PowerISO - (.Power Software Ltd.) [HKLM][64Bits] -- PowerISO =>.Power Software Ltd
O42 - Logiciel: Prince of Persia The Two Thrones - (.Ubisoft.) [HKLM][64Bits] -- {D6782F44-58DB-4DE5-A65C-890320CF3F99} =>.Ubisoft
O42 - Logiciel: QUICKfind server v1.1 - (.IDM.) [HKLM][64Bits] -- QUICKfind =>.IDM
O42 - Logiciel: Realtek Ethernet Controller Driver For Windows 7 - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Realtek USB 2.0 Reader Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {62BBB2F0-E220-4821-A564-730807D2C34D} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Return to Mysterious Island - (..) [HKLM][64Bits] -- Return to Mysterious Island
O42 - Logiciel: Return to Mysterious Island 2 - (..) [HKLM][64Bits] -- Return to Mysterious Island 2_is1
O42 - Logiciel: SAMSUNG USB Driver for Mobile Phones - (.SAMSUNG Electronics Co., Ltd..) [HKLM][64Bits] -- {D0795B21-0CDA-4a92-AB9E-6E92D8111E44} =>.Samsung Electronics CO., LTD.®
O42 - Logiciel: savensharre - (.saVVenshare.) [HKLM][64Bits] -- {62D82EC1-0D3A-DF54-8E3E-07E1337A5311} =>PUP.Optional.SaveShare
O42 - Logiciel: Search-NewTab - (.Search-NeewTab.) [HKLM][64Bits] -- {C670DCAE-E392-AA32-6F42-143C7FC4BDFD} =>PUP.Optional.SearchNewTab
O42 - Logiciel: Skype Click to Call - (.Microsoft Corporation.) [HKLM][64Bits] -- {6D1221A9-17BF-4EC0-81F2-27D30EC30701} =>.Microsoft Corporation
O42 - Logiciel: Skype™ 7.8 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {6A0549A9-1B96-498C-ACBC-3943001FEB19} =>.Skype Technologies S.A.
O42 - Logiciel: SMADAV version 11.3 - (.Smadsoft.) [HKLM][64Bits] -- {8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1 =>.SmadSoft
O42 - Logiciel: swMSM - (.Adobe Systems, Inc.) [HKLM][64Bits] -- {612C34C7-5E90-47D8-9B5C-0F717DD82726} =>.Adobe Systems, Inc
O42 - Logiciel: Update_msi - (.Default Company Name.) [HKLM][64Bits] -- {59B5A9CD-253D-4C41-A073-B387D4C9672D}
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
O42 - Logiciel: WiMAX Connection Manager - (.Huawei Technologies Co.,Ltd.) [HKLM][64Bits] -- WiMAX Connection Manager =>.Huawei Technologies Co.,Ltd
O42 - Logiciel: WinRAR archiver - (.RarLab.) [HKLM][64Bits] -- WinRAR archiver =>.RarLab
O42 - Logiciel: YAC(Yet Another Cleaner!) - (.ELEX DO BRASIL PARTICIPAÇÕES LTDA.) [HKLM][64Bits] -- iSafe =>.SUP.Elex
O42 - Logiciel: Yahoo! Messenger - (.Yahoo! Inc..) [HKLM][64Bits] -- Yahoo! Messenger =>.Yahoo! Inc.

---\\ HKCU & HKLM Software Keys (155) - 43s
HKLM\SOFTWARE\Wow6432Node\0B0A9CB91AB20FB19916CBA43F44CFB1 =>Adware.CrossRider
HKLM\SOFTWARE\Wow6432Node\Adobe =>.Adobe
HKLM\SOFTWARE\Wow6432Node\AppDataLow =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\Arijose
HKLM\SOFTWARE\Wow6432Node\ASIO =>.Steinberg Media Technologies
HKLM\SOFTWARE\Wow6432Node\ASIO4ALL =>.Michael Tippach
HKLM\SOFTWARE\Wow6432Node\Atheros =>.Qualcomm Atheros
HKLM\SOFTWARE\Wow6432Node\AVAST Software =>.AVAST Software
HKLM\SOFTWARE\Wow6432Node\Big Fish Games =>.Big Fish Games
HKLM\SOFTWARE\Wow6432Node\Bunndle =>.Unknown
HKLM\SOFTWARE\Wow6432Node\Caphyon =>.Caphyon
HKLM\SOFTWARE\Wow6432Node\Chromium =>.Chromium
HKLM\SOFTWARE\Wow6432Node\Conduit =>.SUP.Conduit
HKLM\SOFTWARE\Wow6432Node\CyberLink =>.CyberLink Corporation
HKLM\SOFTWARE\Wow6432Node\DataMngr =>PUP.Optional.Datamngr
HKLM\SOFTWARE\Wow6432Node\Delta =>.SUP.DeltaSearch
HKLM\SOFTWARE\Wow6432Node\Disc Soft =>.Disc Soft
HKLM\SOFTWARE\Wow6432Node\DSPRobotics
HKLM\SOFTWARE\Wow6432Node\Elex-tech =>.SUP.Elex
HKLM\SOFTWARE\Wow6432Node\f4dd8fe63ceb13
HKLM\SOFTWARE\Wow6432Node\Firefox =>.Mozilla Corporation
HKLM\SOFTWARE\Wow6432Node\FlyingBird
HKLM\SOFTWARE\Wow6432Node\Footper
HKLM\SOFTWARE\Wow6432Node\FRANCE TELECOM =>.France Telecom
HKLM\SOFTWARE\Wow6432Node\G Data =>.G DATA Software
HKLM\SOFTWARE\Wow6432Node\GlarySoft =>.Glarysoft
HKLM\SOFTWARE\Wow6432Node\GoforFiles =>.GoforFiles
HKLM\SOFTWARE\Wow6432Node\Google =>.Google
HKLM\SOFTWARE\Wow6432Node\Huawei technologies =>.Huawei Technologies
HKLM\SOFTWARE\Wow6432Node\IDM =>.IDM
HKLM\SOFTWARE\Wow6432Node\IM Providers =>.IM Providers
HKLM\SOFTWARE\Wow6432Node\Image-Line =>.Image-Line
HKLM\SOFTWARE\Wow6432Node\InstallShield =>.InstallShield
HKLM\SOFTWARE\Wow6432Node\Intel =>.Intel
HKLM\SOFTWARE\Wow6432Node\IObit =>.IObit
HKLM\SOFTWARE\Wow6432Node\jhdbca
HKLM\SOFTWARE\Wow6432Node\jo
HKLM\SOFTWARE\Wow6432Node\Jucupyletert
HKLM\SOFTWARE\Wow6432Node\KasperskyLab =>.Kaspersky Labs
HKLM\SOFTWARE\Wow6432Node\KONAMI =>.Konami
HKLM\SOFTWARE\Wow6432Node\Lenovo =>.Lenovo
HKLM\SOFTWARE\Wow6432Node\Licenses =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware =>.Malwarebytes' Anti-Malware
HKLM\SOFTWARE\Wow6432Node\Microleaves =>.SUP.Microleaves
HKLM\SOFTWARE\Wow6432Node\MicroRay =>.MicroRay
HKLM\SOFTWARE\Wow6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\msServer
HKLM\SOFTWARE\Wow6432Node\mtUtatity
HKLM\SOFTWARE\Wow6432Node\Notepad++ =>.Don Ho
HKLM\SOFTWARE\Wow6432Node\NSIS_cald4
HKLM\SOFTWARE\Wow6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\Wow6432Node\PowerISO =>.PowerISO Computing
HKLM\SOFTWARE\Wow6432Node\Propellerhead Software =>.Propellerhead Software
HKLM\SOFTWARE\Wow6432Node\Realtek =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp. =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\ScreenShot
HKLM\SOFTWARE\Wow6432Node\Shizerpy
HKLM\SOFTWARE\Wow6432Node\Skype =>.Skype
HKLM\SOFTWARE\Wow6432Node\SoftVoice =>.SoftVoice
HKLM\SOFTWARE\Wow6432Node\SP Global =>PUP.Optional.AdvancedSystemProtector
HKLM\SOFTWARE\Wow6432Node\SProtector =>PUP.Optional.MocaFlix
HKLM\SOFTWARE\Wow6432Node\startpageing123Software
HKLM\SOFTWARE\Wow6432Node\SuppHelpDir =>.Toshiba Corporation
HKLM\SOFTWARE\Wow6432Node\UBISOFT =>.Ubisoft
HKLM\SOFTWARE\Wow6432Node\UCBrowserPID =>.UCWeb Inc.
HKLM\SOFTWARE\Wow6432Node\VideoLAN =>.VideoLAN
HKLM\SOFTWARE\Wow6432Node\Vimicro =>.Vimicro
HKLM\SOFTWARE\Wow6432Node\WebConnect =>PUP.Optional.WebConnect
HKLM\SOFTWARE\Wow6432Node\WinKernelTimeServiceIWN
HKLM\SOFTWARE\Wow6432Node\WinRAR =>.WinRAR
HKLM\SOFTWARE\Wow6432Node\Wow6432Node =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\xerwut.exe
HKLM\SOFTWARE\Wow6432Node\yahoo =>.Yahoo! Inc.
HKLM\SOFTWARE\Wow6432Node\ZSMC =>.ZSMC Corporation
HKLM\SOFTWARE\Wow6432Node\Zutledrasther
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\0B0A9CB91AB20FB19916CBA43F44CFB1 =>Adware.CrossRider
HKCU\SOFTWARE\Adobe =>.Adobe
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\Atgmtu
HKCU\SOFTWARE\AutoTime =>Adware.TopTools
HKCU\SOFTWARE\Avast Software =>.AVAST Software
HKCU\SOFTWARE\BabSolution =>PUP.Optional.BabSolution
HKCU\SOFTWARE\BigBlueBubble
HKCU\SOFTWARE\BitTorrent
HKCU\SOFTWARE\BlueStacks =>.BlueStack Systems, Inc.
HKCU\SOFTWARE\Boolat Games
HKCU\SOFTWARE\Chromium =>.Chromium
HKCU\SOFTWARE\cks =>.Legitimate
HKCU\SOFTWARE\CodeBlocks =>.CodeBlocks Team
HKCU\SOFTWARE\Conduit =>.SUP.Conduit
HKCU\SOFTWARE\csastats =>Adware.InstallCore
HKCU\SOFTWARE\deskapp
HKCU\SOFTWARE\Disc Soft =>.Disc Soft
HKCU\SOFTWARE\drpsu =>.Driver PackSolution
HKCU\SOFTWARE\Elantech =>.Elantech Inc.
HKCU\SOFTWARE\f4dd8fe63ceb13
HKCU\SOFTWARE\FastDataX =>Adware.FastDataX
HKCU\SOFTWARE\Firefox =>.Mozilla Corporation
HKCU\SOFTWARE\Footper
HKCU\SOFTWARE\Glarysoft =>.Glarysoft
HKCU\SOFTWARE\GoforFiles =>.GoforFiles
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\IM Providers =>.IM Providers
HKCU\SOFTWARE\Image-Line =>.Image-Line
HKCU\SOFTWARE\Installer
HKCU\SOFTWARE\Intel =>.Intel
HKCU\SOFTWARE\KasperskyLab =>.Kaspersky Labs
HKCU\SOFTWARE\Macromedia =>.Macromedia
HKCU\SOFTWARE\MCAFEE =>.McAfee Inc.
HKCU\SOFTWARE\Meridian93
HKCU\SOFTWARE\Mozilla =>.Mozilla
HKCU\SOFTWARE\MP3Jam =>.MP3Jam
HKCU\SOFTWARE\Netscape =>.Netscape
HKCU\SOFTWARE\Northcode Inc =>.Northcode Inc
HKCU\SOFTWARE\Oberon Media =>.Oberon Media
HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKCU\SOFTWARE\osTip
HKCU\SOFTWARE\P2PDownloader =>.Unknown
HKCU\SOFTWARE\PopWnd =>.Lenovo Group Limited
HKCU\SOFTWARE\PowerISO =>.PowerISO Computing
HKCU\SOFTWARE\ProductSetup =>Adware.InstallCore
HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\Reimage =>.SUP.ReimageRepair
HKCU\SOFTWARE\Rtp =>.RTP Software
HKCU\SOFTWARE\Skype =>.Skype
HKCU\SOFTWARE\SMADΔV
HKCU\SOFTWARE\Softonic =>.SUP.Softonic
HKCU\SOFTWARE\SoftVoice =>.SoftVoice
HKCU\SOFTWARE\Stargaze Interactive
HKCU\SOFTWARE\SYNCJM =>.SYNCJM
HKCU\SOFTWARE\Sysinternals =>.Sysinternals
HKCU\SOFTWARE\TeleCharger_v2 =>.SUP.Downloader
HKCU\SOFTWARE\The Adventure Company
HKCU\SOFTWARE\TikGames =>.TikGames
HKCU\SOFTWARE\Trolltech =>.Trolltech
HKCU\SOFTWARE\UCBrowserPID =>.UCWeb Inc.
HKCU\SOFTWARE\UpgSvr
HKCU\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation
HKCU\SOFTWARE\VideoBox =>Adware.Amonetize
HKCU\SOFTWARE\Widcomm =>.Widcomm
HKCU\SOFTWARE\WinRAR =>.WinRAR
HKCU\SOFTWARE\WinRAR SFX =>.RarLab
HKCU\SOFTWARE\WinSnare =>.SUP.WinSnare
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\yahoo =>.Yahoo! Inc.
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKCU\SOFTWARE\AppDataLow\Software\Adobe =>.Adobe
HKCU\SOFTWARE\AppDataLow\Software\G DATA =>.G DATA Software
HKCU\SOFTWARE\AppDataLow\Software\SmartBar =>Adware.QuickShare

---\\ Contenu des dossiers Programmes (351) - 70s
O43 - CFD: 12/10/2017 - [] D -- C:\Program Files\2FGC9DGROU
O43 - CFD: 12/10/2017 - [] D -- C:\Program Files\9FXY61TOGW
O43 - CFD: 12/10/2017 - [] D -- C:\Program Files\AVAST Software =>.AVAST Software s.r.o.®
O43 - CFD: 26/03/2016 - [0] D -- C:\Program Files\Babylon =>Adware.Babylon
O43 - CFD: 08/03/2017 - [] D -- C:\Program Files\ByteFence =>.SUP.ByteFence
O43 - CFD: 18/06/2017 - [] AD -- C:\Program Files\Camtel CE682
O43 - CFD: 03/08/2016 - [] D -- C:\Program Files\CMAK =>.Microsoft Corporation
O43 - CFD: 18/06/2017 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\Program Files\DVD Maker =>.Aone Software
O43 - CFD: 08/03/2016 - [] D -- C:\Program Files\Elantech =>.ELAN Microelectronics Corporation®
O43 - CFD: 15/07/2013 - [0] SHD -- C:\Program Files\Fichiers communs =>.Microsoft Corporation
O43 - CFD: 25/12/2013 - [] D -- C:\Program Files\Image-Line =>.Image-Line
O43 - CFD: 03/10/2016 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\Program Files\Lenovo =>.Lenovo
O43 - CFD: 08/03/2016 - [] D -- C:\Program Files\Microsoft Games =>.Microsoft Corporation
O43 - CFD: 15/07/2013 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 01/10/2016 - [] AD -- C:\Program Files\PowerISO =>.PowerISO Computing
O43 - CFD: 12/10/2017 - [] D -- C:\Program Files\QR3TAF2OD3
O43 - CFD: 08/03/2016 - [] D -- C:\Program Files\Realtek =>.Realtek
O43 - CFD: 08/03/2016 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 09/05/2017 - [] D -- C:\Program Files\SAMSUNG =>.Samsung Electronics
O43 - CFD: 18/06/2017 - [] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 02/03/2016 - [] D -- C:\Program Files\VideoLAN =>.VideoLan Team
O43 - CFD: 03/10/2016 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 03/10/2016 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 03/10/2016 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 21/03/2016 - [] D -- C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 03/10/2016 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 21/03/2016 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] SHD -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 13/10/2017 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation
O43 - CFD: 29/10/2015 - [] SD -- C:\Program Files\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 12/10/2017 - [] D -- C:\Program Files\XC550CBZEA
O43 - CFD: 12/10/2017 - [] D -- C:\Program Files\XJ1VXD4E88
O43 - CFD: 12/10/2017 - [] D -- C:\Program Files\XRZRZYAJFS
O43 - CFD: 12/10/2017 - [] D -- C:\Program Files\YBV7RZ3CVM
O43 - CFD: 10/03/2017 - [0] D -- C:\Program Files (x86)\58C2F6C8_cacayima
O43 - CFD: 12/10/2017 - [] D -- C:\Program Files (x86)\5idfebgdtwo
O43 - CFD: 08/03/2016 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Systems, Incorporated®
O43 - CFD: 12/10/2017 - [] D -- C:\Program Files (x86)\amulell =>Adware.aMULEcustom
O43 - CFD: 25/12/2013 - [] D -- C:\Program Files (x86)\ASIO4ALL v2 =>.Michael Tippach
O43 - CFD: 15/07/2013 - [] AD -- C:\Program Files (x86)\Atheros =>.Qualcomm Atheros
O43 - CFD: 03/07/2017 - [] AD -- C:\Program Files (x86)\BikaQRss =>.SUP.BikaQ
O43 - CFD: 16/10/2013 - [] D -- C:\Program Files (x86)\BonanzaDeals =>PUP.Optional.BonanzaDeals
O43 - CFD: 19/07/2015 - [] D -- C:\Program Files (x86)\Cambridge =>.Cambridge
O43 - CFD: 03/08/2016 - [] D -- C:\Program Files (x86)\CMAK =>.Microsoft Corporation
O43 - CFD: 02/03/2016 - [] D -- C:\Program Files (x86)\CodeBlocks =>.CodeBlocks Team
O43 - CFD: 12/10/2017 - [] D -- C:\Program Files (x86)\Coesition =>.VideoLAN®
O43 - CFD: 19/07/2017 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 15/11/2013 - [] D -- C:\Program Files (x86)\Connection Kit
O43 - CFD: 10/03/2017 - [0] D -- C:\Program Files (x86)\deskapp
O43 - CFD: 19/07/2017 - [0] D -- C:\Program Files (x86)\DSPRobotics =>.DSPRobotics
O43 - CFD: 10/03/2017 - [] D -- C:\Program Files (x86)\Elex-tech =>.SUP.Elex
O43 - CFD: 12/10/2017 - [] AD -- C:\Program Files (x86)\FastDataX =>Adware.FastDataX
O43 - CFD: 08/07/2017 - [] AD -- C:\Program Files (x86)\Firefox =>.Mozilla Corporation
O43 - CFD: 10/03/2017 - [] D -- C:\Program Files (x86)\Footper =>.Google Inc®
O43 - CFD: 28/08/2013 - [] D -- C:\Program Files (x86)\G Data =>.G DATA Software
O43 - CFD: 09/03/2017 - [] D -- C:\Program Files (x86)\g12rnbfm
O43 - CFD: 24/09/2013 - [] D -- C:\Program Files (x86)\GamesBar =>PUP.Optional.GamesBar
O43 - CFD: 12/10/2017 - [] D -- C:\Program Files (x86)\Ghesoing Host
O43 - CFD: 20/05/2015 - [] D -- C:\Program Files (x86)\Google =>.Google
O43 - CFD: 19/07/2015 - [] D -- C:\Program Files (x86)\IDM =>.IDM
O43 - CFD: 25/12/2013 - [] D -- C:\Program Files (x86)\Image-Line =>.Image-Line
O43 - CFD: 12/09/2013 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield
O43 - CFD: 08/03/2016 - [] D -- C:\Program Files (x86)\Intel =>.Intel Corporation
O43 - CFD: 03/10/2016 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 03/07/2017 - [0] D -- C:\Program Files (x86)\InternetEverywhere =>.Orange SA
O43 - CFD: 08/05/2015 - [] D -- C:\Program Files (x86)\khi3
O43 - CFD: 12/09/2013 - [] D -- C:\Program Files (x86)\Lenovo =>.Lenovo
O43 - CFD: 14/03/2016 - [] D -- C:\Program Files (x86)\Meridian4
O43 - CFD: 18/06/2017 - [] D -- C:\Program Files (x86)\Microleaves =>.SUP.Microleaves
O43 - CFD: 14/10/2013 - [] AD -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 15/07/2013 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio =>.Microsoft Corporation
O43 - CFD: 15/07/2013 - [] AD -- C:\Program Files (x86)\Microsoft Visual Studio 8 =>.Microsoft Corporation
O43 - CFD: 09/10/2013 - [] D -- C:\Program Files (x86)\Microsoft Works =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 08/03/2017 - [] D -- C:\Program Files (x86)\MIO =>.Mio
O43 - CFD: 08/03/2017 - [0] D -- C:\Program Files (x86)\MK
O43 - CFD: 10/03/2016 - [] AD -- C:\Program Files (x86)\Monopoly
O43 - CFD: 08/07/2017 - [] AD -- C:\Program Files (x86)\Mozilla Firefox =>.Mozilla
O43 - CFD: 08/03/2016 - [] AD -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 02/01/2017 - [] D -- C:\Program Files (x86)\MyPlayCity.com =>.MyPlayCity.com
O43 - CFD: 02/03/2016 - [] D -- C:\Program Files (x86)\Notepad++ =>.Don Ho
O43 - CFD: 12/10/2017 - [] AD -- C:\Program Files (x86)\NoterSave =>.RSA Security
O43 - CFD: 11/11/2016 - [] D -- C:\Program Files (x86)\PdaNet for Android =>.June Fabrics Technology Inc.
O43 - CFD: 10/03/2016 - [0] D -- C:\Program Files (x86)\PopCap Games =>.PopCap Games
O43 - CFD: 15/07/2013 - [] D -- C:\Program Files (x86)\Realtek =>.Realtek
O43 - CFD: 08/03/2016 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 04/07/2017 - [0] D -- C:\Program Files (x86)\SaveShare =>PUP.Optional.SaveShare
O43 - CFD: 12/10/2017 - [] D -- C:\Program Files (x86)\ScreenShared =>Adware.MSIL.ScreenShared
O43 - CFD: 26/02/2016 - [] RD -- C:\Program Files (x86)\Skype =>.Skype
O43 - CFD: 19/07/2017 - [] AD -- C:\Program Files (x86)\SMADAV =>.SmadAV
O43 - CFD: 15/07/2013 - [0] HD -- C:\Program Files (x86)\Temp =>.Microsoft Corporation
O43 - CFD: 13/03/2017 - [] D -- C:\Program Files (x86)\The Adventure Company
O43 - CFD: 13/07/2009 - [0] HD -- C:\Program Files (x86)\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\Program Files (x86)\USB Camera
O43 - CFD: 04/10/2013 - [] D -- C:\Program Files (x86)\VideoLAN =>.VideoLan Team
O43 - CFD: 15/07/2013 - [] D -- C:\Program Files (x86)\Vimicro =>.Vimicro
O43 - CFD: 25/12/2013 - [] D -- C:\Program Files (x86)\VstPlugins =>.VTS
O43 - CFD: 04/07/2017 - [] D -- C:\Program Files (x86)\WiMAX Connection Manager
O43 - CFD: 03/10/2016 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 03/10/2016 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 30/10/2015 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 21/03/2016 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 29/10/2015 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 03/10/2016 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 21/03/2016 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] SHD -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 29/10/2015 - [] SD -- C:\Program Files (x86)\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 25/12/2013 - [] D -- C:\Program Files (x86)\WinRAR =>.WinRAR
O43 - CFD: 15/07/2013 - [] D -- C:\Program Files (x86)\Yahoo! =>.Yahoo!
O43 - CFD: 03/10/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 03/10/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 03/10/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cambridge =>.Cambridge
O43 - CFD: 19/05/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Camtel CE682
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CodeBlocks =>.CodeBlocks Team
O43 - CFD: 08/03/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line =>.Image-Line
O43 - CFD: 08/03/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel =>.Intel Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KAPITALSIN
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo =>.Lenovo
O43 - CFD: 29/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 14/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Meridian4
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 02/01/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPlayCity.com =>.MyPlayCity.com
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ =>.Don Ho
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Orange =>.Orange
O43 - CFD: 01/10/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO =>.PowerISO Computing
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype =>.Skype
O43 - CFD: 08/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMADAV Antivirus =>.SmadAV
O43 - CFD: 29/10/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp =>.Microsoft Corporation
O43 - CFD: 03/10/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Test Simulator
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Adventure Company
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team
O43 - CFD: 04/07/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WiMAX Connection Manager
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 01/10/2017 - [] HD -- C:\ProgramData\8953O2195O6051r9296
O43 - CFD: 11/10/2017 - [] D -- C:\ProgramData\98c66a2c-0201-0 =>.SUP.Polluteware
O43 - CFD: 11/10/2017 - [] D -- C:\ProgramData\98c66a2c-0da1-1 =>.SUP.Polluteware
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Adobe =>.Adobe
O43 - CFD: 24/09/2013 - [] D -- C:\ProgramData\Alawar Stargaze =>.Alawar Entertainment
O43 - CFD: 26/01/2015 - [] D -- C:\ProgramData\APN =>Toolbar.Ask
O43 - CFD: 10/03/2017 - [] D -- C:\ProgramData\Apple =>.Apple Inc.
O43 - CFD: 08/03/2016 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 01/10/2013 - [] D -- C:\ProgramData\Arcade Lab
O43 - CFD: 15/07/2013 - [] D -- C:\ProgramData\Atheros =>.Qualcomm Atheros
O43 - CFD: 12/10/2017 - [] D -- C:\ProgramData\AVAST Software =>.AVAST Software
O43 - CFD: 13/03/2017 - [] AD -- C:\ProgramData\BlueStacks =>.BlueStack Systems, Inc.
O43 - CFD: 03/07/2017 - [] D -- C:\ProgramData\BlueStacksSetup =>.BlueStack Systems, Inc.
O43 - CFD: 15/07/2013 - [0] SHD -- C:\ProgramData\Bureau =>.Microsoft Corporation
O43 - CFD: 17/09/2013 - [] D -- C:\ProgramData\Camtel EVDO-Huawei
O43 - CFD: 29/10/2015 - [0] D -- C:\ProgramData\Comms =>.Microsoft Corporation
O43 - CFD: 19/05/2016 - [] D -- C:\ProgramData\DatacardService =>.Entriq, Inc.
O43 - CFD: 08/03/2016 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 15/07/2013 - [] D -- C:\ProgramData\Downloaded Installations =>.Microsoft Corporation
O43 - CFD: 04/07/2017 - [0] D -- C:\ProgramData\DSearchLink =>.SUP.DeltaSearch
O43 - CFD: 15/07/2013 - [0] SHD -- C:\ProgramData\Favoris =>.Microsoft Corporation
O43 - CFD: 10/03/2016 - [] D -- C:\ProgramData\InstallMate =>Adware.Tarma
O43 - CFD: 15/07/2013 - [] D -- C:\ProgramData\Intel =>.Intel Corporation
O43 - CFD: 01/10/2013 - [] D -- C:\ProgramData\InterAction studios =>.InterAction Studios
O43 - CFD: 08/03/2017 - [] D -- C:\ProgramData\IObit =>.IObit
O43 - CFD: 14/03/2016 - [] D -- C:\ProgramData\Kheops Studio
O43 - CFD: 16/05/2014 - [] D -- C:\ProgramData\KONAMI =>.Konami
O43 - CFD: 04/07/2017 - [] D -- C:\ProgramData\Malwarebytes =>.Malwarebytes
O43 - CFD: 09/09/2014 - [] D -- C:\ProgramData\McAfee =>.McAfee
O43 - CFD: 15/07/2013 - [0] SHD -- C:\ProgramData\Menu Démarrer =>.Microsoft Corporation
O43 - CFD: 28/08/2013 - [] D -- C:\ProgramData\Meridian93 =>.Meridian93 Games
O43 - CFD: 18/06/2017 - [] D -- C:\ProgramData\Microleaves =>.SUP.Microleaves
O43 - CFD: 08/03/2017 - [] ASD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 02/10/2016 - [] D -- C:\ProgramData\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Microsoft OneDrive =>.Microsoft Corporation
O43 - CFD: 15/07/2013 - [0] SHD -- C:\ProgramData\Modèles =>.Microsoft Corporation
O43 - CFD: 06/03/2016 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 02/10/2013 - [] D -- C:\ProgramData\Playrix Entertainment =>.Playrix Entertainment
O43 - CFD: 08/03/2017 - [] D -- C:\ProgramData\ProductData =>.Microsoft Corporation
O43 - CFD: 30/10/2015 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
O43 - CFD: 14/03/2016 - [] D -- C:\ProgramData\RTMI2
O43 - CFD: 13/05/2014 - [] D -- C:\ProgramData\RTMI2-BF
O43 - CFD: 09/05/2017 - [] D -- C:\ProgramData\Samsung =>.Samsung Electronics
O43 - CFD: 04/07/2017 - [] D -- C:\ProgramData\savensharre =>PUP.Optional.SaveShare
O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Skype =>.Skype
O43 - CFD: 21/03/2016 - [] D -- C:\ProgramData\SoftwareDistribution =>.Microsoft Corporation
O43 - CFD: 02/10/2013 - [] D -- C:\ProgramData\SugarGames
O43 - CFD: 28/08/2013 - [] D -- C:\ProgramData\SummerSoft =>.SummerSoft
O43 - CFD: 17/08/2017 - [] AD -- C:\ProgramData\Temp =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\USOPrivate =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\USOShared =>.Microsoft Corporation
O43 - CFD: 18/06/2017 - [] D -- C:\ProgramData\Utatitys
O43 - CFD: 12/10/2017 - [] D -- C:\ProgramData\vCore =>PUP.Optional.AArtemis
O43 - CFD: 04/07/2017 - [] D -- C:\ProgramData\WiMAX Connection Manager
O43 - CFD: 12/10/2017 - [] SHD -- C:\ProgramData\WindowsMsg
O43 - CFD: 15/07/2013 - [] D -- C:\ProgramData\Yahoo! =>.Yahoo!
O43 - CFD: 08/03/2016 - [] AD -- C:\Program Files (x86)\Common Files\Adobe =>.Adobe
O43 - CFD: 18/05/2014 - [] AD -- C:\Program Files (x86)\Common Files\DESIGNER =>.Designer
O43 - CFD: 15/11/2013 - [] D -- C:\Program Files (x86)\Common Files\France Telecom =>.France Telecom
O43 - CFD: 06/02/2014 - [0] D -- C:\Program Files (x86)\Common Files\G Data =>.G DATA Software
O43 - CFD: 15/07/2013 - [] D -- C:\Program Files (x86)\Common Files\InstallShield =>.InstallShield
O43 - CFD: 08/03/2016 - [] AD -- C:\Program Files (x86)\Common Files\Microsoft Shared =>.Microsoft Corporation
O43 - CFD: 15/07/2013 - [] D -- C:\Program Files (x86)\Common Files\postureAgent =>.Microsoft Corporation
O43 - CFD: 29/10/2015 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 28/08/2015 - [] AD -- C:\Program Files (x86)\Common Files\Skype =>.Skype
O43 - CFD: 08/03/2016 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 02/10/2013 - [0] SHD -- C:\Users\LENOVO\AppData\Roaming\.#
O43 - CFD: 19/07/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\43iy32yoyn2
O43 - CFD: 19/07/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\4nfmj2prvio
O43 - CFD: 12/10/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\5mfgdozgavy
O43 - CFD: 19/07/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\9a0511b629fb46179e32b1cf8cf09978
O43 - CFD: 19/07/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\ac47ea1c8cb444e48a8355268641793c
O43 - CFD: 04/07/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 19/07/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\aMule =>Adware.aMULEcustom
O43 - CFD: 13/03/2017 - [0] D -- C:\Users\LENOVO\AppData\Roaming\Atafother
O43 - CFD: 12/10/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\AVAST Software =>.AVAST Software
O43 - CFD: 12/10/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\b4b0z0ajqcb
O43 - CFD: 13/05/2014 - [] D -- C:\Users\LENOVO\AppData\Roaming\BitLord =>PUP.Optional.WhenUSave
O43 - CFD: 13/10/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\BitTorrent
O43 - CFD: 28/08/2013 - [] D -- C:\Users\LENOVO\AppData\Roaming\Boolat Games =>.Boolat Games
O43 - CFD: 13/02/2015 - [0] D -- C:\Users\LENOVO\AppData\Roaming\BRT
O43 - CFD: 19/07/2015 - [] D -- C:\Users\LENOVO\AppData\Roaming\cald4
O43 - CFD: 08/12/2016 - [] D -- C:\Users\LENOVO\AppData\Roaming\CodeBlocks =>.CodeBlocks Team
O43 - CFD: 13/05/2014 - [] D -- C:\Users\LENOVO\AppData\Roaming\DAEMON Tools Lite =>.DAEMON Tools
O43 - CFD: 01/03/2016 - [0] D -- C:\Users\LENOVO\AppData\Roaming\DiskDefrag =>.Auslogics
O43 - CFD: 03/07/2017 - [0] D -- C:\Users\LENOVO\AppData\Roaming\dvdcss =>.VideoLan Team
O43 - CFD: 03/07/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\eCyber =>.SUP.Elex
O43 - CFD: 29/01/2016 - [] D -- C:\Users\LENOVO\AppData\Roaming\Edulang =>.Edulang
O43 - CFD: 10/03/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\Elex-tech =>.SUP.Elex
O43 - CFD: 27/02/2016 - [] D -- C:\Users\LENOVO\AppData\Roaming\EVDO_General
O43 - CFD: 19/05/2016 - [] D -- C:\Users\LENOVO\AppData\Roaming\EVDO_Haier
O43 - CFD: 28/08/2013 - [] D -- C:\Users\LENOVO\AppData\Roaming\EZDownloader =>.EZDownloader
O43 - CFD: 10/03/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\Firefox =>.Mozilla Corporation
O43 - CFD: 12/10/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\fkrz1xsrdn4
O43 - CFD: 13/05/2014 - [] D -- C:\Users\LENOVO\AppData\Roaming\FlowStone =>.DSPRobotics
O43 - CFD: 01/10/2013 - [] D -- C:\Users\LENOVO\AppData\Roaming\GameConsole =>.Legitimate
O43 - CFD: 18/10/2013 - [] D -- C:\Users\LENOVO\AppData\Roaming\GoforFiles =>PUP.Optional.YourFileDownloader
O43 - CFD: 13/10/2017 - [] AD -- C:\Users\LENOVO\AppData\Roaming\gplyra =>.SUP.Gplyra
O43 - CFD: 24/09/2013 - [] D -- C:\Users\LENOVO\AppData\Roaming\HdO Adventure
O43 - CFD: 12/10/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\i2wxpobjy0j
O43 - CFD: 15/07/2013 - [] D -- C:\Users\LENOVO\AppData\Roaming\Identities =>.Microsoft Corporation
O43 - CFD: 03/07/2017 - [0] D -- C:\Users\LENOVO\AppData\Roaming\idesktop =>.Apple Inc.
O43 - CFD: 25/12/2013 - [] D -- C:\Users\LENOVO\AppData\Roaming\Image-Line =>.Image-Line
O43 - CFD: 15/07/2013 - [] D -- C:\Users\LENOVO\AppData\Roaming\InstallShield =>.InstallShield
O43 - CFD: 15/07/2013 - [] D -- C:\Users\LENOVO\AppData\Roaming\Intel Corporation =>.Intel Corporation
O43 - CFD: 08/03/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\IObit =>.IObit
O43 - CFD: 12/10/2017 - [0] D -- C:\Users\LENOVO\AppData\Roaming\Kyubey =>Adware.CrossRider
O43 - CFD: 09/10/2013 - [] D -- C:\Users\LENOVO\AppData\Roaming\LaJangada
O43 - CFD: 31/08/2013 - [] D -- C:\Users\LENOVO\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 14/07/2009 - [0] D -- C:\Users\LENOVO\AppData\Roaming\Media Center Programs =>.Microsoft Corporation
O43 - CFD: 28/08/2013 - [] D -- C:\Users\LENOVO\AppData\Roaming\Meridian93 =>.Meridian93 Games
O43 - CFD: 18/06/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\Microleaves =>.SUP.Microleaves
O43 - CFD: 09/03/2016 - [] SD -- C:\Users\LENOVO\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 13/05/2014 - [] D -- C:\Users\LENOVO\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 02/03/2016 - [] D -- C:\Users\LENOVO\AppData\Roaming\Notepad++ =>.Don Ho
O43 - CFD: 24/09/2013 - [] D -- C:\Users\LENOVO\AppData\Roaming\Oberon Media =>.Oberon Media
O43 - CFD: 19/07/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\ozjhzum052h
O43 - CFD: 13/05/2014 - [] D -- C:\Users\LENOVO\AppData\Roaming\PowerISO =>.PowerISO Computing
O43 - CFD: 08/03/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\Profiles =>.Microsoft Corporation
O43 - CFD: 10/10/2013 - [] D -- C:\Users\LENOVO\AppData\Roaming\Python-Eggs =>.Python
O43 - CFD: 03/07/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\Skype =>.Skype
O43 - CFD: 08/06/2017 - [0] D -- C:\Users\LENOVO\AppData\Roaming\Smadav =>.SmadAV
O43 - CFD: 13/05/2014 - [] D -- C:\Users\LENOVO\AppData\Roaming\SunRay Games
O43 - CFD: 08/03/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\UCChannel =>.SUP.UCBrowser
O43 - CFD: 13/05/2014 - [] D -- C:\Users\LENOVO\AppData\Roaming\ValueApps
O43 - CFD: 26/09/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\vlc =>.VideoLan Team
O43 - CFD: 25/12/2013 - [] D -- C:\Users\LENOVO\AppData\Roaming\WinRAR =>.WinRAR
O43 - CFD: 12/10/2017 - [0] D -- C:\Users\LENOVO\AppData\Roaming\WinSAPSvc =>PUP.Optional.Youndoo
O43 - CFD: 12/10/2017 - [0] D -- C:\Users\LENOVO\AppData\Roaming\WinSnare =>.SUP.WinSnare
O43 - CFD: 13/10/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 08/03/2016 - [0] D -- C:\Users\LENOVO\AppData\Local\ActiveSync =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\Users\LENOVO\AppData\Local\Adobe =>.Adobe
O43 - CFD: 18/06/2017 - [] D -- C:\Users\LENOVO\AppData\Local\AdvinstAnalytics =>.SUP.Various
O43 - CFD: 08/03/2016 - [0] SHD -- C:\Users\LENOVO\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 12/09/2013 - [] D -- C:\Users\LENOVO\AppData\Local\avgchrome
O43 - CFD: 10/10/2013 - [] D -- C:\Users\LENOVO\AppData\Local\Big Fish =>.Big Fish
O43 - CFD: 19/07/2015 - [] D -- C:\Users\LENOVO\AppData\Local\cald4
O43 - CFD: 08/03/2016 - [] D -- C:\Users\LENOVO\AppData\Local\CEF =>.CEF
O43 - CFD: 08/03/2016 - [] D -- C:\Users\LENOVO\AppData\Local\Comms =>.Microsoft Corporation
O43 - CFD: 20/08/2017 - [0] D -- C:\Users\LENOVO\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 06/02/2014 - [0] D -- C:\Users\LENOVO\AppData\Local\Downloaded Installations =>.Microsoft Corporation
O43 - CFD: 29/01/2016 - [] D -- C:\Users\LENOVO\AppData\Local\Edulang =>.Edulang
O43 - CFD: 20/08/2017 - [0] D -- C:\Users\LENOVO\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation
O43 - CFD: 26/02/2016 - [0] SHD -- C:\Users\LENOVO\AppData\Local\EmieBrowserModeList =>.Enterprise mode Site List Mgr
O43 - CFD: 26/02/2016 - [0] SHD -- C:\Users\LENOVO\AppData\Local\EmieSiteList =>.Enterprise mode Site List Mgr
O43 - CFD: 26/02/2016 - [0] SHD -- C:\Users\LENOVO\AppData\Local\EmieUserList =>.Enterprise mode Site List Mgr
O43 - CFD: 10/03/2017 - [] D -- C:\Users\LENOVO\AppData\Local\Firefox =>.Mozilla Corporation
O43 - CFD: 10/03/2017 - [] D -- C:\Users\LENOVO\AppData\Local\Footper
O43 - CFD: 08/03/2017 - [0] D -- C:\Users\LENOVO\AppData\Local\Fusleterfether
O43 - CFD: 01/10/2017 - [] D -- C:\Users\LENOVO\AppData\Local\Google =>.Google
O43 - CFD: 06/03/2016 - [] D -- C:\Users\LENOVO\AppData\Local\GWX =>.GWX
O43 - CFD: 08/03/2016 - [0] SHD -- C:\Users\LENOVO\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 01/10/2017 - [0] D -- C:\Users\LENOVO\AppData\Local\InetInfo
O43 - CFD: 11/10/2017 - [0] D -- C:\Users\LENOVO\AppData\Local\InternetInfoLocation
O43 - CFD: 12/09/2013 - [] D -- C:\Users\LENOVO\AppData\Local\Macromedia =>.Macromedia
O43 - CFD: 02/10/2016 - [] D -- C:\Users\LENOVO\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 13/05/2014 - [] D -- C:\Users\LENOVO\AppData\Local\Microsoft Games =>.Microsoft Corporation
O43 - CFD: 03/07/2017 - [0] D -- C:\Users\LENOVO\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 10/03/2016 - [] D -- C:\Users\LENOVO\AppData\Local\MicrosoftEdge =>.Microsoft Corporation
O43 - CFD: 13/05/2014 - [] D -- C:\Users\LENOVO\AppData\Local\Mozilla =>.Mozilla Corporation
O43 - CFD: 18/06/2017 - [0] D -- C:\Users\LENOVO\AppData\Local\nav.tools
O43 - CFD: 08/03/2016 - [0] D -- C:\Users\LENOVO\AppData\Local\NetworkTiles =>.NetworkTiles
O43 - CFD: 15/08/2016 - [] D -- C:\Users\LENOVO\AppData\Local\Oberon Games =>.Oberon Games
O43 - CFD: 18/06/2017 - [] D -- C:\Users\LENOVO\AppData\Local\Packages =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [0] D -- C:\Users\LENOVO\AppData\Local\PeerDistRepub =>.Microsoft Corporation
O43 - CFD: 28/08/2013 - [] D -- C:\Users\LENOVO\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\Users\LENOVO\AppData\Local\Publishers =>.Microsoft Corporation
O43 - CFD: 09/02/2015 - [] D -- C:\Users\LENOVO\AppData\Local\Skype =>.Skype
O43 - CFD: 01/10/2017 - [0] SHD -- C:\Users\LENOVO\AppData\Local\svchost =>Trojan.Agent
O43 - CFD: 13/10/2017 - [] D -- C:\Users\LENOVO\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [0] SHD -- C:\Users\LENOVO\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\Users\LENOVO\AppData\Local\TileDataLayer =>.Microsoft Corporation
O43 - CFD: 08/03/2017 - [] D -- C:\Users\LENOVO\AppData\Local\UCBrowser =>.SUP.UCBrowser
O43 - CFD: 05/08/2014 - [] D -- C:\Users\LENOVO\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 05/02/2014 - [] D -- C:\Users\LENOVO\AppData\Local\Yahoo
O43 - CFD: 13/10/2017 - [] D -- C:\Users\LENOVO\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 28/08/2013 - [0] D -- C:\Users\LENOVO\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 29/10/2015 - [] RD -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] RD -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 03/10/2016 - [] RD -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 10/03/2017 - [] D -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC =>Adware.aMULEcustom
O43 - CFD: 08/03/2016 - [] D -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2 =>.Michael Tippach
O43 - CFD: 08/03/2016 - [] D -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CodeBlocks =>.CodeBlocks Team
O43 - CFD: 08/03/2016 - [] D -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line =>.Image-Line
O43 - CFD: 29/10/2015 - [] D -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 11/11/2016 - [] RD -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 29/10/2015 - [] RD -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 08/12/2016 - [] D -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Adventure Company
O43 - CFD: 29/10/2015 - [] RSD -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [] D -- C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 08/03/2016 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [0] SHD -- C:\Users\Default\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 04/07/2017 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [0] D -- C:\Users\Default\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 29/10/2015 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [0] SHD -- C:\Users\Default User\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 04/07/2017 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [0] D -- C:\Users\Default User\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 29/10/2015 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 08/03/2016 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 12/10/2017 - [] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\AVAST Software =>.AVAST Software
O43 - CFD: 08/03/2016 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 16/02/2017 - [] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Mozilla =>.Mozilla Corporation
O43 - CFD: 08/03/2016 - [0] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\PeerDistRepub =>.Microsoft Corporation
O43 - CFD: 15/04/2016 - [] SD -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 16/02/2017 - [] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 08/03/2017 - [] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Tencent =>.SUP.Tencent

---\\ ShellExecuteHook (1) - 0s
O46 - SEH:ShellExecuteHooks - (no name) - [HKLM] [64Bits] - {8D0F0CA6-FFDA-11E6-8C16-64006A5CFC23} . (...) -- (.not file.)

---\\ ShellIconOverlayIdentifiers (SIOI) (7) - 1s
O106 - SIOI: ErrorOverlayHandler Class [ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\LENOVO\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SharedOverlayHandler Class [ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\LENOVO\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SharedSyncingOverlayHandler Class [ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\LENOVO\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: UpToDateOverlayHandler Class [ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\LENOVO\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SyncingOverlayHandler Class [ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\LENOVO\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: avast [00asw] - {472083B0-C522-11CF-8763-00608CC02F24}. (.AVAST Software - Avast Shell Extension.) -- C:\Program Files\AVAST Software\Avast\ashShell.dll =>.AVAST Software s.r.o.®
O106 - SIOI: avast [00avast] - {472083B0-C522-11CF-8763-00608CC02F24}. (.AVAST Software - Avast Shell Extension.) -- C:\Program Files\AVAST Software\Avast\ashShell.dll =>.AVAST Software s.r.o.®

---\\ Image File Execution Options (16) - 2s
O50 - IFEO:C:\Windows\System32\cscript.exe - (.Microsoft Corporation - Microsoft ® Console Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\dllhost.exe - (.Microsoft Corporation - COM Surrogate.) [DisableExceptionChainValidation\\3] =>.Microsoft Windows®
O50 - IFEO:C:\WINDOWS\System32\drvinst.exe - (.Microsoft Corporation - Module d’installation de pilotes.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\ie4uinit.exe - (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - Outil d’installation sans assistance d’IE 7.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mmc.exe - (.Microsoft Corporation - Microsoft Management Console.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Hôte des applications HTML de Microsoft(R).) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Windows Presentation Foundation Host.) [MitigationOptions\\1118481] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\PrintIsolationHost.exe - (.Microsoft Corporation - PrintIsolationHost.) [MitigationOptions\\2097152] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\rundll32.exe - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\\4294967296] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\searchprotocolhost.exe - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Application sous-système spouleur.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Application sous-système spouleur.) [MitigationOptions\\2097152] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\wscript.exe - (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation

---\\ Enumération des clés StartupReg (3) - 0s
O53 - SMSR:HKLM\...\startupreg\Babylon Client [Key] [64Bits] . (...) -- C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe (.not file.) =>Adware.Babylon
O53 - SMSR:HKLM\...\startupreg\PWRISOVM.EXE [Key] [64Bits] . (.Power Software Ltd - PowerISO Virtual Drive Manager.) -- C:\Program Files\PowerISO\PWRISOVM.EXE =>.Power Software Ltd
O53 - SMSR:HKLM\...\startupreg\Zune Launcher [Key] [64Bits] . (...) -- C:\Program Files\Zune\ZuneLauncher.exe (.not file.)

---\\ Liste des pilotes du système (87) - 36s
O58 - SDL:2015/10/29 22:17:22 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107360] =>.Microsoft Windows®
O58 - SDL:2012/10/30 03:20:10 A . (.Lenovo Corporation - ACPI Virtual Power Controller Driver.) -- C:\WINDOWS\System32\drivers\AcpiVpc.sys [30816] =>.Lenovo (Beijing) Limited®
O58 - SDL:2015/10/29 22:17:22 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135456] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:22 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [83296] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:22 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259424] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:22 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [26976] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:22 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [131936] =>.Microsoft Windows®
O58 - SDL:2017/10/12 08:13:46 A . (.AVAST Software s.r.o. - IDS Application Activity Monitor Driver..) -- C:\WINDOWS\System32\drivers\aswbidsdrivera.sys [320528] =>.AVAST Software s.r.o.®
O58 - SDL:2017/10/12 08:13:46 A . (.AVAST Software s.r.o. - Application Activity Monitor Helper Driver.) -- C:\WINDOWS\System32\drivers\aswbidsha.sys [198976] =>.AVAST Software s.r.o.®
O58 - SDL:2017/10/12 08:13:46 A . (.AVAST Software s.r.o. - Logging Driver.) -- C:\WINDOWS\System32\drivers\aswbloga.sys [343296] =>.AVAST Software s.r.o.®
O58 - SDL:2017/10/12 08:13:46 A . (.AVAST Software s.r.o. - Universal Driver.) -- C:\WINDOWS\System32\drivers\aswbuniva.sys [57736] =>.AVAST Software s.r.o.®
O58 - SDL:2017/10/12 08:14:42 A . (.AVAST Software - Avast HWID.) -- C:\WINDOWS\System32\drivers\aswHwid.sys [47016] =>.AVAST Software s.r.o.® (.AVAST Software)
O58 - SDL:2017/10/12 08:14:42 A . (.AVAST Software - Avast File System Minifilter for Windows 20.) -- C:\WINDOWS\System32\drivers\aswMonFlt.sys [147784] =>.AVAST Software s.r.o.®
O58 - SDL:2017/10/12 08:14:41 A . (.AVAST Software - Avast WFP Redirect Driver.) -- C:\WINDOWS\System32\drivers\aswRdr2.sys [110376] =>.AVAST Software s.r.o.®
O58 - SDL:2017/10/12 08:14:42 A . (.AVAST Software - Avast Revert.) -- C:\WINDOWS\System32\drivers\aswRvrt.sys [84416] =>.AVAST Software s.r.o.® (.AVAST Software)
O58 - SDL:2017/10/12 08:13:55 A . (.AVAST Software - Avast Virtualization Driver.) -- C:\WINDOWS\System32\drivers\aswSnx.sys [1016384] =>.AVAST Software s.r.o.®
O58 - SDL:2017/10/12 08:14:42 A . (.AVAST Software - Avast self protection module.) -- C:\WINDOWS\System32\drivers\aswSP.sys [590880] =>.AVAST Software s.r.o.®
O58 - SDL:2017/10/12 08:16:09 A . (.AVAST Software - Stream Filter.) -- C:\WINDOWS\System32\drivers\aswstm.sys [199312] =>.AVAST Software s.r.o.®
O58 - SDL:2017/10/12 08:16:21 A . (.AVAST Software - Avast VM Monitor.) -- C:\WINDOWS\System32\drivers\aswvmm.sys [361784] =>.AVAST Software s.r.o.® (.AVAST Software)
O58 - SDL:2015/10/29 22:17:18 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\drivers\athwnx.sys [4207104] =>.Qualcomm Atheros Communications, Inc.
O58 - SDL:2013/09/25 10:25:50 A . (.Beceem communications pvt ltd. - Beceem Communications Inc. WiMAX driver.) -- C:\WINDOWS\System32\drivers\BcmBusCtr_64.sys [32768] =>.Beceem communications pvt ltd.
O58 - SDL:2015/10/29 22:17:22 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn.sys [9728] =>.Windows (R) Win 7 DDK provider
O58 - SDL:2015/10/29 22:17:22 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [9728] =>.Windows (R) Win 7 DDK provider
O58 - SDL:2015/10/29 22:17:22 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [531296] =>.Microsoft Windows®
O58 - SDL:2017/03/04 12:33:01 A . (.Connectify - Connectify NDISRD helper driver.) -- C:\WINDOWS\System32\drivers\cfywlan2.sys [46088] =>.Connectify (Connectify, Inc.)®
O58 - SDL:2017/03/04 12:33:00 A . (.Connectify - CNNCTFY helper driver.) -- C:\WINDOWS\System32\drivers\cnnctfy4.sys [53216] =>.Connectify (Connectify, Inc.)®
O58 - SDL:2009/04/27 06:33:16 A . (.QUALCOMM Incorporated - USB Modem/Serial Device Driver.) -- C:\WINDOWS\System32\drivers\CT_QUALCOMM_U_drv.sys [118016] =>.QUALCOMM Incorporated
O58 - SDL:2010/11/10 21:14:52 RA . (.Realtek Semiconductor Corp. - Realtek Turbo Mode Filter Driver for 39.) -- C:\WINDOWS\System32\drivers\diskperf64.sys [17512] =>.Realtek Semiconductor Corp®
O58 - SDL:2013/09/25 10:25:50 A . (.Beceem communications pvt ltd. - Beceem Communications Inc. WiMAX driver.) -- C:\WINDOWS\System32\drivers\drxvi314_64.sys [266240] =>.Beceem communications pvt ltd.
O58 - SDL:2015/10/06 16:11:38 A . (.ELAN Microelectronics Corp. - ETD Kernel Center.) -- C:\WINDOWS\System32\drivers\ETD.sys [525512] =>.ELAN Microelectronics Corporation®
O58 - SDL:2015/10/29 22:17:22 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3436896] =>.Microsoft Windows®
O58 - SDL:2015/02/25 12:04:23 A . (.Huawei Technologies Co., Ltd. - ew_jubusenum Driver.) -- C:\WINDOWS\System32\drivers\ew_jubusenum.sys [86016] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2013/08/28 07:32:45 A . (.G Data Software AG - Behavior Blocker.) -- C:\WINDOWS\System32\drivers\GDBehave.sys [54136] =>.G DATA Software AG®
O58 - SDL:2013/09/07 08:13:34 A . (.G Data Software AG - G Data WFP Callout Driver.) -- C:\WINDOWS\System32\drivers\gdwfpcd64.sys [65912] =>.G DATA Software AG®
O58 - SDL:2013/09/12 13:03:24 A . (.G Data Software - G Data Rootkit Detector Driver.) -- C:\WINDOWS\System32\drivers\GRD.sys [106648] =>.G DATA Software AG®
O58 - SDL:2016/03/01 22:55:37 A . (.Glarysoft Ltd - The driver for the Startup Manager tool.) -- C:\WINDOWS\System32\drivers\GUBootStartup.sys [20160] =>.Glarysoft Ltd®
O58 - SDL:2010/10/18 23:34:26 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\HECIx64.sys [56344] =>.Intel Corporation®
O58 - SDL:2015/10/29 22:17:22 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64352] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:18 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) -- C:\WINDOWS\System32\drivers\iai2c.sys [81408] =>.Intel(R) Corporation
O58 - SDL:2015/10/29 22:17:18 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [165888] =>.Intel Corporation
O58 - SDL:2015/10/29 22:17:18 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] =>.Intel Corporation - Client Components Group®
O58 - SDL:2015/10/29 22:17:18 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [113152] =>.Intel Corporation
O58 - SDL:2015/10/29 22:17:22 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [673120] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:22 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412000] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:23 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [424800] =>.Microsoft Windows®
O58 - SDL:2015/06/01 11:00:18 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\igdkmd64.sys [5384176] =>.Intel Corporation - pGFX®
O58 - SDL:2010/10/14 08:28:16 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\WINDOWS\System32\drivers\IntcDAud.sys [317440] =>.Intel(R) Corporation
O58 - SDL:2016/05/22 17:41:44 A . (.Elex do Brasil Participações Ltda - iSafe Kernel Boot Driver.) -- C:\WINDOWS\System32\drivers\iSafeKrnlBoot.sys [55056] =>.SUP.Elex
O58 - SDL:2016/05/18 21:42:01 A . (.Elex do Brasil Participações Ltda - iSafeNetFilter SDK WFP Driver (WPP).) -- C:\WINDOWS\System32\drivers\iSafeNetFilter.sys [52392] =>.SUP.Elex
O58 - SDL:2017/10/12 08:16:06 A . (...) -- C:\WINDOWS\System32\drivers\lpsport.sys [61304]
O58 - SDL:2015/10/29 22:17:23 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [108888] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:23 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [104800] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:23 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [99168] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:23 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82784] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:23 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59744] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:23 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575840] =>.Microsoft Windows®
O58 - SDL:2013/08/28 07:32:46 A . (.G Data Software AG - Filesystem MiniInterceptor (Mini Filter).) -- C:\WINDOWS\System32\drivers\MiniIcpt.sys [122744] =>.G DATA Software AG®
O58 - SDL:2015/10/29 22:17:23 A . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [705376] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:23 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63840] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:23 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [76128] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:23 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150368] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:23 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [166240] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:23 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [58208] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:23 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [58720] =>.Microsoft Windows®
O58 - SDL:2013/08/28 07:33:43 A . (.G Data Software AG - WFP PktInterceptor 2 (Pkt2 Filter).) -- C:\WINDOWS\System32\drivers\PktIcpt.sys [59768] =>.G DATA Software AG®
O58 - SDL:2017/03/08 16:53:58 A . (.Sysinternals - www.sysinternals.com - Process Explorer.) -- C:\WINDOWS\System32\drivers\PROCEXP152.SYS [34328] =>.Sysinternals®
O58 - SDL:2015/10/29 22:17:23 A . (.Realtek - Realtek 8136/8168/8169 NDIS 6.40 64-bit Dri.) -- C:\WINDOWS\System32\drivers\rt640x64.sys [589824] =>.Realtek
O58 - SDL:2011/01/04 02:51:16 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\WINDOWS\System32\drivers\RTKVHD64.sys [2697448] =>.Realtek Semiconductor Corp®
O58 - SDL:2010/11/29 21:40:04 A . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/V.) -- C:\WINDOWS\System32\drivers\RtsUVStor.sys [307304] =>.Realtek Semiconductor Corp®
O58 - SDL:2016/02/10 04:21:28 A . (.Power Software Ltd - PowerISO Virtual Drive.) -- C:\WINDOWS\System32\drivers\scdemu.sys [137280] =>.Power Software Limited®
O58 - SDL:2015/10/29 22:17:23 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44896] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:23 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81760] =>.Microsoft Windows®
O58 - SDL:2013/05/28 15:24:48 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ve.) -- C:\WINDOWS\System32\drivers\ssudbus.sys [103064] =>.Samsung Electronics CO., LTD.®
O58 - SDL:2013/05/28 15:24:48 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ve.) -- C:\WINDOWS\System32\drivers\ssudmdm.sys [203672] =>.Samsung Electronics CO., LTD.®
O58 - SDL:2015/10/29 22:17:23 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31072] =>.Microsoft Windows®
O58 - SDL:2013/07/18 00:46:30 A . (...) -- C:\WINDOWS\System32\drivers\USB_BusEnum_H.sys [44544]
O58 - SDL:2013/07/18 00:46:30 A . (.Via Telecom, Inc. - viausbets driver.) -- C:\WINDOWS\System32\drivers\USB_ETS_H.sys [21760] =>.Via Telecom, Inc.
O58 - SDL:2013/07/18 00:46:30 A . (...) -- C:\WINDOWS\System32\drivers\USB_MODEM_H.sys [28160]
O58 - SDL:2013/07/18 00:46:30 A . (...) -- C:\WINDOWS\System32\drivers\USB_WinMux_H.sys [37376]
O58 - SDL:2010/10/21 01:05:22 A . (.Vimicro Corporation - VM0331 Digital Camera Driver.) -- C:\WINDOWS\System32\drivers\vm331avs.sys [228224] =>.Vimicro Corporation
O58 - SDL:2010/08/16 00:28:50 A . (.Vimicro Corporation - Vimicro USB Camera Filter.) -- C:\WINDOWS\System32\drivers\vmuvcflt.sys [8320] =>.Vimicro Corporation
O58 - SDL:2015/10/29 22:17:23 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166752] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:23 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305504] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:23 A . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [26976] =>.Microsoft Windows®
O58 - SDL:2015/10/29 22:17:23 A . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [59232] =>.Microsoft Windows®
O58 - SDL:2015/02/27 06:06:48 N . (.StdLib - StdLib.) -- C:\WINDOWS\System32\drivers\{f365189d-3e18-4f01-8423-a1ed102ed962}w64.sys [48832] {68B083249006BA50D35F50A8F44CD7D4} =>PUP.Optional.LinkiDoo
O58 - SDL:2010/11/24 01:33:26 A . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driv.) -- C:\WINDOWS\System32\athrx.sys [2673664] =>.Atheros Communications, Inc.

---\\ Derniers fichiers modifiés ou crées (Utilisateur) (3) - 69s
O61 - LFC: 2017/10/13 16:03:43 A . (..) -- C:\Users\LENOVO\Downloads\CKScanner (1).exe [468480]
O61 - LFC: 2017/10/13 15:50:40 A . (..) -- C:\Users\LENOVO\Downloads\CKScanner.exe [468480]
O61 - LFC: 2017/10/13 16:09:12 A . (..) -- C:\Users\LENOVO\Downloads\winchk_2.0.exe [315000]

---\\ Associations Shell Spawning (11) - 2s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\WINDOWS\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\WINDOWS\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (...) -- %1" %*
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (...) -- C:\Program Files (x86)\Firefox\Firefox.exe

---\\ Menu de démarrage Internet (4) - 0s
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- c:\program files\internet explorer\iexplore.exe =>.Microsoft Corporation®
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

---\\ Recherche d'infection sur les navigateurs (6) - 8s
O69 - SBI: SearchScopes [HKCU] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKCU] [64Bits]{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} - (DaleSearch) - http://www.dalesearch.com/ =>PUP.Optional.Dalesearch
O69 - SBI: SearchScopes [HKCU] [64Bits]{80c554b9-c7f8-4a21-9471-06d606da78a2} - (Bing) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKCU] [64Bits]{96bd48dd-741b-41ae-ac4a-aff96ba00f7e} - (MyPlayCity) - http://my.myplaycity.com/
O69 - SBI: SearchScopes [HKCU] [64Bits]{9AD09901-06DD-4DDD-A62D-6D2243B771AB} - (MyPlayCity) - http://start.myplaycity.com/
O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com

---\\ Enumère les services démarrés par Svchost (42) - 3s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [192000] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [192000] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\WINDOWS\System32\srvsvc.dll [283136] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\WINDOWS\System32\gpsvc.dll [1339904] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\WINDOWS\System32\ikeext.dll [957952] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\WINDOWS\System32\iphlpsvc.dll [963072] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\WINDOWS\system32\seclogon.dll [31232] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\WINDOWS\System32\appinfo.dll [94720] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\WINDOWS\System32\iscsiexe.dll [151040] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\WINDOWS\System32\eapsvc.dll [112640] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\WINDOWS\System32\schedsvc.dll [1001472] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\System32\wbem\WMIsvc.dll [225280] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\WINDOWS\System32\browser.dll [134656] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\WINDOWS\System32\profsvc.dll [328192] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\WINDOWS\System32\sessenv.dll [372736] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\WINDOWS\System32\wercplsupport.dll [96256] =>.Microsoft Corporation
O83 - Search Svchost Services: DcpSvc (DcpSvc) . (.Microsoft Corporation - dcpsvc Task.) -- C:\WINDOWS\System32\dcpsvc.dll [186880] =>.Microsoft Corporation
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\WINDOWS\System32\wlidsvc.dll [2057216] =>.Microsoft Corporation
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\WINDOWS\System32\ncasvc.dll [168960] =>.Microsoft Corporation
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Service Configuration du réseau.) -- C:\WINDOWS\System32\NetSetupSvc.dll [211456] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\WINDOWS\System32\themeservice.dll [59392] =>.Microsoft Corporation
O83 - Search Svchost Services: RetailDemo (RetailDemo) . (.Microsoft Corporation - RDXService.) -- C:\WINDOWS\System32\RDXService.dll [1073152] =>.Microsoft Corporation
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service de géolocalisation.) -- C:\WINDOWS\System32\lfsvc.dll [27136] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\WINDOWS\System32\rasauto.dll [106496] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\WINDOWS\System32\rasmans.dll [696320] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\WINDOWS\System32\mprdim.dll [507904] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\WINDOWS\System32\sens.dll [73216] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\WINDOWS\System32\ipnathlp.dll [456704] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\WINDOWS\System32\tapisrv.dll [311808] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\WINDOWS\System32\wuaueng.dll [2280960] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\WINDOWS\System32\qmgr.dll [1144320] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\System32\shsvcs.dll [608768] =>.Microsoft Corporation
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\WINDOWS\System32\dmwappushsvc.dll [57856] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\WINDOWS\System32\bdesvc.dll [361472] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\WINDOWS\System32\XboxNetApiSvc.dll [1035776] =>.Microsoft Corporation
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Mettre à jour la session Orchestrator Core.) -- C:\WINDOWS\System32\usocore.dll [379392] =>.Microsoft Corporation
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\WINDOWS\System32\XblGameSave.dll [1139712] =>.Microsoft Corporation
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - DLL Windows Management Service.) -- C:\WINDOWS\System32\Windows.Internal.Management.dll [278016] =>.Microsoft Corporation
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\WINDOWS\System32\DeviceSetupManager.dll [205824] =>.Microsoft Corporation
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\WINDOWS\System32\usermgr.dll [912384] =>.Microsoft Corporation
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\WINDOWS\System32\XblAuthManager.dll [948736] =>.Microsoft Corporation
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\WINDOWS\System32\appmgmts.dll [200192] =>.Microsoft Corporation

---\\ Liste des exceptions du parefeu Windows (26) - 8s
O87 - FAEL: "{D8B96E57-A12F-4220-89EF-2076B7541572}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\WebConnect\bin\WebConnect.BRT.Helper.exe (.not file.) =>PUP.Optional.WebConnect
O87 - FAEL: "{8369CCA4-BDB3-4BF2-ACD8-9677D588FE81}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\WebConnect\bin\WebConnect.BRT.Helper.exe (.not file.) =>PUP.Optional.WebConnect
O87 - FAEL: "UDP Query User{D688B0A1-9AE5-4663-A610-A9A7F758E1BE}C:\program files (x86)\lenovo\energycut\utilty.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\lenovo\energycut\utilty.exe (.not file.)
O87 - FAEL: "TCP Query User{B1C25288-9BFB-4406-97FD-D0E9AE56FCCD}C:\program files (x86)\lenovo\energycut\utilty.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\lenovo\energycut\utilty.exe (.not file.)
O87 - FAEL: "UDP Query User{8B22CC89-C388-4C36-9780-0F2AE582D2AE}E:\arthur\arthur\protocole assembe\the protocole of arthur.exe" [In-None-P17-TRUE] .(...) -- E:\arthur\arthur\protocole assembe\the protocole of arthur.exe (.not file.)
O87 - FAEL: "TCP Query User{D9B74498-42A7-4D87-B5F6-926680CD7960}E:\arthur\arthur\protocole assembe\the protocole of arthur.exe" [In-None-P6-TRUE] .(...) -- E:\arthur\arthur\protocole assembe\the protocole of arthur.exe (.not file.)
O87 - FAEL: "UDP Query User{BE13001F-938C-4F27-88B1-6F887A27D2FC}C:\program files (x86)\microsoft care suite\lumia software recovery tool\lumiasoftwarerecoverytool.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\microsoft care suite\lumia software recovery tool\lumiasoftwarerecoverytool.exe (.not file.)
O87 - FAEL: "TCP Query User{AF457BA8-3858-4B62-95F8-AEA04CC6268D}C:\program files (x86)\microsoft care suite\lumia software recovery tool\lumiasoftwarerecoverytool.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\microsoft care suite\lumia software recovery tool\lumiasoftwarerecoverytool.exe (.not file.)
O87 - FAEL: "UDP Query User{1061B05F-7518-43F0-8A5D-5E3103F1CD75}C:\program files (x86)\common files\nokia\fuse\fuseservice.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\common files\nokia\fuse\fuseservice.exe (.not file.)
O87 - FAEL: "TCP Query User{24468782-EA11-42E8-98AD-FCA10432A6A7}C:\program files (x86)\common files\nokia\fuse\fuseservice.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\common files\nokia\fuse\fuseservice.exe (.not file.)
O87 - FAEL: "{F9430E80-35B8-4587-AFA2-534F94B55A13}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\GoforFiles\GoforFiles.exe (.not file.) =>PUP.Optional.YourFileDownloader
O87 - FAEL: "{55A94A4B-0A08-40BA-97BB-7B82E889BE99}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\GoforFiles\GoforFiles.exe (.not file.) =>PUP.Optional.YourFileDownloader
O87 - FAEL: "{76E42A9D-185F-4EDB-A3BF-D08B321AD3E9}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\GoforFiles\goforfilesdl.exe (.not file.) =>PUP.Optional.YourFileDownloader
O87 - FAEL: "{47BCD8EB-47D3-4ACA-9D0E-A61B6AC4C28B}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\GoforFiles\goforfilesdl.exe (.not file.) =>PUP.Optional.YourFileDownloader
O87 - FAEL: "{94DC5370-CE3C-4221-8B2F-50695879FD48}" [In-None-P6-TRUE] .(...) -- C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe (.not file.)
O87 - FAEL: "{9EA91452-3801-41BC-BBF5-CB3965800452}" [Out-None-P6-TRUE] .(...) -- C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe (.not file.)
O87 - FAEL: "{6E97A410-0734-4C51-98A8-D4C1EEF10F1E}" [In-None-P6-TRUE] .(...) -- C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe (.not file.)
O87 - FAEL: "{45AE9B05-297E-4946-A2C6-FEF6F9F503C3}" [Out-None-P6-TRUE] .(...) -- C:\ProgramData\BlueStacksGameManager\OBS\HD-OBS.exe (.not file.)
O87 - FAEL: "TCP Query User{258B11C1-111A-41E3-A0DB-24C3BE1C4DC3}C:\program files (x86)\connectify\connectify.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\connectify\connectify.exe (.not file.)
O87 - FAEL: "UDP Query User{3AB0F02C-79FE-4E57-8C1F-CBB0A2F80C4A}C:\program files (x86)\connectify\connectify.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\connectify\connectify.exe (.not file.)
O87 - FAEL: "{E6B1B4E1-EEA5-4F92-923F-AF6B0FDB40A3}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe (.not file.)
O87 - FAEL: "{2DA78729-8C14-45FC-AD14-0F08D17BA9A0}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Firefox\Firefox.exe (.not file.)
O87 - FAEL: "TCP Query User{27CA8F56-0F7E-4387-94B6-E83E747EDACD}C:\program files (x86)\amulell\amule.exe" [In-None-P6-TRUE] .(.http://www.amuleall.org/ - All-Platform P2P Client Based on eMule.) -- C:\program files (x86)\amulell\amule.exe =>Adware.aMULEcustom
O87 - FAEL: "UDP Query User{DC01522F-76B4-43F9-8B05-A6909C8DC8BF}C:\program files (x86)\amulell\amule.exe" [In-None-P17-TRUE] .(.http://www.amuleall.org/ - All-Platform P2P Client Based on eMule.) -- C:\program files (x86)\amulell\amule.exe =>Adware.aMULEcustom
O87 - FAEL: "{459D77E5-F156-4E93-B3B0-2CD7D434F67B}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\WiMAX Connection Manager\WiMAX Connection Manager.exe
O87 - FAEL: "{EDA1E489-3F7D-4C45-94BD-A407794C982C}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\WiMAX Connection Manager\WiMAX Connection Manager.exe

---\\ Recherche des packages WindowsInstaller (1) - 15s
[MD5.] [WIS][2017/04/18 05:15:45] (.Microleaves - Advanced Installer 13.8.1 build 77369.) -- C:\WINDOWS\Installer\b3f54c.msi [2752000] =>.SUP.Microleaves

---\\ Recherche de clés de registre Tracing (6) - 12s
HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32 =>.SUP.ByteFence
HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS =>.SUP.ByteFence
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Babylon_RASAPI32 =>Adware.Babylon
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Babylon_RASMANCS =>Adware.Babylon
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BikaQ_RASAPI32 =>.SUP.BikaQ
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BikaQ_RASMANCS =>.SUP.BikaQ

---\\ Scan Additionnel (108) - 1s
HKLM\SYSTEM\CurrentControlSet\Services\GoogleChromeUpService =>PUP.Optional.Zusy
C:\WINDOWS\System32\Tasks\RunAsStdUser Task =>PUP.Optional.iWinArcade
C:\WINDOWS\System32\Tasks\{638C70F6-3679-494A-B300-0F0776904C95} =>PUP.Optional.LiveSupport
C:\WINDOWS\System32\Tasks\GoforFilesUpdate =>PUP.Optional.YourFileDownloader
C:\WINDOWS\System32\Tasks\{372E848F-6076-4630-9028-2978DDF68104} =>PUP.Optional.LiveSupport
C:\WINDOWS\System32\Tasks\Online Application V2G3 =>.SUP.Microleaves
C:\WINDOWS\System32\Tasks\Online Application V2G1 =>.SUP.Microleaves
C:\WINDOWS\System32\Tasks\Online Application V2G2 =>.SUP.Microleaves
C:\WINDOWS\System32\Tasks\{A81BDA75-B943-4F5E-B4AA-8C5CC9E95755} =>PUP.Optional.LiveSupport
C:\WINDOWS\System32\Tasks\{12495545-6BB4-427D-82F6-C0CFFA7D8FB8} =>PUP.Optional.LiveSupport
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NoterSave_is1 =>.SUP.Tuto4PC
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1} =>.SUP.Microleaves
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{62D82EC1-0D3A-DF54-8E3E-07E1337A5311} =>PUP.Optional.SaveShare
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>Heuristic.Suspect
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD} =>PUP.Optional.SearchNewTab
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\NoterSave_is1 =>.SUP.Tuto4PC
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1} =>.SUP.Microleaves
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{62D82EC1-0D3A-DF54-8E3E-07E1337A5311} =>PUP.Optional.SaveShare
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>Heuristic.Suspect
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD} =>PUP.Optional.SearchNewTab
C:\Program Files\Babylon =>Adware.Babylon
C:\Program Files\ByteFence =>.SUP.ByteFence
C:\Program Files (x86)\amulell =>Adware.aMULEcustom
C:\Program Files (x86)\BikaQRss =>.SUP.BikaQ
C:\Program Files (x86)\BonanzaDeals =>PUP.Optional.BonanzaDeals
C:\Program Files (x86)\GamesBar =>PUP.Optional.GamesBar
C:\Program Files (x86)\SaveShare =>PUP.Optional.SaveShare
C:\Program Files (x86)\ScreenShared =>Adware.MSIL.ScreenShared
C:\ProgramData\98c66a2c-0201-0 =>.SUP.Polluteware
C:\ProgramData\98c66a2c-0da1-1 =>.SUP.Polluteware
C:\ProgramData\APN =>Toolbar.Ask
C:\ProgramData\DSearchLink =>.SUP.DeltaSearch
C:\ProgramData\InstallMate =>Adware.Tarma
C:\ProgramData\Microleaves =>.SUP.Microleaves
C:\ProgramData\savensharre =>PUP.Optional.SaveShare
C:\ProgramData\vCore =>PUP.Optional.AArtemis
C:\Users\LENOVO\AppData\Roaming\aMule =>Adware.aMULEcustom
C:\Users\LENOVO\AppData\Roaming\BitLord =>PUP.Optional.WhenUSave
C:\Users\LENOVO\AppData\Roaming\eCyber =>.SUP.Elex
C:\Users\LENOVO\AppData\Roaming\Elex-tech =>.SUP.Elex
C:\Users\LENOVO\AppData\Roaming\GoforFiles =>PUP.Optional.YourFileDownloader
C:\Users\LENOVO\AppData\Roaming\gplyra =>.SUP.Gplyra
C:\Users\LENOVO\AppData\Roaming\Kyubey =>Adware.CrossRider
C:\Users\LENOVO\AppData\Roaming\Microleaves =>.SUP.Microleaves
C:\Users\LENOVO\AppData\Roaming\UCChannel =>.SUP.UCBrowser
C:\Users\LENOVO\AppData\Roaming\WinSAPSvc =>PUP.Optional.Youndoo
C:\Users\LENOVO\AppData\Roaming\WinSnare =>.SUP.WinSnare
C:\Users\LENOVO\AppData\Local\AdvinstAnalytics =>.SUP.Various
C:\Users\LENOVO\AppData\Local\svchost =>Trojan.Agent
C:\Users\LENOVO\AppData\Local\UCBrowser =>.SUP.UCBrowser
C:\Users\LENOVO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC =>Adware.aMULEcustom
HKLM\Software\WOW6432Node\Microsoft\Shared Tools\MSConfig\startupreg\Babylon Client =>Adware.Babylon
C:\WINDOWS\System32\drivers\{f365189d-3e18-4f01-8423-a1ed102ed962}w64.sys =>PUP.Optional.LinkiDoo
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} =>PUP.Optional.Dalesearch
C:\program files (x86)\amulell\amule.exe =>Adware.aMULEcustom
C:\WINDOWS\Installer\b3f54c.msi =>.SUP.Microleaves
HKLM\Software\WOW6432Node\Microsoft\Tracing\ByteFence_RASAPI32 =>.SUP.ByteFence
HKLM\Software\WOW6432Node\Microsoft\Tracing\ByteFence_RASMANCS =>.SUP.ByteFence
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Babylon_RASAPI32 =>Adware.Babylon
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Babylon_RASMANCS =>Adware.Babylon
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BikaQ_RASAPI32 =>.SUP.BikaQ
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BikaQ_RASMANCS =>.SUP.BikaQ
HKLM\SYSTEM\CurrentControlSet\Control\Print\Providers\g12rnbfm =>.SUP.Elex
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\03D22C9C66915D58C88912B64C1F984B8344EF09 =>PUM.Misplaced.Certificate [Comodo Security]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\0F684EC1163281085C6AF20528878103ACEFCAAB =>PUM.Misplaced.Certificate [F-Secure]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\1667908C9E22EFBD0590E088715CC74BE4C60884 =>PUM.Misplaced.Certificate [FRISK]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\18DEA4EFA93B06AE997D234411F3FD72A677EECE =>PUM.Misplaced.Certificate [Bitdefender]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\2026D13756EB0DB753DF26CB3B7EEBE3E70BB2CF =>PUM.Misplaced.Certificate [G-Data]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\249BDA38A611CD746A132FA2AF995A2D3C941264 =>PUM.Misplaced.Certificate [Malwarebytes]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\31AC96A6C17C425222C46D55C3CCA6BA12E54DAF =>PUM.Misplaced.Certificate [Symantec]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\331E2046A1CCA7BFEF766724394BE6112B4CA3F7 =>PUM.Misplaced.Certificate [Trend Micro]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\3353EA609334A9F23A701B9159E30CB6C22D4C59 =>PUM.Misplaced.Certificate [Webroot]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\373C33726722D3A5D1EDD1F1585D5D25B39BEA1A =>PUM.Misplaced.Certificate [SUPERAntiSpyware]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\3850EDD77CC74EC9F4829AE406BBF9C21E0DA87F =>PUM.Misplaced.Certificate [Kaspersky]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\3D496FA682E65FC122351EC29B55AB94F3BB03FC =>PUM.Misplaced.Certificate [AVG Technologies]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\4243A03DB4C3C15149CEA8B38EEA1DA4F26BD159 =>PUM.Misplaced.Certificate [PC Tools]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\42727E052C0C2E1B35AB53E1005FD9EDC9DE8F01 =>PUM.Misplaced.Certificate [K7 Computing]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\4420C99742DF11DD0795BC15B7B0ABF090DC84DF =>PUM.Misplaced.Certificate [Doctor Web]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\4C0AF5719009B7C9D85C5EAEDFA3B7F090FE5FFF =>PUM.Misplaced.Certificate [Emsisoft]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\5240AB5B05D11B37900AC7712A3C6AE42F377C8C =>PUM.Misplaced.Certificate [CheckPoint]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\5DD3D41810F28B2A13E9A004E6412061E28FA48D =>PUM.Misplaced.Certificate [Emsisoft]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\7457A3793086DBB58B3858D6476889E3311E550E =>PUM.Misplaced.Certificate [K7 Computing]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\76A9295EF4343E12DFC5FE05DC57227C1AB00D29 =>PUM.Misplaced.Certificate [BullGuard]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\775B373B33B9D15B58BC02B184704332B97C3CAF =>PUM.Misplaced.Certificate [McAfee]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\872CD334B7E7B3C3D1C6114CD6B221026D505EAB =>PUM.Misplaced.Certificate [Comodo Security]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\88AD5DFE24126872B33175D1778687B642323ACF =>PUM.Misplaced.Certificate [McAfee]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9132E8B079D080E01D52631690BE18EBC2347C1E =>PUM.Misplaced.Certificate [Adaware Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\982D98951CF3C0CA2A02814D474A976CBFF6BDB1 =>PUM.Misplaced.Certificate [Safer Networking]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9A08641F7C5F2CCA0888388BE3E5DBDDAAA3B361 =>PUM.Misplaced.Certificate [Webroot]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9C43F665E690AB4D486D4717B456C5554D4BCEB5 =>PUM.Misplaced.Certificate [ThreatTrack]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9E3F95577B37C74CA2F70C1E1859E798B7FC6B13 =>PUM.Misplaced.Certificate [CurioLab]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\A1F8DCB086E461E2ABB4B46ADCFA0B48C58B6E99 =>PUM.Misplaced.Certificate [Avira Operations]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\A5341949ABE1407DD7BF7DFE75460D9608FBC309 =>PUM.Misplaced.Certificate [BullGuard]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\A59CC32724DD07A6FC33F7806945481A2D13CA2F =>PUM.Misplaced.Certificate [ESET]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\AB7E760DA2485EA9EF5A6EEE7647748D4BA6B947 =>PUM.Misplaced.Certificate [AVG Technologies]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\AD4C5429E10F4FF6C01840C20ABA344D7401209F =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\AD96BB64BA36379D2E354660780C2067B81DA2E0 =>PUM.Misplaced.Certificate [Symantec]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\B8EBF0E696AF77F51C96DB4D044586E2F4F8FD84 =>PUM.Misplaced.Certificate [Malwarebytes]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\CDC37C22FE9272D8F2610206AD397A45040326B8 =>PUM.Misplaced.Certificate [Trend Micro]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\D3F78D747E7C5D6D3AE8ABFDDA7522BFB4CBD598 =>PUM.Misplaced.Certificate [Kaspersky]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\DB303C9B61282DE525DC754A535CA2D6A9BD3D87 =>PUM.Misplaced.Certificate [ThreatTrack]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\DB77E5CFEC34459146748B667C97B185619251BA =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\E22240E837B52E691C71DF248F12D27F96441C00 =>PUM.Misplaced.Certificate [Total Defense]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\E513EAB8610CFFD7C87E00BCA15C23AAB407FCEF =>PUM.Misplaced.Certificate [AVG Technologies]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\ED841A61C0F76025598421BC1B00E24189E68D54 =>PUM.Misplaced.Certificate [Bitdefender]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\F83099622B4A9F72CB5081F742164AD1B8D048C9 =>PUM.Misplaced.Certificate [ESET]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\FBB42F089AF2D570F2BF6F493D107A3255A9BB1A =>PUM.Misplaced.Certificate [Panda Security]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\FFFA650F2CB2ABC0D80527B524DD3F9FC172C138 =>PUM.Misplaced.Certificate [Doctor Web]

---\\ Récapitulatif des éléments trouvés sur votre station (52) - 0s
https://www.anti-malware.top/2016/05/17/adware-zusy/ =>PUP.Optional.Zusy
https://www.nicolascoolman.com/fr/adware-iwinarcade/ =>PUP.Optional.iWinArcade
https://nicolascoolman.eu/2017/09/12/origine-lignes-orphelines/ =>.SUP.Orphan
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.LiveSupport
https://nicolascoolman.eu/2017/09/13/pup-optional-yourfiledownloader/ =>PUP.Optional.YourFileDownloader
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Microleaves
https://nicolascoolman.eu/2017/09/08/adware-imbooster/ =>PUP.Optional.IMBooster
https://nicolascoolman.eu/2017/03/06/hijacker-startpageing123/ =>Hijacker.StartpageIng123
https://nicolascoolman.eu/2017/09/07/pup-optional-salus/ =>.SUP.Linkury
https://www.nicolascoolman.com/fr/pup-optional-tuto4pc/ =>.SUP.Tuto4PC
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.SaveShare
https://nicolascoolman.eu/2017/01/28/heuristic-suspect/ =>Heuristic.Suspect
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.SearchNewTab
https://nicolascoolman.eu/2017/03/11/pup-optional-crossrider/ =>Adware.CrossRider
https://nicolascoolman.eu/2017/02/06/superfluous-conduit/ =>.SUP.Conduit
https://www.nicolascoolman.com/fr/pup-datamngr/ =>PUP.Optional.Datamngr
https://nicolascoolman.eu/2017/09/29/sup-deltasearch/ =>.SUP.DeltaSearch
https://nicolascoolman.eu/2017/03/28/superfluous-elex/ =>.SUP.Elex
https://www.nicolascoolman.com/fr/pup-advancedsystemprotector/ =>PUP.Optional.AdvancedSystemProtector
https://www.nicolascoolman.com/fr/pup-mocaflix/ =>PUP.Optional.MocaFlix
https://www.nicolascoolman.com/fr/pup-webconnect/ =>PUP.Optional.WebConnect
https://nicolascoolman.eu/2017/01/01/adware-toptools/ =>Adware.TopTools
https://www.nicolascoolman.com/fr/hijacker-babsolution/ =>PUP.Optional.BabSolution
https://nicolascoolman.eu/2017/09/19/adware-installcore-3/ =>Adware.InstallCore
https://nicolascoolman.eu/2017/06/21/adware-fastdatax/ =>Adware.FastDataX
https://nicolascoolman.eu/2017/01/27/superfluous-reimagerepair/ =>.SUP.ReimageRepair
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Softonic
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Downloader
https://www.anti-malware.top/2016/05/24/adware-amonetize/ =>Adware.Amonetize
https://nicolascoolman.eu/2017/01/12/superfluous-winsnare/ =>.SUP.WinSnare
https://nicolascoolman.eu/2017/09/21/adware-quickshare/ =>Adware.QuickShare
https://nicolascoolman.eu/2017/03/03/adware-babylon/ =>Adware.Babylon
https://nicolascoolman.eu/2017/03/13/superfluous-bytefence/ =>.SUP.ByteFence
https://nicolascoolman.eu/2017/03/10/adware-amulecustom/ =>Adware.aMULEcustom
https://nicolascoolman.eu/2017/02/17/superfluous-bikaq/ =>.SUP.BikaQ
https://www.anti-malware.top/2016/04/28/pup-optional-bonanzadeals/ =>PUP.Optional.BonanzaDeals
https://www.nicolascoolman.com/fr/adware-gamesbar/ =>PUP.Optional.GamesBar
https://nicolascoolman.eu/2017/01/06/adware-msil-screenshared/ =>Adware.MSIL.ScreenShared
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Polluteware
https://nicolascoolman.eu/2017/02/28/toolbar-ask/ =>Toolbar.Ask
https://nicolascoolman.eu/2017/09/09/adware-tarma/ =>Adware.Tarma
https://www.nicolascoolman.com/fr/pup-aartemis/ =>PUP.Optional.AArtemis
https://www.nicolascoolman.com/fr/adware-whenusave/ =>PUP.Optional.WhenUSave
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Gplyra
https://nicolascoolman.eu/2017/03/04/superfluous-ucbrowser/ =>.SUP.UCBrowser
https://nicolascoolman.eu/2017/03/11/superfluous-youndoo/ =>PUP.Optional.Youndoo
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Various
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Trojan.Agent
https://nicolascoolman.eu/2017/02/23/tencentadressbar/ =>.SUP.Tencent
https://www.nicolascoolman.com/fr/pup-linkidoo/ =>PUP.Optional.LinkiDoo
https://www.nicolascoolman.com/fr/hijacker-dalesearch/ =>PUP.Optional.Dalesearch
https://nicolascoolman.eu/2017/06/26/trojan-certlock/ =>PUM.Misplaced.Certificate

~ Unselected Options: O82,
~ End of the scan, 35703 items in 08mn43s (1438)(0)

Publicité


Signaler le contenu de ce document

Publicité