cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.8.20.122 Par Nicolas Coolman (2015/08/20)
~ Démarré par HiChEm (Administrator) (2015/08/20 14:24:11)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Users\HiChEm\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\HiChEm\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Démarrage du système: Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 10240)

---\\ Navigateurs Internet (3) - 0s
GCIE: Google Chrome v44.0.2403.155
MFIE: Mozilla Firefox 40.0 (x86 fr) v40.0
MSIE: Internet Explorer v11.0.10240.16384

---\\ Informations sur les produits Windows (9) - 1s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
~ Windows(R) Operating System, RETAIL channel
Windows ID Activation : OK
~ Windows Partial Key : 3V66T
Windows License : OK
~ Windows Remaining Initializations Number : 1001
Windows Automatic Updates : OK (Auto)
Windows Activation Technologies : OK

---\\ Logiciels de protection (2) - 4s
Malwarebytes Anti-Malware version 2.1.8.1057
Windows Defender W10 (Deactivate)

---\\ Surveillance de Logiciels (1) - 5s
Adobe Flash Player 18 NPAPI

---\\ Informations sur le système (6) - 0s
~ Operating System: Intel64 Family 6 Model 15 Stepping 13, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 4193.524 MB (45% free)
~ System Restore: Activé (Enable)
~ System drive C: has 41 GB free of 102 GB

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: HICHEM-PC
~ User Name: HiChEm
~ Logged in as Administrator

---\\ Enumération des unités disques (6) - 6s
~ Drive C: has 41 GB free of 102 GB (System)
~ Drive D: has 59 GB free of 102 GB
~ Drive E: has 14 GB free of 36 GB
~ Drive F: has 23 GB free of 30 GB
~ Drive H: has GB free of 0 GB
~ Drive L: has 46 GB free of 205 GB

---\\ Etat du Centre de Sécurité Windows (7) - 0s
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Recherche particulière de fichiers génériques (23) - 0s
[MD5.C6F56519F6F8A5C1B4144CF863CDE0CA] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\WINDOWS\Explorer.exe [4532304]
[MD5.5DED2A3F11AE916C8F2724947E736261] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) () -- C:\WINDOWS\System32\rundll32.exe [59392]
[MD5.CAAA293DD133160DF13D95CC48FC42B9] - (.Microsoft Corporation - Application de démarrage de Windows.) () -- C:\WINDOWS\System32\Wininit.exe [290304]
[MD5.32A862495B7C356B9895FDD0B9023C5F] - (.Microsoft Corporation - Extensions Internet pour Win32.) () -- C:\WINDOWS\System32\wininet.dll [2741248]
[MD5.536B686D86402D254C59B5DE3A575F45] - (.Microsoft Corporation - Application d’ouverture de session Windows.) () -- C:\WINDOWS\System32\Winlogon.exe [578048]
[MD5.8DE3F0DF5BCD3AC6360AB753BD1A63DE] - (.Microsoft Corporation - Bibliothèque de licences.) () -- C:\WINDOWS\System32\sppcomapi.dll [429056]
[MD5.8C795953726C7D2DE72CE4748208C5ED] - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) () -- C:\WINDOWS\System32\fr-FR\user32.dll.mui [20480]
[MD5.6C12C7E01A4F64E0AA9C88AF66955CC9] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) () -- C:\WINDOWS\System32\drivers\AFD.sys [577888]
[MD5.8921DF6060DB5C7700AA48CB12E9EA08] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\WINDOWS\System32\drivers\atapi.sys [28512]
[MD5.F2829DC6D292DCAC5029893BB2E9FEE3] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\WINDOWS\System32\drivers\Cdfs.sys [92672]
[MD5.CA160E02F35A61C6F5C681FB4669C519] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\WINDOWS\System32\drivers\Cdrom.sys [174080]
[MD5.25435407D97419627F4B10653433BF2B] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\WINDOWS\System32\drivers\DfsC.sys [138240]
[MD5.C277A49F8A8295840DEBC9240B75A282] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\WINDOWS\System32\drivers\HDAudBus.sys [80896]
[MD5.D4CDEE4A62BDFFF6E8558A9552148EA7] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\WINDOWS\System32\drivers\i8042prt.sys [114688]
[MD5.5D3744E6FDEC1A6FB3FA9B1DD4AF0694] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\WINDOWS\System32\drivers\IpNat.sys [143360]
[MD5.1DF2C5FD2710A13B07E663A12F0E0EEA] - (.Microsoft Corporation - Minirdr SMB Windows NT.) () -- C:\WINDOWS\System32\drivers\MRxSmb.sys [415232]
[MD5.F0D791348AD254360CC3C3E501CCB745] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\WINDOWS\System32\drivers\netBT.sys [273408]
[MD5.5B3D91EB07785D0EDB19449D5C35E30A] - (.Microsoft Corporation - Pilote du système de fichiers NT.) () -- C:\WINDOWS\System32\drivers\ntfs.sys [2117472]
[MD5.38F1AE32339731F6E5A7281AE8042545] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\WINDOWS\System32\drivers\Parport.sys [96768]
[MD5.CA60F6C03611AF1710BC903ED9F566FB] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [104960]
[MD5.A32AED8C644734B283A7C9D08D76064D] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) () -- C:\WINDOWS\System32\drivers\rdpdr.sys [176128]
[MD5.28E1E63A1AC65E17B3194238FA2CF3BF] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\WINDOWS\System32\drivers\tdx.sys [116576]
[MD5.823A237D871CD652C6BFD47BECB6810A] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\WINDOWS\System32\drivers\volsnap.sys [378720]

---\\ Processus lancés (39) - 4s
[MD5.39CC4A11197CEB38C18F18FCC1820D6C] - (.AMD - AMD External Events Service Module.) -- C:\WINDOWS\system32\atiesrxx.exe [246784] [PID.1156]
[MD5.FE392E13FB5C8BE2CE9128449885BCB5] - (.Performix LLC - Adguard for Windows.) -- C:\Program Files (x86)\Adguard\AdguardSvc.exe [119832] [PID.1828]
[MD5.7E970E7DD4522D826CBC34E268DA9ACE] - (.Copyright 2010 - ALPBCSVC Module.) -- C:\Program Files (x86)\D-Link\DWA-135\ALPBCSVC.exe [66880] [PID.1936]
[MD5.0F32048BF3EA2A85FE3AC48E8E7B7C85] - (.ESET - ESET Service.) -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1353720] [PID.2240]
[MD5.B4789ACB80692481BD4950EB7D46EB20] - (.Copyright (C) 2013 - DCSHOST.) -- C:\ProgramData\DatacardService\HWDeviceService64.exe [351824] [PID.2260]
[MD5.8118AA1C914D1A1171792B72C2A9C881] - (...) -- C:\Program Files (x86)\Wi-Fi\WiFiGxSvc.exe [47464] [PID.3008]
[MD5.53B8D9B905223CBB6317B0FFF61D155A] - (...) -- C:\ProgramData\Djezzy connect\OnlineUpdate\ouc.exe [651856] [PID.3196]
[MD5.230546AE4A19F356C9990382665ADA9A] - (.Nitro PDF Software - Nitro PDF Spool Service.) -- C:\Program Files\Nitro\Pro 10\NitroPDFDriverService10x64.exe [324760] [PID.3256]
[MD5.A39D51B1A6A2DB8DB764601AED6165FB] - (.Nitro PDF Software - Nitro PDF Spool Service.) -- C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920] [PID.3284]
[MD5.E08749C62EBCB67F727FD460A4863388] - (...) -- C:\Program Files\Nitro\Pro 10\Nitro_UpdateService.exe [418968] [PID.3340]
[MD5.E1F36B548A83515C7221EDDEACE27B72] - (.AVG Technologies - AVG PC TuneUp Service.) -- C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2970424] [PID.3804]
[MD5.29DF2514FCED0B7F8E449933EF6E6918] - (...) -- C:\ProgramData\MobiConnect\OnlineUpdate\ouc.exe [656976] [PID.4080]
[MD5.84522A4C370E1256F9724F8F18BFA313] - (.AMD - AMD External Events Client Module.) -- C:\WINDOWS\system32\atieclxx.exe [672768] [PID.4640]
[MD5.BFB31D4DEAE97F2F53A07628AF80EB75] - (.AVG Technologies - AVG PC TuneUp.) -- C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe [2451768] [PID.3452]
[MD5.C8A0145CA371A09BB46136FD722C8549] - (.Huawei Technologies Co., Ltd. - DataCardMonitor MFC Application.) -- C:\ProgramData\DatacardService\DCSHelper.exe [238160] [PID.6156]
[MD5.A118C52E94780AEBFA52D05A3313CCF6] - (.ESET - ESET Main GUI.) -- C:\Program Files\ESET\ESET Smart Security\egui.exe [5595848] [PID.2392]
[MD5.1854D4E2CDD9E71E03196B09582E2B42] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3907152] [PID.5412]
[MD5.6CBC0F3C8AEEC72CD930123F9AFAA85B] - (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe [110160] [PID.6464]
[MD5.1036A5756F04CBA6C7F01DEEEECF8AC6] - (.Performix LLC - Adguard for Windows.) -- C:\Program Files (x86)\Adguard\Adguard.exe [2015768] [PID.3540]
[MD5.44A9229022A519ED45294A1934C05EEC] - (.Flux Software LLC - f.lux.) -- C:\Users\HiChEm\AppData\Local\FluxSoftware\Flux\flux.exe [1017224] [PID.2424]
[MD5.131245F46871105EE8D86679F6FBC21A] - (...) -- C:\Program Files (x86)\DFX\DFX.exe [1272280] [PID.3636]
[MD5.F67991C4EE448C5FF03F148E0A79EF9D] - (.www.IslamicFinder.org - Automatic Athan (Azan) five times a day f.) -- C:\Program Files (x86)\Athan\Athan.exe [1216512] [PID.772]
[MD5.48173D6614239BE20D0068DC0A8BBE35] - (.Copyright © 2013 FXsound.com, a subsidiary of Power T - DFX.) -- C:\Program Files (x86)\DFX\Universal\Apps\DfxSharedApp32.exe [130520] [PID.4676]
[MD5.5D8C990AAB591D609B64DFFB78134D55] - (.Copyright © 2013 FXsound.com, a subsidiary of Power T - DFX.) -- C:\Program Files (x86)\DFX\Universal\Apps\DfxSharedApp64.exe [131544] [PID.1740]
[MD5.4E2136ACC844511E10793D628AACDB5E] - (.MPC-HC Team - MPC-HC x64.) -- C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe [8152064] [PID.7132]
[MD5.F820401D0D2754C3A78C707927058A41] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896] [PID.6224]
[MD5.F820401D0D2754C3A78C707927058A41] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896] [PID.6868]
[MD5.F820401D0D2754C3A78C707927058A41] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896] [PID.188]
[MD5.F820401D0D2754C3A78C707927058A41] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896] [PID.4884]
[MD5.F820401D0D2754C3A78C707927058A41] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896] [PID.1500]
[MD5.F820401D0D2754C3A78C707927058A41] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896] [PID.3892]
[MD5.F820401D0D2754C3A78C707927058A41] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896] [PID.6304]
[MD5.20013128B442F623EAA9FCA7ECCFCE79] - (.Siber Systems Inc. - rf-chrome-nm-host.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome-nm-host.exe [3237952] [PID.1540]
[MD5.F820401D0D2754C3A78C707927058A41] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896] [PID.3440]
[MD5.F820401D0D2754C3A78C707927058A41] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896] [PID.7064]
[MD5.BD92274B08345E915458EE8B28714CD9] - (...) -- C:\Program Files (x86)\MobiConnect\MobiConnect.exe [100352] [PID.4172]
[MD5.BDD14EAA0656530648269B04B9F55F6B] - (.www.sordum.org - DNS Jumper v2.0.) -- C:\Users\HiChEm\Desktop\DnsJumper\DnsJumper.exe [652269] [PID.1440]
[MD5.F820401D0D2754C3A78C707927058A41] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896] [PID.548]
[MD5.63E20985B61368A6172D93D0245DC9F8] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\HiChEm\AppData\Roaming\ZHP\ZHPDiag3.exe [1895424] [PID.2588]

---\\ Google Chrome, Démarrage,Recherche,Extensions (11) - 0s
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.google.dz/
G2 - GCE: Preference [User Data\Default] [alelhddbbhepgpmgidjdcjakblofbmce] __MSG_extName__
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [gighmmpiobklfepjocnamgkkbiglidom] AdBlock
G2 - GCE: Preference [User Data\Default] [lccekmodgklaepjeofjdjpbminllajkg] Chrome Hotword Shared Module
G2 - GCE: Preference [User Data\Default] [mfidmkgnfgnkihnjeklbekckimkipmoe] Flashcontrol
G2 - GCE: Preference [User Data\Default] [ngpampappnmepgilojfohadhhmbhlaek] IDM Integration Module
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pnlccmojcmeohlpggmfnbbiapkmbliob] RoboForm Password Manager

---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (4) - 1s
P2 - EXT: (.Mozilla - Default.) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll
P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google.) -- C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
P2 - FPN: [HKLM] [@nitropdf.com/NitroPDF.PrevVerNPR] - (.Nitro.) -- C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll

---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (17) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1
R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1

---\\ Internet Explorer,Proxy Management (4) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe (.Microsoft Corporation.)
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.)
F2 - REG:system.ini: VMApplet=

---\\ Etude du fichier hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (34)

---\\ Browser Helper Object de navigateur (BHO) (1) - 1s
O2 - BHO: IDM Helper [64Bits] - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll

---\\ Applications lancées au démarrage du système (16) - 1s
O4 - HKLM\..\Run: [egui] . (.ESET - ESET Main GUI.) -- C:\Program Files\ESET\ESET Smart Security\egui.exe
O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe
O4 - HKCU\..\Run: [RoboForm] . (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
O4 - HKCU\..\Run: [Adguard] . (.Performix LLC - Adguard for Windows.) -- C:\Program Files (x86)\Adguard\Adguard.exe
O4 - HKCU\..\Run: [f.lux] . (.Flux Software LLC - f.lux.) -- C:\Users\HiChEm\AppData\Local\FluxSoftware\Flux\flux.exe
O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\HiChEm\AppData\Local\Microsoft\OneDrive\OneDrive.exe
O4 - HKLM\..\Wow6432Node\Run: [DFX] . (...) -- C:\Program Files (x86)\DFX\DFX.exe
O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe
O4 - HKLM\..\Wow6432Node\Run: [Athan] . (.www.IslamicFinder.org - Automatic Athan (Azan) five times a day f.) -- C:\Program Files (x86)\Athan\Athan.exe
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe
O4 - HKUS\S-1-5-21-3706028547-1026032644-3289653491-1000\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe
O4 - HKUS\S-1-5-21-3706028547-1026032644-3289653491-1000\..\Run: [RoboForm] . (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
O4 - HKUS\S-1-5-21-3706028547-1026032644-3289653491-1000\..\Run: [Adguard] . (.Performix LLC - Adguard for Windows.) -- C:\Program Files (x86)\Adguard\Adguard.exe
O4 - HKUS\S-1-5-21-3706028547-1026032644-3289653491-1000\..\Run: [f.lux] . (.Flux Software LLC - f.lux.) -- C:\Users\HiChEm\AppData\Local\FluxSoftware\Flux\flux.exe
O4 - HKUS\S-1-5-21-3706028547-1026032644-3289653491-1000\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\HiChEm\AppData\Local\Microsoft\OneDrive\OneDrive.exe

---\\ Modification Domaine/Adresses DNS (16) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 213.177.160.2 196.29.40.3
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 209.244.0.3 84.200.69.80
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 77.88.8.8,77.88.8.0,
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 77.88.8.8,77.88.8.0,10.216.215.197
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 192.168.4.4 8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.244.0.3 84.200.69.80
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 213.177.160.2 196.29.40.3
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 209.244.0.3 84.200.69.80
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 77.88.8.8,77.88.8.0,
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 77.88.8.8,77.88.8.0,10.216.215.197
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 192.168.4.4 8.8.4.4
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 209.244.0.3 84.200.69.80
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 77.88.8.8,77.88.8.0,
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 77.88.8.8,77.88.8.0,10.216.215.197

---\\ Liste des services NT non Microsoft et non désactivés (16) - 2s
O23 - Service: Adguard Service (Adguard Service) . (.Performix LLC - Adguard for Windows.) - C:\Program Files (x86)\Adguard\AdguardSvc.exe
O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\WINDOWS\system32\atiesrxx.exe
O23 - Service: Djezzy connect. OUC (Djezzy connect. RunOuc) . (...) - C:\Program Files (x86)\Djezzy connect\UpdateDog\ouc.exe
O23 - Service: DWA-135_PBC_WPS Service (DWA-135_PBC_WPS) . (.Copyright 2010 - ALPBCSVC Module.) - C:\Program Files (x86)\D-Link\DWA-135\ALPBCSVC.exe
O23 - Service: ESET Service (ekrn) . (.ESET - ESET Service.) - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HWDeviceService64.exe (HWDeviceService64.exe) . (.Copyright (C) 2013 - DCSHOST.) - C:\ProgramData\DatacardService\HWDeviceService64.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) . (.IObit - Product Updater.) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: MBAMScheduler (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: MobiConnect. OUC (MobiConnect. RunOuc) . (...) - C:\Program Files (x86)\MobiConnect\UpdateDog\ouc.exe
O23 - Service: MyWiFiRouterDHCP (MyWiFiRouterDHCP) . (...) - C:\Program Files (x86)\Wi-Fi\WiFiGxSvc.exe
O23 - Service: NitroPDFDriverCreatorReadSpool10 (NitroDriverReadSpool10) . (.Nitro PDF Software - Nitro PDF Spool Service.) - C:\Program Files\Nitro\Pro 10\NitroPDFDriverService10x64.exe
O23 - Service: NitroPDFDriverCreatorReadSpool9 (NitroDriverReadSpool9) . (.Nitro PDF Software - Nitro PDF Spool Service.) - C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe
O23 - Service: NitroUpdateService (NitroUpdateService) . (...) - C:\Program Files\Nitro\Pro 10\Nitro_UpdateService.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) . (.AVG Technologies - AVG PC TuneUp Service.) - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe

---\\ Tâches planifiées en automatique (41) - 5s
[MD5.368290D0A612D62DA6F3D798B1BB8FE7] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [269000]
[MD5.00000000000000000000000000000000] [APT] [AutoKMS] (...) -- C:\Windows\AutoKMS\AutoKMS.exe (.not file.) [0] =>HackTool.AutoKMS
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineCore1d0bf48cc0f3f9] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineUA1d08fffb289dc2b] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineUA1d0bf48d623f66] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
[MD5.4E574FEBE7CD85BB0A086ABEF602F910] [APT] [Java Platform SE Auto Updater] (.Oracle Corporation.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896]
[MD5.8A3A1B1D58C43A45517321BC8C650752] [APT] [klcp_update] (...) -- C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1175040]
[MD5.6CBC0F3C8AEEC72CD930123F9AFAA85B] [APT] [Run RoboForm TaskBar Icon] (.Siber Systems.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [110160]
[MD5.9BBE6821D91AD7D26138A6567C919F66] [APT] [TuneUpUtilities_Task_BkGndMaintenance2013] (.AVG Technologies.) -- C:\Program Files (x86)\AVG\AVG PC TuneUp\OneClick.exe [555832]
[MD5.EAF81DF89378481017C388F790D4FB84] [APT] [Uninstaller_SkipUac_HiChEm] (.IObit.) -- C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [15889184]
[MD5.00000000000000000000000000000000] [APT] [{B141577B-C8E9-495F-AEF5-7C31EE7DCFCE}] (...) -- D:\????? ? ???? ???????\Ph 8 me By ??????? ????\Ph 8 me By ??????? ????\setup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{D7A9E75A-9DD8-4C01-A4D5-D7C33C0B9C57}] (...) -- D:\????? ? ???? ???????\Ph 8 me By ??????? ????\Ph 8 me By ??????? ????\setup.exe (.not file.) [0]
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job [1002] =>.Adobe Systems Incorporated
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job [1066] =>.Google Inc.
O39 - APT: GoogleUpdateTaskMachineCore1d0bf48cc0f3f9 - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0bf48cc0f3f9.job [1066] =>.Google Inc.
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job [1070] =>.Google Inc.
O39 - APT: GoogleUpdateTaskMachineUA1d08fffb289dc2b - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d08fffb289dc2b.job [1070] =>.Google Inc.
O39 - APT: GoogleUpdateTaskMachineUA1d0bf48d623f66 - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0bf48d623f66.job [1070] =>.Google Inc.
O39 - APT: Uninstaller_SkipUac_HiChEm - (.IObit.) -- C:\WINDOWS\Tasks\Uninstaller_SkipUac_HiChEm.job [300] =>.IObit
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater [3976] =>.Adobe Systems Incorporated
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore [3924] =>.Google Inc.
O39 - APT: GoogleUpdateTaskMachineCore1d0bf48cc0f3f9 - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d0bf48cc0f3f9 [3924] =>.Google Inc.
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA [3504] =>.Google Inc.
O39 - APT: GoogleUpdateTaskMachineUA1d08fffb289dc2b - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d08fffb289dc2b [4176] =>.Google Inc.
O39 - APT: GoogleUpdateTaskMachineUA1d0bf48d623f66 - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d0bf48d623f66 [4176] =>.Google Inc.
O39 - APT: Java Platform SE Auto Updater - (.Oracle Corporation.) -- C:\WINDOWS\System32\Tasks\Java Platform SE Auto Updater [3814] =>.Oracle Corporation
O39 - APT: klcp_update - (...) -- C:\WINDOWS\System32\Tasks\klcp_update [3016]
O39 - APT: Orphean - (...) -- C:\WINDOWS\System32\Tasks\Open URL by RoboForm [4210]
O39 - APT: Run RoboForm TaskBar Icon - (.Siber Systems.) -- C:\WINDOWS\System32\Tasks\Run RoboForm TaskBar Icon [3606] =>.Siber Systems
O39 - APT: TuneUpUtilities_Task_BkGndMaintenance2013 - (.AVG Technologies.) -- C:\WINDOWS\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 [2922] =>.AVG Technologies
O39 - APT: Uninstaller_SkipUac_HiChEm - (.IObit.) -- C:\WINDOWS\System32\Tasks\Uninstaller_SkipUac_HiChEm [2490] =>.IObit
O39 - APT: Orphean - (...) -- C:\WINDOWS\System32\Tasks\{63573E32-9D07-4269-AC59-5CEC9D99DF29} [3372]
O39 - APT: Orphean - (...) -- C:\WINDOWS\System32\Tasks\{9A88905A-892B-498C-BEC8-D3CEE3363BB4} [3530]
O39 - APT: Orphean - (...) -- C:\WINDOWS\System32\Tasks\{AC3EE2A0-B317-4A71-94BC-868629490CCF} [3798]
O39 - APT: {B141577B-C8E9-495F-AEF5-7C31EE7DCFCE} - (...) -- C:\WINDOWS\System32\Tasks\{B141577B-C8E9-495F-AEF5-7C31EE7DCFCE} [3184]
O39 - APT: Orphean - (...) -- C:\WINDOWS\System32\Tasks\{C3FFCF32-6BA8-4C05-B2E2-1C25CD71EC94} [3470]
O39 - APT: {D7A9E75A-9DD8-4C01-A4D5-D7C33C0B9C57} - (...) -- C:\WINDOWS\System32\Tasks\{D7A9E75A-9DD8-4C01-A4D5-D7C33C0B9C57} [3184]
O39 - APT: Orphean - (...) -- C:\WINDOWS\System32\Tasks\{DFD5C267-1A13-4587-A01D-E1F6DAB1261B} [3246]
O39 - APT: Orphean - (...) -- C:\WINDOWS\System32\Tasks\{F4141022-8234-4CF3-9221-A668700928DA} [3328]

---\\ Logiciels installés (69) - 12s
O42 - Logiciel: GlassFish Server Open Source Edition 4.1 - (...) [HKLM][64Bits] -- nbi-glassfish-mod-4.1.0.13.0
O42 - Logiciel: NetBeans IDE 8.0.2 - (.NetBeans.org.) [HKLM][64Bits] -- nbi-nb-base-8.0.2.0.201411181905
O42 - Logiciel: Apache Tomcat 8.0.15 - (...) [HKLM][64Bits] -- nbi-tomcat-8.0.15.0.0
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player
O42 - Logiciel: Nitro Pro 10 - (.Nitro.) [HKLM][64Bits] -- {01396EAF-25FE-446F-A021-672FD38FE598}
O42 - Logiciel: Java 7 Update 45 (64-bit) - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F86417045FF}
O42 - Logiciel: Java 8 Update 51 (64-bit) - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F86418051F0}
O42 - Logiciel: Java SE Development Kit 7 Update 45 (64-bit) - (.Oracle.) [HKLM][64Bits] -- {64A3A4F4-B792-11D6-A78A-00B0D0170450}
O42 - Logiciel: ESET Smart Security - (.ESET, spol s r. o..) [HKLM][64Bits] -- {7C4B5814-9E71-4481-9769-00B8C11D0656}
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: AMD Catalyst Install Manager - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {92265DEC-AA16-8226-AE4B-96165DB368B6}
O42 - Logiciel: Microsoft DVD App Installation for Microsoft.WindowsDVDPlayer_2019.6.11761. - (.Microsoft Corporation.) [HKLM][64Bits] -- {986E003C-E56D-5A47-110E-D3C81F0E8535}
O42 - Logiciel: AMD Drag and Drop Transcoding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {A2AC0D43-9788-B1BD-B2A8-EFC758916BB1}
O42 - Logiciel: AMD Wireless Display v3.0 - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {C16CD4C0-48EE-0F40-C9FD-0778EAF73FBD}
O42 - Logiciel: SAMSUNG USB Driver for Mobile Phones - (.SAMSUNG Electronics Co., Ltd..) [HKLM][64Bits] -- {D0795B21-0CDA-4a92-AB9E-6E92D8111E44}
O42 - Logiciel: AMD Accelerated Video Transcoding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {F7CD07B2-565B-D770-0388-9C16A8FA5B1D}
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe AIR
O42 - Logiciel: Adobe Flash Player 18 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI
O42 - Logiciel: RoboForm 7-9-13-5 (All Users) - (.Siber Systems.) [HKLM][64Bits] -- AI RoboForm
O42 - Logiciel: Athan Basic 4.5 - (...) [HKLM][64Bits] -- Athan
O42 - Logiciel: AVG PC TuneUp 2015 - (.AVG Technologies.) [HKLM][64Bits] -- AVG PC TuneUp
O42 - Logiciel: Adobe Help Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
O42 - Logiciel: DFX - (.Power Technology.) [HKLM][64Bits] -- DFX
O42 - Logiciel: Djezzy connect - (.Huawei Technologies Co.,Ltd.) [HKLM][64Bits] -- Djezzy connect
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome
O42 - Logiciel: Handset WinDriver 1.02.03.00 - (.Huawei technologies Co., Ltd..) [HKLM][64Bits] -- Handset WinDriver
O42 - Logiciel: HSPA USB Modem - (.Nom de votre société.) [HKLM][64Bits] -- InstallShield_{06ADE2A0-E46A-4A84-A211-64CF50520185}
O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM][64Bits] -- Internet Download Manager
O42 - Logiciel: IObit Uninstaller - (.IObit.) [HKLM][64Bits] -- IObitUninstall
O42 - Logiciel: K-Lite Mega Codec Pack 11.3.0 - (...) [HKLM][64Bits] -- KLiteCodecPack_is1
O42 - Logiciel: Malwarebytes Anti-Malware version 2.1.8.1057 - (.Malwarebytes Corporation.) [HKLM][64Bits] -- Malwarebytes Anti-Malware_is1
O42 - Logiciel: MobiConnect - (.Huawei Technologies Co.,Ltd.) [HKLM][64Bits] -- MobiConnect
O42 - Logiciel: Mozilla Firefox 40.0 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 40.0 (x86 fr)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService
O42 - Logiciel: My WIFI Router - (.TxNetwork, Inc..) [HKLM][64Bits] -- My WIFI Router
O42 - Logiciel: OpenVPN 2.3.7-I603 - (...) [HKLM][64Bits] -- OpenVPN
O42 - Logiciel: Ayat - (.UNKNOWN.) [HKLM][64Bits] -- sa.edu.ksa.ayat
O42 - Logiciel: KMPlayer (remove only) - (.PandoraTV.) [HKLM][64Bits] -- The KMPlayer
O42 - Logiciel: WinRAR 5.20 (32-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver
O42 - Logiciel: Your Freedom 20140321-01 - (...) [HKLM][64Bits] -- Your_Deploy_0
O42 - Logiciel: HSPA USB Modem - (.Nom de votre société.) [HKLM][64Bits] -- {06ADE2A0-E46A-4A84-A211-64CF50520185}
O42 - Logiciel: Catalyst Control Center - Branding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {11087D24-567D-7D88-69C6-D7A08B5F4C47}
O42 - Logiciel: Nero Kwik Themes Basic - (.Nero AG.) [HKLM][64Bits] -- {1B6F5E51-575E-4693-BCA2-7543570D076D}
O42 - Logiciel: Wondershare Dr.Fone for Android(Build 5.3.3.23) - (.Wondershare Software Co.,Ltd..) [HKLM][64Bits] -- {1DB91A95-C548-4BA5-9D4C-18C7DEAAC39F}_is1
O42 - Logiciel: Wondershare MobileGo for Android ( Version 4.2.1 ) - (.Wondershare.) [HKLM][64Bits] -- {1E04C795-7359-4E05-8A0E-5644F777AA08}_is1
O42 - Logiciel: Nero Blu-ray Player - (.Nero AG.) [HKLM][64Bits] -- {22124B84-93B2-4603-B212-146665E4B6B1}
O42 - Logiciel: Nero Burning Core - (.Nero AG.) [HKLM][64Bits] -- {228B6C3A-A712-4972-AEB0-E37E83E881E9}
O42 - Logiciel: Nero SharedVideoCodecs - (.Nero AG.) [HKLM][64Bits] -- {2432E589-6256-4513-B0BF-EFA8E325D5F0}
O42 - Logiciel: Nero Effects Basic - (.Nero AG.) [HKLM][64Bits] -- {29F67D84-3A70-456E-806A-52301B02070B}
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {34927EBC-98D4-4D53-98BE-510DF5999F50}
O42 - Logiciel: Adguard - (.Insoft LLC.) [HKLM][64Bits] -- {38cdc926-a78c-4226-aefd-ea7c46ed4a80}
O42 - Logiciel: Ayat - (.UNKNOWN.) [HKLM][64Bits] -- {41E2E6F7-F831-A443-D7D8-3B164D6B936F}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
O42 - Logiciel: Adguard - (.Performix LLC.) [HKLM][64Bits] -- {685F6AB3-7C61-42D1-AE5B-3864E48D1035}
O42 - Logiciel: D-Link DWA-135 - (.D-Link Corporation.) [HKLM][64Bits] -- {6CCDE98A-915E-4818-B4C5-6891D34DCFCA}
O42 - Logiciel: Nero Express - (.Nero AG.) [HKLM][64Bits] -- {6EEF61AB-CC0B-4917-A3F2-97902CD11073}
O42 - Logiciel: Google Earth - (.Google.) [HKLM][64Bits] -- {6F545E5E-4595-11E2-93B6-B8AC6F97B88E}
O42 - Logiciel: Nero Launcher - (.Nero AG.) [HKLM][64Bits] -- {9D780839-6E97-4E2A-A5F7-711AF221B609}
O42 - Logiciel: Nero Audio Pack 1 - (.Nero AG.) [HKLM][64Bits] -- {A7A0BF2E-31CC-49E3-9913-52C503EB969D}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Nero Device Updates - (.Nero AG.) [HKLM][64Bits] -- {ABA7F64A-8CEB-4B59-84D9-B4D98CCD32D4}
O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM][64Bits] -- {ABC88553-8770-4B97-B43E-5A90647A5B63}
O42 - Logiciel: Nero PiP Effects Basic - (.Nero AG.) [HKLM][64Bits] -- {ACE49D50-19CD-44A6-B192-46F985283B26}
O42 - Logiciel: Adobe Help Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AF37176A-78CA-545B-34EF-8B6A21514DD1}
O42 - Logiciel: Nero Burning ROM - (.Nero AG.) [HKLM][64Bits] -- {B3756FCF-13D3-460B-88D5-33CB88CE6CFA}
O42 - Logiciel: Nero Core Components - (.Nero AG.) [HKLM][64Bits] -- {BEBEE34D-84A2-4EDD-8BEA-96CC54371263}
O42 - Logiciel: Nero Disc Menus Basic - (.Nero AG.) [HKLM][64Bits] -- {E17BCB76-9924-4BD5-B6D6-50D3407B4E74}
O42 - Logiciel: Windows ARP Spoofer - (...) [HKLM][64Bits] -- {FB90085B-59E4-40FA-81CA-CBE0E70A7183}
O42 - Logiciel: f.lux - (...) [HKCU][64Bits] -- Flux

---\\ HKCU & HKLM Software Keys (115) - 12s
HKLM\SOFTWARE\Wow6432Node\Adguard
HKLM\SOFTWARE\Wow6432Node\Adobe
HKLM\SOFTWARE\Wow6432Node\AMD
HKLM\SOFTWARE\Wow6432Node\ANI
HKLM\SOFTWARE\Wow6432Node\ATI
HKLM\SOFTWARE\Wow6432Node\ATI Technologies
HKLM\SOFTWARE\Wow6432Node\AVG
HKLM\SOFTWARE\Wow6432Node\Cucusoft
HKLM\SOFTWARE\Wow6432Node\CyberLink
HKLM\SOFTWARE\Wow6432Node\D-Link Corporation
HKLM\SOFTWARE\Wow6432Node\DFX
HKLM\SOFTWARE\Wow6432Node\DiskInternals
HKLM\SOFTWARE\Wow6432Node\ESET
HKLM\SOFTWARE\Wow6432Node\GNU
HKLM\SOFTWARE\Wow6432Node\Google
HKLM\SOFTWARE\Wow6432Node\HaaliMkx
HKLM\SOFTWARE\Wow6432Node\HSPA
HKLM\SOFTWARE\Wow6432Node\Huawei technologies
HKLM\SOFTWARE\Wow6432Node\Icaros
HKLM\SOFTWARE\Wow6432Node\Intel
HKLM\SOFTWARE\Wow6432Node\Internet Download Manager
HKLM\SOFTWARE\Wow6432Node\InterVideo
HKLM\SOFTWARE\Wow6432Node\IObit
HKLM\SOFTWARE\Wow6432Node\JavaSoft
HKLM\SOFTWARE\Wow6432Node\JreMetrics
HKLM\SOFTWARE\Wow6432Node\Khronos
HKLM\SOFTWARE\Wow6432Node\KLCodecPack
HKLM\SOFTWARE\Wow6432Node\KMPlayer
HKLM\SOFTWARE\Wow6432Node\LAV
HKLM\SOFTWARE\Wow6432Node\Macromedia
HKLM\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware
HKLM\SOFTWARE\Wow6432Node\Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\Nalpeiron
HKLM\SOFTWARE\Wow6432Node\Nero
HKLM\SOFTWARE\Wow6432Node\NextSecurity.NET
HKLM\SOFTWARE\Wow6432Node\Nitro
HKLM\SOFTWARE\Wow6432Node\ODBC
HKLM\SOFTWARE\Wow6432Node\OpenVPN
HKLM\SOFTWARE\Wow6432Node\OpenVPN-GUI
HKLM\SOFTWARE\Wow6432Node\PowerTechnology
HKLM\SOFTWARE\Wow6432Node\Siber Systems
HKLM\SOFTWARE\Wow6432Node\Skype
HKLM\SOFTWARE\Wow6432Node\SOSVirus
HKLM\SOFTWARE\Wow6432Node\TuneUp
HKLM\SOFTWARE\Wow6432Node\VMware, Inc.
HKLM\SOFTWARE\Wow6432Node\WafCX
HKLM\SOFTWARE\Wow6432Node\WIBU-SYSTEMS
HKLM\SOFTWARE\Wow6432Node\WinRAR
HKLM\SOFTWARE\Wow6432Node\Wondershare
HKLM\SOFTWARE\Wow6432Node\XinYi Network
HKLM\SOFTWARE\Wow6432Node\Your Freedom
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications
HKCU\SOFTWARE\Adguard
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\AMD
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\ATI
HKCU\SOFTWARE\AVG
HKCU\SOFTWARE\Bmupd
HKCU\SOFTWARE\BugSplat
HKCU\SOFTWARE\Chromium
HKCU\SOFTWARE\CyberLink
HKCU\SOFTWARE\DFX
HKCU\SOFTWARE\DiskInternals
HKCU\SOFTWARE\DownloadManager
HKCU\SOFTWARE\drpsu
HKCU\SOFTWARE\Dz4-EvEr
HKCU\SOFTWARE\ej-technologies
HKCU\SOFTWARE\ESET
HKCU\SOFTWARE\GetData
HKCU\SOFTWARE\GNU
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\GRETECH
HKCU\SOFTWARE\Haali
HKCU\SOFTWARE\Icaros
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\JavaSoft
HKCU\SOFTWARE\KasperskyLab
HKCU\SOFTWARE\KasperskyLabSetup
HKCU\SOFTWARE\Kiloo Games
HKCU\SOFTWARE\KMPlayer
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\madshi
HKCU\SOFTWARE\MediaInfo
HKCU\SOFTWARE\Michael Herf
HKCU\SOFTWARE\Mine
HKCU\SOFTWARE\Mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\MPC-HC
HKCU\SOFTWARE\Nero
HKCU\SOFTWARE\Netscape
HKCU\SOFTWARE\NextSecurity
HKCU\SOFTWARE\Nilings
HKCU\SOFTWARE\NITRO
HKCU\SOFTWARE\ODBC
HKCU\SOFTWARE\OneClickRoot
HKCU\SOFTWARE\PCTuneUp
HKCU\SOFTWARE\RegisteredApplications
HKCU\SOFTWARE\Siber Systems
HKCU\SOFTWARE\Skype
HKCU\SOFTWARE\SMADΔV
HKCU\SOFTWARE\Sysinternals
HKCU\SOFTWARE\Trolltech
HKCU\SOFTWARE\TuneUp
HKCU\SOFTWARE\WinRAR
HKCU\SOFTWARE\WinRAR SFX
HKCU\SOFTWARE\Wondershare
HKCU\SOFTWARE\Wow6432Node
HKCU\SOFTWARE\XinYi Network
HKCU\SOFTWARE\Your Freedom
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\AppDataLow\Software
HKCU\SOFTWARE\AppDataLow\Software\JavaSoft

---\\ Contenu des dossiers Programmes (261) - 11s
O43 - CFD: 2015/08/18 10:49:57 - [] D -- C:\Program Files (x86)\Adguard
O43 - CFD: 2015/06/12 12:02:20 - [] D -- C:\Program Files (x86)\Adobe
O43 - CFD: 2015/08/06 09:13:57 - [] D -- C:\Program Files (x86)\AMD
O43 - CFD: 2015/08/05 19:31:59 - [] D -- C:\Program Files (x86)\AMD AVT
O43 - CFD: 2015/08/19 20:03:25 - [] D -- C:\Program Files (x86)\Athan
O43 - CFD: 2015/05/22 14:45:53 - [] D -- C:\Program Files (x86)\AVG
O43 - CFD: 2015/07/04 14:00:10 - [] D -- C:\Program Files (x86)\Ayat
O43 - CFD: 2015/08/06 11:56:06 - [] D -- C:\Program Files (x86)\Common Files
O43 - CFD: 2015/08/06 12:08:50 - [0] D -- C:\Program Files (x86)\CyberLink
O43 - CFD: 2015/07/28 19:14:44 - [] D -- C:\Program Files (x86)\D-Link
O43 - CFD: 2015/04/24 12:27:16 - [] D -- C:\Program Files (x86)\DFX
O43 - CFD: 2015/05/01 21:24:20 - [] D -- C:\Program Files (x86)\DiskInternals
O43 - CFD: 2015/04/24 14:11:23 - [] D -- C:\Program Files (x86)\Djezzy connect
O43 - CFD: 2015/07/22 19:45:23 - [] HD -- C:\Program Files (x86)\DrFoneAndroid_Temp
O43 - CFD: 2015/07/27 19:16:23 - [] D -- C:\Program Files (x86)\Google
O43 - CFD: 2015/07/22 21:33:11 - [] D -- C:\Program Files (x86)\Handset WinDriver
O43 - CFD: 2015/08/07 16:29:21 - [0] D -- C:\Program Files (x86)\Hostless Modem
O43 - CFD: 2015/08/02 17:56:03 - [] D -- C:\Program Files (x86)\HSPA USB Modem
O43 - CFD: 2015/07/04 14:00:15 - [] HD -- C:\Program Files (x86)\InstallJammer Registry
O43 - CFD: 2015/08/06 11:50:49 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 2015/08/06 09:46:46 - [] D -- C:\Program Files (x86)\Internet Download Manager
O43 - CFD: 2015/07/10 17:23:55 - [] D -- C:\Program Files (x86)\Internet Explorer
O43 - CFD: 2015/04/24 12:35:08 - [] D -- C:\Program Files (x86)\IObit
O43 - CFD: 2015/08/05 20:51:56 - [] D -- C:\Program Files (x86)\K-Lite Codec Pack
O43 - CFD: 2015/07/05 12:23:31 - [] D -- C:\Program Files (x86)\Malwarebytes Anti-Malware
O43 - CFD: 2015/04/27 19:31:44 - [] D -- C:\Program Files (x86)\Messenger for Desktop
O43 - CFD: 2015/07/03 13:45:50 - [] D -- C:\Program Files (x86)\Metal Slug Complete PC
O43 - CFD: 2015/04/24 14:14:09 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services
O43 - CFD: 2015/04/24 14:17:56 - [] D -- C:\Program Files (x86)\Microsoft Office
O43 - CFD: 2015/05/22 16:24:06 - [] D -- C:\Program Files (x86)\Microsoft Silverlight
O43 - CFD: 2015/04/24 14:17:55 - [] D -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
O43 - CFD: 2015/04/24 14:18:10 - [] D -- C:\Program Files (x86)\Microsoft Synchronization Services
O43 - CFD: 2015/08/05 19:32:02 - [] D -- C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 2015/08/07 16:33:59 - [] D -- C:\Program Files (x86)\MobiConnect
O43 - CFD: 2015/06/12 13:10:35 - [] D -- C:\Program Files (x86)\Movie Maker 2.6
O43 - CFD: 2015/08/13 19:02:19 - [] D -- C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 2015/08/18 10:47:29 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service
O43 - CFD: 2015/08/05 19:12:36 - [] D -- C:\Program Files (x86)\MSBuild
O43 - CFD: 2015/06/27 11:06:15 - [] D -- C:\Program Files (x86)\Nero
O43 - CFD: 2015/05/04 19:08:43 - [] D -- C:\Program Files (x86)\NextSecurity.NET
O43 - CFD: 2015/08/18 10:47:28 - [] D -- C:\Program Files (x86)\Nitro
O43 - CFD: 2015/07/31 11:55:21 - [] D -- C:\Program Files (x86)\OpenVPN
O43 - CFD: 2015/07/31 11:41:59 - [] D -- C:\Program Files (x86)\OpenVPN Technologies
O43 - CFD: 2015/08/05 19:12:36 - [] D -- C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 2015/04/24 14:19:26 - [] D -- C:\Program Files (x86)\Siber Systems
O43 - CFD: 2009/07/14 05:57:06 - [0] HD -- C:\Program Files (x86)\Uninstall Information
O43 - CFD: 2015/07/31 23:01:41 - [] D -- C:\Program Files (x86)\Wi-Fi
O43 - CFD: 2015/07/10 17:23:55 - [] D -- C:\Program Files (x86)\Windows Defender
O43 - CFD: 2015/08/05 19:32:03 - [] D -- C:\Program Files (x86)\Windows Mail
O43 - CFD: 2015/07/10 17:23:55 - [] D -- C:\Program Files (x86)\Windows Media Player
O43 - CFD: 2015/07/10 12:04:26 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform
O43 - CFD: 2015/07/10 12:04:22 - [] D -- C:\Program Files (x86)\Windows NT
O43 - CFD: 2015/07/10 17:23:55 - [] D -- C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 2015/07/10 12:04:26 - [] D -- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 2015/08/05 19:32:03 - [] SHD -- C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 2015/07/10 12:04:22 - [] SD -- C:\Program Files (x86)\WindowsPowerShell
O43 - CFD: 2015/04/24 12:22:02 - [] D -- C:\Program Files (x86)\WinRAR
O43 - CFD: 2015/07/22 19:54:38 - [] D -- C:\Program Files (x86)\Wondershare
O43 - CFD: 2015/07/28 18:17:38 - [] D -- C:\Program Files (x86)\Your Freedom
O43 - CFD: 2015/07/10 12:04:26 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 2015/08/05 19:38:21 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adguard
O43 - CFD: 2015/07/10 17:29:09 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2015/08/06 09:15:07 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
O43 - CFD: 2015/08/19 19:10:15 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Athan
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015
O43 - CFD: 2015/08/05 19:32:08 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DFX Audio Enhancer
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Djezzy connect
O43 - CFD: 2015/08/06 19:57:52 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
O43 - CFD: 2009/07/14 16:35:46 - [0] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HSPA USB Modem
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
O43 - CFD: 2015/08/06 18:24:04 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
O43 - CFD: 2015/08/05 20:52:14 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
O43 - CFD: 2015/07/10 12:04:26 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
O43 - CFD: 2015/08/07 16:33:48 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MobiConnect
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetBeans
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoboForm
O43 - CFD: 2015/07/10 12:04:26 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
O43 - CFD: 2015/07/10 12:04:26 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 2015/07/10 17:29:06 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinArp Spoofer
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 2015/08/05 19:32:13 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
O43 - CFD: 2015/08/05 19:38:21 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Your Freedom
O43 - CFD: 2015/08/20 14:24:35 - [] D -- C:\ProgramData\Adguard
O43 - CFD: 2015/07/02 22:07:17 - [] D -- C:\ProgramData\Adobe
O43 - CFD: 2015/04/24 12:33:36 - [] D -- C:\ProgramData\AMD
O43 - CFD: 2015/07/10 13:21:38 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 2015/08/06 09:30:22 - [] D -- C:\ProgramData\ATI
O43 - CFD: 2015/05/22 14:47:12 - [] D -- C:\ProgramData\AVG
O43 - CFD: 2015/07/28 18:55:28 - [] D -- C:\ProgramData\BlueStacksSetup
O43 - CFD: 2015/04/24 12:18:53 - [0] SHD -- C:\ProgramData\Bureau
O43 - CFD: 2015/07/05 14:09:06 - [] D -- C:\ProgramData\Codemasters
O43 - CFD: 2015/08/06 09:28:22 - [] HD -- C:\ProgramData\Common Files
O43 - CFD: 2015/07/10 12:04:22 - [0] D -- C:\ProgramData\Comms
O43 - CFD: 2015/08/13 18:55:45 - [] D -- C:\ProgramData\Cucusoft
O43 - CFD: 2015/07/30 20:56:18 - [] D -- C:\ProgramData\CyberLink
O43 - CFD: 2015/08/07 16:34:20 - [] D -- C:\ProgramData\DatacardService
O43 - CFD: 2015/07/10 13:21:38 - [0] SHD -- C:\ProgramData\Desktop
O43 - CFD: 2015/04/24 12:27:32 - [] D -- C:\ProgramData\DFX
O43 - CFD: 2015/04/24 14:11:19 - [] D -- C:\ProgramData\Djezzy connect
O43 - CFD: 2015/07/10 13:21:38 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 2015/08/06 09:58:50 - [] D -- C:\ProgramData\ESET
O43 - CFD: 2015/04/24 12:18:53 - [0] SHD -- C:\ProgramData\Favoris
O43 - CFD: 2015/04/24 12:30:21 - [0] D -- C:\ProgramData\IDM
O43 - CFD: 2015/04/24 12:36:16 - [] D -- C:\ProgramData\IObit
O43 - CFD: 2015/08/06 18:33:14 - [] D -- C:\ProgramData\Kaspersky Lab Setup Files
O43 - CFD: 2015/06/20 16:32:12 - [] D -- C:\ProgramData\KONAMI
O43 - CFD: 2015/05/15 10:24:02 - [] D -- C:\ProgramData\Malwarebytes
O43 - CFD: 2015/04/24 12:18:53 - [0] SHD -- C:\ProgramData\Menu Démarrer
O43 - CFD: 2015/08/19 15:54:57 - [] SD -- C:\ProgramData\Microsoft
O43 - CFD: 2015/08/11 20:13:36 - [] D -- C:\ProgramData\Microsoft Help
O43 - CFD: 2015/08/05 20:04:17 - [] D -- C:\ProgramData\Microsoft OneDrive
O43 - CFD: 2015/04/24 14:54:30 - [] D -- C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS
O43 - CFD: 2015/08/08 16:39:05 - [] D -- C:\ProgramData\MobiConnect
O43 - CFD: 2015/04/24 12:18:53 - [0] SHD -- C:\ProgramData\Modèles
O43 - CFD: 2015/04/24 12:31:34 - [] D -- C:\ProgramData\Mozilla
O43 - CFD: 2015/06/06 14:36:59 - [] D -- C:\ProgramData\Nero
O43 - CFD: 2015/05/15 10:09:58 - [] D -- C:\ProgramData\Nitro
O43 - CFD: 2015/07/24 16:33:39 - [] D -- C:\ProgramData\Oracle
O43 - CFD: 2015/08/06 11:46:58 - [] D -- C:\ProgramData\Package Cache
O43 - CFD: 2015/08/08 16:36:19 - [] D -- C:\ProgramData\ProductData
O43 - CFD: 2015/06/12 12:04:43 - [] D -- C:\ProgramData\regid.1986-12.com.adobe
O43 - CFD: 2015/07/10 17:29:06 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft
O43 - CFD: 2015/04/24 14:19:51 - [] D -- C:\ProgramData\RoboForm
O43 - CFD: 2015/06/24 19:46:38 - [] D -- C:\ProgramData\Samsung
O43 - CFD: 2015/08/06 11:56:07 - [] D -- C:\ProgramData\Skype
O43 - CFD: 2015/07/10 12:04:22 - [0] D -- C:\ProgramData\SoftwareDistribution
O43 - CFD: 2015/07/10 13:21:38 - [0] SHD -- C:\ProgramData\Start Menu
O43 - CFD: 2015/07/05 14:09:04 - [] D -- C:\ProgramData\Steam
O43 - CFD: 2015/07/06 11:08:04 - [] D -- C:\ProgramData\Sun
O43 - CFD: 2015/08/14 09:40:48 - [0] D -- C:\ProgramData\Temp
O43 - CFD: 2015/07/10 13:21:38 - [0] SHD -- C:\ProgramData\Templates
O43 - CFD: 2015/04/24 14:57:49 - [] D -- C:\ProgramData\TuneUp Software
O43 - CFD: 2015/07/10 13:22:45 - [] D -- C:\ProgramData\USOPrivate
O43 - CFD: 2015/07/10 13:22:45 - [] D -- C:\ProgramData\USOShared
O43 - CFD: 2015/08/06 11:55:08 - [] D -- C:\ProgramData\VMware
O43 - CFD: 2015/07/22 21:12:11 - [] D -- C:\ProgramData\Wondershare
O43 - CFD: 2015/08/07 16:29:28 - [0] D -- C:\ProgramData\ZDSupport
O43 - CFD: 2015/06/28 00:38:54 - [] D -- C:\Program Files (x86)\Common Files\Adobe
O43 - CFD: 2015/07/04 13:59:38 - [] D -- C:\Program Files (x86)\Common Files\Adobe AIR
O43 - CFD: 2015/04/24 12:33:20 - [] D -- C:\Program Files (x86)\Common Files\ATI Technologies
O43 - CFD: 2015/05/16 21:14:58 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER
O43 - CFD: 2015/04/24 12:24:47 - [] D -- C:\Program Files (x86)\Common Files\DFX
O43 - CFD: 2015/05/04 19:08:31 - [] D -- C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 2015/07/16 19:11:11 - [] D -- C:\Program Files (x86)\Common Files\Java
O43 - CFD: 2015/08/05 19:32:01 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared
O43 - CFD: 2015/06/27 10:56:38 - [] D -- C:\Program Files (x86)\Common Files\Nero
O43 - CFD: 2015/06/23 22:53:42 - [] D -- C:\Program Files (x86)\Common Files\Nitro
O43 - CFD: 2015/07/10 12:04:26 - [] D -- C:\Program Files (x86)\Common Files\Services
O43 - CFD: 2015/08/05 19:32:01 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines
O43 - CFD: 2015/08/05 19:32:01 - [] D -- C:\Program Files (x86)\Common Files\System
O43 - CFD: 2015/06/26 10:39:03 - [] D -- C:\Program Files (x86)\Common Files\Wondershare
O43 - CFD: 2015/06/28 00:32:03 - [] D -- C:\Users\HiChEm\AppData\Roaming\Adobe
O43 - CFD: 2015/05/08 13:18:57 - [] D -- C:\Users\HiChEm\AppData\Roaming\AMD
O43 - CFD: 2015/04/24 13:43:34 - [] D -- C:\Users\HiChEm\AppData\Roaming\ATI
O43 - CFD: 2015/05/22 14:46:20 - [] D -- C:\Users\HiChEm\AppData\Roaming\AVG
O43 - CFD: 2015/05/16 21:07:04 - [] D -- C:\Users\HiChEm\AppData\Roaming\BitTorrent Maelstrom
O43 - CFD: 2015/07/30 20:56:17 - [] D -- C:\Users\HiChEm\AppData\Roaming\CyberLink
O43 - CFD: 2015/08/19 21:40:28 - [] D -- C:\Users\HiChEm\AppData\Roaming\DMCache
O43 - CFD: 2015/06/23 22:51:22 - [] D -- C:\Users\HiChEm\AppData\Roaming\Downloaded Installations
O43 - CFD: 2015/04/24 13:40:36 - [] D -- C:\Users\HiChEm\AppData\Roaming\ESET
O43 - CFD: 2015/05/01 21:41:01 - [] D -- C:\Users\HiChEm\AppData\Roaming\FastCopy
O43 - CFD: 2015/07/22 19:28:43 - [0] D -- C:\Users\HiChEm\AppData\Roaming\HMYGSetting
O43 - CFD: 2015/04/24 12:19:29 - [] D -- C:\Users\HiChEm\AppData\Roaming\Identities
O43 - CFD: 2015/07/16 17:55:00 - [] D -- C:\Users\HiChEm\AppData\Roaming\IDM
O43 - CFD: 2015/07/28 19:14:39 - [] D -- C:\Users\HiChEm\AppData\Roaming\InstallShield
O43 - CFD: 2015/04/24 12:35:16 - [] D -- C:\Users\HiChEm\AppData\Roaming\IObit
O43 - CFD: 2015/06/12 11:42:00 - [] D -- C:\Users\HiChEm\AppData\Roaming\Macromedia
O43 - CFD: 2009/07/14 16:35:18 - [0] D -- C:\Users\HiChEm\AppData\Roaming\Media Center Programs
O43 - CFD: 2015/07/22 21:40:34 - [] D -- C:\Users\HiChEm\AppData\Roaming\mgyun
O43 - CFD: 2015/08/05 22:07:02 - [] SD -- C:\Users\HiChEm\AppData\Roaming\Microsoft
O43 - CFD: 2015/07/22 22:01:46 - [] D -- C:\Users\HiChEm\AppData\Roaming\Mobogenie =>PUP.Optional.Mobogenie
O43 - CFD: 2015/04/24 12:32:37 - [] D -- C:\Users\HiChEm\AppData\Roaming\Mozilla
O43 - CFD: 2015/08/05 21:42:47 - [] D -- C:\Users\HiChEm\AppData\Roaming\MPC-HC
O43 - CFD: 2015/06/06 14:11:03 - [] D -- C:\Users\HiChEm\AppData\Roaming\Nero
O43 - CFD: 2015/07/24 16:35:45 - [] D -- C:\Users\HiChEm\AppData\Roaming\NetBeans
O43 - CFD: 2015/08/13 19:32:38 - [] D -- C:\Users\HiChEm\AppData\Roaming\NetGuard
O43 - CFD: 2015/07/06 12:04:37 - [] D -- C:\Users\HiChEm\AppData\Roaming\Nitro
O43 - CFD: 2015/07/14 23:07:10 - [] D -- C:\Users\HiChEm\AppData\Roaming\Nitro PDF
O43 - CFD: 2015/06/12 12:07:55 - [] D -- C:\Users\HiChEm\AppData\Roaming\PDAppFlex
O43 - CFD: 2015/04/24 14:34:25 - [] D -- C:\Users\HiChEm\AppData\Roaming\Performix LLC
O43 - CFD: 2015/07/31 11:42:54 - [] D -- C:\Users\HiChEm\AppData\Roaming\PrivateTunnel
O43 - CFD: 2015/04/24 13:44:21 - [] D -- C:\Users\HiChEm\AppData\Roaming\ProductData
O43 - CFD: 2015/07/09 13:39:30 - [] D -- C:\Users\HiChEm\AppData\Roaming\sa.edu.ksa.ayat
O43 - CFD: 2015/06/29 19:00:49 - [] D -- C:\Users\HiChEm\AppData\Roaming\Skype
O43 - CFD: 2015/06/15 19:26:44 - [0] D -- C:\Users\HiChEm\AppData\Roaming\Smadav
O43 - CFD: 2015/04/24 14:57:12 - [] D -- C:\Users\HiChEm\AppData\Roaming\TuneUp Software
O43 - CFD: 2015/08/06 11:46:56 - [] D -- C:\Users\HiChEm\AppData\Roaming\TunnelBear
O43 - CFD: 2015/07/31 23:01:11 - [] D -- C:\Users\HiChEm\AppData\Roaming\TXWiFiDriver
O43 - CFD: 2015/08/06 18:28:12 - [] D -- C:\Users\HiChEm\AppData\Roaming\vlc
O43 - CFD: 2015/08/06 11:50:57 - [0] D -- C:\Users\HiChEm\AppData\Roaming\VMware
O43 - CFD: 2015/04/24 12:24:17 - [] D -- C:\Users\HiChEm\AppData\Roaming\WinRAR
O43 - CFD: 2015/07/22 19:27:48 - [] D -- C:\Users\HiChEm\AppData\Roaming\Wondershare
O43 - CFD: 2015/08/20 14:24:28 - [] D -- C:\Users\HiChEm\AppData\Roaming\ZHP
O43 - CFD: 2015/06/27 11:00:29 - [] D -- C:\Users\HiChEm\AppData\Local\Adobe
O43 - CFD: 2015/08/05 19:29:38 - [0] SHD -- C:\Users\HiChEm\AppData\Local\Application Data
O43 - CFD: 2015/04/24 13:43:34 - [] D -- C:\Users\HiChEm\AppData\Local\ATI
O43 - CFD: 2015/05/22 14:44:33 - [] D -- C:\Users\HiChEm\AppData\Local\Avg
O43 - CFD: 2015/08/06 09:56:12 - [] D -- C:\Users\HiChEm\AppData\Local\Comms
O43 - CFD: 2015/07/30 20:56:07 - [] D -- C:\Users\HiChEm\AppData\Local\CyberLink
O43 - CFD: 2015/04/24 12:26:54 - [] D -- C:\Users\HiChEm\AppData\Local\DFX
O43 - CFD: 2015/08/04 18:39:14 - [0] D -- C:\Users\HiChEm\AppData\Local\Diagnostics
O43 - CFD: 2015/08/19 00:45:22 - [] D -- C:\Users\HiChEm\AppData\Local\ElevatedDiagnostics
O43 - CFD: 2015/06/26 09:38:49 - [0] SHD -- C:\Users\HiChEm\AppData\Local\EmieBrowserModeList
O43 - CFD: 2015/06/26 09:38:49 - [0] SHD -- C:\Users\HiChEm\AppData\Local\EmieSiteList
O43 - CFD: 2015/06/26 09:38:49 - [0] SHD -- C:\Users\HiChEm\AppData\Local\EmieUserList
O43 - CFD: 2015/04/24 13:40:36 - [] D -- C:\Users\HiChEm\AppData\Local\ESET
O43 - CFD: 2015/07/15 23:28:20 - [] D -- C:\Users\HiChEm\AppData\Local\FluxSoftware
O43 - CFD: 2015/07/27 19:16:26 - [] D -- C:\Users\HiChEm\AppData\Local\Google
O43 - CFD: 2015/06/05 16:40:28 - [] D -- C:\Users\HiChEm\AppData\Local\GWX
O43 - CFD: 2015/08/05 19:29:38 - [0] SHD -- C:\Users\HiChEm\AppData\Local\Historique
O43 - CFD: 2015/07/31 11:43:57 - [0] D -- C:\Users\HiChEm\AppData\Local\HockeyCrashes
O43 - CFD: 2015/07/31 11:43:58 - [] D -- C:\Users\HiChEm\AppData\Local\IsolatedStorage
O43 - CFD: 2015/07/22 21:29:35 - [] D -- C:\Users\HiChEm\AppData\Local\Kingosoft
O43 - CFD: 2015/06/15 19:33:55 - [] D -- C:\Users\HiChEm\AppData\Local\Macromedia
O43 - CFD: 2015/06/28 12:17:12 - [] D -- C:\Users\HiChEm\AppData\Local\Messenger
O43 - CFD: 2015/08/13 19:12:57 - [] D -- C:\Users\HiChEm\AppData\Local\Microsoft
O43 - CFD: 2015/04/24 14:13:28 - [0] D -- C:\Users\HiChEm\AppData\Local\Microsoft Help
O43 - CFD: 2015/08/05 20:18:20 - [] D -- C:\Users\HiChEm\AppData\Local\MicrosoftEdge
O43 - CFD: 2015/07/22 22:08:11 - [] D -- C:\Users\HiChEm\AppData\Local\Mobogenie =>PUP.Optional.Mobogenie
O43 - CFD: 2015/04/24 12:32:44 - [] D -- C:\Users\HiChEm\AppData\Local\Mozilla
O43 - CFD: 2015/07/24 16:34:25 - [] D -- C:\Users\HiChEm\AppData\Local\NetBeans
O43 - CFD: 2015/08/06 19:52:09 - [] D -- C:\Users\HiChEm\AppData\Local\Packages
O43 - CFD: 2015/08/07 12:16:49 - [0] D -- C:\Users\HiChEm\AppData\Local\PeerDistRepub
O43 - CFD: 2015/04/24 12:29:18 - [] D -- C:\Users\HiChEm\AppData\Local\Programs
O43 - CFD: 2015/08/05 20:18:38 - [] D -- C:\Users\HiChEm\AppData\Local\Publishers
O43 - CFD: 2015/05/22 16:37:32 - [] D -- C:\Users\HiChEm\AppData\Local\Skype
O43 - CFD: 2015/08/20 14:24:06 - [] D -- C:\Users\HiChEm\AppData\Local\Temp
O43 - CFD: 2015/08/05 19:29:38 - [0] SHD -- C:\Users\HiChEm\AppData\Local\Temporary Internet Files
O43 - CFD: 2015/08/05 19:59:32 - [] D -- C:\Users\HiChEm\AppData\Local\TileDataLayer
O43 - CFD: 2015/04/24 14:57:13 - [] D -- C:\Users\HiChEm\AppData\Local\TuneUp Software
O43 - CFD: 2015/05/08 15:14:46 - [] D -- C:\Users\HiChEm\AppData\Local\VirtualStore
O43 - CFD: 2015/06/13 17:38:31 - [0] D -- C:\Users\HiChEm\AppData\Local\WMTools Downloaded Files
O43 - CFD: 2015/06/26 10:39:05 - [] D -- C:\Users\HiChEm\AppData\Local\Wondershare
O43 - CFD: 2015/08/02 20:59:12 - [] D -- C:\Users\HiChEm\AppData\Local\Your Freedom
O43 - CFD: 2015/07/10 12:04:26 - [] RD -- C:\Users\HiChEm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 2015/08/05 19:59:31 - [] RD -- C:\Users\HiChEm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2015/08/05 19:59:49 - [] RD -- C:\Users\HiChEm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2015/08/05 19:30:22 - [] D -- C:\Users\HiChEm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DiskInternals
O43 - CFD: 2015/08/05 19:38:20 - [] D -- C:\Users\HiChEm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flux
O43 - CFD: 2015/08/05 19:38:20 - [] D -- C:\Users\HiChEm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
O43 - CFD: 2015/07/10 12:04:26 - [] D -- C:\Users\HiChEm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2015/08/05 19:38:20 - [] D -- C:\Users\HiChEm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My WIFI Router
O43 - CFD: 2015/08/05 19:59:49 - [] RD -- C:\Users\HiChEm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 2015/07/10 12:04:26 - [] RD -- C:\Users\HiChEm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 2015/08/05 19:38:20 - [] D -- C:\Users\HiChEm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
O43 - CFD: 2015/07/10 12:04:45 - [] RSD -- C:\Users\HiChEm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
O43 - CFD: 2015/08/05 19:38:20 - [] D -- C:\Users\HiChEm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 2015/08/05 19:38:20 - [] D -- C:\Users\HiChEm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Your Freedom

---\\ Derniers fichiers créés dans Windows Prefetcher (1) - 10s
O45 - LFCP:[MD5.44F18484DA60BC8B2AF4D2928E5A095F] 2015/08/14 09:28:11 A -- C:\WINDOWS\Prefetch\PERFORMANCEOPTIMIZER.EXE-D034DBC3.pf =>PUP.Optional.BProtector

---\\ Enumération des clés StartupReg (9) - 1s
O53 - SMSR:HKLM\...\startupreg\Connectify Dispatch [Key] . (...) -- C:\Program Files (x86)\Connectify\DispatchUI.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\Connectify Hotspot [Key] . (...) -- C:\Program Files (x86)\Connectify\Connectify.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\HSPALauncher [Key] . (.Copyright (C) 2010 - HSDPALauncher MFC Application.) -- C:\Program Files (x86)\HSPA USB Modem\HSPALauncher.exe
O53 - SMSR:HKLM\...\startupreg\Skype [Key] . (...) -- C:\Program Files (x86)\Skype\Phone\Skype.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\SunJavaUpdateSched [Key] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
O53 - SMSR:HKLM\...\startupreg\TunnelBear [Key] . (...) -- C:\Program Files (x86)\TunnelBear\TBear.Client.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\vmware-tray.exe [Key] . (...) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\Wondershare Helper Compact.exe [Key] . (...) -- C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelperSetup.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\YouCam Service [Key] . (...) -- C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe (.not file.)

---\\ Liste des pilotes du système (79) - 5s
O58 - SDL:2015/07/19 18:17:10 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\WINDOWS\System32\drivers\200F3838.sys [113880]
O58 - SDL:2015/08/07 10:52:32 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\WINDOWS\System32\drivers\36833070.sys [113880]
O58 - SDL:2015/07/10 11:59:38 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107360]
O58 - SDL:2015/06/02 17:38:12 A . (.Copyright (C) Performix LLC 2015 - Adguard TDI network driver.) -- C:\WINDOWS\System32\drivers\adgnetworktdidrv.sys [61432]
O58 - SDL:2015/07/10 11:59:38 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135456]
O58 - SDL:2015/07/29 04:26:10 A . (.Advanced Micro Devices - AMD ACP Binaries.) -- C:\WINDOWS\System32\drivers\amdacpksd.sys [297672]
O58 - SDL:2015/06/03 14:35:36 A . (.Advanced Micro Devices, Inc. - AMD Audio Bus Lower Filter.) -- C:\WINDOWS\System32\drivers\amdkmafd.sys [31992]
O58 - SDL:2015/07/10 11:59:38 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [83296]
O58 - SDL:2015/07/10 11:59:38 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259424]
O58 - SDL:2015/07/10 11:59:38 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [26976]
O58 - SDL:2015/07/28 19:14:47 A . (.Copyright (c) All rights reserved. - NDIS 6.0 Filter Driver.) -- C:\WINDOWS\System32\drivers\anodlwfx.sys [15872]
O58 - SDL:2015/07/10 11:59:38 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [131936]
O58 - SDL:2015/07/22 00:42:04 A . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) -- C:\WINDOWS\System32\drivers\AtihdWT6.sys [102912]
O58 - SDL:2015/07/29 04:15:48 A . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\atikmdag.sys [21622784]
O58 - SDL:2015/07/29 03:22:04 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\WINDOWS\System32\drivers\atikmpag.sys [665088]
O58 - SDL:2015/07/10 11:59:38 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [17624]
O58 - SDL:2015/07/10 11:59:38 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [531296]
O58 - SDL:2011/04/14 04:47:55 A . (.CyberLink Corporation - CyberLink WebCam Virtual Driver.) -- C:\WINDOWS\System32\drivers\clwvd.sys [31216]
O58 - SDL:2015/04/24 14:09:26 A . (.Connectify - NDISRD helper driver.) -- C:\WINDOWS\System32\drivers\cnnctfy3.sys [42152]
O58 - SDL:2012/12/13 16:41:10 A . (.Windows (R) Win 7 DDK provider - Explore Systems Virtual Audio Device.) -- C:\WINDOWS\System32\drivers\dfx11_1x64.sys [28008]
O58 - SDL:2015/07/14 15:29:08 A . (.ESET - Amon monitor.) -- C:\WINDOWS\System32\drivers\eamonm.sys [255240]
O58 - SDL:2015/07/14 15:29:08 A . (.ESET - Devmon monitor.) -- C:\WINDOWS\System32\drivers\edevmon.sys [251632]
O58 - SDL:2015/07/14 15:29:08 A . (.ESET - ESET Helper driver.) -- C:\WINDOWS\System32\drivers\ehdrv.sys [178520]
O58 - SDL:2015/07/14 15:29:08 A . (.ESET - ESET Personal Firewall driver.) -- C:\WINDOWS\System32\drivers\epfw.sys [231520]
O58 - SDL:2015/07/14 15:29:08 A . (.ESET - Epfw NDIS LightWeight Filter.) -- C:\WINDOWS\System32\drivers\EpfwLWF.sys [53360]
O58 - SDL:2015/07/14 15:29:08 A . (.ESET - ESET Personal Firewall driver.) -- C:\WINDOWS\System32\drivers\epfwwfp.sys [72400]
O58 - SDL:2015/07/10 11:59:38 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3436896]
O58 - SDL:2013/11/14 10:39:05 A . (.Huawei Tech. Co., Ltd. - HUAWEI USB Smart Card Driver.) -- C:\WINDOWS\System32\drivers\ewdcsc.sys [32768]
O58 - SDL:2013/11/14 10:39:03 A . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\WINDOWS\System32\drivers\ewusbmdm.sys [226048]
O58 - SDL:2013/11/14 10:39:05 A . (.Huawei Technologies Co., Ltd. - USB NDIS Miniport Driver.) -- C:\WINDOWS\System32\drivers\ewusbwwan.sys [455680]
O58 - SDL:2013/11/14 10:39:05 A . (.Huawei Technologies Co., Ltd. - ew_cdcacm Driver.) -- C:\WINDOWS\System32\drivers\ew_cdcacm.sys [121728]
O58 - SDL:2013/11/14 10:39:05 A . (.Huawei Technologies Co., Ltd. - ew_hwupgrade Driver.) -- C:\WINDOWS\System32\drivers\ew_hwupgrade.sys [22016]
O58 - SDL:2013/11/14 10:39:05 A . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\WINDOWS\System32\drivers\ew_hwusbdev.sys [109568]
O58 - SDL:2013/11/14 10:39:04 A . (.Huawei Technologies Co., Ltd. - ew_jubusenum Driver.) -- C:\WINDOWS\System32\drivers\ew_jubusenum.sys [91648]
O58 - SDL:2013/11/14 10:39:04 A . (.Huawei Technologies Co., Ltd. - ew_jucdcacm Driver.) -- C:\WINDOWS\System32\drivers\ew_jucdcacm.sys [110592]
O58 - SDL:2013/11/14 10:39:05 A . (.Huawei Technologies Co., Ltd. - ew_jucdcndis Driver.) -- C:\WINDOWS\System32\drivers\ew_jucdcecm.sys [77312]
O58 - SDL:2013/11/14 10:39:04 A . (.Huawei Technologies Co., Ltd. - ew_juextctrl Driver.) -- C:\WINDOWS\System32\drivers\ew_juextctrl.sys [30720]
O58 - SDL:2013/11/14 10:39:04 A . (.Huawei Technologies Co., Ltd. - ew_jucdcndis Driver.) -- C:\WINDOWS\System32\drivers\ew_juwwanecm.sys [246272]
O58 - SDL:2012/12/22 02:46:10 A . (.Huawei Technologies Co., Ltd. - Filter Driver.) -- C:\WINDOWS\System32\drivers\ew_usbenumfilter.sys [14976]
O58 - SDL:2013/11/14 10:39:04 A . (.Huawei Technologies Co., Ltd. - ew_cdcndis Driver.) -- C:\WINDOWS\System32\drivers\ew_wwanecm.sys [375040]
O58 - SDL:2015/07/10 11:59:38 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64352]
O58 - SDL:2011/10/24 05:04:32 A . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\WINDOWS\System32\drivers\hw_quusbmdm.sys [223232]
O58 - SDL:2011/10/24 04:51:40 A . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\WINDOWS\System32\drivers\hw_usbdev.sys [116864]
O58 - SDL:2015/07/10 11:59:36 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128]
O58 - SDL:2015/07/10 11:59:36 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [122608]
O58 - SDL:2015/07/10 11:59:38 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [673120]
O58 - SDL:2015/07/10 11:59:38 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412000]
O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [424800]
O58 - SDL:2015/06/12 03:00:58 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\WINDOWS\System32\drivers\idmwfp.sys [197616]
O58 - SDL:2009/10/13 02:15:52 A . (.Atheros Communications, Inc. - Atheros L1 Gigabit Ethernet 10/100/1000Base.) -- C:\WINDOWS\System32\drivers\l160x64.sys [61440]
O58 - SDL:2015/07/10 11:59:38 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [108896]
O58 - SDL:2015/07/10 11:59:38 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [104800]
O58 - SDL:2015/07/10 11:59:38 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [99168]
O58 - SDL:2015/07/10 11:59:38 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82784]
O58 - SDL:2015/06/18 08:41:40 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\WINDOWS\System32\drivers\mbam.sys [25816]
O58 - SDL:2015/06/18 08:41:44 A . (.Malwarebytes Corporation - Malwarebytes Chameleon Protection Driver.) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys [109272]
O58 - SDL:2015/08/18 10:48:24 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [113880]
O58 - SDL:2015/07/10 11:59:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59744]
O58 - SDL:2015/07/10 11:59:39 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575840]
O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [705376]
O58 - SDL:2013/11/14 10:39:04 A . (.DiBcom SA - DiBcom AVSTREAM BDA driver.) -- C:\WINDOWS\System32\drivers\mod7700.sys [1001472]
O58 - SDL:2015/07/10 11:59:39 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63840]
O58 - SDL:2015/06/18 08:41:56 A . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\WINDOWS\System32\drivers\mwac.sys [63704]
O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [76128]
O58 - SDL:2015/07/10 11:59:39 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150368]
O58 - SDL:2015/07/10 11:59:39 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [166240]
O58 - SDL:2015/07/10 11:59:39 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [58208]
O58 - SDL:2015/07/10 11:59:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [58720]
O58 - SDL:2015/07/10 11:59:39 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44896]
O58 - SDL:2015/07/10 11:59:39 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81760]
O58 - SDL:2015/07/10 11:59:39 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31072]
O58 - SDL:2014/08/12 09:45:28 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver.) -- C:\WINDOWS\System32\drivers\tap-tb-0901.sys [38656]
O58 - SDL:2014/11/05 14:16:32 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\WINDOWS\System32\drivers\tap0901.sys [27136]
O58 - SDL:2012/07/15 10:48:16 A . (.The OpenVPN Project - TAP-Win32 Virtual Network Driver.) -- C:\WINDOWS\System32\drivers\tapoas.sys [30720]
O58 - SDL:2015/07/10 11:59:48 A . (...) -- C:\WINDOWS\System32\drivers\Udecx.sys [44032]
O58 - SDL:2015/07/10 11:59:39 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166752]
O58 - SDL:2015/07/10 11:59:39 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305504]
O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [26976]
O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [59232]

---\\ Derniers fichiers modifiés ou crées (Utilisateur) (7) - 6s
O61 - LFC: 2015/08/16 08:53:50 A . (.Beepa Pty Ltd.) -- C:\Users\HiChEm\Downloads\Programs\setup.exe [2326976]
O61 - LFC: 2015/08/18 10:49:19 A . (..) -- C:\Users\HiChEm\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_0_Data.bin [1048576]
O61 - LFC: 2015/08/18 10:49:19 A . (..) -- C:\Users\HiChEm\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_0_Header.bin [9640]
O61 - LFC: 2015/08/19 21:40:30 A . (..) -- C:\Users\HiChEm\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\speech_onecorereg.bin [8192]
O61 - LFC: 2015/08/19 12:13:46 A . (..) -- C:\Users\HiChEm\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\UrlBlock\urlblock_635755670574890145.bin [93165]
O61 - LFC: 2015/08/20 13:37:37 A . (..) -- C:\Users\HiChEm\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [1113849]
O61 - LFC: 2015/08/14 08:06:45 A . (..) -- C:\Users\HiChEm\AppData\Local\ATI\ACE\Manifest.Bin [30042]

---\\ Associations Shell Spawning (10) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S

---\\ Menu de démarrage Internet (12) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe

---\\ Recherche d'infection sur les navigateurs (1) - 5s
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/

---\\ Enumère les fichiers Crack & Keygen (1) - 13s
O82 - LFC: 2015/07/22 19:29:53 A . (...) -- C:\Users\HiChEm\Downloads\Compressed\Wondershare.Dr.Fone.for.Android.[v4.0.x].Keygen-AoRE.rar [0] =>.Crack,Keygen

---\\ Enumère les services démarrés par Svchost (42) - 2s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [192000]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [192000]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\WINDOWS\system32\srvsvc.dll [283136]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\WINDOWS\System32\gpsvc.dll [1335296]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\WINDOWS\System32\ikeext.dll [954368]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\WINDOWS\System32\iphlpsvc.dll [954880]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\WINDOWS\system32\seclogon.dll [31232]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\WINDOWS\System32\appinfo.dll [93696]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\WINDOWS\system32\iscsiexe.dll [151040]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\WINDOWS\System32\eapsvc.dll [106496]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\WINDOWS\system32\schedsvc.dll [1008640]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [226304]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\WINDOWS\System32\browser.dll [133120]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\WINDOWS\system32\profsvc.dll [324608]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [371200]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\WINDOWS\System32\wercplsupport.dll [95744]
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\WINDOWS\system32\wlidsvc.dll [2093056]
O83 - Search Svchost Services: DcpSvc (DcpSvc) . (.Microsoft Corporation - dcpsvc Task.) -- C:\WINDOWS\system32\dcpsvc.dll [196096]
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\WINDOWS\System32\ncasvc.dll [167424]
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Service Configuration du réseau.) -- C:\WINDOWS\System32\NetSetupSvc.dll [186368]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\WINDOWS\System32\rasauto.dll [106496]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\WINDOWS\System32\rasmans.dll [679936]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [497152]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\WINDOWS\System32\sens.dll [72192]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\WINDOWS\System32\ipnathlp.dll [452608]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [311808]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\WINDOWS\system32\wuaueng.dll [2239488]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\WINDOWS\System32\qmgr.dll [1168896]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [593920]
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\WINDOWS\system32\dmwappushsvc.dll [63488]
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\WINDOWS\System32\XblGameSave.dll [1149440]
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\WINDOWS\system32\XboxNetApiSvc.dll [1019392]
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Mettre à jour la session Orchestrator Core.) -- C:\WINDOWS\system32\usocore.dll [343040]
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\WINDOWS\System32\usermgr.dll [717312]
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service de géolocalisation.) -- C:\Windows\System32\lfsvc.dll [27136]
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - DLL Windows Management Service.) -- C:\Windows\System32\Windows.Internal.Management.dll [267776]
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\WINDOWS\System32\XblAuthManager.dll [918016]
O83 - Search Svchost Services: RetailDemo (RetailDemo) . (.Microsoft Corporation - RDXService.) -- C:\WINDOWS\system32\RDXService.dll [988672]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\WINDOWS\System32\bdesvc.dll [359936]
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\WINDOWS\System32\DeviceSetupManager.dll [237568]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\WINDOWS\system32\themeservice.dll [58368]
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [200192]

---\\ Liste des exceptions du parefeu Windows (3) - 2s
O87 - FAEL: "UDP Query User{3CE50A02-3C1F-4A54-B6EE-A0E6BE0B9068}C:\program files (x86)\wondershare\mobilego for android\mobilegoservice.exe" [In-None-P17-TRUE] .(.Wondershare - MobileGo Device Listen Service.) -- C:\program files (x86)\wondershare\mobilego for android\mobilegoservice.exe
O87 - FAEL: "TCP Query User{0FE302EF-82BC-4984-8799-572C46DC1E22}C:\program files (x86)\wondershare\mobilego for android\mobilegoservice.exe" [In-None-P6-TRUE] .(.Wondershare - MobileGo Device Listen Service.) -- C:\program files (x86)\wondershare\mobilego for android\mobilegoservice.exe
O87 - FAEL: "{34D8E01B-51CF-43ED-BAD0-E0F0B55B4C01}" [In-None-P6-TRUE] .(.Performix LLC - Adguard for Windows.) -- C:\Program Files (x86)\Adguard\AdguardSvc.exe

---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (22) - 69s
SR - Auto [2015/07/05 03:17:48] [ 119832] Adguard Service (Adguard Service) . (.Performix LLC.) - C:\Program Files (x86)\Adguard\AdguardSvc.exe
SS - Demand [2015/08/14 09:13:58] [ 269000] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SR - Auto [2015/07/29 03:25:54] [ 246784] (AMD External Events Utility) . (.AMD.) - C:\WINDOWS\system32\atiesrxx.exe
SS - Auto [2013/10/26 10:45:14] [ 651856] Djezzy connect. OUC (Djezzy connect. RunOuc) . (...) - C:\Program Files (x86)\Djezzy connect\UpdateDog\ouc.exe
SR - Auto [2010/08/12 02:56:42] [ 66880] DWA-135_PBC_WPS Service (DWA-135_PBC_WPS) . (.Copyright 2010.) - C:\Program Files (x86)\D-Link\DWA-135\ALPBCSVC.exe
SR - Auto [2015/07/08 15:22:32] [ 1353720] ESET Service (ekrn) . (.ESET.) - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
SS - Auto [2015/04/24 12:31:12] [ 116648] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - Demand [2015/04/24 12:31:12] [ 116648] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SR - Auto [2013/04/10 06:58:06] [ 351824] HWDeviceService64.exe (HWDeviceService64.exe) . (.Copyright (C) 2013.) - C:\ProgramData\DatacardService\HWDeviceService64.exe
SS - Auto [2015/08/06 18:23:49] [ 2585376] LiveUpdate (LiveUpdateSvc) . (.IObit.) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
SS - Auto [2015/06/18 08:39:46] [ 1871160] MBAMScheduler (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
SS - Auto [2015/06/18 08:39:50] [ 1133880] MBAMService (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
SS - Auto [2013/11/14 10:39:30] [ 656976] MobiConnect. OUC (MobiConnect. RunOuc) . (...) - C:\Program Files (x86)\MobiConnect\UpdateDog\ouc.exe
SS - Disabled [2015/08/07 20:04:03] [ 149160] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
SR - Auto [2014/11/18 03:59:18] [ 47464] MyWiFiRouterDHCP (MyWiFiRouterDHCP) . (...) - C:\Program Files (x86)\Wi-Fi\WiFiGxSvc.exe
SR - Auto [2015/05/26 22:40:22] [ 324760] NitroPDFDriverCreatorReadSpool10 (NitroDriverReadSpool10) . (.Nitro PDF Software.) - C:\Program Files\Nitro\Pro 10\NitroPDFDriverService10x64.exe
SR - Auto [2013/10/07 09:42:16] [ 230920] NitroPDFDriverCreatorReadSpool9 (NitroDriverReadSpool9) . (.Nitro PDF Software.) - C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe
SR - Auto [2015/05/26 22:40:24] [ 418968] NitroUpdateService (NitroUpdateService) . (...) - C:\Program Files\Nitro\Pro 10\Nitro_UpdateService.exe
SS - Disabled [2013/10/07 09:42:26] [ 69640] Nalpeiron Licensing Service (nlsX86cc) . (.Nalpeiron Ltd..) - C:\Windows\SysWOW64\NLSSRV32.EXE
SS - Demand [2015/07/09 16:49:00] [ 33080] OpenVPN Service (OpenVPNService) . (.The OpenVPN Project.) - C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe
SS - Disabled [2014/10/13 06:57:46] [ 743688] SAMSUNG Mobile Connectivity Service (ss_conn_service) . (.DEVGURU Co., LTD..) - C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
SR - Auto [2015/06/29 10:24:00] [ 2970424] AVG PC TuneUp Service (TuneUp.UtilitiesSvc) . (.AVG Technologies.) - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe

---\\ Recherche de clés de registre Tracing (2) - 1s
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\PerformanceOptimizer_RASAPI32 =>PUP.Optional.BProtector
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\PerformanceOptimizer_RASMANCS =>PUP.Optional.BProtector

---\\ Scan Additionnel (6) - 0s
C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS
C:\Users\HiChEm\AppData\Roaming\Mobogenie =>PUP.Optional.Mobogenie
C:\Users\HiChEm\AppData\Local\Mobogenie =>PUP.Optional.Mobogenie
C:\WINDOWS\Prefetch\PERFORMANCEOPTIMIZER.EXE-D034DBC3.pf =>PUP.Optional.BProtector
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\PerformanceOptimizer_RASAPI32 =>PUP.Optional.BProtector
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\PerformanceOptimizer_RASMANCS =>PUP.Optional.BProtector

---\\ Récapitulatif des éléments trouvées sur votre station (3) - 0s
http://www.nicolascoolman.fr/trojan-autokms/ =>HackTool.AutoKMS
http://www.nicolascoolman.fr/pup-mobogenie/ =>PUP.Optional.Mobogenie
http://www.nicolascoolman.fr/pup-bprotector/ =>PUP.Optional.BProtector

~ End of the scan, 32316 items in 172 seconds (910)(1)()

Publicité


Signaler le contenu de ce document

Publicité