cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.9.14.141 Par Nicolas Coolman (2015/09/12)
~ Démarré par acer i (Administrator) (2015/09/15 08:27:07)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Users\acer i\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\acer i\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Démarrage du système: Normal (Normal boot)
Windows 10 Home, 64-bit (Build 10240)

---\\ Navigateurs Internet (3) - 0s
GCIE: Google Chrome v45.0.2454.85
MFIE: Mozilla Firefox 40.0.3 (x86 fr) v40.0.3
MSIE: Internet Explorer v11.0.10240.16431

---\\ Informations sur les produits Windows (3) - 3s
~ Windows Server License Manager Script : OK
System - VBScript Engine not found
Windows Automatic Updates : OK

---\\ Logiciels de protection (1) - 1s
Windows Defender W10 (Activate)

---\\ Surveillance de Logiciels (1) - 2s
Adobe Reader X

---\\ Informations sur le système (6) - 0s
~ Operating System: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 4080.92 MB (51% free)
~ System Restore: Activé (Enable)
~ System drive C: has 150 GB free of 237 GB

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: ACER
~ User Name: acer i
~ Logged in as Administrator

---\\ Enumération des unités disques (2) - 0s
~ Drive C: has 150 GB free of 237 GB (System)
~ Drive D: has 238 GB free of 238 GB

---\\ Etat du Centre de Sécurité Windows (7) - 0s
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Recherche particulière de fichiers génériques (25) - 0s
[MD5.F1CBCB7FA6F3B309639AA2D4EF74469C] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\WINDOWS\Explorer.exe [4532304] ©
[MD5.5DED2A3F11AE916C8F2724947E736261] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) () -- C:\WINDOWS\System32\rundll32.exe [59392] ©
[MD5.7718A2A9B2BFB2C8E2BAEB03310CA3FD] - (.Microsoft Corporation - Application de démarrage de Windows.) () -- C:\WINDOWS\System32\Wininit.exe [290312] ©
[MD5.FE32B8423711B4B4378C0BA3C3560ED4] - (.Microsoft Corporation - Extensions Internet pour Win32.) () -- C:\WINDOWS\System32\wininet.dll [2741760] ©
[MD5.26EFEFD877A84EE9FBDE6DEE630892C9] - (.Microsoft Corporation - Application d’ouverture de session Windows.) () -- C:\WINDOWS\System32\Winlogon.exe [578048] ©
[MD5.ECB1943967424DFB96E03F6A098434EF] - (.Microsoft Corporation - Bibliothèque de licences.) () -- C:\WINDOWS\System32\sppcomapi.dll [430592] ©
[MD5.C287D0E32771E3222A444DC527A29477] - (.Microsoft Corporation - DNS DLL de l’API Client.) () -- C:\WINDOWS\System32\dnsapi.dll [680256] ©
[MD5.BB5BBD0E4D04047585E4ED0F07AA51E7] - (.Microsoft Corporation - DNS DLL de l’API Client.) () -- C:\WINDOWS\Syswow64\dnsapi.dll [534064] ©
[MD5.8C795953726C7D2DE72CE4748208C5ED] - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) () -- C:\WINDOWS\System32\fr-FR\user32.dll.mui [20480] ©
[MD5.6C12C7E01A4F64E0AA9C88AF66955CC9] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) () -- C:\WINDOWS\System32\drivers\AFD.sys [577888] ©
[MD5.8921DF6060DB5C7700AA48CB12E9EA08] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\WINDOWS\System32\drivers\atapi.sys [28512] ©
[MD5.F2829DC6D292DCAC5029893BB2E9FEE3] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\WINDOWS\System32\drivers\Cdfs.sys [92672] ©
[MD5.CA160E02F35A61C6F5C681FB4669C519] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\WINDOWS\System32\drivers\Cdrom.sys [174080] ©
[MD5.25435407D97419627F4B10653433BF2B] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\WINDOWS\System32\drivers\DfsC.sys [138240] ©
[MD5.C277A49F8A8295840DEBC9240B75A282] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\WINDOWS\System32\drivers\HDAudBus.sys [80896] ©
[MD5.D4CDEE4A62BDFFF6E8558A9552148EA7] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\WINDOWS\System32\drivers\i8042prt.sys [114688] ©
[MD5.5D3744E6FDEC1A6FB3FA9B1DD4AF0694] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\WINDOWS\System32\drivers\IpNat.sys [143360] ©
[MD5.1DF2C5FD2710A13B07E663A12F0E0EEA] - (.Microsoft Corporation - Minirdr SMB Windows NT.) () -- C:\WINDOWS\System32\drivers\MRxSmb.sys [415232] ©
[MD5.F0D791348AD254360CC3C3E501CCB745] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\WINDOWS\System32\drivers\netBT.sys [273408] ©
[MD5.466EC5659C02ED53DBD47DC1BC2B8086] - (.Microsoft Corporation - Pilote du système de fichiers NT.) () -- C:\WINDOWS\System32\drivers\ntfs.sys [2116448] ©
[MD5.38F1AE32339731F6E5A7281AE8042545] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\WINDOWS\System32\drivers\Parport.sys [96768] ©
[MD5.CA60F6C03611AF1710BC903ED9F566FB] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [104960] ©
[MD5.A32AED8C644734B283A7C9D08D76064D] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) () -- C:\WINDOWS\System32\drivers\rdpdr.sys [176128] ©
[MD5.28E1E63A1AC65E17B3194238FA2CF3BF] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\WINDOWS\System32\drivers\tdx.sys [116576] ©
[MD5.823A237D871CD652C6BFD47BECB6810A] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\WINDOWS\System32\drivers\volsnap.sys [378720] ©

---\\ Processus lancés (23) - 2s
[MD5.7A094E697E8B7B4B495AFA3D522A8E8D] - (.Beijing Rising Information Technology Co., Ltd. - RsMgrSvc Application.) -- C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe [196288] [PID.736] ©
[MD5.CA1789177F06865DD316128704675E74] - (.Tencent - 电脑管家-实时防护服务.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCRTP.exe [297608] [PID.1052] =>PUP.Optional.TencentAddressBar
[MD5.1DBE918F1EDE43C8D49B6D9A7DEA25F3] - (.Intel Corporation - igfxCUIService Module.) -- C:\WINDOWS\system32\igfxCUIService.exe [328608] [PID.1460] ©
[MD5.0DB1E3F6189C628675F855C0EB510419] - (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696] [PID.2044] ©
[MD5.FFDF8F07A900659CF927A273942926F8] - (.Acer Incorporate - LMSvc.) -- C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [457768] [PID.2088] ©
[MD5.11A52CF7B265631DEEB24C6149309EFF] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [64952] [PID.2096] ©
[MD5.ADE85C1EB3D0393D6EC4A77E12D3E3FF] - (.ELAN Microelectronics Corp. - Elan Service.) -- C:\Program Files\Elantech\ETDService.exe [144072] [PID.2108] ©
[MD5.37926AAE7032C1236BA334610A205876] - (.ELAN Microelectronics Corp. - ETD Control Center.) -- C:\Program Files\Elantech\ETDCtrl.exe [3242696] [PID.4124] ©
[MD5.BFE27E59D71DA8D4C5433AECE14C4CBF] - (.Intel Corporation - igfxEM Module.) -- C:\WINDOWS\system32\igfxEM.exe [540064] [PID.4644] ©
[MD5.D6298429D647B5ECFB3D1A407E2C364C] - (.Intel Corporation - igfxHK Module.) -- C:\WINDOWS\system32\igfxHK.exe [256928] [PID.4668] ©
[MD5.97BB6425C86F46C2B21E0861421B6AE5] - (.Intel Corporation - igfxTray Module.) -- C:\WINDOWS\system32\igfxTray.exe [393632] [PID.4696] ©
[MD5.2D4C0A5942B614F8C089ACFB5FC3044B] - (.ELAN Microelectronics Corp. - ETD Control Center Helper.) -- C:\Program Files\Elantech\ETDCtrlHelper.exe [2581768] [PID.1540] ©
[MD5.2F41B7382F80F967A7B45F6C28C4D846] - (.Acer Incorporate - LMEvent.) -- C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe [466472] [PID.5372] ©
[MD5.6E0B176E2B51AF649D664E1887AA55A2] - (.Acer Incorporate - LMTray.) -- C:\Program Files\Acer\Acer Launch Manager\LMTray.exe [451112] [PID.5628] ©
[MD5.16E1EA189D721E60D17D1BC8E0392702] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.6048] ©
[MD5.16E1EA189D721E60D17D1BC8E0392702] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.5496] ©
[MD5.16E1EA189D721E60D17D1BC8E0392702] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.5564] ©
[MD5.16E1EA189D721E60D17D1BC8E0392702] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.4032] ©
[MD5.52069AEB42D3D0F97CBCA1085EBF55E6] - (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432] [PID.2644] ©
[MD5.6A35B295812CE7064CFBCD9F254169CF] - (.Intel Corporation - Intel(R) Local Management Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [390616] [PID.3932] ©
[MD5.16E1EA189D721E60D17D1BC8E0392702] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.1644] ©
[MD5.16E1EA189D721E60D17D1BC8E0392702] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944] [PID.6260] ©
[MD5.018B44D6E41ABDD08403E6B9EC3575B3] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\acer i\AppData\Roaming\ZHP\ZHPDiag3.exe [1929728] [PID.6240] ©

---\\ Google Chrome, Démarrage,Recherche,Extensions (6) - 0s
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.google.com/
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.mystartsearch.com/ =>PUP.Optional.StartSearch
G2 - GCE: Preference [User Data\Default] [bkkbcggnhapdmkeljlodobbkopceiche] Poper Blocker
G2 - GCE: Preference [User Data\Default] [jeaohhlajejodfjadcponpnjgkiikocn] IDM Integration Module
G2 - GCE: Preference [User Data\Default] [lccekmodgklaepjeofjdjpbminllajkg] Chrome Hotword Shared Module
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.

---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (5) - 0s
P2 - EXT: (.Mozilla - Default.) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ©
P2 - FPN: [HKCU] [@iqiyi.com/npWebPlayer] - (.pps-webplayer-plugin.) -- C:\IQIYI Video\LStyle\npWebPlayer.dll =>PUP.Optional.IQIYIVideo
P2 - FPN: [HKLM] [@iqiyi.com/npWebPlayer] - (.pps-webplayer-plugin.) -- C:\IQIYI Video\LStyle\npWebPlayer.dll =>PUP.Optional.IQIYIVideo
P2 - FPN: [HKLM] [@qq.com/npAndroidAssistant] - (.腾讯公司.) -- C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll =>PUP.Optional.TencentAddressBar
P2 - FPN: [HKLM] [@qq.com/QQPCMgr] - (.Tencent Technology (Shenzhen) Company Limited.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\npQMExtensionsMozilla.dll =>PUP.Optional.TencentAddressBar

---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (22) - 1s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/ =>PUP.Optional.Browser
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/ =>PUP.Optional.Browser
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutwkzwgbnf1vt-t6b6ew1p89vdpn8vyuycxrworquh5t2sxljtzaiw3h1fzj66sapi1gnnmpyphtsfwbop4xf-uizrozoucumyrsqzfc39ol3-9gsdo8fpcg-5trzo4lu2n0brscp2nvkf7atnf5epcvzsb-vzymlvhwbgq,,&q={searchterms}
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/ =>PUP.Optional.Qvo6
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutwkzwgbnf1vt-t6b6ew1p89vdpn8vyuycxrworquh5t2sxljtzaiw3h1fzj66sapi1gnnmpyphtsfwbop4xf-uizrozoucumyrsqzfc39ol3-9gsdo8fpcg-5trzo4lu2n0brscp2nvkf7atnf5epcvzsb-vzymlvhwbgq,,&q={searchterms}
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutwkzwgbnf1vt-t6b6ew1p89vdpn8vyuycxrworquh5t2sxljtzaiw3h1fzj66sapi1gnnmpyphtsfwbop4xf-uizrozoucumyrsqzfc39ol3-9gsdo8fpcg-5trzo4lu2n0brscp2nvkf7atnf5epcvzsb-vzymlvhwbgq,,&q={searchterms}
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutwkzwgbnf1vt-t6b6ew1p89vdpn8vyuycxrworquh5t2sxljtzaiw3h1fzj66sapi1gnnmpyphtsfwbop4xf-uizrozoucumyrsqzfc39ol3-9gsdo8fpcg-5trzo4lu2n0brscp2nvkf7atnf5epcvzsb-vzymlvhwbgq,,&q={searchterms}
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1
R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1

---\\ Internet Explorer,Proxy Management (4) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s
F2 - REG:system.ini: UserInit=
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.)
F2 - REG:system.ini: VMApplet=

---\\ Etude du fichier hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)

---\\ Browser Helper Object de navigateur (BHO) (4) - 0s
O2 - BHO: IDM Helper [64Bits] - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll
O2 - BHO: Skype for Business Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} . (.Microsoft Corporation - Skype for Business.) -- C:\Program Files\Microsoft Office\Office15\OCHelper.dll ©
O2 - BHO: TSWebMon [64Bits] - {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} . (.Tencent - 电脑管家-网页防火墙.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\TSWebMon64.dat =>PUP.Optional.TencentAddressBar
O2 - BHO: Microsoft SkyDrive Pro Browser Helper [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} . (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL ©

---\\ Applications lancées au démarrage du système (20) - 1s
O4 - HKLM\..\Run: [ETDCtrl] C:\Program Files (x86)\Elantech\ETDCtrl.exe (.not file.)
O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe ©
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe ©
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe (.not file.)
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe (.not file.)
O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe ©
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_F0B4B8077AD8D159F57087AF16ACE1DF] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\acer i\AppData\Local\Microsoft\OneDrive\OneDrive.exe ©
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe ©
O4 - HKLM\..\Wow6432Node\Run: [HDD Regenerator] C:\Program Files (x86)\HDD Regenerator\Shell.exe (.not file.)
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ©
O4 - HKLM\..\Wow6432Node\Run: [ QQPCTray] . (.Tencent - 电脑管家.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCTray.exe =>PUP.Optional.TencentAddressBar
O4 - HKLM\..\Wow6432Node\Run: [RSDTRAY] . (.Beijing Rising Information Technology Co., Ltd. - tray 应用程序.) -- C:\Program Files (x86)\Rising\RSD\popwndexe.exe ©
O4 - HKLM\..\Wow6432Node\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe (.not file.)
O4 - HKLM\..\policies\Explorer\Run: [BtvStack] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe (.not file.)
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe ©
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe ©
O4 - HKUS\S-1-5-21-17552336-836401412-1218104606-1001\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe ©
O4 - HKUS\S-1-5-21-17552336-836401412-1218104606-1001\..\Run: [GoogleChromeAutoLaunch_F0B4B8077AD8D159F57087AF16ACE1DF] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O4 - HKUS\S-1-5-21-17552336-836401412-1218104606-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\acer i\AppData\Local\Microsoft\OneDrive\OneDrive.exe ©

---\\ Modification Domaine/Adresses DNS (2) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1

---\\ Protocole additionnel (24) - 0s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll ©
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll ©
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll ©
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ©
O18 - Handler: ms-help [64Bits] - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll ©
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll ©
O18 - Handler: osf [64Bits] - {D924BDC6-C83A-4BD5-90D0-095128A113D1} . (.Microsoft Corporation - Microsoft Office 2013 component.) -- C:\Program Files\Microsoft Office\Office15\MSOSB.DLL ©
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\System32\tbauth.dll ©
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll ©
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll ©
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ©
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ©
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ©
O18 - Filter: text/xml [64Bits] - {807583E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL ©

---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (1) - 0s
O20 - AppInit_DLLs: . (...) - C:\ProgramData\Saophase\S--Nix.dll

---\\ Liste des services NT non Microsoft et non désactivés (11) - 1s
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe ©
O23 - Service: Elan Service (ETDService) . (.ELAN Microelectronics Corp. - Elan Service.) - C:\Program Files\Elantech\ETDService.exe ©
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ©
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation - igfxCUIService Module.) - C:\WINDOWS\system32\igfxCUIService.exe ©
O23 - Service: Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe ©
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe ©
O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Intel(R) Local Management Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe ©
O23 - Service: Launch Manager Service (LMSvc) . (.Acer Incorporate - LMSvc.) - C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe ©
O23 - Service: QQPCMgr RTP Service (QQPCRTP) . (.Tencent - 电脑管家-实时防护服务.) - C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCRTP.exe =>PUP.Optional.TencentAddressBar
O23 - Service: Rsd Service (RsMgrSvc) . (.Beijing Rising Information Technology Co., Ltd. - RsMgrSvc Application.) - C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe ©
O23 - Service: @C:\Program Files (x86)\Windows Defender\MpAsDesc.dll,-310 (WinDefend) . (...) - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (.not file.)

---\\ Tâches planifiées en automatique (46) - 3s
[MD5.DD447775B268E90264D5F45EFF374395] [APT] [1fjscpiz] (...) -- C:\Program Files\Common Files\uun0kmvx\0bfd4i2xivy3i.exe [57344]
[MD5.47C1DE0A890613FFCFF1D67648EEDF90] [APT] [Adobe online update program] (.Adobe Systems Incorporated.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920] ©
[MD5.00000000000000000000000000000000] [APT] [APSnotifierPP1] (...) -- C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe (.not file.) [0] =>PUP.Optional.AnyProtect
[MD5.00000000000000000000000000000000] [APT] [APSnotifierPP2] (...) -- C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe (.not file.) [0] =>PUP.Optional.AnyProtect
[MD5.00000000000000000000000000000000] [APT] [APSnotifierPP3] (...) -- C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe (.not file.) [0] =>PUP.Optional.AnyProtect
[MD5.00000000000000000000000000000000] [APT] [ASP] (...) -- C:\Program Files (x86)\RCP\systweakasp.exe (.not file.) [0] =>PUP.Optional.Systweak
[MD5.00000000000000000000000000000000] [APT] [brbrw_2871] (...) -- C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\Crossbrowse.exe (.not file.) [0] =>PUP.Optional.CrossBrowse
[MD5.00000000000000000000000000000000] [APT] [Google Updater and Installer] (...) -- C:\Users\acer i\AppData\Local\Google\Update\GoogleUpdate.exe (.not file.) [0]
[MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] ©
[MD5.DD7423ABBE2913E70D50E9318AD57EE4] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] ©
[MD5.00000000000000000000000000000000] [APT] [I0DS96c2PVs6MbviWTsBaDMNYr] (...) -- C:\Users\acer i\AppData\Roaming\I0DS96c2PVs6MbviWTsBaDMNYr.exe (.not file.) [0] =>PUP.Optional.CrossRider
[MD5.DD447775B268E90264D5F45EFF374395] [APT] [iksodyc4] (...) -- C:\Program Files\Common Files\g4s3xe51\b38d5lkqiwdyn.exe [57344]
[MD5.284B7132DF91F48C83E61A2B437F1776] [APT] [Launch Manager] (.Acer Incorporate.) -- C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe [437288] ©
[MD5.DD447775B268E90264D5F45EFF374395] [APT] [o1kcea11] (...) -- C:\Program Files\Common Files\grkba3hj\787e21u1teirc.exe [57344]
[MD5.00000000000000000000000000000000] [APT] [Price Fountain] (...) -- C:\Users\ACERI~1\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE (.not file.) [0] =>PUP.Optional.PriceFountain
[MD5.DD447775B268E90264D5F45EFF374395] [APT] [ri20bkk0] (...) -- C:\Program Files\Common Files\z5zwqilt\4c3cdtghe1wsd.exe [57344]
[MD5.00000000000000000000000000000000] [APT] [uodate] (...) -- C:\Windows\system32\config\systemprofile\AppData\Local\Jobdax /t 3320 9878 (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [uP8iSTDiLScoe4n9edgWWBW] (...) -- C:\Users\acer i\AppData\Roaming\uP8iSTDiLScoe4n9edgWWBW.exe (.not file.) [0] =>PUP.Optional.CrossRider
[MD5.9DF3A6447120E320EA62C506F1EB1896] [APT] [updateTask] (...) -- c:/task.vbs [651]
O39 - APT: APSnotifierPP1 - (...) -- C:\WINDOWS\Tasks\APSnotifierPP1.job [378] =>PUP.Optional.AnyProtect
O39 - APT: APSnotifierPP2 - (...) -- C:\WINDOWS\Tasks\APSnotifierPP2.job [376] =>PUP.Optional.AnyProtect
O39 - APT: APSnotifierPP3 - (...) -- C:\WINDOWS\Tasks\APSnotifierPP3.job [376] =>PUP.Optional.AnyProtect
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job [1082] ©
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job [1086] ©
O39 - APT: I0DS96c2PVs6MbviWTsBaDMNYr - (...) -- C:\WINDOWS\Tasks\I0DS96c2PVs6MbviWTsBaDMNYr.job [1038] =>PUP.Optional.CrossRider
O39 - APT: Price Fountain - (...) -- C:\WINDOWS\Tasks\Price Fountain.job [308] =>PUP.Optional.PriceFountain
O39 - APT: uP8iSTDiLScoe4n9edgWWBW - (...) -- C:\WINDOWS\Tasks\uP8iSTDiLScoe4n9edgWWBW.job [1032] =>PUP.Optional.CrossRider
O39 - APT: 1fjscpiz - (...) -- C:\WINDOWS\System32\Tasks\1fjscpiz [3266]
O39 - APT: Adobe online update program - (.Adobe Systems Incorporated.) -- C:\WINDOWS\System32\Tasks\Adobe online update program [3804] ©
O39 - APT: APSnotifierPP1 - (...) -- C:\WINDOWS\System32\Tasks\APSnotifierPP1 [2874] =>PUP.Optional.AnyProtect
O39 - APT: APSnotifierPP2 - (...) -- C:\WINDOWS\System32\Tasks\APSnotifierPP2 [2872] =>PUP.Optional.AnyProtect
O39 - APT: APSnotifierPP3 - (...) -- C:\WINDOWS\System32\Tasks\APSnotifierPP3 [2872] =>PUP.Optional.AnyProtect
O39 - APT: ASP - (...) -- C:\WINDOWS\System32\Tasks\ASP [3408] =>PUP.Optional.Systweak
O39 - APT: brbrw_2871 - (...) -- C:\WINDOWS\System32\Tasks\brbrw_2871 [3134] =>PUP.Optional.CrossBrowse
O39 - APT: Google Updater and Installer - (...) -- C:\WINDOWS\System32\Tasks\Google Updater and Installer [3942]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore [3932] ©
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA [4168] ©
O39 - APT: I0DS96c2PVs6MbviWTsBaDMNYr - (...) -- C:\WINDOWS\System32\Tasks\I0DS96c2PVs6MbviWTsBaDMNYr [4150] =>PUP.Optional.CrossRider
O39 - APT: iksodyc4 - (...) -- C:\WINDOWS\System32\Tasks\iksodyc4 [3266]
O39 - APT: Launch Manager - (.Acer Incorporate.) -- C:\WINDOWS\System32\Tasks\Launch Manager [3014] ©
O39 - APT: o1kcea11 - (...) -- C:\WINDOWS\System32\Tasks\o1kcea11 [3266]
O39 - APT: Price Fountain - (...) -- C:\WINDOWS\System32\Tasks\Price Fountain [2846] =>PUP.Optional.PriceFountain
O39 - APT: ri20bkk0 - (...) -- C:\WINDOWS\System32\Tasks\ri20bkk0 [3266]
O39 - APT: uodate - (...) -- C:\WINDOWS\System32\Tasks\uodate [3346]
O39 - APT: uP8iSTDiLScoe4n9edgWWBW - (...) -- C:\WINDOWS\System32\Tasks\uP8iSTDiLScoe4n9edgWWBW [4144] =>PUP.Optional.CrossRider
O39 - APT: updateTask - (...) -- C:\WINDOWS\System32\Tasks\updateTask [3206]

---\\ Logiciels installés (37) - 4s
O42 - Logiciel: ELAN Touchpad 11.15.0.16_X64 - (.ELAN Microelectronic Corp..) [HKLM][64Bits] -- Elantech ©
O42 - Logiciel: WinRAR archiver - (...) [HKLM][64Bits] -- WinRAR archiver
O42 - Logiciel: Broadcom Card Reader Driver Installer - (.Broadcom Corporation.) [HKLM][64Bits] -- {67AA948F-8D83-4566-B84A-7CAABCF64E3F} ©
O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {89AFB053-A343-46EF-97E4-D593AD7184E6} ©
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} ©
O42 - Logiciel: Security Update for Skype for Business 2015 (KB3055014) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{8C2B62DE-0BBD-421A-A0F8-4517146C7725} ©
O42 - Logiciel: Microsoft Access MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0015-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Excel MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0016-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft PowerPoint MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0018-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Publisher MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0019-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Outlook MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001A-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Word MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001B-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft InfoPath MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0044-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft DCF MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0090-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft OneNote MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00A1-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Groove MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00BA-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Security Update for Skype for Business 2015 (KB3055014) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{8C2B62DE-0BBD-421A-A0F8-4517146C7725} ©
O42 - Logiciel: Microsoft Lync MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-012B-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Security Update for Skype for Business 2015 (KB3055014) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90150000-012B-040C-1000-0000000FF1CE}_Office15.PROPLUS_{8C2B62DE-0BBD-421A-A0F8-4517146C7725} ©
O42 - Logiciel: Update for Skype for Business 2015 (KB2889853) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90150000-012B-040C-1000-0000000FF1CE}_Office15.PROPLUS_{DD51BA84-F589-4939-B5FE-5538B3DCC12E} ©
O42 - Logiciel: Acer Launch Manager - (.Acer Incorporated.) [HKLM][64Bits] -- {C18D55BD-1EC6-466D-B763-8EEDDDA9100E} ©
O42 - Logiciel: Broadcom NetLink Controller - (.Broadcom Corporation.) [HKLM][64Bits] -- {D1D7ED66-5C08-40A0-AEC0-B6DF977697BB} ©
O42 - Logiciel: GOM Player - (.Gretech Corporation.) [HKLM][64Bits] -- GOM Player
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome ©
O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM][64Bits] -- Internet Download Manager ©
O42 - Logiciel: Mozilla Firefox 40.0.3 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 40.0.3 (x86 fr) ©
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService ©
O42 - Logiciel: KMPlayer (remove only) - (.PandoraTV.) [HKLM][64Bits] -- The KMPlayer
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player ©
O42 - Logiciel: Java 8 Update 60 - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83218060F0} ©
O42 - Logiciel: Qualcomm Atheros WLAN and Bluetooth Client Installation Program - (.Qualcomm Atheros.) [HKLM][64Bits] -- {28006915-2739-4EBE-B5E8-49B25D32EB33} ©
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} ©
O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A} ©
O42 - Logiciel: Adobe Reader X (10.1.0) MUI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-FFFF-7B44-AA0000000001} ©
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} ©
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} ©
O42 - Logiciel: Popcorn Time - (.Popcorn Official.) [HKCU][64Bits] -- Popcorn Time ©

---\\ HKCU & HKLM Software Keys (121) - 4s
HKLM\SOFTWARE\Wow6432Node\Adobe
HKLM\SOFTWARE\Wow6432Node\AppDataLow
HKLM\SOFTWARE\Wow6432Node\ArenaHD =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\ATHEROS
HKLM\SOFTWARE\Wow6432Node\Chromium
HKLM\SOFTWARE\Wow6432Node\CLSID
HKLM\SOFTWARE\Wow6432Node\Comodo
HKLM\SOFTWARE\Wow6432Node\Crossbrowse =>PUP.Optional.CrossBrowse
HKLM\SOFTWARE\Wow6432Node\downchecker =>PUP.Optional.DownChecker
HKLM\SOFTWARE\Wow6432Node\GlobalUpdate =>PUP.Optional.GlobalUpdate
HKLM\SOFTWARE\Wow6432Node\Google
HKLM\SOFTWARE\Wow6432Node\GRETECH
HKLM\SOFTWARE\Wow6432Node\hdcode
HKLM\SOFTWARE\Wow6432Node\HighDefAction =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\IHProtect =>PUP.Optional.AgentODR
HKLM\SOFTWARE\Wow6432Node\InstallShield
HKLM\SOFTWARE\Wow6432Node\Intel
HKLM\SOFTWARE\Wow6432Node\Internet Download Manager
HKLM\SOFTWARE\Wow6432Node\JavaSoft
HKLM\SOFTWARE\Wow6432Node\JreMetrics
HKLM\SOFTWARE\Wow6432Node\Khronos
HKLM\SOFTWARE\Wow6432Node\KMPlayer
HKLM\SOFTWARE\Wow6432Node\Licenses
HKLM\SOFTWARE\Wow6432Node\LogMeInRescueCallingCard
HKLM\SOFTWARE\Wow6432Node\Macromedia
HKLM\SOFTWARE\Wow6432Node\Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\mtcaMyciloP
HKLM\SOFTWARE\Wow6432Node\mtExtTag
HKLM\SOFTWARE\Wow6432Node\mtSaophase
HKLM\SOFTWARE\Wow6432Node\mtSunlex
HKLM\SOFTWARE\Wow6432Node\MyBrowser
HKLM\SOFTWARE\Wow6432Node\mystartsearchSoftware =>PUP.Optional.StartSearch
HKLM\SOFTWARE\Wow6432Node\Nuance
HKLM\SOFTWARE\Wow6432Node\ODBC
HKLM\SOFTWARE\Wow6432Node\Opera Software
HKLM\SOFTWARE\Wow6432Node\PowerPivot
HKLM\SOFTWARE\Wow6432Node\Qualcomm Atheros WLAN and Bluetooth Client Installation Program
HKLM\SOFTWARE\Wow6432Node\Realtek
HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\Reg
HKLM\SOFTWARE\Wow6432Node\rising
HKLM\SOFTWARE\Wow6432Node\RisingRepire
HKLM\SOFTWARE\Wow6432Node\Rtp
HKLM\SOFTWARE\Wow6432Node\Skype
HKLM\SOFTWARE\Wow6432Node\SupDp =>PUP.Optional.SupTab
HKLM\SOFTWARE\Wow6432Node\Tencent =>PUP.Optional.TencentAddressBar
HKLM\SOFTWARE\Wow6432Node\TuneUp
HKLM\SOFTWARE\Wow6432Node\Uniblue =>PUP.Optional.Uniblue
HKLM\SOFTWARE\Wow6432Node\V9 =>PUP.Optional.V9Software
HKLM\SOFTWARE\Wow6432Node\VideoLAN
HKLM\SOFTWARE\Wow6432Node\Volatile
HKLM\SOFTWARE\Wow6432Node\WdsManPro =>PUP.Optional.WdsManPro
HKLM\SOFTWARE\Wow6432Node\winzipersvc
HKLM\SOFTWARE\Wow6432Node\YorkNewCin =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications
HKCU\SOFTWARE\2b2RrGv7szQYWaB4Y
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\AnyProtect =>PUP.Optional.AnyProtect
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\ArenaHD =>PUP.Optional.CrossRider
HKCU\SOFTWARE\Atheros
HKCU\SOFTWARE\Chromium
HKCU\SOFTWARE\Cinem Plus 2.4cV28.08-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\CinemaPlus-3.2cV04.09-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\CinemaPlus-3.2cV07.09-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\CinemaPlus-3.2cV29.08-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\Crossbrowse =>PUP.Optional.CrossBrowse
HKCU\SOFTWARE\DownloadManager
HKCU\SOFTWARE\Elantech
HKCU\SOFTWARE\globalUpdate =>PUP.Optional.GlobalUpdate
HKCU\SOFTWARE\GoHD-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\GRETECH
HKCU\SOFTWARE\HighDefAction =>PUP.Optional.CrossRider
HKCU\SOFTWARE\I0DS96c2PVs6MbviWTsBaDMNYr
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\InstallPath
HKCU\SOFTWARE\Intel
HKCU\SOFTWARE\JavaSoft
HKCU\SOFTWARE\KMPlayer
HKCU\SOFTWARE\LG Electronics
HKCU\SOFTWARE\Licenses
HKCU\SOFTWARE\Local AppWizard-Generated Applications
HKCU\SOFTWARE\LogMeInRescueCallingCard
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\Mine
HKCU\SOFTWARE\Mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\mtcaMyciloP
HKCU\SOFTWARE\mtExtTag
HKCU\SOFTWARE\mtSaophase
HKCU\SOFTWARE\MyBrowser =>PUP.Optional.MyBrowser
HKCU\SOFTWARE\Netscape
HKCU\SOFTWARE\OB
HKCU\SOFTWARE\ODBC
HKCU\SOFTWARE\OEM
HKCU\SOFTWARE\Opera Software
HKCU\SOFTWARE\PriceFountain =>PUP.Optional.PriceFountain
HKCU\SOFTWARE\Realtek
HKCU\SOFTWARE\Reg
HKCU\SOFTWARE\RegisteredApplications
HKCU\SOFTWARE\Rtp
HKCU\SOFTWARE\SavePass 1.1-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\Shop and Save Up-nv-ie =>PUP.Optional.ShopSave
HKCU\SOFTWARE\Skype
HKCU\SOFTWARE\SYNCJM
HKCU\SOFTWARE\Tencent =>PUP.Optional.TencentAddressBar
HKCU\SOFTWARE\TuneUp
HKCU\SOFTWARE\Unity
HKCU\SOFTWARE\uP8iSTDiLScoe4n9edgWWBW
HKCU\SOFTWARE\WinRAR
HKCU\SOFTWARE\WinRAR SFX
HKCU\SOFTWARE\Wow6432Node
HKCU\SOFTWARE\YorkNewCin =>PUP.Optional.CrossRider
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\AppDataLow\Software
HKCU\SOFTWARE\AppDataLow\Software\Crossrider =>PUP.Optional.CrossRider
HKCU\SOFTWARE\AppDataLow\Software\JavaSoft
HKCU\SOFTWARE\AppDataLow\Software\Unity

---\\ Contenu des dossiers Programmes (196) - 4s
O43 - CFD: 2015/09/08 17:01:35 - [] D -- C:\Program Files (x86)\597D1CB4-1440766203-E311-AEEE-F8A9630E110A =>PUP.Optional.CrossRider
O43 - CFD: 2015/09/09 15:27:25 - [] D -- C:\Program Files (x86)\Adobe
O43 - CFD: 2015/08/29 11:47:42 - [] D -- C:\Program Files (x86)\Adware Removal Tool by TSA
O43 - CFD: 2015/08/29 22:02:49 - [] D -- C:\Program Files (x86)\baidu
O43 - CFD: 2015/08/28 13:52:47 - [0] D -- C:\Program Files (x86)\c9329db9-4161-4320-8666-1785b0e0b3f0 =>PUP.Optional.CrossRider
O43 - CFD: 2015/09/03 09:16:29 - [] D -- C:\Program Files (x86)\Common Files
O43 - CFD: 2015/09/09 22:45:03 - [] D -- C:\Program Files (x86)\globalUpdate =>PUP.Optional.GlobalUpdate
O43 - CFD: 2014/11/16 17:15:40 - [] D -- C:\Program Files (x86)\Google
O43 - CFD: 2014/11/07 15:52:49 - [] D -- C:\Program Files (x86)\GRETECH
O43 - CFD: 2014/12/15 16:24:45 - [] D -- C:\Program Files (x86)\HDD Regenerator
O43 - CFD: 2015/08/29 17:29:00 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 2014/11/07 22:29:24 - [] D -- C:\Program Files (x86)\Intel
O43 - CFD: 2014/11/16 17:37:32 - [] D -- C:\Program Files (x86)\Internet Download Manager
O43 - CFD: 2015/09/03 08:46:17 - [] D -- C:\Program Files (x86)\Internet Explorer
O43 - CFD: 2015/08/28 14:10:37 - [] D -- C:\Program Files (x86)\Java
O43 - CFD: 2015/08/28 14:05:48 - [] D -- C:\Program Files (x86)\LG Electronics
O43 - CFD: 2014/11/07 16:09:39 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services
O43 - CFD: 2014/11/07 16:09:31 - [] D -- C:\Program Files (x86)\Microsoft Office
O43 - CFD: 2015/09/10 19:34:58 - [] D -- C:\Program Files (x86)\Microsoft Silverlight
O43 - CFD: 2014/11/07 16:15:09 - [] D -- C:\Program Files (x86)\Microsoft SQL Server
O43 - CFD: 2015/09/03 09:16:31 - [] D -- C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 2015/09/10 19:51:09 - [] D -- C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 2015/09/10 19:51:08 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service
O43 - CFD: 2015/09/03 08:36:13 - [] D -- C:\Program Files (x86)\MSBuild
O43 - CFD: 2015/08/28 13:57:41 - [] D -- C:\Program Files (x86)\Opera
O43 - CFD: 2014/11/07 21:35:31 - [] D -- C:\Program Files (x86)\Panasonic
O43 - CFD: 2015/09/03 09:16:35 - [] D -- C:\Program Files (x86)\Qualcomm Atheros
O43 - CFD: 2014/11/07 22:33:36 - [] D -- C:\Program Files (x86)\Realtek
O43 - CFD: 2015/09/03 08:36:13 - [] D -- C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 2015/08/29 12:00:43 - [] D -- C:\Program Files (x86)\Rising
O43 - CFD: 2014/11/07 22:34:33 - [0] HD -- C:\Program Files (x86)\Temp
O43 - CFD: 2015/08/28 15:00:29 - [] D -- C:\Program Files (x86)\Tencent =>PUP.Optional.TencentAddressBar
O43 - CFD: 2015/08/29 16:06:29 - [] D -- C:\Program Files (x86)\VAP11G
O43 - CFD: 2014/11/07 15:57:52 - [] D -- C:\Program Files (x86)\VideoLAN
O43 - CFD: 2015/07/10 17:23:55 - [] D -- C:\Program Files (x86)\Windows Defender
O43 - CFD: 2015/08/29 15:11:56 - [] D -- C:\Program Files (x86)\Windows Loader
O43 - CFD: 2015/09/03 09:16:37 - [] D -- C:\Program Files (x86)\Windows Mail
O43 - CFD: 2015/07/10 17:23:55 - [] D -- C:\Program Files (x86)\Windows Media Player
O43 - CFD: 2015/07/10 12:04:26 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform
O43 - CFD: 2015/07/10 12:04:22 - [] D -- C:\Program Files (x86)\Windows NT
O43 - CFD: 2015/07/10 17:23:55 - [] D -- C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 2015/07/10 12:04:26 - [] D -- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 2015/07/10 12:04:22 - [] SHD -- C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 2015/07/10 12:04:22 - [] SD -- C:\Program Files (x86)\WindowsPowerShell
O43 - CFD: 2015/08/28 14:04:46 - [0] D -- C:\Program Files (x86)\WinZipper
O43 - CFD: 2015/07/10 12:04:26 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 2015/07/10 17:28:37 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2015/07/10 12:04:26 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2014/11/07 16:18:57 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
O43 - CFD: 2015/09/03 09:23:26 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM Player
O43 - CFD: 2015/09/07 10:41:23 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 2015/09/03 09:23:26 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
O43 - CFD: 2015/09/03 09:23:26 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
O43 - CFD: 2015/07/10 12:04:26 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2015/09/03 09:23:26 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
O43 - CFD: 2015/09/10 19:35:05 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
O43 - CFD: 2015/07/10 12:04:26 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
O43 - CFD: 2015/07/10 12:04:26 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 2015/07/10 17:28:36 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 2015/09/03 09:23:26 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
O43 - CFD: 2015/09/03 09:23:26 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 2015/09/03 09:16:42 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
O43 - CFD: 2015/08/28 14:24:13 - [] D -- C:\ProgramData\3WinManPro3
O43 - CFD: 2015/08/29 22:02:43 - [0] D -- C:\ProgramData\9WdsManPro9 =>PUP.Optional.WdsManPro
O43 - CFD: 2015/08/29 17:25:18 - [] D -- C:\ProgramData\Adobe
O43 - CFD: 2015/07/10 13:21:38 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 2015/08/28 16:15:30 - [] D -- C:\ProgramData\Application Hosting
O43 - CFD: 2014/11/07 22:43:42 - [] D -- C:\ProgramData\Atheros
O43 - CFD: 2015/08/28 15:47:19 - [] D -- C:\ProgramData\BlueStacksSetup
O43 - CFD: 2014/11/07 19:38:34 - [0] SHD -- C:\ProgramData\Bureau
O43 - CFD: 2015/08/29 22:02:44 - [] D -- C:\ProgramData\caMyciloP
O43 - CFD: 2015/08/28 16:52:59 - [] D -- C:\ProgramData\caMyciloPs
O43 - CFD: 2014/11/07 16:35:42 - [] HD -- C:\ProgramData\Common Files
O43 - CFD: 2015/07/10 12:04:22 - [0] D -- C:\ProgramData\Comms
O43 - CFD: 2015/07/10 13:21:38 - [0] SHD -- C:\ProgramData\Desktop
O43 - CFD: 2015/07/10 13:21:38 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 2015/08/29 22:02:45 - [] D -- C:\ProgramData\ExtTag =>PUP.Optional.ExtTag
O43 - CFD: 2015/08/29 09:49:33 - [] D -- C:\ProgramData\ExtTags =>PUP.Optional.ExtTag
O43 - CFD: 2014/11/07 16:35:24 - [] D -- C:\ProgramData\GRETECH
O43 - CFD: 2015/08/29 22:02:46 - [0] D -- C:\ProgramData\IcyCarje =>PUP.Optional.PennyBee
O43 - CFD: 2014/11/07 16:27:19 - [0] D -- C:\ProgramData\IDM
O43 - CFD: 2014/11/07 22:29:26 - [] D -- C:\ProgramData\Intel
O43 - CFD: 2015/08/28 14:31:47 - [0] D -- C:\ProgramData\IQIYI Video =>PUP.Optional.IQIYIVideo
O43 - CFD: 2015/09/08 17:00:22 - [] D -- C:\ProgramData\lWdsManProl =>PUP.Optional.WdsManPro
O43 - CFD: 2014/11/07 19:38:34 - [0] SHD -- C:\ProgramData\Menu Démarrer
O43 - CFD: 2015/09/03 09:16:43 - [] SD -- C:\ProgramData\Microsoft
O43 - CFD: 2015/09/09 22:13:44 - [] D -- C:\ProgramData\Microsoft Help
O43 - CFD: 2015/09/03 09:41:03 - [] D -- C:\ProgramData\Microsoft OneDrive
O43 - CFD: 2014/11/07 16:19:50 - [] D -- C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS
O43 - CFD: 2014/11/07 19:38:34 - [0] SHD -- C:\ProgramData\Modèles
O43 - CFD: 2015/09/01 20:03:04 - [] D -- C:\ProgramData\MWdsManProM =>PUP.Optional.WdsManPro
O43 - CFD: 2015/08/29 22:02:46 - [] D -- C:\ProgramData\nWdsManPron =>PUP.Optional.WdsManPro
O43 - CFD: 2015/08/28 14:10:45 - [] D -- C:\ProgramData\Oracle
O43 - CFD: 2014/11/07 22:37:12 - [] D -- C:\ProgramData\Qualcomm Atheros
O43 - CFD: 2015/09/03 09:23:26 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft
O43 - CFD: 2015/08/29 12:00:44 - [] D -- C:\ProgramData\Rising
O43 - CFD: 2015/09/03 19:15:14 - [] D -- C:\ProgramData\Saophase
O43 - CFD: 2015/08/29 19:21:24 - [] D -- C:\ProgramData\Saophases
O43 - CFD: 2015/08/28 14:04:22 - [] D -- C:\ProgramData\Skype
O43 - CFD: 2015/09/10 19:40:54 - [] D -- C:\ProgramData\SoftwareDistribution
O43 - CFD: 2015/07/10 13:21:38 - [0] SHD -- C:\ProgramData\Start Menu
O43 - CFD: 2015/06/29 23:56:01 - [] D -- C:\ProgramData\Sun
O43 - CFD: 2015/08/28 13:52:53 - [] D -- C:\ProgramData\Sunlexs
O43 - CFD: 2015/08/30 21:40:35 - [] D -- C:\ProgramData\SWdsManProS =>PUP.Optional.WdsManPro
O43 - CFD: 2014/12/15 16:29:21 - [0] AD -- C:\ProgramData\TEMP
O43 - CFD: 2015/07/10 13:21:38 - [0] SHD -- C:\ProgramData\Templates
O43 - CFD: 2015/08/28 15:03:51 - [] D -- C:\ProgramData\Tencent =>PUP.Optional.TencentAddressBar
O43 - CFD: 2014/11/07 16:38:09 - [] D -- C:\ProgramData\TuneUp Software
O43 - CFD: 2015/09/02 20:02:33 - [0] D -- C:\ProgramData\tWdsManProt =>PUP.Optional.WdsManPro
O43 - CFD: 2015/08/28 15:03:44 - [0] D -- C:\ProgramData\TXQMPC
O43 - CFD: 2015/07/10 13:22:45 - [] D -- C:\ProgramData\USOPrivate
O43 - CFD: 2015/07/10 13:22:45 - [] D -- C:\ProgramData\USOShared
O43 - CFD: 2015/08/29 21:12:05 - [] D -- C:\ProgramData\{b5c6c508-0777-b4a6-b5c6-6c5080771420}
O43 - CFD: 2014/11/07 16:41:09 - [0] SHD -- C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
O43 - CFD: 2014/11/07 22:46:07 - [] D -- C:\Program Files (x86)\Common Files\Adobe
O43 - CFD: 2014/11/07 22:38:11 - [] D -- C:\Program Files (x86)\Common Files\Atheros
O43 - CFD: 2014/11/07 22:33:33 - [] D -- C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 2015/09/03 09:08:39 - [] D -- C:\Program Files (x86)\Common Files\Intel
O43 - CFD: 2015/08/28 14:10:29 - [] D -- C:\Program Files (x86)\Common Files\Java
O43 - CFD: 2015/09/03 09:16:29 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared
O43 - CFD: 2014/11/07 22:28:57 - [] D -- C:\Program Files (x86)\Common Files\postureAgent
O43 - CFD: 2015/07/10 12:04:26 - [] D -- C:\Program Files (x86)\Common Files\Services
O43 - CFD: 2015/07/10 17:23:55 - [] D -- C:\Program Files (x86)\Common Files\System
O43 - CFD: 2015/08/29 13:02:11 - [] D -- C:\Program Files (x86)\Common Files\Tencent =>PUP.Optional.TencentAddressBar
O43 - CFD: 2015/08/29 14:34:11 - [] D -- C:\Users\acer i\AppData\Roaming\Adobe
O43 - CFD: 2015/08/29 16:58:52 - [] SHD -- C:\Users\acer i\AppData\Roaming\AnyProtectEx =>PUP.Optional.AnyProtect
O43 - CFD: 2015/08/30 20:12:22 - [] D -- C:\Users\acer i\AppData\Roaming\Atheros
O43 - CFD: 2015/09/13 15:43:37 - [] D -- C:\Users\acer i\AppData\Roaming\DMCache
O43 - CFD: 2014/11/07 16:32:14 - [] D -- C:\Users\acer i\AppData\Roaming\GRETECH
O43 - CFD: 2015/04/28 19:26:36 - [] D -- C:\Users\acer i\AppData\Roaming\Identities
O43 - CFD: 2015/06/09 15:35:18 - [] D -- C:\Users\acer i\AppData\Roaming\IDM
O43 - CFD: 2015/08/28 14:24:39 - [] D -- C:\Users\acer i\AppData\Roaming\IQIYI Video =>PUP.Optional.IQIYIVideo
O43 - CFD: 2014/11/12 14:31:59 - [] D -- C:\Users\acer i\AppData\Roaming\Macromedia
O43 - CFD: 2015/09/03 14:04:10 - [] SD -- C:\Users\acer i\AppData\Roaming\Microsoft
O43 - CFD: 2015/09/10 19:51:23 - [] D -- C:\Users\acer i\AppData\Roaming\Mozilla
O43 - CFD: 2015/06/21 15:02:30 - [] D -- C:\Users\acer i\AppData\Roaming\OpenCandy =>PUP.Optional.OpenCandy
O43 - CFD: 2015/08/28 13:57:32 - [0] D -- C:\Users\acer i\AppData\Roaming\Opera Software
O43 - CFD: 2015/08/28 14:22:54 - [] D -- C:\Users\acer i\AppData\Roaming\PriceFountain =>PUP.Optional.PriceFountain
O43 - CFD: 2015/08/28 13:30:30 - [] D -- C:\Users\acer i\AppData\Roaming\Skype
O43 - CFD: 2015/08/28 14:10:11 - [] D -- C:\Users\acer i\AppData\Roaming\Sun
O43 - CFD: 2015/08/28 15:40:58 - [] D -- C:\Users\acer i\AppData\Roaming\Tencent =>PUP.Optional.TencentAddressBar
O43 - CFD: 2014/11/07 16:37:55 - [] D -- C:\Users\acer i\AppData\Roaming\TuneUp Software
O43 - CFD: 2015/09/14 20:58:52 - [] D -- C:\Users\acer i\AppData\Roaming\vlc
O43 - CFD: 2015/04/29 15:53:13 - [] D -- C:\Users\acer i\AppData\Roaming\Windows Loader
O43 - CFD: 2014/11/07 16:26:52 - [] D -- C:\Users\acer i\AppData\Roaming\WinRAR
O43 - CFD: 2015/09/15 08:27:23 - [] D -- C:\Users\acer i\AppData\Roaming\ZHP
O43 - CFD: 2015/08/29 22:02:49 - [] D -- C:\Users\acer i\AppData\Local\597D1CB4-1440769858-E311-AEEE-F8A9630E110A
O43 - CFD: 2015/09/02 20:01:49 - [] D -- C:\Users\acer i\AppData\Local\9C8A768C-B357-41C0-963C-BF664363440
O43 - CFD: 2015/08/29 14:34:11 - [] D -- C:\Users\acer i\AppData\Local\Adobe
O43 - CFD: 2015/09/03 09:13:51 - [0] SHD -- C:\Users\acer i\AppData\Local\Application Data
O43 - CFD: 2014/11/07 22:44:18 - [] D -- C:\Users\acer i\AppData\Local\AutorunX2
O43 - CFD: 2014/11/07 22:43:43 - [] D -- C:\Users\acer i\AppData\Local\BMExplorer
O43 - CFD: 2015/09/03 09:38:48 - [] D -- C:\Users\acer i\AppData\Local\Comms
O43 - CFD: 2015/08/30 14:23:30 - [] D -- C:\Users\acer i\AppData\Local\CrashDumps
O43 - CFD: 2014/11/08 21:08:46 - [] D -- C:\Users\acer i\AppData\Local\CrashRpt =>.Superfluous.CrashReports
O43 - CFD: 2015/03/25 19:52:07 - [0] D -- C:\Users\acer i\AppData\Local\Diagnostics
O43 - CFD: 2014/12/14 23:18:56 - [] D -- C:\Users\acer i\AppData\Local\Downloaded Installations
O43 - CFD: 2015/08/28 13:57:33 - [0] SHD -- C:\Users\acer i\AppData\Local\EmieBrowserModeList
O43 - CFD: 2015/08/28 13:57:32 - [0] SHD -- C:\Users\acer i\AppData\Local\EmieSiteList
O43 - CFD: 2015/08/28 13:57:33 - [0] SHD -- C:\Users\acer i\AppData\Local\EmieUserList
O43 - CFD: 2015/09/04 19:49:37 - [] D -- C:\Users\acer i\AppData\Local\globalUpdate =>PUP.Optional.GlobalUpdate
O43 - CFD: 2015/09/10 21:45:24 - [] D -- C:\Users\acer i\AppData\Local\Google
O43 - CFD: 2015/06/03 20:23:18 - [] D -- C:\Users\acer i\AppData\Local\GWX
O43 - CFD: 2015/09/03 09:13:51 - [0] SHD -- C:\Users\acer i\AppData\Local\Historique
O43 - CFD: 2014/11/07 17:02:05 - [] D -- C:\Users\acer i\AppData\Local\Intel_Corporation
O43 - CFD: 2015/09/03 13:00:12 - [] D -- C:\Users\acer i\AppData\Local\Microsoft
O43 - CFD: 2014/11/07 16:09:31 - [0] D -- C:\Users\acer i\AppData\Local\Microsoft Help
O43 - CFD: 2015/09/03 09:44:32 - [] D -- C:\Users\acer i\AppData\Local\MicrosoftEdge
O43 - CFD: 2015/09/11 14:05:01 - [] D -- C:\Users\acer i\AppData\Local\Mozilla
O43 - CFD: 2015/09/03 09:41:23 - [0] D -- C:\Users\acer i\AppData\Local\NetworkTiles
O43 - CFD: 2015/08/28 13:57:36 - [0] D -- C:\Users\acer i\AppData\Local\Opera Software
O43 - CFD: 2015/09/13 14:33:50 - [] D -- C:\Users\acer i\AppData\Local\Packages
O43 - CFD: 2015/09/12 20:13:14 - [] D -- C:\Users\acer i\AppData\Local\Popcorn Time
O43 - CFD: 2015/09/14 21:35:56 - [] D -- C:\Users\acer i\AppData\Local\Popcorn-Time
O43 - CFD: 2014/11/07 19:44:40 - [] D -- C:\Users\acer i\AppData\Local\Programs
O43 - CFD: 2015/09/03 09:39:33 - [] D -- C:\Users\acer i\AppData\Local\Publishers
O43 - CFD: 2015/06/21 15:12:43 - [] D -- C:\Users\acer i\AppData\Local\Skype
O43 - CFD: 2015/08/28 14:26:24 - [] D -- C:\Users\acer i\AppData\Local\SysassistByHotWheel =>PUP.Optional.Generic
O43 - CFD: 2015/09/15 08:27:09 - [] D -- C:\Users\acer i\AppData\Local\Temp
O43 - CFD: 2015/09/03 09:13:51 - [0] SHD -- C:\Users\acer i\AppData\Local\Temporary Internet Files
O43 - CFD: 2015/09/03 09:36:09 - [] D -- C:\Users\acer i\AppData\Local\TileDataLayer
O43 - CFD: 2014/11/07 16:37:55 - [] D -- C:\Users\acer i\AppData\Local\TuneUp Software
O43 - CFD: 2015/08/28 14:29:35 - [0] D -- C:\Users\acer i\AppData\Local\Unity
O43 - CFD: 2015/01/27 14:40:25 - [] D -- C:\Users\acer i\AppData\Local\VirtualStore
O43 - CFD: 2015/07/10 12:04:26 - [] RD -- C:\Users\acer i\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 2015/09/03 09:36:16 - [] RD -- C:\Users\acer i\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2015/09/07 23:36:57 - [] RD -- C:\Users\acer i\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2015/09/03 09:23:26 - [] D -- C:\Users\acer i\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
O43 - CFD: 2015/07/10 12:04:26 - [] D -- C:\Users\acer i\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2015/09/12 20:13:16 - [] D -- C:\Users\acer i\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn Time
O43 - CFD: 2015/09/07 23:36:57 - [] RD -- C:\Users\acer i\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 2015/07/10 12:04:26 - [] RD -- C:\Users\acer i\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 2015/09/03 09:23:26 - [] D -- C:\Users\acer i\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
O43 - CFD: 2015/07/10 12:04:45 - [] RSD -- C:\Users\acer i\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
O43 - CFD: 2015/09/03 09:23:26 - [] D -- C:\Users\acer i\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 2015/08/29 16:57:13 - [0] D -- C:\Users\acer i\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件

---\\ Derniers fichiers créés dans Windows Prefetcher (2) - 6s
O45 - LFCP:[MD5.96EA65585731EBA9D7955BA5706D8651] 2015/09/07 10:43:38 A -- C:\WINDOWS\Prefetch\ANYPROTECT.EXE-1996592C.pf =>PUP.Optional.AnyProtect
O45 - LFCP:[MD5.1A7CB562A6294E4291D146AEB0D05939] 2015/09/09 22:45:03 A -- C:\WINDOWS\Prefetch\GLOBALUPDATE.EXE-35F6B904.pf =>PUP.Optional.GlobalUpdate

---\\ Liste des pilotes du système (58) - 1s
O58 - SDL:2015/07/10 11:59:38 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107360] ©
O58 - SDL:2015/07/10 11:59:38 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135456] ©
O58 - SDL:2015/07/10 11:59:38 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [83296] ©
O58 - SDL:2015/07/10 11:59:38 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259424] ©
O58 - SDL:2015/07/10 11:59:38 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [26976] ©
O58 - SDL:2015/07/10 11:59:38 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [131936] ©
O58 - SDL:2013/08/15 20:13:30 A . (.Qualcomm Atheros Communications, Inc. - Qualcomm Atheros Extensible Wireless LAN de.) -- C:\WINDOWS\System32\drivers\athwbx.sys [3859968] ©
O58 - SDL:2015/07/10 11:59:38 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [17624] ©
O58 - SDL:2013/07/19 14:26:32 A . (.Broadcom Corporation - Broadcom SD 3.0 Driver.) -- C:\WINDOWS\System32\drivers\bScsiSDa.sys [82128] ©
O58 - SDL:2013/09/07 01:29:14 A . (.Qualcomm Atheros - Qualcomm Atheros BUS driver.) -- C:\WINDOWS\System32\drivers\btath_bus.sys [34384] ©
O58 - SDL:2015/03/09 09:48:34 A . (.Qualcomm Atheros - Qualcomm Atheros BtFilter Driver.) -- C:\WINDOWS\System32\drivers\btfilter.sys [599240] ©
O58 - SDL:2015/07/10 11:59:38 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [531296] ©
O58 - SDL:2015/09/14 14:24:31 A . (.ELAN Microelectronics Corp. - ETD Kernel Center.) -- C:\WINDOWS\System32\drivers\ETD.sys [525000] ©
O58 - SDL:2015/07/10 11:59:38 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3436896] ©
O58 - SDL:2015/07/10 11:59:38 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64352] ©
O58 - SDL:2015/07/10 11:59:36 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] ©
O58 - SDL:2015/07/10 11:59:36 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [122608] ©
O58 - SDL:2015/07/10 11:59:38 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [673120] ©
O58 - SDL:2015/07/10 11:59:38 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412000] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [424800] ©
O58 - SDL:2014/06/09 09:41:00 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\WINDOWS\System32\drivers\idmwfp.sys [180136] ©
O58 - SDL:2015/07/30 22:45:32 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\igdkmd64.sys [3797960] ©
O58 - SDL:2013/09/09 18:41:07 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\WINDOWS\System32\drivers\IntcDAud.sys [449528] ©
O58 - SDL:2013/08/22 23:51:12 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\intelaud.sys [39320] ©
O58 - SDL:2015/06/26 21:46:16 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\iwdbus.sys [39480] ©
O58 - SDL:2013/07/26 01:01:48 A . (.Broadcom Corporation - Broadcom NetLink (TM) Gigabit Ethernet NDIS.) -- C:\WINDOWS\System32\drivers\k57nd60a.sys [458960] ©
O58 - SDL:2013/07/17 02:59:00 A . (.Acer Incorporated - LMDriver.) -- C:\WINDOWS\System32\drivers\LMDriver.sys [21360] ©
O58 - SDL:2015/07/10 11:59:38 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [108896] ©
O58 - SDL:2015/07/10 11:59:38 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [104800] ©
O58 - SDL:2015/07/10 11:59:38 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [99168] ©
O58 - SDL:2015/07/10 11:59:38 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82784] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59744] ©
O58 - SDL:2015/07/10 11:59:39 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575840] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [705376] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63840] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [76128] ©
O58 - SDL:2009/10/20 19:19:54 A . (.CACE Technologies, Inc. - npf.sys (NT5/6 AMD64) Kernel Driver.) -- C:\WINDOWS\System32\drivers\npf.sys [47632] ©
O58 - SDL:2015/07/10 11:59:39 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150368] ©
O58 - SDL:2015/07/10 11:59:39 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [166240] ©
O58 - SDL:2015/07/10 11:59:39 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [58208] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [58720] ©
O58 - SDL:2013/07/17 02:59:00 A . (.Acer Incorporated - RadioShim.) -- C:\WINDOWS\System32\drivers\RadioShim.sys [14680] ©
O58 - SDL:2013/08/27 13:37:54 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\WINDOWS\System32\drivers\RTKVHD64.sys [3613528] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44896] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81760] ©
O58 - SDL:2014/01/22 09:52:10 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ve.) -- C:\WINDOWS\System32\drivers\ssudbus.sys [108800] ©
O58 - SDL:2014/01/22 09:52:10 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ve.) -- C:\WINDOWS\System32\drivers\ssudmdm.sys [206080] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31072] ©
O58 - SDL:2015/08/28 15:00:47 A . (.Tencent - 电脑管家-TAO游戏启动加速驱动.) -- C:\WINDOWS\System32\drivers\TAOAccelerator64.sys [74040] =>PUP.Optional.TencentAddressBar
O58 - SDL:2015/08/28 15:00:47 A . (.Tencent Technology(Shenzhen) Company Limited - TAOKernel.) -- C:\WINDOWS\System32\drivers\TAOKernel64.sys [274232]
O58 - SDL:2013/08/22 13:40:24 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver.) -- C:\WINDOWS\System32\drivers\tap0901.sys [40664] ©
O58 - SDL:2013/09/04 00:53:44 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\TeeDriverx64.sys [99288] ©
O58 - SDL:2015/08/28 15:00:47 A . (.电脑管家 - 电脑管家-驱动模块.) -- C:\WINDOWS\System32\drivers\TFsFltX64.sys [87864]
O58 - SDL:2015/07/10 11:59:48 A . (...) -- C:\WINDOWS\System32\drivers\Udecx.sys [44032]
O58 - SDL:2015/07/10 11:59:39 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166752] ©
O58 - SDL:2015/07/10 11:59:39 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305504] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [26976] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [59232] ©

---\\ Derniers fichiers modifiés ou crées (Utilisateur) (54) - 34s
O61 - LFC: 2015/09/10 19:48:49 A . (..) -- C:\Users\acer i\Downloads\Firefox Setup Stub 40.0.3.exe [242936]
O61 - LFC: 2015/09/08 19:35:35 A . (..) -- C:\Users\acer i\AppData\Roaming\Microsoft\UProof\CMAdj.12.bin [616]
O61 - LFC: 2015/09/07 18:50:22 A . (.Copyright (C) 2011 Google Inc..) -- C:\Users\acer i\AppData\Local\Popcorn Time\libEGL.dll [73728]
O61 - LFC: 2015/09/07 18:50:22 A . (.Copyright (C) 2011 Google Inc..) -- C:\Users\acer i\AppData\Local\Popcorn Time\libGLESv2.dll [1481728]
O61 - LFC: 2015/09/07 18:50:24 A . (..) -- C:\Users\acer i\AppData\Local\Popcorn Time\nw.exe [46286848]
O61 - LFC: 2015/09/07 18:49:00 A . (..) -- C:\Users\acer i\AppData\Local\Popcorn Time\Popcorn Time.exe [430080]
O61 - LFC: 2015/09/15 08:13:34 A . (..) -- C:\Users\acer i\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\speech_onecorereg.bin [8192]
O61 - LFC: 2015/09/12 13:35:03 A . (.Copyright © 2014.) -- C:\Users\acer i\AppData\Local\Packages\Logicdesign.EnjoyMovies_qr25n2d1fbb3j\AC\Microsoft\CLR_v4.0\NativeImages\MoviePlusLib\4d393b76855811499b63526b695091fb\MoviePlusLib.ni.dll [92160]
O61 - LFC: 2015/09/12 13:35:03 A . (.Copyright © 2014.) -- C:\Users\acer i\AppData\Local\Packages\Logicdesign.EnjoyMovies_qr25n2d1fbb3j\AC\Microsoft\CLR_v4.0\NativeImages\MoviePlusBackEnd\ad5be763ac3bd731a43f5963e6050ca7\MoviePlusBackEnd.ni.dll [377856]
O61 - LFC: 2015/09/13 14:54:02 A . (..) -- C:\Users\acer i\AppData\Local\Packages\GAMELOFTSA.UNOFriends_0pp20fcewvvtj\LocalState\gv3\Batched.bin [1442]
O61 - LFC: 2015/09/13 14:37:59 A . (..) -- C:\Users\acer i\AppData\Local\Packages\GAMELOFTSA.UNOFriends_0pp20fcewvvtj\LocalState\gv3\Device.bin [200]
O61 - LFC: 2015/09/13 14:54:02 A . (..) -- C:\Users\acer i\AppData\Local\Packages\GAMELOFTSA.UNOFriends_0pp20fcewvvtj\LocalState\gv3\Priority.bin [444]
O61 - LFC: 2015/09/13 14:54:01 A . (..) -- C:\Users\acer i\AppData\Local\Packages\GAMELOFTSA.UNOFriends_0pp20fcewvvtj\LocalState\gv3\Sessions.bin [110]
O61 - LFC: 2015/09/13 14:54:03 A . (..) -- C:\Users\acer i\AppData\Local\Packages\GAMELOFTSA.UNOFriends_0pp20fcewvvtj\LocalState\gv3\Stream.bin [1075]
O61 - LFC: 2015/09/13 14:54:03 A . (..) -- C:\Users\acer i\AppData\Local\Packages\GAMELOFTSA.UNOFriends_0pp20fcewvvtj\LocalState\gv3\Timer.bin [152]
O61 - LFC: 2015/09/13 14:54:03 A . (..) -- C:\Users\acer i\AppData\Local\Packages\GAMELOFTSA.UNOFriends_0pp20fcewvvtj\LocalState\gv3\Token.bin [110]
O61 - LFC: 2015/09/14 21:16:58 A . (..) -- C:\Users\acer i\AppData\Local\Packages\GAMELOFTSA.UNOFriends_0pp20fcewvvtj\AC\Microsoft\CLR_v4.0_32\NativeImages\UnoWindows8\1a011a9251cc89c4c1bb9cac69ed255a\UnoWindows8.ni.dll [138752]
O61 - LFC: 2015/09/14 21:16:56 A . (.Copyright © 2014.) -- C:\Users\acer i\AppData\Local\Packages\GAMELOFTSA.UNOFriends_0pp20fcewvvtj\AC\Microsoft\CLR_v4.0_32\NativeImages\InGameBrowserLibrary\f65b88dadaf456dcc1b9c6abe035781f\InGameBrowserLibrary.ni.dll [80896]
O61 - LFC: 2015/09/14 21:16:51 A . (.Copyright © 2012.) -- C:\Users\acer i\AppData\Local\Packages\GAMELOFTSA.UNOFriends_0pp20fcewvvtj\AC\Microsoft\CLR_v4.0_32\NativeImages\IGPWindows8\de1f4f3f23b120fdc2ea385c6750429f\IGPWindows8.ni.dll [241664]
O61 - LFC: 2015/09/14 21:16:41 A . (.Copyright © 2012.) -- C:\Users\acer i\AppData\Local\Packages\GAMELOFTSA.UNOFriends_0pp20fcewvvtj\AC\Microsoft\CLR_v4.0_32\NativeImages\IGPBridgeLibrary\a059fe08881c94214746bdb0f8eb1dbc\IGPBridgeLibrary.ni.dll [132608]
O61 - LFC: 2015/09/14 21:16:25 A . (.Gameloft.) -- C:\Users\acer i\AppData\Local\Packages\GAMELOFTSA.UNOFriends_0pp20fcewvvtj\AC\Microsoft\CLR_v4.0_32\NativeImages\GA\1a8e9d2a0d231fa44068105fd4a34bf2\GA.ni.dll [120320]
O61 - LFC: 2015/09/14 21:16:38 A . (.Copyright © 2013.) -- C:\Users\acer i\AppData\Local\Packages\GAMELOFTSA.UNOFriends_0pp20fcewvvtj\AC\Microsoft\CLR_v4.0_32\NativeImages\FacebookRun67b5d43e#\cb2f9f51b3f9e54a2c3afdea0a2c049a\FacebookRuntimeComponent.ni.dll [325120]
O61 - LFC: 2015/09/14 21:17:06 A . (.The Outercurve Foundation.) -- C:\Users\acer i\AppData\Local\Packages\GAMELOFTSA.UNOFriends_0pp20fcewvvtj\AC\Microsoft\CLR_v4.0_32\NativeImages\Facebook\172defcb2677c689797b3e685edd38fd\Facebook.ni.dll [466944]
O61 - LFC: 2015/09/12 13:35:02 A . (.Schulte Software Development.) -- C:\Users\acer i\AppData\Local\Packages\Facebook.Facebook_8xx8rvfyw5nnt\AC\Microsoft\CLR_v4.0\NativeImages\WriteableBi1788e114#\c1baed466d570e75ffdc8d428f34e69e\WriteableBitmapEx.WinRT.ni.dll [327168]
O61 - LFC: 2015/09/12 13:35:02 A . (..) -- C:\Users\acer i\AppData\Local\Packages\Facebook.Facebook_8xx8rvfyw5nnt\AC\Microsoft\CLR_v4.0\NativeImages\Notificatioc5a47191#\8be872644830a455bd8f305ccc3e17db\NotificationsExtensions.ni.dll [572928]
O61 - LFC: 2015/09/12 13:34:50 A . (.Copyright © 2013.) -- C:\Users\acer i\AppData\Local\Packages\Facebook.Facebook_8xx8rvfyw5nnt\AC\Microsoft\CLR_v4.0\NativeImages\Facebook-Win8-Base\315bad43ccab4cab44edce07e7a29626\Facebook-Win8-Base.ni.dll [1054208]
O61 - LFC: 2015/09/12 13:34:55 A . (.Copyright © 2013.) -- C:\Users\acer i\AppData\Local\Packages\Facebook.Facebook_8xx8rvfyw5nnt\AC\Microsoft\CLR_v4.0\NativeImages\Facebook-Services\624df8ced88b437e5f2ec772ebb9847d\Facebook-Services.ni.dll [5077504]
O61 - LFC: 2015/09/12 13:35:01 A . (.Copyright © 2013.) -- C:\Users\acer i\AppData\Local\Packages\Facebook.Facebook_8xx8rvfyw5nnt\AC\Microsoft\CLR_v4.0\NativeImages\Facebook-No02b98c3e#\f3e7ab46a558eaa1f53a85908a260972\Facebook-Notifications.ni.dll [20992]
O61 - LFC: 2015/09/12 13:34:56 A . (.Copyright © 2013.) -- C:\Users\acer i\AppData\Local\Packages\Facebook.Facebook_8xx8rvfyw5nnt\AC\Microsoft\CLR_v4.0\NativeImages\Facebook-Models\a0c63900ca4366a3cfa4f18d7079697d\Facebook-Models.ni.dll [1098240]
O61 - LFC: 2015/09/12 13:34:51 A . (.Copyright © 2013.) -- C:\Users\acer i\AppData\Local\Packages\Facebook.Facebook_8xx8rvfyw5nnt\AC\Microsoft\CLR_v4.0\NativeImages\Facebook-Base\d2b5c969d217047f2c5e028f38d15074\Facebook-Base.ni.dll [557568]
O61 - LFC: 2015/09/12 13:34:49 A . (.Copyright © 2013.) -- C:\Users\acer i\AppData\Local\Packages\Facebook.Facebook_8xx8rvfyw5nnt\AC\Microsoft\CLR_v4.0\NativeImages\Facebook\9b4b7168d49bb0cb3083f1fb09c9f88c\Facebook.ni.exe [10094080]
O61 - LFC: 2015/09/12 13:34:58 A . (..) -- C:\Users\acer i\AppData\Local\Packages\Facebook.Facebook_8xx8rvfyw5nnt\AC\Microsoft\CLR_v4.0\NativeImages\Bing.Maps\3be9d02df87a03df6fb0a9b04a4a6c89\Bing.Maps.ni.dll [1305600]
O61 - LFC: 2015/09/12 13:34:52 A . (.Autofac Project - http://autofac.org.) -- C:\Users\acer i\AppData\Local\Packages\Facebook.Facebook_8xx8rvfyw5nnt\AC\Microsoft\CLR_v4.0\NativeImages\Autofac\925d3a64cef63401c95d8a9291aa0312\Autofac.ni.dll [987648]
O61 - LFC: 2015/09/12 13:34:41 A . (.Simon Mourier.) -- C:\Users\acer i\AppData\Local\Packages\7093ShaymaaMustafa.HDMovies_7d5g2ce8hap8g\AC\Microsoft\CLR_v4.0\NativeImages\HtmlAgilityPack\ad09b570e308fc18b4e0f35900b4e71f\HtmlAgilityPack.ni.dll [413696]
O61 - LFC: 2015/09/12 13:34:39 A . (.Aly Ahmed.) -- C:\Users\acer i\AppData\Local\Packages\7093ShaymaaMustafa.HDMovies_7d5g2ce8hap8g\AC\Microsoft\CLR_v4.0\NativeImages\HDMovies\f4a86dbd2622b9bcc4f84b84ead0ea98\HDMovies.ni.exe [1112064]
O61 - LFC: 2015/09/12 13:34:35 A . (.Copyright © 2012.) -- C:\Users\acer i\AppData\Local\Packages\24264Craftbox.Showtime_hqe9ecxhfeext\AC\Microsoft\CLR_v4.0\NativeImages\WindowsRunt7281f979#\fc3502272b8cd168b3611e345bde600c\WindowsRuntimeGoogleAnalytics.ni.dll [25088]
O61 - LFC: 2015/09/12 13:34:36 A . (.Nascent Digital.) -- C:\Users\acer i\AppData\Local\Packages\24264Craftbox.Showtime_hqe9ecxhfeext\AC\Microsoft\CLR_v4.0\NativeImages\Nascent.Goo7f07e5d4#\bdcf427a6124b5b0dfb7d5a2f9c7a6a3\Nascent.GoogleAnalytics.ni.dll [104448]
O61 - LFC: 2015/09/07 10:41:35 A . (.AnyProtect.com.) -- C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\ONGJCPIA\AnyProtect[1].exe [6434816] =>PUP.Optional.AnyProtect
O61 - LFC: 2015/09/07 10:36:14 A . (..) -- C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\ONGJCPIA\cmmdWriter[1].exe [40746]
O61 - LFC: 2015/09/07 10:38:53 A . (..) -- C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\ONGJCPIA\policyname[1].exe [55197]
O61 - LFC: 2015/09/09 15:26:58 A . (.YIDVJ.) -- C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\ONGJCPIA\Reimage[2].exe [837472] =>PUP.Optional.ReImageRepair
O61 - LFC: 2015/09/07 10:36:22 A . (..) -- C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\ONGJCPIA\setup[2].exe [1998408]
O61 - LFC: 2015/09/07 10:39:39 A . (.Cinema PlusV07.09.) -- C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\ONGJCPIA\setup[3].exe [14254824]
O61 - LFC: 2015/09/07 10:39:57 A . (.Copyright 2013.) -- C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\ONGJCPIA\Validate[1].exe [61981]
O61 - LFC: 2015/09/07 10:39:01 A . (..) -- C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\EJLFGOSP\VuuPC_VO2_8907[1].exe [228296] =>PUP.Optional.VuuPC
O61 - LFC: 2015/09/07 10:37:18 A . (..) -- C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\8NT2O7J0\4bbda52393b575e64d530bd478a6717b[1].exe [59769]
O61 - LFC: 2015/09/07 10:36:16 A . (..) -- C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\8NT2O7J0\a7RAuVs[1].exe [165898]
O61 - LFC: 2015/09/07 10:40:00 A . (.CMI Limited.) -- C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\8NT2O7J0\AnyProtectSetup[1].exe [613255] =>PUP.Optional.AnyProtect
O61 - LFC: 2015/09/07 10:36:58 A . (.WillLink.net.) -- C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\8NT2O7J0\cmi_mystartsearch[1].exe [350360] =>PUP.Optional.StartSearch
O61 - LFC: 2015/09/07 10:37:31 A . (..) -- C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\3065MAEL\Bundle_CPUminer[1].exe [100529]
O61 - LFC: 2015/09/07 10:37:26 A . (..) -- C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\3065MAEL\df4a6a3ed77e60d6758afca091ca0c1f[2].exe [83223]
O61 - LFC: 2015/09/07 10:36:29 A . (..) -- C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\3065MAEL\SearchUpdater[1].exe [124154]
O61 - LFC: 2015/09/07 10:37:46 A . (..) -- C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\3065MAEL\smt[1].exe [211114]
O61 - LFC: 2015/09/15 08:16:23 A . (..) -- C:\Users\acer i\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [674082]

---\\ Associations Shell Spawning (10) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe ©
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe ©
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ©
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe ©
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe ©
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S

---\\ Menu de démarrage Internet (12) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe ©
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.mystartsearch.com/ ©
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Internet Explorer\iexplore.ex http://www.mystartsearch.com/ =>PUP.Optional.StartSearch
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©

---\\ Recherche d'infection sur les navigateurs (1) - 2s
O69 - SBI: SearchScopes [HKCU] {ielnksrch} [DefaultScope] - (Search the web) - http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTwkzwGbNf1vT-T6b6EW1p89vdPn8vYuYCxRworQUH5t2SxLjTzAIW3H1fZj66SaPi1gNNMpyPhTSFwbOP4xf-uizRoZOUCUMYRSqZfc39Ol3-9GSdo8FpcG-5tRzO4lU2n0brScp2nVKF7AtnF5EPcvzSb-VzymLvHwbGQ,,&q={searchTerms}

---\\ Enumère les fichiers Crack & Keygen (2) - 57s
O82 - LFC: 2015/01/29 20:08:14 A . (...) -- C:\Users\acer i\Documents\Bluetooth Folder\Windows Loader 2.2.2.exe [598840] =>.Crack,Keygen
O82 - LFC: 2014/03/11 02:30:28 A . (...) -- C:\Users\acer i\AppData\Roaming\Windows Loader\Windows Activator.exe [335360] =>.Crack,Keygen

---\\ Enumère les services démarrés par Svchost (41) - 1s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [192000] ©
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [192000] ©
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\WINDOWS\system32\srvsvc.dll [283136] ©
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\WINDOWS\System32\gpsvc.dll [1335296] ©
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\WINDOWS\System32\ikeext.dll [954368] ©
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\WINDOWS\System32\iphlpsvc.dll [954880] ©
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\WINDOWS\system32\seclogon.dll [31232] ©
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\WINDOWS\System32\appinfo.dll [93696] ©
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\WINDOWS\system32\iscsiexe.dll [151040] ©
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\WINDOWS\System32\eapsvc.dll [106496] ©
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\WINDOWS\system32\schedsvc.dll [1008640] ©
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [226304] ©
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\WINDOWS\System32\browser.dll [133120] ©
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\WINDOWS\system32\profsvc.dll [324608] ©
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [371200] ©
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\WINDOWS\System32\wercplsupport.dll [95744] ©
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\WINDOWS\system32\wlidsvc.dll [2093056] ©
O83 - Search Svchost Services: DcpSvc (DcpSvc) . (.Microsoft Corporation - dcpsvc Task.) -- C:\WINDOWS\system32\dcpsvc.dll [196096] ©
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\WINDOWS\System32\ncasvc.dll [167424] ©
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Service Configuration du réseau.) -- C:\WINDOWS\System32\NetSetupSvc.dll [187392] ©
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\WINDOWS\System32\rasauto.dll [106496] ©
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\WINDOWS\System32\rasmans.dll [679936] ©
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [497152] ©
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\WINDOWS\System32\sens.dll [72192] ©
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\WINDOWS\System32\ipnathlp.dll [452608] ©
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [311808] ©
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\WINDOWS\system32\wuaueng.dll [2235904] ©
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\WINDOWS\System32\qmgr.dll [1168896] ©
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [593920] ©
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\WINDOWS\system32\dmwappushsvc.dll [63488] ©
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\WINDOWS\System32\XblGameSave.dll [1149440] ©
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\WINDOWS\system32\XboxNetApiSvc.dll [1019392] ©
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Mettre à jour la session Orchestrator Core.) -- C:\WINDOWS\system32\usocore.dll [343040] ©
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\WINDOWS\System32\usermgr.dll [717312] ©
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service de géolocalisation.) -- C:\Windows\System32\lfsvc.dll [27136] ©
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - DLL Windows Management Service.) -- C:\Windows\System32\Windows.Internal.Management.dll [267776] ©
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\WINDOWS\System32\XblAuthManager.dll [918016] ©
O83 - Search Svchost Services: RetailDemo (RetailDemo) . (.Microsoft Corporation - RDXService.) -- C:\WINDOWS\system32\RDXService.dll [996352] ©
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\WINDOWS\System32\bdesvc.dll [359936] ©
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\WINDOWS\System32\DeviceSetupManager.dll [237568] ©
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\WINDOWS\system32\themeservice.dll [58368] ©

---\\ Liste des exceptions du parefeu Windows (55) - 5s
O87 - FAEL: "{5B5D72F9-D92C-4502-8CDA-6AE96B9850E2}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-弹窗拦截.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QMAdBlock.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{FA20A817-66D5-4649-AAEB-5C19ADB2B89D}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-帐号宝.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QMAccountProtection.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{62EB9611-6C9D-46E6-AB02-FB9A19F7DAA4}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-路由器管家.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QMRouterMgr.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{8293509F-7CDA-496F-B9B4-842E01473A8A}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-反病毒引擎升级程序.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\TpkUpdate.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{5D466A30-2AC7-470D-8006-9FBCAB7DA504}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-模块升级.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCPatch.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{E5955F1B-B61E-4FCC-B89A-0D3679875E3B}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-卸载程序.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\Uninst.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{A4C97DEE-D6F6-4256-AE6E-1C058A7C0DBF}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-修复器.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQRepair.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{192EF5B6-105A-441F-BD4E-CE35AEEF1170}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-杀毒.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCUpdateAVLib.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{89754195-0F00-46B3-9AE5-99CF5988042B}" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{8F5FF564-07F3-43C7-BF1F-39C0885F5A88}" [In-None-P6-TRUE] .(.Tencent - 腾讯高速下载引擎.) -- C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{A7B877EC-0883-4773-AB4C-E0E192C83139}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-系统优化.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCSysOptimize.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{510C059F-C045-4203-B1D2-B04462BCD627}" [In-None-P6-TRUE] .(.Copyright (C) 2012 - 电脑管家-游戏专区.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCSoftGame.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{5B89DE2C-E2EC-47B0-B18C-8078977E1CAD}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-自升级程序.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QMUpdate\QQPCMgrUpdate.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{184DA124-020F-4720-80F5-0C9F83313F1E}" [In-None-P6-TRUE] .(.Copyright (C) 2012 - 电脑管家-引导启动.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCLaunch.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{03491DE4-AFFC-4A3B-A209-D5C4A82B6667}" [In-None-P6-TRUE] .(.Tencent - 电脑诊所.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCClinic.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{78327E7E-E24A-4FF9-AFC7-E629133C0491}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-日志上传.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCBTU.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{96A297B1-F050-4FF9-8F8C-15077A21FA4F}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-网络流量监控.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\plugins\QMNetMon\QQPCNetFlow.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{2D017C8D-1BCC-4CA7-8AB7-B90818AFFA43}" [In-None-P6-TRUE] .(.Tencent - 软件管理.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCSoftMgr.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{395D7E84-E256-43AA-9557-227718AD800F}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-设置中心.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPConfig.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{00CE1917-247F-4AD9-88B6-8D1A84924DE5}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-漏洞扫描.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCLeakScan.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{588BB7A1-DD35-470C-8D0A-E7DAF2E90AFC}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-未知文件打开.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCFileOpen.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{FB8D1DAF-6560-4BD8-B18C-4277C91C4645}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-crash上报.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\bugreport.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{EDACF75D-4421-4AEB-BAC2-32AE37BB5245}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-下载中心.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QMDL.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{D8E49146-8914-409A-BB13-E866B11519C9}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-实时防护服务.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCRTP.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{8F841AAA-903C-4784-872C-6437314669BB}" [In-None-P6-TRUE] .(.Tencent - 电脑管家.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCMgr.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{2632F064-A205-4AA2-8817-AF527BA81335}" [In-None-P6-TRUE] .(.Tencent - 电脑管家.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCTray.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{1A8ECFCF-73E3-4875-9500-E38F29E50F02}" [In-None-P6-TRUE] .(.Tencent - 电脑管家-安装引导.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCmgrInstallGuide.exe =>PUP.Optional.TencentAddressBar
O87 - FAEL: "{C7EB50BA-292D-4EA1-BE81-7780D679DAEE}" [In-None-P6-TRUE] .(...) -- C:\IQIYI Video\LStyle\QyPlayer.exe (.not file.) =>PUP.Optional.IQIYIVideo
O87 - FAEL: "{D3079568-0CC4-4F43-9BFC-70ECCD8401EA}" [In-None-P6-TRUE] .(...) -- C:\IQIYI Video\Common\QyKernel.exe (.not file.) =>PUP.Optional.IQIYIVideo
O87 - FAEL: "{5427A370-BDDD-417E-BD84-6373FBE89FBB}" [In-None-P6-TRUE] .(...) -- C:\IQIYI Video\LStyle\QyWebPlayer.exe (.not file.) =>PUP.Optional.IQIYIVideo
O87 - FAEL: "{BB3F147D-40BB-4C9F-B994-F1FF48E5E270}" [In-None-P6-TRUE] .(...) -- C:\IQIYI Video\LStyle\QyClient.exe (.not file.) =>PUP.Optional.IQIYIVideo
O87 - FAEL: "{3AC7E28A-0ACA-4B17-B451-EB5744AEAA0A}" [In-None-P6-TRUE] .(...) -- C:\Users\acer i\AppData\Roaming\IQIYI Video\LStyle\QyUpdate.exe (.not file.) =>PUP.Optional.IQIYIVideo
O87 - FAEL: "{11E080DA-F113-4B36-BCA3-36EC96F43853}" [In-None-P6-TRUE] .(.爱奇艺 - 爱奇艺万能播放器.) -- C:\IQIYI Video\GeePlayer\GeePlayer.exe =>PUP.Optional.IQIYIVideo
O87 - FAEL: "{CA6A11B1-3932-4A85-8CC0-3D6ACD84EAB3}" [In-None-P17-TRUE] .(...) -- C:\ProgramData\IcyCarje\gigoamaw.exe (.not file.) =>PUP.Optional.PennyBee
O87 - FAEL: "{E8BB28BF-509A-4E41-B43F-567CA41189D4}" [In-None-P6-TRUE] .(...) -- C:\ProgramData\IcyCarje\gigoamaw.exe (.not file.) =>PUP.Optional.PennyBee
O87 - FAEL: "{27032E54-2A5A-475C-9957-5BA8054FF16B}" [In-None-P17-TRUE] .(...) -- C:\ProgramData\IcyCarje\gigoamaw.exe (.not file.) =>PUP.Optional.PennyBee
O87 - FAEL: "{08A0F07A-382E-4066-B971-FFB5D55EED40}" [In-None-P6-TRUE] .(...) -- C:\ProgramData\IcyCarje\gigoamaw.exe (.not file.) =>PUP.Optional.PennyBee
O87 - FAEL: "{FCA0C667-2D14-4664-9C3B-F2D37635D197}" [In-None-P17-TRUE] .(...) -- C:\Users\acer i\AppData\Roaming\uTorrent\uTorrent.exe (.not file.)
O87 - FAEL: "{FC5EA2F2-04BB-4B7B-92B5-306AE586FA18}" [In-None-P6-TRUE] .(...) -- C:\Users\acer i\AppData\Roaming\uTorrent\uTorrent.exe (.not file.)
O87 - FAEL: "{CE359F21-5338-4A57-B705-2C43B52377C0}" [In-None-P17-TRUE] .(...) -- C:\Program Files\KMSpico\Service_KMS.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{CDDE2ED5-A741-4089-8899-43A5E841A304}" [In-None-P6-TRUE] .(...) -- C:\Program Files\KMSpico\Service_KMS.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{C96C7FB0-F535-4A3F-A835-C608E160E7A4}" [In-None-P17-TRUE] .(...) -- C:\Program Files\KMSpico\KMSELDI.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{DE9F1A82-A446-45A9-88AA-CF3369381536}" [In-None-P6-TRUE] .(...) -- C:\Program Files\KMSpico\KMSELDI.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{67C6F627-5D39-448E-ACE5-EB900A185ED9}" [In-None-P17-TRUE] .(...) -- C:\Program Files\KMSpico\Service_KMS.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{7D018517-7894-49C4-AFFD-6A5662EC9F2E}" [In-None-P6-TRUE] .(...) -- C:\Program Files\KMSpico\Service_KMS.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{88612FA8-B2D0-45B3-A2A5-D51BEBF8A981}" [In-None-P17-TRUE] .(...) -- C:\Windows\System32\KMSServer.exe (.not file.)
O87 - FAEL: "{C359993D-70CE-4BE3-BB63-9A50E85F5B98}" [In-None-P6-TRUE] .(...) -- C:\Windows\System32\KMSServer.exe (.not file.)
O87 - FAEL: "{C8E4930E-B2AA-4C5F-BDDD-DAEE1D0BDF7C}" [In-None-P17-TRUE] .(...) -- C:\Program Files\KMSpico\AutoPico.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{191A24D5-83F3-44E2-8D4F-8EC9ACEE566E}" [In-None-P6-TRUE] .(...) -- C:\Program Files\KMSpico\AutoPico.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{1CF9D6AE-9D73-467D-9937-648D8BCC4DBA}" [In-None-P17-TRUE] .(...) -- C:\Windows\System32\KMSServer.exe (.not file.)
O87 - FAEL: "{10FDEE08-E359-412A-92A0-ED983B10EB10}" [In-None-P6-TRUE] .(...) -- C:\Windows\System32\KMSServer.exe (.not file.)
O87 - FAEL: "{5EAD16A6-1537-42DE-A560-DEC2B42732CD}" [In-None-P17-TRUE] .(...) -- C:\Program Files\KMSpico\AutoPico.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{A741BD4F-4AE5-403F-ADD6-F05FA83465BB}" [In-None-P6-TRUE] .(...) -- C:\Program Files\KMSpico\AutoPico.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{6648B6C7-0E64-4693-A5AE-29E86FB52557}" [In-None-P17-TRUE] .(...) -- C:\Program Files\KMSpico\KMSELDI.exe (.not file.) =>HackTool.KMSpico
O87 - FAEL: "{A6D82BEA-CE5D-47E6-BEC8-B442CE7794A0}" [In-None-P6-TRUE] .(...) -- C:\Program Files\KMSpico\KMSELDI.exe (.not file.) =>HackTool.KMSpico

---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (17) - 19s

SR - Auto [2011/06/06 12:55:28] [ 64952] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe ©
SS - Demand [2015/07/30 22:45:34] [ 290208] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe ©
SR - Auto [2015/09/14 14:24:35] [ 144072] Elan Service (ETDService) . (.ELAN Microelectronics Corp..) - C:\Program Files\Elantech\ETDService.exe ©
SS - Auto [2015/08/28 14:01:45] [ 144200] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ©
SS - Demand [2015/08/28 14:01:45] [ 144200] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ©
SS - Demand [2012/04/24 14:37:56] [ 169752] Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe ©
SR - Auto [2015/07/30 22:45:32] [ 328608] Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation.) - C:\WINDOWS\system32\igfxCUIService.exe ©
SR - Auto [2013/05/11 17:45:38] [ 733696] Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe ©
SS - Demand [2013/05/11 17:45:54] [ 822232] Intel(R) Capability Licensing Service TCP IP Interface (Intel(R) Capability Licensing Service TCP IP Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe ©
SR - Auto [2013/09/04 00:53:42] [ 169432] Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe ©
SR - Auto [2013/09/04 00:53:48] [ 390616] Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe ©
SR - Auto [2013/08/02 18:47:44] [ 457768] Launch Manager Service (LMSvc) . (.Acer Incorporate.) - C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe ©
SS - Demand [2015/08/26 13:46:30] [ 149160] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe ©
SR - Auto [2015/08/28 15:00:35] [ 297608] QQPCMgr RTP Service (QQPCRTP) . (.Tencent.) - C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCRTP.exe =>PUP.Optional.TencentAddressBar
SR - Auto [2015/08/28 16:04:37] [ 196288] Rsd Service (RsMgrSvc) . (.Beijing Rising Information Technology Co., Ltd..) - C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe ©
SS - Demand [2015/08/28 15:00:36] [ 293856] TAOFrame (TAOFrame) . (.Tencent.) - C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\TAOFrame.exe =>PUP.Optional.TencentAddressBar

---\\ Scan Additionnel (114) - 0s
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCRTP.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\npQMExtensionsMozilla.dll =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\TSWebMon64.dat =>PUP.Optional.TencentAddressBar
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCTray.exe =>PUP.Optional.TencentAddressBar
HKLM\SYSTEM\CurrentControlSet\Services\QQPCRTP =>PUP.Optional.TencentAddressBar
HKCU\SOFTWARE\I0DS96c2PVs6MbviWTsBaDMNYr =>PUP.Optional.CrossRider
HKCU\SOFTWARE\uP8iSTDiLScoe4n9edgWWBW =>PUP.Optional.CrossRider
C:\WINDOWS\Tasks\APSnotifierPP1.job =>PUP.Optional.AnyProtect
C:\WINDOWS\Tasks\APSnotifierPP2.job =>PUP.Optional.AnyProtect
C:\WINDOWS\Tasks\APSnotifierPP3.job =>PUP.Optional.AnyProtect
C:\WINDOWS\Tasks\I0DS96c2PVs6MbviWTsBaDMNYr.job =>PUP.Optional.CrossRider
C:\WINDOWS\Tasks\Price Fountain.job =>PUP.Optional.PriceFountain
C:\WINDOWS\Tasks\uP8iSTDiLScoe4n9edgWWBW.job =>PUP.Optional.CrossRider
C:\WINDOWS\System32\Tasks\APSnotifierPP1 =>PUP.Optional.AnyProtect
C:\WINDOWS\System32\Tasks\APSnotifierPP2 =>PUP.Optional.AnyProtect
C:\WINDOWS\System32\Tasks\APSnotifierPP3 =>PUP.Optional.AnyProtect
C:\WINDOWS\System32\Tasks\ASP =>PUP.Optional.Systweak
C:\WINDOWS\System32\Tasks\brbrw_2871 =>PUP.Optional.CrossBrowse
C:\WINDOWS\System32\Tasks\I0DS96c2PVs6MbviWTsBaDMNYr =>PUP.Optional.CrossRider
C:\WINDOWS\System32\Tasks\Price Fountain =>PUP.Optional.PriceFountain
C:\WINDOWS\System32\Tasks\uP8iSTDiLScoe4n9edgWWBW =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\ArenaHD =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Crossbrowse =>PUP.Optional.CrossBrowse
HKLM\SOFTWARE\Wow6432Node\downchecker =>PUP.Optional.DownChecker
HKLM\SOFTWARE\Wow6432Node\GlobalUpdate =>PUP.Optional.GlobalUpdate
HKLM\SOFTWARE\Wow6432Node\HighDefAction =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\IHProtect =>PUP.Optional.AgentODR
HKLM\SOFTWARE\Wow6432Node\mystartsearchSoftware =>PUP.Optional.StartSearch
HKLM\SOFTWARE\Wow6432Node\SupDp =>PUP.Optional.SupTab
HKLM\SOFTWARE\Wow6432Node\Tencent =>PUP.Optional.TencentAddressBar
HKLM\SOFTWARE\Wow6432Node\Uniblue =>PUP.Optional.Uniblue
HKLM\SOFTWARE\Wow6432Node\V9 =>PUP.Optional.V9Software
HKLM\SOFTWARE\Wow6432Node\WdsManPro =>PUP.Optional.WdsManPro
HKLM\SOFTWARE\Wow6432Node\YorkNewCin =>PUP.Optional.CrossRider
HKCU\SOFTWARE\AnyProtect =>PUP.Optional.AnyProtect
HKCU\SOFTWARE\ArenaHD =>PUP.Optional.CrossRider
HKCU\SOFTWARE\Cinem Plus 2.4cV28.08-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\CinemaPlus-3.2cV04.09-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\CinemaPlus-3.2cV07.09-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\CinemaPlus-3.2cV29.08-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\Crossbrowse =>PUP.Optional.CrossBrowse
HKCU\SOFTWARE\globalUpdate =>PUP.Optional.GlobalUpdate
HKCU\SOFTWARE\GoHD-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\HighDefAction =>PUP.Optional.CrossRider
HKCU\SOFTWARE\MyBrowser =>PUP.Optional.MyBrowser
HKCU\SOFTWARE\PriceFountain =>PUP.Optional.PriceFountain
HKCU\SOFTWARE\SavePass 1.1-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\Shop and Save Up-nv-ie =>PUP.Optional.ShopSave
HKCU\SOFTWARE\Tencent =>PUP.Optional.TencentAddressBar
HKCU\SOFTWARE\YorkNewCin =>PUP.Optional.CrossRider
HKCU\SOFTWARE\AppDataLow\Software\Crossrider =>PUP.Optional.CrossRider
C:\Program Files (x86)\597D1CB4-1440766203-E311-AEEE-F8A9630E110A =>PUP.Optional.CrossRider
C:\Program Files (x86)\c9329db9-4161-4320-8666-1785b0e0b3f0 =>PUP.Optional.CrossRider
C:\Program Files (x86)\globalUpdate =>PUP.Optional.GlobalUpdate
C:\Program Files (x86)\Tencent =>PUP.Optional.TencentAddressBar
C:\ProgramData\9WdsManPro9 =>PUP.Optional.WdsManPro
C:\ProgramData\ExtTag =>PUP.Optional.ExtTag
C:\ProgramData\ExtTags =>PUP.Optional.ExtTag
C:\ProgramData\IcyCarje =>PUP.Optional.PennyBee
C:\ProgramData\IQIYI Video =>PUP.Optional.IQIYIVideo
C:\ProgramData\lWdsManProl =>PUP.Optional.WdsManPro
C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS
C:\ProgramData\MWdsManProM =>PUP.Optional.WdsManPro
C:\ProgramData\nWdsManPron =>PUP.Optional.WdsManPro
C:\ProgramData\SWdsManProS =>PUP.Optional.WdsManPro
C:\ProgramData\Tencent =>PUP.Optional.TencentAddressBar
C:\ProgramData\tWdsManProt =>PUP.Optional.WdsManPro
C:\Program Files (x86)\Common Files\Tencent =>PUP.Optional.TencentAddressBar
C:\Users\acer i\AppData\Roaming\AnyProtectEx =>PUP.Optional.AnyProtect
C:\Users\acer i\AppData\Roaming\IQIYI Video =>PUP.Optional.IQIYIVideo
C:\Users\acer i\AppData\Roaming\OpenCandy =>PUP.Optional.OpenCandy
C:\Users\acer i\AppData\Roaming\PriceFountain =>PUP.Optional.PriceFountain
C:\Users\acer i\AppData\Roaming\Tencent =>PUP.Optional.TencentAddressBar
C:\Users\acer i\AppData\Local\CrashRpt =>.Superfluous.CrashReports
C:\Users\acer i\AppData\Local\globalUpdate =>PUP.Optional.GlobalUpdate
C:\Users\acer i\AppData\Local\SysassistByHotWheel =>PUP.Optional.Generic
C:\WINDOWS\Prefetch\ANYPROTECT.EXE-1996592C.pf =>PUP.Optional.AnyProtect
C:\WINDOWS\Prefetch\GLOBALUPDATE.EXE-35F6B904.pf =>PUP.Optional.GlobalUpdate
C:\WINDOWS\System32\drivers\TAOAccelerator64.sys =>PUP.Optional.TencentAddressBar
C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\ONGJCPIA\AnyProtect[1].exe =>PUP.Optional.AnyProtect
C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\ONGJCPIA\Reimage[2].exe =>PUP.Optional.ReImageRepair
C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\EJLFGOSP\VuuPC_VO2_8907[1].exe =>PUP.Optional.VuuPC
C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\8NT2O7J0\AnyProtectSetup[1].exe =>PUP.Optional.AnyProtect
C:\Users\acer i\AppData\Local\Microsoft\Windows\INetCache\IE\8NT2O7J0\cmi_mystartsearch[1].exe =>PUP.Optional.StartSearch
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QMAdBlock.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QMAccountProtection.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QMRouterMgr.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\TpkUpdate.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCPatch.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\Uninst.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQRepair.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCUpdateAVLib.exe =>PUP.Optional.TencentAddressBar
C:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe =>PUP.Optional.TencentAddressBar
C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCSysOptimize.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCSoftGame.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QMUpdate\QQPCMgrUpdate.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCLaunch.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCClinic.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCBTU.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\plugins\QMNetMon\QQPCNetFlow.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCSoftMgr.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPConfig.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCLeakScan.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCFileOpen.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\bugreport.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QMDL.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCMgr.exe =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\QQPCmgrInstallGuide.exe =>PUP.Optional.TencentAddressBar
C:\IQIYI Video\GeePlayer\GeePlayer.exe =>PUP.Optional.IQIYIVideo
HKLM\SYSTEM\CurrentControlSet\Services\TAOFrame =>PUP.Optional.TencentAddressBar
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16600.237\TAOFrame.exe =>PUP.Optional.TencentAddressBar

---\\ Récapitulatif des éléments trouvées sur votre station (28) - 0s
http://www.nicolascoolman.fr/adware-tencentaddressbar/ =>PUP.Optional.TencentAddressBar
http://www.nicolascoolman.fr/pup-optional-startsearch/ =>PUP.Optional.StartSearch
http://www.nicolascoolman.fr/blog =>PUP.Optional.IQIYIVideo
http://www.nicolascoolman.fr/hijacker-browsers/ =>PUP.Optional.Browser
http://www.nicolascoolman.fr/hijacker-qvo6/ =>PUP.Optional.Qvo6
http://www.nicolascoolman.fr/pup-anyprotect/ =>PUP.Optional.AnyProtect
http://www.nicolascoolman.fr/pup-systweak/ =>PUP.Optional.Systweak
http://www.nicolascoolman.fr/blog =>PUP.Optional.CrossBrowse
http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider
http://www.nicolascoolman.fr/blog =>PUP.Optional.PriceFountain
http://www.nicolascoolman.fr/blog =>PUP.Optional.DownChecker
http://www.nicolascoolman.fr/pup-globalupdate/ =>PUP.Optional.GlobalUpdate
http://www.nicolascoolman.fr/blog =>PUP.Optional.AgentODR
http://www.nicolascoolman.fr/pup-suptab/ =>PUP.Optional.SupTab
http://www.nicolascoolman.fr/blog =>PUP.Optional.Uniblue
http://www.nicolascoolman.fr/pup-v9software/ =>PUP.Optional.V9Software
http://www.nicolascoolman.fr/blog =>PUP.Optional.WdsManPro
http://www.nicolascoolman.fr/blog =>PUP.Optional.MyBrowser
http://www.nicolascoolman.fr/blog =>PUP.Optional.ShopSave
http://www.nicolascoolman.fr/pup-optional-exttag =>PUP.Optional.ExtTag
http://www.nicolascoolman.fr/blog =>PUP.Optional.PennyBee
http://www.nicolascoolman.fr/trojan-autokms/ =>HackTool.AutoKMS
http://www.nicolascoolman.fr/adware-opencandy/ =>PUP.Optional.OpenCandy
http://www.nicolascoolman.fr/blog =>.Superfluous.CrashReports
http://www.nicolascoolman.fr/blog =>PUP.Optional.Generic
http://www.nicolascoolman.fr/rogue-reimagerepair/ =>PUP.Optional.ReImageRepair
http://www.nicolascoolman.fr/pup-vuupc/ =>PUP.Optional.VuuPC
http://www.nicolascoolman.fr/pup-kmspico/ =>HackTool.KMSpico

~ End of the scan, 28676 items in 153 seconds (1009)(2)()

Publicité


Signaler le contenu de ce document

Publicité