cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.11.25.174 Par Nicolas Coolman (2015/11/25)
~ Démarré par deiaabdelrahman (Administrator) (2015/11/26 19:02:02)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Users\deiaabdelrahman\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\deiaabdelrahman\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Démarrage du système: Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 10240)

---\\ Navigateurs Internet (3) - 0s
MFIE: Mozilla Firefox 42.0 (x86 fr) v42.0
OPIE: Opera 33.0.1990.115 v33.0.1990.115
MSIE: Internet Explorer v11.0.10240.16590

---\\ Informations sur les produits Windows (7) - 0s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
~ Windows(R) Operating System, RETAIL channel
Windows ID Activation : OK
~ Windows Partial Key : 3V66T
~ Windows Remaining Initializations Number : 1001
Windows Automatic Updates : OK

---\\ Logiciels de protection (1) - 1s
Windows Defender (Activate)

---\\ Surveillance de Logiciels (1) - 1s
Adobe Flash Player 18 PPAPI

---\\ Informations sur le système (6) - 0s
~ Operating System: AMD64 Family 16 Model 2 Stepping 3, AuthenticAMD
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 2096.628 MB (29% free)
System Restore: Activé (Enable)
System drive C: has 71 GB () free of 89 GB

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: DESKTOP-09PQ0O5
~ User Name: deiaabdelrahman
~ Logged in as Administrator

---\\ Enumération des unités disques (4) - 0s
~ Drive C: has 71 GB free of 89 GB (System)
~ Drive D: has 50 GB free of 50 GB
~ Drive E: has 49 GB free of 49 GB
~ Drive F: has 48 GB free of 48 GB

---\\ Etat du Centre de Sécurité Windows (7) - 0s
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Recherche particulière de fichiers génériques (25) - 1s
[MD5.F1CBCB7FA6F3B309639AA2D4EF74469C] - 11/08/2015 - (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\Explorer.exe [4532304] ©
[MD5.5DED2A3F11AE916C8F2724947E736261] - 10/07/2015 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe [59392] ©
[MD5.7718A2A9B2BFB2C8E2BAEB03310CA3FD] - 18/07/2015 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\System32\Wininit.exe [290312] ©
[MD5.E5D86250453B33900666D92ED1A92ABE] - 17/09/2015 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [2740224] ©
[MD5.A7C48B051A9C5D5054916DE5BEBBCA2D] - 05/11/2015 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\Windows\System32\Winlogon.exe [579072] ©
[MD5.ECB1943967424DFB96E03F6A098434EF] - 19/07/2015 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [430592] ©
[MD5.C287D0E32771E3222A444DC527A29477] - 10/07/2015 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\System32\dnsapi.dll [680256] ©
[MD5.BB5BBD0E4D04047585E4ED0F07AA51E7] - 10/07/2015 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\Syswow64\dnsapi.dll [534064] ©
[MD5.8C795953726C7D2DE72CE4748208C5ED] - 10/07/2015 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [20480] ©
[MD5.A3D96563BF46FC8A0E5756B796127D14] - 05/11/2015 - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\Windows\System32\drivers\AFD.sys [577888] ©
[MD5.8921DF6060DB5C7700AA48CB12E9EA08] - 10/07/2015 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [28512] ©
[MD5.F2829DC6D292DCAC5029893BB2E9FEE3] - 10/07/2015 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [92672] ©
[MD5.CA160E02F35A61C6F5C681FB4669C519] - 10/07/2015 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [174080] ©
[MD5.25435407D97419627F4B10653433BF2B] - 10/07/2015 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [138240] ©
[MD5.C277A49F8A8295840DEBC9240B75A282] - 10/07/2015 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [80896] ©
[MD5.D4CDEE4A62BDFFF6E8558A9552148EA7] - 10/07/2015 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [114688] ©
[MD5.5D3744E6FDEC1A6FB3FA9B1DD4AF0694] - 10/07/2015 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [143360] ©
[MD5.1DF2C5FD2710A13B07E663A12F0E0EEA] - 10/07/2015 - (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\Windows\System32\drivers\MRxSmb.sys [415232] ©
[MD5.F0D791348AD254360CC3C3E501CCB745] - 10/07/2015 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [273408] ©
[MD5.466EC5659C02ED53DBD47DC1BC2B8086] - 30/07/2015 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [2116448] ©
[MD5.38F1AE32339731F6E5A7281AE8042545] - 10/07/2015 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\Parport.sys [96768] ©
[MD5.CA60F6C03611AF1710BC903ED9F566FB] - 10/07/2015 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [104960] ©
[MD5.A32AED8C644734B283A7C9D08D76064D] - 10/07/2015 - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) -- C:\Windows\System32\drivers\rdpdr.sys [176128] ©
[MD5.D42AC03ACF9CA67693D1D9BB4D2A0BC8] - 05/11/2015 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [116064] ©
[MD5.823A237D871CD652C6BFD47BECB6810A] - 10/07/2015 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [378720] ©

---\\ Logiciels installés (54) - 6s
O42 - Logiciel: 7-Zip 9.38 beta - (...) [HKLM][64Bits] -- 7-Zip
O42 - Logiciel: Adobe Flash Player 18 PPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player PPAPI ©
O42 - Logiciel: AMD Catalyst Control Center - (.Nom de votre société.) [HKLM][64Bits] -- {704DED82-510A-050A-2650-1E9BF19DCEF2}
O42 - Logiciel: AMD Catalyst Install Manager - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {3D601C6F-3728-D535-3700-09CB6F4A04FF} ©
O42 - Logiciel: AMD Fuel - (.Nom de votre société.) [HKLM][64Bits] -- {CC1134E1-076E-932B-62BA-FB6BD0F2CC90}
O42 - Logiciel: Catalyst Control Center - Branding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {11087D24-567D-7D88-69C6-D7A08B5F4C47} ©
O42 - Logiciel: Catalyst Control Center Graphics Previews Common - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {09E83B86-802D-4AF3-2357-74BDC336ECA8} ©
O42 - Logiciel: Catalyst Control Center InstallProxy - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {209968C8-9E75-4EAF-A074-43642AFF3681} ©
O42 - Logiciel: Catalyst Control Center Localization All - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {CE8C4233-1F37-66A2-C634-A705897E4442} ©
O42 - Logiciel: CCC Help Chinese Standard - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {B3D5812C-3977-756D-EA39-E62EA49EDDFA} ©
O42 - Logiciel: CCC Help Chinese Traditional - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {9B0B1AE1-BBF5-7321-0081-BAECFE3D0BA5} ©
O42 - Logiciel: CCC Help Czech - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {EC8BCDD1-5D38-5CF8-EBE1-50CCE9B3DF52} ©
O42 - Logiciel: CCC Help Danish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {6DF64C4C-F40A-31C7-F11B-C1048FDAEA2C} ©
O42 - Logiciel: CCC Help Dutch - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {46F9D753-A54E-B2B3-D8DF-46564236E205} ©
O42 - Logiciel: CCC Help English - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {CB4849B4-4914-0FEF-A697-2B883B187172} ©
O42 - Logiciel: CCC Help Finnish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {4FA310C6-467E-1047-BD7C-CC3AABD16B13} ©
O42 - Logiciel: CCC Help French - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {05F9C385-D22D-26CA-17AA-642A850DA246} ©
O42 - Logiciel: CCC Help German - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {B2BD683C-F4AD-1337-21A4-B11886B9AD63} ©
O42 - Logiciel: CCC Help Greek - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {8A15A7B4-A1B9-CB28-4CAE-DD0929D88007} ©
O42 - Logiciel: CCC Help Hungarian - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {6ACB683B-C95B-219C-D3B7-BB1CD793DD0E} ©
O42 - Logiciel: CCC Help Italian - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {3B158EB5-35AA-4F36-1BED-2CBF9ACCC540} ©
O42 - Logiciel: CCC Help Japanese - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {88B00677-C761-D984-297C-55A1976D7D94} ©
O42 - Logiciel: CCC Help Korean - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {F4D77EDB-2647-0E49-1C9B-5531CFE9742E} ©
O42 - Logiciel: CCC Help Norwegian - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {1DB6AF7C-62E3-2F21-26A9-E7DDA941A114} ©
O42 - Logiciel: CCC Help Polish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {C3F3A7DE-1549-4289-D28B-40259CB65245} ©
O42 - Logiciel: CCC Help Portuguese - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {A7734394-6928-AD84-E8D6-1F7BB5C1A256} ©
O42 - Logiciel: CCC Help Russian - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {32AB3D1A-178F-2D0A-6EDB-79BBE84A08A9} ©
O42 - Logiciel: CCC Help Spanish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {8D400AAF-13B7-2AA1-BC09-BE02975E71F1} ©
O42 - Logiciel: CCC Help Swedish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {F1335EA8-AB99-7F23-A364-C6214383ACF8} ©
O42 - Logiciel: CCC Help Thai - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {5237561A-D3EB-3067-E69D-A9A4661A494A} ©
O42 - Logiciel: CCC Help Turkish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {4ED5EBA1-9681-E584-C8FD-66F832423B71} ©
O42 - Logiciel: ccc-utility64 - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {11581165-6149-FB09-2B9B-5EAAEFE94EE6} ©
O42 - Logiciel: Compatible Web Directory - (.Compatible Web Directory.) [HKLM][64Bits] -- PopupProduct =>PUP.Optional.CompatibleWebDir
O42 - Logiciel: Cooking Comp - (.Total Style corp.) [HKCU][64Bits] -- {9563BC59-9556-4805-8CD4-886781779D8D}
O42 - Logiciel: DriversCloud.com (64 bits) - (.Cybelsoft.) [HKLM][64Bits] -- {8A6F0F58-AE48-4F4C-A06F-C391AB17069C} ©
O42 - Logiciel: Internet Download Manager - (.Tonec Inc..) [HKLM][64Bits] -- Internet Download Manager ©
O42 - Logiciel: Internet Quick Access - (.Internet Quick Access.) [HKCU][64Bits] -- InternetQuickAccess =>PUP.Optional.InternetQuickAccess
O42 - Logiciel: istartsurf uninstall - (.istartsurf.) [HKLM][64Bits] -- istartsurf uninstall =>PUP.Optional.IsStart
O42 - Logiciel: jogotempo 3.4 - (.DN.) [HKLM][64Bits] -- jogotempo =>PUP.Optional.Jogotempo
O42 - Logiciel: Lucky Bright - (.Lucky Bright.) [HKLM][64Bits] -- Lucky Bright =>PUP.Optional.LuckyBright
O42 - Logiciel: Mozilla Firefox 42.0 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 42.0 (x86 fr) ©
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService ©
O42 - Logiciel: Numerical Order Bluetooth - (.Numerical Order Bluetooth.) [HKLM][64Bits] -- SoftwareUpdater =>PUP.Optional.SoftwareUpdater
O42 - Logiciel: Opera Stable 33.0.1990.115 - (.Opera Software.) [HKLM][64Bits] -- Opera 33.0.1990.115 ©
O42 - Logiciel: oursurfing - (...) [HKLM][64Bits] -- oursurfing =>PUP.Optional.OurSurfing
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} ©
O42 - Logiciel: RegClean Pro - (.systweak.com.) [HKLM][64Bits] -- RegClean Pro_is1 =>PUP.Optional.RegistryPowerCleaner
O42 - Logiciel: Remote Desktop Access (VuuPC) - (.CMI Limited.) [HKLM][64Bits] -- VOPackage =>PUP.Optional.Downware
O42 - Logiciel: SevenZip - (.SevenZip.) [HKLM][64Bits] -- SevenZip ©
O42 - Logiciel: SnapDo - (.Resoft.) [HKLM][64Bits] -- {A2E4F0FE-3938-4317-B720-EA4D8E4D092C} =>PUP.Optional.SmartBar
O42 - Logiciel: Unity Web Player - (.Unity Technologies ApS.) [HKCU][64Bits] -- UnityWebPlayer ©
O42 - Logiciel: WinRAR 5.21 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver ©
O42 - Logiciel: 爱奇艺万能播放器 - (.爱奇艺.) [HKLM][64Bits] -- GeePlayer
O42 - Logiciel: 爱奇艺影音 - (.爱奇艺.) [HKLM][64Bits] -- IQIYI Video =>.Superfluous.IQIYIVideo

---\\ HKCU & HKLM Software Keys (62) - 6s
HKLM\SOFTWARE\Wow6432Node\7-Zip
HKLM\SOFTWARE\Wow6432Node\ATI
HKLM\SOFTWARE\Wow6432Node\ATI Technologies
HKLM\SOFTWARE\Wow6432Node\downchecker =>PUP.Optional.DownChecker
HKLM\SOFTWARE\Wow6432Node\Google
HKLM\SOFTWARE\Wow6432Node\ihpmserver =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\im-dosearch =>PUP.Optional.Generic
HKLM\SOFTWARE\Wow6432Node\Intel
HKLM\SOFTWARE\Wow6432Node\Internet Download Manager
HKLM\SOFTWARE\Wow6432Node\LuckyBright =>PUP.Optional.LuckyBright
HKLM\SOFTWARE\Wow6432Node\Macromedia
HKLM\SOFTWARE\Wow6432Node\Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\mtcaMyciloP
HKLM\SOFTWARE\Wow6432Node\mtMedlight
HKLM\SOFTWARE\Wow6432Node\mtZitenop
HKLM\SOFTWARE\Wow6432Node\navegaki =>PUP.Optional.Navegaki
HKLM\SOFTWARE\Wow6432Node\NetTcpHandler =>PUP.Optional.NetService
HKLM\SOFTWARE\Wow6432Node\NtSvcHandler =>PUP.Optional.NetService
HKLM\SOFTWARE\Wow6432Node\Nuance
HKLM\SOFTWARE\Wow6432Node\ODBC
HKLM\SOFTWARE\Wow6432Node\oursurfingSoftware =>PUP.Optional.OurSurfing
HKLM\SOFTWARE\Wow6432Node\RayDld =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Realtek
HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\Reg
HKLM\SOFTWARE\Wow6432Node\Rtp
HKLM\SOFTWARE\Wow6432Node\Sakura =>PUP.Optional.GameGogle
HKLM\SOFTWARE\Wow6432Node\SRS Labs
HKLM\SOFTWARE\Wow6432Node\Systweak =>PUP.Optional.Systweak
HKLM\SOFTWARE\Wow6432Node\WdsManPro =>PUP.Optional.WdsManPro
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications
HKCU\SOFTWARE\7-Zip
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\ATI
HKCU\SOFTWARE\Chromium
HKCU\SOFTWARE\DownloadManager
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\InstallPath
HKCU\SOFTWARE\Licenses
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\Mine
HKCU\SOFTWARE\Mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\OB
HKCU\SOFTWARE\Opera Software
HKCU\SOFTWARE\PPStream
HKCU\SOFTWARE\QyGameClient =>.Superfluous.IQIYIVideo
HKCU\SOFTWARE\Realtek
HKCU\SOFTWARE\Reg
HKCU\SOFTWARE\RegisteredApplications
HKCU\SOFTWARE\Rtp
HKCU\SOFTWARE\systweak =>PUP.Optional.Systweak
HKCU\SOFTWARE\TeleCharger
HKCU\SOFTWARE\Unity
HKCU\SOFTWARE\WinRAR
HKCU\SOFTWARE\WinRAR SFX
HKCU\SOFTWARE\Wow6432Node
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\AppDataLow\Software
HKCU\SOFTWARE\AppDataLow\Software\Unity

---\\ Liste des services NT non Microsoft et non désactivés (14) - 0s
O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\system32\atiesrxx.exe ©
O23 - Service: AMD FUEL Service (AMD FUEL Service) . (.Advanced Micro Devices, Inc. - Service Fusion Utility.) - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe ©
O23 - Service: ApplicationHosting (ApplicationHosting) . (...) - C:\ProgramData\ApplicationHosting\ApplicationHosting.exe =>PUP.Optional.ApplicationHosting
O23 - Service: caMyciloP (caMyciloP) . (...) - C:\ProgramData\caMyciloP\caMyciloP.exe =>PUP.Optional.Salus
O23 - Service: Saotouch (downloadexproduci) . (. - xrc.) - C:\Users\deiaabdelrahman\AppData\Local\saotech.exe
O23 - Service: Dripkix Service (Dripkix) . (.Copyright © 2015 - .) - C:\Program Files\Dripkix\Dripkix.exe =>PUP.Optional.Amonetize
O23 - Service: Normal Blind Carbon Copy (hidekoqe) . (...) - C:\Users\deiaabdelrahman\AppData\Local\FFFFFFFF-1448563076-FFFF-FFFF-FFFFFFFFFFFF\qnsgFAB2.tmp =>PUP.Optional.CrossRider
O23 - Service: Zap Controller (hotnix32) . (.Copyright © 2015 - .) - C:\Program Files\NixController\hotnix.exe =>PUP.Optional.Amonetize
O23 - Service: Medlight (Medlight) . (...) - C:\ProgramData\Medlight\Medlight.exe =>PUP.Optional.Salus
O23 - Service: Net.Tcp Service Handler (NetTcpHandler) . (...) - C:\Users\deiaabdelrahman\AppData\Roaming\NetService\netservice.exe =>PUP.Optional.NetService
O23 - Service: Red Green Blue Dual Core (rylusycy) . (...) - C:\Users\deiaabdelrahman\AppData\Local\FFFFFFFF-1448222012-FFFF-FFFF-FFFFFFFFFFFF\snsa8F7E.tmp =>PUP.Optional.CrossRider
O23 - Service: Service Mgr LuckyBright (Service Mgr LuckyBright) . (...) - C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugincontainer.exe =>PUP.Optional.LuckyBright
O23 - Service: Update Mgr LuckyBright (Update Mgr LuckyBright) . (...) - C:\Program Files (x86)\Common Files\9466af57-1f38-4973-ab1c-22f7e17e2d6a\updater.exe =>PUP.Optional.LuckyBright
O23 - Service: Zitenop (Zitenop) . (...) - C:\ProgramData\Zitenop\Zitenop.exe =>PUP.Optional.Salus

---\\ Tâches planifiées en automatique (13) - 4s
[MD5.011BD8A49AF856E8A8EE32652D1CFC05] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [268976] ©
[MD5.00000000000000000000000000000000] [APT] [Opera scheduled Autoupdate 1448218280] (...) -- C:\Program Files (x86)\Opera\launcher.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [prodnct] (...) -- C:\Windows\system32\config\systemprofile\AppData\Local\Icerunfresh /t 2172 8154 (.not file.) [0]
[MD5.8417AAF8506D753104213C763292977E] [APT] [RegClean Pro_DEFAULT] (...) -- C:\Program Files (x86)\RCP\RegCleanPro.exe [9693616] =>PUP.Optional.RegistryPowerCleaner
[MD5.8417AAF8506D753104213C763292977E] [APT] [RegClean Pro_UPDATES] (...) -- C:\Program Files (x86)\RCP\RegCleanPro.exe [9693616] =>PUP.Optional.RegistryPowerCleaner
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002] ©
O39 - APT: RegClean Pro_DEFAULT - (...) -- C:\Windows\Tasks\RegClean Pro_DEFAULT.job [310] =>PUP.Optional.RegistryPowerCleaner
O39 - APT: RegClean Pro_UPDATES - (...) -- C:\Windows\Tasks\RegClean Pro_UPDATES.job [318] =>PUP.Optional.RegistryPowerCleaner
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [3978] ©
O39 - APT: Opera scheduled Autoupdate 1448218280 - (...) -- C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1448218280 [3990]
O39 - APT: prodnct - (...) -- C:\Windows\System32\Tasks\prodnct [3334]
O39 - APT: RegClean Pro_DEFAULT - (...) -- C:\Windows\System32\Tasks\RegClean Pro_DEFAULT [2994] =>PUP.Optional.RegistryPowerCleaner
O39 - APT: RegClean Pro_UPDATES - (...) -- C:\Windows\System32\Tasks\RegClean Pro_UPDATES [3150] =>PUP.Optional.RegistryPowerCleaner

---\\ Processus lancés (36) - 1s
[MD5.7FE59496114A48A64E98E3218664A3E6] - (.AMD - AMD External Events Service Module.) -- C:\Windows\System32\atiesrxx.exe [238080] [PID.1052] ©
[MD5.0594DCF055A1F567CAFF49B780BA0399] - (.AMD - AMD External Events Client Module.) -- C:\Windows\System32\atieclxx.exe [514048] [PID.1104] ©
[MD5.CD705E27BE16A31E1FE97DFEC4977854] - (.Advanced Micro Devices, Inc. - Service Fusion Utility.) -- C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064] [PID.1804] ©
[MD5.2B861827E6EAB6B4A8F6E65C21EE2C8C] - (...) -- C:\ProgramData\ApplicationHosting\ApplicationHosting.exe [792576] [PID.1832] =>PUP.Optional.ApplicationHosting
[MD5.2B6C46C7865C54D0B58C30CEB1A8459A] - (...) -- C:\ProgramData\caMyciloP\caMyciloP.exe [792576] [PID.1840] =>PUP.Optional.Salus
[MD5.39060182BF3061CF8648093A2B0DBD2D] - (. - xrc.) -- C:\Users\deiaabdelrahman\AppData\Local\saotech.exe [60416] [PID.1876]
[MD5.790AC1BEFFBCC73A7ADD37CF7030E44C] - (.Copyright © 2015 - .) -- C:\Program Files\Dripkix\Dripkix.exe [379904] [PID.2008] =>PUP.Optional.Amonetize
[MD5.C38B5B86331AC171AE38829A057A8B4D] - (...) -- C:\Users\deiaabdelrahman\AppData\Local\FFFFFFFF-1448563076-FFFF-FFFF-FFFFFFFFFFFF\qnsgFAB2.tmp [142336] [PID.1276] =>PUP.Optional.CrossRider
[MD5.9C465BF9F3627705578DBAB890AD4644] - (.Copyright © 2015 - .) -- C:\Program Files\NixController\hotnix.exe [379392] [PID.1448] =>PUP.Optional.Amonetize
[MD5.CDD75D1305CB2D87E8F3A58F20FF685A] - (...) -- C:\ProgramData\Medlight\Medlight.exe [792576] [PID.2404] =>PUP.Optional.Salus
[MD5.A271A66ABF8CAC3606FB114D7E8C517B] - (...) -- C:\Users\deiaabdelrahman\AppData\Roaming\NetService\netservice.exe [173088] [PID.2424] =>PUP.Optional.NetService
[MD5.793F4251E13ED40FA19D9016500BE319] - (...) -- C:\Users\deiaabdelrahman\AppData\Local\FFFFFFFF-1448222012-FFFF-FFFF-FFFFFFFFFFFF\snsa8F7E.tmp [329216] [PID.2476] =>PUP.Optional.CrossRider
[MD5.5C3C447871CA9FCFABAD02B3C020EC01] - (...) -- C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugincontainer.exe [635624] [PID.2612] =>PUP.Optional.CrossRider
[MD5.5B2BD7C8A7B041154E653AF8429D4DDB] - (...) -- C:\ProgramData\Zitenop\Zitenop.exe [792576] [PID.2860] =>PUP.Optional.Salus
[MD5.436CB2FD6EBE5C635D5F623CE9956785] - (.Copyright © 2015 - .) -- C:\Program Files\Dripkix\packages\b542ac8e-9176-43e9-a72a-a53f8e7797b7\Drip.exe [855040] [PID.2136] =>PUP.Optional.Amonetize
[MD5.2B6C46C7865C54D0B58C30CEB1A8459A] - (...) -- C:\ProgramData\caMyciloP\caMyciloP.exe [792576] [PID.4936] =>PUP.Optional.Salus
[MD5.08D9600B273D85C4CC5E4D6116E1941A] - (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13876952] [PID.5836] ©
[MD5.668B048C053FE5C5E243F44EB061D01C] - (...) -- C:\Program Files (x86)\Common Files\9466af57-1f38-4973-ab1c-22f7e17e2d6a\updater.exe [541928] [PID.5952] =>PUP.Optional.CrossRider
[MD5.D69ABF64473B2CA863BB82EEC91B7D40] - (. - pps.) -- C:\Program Files (x86)\baidu\pps.exe [81920] [PID.6096]
[MD5.089AC78F91E11841D5D4E65719464285] - (.iQIYI.COM - 爱奇艺HCDN网络数据传输组件.) -- C:\IQIYI Video\Common\QyKernel.exe [576104] [PID.1664] ©
[MD5.E4085C9692976E98DC081828485BDE48] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3911248] [PID.2264] ©
[MD5.74DB533FAE69251E9BD59A0BD1FC27C0] - (...) -- C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\10\Plugin.exe [446696] [PID.5180] =>PUP.Optional.CrossRider
[MD5.2DA4EC580C18362EBEC6D39D6B897E2F] - (...) -- C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\5\Plugin.exe [708840] [PID.2624] =>PUP.Optional.CrossRider
[MD5.8455395954E83094D8701DC88FB629B4] - (...) -- C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\7\Plugin.exe [458472] [PID.2676] =>PUP.Optional.CrossRider
[MD5.8455395954E83094D8701DC88FB629B4] - (...) -- C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\7\Plugin.exe [458472] [PID.5800] =>PUP.Optional.CrossRider
[MD5.E9C6EF9437ECB30911488F9313AD821A] - (.Tonec Inc. - Internet Download Manager agent for click m.) -- C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe [269848] [PID.5808] ©
[MD5.074A30C3F8C8DD79CF7DD386D34CFE40] - (...) -- C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\3\Plugin.exe [599784] [PID.5356] =>PUP.Optional.CrossRider
[MD5.BE2CADA2C7D15D8D712F97DDD5C7F83A] - (...) -- C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\8\Plugin.exe [1245928] [PID.6056] =>PUP.Optional.CrossRider
[MD5.B3A952258A347B96710D9A11167032D4] - (...) -- C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\12\Plugin.exe [1009384] [PID.4740] =>PUP.Optional.CrossRider
[MD5.074A30C3F8C8DD79CF7DD386D34CFE40] - (...) -- C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\3\Plugin.exe [599784] [PID.1932] =>PUP.Optional.CrossRider
[MD5.60988A07512456741E0657157A56EDF9] - (...) -- C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\2\Plugin.exe [1710312] [PID.5384] =>PUP.Optional.CrossRider
[MD5.B3A952258A347B96710D9A11167032D4] - (...) -- C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\12\Plugin.exe [1009384] [PID.3272] =>PUP.Optional.CrossRider
[MD5.92B35B8A5F512AF7B463C19D77E9F5C7] - (.Advanced Micro Devices Inc. - Catalyst Control Center: Monitoring program.) -- C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe [307400] [PID.5336] ©
[MD5.F672D6C13FDCBA7C816BA834A0F8AA85] - (.Advanced Micro Devices Inc. - Catalyst Control Center: Host application.) -- C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe [307912] [PID.3888] ©
[MD5.4B0583A0A6A22D9F453BFFD467E68190] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [392872] [PID.2492] ©
[MD5.4E980078E8F1F28EEF6A00F1347D868E] - (.Copyright (C) 2015 Nicolas Coolman - ZHPDiag.) -- C:\Users\deiaabdelrahman\Desktop\ZHPDiag3.exe [1976320] [PID.5320] ©

---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (15) - 1s
M0 - MFSP: prefs.js [deiaabdelrahman - 21432xnr.default] https://www.google.fr/?gws_rd=ssl
M0 - MFSP: prefs.js [deiaabdelrahman - 21432xnr.default] about:preferences
P2 - EXT FILE: (...) -- C:\Users\deiaabdelrahman\AppData\Roaming\Mozilla\Firefox\Profiles\21432xnr.default\extensions\adblockpopups@jessehakanen.net.xpi
P2 - EXT FILE: (...) -- C:\Users\deiaabdelrahman\AppData\Roaming\Mozilla\Firefox\Profiles\21432xnr.default\extensions\adguardadblocker@adguard.com.xpi =>PUP.Optional.Adblocker
P2 - EXT FILE: (...) -- C:\Users\deiaabdelrahman\AppData\Roaming\Mozilla\Firefox\Profiles\21432xnr.default\extensions\jid1-dwtFBkQjb3SIQp@jetpack.xpi
P2 - EXT FILE: (...) -- C:\Users\deiaabdelrahman\AppData\Roaming\Mozilla\Firefox\Profiles\21432xnr.default\extensions\jid1-dwtGBwQjx3SUQc@jetpack.xpi
P2 - EXT FILE: (...) -- C:\Users\deiaabdelrahman\AppData\Roaming\Mozilla\Firefox\Profiles\21432xnr.default\extensions\jid1-q4sG8pYhq8KGHs@jetpack.xpi
P2 - EXT FILE: (...) -- C:\Users\deiaabdelrahman\AppData\Roaming\Mozilla\Firefox\Profiles\21432xnr.default\extensions\jid1-w4wG5nJhx4LJZr@jetpack.xpi
P2 - EXT FILE: (...) -- C:\Users\deiaabdelrahman\AppData\Roaming\Mozilla\Firefox\Profiles\21432xnr.default\extensions\{ba7210aa-9217-49d6-9523-f3d2f6356716}.xpi
P2 - EXT FILE: (...) -- C:\Users\deiaabdelrahman\AppData\Roaming\Mozilla\Firefox\Profiles\21432xnr.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
P2 - EXT FILE: (...) -- C:\Users\deiaabdelrahman\AppData\Roaming\Mozilla\Firefox\Profiles\21432xnr.default\extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi
P2 - EXT FILE: (...) -- C:\Users\deiaabdelrahman\AppData\Roaming\Mozilla\Firefox\Profiles\21432xnr.default\searchplugins\findit.xml =>PUP.Optional.SmartBar
P2 - EXT: (.Mozilla - Default.) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ©
P2 - FPN: [HKCU] [@iqiyi.com/npWebPlayer] - (.爱奇艺公司.) -- C:\IQIYI Video\LStyle\npWebPlayer.dll =>.Superfluous.IQIYIVideo
P2 - FPN: [HKLM] [@iqiyi.com/npWebPlayer] - (.爱奇艺公司.) -- C:\IQIYI Video\LStyle\npWebPlayer.dll =>.Superfluous.IQIYIVideo

---\\ Opera, Démarrage,Recherche,Plugins (1) - 0s
B2 - EXT: [{background:{scripts:[background.js]}content_scrip] C:\Users\deiaabdelrahman\AppData\Roaming\Opera Software\Opera Stable\Extensions\pogiioopimdkbinddahohmgcinolabkn

---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (21) - 1s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_ByuMcS4zqTgWbU8u6bdWk3wHHtbAzGu1_BGEJNsz3ML44dgC7s4RvgkgFF2x1lN9rRQpiFxTZBz8sn4KiO3sEhmG7YYdFYSg5aimtP89ayTVW3AYNPY0ZvVSt37GGtbLHT1C1YuA3yIr2Zmc1yXcJqlpdtQl- =>PUP.Optional.Linkury
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutxkij9_byumcs4zqtgwbu8u6bdwk3whhtbazgu1_bgejnsz3ml44dgc7s4rvgkgff2x1ln9rrqpifxtzbz8sn47sp0cpxul9gz1jvjuocgxg6_8braxys9rzojm-hcxu8nnubznywhajspypnrczd-txaipvzb2o-sl5&q={searchterms} =>PUP.Optional.Linkury
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.oursurfing.com/ =>PUP.Optional.OurSurfing
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutxkij9_byumcs4zqtgwbu8u6bdwk3whhtbazgu1_bgejnsz3ml44dgc7s4rvgkgff2x1ln9rrqpifxtzbz8sn47sp0cpxul9gz1jvjuocgxg6_8braxys9rzojm-hcxu8nnubznywhajspypnrczd-txaipvzb2o-sl5&q={searchterms} =>PUP.Optional.Linkury
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.oursurfing.com/ =>PUP.Optional.OurSurfing
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.oursurfing.com/ =>PUP.Optional.OurSurfing
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oursurfing.com/ =>PUP.Optional.OurSurfing
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutxkij9_byumcs4zqtgwbu8u6bdwk3whhtbazgu1_bgejnsz3ml44dgc7s4rvgkgff2x1ln9rrqpifxtzbz8sn47sp0cpxul9gz1jvjuocgxg6_8braxys9rzojm-hcxu8nnubznywhajspypnrczd-txaipvzb2o-sl5&q={searchterms} =>PUP.Optional.Linkury
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutxkij9_byumcs4zqtgwbu8u6bdwk3whhtbazgu1_bgejnsz3ml44dgc7s4rvgkgff2x1ln9rrqpifxtzbz8sn47sp0cpxul9gz1jvjuocgxg6_8braxys9rzojm-hcxu8nnubznywhajspypnrczd-txaipvzb2o-sl5&q={searchterms} =>PUP.Optional.Linkury
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.oursurfing.com/ =>PUP.Optional.OurSurfing
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.oursurfing.com/ =>PUP.Optional.OurSurfing
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oursurfing.com/ =>PUP.Optional.OurSurfing
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1
R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1

---\\ Internet Explorer,Proxy Management (2) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1

---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s
F2 - REG:system.ini: UserInit=
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) ©
F2 - REG:system.ini: VMApplet=

---\\ Etude du fichier hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)

---\\ Browser Helper Object de navigateur (BHO) (1) - 0s
O2 - BHO: IDM Helper [64Bits] - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Internet Download Manager, Tonec Inc. - IDM Browser Helper Object.) -- C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll ©

---\\ Applications lancées au démarrage du système (16) - 0s
O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe ©
O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\OneDrive\OneDrive.exe ©
O4 - HKCU\..\Run: [apphide] . (. - pps.) -- C:\Program Files (x86)\baidu\pps.exe
O4 - HKCU\..\Run: [HCDNClient] . (.iQIYI.COM - 爱奇艺HCDN网络数据传输组件.) -- C:\IQIYI Video\Common\QyKernel.exe ©
O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe ©
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\deiaabdelrahman\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\cmd.exe ©
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\deiaabdelrahman\AppData\Local\Microsoft\OneDrive\17.3.5892.0626] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\cmd.exe ©
O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe ©
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe ©
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe ©
O4 - HKUS\S-1-5-21-1382941356-707450513-1370848545-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\OneDrive\OneDrive.exe ©
O4 - HKUS\S-1-5-21-1382941356-707450513-1370848545-1001\..\Run: [apphide] . (. - pps.) -- C:\Program Files (x86)\baidu\pps.exe
O4 - HKUS\S-1-5-21-1382941356-707450513-1370848545-1001\..\Run: [HCDNClient] . (.iQIYI.COM - 爱奇艺HCDN网络数据传输组件.) -- C:\IQIYI Video\Common\QyKernel.exe ©
O4 - HKUS\S-1-5-21-1382941356-707450513-1370848545-1001\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe ©
O4 - HKUS\S-1-5-21-1382941356-707450513-1370848545-1001\..\RunOnce: [Uninstall C:\Users\deiaabdelrahman\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\cmd.exe ©
O4 - HKUS\S-1-5-21-1382941356-707450513-1370848545-1001\..\RunOnce: [Uninstall C:\Users\deiaabdelrahman\AppData\Local\Microsoft\OneDrive\17.3.5892.0626] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\cmd.exe ©

---\\ Raccourcis Global Startup (9) - 1s
O4 - GS\Quicklaunch [Administrateur]: Internet Quick Access.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\deiaabdelrahman\AppData\Local\Chromium\Application\chrome.exe =>
O4 - GS\Quicklaunch [Administrateur]: 爱奇艺万能播放器.lnk . (.爱奇艺 - 爱奇艺万能播放器.) C:\IQIYI Video\GeePlayer\GeePlayer\GeePlayer.exe =>.Superfluous.IQIYIVideo
O4 - GS\Quicklaunch [DefaultAccount]: Internet Quick Access.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\deiaabdelrahman\AppData\Local\Chromium\Application\chrome.exe =>
O4 - GS\Quicklaunch [DefaultAccount]: 爱奇艺万能播放器.lnk . (.爱奇艺 - 爱奇艺万能播放器.) C:\IQIYI Video\GeePlayer\GeePlayer\GeePlayer.exe =>.Superfluous.IQIYIVideo
O4 - GS\Quicklaunch [deiaabdelrahman]: Internet Quick Access.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\deiaabdelrahman\AppData\Local\Chromium\Application\chrome.exe =>
O4 - GS\Quicklaunch [deiaabdelrahman]: 爱奇艺万能播放器.lnk . (.爱奇艺 - 爱奇艺万能播放器.) C:\IQIYI Video\GeePlayer\GeePlayer\GeePlayer.exe =>.Superfluous.IQIYIVideo
O4 - GS\Quicklaunch [Invité]: Internet Quick Access.lnk . (.IMALI - N.I. MEDIA LTD - Internet Quick Access.) C:\Users\deiaabdelrahman\AppData\Local\Chromium\Application\chrome.exe =>
O4 - GS\Quicklaunch [Invité]: 爱奇艺万能播放器.lnk . (.爱奇艺 - 爱奇艺万能播放器.) C:\IQIYI Video\GeePlayer\GeePlayer\GeePlayer.exe =>.Superfluous.IQIYIVideo
O4 - GS\Programs [Public]: 爱奇艺万能播放器.lnk . (.爱奇艺 - 爱奇艺万能播放器.) C:\IQIYI Video\GeePlayer\GeePlayer\GeePlayer.exe =>.Superfluous.IQIYIVideo

---\\ Modification Domaine/Adresses DNS (4) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 198.153.192.50 198.153.194.50
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = domain.name
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 198.153.192.50 198.153.194.50
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpDomain = domain.name

---\\ Protocole additionnel (18) - 0s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll ©
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll ©
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\SysWOW64\inetcomm.dll ©
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll ©
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\SysWOW64\tbauth.dll ©
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll ©
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©

---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (1) - 0s
O20 - AppInit_DLLs: . (...) - C:\ProgramData\caMyciloP\Icetamtech.dll =>PUP.Optional.Salus

---\\ Contenu des dossiers Programmes (130) - 7s
O43 - CFD: 21/11/2015 - [] D -- C:\Program Files (x86)\7-Zip
O43 - CFD: 26/11/2015 - [] D -- C:\Program Files (x86)\AMD
O43 - CFD: 21/11/2015 - [] D -- C:\Program Files (x86)\baidu
O43 - CFD: 22/11/2015 - [] D -- C:\Program Files (x86)\Common Files
O43 - CFD: 22/11/2015 - [] D -- C:\Program Files (x86)\FFFFFFFF-1448218360-FFFF-FFFF-FFFFFFFFFFFF =>PUP.Optional.CrossRider
O43 - CFD: 26/11/2015 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 23/11/2015 - [] D -- C:\Program Files (x86)\Internet Download Manager
O43 - CFD: 23/11/2015 - [] D -- C:\Program Files (x86)\Internet Explorer
O43 - CFD: 22/11/2015 - [] D -- C:\Program Files (x86)\jogotempo =>PUP.Optional.Jogotempo
O43 - CFD: 22/11/2015 - [] D -- C:\Program Files (x86)\Lucky Bright =>PUP.Optional.LuckyBright
O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 23/11/2015 - [] D -- C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 23/11/2015 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service
O43 - CFD: 22/11/2015 - [] D -- C:\Program Files (x86)\RCP
O43 - CFD: 26/11/2015 - [] D -- C:\Program Files (x86)\Realtek
O43 - CFD: 22/11/2015 - [] D -- C:\Program Files (x86)\SevenZip
O43 - CFD: 26/11/2015 - [0] HD -- C:\Program Files (x86)\Temp
O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Windows Defender
O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Windows Mail
O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Windows Media Player
O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform
O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Windows NT
O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 10/07/2015 - [] SHD -- C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 10/07/2015 - [] SD -- C:\Program Files (x86)\WindowsPowerShell
O43 - CFD: 21/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
O43 - CFD: 23/11/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 10/07/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 10/07/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 26/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
O43 - CFD: 22/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriversCloud.com
O43 - CFD: 22/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
O43 - CFD: 10/07/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 22/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro =>PUP.Optional.RegistryPowerCleaner
O43 - CFD: 10/07/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
O43 - CFD: 10/07/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 10/07/2015 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 23/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 26/11/2015 - [] D -- C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a
O43 - CFD: 26/11/2015 - [] D -- C:\ProgramData\AMD
O43 - CFD: 10/07/2015 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 21/11/2015 - [] D -- C:\ProgramData\ApplicationHosting =>PUP.Optional.ApplicationHosting
O43 - CFD: 26/11/2015 - [] D -- C:\ProgramData\ATI
O43 - CFD: 10/11/2015 - [0] SHD -- C:\ProgramData\Bureau
O43 - CFD: 26/11/2015 - [] D -- C:\ProgramData\caMyciloP =>PUP.Optional.Salus
O43 - CFD: 22/11/2015 - [] D -- C:\ProgramData\caMyciloPs =>PUP.Optional.Salus
O43 - CFD: 10/07/2015 - [0] D -- C:\ProgramData\Comms
O43 - CFD: 10/07/2015 - [0] SHD -- C:\ProgramData\Desktop
O43 - CFD: 10/07/2015 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 22/11/2015 - [] D -- C:\ProgramData\DriversCloud.com
O43 - CFD: 22/11/2015 - [] D -- C:\ProgramData\eWMiniProe
O43 - CFD: 22/11/2015 - [0] D -- C:\ProgramData\IDM
O43 - CFD: 21/11/2015 - [0] D -- C:\ProgramData\IQIYI Video =>.Superfluous.IQIYIVideo
O43 - CFD: 26/11/2015 - [] D -- C:\ProgramData\Medlight =>PUP.Optional.Salus
O43 - CFD: 21/11/2015 - [] D -- C:\ProgramData\Medlights =>PUP.Optional.Salus
O43 - CFD: 10/11/2015 - [0] SHD -- C:\ProgramData\Menu Démarrer
O43 - CFD: 22/11/2015 - [] SD -- C:\ProgramData\Microsoft
O43 - CFD: 21/11/2015 - [] D -- C:\ProgramData\Microsoft OneDrive
O43 - CFD: 10/11/2015 - [0] SHD -- C:\ProgramData\Modèles
O43 - CFD: 26/11/2015 - [] D -- C:\ProgramData\Package Cache
O43 - CFD: 10/07/2015 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft
O43 - CFD: 10/07/2015 - [0] D -- C:\ProgramData\SoftwareDistribution
O43 - CFD: 10/07/2015 - [0] SHD -- C:\ProgramData\Start Menu
O43 - CFD: 10/07/2015 - [0] SHD -- C:\ProgramData\Templates
O43 - CFD: 10/07/2015 - [] D -- C:\ProgramData\USOPrivate
O43 - CFD: 10/07/2015 - [] D -- C:\ProgramData\USOShared
O43 - CFD: 23/11/2015 - [] D -- C:\ProgramData\XWMiniProX
O43 - CFD: 26/11/2015 - [] D -- C:\ProgramData\Zitenop =>PUP.Optional.Salus
O43 - CFD: 23/11/2015 - [] D -- C:\ProgramData\Zitenops =>PUP.Optional.Salus
O43 - CFD: 26/11/2015 - [] D -- C:\Program Files (x86)\Common Files\9466af57-1f38-4973-ab1c-22f7e17e2d6a
O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared
O43 - CFD: 21/11/2015 - [] D -- C:\Program Files (x86)\Common Files\S-oveis
O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Common Files\Services
O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Common Files\System
O43 - CFD: 21/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\Adobe
O43 - CFD: 26/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\ATI
O43 - CFD: 26/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\DMCache
O43 - CFD: 22/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\IDM
O43 - CFD: 25/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\IQIYI Video =>.Superfluous.IQIYIVideo
O43 - CFD: 22/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\istartpageing =>PUP.Optional.IstartPageing
O43 - CFD: 21/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\Macromedia
O43 - CFD: 21/11/2015 - [] SD -- C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft
O43 - CFD: 23/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\Mozilla
O43 - CFD: 22/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\NetService =>PUP.Optional.NetService
O43 - CFD: 22/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\OpenCandy =>PUP.Optional.OpenCandy
O43 - CFD: 22/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\Opera Software
O43 - CFD: 25/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\RunDir =>PUP.Optional.NetService
O43 - CFD: 25/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\shortCutStore
O43 - CFD: 22/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\systweak =>PUP.Optional.Systweak
O43 - CFD: 22/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\VOPackage =>PUP.Optional.Downware
O43 - CFD: 23/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\WinRAR
O43 - CFD: 26/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\ZHP
O43 - CFD: 26/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\AMD
O43 - CFD: 21/11/2015 - [0] SHD -- C:\Users\deiaabdelrahman\AppData\Local\Application Data
O43 - CFD: 26/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\ATI
O43 - CFD: 22/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\Chromium
O43 - CFD: 25/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\Comms
O43 - CFD: 21/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\Cooking Comp
O43 - CFD: 22/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\Diagnostics
O43 - CFD: 26/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\FFFFFFFF-1448222012-FFFF-FFFF-FFFFFFFFFFFF
O43 - CFD: 26/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\FFFFFFFF-1448563076-FFFF-FFFF-FFFFFFFFFFFF
O43 - CFD: 21/11/2015 - [0] SHD -- C:\Users\deiaabdelrahman\AppData\Local\Historique
O43 - CFD: 25/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft
O43 - CFD: 21/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\MicrosoftEdge
O43 - CFD: 23/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\Mozilla
O43 - CFD: 22/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\Opera Software
O43 - CFD: 21/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\Packages
O43 - CFD: 21/11/2015 - [0] D -- C:\Users\deiaabdelrahman\AppData\Local\PeerDistRepub
O43 - CFD: 21/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\Programs
O43 - CFD: 21/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\Publishers
O43 - CFD: 23/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\SysassistByHotWheel =>PUP.Optional.Generic
O43 - CFD: 26/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\Temp
O43 - CFD: 21/11/2015 - [0] SHD -- C:\Users\deiaabdelrahman\AppData\Local\Temporary Internet Files
O43 - CFD: 21/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\TileDataLayer
O43 - CFD: 21/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Local\Unity
O43 - CFD: 21/11/2015 - [0] D -- C:\Users\deiaabdelrahman\AppData\Local\VirtualStore
O43 - CFD: 10/07/2015 - [] RD -- C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 22/11/2015 - [] RD -- C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 23/11/2015 - [] RD -- C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 22/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
O43 - CFD: 22/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Quick Access =>PUP.Optional.InternetQuickAccess
O43 - CFD: 22/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\jogotempo =>PUP.Optional.Jogotempo
O43 - CFD: 10/07/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 22/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SevenZip 9.20
O43 - CFD: 23/11/2015 - [] RD -- C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 10/07/2015 - [] RD -- C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 22/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage =>PUP.Optional.Downware
O43 - CFD: 10/07/2015 - [] RSD -- C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
O43 - CFD: 23/11/2015 - [] D -- C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR

---\\ Derniers fichiers créés dans Windows Prefetcher (5) - 12s
O45 - LFCP:[MD5.EED11ABF2B178D563842DF3E3105EF5B] 26/11/2015 A -- C:\Windows\Prefetch\CAMYCILOP.EXE-6CEDE6AE.pf =>PUP.Optional.Salus
O45 - LFCP:[MD5.169EC466DBF422CA024D83D93DA72881] 26/11/2015 A -- C:\Windows\Prefetch\MEDLIGHT.EXE-AB202790.pf =>PUP.Optional.Salus
O45 - LFCP:[MD5.EDED61A3339CC5AA4CFF2188A031FF31] 25/11/2015 A -- C:\Windows\Prefetch\QIYIDACL.EXE-DD71C206.pf =>.Superfluous.IQIYIVideo
O45 - LFCP:[MD5.8804355382D6AE322318DC9F98C42A56] 21/11/2015 A -- C:\Windows\Prefetch\WINDOWS 10 LOADER BY KMSPICO -77EA2A90.pf =>HackTool.KMSpico
O45 - LFCP:[MD5.A1A18ADF93A0C2910204384096CB5DC9] 26/11/2015 A -- C:\Windows\Prefetch\ZITENOP.EXE-7623D2DE.pf =>PUP.Optional.Salus

---\\ ShellIconOverlayIdentifiers (SIOI) (5) - 0s
O106 - SIOI: ErrorOverlayHandler Class [ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileSyncShell.dll ©
O106 - SIOI: SharedOverlayHandler Class [ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileSyncShell.dll ©
O106 - SIOI: SharedSyncingOverlayHandler Class [ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileSyncShell.dll ©
O106 - SIOI: UpToDateOverlayHandler Class [ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileSyncShell.dll ©
O106 - SIOI: SyncingOverlayHandler Class [ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileSyncShell.dll ©

---\\ Liste des pilotes du système (43) - 1s
O58 - SDL:2015/07/10 11:59:38 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\drivers\3ware.sys [107360] ©
O58 - SDL:2015/07/10 11:59:38 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\Windows\System32\drivers\adp80xx.sys [1135456] ©
O58 - SDL:2015/07/10 11:59:38 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [83296] ©
O58 - SDL:2015/07/10 11:59:38 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [259424] ©
O58 - SDL:2015/07/10 11:59:38 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [26976] ©
O58 - SDL:2015/07/10 11:59:38 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [131936] ©
O58 - SDL:2015/11/21 19:57:41 A . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\System32\drivers\atikmdag.sys [11922944] ©
O58 - SDL:2015/11/21 19:57:41 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\Windows\System32\drivers\atikmpag.sys [359936] ©
O58 - SDL:2015/07/10 11:59:38 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\drivers\bcmfn2.sys [17624] ©
O58 - SDL:2015/07/10 11:59:38 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [531296] ©
O58 - SDL:2015/07/10 11:59:38 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3436896] ©
O58 - SDL:2015/07/10 11:59:38 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [64352] ©
O58 - SDL:2015/07/10 11:59:36 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [38128] ©
O58 - SDL:2015/07/10 11:59:36 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_I2C.sys [122608] ©
O58 - SDL:2015/07/10 11:59:38 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\Windows\System32\drivers\iaStorAV.sys [673120] ©
O58 - SDL:2015/07/10 11:59:38 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [412000] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\Windows\System32\drivers\ibbus.sys [424800] ©
O58 - SDL:2015/06/12 03:00:58 A . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\drivers\idmwfp.sys [197616] ©
O58 - SDL:2015/07/10 11:59:38 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [108896] ©
O58 - SDL:2015/07/10 11:59:38 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2i.sys [104800] ©
O58 - SDL:2015/07/10 11:59:38 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas3i.sys [99168] ©
O58 - SDL:2015/07/10 11:59:38 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sss.sys [82784] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [59744] ©
O58 - SDL:2015/07/10 11:59:39 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\megasr.sys [575840] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - MLX4 Bus Driver.) -- C:\Windows\System32\drivers\mlx4_bus.sys [705376] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\Windows\System32\drivers\mvumis.sys [63840] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\Windows\System32\drivers\ndfltr.sys [76128] ©
O58 - SDL:2015/07/10 11:59:39 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [150368] ©
O58 - SDL:2015/07/10 11:59:39 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [166240] ©
O58 - SDL:2015/07/10 11:59:39 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\percsas2i.sys [58208] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\percsas3i.sys [58720] ©
O58 - SDL:2015/05/05 19:24:16 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RTKVHD64.sys [4467928] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [44896] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [81760] ©
O58 - SDL:2015/11/23 18:48:55 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ve.) -- C:\Windows\System32\drivers\ssudbus.sys [108800] ©
O58 - SDL:2015/11/23 18:49:08 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ve.) -- C:\Windows\System32\drivers\ssudmdm.sys [206080] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\Windows\System32\drivers\stexstor.sys [31072] ©
O58 - SDL:2015/07/10 11:59:48 A . (...) -- C:\Windows\System32\drivers\Udecx.sys [44032]
O58 - SDL:2015/07/10 11:59:39 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [166752] ©
O58 - SDL:2015/07/10 11:59:39 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\Windows\System32\drivers\VSTXRAID.SYS [305504] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - Kernel WinMad.) -- C:\Windows\System32\drivers\winmad.sys [26976] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - Kernel WinVerbs.) -- C:\Windows\System32\drivers\winverbs.sys [59232] ©
O58 - SDL:2015/07/10 11:59:39 A . (.Marvell - NDIS6.30 Miniport Driver for Marvell Yukon.) -- C:\Windows\System32\drivers\yk63x64.sys [295216] ©

---\\ Derniers fichiers modifiés ou crées (Utilisateur) (66) - 60s
O61 - LFC: 2015/11/23 22:45:19 A . (..) -- C:\Users\deiaabdelrahman\Downloads\Firefox Setup Stub 42.0.exe [243992]
O61 - LFC: 2015/11/21 20:04:50 A . (..) -- C:\Users\deiaabdelrahman\Downloads\Windows 10 Loader by KMSpico Daz Activator__13150_i1752150271_il94074.exe [753840] =>HackTool.KMSpico
O61 - LFC: 2015/11/22 17:19:38 A . (.http://www.youtube.com/user/suhylo.) -- C:\Users\deiaabdelrahman\Downloads\Windows 10 WaterMark-Remove (1).exe [567296]
O61 - LFC: 2015/11/22 17:17:09 A . (.http://www.youtube.com/user/suhylo.) -- C:\Users\deiaabdelrahman\Downloads\Windows 10 WaterMark-Remove.exe [567296]
O61 - LFC: 2015/11/23 22:31:56 A . (..) -- C:\Users\deiaabdelrahman\Downloads\Programs\DriversCloudx64_8_0_2_1.exe [5669256]
O61 - LFC: 2015/11/22 19:51:56 A . (..) -- C:\Users\deiaabdelrahman\Downloads\Programs\DriversCloud_Win.exe [268248]
O61 - LFC: 2015/11/24 21:34:51 A . (.Software.) -- C:\Users\deiaabdelrahman\Downloads\Programs\microsoft-office-2010-ser.exe [933320]
O61 - LFC: 2015/11/23 23:21:55 A . (..) -- C:\Users\deiaabdelrahman\Downloads\Programs\winrar-x64-521fr.exe [2038736]
O61 - LFC: 2015/11/22 19:46:57 A . (..) -- C:\Users\deiaabdelrahman\Downloads\IDM 6.25 Build 1 working\idman625build1.exe [6819848]
O61 - LFC: 2015/11/22 19:54:27 A . (..) -- C:\Users\deiaabdelrahman\Desktop\File2.exe [515395]
O61 - LFC: 2015/11/22 19:52:41 A . (..) -- C:\Users\deiaabdelrahman\AppData\Roaming\VOPackage\Uninstall.exe [59080] =>PUP.Optional.Downware
O61 - LFC: 2015/11/22 19:52:26 A . (..) -- C:\Users\deiaabdelrahman\AppData\Roaming\VOPackage\VOPackage.exe [623369] =>PUP.Optional.Downware
O61 - LFC: 2015/11/23 19:23:49 A . (..) -- C:\Users\deiaabdelrahman\AppData\Roaming\systweak\regclean pro\Version 6.1\backup0.bin [595] =>PUP.Optional.RegistryPowerCleaner
O61 - LFC: 2015/11/26 15:01:36 A . (..) -- C:\Users\deiaabdelrahman\AppData\Roaming\systweak\regclean pro\Version 6.1\backup3.bin [514] =>PUP.Optional.RegistryPowerCleaner
O61 - LFC: 2015/11/26 15:01:36 A . (..) -- C:\Users\deiaabdelrahman\AppData\Roaming\systweak\regclean pro\Version 6.1\backup4.bin [716] =>PUP.Optional.RegistryPowerCleaner
O61 - LFC: 2015/11/26 15:01:36 A . (..) -- C:\Users\deiaabdelrahman\AppData\Roaming\systweak\regclean pro\Version 6.1\backup6.bin [515] =>PUP.Optional.RegistryPowerCleaner
O61 - LFC: 2015/11/23 19:23:50 A . (..) -- C:\Users\deiaabdelrahman\AppData\Roaming\systweak\regclean pro\Version 6.1\backup7.bin [657] =>PUP.Optional.RegistryPowerCleaner
O61 - LFC: 2015/11/25 03:15:15 A . (..) -- C:\Users\deiaabdelrahman\AppData\Roaming\RunDir\anbd.exe [160200]
O61 - LFC: 2015/11/20 06:32:09 A . (..) -- C:\Users\deiaabdelrahman\AppData\Roaming\RunDir\cert.exe [130504]
O61 - LFC: 2015/11/25 03:15:15 A . (..) -- C:\Users\deiaabdelrahman\AppData\Roaming\RunDir\temp\anbd.exe [160200]
O61 - LFC: 2015/11/20 06:32:09 A . (..) -- C:\Users\deiaabdelrahman\AppData\Roaming\RunDir\temp\cert.exe [130504]
O61 - LFC: 2015/11/22 19:55:52 A . (..) -- C:\Users\deiaabdelrahman\AppData\Roaming\OpenCandy\3E240221DE4146AA8316C0C11FF9A790\setup.exe [316168] =>PUP.Optional.OpenCandy
O61 - LFC: 2015/11/21 20:09:33 A . (.爱奇艺.) -- C:\Users\deiaabdelrahman\AppData\Roaming\IQIYI Video\LStyle\QyUpdate\IQIYIsetup_update_20150831.exe [54762696] =>.Superfluous.IQIYIVideo
O61 - LFC: 2015/11/21 19:47:53 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\saotech.exe [60416]
O61 - LFC: 2015/11/25 10:20:05 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\LocalState\GameDVR\KnownGameList.bin [38492]
O61 - LFC: 2015/11/21 19:53:36 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_0_Data.bin [2097676]
O61 - LFC: 2015/11/21 19:32:38 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_0_Header.bin [9640]
O61 - LFC: 2015/11/26 18:43:12 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\speech_onecorereg.bin [8192]
O61 - LFC: 2015/11/26 18:09:00 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\UrlBlock\urlblock_635841462953579447.bin [59204]
O61 - LFC: 2015/11/22 20:04:36 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\TYK6KH6V\FinalInstaller_dotnet4[1].exe [3030016]
O61 - LFC: 2015/11/22 20:04:20 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\TYK6KH6V\policyname[1].exe [55404]
O61 - LFC: 2015/11/22 20:05:42 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\TYK6KH6V\setup_38a77a[1].exe [10240]
O61 - LFC: 2015/11/22 19:53:16 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\TYK6KH6V\SFSetup[1].exe [415100]
O61 - LFC: 2015/11/22 19:53:37 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\TYK6KH6V\SU_Srv[1].exe [329216]
O61 - LFC: 2015/11/22 19:47:24 A . (.Copyright (C) 2015.) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\SUV17I4S\Bundle[1].exe [843776]
O61 - LFC: 2015/11/22 19:52:47 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\SUV17I4S\DriversCloudx64_8_0_2_1[1].exe [5669256]
O61 - LFC: 2015/11/22 20:02:03 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\SUV17I4S\o1IgHj[1].exe [162647]
O61 - LFC: 2015/11/21 20:08:14 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\SUV17I4S\qqpcmgr_v10.7.16065.215_71643_Silence[1].exe [1245184]
O61 - LFC: 2015/11/22 20:04:09 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\SUV17I4S\setup_362[1].exe [254464]
O61 - LFC: 2015/11/22 20:04:31 A . (.Copyright 2013.) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\SUV17I4S\Validate[1].exe [61981]
O61 - LFC: 2015/11/22 19:47:01 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\8VZ160D0\5651ffd3a6f68[1].exe [76368]
O61 - LFC: 2015/11/22 20:02:18 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\8VZ160D0\cmi_mystartsearch[1].exe [770224] =>PUP.Optional.StartSearch
O61 - LFC: 2015/11/22 20:01:52 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\8VZ160D0\cmmdWriter[1].exe [52093]
O61 - LFC: 2015/11/22 19:47:20 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\8VZ160D0\icp_istartsurf[1].exe [361720] =>PUP.Optional.IsStart
O61 - LFC: 2015/11/22 20:05:27 A . (.systweak.com.) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\8VZ160D0\rcpsetup_17970[1].exe [4614360]
O61 - LFC: 2015/11/22 19:53:33 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\8VZ160D0\runasu[1].exe [52736]
O61 - LFC: 2015/11/22 19:52:16 A . (.© 2015.) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\38J8I3HU\install[1].exe [372712]
O61 - LFC: 2015/11/22 20:02:38 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\38J8I3HU\prepreinstaller_win[1].exe [332800]
O61 - LFC: 2015/11/22 20:02:15 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\38J8I3HU\SearchUpdater[1].exe [130691]
O61 - LFC: 2015/11/22 19:56:14 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\38J8I3HU\sevenzip-setup-ap[1].exe [1119845]
O61 - LFC: 2015/11/22 20:02:29 A . (.Copyright © 2014.) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\38J8I3HU\SilentInstaller_dotnet4[1].exe [317952]
O61 - LFC: 2015/11/22 19:53:35 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\38J8I3HU\Update_Notifier[1].exe [604672]
O61 - LFC: 2015/11/22 20:05:06 A . (.Copyright 2013.) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\38J8I3HU\Validate[1].exe [61981]
O61 - LFC: 2015/11/22 19:52:26 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\38J8I3HU\VOPackage[1].exe [623369] =>PUP.Optional.Downware
O61 - LFC: 2015/11/22 20:04:44 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\38J8I3HU\VuuPC_VO2_8907[1].exe [232469] =>PUP.Optional.VuuPC
O61 - LFC: 2015/11/21 19:33:18 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\1036\StructuredQuerySchema.bin [433477]
O61 - LFC: 2015/11/22 20:07:19 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Internet Explorer\UrlBlock\urlblock_635838133505512056.bin [59936]
O61 - LFC: 2015/11/22 16:35:52 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Microsoft\GameDVR\KnownGameList.bin [48528]
O61 - LFC: 2015/11/26 18:38:19 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\FFFFFFFF-1448563076-FFFF-FFFF-FFFFFFFFFFFF\Uninstall.exe [51069]
O61 - LFC: 2015/11/22 18:23:44 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\FFFFFFFF-1448222012-FFFF-FFFF-FFFFFFFFFFFF\pnsa8F81.exe [127515]
O61 - LFC: 2015/11/22 19:53:33 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\FFFFFFFF-1448222012-FFFF-FFFF-FFFFFFFFFFFF\rnsa8F7F.exe [52736]
O61 - LFC: 2015/11/22 19:53:37 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\FFFFFFFF-1448222012-FFFF-FFFF-FFFFFFFFFFFF\Uninstall.exe [50341]
O61 - LFC: 2015/11/21 19:45:05 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Cooking Comp\zBin\CookingComp.dll [30720]
O61 - LFC: 2015/11/21 19:45:05 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\Cooking Comp\zBin\xjryq.dll [12288]
O61 - LFC: 2015/11/22 20:06:41 A . (.IMALI - N.I. MEDIA LTD.) -- C:\Users\deiaabdelrahman\AppData\Local\Chromium\Application\45.0.2433.0\Installer\setup.exe [933376]
O61 - LFC: 2015/11/26 18:47:59 A . (..) -- C:\Users\deiaabdelrahman\AppData\Local\ATI\ACE\Manifest.Bin [30042]

---\\ Associations Shell Spawning (11) - 1s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe ©
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe ©
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ©
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe ©
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe ©
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe ©

---\\ Menu de démarrage Internet (12) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe ©
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Internet Explorer\iexplore.ex http://www.istartsurf.com/ =>PUP.Optional.IsStart
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files (x86)\Opera\Launcher.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - 'Firefox' Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Program Files (x86)\Opera\Launcher.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - 'Firefox' Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Program Files (x86)\Opera\Launcher.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - 'Firefox' Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Program Files (x86)\Opera\Launcher.exe (.not file.)

---\\ Recherche d'infection sur les navigateurs (4) - 8s
O69 - SBI: prefs.js [deiaabdelrahman - 21432xnr.default] user_pref("browser.newtab.url", "C:\\ProgramData\\Zitenops\\ff.NT"); =>PUP.Optional.Salus
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com/
O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} - (oursurfing) - http://www.oursurfing.com/
O69 - SBI: SearchScopes [HKCU] {ielnksrch} [DefaultScope] - (Search the web) - http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_ByuMcS4zqTgWbU8u6bdWk3wHHtbAzGu1_BGEJNsz3ML44dgC7s4RvgkgFF2x1lN9rRQpiFxTZBz8sn47SP0CpxuL9gz1JvJuOCGXg6_8brAxYs9rzojm-hCXU8nNuBznyWHAJsPYpnrCZD-TxaiPVZB2o-sl5&q={searchTerms}

---\\ Enumère les services démarrés par Svchost (42) - 1s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [192000] ©
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [192000] ©
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [283136] ©
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [1335296] ©
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\IKEEXT.DLL [954368] ©
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [954880] ©
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\System32\seclogon.dll [31232] ©
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [93696] ©
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [151040] ©
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [106496] ©
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1008640] ©
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [226304] ©
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [133120] ©
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [324608] ©
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [371200] ©
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [95744] ©
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\Windows\System32\wlidsvc.dll [2093056] ©
O83 - Search Svchost Services: DcpSvc (DcpSvc) . (.Microsoft Corporation - dcpsvc Task.) -- C:\Windows\System32\dcpsvc.dll [196096] ©
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\Windows\System32\NcaSvc.dll [167424] ©
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Service Configuration du réseau.) -- C:\Windows\System32\NetSetupSvc.dll [187392] ©
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [106496] ©
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\Windows\System32\rasmans.dll [679936] ©
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [497152] ©
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [72192] ©
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [452608] ©
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [311808] ©
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\System32\wuaueng.dll [2236416] ©
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [1168896] ©
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [593920] ©
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\Windows\System32\dmwappushsvc.dll [63488] ©
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\Windows\System32\XblGameSave.dll [1149440] ©
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\Windows\System32\XboxNetApiSvc.dll [1019392] ©
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Mettre à jour la session Orchestrator Core.) -- C:\Windows\System32\usocore.dll [343040] ©
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\Windows\System32\usermgr.dll [713216] ©
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service de géolocalisation.) -- C:\Windows\System32\lfsvc.dll [27136] ©
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - DLL Windows Management Service.) -- C:\Windows\System32\Windows.Internal.Management.dll [267776] ©
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\Windows\System32\XblAuthManager.dll [918016] ©
O83 - Search Svchost Services: RetailDemo (RetailDemo) . (.Microsoft Corporation - RDXService.) -- C:\Windows\System32\RDXService.dll [1015808] ©
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [359936] ©
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\Windows\System32\DeviceSetupManager.dll [237568] ©
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [58368] ©
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [200192] ©

---\\ Liste des exceptions du parefeu Windows (9) - 2s
O87 - FAEL: "{79212358-7564-4782-906A-30BC0F5BCF61}" [In-None-P6-TRUE] .(...) -- C:\Users\deiaabdelrahman\AppData\Roaming\IQIYI Video\LStyle\GpUpdate.exe (.not file.) =>.Superfluous.IQIYIVideo
O87 - FAEL: "{4434791F-FD4F-4694-8A8E-57782A2CB6F4}" [In-None-P6-TRUE] .(.爱奇艺 - 爱奇艺万能播放器.) -- C:\IQIYI Video\GeePlayer\GeePlayer.exe =>.Superfluous.IQIYIVideo
O87 - FAEL: "{18A70389-49DE-4E6C-9E9C-99DE77BEF618}" [In-None-P6-TRUE] .(.爱奇艺 - 爱奇艺升级模块.) -- C:\Users\deiaabdelrahman\AppData\Roaming\IQIYI Video\LStyle\QyUpdate.exe =>.Superfluous.IQIYIVideo
O87 - FAEL: "{2ED4503C-E8DF-4B8C-8847-FE43192FAC23}" [In-None-P6-TRUE] .(.爱奇艺 - 爱奇艺PPS影音.) -- C:\IQIYI Video\LStyle\QyClient.exe =>.Superfluous.IQIYIVideo
O87 - FAEL: "{57076047-9FC4-434B-9343-F35101CF0A50}" [In-None-P6-TRUE] .(.爱奇艺公司 - 爱奇艺PPS影音 网页播放组件.) -- C:\IQIYI Video\LStyle\QyWebPlayer.exe =>.Superfluous.IQIYIVideo
O87 - FAEL: "{4BFC2406-219E-4700-B79D-0197B92C912F}" [In-None-P6-TRUE] .(.爱奇艺 - 爱奇艺视频播放器.) -- C:\IQIYI Video\LStyle\QyPlayer.exe =>.Superfluous.IQIYIVideo
O87 - FAEL: "{A4CEFDA4-9B78-493B-8CCF-CFF9FB11F6A5}" [In-None-P17-TRUE] .(.IMALI - N.I. MEDIA LTD - Internet Quick Access.) -- C:\Users\deiaabdelrahman\AppData\Local\Chromium\Application\chrome.exe
O87 - FAEL: "{5D79633B-7960-466E-95D5-2AF58D6CBE09}" [In-None-P17-TRUE] .(.爱奇艺 - 爱奇艺升级模块.) -- C:\Users\deiaabdelrahman\AppData\Roaming\IQIYI Video\GeePlayer\GpUpdate.exe =>.Superfluous.IQIYIVideo
O87 - FAEL: "{C2F6A154-3008-498D-AD51-B2E842D12EF7}" [In-None-P17-TRUE] .(.爱奇艺 - 爱奇艺万能播放器.) -- C:\IQIYI Video\GeePlayer\GeePlayer\GeePlayer.exe =>.Superfluous.IQIYIVideo

---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (17) - 20s

SS - Demand [22/11/2015] [ 268976] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ©
SR - Auto [21/11/2015] [ 238080] (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe ©
SR - Auto [06/08/2015] [ 344064] AMD FUEL Service (AMD FUEL Service) . (.Advanced Micro Devices, Inc..) - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe ©
SR - Auto [21/11/2015] [ 792576] ApplicationHosting (ApplicationHosting) . (...) - C:\ProgramData\ApplicationHosting\ApplicationHosting.exe =>PUP.Optional.ApplicationHosting
SR - Auto [22/11/2015] [ 792576] caMyciloP (caMyciloP) . (...) - C:\ProgramData\caMyciloP\caMyciloP.exe =>PUP.Optional.Salus
SR - Auto [21/11/2015] [ 60416] Saotouch (downloadexproduci) . (...) - C:\Users\deiaabdelrahman\AppData\Local\saotech.exe
SR - Auto [12/11/2015] [ 379904] Dripkix Service (Dripkix) . (.Copyright © 2015.) - C:\Program Files\Dripkix\Dripkix.exe =>PUP.Optional.Amonetize
SR - Auto [13/10/2015] [ 142336] Normal Blind Carbon Copy (hidekoqe) . (...) - C:\Users\deiaabdelrahman\AppData\Local\FFFFFFFF-1448563076-FFFF-FFFF-FFFFFFFFFFFF\qnsgFAB2.tmp =>PUP.Optional.CrossRider
SR - Auto [18/10/2015] [ 379392] Zap Controller (hotnix32) . (.Copyright © 2015.) - C:\Program Files\NixController\hotnix.exe =>PUP.Optional.Amonetize
SR - Auto [21/11/2015] [ 792576] Medlight (Medlight) . (...) - C:\ProgramData\Medlight\Medlight.exe =>PUP.Optional.Salus
SS - Demand [30/10/2015] [ 147624] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe ©
SR - Auto [09/07/2015] [ 173088] Net.Tcp Service Handler (NetTcpHandler) . (...) - C:\Users\deiaabdelrahman\AppData\Roaming\NetService\netservice.exe =>PUP.Optional.NetService
SR - Auto [22/11/2015] [ 329216] Red Green Blue Dual Core (rylusycy) . (...) - C:\Users\deiaabdelrahman\AppData\Local\FFFFFFFF-1448222012-FFFF-FFFF-FFFFFFFFFFFF\snsa8F7E.tmp =>PUP.Optional.CrossRider
SR - Auto [26/11/2015] [ 635624] Service Mgr LuckyBright (Service Mgr LuckyBright) . (...) - C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugincontainer.exe =>PUP.Optional.LuckyBright
SR - Auto [26/11/2015] [ 541928] Update Mgr LuckyBright (Update Mgr LuckyBright) . (...) - C:\Program Files (x86)\Common Files\9466af57-1f38-4973-ab1c-22f7e17e2d6a\updater.exe =>PUP.Optional.LuckyBright
SR - Auto [23/11/2015] [ 792576] Zitenop (Zitenop) . (...) - C:\ProgramData\Zitenop\Zitenop.exe =>PUP.Optional.Salus

---\\ Recherche de clés de registre Tracing (10) - 2s
HKLM\SOFTWARE\Microsoft\Tracing\Dripkix_RASAPI32 =>PUP.Optional.Amonetize
HKLM\SOFTWARE\Microsoft\Tracing\Dripkix_RASMANCS =>PUP.Optional.Amonetize
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ApplicationHosting_RASAPI32 =>PUP.Optional.ApplicationHosting
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ApplicationHosting_RASMANCS =>PUP.Optional.ApplicationHosting
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\caMyciloP_RASAPI32 =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\caMyciloP_RASMANCS =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Medlight_RASAPI32 =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Medlight_RASMANCS =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Zitenop_RASAPI32 =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Zitenop_RASMANCS =>PUP.Optional.Salus

---\\ Scan Additionnel (128) - 0s
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IQIYI Video =>.Superfluous.IQIYIVideo
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\istartsurf uninstall =>PUP.Optional.IsStart
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\jogotempo =>PUP.Optional.Jogotempo
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Lucky Bright =>PUP.Optional.LuckyBright
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\oursurfing =>PUP.Optional.OurSurfing
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PopupProduct =>PUP.Optional.CompatibleWebDir
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RegClean Pro_is1 =>PUP.Optional.RegistryPowerCleaner
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdater =>PUP.Optional.SoftwareUpdater
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage =>PUP.Optional.Downware
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A2E4F0FE-3938-4317-B720-EA4D8E4D092C} =>PUP.Optional.SmartBar
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InternetQuickAccess =>PUP.Optional.InternetQuickAccess
HKLM\SOFTWARE\Wow6432Node\downchecker =>PUP.Optional.DownChecker
HKLM\SOFTWARE\Wow6432Node\ihpmserver =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\im-dosearch =>PUP.Optional.Generic
HKLM\SOFTWARE\Wow6432Node\LuckyBright =>PUP.Optional.LuckyBright
HKLM\SOFTWARE\Wow6432Node\navegaki =>PUP.Optional.Navegaki
HKLM\SOFTWARE\Wow6432Node\NetTcpHandler =>PUP.Optional.NetService
HKLM\SOFTWARE\Wow6432Node\NtSvcHandler =>PUP.Optional.NetService
HKLM\SOFTWARE\Wow6432Node\oursurfingSoftware =>PUP.Optional.OurSurfing
HKLM\SOFTWARE\Wow6432Node\RayDld =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Sakura =>PUP.Optional.GameGogle
HKLM\SOFTWARE\Wow6432Node\Systweak =>PUP.Optional.Systweak
HKLM\SOFTWARE\Wow6432Node\WdsManPro =>PUP.Optional.WdsManPro
HKCU\SOFTWARE\QyGameClient =>.Superfluous.IQIYIVideo
HKCU\SOFTWARE\systweak =>PUP.Optional.Systweak
HKLM\SYSTEM\CurrentControlSet\Services\ApplicationHosting =>PUP.Optional.ApplicationHosting
C:\ProgramData\ApplicationHosting\ApplicationHosting.exe =>PUP.Optional.ApplicationHosting
HKLM\SYSTEM\CurrentControlSet\Services\caMyciloP =>PUP.Optional.Salus
C:\ProgramData\caMyciloP\caMyciloP.exe =>PUP.Optional.Salus
HKLM\SYSTEM\CurrentControlSet\Services\Dripkix =>PUP.Optional.Amonetize
C:\Program Files\Dripkix\Dripkix.exe =>PUP.Optional.Amonetize
HKLM\SYSTEM\CurrentControlSet\Services\hidekoqe =>PUP.Optional.CrossRider
C:\Users\deiaabdelrahman\AppData\Local\FFFFFFFF-1448563076-FFFF-FFFF-FFFFFFFFFFFF\qnsgFAB2.tmp =>PUP.Optional.CrossRider
HKLM\SYSTEM\CurrentControlSet\Services\hotnix32 =>PUP.Optional.Amonetize
C:\Program Files\NixController\hotnix.exe =>PUP.Optional.Amonetize
HKLM\SYSTEM\CurrentControlSet\Services\Medlight =>PUP.Optional.Salus
C:\ProgramData\Medlight\Medlight.exe =>PUP.Optional.Salus
HKLM\SYSTEM\CurrentControlSet\Services\NetTcpHandler =>PUP.Optional.NetService
C:\Users\deiaabdelrahman\AppData\Roaming\NetService\netservice.exe =>PUP.Optional.NetService
HKLM\SYSTEM\CurrentControlSet\Services\rylusycy =>PUP.Optional.CrossRider
C:\Users\deiaabdelrahman\AppData\Local\FFFFFFFF-1448222012-FFFF-FFFF-FFFFFFFFFFFF\snsa8F7E.tmp =>PUP.Optional.CrossRider
HKLM\SOFTWARE\LuckyBright =>PUP.Optional.LuckyBright
C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a =>PUP.Optional.LuckyBright
C:\Program Files (x86)\Common Files\9466af57-1f38-4973-ab1c-22f7e17e2d6a =>PUP.Optional.LuckyBright
HKLM\SYSTEM\CurrentControlSet\Services\Service Mgr LuckyBright =>PUP.Optional.LuckyBright
C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugincontainer.exe =>PUP.Optional.LuckyBright
HKLM\SYSTEM\CurrentControlSet\Services\Update Mgr LuckyBright =>PUP.Optional.LuckyBright
C:\Program Files (x86)\Common Files\9466af57-1f38-4973-ab1c-22f7e17e2d6a\updater.exe =>PUP.Optional.LuckyBright
HKLM\SYSTEM\CurrentControlSet\Services\Zitenop =>PUP.Optional.Salus
C:\ProgramData\Zitenop\Zitenop.exe =>PUP.Optional.Salus
C:\Program Files (x86)\RCP\RegCleanPro.exe =>PUP.Optional.RegistryPowerCleaner
C:\Windows\Tasks\RegClean Pro_DEFAULT.job =>PUP.Optional.RegistryPowerCleaner
C:\Windows\Tasks\RegClean Pro_UPDATES.job =>PUP.Optional.RegistryPowerCleaner
C:\Windows\System32\Tasks\RegClean Pro_DEFAULT =>PUP.Optional.RegistryPowerCleaner
C:\Windows\System32\Tasks\RegClean Pro_UPDATES =>PUP.Optional.RegistryPowerCleaner
C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugincontainer.exe =>PUP.Optional.CrossRider
C:\Program Files\Dripkix\packages\b542ac8e-9176-43e9-a72a-a53f8e7797b7\Drip.exe =>PUP.Optional.Amonetize
C:\Program Files (x86)\Common Files\9466af57-1f38-4973-ab1c-22f7e17e2d6a\updater.exe =>PUP.Optional.CrossRider
C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\10\Plugin.exe =>PUP.Optional.CrossRider
C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\5\Plugin.exe =>PUP.Optional.CrossRider
C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\7\Plugin.exe =>PUP.Optional.CrossRider
C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\3\Plugin.exe =>PUP.Optional.CrossRider
C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\8\Plugin.exe =>PUP.Optional.CrossRider
C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\12\Plugin.exe =>PUP.Optional.CrossRider
C:\ProgramData\9466af57-1f38-4973-ab1c-22f7e17e2d6a\plugins\2\Plugin.exe =>PUP.Optional.CrossRider
C:\Users\deiaabdelrahman\AppData\Roaming\Mozilla\Firefox\Profiles\21432xnr.default\extensions\adguardadblocker@adguard.com.xpi =>PUP.Optional.Adblocker
C:\Users\deiaabdelrahman\AppData\Roaming\Mozilla\Firefox\Profiles\21432xnr.default\searchplugins\findit.xml =>PUP.Optional.SmartBar
C:\IQIYI Video\LStyle\npWebPlayer.dll =>.Superfluous.IQIYIVideo
C:\ProgramData\caMyciloP\Icetamtech.dll =>PUP.Optional.Salus
C:\Program Files (x86)\FFFFFFFF-1448218360-FFFF-FFFF-FFFFFFFFFFFF =>PUP.Optional.CrossRider
C:\Program Files (x86)\jogotempo =>PUP.Optional.Jogotempo
C:\Program Files (x86)\Lucky Bright =>PUP.Optional.LuckyBright
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro =>PUP.Optional.RegistryPowerCleaner
C:\ProgramData\ApplicationHosting =>PUP.Optional.ApplicationHosting
C:\ProgramData\caMyciloP =>PUP.Optional.Salus
C:\ProgramData\caMyciloPs =>PUP.Optional.Salus
C:\ProgramData\IQIYI Video =>.Superfluous.IQIYIVideo
C:\ProgramData\Medlight =>PUP.Optional.Salus
C:\ProgramData\Medlights =>PUP.Optional.Salus
C:\ProgramData\Zitenop =>PUP.Optional.Salus
C:\ProgramData\Zitenops =>PUP.Optional.Salus
C:\Users\deiaabdelrahman\AppData\Roaming\IQIYI Video =>.Superfluous.IQIYIVideo
C:\Users\deiaabdelrahman\AppData\Roaming\istartpageing =>PUP.Optional.IstartPageing
C:\Users\deiaabdelrahman\AppData\Roaming\NetService =>PUP.Optional.NetService
C:\Users\deiaabdelrahman\AppData\Roaming\OpenCandy =>PUP.Optional.OpenCandy
C:\Users\deiaabdelrahman\AppData\Roaming\RunDir =>PUP.Optional.NetService
C:\Users\deiaabdelrahman\AppData\Roaming\systweak =>PUP.Optional.Systweak
C:\Users\deiaabdelrahman\AppData\Roaming\VOPackage =>PUP.Optional.Downware
C:\Users\deiaabdelrahman\AppData\Local\SysassistByHotWheel =>PUP.Optional.Generic
C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Quick Access =>PUP.Optional.InternetQuickAccess
C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\jogotempo =>PUP.Optional.Jogotempo
C:\Users\deiaabdelrahman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage =>PUP.Optional.Downware
C:\Windows\Prefetch\CAMYCILOP.EXE-6CEDE6AE.pf =>PUP.Optional.Salus
C:\Windows\Prefetch\MEDLIGHT.EXE-AB202790.pf =>PUP.Optional.Salus
C:\Windows\Prefetch\QIYIDACL.EXE-DD71C206.pf =>.Superfluous.IQIYIVideo
C:\Windows\Prefetch\WINDOWS 10 LOADER BY KMSPICO -77EA2A90.pf =>HackTool.KMSpico
C:\Windows\Prefetch\ZITENOP.EXE-7623D2DE.pf =>PUP.Optional.Salus
C:\Users\deiaabdelrahman\Downloads\Windows 10 Loader by KMSpico Daz Activator__13150_i1752150271_il94074.exe =>HackTool.KMSpico
C:\Users\deiaabdelrahman\AppData\Roaming\VOPackage\Uninstall.exe =>PUP.Optional.Downware
C:\Users\deiaabdelrahman\AppData\Roaming\VOPackage\VOPackage.exe =>PUP.Optional.Downware
C:\Users\deiaabdelrahman\AppData\Roaming\systweak\regclean pro\Version 6.1\backup0.bin =>PUP.Optional.RegistryPowerCleaner
C:\Users\deiaabdelrahman\AppData\Roaming\systweak\regclean pro\Version 6.1\backup3.bin =>PUP.Optional.RegistryPowerCleaner
C:\Users\deiaabdelrahman\AppData\Roaming\systweak\regclean pro\Version 6.1\backup4.bin =>PUP.Optional.RegistryPowerCleaner
C:\Users\deiaabdelrahman\AppData\Roaming\systweak\regclean pro\Version 6.1\backup6.bin =>PUP.Optional.RegistryPowerCleaner
C:\Users\deiaabdelrahman\AppData\Roaming\systweak\regclean pro\Version 6.1\backup7.bin =>PUP.Optional.RegistryPowerCleaner
C:\Users\deiaabdelrahman\AppData\Roaming\OpenCandy\3E240221DE4146AA8316C0C11FF9A790\setup.exe =>PUP.Optional.OpenCandy
C:\Users\deiaabdelrahman\AppData\Roaming\IQIYI Video\LStyle\QyUpdate\IQIYIsetup_update_20150831.exe =>.Superfluous.IQIYIVideo
C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\8VZ160D0\cmi_mystartsearch[1].exe =>PUP.Optional.StartSearch
C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\8VZ160D0\icp_istartsurf[1].exe =>PUP.Optional.IsStart
C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\38J8I3HU\VOPackage[1].exe =>PUP.Optional.Downware
C:\Users\deiaabdelrahman\AppData\Local\Microsoft\Windows\INetCache\IE\38J8I3HU\VuuPC_VO2_8907[1].exe =>PUP.Optional.VuuPC
C:\IQIYI Video\GeePlayer\GeePlayer.exe =>.Superfluous.IQIYIVideo
C:\Users\deiaabdelrahman\AppData\Roaming\IQIYI Video\LStyle\QyUpdate.exe =>.Superfluous.IQIYIVideo
C:\IQIYI Video\LStyle\QyClient.exe =>.Superfluous.IQIYIVideo
C:\IQIYI Video\LStyle\QyWebPlayer.exe =>.Superfluous.IQIYIVideo
C:\IQIYI Video\LStyle\QyPlayer.exe =>.Superfluous.IQIYIVideo
C:\Users\deiaabdelrahman\AppData\Roaming\IQIYI Video\GeePlayer\GpUpdate.exe =>.Superfluous.IQIYIVideo
C:\IQIYI Video\GeePlayer\GeePlayer\GeePlayer.exe =>.Superfluous.IQIYIVideo
HKLM64\SOFTWARE\Microsoft\Tracing\Dripkix_RASAPI32 =>PUP.Optional.Amonetize
HKLM64\SOFTWARE\Microsoft\Tracing\Dripkix_RASMANCS =>PUP.Optional.Amonetize
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ApplicationHosting_RASAPI32 =>PUP.Optional.ApplicationHosting
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ApplicationHosting_RASMANCS =>PUP.Optional.ApplicationHosting
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\caMyciloP_RASAPI32 =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\caMyciloP_RASMANCS =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Medlight_RASAPI32 =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Medlight_RASMANCS =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Zitenop_RASAPI32 =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Zitenop_RASMANCS =>PUP.Optional.Salus

---\\ Récapitulatif des éléments trouvés sur votre station (29) - 0s
http://www.nicolascoolman.fr/?p=4664 =>.Superfluous.IQIYIVideo
http://www.nicolascoolman.fr/?p=1994 =>PUP.Optional.IsStart
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.Jogotempo
http://www.nicolascoolman.fr/?p=4907 =>PUP.Optional.LuckyBright
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.OurSurfing
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.CompatibleWebDir
http://www.nicolascoolman.fr/?p=558 =>PUP.Optional.RegistryPowerCleaner
http://www.nicolascoolman.fr/?p=641 =>PUP.Optional.SoftwareUpdater
http://www.nicolascoolman.fr/?p=401 =>PUP.Optional.Downware
http://www.nicolascoolman.fr/?p=308 =>PUP.Optional.SmartBar
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.InternetQuickAccess
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.DownChecker
http://www.nicolascoolman.fr/?p=180 =>PUP.Optional.CrossRider
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.Generic
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.Navegaki
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.NetService
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.GameGogle
http://www.nicolascoolman.fr/?p=2580 =>PUP.Optional.Systweak
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.WdsManPro
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.ApplicationHosting
http://www.nicolascoolman.fr/?p=2645 =>PUP.Optional.Salus
http://www.nicolascoolman.fr/?p=2072 =>PUP.Optional.Amonetize
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.Adblocker
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.Linkury
http://www.nicolascoolman.fr/?p=4936 =>PUP.Optional.IstartPageing
http://www.nicolascoolman.fr/?p=197 =>PUP.Optional.OpenCandy
http://www.nicolascoolman.fr/?p=989 =>HackTool.KMSpico
http://www.nicolascoolman.fr/?p=4060 =>PUP.Optional.StartSearch
http://www.nicolascoolman.fr/?p=1216 =>PUP.Optional.VuuPC

~ End of the scan, 16028 items in 137 seconds (879)(0)

Publicité


Signaler le contenu de ce document

Publicité