cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.12.7.181 Par Nicolas Coolman (2015/12/07)
~ Démarré par Alexis (Administrator) (2015/12/08 22:33:38)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Users\Alexis\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\Alexis\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Deactivate
~ Démarrage du système: Normal (Normal boot)
Windows 7 Ultimate, 64-bit (Build 7601)

---\\ Navigateurs Internet (3) - 0s
GCIE: Google Chrome v46.0.2490.86
MFIE: Mozilla Firefox 42.0 (x86 fr) v42.0
MSIE: Internet Explorer v9.0.8112.16421

---\\ Informations sur les produits Windows (4) - 3s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK
Windows Activation Technologies : KO

---\\ Logiciels de protection (1) - 3s
Windows Defender W7 (Deactivate)

---\\ Logiciels d'optimisation (1) - 4s
CCleaner v5.11

---\\ Surveillance de Logiciels (1) - 4s
Adobe Flash Player 19 NPAPI

---\\ Informations sur le système (6) - 0s
~ Operating System: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 8345.8 MB (55% free)
System Restore: Activé (Enable)
System drive C: has 8 GB () free of 155 GB =>Alerte espace disque inférieur à 20 Go

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: ALEXIS-PC
~ User Name: Alexis
~ Logged in as Administrator

---\\ Enumération des unités disques (3) - 0s
~ Drive C: has 8 GB free of 155 GB (System)
~ Drive D: has 11 GB free of 149 GB
~ Drive F: has GB free of 0 GB

---\\ Etat du Centre de Sécurité Windows (11) - 0s
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoResolveSearch: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: Modified
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Recherche particulière de fichiers génériques (26) - 2s
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - 25/02/2011 - (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\Explorer.exe [2871808] ©
[MD5.DD81D91FF3B0763C392422865C9AC12E] - 14/07/2009 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe [45568] ©
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - 14/07/2009 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\System32\Wininit.exe [129024] ©
[MD5.5A45FA344F4AD99D903F4B20E43B89EC] - 11/07/2012 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [1392128] ©
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - 21/11/2010 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\Windows\System32\Winlogon.exe [390656] ©
[MD5.067FA52BFB59A56110A12312EF9AF243] - 21/11/2010 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [232448] ©
[MD5.2EE46D0268B69DFED15647DD974FE37E] - 11/07/2012 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\System32\dnsapi.dll [357888] © =>Hijacker.DNS.Hosts
[MD5.444D310F8A73A1E4DE5BB650B3708462] - 11/07/2012 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\Syswow64\dnsapi.dll [270336] © =>Hijacker.DNS.Hosts
[MD5.0D57D091E06BB1E58E72E5D08479FDDF] - 21/11/2010 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [20480] ©
[MD5.1C7857B62DE5994A75B054A9FD4C3825] - 28/12/2011 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [498688] ©
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - 14/07/2009 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [24128] =>.Microsoft Windows®
[MD5.B8BD2BB284668C84865658C77574381A] - 14/07/2009 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [92160] ©
[MD5.F036CE71586E93D94DAB220D7BDF4416] - 21/11/2010 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [147456] ©
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - 21/11/2010 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [102400] ©
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - 21/11/2010 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [122368] ©
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - 14/07/2009 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [105472] ©
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - 14/07/2009 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [116224] ©
[MD5.A5D9106A73DC88564C825D317CAC68AC] - 27/04/2011 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [158208] ©
[MD5.09594D1089C523423B32A4229263F068] - 21/11/2010 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [261632] ©
[MD5.05D78AA5CB5F3F5C31160BDB955D0B7C] - 21/11/2010 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [1659776] =>.Microsoft Windows®
[MD5.0086431C29C35BE1DBC43F52CC273887] - 14/07/2009 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\Parport.sys [97280] ©
[MD5.471815800AE33E6F1C32FB1B97C490CA] - 21/11/2010 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [129536] ©
[MD5.1B6163C503398B23FF8B939C67747683] - 21/11/2010 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [165888] ©
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - 14/07/2009 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [93184] ©
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - 21/11/2010 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [119296] ©
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - 21/11/2010 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [295808] =>.Microsoft Windows®

---\\ Liste des services NT non Microsoft et non désactivés (24) - 2s
O23 - Service: Airtop (Airtop) . (...) - C:\ProgramData\Airtop\Airtop.exe =>PUP.Optional.Salus
O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\System32\atiesrxx.exe ©
O23 - Service: Apple Mobile Device Service (Apple Mobile Device Service) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe =>.Apple Inc.®
O23 - Service: ApplicationHosting (ApplicationHosting) . (...) - C:\ProgramData\ApplicationHosting\ApplicationHosting.exe =>PUP.Optional.ApplicationHosting
O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.®
O23 - Service: Service Mise à jour Dropbox (dbupdate) (dbupdate) . (.Dropbox, Inc. - Dropbox Update.) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe {0C89CBE063927780186EC0063F10D323} ©
O23 - Service: Touchla (doonioaduuaate) . (. - xrc.) - C:\Users\Alexis\AppData\Local\Labsoltax.exe
O23 - Service: Dripkix Service (Dripkix) . (.Copyright © 2015 - .) - C:\Program Files\Dripkix\Dripkix.exe =>PUP.Optional.Amonetize
O23 - Service: FastCompress (FastCompress) . (.Adlegend Media - Support File.) - C:\Program Files (x86)\FastCompress-Zip\Fast_Support.exe {11210D7D7D1C16D9150B69F8767D7C855E19} ©
O23 - Service: Desktop Upload (ginoquci) . (...) - C:\Users\Alexis\AppData\Local\Temp\nsb8202.tmp
O23 - Service: Rename Outline (gufutoqu) . (...) - C:\Program Files (x86)\032B0290-1449484090-0559-0306-940700080009\knsjC532.tmp =>PUP.Optional.CrossRider
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
O23 - Service: Ma-Config Agent (MaConfigAgent) . (.CybelSoft - Service de détection matériel.) - C:\Program Files\ma-config.com\MaConfigAgent.exe =>.Cybelsoft®
O23 - Service: Add Telephone Line (nyneryxo) . (...) - C:\Program Files (x86)\032B0290-1449484090-0559-0306-940700080009\hnsg5CE7.tmp =>PUP.Optional.CrossRider
O23 - Service: Razer Game Scanner (Razer Game Scanner Service) . (.Copyright © 2013-2015 - GameScannerService.) - C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe =>.Razer Inc.®
O23 - Service: Free Up Joystick (roqenufe) . (...) - C:\Program Files (x86)\032B0290-1449484090-0559-0306-940700080009\jnsb480E.tmp =>PUP.Optional.CrossRider
O23 - Service: RzKLService (RzKLService) . (.Razer Inc. - RzKLService.exe.) - C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe =>.Razer Inc.®
O23 - Service: Razer Surround Audio Service (RzMaelstromVADStreamingService) . (.A-Volute - Maelstrom VAD Streaming Service.) - C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzMaelstromVADStreamingService.exe
O23 - Service: SSFK (SSFK) . (.TODO: <公司名> - TODO: <文件说明>.) - C:\Program Files (x86)\SFK\SSFK.exe {1121D343CEADB8041BAC48B044906C5E105E} =>PUP.Optional.MyWebSearch
O23 - Service: SAMSUNG Mobile Connectivity Service (ss_conn_service) . (.DEVGURU Co., LTD. - MSS CS Connectivity Service.) - C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe =>.DEVGURU CO LTD®
O23 - Service: Update Mgr AssistPoint (Update Mgr AssistPoint) . (...) - C:\Program Files (x86)\Common Files\c716fd70-872c-4aaa-a07f-e248365d7f56\updater.exe (.not file.) =>PUP.Optional.AssistPoint
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) . (.Sysinternals process Explorer - Sysinternals process Explorer.) - C:\ProgramData\Tmp0x0x\ProtectWindowsManager.exe {11215BD52CE822E39F61AAE0642B2F566ABD} =>PUP.Optional.WpManager
O23 - Service: WNetEnhancer Service (WNetEnhancer Service) . (...) - C:\Program Files (x86)\WNetEnhancer\WNetEnhancer Internet Enhancer\663d2e82e7a5dc32e243ab08ac2ec4a6.exe =>PUP.Optional.Wajam
O23 - Service: Zitenop (Zitenop) . (...) - C:\ProgramData\Zitenop\Zitenop.exe =>PUP.Optional.Salus

---\\ Tâches planifiées en automatique (33) - 8s
[MD5.280A526E8111AC6A5BCC1A059E1E0340] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [269000] =>.Adobe Systems Incorporated®
[MD5.00000000000000000000000000000000] [APT] [AdobeAAMUpdater-1.0-Alexis-PC-Alexis] (...) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (.not file.) [0]
[MD5.E49FD011745BFC5621C586CCD07FF81E] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6564776] =>.Piriform Ltd®
[MD5.33BFEC2B102B196B62ABB9947C7D7E23] [APT] [DropboxUpdateTaskMachineCore] (.Dropbox, Inc..) -- C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048] {0C89CBE063927780186EC0063F10D323} ©
[MD5.33BFEC2B102B196B62ABB9947C7D7E23] [APT] [DropboxUpdateTaskMachineUA] (.Dropbox, Inc..) -- C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048] {0C89CBE063927780186EC0063F10D323} ©
[MD5.053EEEE1ABAE53F044F1E386E22AE525] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc®
[MD5.053EEEE1ABAE53F044F1E386E22AE525] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc®
[MD5.5CB43CAD6E0507ED5363DD352478D408] [APT] [kol3015] (...) -- C:\Program Files (x86)\Fast-Search\kol3015.exe [58701] =>PUP.Optional.FastSearch
[MD5.B7DE5EBDB81CA20938830638FBBBB779] [APT] [updateTask] (...) -- c:/task.vbs [592]
[MD5.00000000000000000000000000000000] [APT] [Urecceqm] (...) -- C:\PROGRA~1\GROOVE~1\Okael.bat (.not file.) [0] =>PUP.Optional.Groover
[MD5.8643E609F6E5C53EFD9AF59CBBEFEE1D] [APT] [VKCAGRPJFKDHGGAN] (.All rights reserved..) -- C:\ProgramData\Service7609\Service7609.exe [419328] =>Heuristic.Graftor
[MD5.7A2870C2A8283B3630BF7670D0362B94] [APT] [{195C9C7A-8C13-41C8-8780-8310CF103364}] (.Google Inc..) -- c:\program files (x86)\Google\Chrome\application\chrome.exe [811848] =>.Google Inc®
[MD5.C7D113EDE88B40CCC634EDEFC92C750D] [APT] [{48A1ACB4-CB8C-4160-8D6A-45860DC00F1C}] (.8pecxstudios.) -- d:\program files (x86)\Cyberfox\Cyberfox.exe [781856] {275F7B4841402DE0F41C8CCF30795AC2} ©
[MD5.5353A34090BABE3CD48B70569AF0DD12] [APT] [{5F5F8BA0-73A5-4940-BE02-7D58B8CF1E27}] (.Valve Corporation.) -- D:\Program Files (x86)\Steam\Steam.exe [3011152] =>.Valve®
[MD5.5353A34090BABE3CD48B70569AF0DD12] [APT] [{EEE10425-C61E-47E9-A9FD-E5F7312FF846}] (.Valve Corporation.) -- D:\Program Files (x86)\Steam\Steam.exe [3011152] =>.Valve®
[MD5.BC41666FF68C364CD3EAA486E50C9270] [APT] [Apple\AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [563000] =>.Apple Inc.®
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002] ©
O39 - APT: DropboxUpdateTaskMachineCore - (.Dropbox, Inc..) -- C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job [1182] ©
O39 - APT: DropboxUpdateTaskMachineUA - (.Dropbox, Inc..) -- C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job [1186] ©
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1066] ©
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1070] ©
O39 - APT: VKCAGRPJFKDHGGAN - (.All rights reserved..) -- C:\Windows\Tasks\VKCAGRPJFKDHGGAN.job [344] =>Heuristic.Graftor
O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [3940] ©
O39 - APT: AdobeAAMUpdater-1.0-Alexis-PC-Alexis - (...) -- C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-Alexis-PC-Alexis [3506]
O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\Windows\System32\Tasks\CCleanerSkipUAC [2774] ©
O39 - APT: DropboxUpdateTaskMachineCore - (.Dropbox, Inc..) -- C:\Windows\System32\Tasks\DropboxUpdateTaskMachineCore [3930] ©
O39 - APT: DropboxUpdateTaskMachineUA - (.Dropbox, Inc..) -- C:\Windows\System32\Tasks\DropboxUpdateTaskMachineUA [4182] ©
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [3814] ©
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [4066] ©
O39 - APT: kol3015 - (...) -- C:\Windows\System32\Tasks\kol3015 [3090] =>PUP.Optional.FastSearch
O39 - APT: updateTask - (...) -- C:\Windows\System32\Tasks\updateTask [3150]
O39 - APT: Urecceqm - (...) -- C:\Windows\System32\Tasks\Urecceqm [3338] =>PUP.Optional.Groover
O39 - APT: VKCAGRPJFKDHGGAN - (.All rights reserved..) -- C:\Windows\System32\Tasks\VKCAGRPJFKDHGGAN [3380] =>Heuristic.Graftor

---\\ Processus lancés (27) - 4s
[MD5.E338ECFE8E997B8E7EC7165764F67F8A] - (.AMD - AMD External Events Service Module.) -- C:\Windows\System32\atiesrxx.exe [246272] [PID.168] ©
[MD5.13155ABE5CEE5F2332885574A2432C01] - (.AMD - AMD External Events Client Module.) -- C:\Windows\System32\atieclxx.exe [776192] [PID.1336] ©
[MD5.79FE7F781972884B7AB05B4E60CC5ED9] - (.Sysinternals process Explorer - Sysinternals process Explorer.) -- C:\ProgramData\Tmp0x0x\ProtectWindowsManager.exe [344232] [PID.1400] {11215BD52CE822E39F61AAE0642B2F566ABD} ©
[MD5.63702EE9CBE4347C48FA6F30083D26A2] - (...) -- C:\ProgramData\Airtop\Airtop.exe [401408] [PID.1724] =>PUP.Optional.Salus
[MD5.165DA337583D903CEEC988F56F933419] - (...) -- C:\ProgramData\ApplicationHosting\ApplicationHosting.exe [401408] [PID.1928] =>PUP.Optional.ApplicationHosting
[MD5.790AC1BEFFBCC73A7ADD37CF7030E44C] - (.Copyright © 2015 - .) -- C:\Program Files\Dripkix\Dripkix.exe [379904] [PID.2084] =>PUP.Optional.Amonetize
[MD5.F5FDE761873B4B45C4D6AD9CE3F95442] - (...) -- C:\Users\Alexis\AppData\Local\Temp\nsb8202.tmp [222208] [PID.2120]
[MD5.71678A862FDBACC1B5A15BE31008306E] - (...) -- C:\Program Files (x86)\032B0290-1449484090-0559-0306-940700080009\hnsg5CE7.tmp [134656] [PID.2432] =>PUP.Optional.CrossRider
[MD5.74752ECD1495E4388CCC3B781E637F91] - (...) -- C:\Program Files (x86)\032B0290-1449484090-0559-0306-940700080009\jnsb480E.tmp [307200] [PID.2556] =>PUP.Optional.CrossRider
[MD5.0436A7489D3FB6D2BACB37415A6BF4C4] - (.A-Volute - Maelstrom VAD Streaming Service.) -- C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzMaelstromVADStreamingService.exe [4250624] [PID.2600]
[MD5.44D1D137952BE444B2BD998200151DFC] - (.TODO: <公司名> - TODO: <文件说明>.) -- C:\Program Files (x86)\SFK\SSFK.exe [155280] [PID.2760] {1121D343CEADB8041BAC48B044906C5E105E}
[MD5.4DDF155817D2BF79675B400038A41317] - (...) -- C:\Program Files (x86)\WNetEnhancer\WNetEnhancer Internet Enhancer\663d2e82e7a5dc32e243ab08ac2ec4a6.exe [1457152] [PID.2948] =>PUP.Optional.Wajam
[MD5.F64E1F680DEEE761AE00D650EC0FB129] - (...) -- C:\Users\Alexis\AppData\Local\gmsd_fr_005010169\upgmsd_fr_005010169.exe [3261616] [PID.4836] {1121659F89D645B84A6361DBAB1CE36D6315} =>PUP.Optional.CrossRider
[MD5.A005676B30AEB3C7703C317D992B193A] - (.Copyright © 2015 - MalwareProtectionClient.) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\MalwareProtectionClient.exe [291648] [PID.1108] {0DB13F364982158C0E6000F666CC2AA4} =>.Superfluous.MalwareProtection
[MD5.A005676B30AEB3C7703C317D992B193A] - (...) -- C:\Program Files (x86)\rec_en_77\rec_en_77.exe [291648] [PID.3936] {11219EC4C02D1E1878E59FED81CDA1E305F8} =>PUP.Optional.Tuto4PC
[MD5.A005676B30AEB3C7703C317D992B193A] - (...) -- C:\Program Files (x86)\gmsd_fr_005010169\gmsd_fr_005010169.exe [291648] [PID.4320] {1121659F89D645B84A6361DBAB1CE36D6315} =>PUP.Optional.CrossRider
[MD5.A005676B30AEB3C7703C317D992B193A] - (...) -- C:\ProgramData\Airtop\Airtop.exe [291648] [PID.6276] =>PUP.Optional.Salus
[MD5.A005676B30AEB3C7703C317D992B193A] - (.Alexander Roshal - WinRAR archiver.) -- D:\Program Files (x86)\WinRAR\WinRAR.exe [291648] [PID.6908]
[MD5.A005676B30AEB3C7703C317D992B193A] - (...) -- C:\Program Files (x86)\WNetEnhancer\WNetEnhancer Internet Enhancer\7e0e6c165467f226fa2a8f9d6445d9af.exe [291648] [PID.10592] =>PUP.Optional.Wajam
[MD5.A005676B30AEB3C7703C317D992B193A] - (.Adlegend Media - Support File.) -- C:\Program Files (x86)\FastCompress-Zip\Fast_Support.exe [291648] [PID.15612] {11210D7D7D1C16D9150B69F8767D7C855E19} ©
[MD5.A005676B30AEB3C7703C317D992B193A] - (.Copyright © 2015 - .) -- C:\Program Files\Dripkix\packages\76b17136-be0a-4a59-8a8b-6dca3c97cc4d\Drip.exe [291648] [PID.14572] =>PUP.Optional.Amonetize
[MD5.A005676B30AEB3C7703C317D992B193A] - (...) -- C:\ProgramData\Zitenop\Zitenop.exe [291648] [PID.9696] =>PUP.Optional.Salus
[MD5.A005676B30AEB3C7703C317D992B193A] - (...) -- C:\Program Files (x86)\032B0290-1449484090-0559-0306-940700080009\knsjC532.tmp [291648] [PID.16588] =>PUP.Optional.CrossRider
[MD5.A005676B30AEB3C7703C317D992B193A] - (.TeamSpeak Systems GmbH - TeamSpeak 3 Client.) -- C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe [291648] [PID.4144] {7F5E65E3859D53019B20374E9FDA5B38} ©
[MD5.A005676B30AEB3C7703C317D992B193A] - (.8pecxstudios - Cyberfox.) -- D:\Program Files (x86)\Cyberfox\Cyberfox.exe [291648] [PID.3616] {275F7B4841402DE0F41C8CCF30795AC2} ©
[MD5.A005676B30AEB3C7703C317D992B193A] - (.Copyright (C) 2015 Nicolas Coolman - ZHPDiag.) -- C:\Users\Alexis\Downloads\ZHPDiag3.exe [291648] [PID.14916] ©
[MD5.A005676B30AEB3C7703C317D992B193A] - (.Copyright (C) 2015 Nicolas Coolman - ZHPDiag.) -- C:\Users\Alexis\Downloads\ZHPDiag3.exe [291648] [PID.5108] ©

---\\ Google Chrome, Démarrage,Recherche,Extensions (2) - 34s
G2 - GCE: Preference [User Data\Default] [fhdcbgmkmfapmaccefgcigficdnphjbn] [{"background":{"scripts":["background.js"]},"conte] {background:{scripts:[background.js]}content_scrip =>Hijacker.Browser
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.

---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (21) - 2s
P2 - EXT FILE: (...) -- C:\Users\Alexis\AppData\Roaming\Mozilla\Firefox\Profiles\8i3qsk17.default\searchplugins\default.xml
P2 - EXT FILE: (...) -- C:\Users\Alexis\AppData\Roaming\Mozilla\Firefox\Profiles\8i3qsk17.default\searchplugins\findit.xml =>PUP.Optional.SmartBar
P2 - EXT FILE: (...) -- C:\Users\Alexis\AppData\Roaming\Mozilla\Firefox\Profiles\8i3qsk17.default\searchplugins\istartpageing.xml =>PUP.Optional.IstartPageing
P2 - EXT FILE: (...) -- C:\Users\Alexis\AppData\Roaming\Mozilla\Firefox\Profiles\8i3qsk17.default\searchplugins\search-simple.xml =>PUP.Optional.SearchSimple
P2 - EXT FILE: (...) -- C:\Users\Alexis\AppData\Roaming\Mozilla\Firefox\Profiles\8i3qsk17.default\searchplugins\yahoo.xml =>PUP.Optional.BDYahoo
P2 - EXT: (.Mozilla - Default.) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ©
P2 - EXT: (.lightningnewtab.com - Newtab.) -- C:\Users\Alexis\AppData\Roaming\Mozilla\Firefox\Profiles\8i3qsk17.default\extensions\deskCutv2@gmail.com =>PUP.Optional.LightningNewTab
P2 - EXT: (.roc - YahooToolsProtected .) -- C:\Users\Alexis\AppData\Roaming\Mozilla\Firefox\Profiles\8i3qsk17.default\extensions\yahooprotected@gmail.com
P2 - FPN: [HKCU] [pandonetworks.com/PandoWebPlugin] - (.Pando Networks.) -- C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll ©
P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (.Apple Inc..) -- C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ©
P2 - FPN: [HKLM] [@esn.me/esnsonar,version=0.70.4] - (.ESN Social Software AB.) -- C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll ©
P2 - FPN: [HKLM] [@esn/npbattlelog,version=2.5.1] - (.EA Digital Illusions CE AB.) -- C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll ©
P2 - FPN: [HKLM] [@esn/npbattlelog,version=2.7.1] - (.EA Digital Illusions CE AB.) -- C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll ©
P2 - FPN: [HKLM] [@java.com/DTPlugin,version=11.65.2] - (.Oracle Corporation.) -- C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll ©
P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=11.65.2] - (.Oracle Corporation.) -- C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll ©
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (.Microsoft Corporation.) -- C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ©
P2 - FPN: [HKLM] [@pandonetworks.com/PandoWebPlugin] - (.Pando Networks.) -- C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc..) -- C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll ©
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc..) -- C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll ©
P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.2.1] - (.VideoLAN.) -- C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll ©

---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (16) - 1s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_ByKo5GOPu13rXw155J4OB8oo3_nrI_YPbYytCFQMvqrv5QNdU0j2sjSZdooisThXcRcgUYaWyOaN5DqyNbRFcqYtiw8A0zjNGuJWk93003G8B1-suLT2VAyq6xBHqSp2uzWkn2eJkBUuIoLVNyLfxNC1mvis4 =>PUP.Optional.Linkury
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com?fr=hp-avast&type=avastbcl
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com?fr=hp-avast&type=avastbcl
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutxkij9_byko5gopu13rxw155j4ob8oo3_nri_ypbyytcfqmvqrv5qndu0j2sjszdooisthxcrcguyawyoan5dqdcbztevk9yo_oplzovxeitjg-jalxk8sgq8x5mlsdgtsrv4swri8h3dyautnqleoivqh8ejs0eb78f&q={searchterms} =>PUP.Optional.Linkury
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutxkij9_byko5gopu13rxw155j4ob8oo3_nri_ypbyytcfqmvqrv5qndu0j2sjszdooisthxcrcguyawyoan5dqdcbztevk9yo_oplzovxeitjg-jalxk8sgq8x5mlsdgtsrv4swri8h3dyautnqleoivqh8ejs0eb78f&q={searchterms} =>PUP.Optional.Linkury
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutxkij9_byko5gopu13rxw155j4ob8oo3_nri_ypbyytcfqmvqrv5qndu0j2sjszdooisthxcrcguyawyoan5dqdcbztevk9yo_oplzovxeitjg-jalxk8sgq8x5mlsdgtsrv4swri8h3dyautnqleoivqh8ejs0eb78f&q={searchterms} =>PUP.Optional.Linkury
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutxkij9_byko5gopu13rxw155j4ob8oo3_nri_ypbyytcfqmvqrv5qndu0j2sjszdooisthxcrcguyawyoan5dqdcbztevk9yo_oplzovxeitjg-jalxk8sgq8x5mlsdgtsrv4swri8h3dyautnqleoivqh8ejs0eb78f&q={searchterms} =>PUP.Optional.Linkury
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKEY_USERS\S-1-5-21-921229589-2242423223-674013632-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbutxkij9_byko5gopu13rxw155j4ob8oo3_nri_ypbyytcfqmvqrv5qndu0j2sjszdooisthxcrcguyawyoan5dqdcbztevk9yo_oplzovxeitjg-jalxk8sgq8x5mlsdgtsrv4swri8h3dyautnqleoivqh8ejs0eb78f&q={searchterms} =>PUP.Optional.Linkury
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer

---\\ Internet Explorer,Proxy Management (7) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <-loopback>
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:52083;https=127.0.0.1:52083 =>Hijacker.Proxy
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0

---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) ©
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) ©
F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) ©

---\\ Etude du fichier hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)

---\\ Browser Helper Object de navigateur (BHO) (6) - 0s
O2 - BHO: CrossriderApp0035497 [64Bits] - {11111111-1111-1111-1111-110311541197} (Orphean) =>PUP.Optional.CrossRider
O2 - BHO: CrossriderApp0048922 [64Bits] - {11111111-1111-1111-1111-110411891122} (Orphean) =>PUP.Optional.CrossRider
O2 - BHO: TrustMediaViewerV1alpha1193 [64Bits] - {30c23909-a0f6-4e68-a6f7-919ff3cfac34} (Orphean) =>PUP.Optional.MediaViewer
O2 - BHO: ExplorerBHO Class [64Bits] - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} . (.IvoSoft - Adds classic Windows Explorer features.) -- C:\Program Files\Classic Shell\ClassicExplorer32.dll ©
O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll =>.Oracle America, Inc.®
O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll =>.Oracle America, Inc.®

---\\ Internet Explorer, Barre d'outil (1) - 1s
O3 - Toolbar: (no name) - [HKLM]{553891B7-A0D5-4526-BE18-D3CE461D6310} (Orphean) ©

---\\ Applications lancées au démarrage du système (26) - 1s
O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe =>.Apple Inc.®
O4 - HKLM\..\Run: [SpaceSoundPro] C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe (.not file.) =>PUP.Optional.SpaceSoundPro
O4 - HKCU\..\Run: [Speech Recognition] . (.Microsoft Corporation - Reconnaissance vocale.) -- C:\Windows\Speech\Common\sapisvr.exe ©
O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - HKCU\..\Run: [DAEMON Tools Lite] . (.Disc Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe =>.Disc Soft Ltd®
O4 - HKCU\..\Run: [WindApp] C:\Users\Alexis\AppData\Roaming\Store\WindApp\WindApp.exe (.not file.) =>PUP.Optional.Nosibay
O4 - HKCU\..\Run: [Selection Tools] C:\Users\Alexis\AppData\Roaming\WTools\Selection Tools\Selection Tools.exe (.not file.) =>PUP.Optional.Nosibay
O4 - HKLM\..\Wow6432Node\Run: [USB3MON] . (.Intel Corporation - Intel(R) USB 3.0 Monitor.) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe =>.Intel Corporation®
O4 - HKLM\..\Wow6432Node\Run: [LifeCam] . (.Microsoft Corporation - LifeExp.exe.) -- C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe =>.Microsoft Corporation®
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle America, Inc.®
O4 - HKLM\..\Wow6432Node\Run: [Dropbox] . (.Dropbox, Inc. - Dropbox.) -- C:\Program Files (x86)\Dropbox\Client\Dropbox.exe =>.Dropbox, Inc®
O4 - HKLM\..\Wow6432Node\Run: [MalwareProtectionLive] . (.Copyright © 2015 - MalwareProtectionClient.) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\MalwareProtectionClient.exe {0DB13F364982158C0E6000F666CC2AA4} =>.Superfluous.MalwareProtection
O4 - HKLM\..\Wow6432Node\Run: [ospd_us_013010168] (Orphean) =>PUP.Optional.CrossRider
O4 - HKLM\..\Wow6432Node\Run: [rec_en_77] . (...) -- C:\Program Files (x86)\rec_en_77\rec_en_77.exe {11219EC4C02D1E1878E59FED81CDA1E305F8} =>PUP.Optional.Tuto4PC
O4 - HKLM\..\Wow6432Node\Run: [gmsd_fr_005010169] . (...) -- C:\Program Files (x86)\gmsd_fr_005010169\gmsd_fr_005010169.exe {1121659F89D645B84A6361DBAB1CE36D6315} =>PUP.Optional.CrossRider
O4 - HKLM\..\Wow6432Node\RunOnce: [upgmsd_fr_005010169.exe] . (...) -- C:\Users\Alexis\AppData\Local\gmsd_fr_005010169\upgmsd_fr_005010169.exe {1121659F89D645B84A6361DBAB1CE36D6315} =>PUP.Optional.CrossRider
O4 - HKLM\..\Wow6432Node\RunOnce: [Update] C:\Users\Alexis\AppData\Roaming\VOPackage\VOPackage.exe (.not file.) =>PUP.Optional.Downware
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\sidebar.exe ©
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\sidebar.exe ©
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe ©
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe ©
O4 - HKUS\S-1-5-21-921229589-2242423223-674013632-1001\..\Run: [Speech Recognition] . (.Microsoft Corporation - Reconnaissance vocale.) -- C:\Windows\Speech\Common\sapisvr.exe ©
O4 - HKUS\S-1-5-21-921229589-2242423223-674013632-1001\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - HKUS\S-1-5-21-921229589-2242423223-674013632-1001\..\Run: [DAEMON Tools Lite] . (.Disc Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe =>.Disc Soft Ltd®
O4 - HKUS\S-1-5-21-921229589-2242423223-674013632-1001\..\Run: [WindApp] C:\Users\Alexis\AppData\Roaming\Store\WindApp\WindApp.exe (.not file.) =>PUP.Optional.Nosibay
O4 - HKUS\S-1-5-21-921229589-2242423223-674013632-1001\..\Run: [Selection Tools] C:\Users\Alexis\AppData\Roaming\WTools\Selection Tools\Selection Tools.exe (.not file.) =>PUP.Optional.Nosibay

---\\ Winsock hijacker (Layered Service Provider) (15) - 0s
O10 - WLSP:\Catalog_Entries\000000000001\Winsock LSP File . (...) -- C:\Windows\System32\Ekiraky.dll (Not File) =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries\000000000002\Winsock LSP File . (...) -- C:\Windows\System32\Ekiraky.dll (Not File) =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries\000000000003\Winsock LSP File . (...) -- C:\Windows\System32\Ekiraky.dll (Not File) =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries\000000000004\Winsock LSP File . (...) -- C:\Windows\System32\Ekiraky.dll (Not File) =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries\000000000015\Winsock LSP File . (...) -- C:\Windows\System32\Ekiraky.dll (Not File) =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries64\000000000001\Winsock LSP File . (...) -- C:\Windows\system32\Ekiraky64.dll =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries64\000000000002\Winsock LSP File . (...) -- C:\Windows\system32\Ekiraky64.dll =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries64\000000000003\Winsock LSP File . (...) -- C:\Windows\system32\Ekiraky64.dll =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries64\000000000004\Winsock LSP File . (...) -- C:\Windows\system32\Ekiraky64.dll =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries64\000000000005\Winsock LSP File . (...) -- C:\Windows\system32\Ofuwday64.dll =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries64\000000000006\Winsock LSP File . (...) -- C:\Windows\system32\Ofuwday64.dll =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries64\000000000007\Winsock LSP File . (...) -- C:\Windows\system32\Ofuwday64.dll =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries64\000000000008\Winsock LSP File . (...) -- C:\Windows\system32\Ofuwday64.dll =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries64\000000000019\Winsock LSP File . (...) -- C:\Windows\system32\Ofuwday64.dll =>Hijacker.Winsock
O10 - WLSP:\Catalog_Entries64\000000000020\Winsock LSP File . (...) -- C:\Windows\system32\Ekiraky64.dll =>Hijacker.Winsock

---\\ Modification Domaine/Adresses DNS (12) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 104.197.191.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.20.115 192.168.20.116
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = crdp-lille.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 104.197.191.4
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.20.115 192.168.20.116
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.254
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpDomain = crdp-lille.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 104.197.191.4
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpNameServer = 192.168.20.115 192.168.20.116
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.254
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpDomain = crdp-lille.local

---\\ Protocole additionnel (21) - 2s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll ©
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll ©
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll ©
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll ©
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: skype4com [64Bits] - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} . (.Skype Technologies - Skype4COM.) -- C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll =>.Skype Software Sarl®
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll ©
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®

---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (1) - 0s
O20 - AppInit_DLLs: . (...) - C:\ProgramData\Zitenop\Viajob.dll =>PUP.Optional.Salus

---\\ Logiciels installés (105) - 48s
O42 - Logiciel: @BIOS - (.GIGABYTE.) [HKLM][64Bits] -- {B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83} ©
O42 - Logiciel: Adobe Flash Player 19 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX ©
O42 - Logiciel: Adobe Flash Player 19 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI ©
O42 - Logiciel: AMD Accelerated Video Transcoding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {C82415B1-6D78-7002-1E5A-338B06C20524} ©
O42 - Logiciel: AMD APP SDK Runtime - (.Advanced Micro Devices Inc..) [HKLM][64Bits] -- {503F672D-6C84-448A-8F8F-4BC35AC83441} ©
O42 - Logiciel: AMD Catalyst Control Center - (.Nom de votre société.) [HKLM][64Bits] -- {DC914285-C110-6FB9-0235-339080572BB9}
O42 - Logiciel: AMD Catalyst Install Manager - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {4D4964B2-1FAD-A4A1-052A-7F048C7A128D} ©
O42 - Logiciel: AMD Drag and Drop Transcoding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {0407893F-352C-B182-E04A-A8C3333DA29B} ©
O42 - Logiciel: AMD Media Foundation Decoders - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {55B348BE-A3BE-9AE7-58BD-BE45B9A28F82} ©
O42 - Logiciel: AMD Wireless Display v3.0 - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {426582A8-202F-D13C-8BD5-F00551BAFC93} ©
O42 - Logiciel: Apple Application Support (32 bits) - (.Apple Inc..) [HKLM][64Bits] -- {A50679D9-6CBD-4FCD-BACB-62EF3894F6F3} ©
O42 - Logiciel: Apple Application Support (64 bits) - (.Apple Inc..) [HKLM][64Bits] -- {1F72FDD5-A069-45B4-928F-D0F16492DC69} ©
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM][64Bits] -- {FD244E19-6EFE-4A2D-948A-0D45D4C168BE} ©
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM][64Bits] -- {FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF} ©
O42 - Logiciel: Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver - (.Atheros Communications Inc..) [HKLM][64Bits] -- {3108C217-BE83-42E4-AE9E-A56A2A92E549} ©
O42 - Logiciel: AutoGreen B12.0206.1 - (.GIGABYTE.) [HKLM][64Bits] -- {C75FAD21-EC08-42F3-92D6-C9C0AB355345} ©
O42 - Logiciel: AutoGreen B12.0206.1 - (.GIGABYTE.) [HKLM][64Bits] -- InstallShield_{C75FAD21-EC08-42F3-92D6-C9C0AB355345} ©
O42 - Logiciel: Battlefield 3™ - (.Electronic Arts.) [HKLM][64Bits] -- {76285C16-411A-488A-BCE3-C83CB933D8CF} ©
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM][64Bits] -- {56DDDFB8-7F79-4480-89D5-25E1F52AB28F} ©
O42 - Logiciel: Canon MG3100 series MP Drivers - (...) [HKLM][64Bits] -- {1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG3100_series
O42 - Logiciel: Catalyst Control Center - Branding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {11087D24-567D-7D88-69C6-D7A08B5F4C47} ©
O42 - Logiciel: Catalyst Control Center Graphics Previews Common - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {D48A6B6E-F184-0FDC-37E7-747B99D05849} ©
O42 - Logiciel: Catalyst Control Center Localization All - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {ECBD4C97-2421-F72D-D464-F1865B5B9BAE} ©
O42 - Logiciel: CCC Help Chinese Standard - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {E12EFCDD-4216-B13C-A7FD-193E5B310FDC} ©
O42 - Logiciel: CCC Help Chinese Traditional - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {2DDBBBAC-CD01-BC14-379F-D4410EA23EE8} ©
O42 - Logiciel: CCC Help Czech - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {BED52158-4FA3-E3C6-0469-57CB86DD31B1} ©
O42 - Logiciel: CCC Help Danish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {98DD4A71-7634-93FE-E654-EE0702755079} ©
O42 - Logiciel: CCC Help Dutch - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {A5FFD88B-9054-94F8-2A98-74BFE092DD7E} ©
O42 - Logiciel: CCC Help English - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {4D8DAEC1-E68E-6D3B-59F1-C467EB716FC9} ©
O42 - Logiciel: CCC Help Finnish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {C561B330-D61D-1145-1FBA-659F495A37DD} ©
O42 - Logiciel: CCC Help French - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {06321F6A-683B-67C8-C0C4-377E828A6B35} ©
O42 - Logiciel: CCC Help German - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {F3A362D2-3AE5-135F-6D4B-B503FA940B2A} ©
O42 - Logiciel: CCC Help Greek - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {1FEB2431-43FC-A347-E3CF-19A11882C836} ©
O42 - Logiciel: CCC Help Hungarian - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {9BE5D029-21AF-4AF8-E8AC-5EE820989D6D} ©
O42 - Logiciel: CCC Help Italian - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {D42AE073-7032-64E9-DEE7-DDD5B06C8CBA} ©
O42 - Logiciel: CCC Help Japanese - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {45EA0C40-75A8-B25B-9407-65A091598A3B} ©
O42 - Logiciel: CCC Help Korean - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {2133B48A-B339-9B36-D9A2-30080100BC98} ©
O42 - Logiciel: CCC Help Norwegian - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {4EE3E380-B8FC-5D63-3152-8DEE19A57B6B} ©
O42 - Logiciel: CCC Help Polish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {8C025263-0129-6713-35C0-9246C80B32D1} ©
O42 - Logiciel: CCC Help Portuguese - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {1D844E6F-8132-D0AB-98CA-BD3B497DD284} ©
O42 - Logiciel: CCC Help Russian - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {369F8F60-0D34-3551-8CF5-F9AD0B9B7F67} ©
O42 - Logiciel: CCC Help Spanish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {6FE68FBF-4815-DDA9-9346-FF6E512A8B3A} ©
O42 - Logiciel: CCC Help Swedish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {25AFF9AE-4FA6-1529-F861-E122311C7FF9} ©
O42 - Logiciel: CCC Help Thai - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {79C8C8FD-8472-B94D-3E2F-BEA23A79A664} ©
O42 - Logiciel: CCC Help Turkish - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {C05C1350-C3D9-519C-8D3D-A5527D24DFD6} ©
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner ©
O42 - Logiciel: Clicker Heroes - (.Playsaurus.) [HKLM][64Bits] -- Steam App 363970 © =>.SteamApp.Game
O42 - Logiciel: Curse Client - (.Curse.) [HKCU][64Bits] -- 101a9f93b8f0bb6f ©
O42 - Logiciel: DAEMON Tools Lite - (.Disc Soft Ltd.) [HKLM][64Bits] -- DAEMON Tools Lite ©
O42 - Logiciel: DayZ - (.Bohemia Interactive.) [HKLM][64Bits] -- Steam App 221100 © =>.SteamApp.Game
O42 - Logiciel: Dropbox - (.Dropbox, Inc..) [HKLM][64Bits] -- Dropbox ©
O42 - Logiciel: Dropbox Update Helper - (.Dropbox, Inc..) [HKLM][64Bits] -- {099218A5-A723-43DC-8DB5-6173656A1E94} ©
O42 - Logiciel: Easy Tune 6 B12.0626.1 - (.GIGABYTE.) [HKLM][64Bits] -- {457D7505-D665-4F95-91C3-ECB8C56E9ACA} ©
O42 - Logiciel: Easy Tune 6 B12.0626.1 - (.GIGABYTE.) [HKLM][64Bits] -- InstallShield_{457D7505-D665-4F95-91C3-ECB8C56E9ACA} ©
O42 - Logiciel: Etron USB3.0 Host Controller - (.Etron Technology.) [HKLM][64Bits] -- {DFBB738C-71D8-4DC5-B8D2-D65C37680E27} ©
O42 - Logiciel: Etron USB3.0 Host Controller - (.Etron Technology.) [HKLM][64Bits] -- InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27} ©
O42 - Logiciel: FastCompress-Zip_1.0.2.1_Release - (...) [HKLM][64Bits] -- FastCompress-Zip
O42 - Logiciel: FIFA 14 - (.Electronic Arts.) [HKLM][64Bits] -- {AA7A2800-1E75-4240-855B-03AFF8E5171E} ©
O42 - Logiciel: GamesDesktop 001.005010169 - (.GAMESDESKTOP.) [HKLM][64Bits] -- gmsd_fr_005010169_is1 =>PUP.Optional.GamesDesktop
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome ©
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} ©
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} ©
O42 - Logiciel: Hearthstone - (.Blizzard Entertainment.) [HKLM][64Bits] -- Hearthstone ©
O42 - Logiciel: Heroes of the Storm - (.Blizzard Entertainment.) [HKLM][64Bits] -- Heroes of the Storm ©
O42 - Logiciel: iCloud - (.Apple Inc..) [HKLM][64Bits] -- {709A2D23-C25E-47B5-9268-CB6FEE648504} ©
O42 - Logiciel: Intel(R) USB 3.0 eXtensible Host Controller Driver - (.Intel Corporation.) [HKLM][64Bits] -- {240C3DDD-C5E9-4029-9DF7-95650D040CF2} ©
O42 - Logiciel: iRoot - (.Shenzhen Xinyi Network Co.,Ltd..) [HKLM][64Bits] -- {1295E43F-382A-4CB2-9E0F-079C0D7401BB}_is1
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM][64Bits] -- {96984DE8-1DB8-425C-AC8C-3098BC696F04} ©
O42 - Logiciel: Java 8 Update 65 - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83218065F0} ©
O42 - Logiciel: Java 8 Update 66 (64-bit) - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F86418066F0} ©
O42 - Logiciel: Java Auto Updater - (.Oracle Corporation.) [HKLM][64Bits] -- {4A03706F-666A-4037-7777-5F2748764D10} ©
O42 - Logiciel: Kingo ROOT version 1.4.2.2494 - (.Kingosoft Technology Ltd..) [HKLM][64Bits] -- {AE7675D6-0B31-494F-ABFA-822E1A0FDF17}_is1 ©
O42 - Logiciel: LibreOffice 5.0.3.2 - (.The Document Foundation.) [HKLM][64Bits] -- {D61E7AA0-0380-49B9-8DDD-7685E2306176} ©
O42 - Logiciel: Ma-Config.com (64 bits) - (.Cybelsoft.) [HKLM][64Bits] -- {E1322B8A-6F66-44ED-95D5-7FEBC50AC814} ©
O42 - Logiciel: Malware Protection Live - (...) [HKLM][64Bits] -- MalwareProtectionLive
O42 - Logiciel: MEGAsync - (.Mega Limited.) [HKLM][64Bits] -- MEGAsync ©
O42 - Logiciel: Microsoft Corporation - (.Microsoft Corporation.) [HKLM][64Bits] -- {9C5A08BF-BB99-4998-81BD-F6CC32483B34} ©
O42 - Logiciel: Microsoft Corporation - (.Microsoft Corporation.) [HKLM][64Bits] -- {B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800} ©
O42 - Logiciel: Microsoft LifeCam - (.Microsoft Corporation.) [HKLM][64Bits] -- {5CE7E3F5-9803-4F32-AA89-2D8848A80109} ©
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} ©
O42 - Logiciel: Mozilla Firefox 42.0 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 42.0 (x86 fr) ©
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService ©
O42 - Logiciel: Notepad++ - (.Notepad++ Team.) [HKLM][64Bits] -- Notepad++ ©
O42 - Logiciel: NVIDIA PhysX - (.NVIDIA Corporation.) [HKLM][64Bits] -- {DEA314C4-0929-4250-BC92-98E4C105F28D} ©
O42 - Logiciel: OEM Application Profile - (.Nom de votre société.) [HKLM][64Bits] -- {69C424A3-8863-FF59-FCF3-E3D94AB696FA}
O42 - Logiciel: Oracle VM VirtualBox 5.0.10 - (.Oracle Corporation.) [HKLM][64Bits] -- {F6E922CF-068D-4AFC-8DBF-4636B84AF0A5} ©
O42 - Logiciel: Origin - (.Electronic Arts, Inc..) [HKLM][64Bits] -- Origin ©
O42 - Logiciel: Rainbow Six Siege - Open Beta - (.Ubisoft.) [HKLM][64Bits] -- Uplay Install 1001 ©
O42 - Logiciel: Razer Cortex - (.Razer Inc..) [HKLM][64Bits] -- Razer Cortex_is1 ©
O42 - Logiciel: Razer Surround - (.Razer Inc..) [HKLM][64Bits] -- Razer Surround ©
O42 - Logiciel: Razer Synapse - (.Razer Inc..) [HKLM][64Bits] -- {0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6} ©
O42 - Logiciel: recALL version 15.02 - (...) [HKLM][64Bits] -- recALL_is1
O42 - Logiciel: Rust - (.Facepunch Studios.) [HKLM][64Bits] -- Steam App 252490 © =>.SteamApp.Game
O42 - Logiciel: SafeFinder - (.Linkury.) [HKLM][64Bits] -- {D71F4C2F-F591-45C8-87D7-C1FD4DC4A7EC} =>PUP.Optional.SmartBar
O42 - Logiciel: Samsung Kies3 - (.Samsung Electronics Co., Ltd..) [HKLM][64Bits] -- {88547073-C566-4895-9005-EBE98EA3F7C7} ©
O42 - Logiciel: Samsung Kies3 - (.Samsung Electronics Co., Ltd..) [HKLM][64Bits] -- InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7} ©
O42 - Logiciel: Samsung USB Driver for Mobile Phones - (.Samsung Electronics Co., Ltd..) [HKLM][64Bits] -- {D0795B21-0CDA-4a92-AB9E-6E92D8111E44} ©
O42 - Logiciel: Skype™ 6.21 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7} ©
O42 - Logiciel: SVH - (...) [HKLM][64Bits] -- rec_en_77_is1 =>PUP.Optional.Tuto4PC
O42 - Logiciel: TeamSpeak 3 Client - (.TeamSpeak Systems GmbH.) [HKLM][64Bits] -- TeamSpeak 3 Client ©
O42 - Logiciel: UNetbootin - (...) [HKLM][64Bits] -- UNetbootin
O42 - Logiciel: Uplay - (.Ubisoft.) [HKLM][64Bits] -- Uplay ©
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player ©
O42 - Logiciel: Warface - (.Crytek.) [HKLM][64Bits] -- Steam App 291480 © =>.SteamApp.Game
O42 - Logiciel: Wireshark 1.12.8 (64-bit) - (.The Wireshark developer community, http://www.wireshark.org.) [HKLM][64Bits] -- Wireshark ©

---\\ HKCU & HKLM Software Keys (172) - 48s
HKLM\SOFTWARE\Wow6432Node\Adobe
HKLM\SOFTWARE\Wow6432Node\AdwCleaner
HKLM\SOFTWARE\Wow6432Node\AGEIA Technologies
HKLM\SOFTWARE\Wow6432Node\AMD
HKLM\SOFTWARE\Wow6432Node\Apple Inc.
HKLM\SOFTWARE\Wow6432Node\ArenaNet
HKLM\SOFTWARE\Wow6432Node\AssistPoint =>PUP.Optional.AssistPoint
HKLM\SOFTWARE\Wow6432Node\Atheros Communications Inc.
HKLM\SOFTWARE\Wow6432Node\ATI
HKLM\SOFTWARE\Wow6432Node\ATI Technologies
HKLM\SOFTWARE\Wow6432Node\Battlelog Web Plugins
HKLM\SOFTWARE\Wow6432Node\Blizzard Entertainment
HKLM\SOFTWARE\Wow6432Node\Client
HKLM\SOFTWARE\Wow6432Node\DICE
HKLM\SOFTWARE\Wow6432Node\Disc Soft
HKLM\SOFTWARE\Wow6432Node\dotNetInstaller
HKLM\SOFTWARE\Wow6432Node\downchecker =>PUP.Optional.DownChecker
HKLM\SOFTWARE\Wow6432Node\Dropbox
HKLM\SOFTWARE\Wow6432Node\DropboxUpdate
HKLM\SOFTWARE\Wow6432Node\EA Games
HKLM\SOFTWARE\Wow6432Node\EA Sports
HKLM\SOFTWARE\Wow6432Node\EasyAntiCheat
HKLM\SOFTWARE\Wow6432Node\Electronic Arts
HKLM\SOFTWARE\Wow6432Node\Fast-Search =>PUP.Optional.FastSearch
HKLM\SOFTWARE\Wow6432Node\FastCompress-Zip
HKLM\SOFTWARE\Wow6432Node\FFPluginHp =>PUP.Optional.SweetSearch
HKLM\SOFTWARE\Wow6432Node\FileZilla Client
HKLM\SOFTWARE\Wow6432Node\Fraps
HKLM\SOFTWARE\Wow6432Node\Gameforge
HKLM\SOFTWARE\Wow6432Node\gamersfirst
HKLM\SOFTWARE\Wow6432Node\GAMESDESKTOP =>PUP.Optional.GamesDesktop
HKLM\SOFTWARE\Wow6432Node\Gigabyte
HKLM\SOFTWARE\Wow6432Node\Google
HKLM\SOFTWARE\Wow6432Node\Havij
HKLM\SOFTWARE\Wow6432Node\IM Providers
HKLM\SOFTWARE\Wow6432Node\InstallShield
HKLM\SOFTWARE\Wow6432Node\Intel
HKLM\SOFTWARE\Wow6432Node\istartpageingSoftware =>PUP.Optional.IstartPageing
HKLM\SOFTWARE\Wow6432Node\JavaSoft
HKLM\SOFTWARE\Wow6432Node\JreMetrics
HKLM\SOFTWARE\Wow6432Node\Khronos
HKLM\SOFTWARE\Wow6432Node\LibreOffice
HKLM\SOFTWARE\Wow6432Node\Licenses
HKLM\SOFTWARE\Wow6432Node\Loader
HKLM\SOFTWARE\Wow6432Node\LolliScan =>PUP.Optional.Graftor
HKLM\SOFTWARE\Wow6432Node\Macromedia
HKLM\SOFTWARE\Wow6432Node\mount&blade warband
HKLM\SOFTWARE\Wow6432Node\Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\mtAirtop =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\mtZitenop =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Notepad++
HKLM\SOFTWARE\Wow6432Node\ODBC
HKLM\SOFTWARE\Wow6432Node\Opera Software
HKLM\SOFTWARE\Wow6432Node\Origin
HKLM\SOFTWARE\Wow6432Node\Origin Games
HKLM\SOFTWARE\Wow6432Node\Overwolf
HKLM\SOFTWARE\Wow6432Node\Razer
HKLM\SOFTWARE\Wow6432Node\RichMediaViewV1 =>PUP.Optional.MediaViewer
HKLM\SOFTWARE\Wow6432Node\RichMediaViewV1release399 =>PUP.Optional.MediaViewer
HKLM\SOFTWARE\Wow6432Node\Samsung
HKLM\SOFTWARE\Wow6432Node\SensePlus-nv =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\SensePlus-nv-ie =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Skype
HKLM\SOFTWARE\Wow6432Node\SoftVoice
HKLM\SOFTWARE\Wow6432Node\SpaceSondPro =>PUP.Optional.SpaceSoundPro
HKLM\SOFTWARE\Wow6432Node\Spotflux, Inc
HKLM\SOFTWARE\Wow6432Node\SVH
HKLM\SOFTWARE\Wow6432Node\SwiftSearch_1.10.0.25 =>PUP.Optional.Generic
HKLM\SOFTWARE\Wow6432Node\TeamSpeak 3 Client
HKLM\SOFTWARE\Wow6432Node\The Document Foundation
HKLM\SOFTWARE\Wow6432Node\THQ
HKLM\SOFTWARE\Wow6432Node\TrustMediaViewerV1alpha1193 =>PUP.Optional.MediaViewer
HKLM\SOFTWARE\Wow6432Node\Tutorials =>PUP.Optional.AgenceExclusive
HKLM\SOFTWARE\Wow6432Node\Ubisoft
HKLM\SOFTWARE\Wow6432Node\Valve
HKLM\SOFTWARE\Wow6432Node\VideoLAN
HKLM\SOFTWARE\Wow6432Node\Volatile
HKLM\SOFTWARE\Wow6432Node\WinRAR
HKLM\SOFTWARE\Wow6432Node\WNetEnhancer =>PUP.Optional.Wajam
HKLM\SOFTWARE\Wow6432Node\XinYi Network
HKLM\SOFTWARE\Wow6432Node\yoursearchingSoftware =>PUP.Optional.YourSearching
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications
HKCU\SOFTWARE\7room
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\AhnLab
HKCU\SOFTWARE\Aion
HKCU\SOFTWARE\AMD
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\Apple Computer, Inc.
HKCU\SOFTWARE\Apple Inc.
HKCU\SOFTWARE\ATI
HKCU\SOFTWARE\Audacity
HKCU\SOFTWARE\AVAST Software
HKCU\SOFTWARE\Blizzard Entertainment
HKCU\SOFTWARE\Bugsplat
HKCU\SOFTWARE\Canon
HKCU\SOFTWARE\DailyPcClean =>PUP.Optional.DailyPCClean
HKCU\SOFTWARE\Disc Soft
HKCU\SOFTWARE\Drivers
HKCU\SOFTWARE\Dropbox
HKCU\SOFTWARE\DropboxUpdate
HKCU\SOFTWARE\ej-technologies
HKCU\SOFTWARE\Electronic Arts
HKCU\SOFTWARE\Facepunch Studios LTD
HKCU\SOFTWARE\FastCompress-Zip
HKCU\SOFTWARE\FixKorea
HKCU\SOFTWARE\Gameforge4d
HKCU\SOFTWARE\GfaceGmbh
HKCU\SOFTWARE\Gigabyte
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\IGA
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\InstallPath
HKCU\SOFTWARE\IvoSoft
HKCU\SOFTWARE\iWebar-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\JavaSoft
HKCU\SOFTWARE\Licenses
HKCU\SOFTWARE\Local AppWizard-Generated Applications
HKCU\SOFTWARE\Logitech
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\MainConcept
HKCU\SOFTWARE\MainConcept (Consumer)
HKCU\SOFTWARE\Mirillis
HKCU\SOFTWARE\MountAndBladeWarbandKeys
HKCU\SOFTWARE\Mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\Mumble
HKCU\SOFTWARE\Nexon
HKCU\SOFTWARE\Nosibay =>PUP.Optional.SPointer
HKCU\SOFTWARE\OB
HKCU\SOFTWARE\Opera Software
HKCU\SOFTWARE\Oracle
HKCU\SOFTWARE\Parsec Productions
HKCU\SOFTWARE\Piriform
HKCU\SOFTWARE\Raptr
HKCU\SOFTWARE\Razer
HKCU\SOFTWARE\Rtp
HKCU\SOFTWARE\Samsung
HKCU\SOFTWARE\SKS
HKCU\SOFTWARE\Skype
HKCU\SOFTWARE\SoftVoice
HKCU\SOFTWARE\Software
HKCU\SOFTWARE\Store =>PUP.Optional.Generic
HKCU\SOFTWARE\SysProgs
HKCU\SOFTWARE\System32
HKCU\SOFTWARE\TeamSpeak 3 Client
HKCU\SOFTWARE\TechSmith
HKCU\SOFTWARE\tfdfu
HKCU\SOFTWARE\The Creative Assembly
HKCU\SOFTWARE\The Document Foundation
HKCU\SOFTWARE\The Fun Pimps
HKCU\SOFTWARE\Trolltech
HKCU\SOFTWARE\tstamptoken =>PUP.Optional.MaxComputerCleaner
HKCU\SOFTWARE\Tutorials =>PUP.Optional.AgenceExclusive
HKCU\SOFTWARE\TutoTag =>PUP.Optional.AgenceExclusive
HKCU\SOFTWARE\Unity
HKCU\SOFTWARE\Valve
HKCU\SOFTWARE\VIA
HKCU\SOFTWARE\Wargaming.net
HKCU\SOFTWARE\Win
HKCU\SOFTWARE\WinRAR
HKCU\SOFTWARE\WinRAR SFX
HKCU\SOFTWARE\Wireshark
HKCU\SOFTWARE\WNetEnhancer =>PUP.Optional.Wajam
HKCU\SOFTWARE\Wow6432Node
HKCU\SOFTWARE\WTools =>PUP.Optional.Nosibay
HKCU\SOFTWARE\XinYi Network
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\Intel\Indeo\4.1
HKCU\SOFTWARE\AppDataLow\Software

---\\ Contenu des dossiers Programmes (336) - 31s
O43 - CFD: 08/12/2015 - [] D -- C:\Program Files (x86)\032B0290-1449484090-0559-0306-940700080009 =>PUP.Optional.CrossRider
O43 - CFD: 07/12/2015 - [] D -- C:\Program Files (x86)\032B0290-1449484097-0559-0306-940700080009 =>PUP.Optional.CrossRider
O43 - CFD: 23/03/2015 - [] D -- C:\Program Files (x86)\209fe72e-431d-43ba-948d-1274eef4bd7f =>PUP.Optional.CrossRider
O43 - CFD: 23/03/2015 - [] D -- C:\Program Files (x86)\6d2018b6-192d-498a-8d18-12afcb059256 =>PUP.Optional.CrossRider
O43 - CFD: 23/03/2015 - [] D -- C:\Program Files (x86)\Adobe
O43 - CFD: 23/03/2015 - [] D -- C:\Program Files (x86)\AMD
O43 - CFD: 02/06/2013 - [] D -- C:\Program Files (x86)\AMD APP
O43 - CFD: 14/02/2015 - [] D -- C:\Program Files (x86)\AMD AVT
O43 - CFD: 18/10/2015 - [] D -- C:\Program Files (x86)\Apple Software Update
O43 - CFD: 18/11/2015 - [] D -- C:\Program Files (x86)\Assist Point =>PUP.Optional.AssistPoint
O43 - CFD: 21/09/2015 - [] D -- C:\Program Files (x86)\Battle.net
O43 - CFD: 22/10/2015 - [] D -- C:\Program Files (x86)\Battlelog Web Plugins
O43 - CFD: 18/10/2015 - [] D -- C:\Program Files (x86)\Bonjour
O43 - CFD: 08/12/2015 - [] D -- C:\Program Files (x86)\Common Files
O43 - CFD: 25/06/2014 - [] D -- C:\Program Files (x86)\DAEMON Tools Lite
O43 - CFD: 22/11/2015 - [] D -- C:\Program Files (x86)\Dropbox
O43 - CFD: 14/02/2015 - [] D -- C:\Program Files (x86)\Etron Technology
O43 - CFD: 08/12/2015 - [] D -- C:\Program Files (x86)\Fast-Search =>PUP.Optional.FastSearch
O43 - CFD: 08/12/2015 - [] D -- C:\Program Files (x86)\FastCompress-Zip
O43 - CFD: 07/12/2015 - [] D -- C:\Program Files (x86)\Feed Notifier
O43 - CFD: 26/10/2015 - [] D -- C:\Program Files (x86)\GameforgeLive
O43 - CFD: 13/12/2014 - [] D -- C:\Program Files (x86)\GIGABYTE
O43 - CFD: 07/12/2015 - [] D -- C:\Program Files (x86)\gmsd_fr_005010169 =>PUP.Optional.CrossRider
O43 - CFD: 28/10/2015 - [] D -- C:\Program Files (x86)\Google
O43 - CFD: 21/05/2015 - [] D -- C:\Program Files (x86)\Hearthstone
O43 - CFD: 28/10/2015 - [] D -- C:\Program Files (x86)\Image-Line
O43 - CFD: 06/12/2015 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 13/12/2014 - [] D -- C:\Program Files (x86)\Intel
O43 - CFD: 11/07/2012 - [] D -- C:\Program Files (x86)\Internet Explorer
O43 - CFD: 18/10/2015 - [] D -- C:\Program Files (x86)\iTunes
O43 - CFD: 30/10/2015 - [] D -- C:\Program Files (x86)\Java
O43 - CFD: 06/12/2015 - [] D -- C:\Program Files (x86)\Kingo ROOT
O43 - CFD: 03/11/2015 - [] D -- C:\Program Files (x86)\LibreOffice 5
O43 - CFD: 12/12/2014 - [] D -- C:\Program Files (x86)\Microsoft LifeCam
O43 - CFD: 07/12/2015 - [] D -- C:\Program Files (x86)\Microsoft Silverlight
O43 - CFD: 17/09/2013 - [] D -- C:\Program Files (x86)\Microsoft XNA
O43 - CFD: 02/06/2013 - [] D -- C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 21/11/2015 - [0] D -- C:\Program Files (x86)\Mirillis
O43 - CFD: 14/11/2015 - [] D -- C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 15/11/2015 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\MSBuild
O43 - CFD: 01/11/2013 - [] D -- C:\Program Files (x86)\Mumble
O43 - CFD: 03/05/2015 - [] D -- C:\Program Files (x86)\NVIDIA Corporation
O43 - CFD: 08/12/2015 - [] D -- C:\Program Files (x86)\Opera
O43 - CFD: 28/10/2015 - [] D -- C:\Program Files (x86)\Overwolf
O43 - CFD: 09/06/2013 - [] D -- C:\Program Files (x86)\Pando Networks
O43 - CFD: 14/12/2014 - [] D -- C:\Program Files (x86)\Raptr
O43 - CFD: 14/02/2015 - [] D -- C:\Program Files (x86)\Razer
O43 - CFD: 07/12/2015 - [] D -- C:\Program Files (x86)\rec_en_77 =>PUP.Optional.Tuto4PC
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 06/11/2015 - [] D -- C:\Program Files (x86)\RegCleaner
O43 - CFD: 06/12/2015 - [] D -- C:\Program Files (x86)\Samsung
O43 - CFD: 08/12/2015 - [] D -- C:\Program Files (x86)\SFK =>PUP.Optional.MyWebSearch
O43 - CFD: 21/11/2015 - [] RD -- C:\Program Files (x86)\Skype
O43 - CFD: 24/09/2014 - [] D -- C:\Program Files (x86)\Spotflux
O43 - CFD: 28/11/2015 - [] D -- C:\Program Files (x86)\Ubisoft
O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files (x86)\Uninstall Information
O43 - CFD: 21/11/2015 - [] D -- C:\Program Files (x86)\VIA
O43 - CFD: 15/11/2015 - [] D -- C:\Program Files (x86)\VideoLAN
O43 - CFD: 07/12/2015 - [] D -- C:\Program Files (x86)\VROOT
O43 - CFD: 21/11/2015 - [0] D -- C:\Program Files (x86)\VS Revo Group
O43 - CFD: 11/07/2012 - [] D -- C:\Program Files (x86)\WinCDEmu
O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Defender
O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Mail
O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Media Player
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Windows NT
O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 07/12/2015 - [] D -- C:\Program Files (x86)\WNetEnhancer =>PUP.Optional.Wajam
O43 - CFD: 17/06/2015 - [] D -- C:\Program Files (x86)\World of Warcraft
O43 - CFD: 11/07/2012 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 11/07/2012 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 14/02/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
O43 - CFD: 11/05/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
O43 - CFD: 19/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
O43 - CFD: 27/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
O43 - CFD: 25/06/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
O43 - CFD: 22/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
O43 - CFD: 14/10/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 14
O43 - CFD: 09/01/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
O43 - CFD: 08/11/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 07/12/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP =>PUP.Optional.GamesDesktop
O43 - CFD: 13/12/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGABYTE
O43 - CFD: 28/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 21/05/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
O43 - CFD: 18/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
O43 - CFD: 21/05/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
O43 - CFD: 18/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
O43 - CFD: 30/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
O43 - CFD: 06/12/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kingo ROOT
O43 - CFD: 03/11/2015 - [] SD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.0
O43 - CFD: 14/02/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ma-config.com
O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 12/12/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft LifeCam
O43 - CFD: 07/12/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
O43 - CFD: 01/11/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble
O43 - CFD: 09/01/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
O43 - CFD: 21/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
O43 - CFD: 08/11/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
O43 - CFD: 14/02/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
O43 - CFD: 06/12/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
O43 - CFD: 13/11/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
O43 - CFD: 08/12/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 01/06/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
O43 - CFD: 01/06/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
O43 - CFD: 15/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
O43 - CFD: 07/12/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VROOT
O43 - CFD: 25/06/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 07/12/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WNetEnhancer =>PUP.Optional.Wajam
O43 - CFD: 10/05/2015 - [] D -- C:\ProgramData\.mono
O43 - CFD: 18/10/2015 - [] D -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
O43 - CFD: 08/12/2015 - [] D -- C:\ProgramData\3a08aecf-996c-434c-872d-c3768a6d9134
O43 - CFD: 07/12/2015 - [] D -- C:\ProgramData\5673cc4a-1bd3-1
O43 - CFD: 07/12/2015 - [] D -- C:\ProgramData\5673cc4a-61b7-0
O43 - CFD: 07/12/2015 - [] D -- C:\ProgramData\7c0535b143fc4671b6ebd202fbffe066
O43 - CFD: 16/09/2014 - [] D -- C:\ProgramData\Adobe
O43 - CFD: 08/12/2015 - [] D -- C:\ProgramData\Airtop =>PUP.Optional.Salus
O43 - CFD: 07/12/2015 - [] D -- C:\ProgramData\Airtops =>PUP.Optional.Salus
O43 - CFD: 14/02/2015 - [] D -- C:\ProgramData\AMD
O43 - CFD: 18/10/2015 - [] D -- C:\ProgramData\Apple
O43 - CFD: 18/10/2015 - [] D -- C:\ProgramData\Apple Computer
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 07/12/2015 - [] D -- C:\ProgramData\ApplicationHosting =>PUP.Optional.ApplicationHosting
O43 - CFD: 14/02/2015 - [] D -- C:\ProgramData\ATI
O43 - CFD: 16/02/2015 - [] D -- C:\ProgramData\AVAST Software
O43 - CFD: 11/06/2013 - [] D -- C:\ProgramData\Battle.net
O43 - CFD: 05/04/2015 - [] D -- C:\ProgramData\Blizzard Entertainment
O43 - CFD: 11/07/2012 - [0] SHD -- C:\ProgramData\Bureau
O43 - CFD: 07/12/2015 - [] D -- C:\ProgramData\c716fd70-872c-4aaa-a07f-e248365d7f56
O43 - CFD: 09/03/2014 - [] HD -- C:\ProgramData\CanonBJ
O43 - CFD: 25/06/2014 - [] D -- C:\ProgramData\DAEMON Tools Lite
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Desktop
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 22/11/2015 - [] D -- C:\ProgramData\Dropbox
O43 - CFD: 19/10/2015 - [] D -- C:\ProgramData\EA Core
O43 - CFD: 19/10/2015 - [] D -- C:\ProgramData\EA Logs
O43 - CFD: 14/10/2013 - [] D -- C:\ProgramData\Electronic Arts
O43 - CFD: 11/07/2012 - [0] SHD -- C:\ProgramData\Favoris
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Favorites
O43 - CFD: 28/10/2015 - [] D -- C:\ProgramData\GFACE
O43 - CFD: 24/09/2014 - [] D -- C:\ProgramData\Glyph
O43 - CFD: 12/11/2013 - [] D -- C:\ProgramData\LogMeIn
O43 - CFD: 14/02/2015 - [] D -- C:\ProgramData\ma-config.com
O43 - CFD: 08/11/2014 - [] D -- C:\ProgramData\Malwarebytes
O43 - CFD: 11/07/2012 - [0] SHD -- C:\ProgramData\Menu Démarrer
O43 - CFD: 07/12/2015 - [] D -- C:\ProgramData\Microsoft
O43 - CFD: 08/05/2015 - [] D -- C:\ProgramData\Mirillis
O43 - CFD: 11/07/2012 - [0] SHD -- C:\ProgramData\Modèles
O43 - CFD: 23/09/2014 - [] D -- C:\ProgramData\Nexon
O43 - CFD: 14/12/2014 - [] D -- C:\ProgramData\Norton
O43 - CFD: 13/12/2014 - [] D -- C:\ProgramData\NortonInstaller
O43 - CFD: 30/10/2015 - [] D -- C:\ProgramData\Oracle
O43 - CFD: 15/11/2015 - [] D -- C:\ProgramData\Origin
O43 - CFD: 14/02/2015 - [] D -- C:\ProgramData\Package Cache
O43 - CFD: 11/01/2015 - [] D -- C:\ProgramData\PMB Files
O43 - CFD: 14/02/2015 - [] D -- C:\ProgramData\Razer
O43 - CFD: 16/09/2014 - [] D -- C:\ProgramData\regid.1986-12.com.adobe
O43 - CFD: 24/09/2014 - [] D -- C:\ProgramData\Riot Games
O43 - CFD: 15/07/2014 - [] D -- C:\ProgramData\RogueKiller
O43 - CFD: 31/05/2014 - [] D -- C:\ProgramData\RzMaelstromVAD_1.1.58.1854
O43 - CFD: 06/12/2015 - [] D -- C:\ProgramData\Samsung
O43 - CFD: 07/12/2015 - [] D -- C:\ProgramData\Service7609 =>Heuristic.Graftor
O43 - CFD: 13/11/2014 - [] D -- C:\ProgramData\Skype
O43 - CFD: 24/09/2014 - [] D -- C:\ProgramData\spotflux
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Start Menu
O43 - CFD: 19/11/2013 - [] D -- C:\ProgramData\Sun
O43 - CFD: 21/11/2015 - [0] D -- C:\ProgramData\TamoSoft
O43 - CFD: 25/06/2013 - [] D -- C:\ProgramData\TechSmith
O43 - CFD: 07/04/2015 - [0] AD -- C:\ProgramData\TEMP
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Templates
O43 - CFD: 07/12/2015 - [] D -- C:\ProgramData\Tmp0x0x
O43 - CFD: 02/06/2015 - [] D -- C:\ProgramData\TrackMania
O43 - CFD: 23/06/2013 - [] D -- C:\ProgramData\WarThunder
O43 - CFD: 08/12/2015 - [] D -- C:\ProgramData\Zitenop =>PUP.Optional.Salus
O43 - CFD: 08/12/2015 - [] D -- C:\ProgramData\Zitenops =>PUP.Optional.Salus
O43 - CFD: 10/04/2014 - [] D -- C:\Program Files (x86)\Common Files\Adobe AIR
O43 - CFD: 18/10/2015 - [] D -- C:\Program Files (x86)\Common Files\Apple
O43 - CFD: 02/06/2013 - [] D -- C:\Program Files (x86)\Common Files\ATI Technologies
O43 - CFD: 14/06/2014 - [] D -- C:\Program Files (x86)\Common Files\BattlEye
O43 - CFD: 21/05/2015 - [] D -- C:\Program Files (x86)\Common Files\Blizzard Entertainment
O43 - CFD: 06/12/2015 - [] D -- C:\Program Files (x86)\Common Files\c716fd70-872c-4aaa-a07f-e248365d7f56
O43 - CFD: 26/10/2015 - [] D -- C:\Program Files (x86)\Common Files\Config
O43 - CFD: 07/12/2015 - [] D -- C:\Program Files (x86)\Common Files\Danstring
O43 - CFD: 19/10/2015 - [] HD -- C:\Program Files (x86)\Common Files\EAInstaller
O43 - CFD: 13/12/2014 - [] D -- C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 30/10/2015 - [] D -- C:\Program Files (x86)\Common Files\Java
O43 - CFD: 17/09/2013 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared
O43 - CFD: 21/05/2015 - [] D -- C:\Program Files (x86)\Common Files\Propellerhead Software
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Common Files\Services
O43 - CFD: 13/11/2014 - [] D -- C:\Program Files (x86)\Common Files\Skype
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines
O43 - CFD: 09/09/2015 - [] D -- C:\Program Files (x86)\Common Files\Steam
O43 - CFD: 11/07/2012 - [] D -- C:\Program Files (x86)\Common Files\System
O43 - CFD: 03/05/2015 - [] D -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
O43 - CFD: 21/02/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\.minecraft
O43 - CFD: 10/05/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\.mono
O43 - CFD: 13/04/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\8pecxstudios
O43 - CFD: 20/09/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\Adobe
O43 - CFD: 14/04/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\AMD
O43 - CFD: 26/08/2013 - [] D -- C:\Users\Alexis\AppData\Roaming\AnkamaCertificates
O43 - CFD: 26/08/2013 - [] D -- C:\Users\Alexis\AppData\Roaming\app
O43 - CFD: 15/11/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Apple Computer
O43 - CFD: 01/06/2013 - [] D -- C:\Users\Alexis\AppData\Roaming\ATI
O43 - CFD: 03/02/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Audacity
O43 - CFD: 11/05/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\Awesomium
O43 - CFD: 03/10/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\Battle.net
O43 - CFD: 12/11/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\com.playsaurus.heroclicker
O43 - CFD: 21/02/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Curse Advertising
O43 - CFD: 22/11/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\DAEMON Tools Lite
O43 - CFD: 26/08/2013 - [] D -- C:\Users\Alexis\AppData\Roaming\Dofus
O43 - CFD: 26/08/2013 - [] D -- C:\Users\Alexis\AppData\Roaming\Dofus-2
O43 - CFD: 29/08/2013 - [] D -- C:\Users\Alexis\AppData\Roaming\Dofus-3
O43 - CFD: 04/02/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\Dofus2
O43 - CFD: 22/11/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Dropbox
O43 - CFD: 09/01/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\FileZilla
O43 - CFD: 17/06/2013 - [] D -- C:\Users\Alexis\AppData\Roaming\ftblauncher
O43 - CFD: 13/01/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Guild Wars 2
O43 - CFD: 07/12/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\GytjeOibyirn
O43 - CFD: 12/04/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\HeroesAndGeneralsDesktop
O43 - CFD: 04/06/2013 - [] D -- C:\Users\Alexis\AppData\Roaming\Identities
O43 - CFD: 21/05/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Image-Line
O43 - CFD: 13/12/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\InstallShield
O43 - CFD: 08/12/2015 - [0] D -- C:\Users\Alexis\AppData\Roaming\istartpageing =>PUP.Optional.IstartPageing
O43 - CFD: 20/12/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\java
O43 - CFD: 25/06/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\Kalypso Media
O43 - CFD: 12/12/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\library_dir
O43 - CFD: 09/09/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\LibreOffice
O43 - CFD: 10/06/2013 - [] D -- C:\Users\Alexis\AppData\Roaming\LolClient
O43 - CFD: 09/06/2013 - [] D -- C:\Users\Alexis\AppData\Roaming\Macromedia
O43 - CFD: 07/12/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\mgyun
O43 - CFD: 05/05/2015 - [] SD -- C:\Users\Alexis\AppData\Roaming\Microsoft
O43 - CFD: 08/05/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Mirillis
O43 - CFD: 01/06/2013 - [] D -- C:\Users\Alexis\AppData\Roaming\Mount&Blade Warband
O43 - CFD: 25/08/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\Mozilla
O43 - CFD: 15/07/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\Mumble
O43 - CFD: 07/12/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\NivriWaickyr
O43 - CFD: 08/12/2015 - [0] D -- C:\Users\Alexis\AppData\Roaming\Nosibay =>PUP.Optional.BubbleDock
O43 - CFD: 09/01/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Notepad++
O43 - CFD: 08/12/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\OpenCandy =>PUP.Optional.OpenCandy
O43 - CFD: 08/12/2015 - [0] D -- C:\Users\Alexis\AppData\Roaming\Opera Software
O43 - CFD: 09/10/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Origin
O43 - CFD: 14/12/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\Raptr
O43 - CFD: 26/08/2013 - [] D -- C:\Users\Alexis\AppData\Roaming\Reg
O43 - CFD: 26/08/2013 - [] D -- C:\Users\Alexis\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
O43 - CFD: 17/02/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\RIFT
O43 - CFD: 23/12/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\Riot Games
O43 - CFD: 06/12/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Samsung
O43 - CFD: 07/06/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Shooter
O43 - CFD: 08/12/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Skype
O43 - CFD: 08/12/2015 - [0] D -- C:\Users\Alexis\AppData\Roaming\Store =>PUP.Optional.Nosibay
O43 - CFD: 05/11/2013 - [] D -- C:\Users\Alexis\AppData\Roaming\SumatraPDF
O43 - CFD: 30/10/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Sun
O43 - CFD: 27/10/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\TeamViewer
O43 - CFD: 14/07/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Teeworlds
O43 - CFD: 24/09/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\TERA
O43 - CFD: 30/06/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\Tropico 5
O43 - CFD: 08/12/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\TS3Client
O43 - CFD: 15/11/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\vlc
O43 - CFD: 14/06/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\Wargaming.net
O43 - CFD: 25/06/2013 - [] D -- C:\Users\Alexis\AppData\Roaming\WinRAR
O43 - CFD: 11/09/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Wireshark
O43 - CFD: 17/09/2013 - [] D -- C:\Users\Alexis\AppData\Roaming\WorldPainter
O43 - CFD: 08/12/2015 - [0] D -- C:\Users\Alexis\AppData\Roaming\WTools
O43 - CFD: 20/09/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\XnView
O43 - CFD: 07/12/2015 - [0] D -- C:\Users\Alexis\AppData\Roaming\yoursearching =>PUP.Optional.YourSearching
O43 - CFD: 08/12/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\ZHP
O43 - CFD: 07/12/2015 - [] D -- C:\Users\Alexis\AppData\Local\032B0290-1449487728-0559-0306-940700080009
O43 - CFD: 10/04/2014 - [] D -- C:\Users\Alexis\AppData\Local\41
O43 - CFD: 13/04/2015 - [] D -- C:\Users\Alexis\AppData\Local\8pecxstudios
O43 - CFD: 20/09/2014 - [] D -- C:\Users\Alexis\AppData\Local\Adobe
O43 - CFD: 26/08/2015 - [] D -- C:\Users\Alexis\AppData\Local\Anno Online
O43 - CFD: 08/06/2013 - [] D -- C:\Users\Alexis\AppData\Local\Apple
O43 - CFD: 08/06/2013 - [] D -- C:\Users\Alexis\AppData\Local\Apple Computer
O43 - CFD: 02/06/2013 - [0] SHD -- C:\Users\Alexis\AppData\Local\Application Data
O43 - CFD: 01/06/2013 - [] D -- C:\Users\Alexis\AppData\Local\Apps
O43 - CFD: 01/06/2013 - [] D -- C:\Users\Alexis\AppData\Local\ATI
O43 - CFD: 21/09/2015 - [] D -- C:\Users\Alexis\AppData\Local\Battle.net
O43 - CFD: 11/05/2014 - [] D -- C:\Users\Alexis\AppData\Local\Blizzard
O43 - CFD: 11/05/2014 - [] D -- C:\Users\Alexis\AppData\Local\Blizzard Entertainment
O43 - CFD: 04/01/2014 - [] D -- C:\Users\Alexis\AppData\Local\CDWLauncher
O43 - CFD: 23/08/2015 - [] D -- C:\Users\Alexis\AppData\Local\CEF
O43 - CFD: 08/12/2015 - [] D -- C:\Users\Alexis\AppData\Local\CrashDumps
O43 - CFD: 23/03/2015 - [] D -- C:\Users\Alexis\AppData\Local\CrashRpt =>.Superfluous.CrashReports
O43 - CFD: 24/09/2014 - [] D -- C:\Users\Alexis\AppData\Local\CSO
O43 - CFD: 14/06/2014 - [] D -- C:\Users\Alexis\AppData\Local\DayZ
O43 - CFD: 29/10/2015 - [0] D -- C:\Users\Alexis\AppData\Local\Deployment
O43 - CFD: 22/11/2015 - [] D -- C:\Users\Alexis\AppData\Local\Dropbox
O43 - CFD: 21/11/2013 - [] D -- C:\Users\Alexis\AppData\Local\Eclipse
O43 - CFD: 16/11/2015 - [] D -- C:\Users\Alexis\AppData\Local\ElevatedDiagnostics
O43 - CFD: 19/10/2015 - [] D -- C:\Users\Alexis\AppData\Local\ESN
O43 - CFD: 24/09/2014 - [] D -- C:\Users\Alexis\AppData\Local\Glyph
O43 - CFD: 08/12/2015 - [] D -- C:\Users\Alexis\AppData\Local\gmsd_fr_005010169 =>PUP.Optional.CrossRider
O43 - CFD: 01/06/2013 - [] D -- C:\Users\Alexis\AppData\Local\Google
O43 - CFD: 02/06/2013 - [0] SHD -- C:\Users\Alexis\AppData\Local\Historique
O43 - CFD: 07/12/2015 - [] D -- C:\Users\Alexis\AppData\Local\Installer =>PUP.Optional.InstallPedia
O43 - CFD: 06/12/2015 - [] D -- C:\Users\Alexis\AppData\Local\Kingosoft
O43 - CFD: 12/11/2013 - [] D -- C:\Users\Alexis\AppData\Local\LogMeIn
O43 - CFD: 28/08/2014 - [] D -- C:\Users\Alexis\AppData\Local\Macromedia
O43 - CFD: 06/12/2015 - [] D -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive =>.Superfluous.MalwareProtection
O43 - CFD: 07/12/2015 - [] D -- C:\Users\Alexis\AppData\Local\Mega Limited
O43 - CFD: 07/12/2015 - [] D -- C:\Users\Alexis\AppData\Local\MEGAsync
O43 - CFD: 07/12/2015 - [] D -- C:\Users\Alexis\AppData\Local\Microsoft
O43 - CFD: 08/05/2015 - [] D -- C:\Users\Alexis\AppData\Local\Mirillis
O43 - CFD: 25/08/2014 - [] D -- C:\Users\Alexis\AppData\Local\Mozilla
O43 - CFD: 08/12/2015 - [0] D -- C:\Users\Alexis\AppData\Local\Opera Software
O43 - CFD: 14/10/2013 - [] D -- C:\Users\Alexis\AppData\Local\Origin
O43 - CFD: 11/01/2015 - [] D -- C:\Users\Alexis\AppData\Local\PMB Files
O43 - CFD: 23/06/2013 - [] D -- C:\Users\Alexis\AppData\Local\Programs
O43 - CFD: 19/10/2015 - [] D -- C:\Users\Alexis\AppData\Local\PunkBuster
O43 - CFD: 14/02/2015 - [] D -- C:\Users\Alexis\AppData\Local\Razer
O43 - CFD: 14/02/2015 - [] D -- C:\Users\Alexis\AppData\Local\Razer_Inc
O43 - CFD: 07/12/2015 - [] D -- C:\Users\Alexis\AppData\Local\rec_en_77 =>PUP.Optional.Tuto4PC
O43 - CFD: 14/02/2015 - [] D -- C:\Users\Alexis\AppData\Local\RzStats
O43 - CFD: 27/05/2014 - [] D -- C:\Users\Alexis\AppData\Local\Skype
O43 - CFD: 08/12/2015 - [] D -- C:\Users\Alexis\AppData\Local\SmartWeb =>PUP.Optional.SmartWebSearch
O43 - CFD: 10/04/2014 - [] D -- C:\Users\Alexis\AppData\Local\Software =>PUP.Optional.Boxore
O43 - CFD: 20/02/2015 - [] D -- C:\Users\Alexis\AppData\Local\Steam
O43 - CFD: 25/06/2013 - [] D -- C:\Users\Alexis\AppData\Local\TechSmith
O43 - CFD: 08/12/2015 - [] D -- C:\Users\Alexis\AppData\Local\Temp
O43 - CFD: 07/12/2015 - [0] D -- C:\Users\Alexis\AppData\Local\Tempfolder
O43 - CFD: 02/06/2013 - [0] SHD -- C:\Users\Alexis\AppData\Local\Temporary Internet Files
O43 - CFD: 12/04/2015 - [] D -- C:\Users\Alexis\AppData\Local\Ubisoft
O43 - CFD: 28/11/2015 - [] D -- C:\Users\Alexis\AppData\Local\Ubisoft Game Launcher
O43 - CFD: 23/06/2013 - [0] D -- C:\Users\Alexis\AppData\Local\WarThunder
O43 - CFD: 28/10/2015 - [] D -- C:\Users\Alexis\AppData\Local\wf-launcher
O43 - CFD: 07/12/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 08/12/2015 - [] RD -- C:\Users\Alexis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 21/02/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse
O43 - CFD: 21/11/2015 - [0] D -- C:\Users\Alexis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 07/12/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
O43 - CFD: 07/12/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MEGAsync
O43 - CFD: 09/01/2015 - [0] D -- C:\Users\Alexis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
O43 - CFD: 08/12/2015 - [] RD -- C:\Users\Alexis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 13/12/2014 - [] D -- C:\Users\Alexis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
O43 - CFD: 28/11/2015 - [] D -- C:\Users\Alexis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft

---\\ Derniers fichiers créés dans Windows Prefetcher (7) - 10s
O45 - LFCP:[MD5.91F5519404E8885113099DEFC56BAC6F] 08/12/2015 A -- C:\Windows\Prefetch\62793.WINDAPP.MON001.NO.EXE-5D7E35F7.pf =>PUP.Optional.Nosibay
O45 - LFCP:[MD5.8B05E5A4971FDDF3A6A5400F14AFF63A] 08/12/2015 A -- C:\Windows\Prefetch\BUBBLE DOCK BSETUP.EXE-29E55CE8.pf =>PUP.Optional.BubbleDock
O45 - LFCP:[MD5.6AF2E1DA57B1B6EA33EC5605ED054529] 08/12/2015 A -- C:\Windows\Prefetch\BUBBLE DOCK.EXE-C3A82C7A.pf =>PUP.Optional.BubbleDock
O45 - LFCP:[MD5.38DB5057F06C489999555EF8C692A5D9] 08/12/2015 A -- C:\Windows\Prefetch\LBUBBLE DOCK.EXE-2F791CAE.pf =>PUP.Optional.BubbleDock
O45 - LFCP:[MD5.0B3EAB6AEFC776BC375E5EF57AE00F7D] 08/12/2015 A -- C:\Windows\Prefetch\SEARCHMOREKNOWDESKTOPSEARCH.E-4D59CE71.pf =>PUP.Optional.DesktopSearch
O45 - LFCP:[MD5.B735FBB9A79BCF9864E09FD22C68F79C] 08/12/2015 A -- C:\Windows\Prefetch\SELECTION TOOLS.EXE-E43D508D.pf =>PUP.Optional.Nosibay
O45 - LFCP:[MD5.1E176CAD970806CAC2AB01F306410518] 08/12/2015 A -- C:\Windows\Prefetch\UPGMSD_FR_005010169.EXE-06E01730.pf =>PUP.Optional.CrossRider

---\\ ShellIconOverlayIdentifiers (SIOI) (14) - 6s
O106 - SIOI: DropboxExt1 Class [ DropboxExt1] - {FB314ED9-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll {017CA19B5859E83F44D874C1CE506E6D} ©
O106 - SIOI: DropboxExt2 Class [ DropboxExt2] - {FB314EDA-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll {017CA19B5859E83F44D874C1CE506E6D} ©
O106 - SIOI: DropboxExt5 Class [ DropboxExt3] - {FB314EDD-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll {017CA19B5859E83F44D874C1CE506E6D} ©
O106 - SIOI: DropboxExt6 Class [ DropboxExt4] - {FB314EDE-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll {017CA19B5859E83F44D874C1CE506E6D} ©
O106 - SIOI: DropboxExt3 Class [ DropboxExt5] - {FB314EDB-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll {017CA19B5859E83F44D874C1CE506E6D} ©
O106 - SIOI: DropboxExt7 Class [ DropboxExt6] - {FB314EDF-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll {017CA19B5859E83F44D874C1CE506E6D} ©
O106 - SIOI: DropboxExt4 Class [ DropboxExt7] - {FB314EDC-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll {017CA19B5859E83F44D874C1CE506E6D} ©
O106 - SIOI: DropboxExt8 Class [ DropboxExt8] - {FB314EE0-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll {017CA19B5859E83F44D874C1CE506E6D} ©
O106 - SIOI: ###MegaShellExtPending [###MegaShellExtPending] - {056D528D-CE28-4194-9BA3-BA2E9197FF8C}. (...) -- C:\Users\Alexis\AppData\Local\MEGAsync\ShellExtX32.dll
O106 - SIOI: ###MegaShellExtSynced [###MegaShellExtSynced] - {05B38830-F4E9-4329-978B-1DD28605D202}. (...) -- C:\Users\Alexis\AppData\Local\MEGAsync\ShellExtX32.dll
O106 - SIOI: ###MegaShellExtSyncing [###MegaShellExtSyncing] - {0596C850-7BDD-4C9D-AFDF-873BE6890637}. (...) -- C:\Users\Alexis\AppData\Local\MEGAsync\ShellExtX32.dll
O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - DLL d’extension d’environnement de stockage.) -- C:\Windows\System32\EhStorShell.dll ©
O106 - SIOI: ShareOverlay Class [ShareOverlay] - {594D4122-1F87-41E2-96C7-825FB4796516}. (.IvoSoft - Adds classic Windows Explorer features.) -- C:\Program Files\Classic Shell\ClassicExplorer32.dll ©
O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll ©

---\\ Enumération des clés StartupReg (11) - 1s
O53 - SMSR:HKLM\...\startupreg\cacaoweb [Key] . (...) -- C:\Users\Alexis\AppData\Roaming\cacaoweb\cacaoweb.exe (.not file.) =>.Superfluous.CacaoWeb
O53 - SMSR:HKLM\...\startupreg\CCleaner Monitoring [Key] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe ©
O53 - SMSR:HKLM\...\startupreg\GoogleChromeAutoLaunch_C46C75B69F6A4FF65E3F09375992B78F [Key] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O53 - SMSR:HKLM\...\startupreg\Overwolf [Key] . (...) -- C:\Program Files (x86)\Overwolf\Overwolf.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\Razer Synapse [Key] . (.Razer Inc. - Razer Synapse.) -- C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe ©
O53 - SMSR:HKLM\...\startupreg\RazerCortex [Key] . (.Razer Inc. - RazerCortex.exe.) -- C:\Program Files (x86)\Razer\Razer Cortex\RazerCortex.exe ©
O53 - SMSR:HKLM\...\startupreg\RocketDock [Key] . (...) -- C:\Program Files (x86)\RocketDock\RocketDock.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\Skype [Key] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe ©
O53 - SMSR:HKLM\...\startupreg\StartCCC [Key] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe ©
O53 - SMSR:HKLM\...\startupreg\Steam [Key] . (.Valve Corporation - Steam Client Bootstrapper.) -- D:\Program Files (x86)\Steam\Steam.exe ©
O53 - SMSR:HKLM\...\startupreg\uTorrent [Key] . (...) -- C:\Users\Alexis\AppData\Roaming\uTorrent\uTorrent.exe (.not file.)

---\\ Liste des pilotes du système (78) - 25s
O58 - SDL:2009/07/14 02:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [491088] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [339536] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\drivers\adpu320.sys [182864] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [15440] =>.Microsoft Windows®
O58 - SDL:2014/12/23 23:40:56 A . (.Advanced Micro Devices - AMD ACP Binaries.) -- C:\Windows\System32\drivers\amdacpksd.sys [294600] =>.Advanced Micro Devices, Inc.®
O58 - SDL:2014/10/28 00:46:12 A . (.Advanced Micro Devices, Inc. - AMD PCI Root Bus Lower Filter.) -- C:\Windows\System32\drivers\amdkmpfd.sys [62152] =>.Advanced Micro Devices, Inc.®
O58 - SDL:2010/11/21 04:23:47 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [107904] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [194128] =>.Microsoft Windows®
O58 - SDL:2010/11/21 04:23:47 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [27008] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [87632] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [97856] =>.Microsoft Windows®
O58 - SDL:2009/06/20 03:09:57 A . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driv.) -- C:\Windows\System32\drivers\athrx.sys [1394688] ©
O58 - SDL:2014/06/21 18:01:22 A . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) -- C:\Windows\System32\drivers\AtihdW76.sys [94720] ©
O58 - SDL:2014/12/23 23:39:02 A . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\System32\drivers\atikmdag.sys [18977280] ©
O58 - SDL:2014/12/23 23:08:00 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\Windows\System32\drivers\atikmpag.sys [591872] ©
O58 - SDL:2009/06/10 21:34:23 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60a.sys [270848] ©
O58 - SDL:2011/08/08 19:13:12 A . (.SysProgs.org - WinCDEmu virtual CDROM bus.) -- C:\Windows\System32\drivers\BazisVirtualCDBus.sys [198480] {1734AA23F6C88B7F2E7FC68F7118423E}
O58 - SDL:2009/06/10 21:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [18432] ©
O58 - SDL:2009/06/10 21:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [8704] ©
O58 - SDL:2009/07/14 02:19:07 A . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [286720] ©
O58 - SDL:2009/06/10 21:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [47104] ©
O58 - SDL:2009/06/10 21:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [14976] ©
O58 - SDL:2009/06/10 21:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [14720] ©
O58 - SDL:2009/06/10 21:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [468480] ©
O58 - SDL:2015/12/07 19:36:36 A . (.Cherimoya Ltd - Cherimoya Ltd.) -- C:\Windows\System32\drivers\cherimoya.sys [61336] {1121B348573C1CA1DF257D517183A16A9C79} =>PUP.Optional.Shopperz
O58 - SDL:2009/07/14 02:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [17488] =>.Microsoft Windows®
O58 - SDL:2014/06/25 17:12:05 A . (.Disc Soft Ltd - DAEMON Tools Virtual Bus Driver.) -- C:\Windows\System32\drivers\dtsoftbus01.sys [283064] =>.Disc Soft Ltd®
O58 - SDL:2009/06/10 21:35:09 A . (.Intel Corporation - Intel(R) PRO/1000 Adapter NDIS 6 deserializ.) -- C:\Windows\System32\drivers\E1G6032E.sys [145792] ©
O58 - SDL:2009/07/14 02:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [530496] =>.Microsoft Windows®
O58 - SDL:2012/02/03 19:23:56 A . (.Etron Technology Inc - Etron eXtensible Hub Driver..) -- C:\Windows\System32\drivers\EtronHub3.sys [59520] ©
O58 - SDL:2012/02/03 19:23:56 A . (.Etron Technology Inc - Etron eXtensible Host Controller Driver..) -- C:\Windows\System32\drivers\EtronXHCI.sys [84736] ©
O58 - SDL:2009/06/10 21:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3286016] ©
O58 - SDL:2012/08/21 12:01:20 A . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\System32\drivers\GEARAspiWDM.sys [33240] =>.GEAR Software Inc.®
O58 - SDL:2015/01/14 11:32:32 AH . (.LogMeIn, Inc. - Hamachi Virtual Network Interface Driver.) -- C:\Windows\System32\drivers\hamachi.sys [33856] {0FC50C0152AB6D162B832AC3528B10F1} ©
O58 - SDL:2009/06/10 21:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [31232] ©
O58 - SDL:2012/07/17 18:12:08 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\drivers\HECIx64.sys [62784] =>.Intel Corporation®
O58 - SDL:2010/11/21 04:23:47 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [78720] =>.Microsoft Windows®
O58 - SDL:2010/11/21 04:23:47 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [410496] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [44112] =>.Microsoft Windows®
O58 - SDL:2012/05/20 17:25:32 A . (.Intel Corporation - Intel(R) USB 3.0 Host Controller Switch Dri.) -- C:\Windows\System32\drivers\iusb3hcs.sys [19264] =>.Intel Corporation®
O58 - SDL:2012/05/20 17:25:32 A . (.Intel Corporation - Intel(R) USB 3.0 Hub Driver.) -- C:\Windows\System32\drivers\iusb3hub.sys [357184] =>.Intel Corporation®
O58 - SDL:2012/05/20 17:25:32 A . (.Intel Corporation - Intel(R) USB 3.0 eXtensible Host Controller.) -- C:\Windows\System32\drivers\iusb3xhc.sys [789824] =>.Intel Corporation®
O58 - SDL:2012/04/25 08:07:18 A . (.Qualcomm Atheros Co., Ltd. - Qualcomm Atheros Ar81xx series PCI-E Gigabi.) -- C:\Windows\System32\drivers\L1C62x64.sys [104560] {709771C02A395029A68C5FBDB0E867FD} ©
O58 - SDL:2009/07/14 02:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [114752] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [106560] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [65600] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [115776] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [35392] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [284736] =>.Microsoft Windows®
O58 - SDL:2014/08/08 18:12:14 A . (.NetFilterSDK.com - NetFilter SDK TDI Hook Driver (WPP).) -- C:\Windows\System32\drivers\netfilter2.sys [60160] {787B156DBE2C603B1C32E7122CF5A030}
O58 - SDL:2009/07/14 02:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [51264] =>.Microsoft Windows®
O58 - SDL:2010/11/21 04:23:47 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [148352] =>.Microsoft Windows®
O58 - SDL:2010/11/21 04:23:47 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [166272] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1524816] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [128592] =>.Microsoft Windows®
O58 - SDL:2009/06/10 21:35:42 A . (.Realtek Corporation - Realtek 8101E/8168/8169 NDIS 6.20 64-bit Dr.) -- C:\Windows\System32\drivers\Rt64win7.sys [187392] ©
O58 - SDL:2009/06/10 21:35:46 A . (.Realtek Semiconductor Corporation - Realtek RTL8187B NDIS Driver.) -- C:\Windows\System32\drivers\RTL8187B.sys [416768] ©
O58 - SDL:2014/12/30 10:35:54 A . (.Razer Inc - Razer RzEndPt.) -- C:\Windows\System32\drivers\rzendpt.sys [39592] =>.Razer Inc.®
O58 - SDL:2014/05/23 11:34:46 A . (.Windows (R) Win 7 DDK provider - Maelstrom VAD Audio driver.) -- C:\Windows\System32\drivers\RzMaelstromVAD.sys [32768] ©
O58 - SDL:2015/01/31 01:08:58 A . (.Razer, Inc. - Razer Overlay Support.) -- C:\Windows\System32\drivers\rzpmgrk.sys [37184] =>.Razer Inc.®
O58 - SDL:2014/12/10 21:43:07 A . (.Razer, Inc. - Razer Overlay Support.) -- C:\Windows\System32\drivers\rzpnk.sys [129600] =>.Razer Inc.®
O58 - SDL:2014/12/30 10:35:54 A . (.Razer Inc - Razer Rzudd Engine.) -- C:\Windows\System32\drivers\rzudd.sys [177832] =>.Razer Inc.®
O58 - SDL:2009/06/10 21:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] ©
O58 - SDL:2009/07/14 01:00:40 A . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\drivers\serial.sys [94208] ©
O58 - SDL:2009/07/14 02:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [43584] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [80464] =>.Microsoft Windows®
O58 - SDL:2011/05/13 03:21:04 A . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\Windows\System32\drivers\ssadwh.sys [13800] ©
O58 - SDL:2015/05/21 07:02:42 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ve.) -- C:\Windows\System32\drivers\ssudbus.sys [110720] =>.DEVGURU CO LTD®
O58 - SDL:2015/05/21 07:02:42 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ve.) -- C:\Windows\System32\drivers\ssudmdm.sys [206080] =>.DEVGURU CO LTD®
O58 - SDL:2009/07/14 02:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [24656] =>.Microsoft Windows®
O58 - SDL:2014/08/08 18:12:10 A . (.Spotflux, Inc. - Spotflux Network Device Driver.) -- C:\Windows\System32\drivers\tapSF0901.sys [39104] {787B156DBE2C603B1C32E7122CF5A030}
O58 - SDL:2012/12/13 12:50:36 A . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\drivers\usbaapl64.sys [54784] ©
O58 - SDL:2015/11/10 17:56:50 A . (.Oracle Corporation - VirtualBox Support Driver.) -- C:\Windows\System32\drivers\VBoxDrv.sys [964928] {51CA009816FDBD80F120E015EE75823E} ©
O58 - SDL:2015/11/10 17:56:22 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Lightweight Filter Driv.) -- C:\Windows\System32\drivers\VBoxNetLwf.sys [194976] {51CA009816FDBD80F120E015EE75823E} ©
O58 - SDL:2015/11/10 17:56:20 A . (.Oracle Corporation - VirtualBox USB Monitor Driver.) -- C:\Windows\System32\drivers\VBoxUSBMon.sys [138904] {51CA009816FDBD80F120E015EE75823E} ©
O58 - SDL:2009/07/14 02:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [17488] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [161872] =>.Microsoft Windows®
O58 - SDL:2009/03/18 17:35:42 AH . (.LogMeIn, Inc. - Hamachi Virtual Network Interface Driver.) -- C:\Windows\System32\hamachi.sys [33856] {0FC50C0152AB6D162B832AC3528B10F1} ©

---\\ Derniers fichiers modifiés ou crées (Utilisateur) (48) - 37s
O61 - LFC: 2015/12/08 22:36:33 A . (.Nicolas Coolman.) -- C:\Users\Alexis\ZHPCleaner.exe [291648] ©
O61 - LFC: 2015/12/06 17:25:36 A . (..) -- C:\Users\Alexis\Downloads\android_root_other-68856381.exe [291648] {67AFE4FB2458A37CFEBA2D43EC2594B2}
O61 - LFC: 2015/12/06 17:29:49 A . (.Kingosoft Technology Ltd..) -- C:\Users\Alexis\Downloads\android_root_other.exe [291648] {4BA0711A8EBE6D481E1846163BA3D2FD} ©
O61 - LFC: 2015/12/07 00:51:21 A . (.MEGA Limited.) -- C:\Users\Alexis\Downloads\MEGAsyncSetup(1).exe [291648] {11212775AC8BD188EC962027044A8529D2BF} ©
O61 - LFC: 2015/12/06 19:53:36 A . (.MEGA Limited.) -- C:\Users\Alexis\Downloads\MEGAsyncSetup.exe [291648] {11212775AC8BD188EC962027044A8529D2BF} ©
O61 - LFC: 2015/12/07 00:55:36 N . (..) -- C:\Users\Alexis\Downloads\SRSRoot.exe [291648]
O61 - LFC: 2015/12/08 22:35:46 A . (.Nicolas Coolman.) -- C:\Users\Alexis\Downloads\ZHPCleaner.exe [291648] ©
O61 - LFC: 2015/12/08 22:32:39 A . (.Copyright (C) 2015 Nicolas Coolman.) -- C:\Users\Alexis\Downloads\ZHPDiag3.exe [291648] ©
O61 - LFC: 2015/12/07 11:34:22 A . (..) -- C:\Users\Alexis\Desktop\File2.exe [291648]
O61 - LFC: 2015/12/07 18:40:34 A . (..) -- C:\Users\Alexis\AppData\Roaming\moses.exe [291648]
O61 - LFC: 2015/12/08 22:36:33 A . (.Nicolas Coolman.) -- C:\Users\Alexis\AppData\Roaming\ZHP\ZHPCleaner.exe [291648] ©
O61 - LFC: 2015/12/08 22:32:39 A . (.Copyright (C) 2015 Nicolas Coolman.) -- C:\Users\Alexis\AppData\Roaming\ZHP\ZHPDiag3.exe [291648] ©
O61 - LFC: 2015/12/08 19:19:35 A . (..) -- C:\Users\Alexis\AppData\Roaming\OpenCandy\34B2AA63A5384F389CDE46C223899B62\setup.exe [291648] {785165B82B596AA4788FFE2543F5E3A3} =>PUP.Optional.OpenCandy
O61 - LFC: 2015/12/07 16:19:48 A . (..) -- C:\Users\Alexis\AppData\Roaming\NivriWaickyr\Wilnifg.exe [291648] {01}
O61 - LFC: 2015/12/07 11:34:23 A . (..) -- C:\Users\Alexis\AppData\Roaming\mgyun\cache2.bin [291648]
O61 - LFC: 2015/12/07 11:34:37 A . (..) -- C:\Users\Alexis\AppData\Roaming\mgyun\cache3.bin [291648]
O61 - LFC: 2015/12/07 18:37:30 A . (..) -- C:\Users\Alexis\AppData\Roaming\GytjeOibyirn\Todno.exe [291648] {01}
O61 - LFC: 2015/12/07 11:31:42 A . (..) -- C:\Users\Alexis\AppData\Local\Labsoltax.exe [291648]
O61 - LFC: 2015/12/07 19:36:12 A . (.SoftBrain Technologies Ltd..) -- C:\Users\Alexis\AppData\Local\SmartWeb\__u.exe [291648] =>PUP.Optional.SmartWebSearch
O61 - LFC: 2015/12/03 00:47:18 A . (.Copyright © 2015.) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\MalwareProtectionClient.exe [291648] {0DB13F364982158C0E6000F666CC2AA4} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/06 17:29:58 A . (..) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\uninstall.exe [291648] =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/07 11:34:48 A . (.Install helper Team.) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\dhk788-3a9a96c7-8f69-4647-9872-16437b5b16de.exe [291648] {61F716E4410768DA5306101E504DEBAA} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/07 11:34:48 A . (.Install helper Team.) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\dhk788-707685b8-9510-4ff3-8d9b-66c5b2ace5e1.exe [291648] {61F716E4410768DA5306101E504DEBAA} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/07 11:34:48 A . (.Install helper Team.) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\dhk788-d46d40c8-5a1f-462b-8fc5-0efe407a4b6c.exe [291648] {61F716E4410768DA5306101E504DEBAA} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/08 20:56:10 A . (.Install helper Team.) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\dhk806-038de6af-266b-4db6-9bce-467e8e47e7f9.exe [291648] {61F716E4410768DA5306101E504DEBAA} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/08 19:19:35 A . (.Install helper Team.) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\dhk806-199137ac-027c-4333-baab-cae18c999c04.exe [291648] {61F716E4410768DA5306101E504DEBAA} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/08 19:19:35 A . (.Install helper Team.) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\dhk806-2fccb677-dd11-496c-bfa7-f0a17884f442.exe [291648] {61F716E4410768DA5306101E504DEBAA} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/08 20:56:09 A . (.Install helper Team.) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\dhk806-9e143978-55e7-4b1a-93f8-686f3932e040.exe [291648] {61F716E4410768DA5306101E504DEBAA} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/08 20:56:10 A . (.Install helper Team.) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\dhk806-fb65f2c4-9535-4cf0-931e-162f077786f5.exe [291648] {61F716E4410768DA5306101E504DEBAA} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/06 20:26:21 A . (..) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\Plugin-1be8e3fe-7dc0-49d5-b23e-2052f8907396.exe [291648] {58FC58A52C291B337067DC6AA50B8FB3} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/06 18:26:22 A . (..) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\Plugin-1f547a07-0ceb-45b3-8d0f-e4def2e0649f.exe [291648] {58FC58A52C291B337067DC6AA50B8FB3} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/06 18:26:21 A . (..) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\Plugin-7efed5dd-539c-4e72-9ca6-78a2a26aa312.exe [291648] {58FC58A52C291B337067DC6AA50B8FB3} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/06 18:26:23 A . (..) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\Plugin-804581a9-2808-4904-bdba-b2e1a8e202f6.exe [291648] {58FC58A52C291B337067DC6AA50B8FB3} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/06 18:26:21 A . (..) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\Plugin-bbe34a65-25a8-45a3-8edb-74fe73cad706.exe [291648] {58FC58A52C291B337067DC6AA50B8FB3} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/06 20:26:21 A . (..) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\Plugin-df048cc4-12d2-4af3-92a1-fb80db26b245.exe [291648] {58FC58A52C291B337067DC6AA50B8FB3} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/06 20:26:21 A . (..) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\Plugin-e0d53720-fcb2-4e63-9a02-b9410494df97.exe [291648] {58FC58A52C291B337067DC6AA50B8FB3} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/06 20:26:21 A . (..) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\Plugin-e4ecbe96-ee3f-4a16-94c8-25c0957ade02.exe [291648] {58FC58A52C291B337067DC6AA50B8FB3} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/06 21:26:23 A . (..) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\PluginContainer-a8477e14-c262-47a1-b087-f92bcab8ffc2.exe [291648] {58FC58A52C291B337067DC6AA50B8FB3} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/07 10:26:22 A . (..) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\PluginContainer-b7bb3717-0d9f-40f5-9520-0a117e442387.exe [291648] {58FC58A52C291B337067DC6AA50B8FB3} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/07 01:26:22 A . (..) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\PluginContainer-fef9969e-6be4-4057-a284-4e13e2dacf25.exe [291648] {58FC58A52C291B337067DC6AA50B8FB3} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/06 18:21:20 A . (..) -- C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\updater-474f52e6-893e-4734-81ac-8e3f554bf11a.exe [291648] {58FC58A52C291B337067DC6AA50B8FB3} =>.Superfluous.MalwareProtection
O61 - LFC: 2015/12/07 11:38:16 A . (.Copyright (C) 2014.) -- C:\Users\Alexis\AppData\Local\Installer\Install_26144\YTDownloader.exe [291648] =>PUP.Optional.YTDownloader
O61 - LFC: 2015/12/02 23:43:38 A . (..) -- C:\Users\Alexis\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [291648]
O61 - LFC: 2015/12/07 13:05:38 A . (..) -- C:\Users\Alexis\AppData\Local\gmsd_fr_005010169\upgmsd_fr_005010169.exe [291648] {1121659F89D645B84A6361DBAB1CE36D6315} =>PUP.Optional.CrossRider
O61 - LFC: 2015/12/08 20:19:48 A . (..) -- C:\Users\Alexis\AppData\Local\gmsd_fr_005010169\Download\myoffergroup_fr.exe [291648] =>PUP.Optional.CrossRider
O61 - LFC: 2015/12/04 11:07:32 A . (..) -- C:\Users\Alexis\AppData\Local\032B0290-1449487728-0559-0306-940700080009\pnsrBCC6.exe [291648]
O61 - LFC: 2015/12/07 11:28:48 A . (..) -- C:\Users\Alexis\AppData\Local\032B0290-1449487728-0559-0306-940700080009\rnsrBCC4.exe [291648]
O61 - LFC: 2015/12/07 11:28:48 A . (..) -- C:\Users\Alexis\AppData\Local\032B0290-1449487728-0559-0306-940700080009\Uninstall.exe [291648]

---\\ Associations Shell Spawning (11) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe ©
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe ©
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe ©
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe ©
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.8pecxstudios - Cyberfox.) -- D:\Program Files (x86)\Cyberfox\Cyberfox.exe {275F7B4841402DE0F41C8CCF30795AC2} ©

---\\ Menu de démarrage Internet (20) - 2s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Users\Alexis\AppData\Local\BoBrowser\Application\bobrowser.exe =>PUP.Optional.BoBrowser
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.8pecxstudios - Cyberfox.) -- D:\Program Files (x86)\Cyberfox\Cyberfox.exe http://www.piesearch.com/ =>PUP.Optional.PieSearch
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://www.piesearch.com/ =>PUP.Optional.PieSearch
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.piesearch.com/ =>PUP.Optional.PieSearch
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files (x86)\Internet Explorer\iexplore.ex http://www.yoursearching.com/ =>PUP.Optional.YourSearching
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Users\Alexis\AppData\Local\BoBrowser\Application\bobrowser.exe (.not file.) =>PUP.Optional.BoBrowser
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.8pecxstudios - Cyberfox Helper.) -- D:\Program Files (x86)\Cyberfox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - 'Firefox' Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Users\Alexis\AppData\Local\BoBrowser\Application\bobrowser.exe (.not file.) =>PUP.Optional.BoBrowser
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.8pecxstudios - Cyberfox Helper.) -- D:\Program Files (x86)\Cyberfox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - 'Firefox' Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Users\Alexis\AppData\Local\BoBrowser\Application\bobrowser.exe (.not file.) =>PUP.Optional.BoBrowser
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.8pecxstudios - Cyberfox Helper.) -- D:\Program Files (x86)\Cyberfox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - 'Firefox' Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©

---\\ Recherche d'infection sur les navigateurs (19) - 7s
O69 - SBI: prefs.js [Alexis - 8i3qsk17.default] user_pref("browser.search.defaultenginename", "webssearches"); =>PUP.Optional.WebsSearches
O69 - SBI: prefs.js [Alexis - 8i3qsk17.default] user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine"); =>PUP.Optional.SearchEngine
O69 - SBI: prefs.js [Alexis - 8i3qsk17.default] user_pref("browser.search.searchengine.ptid", "cmi"); =>PUP.Optional.SearchEngine
O69 - SBI: prefs.js [Alexis - 8i3qsk17.default] user_pref("browser.search.searchengine.uid", "WDCXWD3200AAJS-00B4A0_WD-WMAT1032030320303"); =>PUP.Optional.SearchEngine
O69 - SBI: prefs.js [Alexis - 8i3qsk17.default] user_pref("browser.search.selectedEngine", "webssearches"); =>PUP.Optional.WebsSearches
O69 - SBI: prefs.js [Alexis - 8i3qsk17.default] user_pref("browser.startup.homepage", "C:\\ProgramData\\Zitenops\\ff.HP"); =>PUP.Optional.Salus
O69 - SBI: prefs.js [Alexis - 8i3qsk17.default] user_pref("extensions.enabledAddons", "yahooprotected%40gmail.com:1.0.1.1042,deskCutv2%40gmail.com:0.1.12,%7B972ce4c6-7e08-4474-a2[...] =>PUP.Optional.DeskCut
O69 - SBI: prefs.js [Alexis - 8i3qsk17.default] user_pref("extensions.quick_start.enable_search1", false); =>PUP.Optional.QuickStart
O69 - SBI: prefs.js [Alexis - 8i3qsk17.default] user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false); =>PUP.Optional.QuickStart
O69 - SBI: prefs.js [Alexis - 8i3qsk17.default] user_pref("extensions.xpiState", "{\"app-profile\":{\"deskCutv2@gmail.com\":{\"d\":\"C:\\\\Users\\\\Alexis\\\\AppData\\\\Roaming\\[...] =>PUP.Optional.DeskCut
O69 - SBI: prefs.js [Alexis - 8i3qsk17.default] user_pref("keyword.URL", "http://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQsNBwlCRAUSbQAIUgFcFQYXcBQAVlwQDAZAIwAAAg1JR[...] =>PUP.Optional.Browser
O69 - SBI: SearchScopes [HKCU] OldSearch - (Bing) - http://www.bing.com/
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com/
O69 - SBI: SearchScopes [HKCU] {2B242C78-B2B9-4B13-9C1F-ED589474B5BC} - (Yahoo Search!) - http://search.yahoo.com/
O69 - SBI: SearchScopes [HKCU] {74BB5483-E6D3-4F34-8932-567807084D2E} - (Bing) - http://www.bing.com/
O69 - SBI: SearchScopes [HKCU] {B37A3067-8B54-4980-88AA-C660C8CCE4E8} [DefaultScope] - (Default) - http://searchinterneat-a.akamaihd.net/
O69 - SBI: SearchScopes [HKCU] {ielnksrch} - (Search the web) - http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_ByKo5GOPu13rXw155J4OB8oo3_nrI_YPbYytCFQMvqrv5QNdU0j2sjSZdooisThXcRcgUYaWyOaN5DqDcBztEVk9yo_oPLzoVXEITJg-jALxK8Sgq8x5MlsDgTSRv4sWri8h3dyAuTNqLEoIvqh8EJS0eB78f&q={searchTerms}
O69 - SBI: SearchScopes [HKUS\.DEFAULT] {006ee092-9658-4fd6-bd8e-a21a348e59f5} - (Web Search) - http://feed.snapdo.com/
O69 - SBI: SearchScopes [HKUS\S-1-5-18] {006ee092-9658-4fd6-bd8e-a21a348e59f5} - (Web Search) - http://feed.snapdo.com/

---\\ Enumère les fichiers Crack & Keygen (3) - 13s
O82 - LFC: 2014/11/24 21:34:14 A . (...) -- C:\Users\Alexis\Downloads\Windows Loader 2.2.2.zip [291648] =>.Crack,Keygen
O82 - LFC: 2014/11/24 21:28:58 A . (...) -- C:\Users\Alexis\Downloads\Windows Loader 2.2.2__8173_il6 (2).exe [291648] =>.Crack,Keygen
O82 - LFC: 2014/04/28 21:31:50 A . (...) -- C:\Users\Alexis\Desktop\CRACKHACK\Windows Loader.exe [291648] =>.Crack,Keygen

---\\ Enumère les services démarrés par Svchost (33) - 3s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [72192] ©
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [80384] ©
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [80384] ©
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\system32\srvsvc.dll [236032] ©
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [777728] ©
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [853504] ©
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [679424] ©
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [99328] ©
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [344064] ©
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [97792] ©
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [64512] ©
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [359424] ©
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [316928] ©
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du se.) -- C:\Windows\System32\termsrv.dll [680960] ©
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\system32\wuaueng.dll [2477536] =>.Microsoft Windows Component Publisher®
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [849920] ©
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [370688] ©
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [569344] ©
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\system32\seclogon.dll [30720] ©
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [70656] ©
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\system32\iscsiexe.dll [156672] ©
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\system32\mmcss.dll [67584] ©
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [242688] ©
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [121856] ©
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [136192] ©
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [111104] ©
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\system32\schedsvc.dll [1110016] ©
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\system32\kmsvc.dll [90624] ©
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84480] ©
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [209920] ©
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\system32\themeservice.dll [44544] ©
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [100864] ©
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [193536] ©

---\\ Liste des exceptions du parefeu Windows (47) - 9s
O87 - FAEL: "TCP Query User{49B5280C-A8E4-43A4-9A82-0BB7855390D8}C:\users\alexis\appdata\roaming\cacaoweb\cacaoweb.exe" [In-None-P6-TRUE] .(...) -- C:\users\alexis\appdata\roaming\cacaoweb\cacaoweb.exe (.not file.) =>.Superfluous.CacaoWeb
O87 - FAEL: "UDP Query User{31C68931-48F1-4C3A-A65D-4B718AE992AB}C:\users\alexis\appdata\roaming\cacaoweb\cacaoweb.exe" [In-None-P17-TRUE] .(...) -- C:\users\alexis\appdata\roaming\cacaoweb\cacaoweb.exe (.not file.) =>.Superfluous.CacaoWeb
O87 - FAEL: "{670002F7-6A24-46D6-9E96-75E41325BB2B}" [In-None-P6-TRUE] .(.Copyright (C) 2007-2011, Pando Networks Inc. - Pando Media Booster.) -- C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe {69FD587152CFDDF516423156E752D014}
O87 - FAEL: "{2BCD1A05-231A-4144-8D45-6B132E7EBD2F}" [In-None-P17-TRUE] .(.Copyright (C) 2007-2011, Pando Networks Inc. - Pando Media Booster.) -- C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe {69FD587152CFDDF516423156E752D014}
O87 - FAEL: "{E5AF1923-2456-4DED-B92C-DE4EB7AB253C}" [In-None-P6-TRUE] .(.Copyright (C) 2007-2011, Pando Networks Inc. - Pando Media Booster.) -- C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe {69FD587152CFDDF516423156E752D014}
O87 - FAEL: "{A4B9719D-0F33-4B58-A0A2-23F05DBA0EE3}" [In-None-P17-TRUE] .(.Copyright (C) 2007-2011, Pando Networks Inc. - Pando Media Booster.) -- C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe {69FD587152CFDDF516423156E752D014}
O87 - FAEL: "{0A7F66E5-3209-449D-913B-467BE2D7B968}" [In-None-P17-TRUE] .(.Copyright (C) 2007-2011, Pando Networks Inc. - Pando Media Booster.) -- C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe {69FD587152CFDDF516423156E752D014}
O87 - FAEL: "{0685F73F-F61A-4A20-9235-B6A5E9218647}" [In-None-P6-TRUE] .(...) -- D:\Program Files (x86)\StarCraft II\StarCraft II Public Test.exe (.not file.)
O87 - FAEL: "{09990D12-76BA-4EC7-9AD5-3B8DDE868B83}" [In-None-P17-TRUE] .(...) -- D:\Program Files (x86)\StarCraft II\StarCraft II Public Test.exe (.not file.)
O87 - FAEL: "{72995A1F-A14D-40D5-8DB0-FC880C794076}" [In-None-P6-TRUE] .(.Taleworlds Entertainment - Mount&Blade: Warband.) -- D:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe ©
O87 - FAEL: "{7B4ED46A-EFEF-465A-A198-EF6C43EA8696}" [In-None-P17-TRUE] .(.Taleworlds Entertainment - Mount&Blade: Warband.) -- D:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe ©
O87 - FAEL: "{1A0E63C2-6811-4D1F-8B51-9F6533D34ACE}" [In-None-P6-TRUE] .(...) -- D:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
O87 - FAEL: "{50245DAC-284B-42D4-885E-6CE2B7361A43}" [In-None-P17-TRUE] .(...) -- D:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
O87 - FAEL: "TCP Query User{358AA87B-A09C-4F35-917F-40E1D02FA63F}C:\users\alexis\appdata\roaming\cacaoweb\cacaoweb.exe" [In-None-P6-TRUE] .(...) -- C:\users\alexis\appdata\roaming\cacaoweb\cacaoweb.exe (.not file.) =>.Superfluous.CacaoWeb
O87 - FAEL: "UDP Query User{0B59EE0B-39B5-4780-8B3B-56484F8D5D2B}C:\users\alexis\appdata\roaming\cacaoweb\cacaoweb.exe" [In-None-P17-TRUE] .(...) -- C:\users\alexis\appdata\roaming\cacaoweb\cacaoweb.exe (.not file.) =>.Superfluous.CacaoWeb
O87 - FAEL: "TCP Query User{6422AA8E-E348-4504-A2F9-DB7B37DD02EA}D:\program files (x86)\steam\steamapps\common\war thunder\aces.exe" [In-None-P6-TRUE] .(...) -- D:\program files (x86)\steam\steamapps\common\war thunder\aces.exe
O87 - FAEL: "UDP Query User{74ECAB2D-A71A-4FE0-B741-A52C639BD0FD}D:\program files (x86)\steam\steamapps\common\war thunder\aces.exe" [In-None-P17-TRUE] .(...) -- D:\program files (x86)\steam\steamapps\common\war thunder\aces.exe
O87 - FAEL: "{F2185804-D974-4D92-AE1B-184A7B37F41E}" [In-None-P6-TRUE] .(...) -- C:\Users\Alexis\AppData\Roaming\uTorrent\uTorrent.exe (.not file.)
O87 - FAEL: "{7CFECBD8-3907-4691-BEAF-0D4ADC91F146}" [In-None-P17-TRUE] .(...) -- C:\Users\Alexis\AppData\Roaming\uTorrent\uTorrent.exe (.not file.)
O87 - FAEL: "TCP Query User{AA9C8D9A-DDD3-4D3E-B4FD-691F2CA2AAC8}C:\program files (x86)\maniaplanet\maniaplanet.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\maniaplanet\maniaplanet.exe (.not file.)
O87 - FAEL: "UDP Query User{14AC968B-4484-4CD2-AB12-EEC7BCCAB1C9}C:\program files (x86)\maniaplanet\maniaplanet.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\maniaplanet\maniaplanet.exe (.not file.)
O87 - FAEL: "TCP Query User{6026335B-ABCB-4D75-85D6-86637690C871}C:\program files (x86)\gameforgelive\games\fra_fra\aion\nclauncher.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\gameforgelive\games\fra_fra\aion\nclauncher.exe (.not file.)
O87 - FAEL: "UDP Query User{0EADC98B-D0E1-4792-9BEA-AC9C17EAE53A}C:\program files (x86)\gameforgelive\games\fra_fra\aion\nclauncher.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\gameforgelive\games\fra_fra\aion\nclauncher.exe (.not file.)
O87 - FAEL: "{BB9F2486-FF24-41B1-BF92-F3B44B9D7113}" [In-None-P6-TRUE] .(...) -- C:\Users\Alexis\AppData\Roaming\uTorrent\uTorrent.exe (.not file.)
O87 - FAEL: "{D23B2DD5-660E-4BFC-A50A-5C50B4BA107D}" [In-None-P17-TRUE] .(...) -- C:\Users\Alexis\AppData\Roaming\uTorrent\uTorrent.exe (.not file.)
O87 - FAEL: "{09E3D1ED-D5ED-417B-93CC-55F2D852735E}" [In-None-P6-TRUE] .(...) -- D:\Program Files (x86)\Steam\SteamApps\common\Rust\Rust.exe {008E759F39278718B7}
O87 - FAEL: "{2DCAD100-E5C2-49C3-BF95-7DA2E149F370}" [In-None-P17-TRUE] .(...) -- D:\Program Files (x86)\Steam\SteamApps\common\Rust\Rust.exe {008E759F39278718B7}
O87 - FAEL: "{29E3EB95-5C38-4632-84F4-E784A4A3CCBC}" [In-None-P6-TRUE] .(.BattlEye Innovations - BattlEye Launcher.) -- D:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ_BE.exe {42BE0082B9A0C36589A976D4B4F924BA} ©
O87 - FAEL: "{88ED4924-BF2D-4340-9E57-DC49AEB2BC45}" [In-None-P17-TRUE] .(.BattlEye Innovations - BattlEye Launcher.) -- D:\Program Files (x86)\Steam\SteamApps\common\DayZ\DayZ_BE.exe {42BE0082B9A0C36589A976D4B4F924BA} ©
O87 - FAEL: "{B626E68A-A5B9-4210-9406-F2B1467273E6}" [In-None-P6-TRUE] .(.Curse - Curse Client.) -- C:\Users\Alexis\AppData\Local\Apps\2.0\008PB8MC.NLP\EL4WWZB4.8T0\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\CurseClient.exe ©
O87 - FAEL: "{0D2B8924-E900-4227-8E71-69C185198F6D}" [In-None-P17-TRUE] .(.Curse - Curse Client.) -- C:\Users\Alexis\AppData\Local\Apps\2.0\008PB8MC.NLP\EL4WWZB4.8T0\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\CurseClient.exe ©
O87 - FAEL: "{67C447AB-4AF9-4CBC-81F6-A0D58702722A}" [In-None-P6-TRUE] .(...) -- D:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe (.not file.)
O87 - FAEL: "{7390D6E6-A7D0-41C9-8A93-BD5BD853CB99}" [In-None-P17-TRUE] .(...) -- D:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe (.not file.)
O87 - FAEL: "{6F1A494B-95EE-48BC-80A8-4051D8F0D628}" [In-None-P6-TRUE] .(.Curse - Curse Client.) -- C:\Users\Alexis\AppData\Local\Apps\2.0\008PB8MC.NLP\EL4WWZB4.8T0\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\CurseClient.exe ©
O87 - FAEL: "{D6845F73-5C54-4BE3-A5E8-3912ACBA8F6F}" [In-None-P17-TRUE] .(.Curse - Curse Client.) -- C:\Users\Alexis\AppData\Local\Apps\2.0\008PB8MC.NLP\EL4WWZB4.8T0\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\CurseClient.exe ©
O87 - FAEL: "{E840A0EA-C418-456F-BBDC-3EEFC3840B31}" [In-None-P6-TRUE] .(...) -- C:\Windows\SysWOW64\PnkBstrA.exe (.not file.)
O87 - FAEL: "{AA76ED8F-BB41-4B71-A4D8-0CA4B519ADF5}" [In-None-P17-TRUE] .(...) -- C:\Windows\SysWOW64\PnkBstrA.exe (.not file.)
O87 - FAEL: "{F1889BBD-55EB-4C5A-82B1-A33DAFE5BF48}" [In-None-P6-TRUE] .(...) -- C:\Windows\SysWOW64\PnkBstrB.exe (.not file.)
O87 - FAEL: "{134503F8-8E07-47ED-870C-D84D2BAC4224}" [In-None-P17-TRUE] .(...) -- C:\Windows\SysWOW64\PnkBstrB.exe (.not file.)
O87 - FAEL: "{F84F2254-412D-4035-9FEE-65D51C506EDF}" [In-None-P6-TRUE] .(.EA Digital Illusions CE AB - Battlefield 3™.) -- D:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe {0C618E5C55725B09158B62149C425BA5} ©
O87 - FAEL: "{C7A8C4E9-265F-4FF3-ADCE-7730CCB6EA0C}" [In-None-P17-TRUE] .(.EA Digital Illusions CE AB - Battlefield 3™.) -- D:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe {0C618E5C55725B09158B62149C425BA5} ©
O87 - FAEL: "{AA357A31-535A-4C15-84AF-3647553D0DEF}" [In-None-P6-TRUE] .(...) -- D:\Program Files (x86)\Steam\SteamApps\common\Clicker Heroes\Clicker Heroes.exe
O87 - FAEL: "{3A914261-9B79-4186-B019-A5A8D635A287}" [In-None-P17-TRUE] .(...) -- D:\Program Files (x86)\Steam\SteamApps\common\Clicker Heroes\Clicker Heroes.exe
O87 - FAEL: "{4EB032EA-499B-4F15-B56A-6F9FDED70BE9}" [In-None-P6-TRUE] .(...) -- D:\Program Files (x86)\Steam\SteamApps\common\Warface\live\nw.exe {0AEBA8669460A2A96F4D6F3A2E13E864}
O87 - FAEL: "{89263BE6-F6CB-43B0-9478-1901D71A2A50}" [In-None-P17-TRUE] .(...) -- D:\Program Files (x86)\Steam\SteamApps\common\Warface\live\nw.exe {0AEBA8669460A2A96F4D6F3A2E13E864}
O87 - FAEL: "{DD9B4BFC-54AF-4950-8021-7A796334AE87}" [In-None-P6-TRUE] .(...) -- C:\Users\Alexis\Downloads\android_root_other-68856381.exe {67AFE4FB2458A37CFEBA2D43EC2594B2}
O87 - FAEL: "{884D785F-EE6C-4017-9730-4BDAB7244CA4}" [In-None-P17-TRUE] .(...) -- C:\Users\Alexis\Downloads\android_root_other-68856381.exe {67AFE4FB2458A37CFEBA2D43EC2594B2}

---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (34) - 9s

SS - Demand [11/11/2015] [ 291648] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated®
SR - Auto [07/12/2015] [ 291648] Airtop (Airtop) . (...) - C:\ProgramData\Airtop\Airtop.exe =>PUP.Optional.Salus
SR - Auto [0] [ 291648] (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe ©
SR - Auto [02/09/2015] [ 291648] Apple Mobile Device Service (Apple Mobile Device Service) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe =>.Apple Inc.®
SR - Auto [07/12/2015] [ 291648] ApplicationHosting (ApplicationHosting) . (...) - C:\ProgramData\ApplicationHosting\ApplicationHosting.exe =>PUP.Optional.ApplicationHosting
SS - Demand [14/06/2014] [ 291648] BattlEye Service (BEService) . (...) - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
SR - Auto [12/08/2015] [ 291648] Service Bonjour (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.®
SS - Auto [22/11/2015] [ 291648] Service Mise à jour Dropbox (dbupdate) (dbupdate) . (.Dropbox, Inc..) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe {0C89CBE063927780186EC0063F10D323} ©
SS - Demand [22/11/2015] [ 291648] Service Mise à jour Dropbox (dbupdatem) (dbupdatem) . (.Dropbox, Inc..) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe {0C89CBE063927780186EC0063F10D323} ©
SS - Auto [07/12/2015] [ 291648] Touchla (doonioaduuaate) . (...) - C:\Users\Alexis\AppData\Local\Labsoltax.exe
SR - Auto [12/11/2015] [ 291648] Dripkix Service (Dripkix) . (.Copyright © 2015.) - C:\Program Files\Dripkix\Dripkix.exe =>PUP.Optional.Amonetize
SR - Auto [05/08/2015] [ 291648] FastCompress (FastCompress) . (.Adlegend Media.) - C:\Program Files (x86)\FastCompress-Zip\Fast_Support.exe {11210D7D7D1C16D9150B69F8767D7C855E19} ©
SR - Auto [07/12/2015] [ 291648] Desktop Upload (ginoquci) . (...) - C:\Users\Alexis\AppData\Local\Temp\nsb8202.tmp
SR - Auto [08/12/2015] [ 291648] Rename Outline (gufutoqu) . (...) - C:\Program Files (x86)\032B0290-1449484090-0559-0306-940700080009\knsjC532.tmp =>PUP.Optional.CrossRider
SS - Auto [28/10/2015] [ 291648] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [28/10/2015] [ 291648] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [30/08/2011] [ 291648] Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe ©
SS - Demand [04/04/2005] [ 291648] InstallDriver Table Manager (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe ©
SR - Demand [23/09/2015] [ 291648] Service de l’iPod (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe =>.Apple Inc.®
SR - Auto [15/10/2014] [ 291648] Ma-Config Agent (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe =>.Cybelsoft®
SS - Demand [06/11/2015] [ 291648] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation®
SR - Auto [07/12/2015] [ 291648] Add Telephone Line (nyneryxo) . (...) - C:\Program Files (x86)\032B0290-1449484090-0559-0306-940700080009\hnsg5CE7.tmp =>PUP.Optional.CrossRider
SS - Demand [26/10/2015] [ 291648] Origin Client Service (Origin Client Service) . (.Electronic Arts.) - D:\Program Files (x86)\Origin\OriginClientService.exe =>.Electronic Arts, Inc.®
SR - Auto [31/01/2015] [ 291648] Razer Game Scanner (Razer Game Scanner Service) . (.Copyright © 2013-2015.) - C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe =>.Razer Inc.®
SR - Auto [07/12/2015] [ 291648] Free Up Joystick (roqenufe) . (...) - C:\Program Files (x86)\032B0290-1449484090-0559-0306-940700080009\jnsb480E.tmp =>PUP.Optional.CrossRider
SR - Auto [26/01/2015] [ 291648] RzKLService (RzKLService) . (.Razer Inc..) - C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe =>.Razer Inc.®
SR - Auto [09/06/2014] [ 291648] Razer Surround Audio Service (RzMaelstromVADStreamingService) . (.A-Volute.) - C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzMaelstromVADStreamingService.exe
SR - Auto [07/12/2015] [ 291648] SSFK (SSFK) . (.TODO: <公司名>.) - C:\Program Files (x86)\SFK\SSFK.exe {1121D343CEADB8041BAC48B044906C5E105E} =>PUP.Optional.MyWebSearch
SR - Auto [21/05/2015] [ 291648] SAMSUNG Mobile Connectivity Service (ss_conn_service) . (.DEVGURU Co., LTD..) - C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe =>.DEVGURU CO LTD®
SS - Demand [19/08/2015] [ 291648] Steam Client Service (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe =>.Valve®
SR - Auto [07/12/2015] [ 291648] WindowsMangerProtect Service (WindowsMangerProtect) . (.Sysinternals process Explorer.) - C:\ProgramData\Tmp0x0x\ProtectWindowsManager.exe {11215BD52CE822E39F61AAE0642B2F566ABD} =>PUP.Optional.WpManager
SR - Auto [04/12/2015] [ 291648] WNetEnhancer Service (WNetEnhancer Service) . (...) - C:\Program Files (x86)\WNetEnhancer\WNetEnhancer Internet Enhancer\663d2e82e7a5dc32e243ab08ac2ec4a6.exe =>PUP.Optional.Wajam
SR - Auto [08/12/2015] [ 291648] Zitenop (Zitenop) . (...) - C:\ProgramData\Zitenop\Zitenop.exe =>PUP.Optional.Salus

---\\ Recherche de clés de registre Tracing (26) - 8s
HKLM\SOFTWARE\Microsoft\Tracing\Dripkix_RASAPI32 =>PUP.Optional.Amonetize
HKLM\SOFTWARE\Microsoft\Tracing\Dripkix_RASMANCS =>PUP.Optional.Amonetize
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Airtop_RASAPI32 =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Airtop_RASMANCS =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ApplicationHosting_RASAPI32 =>PUP.Optional.ApplicationHosting
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ApplicationHosting_RASMANCS =>PUP.Optional.ApplicationHosting
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Bubble Dock BSetup_RASAPI32 =>PUP.Optional.BubbleDock
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Bubble Dock BSetup_RASMANCS =>PUP.Optional.BubbleDock
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Bubble Dock Uninstall_RASAPI32 =>PUP.Optional.BubbleDock
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Bubble Dock Uninstall_RASMANCS =>PUP.Optional.BubbleDock
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Bubble Dock_RASAPI32 =>PUP.Optional.BubbleDock
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Bubble Dock_RASMANCS =>PUP.Optional.BubbleDock
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\OneSystemCare_RASAPI32 =>PUP.Optional.OneSystemCare
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\OneSystemCare_RASMANCS =>PUP.Optional.OneSystemCare
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Selection Tools Uninstall_RASAPI32 =>PUP.Optional.Nosibay
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Selection Tools Uninstall_RASMANCS =>PUP.Optional.Nosibay
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Selection Tools_RASAPI32 =>PUP.Optional.Nosibay
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Selection Tools_RASMANCS =>PUP.Optional.Nosibay
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SpaceSoundPro_RASAPI32 =>PUP.Optional.SpaceSoundPro
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SpaceSoundPro_RASMANCS =>PUP.Optional.SpaceSoundPro
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\upgmsd_fr_005010169_RASAPI32 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\upgmsd_fr_005010169_RASMANCS =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\upospd_us_013010168_RASAPI32 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\upospd_us_013010168_RASMANCS =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Zitenop_RASAPI32 =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Zitenop_RASMANCS =>PUP.Optional.Salus

---\\ Scan Additionnel (166) - 1s
HKLM\SYSTEM\CurrentControlSet\Services\Airtop =>PUP.Optional.Salus
C:\ProgramData\Airtop\Airtop.exe =>PUP.Optional.Salus
HKLM\SYSTEM\CurrentControlSet\Services\ApplicationHosting =>PUP.Optional.ApplicationHosting
C:\ProgramData\ApplicationHosting\ApplicationHosting.exe =>PUP.Optional.ApplicationHosting
HKLM\SYSTEM\CurrentControlSet\Services\Dripkix =>PUP.Optional.Amonetize
C:\Program Files\Dripkix\Dripkix.exe =>PUP.Optional.Amonetize
HKLM\SYSTEM\CurrentControlSet\Services\gufutoqu =>PUP.Optional.CrossRider
C:\Program Files (x86)\032B0290-1449484090-0559-0306-940700080009\knsjC532.tmp =>PUP.Optional.CrossRider
HKLM\SYSTEM\CurrentControlSet\Services\nyneryxo =>PUP.Optional.CrossRider
C:\Program Files (x86)\032B0290-1449484090-0559-0306-940700080009\hnsg5CE7.tmp =>PUP.Optional.CrossRider
HKLM\SYSTEM\CurrentControlSet\Services\roqenufe =>PUP.Optional.CrossRider
C:\Program Files (x86)\032B0290-1449484090-0559-0306-940700080009\jnsb480E.tmp =>PUP.Optional.CrossRider
HKLM\SYSTEM\CurrentControlSet\Services\SSFK =>PUP.Optional.MyWebSearch
C:\Program Files (x86)\SFK\SSFK.exe =>PUP.Optional.MyWebSearch
HKLM\SOFTWARE\AssistPoint =>PUP.Optional.AssistPoint
HKLM\SYSTEM\CurrentControlSet\Services\Update Mgr AssistPoint =>PUP.Optional.AssistPoint
HKLM\SYSTEM\CurrentControlSet\Services\WindowsMangerProtect =>PUP.Optional.WpManager
C:\ProgramData\Tmp0x0x\ProtectWindowsManager.exe =>PUP.Optional.WpManager
HKLM\SYSTEM\CurrentControlSet\Services\WNetEnhancer Service =>PUP.Optional.Wajam
C:\Program Files (x86)\WNetEnhancer\WNetEnhancer Internet Enhancer\663d2e82e7a5dc32e243ab08ac2ec4a6.exe =>PUP.Optional.Wajam
HKLM\SYSTEM\CurrentControlSet\Services\Zitenop =>PUP.Optional.Salus
C:\ProgramData\Zitenop\Zitenop.exe =>PUP.Optional.Salus
C:\Program Files (x86)\Fast-Search\kol3015.exe =>PUP.Optional.FastSearch
C:\ProgramData\Service7609 =>Heuristic.Graftor
C:\ProgramData\Service7609\Service7609.exe =>Heuristic.Graftor
C:\Windows\Tasks\VKCAGRPJFKDHGGAN.job =>Heuristic.Graftor
C:\Windows\System32\Tasks\kol3015 =>PUP.Optional.FastSearch
C:\Windows\System32\Tasks\Urecceqm =>PUP.Optional.Groover
C:\Windows\System32\Tasks\VKCAGRPJFKDHGGAN =>Heuristic.Graftor
C:\Users\Alexis\AppData\Local\gmsd_fr_005010169\upgmsd_fr_005010169.exe =>PUP.Optional.CrossRider
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\MalwareProtectionClient.exe =>.Superfluous.MalwareProtection
C:\Program Files (x86)\rec_en_77\rec_en_77.exe =>PUP.Optional.Tuto4PC
C:\Program Files (x86)\gmsd_fr_005010169\gmsd_fr_005010169.exe =>PUP.Optional.CrossRider
C:\Program Files (x86)\WNetEnhancer\WNetEnhancer Internet Enhancer\7e0e6c165467f226fa2a8f9d6445d9af.exe =>PUP.Optional.Wajam
C:\Program Files\Dripkix\packages\76b17136-be0a-4a59-8a8b-6dca3c97cc4d\Drip.exe =>PUP.Optional.Amonetize
C:\Users\Alexis\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhdcbgmkmfapmaccefgcigficdnphjbn =>Hijacker.Browser
C:\Users\Alexis\AppData\Roaming\Mozilla\Firefox\Profiles\8i3qsk17.default\searchplugins\findit.xml =>PUP.Optional.SmartBar
C:\Users\Alexis\AppData\Roaming\Mozilla\Firefox\Profiles\8i3qsk17.default\searchplugins\istartpageing.xml =>PUP.Optional.IstartPageing
C:\Users\Alexis\AppData\Roaming\Mozilla\Firefox\Profiles\8i3qsk17.default\searchplugins\search-simple.xml =>PUP.Optional.SearchSimple
C:\Users\Alexis\AppData\Roaming\Mozilla\Firefox\Profiles\8i3qsk17.default\searchplugins\yahoo.xml =>PUP.Optional.BDYahoo
C:\Users\Alexis\AppData\Roaming\Mozilla\Firefox\Profiles\8i3qsk17.default\extensions\deskCutv2@gmail.com =>PUP.Optional.LightningNewTab
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311541197} =>PUP.Optional.CrossRider
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411891122} =>PUP.Optional.CrossRider
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30c23909-a0f6-4e68-a6f7-919ff3cfac34} =>PUP.Optional.MediaViewer
C:\Windows\system32\Ekiraky64.dll =>Hijacker.Winsock
C:\Windows\system32\Ofuwday64.dll =>Hijacker.Winsock
C:\ProgramData\Zitenop\Viajob.dll =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\gmsd_fr_005010169_is1 =>PUP.Optional.GamesDesktop
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\rec_en_77_is1 =>PUP.Optional.Tuto4PC
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D71F4C2F-F591-45C8-87D7-C1FD4DC4A7EC} =>PUP.Optional.SmartBar
HKLM\SOFTWARE\Wow6432Node\AssistPoint =>PUP.Optional.AssistPoint
HKLM\SOFTWARE\Wow6432Node\downchecker =>PUP.Optional.DownChecker
HKLM\SOFTWARE\Wow6432Node\Fast-Search =>PUP.Optional.FastSearch
HKLM\SOFTWARE\Wow6432Node\FFPluginHp =>PUP.Optional.SweetSearch
HKLM\SOFTWARE\Wow6432Node\GAMESDESKTOP =>PUP.Optional.GamesDesktop
HKLM\SOFTWARE\Wow6432Node\istartpageingSoftware =>PUP.Optional.IstartPageing
HKLM\SOFTWARE\Wow6432Node\LolliScan =>PUP.Optional.Graftor
HKLM\SOFTWARE\Wow6432Node\mtAirtop =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\mtZitenop =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\RichMediaViewV1 =>PUP.Optional.MediaViewer
HKLM\SOFTWARE\Wow6432Node\RichMediaViewV1release399 =>PUP.Optional.MediaViewer
HKLM\SOFTWARE\Wow6432Node\SensePlus-nv =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\SensePlus-nv-ie =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\SpaceSondPro =>PUP.Optional.SpaceSoundPro
HKLM\SOFTWARE\Wow6432Node\SwiftSearch_1.10.0.25 =>PUP.Optional.Generic
HKLM\SOFTWARE\Wow6432Node\TrustMediaViewerV1alpha1193 =>PUP.Optional.MediaViewer
HKLM\SOFTWARE\Wow6432Node\Tutorials =>PUP.Optional.AgenceExclusive
HKLM\SOFTWARE\Wow6432Node\WNetEnhancer =>PUP.Optional.Wajam
HKLM\SOFTWARE\Wow6432Node\yoursearchingSoftware =>PUP.Optional.YourSearching
HKCU\SOFTWARE\DailyPcClean =>PUP.Optional.DailyPCClean
HKCU\SOFTWARE\iWebar-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\Nosibay =>PUP.Optional.SPointer
HKCU\SOFTWARE\Store =>PUP.Optional.Generic
HKCU\SOFTWARE\tstamptoken =>PUP.Optional.MaxComputerCleaner
HKCU\SOFTWARE\Tutorials =>PUP.Optional.AgenceExclusive
HKCU\SOFTWARE\TutoTag =>PUP.Optional.AgenceExclusive
HKCU\SOFTWARE\WNetEnhancer =>PUP.Optional.Wajam
HKCU\SOFTWARE\WTools =>PUP.Optional.Nosibay
C:\Program Files (x86)\032B0290-1449484090-0559-0306-940700080009 =>PUP.Optional.CrossRider
C:\Program Files (x86)\032B0290-1449484097-0559-0306-940700080009 =>PUP.Optional.CrossRider
C:\Program Files (x86)\209fe72e-431d-43ba-948d-1274eef4bd7f =>PUP.Optional.CrossRider
C:\Program Files (x86)\6d2018b6-192d-498a-8d18-12afcb059256 =>PUP.Optional.CrossRider
C:\Program Files (x86)\Assist Point =>PUP.Optional.AssistPoint
C:\Program Files (x86)\Fast-Search =>PUP.Optional.FastSearch
C:\Program Files (x86)\gmsd_fr_005010169 =>PUP.Optional.CrossRider
C:\Program Files (x86)\rec_en_77 =>PUP.Optional.Tuto4PC
C:\Program Files (x86)\SFK =>PUP.Optional.MyWebSearch
C:\Program Files (x86)\WNetEnhancer =>PUP.Optional.Wajam
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP =>PUP.Optional.GamesDesktop
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WNetEnhancer =>PUP.Optional.Wajam
C:\ProgramData\Airtop =>PUP.Optional.Salus
C:\ProgramData\Airtops =>PUP.Optional.Salus
C:\ProgramData\ApplicationHosting =>PUP.Optional.ApplicationHosting
C:\ProgramData\Zitenop =>PUP.Optional.Salus
C:\ProgramData\Zitenops =>PUP.Optional.Salus
C:\Users\Alexis\AppData\Roaming\istartpageing =>PUP.Optional.IstartPageing
C:\Users\Alexis\AppData\Roaming\Nosibay =>PUP.Optional.BubbleDock
C:\Users\Alexis\AppData\Roaming\OpenCandy =>PUP.Optional.OpenCandy
C:\Users\Alexis\AppData\Roaming\Store =>PUP.Optional.Nosibay
C:\Users\Alexis\AppData\Roaming\yoursearching =>PUP.Optional.YourSearching
C:\Users\Alexis\AppData\Local\CrashRpt =>.Superfluous.CrashReports
C:\Users\Alexis\AppData\Local\gmsd_fr_005010169 =>PUP.Optional.CrossRider
C:\Users\Alexis\AppData\Local\Installer =>PUP.Optional.InstallPedia
C:\Users\Alexis\AppData\Local\MalwareProtectionLive =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\rec_en_77 =>PUP.Optional.Tuto4PC
C:\Users\Alexis\AppData\Local\SmartWeb =>PUP.Optional.SmartWebSearch
C:\Users\Alexis\AppData\Local\Software =>PUP.Optional.Boxore
C:\Windows\Prefetch\62793.WINDAPP.MON001.NO.EXE-5D7E35F7.pf =>PUP.Optional.Nosibay
C:\Windows\Prefetch\BUBBLE DOCK BSETUP.EXE-29E55CE8.pf =>PUP.Optional.BubbleDock
C:\Windows\Prefetch\BUBBLE DOCK.EXE-C3A82C7A.pf =>PUP.Optional.BubbleDock
C:\Windows\Prefetch\LBUBBLE DOCK.EXE-2F791CAE.pf =>PUP.Optional.BubbleDock
C:\Windows\Prefetch\SEARCHMOREKNOWDESKTOPSEARCH.E-4D59CE71.pf =>PUP.Optional.DesktopSearch
C:\Windows\Prefetch\SELECTION TOOLS.EXE-E43D508D.pf =>PUP.Optional.Nosibay
C:\Windows\Prefetch\UPGMSD_FR_005010169.EXE-06E01730.pf =>PUP.Optional.CrossRider
C:\Windows\System32\drivers\cherimoya.sys =>PUP.Optional.Shopperz
C:\Users\Alexis\AppData\Roaming\OpenCandy\34B2AA63A5384F389CDE46C223899B62\setup.exe =>PUP.Optional.OpenCandy
C:\Users\Alexis\AppData\Local\SmartWeb\__u.exe =>PUP.Optional.SmartWebSearch
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\uninstall.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\dhk788-3a9a96c7-8f69-4647-9872-16437b5b16de.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\dhk788-707685b8-9510-4ff3-8d9b-66c5b2ace5e1.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\dhk788-d46d40c8-5a1f-462b-8fc5-0efe407a4b6c.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\dhk806-038de6af-266b-4db6-9bce-467e8e47e7f9.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\dhk806-199137ac-027c-4333-baab-cae18c999c04.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\dhk806-2fccb677-dd11-496c-bfa7-f0a17884f442.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\dhk806-9e143978-55e7-4b1a-93f8-686f3932e040.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\dhk806-fb65f2c4-9535-4cf0-931e-162f077786f5.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\Plugin-1be8e3fe-7dc0-49d5-b23e-2052f8907396.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\Plugin-1f547a07-0ceb-45b3-8d0f-e4def2e0649f.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\Plugin-7efed5dd-539c-4e72-9ca6-78a2a26aa312.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\Plugin-804581a9-2808-4904-bdba-b2e1a8e202f6.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\Plugin-bbe34a65-25a8-45a3-8edb-74fe73cad706.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\Plugin-df048cc4-12d2-4af3-92a1-fb80db26b245.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\Plugin-e0d53720-fcb2-4e63-9a02-b9410494df97.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\Plugin-e4ecbe96-ee3f-4a16-94c8-25c0957ade02.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\PluginContainer-a8477e14-c262-47a1-b087-f92bcab8ffc2.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\PluginContainer-b7bb3717-0d9f-40f5-9520-0a117e442387.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\PluginContainer-fef9969e-6be4-4057-a284-4e13e2dacf25.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\MalwareProtectionLive\quarantine\updater-474f52e6-893e-4734-81ac-8e3f554bf11a.exe =>.Superfluous.MalwareProtection
C:\Users\Alexis\AppData\Local\Installer\Install_26144\YTDownloader.exe =>PUP.Optional.YTDownloader
C:\Users\Alexis\AppData\Local\gmsd_fr_005010169\Download\myoffergroup_fr.exe =>PUP.Optional.CrossRider
HKLM64\SOFTWARE\Microsoft\Tracing\Dripkix_RASAPI32 =>PUP.Optional.Amonetize
HKLM64\SOFTWARE\Microsoft\Tracing\Dripkix_RASMANCS =>PUP.Optional.Amonetize
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Airtop_RASAPI32 =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Airtop_RASMANCS =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ApplicationHosting_RASAPI32 =>PUP.Optional.ApplicationHosting
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ApplicationHosting_RASMANCS =>PUP.Optional.ApplicationHosting
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Bubble Dock BSetup_RASAPI32 =>PUP.Optional.BubbleDock
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Bubble Dock BSetup_RASMANCS =>PUP.Optional.BubbleDock
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Bubble Dock Uninstall_RASAPI32 =>PUP.Optional.BubbleDock
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Bubble Dock Uninstall_RASMANCS =>PUP.Optional.BubbleDock
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Bubble Dock_RASAPI32 =>PUP.Optional.BubbleDock
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Bubble Dock_RASMANCS =>PUP.Optional.BubbleDock
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\OneSystemCare_RASAPI32 =>PUP.Optional.OneSystemCare
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\OneSystemCare_RASMANCS =>PUP.Optional.OneSystemCare
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Selection Tools Uninstall_RASAPI32 =>PUP.Optional.Nosibay
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Selection Tools Uninstall_RASMANCS =>PUP.Optional.Nosibay
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Selection Tools_RASAPI32 =>PUP.Optional.Nosibay
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Selection Tools_RASMANCS =>PUP.Optional.Nosibay
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SpaceSoundPro_RASAPI32 =>PUP.Optional.SpaceSoundPro
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SpaceSoundPro_RASMANCS =>PUP.Optional.SpaceSoundPro
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\upgmsd_fr_005010169_RASAPI32 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\upgmsd_fr_005010169_RASMANCS =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\upospd_us_013010168_RASAPI32 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\upospd_us_013010168_RASMANCS =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Zitenop_RASAPI32 =>PUP.Optional.Salus
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Zitenop_RASMANCS =>PUP.Optional.Salus

---\\ Récapitulatif des éléments trouvés sur votre station (53) - 0s
http://www.nicolascoolman.fr/?p=4664 =>Hijacker.DNS.Hosts
http://www.nicolascoolman.fr/?p=2645 =>PUP.Optional.Salus
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.ApplicationHosting
http://www.nicolascoolman.fr/?p=2072 =>PUP.Optional.Amonetize
http://www.nicolascoolman.fr/?p=180 =>PUP.Optional.CrossRider
http://www.nicolascoolman.fr/?p=220 =>PUP.Optional.MyWebSearch
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.AssistPoint
http://www.nicolascoolman.fr/?p=173 =>PUP.Optional.WpManager
http://www.nicolascoolman.fr/?p=263 =>PUP.Optional.Wajam
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.FastSearch
http://www.nicolascoolman.fr/?p=4161 =>PUP.Optional.Groover
http://www.nicolascoolman.fr/?p=4664 =>Heuristic.Graftor
http://www.nicolascoolman.fr/?p=29 =>PUP.Optional.SmartWebSearch
http://www.nicolascoolman.fr/?p=4664 =>.Superfluous.MalwareProtection
http://www.nicolascoolman.fr/?p=4879 =>PUP.Optional.Tuto4PC
http://www.nicolascoolman.fr/?p=4664 =>Hijacker.Browser
http://www.nicolascoolman.fr/?p=308 =>PUP.Optional.SmartBar
http://www.nicolascoolman.fr/?p=4936 =>PUP.Optional.IstartPageing
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.SearchSimple
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.BDYahoo
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.LightningNewTab
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.Linkury
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.MediaViewer
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.SpaceSoundPro
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.Nosibay
http://www.nicolascoolman.fr/?p=401 =>PUP.Optional.Downware
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.GamesDesktop
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.DownChecker
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.SweetSearch
http://www.nicolascoolman.fr/?p=2460 =>PUP.Optional.Graftor
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.Generic
http://www.nicolascoolman.fr/?p=122 =>PUP.Optional.AgenceExclusive
http://www.nicolascoolman.fr/?p=5037 =>PUP.Optional.YourSearching
http://www.nicolascoolman.fr/?p=4047 =>PUP.Optional.DailyPCClean
http://www.nicolascoolman.fr/?p=205 =>PUP.Optional.SPointer
http://www.nicolascoolman.fr/?p=2576 =>PUP.Optional.MaxComputerCleaner
http://www.nicolascoolman.fr/?p=177 =>PUP.Optional.BubbleDock
http://www.nicolascoolman.fr/?p=197 =>PUP.Optional.OpenCandy
http://www.nicolascoolman.fr/?p=4664 =>.Superfluous.CrashReports
http://www.nicolascoolman.fr/?p=943 =>PUP.Optional.InstallPedia
http://www.nicolascoolman.fr/?p=90 =>PUP.Optional.Boxore
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.DesktopSearch
http://www.nicolascoolman.fr/?p=338 =>.Superfluous.CacaoWeb
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.Shopperz
http://www.nicolascoolman.fr/?p=1780 =>PUP.Optional.YTDownloader
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.BoBrowser
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.PieSearch
http://www.nicolascoolman.fr/?p=248 =>PUP.Optional.WebsSearches
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.SearchEngine
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.DeskCut
http://www.nicolascoolman.fr/?p=666 =>PUP.Optional.QuickStart
http://www.nicolascoolman.fr/?p=546 =>PUP.Optional.Browser
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.OneSystemCare

~ End of the scan, 26428 items in 283 seconds (1502)(3)

Publicité


Signaler le contenu de ce document

Publicité