cjoint

Publicité


Publicité

Commentaire : A'l;équipe de Nicolas Coolman. Bonjour à tous, je joins mon rapport de diagnostic afin que vous puissiez me dire si mon ordinateur est infecté et m'expliquer ce que je dois faire pour le désinfecter. Je vous remercie par avance

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2017.9.18.163 Par Nicolas Coolman (2017/09/18)
~ Démarré par Marc (Administrator) (2017/09/19 16:04:38)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Legal
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Users\Marc\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\Marc\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Démarrage du système: Normal (Normal boot)
Windows 10 Home, 64-bit (Build 15063) =>.Microsoft Corporation

---\\ Navigateurs Internet (3) - 0s
~ GCIE: Google Chrome v60.0.3112.113
~ MSIE: Microsoft Edge v40
~ MSIE: Internet Explorer v11.608.15063.0

---\\ Informations sur les produits Windows (8) - 0s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
~ Windows(R) Operating System, RETAIL channel
Windows ID Activation : OK
~ Windows Partial Key : 8HVX7
Windows License : OK
~ Windows Remaining Initializations Number : 1001
Windows Automatic Updates : OK

---\\ Logiciels de protection (2) - 4s
McAfee LiveSafe v16.0.3 (Protection)
Windows Defender (Deactivate)

---\\ Surveillance de Logiciels (2) - 4s
~ Adobe Flash Player 27 PPAPI (Surveillance)
~ Adobe Acrobat Reader DC - Français (Surveillance)

---\\ Logiciels de partage P2P (1) - 5s
~ µTorrent v3.5.0.43916 (P2P)

---\\ Informations sur le système (6) - 0s
~ Operating System: AMD64 Family 22 Model 0 Stepping 1, AuthenticAMD
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 4126.04 MB (39% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 155 GB (33%) free of 463 GB : OK =>.Disk Space

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: P-BELL-MB
~ User Name: Marc
~ Logged in as Administrator

---\\ Enumération des unités disques (2) - 0s
~ Drive C: has 155 GB free of 463 GB (System)
~ Drive H: has 1111 GB free of 1907 GB

---\\ Etat du Centre de Sécurité Windows (7) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Recherche particulière de fichiers génériques (25) - 3s
[MD5.3AF6D6F752EDE013ED15DFD2D44F8EF9] - 05/09/2017 - (.Microsoft Corporation - Explorateur Windows.) -- C:\WINDOWS\Explorer.exe [4848960] =>.Microsoft Windows®
[MD5.ECB702B8C5650381C0784F1EEABB97BC] - 18/03/2017 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\WINDOWS\System32\rundll32.exe [68608] =>.Microsoft Corporation
[MD5.0242626678C83AE788C655C1990A3CC3] - 28/07/2017 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\WINDOWS\System32\Wininit.exe [318232] =>.Microsoft Windows Publisher®
[MD5.9AA7516745C98B81FC10227FF2652391] - 05/09/2017 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\WINDOWS\System32\wininet.dll [3307008] =>.Microsoft Corporation
[MD5.9CDA170849A4F66F4D68B3DBB3AC8394] - 05/09/2017 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\WINDOWS\System32\Winlogon.exe [706560] =>.Microsoft Corporation
[MD5.50CDF68A8EA8A2A9165CD573FA6C42D8] - 18/03/2017 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\WINDOWS\System32\sppcomapi.dll [414208] =>.Microsoft Corporation
[MD5.0F9FA6A2D4EAE50393DCE473759A9845] - 18/03/2017 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\WINDOWS\System32\dnsapi.dll [661224] =>.Microsoft Windows®
[MD5.3F969D5ADEAB3284ABD500B37D74A8F8] - 18/03/2017 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\WINDOWS\Syswow64\dnsapi.dll [508344] =>.Microsoft Windows®
[MD5.70E14A01193D817004C0F88E767BC59B] - 19/03/2017 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\WINDOWS\System32\fr-FR\user32.dll.mui [19968] =>.Microsoft Corporation
[MD5.5A6D591D56791BA63CE73FCAD60D89A1] - 05/09/2017 - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\WINDOWS\System32\drivers\AFD.sys [610720] =>.Microsoft Windows®
[MD5.01733BEEE02E51F712330D5909BD701C] - 18/03/2017 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [29088] =>.Microsoft Windows®
[MD5.B6E5AD7C83A5254DEE9D86023C0E5A81] - 18/03/2017 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [93184] =>.Microsoft Corporation
[MD5.ABE77AD954BC3D72F559CF0C381E50BC] - 18/03/2017 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [160256] =>.Microsoft Corporation
[MD5.185A4519B7764F4DEF714D890A7A9FD2] - 18/03/2017 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\DfsC.sys [150528] =>.Microsoft Corporation
[MD5.02B9639D9997E95CDF2F4C4F3BDCC73D] - 20/06/2017 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [86528] =>.Microsoft Corporation
[MD5.C6C8315E3262FAE460529C6DA2951682] - 18/03/2017 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [115200] =>.Microsoft Corporation
[MD5.DCC05E5EAA580C97F13B434FAFACED85] - 18/03/2017 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [214528] =>.Microsoft Corporation
[MD5.F2AD1B72C5A6475FB5FF332E1980DF88] - 18/03/2017 - (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [467352] =>.Microsoft Windows®
[MD5.BAD3C424788BC071C3EC82CFCDA954D2] - 05/09/2017 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [305152] =>.Microsoft Corporation
[MD5.075F8C81457804BB79DD33FE69A96C57] - 28/07/2017 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\WINDOWS\System32\drivers\ntfs.sys [2327456] =>.Microsoft Windows®
[MD5.2CC6C325B271C7CA60F374F8F868CB45] - 18/03/2017 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\WINDOWS\System32\drivers\Parport.sys [97792] =>.Microsoft Corporation
[MD5.5279EC98F6218D29EADDFECCC0D80E9A] - 18/03/2017 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [107008] =>.Microsoft Corporation
[MD5.53A01D3FDB701AC5D9DDE4140227E3D9] - 20/03/2017 - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [183296] =>.Microsoft Corporation
[MD5.D74756DD1518D28A09CDA99696273FA4] - 01/08/2017 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [119712] =>.Microsoft Windows®
[MD5.E3429DBBEA3965BB96E24B16EF4A2551] - 18/03/2017 - (.Microsoft Corporation - Volume Shadow Copy driver.) -- C:\WINDOWS\System32\drivers\volsnap.sys [397216] =>.Microsoft Windows®

---\\ Liste des services NT non Microsoft et non désactivés (20) - 4s
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
O23 - Service: @C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe, (CIJSRegister) . (.CANON INC. - Canon IJ Scan Utility SETEVENT.) - C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe =>.Canon Inc.®
O23 - Service: Clean Master Core Service (cmcore) . (.Kingsoft Corporation - Clean Master.) - c:\program files (x86)\cmcm\Clean Master\cmcore.exe =>.Beijing Kingsoft Security software Co.,Ltd®
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
O23 - Service: McAfee Home Network (HomeNetSvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) . (.Copyright CANON INC. 2006-2016 - Inkjet Printer/Scanner/Fax Extended Survey.) - C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe =>.Canon Inc.®
O23 - Service: Le VPN Service (Le VPN Service) . (...) - C:\Program Files (x86)\VTNV Solutions Ltd.\Le VPN\Le VPN Service.exe
O23 - Service: McAfee SiteAdvisor Service (McAfee SiteAdvisor Service) . (.McAfee, Inc. - McAfee WebAdvisor.) - C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe =>.McAfee, Inc.®
O23 - Service: McAfee AP Service (McAPExe) . (.McAfee, Inc. - McAfee Access Protection.) - C:\Program Files\Common Files\McAfee\VSCore_15_7\McApExe.exe =>.McAfee, Inc.®
O23 - Service: McAfee Boot Delay Start Service (McBootDelayStartSvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
O23 - Service: McAfee CSP Service (mccspsvc) . (.McAfee, Inc. - McAfee CSP Service Host.) - C:\Program Files\Common Files\McAfee\CSP\2.5.312.0\McCSPServiceHost.exe =>.McAfee, Inc.®
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
O23 - Service: McAfee Platform Services (mcpltsvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
O23 - Service: McAfee Proxy Service (McProxy) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
O23 - Service: McAfee Service Controller (mfemms) . (.McAfee, Inc. - McAfee Management Service.) - C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe =>.McAfee, Inc.®
O23 - Service: McAfee Module Core Service (ModuleCoreService) . (.McAfee, Inc. - McAfee Module Core Service.) - C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe =>.McAfee, Inc.®
O23 - Service: Orange update Core Service (Orange update Core Service) . (...) - C:\Program Files (x86)\Orange\OrangeUpdate\Service\OUCore.exe (.not file.)
O23 - Service: Intel Security PEF Service (PEFService) . (.Intel Security, Inc. - Intel Security PEF Service.) - C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe =>.McAfee, Inc.®
O23 - Service: Intel Security True Key (TrueKey) . (.McAfee, Inc. - Intel Security True Key.) - C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe =>.McAfee, Inc.®
O23 - Service: Intel Security True Key Scheduler (TrueKeyScheduler) . (.McAfee, Inc. - Intel Security True Key.) - C:\Program Files\TrueKey\McTkSchedulerService.exe =>.McAfee, Inc.®

---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (26) - 100s
SR - Auto [19/07/2017] [ 83032] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
SS - Demand [13/09/2017] [ 272384] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\syswow64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated®
SR - Auto [02/06/2016] [ 153736] @C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe, (CIJSRegister) . (.CANON INC..) - C:\Program Files (x86)\Canon\IJ Scan Utility\SETEVENT.exe =>.Canon Inc.®
SS - Demand [10/08/2017] [ 1511728] ClientAnalyticsService (ClientAnalyticsService) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe =>.McAfee, Inc.®
SR - Auto [22/06/2017] [ 315208] Clean Master Core Service (cmcore) . (.Kingsoft Corporation.) - c:\program files (x86)\cmcm\Clean Master\cmcore.exe =>.Beijing Kingsoft Security software Co.,Ltd®
SS - Auto [24/05/2017] [ 153168] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [24/05/2017] [ 153168] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SR - Auto [22/02/2017] [ 641520] McAfee Home Network (HomeNetSvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
SR - Auto [04/02/2016] [ 387144] Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) . (.Copyright CANON INC. 2006-2016.) - C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe =>.Canon Inc.®
SR - Auto [17/04/2017] [ 78336] Le VPN Service (Le VPN Service) . (...) - C:\Program Files (x86)\VTNV Solutions Ltd.\Le VPN\Le VPN Service.exe
SR - Auto [06/09/2017] [ 590880] McAfee SiteAdvisor Service (McAfee SiteAdvisor Service) . (.McAfee, Inc..) - C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe =>.McAfee, Inc.®
SR - Auto [07/08/2017] [ 993256] McAfee AP Service (McAPExe) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\VSCore_15_7\McApExe.exe =>.McAfee, Inc.®
SR - Auto [22/02/2017] [ 641520] McAfee Boot Delay Start Service (McBootDelayStartSvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
SR - Auto [31/05/2017] [ 2139832] McAfee CSP Service (mccspsvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\CSP\2.5.312.0\McCSPServiceHost.exe =>.McAfee, Inc.®
SR - Auto [22/02/2017] [ 641520] McAfee Personal Firewall Service (McMPFSvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
SR - Auto [22/02/2017] [ 641520] McAfee Platform Services (mcpltsvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
SR - Auto [22/02/2017] [ 641520] McAfee Proxy Service (McProxy) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
SR - Demand [21/06/2017] [ 242640] McAfee Firewall Core Service (mfefire) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe =>.McAfee, Inc.®
SR - Auto [21/06/2017] [ 394704] McAfee Service Controller (mfemms) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe =>.McAfee, Inc.®
SR - Demand [21/06/2017] [ 350160] McAfee Validation Trust Protection Service (mfevtp) . (.McAfee, Inc..) - C:\WINDOWS\system32\mfevtps.exe =>.McAfee, Inc.®
SR - Auto [17/08/2017] [ 1546904] McAfee Module Core Service (ModuleCoreService) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe =>.McAfee, Inc.®
SR - Demand [22/02/2017] [ 641520] McAfee Anti-Spam Service (MSK80Service) . (.McAfee, Inc..) - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe =>.McAfee, Inc.®
SR - Auto [31/07/2017] [ 1043864] Intel Security PEF Service (PEFService) . (.Intel Security, Inc..) - C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe =>.McAfee, Inc.®
SR - Auto [19/06/2017] [ 1001920] Intel Security True Key (TrueKey) . (.McAfee, Inc..) - C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe =>.McAfee, Inc.®
SR - Auto [19/06/2017] [ 16928] Intel Security True Key Scheduler (TrueKeyScheduler) . (.McAfee, Inc..) - C:\Program Files\TrueKey\McTkSchedulerService.exe =>.McAfee, Inc.®
SS - Demand [19/06/2017] [ 87760] Intel Security True Key Helper Service (TrueKeyServiceHelper) . (.McAfee, Inc..) - C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe =>.McAfee, Inc.®

---\\ Tâches planifiées en automatique (Registre) (10) - 8s
O40 - TASK: {11940B43-B300-4D9E-83FC-1A462FC3BDD1} [64Bits][\Adobe Flash Player Updater] - (.Adobe Systems Incorporated - Adobe® Flash® Player Update Service 27.0 r0.) -- C:\Windows\syswow64\Macromed\Flash\FlashPlayerUpdateService.exe [272384] =>.Adobe Systems Incorporated®
O40 - TASK: {12C75493-5BAE-471C-9D8C-6E72A1693300} [64Bits][\GoogleUpdateTaskMachineUA] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168] =>.Google Inc®
O40 - TASK: {3AC2C9F9-2990-4A46-AF27-F25DEE56CB35} [64Bits][\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse] - (.McAfee, Inc. - McAfee DAT Reputation Agent.) -- C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe [1779568] =>.McAfee, Inc.®
O40 - TASK: {96723353-3C1E-4857-981F-D82675AE38EA} [64Bits][\GoogleUpdateTaskMachineCore] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168] =>.Google Inc®
O40 - TASK: {A4579021-AD5B-48DB-84D9-D6FC1B697993} [64Bits][\AutoKMS] - (. - AutoKMS.) -- C:\WINDOWS\AutoKMS\AutoKMS.exe (.not file.) [0] (.Orphan.) =>HackTool.AutoKMS
O40 - TASK: {B4A1E047-BF4D-4DFD-9776-78595DEC1947} [64Bits][\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse] - (.McAfee, Inc. - McAfee DAT Reputation Agent.) -- C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe [1779568] =>.McAfee, Inc.®
O40 - TASK: {D15A046E-751B-42F4-8D16-3EFB13168DCF} [64Bits][\McAfeeLogon] - (.McAfee, Inc. - McAfee.) -- C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [745296] =>.McAfee, Inc.®
O40 - TASK: {D5715F29-70A5-4A2E-99C6-4BB8CCCABFBC} [64Bits][\CCleanerSkipUAC] - (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe [7684824] =>.Piriform Ltd®
O40 - TASK: {DE2FDA3F-F1A3-4981-9C13-BE3E79A22AF5} [64Bits][\Adobe Acrobat Update Task] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1165920] =>.Adobe Systems, Incorporated®
O40 - TASK: {EB91A031-1BA9-4550-AAFA-6CE5229DC113} [64Bits][\Adobe Flash Player PPAPI Notifier] - (.Adobe Systems Incorporated - Adobe® Flash® Player Installer/Uninstaller.) -- C:\Windows\syswow64\Macromed\Flash\FlashUtil32_27_0_0_130_pepper.exe [1286144] =>.Adobe Systems Incorporated®

---\\ Applications lancées au démarrage du système (16) - 2s
O4 - HKLM\..\Run: [SecurityHealth] . (.Microsoft Corporation - Windows Defender notification icon.) -- C:\Program Files\Windows Defender\MSASCuiL.exe =>.Microsoft Windows®
O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp®
O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\Marc\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - HKCU\..\Run: [Le VPN] . (...) -- C:\Program Files (x86)\VTNV Solutions Ltd\Le VPN\Le VPN.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_DEC2D89A3B6F06ADCC4F89EA2A899238] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - HKCU\..\Run: [uTorrent] . (.BitTorrent Inc. - µTorrent.) -- C:\Users\Marc\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - HKLM\..\Wow6432Node\Run: [CanonQuickMenu] . (.CANON INC. - Canon Quick Menu.) -- C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE =>.Canon Inc.®
O4 - HKLM\..\Wow6432Node\Run: [cmsc] . (.Kingsoft Corporation - Clean Master.) -- c:\program files (x86)\cmcm\Clean Master\cmtray.exe =>.Beijing Kingsoft Security software Co.,Ltd®
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows®
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows®
O4 - HKUS\S-1-5-21-2482908694-834623207-668491118-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\Marc\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - HKUS\S-1-5-21-2482908694-834623207-668491118-1001\..\Run: [Le VPN] . (...) -- C:\Program Files (x86)\VTNV Solutions Ltd\Le VPN\Le VPN.exe
O4 - HKUS\S-1-5-21-2482908694-834623207-668491118-1001\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - HKUS\S-1-5-21-2482908694-834623207-668491118-1001\..\Run: [GoogleChromeAutoLaunch_DEC2D89A3B6F06ADCC4F89EA2A899238] . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - HKUS\S-1-5-21-2482908694-834623207-668491118-1001\..\Run: [uTorrent] . (.BitTorrent Inc. - µTorrent.) -- C:\Users\Marc\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®

---\\ Google Chrome, Démarrage,Recherche,Extensions (20) - 3s
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.wordreference.com/
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.google.lu =>.Google Inc.
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://mypf/Pages/Index.aspx
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://mail.ru/
G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] =>.Google Inc. {Slides}
G2 - GCE: Preference [User Data\Default] [ajpgkpeckebdhofmmjfgcjjiiejpodla] =>.xmarks {Bookmark Sync}
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] =>.Google Inc. {Docs}
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] http://drive.google.com/ =>.Google Inc. {Drive}
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] http://www.youtube.com =>.Youtube {Youtube}
G2 - GCE: Preference [User Data\Default] [efaidnbmnnnibpcajpcglclefindmkaj] =>.Adobe Inc. {Acrobat}
G2 - GCE: Preference [User Data\Default] [ejidjjhkpiempkbhmpbfngldlkglhimk] http://mail.google.com/ =>.Google Inc. {Gmail Hors Connexion}
G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] =>.Google Inc. {Sheets}
G2 - GCE: Preference [User Data\Default] [fheoggkfdfchfphceeifdbepaooicaho] McAfee® WebAdvisor =>.McAfee Inc.
G2 - GCE: Preference [User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] =>.Google Inc. {Docs hors connexion}
G2 - GCE: Preference [User Data\Default] [gojdjeahdkhocbgjaionomoeieakjgnb] Mise en route
G2 - GCE: Preference [User Data\Default] [nbeldjopgciegccabfohnefghfpinncn] True Key™ by Intel Security =>.truekey.com
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] =>.Google Inc. {Wallet}
G2 - GCE: Preference [User Data\Default] [obhijjefkkokfaiffkcemldacdabpeei] AIO Search =>.aiosearch.com
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] http://mail.google.com/ =>.Google Inc. {Gmail}
G2 - GCE: Preference [User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.

---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (1) - 0s
P2 - FPN: [HKLM] [@mcafee.com/MSC,version=10] - (.McAfee Total Protection MIME Plugin.) -- c:\Program Files (x86)\McAfee\MSC\npMcSnFFPl.dll =>.McAfee Total Protection MIME Plugin

---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (15) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.15063.608 (WinBuild.160101.0800)) -- C:\Windows\syswow64\ieframe.dll =>.Microsoft Corporation

---\\ Internet Explorer,Proxy Management (3) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s
F2 - REG:system.ini: UserInit=
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=

---\\ Etude du fichier hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)

---\\ Browser Helper Object de navigateur (BHO) (4) - 1s
O2 - BHO: True Key Helper [64Bits] - {0F4B8786-5502-4803-8EBC-F652A1153BB6} . (.Intel Security - True Key Internet Explorer Extension.) -- C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll =>.McAfee, Inc.®
O2 - BHO: Canon Easy-WebPrint EX BHO [64Bits] - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} . (.CANON INC. - Easy-WebPrint EX.) -- C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll =>.Canon Inc.®
O2 - BHO: McAfee WebAdvisor BHO [64Bits] - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} . (.McAfee, Inc. - WebAdvisor.) -- c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll =>.McAfee, Inc.®
O2 - BHO: Microsoft OneDrive for Business Browser Helper [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} . (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL =>.Microsoft Corporation®

---\\ Raccourcis Global Startup (119) - 22s
O4 - GS\Desktop [Administrateur]: MKV Player.lnk . (.vsevensoft.com - MKV Player.) C:\Program Files (x86)\MKV Player\MKV Player.exe =>.vsevensoft.com
O4 - GS\Desktop [Administrateur]: Stellar OST to PST Converter.lnk . (.Stellar Information Technology Pvt. Ltd. - Stellar OST to PST Converter.) C:\Program Files\Stellar OST to PST Converter\ost2pstf.exe {6BC1299F176C6D5EEA46A0EAEC3899A9} =>.Stellar Information Technology Pvt. Ltd.
O4 - GS\Desktop [Administrateur]: Stellar Phoenix Windows Data Recovery - Home.lnk . (.Stellar Information Technology Pvt. Ltd. - Windows data Recovery.) C:\Program Files (x86)\Stellar Phoenix Windows Data Recovery\spwdrhfsa.exe =>.Stellar Information Technology Private Limited®
O4 - GS\Desktop [Administrateur]: Usenet.nl.lnk . (.Copyright © 2009 - Usenet.nl.) C:\Program Files (x86)\Usenet.nl\Usenet.nl.exe
O4 - GS\Desktop [Administrateur]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Marc\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Administrateur]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Marc\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\Quicklaunch [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Administrateur]: Mail.Ru.lnk . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) C:\Windows\System32\rundll32.exe url,FileProtocolHandler "http://www.mail.ru/ =>..Microsoft Corporation
O4 - GS\Quicklaunch [Administrateur]: Microsoft Outlook.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office\Office16\OUTLOOK.EXE /recycle =>.Microsoft Corporation
O4 - GS\Quicklaunch [Administrateur]: Stellar OST to PST Converter.lnk . (.Stellar Information Technology Pvt. Ltd. - Stellar OST to PST Converter.) C:\Program Files\Stellar OST to PST Converter\ost2pstf.exe {6BC1299F176C6D5EEA46A0EAEC3899A9} =>.Stellar Information Technology Pvt. Ltd.
O4 - GS\Quicklaunch [Administrateur]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Marc\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [Administrateur]: Destinataire de télécopie.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrateur]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrateur]: Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrateur]: Excel 2016 (2).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.57D52F1E.F0D3.4F58.8F76.E727437CB7A9.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Administrateur]: Excel 2016 (3).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.57D52F1E.F0D3.4F58.8F76.E727437CB7A9.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Administrateur]: Excel 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.57D52F1E.F0D3.4F58.8F76.E727437CB7A9.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Administrateur]: Le VPN.lnk . (...) C:\WINDOWS\Installer\{345A5CBC-C4E2-455D-AA2B-DF6446AC5C1D}\LeVPN.exe
O4 - GS\TaskBar [Administrateur]: Microsoft Money.lnk . (.Microsoft Corp. - Microsoft Money.) C:\Program Files (x86)\Microsoft Money\System\msmoney.exe =>.Microsoft Corp.
O4 - GS\TaskBar [Administrateur]: Outlook 2016 (2).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.7E3E9021.9723.4BFF.BACD.087B95A4CC01.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Administrateur]: Outlook 2016 (3).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.7E3E9021.9723.4BFF.BACD.087B95A4CC01.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Administrateur]: Outlook 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.7E3E9021.9723.4BFF.BACD.087B95A4CC01.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Administrateur]: Word 2016 (2).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.40BB677D.0A7A.4D43.9F72.5AE6F0E97EE2.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Administrateur]: Word 2016 (3).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.40BB677D.0A7A.4D43.9F72.5AE6F0E97EE2.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Administrateur]: Word 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.40BB677D.0A7A.4D43.9F72.5AE6F0E97EE2.exe =>.Microsoft Corporation®
O4 - GS\Programs [Administrateur]: Fonctionnalités optionnelles.lnk . (.Microsoft Corporation - Assistance des fonctionnalités à la demande.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Programs [Administrateur]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Marc\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Marc]: MKV Player.lnk . (.vsevensoft.com - MKV Player.) C:\Program Files (x86)\MKV Player\MKV Player.exe =>.vsevensoft.com
O4 - GS\Desktop [Marc]: Stellar OST to PST Converter.lnk . (.Stellar Information Technology Pvt. Ltd. - Stellar OST to PST Converter.) C:\Program Files\Stellar OST to PST Converter\ost2pstf.exe {6BC1299F176C6D5EEA46A0EAEC3899A9} =>.Stellar Information Technology Pvt. Ltd.
O4 - GS\Desktop [Marc]: Stellar Phoenix Windows Data Recovery - Home.lnk . (.Stellar Information Technology Pvt. Ltd. - Windows data Recovery.) C:\Program Files (x86)\Stellar Phoenix Windows Data Recovery\spwdrhfsa.exe =>.Stellar Information Technology Private Limited®
O4 - GS\Desktop [Marc]: Usenet.nl.lnk . (.Copyright © 2009 - Usenet.nl.) C:\Program Files (x86)\Usenet.nl\Usenet.nl.exe
O4 - GS\Desktop [Marc]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Marc\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Marc]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Marc\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\Quicklaunch [Marc]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Marc]: Mail.Ru.lnk . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) C:\Windows\System32\rundll32.exe url,FileProtocolHandler "http://www.mail.ru/ =>..Microsoft Corporation
O4 - GS\Quicklaunch [Marc]: Microsoft Outlook.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office\Office16\OUTLOOK.EXE /recycle =>.Microsoft Corporation
O4 - GS\Quicklaunch [Marc]: Stellar OST to PST Converter.lnk . (.Stellar Information Technology Pvt. Ltd. - Stellar OST to PST Converter.) C:\Program Files\Stellar OST to PST Converter\ost2pstf.exe {6BC1299F176C6D5EEA46A0EAEC3899A9} =>.Stellar Information Technology Pvt. Ltd.
O4 - GS\Quicklaunch [Marc]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Marc\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [Marc]: Destinataire de télécopie.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Marc]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Marc]: Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Marc]: Excel 2016 (2).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.57D52F1E.F0D3.4F58.8F76.E727437CB7A9.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Marc]: Excel 2016 (3).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.57D52F1E.F0D3.4F58.8F76.E727437CB7A9.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Marc]: Excel 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.57D52F1E.F0D3.4F58.8F76.E727437CB7A9.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Marc]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Marc]: Le VPN.lnk . (...) C:\WINDOWS\Installer\{345A5CBC-C4E2-455D-AA2B-DF6446AC5C1D}\LeVPN.exe
O4 - GS\TaskBar [Marc]: Microsoft Money.lnk . (.Microsoft Corp. - Microsoft Money.) C:\Program Files (x86)\Microsoft Money\System\msmoney.exe =>.Microsoft Corp.
O4 - GS\TaskBar [Marc]: Outlook 2016 (2).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.7E3E9021.9723.4BFF.BACD.087B95A4CC01.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Marc]: Outlook 2016 (3).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.7E3E9021.9723.4BFF.BACD.087B95A4CC01.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Marc]: Outlook 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.7E3E9021.9723.4BFF.BACD.087B95A4CC01.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Marc]: Word 2016 (2).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.40BB677D.0A7A.4D43.9F72.5AE6F0E97EE2.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Marc]: Word 2016 (3).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.40BB677D.0A7A.4D43.9F72.5AE6F0E97EE2.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Marc]: Word 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.40BB677D.0A7A.4D43.9F72.5AE6F0E97EE2.exe =>.Microsoft Corporation®
O4 - GS\Programs [Marc]: Fonctionnalités optionnelles.lnk . (.Microsoft Corporation - Assistance des fonctionnalités à la demande.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Programs [Marc]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Marc\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\Desktop [marc-]: MKV Player.lnk . (.vsevensoft.com - MKV Player.) C:\Program Files (x86)\MKV Player\MKV Player.exe =>.vsevensoft.com
O4 - GS\Desktop [marc-]: Stellar OST to PST Converter.lnk . (.Stellar Information Technology Pvt. Ltd. - Stellar OST to PST Converter.) C:\Program Files\Stellar OST to PST Converter\ost2pstf.exe {6BC1299F176C6D5EEA46A0EAEC3899A9} =>.Stellar Information Technology Pvt. Ltd.
O4 - GS\Desktop [marc-]: Stellar Phoenix Windows Data Recovery - Home.lnk . (.Stellar Information Technology Pvt. Ltd. - Windows data Recovery.) C:\Program Files (x86)\Stellar Phoenix Windows Data Recovery\spwdrhfsa.exe =>.Stellar Information Technology Private Limited®
O4 - GS\Desktop [marc-]: Usenet.nl.lnk . (.Copyright © 2009 - Usenet.nl.) C:\Program Files (x86)\Usenet.nl\Usenet.nl.exe
O4 - GS\Desktop [marc-]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Marc\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [marc-]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Marc\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\Quicklaunch [marc-]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [marc-]: Mail.Ru.lnk . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) C:\Windows\System32\rundll32.exe url,FileProtocolHandler "http://www.mail.ru/ =>..Microsoft Corporation
O4 - GS\Quicklaunch [marc-]: Microsoft Outlook.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Microsoft Office\Office16\OUTLOOK.EXE /recycle =>.Microsoft Corporation
O4 - GS\Quicklaunch [marc-]: Stellar OST to PST Converter.lnk . (.Stellar Information Technology Pvt. Ltd. - Stellar OST to PST Converter.) C:\Program Files\Stellar OST to PST Converter\ost2pstf.exe {6BC1299F176C6D5EEA46A0EAEC3899A9} =>.Stellar Information Technology Pvt. Ltd.
O4 - GS\Quicklaunch [marc-]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Marc\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [marc-]: Destinataire de télécopie.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\System32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [marc-]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [marc-]: Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [marc-]: Excel 2016 (2).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.57D52F1E.F0D3.4F58.8F76.E727437CB7A9.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [marc-]: Excel 2016 (3).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.57D52F1E.F0D3.4F58.8F76.E727437CB7A9.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [marc-]: Excel 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.57D52F1E.F0D3.4F58.8F76.E727437CB7A9.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [marc-]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [marc-]: Le VPN.lnk . (...) C:\WINDOWS\Installer\{345A5CBC-C4E2-455D-AA2B-DF6446AC5C1D}\LeVPN.exe
O4 - GS\TaskBar [marc-]: Microsoft Money.lnk . (.Microsoft Corp. - Microsoft Money.) C:\Program Files (x86)\Microsoft Money\System\msmoney.exe =>.Microsoft Corp.
O4 - GS\TaskBar [marc-]: Outlook 2016 (2).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.7E3E9021.9723.4BFF.BACD.087B95A4CC01.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [marc-]: Outlook 2016 (3).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.7E3E9021.9723.4BFF.BACD.087B95A4CC01.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [marc-]: Outlook 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.7E3E9021.9723.4BFF.BACD.087B95A4CC01.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [marc-]: Word 2016 (2).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.40BB677D.0A7A.4D43.9F72.5AE6F0E97EE2.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [marc-]: Word 2016 (3).lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.40BB677D.0A7A.4D43.9F72.5AE6F0E97EE2.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [marc-]: Word 2016.lnk . (...) C:\WINDOWS\Installer\{90160000-0011-0000-1000-0000000FF1CE}\Icon.40BB677D.0A7A.4D43.9F72.5AE6F0E97EE2.exe =>.Microsoft Corporation®
O4 - GS\Programs [marc-]: Fonctionnalités optionnelles.lnk . (.Microsoft Corporation - Assistance des fonctionnalités à la demande.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Programs [marc-]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Marc\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\CommonDesktop [Public]: Acrobat Reader DC.lnk . (.Adobe Systems Incorporated - Adobe Acrobat Reader DC.) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe =>.Adobe Systems, Incorporated®
O4 - GS\CommonDesktop [Public]: Canon Quick Menu.lnk . (.CANON INC. - Canon Quick Menu.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE =>.Canon Inc.®
O4 - GS\CommonDesktop [Public]: Canon TS5000 series Manuel à l'écran.lnk . (...) C:\Program Files\Canon\IJ Manual\TS5000 series\French\CDM\Top.html
O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Ltd - CCleaner.) C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - GS\CommonDesktop [Public]: Clean Master.lnk . (.Kingsoft Corporation - Clean Master.) C:\Program Files (x86)\cmcm\Clean Master\kcleaner.exe -src:2 =>.Beijing Kingsoft Security software Co.,Ltd®
O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\CommonDesktop [Public]: Google Earth Pro.lnk . (.Google - Google Earth.) C:\Program Files (x86)\Google\Google Earth Pro\client\googleearth.exe =>.Google Inc®
O4 - GS\CommonDesktop [Public]: Le VPN.lnk . (...) C:\WINDOWS\Installer\{345A5CBC-C4E2-455D-AA2B-DF6446AC5C1D}\LeVPN.exe
O4 - GS\CommonDesktop [Public]: McAfee LiveSafe.lnk . (.McAfee, Inc. - .) C:\Program Files (x86)\Common Files\McAfee\Platform\McUICnt.exe /desktopicon /platui =>.McAfee, Inc.
O4 - GS\CommonDesktop [Public]: Microsoft Money.lnk . (.Microsoft Corp. - Microsoft Money.) C:\Program Files (x86)\Microsoft Money\System\msmoney.exe =>.Microsoft Corp.
O4 - GS\CommonDesktop [Public]: True Key.lnk . (.Intel Security - .) C:\Program Files (x86)\Intel Security\True Key\application\truekey.exe --open-source=dtopicon =>.Intel Security
O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe =>.VideoLAN®
O4 - GS\Programs [Public]: Fonctionnalités optionnelles.lnk . (.Microsoft Corporation - Assistance des fonctionnalités à la demande.) C:\Windows\System32\fodhelper.exe =>.Microsoft Corporation
O4 - GS\Programs [Public]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\Marc\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation®
O4 - GS\Accessories [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Bloc-notes.) C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\WINDOWS\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Quick Assist.lnk . (.Microsoft Corporation - Quick Assist.) C:\WINDOWS\system32\quickassist.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Connexion Bureau à distance.) C:\WINDOWS\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Outil Capture d’écran.) C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Enregistreur d’actions.) C:\WINDOWS\system32\psr.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Application Windows Wordpad.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: XPS Viewer.lnk . (.Microsoft Corporation - Visionneuse XPS.) C:\WINDOWS\system32\xpsrchvw.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Table des caractères.) C:\WINDOWS\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Acrobat Reader DC.lnk . (.Flexera Software LLC - InstallShield.) C:\WINDOWS\Installer\{AC76BA86-7AD7-1036-7B44-AC0F074E4100}\SC_Reader.ico =>.Flexera Software LLC
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\ProgramsCommon [Public]: Google Earth Pro.lnk . (.Google - Google Earth.) C:\Program Files (x86)\Google\Google Earth Pro\client\googleearth.exe =>.Google Inc®
O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\WINDOWS\System32\Control.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Microsoft Money.lnk . (.Microsoft Corp. - Microsoft Money.) C:\Program Files (x86)\Microsoft Money\System\msmoney.exe =>.Microsoft Corp.
O4 - GS\ProgramsCommon [Public]: MiracastView.lnk . (.Microsoft Corporation - MiracastView.) C:\WINDOWS\MiracastView\MiracastView.exe =>.Microsoft Windows®
O4 - GS\ProgramsCommon [Public]: PrintDialog.lnk . (.Microsoft Corporation - Print Dialog.) C:\WINDOWS\PrintDialog\PrintDialog.exe =>.Microsoft Windows®
O4 - GS\ProgramsCommon [Public]: True Key.lnk . (.Intel Security - .) C:\Program Files (x86)\Intel Security\True Key\application\truekey.exe --open-source=startmenu =>.Intel Security

---\\ Modification Domaine/Adresses DNS (4) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.254 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{12E92534-F051-41D0-8A72-958F884F3750}: NameServer = 8.8.4.4 8.8.8.8 =>.France Google Cloud
O17 - HKLM\System\CCS\Services\Tcpip\..\{542B0680-9CFC-462B-957D-5881DAA2EA8A}: NameServer = 8.8.4.4 8.8.8.8 =>.France Google Cloud
O17 - HKLM\System\CCS\Services\Tcpip\..\{5ec628f8-f696-411e-8aef-0be028303adf}: DhcpNameServer = 192.168.0.254 =>.Local IP Adress

---\\ Protocole additionnel (27) - 1s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\syswow64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\syswow64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\syswow64\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\syswow64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\syswow64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\syswow64\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\syswow64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\syswow64\itss.dll =>.Microsoft Corporation
O18 - Handler: mso-minsb.16 [64Bits] - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} . (.Microsoft Corporation - Microsoft Office 2016 component.) -- C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL =>.Microsoft Corporation®
O18 - Handler: osf.16 [64Bits] - {5504BE45-A83B-4808-900A-3A5C36E7F77A} . (.Microsoft Corporation - Microsoft Office 2016 component.) -- C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL =>.Microsoft Corporation®
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\syswow64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: sacore [64Bits] - {5513F07E-936B-4E52-9B00-067394E91CC5} . (.McAfee, Inc. - WebAdvisor.) -- c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll =>.McAfee, Inc.®
O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\syswow64\tbauth.dll =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\syswow64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\syswow64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: windows.tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\syswow64\tbauth.dll =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\syswow64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\syswow64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-mfe-ipt [64Bits] - {3EF5086B-5478-4598-A054-786C45D75692} . (.McAfee, Inc. - McAfee MSC IE plugin DLL.) -- c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll =>.McAfee, Inc.®
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\syswow64\mscoree.dll =>.Microsoft Corporation
O18 - Filter: text/xml [64Bits] - {807583E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF.DLL =>.Microsoft Corporation®

---\\ Logiciels installés (53) - 18s
O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU][64Bits] -- uTorrent =>.BitTorrent Inc®
O42 - Logiciel: 7-Zip 16.04 (x64) - (.Igor Pavlov.) [HKLM][64Bits] -- 7-Zip =>.Igor Pavlov
O42 - Logiciel: 7-Zip 9.20 (x64 edition) - (.Igor Pavlov.) [HKLM][64Bits] -- {23170F69-40C1-2702-0920-000001000000} =>.Igor Pavlov
O42 - Logiciel: Adobe Acrobat Reader DC - Français - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1036-7B44-AC0F074E4100} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {25A60C59-0FDC-4D73-81F4-D4A6D4E0CB92} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe AIR =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Flash Player 27 PPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player PPAPI =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-0804-1033-1959-001824237067} =>.Adobe Systems Incorporated
O42 - Logiciel: Canon Easy-WebPrint EX - (.Canon Inc..) [HKLM][64Bits] -- Easy-WebPrint EX =>.Canon Inc.®
O42 - Logiciel: Canon IJ Scan Utility - (.Canon Inc..) [HKLM][64Bits] -- Canon_IJ_Scan_Utility =>.Canon Inc.®
O42 - Logiciel: Canon Inkjet Printer/Scanner/Fax Extended Survey Program - (.Canon Inc..) [HKLM][64Bits] -- CANONIJPLM100 =>.Canon Inc.®
O42 - Logiciel: Canon My Image Garden - (.Canon Inc..) [HKLM][64Bits] -- Canon My Image Garden =>.Canon Inc.®
O42 - Logiciel: Canon My Image Garden Design Files - (.Canon Inc..) [HKLM][64Bits] -- Canon My Image Garden Design Files =>.Canon Inc.®
O42 - Logiciel: Canon Quick Menu - (.Canon Inc..) [HKLM][64Bits] -- CanonQuickMenu =>.Canon Inc.®
O42 - Logiciel: Canon TS5000 series Manuel à l'écran - (.Canon Inc..) [HKLM][64Bits] -- Canon TS5000 series Manuel à l'écran =>.Canon Inc.®
O42 - Logiciel: Canon TS5000 series MP Drivers - (.Canon Inc..) [HKLM][64Bits] -- {1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_TS5000_series =>.Canon Inc.®
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>.Piriform Ltd®
O42 - Logiciel: Clean Master - (.Cheetah Mobile.) [HKLM][64Bits] -- Clean Master =>.Beijing Kingsoft Security software Co.,Ltd®
O42 - Logiciel: Enregistrement utilisateur de Canon TS5000 series - (.‭Canon Inc..) [HKLM][64Bits] -- Enregistrement utilisateur de Canon TS5000 series =>.Canon Inc.®
O42 - Logiciel: Extension Système de Microsoft Money - (.Microsoft.) [HKLM][64Bits] -- {8C64E149-54BA-11D6-91B1-00500462BE80} =>.Microsoft
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome =>.Google Inc®
O42 - Logiciel: Google Earth Pro - (.Google.) [HKLM][64Bits] -- {ECF2E224-42F5-4E50-B58E-94CA70E85697} =>.Google
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: Intel Security True Key - (.Intel Security.) [HKLM][64Bits] -- TrueKey =>.McAfee, Inc.®
O42 - Logiciel: Intel® RealSense™ SDK 2014 Runtime (x64): Core - (.Intel Corporation.) [HKLM][64Bits] -- {37D41A97-6B02-4C30-8753-85107BE1D674} =>.Intel Corporation
O42 - Logiciel: Le VPN - (.VTNV Solutions Ltd.) [HKLM][64Bits] -- {a64cf886-c5f7-4b42-96ea-e75dea998fb3} {275411C316A74985D5B9E8B3A1FC820A}
O42 - Logiciel: Le VPN - (.VTNV Solutions Ltd..) [HKLM][64Bits] -- {345A5CBC-C4E2-455D-AA2B-DF6446AC5C1D}
O42 - Logiciel: McAfee LiveSafe - (.McAfee, Inc..) [HKLM][64Bits] -- MSC =>.McAfee, Inc.®
O42 - Logiciel: McAfee WebAdvisor - (.McAfee, Inc..) [HKLM][64Bits] -- {35ED3F83-4BDC-4c44-8EC6-6A8301C7413A} =>.McAfee, Inc.®
O42 - Logiciel: Microsoft Access MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0015-040C-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft DCF MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0090-040C-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Excel MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0016-040C-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Groove MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-00BA-040C-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft InfoPath MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0044-040C-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Money - (.Microsoft.) [HKLM][64Bits] -- {1D643CD0-4DD6-11D7-A4E0-000874180BB3} =>.Microsoft
O42 - Logiciel: Microsoft OneDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- OneDriveSetup.exe =>.Microsoft Corporation®
O42 - Logiciel: Microsoft OneNote MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-00A1-040C-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Outlook MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001A-040C-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft PowerPoint MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0018-040C-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Publisher MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-0019-040C-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Skype for Business MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-012B-040C-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Word MUI (French) 2016 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-001B-040C-1000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: MKV Player 2.1.23 - (..) [HKLM][64Bits] -- MKV Player_is1
O42 - Logiciel: NVIDIA Install Application - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer =>.NVIDIA Corporation
O42 - Logiciel: Panneau de configuration NVIDIA 376.54 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel =>.NVIDIA Corporation
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp®
O42 - Logiciel: Security Update for Skype for Business 2016 (KB3115408) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-00C1-0000-1000-0000000FF1CE}_Office16.PROPLUS_{C5C666D0-D5BD-4FE8-BE51-938926DC58E1} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Skype for Business 2016 (KB4011040) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-0011-0000-1000-0000000FF1CE}_Office16.PROPLUS_{D57DBD71-B426-45C4-9B1D-6347DE27B73D} =>.Microsoft Corporation®
O42 - Logiciel: Security Update for Skype for Business 2016 (KB4011040) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90160000-012B-040C-1000-0000000FF1CE}_Office16.PROPLUS_{D57DBD71-B426-45C4-9B1D-6347DE27B73D} =>.Microsoft Corporation®
O42 - Logiciel: Stellar OST to PST Converter - (.Stellar Information Technology Pvt. Ltd..) [HKLM][64Bits] -- Stellar OST to PST Converter_is1 =>.Stellar Information Technology Pvt. Ltd.
O42 - Logiciel: Stellar Phoenix Windows Data Recovery - Home - (.Stellar Information Technology Pvt Ltd..) [HKLM][64Bits] -- Stellar Phoenix Windows Data Recovery - Home_is1 =>.Stellar Information Technology Pvt Ltd.
O42 - Logiciel: Usenet.nl - (..) [HKLM][64Bits] -- Usenet.nl_is1 =>.TangySoft Ltd.®
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN

---\\ HKCU & HKLM Software Keys (65) - 18s
HKLM\SOFTWARE\Wow6432Node\Adobe =>.Adobe
HKLM\SOFTWARE\Wow6432Node\AMD =>.AMD
HKLM\SOFTWARE\Wow6432Node\Applogon =>.Unknown
HKLM\SOFTWARE\Wow6432Node\CANON =>.Canon
HKLM\SOFTWARE\Wow6432Node\Canon_Inc_IC =>.Canon Inc.
HKLM\SOFTWARE\Wow6432Node\cmcm =>.Cheetah Mobile
HKLM\SOFTWARE\Wow6432Node\Google =>.Google
HKLM\SOFTWARE\Wow6432Node\Intel =>.Intel
HKLM\SOFTWARE\Wow6432Node\Intel Security =>.Intel Security
HKLM\SOFTWARE\Wow6432Node\Khronos =>.Khronos
HKLM\SOFTWARE\Wow6432Node\Licenses =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\LogMeIn Rescue =>.LogMeIn Entreprise
HKLM\SOFTWARE\Wow6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\Wow6432Node\McAfee =>.McAfee Inc.
HKLM\SOFTWARE\Wow6432Node\McAfee.com =>.McAfee Inc.
HKLM\SOFTWARE\Wow6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\Nuance =>.Nuance
HKLM\SOFTWARE\Wow6432Node\NVIDIA Corporation =>.nVidia Corporation
HKLM\SOFTWARE\Wow6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\Wow6432Node\OldTimer Tools =>.OldTimer Tools
HKLM\SOFTWARE\Wow6432Node\Orange =>.Orange
HKLM\SOFTWARE\Wow6432Node\Piriform =>.Piriform
HKLM\SOFTWARE\Wow6432Node\PowerPivot =>.PowerPivot
HKLM\SOFTWARE\Wow6432Node\SiteAdvisor =>.McAfee Inc.
HKLM\SOFTWARE\Wow6432Node\Stellar Data Recovery =>.Stellar Systems
HKLM\SOFTWARE\Wow6432Node\TrueKey =>.Intel Corporation
HKLM\SOFTWARE\Wow6432Node\VideoLAN =>.VideoLAN
HKLM\SOFTWARE\Wow6432Node\Wondershare =>.Wondershare
HKLM\SOFTWARE\Wow6432Node\WOW6432Node =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\7-Zip =>.Igor Pavlov
HKCU\SOFTWARE\Adobe =>.Adobe
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\BCGP AppWizard-Generated Applications
HKCU\SOFTWARE\BitTorrent
HKCU\SOFTWARE\Canon =>.Canon
HKCU\SOFTWARE\Chromium =>.Chromium
HKCU\SOFTWARE\cmcm =>.Cheetah Mobile
HKCU\SOFTWARE\ESET =>.ESET
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\Intel Security =>.Intel Security
HKCU\SOFTWARE\kde.org =>.kde.org
HKCU\SOFTWARE\Le VPN
HKCU\SOFTWARE\McAfee =>.McAfee Inc.
HKCU\SOFTWARE\Mirage =>.Mirage Game
HKCU\SOFTWARE\Netscape =>.Netscape
HKCU\SOFTWARE\nuevos-programas.com =>PUP.Optional.Generic
HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKCU\SOFTWARE\Piriform =>.Piriform
HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKCU\SOFTWARE\Redemption =>.Legitimate
HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\Stellar Data Recovery =>.Stellar Systems
HKCU\SOFTWARE\SyncEngines =>.Microsoft Corporation
HKCU\SOFTWARE\Trolltech =>.Trolltech
HKCU\SOFTWARE\TrueKey =>.Intel Corporation
HKCU\SOFTWARE\Video Player
HKCU\SOFTWARE\VTNV Solutions Ltd.
HKCU\SOFTWARE\WinRAR SFX =>.RarLab
HKCU\SOFTWARE\WOW6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKCU\SOFTWARE\AppDataLow\Software\Canon =>.Canon
HKCU\SOFTWARE\AppDataLow\Software\PasswordBox =>.PasswordBox Inc

---\\ Contenu des dossiers Programmes (194) - 22s
O43 - CFD: 19/06/2017 - [] AD -- C:\Program Files\7-Zip =>.Igor Pavlov
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files\Canon =>.Canon Inc.®
O43 - CFD: 24/05/2017 - [] HD -- C:\Program Files\CanonBJ =>.Canon Inc.
O43 - CFD: 22/06/2017 - [] AD -- C:\Program Files\CCleaner =>.Piriform Ltd
O43 - CFD: 29/05/2017 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [0] SHD -- C:\Program Files\Fichiers communs =>.Microsoft Corporation
O43 - CFD: 29/05/2017 - [] D -- C:\Program Files\Intel Security =>.Intel Corporation
O43 - CFD: 14/09/2017 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 03/07/2017 - [] AD -- C:\Program Files\McAfee =>.McAfee
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files\McAfee.com =>.McAfee Inc.
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files\Microsoft Analysis Services =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] AD -- C:\Program Files\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files\Microsoft SQL Server =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files\Realtek =>.Realtek
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 12/06/2017 - [] AD -- C:\Program Files\Stellar OST to PST Converter =>.Stellar Systems
O43 - CFD: 18/08/2017 - [] D -- C:\Program Files\TrueKey =>.Intel Corporation
O43 - CFD: 12/07/2017 - [] RD -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 14/09/2017 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 14/09/2017 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files\Windows Security =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] SHD -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 19/09/2017 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 31/05/2017 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Systems Incorporated®
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\Canon =>.Canon Inc.®
O43 - CFD: 22/06/2017 - [] D -- C:\Program Files (x86)\cmcm =>.Cheetah Mobile
O43 - CFD: 20/06/2017 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 23/08/2017 - [] D -- C:\Program Files (x86)\Google =>.Google Inc®
O43 - CFD: 14/09/2017 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 19/09/2017 - [] D -- C:\Program Files (x86)\McAfee =>.McAfee
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services =>.Microsoft Corporation
O43 - CFD: 03/06/2017 - [] AD -- C:\Program Files (x86)\Microsoft Money =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\Microsoft SQL Server =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] AD -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 27/07/2017 - [] AD -- C:\Program Files (x86)\MKV Player
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 18/09/2017 - [] AD -- C:\Program Files (x86)\Stellar Phoenix Windows Data Recovery =>.Stellar Systems
O43 - CFD: 24/05/2017 - [0] HD -- C:\Program Files (x86)\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 06/09/2017 - [] AD -- C:\Program Files (x86)\Usenet.nl =>.Usenet
O43 - CFD: 08/06/2017 - [] D -- C:\Program Files (x86)\VideoLAN =>.VideoLan Team
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\VTNV Solutions Ltd
O43 - CFD: 12/07/2017 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 14/09/2017 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 14/09/2017 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] SHD -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 20/06/2017 - [0] D -- C:\Program Files (x86)\Wondershare =>.Wondershare
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip =>.Igor Pavlov
O43 - CFD: 24/05/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 12/07/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 14/09/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon TS5000 series Manuel à l'écran
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities =>.Canon Inc.
O43 - CFD: 22/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd
O43 - CFD: 22/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clean Master =>.Cheetah Mobile
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Enregistrement utilisateur de Canon TS5000 series
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Le VPN
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee =>.McAfee
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 =>.Microsoft Corporation
O43 - CFD: 27/07/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKV Player
O43 - CFD: 20/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Orange =>.Orange
O43 - CFD: 24/05/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 12/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stellar OST to PST Converter =>.Stellar Systems
O43 - CFD: 20/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stellar Phoenix Windows Data Recovery - Home =>.Stellar Systems
O43 - CFD: 24/05/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 06/09/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Usenet.nl =>.Usenet
O43 - CFD: 08/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team
O43 - CFD: 31/05/2017 - [] D -- C:\ProgramData\Adobe =>.Adobe
O43 - CFD: 24/05/2017 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [0] SHD -- C:\ProgramData\Bureau =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\Canon =>.Canon
O43 - CFD: 24/05/2017 - [] HD -- C:\ProgramData\CanonBJ =>.Canon Inc.
O43 - CFD: 16/08/2017 - [] HD -- C:\ProgramData\CanonIJMIG =>.Canon Inc.
O43 - CFD: 04/09/2017 - [] D -- C:\ProgramData\CanonIJPLM =>.Canon Inc.
O43 - CFD: 24/05/2017 - [] HD -- C:\ProgramData\CanonIJQuickMenu =>.Canon Inc.
O43 - CFD: 03/06/2017 - [] HD -- C:\ProgramData\CanonIJScan =>.Canon Inc.
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\CanonIJWSpt =>.Canon Inc.
O43 - CFD: 22/06/2017 - [] D -- C:\ProgramData\cmcm =>.Cheetah Mobile
O43 - CFD: 24/05/2017 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 12/06/2017 - [] D -- C:\ProgramData\Downloaded Installations =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\Intel Security =>.Intel Corporation
O43 - CFD: 12/06/2017 - [] RASHD -- C:\ProgramData\Key-Base =>.Unknown
O43 - CFD: 22/06/2017 - [] D -- C:\ProgramData\Kingsoft =>.Kingosoft Technology Ltd
O43 - CFD: 06/09/2017 - [] D -- C:\ProgramData\McAfee =>.McAfee
O43 - CFD: 24/05/2017 - [0] SHD -- C:\ProgramData\Menu Démarrer =>.Microsoft Corporation
O43 - CFD: 19/07/2017 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 13/09/2017 - [] D -- C:\ProgramData\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\Microsoft OneDrive =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\Microsoft Toolkit =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [0] SHD -- C:\ProgramData\Modèles =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 06/06/2017 - [] D -- C:\ProgramData\Orange =>.Orange
O43 - CFD: 12/06/2017 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] AD -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [0] D -- C:\ProgramData\SoftwareDistribution =>.Microsoft Corporation
O43 - CFD: 19/09/2017 - [0] AD -- C:\ProgramData\TEMP =>.Microsoft Corporation
O43 - CFD: 29/05/2017 - [] D -- C:\ProgramData\TrueKey =>.Intel Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\USOPrivate =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\USOShared =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\VS Revo Group =>.VS Revo Group
O43 - CFD: 24/05/2017 - [] D -- C:\ProgramData\WindowsHolographicDevices =>.Microsoft Corporation
O43 - CFD: 12/06/2017 - [0] D -- C:\ProgramData\{3FE5AE9E-A2AF-C86C-0E73-A631AD097A5F}
O43 - CFD: 31/05/2017 - [] AD -- C:\Program Files (x86)\Common Files\Adobe =>.Adobe
O43 - CFD: 24/05/2017 - [] AD -- C:\Program Files (x86)\Common Files\Adobe AIR =>.Adobe Inc.
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\Common Files\McAfee =>.McAfee
O43 - CFD: 03/06/2017 - [] AD -- C:\Program Files (x86)\Common Files\Microsoft Shared =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 20/06/2017 - [] D -- C:\Program Files (x86)\Common Files\Wondershare =>.Wondershare
O43 - CFD: 31/05/2017 - [] D -- C:\Users\Marc\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 03/06/2017 - [] D -- C:\Users\Marc\AppData\Roaming\Canon =>.Canon
O43 - CFD: 29/05/2017 - [] D -- C:\Users\Marc\AppData\Roaming\Google =>.Google
O43 - CFD: 24/05/2017 - [] D -- C:\Users\Marc\AppData\Roaming\Le VPN
O43 - CFD: 24/05/2017 - [] D -- C:\Users\Marc\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 22/07/2017 - [] SD -- C:\Users\Marc\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Users\Marc\AppData\Roaming\NVIDIA =>.nVidia Corporation
O43 - CFD: 20/06/2017 - [] D -- C:\Users\Marc\AppData\Roaming\Skype =>.Skype
O43 - CFD: 29/06/2017 - [] D -- C:\Users\Marc\AppData\Roaming\Thinstall =>.VMare
O43 - CFD: 07/09/2017 - [] D -- C:\Users\Marc\AppData\Roaming\Usenet.nl =>.Usenet
O43 - CFD: 19/09/2017 - [] D -- C:\Users\Marc\AppData\Roaming\uTorrent
O43 - CFD: 19/09/2017 - [] D -- C:\Users\Marc\AppData\Roaming\vlc =>.VideoLan Team
O43 - CFD: 13/06/2017 - [] D -- C:\Users\Marc\AppData\Roaming\WinRAR =>.WinRAR
O43 - CFD: 19/09/2017 - [] D -- C:\Users\Marc\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 31/08/2017 - [] D -- C:\Users\Marc\AppData\Local\Adobe =>.Adobe
O43 - CFD: 24/05/2017 - [0] SHD -- C:\Users\Marc\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 31/05/2017 - [] D -- C:\Users\Marc\AppData\Local\Apps =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Users\Marc\AppData\Local\CEF =>.CEF
O43 - CFD: 24/05/2017 - [] D -- C:\Users\Marc\AppData\Local\Comms =>.Microsoft Corporation
O43 - CFD: 01/06/2017 - [] D -- C:\Users\Marc\AppData\Local\ConnectedDevicesPlatform =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [0] D -- C:\Users\Marc\AppData\Local\DBG =>.DBG
O43 - CFD: 08/09/2017 - [] D -- C:\Users\Marc\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 08/09/2017 - [] D -- C:\Users\Marc\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Users\Marc\AppData\Local\Google =>.Google
O43 - CFD: 24/05/2017 - [0] SHD -- C:\Users\Marc\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 29/05/2017 - [0] D -- C:\Users\Marc\AppData\Local\LogMeIn Rescue Applet =>.LogMeIn
O43 - CFD: 19/07/2017 - [] D -- C:\Users\Marc\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 25/07/2017 - [] D -- C:\Users\Marc\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Users\Marc\AppData\Local\MicrosoftEdge =>.Microsoft Corporation
O43 - CFD: 11/09/2017 - [] D -- C:\Users\Marc\AppData\Local\OfficeBSCache-MyComputer
O43 - CFD: 11/09/2017 - [] D -- C:\Users\Marc\AppData\Local\OfficeBSCache-OD-marc.balley@outlook.com
O43 - CFD: 15/09/2017 - [] D -- C:\Users\Marc\AppData\Local\Packages =>.Microsoft Corporation
O43 - CFD: 12/09/2017 - [0] D -- C:\Users\Marc\AppData\Local\PackageStaging =>.Apcera
O43 - CFD: 24/05/2017 - [] D -- C:\Users\Marc\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Users\Marc\AppData\Local\Publishers =>.Microsoft Corporation
O43 - CFD: 05/06/2017 - [] D -- C:\Users\Marc\AppData\Local\Recovery =>.Recovery Labs
O43 - CFD: 19/09/2017 - [] D -- C:\Users\Marc\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [0] SHD -- C:\Users\Marc\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 29/06/2017 - [] D -- C:\Users\Marc\AppData\Local\Thinstall =>.VMare
O43 - CFD: 24/05/2017 - [] D -- C:\Users\Marc\AppData\Local\TileDataLayer =>.Microsoft Corporation
O43 - CFD: 28/07/2017 - [] D -- C:\Users\Marc\AppData\Local\tkdata =>.TK-Data
O43 - CFD: 03/06/2017 - [] D -- C:\Users\Marc\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 20/06/2017 - [] D -- C:\Users\Marc\AppData\Local\Wondershare =>.Wondershare
O43 - CFD: 19/09/2017 - [] D -- C:\Users\Marc\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 24/05/2017 - [0] D -- C:\Users\Marc\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] RD -- C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] RD -- C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 15/09/2017 - [] RD -- C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 24/05/2017 - [] D -- C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dashlane =>.Dashlane
O43 - CFD: 24/05/2017 - [] D -- C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP =>.Hewlett-Packard
O43 - CFD: 24/05/2017 - [] D -- C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 15/09/2017 - [] RD -- C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] RD -- C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] RD -- C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [0] D -- C:\Users\Default\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [0] D -- C:\Users\Default User\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 25/05/2017 - [0] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\DBG =>.DBG
O43 - CFD: 24/05/2017 - [] D -- C:\WINDOWS\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 24/05/2017 - [] -- C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Le VPN Service

---\\ ShellIconOverlayIdentifiers (SIOI) (9) - 1s
O106 - SIOI: ErrorOverlayHandler Class [ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Marc\AppData\Local\Microsoft\OneDrive\17.3.6966.0824\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SharedOverlayHandler Class [ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Marc\AppData\Local\Microsoft\OneDrive\17.3.6966.0824\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SharedSyncingOverlayHandler Class [ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Marc\AppData\Local\Microsoft\OneDrive\17.3.6966.0824\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: UpToDateOverlayHandler Class [ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Marc\AppData\Local\Microsoft\OneDrive\17.3.6966.0824\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: SyncingOverlayHandler Class [ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Marc\AppData\Local\Microsoft\OneDrive\17.3.6966.0824\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: ReadOnlyOverlayHandler Class [ OneDrive6] - {9AA2F32D-362A-42D9-9328-24A483E2CCC3}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Marc\AppData\Local\Microsoft\OneDrive\17.3.6966.0824\FileSyncShell.dll =>.Microsoft Corporation®
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) [ SkyDrivePro1 (ErrorConflict)] - {8BA85C75-763B-4103-94EB-9470F12FE0F7}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) [ SkyDrivePro2 (SyncInProgress)] - {CD55129A-B1A1-438E-A425-CEBC7DC684EE}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 3 (InSync) [ SkyDrivePro3 (InSync)] - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL =>.Microsoft Corporation®

---\\ Image File Execution Options (18) - 1s
O50 - IFEO:C:\Windows\System32\cscript.exe - (.Microsoft Corporation - Microsoft ® Console Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\dllhost.exe - (.Microsoft Corporation - COM Surrogate.) [DisableExceptionChainValidation\\3] =>.Microsoft Windows®
O50 - IFEO:C:\WINDOWS\System32\drvinst.exe - (.Microsoft Corporation - Module d’installation de pilotes.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\ie4uinit.exe - (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - Outil d’installation sans assistance d’IE 7.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mmc.exe - (.Microsoft Corporation - Microsoft Management Console.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\MRT.exe - (.Microsoft Corporation - Outil de suppression de logiciels malveilla.) [CFGOptions\\1] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Hôte des applications HTML de Microsoft(R).) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Windows Presentation Foundation Host.) [MitigationOptions\\1118481] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\PrintIsolationHost.exe - (.Microsoft Corporation - PrintIsolationHost.) [MitigationOptions\\2097152] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\rundll32.exe - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\\4294967296] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\searchprotocolhost.exe - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Application sous-système spouleur.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\WINDOWS\System32\spoolsv.exe - (.Microsoft Corporation - Application sous-système spouleur.) [MitigationOptions\\2097152] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\svchost.exe - (.Microsoft Corporation - Processus hôte pour les services Windows.) [MinimumStackCommitInBytes\\32768] =>.Microsoft Windows Publisher®
O50 - IFEO:C:\Windows\System32\wscript.exe - (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation

---\\ Liste des pilotes du système (72) - 23s
O58 - SDL:2017/03/18 22:56:25 N . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107424] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135512] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [83352] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259488] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [27040] =>.Microsoft Windows®
O58 - SDL:2012/11/30 08:31:00 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amd_sata.sys [80552] =>.Advanced Micro Devices, Inc.®
O58 - SDL:2012/11/30 08:31:02 A . (.Advanced Micro Devices - Stor Filter Driver.) -- C:\WINDOWS\System32\drivers\amd_xata.sys [26280] =>.Advanced Micro Devices, Inc.®
O58 - SDL:2017/03/18 22:56:25 N . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [132000] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [9728] =>.Windows (R) Win 7 DDK provider
O58 - SDL:2017/03/18 22:56:23 N . (.QLogic Corporation - QLogic Gigabit Ethernet VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [533920] =>.Microsoft Windows®
O58 - SDL:2017/06/26 09:25:56 A . (.McAfee, Inc. - McAfee Personal Firewall IDS Plugin.) -- C:\WINDOWS\System32\drivers\cfwids.sys [77800] =>.McAfee, Inc.®
O58 - SDL:2017/03/18 22:56:25 N . (.Chelsio Communications - Chelsio iSCSI Crash Dump Driver.) -- C:\WINDOWS\System32\drivers\cht4dx64.sys [102816] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Chelsio Communications - Chelsio iSCSI VMiniport Driver.) -- C:\WINDOWS\System32\drivers\cht4sx64.sys [347032] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Chelsio Communications - Virtual Bus Driver for Chelsio ® T4 Chipset.) -- C:\WINDOWS\System32\drivers\cht4vx64.sys [2104224] =>.Microsoft Windows®
O58 - SDL:2012/10/19 04:52:32 N . (.Windows (R) Win 7 DDK provider - IEEE-1284.4-1999 Driver.) -- C:\WINDOWS\System32\drivers\Dot4.sys [151968] =>.Hewlett-Packard Company®
O58 - SDL:2017/03/18 22:56:23 N . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3419040] =>.Microsoft Windows®
O58 - SDL:2017/08/07 22:43:26 A . (.McAfee, Inc. - McAfee HIP IPS Driver.) -- C:\WINDOWS\System32\drivers\HipShieldK.sys [209608] =>.McAfee, Inc.®
O58 - SDL:2017/03/18 22:56:25 N . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64416] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:28 N . (.Intel(R) Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iagpio.sys [33280] =>.Intel(R) Corporation
O58 - SDL:2017/03/18 22:56:28 N . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) -- C:\WINDOWS\System32\drivers\iai2c.sys [81408] =>.Intel(R) Corporation
O58 - SDL:2017/03/18 22:56:28 N . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [70656] =>.Intel Corporation
O58 - SDL:2017/03/18 22:56:28 N . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [85504] =>.Intel Corporation
O58 - SDL:2017/03/18 22:56:28 N . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [165376] =>.Intel Corporation
O58 - SDL:2017/03/18 22:56:28 N . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [168448] =>.Intel Corporation
O58 - SDL:2017/03/18 22:56:23 N . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] =>.Intel Corporation - Client Components Group®
O58 - SDL:2017/03/18 22:56:19 N . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [113152] =>.Intel Corporation
O58 - SDL:2017/03/18 22:56:26 N . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [673184] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:26 N . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412064] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [526240] =>.Microsoft Windows®
O58 - SDL:2017/06/22 19:22:46 A . (.Kingsoft Corporation - Kingsoft KSAPI Module.) -- C:\WINDOWS\System32\drivers\ksapi.sys [81768] =>.Beijing Kingsoft Security software Co.,Ltd®
O58 - SDL:2017/06/22 19:22:46 A . (.Kingsoft Corporation - Kingsoft KSAPI Module.) -- C:\WINDOWS\System32\drivers\ksapi64.sys [56680] =>.Beijing Kingsoft Security software Co.,Ltd®
O58 - SDL:2017/03/18 22:56:25 N . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [108960] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [123808] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [103328] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82848] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59808] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\MegaSas2i.sys [64416] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575904] =>.Microsoft Windows®
O58 - SDL:2017/06/26 09:25:56 A . (.McAfee, Inc. - McAfee Arbitrary Access Control Driver.) -- C:\WINDOWS\System32\drivers\mfeaack.sys [487408] =>.McAfee, Inc.®
O58 - SDL:2017/06/26 09:25:56 A . (.McAfee, Inc. - Anti-Virus File System Filter Driver.) -- C:\WINDOWS\System32\drivers\mfeavfk.sys [355312] =>.McAfee, Inc.®
O58 - SDL:2017/06/27 19:13:40 A . (.McAfee LLC. - McAfee Driver Cleaning Driver.) -- C:\WINDOWS\System32\drivers\mfeclnrk.sys [31192] =>.McAfee, Inc.®
O58 - SDL:2017/06/26 09:25:56 A . (.McAfee, Inc. - McAfee ELAM Driver.) -- C:\WINDOWS\System32\drivers\mfeelamk.sys [84544] =>.Microsoft Windows Early Launch Anti-malware Publisher®
O58 - SDL:2017/06/26 09:25:56 A . (.McAfee, Inc. - McAfee Core Firewall Engine Driver.) -- C:\WINDOWS\System32\drivers\mfefirek.sys [506352] =>.McAfee, Inc.®
O58 - SDL:2017/06/26 09:25:56 A . (.McAfee, Inc. - McAfee Link Driver.) -- C:\WINDOWS\System32\drivers\mfehidk.sys [933360] =>.McAfee, Inc.®
O58 - SDL:2017/06/27 19:13:40 A . (.McAfee LLC. - Event Driver.) -- C:\WINDOWS\System32\drivers\mfencbdc.sys [504792] =>.McAfee, Inc.®
O58 - SDL:2017/06/27 19:13:40 A . (.McAfee LLC. - Detection driver.) -- C:\WINDOWS\System32\drivers\mfencrk.sys [108504] =>.McAfee, Inc.®
O58 - SDL:2017/06/26 09:25:56 A . (.McAfee, Inc. - AAC Protected Launch Plugin Driver.) -- C:\WINDOWS\System32\drivers\mfeplk.sys [116208] =>.McAfee, Inc.®
O58 - SDL:2017/06/26 09:25:56 A . (.McAfee, Inc. - Anti-Virus Mini-Firewall Driver.) -- C:\WINDOWS\System32\drivers\mfewfpk.sys [253424] =>.McAfee, Inc.®
O58 - SDL:2017/03/18 22:56:25 N . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [842656] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63904] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [108960] =>.Microsoft Windows®
O58 - SDL:2017/01/25 19:12:28 A . (.NVIDIA Corporation - NVIDIA HDMI Audio Driver.) -- C:\WINDOWS\System32\drivers\nvhda64v.sys [221640] =>.NVIDIA Corporation®
O58 - SDL:2017/03/18 22:56:25 N . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150432] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [166304] =>.Microsoft Windows®
O58 - SDL:2017/01/25 19:13:18 A . (.NVIDIA Corporation - Stereoscopic 3D USB controller driver.) -- C:\WINDOWS\System32\drivers\nvstusb.sys [478272] =>.NVIDIA Corporation®
O58 - SDL:2017/03/18 22:56:25 N . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [58784] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [61848] =>.Microsoft Windows®
O58 - SDL:2013/03/19 12:47:24 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.30 64-bit Dr.) -- C:\WINDOWS\System32\drivers\Rt630x64.sys [792648] =>.Realtek Semiconductor Corp®
O58 - SDL:2017/05/17 04:23:30 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.40 64-bit Dr.) -- C:\WINDOWS\System32\drivers\rt640x64.sys [963056] =>.Realtek Semiconductor Corp.®
O58 - SDL:2013/03/12 15:12:24 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\WINDOWS\System32\drivers\RTKVHD64.sys [3346760] =>.Realtek Semiconductor Corp®
O58 - SDL:2012/12/21 09:41:42 A . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/V.) -- C:\WINDOWS\System32\drivers\RtsUStor.sys [258784] =>.Realtek Semiconductor Corp®
O58 - SDL:2017/03/18 22:56:26 N . (...) -- C:\WINDOWS\System32\drivers\SDFRd.sys [31128] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44960] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81824] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31136] =>.Microsoft Windows®
O58 - SDL:2017/03/30 10:34:12 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\WINDOWS\System32\drivers\tap0901.sys [27136] =>.The OpenVPN Project
O58 - SDL:2015/10/29 21:43:10 A . (.TP Microelectronic - TP TouchPad Filter Driver.) -- C:\WINDOWS\System32\drivers\tpfilter.sys [25928] =>.BYD precision manufacture company®
O58 - SDL:2012/08/28 14:27:24 A . (.Advanced Micro Devices - AMD USB Filter Driver.) -- C:\WINDOWS\System32\drivers\usbfilter.sys [58536] =>.Advanced Micro Devices, Inc.®
O58 - SDL:2017/03/18 22:56:25 N . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166816] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305568] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [32160] =>.Microsoft Windows®
O58 - SDL:2017/03/18 22:56:25 N . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [64920] =>.Microsoft Windows®

---\\ Associations Shell Spawning (10) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\WINDOWS\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\WINDOWS\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (...) -- %1" %*
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S

---\\ Menu de démarrage Internet (8) - 1s
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

---\\ Recherche d'infection sur les navigateurs (2) - 0s
O69 - SBI: SearchScopes [HKCU] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com

---\\ Enumère les services démarrés par Svchost (47) - 1s
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [189952] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [189952] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\WINDOWS\System32\srvsvc.dll [303104] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\WINDOWS\System32\gpsvc.dll [1269248] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\WINDOWS\System32\ikeext.dll [934912] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\WINDOWS\System32\iphlpsvc.dll [996864] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\WINDOWS\system32\seclogon.dll [31232] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\WINDOWS\System32\appinfo.dll [138752] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\WINDOWS\System32\iscsiexe.dll [150016] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\WINDOWS\System32\eapsvc.dll [108032] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\WINDOWS\System32\schedsvc.dll [877568] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\System32\wbem\WMIsvc.dll [221696] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\WINDOWS\System32\browser.dll [133120] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\WINDOWS\System32\profsvc.dll [413184] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\WINDOWS\System32\sessenv.dll [385536] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\WINDOWS\System32\wercplsupport.dll [93184] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\WINDOWS\System32\XboxNetApiSvc.dll [1067008] =>.Microsoft Corporation
O83 - Search Svchost Services: WpnService (WpnService) . (.Microsoft Corporation - Service du système de notifications Push Wi.) -- C:\WINDOWS\System32\WpnService.dll [276480] =>.Microsoft Corporation
O83 - Search Svchost Services: wisvc (wisvc) . (.Microsoft Corporation - Paramètres de vol.) -- C:\WINDOWS\System32\flightsettings.dll [699904] =>.Microsoft Corporation
O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\WINDOWS\System32\dmwappushsvc.dll [55296] =>.Microsoft Corporation
O83 - Search Svchost Services: TokenBroker (TokenBroker) . (.Microsoft Corporation - Token Broker.) -- C:\WINDOWS\System32\TokenBroker.dll [1052160] =>.Microsoft Corporation
O83 - Search Svchost Services: XboxGipSvc (XboxGipSvc) . (.Microsoft Corporation - Xbox Gip Management Service.) -- C:\WINDOWS\System32\XboxGipSvc.dll [18944] =>.Microsoft Corporation
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\WINDOWS\System32\DeviceSetupManager.dll [233984] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\WINDOWS\System32\themeservice.dll [69632] =>.Microsoft Corporation
O83 - Search Svchost Services: xbgm (xbgm) . (.Microsoft Corporation - Xbox Game Monitoring Service.) -- C:\WINDOWS\System32\xbgmsvc.dll [301216] =>.Microsoft Windows Publisher®
O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Service Configuration du réseau.) -- C:\WINDOWS\System32\NetSetupSvc.dll [261632] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\WINDOWS\System32\bdesvc.dll [385536] =>.Microsoft Corporation
O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\WINDOWS\System32\usermgr.dll [877568] =>.Microsoft Corporation
O83 - Search Svchost Services: shpamsvc (shpamsvc) . (.Microsoft Corporation - SharedPC.AccountManager.) -- C:\WINDOWS\System32\Windows.SharedPC.AccountManager.dll [192512] =>.Microsoft Corporation
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\WINDOWS\System32\ncasvc.dll [167424] =>.Microsoft Corporation
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\WINDOWS\System32\wlidsvc.dll [2153984] =>.Microsoft Corporation
O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\WINDOWS\System32\XblGameSave.dll [1135104] =>.Microsoft Corporation
O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - DLL Windows Management Service.) -- C:\WINDOWS\System32\Windows.Internal.Management.dll [536064] =>.Microsoft Corporation
O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\WINDOWS\System32\XblAuthManager.dll [1015296] =>.Microsoft Corporation
O83 - Search Svchost Services: NaturalAuthentication (NaturalAuthentication) . (.Microsoft Corporation - Service d’authentification naturelle.) -- C:\WINDOWS\System32\NaturalAuth.dll [723968] =>.Microsoft Corporation
O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Mettre à jour la session Orchestrator Core.) -- C:\WINDOWS\System32\usocore.dll [681984] =>.Microsoft Corporation
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service de géolocalisation.) -- C:\WINDOWS\System32\lfsvc.dll [43520] =>.Microsoft Corporation
O83 - Search Svchost Services: Irmon (Irmon) . (.Microsoft Corporation - Moniteur infrarouge.) -- C:\WINDOWS\System32\irmon.dll [24576] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\WINDOWS\System32\rasauto.dll [104448] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\WINDOWS\System32\rasmans.dll [874496] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\WINDOWS\System32\mprdim.dll [490496] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\WINDOWS\System32\sens.dll [69632] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\WINDOWS\System32\ipnathlp.dll [537600] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\WINDOWS\System32\tapisrv.dll [306688] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\WINDOWS\System32\wuaueng.dll [2445824] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\WINDOWS\System32\qmgr.dll [1159680] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\System32\shsvcs.dll [612864] =>.Microsoft Corporation

---\\ Liste des exceptions du parefeu Windows (2) - 3s
O87 - FAEL: "{1D97ADB4-1F10-4022-A7FF-D8E1242BF53F}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Orange\OrangeUpdate\Service\OUCore.exe (.not file.)
O87 - FAEL: "{280A2226-EF68-460B-B3A3-293A0BC8069A}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Orange\OrangeUpdate\Service\OUCore.exe (.not file.)

---\\ Scan Additionnel (1) - 6s
C:\WINDOWS\System32\Tasks\AutoKMS =>HackTool.AutoKMS

---\\ Récapitulatif des éléments trouvés sur votre station (2) - 0s
https://nicolascoolman.eu/2017/02/02/hacktool-autokms/ =>HackTool.AutoKMS
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.Generic

~ Unselected Options: O82,
~ End of the scan, 14337 items in 05mn05s (901)(0)

Publicité


Signaler le contenu de ce document

Publicité