~ ZHPDiag v2016.3.29.78 Par Nicolas Coolman (2016/03/29) ~ Démarré par Daz (Administrator) (2016/03/30 08:07:26) ~ Site: http://www.nicolascoolman.com ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Etat de la version: Version OK ~ Mode: Scanner ~ Rapport: C:\Users\Daz\Desktop\ZHPDiag.txt ~ Rapport: C:\Users\Daz\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Deactivate ~ Démarrage du système: Normal (Normal boot) Windows 8.1, 64-bit (Build 9600) ---\\ Navigateurs Internet (2) - 0s MFIE: Mozilla Firefox 46.0 (x86 fr) MSIE: Internet Explorer v11.0.9600.18231 ---\\ Informations sur les produits Windows (8) - 3s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK ~ Windows(R) Operating System, OEM_DM channel Windows ID Activation : OK ~ Windows Partial Key : W8CMG Windows License : OK ~ Windows Remaining Initializations Number : 1000 Windows Automatic Updates : OK ---\\ Logiciels de protection (1) - 2s Windows Defender (Deactivate) ---\\ Informations sur le système (6) - 0s ~ Operating System: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel ~ Operating System: 64-bit ~ Boot mode: Normal (Normal boot) Total RAM: 8278.296 MB (77% free) System Restore: Activé (Enable) System drive C: has 66 GB () free of 102 GB ---\\ Mode de connexion au système (3) - 0s ~ Computer Name: ANONYMOUS ~ User Name: Daz ~ Logged in as Administrator ---\\ Enumération des unités disques (6) - 0s ~ Drive B: has 40 GB free of 102 GB ~ Drive C: has 66 GB free of 102 GB (System) ~ Drive E: has 15 GB free of 20 GB ~ Drive F: has 192 GB free of 464 GB ~ Drive S: has 15 GB free of 20 GB ~ Drive T: has 1 GB free of 5 GB ---\\ Etat du Centre de Sécurité Windows (11) - 0s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ---\\ Recherche particulière de fichiers génériques (25) - 1s [MD5.B3541A5A20C6264781909B1B7FE54836] - 09/02/2016 - (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\Explorer.exe [2757616] =>.Microsoft Windows® [MD5.6C308D32AFA41D26CE2A0EA8F7B79565] - 21/11/2014 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe [54784] =>.Microsoft Corporation [MD5.EC302D06155F8E3C383750993FCB6B27] - 05/10/2015 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\System32\Wininit.exe [146432] =>.Microsoft Corporation [MD5.C15649DEABA6B45562009663673E23D1] - 08/02/2016 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [2597376] =>.Microsoft Corporation [MD5.B1102BBDDD9C87B3D609D6C08F7A3DBD] - 05/01/2016 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\Windows\System32\Winlogon.exe [570880] =>.Microsoft Corporation [MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - 21/11/2014 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [447488] =>.Microsoft Corporation [MD5.0B082D6D7A53D91678E7409DD145E89C] - 05/11/2014 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\System32\dnsapi.dll [657920] =>.Microsoft Corporation [MD5.205BDB00F4C032AF45A6BFD18EA7886C] - 05/11/2014 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\Syswow64\dnsapi.dll [498688] =>.Microsoft Corporation [MD5.E37F897ED7B5AFF79B1398258DB96BD9] - 21/11/2014 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [19456] =>.Microsoft Corporation [MD5.A460C3AF3755A2A79A3C8EFE72E147B5] - 13/10/2015 - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\Windows\System32\drivers\AFD.sys [559616] =>.Microsoft Corporation [MD5.74B14192CF79A72F7536B27CB8814FBD] - 22/08/2013 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [26464] =>.Microsoft Windows® [MD5.2FA6510E33F7DEFEC03658B74101A9B9] - 22/08/2013 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [88576] =>.Microsoft Corporation [MD5.C6796EA22B513E3457514D92DCDB1A3D] - 22/08/2013 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [164352] =>.Microsoft Corporation [MD5.A03F362C5557E238CBFA914689C77248] - 21/11/2014 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [134144] =>.Microsoft Corporation [MD5.D4B7ED39C7900384D9E5C1283F1E7926] - 21/11/2014 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [76800] =>.Microsoft Corporation [MD5.49EE0AE9E5B64FFBBD06D55C4984B598] - 04/11/2014 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [108544] =>.Microsoft Corporation [MD5.B7342B3C58E91107F6E946A93D9D4EFD] - 21/11/2014 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [142848] =>.Microsoft Corporation [MD5.61000E7155E92342D0D5338CE05D102A] - 10/01/2016 - (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\Windows\System32\drivers\MRxSmb.sys [401920] =>.Microsoft Corporation [MD5.0217532E19A748F0E5D569307363D5FD] - 22/08/2013 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [282624] =>.Microsoft Corporation [MD5.9980B262DBE439AE6BDC91AA985F19EE] - 30/12/2015 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [2017624] =>.Microsoft Windows® [MD5.764B1121867B2D9B31C491668AC72B2B] - 22/08/2013 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\Parport.sys [94208] =>.Microsoft Corporation [MD5.235624C147E3CB4C288D5D3D8E8D64A2] - 02/02/2016 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [112640] =>.Microsoft Corporation [MD5.680C1DAE268B6FB67FA21B389A8B79EF] - 21/11/2014 - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) -- C:\Windows\System32\drivers\rdpdr.sys [195584] =>.Microsoft Corporation [MD5.E0BD2D83875464FEEEB242CBA8B7E073] - 13/10/2015 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [108032] =>.Microsoft Corporation [MD5.D537962695CAFEC1301F3EB7C8C3A1D2] - 07/02/2016 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [316760] =>.Microsoft Windows® ---\\ Liste des services NT non Microsoft et non désactivés (9) - 1s O23 - Service: Avira Protection e-mail (AntiVirMailService) . (.Avira Operations GmbH & Co. KG - Antivirus MailScanner WFP Service.) - T:\Avira\Avira\Antivirus\avmailc7.exe =>.Avira Operations GmbH & Co. KG® O23 - Service: Avira Planificateur (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - T:\Avira\Avira\Antivirus\sched.exe =>.Avira Operations GmbH & Co. KG® O23 - Service: Avira Protection temps réel (AntiVirService) . (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - T:\Avira\Avira\Antivirus\avguard.exe =>.Avira Operations GmbH & Co. KG® O23 - Service: Avira Protection Web (AntiVirWebService) . (.Avira Operations GmbH & Co. KG - AntiVir WebGuard WFP Service.) - T:\Avira\Avira\Antivirus\avwebg7.exe =>.Avira Operations GmbH & Co. KG® O23 - Service: AOMEI Backupper Scheduler Service (Backupper Service) . (.AOMEI Tech Co., Ltd. - AOMEI Backupper Schedule task service.) - T:\Aomei PartitionPro\AOMEI Backupper\ABService.exe =>.ChengDu AoMei Tech Co., Ltd® O23 - Service: Malwarebytes Anti-Exploit Service (MbaeSvc) . (.Malwarebytes Corporation - Malwarebytes Anti-Exploit Service.) - C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe =>.Malwarebytes Corporation® O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - T:\Skype\Updater\Updater.exe =>.Skype Software Sarl® O23 - Service: TeamViewer 11 (TeamViewer) . (.TeamViewer GmbH - TeamViewer 11.) - T:\TeamViewer\TeamViewer_Service.exe =>.TeamViewer® O23 - Service: Unchecky (Unchecky) . (.RaMMicHaeL - Unchecky Service.) - T:\Unchecky\bin\unchecky_svc.exe =>.Reason Software Company Inc.® ---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (16) - 13s SS - Disabl [17/11/2009] [ 98208] Andrea RT Filters Service (AERTFilters) . (.Andrea Electronics Corporation.) - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe =>.Andrea Electronics® SS - Auto [22/02/2016] [ 955736] Avira Protection e-mail (AntiVirMailService) . (.Avira Operations GmbH & Co. KG.) - T:\Avira\Avira\Antivirus\avmailc7.exe =>.Avira Operations GmbH & Co. KG® SR - Auto [22/02/2016] [ 466504] Avira Planificateur (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG.) - T:\Avira\Avira\Antivirus\sched.exe =>.Avira Operations GmbH & Co. KG® SR - Auto [22/02/2016] [ 466504] Avira Protection temps réel (AntiVirService) . (.Avira Operations GmbH & Co. KG.) - T:\Avira\Avira\Antivirus\avguard.exe =>.Avira Operations GmbH & Co. KG® SR - Auto [22/02/2016] [ 1424880] Avira Protection Web (AntiVirWebService) . (.Avira Operations GmbH & Co. KG.) - T:\Avira\Avira\Antivirus\avwebg7.exe =>.Avira Operations GmbH & Co. KG® SR - Auto [15/09/2015] [ 29912] AOMEI Backupper Scheduler Service (Backupper Service) . (.AOMEI Tech Co., Ltd..) - T:\Aomei PartitionPro\AOMEI Backupper\ABService.exe =>.ChengDu AoMei Tech Co., Ltd® SS - Disabl [27/08/2015] [ 291744] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe =>.Intel Corporation - pGFX® SS - Disabl [08/07/2009] [ 30520] @oem16.inf,%hpservice_desc%;HP Service (hpsrv) . (.Hewlett-Packard.) - C:\Windows\System32\Hpservice.exe =>.Hewlett-Packard SS - Disabl [21/11/2013] [ 15720] Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe =>.Intel Corporation - Intel® Rapid Storage Technology® SS - Disabl [27/08/2015] [ 330136] Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) . (.Intel Corporation.) - C:\Windows\System32\igfxCUIService.exe =>.Intel Corporation SR - Auto [29/01/2016] [ 740832] Malwarebytes Anti-Exploit Service (MbaeSvc) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe =>.Malwarebytes Corporation® SS - Disabl [22/05/2015] [ 294616] Realtek Audio Service (RtkAudioService) . (.Realtek Semiconductor.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe =>.Realtek Semiconductor Corp® SS - Auto [23/03/2016] [ 327808] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - T:\Skype\Updater\Updater.exe =>.Skype Software Sarl® SR - Auto [02/03/2016] [ 6942480] TeamViewer 11 (TeamViewer) . (.TeamViewer GmbH.) - T:\TeamViewer\TeamViewer_Service.exe =>.TeamViewer® SR - Auto [20/03/2016] [ 254904] Unchecky (Unchecky) . (.RaMMicHaeL.) - T:\Unchecky\bin\unchecky_svc.exe =>.Reason Software Company Inc.® ---\\ Tâches planifiées en automatique (9) - 3s [MD5.74518A2233AC066064058A3F0E30E1E1] [APT] [BDAntiCryptoWallTask] (...) -- C:\Program Files\Bitdefender\Tools\BDAntiRansomware\BDAntiRansomware.exe [1280632] (.Activate.) =>.Bitdefender SRL® [MD5.4654B14F6E7CD4C70892F3017F5FDF0C] [APT] [GlaryInitialize] (.Glarysoft Ltd.) -- T:\GlaryUtilities\Glary Utilities\initialize.exe [92448] (.Activate.) =>.Glarysoft Ltd® [MD5.90453DA9C3E44D3A6C36397CB2F924E4] [APT] [GlaryOneClickOptimizer] (.Glarysoft Ltd.) -- T:\GlaryUtilities\Glary Utilities\oneclickoptimizer.exe [365856] (.Activate.) =>.Glarysoft Ltd® [MD5.72AD9BA10CF146B025FA77315C3B3D8C] [APT] [Auslogics\] (.Auslogics.) -- T:\Auslogics\Auslogics Disk Defrag\DiskDefrag.exe [1233224] (.Activate.) =>.Auslogics Software Pty Ltd® O39 - APT: GlaryInitialize - (.Glarysoft Ltd.) -- C:\Windows\Tasks\GlaryInitialize.job [330] =>.Glarysoft Ltd® O39 - APT: GlaryOneClickOptimizer - (.Glarysoft Ltd.) -- C:\Windows\Tasks\GlaryOneClickOptimizer.job [408] =>.Glarysoft Ltd® O39 - APT: BDAntiCryptoWallTask - (...) -- C:\Windows\System32\Tasks\BDAntiCryptoWallTask [3106] =>.Bitdefender SRL® O39 - APT: GlaryInitialize - (.Glarysoft Ltd.) -- C:\Windows\System32\Tasks\GlaryInitialize [2584] =>.Glarysoft Ltd® O39 - APT: GlaryOneClickOptimizer - (.Glarysoft Ltd.) -- C:\Windows\System32\Tasks\GlaryOneClickOptimizer [3288] =>.Glarysoft Ltd® ---\\ Processus lancés (21) - 1s [MD5.98C06275DB53A1E70AB8CB94013B20D4] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) -- T:\Avira\Avira\Antivirus\sched.exe [466504] [PID.1320] =>.Avira Operations GmbH & Co. KG® [MD5.74518A2233AC066064058A3F0E30E1E1] - (...) -- C:\Program Files\Bitdefender\Tools\BDAntiRansomware\BDAntiRansomware.exe [1280632] [PID.1520] =>.Bitdefender SRL® [MD5.889E56C58F5AC4242E395E3AD5F7780C] - (.IvoSoft - Classic Start Menu.) -- T:\ClassicShell\ClassicStartMenu.exe [161728] [PID.1796] =>.Ivaylo Beltchev® [MD5.98C06275DB53A1E70AB8CB94013B20D4] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) -- T:\Avira\Avira\Antivirus\avguard.exe [466504] [PID.1360] =>.Avira Operations GmbH & Co. KG® [MD5.7228CA6320ABA120DAAA69C740B73943] - (.AOMEI Tech Co., Ltd. - AOMEI Backupper Schedule task service.) -- T:\Aomei PartitionPro\AOMEI Backupper\ABService.exe [29912] [PID.1400] =>.ChengDu AoMei Tech Co., Ltd® [MD5.6761C5500F6A54BF31BA91F409234426] - (.Malwarebytes Corporation - Malwarebytes Anti-Exploit Service.) -- C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [740832] [PID.1764] =>.Malwarebytes Corporation® [MD5.DF31218C72DBF86A50F332B64C1CC3E1] - (.Malwarebytes Corporation - Malwarebytes Anti-Exploit 64bit tasks.) -- C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe [361440] [PID.2080] =>.Malwarebytes Corporation® [MD5.E9D702580349582413503A28F8329B32] - (.TeamViewer GmbH - TeamViewer 11.) -- T:\TeamViewer\TeamViewer_Service.exe [6942480] [PID.2456] =>.TeamViewer® [MD5.0C28A362D8A65795C44E1B06994B8981] - (.RaMMicHaeL - Unchecky Service.) -- T:\Unchecky\bin\unchecky_svc.exe [254904] [PID.2528] =>.Reason Software Company Inc.® [MD5.81829A75BF31F54FB619EF8E19840ED6] - (.RaMMicHaeL - Unchecky Background Process.) -- T:\Unchecky\bin\unchecky_bg.exe [569784] [PID.2708] =>.Reason Software Company Inc.® [MD5.10578A03586B8727D4B549351CAF4174] - (.Avira Operations GmbH & Co. KG - AntiVir shadow copy service.) -- T:\Avira\Avira\Antivirus\avshadow.exe [1036576] [PID.3056] =>.Avira Operations GmbH & Co. KG® [MD5.1F5CC3C23E10290A3FF9CAA74AA30D07] - (.Avira Operations GmbH & Co. KG - AntiVir WebGuard WFP Service.) -- T:\Avira\Avira\Antivirus\avwebg7.exe [1424880] [PID.1100] =>.Avira Operations GmbH & Co. KG® [MD5.BA00E1FCDD7FDCA70024BE182EB2C158] - (.PeerBlock, LLC - PeerBlock.) -- T:\PeerBlock\PeerBlock\peerblock.exe [2513992] [PID.3844] =>.PeerBlock, LLC® [MD5.235B72AF442823FF17751417DC904D15] - (.Malwarebytes Corporation - Malwarebytes Anti-Exploit.) -- C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2622432] [PID.3904] =>.Malwarebytes Corporation® [MD5.16615469CD17A7733CC181BD24BF2EDA] - (.QFX Software Corporation - KeyScrambler.) -- T:\KeyScrambler\KeyScrambler.exe [515600] [PID.3936] {1121AA63269A3F1D9DEE7412EC4CFEC18EED} =>.QFX Software Corporation [MD5.1CE11C53E562D5F7EAFCF47E0E696516] - (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- T:\Avira\Avira\Antivirus\avgnt.exe [807392] [PID.3972] =>.Avira Operations GmbH & Co. KG® [MD5.C847026D74385AD9BAD13D10104B7B16] - (.QFX Software Corporation - KeyScrambler.) -- T:\KeyScrambler\x64\KeyScrambler.exe [569360] [PID.4080] {1121AA63269A3F1D9DEE7412EC4CFEC18EED} =>.QFX Software Corporation [MD5.CD18C9B71AF5F5965568F3BCF0E1FEB4] - (.Mozilla Corporation - Thunderbird.) -- T:\Thunderbird\thunderbird.exe [491464] [PID.1840] =>.Mozilla Corporation® [MD5.47C5D8B646991D2BA9F2150A4C785D98] - (...) -- T:\Q-Bitorrent\qBittorrent\qbittorrent.exe [16470528] [PID.1440] [MD5.95A16F306C4478ECB4AC65C6A33CA431] - (.Mozilla Corporation - Firefox.) -- T:\Firefox\firefox.exe [392136] [PID.4384] =>.Mozilla Corporation® [MD5.F6DF107BFB4F60020A009B51EBBB15CA] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Daz\ZHPDiag3.exe [2168320] [PID.2840] =>.Nicolas Coolman ---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (13) - 2s M0 - MFSP: prefs.js [Daz - sboanbhh.default] http://www.orange.fr/portail P2 - EXT FILE: (...) -- C:\Users\Daz\AppData\Roaming\Mozilla\Firefox\Profiles\sboanbhh.default\extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi P2 - EXT FILE: (...) -- C:\Users\Daz\AppData\Roaming\Mozilla\Firefox\Profiles\sboanbhh.default\extensions\elemhidehelper@adblockplus.org.xpi P2 - EXT FILE: (...) -- C:\Users\Daz\AppData\Roaming\Mozilla\Firefox\Profiles\sboanbhh.default\extensions\faviconizetab@espion.just-size.jp.xpi P2 - EXT FILE: (...) -- C:\Users\Daz\AppData\Roaming\Mozilla\Firefox\Profiles\sboanbhh.default\extensions\trafficlight@bitdefender.com.xpi P2 - EXT FILE: (...) -- C:\Users\Daz\AppData\Roaming\Mozilla\Firefox\Profiles\sboanbhh.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi P2 - EXT FILE: (...) -- C:\Users\Daz\AppData\Roaming\Mozilla\Firefox\Profiles\sboanbhh.default\extensions\{79c50f9a-2ffe-4ee0-8a37-fae4f5dacd4f}.xpi P2 - EXT FILE: (...) -- C:\Users\Daz\AppData\Roaming\Mozilla\Firefox\Profiles\sboanbhh.default\extensions\{c0af4d2f-2ce4-9471-49e2-1e5ca8a57dd2}.xpi P2 - EXT FILE: (...) -- C:\Users\Daz\AppData\Roaming\Mozilla\Firefox\Profiles\sboanbhh.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi P2 - EXT FILE: (...) -- C:\Users\Daz\AppData\Roaming\Mozilla\Firefox\Profiles\sboanbhh.default\searchplugins\ixquick-https---francais.xml P2 - EXT FILE: (...) -- C:\Users\Daz\AppData\Roaming\Mozilla\Firefox\Profiles\sboanbhh.default\searchplugins\pc-astuces.xml P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll =>.Adobe Systems Incorporated P2 - FPN: [HKLM] [@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf] - (...) -- C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll ---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (17) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.fr R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.fr R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://google.fr R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?linkid=54896 R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?linkid=69157 R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?linkid=54896 R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://google.fr R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?linkid=69157 R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?linkid=54896 R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://google.fr R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?linkid=69157 R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?linkid=54896 R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 0 R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 0 ---\\ Internet Explorer,Proxy Management (6) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 ---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s F2 - REG:system.ini: UserInit=C:\Windows\System32\Userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation ---\\ Etude du fichier hosts (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (110) ---\\ Applications lancées au démarrage du système (6) - 0s O4 - HKLM\..\Run: [Classic Start Menu] . (.IvoSoft - Classic Start Menu.) -- T:\ClassicShell\ClassicStartMenu.exe =>.Ivaylo Beltchev® O4 - HKCU\..\Run: [PeerBlock] . (.PeerBlock, LLC - PeerBlock.) -- T:\PeerBlock\PeerBlock\peerblock.exe =>.PeerBlock, LLC® O4 - HKLM\..\Wow6432Node\Run: [Malwarebytes Anti-Exploit] . (.Malwarebytes Corporation - Malwarebytes Anti-Exploit.) -- C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe =>.Malwarebytes Corporation® O4 - HKLM\..\Wow6432Node\Run: [KeyScrambler] . (.QFX Software Corporation - KeyScrambler.) -- T:\KeyScrambler\keyscrambler.exe {1121AA63269A3F1D9DEE7412EC4CFEC18EED} =>.QFX Software Corporation O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- T:\Avira\Avira\Antivirus\avgnt.exe =>.Avira Operations GmbH & Co. KG® O4 - HKUS\S-1-5-21-3922014447-3414764430-3753204850-1001\..\Run: [PeerBlock] . (.PeerBlock, LLC - PeerBlock.) -- T:\PeerBlock\PeerBlock\peerblock.exe =>.PeerBlock, LLC® ---\\ Raccourcis Global Startup (33) - 3s O4 - GS\Desktop [Administrateur]: Data (P).lnk . (...) P:\ O4 - GS\Desktop [Administrateur]: Externe (E).lnk . (...) E:\ O4 - GS\Desktop [Administrateur]: Films (F).lnk . (...) F:\ O4 - GS\Desktop [Administrateur]: Gestion.lnk . (...) C:\Windows\system32\compmgmt.msc O4 - GS\Desktop [Administrateur]: P2P.lnk . (...) F:\P2P O4 - GS\Desktop [Administrateur]: Principal (C).lnk . (...) C:\ O4 - GS\Desktop [Administrateur]: Sauvegarde (S).lnk . (...) S:\ O4 - GS\Desktop [Administrateur]: Test (T).lnk . (...) T:\ O4 - GS\Desktop [Administrateur]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) C:\Users\Daz\ZHPCleaner.exe =>.Nicolas Coolman O4 - GS\Desktop [Administrateur]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Daz\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\sendTo [Administrateur]: Skype.lnk . (.Skype Technologies S.A. - Skype.) T:\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - GS\sendTo [Administrateur]: TeamViewer.lnk . (.TeamViewer GmbH - TeamViewer 11.) T:\TeamViewer\TeamViewer.exe =>.TeamViewer® O4 - GS\TaskBar [Administrateur]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) T:\Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\TaskBar [Administrateur]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) T:\Thunderbird\thunderbird.exe =>.Mozilla Corporation® O4 - GS\TaskBar [Administrateur]: qBittorrent.lnk . (...) T:\Q-Bitorrent\qBittorrent\qbittorrent.exe O4 - GS\TaskBar [Administrateur]: Skype.lnk . (.Skype Technologies S.A. - Skype.) T:\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - GS\Desktop [Daz]: Data (P).lnk . (...) P:\ O4 - GS\Desktop [Daz]: Externe (E).lnk . (...) E:\ O4 - GS\Desktop [Daz]: Films (F).lnk . (...) F:\ O4 - GS\Desktop [Daz]: Gestion.lnk . (...) C:\Windows\system32\compmgmt.msc O4 - GS\Desktop [Daz]: P2P.lnk . (...) F:\P2P O4 - GS\Desktop [Daz]: Principal (C).lnk . (...) C:\ O4 - GS\Desktop [Daz]: Sauvegarde (S).lnk . (...) S:\ O4 - GS\Desktop [Daz]: Test (T).lnk . (...) T:\ O4 - GS\Desktop [Daz]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) C:\Users\Daz\ZHPCleaner.exe =>.Nicolas Coolman O4 - GS\Desktop [Daz]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Daz\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\sendTo [Daz]: Skype.lnk . (.Skype Technologies S.A. - Skype.) T:\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - GS\sendTo [Daz]: TeamViewer.lnk . (.TeamViewer GmbH - TeamViewer 11.) T:\TeamViewer\TeamViewer.exe =>.TeamViewer® O4 - GS\TaskBar [Daz]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) T:\Firefox\firefox.exe =>.Mozilla Corporation® O4 - GS\TaskBar [Daz]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) T:\Thunderbird\thunderbird.exe =>.Mozilla Corporation® O4 - GS\TaskBar [Daz]: qBittorrent.lnk . (...) T:\Q-Bitorrent\qBittorrent\qbittorrent.exe O4 - GS\TaskBar [Daz]: Skype.lnk . (.Skype Technologies S.A. - Skype.) T:\Skype\Phone\Skype.exe =>.Skype Software Sarl® O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Ltd - CCleaner.) T:\CCleaner\CCleaner64.exe =>.Piriform Ltd® ---\\ Modification Domaine/Adresses DNS (4) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{C594A004-7E24-4332-A8B2-03AE8BBD83F2}: NameServer = 208.67.222.222,208.67.220.220 O17 - HKLM\System\CCS\Services\Tcpip\..\{73FCB2B8-51B4-4EC1-87F8-F862CA84338C}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{C594A004-7E24-4332-A8B2-03AE8BBD83F2}: DhcpNameServer = 192.168.1.1 192.168.1.1 ---\\ Protocole additionnel (22) - 1s O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\SysWOW64\inetcomm.dll =>.Microsoft Corporation O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: ms-help [64Bits] - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll =>.Microsoft Corporation® O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL =>.Microsoft Corporation® ---\\ Logiciels installés (30) - 6s O42 - Logiciel: Adobe Flash Player 21 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated® O42 - Logiciel: Avira Antivirus v15.0.16.282 - (.Avira Operations GmbH & Co. KG.) [HKLM][64Bits] -- Avira Antivirus =>.Avira Operations GmbH & Co. KG® O42 - Logiciel: AxCrypt 1.7.3156.0 - (.Axantum Software AB.) [HKLM][64Bits] -- {8B49CDB9-824C-44D6-A5D3-D0235D3030B8} =>.Axantum Software AB O42 - Logiciel: BDAntiRansomware - (.Bitdefender.) [HKLM][64Bits] -- {BE40AB1F-558F-4434-B72F-461EF97E7796}_is1 =>.BitDefender O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>.Piriform Ltd® O42 - Logiciel: Classic Shell - (.IvoSoft.) [HKLM][64Bits] -- {D4B3454F-7529-4F5F-851D-2C36933F7D64} =>.IvoSoft O42 - Logiciel: HP 3D DriveGuard - (.Hewlett-Packard.) [HKLM][64Bits] -- {C4324BAA-8D97-46CA-A317-3783EC16E334} =>.Hewlett-Packard O42 - Logiciel: HP Wireless Button Driver - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {941DE69D-6CEE-4171-8F1F-3D7E352AA498} =>.Hewlett-Packard Company O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} =>.Intel Corporation - pGFX® O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {27DEA29A-222C-45F8-B70D-0A7B303FC71B} =>.Intel Corporation O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {409CB30E-E457-4008-9B1A-ED1B9EA21140} =>.Intel Corporation O42 - Logiciel: KeyScrambler - (.QFX Software Corporation.) [HKLM][64Bits] -- KeyScrambler =>.QFX Software Corporation O42 - Logiciel: L-Calmens - (...) [HKCU][64Bits] -- L-Calmens O42 - Logiciel: Logiciel de base du périphérique HP Deskjet 3050A J611 series - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {2728177B-FBEC-415F-A9F5-83CD6CBD4816} =>.Hewlett-Packard Co. O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation O42 - Logiciel: MozBackup 1.5.1 - (.Pavel Cvrcek.) [HKLM][64Bits] -- MozBackup =>.Pavel Cvrcek O42 - Logiciel: Mozilla Firefox 46.0 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 46.0 (x86 fr) =>.Mozilla Corporation® O42 - Logiciel: Mozilla Thunderbird 45.0 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Thunderbird 45.0 (x86 fr) =>.Mozilla Corporation® O42 - Logiciel: qBittorrent 3.3.4 - (.The qBittorrent project.) [HKLM][64Bits] -- qBittorrent =>.The qBittorrent project O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp® O42 - Logiciel: Skype™ 7.22 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {FC965A47-4839-40CA-B618-18F486F042C6} =>.Skype Technologies S.A. O42 - Logiciel: Speccy - (.Piriform.) [HKLM][64Bits] -- Speccy =>.Piriform Ltd® O42 - Logiciel: SumatraPDF - (.Krzysztof Kowalczyk.) [HKLM][64Bits] -- SumatraPDF =>.Krzysztof Kowalczyk® O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey =>.Synaptics Incorporated O42 - Logiciel: TeamViewer 11 - (.TeamViewer.) [HKLM][64Bits] -- TeamViewer =>.TeamViewer® O42 - Logiciel: Unchecky v0.4.3 - (.RaMMicHaeL.) [HKLM][64Bits] -- Unchecky =>.Reason Software Company Inc.® O42 - Logiciel: Unlocker 1.9.2 - (.Cedrick Collomb.) [HKLM][64Bits] -- Unlocker =>.Cedrick Collomb O42 - Logiciel: Windows 7 Games for Windows 8 and 10 - (...) [HKLM][64Bits] -- MicrosoftGamesForWin8 O42 - Logiciel: WinRAR 5.30 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver =>.win.rar GmbH® O42 - Logiciel: ZebHelpProcess 2016 - (.Nicolas Coolman.) [HKLM][64Bits] -- ZebHelpProcess_is1 =>.Nicolas Coolman ---\\ HKCU & HKLM Software Keys (91) - 6s HKLM\SOFTWARE\Wow6432Node\AdwCleaner HKLM\SOFTWARE\Wow6432Node\AppDataLow HKLM\SOFTWARE\Wow6432Node\Apple Inc. HKLM\SOFTWARE\Wow6432Node\AskToolbar =>Toolbar.Ask HKLM\SOFTWARE\Wow6432Node\Avira HKLM\SOFTWARE\Wow6432Node\Borland HKLM\SOFTWARE\Wow6432Node\Canneverbe Limited HKLM\SOFTWARE\Wow6432Node\EaseUS HKLM\SOFTWARE\Wow6432Node\Freemake HKLM\SOFTWARE\Wow6432Node\GlarySoft HKLM\SOFTWARE\Wow6432Node\GNU HKLM\SOFTWARE\Wow6432Node\Google HKLM\SOFTWARE\Wow6432Node\HaaliMkx HKLM\SOFTWARE\Wow6432Node\Hewlett-Packard HKLM\SOFTWARE\Wow6432Node\HP HKLM\SOFTWARE\Wow6432Node\HPQ HKLM\SOFTWARE\Wow6432Node\IM Providers HKLM\SOFTWARE\Wow6432Node\Intel HKLM\SOFTWARE\Wow6432Node\Khronos HKLM\SOFTWARE\Wow6432Node\KLCodecPack HKLM\SOFTWARE\Wow6432Node\LAV HKLM\SOFTWARE\Wow6432Node\Macromedia HKLM\SOFTWARE\Wow6432Node\Malwarebytes Anti-Exploit HKLM\SOFTWARE\Wow6432Node\Malwarebytes Anti-Rootkit HKLM\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware HKLM\SOFTWARE\Wow6432Node\Mozilla HKLM\SOFTWARE\Wow6432Node\mozilla.org HKLM\SOFTWARE\Wow6432Node\MozillaPlugins HKLM\SOFTWARE\Wow6432Node\Nuance HKLM\SOFTWARE\Wow6432Node\ODBC HKLM\SOFTWARE\Wow6432Node\qBittorrent HKLM\SOFTWARE\Wow6432Node\QFX Software HKLM\SOFTWARE\Wow6432Node\Realtek HKLM\SOFTWARE\Wow6432Node\Skype HKLM\SOFTWARE\Wow6432Node\Synaptics HKLM\SOFTWARE\Wow6432Node\TeamViewer HKLM\SOFTWARE\Wow6432Node\Trolltech HKLM\SOFTWARE\Wow6432Node\Unchecky HKLM\SOFTWARE\Wow6432Node\Volatile HKLM\SOFTWARE\Wow6432Node\WinRAR HKLM\SOFTWARE\Wow6432Node\WiseCleaner HKLM\SOFTWARE\Wow6432Node\X-AVCSD HKLM\SOFTWARE\Wow6432Node\RegisteredApplications HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\Auslogics HKCU\SOFTWARE\Avira HKCU\SOFTWARE\Axantum HKCU\SOFTWARE\Bitdefender HKCU\SOFTWARE\Borland HKCU\SOFTWARE\Canneverbe Limited HKCU\SOFTWARE\CrystalIdea Software HKCU\SOFTWARE\EaseUS HKCU\SOFTWARE\EpmNewsInfo HKCU\SOFTWARE\Freemake HKCU\SOFTWARE\FreeSoftLand HKCU\SOFTWARE\GlarySoft HKCU\SOFTWARE\GNU HKCU\SOFTWARE\Haali HKCU\SOFTWARE\HP HKCU\SOFTWARE\HSWETS6UQr1PR HKCU\SOFTWARE\IM Providers HKCU\SOFTWARE\Intel HKCU\SOFTWARE\IvoSoft HKCU\SOFTWARE\Locky =>Ransomware.Locky HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\madshi HKCU\SOFTWARE\Mozilla HKCU\SOFTWARE\Mozilla Backup HKCU\SOFTWARE\MozillaPlugins HKCU\SOFTWARE\MPC-HC HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\ODBC HKCU\SOFTWARE\OVH HKCU\SOFTWARE\Piriform HKCU\SOFTWARE\QFX Software HKCU\SOFTWARE\QtProject HKCU\SOFTWARE\Realtek HKCU\SOFTWARE\RegisteredApplications HKCU\SOFTWARE\Skype HKCU\SOFTWARE\Synaptics HKCU\SOFTWARE\SysInternals HKCU\SOFTWARE\TeamViewer HKCU\SOFTWARE\Thunderbird HKCU\SOFTWARE\Tracker Software HKCU\SOFTWARE\UltimateOutsider HKCU\SOFTWARE\Unchecky HKCU\SOFTWARE\Winaero.com HKCU\SOFTWARE\WinRAR HKCU\SOFTWARE\Wow6432Node HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Software ---\\ Contenu des dossiers Programmes (170) - 7s O43 - CFD: 21/09/2015 - [] D -- C:\Program Files\Axantum =>.Axantum Software AB® O43 - CFD: 29/03/2016 - [] D -- C:\Program Files\Bitdefender =>.Bitdefender SRL® O43 - CFD: 25/03/2016 - [] D -- C:\Program Files\Common Files O43 - CFD: 21/09/2015 - [0] SHD -- C:\Program Files\Fichiers communs O43 - CFD: 22/09/2015 - [] D -- C:\Program Files\Hewlett-Packard =>.Hewlett-Packard Company® O43 - CFD: 03/03/2016 - [] D -- C:\Program Files\HP =>.Hewlett Packard® O43 - CFD: 24/09/2015 - [] D -- C:\Program Files\Intel =>.Intel Corporation - Intel® Rapid Storage Technology® O43 - CFD: 09/03/2016 - [] D -- C:\Program Files\Internet Explorer O43 - CFD: 10/02/2016 - [] D -- C:\Program Files\Microsoft Games O43 - CFD: 21/09/2015 - [] D -- C:\Program Files\Microsoft Office O43 - CFD: 10/02/2016 - [] D -- C:\Program Files\Microsoft Silverlight =>.Microsoft Corporation® O43 - CFD: 21/09/2015 - [] D -- C:\Program Files\MSBuild O43 - CFD: 04/10/2015 - [] D -- C:\Program Files\Realtek =>.Andrea Electronics® O43 - CFD: 21/09/2015 - [] D -- C:\Program Files\Reference Assemblies O43 - CFD: 21/09/2015 - [] D -- C:\Program Files\Synaptics =>.Synaptics Incorporated® O43 - CFD: 21/09/2015 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation® O43 - CFD: 10/02/2016 - [] D -- C:\Program Files\Windows Journal O43 - CFD: 21/11/2014 - [] D -- C:\Program Files\Windows Mail O43 - CFD: 21/11/2014 - [] D -- C:\Program Files\Windows Media Player O43 - CFD: 21/11/2014 - [] D -- C:\Program Files\Windows Multimedia Platform O43 - CFD: 21/09/2015 - [] D -- C:\Program Files\Windows NT O43 - CFD: 21/11/2014 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation® O43 - CFD: 21/11/2014 - [] D -- C:\Program Files\Windows Portable Devices O43 - CFD: 22/08/2013 - [] SHD -- C:\Program Files\Windows Sidebar O43 - CFD: 26/03/2016 - [] HD -- C:\Program Files\WindowsApps O43 - CFD: 21/11/2014 - [] D -- C:\Program Files\WindowsPowerShell O43 - CFD: 29/03/2016 - [] D -- C:\Program Files (x86)\Common Files O43 - CFD: 22/09/2015 - [] D -- C:\Program Files (x86)\Hewlett-Packard =>.Hewlett-Packard Company® O43 - CFD: 22/03/2016 - [] D -- C:\Program Files (x86)\HP {00AD4EEC891A671ADEC499C6A1BE34D9B0} O43 - CFD: 16/12/2015 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.Realtek Semiconductor Corp® O43 - CFD: 28/10/2015 - [] D -- C:\Program Files (x86)\Intel =>.Intel Corporation - pGFX® O43 - CFD: 19/03/2016 - [] D -- C:\Program Files (x86)\Internet Explorer O43 - CFD: 02/02/2016 - [] D -- C:\Program Files (x86)\Malwarebytes Anti-Exploit =>.Malwarebytes Corporation® O43 - CFD: 17/12/2015 - [] D -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation® O43 - CFD: 10/02/2016 - [] D -- C:\Program Files (x86)\Microsoft Silverlight =>.Microsoft Corporation® O43 - CFD: 21/09/2015 - [] D -- C:\Program Files (x86)\Microsoft.NET O43 - CFD: 21/09/2015 - [] D -- C:\Program Files (x86)\MSBuild O43 - CFD: 17/12/2015 - [] D -- C:\Program Files (x86)\MSECache O43 - CFD: 04/10/2015 - [] D -- C:\Program Files (x86)\Realtek =>.Realtek Semiconductor Corp® O43 - CFD: 21/09/2015 - [] D -- C:\Program Files (x86)\Reference Assemblies O43 - CFD: 28/03/2016 - [] D -- C:\Program Files (x86)\Skype =>.Skype Software Sarl® O43 - CFD: 04/10/2015 - [0] HD -- C:\Program Files (x86)\Temp O43 - CFD: 21/09/2015 - [] D -- C:\Program Files (x86)\Windows Defender O43 - CFD: 21/11/2014 - [] D -- C:\Program Files (x86)\Windows Mail O43 - CFD: 21/11/2014 - [] D -- C:\Program Files (x86)\Windows Media Player O43 - CFD: 21/11/2014 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Windows NT O43 - CFD: 21/11/2014 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation® O43 - CFD: 21/11/2014 - [] D -- C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 22/08/2013 - [] SHD -- C:\Program Files (x86)\Windows Sidebar O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\WindowsPowerShell O43 - CFD: 21/11/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 09/03/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 21/09/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 23/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOMEI Backupper O43 - CFD: 21/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics O43 - CFD: 25/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira O43 - CFD: 21/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Axantum AxCrypt O43 - CFD: 29/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BDAntiRansomware O43 - CFD: 10/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner O43 - CFD: 17/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell O43 - CFD: 23/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 10.8 O43 - CFD: 09/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake O43 - CFD: 22/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FSL O43 - CFD: 10/02/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 21/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities O43 - CFD: 03/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP O43 - CFD: 24/09/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel O43 - CFD: 21/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack O43 - CFD: 24/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeyScrambler O43 - CFD: 24/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit O43 - CFD: 19/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware O43 - CFD: 21/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office O43 - CFD: 09/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight O43 - CFD: 05/02/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniTool Power Data Recovery 7.0 O43 - CFD: 21/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozBackup O43 - CFD: 08/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeerBlock O43 - CFD: 30/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent O43 - CFD: 13/12/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype O43 - CFD: 18/01/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy O43 - CFD: 04/03/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp O43 - CFD: 21/11/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 21/11/2014 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 21/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unchecky O43 - CFD: 07/01/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 19/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Folder Hider O43 - CFD: 19/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP O43 - CFD: 27/03/2016 - [] D -- C:\ProgramData\AomeiBR O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 25/03/2016 - [] D -- C:\ProgramData\Avira O43 - CFD: 21/09/2015 - [0] SHD -- C:\ProgramData\Bureau O43 - CFD: 08/02/2016 - [] D -- C:\ProgramData\Canneverbe Limited O43 - CFD: 21/09/2015 - [] D -- C:\ProgramData\ClassicShell O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 09/03/2016 - [] D -- C:\ProgramData\Freemake O43 - CFD: 22/09/2015 - [] D -- C:\ProgramData\Hewlett-Packard O43 - CFD: 03/03/2016 - [] D -- C:\ProgramData\HP O43 - CFD: 24/09/2015 - [] D -- C:\ProgramData\Intel O43 - CFD: 03/01/2016 - [] D -- C:\ProgramData\Malwarebytes O43 - CFD: 30/03/2016 - [] D -- C:\ProgramData\Malwarebytes Anti-Exploit O43 - CFD: 21/09/2015 - [0] SHD -- C:\ProgramData\Menu Démarrer O43 - CFD: 11/11/2015 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 09/03/2016 - [] D -- C:\ProgramData\Microsoft Help O43 - CFD: 21/09/2015 - [0] SHD -- C:\ProgramData\Modèles O43 - CFD: 27/01/2016 - [] D -- C:\ProgramData\Package Cache O43 - CFD: 26/03/2016 - [] D -- C:\ProgramData\QFX Software O43 - CFD: 21/11/2014 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft O43 - CFD: 28/03/2016 - [0] D -- C:\ProgramData\Skype O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 28/03/2016 - [] D -- C:\ProgramData\Unchecky O43 - CFD: 12/10/2015 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER O43 - CFD: 05/01/2016 - [] D -- C:\Program Files (x86)\Common Files\Freemake Shared O43 - CFD: 28/10/2015 - [] D -- C:\Program Files (x86)\Common Files\Intel O43 - CFD: 24/09/2015 - [] D -- C:\Program Files (x86)\Common Files\Intel Corporation O43 - CFD: 12/10/2015 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Common Files\Services O43 - CFD: 24/03/2016 - [] D -- C:\Program Files (x86)\Common Files\Skype O43 - CFD: 21/11/2014 - [] D -- C:\Program Files (x86)\Common Files\System O43 - CFD: 17/12/2015 - [] D -- C:\Users\Daz\AppData\Roaming\Adobe O43 - CFD: 26/03/2016 - [] D -- C:\Users\Daz\AppData\Roaming\AnyDesk O43 - CFD: 21/09/2015 - [] D -- C:\Users\Daz\AppData\Roaming\Auslogics O43 - CFD: 25/03/2016 - [] D -- C:\Users\Daz\AppData\Roaming\Avira O43 - CFD: 21/09/2015 - [] D -- C:\Users\Daz\AppData\Roaming\Canneverbe Limited O43 - CFD: 21/09/2015 - [] D -- C:\Users\Daz\AppData\Roaming\ClassicShell O43 - CFD: 03/02/2016 - [] D -- C:\Users\Daz\AppData\Roaming\CrystalIdea Software O43 - CFD: 29/11/2015 - [] D -- C:\Users\Daz\AppData\Roaming\GlarySoft O43 - CFD: 24/09/2015 - [] D -- C:\Users\Daz\AppData\Roaming\Intel Corporation O43 - CFD: 27/03/2016 - [] D -- C:\Users\Daz\AppData\Roaming\Macromedia O43 - CFD: 19/02/2016 - [] SD -- C:\Users\Daz\AppData\Roaming\Microsoft O43 - CFD: 22/02/2016 - [] D -- C:\Users\Daz\AppData\Roaming\Mozilla O43 - CFD: 30/03/2016 - [] D -- C:\Users\Daz\AppData\Roaming\qBittorrent O43 - CFD: 26/03/2016 - [] D -- C:\Users\Daz\AppData\Roaming\QFX Software O43 - CFD: 28/03/2016 - [] D -- C:\Users\Daz\AppData\Roaming\Skype O43 - CFD: 21/09/2015 - [] D -- C:\Users\Daz\AppData\Roaming\SumatraPDF O43 - CFD: 29/03/2016 - [] D -- C:\Users\Daz\AppData\Roaming\TeamViewer O43 - CFD: 29/03/2016 - [] D -- C:\Users\Daz\AppData\Roaming\Thunderbird O43 - CFD: 23/09/2015 - [] D -- C:\Users\Daz\AppData\Roaming\WinRAR O43 - CFD: 30/03/2016 - [] D -- C:\Users\Daz\AppData\Roaming\ZHP O43 - CFD: 24/03/2016 - [0] D -- C:\Users\Daz\AppData\Local\Adobe O43 - CFD: 21/09/2015 - [0] SHD -- C:\Users\Daz\AppData\Local\Application Data O43 - CFD: 24/01/2016 - [] D -- C:\Users\Daz\AppData\Local\AxCrypt O43 - CFD: 30/03/2016 - [] D -- C:\Users\Daz\AppData\Local\ClassicShell O43 - CFD: 05/01/2016 - [] D -- C:\Users\Daz\AppData\Local\FreemakeVideoConverter O43 - CFD: 21/09/2015 - [0] SHD -- C:\Users\Daz\AppData\Local\Historique O43 - CFD: 03/03/2016 - [] D -- C:\Users\Daz\AppData\Local\HP O43 - CFD: 17/12/2015 - [] D -- C:\Users\Daz\AppData\Local\Macromedia O43 - CFD: 20/01/2016 - [] D -- C:\Users\Daz\AppData\Local\Microsoft O43 - CFD: 10/02/2016 - [] D -- C:\Users\Daz\AppData\Local\Microsoft Games O43 - CFD: 21/09/2015 - [0] D -- C:\Users\Daz\AppData\Local\Microsoft Help O43 - CFD: 06/01/2016 - [] D -- C:\Users\Daz\AppData\Local\Microsoft_Corporation O43 - CFD: 16/12/2015 - [] D -- C:\Users\Daz\AppData\Local\Mozilla O43 - CFD: 19/02/2016 - [] D -- C:\Users\Daz\AppData\Local\Package Cache O43 - CFD: 09/12/2015 - [] D -- C:\Users\Daz\AppData\Local\Packages O43 - CFD: 03/01/2016 - [] D -- C:\Users\Daz\AppData\Local\Programs O43 - CFD: 30/03/2016 - [] D -- C:\Users\Daz\AppData\Local\qBittorrent O43 - CFD: 15/03/2016 - [] D -- C:\Users\Daz\AppData\Local\TeamViewer O43 - CFD: 30/03/2016 - [] D -- C:\Users\Daz\AppData\Local\Temp O43 - CFD: 21/09/2015 - [0] SHD -- C:\Users\Daz\AppData\Local\Temporary Internet Files O43 - CFD: 24/01/2016 - [] D -- C:\Users\Daz\AppData\Local\Thunderbird O43 - CFD: 08/10/2015 - [] D -- C:\Users\Daz\AppData\Local\VirtualStore O43 - CFD: 21/11/2014 - [] RD -- C:\Users\Daz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 21/11/2014 - [] RD -- C:\Users\Daz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 21/03/2016 - [] RD -- C:\Users\Daz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 21/09/2015 - [] D -- C:\Users\Daz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake O43 - CFD: 21/03/2016 - [] RD -- C:\Users\Daz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 21/11/2014 - [] RD -- C:\Users\Daz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 21/09/2015 - [] D -- C:\Users\Daz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker O43 - CFD: 07/01/2016 - [] D -- C:\Users\Daz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR ---\\ ShellIconOverlayIdentifiers (SIOI) (1) - 0s O106 - SIOI: ShareOverlay Class [ShareOverlay] - {594D4122-1F87-41E2-96C7-825FB4796516}. (.IvoSoft - Adds classic Windows Explorer features.) -- T:\ClassicShell\ClassicExplorer32.dll =>.Ivaylo Beltchev® ---\\ Liste des pilotes du système (80) - 5s O58 - SDL:2013/08/22 14:43:41 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\drivers\3ware.sys [108896] =>.Microsoft Windows® O58 - SDL:2009/07/08 13:48:50 A . (.Hewlett-Packard - HP Accelerometer.) -- C:\Windows\System32\drivers\Accelerometer.sys [41272] =>.Hewlett-Packard Company® O58 - SDL:2013/08/22 14:43:41 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\Windows\System32\drivers\adp80xx.sys [782176] =>.Microsoft Windows® O58 - SDL:2015/09/23 11:02:29 A . (.Acronis - File Level CDP Kernel Helper.) -- C:\Windows\System32\drivers\afcdp.sys [367200] =>.Acronis, Inc® O58 - SDL:2013/08/22 14:43:41 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [79200] =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:41 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [259424] =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:40 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [25952] =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:41 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [114016] =>.Microsoft Windows® O58 - SDL:2016/02/22 18:23:38 A . (.Avira Operations GmbH & Co. KG - Avira Minifilter Driver.) -- C:\Windows\System32\drivers\avgntflt.sys [128664] =>.Avira Operations GmbH & Co. KG® O58 - SDL:2016/02/22 18:23:39 A . (.Avira Operations GmbH & Co. KG - Avira Driver for Security Enhancement.) -- C:\Windows\System32\drivers\avipbb.sys [137952] =>.Avira Operations GmbH & Co. KG® O58 - SDL:2016/02/22 18:23:39 A . (.Avira Operations GmbH & Co. KG - Avira Manager Driver.) -- C:\Windows\System32\drivers\avkmgr.sys [35488] =>.Avira Operations GmbH & Co. KG® O58 - SDL:2016/02/22 18:23:40 A . (.Avira Operations GmbH & Co. KG - Avira WFP Network Driver.) -- C:\Windows\System32\drivers\avnetflt.sys [68936] =>.Avira Operations GmbH & Co. KG® O58 - SDL:2013/08/13 01:25:46 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\drivers\bcmfn2.sys [17624] =>.Broadcom Corporation® O58 - SDL:2014/12/15 00:59:40 A . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Backup Driver.) -- C:\Windows\System32\drivers\eubakup.sys [60968] =>.CHENGDU YIWO Tech Development Co., Ltd.® O58 - SDL:2014/12/15 00:59:40 A . (...) -- C:\Windows\System32\drivers\EUBKMON.sys [48168] =>.CHENGDU YIWO Tech Development Co., Ltd.® O58 - SDL:2014/12/15 00:59:40 A . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Access Driver.) -- C:\Windows\System32\drivers\eudskacs.sys [18472] =>.CHENGDU YIWO Tech Development Co., Ltd.® O58 - SDL:2014/12/15 00:59:40 A . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Backup Image Preview Driver.) -- C:\Windows\System32\drivers\EuFdDisk.sys [192040] =>.CHENGDU YIWO Tech Development Co., Ltd.® O58 - SDL:2013/08/22 14:43:45 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3357024] =>.Microsoft Windows® O58 - SDL:2015/09/23 11:02:19 A . (.Acronis International GmbH - Acronis Storage Filter Management Driver.) -- C:\Windows\System32\drivers\fltsrv.sys [108832] =>.Acronis International GmbH® O58 - SDL:2015/12/13 09:18:16 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\Windows\System32\drivers\fsfreedometap.sys [34344] =>.F-Secure Corporation® O58 - SDL:2012/07/17 18:12:08 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\drivers\HECIx64.sys [62784] =>.Intel Corporation® O58 - SDL:2009/07/08 13:49:08 A . (.Hewlett-Packard - HP Disk Filter - SATA/RAID.) -- C:\Windows\System32\drivers\hpdskflt.sys [30008] =>.Hewlett-Packard Company® O58 - SDL:2013/08/22 14:43:45 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [64352] =>.Microsoft Windows® O58 - SDL:2013/07/30 20:47:35 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568] =>.Intel Corporation - Software and Firmware Products® O58 - SDL:2013/07/25 21:05:39 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320] =>.Intel Corporation - Software and Firmware Products® O58 - SDL:2013/11/21 08:31:28 A . (.Intel Corporation - Intel Rapid Storage Technology driver - x64.) -- C:\Windows\System32\drivers\iaStorA.sys [632168] =>.Intel Corporation - Intel® Rapid Storage Technology® O58 - SDL:2013/08/10 02:39:30 A . (.Intel Corporation - Intel Rapid Storage Technology driver (inbo.) -- C:\Windows\System32\drivers\iaStorAV.sys [651248] =>.Intel Corporation - Intel® Rapid Storage Technology® O58 - SDL:2013/08/22 14:43:45 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [412000] =>.Microsoft Windows® O58 - SDL:2015/08/27 18:20:10 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd64.sys [3797424] =>.Intel Corporation - pGFX® O58 - SDL:2015/08/21 11:50:48 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\Windows\System32\drivers\IntcDAud.sys [463112] =>.Intel Corporation - Client Components Group® O58 - SDL:2015/07/20 21:45:04 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\Windows\System32\drivers\intelaud.sys [50240] =>.Intel(R) Wireless Display® O58 - SDL:2015/07/20 21:45:04 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\Windows\System32\drivers\iwdbus.sys [38976] =>.Intel(R) Wireless Display® O58 - SDL:2015/08/18 18:25:20 A . (.QFX Software Corporation - KeyScrambler Keyboard Encryption Driver.) -- C:\Windows\System32\drivers\keyscrambler.sys [224720] =>.QFX Software Corporation® O58 - SDL:2013/08/22 14:43:44 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [109408] =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [93536] =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:44 A . (.LSI Corporation - LSI SAS Gen3 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas3.sys [81760] =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sss.sys [82784] =>.Microsoft Windows® O58 - SDL:2015/10/05 09:50:06 A . (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\mbam.sys [25816] =>.Malwarebytes Corporation® O58 - SDL:2016/01/27 13:13:00 A . (.Malwarebytes - Malwarebytes Chameleon Protection Driver.) -- C:\Windows\System32\drivers\mbamchameleon.sys [109272] =>.Malwarebytes Corporation® O58 - SDL:2016/03/25 09:38:36 A . (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys [192216] =>.Malwarebytes Corporation® O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [56672] =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\megasr.sys [575840] =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:49 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\Windows\System32\drivers\mvumis.sys [63840] =>.Microsoft Windows® O58 - SDL:2015/10/05 09:50:22 A . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\Windows\System32\drivers\mwac.sys [64216] =>.Malwarebytes Corporation® O58 - SDL:2015/12/11 09:27:50 A . (.CACE Technologies, Inc. - npf.sys (NT5/6 AMD64) Kernel Driver.) -- C:\Windows\System32\drivers\npf.sys [35344] =>.CACE Technologies, Inc.® O58 - SDL:2013/08/22 14:43:31 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [150368] =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:32 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [168288] =>.Microsoft Windows® O58 - SDL:2015/08/24 04:24:09 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.30 64-bit Dr.) -- C:\Windows\System32\drivers\Rt630x64.sys [885504] =>.Realtek Semiconductor Corp® O58 - SDL:2015/06/18 18:45:16 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RTKVHD64.sys [4496600] =>.Realtek Semiconductor Corp® O58 - SDL:2016/02/26 13:14:40 A . (.Realtek Semiconductor Corporation - Realtek PCIE NDIS Driver 41728.) -- C:\Windows\System32\drivers\rtwlane.sys [4899584] =>.Realtek Semiconductor Corp® O58 - SDL:2013/08/22 17:35:09 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] =>.Macrovision Corporation, Macrovision Europe Limited, O58 - SDL:2013/08/22 14:43:31 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [44896] =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:32 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [81760] =>.Microsoft Windows® O58 - SDL:2011/10/14 05:37:42 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\Windows\System32\drivers\Smb_driver.sys [20016] =>.Synaptics Incorporated® O58 - SDL:2015/09/23 11:02:23 A . (.Acronis - Acronis Snapshot API.) -- C:\Windows\System32\drivers\snapman.sys [233760] =>.Acronis International GmbH® O58 - SDL:2013/08/22 14:43:32 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\Windows\System32\drivers\stexstor.sys [31072] =>.Microsoft Windows® O58 - SDL:2011/10/14 05:37:44 A . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\Windows\System32\drivers\SynTP.sys [396848] =>.Synaptics Incorporated® O58 - SDL:2015/09/26 09:27:05 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\Windows\System32\drivers\tap0901.sys [33832] =>.F-Secure Corporation® O58 - SDL:2015/09/23 11:02:25 A . (.Acronis International GmbH - Acronis Try&Decide Volume Filter Driver.) -- C:\Windows\System32\drivers\tdrpman.sys [1462560] =>.Acronis International GmbH® O58 - SDL:2016/03/02 12:39:01 A . (.TeamViewer GmbH - TeamViewerVPN Network Adapter.) -- C:\Windows\System32\drivers\teamviewervpn.sys [35112] =>.TeamViewer GmbH® O58 - SDL:2015/09/23 11:02:26 A . (.Acronis International GmbH - Acronis Backup Archive Explorer.) -- C:\Windows\System32\drivers\tib.sys [1120032] =>.Acronis International GmbH® O58 - SDL:2015/09/23 11:02:27 A . (.Acronis - Acronis Backup Archive Mounter.) -- C:\Windows\System32\drivers\tib_mounter.sys [183224] =>.Acronis International GmbH® O58 - SDL:2015/11/26 22:30:53 A . (...) -- C:\Windows\System32\drivers\TrueSight.sys [37624] =>.Adlice® O58 - SDL:2013/10/07 14:58:38 A . (.Paragon - Image Mounter File I/O.) -- C:\Windows\System32\drivers\UimFIO.sys [472016] =>.Paragon Software GmbH® O58 - SDL:2013/10/07 14:58:38 A . (.Windows (R) 2000 DDK provider - Image Mounter SCSI Port Driver.) -- C:\Windows\System32\drivers\uimx64.sys [90960] =>.Paragon Software GmbH® O58 - SDL:2013/10/07 14:58:38 A . (.Paragon - Image Mounter.) -- C:\Windows\System32\drivers\Uim_IMx64.sys [633680] =>.Paragon Software GmbH® O58 - SDL:2013/10/07 14:58:38 A . (.Paragon - Image Mounter plugin.) -- C:\Windows\System32\drivers\uim_vimx64.sys [390352] =>.Paragon Software GmbH® O58 - SDL:2016/01/19 18:40:20 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Host-Only Network Adapt.) -- C:\Windows\System32\drivers\VBoxNetAdp6.sys [117768] =>.Oracle Corporation® O58 - SDL:2016/01/19 18:40:20 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Lightweight Filter Driv.) -- C:\Windows\System32\drivers\VBoxNetLwf.sys [194976] =>.Oracle Corporation® O58 - SDL:2013/08/22 14:43:34 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [19808] =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:34 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [168800] =>.Microsoft Windows® O58 - SDL:2013/08/22 14:43:34 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\Windows\System32\drivers\VSTXRAID.SYS [305504] =>.Microsoft Windows® O58 - SDL:2016/03/21 20:08:28 A . (.HP - HP Wireless Button Driver.) -- C:\Windows\System32\drivers\WirelessButtonDriver64.sys [31840] {00AD4EEC891A671ADEC499C6A1BE34D9B0} =>.HP O58 - SDL:2016/01/27 14:41:48 A . (.Zemana Ltd. - ZAM.) -- C:\Windows\System32\drivers\zam64.sys [202144] =>.Zemana Ltd.® O58 - SDL:2016/01/27 14:41:45 A . (.Zemana Ltd. - ZAM.) -- C:\Windows\System32\drivers\zamguard64.sys [202144] =>.Zemana Ltd.® O58 - SDL:2015/02/26 01:00:00 A . (...) -- C:\Windows\System32\ambakdrv.sys [30648] O58 - SDL:2015/02/26 01:00:00 A . (...) -- C:\Windows\System32\ammntdrv.sys [151480] O58 - SDL:2015/02/26 01:00:00 A . (...) -- C:\Windows\System32\amwrtdrv.sys [17848] O58 - SDL:2014/11/18 14:39:06 A . (...) -- C:\Windows\System32\epmntdrv.sys [18528] =>.CHENGDU YIWO Tech Development Co., Ltd.® O58 - SDL:2014/11/18 14:39:06 A . (...) -- C:\Windows\System32\EuGdiDrv.sys [10848] =>.CHENGDU YIWO Tech Development Co., Ltd.® ---\\ Associations Shell Spawning (10) - 1s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe =>.Microsoft Corporation O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- T:\Firefox\firefox.exe =>.Mozilla Corporation® ---\\ Menu de démarrage Internet (4) - 0s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- T:\Firefox\firefox.exe =>.Mozilla Corporation® O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- T:\Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- T:\Firefox\uninstall\helper.exe =>.Mozilla Corporation O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- T:\Firefox\uninstall\helper.exe =>.Mozilla Corporation ---\\ Enumère les services démarrés par Svchost (34) - 1s O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [214528] =>.Microsoft Corporation O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [156160] =>.Microsoft Corporation O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [156160] =>.Microsoft Corporation O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\system32\srvsvc.dll [329216] =>.Microsoft Corporation O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [1360896] =>.Microsoft Corporation O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [1083904] =>.Microsoft Corporation O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [926208] =>.Microsoft Corporation O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\system32\seclogon.dll [31744] =>.Microsoft Corporation O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [110080] =>.Microsoft Corporation O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\system32\iscsiexe.dll [151040] =>.Microsoft Corporation O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [110592] =>.Microsoft Corporation O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\system32\schedsvc.dll [1265152] =>.Microsoft Corporation O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [230400] =>.Microsoft Corporation O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\system32\mmcss.dll [71168] =>.Microsoft Corporation O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [135168] =>.Microsoft Corporation O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [228864] =>.Microsoft Corporation O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [339968] =>.Microsoft Corporation O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84992] =>.Microsoft Corporation O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\system32\kmsvc.dll [101376] =>.Microsoft Corporation O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [348672] =>.Microsoft Corporation O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service d’infrastructure de localisation Wi.) -- C:\Windows\System32\GeofenceMonitorService.dll [522240] =>.Microsoft Corporation O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\Windows\system32\wlidsvc.dll [1639424] =>.Microsoft Corporation O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\system32\themeservice.dll [59392] =>.Microsoft Corporation O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\Windows\System32\DeviceSetupManager.dll [206848] =>.Microsoft Corporation O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\Windows\System32\ncasvc.dll [166400] =>.Microsoft Corporation O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [102912] =>.Microsoft Corporation O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\Windows\System32\rasmans.dll [542208] =>.Microsoft Corporation O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [226816] =>.Microsoft Corporation O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\sens.dll [73728] =>.Microsoft Corporation O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [452608] =>.Microsoft Corporation O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [313344] =>.Microsoft Corporation O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\system32\wuaueng.dll [3708416] =>.Microsoft Corporation O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [933376] =>.Microsoft Corporation O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [640000] =>.Microsoft Corporation ---\\ Liste des exceptions du parefeu Windows (2) - 1s O87 - FAEL: "{043DD01D-791E-4759-8E47-FBD195DEFED5}" [In-None-P6-TRUE] .(...) -- T:\Q-Bitorrent\qBittorrent\qbittorrent.exe O87 - FAEL: "{1D96E84B-516A-42F2-894B-130B2931DFC9}" [In-None-P17-TRUE] .(...) -- T:\Q-Bitorrent\qBittorrent\qbittorrent.exe ---\\ Scan Additionnel (2) - 0s HKLM\SOFTWARE\Wow6432Node\AskToolbar =>Toolbar.Ask HKCU\SOFTWARE\Locky =>Ransomware.Locky ---\\ Récapitulatif des éléments trouvés sur votre station (2) - 0s http://www.nicolascoolman.fr/?p=235 =>Toolbar.Ask http://www.nicolascoolman.fr/?p=4664 =>Ransomware.Locky ~ End of the scan, 3472 items in 00h01mn39s (680)(0)