cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2015.10.22.154 Par Nicolas Coolman (2015/10/22)
~ Démarré par QBDO (Administrator) (2015/10/25 18:56:20)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Users\QBDO\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\QBDO\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Deactivate
~ Démarrage du système: Normal (Normal boot)
Windows 7 Professional, 64-bit Service Pack 1 (Build 7601)

---\\ Navigateurs Internet (3) - 0s
GCIE: Google Chrome v46.0.2490.71
MFIE: MozillaMaintenanceService v40.0.3
MSIE: Internet Explorer v11.0.9600.17843

---\\ Informations sur les produits Windows (4) - 3s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ Logiciels de protection (1) - 11s
Windows Defender W7 (Activate)

---\\ Logiciels d'optimisation (1) - 12s
CCleaner v5.08

---\\ Surveillance de Logiciels (1) - 12s
Adobe Flash Player 10 ActiveX

---\\ Logiciels de partage P2P (1) - 12s
qBittorrent 3.2.4 v3.2.4

---\\ Informations sur le système (6) - 0s
~ Operating System: Intel64 Family 6 Model 42 Stepping 7, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 3986.8 MB (29% free)
~ System Restore: Activé (Enable)
~ System drive C: has 157 GB free of 276 GB

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: QBDO-PC
~ User Name: QBDO
~ Logged in as Administrator

---\\ Enumération des unités disques (3) - 0s
~ Drive C: has 157 GB free of 276 GB (System)
~ Drive D: has 0 GB free of 0 GB
~ Drive F: has 167 GB free of 199 GB

---\\ Etat du Centre de Sécurité Windows (11) - 0s
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Recherche particulière de fichiers génériques (26) - 2s
[MD5.AC4C51EB24AA95B77F705AB159189E24] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\Windows\Explorer.exe [2872320] ©
[MD5.DD81D91FF3B0763C392422865C9AC12E] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) () -- C:\Windows\System32\rundll32.exe [45568] ©
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) () -- C:\Windows\System32\Wininit.exe [129024] ©
[MD5.417F80E4AFBA1AA9EBBD618F1C6D9165] - (.Microsoft Corporation - Extensions Internet pour Win32.) () -- C:\Windows\System32\wininet.dll [2426880] ©
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d’ouverture de session Windows.) () -- C:\Windows\System32\Winlogon.exe [390656] ©
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) () -- C:\Windows\System32\sppcomapi.dll [232448] ©
[MD5.A52B6CC24063CC83C78C0E6F24DEEC01] - (.Microsoft Corporation - DNS DLL de l’API Client.) () -- C:\Windows\System32\dnsapi.dll [357888] ©
[MD5.59DF156711A76BCB993253EC6C9BBF41] - (.Microsoft Corporation - DNS DLL de l’API Client.) () -- C:\Windows\Syswow64\dnsapi.dll [270336] ©
[MD5.0D57D091E06BB1E58E72E5D08479FDDF] - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) () -- C:\Windows\System32\fr-FR\user32.dll.mui [20480] ©
[MD5.314C17917AC8523EC77A710215012A65] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\Windows\System32\drivers\AFD.sys [497152] ©
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\Windows\System32\drivers\atapi.sys [24128] ©
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\Windows\System32\drivers\Cdfs.sys [92160] ©
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\Windows\System32\drivers\Cdrom.sys [147456] ©
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\Windows\System32\drivers\DfsC.sys [102400] ©
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\Windows\System32\drivers\HDAudBus.sys [122368] ©
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\Windows\System32\drivers\i8042prt.sys [105472] ©
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\Windows\System32\drivers\IpNat.sys [116224] ©
[MD5.FAF015B07E3A2874A790A39B7D2C579F] - (.Microsoft Corporation - Windows NT SMB Minirdr.) () -- C:\Windows\System32\drivers\MRxSmb.sys [158208] ©
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\Windows\System32\drivers\netBT.sys [261632] ©
[MD5.05D78AA5CB5F3F5C31160BDB955D0B7C] - (.Microsoft Corporation - Pilote du système de fichiers NT.) () -- C:\Windows\System32\drivers\ntfs.sys [1659776] ©
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\Windows\System32\drivers\Parport.sys [97280] ©
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\Windows\System32\drivers\Rasl2tp.sys [129536] ©
[MD5.1B6163C503398B23FF8B939C67747683] - (.Microsoft Corporation - Microsoft RDP Device redirector.) () -- C:\Windows\System32\drivers\rdpdr.sys [165888] ©
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) () -- C:\Windows\System32\drivers\smb.sys [93184] ©
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\Windows\System32\drivers\tdx.sys [119296] ©
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\Windows\System32\drivers\volsnap.sys [295808] ©

---\\ Processus lancés (16) - 3s
[MD5.3A65D4AF876F6CD47B22AA93A31E4646] - (.Intel(R) Corporation - Intel(R) PROSet/Wireless Event Log Service.) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe [626960] [PID.1720] ©
[MD5.B29F5BD169CDDEE1049015255E7E3FBD] - (.Intel(R) Corporation - Intel(R) PROSet/Wireless Registry Service.) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [148752] [PID.1796] ©
[MD5.9E35C40B0952F27E3F57E8F1D449F0A0] - (.Intel® Corporation - Intel® PROSet/Wireless Zero Configure Servi.) -- C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2671376] [PID.1936] ©
[MD5.47DBCC66CF9A3DCEF2D42051431160D3] - (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe [8418584] [PID.3004] ©
[MD5.34C60D1F16D8FE67277DBB9D7E59F89D] - (.Intel(R) Corporation - Intel(R) BlueTooth(R) HS Security Manager S.) -- C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [135952] [PID.3768] ©
[MD5.6547D87C8DFC563C76441FE6E4126B1B] - (.Disc Soft Ltd - Disc Soft Bus Service.) -- C:\Program Files\DAEMON Tools Pro\DiscSoftBusService.exe [1278296] [PID.3256] ©
[MD5.FBD72D119CEB8CC8514828AE13776626] - (.Disc Soft Ltd - DAEMON Tools Shell Extensions Helper.) -- C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe [4454744] [PID.5920] ©
[MD5.EF49397315A9368DB1B4574284C71A59] - (.Apache Friends - Start and stop XAMPP.) -- C:\xampp\xampp_start.exe [147456] [PID.2028]
[MD5.38C3695A0C1403170FBB4C4E5C1474B3] - (.Maxthon International ltd. - Maxthon Cloud Browser.) -- C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [322984] [PID.5904] ©
[MD5.38C3695A0C1403170FBB4C4E5C1474B3] - (.Maxthon International ltd. - Maxthon Cloud Browser.) -- C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [322984] [PID.4120] ©
[MD5.38C3695A0C1403170FBB4C4E5C1474B3] - (.Maxthon International ltd. - Maxthon Cloud Browser.) -- C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [322984] [PID.3492] ©
[MD5.38C3695A0C1403170FBB4C4E5C1474B3] - (.Maxthon International ltd. - Maxthon Cloud Browser.) -- C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [322984] [PID.4868] ©
[MD5.38C3695A0C1403170FBB4C4E5C1474B3] - (.Maxthon International ltd. - Maxthon Cloud Browser.) -- C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [322984] [PID.2188] ©
[MD5.38C3695A0C1403170FBB4C4E5C1474B3] - (.Maxthon International ltd. - Maxthon Cloud Browser.) -- C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [322984] [PID.5032] ©
[MD5.38C3695A0C1403170FBB4C4E5C1474B3] - (.Maxthon International ltd. - Maxthon Cloud Browser.) -- C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [322984] [PID.5104] ©
[MD5.231AE3BE35DFA790FE484CCA354BCD15] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\QBDO\Desktop\ZHPDiag3.exe [1958912] [PID.3188] ©

---\\ Google Chrome, Démarrage,Recherche,Extensions (17) - 1s
G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.oursurfing.com/ =>PUP.Optional.OurSurfing
G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [albbiglcfndaaphglmeaejkhepckkfgf] Hide My IP
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [cphljojhgmnabimjemakjleocdheengh] XJZ Survey Remover
G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [gkojfkhlekighikafcpjkiklfbnlmeio] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [lnkdbjbjpnpjeciipoaflmpcddinpjjp] Ashish Mishra
G2 - GCE: Preference [User Data\Default] [molncoemjfmpgdkbdlbjmhlcgniigdnf] Project Naptha
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [nolijncfnkgaikbjbdaogikpmpbdcdef] nolijncfnkgaikbjbdaogikpmpbdcdef
G2 - GCE: Preference [User Data\Default] [ocifcklkibdehekfnmflempfgjhbedch] __MSG_name__
G2 - GCE: Preference [User Data\Default] [ojhbgcchcbdjdenibfmjofobklkkhofc] Simple EPUB Reader
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc.

---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (1) - 1s
P2 - EXT FILE: (...) -- C:\Users\QBDO\AppData\Roaming\Mozilla\Firefox\Profiles\pet7wwwp.default\searchplugins\findit.xml =>PUP.Optional.SmartBar

---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (19) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNZ4IeknwsEdyUfUeYGEUy1UhH0wHmr1ht_wJaCyteue9qd2nDQWidZvPxsR-Yqk-MJLVy5g_WDTkjJ0Aox_vw4TZWRpC_xydQkZpgJKfOXJa9O3MwB7OJiwxXYg4GKP_G8Y9vPcEL3yon3kvl3jaEeuMKLG_N
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyryeqqao2txtgptboxpbnz4ieknwsedyufueygeuy1uhh0whmr1ht_wjacyteue9qd2ndqwidzvpxsr-yqk-mjlvy5g_wdtkjj0xgajwkx9smk1aahhbyljyxyl1aoyoiw4qyw40kcisa-wpxqdptznrdmx1w0_o51mg_blla2sn04lff&q={searchterms}
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.oursurfing.com/ =>PUP.Optional.OurSurfing
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyryeqqao2txtgptboxpbnz4ieknwsedyufueygeuy1uhh0whmr1ht_wjacyteue9qd2ndqwidzvpxsr-yqk-mjlvy5g_wdtkjj0xgajwkx9smk1aahhbyljyxyl1aoyoiw4qyw40kcisa-wpxqdptznrdmx1w0_o51mg_blla2sn04lff&q={searchterms}
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.oursurfing.com/ =>PUP.Optional.OurSurfing
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oursurfing.com/ =>PUP.Optional.OurSurfing
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyryeqqao2txtgptboxpbnz4ieknwsedyufueygeuy1uhh0whmr1ht_wjacyteue9qd2ndqwidzvpxsr-yqk-mjlvy5g_wdtkjj0xgajwkx9smk1aahhbyljyxyl1aoyoiw4qyw40kcisa-wpxqdptznrdmx1w0_o51mg_blla2sn04lff&q={searchterms}
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyryeqqao2txtgptboxpbnz4ieknwsedyufueygeuy1uhh0whmr1ht_wjacyteue9qd2ndqwidzvpxsr-yqk-mjlvy5g_wdtkjj0xgajwkx9smk1aahhbyljyxyl1aoyoiw4qyw40kcisa-wpxqdptznrdmx1w0_o51mg_blla2sn04lff&q={searchterms}
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.oursurfing.com/ =>PUP.Optional.OurSurfing
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oursurfing.com/ =>PUP.Optional.OurSurfing
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer

---\\ Internet Explorer,Proxy Management (4) - 0s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 1s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) ©
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) ©
F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) ©

---\\ Etude du fichier hosts (5) - 0s
128.199
127
128.199

127

~ Nombre lignes détournées 128.199

35 (Hosts file redirected)

---\\ Browser Helper Object de navigateur (BHO) (5) - 0s
O2 - BHO: Lync Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} . (.Microsoft Corporation - Microsoft Lync.) -- C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll ©
O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (Orphean)
O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL ©
O2 - BHO: Microsoft SkyDrive Pro Browser Helper [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} . (.Microsoft Corporation - Microsoft SkyDrive Pro Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL ©
O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} (Orphean)

---\\ Applications lancées au démarrage du système (8) - 0s
O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe ©
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] . (.Disc Soft Ltd - DAEMON Tools Pro Agent.) -- C:\Program Files\DAEMON Tools Pro\DTAgent.exe ©
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\sidebar.exe ©
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\sidebar.exe ©
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe ©
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe ©
O4 - HKUS\S-1-5-21-35204602-2475897552-2890194827-1000\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe ©
O4 - HKUS\S-1-5-21-35204602-2475897552-2890194827-1000\..\Run: [DAEMON Tools Pro Agent] . (.Disc Soft Ltd - DAEMON Tools Pro Agent.) -- C:\Program Files\DAEMON Tools Pro\DTAgent.exe ©

---\\ Modification Domaine/Adresses DNS (3) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1

---\\ Protocole additionnel (22) - 0s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll ©
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll ©
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll ©
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll ©
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll ©
O18 - Handler: osf [64Bits] - {D924BDC6-C83A-4BD5-90D0-095128A113D1} . (.Microsoft Corporation - Microsoft Office 2013 component.) -- C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL ©
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll ©
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll ©
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ©
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ©
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ©
O18 - Filter: text/xml [64Bits] - {807583E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL ©

---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (1) - 0s
O20 - AppInit_DLLs: . (...) - C:\ProgramData\Saophase\Singhome.dll

---\\ Liste des services NT non Microsoft et non désactivés (4) - 1s
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Sec (BTHSSecurityMgr) . (.Intel(R) Corporation - Intel(R) BlueTooth(R) HS Security Manager S.) - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe ©
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) . (.Intel(R) Corporation - Intel(R) PROSet/Wireless Event Log Service.) - C:\Program Files\Intel\WiFi\bin\EvtEng.exe ©
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) . (.Intel(R) Corporation - Intel(R) PROSet/Wireless Registry Service.) - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe ©
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) . (.Intel® Corporation - Intel® PROSet/Wireless Zero Configure Servi.) - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe ©

---\\ Tâches planifiées en automatique (16) - 5s
[MD5.26E4DFE21BCC0695E5EE93F76E0F0515] [APT] [AdobeAAMUpdater-1.0-QBDO-PC-QBDO] (.Adobe Systems Incorporated.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [542624] ©
[MD5.D4F602B1F775B5827932D3C5B04A3FD2] [APT] [AutoKMS] (.CODYQX4.) -- C:\Windows\AutoKMS\AutoKMS.exe [3372032] =>HackTool.AutoKMS
[MD5.86586F266431274FA214F849D125AC89] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6523160] ©
[MD5.D97689882E3A2F9355B155F3EC107DFE] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2442056] ©
[MD5.D97689882E3A2F9355B155F3EC107DFE] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2442056] ©
[MD5.38C3695A0C1403170FBB4C4E5C1474B3] [APT] [Maxthon Update] (.Maxthon International ltd..) -- C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [322984] ©
[MD5.C3FE887CEE6FF8D2EF2A8231C12F0DEA] [APT] [yuqatigf] (...) -- C:\Program Files\Common Files\0w1twvts\94e63nc55k4xa.exe [2285568]
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1066] ©
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1070] ©
O39 - APT: AdobeAAMUpdater-1.0-QBDO-PC-QBDO - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-QBDO-PC-QBDO [3498] ©
O39 - APT: AutoKMS - (.CODYQX4.) -- C:\Windows\System32\Tasks\AutoKMS [3488] =>HackTool.AutoKMS
O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\Windows\System32\Tasks\CCleanerSkipUAC [2786] ©
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [3814] ©
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [4066] ©
O39 - APT: Maxthon Update - (.Maxthon International ltd..) -- C:\Windows\System32\Tasks\Maxthon Update [3578] ©
O39 - APT: yuqatigf - (...) -- C:\Windows\System32\Tasks\yuqatigf [3156]

---\\ Logiciels installés (156) - 10s
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner ©
O42 - Logiciel: DAEMON Tools Pro - (.Disc Soft Ltd.) [HKLM][64Bits] -- DAEMON Tools Pro ©
O42 - Logiciel: EaseUS Data Recovery Wizard 8.8 - (.EaseUS.) [HKLM][64Bits] -- EaseUS Data Recovery Wizard 8.8_is1 ©
O42 - Logiciel: Intel PROSet Wireless - (...) [HKLM][64Bits] -- ProInst
O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey ©
O42 - Logiciel: TeraCopy 2.22 - (.Code Sector.) [HKLM][64Bits] -- TeraCopy_is1
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player ©
O42 - Logiciel: WinRAR 5.21 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver ©
O42 - Logiciel: IIS Express Application Compatibility Database for x64 - (...) [HKLM][64Bits] -- {08274920-8908-45c2-9258-8ad67ff77b09}.sdb
O42 - Logiciel: Java 8 Update 60 (64-bit) - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F86418060F0} ©
O42 - Logiciel: Vegas Pro 13.0 (64-bit) - (.Sony.) [HKLM][64Bits] -- {3814DB30-091D-11E4-BDE0-F04DA23A5C58} ©
O42 - Logiciel: MSVCRT Redists - (.Sony Creative Software Inc..) [HKLM][64Bits] -- {3BFC9CAE-091D-11E4-886A-F04DA23A5C58} ©
O42 - Logiciel: Microsoft Build Tools Language Resources 14.0 (amd64) - (.Microsoft Corporation.) [HKLM][64Bits] -- {4B7958F6-4943-4903-B379-9180DC8C2105} ©
O42 - Logiciel: Windows Software Development Kit DirectX x64 Remote - (.Microsoft Corporation.) [HKLM][64Bits] -- {5247E16E-BCF8-95AB-1653-B3F8FBF8B3F1} ©
O42 - Logiciel: Visual C++ IDE x64 Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {55168F96-0BEA-3A05-95C7-D31D211D707E} ©
O42 - Logiciel: IIS 10.0 Express - (.Microsoft Corporation.) [HKLM][64Bits] -- {5984D8DA-C1AF-4284-9C88-D7150425B315} ©
O42 - Logiciel: Java SE Development Kit 8 Update 60 (64-bit) - (.Oracle Corporation.) [HKLM][64Bits] -- {64A3A4F4-B792-11D6-A78A-00B0D0180600} ©
O42 - Logiciel: Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed - (.Intel Corporation.) [HKLM][64Bits] -- {705EE775-5776-48FD-B704-C3C9CF535420} ©
O42 - Logiciel: Microsoft System CLR Types pour SQL Server 2014 - (.Microsoft Corporation.) [HKLM][64Bits] -- {76582300-132C-4B08-9DFB-350E9E9260EA} ©
O42 - Logiciel: Epic Games Launcher - (.Epic Games, Inc..) [HKLM][64Bits] -- {89009F5F-0A2C-4196-9543-EA50C81CF26E} ©
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} ©
O42 - Logiciel: Microsoft Build Tools 14.0 (amd64) - (.Microsoft Corporation.) [HKLM][64Bits] -- {8C918E5B-E238-401F-9F6E-4FB84B024CA2} ©
O42 - Logiciel: Microsoft Access MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0015-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Excel MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0016-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft PowerPoint MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0018-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Publisher MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0019-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Outlook MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001A-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Word MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001B-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft InfoPath MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0044-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft DCF MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0090-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft OneNote MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00A1-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Groove MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00BA-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Microsoft Lync MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-012B-040C-1000-0000000FF1CE} ©
O42 - Logiciel: Windows Software Development Kit for Windows Store Apps DirectX x64 Remote - (.Microsoft Corporation.) [HKLM][64Bits] -- {96F4525A-470D-F15C-796E-58D9988C3E5F} ©
O42 - Logiciel: IIS Express Application Compatibility Database for x86 - (...) [HKLM][64Bits] -- {ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb
O42 - Logiciel: Visual Studio 2015 Prerequisites - FRA Language Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {AF1C7D47-5BA6-4485-98D0-793E6B944CD5} ©
O42 - Logiciel: Windows Software Development Kit DirectX x64 Remote - (.Microsoft Corporation.) [HKLM][64Bits] -- {B74B199A-EDD4-B657-E055-327D454402D2} ©
O42 - Logiciel: Logiciel Intel® PROSet/Wireless WiFi - (.Intel Corporation.) [HKLM][64Bits] -- {BAA0BE9B-9E6D-4802-91CB-FB7ED5CD4BEF} ©
O42 - Logiciel: Microsoft .NET Version Manager (x64) 1.0.0-beta5 - (.Microsoft Corporation.) [HKLM][64Bits] -- {c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738} ©
O42 - Logiciel: SAMSUNG USB Driver for Mobile Phones - (.SAMSUNG Electronics Co., Ltd..) [HKLM][64Bits] -- {D0795B21-0CDA-4a92-AB9E-6E92D8111E44} ©
O42 - Logiciel: Visual Studio 2015 Prerequisites - (.Microsoft Corporation.) [HKLM][64Bits] -- {DF32E41C-24AD-4A87-B43A-B38553B1806E} ©
O42 - Logiciel: Microsoft Web Deploy 3.6 - (.Microsoft Corporation.) [HKLM][64Bits] -- {ED4CC1E5-043E-4157-8452-B5E533FE2BA1} ©
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe AIR ©
O42 - Logiciel: Adobe Digital Editions 4.0 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Digital Editions 4.0 ©
O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX ©
O42 - Logiciel: Adobe Muse - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- AdobeMuse ©
O42 - Logiciel: Bandisoft MPEG-1 Decoder - (.Bandisoft.com.) [HKLM][64Bits] -- BandiMPEG1 ©
O42 - Logiciel: BeinConnecTVv2 - (...) [HKLM][64Bits] -- BeinConnecTVv2
O42 - Logiciel: Connect24@24 - (...) [HKLM][64Bits] -- Connect24@24
O42 - Logiciel: FBReader for Windows - (...) [HKLM][64Bits] -- FBReader for Windows
O42 - Logiciel: Foxit Reader - (.Foxit Software Inc..) [HKLM][64Bits] -- Foxit Reader_is1 ©
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome ©
O42 - Logiciel: Maxthon Cloud Browser - (.Maxthon International Limited.) [HKLM][64Bits] -- Maxthon3 ©
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService ©
O42 - Logiciel: Logiciels National Instruments - (.National Instruments.) [HKLM][64Bits] -- NI Uninstaller ©
O42 - Logiciel: Driver ODBC pour HFSQL 32 bits - (...) [HKLM][64Bits] -- ODBC_HFSQL32
O42 - Logiciel: Driver ODBC pour HFSQL 64 bits - (...) [HKLM][64Bits] -- ODBC_HFSQL64
O42 - Logiciel: qBittorrent 3.2.4 - (.The qBittorrent project.) [HKLM][64Bits] -- qBittorrent
O42 - Logiciel: Sublime Text Build 3083 - (.Sublime HQ Pty Ltd.) [HKLM][64Bits] -- Sublime Text 3_is1
O42 - Logiciel: Super Hide IP - (...) [HKLM][64Bits] -- SuperHideIP
O42 - Logiciel: Unity - (.Unity Technologies ApS.) [HKLM][64Bits] -- Unity ©
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {0274D240-4D1D-4FDA-9A36-09F0BECD288F} ©
O42 - Logiciel: Visual C++ Compiler/Tools X86 Base Resource Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {035D19A8-F1B3-3D66-837F-C6D727926963} ©
O42 - Logiciel: Monitor de red inalámbrica - (...) [HKLM][64Bits] -- {1224EA61-3973-4DA7-A9E6-D910A8FC7879}
O42 - Logiciel: Visual C++ IDE Debugger Resource Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {14CC958F-7884-322D-BE09-5CE8CE53576B} ©
O42 - Logiciel: Tools for .Net 3.5 - (.Microsoft Corporation.) [HKLM][64Bits] -- {1690CE56-2231-4E59-9006-A0876D949EA8} ©
O42 - Logiciel: Visual C++ IDE Common Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {1A6302B8-FD7B-32F9-ACC1-7C0B776D21A2} ©
O42 - Logiciel: Entity Framework 6.1.3 Tools for Visual Studio 2015 - (.Microsoft Corporation.) [HKLM][64Bits] -- {1A8A9739-BAD7-491F-B5B9-A79A2B965422} ©
O42 - Logiciel: Assemblys du Kit de développement logiciel (SDK) Windows Phone 8.0 pour Vis - (.Microsoft Corporation.) [HKLM][64Bits] -- {1A8C4E94-C4A9-327E-9378-3EE88CB1042A} ©
O42 - Logiciel: Roslyn Language Services - x86 - (.Microsoft Corporation.) [HKLM][64Bits] -- {1E3168EE-DCCA-33A1-AD17-5962A59118A3} ©
O42 - Logiciel: AzureTools.Notifications - (.Microsoft Corporation.) [HKLM][64Bits] -- {1E5CA362-39B6-4BD0-B9C0-69CF15F0FEA2} ©
O42 - Logiciel: PDF Settings CC - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {1FBAE18D-4DE4-47AA-83EC-D1B046F262DC} ©
O42 - Logiciel: Visual C++ IDE Debugger Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {2079BC7F-41D0-3CE8-BB24-D1DC292DE4C8} ©
O42 - Logiciel: Microsoft Azure Shared Components for Visual Studio 2015 - v1.5 - (.Microsoft Corporation.) [HKLM][64Bits] -- {216094CE-EC45-4372-B6C6-0F2B8DE52679} ©
O42 - Logiciel: Visual C++ Compiler/Tools X86 Base Resource Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {22ADF73E-005C-38FA-BFDB-AE763E5993A8} ©
O42 - Logiciel: Adobe Muse - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {23572B8A-20C2-78B2-F159-F3D522813BA3} ©
O42 - Logiciel: Intel(R) USB 3.0 eXtensible Host Controller Driver - (.Intel Corporation.) [HKLM][64Bits] -- {240C3DDD-C5E9-4029-9DF7-95650D040CF2} ©
O42 - Logiciel: Module linguistique de Dotfuscator and Analytics Community Edition 5.18.1 f - (.PreEmptive Solutions.) [HKLM][64Bits] -- {242E5CC0-31F6-4C13-90B1-93859035E410} ©
O42 - Logiciel: Visual C++ Library PGO X86 Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {24D8C6FB-19E6-3E96-A94F-D4FCE4CBC6D0} ©
O42 - Logiciel: Adobe Photoshop CC - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {2D99B50E-431D-4AA8-85C1-172A6F8BCF09} ©
O42 - Logiciel: Microsoft NuGet - Visual Studio 2015 - (.Microsoft Corporation.) [HKLM][64Bits] -- {2FB312D3-E28F-3094-B6ED-47000F25D193} ©
O42 - Logiciel: Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver - (.Atheros Communications Inc..) [HKLM][64Bits] -- {3108C217-BE83-42E4-AE9E-A56A2A92E549} ©
O42 - Logiciel: WCF Data Services 5.6.4 FRA Language Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {314D548C-60FF-48F8-BEAE-C94946706349} ©
O42 - Logiciel: Blend for Visual Studio SDK for .NET 4.5 - (.Microsoft Corporation.) [HKLM][64Bits] -- {37E53780-3944-4A6A-842F-727128E8616E} ©
O42 - Logiciel: Visual C++ MSBuild Base Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {384BAE4F-6233-3E67-99A3-87268642493D} ©
O42 - Logiciel: Visual C++ IDE Base Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {3C0FA0FD-3422-3D08-B1F9-BF34BE7DE12B} ©
O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {3E29EE6C-963A-4aae-86C1-DC237C4A49FC} ©
O42 - Logiciel: Intel® Watchdog Timer Driver (Intel® WDT) - (.Intel Corporation.) [HKLM][64Bits] -- {3FD0C489-0F02-481a-A3E1-9754CD396761} ©
O42 - Logiciel: Azure AD Authentication Connected Service - (.Microsoft Corporation.) [HKLM][64Bits] -- {3FEAC561-1CF6-41D6-B0F3-BECDD9C88A1B} ©
O42 - Logiciel: Foxit Cloud - (.Foxit Software Inc..) [HKLM][64Bits] -- {41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1 ©
O42 - Logiciel: Adaptador USB Inalámbrico - (...) [HKLM][64Bits] -- {41D7F8AB-6EFE-4104-ABF6-EBE4E65BEAEE}
O42 - Logiciel: Windows Espc Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {42AF2A8C-6EBB-3D2E-9BF1-6135379FBABC} ©
O42 - Logiciel: PreEmptive Analytics Visual Studio Components - (.PreEmptive Solutions.) [HKLM][64Bits] -- {436A18DD-5F2C-4B3C-985E-AD3C13B0CC25} ©
O42 - Logiciel: Sybase PowerAMC 15.1 - (.Sybase Inc..) [HKLM][64Bits] -- {48B0BE4A-EDC9-44C4-A3DB-67D62D75961F}
O42 - Logiciel: Visual C++ MSBuild Base Resource Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {4BCA1E3C-A809-353D-89E4-47D4E345BD6B} ©
O42 - Logiciel: Microsoft Azure Mobile Services Tools for Visual Studio - v1.4 - (.Microsoft Corporation.) [HKLM][64Bits] -- {5536AAD4-740A-4577-843D-4281D3F30726} ©
O42 - Logiciel: Windows Software Development Kit for Windows Store Apps DirectX x86 Remote - (.Microsoft Corporation.) [HKLM][64Bits] -- {56AD3004-0B49-967F-F682-B05650B61A78} ©
O42 - Logiciel: Visual F# 4.0 VS Language Pack - FRA - (.Microsoft Corporation.) [HKLM][64Bits] -- {5831AA1C-FB83-3F63-8346-5A51E7272D44} ©
O42 - Logiciel: Roslyn Language Services - x86 - (.Microsoft Corporation.) [HKLM][64Bits] -- {5B47029B-1E62-30FF-906E-694851C22782} ©
O42 - Logiciel: Visual C++ MSBuild X86 Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {5F867E41-0322-3590-B09E-B2D318CEBBF1} ©
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} ©
O42 - Logiciel: Visual C++ MSBuild X64 Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {62A6BB84-126D-3132-A4F2-B250BFB9AB3F} ©
O42 - Logiciel: Prezi - (.Nom de votre société.) [HKLM][64Bits] -- {63B8F931-2BF3-4D5D-9C28-E2EF88D83DFD}
O42 - Logiciel: Microsoft Agents pour Visual Studio 2015 Preview - FRA - (.Microsoft Corporation.) [HKLM][64Bits] -- {643108C8-AF54-39A4-AFC2-F8290D9BB870} ©
O42 - Logiciel: Visual C++ IDE Professional Core Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {743FC372-B1A2-3A5A-BF20-E2AF24435685} ©
O42 - Logiciel: Microsoft Expression Blend SDK for .NET 4 - (.Microsoft Corporation.) [HKLM][64Bits] -- {7B6B35D5-404D-498E-95D0-3CCB2B2FC6F9} ©
O42 - Logiciel: Visual C++ Compiler/Tools X86 Base Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {80025584-1880-35C4-AF00-D315726DD3B0} ©
O42 - Logiciel: Rosetta Stone Version 3 - (.Rosetta Stone Ltd..) [HKLM][64Bits] -- {80F7CA44-F3A5-4853-8BA6-DDF57CD4F078}
O42 - Logiciel: Swifi version 1.0 - (.Merousoft, Inc..) [HKLM][64Bits] -- {81F65D8F-7196-4099-9C7F-EA5726D9E227}_is1
O42 - Logiciel: Visual C++ MSBuild ARM Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {8A56053B-10D9-333C-802F-FD804C4D6D35} ©
O42 - Logiciel: Camtasia Studio 8 - (.TechSmith Corporation.) [HKLM][64Bits] -- {904AC0F0-F69E-467E-A719-B083940F608A} ©
O42 - Logiciel: Applications hybrides multi-appareils en C# - Modèles - FRA - (.Microsoft Corporation.) [HKLM][64Bits] -- {9222F12D-9DD6-3F84-BF8D-A70B9BB4ECAB} ©
O42 - Logiciel: Microsoft Portable Library Multi-Targeting Pack Language Pack - fra - (.Microsoft Corporation.) [HKLM][64Bits] -- {95E43794-D2BA-39B8-B638-DFC378F08AF3} ©
O42 - Logiciel: Tencent version 1.9 - (...) [HKLM][64Bits] -- {96F04C1B-E352-4A90-BED4-11A0FA968BC2}_is1 =>PUP.Optional.TencentAddressBar
O42 - Logiciel: Dotfuscator and Analytics Community Edition 5.18.1 - (.PreEmptive Solutions.) [HKLM][64Bits] -- {9890DF1A-10E9-4236-94B1-1EFAA4099F13} ©
O42 - Logiciel: Application Insights Tools for Visual Studio 2015 - (.Microsoft Corporation.) [HKLM][64Bits] -- {9F429DF7-F8DD-4980-9673-E6DACA012F6C} ©
O42 - Logiciel: Microsoft Azure Mobile Services SDK V2.0 - (.Microsoft Corporation.) [HKLM][64Bits] -- {A00EC54A-CE16-4CF6-A14A-5CF81A1FE03F} ©
O42 - Logiciel: Windows Software Development Kit DirectX x86 Remote - (.Microsoft Corporation.) [HKLM][64Bits] -- {A1CB8286-CFB3-A985-D799-721A0F2A27F3} ©
O42 - Logiciel: Visual C++ IDE Core Professional Plus Resource Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {A1D8A196-4F83-3399-83CF-A1557E943766} ©
O42 - Logiciel: Microsoft Azure Mobile Services Connected Service - (.Microsoft Corporation.) [HKLM][64Bits] -- {A4495E4F-5218-48FB-8AD2-F3076011B9E1} ©
O42 - Logiciel: Windows Software Development Kit DirectX x86 Remote - (.Microsoft Corporation.) [HKLM][64Bits] -- {A6030DAD-1600-F767-C8DD-C722ADFE8FBC} ©
O42 - Logiciel: Module linguistique des composants partagés Microsoft Azure pour Visual Stu - (.Microsoft Corporation.) [HKLM][64Bits] -- {A7B54F58-F1FB-4BC0-BF2A-0A32A8C3F61D} ©
O42 - Logiciel: Microsoft Build Tools Language Resources 14.0 (x86) - (.Microsoft Corporation.) [HKLM][64Bits] -- {A7E88B38-6886-4474-9D85-A8ABE5FCD80E} ©
O42 - Logiciel: Visual C++ IDE Base Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {B4455386-EEC8-3ADB-B63B-F10F108D04A9} ©
O42 - Logiciel: PreEmptive Analytics Client French Language Pack - (.PreEmptive Solutions.) [HKLM][64Bits] -- {B7B58EF9-6307-4DCF-8276-2F17D1E6DE69} ©
O42 - Logiciel: Visual C++ IDE Common Resource Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {BA2D41E6-FF76-3980-82CD-5D38F6244D78} ©
O42 - Logiciel: Microsoft Portable Library Multi-Targeting Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {C11CD3FC-F7A0-3A92-8B38-02D5E6C79FAE} ©
O42 - Logiciel: Realtek PCIE Card Reader - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {C1594429-8296-4652-BF54-9DBE4932A44C} ©
O42 - Logiciel: Tools for .Net 3.5 - FRA Lang Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {C37962EE-EE24-4E9F-8A41-514ACD79177C} ©
O42 - Logiciel: Visual C++ IDE Base Resource Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {C4D5152E-9477-36BF-898B-48837B684788} ©
O42 - Logiciel: Microsoft Azure Storage Connected Service - (.Microsoft Corporation.) [HKLM][64Bits] -- {C6A4A3DF-5A1E-4825-8D38-E5B00C196B31} ©
O42 - Logiciel: Module linguistique de la visionneuse d'aide Microsoft 2.2 - FRA - (.Microsoft Corporation.) [HKLM][64Bits] -- {CA7DEAE0-CDD3-3E30-A0D2-05246EC3D6F9} ©
O42 - Logiciel: Enterprise Architect 11 - (.Sparx Systems.) [HKLM][64Bits] -- {CC98E8B3-FAAA-4D09-A813-A44C9FA1A3EE}
O42 - Logiciel: Python 3.4.3 - (.Python Software Foundation.) [HKLM][64Bits] -- {CCD588A7-8D55-49F1-A30C-47FAB40889ED} ©
O42 - Logiciel: Windows 7 USB/DVD Download Tool - (.Microsoft Corporation.) [HKLM][64Bits] -- {CCF298AF-9CE1-4B26-B251-486E98A34789} ©
O42 - Logiciel: Microsoft Agents for Visual Studio 2015 Preview - (.Microsoft Corporation.) [HKLM][64Bits] -- {CE37CE67-2660-30EE-805B-78829CC3554B} ©
O42 - Logiciel: Update for (KB2504637) - (.Microsoft Corporation.) [HKLM][64Bits] -- {CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637 ©
O42 - Logiciel: Microsoft Build Tools 14.0 (x86) - (.Microsoft Corporation.) [HKLM][64Bits] -- {D1437F51-786A-4F57-A99C-F8E94FBA1BD8} ©
O42 - Logiciel: Microsoft.VisualStudio.Office365 - (.Microsoft Corporation.) [HKLM][64Bits] -- {D1E9367F-5F7C-4019-96B7-45967FD60DB4} ©
O42 - Logiciel: WCF Data Services 5.6.4 Runtime - (.Microsoft Corporation.) [HKLM][64Bits] -- {DB85E7BD-B2DD-43D4-B3C0-23D7B527B597} ©
O42 - Logiciel: Module linguistique Microsoft Azure Mobile Services Tools pour Visual Studi - (.Microsoft Corporation.) [HKLM][64Bits] -- {DD61292F-143F-4424-B78B-B229F7B99CF7} ©
O42 - Logiciel: HD Webcam - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {E0A7ED39-8CD6-4351-93C3-69CCA00D12B4} ©
O42 - Logiciel: TypeScript Power Tool - (.Microsoft Corporation.) [HKLM][64Bits] -- {E51EAA08-F838-4CCE-B011-A82469BE6CC5} ©
O42 - Logiciel: Visual C++ Compiler/Tools X86 Base Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {E5628C7D-AF4C-36EE-8EA3-CCA584355DC8} ©
O42 - Logiciel: Visual C++ IDE Base Resource Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {EA440F0D-0860-3C88-9926-6E237525524A} ©
O42 - Logiciel: Light Image Resizer 4.7.3.1 - (.ObviousIdea.) [HKLM][64Bits] -- {EBE030DD-D404-4D92-85E9-8C3624820808}_is1 ©
O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} ©
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} ©
O42 - Logiciel: Microsoft System CLR Types pour SQL Server 2014 - (.Microsoft Corporation.) [HKLM][64Bits] -- {F531C37C-D2F8-4BF8-BBE8-E943F787F761} ©
O42 - Logiciel: Intel(R) Control Center - (.Intel Corporation.) [HKLM][64Bits] -- {F8A9085D-4C7A-41a9-8A77-C8998A96C421} ©
O42 - Logiciel: Visual F# 4.0 SDK Language Pack - FRA - (.Microsoft Corporation.) [HKLM][64Bits] -- {FAD6352E-716B-3F40-94CA-8E919685A965} ©
O42 - Logiciel: Composants requis pour SSDT - (.Microsoft Corporation.) [HKLM][64Bits] -- {FAFA0B40-AF76-4158-9DFA-1D2052CD0963} ©
O42 - Logiciel: Windows Espc Resource Package - (.Microsoft Corporation.) [HKLM][64Bits] -- {FC94D188-1E08-3707-9D23-F41178D44664} ©
O42 - Logiciel: Intel(R) SDK for OpenCL - CPU Only Runtime Package - (.Intel Corporation.) [HKLM][64Bits] -- {FCB3772C-B7D0-4933-B1A9-3707EBACC573} ©
O42 - Logiciel: Unity Web Player - (.Unity Technologies ApS.) [HKCU][64Bits] -- UnityWebPlayer ©
O42 - Logiciel: WinDev 19 - (.PC SOFT.) [HKCU][64Bits] -- WinDev19

---\\ HKCU & HKLM Software Keys (129) - 10s
HKLM\SOFTWARE\Wow6432Node\Adobe
HKLM\SOFTWARE\Wow6432Node\Aladdin Knowledge Systems
HKLM\SOFTWARE\Wow6432Node\AppDataLow
HKLM\SOFTWARE\Wow6432Node\ArenaHD =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Atheros Communications Inc.
HKLM\SOFTWARE\Wow6432Node\Avg
HKLM\SOFTWARE\Wow6432Node\BandiMPEG1
HKLM\SOFTWARE\Wow6432Node\BSD
HKLM\SOFTWARE\Wow6432Node\CDDB
HKLM\SOFTWARE\Wow6432Node\Crossbrowse =>PUP.Optional.CrossBrowse
HKLM\SOFTWARE\Wow6432Node\Disc Soft
HKLM\SOFTWARE\Wow6432Node\DT Soft
HKLM\SOFTWARE\Wow6432Node\FLEXlm License Manager
HKLM\SOFTWARE\Wow6432Node\Foxit Software
HKLM\SOFTWARE\Wow6432Node\Gemtek Electronics Inc.
HKLM\SOFTWARE\Wow6432Node\Google
HKLM\SOFTWARE\Wow6432Node\HighDefAction =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\ihpmserver
HKLM\SOFTWARE\Wow6432Node\Intel
HKLM\SOFTWARE\Wow6432Node\Javasoft
HKLM\SOFTWARE\Wow6432Node\JreMetrics
HKLM\SOFTWARE\Wow6432Node\Khronos
HKLM\SOFTWARE\Wow6432Node\Macromedia
HKLM\SOFTWARE\Wow6432Node\Macrovision
HKLM\SOFTWARE\Wow6432Node\Maxthon3
HKLM\SOFTWARE\Wow6432Node\Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\mtcaMyciloP
HKLM\SOFTWARE\Wow6432Node\mtSaophase
HKLM\SOFTWARE\Wow6432Node\National Instruments
HKLM\SOFTWARE\Wow6432Node\Nuance
HKLM\SOFTWARE\Wow6432Node\NuGet
HKLM\SOFTWARE\Wow6432Node\ObviousIdea
HKLM\SOFTWARE\Wow6432Node\ODBC
HKLM\SOFTWARE\Wow6432Node\oursurfingSoftware =>PUP.Optional.OurSurfing
HKLM\SOFTWARE\Wow6432Node\PowerPivot
HKLM\SOFTWARE\Wow6432Node\PreEmptive Solutions
HKLM\SOFTWARE\Wow6432Node\qBittorrent
HKLM\SOFTWARE\Wow6432Node\Qualcomm Atheros Inc.
HKLM\SOFTWARE\Wow6432Node\RayDld =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Realtek
HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\Rtp
HKLM\SOFTWARE\Wow6432Node\Sony Creative Software
HKLM\SOFTWARE\Wow6432Node\SparkLAN, Inc.
HKLM\SOFTWARE\Wow6432Node\SRS Labs
HKLM\SOFTWARE\Wow6432Node\SuperHideIP
HKLM\SOFTWARE\Wow6432Node\Sybase
HKLM\SOFTWARE\Wow6432Node\Systweak =>PUP.Optional.Systweak
HKLM\SOFTWARE\Wow6432Node\TechSmith
HKLM\SOFTWARE\Wow6432Node\ThinPrint
HKLM\SOFTWARE\Wow6432Node\TweakBit
HKLM\SOFTWARE\Wow6432Node\VMware, Inc.
HKLM\SOFTWARE\Wow6432Node\WafCX
HKLM\SOFTWARE\Wow6432Node\Wondershare
HKLM\SOFTWARE\Wow6432Node\Wow6432Node
HKLM\SOFTWARE\Wow6432Node\YorkNewCin =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\Aqlm
HKCU\SOFTWARE\ArenaHD =>PUP.Optional.CrossRider
HKCU\SOFTWARE\BandiMPEG1
HKCU\SOFTWARE\BrashMonkey
HKCU\SOFTWARE\BSD
HKCU\SOFTWARE\Chromium
HKCU\SOFTWARE\CinemaP-1.9cV23.09-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\Code Sector
HKCU\SOFTWARE\DefaultCompany
HKCU\SOFTWARE\DirectShow
HKCU\SOFTWARE\Disc Soft
HKCU\SOFTWARE\drpsu
HKCU\SOFTWARE\Epic Games
HKCU\SOFTWARE\FBReader
HKCU\SOFTWARE\Foxit Software
HKCU\SOFTWARE\FreeTime
HKCU\SOFTWARE\globalUpdate =>PUP.Optional.GlobalUpdate
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\HighDefAction =>PUP.Optional.CrossRider
HKCU\SOFTWARE\IM Providers
HKCU\SOFTWARE\Innovative Solutions
HKCU\SOFTWARE\Intel
HKCU\SOFTWARE\JavaSoft
HKCU\SOFTWARE\Local AppWizard-Generated Applications
HKCU\SOFTWARE\Macromedia
HKCU\SOFTWARE\MainConcept
HKCU\SOFTWARE\Maxthon3
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\mtcaMyciloP
HKCU\SOFTWARE\Mvbl
HKCU\SOFTWARE\National Instruments
HKCU\SOFTWARE\Netscape
HKCU\SOFTWARE\ObviousIdea
HKCU\SOFTWARE\ODBC
HKCU\SOFTWARE\Opera Software
HKCU\SOFTWARE\PC SOFT
HKCU\SOFTWARE\PEP
HKCU\SOFTWARE\Piriform
HKCU\SOFTWARE\Python
HKCU\SOFTWARE\Qdvvnul
HKCU\SOFTWARE\QtProject
HKCU\SOFTWARE\Realtek
HKCU\SOFTWARE\SMADΔV
HKCU\SOFTWARE\Sony Creative Software
HKCU\SOFTWARE\Sony Ericsson
HKCU\SOFTWARE\Sparx Systems
HKCU\SOFTWARE\Sybase
HKCU\SOFTWARE\Synaptics
HKCU\SOFTWARE\Sysinternals
HKCU\SOFTWARE\systweak =>PUP.Optional.Systweak
HKCU\SOFTWARE\TechSmith
HKCU\SOFTWARE\Trolltech
HKCU\SOFTWARE\Unity
HKCU\SOFTWARE\Unity Technologies
HKCU\SOFTWARE\VB and VBA Program Settings
HKCU\SOFTWARE\VMware, Inc.
HKCU\SOFTWARE\WinRAR
HKCU\SOFTWARE\WinRAR SFX
HKCU\SOFTWARE\Wintertree
HKCU\SOFTWARE\Wondershare
HKCU\SOFTWARE\Wow6432Node
HKCU\SOFTWARE\YorkNewCin =>PUP.Optional.CrossRider
HKCU\SOFTWARE\YourCompanyName
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\AppDataLow\Software
HKCU\SOFTWARE\AppDataLow\Software\Crossrider =>PUP.Optional.CrossRider
HKCU\SOFTWARE\AppDataLow\Software\JavaSoft
HKCU\SOFTWARE\AppDataLow\Software\Unity

---\\ Contenu des dossiers Programmes (283) - 15s
O43 - CFD: 2015/10/17 21:28:56 - [] D -- C:\Program Files (x86)\Adobe
O43 - CFD: 2015/10/18 00:37:37 - [] D -- C:\Program Files (x86)\Adobe Muse
O43 - CFD: 2015/09/23 14:10:50 - [] D -- C:\Program Files (x86)\AppInsights
O43 - CFD: 2015/09/02 19:40:47 - [] D -- C:\Program Files (x86)\BandiMPEG1
O43 - CFD: 2015/10/25 13:27:38 - [] D -- C:\Program Files (x86)\BeinConnecTVv2
O43 - CFD: 2015/09/02 16:11:07 - [] D -- C:\Program Files (x86)\Cisco
O43 - CFD: 2015/10/22 18:30:31 - [] D -- C:\Program Files (x86)\Common Files
O43 - CFD: 2015/10/25 13:35:49 - [] D -- C:\Program Files (x86)\Connect24@24
O43 - CFD: 2015/10/24 19:57:26 - [] D -- C:\Program Files (x86)\Cracklock
O43 - CFD: 2015/09/18 17:30:47 - [] HD -- C:\Program Files (x86)\Dr.Fone_Temp
O43 - CFD: 2015/09/19 10:42:32 - [] HD -- C:\Program Files (x86)\DrFoneAndroid_Temp
O43 - CFD: 2015/09/28 20:37:16 - [] D -- C:\Program Files (x86)\FBReader
O43 - CFD: 2015/09/08 21:53:35 - [] D -- C:\Program Files (x86)\Foxit Software
O43 - CFD: 2015/09/23 18:21:23 - [] D -- C:\Program Files (x86)\globalUpdate =>PUP.Optional.GlobalUpdate
O43 - CFD: 2015/10/06 06:35:18 - [] D -- C:\Program Files (x86)\Google
O43 - CFD: 2015/09/23 11:34:49 - [] D -- C:\Program Files (x86)\IIS
O43 - CFD: 2015/09/23 11:36:46 - [] D -- C:\Program Files (x86)\IIS Express
O43 - CFD: 2015/09/11 21:48:34 - [] D -- C:\Program Files (x86)\Innovative Solutions
O43 - CFD: 2015/10/07 08:29:53 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 2015/09/12 00:10:44 - [] D -- C:\Program Files (x86)\Intel
O43 - CFD: 2015/09/23 13:27:46 - [] D -- C:\Program Files (x86)\Internet Explorer
O43 - CFD: 2015/09/03 08:20:19 - [] D -- C:\Program Files (x86)\Maxthon
O43 - CFD: 2015/09/14 13:47:58 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services
O43 - CFD: 2015/09/23 11:48:22 - [] D -- C:\Program Files (x86)\Microsoft ASP.NET
O43 - CFD: 2015/09/23 11:27:33 - [] D -- C:\Program Files (x86)\Microsoft Help Viewer
O43 - CFD: 2015/09/14 09:22:55 - [] D -- C:\Program Files (x86)\Microsoft Office
O43 - CFD: 2015/09/23 11:36:13 - [] D -- C:\Program Files (x86)\Microsoft Office365 Tools
O43 - CFD: 2015/09/23 11:58:52 - [] D -- C:\Program Files (x86)\Microsoft SDKs
O43 - CFD: 2015/09/05 12:47:12 - [] D -- C:\Program Files (x86)\Microsoft Silverlight
O43 - CFD: 2015/09/23 11:54:21 - [] D -- C:\Program Files (x86)\Microsoft SQL Server
O43 - CFD: 2015/09/23 11:54:11 - [] D -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
O43 - CFD: 2015/09/23 11:31:32 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio 12.0
O43 - CFD: 2015/09/23 11:50:11 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio 14.0
O43 - CFD: 2015/09/23 11:35:01 - [] D -- C:\Program Files (x86)\Microsoft WCF Data Services
O43 - CFD: 2015/09/23 11:44:14 - [] D -- C:\Program Files (x86)\Microsoft Web Tools
O43 - CFD: 2015/09/23 11:21:25 - [] D -- C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 2015/09/14 13:51:43 - [] D -- C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 2015/09/02 14:45:10 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service
O43 - CFD: 2015/09/23 11:28:09 - [] D -- C:\Program Files (x86)\MSBuild
O43 - CFD: 2015/09/23 13:50:35 - [] D -- C:\Program Files (x86)\National Instruments
O43 - CFD: 2015/09/23 11:35:14 - [] D -- C:\Program Files (x86)\NuGet
O43 - CFD: 2015/09/15 10:59:28 - [] D -- C:\Program Files (x86)\ObviousIdea
O43 - CFD: 2015/09/19 13:48:27 - [] D -- C:\Program Files (x86)\Opera
O43 - CFD: 2015/10/15 09:54:15 - [] D -- C:\Program Files (x86)\Prezi
O43 - CFD: 2015/10/17 20:37:08 - [] D -- C:\Program Files (x86)\qBittorrent
O43 - CFD: 2015/09/02 20:43:41 - [] D -- C:\Program Files (x86)\QuickTime
O43 - CFD: 2015/09/19 13:47:34 - [] D -- C:\Program Files (x86)\RayDld =>PUP.Optional.CrossRider
O43 - CFD: 2015/09/02 16:38:59 - [] D -- C:\Program Files (x86)\Realtek
O43 - CFD: 2009/07/14 05:32:38 - [] D -- C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 2015/10/03 08:54:53 - [] D -- C:\Program Files (x86)\Rosetta Stone
O43 - CFD: 2015/09/07 20:00:14 - [] D -- C:\Program Files (x86)\Share Wifi
O43 - CFD: 2015/09/23 11:49:40 - [] D -- C:\Program Files (x86)\ShellDir
O43 - CFD: 2015/09/10 10:12:16 - [] D -- C:\Program Files (x86)\Sony
O43 - CFD: 2015/10/08 19:01:49 - [] D -- C:\Program Files (x86)\Sparx Systems
O43 - CFD: 2015/10/11 13:44:49 - [] D -- C:\Program Files (x86)\Sublime Text 3
O43 - CFD: 2015/10/08 17:59:24 - [] D -- C:\Program Files (x86)\SuperHideIP
O43 - CFD: 2015/10/07 08:28:46 - [] D -- C:\Program Files (x86)\Sybase
O43 - CFD: 2015/09/02 20:43:24 - [] D -- C:\Program Files (x86)\TechSmith
O43 - CFD: 2015/09/11 23:54:24 - [0] HD -- C:\Program Files (x86)\Temp
O43 - CFD: 2015/09/23 12:14:36 - [] D -- C:\Program Files (x86)\Tencent =>PUP.Optional.TencentAddressBar
O43 - CFD: 2009/07/14 04:57:06 - [0] HD -- C:\Program Files (x86)\Uninstall Information
O43 - CFD: 2015/10/11 11:49:38 - [] D -- C:\Program Files (x86)\VMware
O43 - CFD: 2011/04/12 09:16:36 - [] D -- C:\Program Files (x86)\Windows Defender
O43 - CFD: 2015/09/23 11:53:19 - [] D -- C:\Program Files (x86)\Windows Kits
O43 - CFD: 2011/04/12 09:16:36 - [] D -- C:\Program Files (x86)\Windows Mail
O43 - CFD: 2011/04/12 09:16:36 - [] D -- C:\Program Files (x86)\Windows Media Player
O43 - CFD: 2009/07/14 05:32:38 - [] D -- C:\Program Files (x86)\Windows NT
O43 - CFD: 2011/04/12 09:16:36 - [] D -- C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 2010/11/21 03:31:38 - [] D -- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 2011/04/12 09:16:36 - [] D -- C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 2015/09/19 10:42:26 - [0] D -- C:\Program Files (x86)\Wondershare
O43 - CFD: 2015/10/24 11:12:14 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2015/10/24 11:12:19 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2015/10/24 14:15:09 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BeinConnecTVv2
O43 - CFD: 2015/10/24 11:12:29 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
O43 - CFD: 2015/10/24 11:12:34 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Connect24@24
O43 - CFD: 2015/10/24 19:57:25 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cracklock
O43 - CFD: 2015/10/24 11:12:45 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Pro
O43 - CFD: 2015/10/24 11:12:50 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Data Recovery Wizard 8.8
O43 - CFD: 2015/10/24 11:12:55 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Enterprise Architect 11
O43 - CFD: 2015/10/24 11:13:00 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FBReader for Windows
O43 - CFD: 2015/10/24 11:13:05 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
O43 - CFD: 2015/10/24 11:13:10 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 2015/10/24 11:13:15 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 2015/10/24 11:13:21 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
O43 - CFD: 2015/10/24 11:13:26 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless
O43 - CFD: 2015/10/24 11:13:31 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
O43 - CFD: 2015/10/24 11:51:36 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
O43 - CFD: 2015/10/24 14:16:27 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2015/10/24 11:13:52 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Expression
O43 - CFD: 2015/10/24 11:14:02 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
O43 - CFD: 2015/10/24 11:14:07 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
O43 - CFD: 2015/10/24 11:14:12 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Monitor de Red Inalámbrica
O43 - CFD: 2015/10/24 11:52:22 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MySQL
O43 - CFD: 2015/10/24 11:52:32 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\National Instruments
O43 - CFD: 2015/10/24 11:14:43 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ObviousIdea
O43 - CFD: 2015/10/24 11:52:47 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
O43 - CFD: 2015/10/24 11:14:59 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rosetta Stone
O43 - CFD: 2015/10/24 11:53:03 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Share Wifi
O43 - CFD: 2015/10/24 11:53:13 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
O43 - CFD: 2015/10/24 11:15:19 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 2015/10/24 11:15:24 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Super Hide IP
O43 - CFD: 2015/10/24 11:15:35 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sybase
O43 - CFD: 2015/10/24 11:53:39 - [] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
O43 - CFD: 2015/10/24 11:15:45 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
O43 - CFD: 2015/10/24 11:15:50 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tencent =>PUP.Optional.TencentAddressBar
O43 - CFD: 2015/10/24 11:15:55 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy
O43 - CFD: 2015/10/24 11:16:01 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unity 5.0.2f1 (64-bit)
O43 - CFD: 2015/10/24 11:16:06 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
O43 - CFD: 2015/10/24 11:16:16 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2015
O43 - CFD: 2015/10/24 11:54:20 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDev 19
O43 - CFD: 2015/10/24 11:16:27 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 2015/10/24 11:16:32 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
O43 - CFD: 2015/10/24 09:58:50 - [] D -- C:\ProgramData\Adobe
O43 - CFD: 2009/07/14 05:08:56 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 2015/10/24 10:56:41 - [] D -- C:\ProgramData\Baidu
O43 - CFD: 2015/10/24 10:56:57 - [] D -- C:\ProgramData\BSD
O43 - CFD: 2015/09/02 13:52:48 - [0] SHD -- C:\ProgramData\Bureau
O43 - CFD: 2015/10/24 10:57:20 - [] D -- C:\ProgramData\caMyciloP
O43 - CFD: 2015/10/24 10:57:25 - [] D -- C:\ProgramData\caMyciloPs
O43 - CFD: 2015/10/24 10:57:30 - [] HD -- C:\ProgramData\Common Files
O43 - CFD: 2015/10/24 10:57:35 - [] D -- C:\ProgramData\C__Users_QBDO_AppData_Local_Temp_Rar$EXa0.137_Crack_SuperHideIP.exe
O43 - CFD: 2015/10/24 10:57:40 - [] D -- C:\ProgramData\DAEMON Tools Pro
O43 - CFD: 2009/07/14 05:08:56 - [0] SHD -- C:\ProgramData\Desktop
O43 - CFD: 2009/07/14 05:08:56 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 2015/10/24 17:13:10 - [] D -- C:\ProgramData\Epic
O43 - CFD: 2015/09/02 13:52:48 - [0] SHD -- C:\ProgramData\Favoris
O43 - CFD: 2009/07/14 05:08:56 - [0] SHD -- C:\ProgramData\Favorites
O43 - CFD: 2015/10/24 10:58:06 - [] D -- C:\ProgramData\FLEXnet
O43 - CFD: 2015/10/24 10:59:13 - [] D -- C:\ProgramData\Intel
O43 - CFD: 2015/10/24 10:59:44 - [] D -- C:\ProgramData\Intel.sav
O43 - CFD: 2015/09/02 13:52:48 - [0] SHD -- C:\ProgramData\Menu Démarrer
O43 - CFD: 2015/10/24 11:00:04 - [] D -- C:\ProgramData\MFAData
O43 - CFD: 2015/10/24 12:02:10 - [] SD -- C:\ProgramData\Microsoft
O43 - CFD: 2015/10/24 14:27:07 - [] D -- C:\ProgramData\Microsoft DNX
O43 - CFD: 2015/10/24 12:02:26 - [] D -- C:\ProgramData\Microsoft Help
O43 - CFD: 2015/10/24 12:02:31 - [] D -- C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS
O43 - CFD: 2015/09/02 13:52:48 - [0] SHD -- C:\ProgramData\Modèles
O43 - CFD: 2015/10/24 12:06:58 - [] D -- C:\ProgramData\National Instruments
O43 - CFD: 2015/10/24 12:07:19 - [] D -- C:\ProgramData\NuGet
O43 - CFD: 2015/10/24 12:07:40 - [] D -- C:\ProgramData\Oracle
O43 - CFD: 2015/10/24 13:03:31 - [] D -- C:\ProgramData\Package Cache
O43 - CFD: 2015/10/24 13:03:46 - [] D -- C:\ProgramData\PowerAMC 15
O43 - CFD: 2015/10/24 13:05:18 - [] D -- C:\ProgramData\PreEmptive Solutions
O43 - CFD: 2015/10/24 13:05:24 - [] D -- C:\ProgramData\Prism
O43 - CFD: 2015/10/24 13:05:29 - [] D -- C:\ProgramData\Qualcomm Atheros
O43 - CFD: 2015/10/24 13:05:34 - [] D -- C:\ProgramData\regid.1986-12.com.adobe
O43 - CFD: 2015/10/24 13:05:39 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft
O43 - CFD: 2015/10/24 13:05:44 - [] D -- C:\ProgramData\regid.1995-08.com.techsmith
O43 - CFD: 2015/10/24 13:06:05 - [] D -- C:\ProgramData\Roaming
O43 - CFD: 2015/10/08 22:14:24 - [] D -- C:\ProgramData\Rosetta Stone
O43 - CFD: 2015/09/18 20:50:34 - [] D -- C:\ProgramData\Samsung
O43 - CFD: 2015/10/24 10:40:27 - [] D -- C:\ProgramData\Saophase
O43 - CFD: 2015/09/23 13:43:45 - [] D -- C:\ProgramData\Saophases
O43 - CFD: 2015/09/10 10:12:16 - [] D -- C:\ProgramData\Sony
O43 - CFD: 2009/07/14 05:08:56 - [0] SHD -- C:\ProgramData\Start Menu
O43 - CFD: 2015/10/07 20:20:24 - [] D -- C:\ProgramData\SuperHideIP
O43 - CFD: 2015/09/02 20:43:24 - [] D -- C:\ProgramData\TechSmith
O43 - CFD: 2009/07/14 05:08:56 - [0] SHD -- C:\ProgramData\Templates
O43 - CFD: 2015/09/11 22:42:04 - [] D -- C:\ProgramData\TweakBit
O43 - CFD: 2015/10/17 08:32:17 - [] D -- C:\ProgramData\Unity
O43 - CFD: 2015/10/24 10:40:16 - [] D -- C:\ProgramData\VMware
O43 - CFD: 2015/09/23 21:21:17 - [] D -- C:\ProgramData\VsTelemetry
O43 - CFD: 2015/09/18 19:30:14 - [] D -- C:\ProgramData\Wondershare
O43 - CFD: 2015/09/13 09:40:17 - [] D -- C:\Program Files (x86)\Common Files\Adobe
O43 - CFD: 2015/10/17 21:28:56 - [] D -- C:\Program Files (x86)\Common Files\Adobe AIR
O43 - CFD: 2015/10/22 18:30:31 - [] D -- C:\Program Files (x86)\Common Files\Aladdin Shared
O43 - CFD: 2015/09/23 11:27:43 - [] D -- C:\Program Files (x86)\Common Files\Designer
O43 - CFD: 2015/09/11 21:38:53 - [] D -- C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 2015/09/02 16:55:55 - [] D -- C:\Program Files (x86)\Common Files\Intel Corporation
O43 - CFD: 2015/09/29 20:03:22 - [] D -- C:\Program Files (x86)\Common Files\Java
O43 - CFD: 2015/10/03 08:55:04 - [] D -- C:\Program Files (x86)\Common Files\Macrovision Shared
O43 - CFD: 2015/09/23 13:55:27 - [] D -- C:\Program Files (x86)\Common Files\Merge Modules
O43 - CFD: 2015/09/23 11:46:38 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared
O43 - CFD: 2015/09/23 13:53:45 - [] D -- C:\Program Files (x86)\Common Files\OPC Foundation
O43 - CFD: 2015/10/21 21:01:01 - [] D -- C:\Program Files (x86)\Common Files\PC SOFT
O43 - CFD: 2015/10/21 20:46:11 - [] D -- C:\Program Files (x86)\Common Files\SafeNet Sentinel
O43 - CFD: 2009/07/14 03:20:08 - [] D -- C:\Program Files (x86)\Common Files\Services
O43 - CFD: 2009/07/14 03:20:08 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines
O43 - CFD: 2015/09/14 09:21:19 - [] D -- C:\Program Files (x86)\Common Files\System
O43 - CFD: 2015/09/02 20:43:35 - [] D -- C:\Program Files (x86)\Common Files\TechSmith Shared
O43 - CFD: 2015/10/11 11:49:48 - [] D -- C:\Program Files (x86)\Common Files\ThinPrint
O43 - CFD: 2015/10/11 11:49:38 - [] D -- C:\Program Files (x86)\Common Files\VMware
O43 - CFD: 2015/10/08 19:00:02 - [] D -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
O43 - CFD: 2015/09/18 17:11:54 - [] D -- C:\Program Files (x86)\Common Files\Wondershare
O43 - CFD: 2015/10/17 21:33:20 - [] D -- C:\Users\QBDO\AppData\Roaming\Adobe
O43 - CFD: 2015/10/17 22:06:25 - [] D -- C:\Users\QBDO\AppData\Roaming\AdobeMuse
O43 - CFD: 2015/10/17 21:34:51 - [0] D -- C:\Users\QBDO\AppData\Roaming\AdobeMuseLibrary
O43 - CFD: 2015/10/23 19:56:28 - [] D -- C:\Users\QBDO\AppData\Roaming\Applications WinDev
O43 - CFD: 2015/09/02 19:57:34 - [] D -- C:\Users\QBDO\AppData\Roaming\BANDISOFT
O43 - CFD: 2015/10/15 08:11:54 - [] D -- C:\Users\QBDO\AppData\Roaming\com.prezi.PreziDesktop
O43 - CFD: 2015/09/23 12:15:25 - [] D -- C:\Users\QBDO\AppData\Roaming\cpuminer
O43 - CFD: 2015/10/08 17:57:50 - [] D -- C:\Users\QBDO\AppData\Roaming\C__Users_QBDO_AppData_Local_Temp_Rar$EXa0.137_Crack_SuperHideIP.exe
O43 - CFD: 2015/09/14 13:24:31 - [] D -- C:\Users\QBDO\AppData\Roaming\DAEMON Tools iSCSI Target
O43 - CFD: 2015/10/25 18:51:39 - [] D -- C:\Users\QBDO\AppData\Roaming\DAEMON Tools Pro
O43 - CFD: 2015/10/11 17:11:10 - [] D -- C:\Users\QBDO\AppData\Roaming\FileZilla
O43 - CFD: 2015/09/16 04:56:25 - [] D -- C:\Users\QBDO\AppData\Roaming\Foxit Software
O43 - CFD: 2015/09/18 17:13:31 - [0] D -- C:\Users\QBDO\AppData\Roaming\HMYGSetting
O43 - CFD: 2015/09/02 13:53:22 - [] D -- C:\Users\QBDO\AppData\Roaming\Identities
O43 - CFD: 2015/09/02 16:29:55 - [] D -- C:\Users\QBDO\AppData\Roaming\InstallShield
O43 - CFD: 2015/09/02 16:12:18 - [] D -- C:\Users\QBDO\AppData\Roaming\Intel
O43 - CFD: 2015/09/02 16:55:20 - [] D -- C:\Users\QBDO\AppData\Roaming\Intel Corporation
O43 - CFD: 2015/09/03 15:07:57 - [] D -- C:\Users\QBDO\AppData\Roaming\Macromedia
O43 - CFD: 2015/09/03 08:20:45 - [] D -- C:\Users\QBDO\AppData\Roaming\Maxthon3
O43 - CFD: 2011/04/12 09:28:08 - [0] D -- C:\Users\QBDO\AppData\Roaming\Media Center Programs
O43 - CFD: 2015/10/21 10:34:55 - [] SD -- C:\Users\QBDO\AppData\Roaming\Microsoft
O43 - CFD: 2015/09/12 07:49:01 - [] D -- C:\Users\QBDO\AppData\Roaming\MonoDevelop-Unity-4.0
O43 - CFD: 2015/09/02 14:45:28 - [] D -- C:\Users\QBDO\AppData\Roaming\Mozilla
O43 - CFD: 2015/09/28 21:21:14 - [] D -- C:\Users\QBDO\AppData\Roaming\NuGet
O43 - CFD: 2015/09/15 11:02:40 - [] D -- C:\Users\QBDO\AppData\Roaming\ObviousIdea
O43 - CFD: 2015/09/19 13:48:24 - [0] D -- C:\Users\QBDO\AppData\Roaming\Opera Software
O43 - CFD: 2015/09/19 13:47:19 - [] D -- C:\Users\QBDO\AppData\Roaming\oursurfing =>PUP.Optional.OurSurfing
O43 - CFD: 2015/09/10 10:14:57 - [0] D -- C:\Users\QBDO\AppData\Roaming\Publish Providers
O43 - CFD: 2015/10/25 14:54:30 - [] D -- C:\Users\QBDO\AppData\Roaming\qBittorrent
O43 - CFD: 2015/09/30 11:15:12 - [] D -- C:\Users\QBDO\AppData\Roaming\QtProject
O43 - CFD: 2015/10/08 19:43:31 - [0] D -- C:\Users\QBDO\AppData\Roaming\Smadav
O43 - CFD: 2015/09/10 10:26:57 - [] D -- C:\Users\QBDO\AppData\Roaming\Sony
O43 - CFD: 2015/10/08 19:03:04 - [] D -- C:\Users\QBDO\AppData\Roaming\Sparx Systems
O43 - CFD: 2015/09/12 07:48:56 - [] D -- C:\Users\QBDO\AppData\Roaming\stetic
O43 - CFD: 2015/10/11 13:44:54 - [] D -- C:\Users\QBDO\AppData\Roaming\Sublime Text 3
O43 - CFD: 2015/09/29 20:01:01 - [] D -- C:\Users\QBDO\AppData\Roaming\Sun
O43 - CFD: 2015/10/07 20:20:24 - [] D -- C:\Users\QBDO\AppData\Roaming\SuperHideIP
O43 - CFD: 2015/09/12 07:23:29 - [] D -- C:\Users\QBDO\AppData\Roaming\Synaptics
O43 - CFD: 2015/09/19 21:45:23 - [] D -- C:\Users\QBDO\AppData\Roaming\systweak =>PUP.Optional.Systweak
O43 - CFD: 2015/09/02 20:44:57 - [] D -- C:\Users\QBDO\AppData\Roaming\TechSmith
O43 - CFD: 2015/10/25 17:33:50 - [] D -- C:\Users\QBDO\AppData\Roaming\TeraCopy
O43 - CFD: 2015/09/13 14:40:15 - [] D -- C:\Users\QBDO\AppData\Roaming\Unity
O43 - CFD: 2015/10/25 11:13:46 - [] D -- C:\Users\QBDO\AppData\Roaming\Unreal Engine
O43 - CFD: 2015/10/25 17:32:32 - [] D -- C:\Users\QBDO\AppData\Roaming\vlc
O43 - CFD: 2015/10/11 20:18:52 - [] D -- C:\Users\QBDO\AppData\Roaming\VMware
O43 - CFD: 2015/09/02 14:49:32 - [] D -- C:\Users\QBDO\AppData\Roaming\WinRAR
O43 - CFD: 2015/09/18 17:52:14 - [] D -- C:\Users\QBDO\AppData\Roaming\Wondershare
O43 - CFD: 2015/10/25 18:56:47 - [] D -- C:\Users\QBDO\AppData\Roaming\ZHP
O43 - CFD: 2015/10/11 07:20:30 - [0] D -- C:\Users\QBDO\AppData\Roaming\{386C3A6A-68E1-4C91-AEA1-B6B7EEF84008}
O43 - CFD: 2015/10/11 07:18:53 - [0] D -- C:\Users\QBDO\AppData\Roaming\{3994AA12-0475-4644-BB82-C060C51518EB}
O43 - CFD: 2015/10/11 07:14:46 - [0] D -- C:\Users\QBDO\AppData\Roaming\{46AAE192-B04C-49B7-84B9-476D80806BB2}
O43 - CFD: 2015/10/11 07:19:44 - [0] D -- C:\Users\QBDO\AppData\Roaming\{7DBFF97A-388B-491A-9BFE-BCE69EF6A699}
O43 - CFD: 2015/10/11 07:14:27 - [0] D -- C:\Users\QBDO\AppData\Roaming\{D30A88AE-3793-41D3-926A-E3157998582B}
O43 - CFD: 2015/10/25 09:04:18 - [] D -- C:\Users\QBDO\AppData\Local\Adobe
O43 - CFD: 2015/09/12 15:18:12 - [] D -- C:\Users\QBDO\AppData\Local\Adobe_Systems_Incorporate
O43 - CFD: 2015/09/02 13:52:58 - [0] SHD -- C:\Users\QBDO\AppData\Local\Application Data
O43 - CFD: 2015/10/04 11:42:17 - [] D -- C:\Users\QBDO\AppData\Local\Apps
O43 - CFD: 2015/10/16 21:52:34 - [] D -- C:\Users\QBDO\AppData\Local\Avg2015
O43 - CFD: 2015/10/24 17:13:26 - [] D -- C:\Users\QBDO\AppData\Local\CEF
O43 - CFD: 2015/10/25 18:54:18 - [] D -- C:\Users\QBDO\AppData\Local\CrashDumps
O43 - CFD: 2015/10/18 21:50:36 - [] D -- C:\Users\QBDO\AppData\Local\Eclipse
O43 - CFD: 2015/09/11 13:44:24 - [] D -- C:\Users\QBDO\AppData\Local\ElevatedDiagnostics
O43 - CFD: 2015/10/24 17:13:09 - [] D -- C:\Users\QBDO\AppData\Local\EpicGamesLauncher
O43 - CFD: 2015/09/14 13:39:50 - [] D -- C:\Users\QBDO\AppData\Local\globalUpdate =>PUP.Optional.GlobalUpdate
O43 - CFD: 2015/09/17 04:21:24 - [] D -- C:\Users\QBDO\AppData\Local\Google
O43 - CFD: 2015/09/02 13:52:58 - [0] SHD -- C:\Users\QBDO\AppData\Local\Historique
O43 - CFD: 2015/10/16 21:52:34 - [] D -- C:\Users\QBDO\AppData\Local\MFAData
O43 - CFD: 2015/10/15 12:21:41 - [] D -- C:\Users\QBDO\AppData\Local\Microsoft
O43 - CFD: 2015/09/03 07:57:39 - [0] D -- C:\Users\QBDO\AppData\Local\Microsoft Help
O43 - CFD: 2015/09/12 07:48:54 - [] D -- C:\Users\QBDO\AppData\Local\MonoDevelop-Unity-4.0
O43 - CFD: 2015/09/02 14:51:29 - [] D -- C:\Users\QBDO\AppData\Local\Mozilla
O43 - CFD: 2015/09/23 13:55:55 - [] D -- C:\Users\QBDO\AppData\Local\National Instruments
O43 - CFD: 2015/09/19 13:48:24 - [0] D -- C:\Users\QBDO\AppData\Local\Opera Software
O43 - CFD: 2015/10/22 21:31:22 - [] D -- C:\Users\QBDO\AppData\Local\PC SOFT
O43 - CFD: 2015/09/14 11:59:33 - [] D -- C:\Users\QBDO\AppData\Local\pip
O43 - CFD: 2015/09/07 17:37:13 - [] D -- C:\Users\QBDO\AppData\Local\Programs
O43 - CFD: 2015/09/14 11:59:16 - [] D -- C:\Users\QBDO\AppData\Local\qBittorrent
O43 - CFD: 2015/09/10 10:14:51 - [] D -- C:\Users\QBDO\AppData\Local\Sony
O43 - CFD: 2015/10/11 13:44:54 - [] D -- C:\Users\QBDO\AppData\Local\Sublime Text 3
O43 - CFD: 2015/09/02 20:44:25 - [] D -- C:\Users\QBDO\AppData\Local\TechSmith
O43 - CFD: 2015/10/25 18:57:13 - [] D -- C:\Users\QBDO\AppData\Local\Temp
O43 - CFD: 2015/09/02 13:52:58 - [0] SHD -- C:\Users\QBDO\AppData\Local\Temporary Internet Files
O43 - CFD: 2015/10/06 06:34:37 - [] D -- C:\Users\QBDO\AppData\Local\Unity
O43 - CFD: 2015/10/25 11:13:51 - [] D -- C:\Users\QBDO\AppData\Local\UnrealEngine
O43 - CFD: 2015/10/24 17:13:10 - [] D -- C:\Users\QBDO\AppData\Local\UnrealEngineLauncher
O43 - CFD: 2015/09/02 13:53:13 - [0] D -- C:\Users\QBDO\AppData\Local\VirtualStore
O43 - CFD: 2015/10/11 20:18:52 - [0] D -- C:\Users\QBDO\AppData\Local\VMware
O43 - CFD: 2015/09/18 17:11:56 - [] D -- C:\Users\QBDO\AppData\Local\Wondershare
O43 - CFD: 2009/07/14 04:54:32 - [] RD -- C:\Users\QBDO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 2015/09/14 18:23:32 - [] RD -- C:\Users\QBDO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 2015/09/12 15:10:45 - [] D -- C:\Users\QBDO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Applications Chrome
O43 - CFD: 2015/09/28 20:37:16 - [0] D -- C:\Users\QBDO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FBReader for Windows
O43 - CFD: 2015/09/12 15:10:41 - [] D -- C:\Users\QBDO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 2009/07/14 04:49:38 - [] RD -- C:\Users\QBDO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 2015/09/14 11:59:41 - [] D -- C:\Users\QBDO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.4
O43 - CFD: 2015/10/17 16:34:02 - [] RD -- C:\Users\QBDO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 2015/10/04 11:42:19 - [] D -- C:\Users\QBDO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
O43 - CFD: 2015/09/28 22:28:16 - [] D -- C:\Users\QBDO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR

---\\ ShellIconOverlayIdentifiers (SIOI) (5) - 0s
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) [ SkyDrivePro1 (ErrorConflict)] - {8BA85C75-763B-4103-94EB-9470F12FE0F7}. (.Microsoft Corporation - Microsoft SkyDrive Pro Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL ©
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) [ SkyDrivePro2 (SyncInProgress)] - {CD55129A-B1A1-438E-A425-CEBC7DC684EE}. (.Microsoft Corporation - Microsoft SkyDrive Pro Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL ©
O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 3 (InSync) [ SkyDrivePro3 (InSync)] - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1}. (.Microsoft Corporation - Microsoft SkyDrive Pro Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL ©
O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - DLL d’extension d’environnement de stockage.) -- C:\Windows\System32\EhStorShell.dll ©
O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll ©

---\\ Enumération des clés StartupReg (18) - 2s
O53 - SMSR:HKLM\...\startupreg\AdobeAAMUpdater-1.0 [Key] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe ©
O53 - SMSR:HKLM\...\startupreg\AdobeCEPServiceManager [Key] . (.Adobe Systems Incorporated - Adobe CEP Service Manager.) -- C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe ©
O53 - SMSR:HKLM\...\startupreg\app [Key] . (...) -- C:\Program Files (x86)\Tencent\app.exe =>PUP.Optional.TencentAddressBar
O53 - SMSR:HKLM\...\startupreg\BLEServicesCtrl [Key] . (.Intel Corporation - Bluetooth LE Services Control Program.) -- C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe ©
O53 - SMSR:HKLM\...\startupreg\BTMTrayAgent [Key] . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- rundll32.exe (.not file.) ©
O53 - SMSR:HKLM\...\startupreg\cpuminer [Key] . (...) -- C:\Windows\system32\cpm.exe
O53 - SMSR:HKLM\...\startupreg\DAEMON Tools Pro Agent [Key] . (.Disc Soft Ltd - DAEMON Tools Pro Agent.) -- C:\Program Files\DAEMON Tools Pro\DTAgent.exe ©
O53 - SMSR:HKLM\...\startupreg\HotKeysCmds [Key] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe ©
O53 - SMSR:HKLM\...\startupreg\IAStorIcon [Key] . (.Intel Corporation - IAStorIcon.) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe ©
O53 - SMSR:HKLM\...\startupreg\IgfxTray [Key] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe ©
O53 - SMSR:HKLM\...\startupreg\Persistence [Key] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe ©
O53 - SMSR:HKLM\...\startupreg\RTHDVCPL [Key] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe ©
O53 - SMSR:HKLM\...\startupreg\RtsCM [Key] . (.Realtek Semiconductor Corp. - Realtek Camera Man.) -- RTSCM64.EXE (.not file.) ©
O53 - SMSR:HKLM\...\startupreg\SunJavaUpdateSched [Key] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ©
O53 - SMSR:HKLM\...\startupreg\SynTPEnh [Key] . (.Synaptics Incorporated - .) -- C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.) ©
O53 - SMSR:HKLM\...\startupreg\USB3MON [Key] . (.Intel Corporation - Intel(R) USB 3.0 Monitor.) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe ©
O53 - SMSR:HKLM\...\startupreg\vmware-tray.exe [Key] . (.VMware, Inc. - VMware Tray Process.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe ©
O53 - SMSR:HKLM\...\startupreg\winlogon [Key] . (...) -- C:\Windows\System32\cleanmg.exe (.not file.)

---\\ Liste des pilotes du système (85) - 6s
O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [491088] ©
O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [339536] ©
O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\drivers\adpu320.sys [182864] ©
O58 - SDL:2013/01/14 10:32:16 A . (.SafeNet Inc. - SafeNet-Inc. Sentinel Class Driver.) -- C:\Windows\System32\drivers\aksclass.sys [21448]
O58 - SDL:2013/01/14 10:32:16 A . (.SafeNet Inc. - Safenet Inc. Sentinel Data Filter Driver.) -- C:\Windows\System32\drivers\aksdf.sys [90056]
O58 - SDL:2013/02/19 13:04:12 A . (.SafeNet Inc. - Ancillary Function Driver.) -- C:\Windows\System32\drivers\aksfridge.sys [141064]
O58 - SDL:2013/01/14 10:32:16 A . (.SafeNet Inc. - AKSHASP Device Driver.) -- C:\Windows\System32\drivers\akshasp.sys [60488]
O58 - SDL:2013/01/14 10:32:16 A . (.SafeNet Inc. - Sentinel HL Device Driver.) -- C:\Windows\System32\drivers\akshhl.sys [63944]
O58 - SDL:2013/03/05 13:01:54 A . (.SafeNet Inc. - SafeNet-Inc. Sentinel USB Key Driver.) -- C:\Windows\System32\drivers\aksusb.sys [303368]
O58 - SDL:2009/07/14 01:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [15440] ©
O58 - SDL:2010/11/21 03:23:47 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [107904] ©
O58 - SDL:2009/07/14 01:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [194128] ©
O58 - SDL:2010/11/21 03:23:47 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [27008] ©
O58 - SDL:2012/03/01 08:55:26 A . (.Windows (R) Win 7 DDK provider - Intel® Centrino® Wireless Bluetooth® + High.) -- C:\Windows\System32\drivers\AmpPal.sys [195584] ©
O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [87632] ©
O58 - SDL:2009/07/14 01:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [97856] ©
O58 - SDL:2009/06/10 20:34:23 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60a.sys [270848] ©
O58 - SDL:2009/06/10 20:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [18432] ©
O58 - SDL:2009/06/10 20:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [8704] ©
O58 - SDL:2009/07/14 01:19:07 A . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [286720] ©
O58 - SDL:2009/06/10 20:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [47104] ©
O58 - SDL:2009/06/10 20:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [14976] ©
O58 - SDL:2009/06/10 20:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [14720] ©
O58 - SDL:2012/02/13 06:53:54 A . (.Intel Corporation - Bluetooth Auxiliary Driver.) -- C:\Windows\System32\drivers\btmaux.sys [95232] ©
O58 - SDL:2012/02/13 07:10:40 A . (.Intel Corporation - Bluetooth HighSpeed Filter Driver.) -- C:\Windows\System32\drivers\btmhsf.sys [747008] ©
O58 - SDL:2009/06/10 20:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [468480] ©
O58 - SDL:2009/07/14 01:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [17488] ©
O58 - SDL:2015/09/14 13:26:41 A . (.Disc Soft Ltd - DAEMON Tools Pro Virtual SCSI Bus Driver.) -- C:\Windows\System32\drivers\dtproscsibus.sys [30352] ©
O58 - SDL:2009/07/14 01:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [530496] ©
O58 - SDL:2009/06/10 20:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3286016] ©
O58 - SDL:2013/03/11 10:03:58 A . (.SafeNet Inc. - Sentinel Hardlock Device Driver for Windows.) -- C:\Windows\System32\drivers\hardlock.sys [331144]
O58 - SDL:2015/08/11 17:27:10 A . (.VMware, Inc. - VMware USB monitor.) -- C:\Windows\System32\drivers\hcmon.sys [57536] ©
O58 - SDL:2009/06/10 20:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [31232] ©
O58 - SDL:2012/07/17 16:12:08 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\drivers\HECIx64.sys [62784] ©
O58 - SDL:2010/11/21 03:23:47 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [78720] ©
O58 - SDL:2011/11/29 17:40:32 A . (.Intel Corporation - Intel Rapid Storage Technology driver - x64.) -- C:\Windows\System32\drivers\iaStor.sys [568600] ©
O58 - SDL:2010/11/21 03:23:47 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [410496] ©
O58 - SDL:2012/03/21 09:13:14 A . (.Intel Corporation - Intel(R) Centrino(R) Wireless (Bluetooth Ad.) -- C:\Windows\System32\drivers\iBtFltCoex.sys [60928] ©
O58 - SDL:2010/08/17 23:28:32 A . (.Intel Corporation - Intel(R) Watchdog Timer Driver (Intel(R) WD.) -- C:\Windows\System32\drivers\ICCWDT.sys [26136] ©
O58 - SDL:2015/05/26 19:02:50 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd64.sys [5375448] ©
O58 - SDL:2009/07/14 01:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [44112] ©
O58 - SDL:2014/09/29 09:16:30 A . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\Windows\System32\drivers\IntcDAud.sys [454416] ©
O58 - SDL:2012/05/20 16:25:32 A . (.Intel Corporation - Intel(R) USB 3.0 Host Controller Switch Dri.) -- C:\Windows\System32\drivers\iusb3hcs.sys [19264] ©
O58 - SDL:2012/05/20 16:25:32 A . (.Intel Corporation - Intel(R) USB 3.0 Hub Driver.) -- C:\Windows\System32\drivers\iusb3hub.sys [357184] ©
O58 - SDL:2012/05/20 16:25:32 A . (.Intel Corporation - Intel(R) USB 3.0 eXtensible Host Controller.) -- C:\Windows\System32\drivers\iusb3xhc.sys [789824] ©
O58 - SDL:2013/07/18 11:54:52 A . (.Qualcomm Atheros Co., Ltd. - Qualcomm Atheros Ar81xx series PCI-E Gigabi.) -- C:\Windows\System32\drivers\L1C62x64.sys [129224] ©
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [114752] ©
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [106560] ©
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [65600] ©
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [115776] ©
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [35392] ©
O58 - SDL:2009/07/14 01:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [284736] ©
O58 - SDL:2012/03/12 12:06:46 A . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\Windows\System32\drivers\Netwsw00.sys [11471872] ©
O58 - SDL:2015/01/09 18:11:14 A . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\Windows\System32\drivers\NETwsw01.sys [11532704] ©
O58 - SDL:2009/07/14 01:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [51264] ©
O58 - SDL:2010/11/21 03:23:47 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [148352] ©
O58 - SDL:2010/11/21 03:23:47 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [166272] ©
O58 - SDL:2015/08/31 10:54:34 A . (.Conexant Systems, Inc. - PRISM Wireless NDIS 5.1 Driver.) -- C:\Windows\System32\drivers\PRISMA02.sys [460544] ©
O58 - SDL:2009/07/14 01:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1524816] ©
O58 - SDL:2009/07/14 01:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [128592] ©
O58 - SDL:2015/06/02 16:48:26 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RTKVHD64.sys [4477656] ©
O58 - SDL:2014/11/06 14:57:46 A . (.Realtek Semiconductor Corp. - Realtek Pcie CardReader Driver for 2K/XP/Vi.) -- C:\Windows\System32\drivers\RtsPStor.sys [359128] ©
O58 - SDL:2014/11/21 15:28:58 A . (.Realtek Semiconductor Corp. - Realtek UVC Driver for XP/Vista/Win7/Win8.) -- C:\Windows\System32\drivers\rtsuvc.sys [2584280] ©
O58 - SDL:2009/06/10 20:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] ©
O58 - SDL:2015/10/20 22:42:08 A . (.Chingachguk & Denger2k - Virtual USB bus driver.) -- C:\Windows\System32\drivers\sicohfarfo.sys [41984]
O58 - SDL:2009/07/14 01:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [43584] ©
O58 - SDL:2009/07/14 01:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [80464] ©
O58 - SDL:2014/12/11 21:56:26 A . (.Synaptics Incorporated - Synaptics SMBus Driver.) -- C:\Windows\System32\drivers\Smb_driver_Intel.sys [33448] ©
O58 - SDL:2012/02/24 09:14:42 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ve.) -- C:\Windows\System32\drivers\ssudbus.sys [99384] ©
O58 - SDL:2012/02/24 09:14:42 A . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ve.) -- C:\Windows\System32\drivers\ssudmdm.sys [203320] ©
O58 - SDL:2009/07/14 01:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [24656] ©
O58 - SDL:2014/12/25 19:58:22 A . (.Synaptics Incorporated - Synaptics Touchpad Win64 Driver.) -- C:\Windows\System32\drivers\SynTP.sys [586408] ©
O58 - SDL:2015/01/29 06:14:18 A . (.TOSHIBA CORPORATION - Bluetooth USB Miniport Driver.) -- C:\Windows\System32\drivers\tosrfusb.sys [77752] ©
O58 - SDL:2015/10/02 12:36:10 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Host-Only Network Adapt.) -- C:\Windows\System32\drivers\VBoxNetAdp6.sys [117768] ©
O58 - SDL:2015/10/02 12:36:10 A . (.Oracle Corporation - VirtualBox NDIS 6.0 Lightweight Filter Driv.) -- C:\Windows\System32\drivers\VBoxNetLwf.sys [146584] ©
O58 - SDL:2009/07/14 01:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [17488] ©
O58 - SDL:2015/08/03 23:10:18 A . (.VMware, Inc. - VMware PCI VMCI Bus Device.) -- C:\Windows\System32\drivers\vmci.sys [90816] ©
O58 - SDL:2015/08/14 11:43:08 A . (.VMware, Inc. - VMware virtual network driver (64-bit).) -- C:\Windows\System32\drivers\vmnet.sys [27328] ©
O58 - SDL:2015/08/14 11:43:08 A . (.VMware, Inc. - VMware virtual network adapter driver (64-b.) -- C:\Windows\System32\drivers\vmnetadapter.sys [28864] ©
O58 - SDL:2015/08/14 11:43:08 A . (.VMware, Inc. - VMware bridge driver (64-bit).) -- C:\Windows\System32\drivers\vmnetbridge.sys [48832] ©
O58 - SDL:2015/08/14 11:43:18 A . (.VMware, Inc. - VMware network application interface driver.) -- C:\Windows\System32\drivers\vmnetuserif.sys [26816] ©
O58 - SDL:2015/08/14 12:03:06 A . (.VMware, Inc. - VMware kernel driver.) -- C:\Windows\System32\drivers\vmx86.sys [66752] ©
O58 - SDL:2009/07/14 01:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [161872] ©
O58 - SDL:2015/08/03 23:10:20 A . (.VMware, Inc. - VMware vSockets Service.) -- C:\Windows\System32\drivers\vsock.sys [75512] ©
O58 - SDL:2015/10/22 21:20:15 A . (.Chingachguk & Denger2k - Virtual USB bus driver.) -- C:\Windows\System32\drivers\xusbbus.sys [41984]

---\\ Derniers fichiers modifiés ou crées (Utilisateur) (18) - 15s
O61 - LFC: 2015/10/21 12:41:35 A . (.PC SOFT.) -- C:\Users\QBDO\Downloads\windev19\WD190PACK040j.exe [1270789464]
O61 - LFC: 2015/10/21 12:41:36 A . (.PC SOFT.) -- C:\Users\QBDO\Downloads\windev19\WD190PACK044k.exe [1162970776]
O61 - LFC: 2015/10/21 12:41:36 A . (.PC SOFT.) -- C:\Users\QBDO\Downloads\windev19\WD190PACK044n.exe [483590144]
O61 - LFC: 2015/10/21 12:41:35 A . (.PC SOFT.) -- C:\Users\QBDO\Downloads\windev19\WD190PACKDVD030e.exe [3264398366]
O61 - LFC: 2015/10/20 22:03:02 A . (..) -- C:\Users\QBDO\Downloads\windev19\DUMP WD19 [Fekbbus]\DUMPT WD19\dseo13b.exe [722414]
O61 - LFC: 2015/10/20 22:42:08 A . (.SafeNet Inc..) -- C:\Users\QBDO\Downloads\windev19\DUMP WD19 [Fekbbus]\DUMPT WD19\haspdinst.exe [14977096]
O61 - LFC: 2015/10/20 22:03:10 A . (..) -- C:\Users\QBDO\Downloads\windev19\DUMP WD19 [Fekbbus]\DUMPT WD19\install sertif.cmd [105]
O61 - LFC: 2015/10/20 22:03:10 A . (..) -- C:\Users\QBDO\Downloads\windev19\DUMP WD19 [Fekbbus]\DUMPT WD19\install-emulator.bat [443]
O61 - LFC: 2015/10/20 22:03:10 A . (..) -- C:\Users\QBDO\Downloads\windev19\DUMP WD19 [Fekbbus]\DUMPT WD19\restart-Virtual Dongle.bat [34]
O61 - LFC: 2015/10/20 22:42:08 A . (..) -- C:\Users\QBDO\Downloads\windev19\DUMP V19 x64 [sicohfarfo_x64]\sicohfarfo_x64\dseo13b.exe [722414]
O61 - LFC: 2015/10/20 22:03:10 A . (..) -- C:\Users\QBDO\Downloads\windev19\DUMP V19 x64 [sicohfarfo_x64]\sicohfarfo_x64\install.cmd [88]
O61 - LFC: 2015/10/20 22:03:10 A . (..) -- C:\Users\QBDO\Downloads\windev19\DUMP V19 x64 [sicohfarfo_x64]\sicohfarfo_x64\remove.cmd [145]
O61 - LFC: 2015/10/20 22:03:10 A . (..) -- C:\Users\QBDO\Downloads\windev19\DUMP V19 x64 [sicohfarfo_x64]\sicohfarfo_x64\restart.cmd [41]
O61 - LFC: 2015/10/20 22:42:08 A . (.Chingachguk & Denger2k.) -- C:\Users\QBDO\Downloads\windev19\DUMP V19 x64 [sicohfarfo_x64]\sicohfarfo_x64\sicohfarfo.sys [41984]
O61 - LFC: 2015/10/20 21:38:39 A . (..) -- C:\Users\QBDO\Downloads\Windev18\Windev Mobile\WM180PACKDVD036f.exe [879040011]
O61 - LFC: 2015/10/20 21:38:39 A . (..) -- C:\Users\QBDO\Downloads\Windev18\Windev\WD180PACKDVD036f.exe [1451229184]
O61 - LFC: 2015/10/25 11:26:26 A . (..) -- C:\Users\QBDO\AppData\Local\UnrealEngine\4.9\Intermediate\CachedAssetRegistry.bin [11706086]
O61 - LFC: 2015/10/25 12:19:46 A . (..) -- C:\Users\QBDO\AppData\Local\Google\Chrome\User Data\ev_hashes_whitelist.bin [674082]

---\\ Associations Shell Spawning (11) - 1s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe ©
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe ©
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ©
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe ©
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe ©
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Maxthon International ltd. - Maxthon Cloud Browser.) -- C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe ©

---\\ Menu de démarrage Internet (12) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ©
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Maxthon International ltd. - Maxthon Cloud Browser.) -- C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Maxthon International ltd. - Maxthon Cloud Browser.) -- C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Maxthon International ltd. - Maxthon Cloud Browser.) -- C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe ©
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Maxthon International ltd. - Maxthon Cloud Browser.) -- C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe ©

---\\ Recherche d'infection sur les navigateurs (3) - 5s
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com/
O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} - (oursurfing) - http://www.oursurfing.com/ =>PUP.Optional.OurSurfing
O69 - SBI: SearchScopes [HKCU] {ielnksrch} [DefaultScope] - (Search the web) - http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNZ4IeknwsEdyUfUeYGEUy1UhH0wHmr1ht_wJaCyteue9qd2nDQWidZvPxsR-Yqk-MJLVy5g_WDTkjJ0xgajWkx9smk1AahhBYljyXyl1aOyoIW4QYw40kCIsa-WPxqDptZNRdMX1W0_O51MG_BllA2SN04LFF&q={searchTerms}

---\\ Enumère les fichiers Crack & Keygen (2) - 13s
O82 - LFC: 2015/07/31 15:16:45 A . (...) -- C:\Users\QBDO\Documents\Téléchargements\EaseUS Data Recovery Wizard v8.8.0 + KeyGen\EaseUS Data Recovery Wizard v8.8.0 + KeyGen\setup.exe [10924990] =>.Crack,Keygen
O82 - LFC: 2014/07/28 18:12:08 A . (...) -- C:\Users\QBDO\Documents\Téléchargements\EaseUS Data Recovery Wizard v8.8.0 + KeyGen\EaseUS Data Recovery Wizard v8.8.0 + KeyGen\Keygen\Keygen.exe [97280] =>.Crack,Keygen

---\\ Enumère les services démarrés par Svchost (33) - 0s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [72192] ©
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [80384] ©
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [80384] ©
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\system32\srvsvc.dll [236032] ©
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [777728] ©
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [853504] ©
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [679424] ©
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [99328] ©
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [344064] ©
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [97792] ©
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [64512] ©
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [359424] ©
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [316928] ©
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du se.) -- C:\Windows\System32\termsrv.dll [680960] ©
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\system32\wuaueng.dll [2477536] ©
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [849920] ©
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [370688] ©
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [569344] ©
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\system32\seclogon.dll [30720] ©
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [70656] ©
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\system32\iscsiexe.dll [156672] ©
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\system32\mmcss.dll [67584] ©
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [242688] ©
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [121856] ©
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [136192] ©
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [111104] ©
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\system32\schedsvc.dll [1110016] ©
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\system32\kmsvc.dll [90624] ©
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84480] ©
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [209920] ©
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\system32\themeservice.dll [44544] ©
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [100864] ©
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [193536] ©

---\\ Liste des exceptions du parefeu Windows (33) - 3s
O87 - FAEL: "TCP Query User{F77866DD-C3C3-4582-AEF6-B06A6CFCFEB3}G:\films\bandisoft bandicam v2.2.5.815 + serial\bdcamsetup.exe" [In-None-P6-TRUE] .(...) -- G:\films\bandisoft bandicam v2.2.5.815 + serial\bdcamsetup.exe (.not file.)
O87 - FAEL: "UDP Query User{8516E9DE-0117-4EFA-8550-CF4371E9310B}G:\films\bandisoft bandicam v2.2.5.815 + serial\bdcamsetup.exe" [In-None-P17-TRUE] .(...) -- G:\films\bandisoft bandicam v2.2.5.815 + serial\bdcamsetup.exe (.not file.)
O87 - FAEL: "TCP Query User{5A767E55-D7A4-44EE-97F5-99124846F796}G:\code moha.exe" [In-None-P6-TRUE] .(...) -- G:\code moha.exe (.not file.)
O87 - FAEL: "UDP Query User{81D18FC1-AC41-47ED-BB9F-C0F4ADA3F86D}G:\code moha.exe" [In-None-P17-TRUE] .(...) -- G:\code moha.exe (.not file.)
O87 - FAEL: "TCP Query User{02CFD8B7-3F61-4247-B434-7770147A45D2}C:\windows\syswow64\cleanmg.exe" [In-None-P6-TRUE] .(...) -- C:\windows\syswow64\cleanmg.exe
O87 - FAEL: "UDP Query User{A10D0F63-95C6-4306-B561-C3D1DB1757F2}C:\windows\syswow64\cleanmg.exe" [In-None-P17-TRUE] .(...) -- C:\windows\syswow64\cleanmg.exe
O87 - FAEL: "TCP Query User{33981B3D-EF57-4160-ABDD-667732D44238}C:\program files\unity\monodevelop\bin\monodevelop.exe" [In-None-P6-TRUE] .(.(c) 2004 MonoDevelop Team and Mike Krueger 2000-2003 - MonoDevelop.) -- C:\program files\unity\monodevelop\bin\monodevelop.exe
O87 - FAEL: "UDP Query User{99D134DF-721B-47CC-BFF7-A6A749B625C1}C:\program files\unity\monodevelop\bin\monodevelop.exe" [In-None-P17-TRUE] .(.(c) 2004 MonoDevelop Team and Mike Krueger 2000-2003 - MonoDevelop.) -- C:\program files\unity\monodevelop\bin\monodevelop.exe
O87 - FAEL: "{D96D9B61-58C7-4DA1-93F4-95A7F953E593}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
O87 - FAEL: "{ABC0F9B5-009C-4997-A9AD-3B3FE497ED77}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
O87 - FAEL: "{F8937C04-2A0B-4116-94D0-7ED06D7B48C5}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\qBittorrent\qbittorrent.exe
O87 - FAEL: "{2B7C037D-A5F6-4201-A3B3-3E755B5180C3}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\qBittorrent\qbittorrent.exe
O87 - FAEL: "TCP Query User{BDF2D50A-FF26-41A2-80DB-DFEDE449AC38}C:\program files (x86)\adobe muse\adobe muse.exe" [In-None-P6-FALSE] .(...) -- C:\program files (x86)\adobe muse\adobe muse.exe
O87 - FAEL: "UDP Query User{2BB56E0F-1F32-46E3-8281-22740079E2DF}C:\program files (x86)\adobe muse\adobe muse.exe" [In-None-P17-FALSE] .(...) -- C:\program files (x86)\adobe muse\adobe muse.exe
O87 - FAEL: "{52E0A573-8209-40C7-9AA4-28FF22272E08}" [In-None-P6-FALSE] .(...) -- C:\program files (x86)\adobe muse\adobe muse.exe
O87 - FAEL: "{7377F52F-3D8F-4C39-9382-52FC80098196}" [In-None-P17-FALSE] .(...) -- C:\program files (x86)\adobe muse\adobe muse.exe
O87 - FAEL: "{E2284E39-BC42-4522-A4AF-373C10E417CD}" [In-None-P17-TRUE] .(.SafeNet Inc. - Sentinel LDK License Manager Service.) -- C:\Windows\system32\hasplms.exe
O87 - FAEL: "TCP Query User{41492246-C711-4F37-9955-46FAFEB26B4F}C:\users\qbdo\appdata\local\temp\iqkg.exe" [In-None-P6-TRUE] .(...) -- C:\users\qbdo\appdata\local\temp\iqkg.exe (.not file.)
O87 - FAEL: "UDP Query User{E0E2F102-BEDE-426F-BFE6-0502BA1CBAAC}C:\users\qbdo\appdata\local\temp\iqkg.exe" [In-None-P17-TRUE] .(...) -- C:\users\qbdo\appdata\local\temp\iqkg.exe (.not file.)
O87 - FAEL: "TCP Query User{797E6ED0-92D9-4B93-8DD0-50BB9C16728A}C:\users\qbdo\appdata\local\temp\wingkdy.exe" [In-None-P6-TRUE] .(...) -- C:\users\qbdo\appdata\local\temp\wingkdy.exe (.not file.)
O87 - FAEL: "UDP Query User{1826D8BE-0AD8-4F29-91C7-6BD7E127225C}C:\users\qbdo\appdata\local\temp\wingkdy.exe" [In-None-P17-TRUE] .(...) -- C:\users\qbdo\appdata\local\temp\wingkdy.exe (.not file.)
O87 - FAEL: "TCP Query User{B0547919-CFAF-4C59-85FA-BDE0EF926B62}C:\users\qbdo\appdata\local\temp\winodjxf.exe" [In-None-P6-TRUE] .(...) -- C:\users\qbdo\appdata\local\temp\winodjxf.exe (.not file.)
O87 - FAEL: "UDP Query User{647FBD73-DB96-4C38-8FE5-B8F321617AF2}C:\users\qbdo\appdata\local\temp\winodjxf.exe" [In-None-P17-TRUE] .(...) -- C:\users\qbdo\appdata\local\temp\winodjxf.exe (.not file.)
O87 - FAEL: "TCP Query User{F2C569CB-A767-49D3-82D9-58D854690FB4}C:\users\qbdo\appdata\local\temp\rar$exa0.667\beinjo connect v1.4.exe" [In-None-P6-TRUE] .(.Copyright © 2015 - WindowsFormsApplication1.) -- C:\users\qbdo\appdata\local\temp\rar$exa0.667\beinjo connect v1.4.exe
O87 - FAEL: "UDP Query User{9E9ED4B3-4B8D-4274-A580-6942113C765B}C:\users\qbdo\appdata\local\temp\rar$exa0.667\beinjo connect v1.4.exe" [In-None-P17-TRUE] .(.Copyright © 2015 - WindowsFormsApplication1.) -- C:\users\qbdo\appdata\local\temp\rar$exa0.667\beinjo connect v1.4.exe
O87 - FAEL: "TCP Query User{105F5D62-456D-4698-A6D8-6587529A5CB6}C:\users\qbdo\appdata\local\temp\mgoeo.exe" [In-None-P6-TRUE] .(...) -- C:\users\qbdo\appdata\local\temp\mgoeo.exe (.not file.)
O87 - FAEL: "UDP Query User{5DE748B9-EEED-4107-BA08-1350D46BF773}C:\users\qbdo\appdata\local\temp\mgoeo.exe" [In-None-P17-TRUE] .(...) -- C:\users\qbdo\appdata\local\temp\mgoeo.exe (.not file.)
O87 - FAEL: "TCP Query User{E69D1573-54CE-493D-B3E6-1465A2089BFB}C:\xampp\xampp_start.exe" [In-None-P6-TRUE] .(.Apache Friends - Start and stop XAMPP.) -- C:\xampp\xampp_start.exe
O87 - FAEL: "UDP Query User{06E127DB-B15E-472D-A7BD-EF2BDEA7D6AD}C:\xampp\xampp_start.exe" [In-None-P17-TRUE] .(.Apache Friends - Start and stop XAMPP.) -- C:\xampp\xampp_start.exe
O87 - FAEL: "TCP Query User{6ECC2733-AAA8-45B6-AEDD-BF605130FB86}C:\users\qbdo\appdata\local\temp\winvdnple.exe" [In-None-P6-TRUE] .(...) -- C:\users\qbdo\appdata\local\temp\winvdnple.exe (.not file.)
O87 - FAEL: "UDP Query User{0F8339A3-EC9D-4D4E-AA04-F2A52E8ADA7F}C:\users\qbdo\appdata\local\temp\winvdnple.exe" [In-None-P17-TRUE] .(...) -- C:\users\qbdo\appdata\local\temp\winvdnple.exe (.not file.)
O87 - FAEL: "TCP Query User{1C1464D2-A44F-49AF-972B-0911DEF58329}C:\users\qbdo\appdata\local\temp\winmsepd.exe" [In-None-P6-TRUE] .(...) -- C:\users\qbdo\appdata\local\temp\winmsepd.exe (.not file.)
O87 - FAEL: "UDP Query User{4906B1C7-2FFA-4322-8133-B079591FB4C2}C:\users\qbdo\appdata\local\temp\winmsepd.exe" [In-None-P17-TRUE] .(...) -- C:\users\qbdo\appdata\local\temp\winmsepd.exe (.not file.)

---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (42) - 16s

SS - Disabled [2012/03/01 09:35:24] [ 659976] Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) . (.Intel Corporation.) - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe ©
SS - Disabled [2012/03/27 06:01:56] [ 1014096] Bluetooth Device Monitor (Bluetooth Device Monitor) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe ©
SS - Disabled [2012/03/27 06:02:02] [ 1304912] Bluetooth Media Service (Bluetooth Media Service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe ©
SS - Disabled [2012/03/27 06:02:04] [ 1104208] Bluetooth OBEX Service (Bluetooth OBEX Service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe ©
SR - Auto [2012/03/08 10:19:40] [ 135952] Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Sec (BTHSSecurityMgr) . (.Intel(R) Corporation.) - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe ©
SS - Disabled [2015/09/17 12:18:58] [ 515584] caMyciloP (caMyciloP) . (...) - C:\ProgramData\caMyciloP\caMyciloP.exe
SS - Disabled [2015/08/06 07:11:34] [ 379392] Compliant Host Controller (cohci1394) . (.Copyright © 2015.) - C:\Program Files\Controller\cohc.exe
SS - Disabled [2015/06/04 20:21:38] [ 280680] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe ©
SR - Demand [2015/07/29 08:55:36] [ 1278296] Disc Soft Pro Bus Service (Disc Soft Pro Bus Service) . (.Disc Soft Ltd.) - C:\Program Files\DAEMON Tools Pro\DiscSoftBusService.exe ©
SR - Auto [2012/04/17 17:20:36] [ 626960] Intel(R) PROSet/Wireless Event Log (EvtEng) . (.Intel(R) Corporation.) - C:\Program Files\Intel\WiFi\bin\EvtEng.exe ©
SS - Disabled [2015/10/03 08:55:04] [ 729352] FLEXnet Licensing Service (FLEXnet Licensing Service) . (.Acresso Software Inc..) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe ©
SS - Disabled [2015/10/11 13:29:18] [ 2442056] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ©
SS - Disabled [2015/10/11 13:29:18] [ 2442056] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ©
SS - Disabled [2013/01/11 14:36:24] [ 4466120] Sentinel Local License Manager (hasplms) . (.SafeNet Inc..) - C:\Windows\system32\hasplms.exe
SS - Disabled [2011/11/29 18:04:56] [ 13592] Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe ©
SS - Disabled [2012/04/24 12:37:56] [ 169752] Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe ©
SS - Disabled [2015/09/09 10:20:12] [ 268520] ihpmServer (ihpmServer) . (.Copyright 2015. All rights reserved..) - C:\Program Files (x86)\RayDld\ihpmServer.exe =>PUP.Optional.CrossRider
SS - Disabled [2015/09/03 08:22:27] [ 1871784] Maxthon Core Update Service (MaxthonUpdateSvc) . (.Maxthon.) - C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe ©
SS - Disabled [2015/08/26 12:46:30] [ 214696] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe ©
SS - Disabled [2015/06/12 09:06:32] [ 84792] NI Configuration Manager (mxssvr) . (.National Instruments Corporation.) - C:\Program Files (x86)\National Instruments\MAX\nimxs.exe ©
SS - Demand [2015/10/07 20:27:23] [ 1388544] Wireless PAN DHCP Server (MyWiFiDHCPDNS) . (.Copyright (C) 2005-2010 by Achal Dhir.) - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ©
SS - Disabled [2015/06/03 07:53:28] [ 57184] NI Application Web Server (NIApplicationWebServer) . (.National Instruments Corporation.) - C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe ©
SS - Disabled [2015/10/08 21:08:49] [ 1196032] NI Application Web Server (64-bit) (NIApplicationWebServer64) . (.National Instruments Corporation.) - C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe ©
SS - Disabled [2015/06/02 15:52:48] [ 571712] NI Authentication Service (niauth) . (.National Instruments Corporation.) - C:\Program Files (x86)\National Instruments\Shared\niauth\niauth_daemon.exe ©
SS - Disabled [2015/06/01 20:01:52] [ 399152] NI Domain Service (NIDomainService) . (.National Instruments Corporation.) - C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe ©
SS - Disabled [2010/08/02 08:00:00] [ 1427688] NI License Server (NILM License Manager) . (.Macrovision Corporation.) - C:\Program Files (x86)\National Instruments\Shared\License Manager\Bin\lmgrd.exe ©
SS - Disabled [2014/06/06 16:12:20] [ 320368] NI mDNS Responder Service (nimDNSResponder) . (.National Instruments Corporation.) - C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe ©
SS - Disabled [2015/06/02 16:03:34] [ 89928] NI Service Locator (NiSvcLoc) . (.National Instruments Corporation.) - C:\Program Files (x86)\National Instruments\Shared\nisvcloc\nisvcloc.exe ©
SS - Disabled [2015/06/03 07:53:28] [ 57168] NI System Web Server (NISystemWebServer) . (.National Instruments Corporation.) - C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe ©
SS - Disabled [2015/06/11 00:20:00] [ 703304] NI Variable Engine (NITaggerService) . (.National Instruments Corporation.) - C:\Program Files (x86)\National Instruments\Shared\Tagger\tagsrv.exe ©
SS - Disabled [2015/05/26 19:47:14] [ 172832] OpcEnum (OpcEnum) . (.OPC Foundation.) - C:\Windows\SysWOW64\Opcenum.exe ©
SS - Disabled [2015/10/04 21:20:06] [ 2523149] Office 64 Source Engine (ose64) . (...) - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
SR - Auto [2012/04/17 17:20:32] [ 148752] Intel(R) PROSet/Wireless Registry Service (RegSrvc) . (.Intel(R) Corporation.) - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe ©
SS - Disabled [2015/09/17 12:18:58] [ 441856] Saophase (Saophase) . (...) - C:\ProgramData\Saophase\Saophase.exe
SS - Disabled [2014/12/25 19:58:36] [ 220840] SynTPEnh Caller Service (SynTPEnhService) . (.Synaptics Incorporated.) - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe ©
SS - Disabled [2015/08/14 11:43:38] [ 89792] VMware Authorization Service (VMAuthdService) . (.VMware, Inc..) - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe ©
SS - Disabled [2015/08/14 12:03:14] [ 358080] VMware DHCP Service (VMnetDHCP) . (.VMware, Inc..) - C:\Windows\SysWOW64\vmnetdhcp.exe ©
SS - Disabled [2015/08/11 17:27:04] [ 906944] VMware USB Arbitration Service (VMUSBArbService) . (.VMware, Inc..) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe ©
SS - Disabled [2015/08/14 12:03:20] [ 391872] VMware NAT Service (VMware NAT Service) . (.VMware, Inc..) - C:\Windows\SysWOW64\vmnat.exe ©
SS - Disabled [2015/08/14 12:02:14] [12465344] VMware Workstation Server (VMwareHostd) . (...) - C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
SR - Auto [2012/04/17 17:20:50] [ 2671376] Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) . (.Intel® Corporation.) - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe ©

---\\ Recherche de clés de registre Tracing (4) - 5s
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\amt_oursurfing_RASAPI32 =>PUP.Optional.OurSurfing
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\amt_oursurfing_RASMANCS =>PUP.Optional.OurSurfing
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\appshat_generic_RASAPI32 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\appshat_generic_RASMANCS =>PUP.Optional.CrossRider

---\\ Scan Additionnel (33) - 0s
C:\Users\QBDO\AppData\Roaming\Mozilla\Firefox\Profiles\pet7wwwp.default\searchplugins\findit.xml =>PUP.Optional.SmartBar
C:\Windows\AutoKMS\AutoKMS.exe =>HackTool.AutoKMS
C:\Windows\System32\Tasks\AutoKMS =>HackTool.AutoKMS
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{96F04C1B-E352-4A90-BED4-11A0FA968BC2}_is1 =>PUP.Optional.TencentAddressBar
HKLM\SOFTWARE\Wow6432Node\ArenaHD =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Crossbrowse =>PUP.Optional.CrossBrowse
HKLM\SOFTWARE\Wow6432Node\HighDefAction =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\oursurfingSoftware =>PUP.Optional.OurSurfing
HKLM\SOFTWARE\Wow6432Node\RayDld =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Systweak =>PUP.Optional.Systweak
HKLM\SOFTWARE\Wow6432Node\YorkNewCin =>PUP.Optional.CrossRider
HKCU\SOFTWARE\ArenaHD =>PUP.Optional.CrossRider
HKCU\SOFTWARE\CinemaP-1.9cV23.09-nv-ie =>PUP.Optional.CrossRider
HKCU\SOFTWARE\globalUpdate =>PUP.Optional.GlobalUpdate
HKCU\SOFTWARE\HighDefAction =>PUP.Optional.CrossRider
HKCU\SOFTWARE\systweak =>PUP.Optional.Systweak
HKCU\SOFTWARE\YorkNewCin =>PUP.Optional.CrossRider
HKCU\SOFTWARE\AppDataLow\Software\Crossrider =>PUP.Optional.CrossRider
C:\Program Files (x86)\globalUpdate =>PUP.Optional.GlobalUpdate
C:\Program Files (x86)\RayDld =>PUP.Optional.CrossRider
C:\Program Files (x86)\Tencent =>PUP.Optional.TencentAddressBar
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tencent =>PUP.Optional.TencentAddressBar
C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS
C:\Users\QBDO\AppData\Roaming\oursurfing =>PUP.Optional.OurSurfing
C:\Users\QBDO\AppData\Roaming\systweak =>PUP.Optional.Systweak
C:\Users\QBDO\AppData\Local\globalUpdate =>PUP.Optional.GlobalUpdate
C:\Program Files (x86)\Tencent\app.exe =>PUP.Optional.TencentAddressBar
HKLM\SYSTEM\CurrentControlSet\Services\ihpmServer =>PUP.Optional.CrossRider
C:\Program Files (x86)\RayDld\ihpmServer.exe =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\amt_oursurfing_RASAPI32 =>PUP.Optional.OurSurfing
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\amt_oursurfing_RASMANCS =>PUP.Optional.OurSurfing
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\appshat_generic_RASAPI32 =>PUP.Optional.CrossRider
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\appshat_generic_RASMANCS =>PUP.Optional.CrossRider

---\\ Récapitulatif des éléments trouvées sur votre station (8) - 0s
http://www.nicolascoolman.fr/blog =>PUP.Optional.OurSurfing
http://www.nicolascoolman.fr/hijacker-smartbar/ =>PUP.Optional.SmartBar
http://www.nicolascoolman.fr/trojan-autokms/ =>HackTool.AutoKMS
http://www.nicolascoolman.fr/adware-tencentaddressbar/ =>PUP.Optional.TencentAddressBar
http://www.nicolascoolman.fr/pup-crossrider/ =>PUP.Optional.CrossRider
http://www.nicolascoolman.fr/blog =>PUP.Optional.CrossBrowse
http://www.nicolascoolman.fr/pup-systweak/ =>PUP.Optional.Systweak
http://www.nicolascoolman.fr/pup-globalupdate/ =>PUP.Optional.GlobalUpdate

~ End of the scan, 57225 items in 136 seconds (1101)(2)()

Publicité


Signaler le contenu de ce document

Publicité