cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2017.8.15.140 Par Nicolas Coolman (2017/08/15)
~ Démarré par Admin (Administrator) (2017/08/31 12:40:23)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Illegal
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Users\Admin\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\Admin\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Démarrage du système: Normal (Normal boot)
Windows 7 Professional, 64-bit Service Pack 1 (Build 7601) =>.Microsoft Corporation

---\\ Navigateurs Internet (2) - 0s
~ MFIE: Mozilla Firefox 55.0.3 (x86 fr)
~ MSIE: Internet Explorer v11.0.9600.18537

---\\ Informations sur les produits Windows (4) - 0s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ Logiciels de protection (2) - 2s
Avira Antivirus v15.0.29.32 (Protection)
Norton Internet Security v19.9.1.14 (Protection)

---\\ Surveillance de Logiciels (1) - 2s
~ Adobe Flash Player 24 NPAPI (Surveillance)

---\\ Logiciels de partage P2P (1) - 2s
~ µTorrent v3.5.0.43916 (P2P)

---\\ Informations sur le système (6) - 0s
~ Operating System: AMD64 Family 21 Model 2 Stepping 0, AuthenticAMD
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 8370.296 MB (69% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 695 GB (72%) free of 953 GB : OK =>.Disk Space

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: ADMIN-PC
~ User Name: Admin
~ Logged in as Administrator

---\\ Enumération des unités disques (1) - 0s
~ Drive C: has 695 GB free of 953 GB (System)

---\\ Etat du Centre de Sécurité Windows (11) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Recherche particulière de fichiers génériques (26) - 1s
[MD5.38AE1B3C38FAEF56FE4907922F0385BA] - 16/06/2012 - (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\Explorer.exe [3229696] =>.Microsoft Corporation
[MD5.DD81D91FF3B0763C392422865C9AC12E] - 16/06/2012 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe [45568] =>.Microsoft Corporation
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - 16/06/2012 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\System32\Wininit.exe [129024] =>.Microsoft Corporation
[MD5.105954F9BEAD700A6DF4B5B489FCCB4B] - 16/06/2012 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [2920960] =>.Microsoft Corporation
[MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - 16/06/2012 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\Windows\System32\Winlogon.exe [455168] =>.Microsoft Corporation
[MD5.067FA52BFB59A56110A12312EF9AF243] - 16/06/2012 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [232448] =>.Microsoft Corporation
[MD5.492D07D79E7024CA310867B526D9636D] - 16/06/2012 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\System32\dnsapi.dll [357888] =>.Microsoft Corporation
[MD5.B40420876B9288E0A1C8CCA8A84E5DC9] - 16/06/2012 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\Syswow64\dnsapi.dll [270336] =>.Microsoft Corporation
[MD5.0D57D091E06BB1E58E72E5D08479FDDF] - 16/06/2012 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [20480] =>.Microsoft Corporation
[MD5.9A4A1EEE802BF2F878EE8EAB407B21B7] - 16/06/2012 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [497664] =>.Microsoft Corporation
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - 16/06/2012 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [24128] =>.Microsoft Windows®
[MD5.B8BD2BB284668C84865658C77574381A] - 16/06/2012 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [92160] =>.Microsoft Corporation
[MD5.F036CE71586E93D94DAB220D7BDF4416] - 16/06/2012 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [147456] =>.Microsoft Corporation
[MD5.9B38580063D281A99E68EF5813022A5F] - 16/06/2012 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [106496] =>.Microsoft Corporation
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - 16/06/2012 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [122368] =>.Microsoft Corporation
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - 16/06/2012 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [105472] =>.Microsoft Corporation
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - 16/06/2012 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [116224] =>.Microsoft Corporation
[MD5.632E8A00090E4F85F304E152C92C7F2C] - 16/06/2012 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [159744] =>.Microsoft Corporation
[MD5.E47D571FEC2C76E867935109AB2A770C] - 16/06/2012 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [262144] =>.Microsoft Corporation
[MD5.47B2D0B31BDC3EBE6090228E2BA3764D] - 16/06/2012 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [1684416] =>.Microsoft Windows®
[MD5.0086431C29C35BE1DBC43F52CC273887] - 16/06/2012 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\Parport.sys [97280] =>.Microsoft Corporation
[MD5.471815800AE33E6F1C32FB1B97C490CA] - 16/06/2012 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [129536] =>.Microsoft Corporation
[MD5.1B6163C503398B23FF8B939C67747683] - 16/06/2012 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [165888] =>.Microsoft Corporation
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - 16/06/2012 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [93184] =>.Microsoft Corporation
[MD5.AA77EB517D2F07A947294F260E3ACA83] - 16/06/2012 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [118272] =>.Microsoft Corporation
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - 16/06/2012 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [295808] =>.Microsoft Windows®

---\\ Liste des services NT non Microsoft et non désactivés (14) - 1s
O23 - Service: Apple Mobile Device Service (Apple Mobile Device Service) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe =>.Apple Inc.®
O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.®
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) . (.NVIDIA Corporation - NVIDIA GeForce ExperienceService.) - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe =>.NVIDIA Corporation®
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) . (.Hi-Rez Studios - HiPatchService.) - C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe =>.Hi-Rez Studios
O23 - Service: Malwarebytes Service (MBAMService) . (.Malwarebytes - Malwarebytes Service.) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation®
O23 - Service: Norton Internet Security (NIS) . (.Symantec Corporation - Symantec Service Framework.) - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe =>.Symantec Corporation®
O23 - Service: Norton PC Checkup Application Launcher (Norton PC Checkup Application Launcher) . (.Symantec Corporation - Norton PC Checkup Launcher Service.) - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\SymcPCCULaunchSvc.exe =>.Symantec Corporation®
O23 - Service: NVIDIA Network Service (NvNetworkService) . (.NVIDIA Corporation - NVIDIA Network Service.) - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe =>.NVIDIA Corporation®
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) . (.NVIDIA Corporation - NVIDIA Streamer Service.) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe =>.NVIDIA Corporation®
O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 347.2.) - C:\Windows\system32\nvvsvc.exe =>.NVIDIA Corporation
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) . (.Symantec Corporation - Symantec Service Framework.) - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\ccSvcHst.exe =>.Symantec Corporation®
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl®
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) . (.NVIDIA Corporation - Stereo Vision Control Panel API Server.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe =>.NVIDIA Corporation®

---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (25) - 37s
SS - Disabl [16/06/2012] [ 138272] Avira Protection e-mail (AntiVirMailService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe =>.Avira Operations GmbH & Co. KG®
SS - Disabl [16/06/2012] [ 138272] Avira Planificateur (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Antivirus\sched.exe =>.Avira Operations GmbH & Co. KG®
SS - Disabl [16/06/2012] [ 138272] Avira Protection temps réel (AntiVirService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Antivirus\avguard.exe =>.Avira Operations GmbH & Co. KG®
SS - Disabl [16/06/2012] [ 138272] Avira Protection Web (AntiVirWebService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe =>.Avira Operations GmbH & Co. KG®
SR - Auto [16/06/2012] [ 138272] Apple Mobile Device Service (Apple Mobile Device Service) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe =>.Apple Inc.®
SS - Disabl [16/06/2012] [ 138272] Avira Service Host (Avira.ServiceHost) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe =>.Avira Operations GmbH & Co. KG®
SS - Demand [16/06/2012] [ 138272] BattlEye Service (BEService) . (...) - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe =>.BattlEye Innovations e.K.®
SR - Auto [16/06/2012] [ 138272] Service Bonjour (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.®
SR - Auto [16/06/2012] [ 138272] NVIDIA GeForce Experience Service (GfExperienceService) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe =>.NVIDIA Corporation®
SS - Auto [16/06/2012] [ 138272] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [16/06/2012] [ 138272] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [16/06/2012] [ 138272] Google Software Updater (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe =>.Google Inc®
SPaused - Auto [16/06/2012] [ 138272] Hi-Rez Studios Authenticate and Update Service (HiPatchService) . (.Hi-Rez Studios.) - C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe =>.Hi-Rez Studios
SR - Demand [16/06/2012] [ 138272] Service de l’iPod (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe =>.Apple Inc.®
SR - Auto [16/06/2012] [ 138272] Malwarebytes Service (MBAMService) . (.Malwarebytes.) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation®
SR - Auto [16/06/2012] [ 138272] Norton Internet Security (NIS) . (.Symantec Corporation.) - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe =>.Symantec Corporation®
SR - Auto [16/06/2012] [ 138272] Norton PC Checkup Application Launcher (Norton PC Checkup Application Launcher) . (.Symantec Corporation.) - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\SymcPCCULaunchSvc.exe =>.Symantec Corporation®
SR - Auto [16/06/2012] [ 138272] NVIDIA Network Service (NvNetworkService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe =>.NVIDIA Corporation®
SR - Demand [16/06/2012] [ 138272] NVIDIA Streamer Network Service (NvStreamNetworkSvc) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe =>.NVIDIA Corporation®
SR - Auto [16/06/2012] [ 138272] NVIDIA Streamer Service (NvStreamSvc) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe =>.NVIDIA Corporation®
SR - Auto [16/06/2012] [ 138272] NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe =>.NVIDIA Corporation®
SR - Auto [16/06/2012] [ 138272] Common Client Job Manager Service (PCCUJobMgr) . (.Symantec Corporation.) - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\ccSvcHst.exe =>.Symantec Corporation®
SS - Auto [16/06/2012] [ 138272] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl®
SS - Demand [16/06/2012] [ 138272] Steam Client Service (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe =>.Valve®
SR - Auto [16/06/2012] [ 138272] NVIDIA Stereoscopic 3D Driver Service (Stereo Service) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe =>.NVIDIA Corporation®

---\\ Tâches planifiées en automatique (13) - 4s
[MD5.1A709A8B23B584115F2CCEEDAD64DE97] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [7173848] (.Activate.) =>.Piriform Ltd®
[MD5.A8FD9222E4D72596BB37DA8BE95C0BA4] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752] (.Activate.) =>.Google Inc®
[MD5.A8FD9222E4D72596BB37DA8BE95C0BA4] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752] (.Activate.) =>.Google Inc®
[MD5.9B54F1A6BF873FC43E9EAC7A6518E018] [APT] [Norton WSC Integration] (.Symantec Corporation.) -- C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\WSCStub.exe [1346024] (.Activate.) =>.Symantec Corporation®
[MD5.9B54F1A6BF873FC43E9EAC7A6518E018] [APT] [{E5355B64-E3EC-4442-B43D-028343DA2A9B}] (.Mozilla Corporation.) -- c:\program files (x86)\mozilla firefox\firefox.exe [532432] (.Activate.) =>.Mozilla Corporation®
[MD5.9B54F1A6BF873FC43E9EAC7A6518E018] [APT] [Norton Internet Security\Norton Error Analyzer] (.Symantec Corporation.) -- C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\symerr.exe [50544] (.Activate.) =>.Symantec Corporation®
[MD5.9B54F1A6BF873FC43E9EAC7A6518E018] [APT] [Norton Internet Security\Norton Error Processor] (.Symantec Corporation.) -- C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\symerr.exe [50544] (.Activate.) =>.Symantec Corporation®
[MD5.9B54F1A6BF873FC43E9EAC7A6518E018] [APT] [Remediation\AntimalwareMigrationTask] (.Symantec Corporation.) -- C:\Program Files\Common Files\AV\Norton Internet Security\Upgrade.exe [1346024] (.Activate.) =>.Symantec Corporation®
O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\Windows\System32\Tasks\CCleanerSkipUAC [2790] =>.Piriform Ltd®
O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [3372] =>.Google Inc®
O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [3500] =>.Google Inc®
O39 - APT: Norton WSC Integration - (.Symantec Corporation.) -- C:\Windows\System32\Tasks\Norton WSC Integration [3234] =>.Symantec Corporation®
O39 - APT: {E5355B64-E3EC-4442-B43D-028343DA2A9B} - (.Mozilla Corporation.) -- C:\Windows\System32\Tasks\{E5355B64-E3EC-4442-B43D-028343DA2A9B} [3076] =>.Mozilla Corporation®

---\\ Applications lancées au démarrage du système (39) - 5s
O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe =>.Realtek Semiconductor Corp®
O4 - HKLM\..\Run: [NvBackend] . (.NVIDIA Corporation - NVIDIA Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe =>.NVIDIA Corporation®
O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe =>.Apple Inc.®
O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - HKCU\..\Run: [com.squirrel.splice.Splice] . (.Splice - Splice.) -- C:\Users\Admin\AppData\Local\splice\app-3.0.147111\Splice.exe {4D666A27A0AE249F9F2FD4152DD9066C} =>.Splice
O4 - HKCU\..\Run: [AutoLex.lnk] . (...) -- C:\Users\Admin\AppData\Roaming\AutoLex\AutoLex.lnk
O4 - HKCU\..\Run: [lsmwn] . (...) -- C:\Users\Admin\AppData\Roaming\lsm store files\start64.vbs
O4 - HKCU\..\Run: [lsmws] -- C:\Users\Admin\AppData\Roaming\lsm local files\start.vbs (.not file.)
O4 - HKCU\..\Run: [taskengst] -- C:\Users\Admin\AppData\Roaming\taskeng saved files\start.vbs (.not file.)
O4 - HKCU\..\Run: [w0lqitpags5] -- C:\Users\Admin\AppData\Roaming\xfx0htwvs4z\zflfsymcfzq.exe (.not file.) =>Adware.Wizzcaster
O4 - HKCU\..\Run: [43vsbuvs3h4] -- C:\Users\Admin\AppData\Roaming\yjnm0k22ion\xasa2kfexzp.exe (.not file.) =>Adware.Wizzcaster
O4 - HKCU\..\Run: [dwmst] -- C:\Users\Admin\AppData\Roaming\dwm saved files\start.vbs (.not file.)
O4 - HKCU\..\Run: [sy2pp0i44mo] -- C:\Users\Admin\AppData\Roaming\djzziomfbjk\hduyuaweljx.exe (.not file.) =>Adware.Wizzcaster
O4 - HKCU\..\Run: [zairxcurxon] -- C:\Users\Admin\AppData\Roaming\zykcrmxrdwu\sczroli324x.exe (.not file.) =>Adware.Wizzcaster
O4 - HKCU\..\Run: [eaavj4ecp4q] -- C:\Users\Admin\AppData\Roaming\o4twkk0j1md\lbzx41eykyd.exe (.not file.) =>Adware.Wizzcaster
O4 - HKCU\..\Run: [g4ij1t5zohh] -- C:\Users\Admin\AppData\Roaming\gamxw0srihp\j1ebpjx10fy.exe (.not file.) =>Adware.Wizzcaster
O4 - HKLM\..\Wow6432Node\Run: [VirtualCloneDrive] . (.Elaborate Bytes AG - Virtual CloneDrive Daemon.) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe =>.Elaborate Bytes AG®
O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Program Files (x86)\Avira\Antivirus\avgnt.exe =>.Avira Operations GmbH & Co. KG®
O4 - HKLM\..\Wow6432Node\Run: [Avira SystrayStartTrigger] . (.Avira Operations GmbH & Co. KG - Avira Connect.) -- C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe =>.Avira Operations GmbH & Co. KG®
O4 - HKLM\..\Wow6432Node\Run: [Wondershare Helper Compact.exe] . (.Wondershare - Wondershare Studio.) -- C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe =>.Wondershare software CO., LIMITED®
O4 - HKUS\.DEFAULT\..\Run: [Norton Download Manager{NIS227132-OEM-FSD56093}] . (.Symantec Corporation - Norton Download Manager.) -- C:\Users\Public\Downloads\Norton\{NIS227132-OEM-FSD56093}\FSDUI_Custom.exe {69B8F396B6F4205E5BC25F1B4542F2CB} =>.Symantec Corporation
O4 - HKUS\S-1-5-18\..\Run: [Norton Download Manager{NIS227132-OEM-FSD56093}] . (.Symantec Corporation - Norton Download Manager.) -- C:\Users\Public\Downloads\Norton\{NIS227132-OEM-FSD56093}\FSDUI_Custom.exe {69B8F396B6F4205E5BC25F1B4542F2CB} =>.Symantec Corporation
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-2407023709-1011807550-9218861-1000\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - HKUS\S-1-5-21-2407023709-1011807550-9218861-1000\..\Run: [com.squirrel.splice.Splice] . (.Splice - Splice.) -- C:\Users\Admin\AppData\Local\splice\app-3.0.147111\Splice.exe {4D666A27A0AE249F9F2FD4152DD9066C} =>.Splice
O4 - HKUS\S-1-5-21-2407023709-1011807550-9218861-1000\..\Run: [AutoLex.lnk] . (...) -- C:\Users\Admin\AppData\Roaming\AutoLex\AutoLex.lnk
O4 - HKUS\S-1-5-21-2407023709-1011807550-9218861-1000\..\Run: [lsmwn] . (...) -- C:\Users\Admin\AppData\Roaming\lsm store files\start64.vbs
O4 - HKUS\S-1-5-21-2407023709-1011807550-9218861-1000\..\Run: [lsmws] -- C:\Users\Admin\AppData\Roaming\lsm local files\start.vbs (.not file.)
O4 - HKUS\S-1-5-21-2407023709-1011807550-9218861-1000\..\Run: [taskengst] -- C:\Users\Admin\AppData\Roaming\taskeng saved files\start.vbs (.not file.)
O4 - HKUS\S-1-5-21-2407023709-1011807550-9218861-1000\..\Run: [w0lqitpags5] -- C:\Users\Admin\AppData\Roaming\xfx0htwvs4z\zflfsymcfzq.exe (.not file.) =>Adware.Wizzcaster
O4 - HKUS\S-1-5-21-2407023709-1011807550-9218861-1000\..\Run: [43vsbuvs3h4] -- C:\Users\Admin\AppData\Roaming\yjnm0k22ion\xasa2kfexzp.exe (.not file.) =>Adware.Wizzcaster
O4 - HKUS\S-1-5-21-2407023709-1011807550-9218861-1000\..\Run: [dwmst] -- C:\Users\Admin\AppData\Roaming\dwm saved files\start.vbs (.not file.)
O4 - HKUS\S-1-5-21-2407023709-1011807550-9218861-1000\..\Run: [sy2pp0i44mo] -- C:\Users\Admin\AppData\Roaming\djzziomfbjk\hduyuaweljx.exe (.not file.) =>Adware.Wizzcaster
O4 - HKUS\S-1-5-21-2407023709-1011807550-9218861-1000\..\Run: [zairxcurxon] -- C:\Users\Admin\AppData\Roaming\zykcrmxrdwu\sczroli324x.exe (.not file.) =>Adware.Wizzcaster
O4 - HKUS\S-1-5-21-2407023709-1011807550-9218861-1000\..\Run: [eaavj4ecp4q] -- C:\Users\Admin\AppData\Roaming\o4twkk0j1md\lbzx41eykyd.exe (.not file.) =>Adware.Wizzcaster
O4 - HKUS\S-1-5-21-2407023709-1011807550-9218861-1000\..\Run: [g4ij1t5zohh] -- C:\Users\Admin\AppData\Roaming\gamxw0srihp\j1ebpjx10fy.exe (.not file.) =>Adware.Wizzcaster

---\\ Processus lancés (34) - 2s
[MD5.00000000000000000000000000000000] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 347.2.) -- C:\Windows\system32\nvvsvc.exe [0] [PID.960] =>.NVIDIA Corporation
[MD5.8330F6741D4D8691B58663EBD831F8D7] - (.NVIDIA Corporation - Stereo Vision Control Panel API Server.) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [410768] [PID.988] =>.NVIDIA Corporation®
[MD5.E64F67D30E15FEBBF9722C4CF830B67A] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe [1249424] [PID.1464] =>.NVIDIA Corporation®
[MD5.00000000000000000000000000000000] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 347.2.) -- C:\Windows\system32\nvvsvc.exe [0] [PID.1476] =>.NVIDIA Corporation
[MD5.7DEFAE8665BCEDDC2C9983138D69D7A5] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768] [PID.1720] =>.Apple Inc.®
[MD5.B5C2F92EE1106DFE7BB1CCE4D35B6037] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [462096] [PID.1796] =>.Apple Inc.®
[MD5.C6E1E9A45C8BCFD073148B6A6B038C69] - (.NVIDIA Corporation - NVIDIA GeForce ExperienceService.) -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1165368] [PID.1868] =>.NVIDIA Corporation®
[MD5.29B516DB7447E6BB929D3B6D20DA3509] - (.Hi-Rez Studios - HiPatchService.) -- C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728] [PID.1924] =>.Hi-Rez Studios
[MD5.F2840DBFE9322F35557219AE82CC4597] - (.Symantec Corporation - Symantec Service Framework.) -- C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe [138272] [PID.1976] =>.Symantec Corporation®
[MD5.A6102293847A7A2DF01E7BF7AC1C1F12] - (.NVIDIA Corporation - NVIDIA Network Service.) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1881144] [PID.1256] =>.NVIDIA Corporation®
[MD5.A8213BF32D2E75ADD362E118AD164749] - (.NVIDIA Corporation - NVIDIA Streamer Service.) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2522680] [PID.1656] =>.NVIDIA Corporation®
[MD5.2F86BE1818C2D7AC90478E3323EE7FCB] - (.Symantec Corporation - Symantec Service Framework.) -- C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\ccSvcHst.exe [126392] [PID.1908] =>.Symantec Corporation®
[MD5.2F86BE1818C2D7AC90478E3323EE7FCB] - (.Symantec Corporation - Symantec Service Framework.) -- C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\ccSvcHst.exe [126392] [PID.2340] =>.Symantec Corporation®
[MD5.F2840DBFE9322F35557219AE82CC4597] - (.Symantec Corporation - Symantec Service Framework.) -- C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe [138272] [PID.2348] =>.Symantec Corporation®
[MD5.AF04B6DDF123991C625472494BC1221C] - (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112] [PID.3280] =>.Realtek Semiconductor Corp®
[MD5.BE586B5D1D73E1F07ED5AADDEFBCAA47] - (.NVIDIA Corporation - NVIDIA Backend.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2398776] [PID.3348] =>.NVIDIA Corporation®
[MD5.B3E7F1FBF29EF94A797238B9ACB8D993] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [303928] [PID.3464] =>.Apple Inc.®
[MD5.1F938E083D3AC72D100D7A4230EBA775] - (.lisa - lisa.) -- C:\Users\Admin\AppData\Roaming\AutoLex\madox.exe [432640] [PID.3540]
[MD5.3BD79A1F6D2EA0FDDEA3F8914B2A6A0C] - (.Elaborate Bytes AG - Virtual CloneDrive Daemon.) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984] [PID.3892] =>.Elaborate Bytes AG®
[MD5.A95474B14C558CF85A79C18C9356CBCA] - (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe [9292504] [PID.4032] =>.Piriform Ltd®
[MD5.C2AAAE85C511E99F13397F0A52DC7ADA] - (...) -- C:\Users\Admin\AppData\Roaming\lsm store files\lsm.exe [1963572] [PID.4200]
[MD5.D97BD80A6F08752D37A3CF8D3935E666] - (.NVIDIA Corporation - NVIDIA Settings.) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe [2448200] [PID.4276] =>.NVIDIA Corporation®
[MD5.A3F0187B2B6402168E65BE6688002041] - (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [919032] [PID.4556] =>.Avira Operations GmbH & Co. KG®
[MD5.C6BDF0F7C7354CE2073BAB2C8B1BE845] - (.Wondershare - Wondershare Studio.) -- C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2137744] [PID.4612] =>.Wondershare software CO., LIMITED®
[MD5.E6A64322EB213AEACBB61584AA6FB032] - (.NVIDIA Corporation - NVIDIA Network Stream Service.) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3634232] [PID.3760] =>.NVIDIA Corporation®
[MD5.6AA800365EA5A95F4459CCED9346F605] - (.NVIDIA Corporation - NVIDIA Streamer User Agent.) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe [21332536] [PID.4084] =>.NVIDIA Corporation®
[MD5.97E689B69A93F3729CB9F1B3C072BAA1] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [532432] [PID.4232] =>.Mozilla Corporation®
[MD5.8A2A79444C72D6342976724F6908495B] - (.Apple Inc. - iPodService Module (64-bit).) -- C:\Program Files\iPod\bin\iPodService.exe [689464] [PID.5780] =>.Apple Inc.®
[MD5.721682423445E5C132A4895E308AD7A9] - (.Avira Operations GmbH & Co. KG - Avira.) -- C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe [298920] [PID.5932] =>.Avira Operations GmbH & Co. KG®
[MD5.0EF85BD11BD111A0F077707FF8D2AB35] - (.Symantec Corporation - Norton PC Checkup Launcher Service.) -- C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\SymcPCCULaunchSvc.exe [123320] [PID.5532] =>.Symantec Corporation®
[MD5.FEAF4E98C93BC3512B8108D2F534A3BA] - (.Malwarebytes - Malwarebytes Service.) -- C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960] [PID.4472] =>.Malwarebytes Corporation®
[MD5.452F328A992CFF8508DCC20557969D82] - (.Malwarebytes - Malwarebytes Tray Application.) -- C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe [3410384] [PID.2732] =>.Malwarebytes Corporation®
[MD5.E716A50E5EDB0B155AFB6ADE85250902] - (.Malwarebytes - Malwarebytes.) -- C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe [9532880] [PID.5964] =>.Malwarebytes Corporation®
[MD5.86EBD460621BAB6AFE8595392B0560CA] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Admin\Desktop\zhpdiag_2017.8.15.140.exe [2812800] [PID.3904] =>.Nicolas Coolman

---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (9) - 1s
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\aushelper@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\clicktoplay-rollout@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\followonsearch@mozilla.com.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\shield-recipe-client@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files (x86)\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi =>.Mozilla Corporation
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll =>.Adobe Systems Incorporated

---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (19) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr =>.Google Inc.
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr =>.Google Inc.
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr =>.Google Inc.
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = www.google.com =>.Google Inc.
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com =>.Dell Inc.
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = www.google.com =>.Google Inc.
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr/ =>.Google Inc.
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr =>.Google Inc.
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr =>.Google Inc.
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = www.google.com =>.Google Inc.
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr/ =>.Google Inc.
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr =>.Google Inc.
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr =>.Google Inc.
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKEY_USERS\S-1-5-21-2407023709-1011807550-9218861-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = www.google.com =>.Google Inc.
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphan =>.Microsoft Internet Explorer

---\\ Internet Explorer,Proxy Management (3) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 1s
F2 - REG:system.ini: UserInit=C:\Windows\System32\Userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation

---\\ Etude du fichier hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (35)

---\\ Raccourcis Global Startup (101) - 11s
O4 - GS\Desktop [Admin]: ASIO4ALL v2 Instruction Manual.lnk . (...) C:\Program Files (x86)\ASIO4ALL v2\ASIO4ALL v2 Instruction Manual.pdf
O4 - GS\Desktop [Admin]: AuraKingdom-FR.lnk . (.X-LEGEND ENTERTAINMENT - Aura Kingdom.) C:\AeriaGames\AuraKingdom-FR\Launcher.exe =>.X-Legend Entertainment CO., LTD.®
O4 - GS\Desktop [Admin]: Dofus.lnk . (.Ankama Studio - Launcher Dofus.) C:\Users\Admin\AppData\Local\Ankama\Dofus\Dofus.exe =>.Ankama Games®
O4 - GS\Desktop [Admin]: FL Studio 12 (64bit).lnk . (.Image-Line - FL Studio.) C:\Program Files (x86)\Image-Line\FL Studio 12\FL64.exe =>.Image-Line
O4 - GS\Desktop [Admin]: FL Studio 12 - Raccourci.lnk . (...) C:\Program Files (x86)\Image-Line\FL Studio 12
O4 - GS\Desktop [Admin]: FL Studio 12.lnk . (.Image-Line - FL Studio.) C:\Program Files (x86)\Image-Line\FL Studio 12\FL.exe =>.Image-Line
O4 - GS\Desktop [Admin]: Microsoft Word Starter 2010.lnk . (.Microsoft Corporation - Microsoft Office Client Virtualization Hand.) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE "Microsoft Word Starter 2010 90140066040C0000" =>.Microsoft Corporation®
O4 - GS\Desktop [Admin]: Ori and the Blind Forest.lnk . (...) C:\Program Files (x86)\Ori and the Blind Forest\ori.exe
O4 - GS\Desktop [Admin]: Splice.lnk . (.Splice - Splice.) C:\Users\Admin\AppData\Local\splice\Splice.exe =>.Splice
O4 - GS\Desktop [Admin]: ZHPCleaner.lnk . (...) C:\Users\Admin\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
O4 - GS\Desktop [Admin]: ZHPDiag.lnk . (...) C:\Users\Admin\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Admin]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [Admin]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Admin]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\TaskBar [Admin]: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Admin]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Desktop [Administrateur]: ASIO4ALL v2 Instruction Manual.lnk . (...) C:\Program Files (x86)\ASIO4ALL v2\ASIO4ALL v2 Instruction Manual.pdf
O4 - GS\Desktop [Administrateur]: AuraKingdom-FR.lnk . (.X-LEGEND ENTERTAINMENT - Aura Kingdom.) C:\AeriaGames\AuraKingdom-FR\Launcher.exe =>.X-Legend Entertainment CO., LTD.®
O4 - GS\Desktop [Administrateur]: Dofus.lnk . (.Ankama Studio - Launcher Dofus.) C:\Users\Admin\AppData\Local\Ankama\Dofus\Dofus.exe =>.Ankama Games®
O4 - GS\Desktop [Administrateur]: FL Studio 12 (64bit).lnk . (.Image-Line - FL Studio.) C:\Program Files (x86)\Image-Line\FL Studio 12\FL64.exe =>.Image-Line
O4 - GS\Desktop [Administrateur]: FL Studio 12 - Raccourci.lnk . (...) C:\Program Files (x86)\Image-Line\FL Studio 12
O4 - GS\Desktop [Administrateur]: FL Studio 12.lnk . (.Image-Line - FL Studio.) C:\Program Files (x86)\Image-Line\FL Studio 12\FL.exe =>.Image-Line
O4 - GS\Desktop [Administrateur]: Microsoft Word Starter 2010.lnk . (.Microsoft Corporation - Microsoft Office Client Virtualization Hand.) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE "Microsoft Word Starter 2010 90140066040C0000" =>.Microsoft Corporation®
O4 - GS\Desktop [Administrateur]: Ori and the Blind Forest.lnk . (...) C:\Program Files (x86)\Ori and the Blind Forest\ori.exe
O4 - GS\Desktop [Administrateur]: Splice.lnk . (.Splice - Splice.) C:\Users\Admin\AppData\Local\splice\Splice.exe =>.Splice
O4 - GS\Desktop [Administrateur]: ZHPCleaner.lnk . (...) C:\Users\Admin\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
O4 - GS\Desktop [Administrateur]: ZHPDiag.lnk . (...) C:\Users\Admin\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Administrateur]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [Administrateur]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrateur]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\TaskBar [Administrateur]: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrateur]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Desktop [postgres]: ASIO4ALL v2 Instruction Manual.lnk . (...) C:\Program Files (x86)\ASIO4ALL v2\ASIO4ALL v2 Instruction Manual.pdf
O4 - GS\Desktop [postgres]: AuraKingdom-FR.lnk . (.X-LEGEND ENTERTAINMENT - Aura Kingdom.) C:\AeriaGames\AuraKingdom-FR\Launcher.exe =>.X-Legend Entertainment CO., LTD.®
O4 - GS\Desktop [postgres]: Dofus.lnk . (.Ankama Studio - Launcher Dofus.) C:\Users\Admin\AppData\Local\Ankama\Dofus\Dofus.exe =>.Ankama Games®
O4 - GS\Desktop [postgres]: FL Studio 12 (64bit).lnk . (.Image-Line - FL Studio.) C:\Program Files (x86)\Image-Line\FL Studio 12\FL64.exe =>.Image-Line
O4 - GS\Desktop [postgres]: FL Studio 12 - Raccourci.lnk . (...) C:\Program Files (x86)\Image-Line\FL Studio 12
O4 - GS\Desktop [postgres]: FL Studio 12.lnk . (.Image-Line - FL Studio.) C:\Program Files (x86)\Image-Line\FL Studio 12\FL.exe =>.Image-Line
O4 - GS\Desktop [postgres]: Microsoft Word Starter 2010.lnk . (.Microsoft Corporation - Microsoft Office Client Virtualization Hand.) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE "Microsoft Word Starter 2010 90140066040C0000" =>.Microsoft Corporation®
O4 - GS\Desktop [postgres]: Ori and the Blind Forest.lnk . (...) C:\Program Files (x86)\Ori and the Blind Forest\ori.exe
O4 - GS\Desktop [postgres]: Splice.lnk . (.Splice - Splice.) C:\Users\Admin\AppData\Local\splice\Splice.exe =>.Splice
O4 - GS\Desktop [postgres]: ZHPCleaner.lnk . (...) C:\Users\Admin\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
O4 - GS\Desktop [postgres]: ZHPDiag.lnk . (...) C:\Users\Admin\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [postgres]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [postgres]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [postgres]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\TaskBar [postgres]: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\TaskBar [postgres]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\CommonDesktop [Public]: Application Blizzard.lnk . (.Blizzard Entertainment - Blizzard App Launcher.) C:\Program Files (x86)\Blizzard App\Battle.net Launcher.exe =>.Blizzard Entertainment, Inc.®
O4 - GS\CommonDesktop [Public]: Avira Connect.lnk . (.Avira Operations GmbH & Co. KG - Avira.) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe /showMiniGui =>.Avira Operations GmbH & Co. KG®
O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Ltd - CCleaner.) C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - GS\CommonDesktop [Public]: Download icq.lnk . (...) C:\Users\Admin\AppData\Local\Temp\is-FKHSV.tmp\up(164).exe -sprunfromlink
O4 - GS\CommonDesktop [Public]: Far Cry Primal.lnk . (.Ubisoft Entertainment - Far Cry Primal.) C:\Games\Far Cry Primal\bin\FCPrimal.exe =>.UBISOFT ENTERTAINMENT INC.®
O4 - GS\CommonDesktop [Public]: GeForce Experience.lnk . (.NVIDIA Corporation - NVIDIA GeForce Experience Launcher Applicat.) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\LaunchGFExperience.exe =>.NVIDIA Corporation®
O4 - GS\CommonDesktop [Public]: Hearthstone.lnk . (.Blizzard Entertainment - Hearthstone Beta Launcher.) C:\Program Files (x86)\Hearthstone\Hearthstone Beta Launcher.exe =>.Blizzard Entertainment, Inc.®
O4 - GS\CommonDesktop [Public]: Hi-Rez Diagnostics and Support.lnk . (...) C:\Program Files (x86)\Hi-Rez Studios\HiRezGamesDiagAndSupport.exe
O4 - GS\CommonDesktop [Public]: League of Legends.lnk . (...) C:\Riot Games\League of Legends\lol.launcher.exe =>.Riot Games, Inc.®
O4 - GS\CommonDesktop [Public]: Malwarebytes.lnk . (.Malwarebytes - Malwarebytes.) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe =>.Malwarebytes Corporation®
O4 - GS\CommonDesktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\CommonDesktop [Public]: Norton Internet Security.lnk . (.Symantec Corporation - Norton Protection Center UI Stub.) C:\Program Files (x86)\Norton Internet Security\Engine64\19.9.1.14\uistub.exe =>.Symantec Corporation®
O4 - GS\CommonDesktop [Public]: Norton PC Checkup.LNK . (.Symantec Corporation - Norton PC Checkup Application Launcher.) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.96\Norton PC Checkup.exe =>.Symantec Corporation®
O4 - GS\CommonDesktop [Public]: Paladins.lnk . (...) C:\Program Files (x86)\Hi-Rez Studios\HirezLauncherUI.exe game=400 product=402
O4 - GS\CommonDesktop [Public]: Steam.lnk . (.Valve Corporation - Steam Client Bootstrapper.) C:\Program Files (x86)\Steam\Steam.exe =>.Valve®
O4 - GS\CommonDesktop [Public]: Virtual CloneDrive.lnk . (.Elaborate Bytes AG - VirtualCloneDrive Preferences.) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDPrefs.exe =>.Elaborate Bytes AG
O4 - GS\Accessories [Public]: Command Prompt.lnk . (.Microsoft Corporation - Interpréteur de commandes Windows.) C:\Windows\system32\cmd.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Bloc-notes.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\SystemTools [Public]: Private Character Editor.lnk . (.Microsoft Corporation - Éditeur de caractères privés.) C:\Windows\system32\eudcedit.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Calculatrice de Windows.) C:\Windows\system32\calc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - Afficher le commutateur.) C:\Windows\system32\displayswitch.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Accessoire du panneau de saisie mathématiqu.) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - Centre de mobilité Windows.) C:\Windows\system32\mblctr.exe /open =>.Microsoft Corporation
O4 - GS\Accessories [Public]: NetworkProjection.lnk . (.Microsoft Corporation - Connect to a Network Projector.) C:\Windows\system32\NetProj.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\Windows\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Connexion Bureau à distance.) C:\Windows\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Outil Capture.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Magnétophone Windows.) C:\Windows\system32\SoundRecorder.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - Pense-bête.) C:\Windows\system32\StikyNot.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) C:\Windows\System32\mobsync.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Welcome Center.lnk . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) C:\Windows\system32\rundll32.exe =>..Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Application Windows Wordpad.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Table des caractères.) C:\Windows\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - Défragmenteur de disque Microsoft®.) C:\Windows\system32\dfrgui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - Gestionnaire de nettoyage de disque pour Wi.) C:\Windows\system32\cleanmgr.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - Moniteur de ressources et de performances.) C:\Windows\system32\perfmon.exe /res =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - Informations système.) C:\Windows\system32\msinfo32.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - Restauration du système de Microsoft® Windo.) C:\Windows\system32\rstrui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) C:\Windows\system32\taskschd.msc /s =>..Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - Application post-migration de transfert de.) C:\Windows\system32\migwiz\postmig.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - Application Transfert de fichiers et paramè.) C:\Windows\system32\migwiz\migwiz.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Apple Software Update.lnk . (...) C:\Windows\Installer\{52D87F32-70E4-4348-8148-C0B9F35B1314}\AppleSoftwareUpdateIco.exe =>.Apple Inc.
O4 - GS\ProgramsCommon [Public]: Media Center.lnk . (.Microsoft Corporation - Windows Media Center.) C:\Windows\ehome\ehshell.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\ProgramsCommon [Public]: Shotcut.lnk . (...) C:\Program Files\Shotcut\shotcut.exe
O4 - GS\ProgramsCommon [Public]: Sidebar.lnk . (.Microsoft Corporation - Gadgets du Bureau Windows.) C:\Program Files (x86)\Windows Sidebar\sidebar.exe /showgadgets =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Anytime Upgrade.lnk . (.Microsoft Corporation - Interface utilisateur de Mise à niveau expr.) C:\Windows\system32\WindowsAnytimeUpgradeUI.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows DVD Maker.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\DVD Maker\DVDMaker.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: XPS Viewer.lnk . (.Microsoft Corporation - Visionneuse XPS.) C:\Windows\system32\xpsrchvw.exe =>.Microsoft Corporation

---\\ Modification Domaine/Adresses DNS (3) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{E1CCFA47-6014-4A0B-99D9-30CCEF9CCF74}: NameServer = 8.8.8.8,8.8.4.4 =>.France Google Cloud
O17 - HKLM\System\CCS\Services\Tcpip\..\{E1CCFA47-6014-4A0B-99D9-30CCEF9CCF74}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress

---\\ Protocole additionnel (20) - 1s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®

---\\ Logiciels installés (64) - 15s
O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU][64Bits] -- uTorrent =>.BitTorrent Inc®
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {BBEC10F9-AC15-41EE-A271-0B1077F53740} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe AIR =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Flash Player 24 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated®
O42 - Logiciel: Apple Application Support (32 bits) - (.Apple Inc..) [HKLM][64Bits] -- {E92BB800-BCC5-4C25-8102-AC2C3B7C7C1E} =>.Apple Inc.
O42 - Logiciel: Apple Application Support (64 bits) - (.Apple Inc..) [HKLM][64Bits] -- {9C912B1E-06DD-43EF-BB2B-45CB2C88BAAE} =>.Apple Inc.
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM][64Bits] -- {0A596141-97D5-45FA-9281-98DFAF48D579} =>.Apple Inc.
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM][64Bits] -- {52D87F32-70E4-4348-8148-C0B9F35B1314} =>.Apple Inc.
O42 - Logiciel: Application Blizzard - (.Blizzard Entertainment.) [HKLM][64Bits] -- Battle.net =>.Blizzard Entertainment, Inc.®
O42 - Logiciel: ARK: Survival Evolved - (.Studio Wildcard.) [HKLM][64Bits] -- Steam App 346110 =>.Valve®
O42 - Logiciel: ASIO4ALL - (.Michael Tippach.) [HKLM][64Bits] -- ASIO4ALL =>.Michael Tippach
O42 - Logiciel: ATI Catalyst Install Manager - (.ATI Technologies, Inc..) [HKLM][64Bits] -- {62140B07-129A-2BD0-81D2-2A1A7408ADC8} =>.ATI Technologies, Inc.
O42 - Logiciel: AuraKingdom-FR - (..) [HKLM][64Bits] -- AuraKingdom-FR
O42 - Logiciel: Avira Antivirus v15.0.29.32 - (.Avira Operations GmbH & Co. KG.) [HKLM][64Bits] -- Avira Antivirus =>.Avira Operations GmbH & Co. KG®
O42 - Logiciel: Avira Connect v1.2.92.32157 - (.Avira Operations GmbH & Co. KG.) [HKLM][64Bits] -- {7990b9d3-2da3-4eef-bf20-73a05086fd12} =>.Avira Operations GmbH & Co. KG®
O42 - Logiciel: Avira Connect v1.2.92.32157 - (.Avira Operations GmbH & Co. KG.) [HKLM][64Bits] -- {E972AE5C-71B3-4D35-8193-BC4CC2F1FA20} =>.Avira Operations GmbH & Co. KG
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM][64Bits] -- {56DDDFB8-7F79-4480-89D5-25E1F52AB28F} =>.Apple Inc.
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>.Piriform Ltd®
O42 - Logiciel: Dofus - (.Ankama.) [HKCU][64Bits] -- 2744A393-554C-4E35-A24F-DEF0392B4484-2 =>.Ankama Games®
O42 - Logiciel: FL Studio 12 - (.Image-Line.) [HKLM][64Bits] -- FL Studio 12 =>.Image-Line
O42 - Logiciel: FL Studio ASIO - (.Image-Line.) [HKLM][64Bits] -- FL Studio ASIO =>.Image-Line
O42 - Logiciel: Google Chrome - (.Google, Inc..) [HKLM][64Bits] -- {B6672F0B-E459-3757-BD73-E326F6294D96} =>.Google, Inc.
O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {18455581-E099-4BA8-BC6B-F34B2F06600C} =>.Google Inc.
O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {2318C2B1-4965-11d4-9B18-009027A5CD4F} =>.Google Inc®
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: Hearthstone - (.Blizzard Entertainment.) [HKLM][64Bits] -- Hearthstone =>.Blizzard Entertainment, Inc.®
O42 - Logiciel: Helm - (.Matt Tytel.) [HKLM][64Bits] -- {971514BD-7CC3-414F-9258-B79E6D53EC46}
O42 - Logiciel: IL Download Manager - (.Image-Line.) [HKLM][64Bits] -- IL Download Manager =>.Image-Line
O42 - Logiciel: IL Gross Beat - (.Image-Line.) [HKLM][64Bits] -- IL Gross Beat =>.Image-Line
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM][64Bits] -- {F0C7385A-9D20-45F3-8101-05D383885180} =>.Apple Inc.
O42 - Logiciel: League of Legends - (.Riot Games.) [HKLM][64Bits] -- {8E0BDF1C-26D9-4579-A677-53A4CC0D3693} =>.Riot Games
O42 - Logiciel: League of Legends - (.Riot Games.) [HKLM][64Bits] -- League of Legends 4.1.2 =>.Riot Games
O42 - Logiciel: Malwarebytes version 3.2.2.2018 - (.Malwarebytes.) [HKLM][64Bits] -- {35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1 =>.Malwarebytes Corporation®
O42 - Logiciel: Mises à jour NVIDIA 2.11.4.1 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update =>.NVIDIA Corporation
O42 - Logiciel: Mozilla Firefox 55.0.3 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 55.0.3 (x86 fr) =>.Mozilla Corporation®
O42 - Logiciel: Nightlife - (.Acoustica.) [HKLM][64Bits] -- Nightlife =>.Acoustica, Inc®
O42 - Logiciel: Norton Internet Security - (.Symantec Corporation.) [HKLM][64Bits] -- NIS =>.Symantec Corporation®
O42 - Logiciel: Norton PC Checkup - (.Symantec Corporation.) [HKLM][64Bits] -- NortonPCCheckup =>.Symantec Corporation®
O42 - Logiciel: NVIDIA GeForce Experience 2.11.4.1 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA GeForce Experience Service - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GfExperienceService =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Install Application - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA LED Visualizer 1.0 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Logiciel système PhysX 9.15.0428 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Network Service - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Pilote 3D Vision 347.25 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Pilote audio HD : 1.3.34.4 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Pilote du contrôleur 3D Vision 352.65 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Pilote graphique 347.25 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA ShadowPlay 2.11.4.1 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Stereoscopic 3D Driver - (.NVIDIA Corporation.) [HKLM][64Bits] -- NVIDIAStereo =>.NVIDIA Corporation®
O42 - Logiciel: NVIDIA Update Core - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core =>.NVIDIA Corporation
O42 - Logiciel: NVIDIA Virtual Audio 1.2.40 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver =>.NVIDIA Corporation
O42 - Logiciel: Panneau de configuration NVIDIA 347.25 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel =>.NVIDIA Corporation
O42 - Logiciel: Qualcomm Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Dr - (.Qualcomm Atheros Communications Inc..) [HKLM][64Bits] -- {3108C217-BE83-42E4-AE9E-A56A2A92E549} =>.Qualcomm Atheros Communications Inc.
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} =>.Realtek Semiconductor Corp.
O42 - Logiciel: SHIELD Streaming - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv =>.NVIDIA Corporation
O42 - Logiciel: SHIELD Wireless Controller Driver - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController =>.NVIDIA Corporation
O42 - Logiciel: Shotcut - (..) [HKLM][64Bits] -- Shotcut
O42 - Logiciel: Skype™ 7.35 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {3B7E914A-93D5-4A29-92BB-AF8C3F66C431} =>.Skype Technologies S.A.
O42 - Logiciel: SmartCardPlugin - (.Actoll.) [HKLM][64Bits] -- {A1B27D6A-5E69-4E6E-AC3F-5BDFCB5A63A9} =>.Actoll
O42 - Logiciel: Splice - (.Distributed Creation, Inc..) [HKCU][64Bits] -- splice
O42 - Logiciel: Steam - (.Valve Corporation.) [HKLM][64Bits] -- Steam =>.Valve®
O42 - Logiciel: VirtualCloneDrive - (.Elaborate Bytes.) [HKLM][64Bits] -- VirtualCloneDrive =>.Elaborate Bytes
O42 - Logiciel: WinRAR 5.40 (32-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver =>.win.rar GmbH®

---\\ HKCU & HKLM Software Keys (99) - 15s
HKLM\SOFTWARE\Wow6432Node\Actoll =>.Actoll
HKLM\SOFTWARE\Wow6432Node\Adobe =>.Adobe
HKLM\SOFTWARE\Wow6432Node\AGEIA Technologies =>.AGEIA Technologies
HKLM\SOFTWARE\Wow6432Node\Apple Inc. =>.Apple Inc.
HKLM\SOFTWARE\Wow6432Node\ASIO =>.Steinberg Media Technologies
HKLM\SOFTWARE\Wow6432Node\ASIO4ALL =>.Michael Tippach
HKLM\SOFTWARE\Wow6432Node\ASUS =>.ASUS
HKLM\SOFTWARE\Wow6432Node\ATI Technologies =>.ATI Technologies
HKLM\SOFTWARE\Wow6432Node\Avira =>.Avira
HKLM\SOFTWARE\Wow6432Node\Blizzard Entertainment =>.Blizzard Entertainment
HKLM\SOFTWARE\Wow6432Node\EasyAntiCheat =>.EasyAntiCheat
HKLM\SOFTWARE\Wow6432Node\Elaborate Bytes =>.Elaborate Bytes
HKLM\SOFTWARE\Wow6432Node\FFOnline
HKLM\SOFTWARE\Wow6432Node\Google =>.Google
HKLM\SOFTWARE\Wow6432Node\Hi-Rez Studios =>.Hi-Rez Studios
HKLM\SOFTWARE\Wow6432Node\HiRez Studios =>.Hirez Studios
HKLM\SOFTWARE\Wow6432Node\IM Providers =>.IM Providers
HKLM\SOFTWARE\Wow6432Node\Image-Line =>.Image-Line
HKLM\SOFTWARE\Wow6432Node\Intel =>.Intel
HKLM\SOFTWARE\Wow6432Node\JavaSoft =>.JavaSoft
HKLM\SOFTWARE\Wow6432Node\Khronos =>.Khronos
HKLM\SOFTWARE\Wow6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\Wow6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\Norton =>.Symantec Corporation
HKLM\SOFTWARE\Wow6432Node\NVIDIA Corporation =>.nVidia Corporation
HKLM\SOFTWARE\Wow6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\Wow6432Node\Propellerhead Software =>.Propellerhead Software
HKLM\SOFTWARE\Wow6432Node\Qualcomm Atheros Communications Inc. =>.Qualcomm Atheros
HKLM\SOFTWARE\Wow6432Node\Realtek =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp. =>.Realtek Semiconductor Corp.
HKLM\SOFTWARE\Wow6432Node\Riot Games =>.Riot Games
HKLM\SOFTWARE\Wow6432Node\Shotcut
HKLM\SOFTWARE\Wow6432Node\Skype =>.Skype
HKLM\SOFTWARE\Wow6432Node\SoftVoice =>.SoftVoice
HKLM\SOFTWARE\Wow6432Node\Symantec =>.Symantec
HKLM\SOFTWARE\Wow6432Node\U-HE
HKLM\SOFTWARE\Wow6432Node\Valve =>.Valve
HKLM\SOFTWARE\Wow6432Node\WafCX =>.WafCX
HKLM\SOFTWARE\Wow6432Node\WinRAR =>.WinRAR
HKLM\SOFTWARE\Wow6432Node\Wondershare =>.Wondershare
HKLM\SOFTWARE\Wow6432Node\X-AVCSD =>.Avira Software
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\Acoustica =>.Acoustica
HKCU\SOFTWARE\Aeria Games =>.Aeria Games
HKCU\SOFTWARE\Ankama =>.Ankama
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\Apple Computer, Inc. =>.Apple Computer, Inc.
HKCU\SOFTWARE\Apple Inc. =>.Apple Inc.
HKCU\SOFTWARE\ASUS =>.ASUS
HKCU\SOFTWARE\Avira =>.Avira
HKCU\SOFTWARE\BitTorrent
HKCU\SOFTWARE\Blackmagic Design =>.Blackmagic Design
HKCU\SOFTWARE\Blizzard Entertainment =>.Blizzard Entertainment
HKCU\SOFTWARE\BugSplat =>.Bugsplat Game
HKCU\SOFTWARE\Chromium =>.Chromium
HKCU\SOFTWARE\Elaborate Bytes =>.Elaborate Bytes
HKCU\SOFTWARE\FireBird
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\Helm
HKCU\SOFTWARE\IM =>Adware.InstallCore
HKCU\SOFTWARE\IM Providers =>.IM Providers
HKCU\SOFTWARE\Image-Line =>.Image-Line
HKCU\SOFTWARE\JavaSoft =>.JavaSoft
HKCU\SOFTWARE\JetBrains =>.JetBrains
HKCU\SOFTWARE\LennarDigital
HKCU\SOFTWARE\Local AppWizard-Generated Applications =>.ZWCAD
HKCU\SOFTWARE\Logitech =>.Logitech
HKCU\SOFTWARE\Macromedia =>.Macromedia
HKCU\SOFTWARE\Malwarebytes =>.Malwarebytes
HKCU\SOFTWARE\Meltytech
HKCU\SOFTWARE\Mozilla =>.Mozilla
HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKCU\SOFTWARE\Norton =>.Symantec Corporation
HKCU\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation
HKCU\SOFTWARE\Piriform =>.Piriform
HKCU\SOFTWARE\ProtectedStorage =>.Microsoft Corporation
HKCU\SOFTWARE\QtProject =>.QtProject
HKCU\SOFTWARE\Realtek =>.Realtek Semiconductor Corp.
HKCU\SOFTWARE\reFX =>.reFX Audio Software Inc
HKCU\SOFTWARE\Rtp =>.RTP Software
HKCU\SOFTWARE\Sandbox Interactive GmbH =>.Sandbox Interactive GmbH
HKCU\SOFTWARE\SandboxInteractive
HKCU\SOFTWARE\Skype =>.Skype
HKCU\SOFTWARE\skypeapp-3f8de88e1f0a
HKCU\SOFTWARE\SoftVoice =>.SoftVoice
HKCU\SOFTWARE\Symantec =>.Symantec
HKCU\SOFTWARE\Tific =>.Tific
HKCU\SOFTWARE\Trolltech =>.Trolltech
HKCU\SOFTWARE\Ubisoft =>.Ubisoft
HKCU\SOFTWARE\Unity =>.Unity
HKCU\SOFTWARE\Valve =>.Valve
HKCU\SOFTWARE\WinRAR =>.WinRAR
HKCU\SOFTWARE\WinRAR SFX =>.RarLab
HKCU\SOFTWARE\Wondershare =>.Wondershare
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation

---\\ Contenu des dossiers Programmes (257) - 12s
O43 - CFD: 23/01/2015 - [] D -- C:\Program Files\ATI =>.ATI Technologies, Inc®
O43 - CFD: 29/06/2017 - [] D -- C:\Program Files\Bonjour =>.Apple Inc.
O43 - CFD: 22/03/2017 - [] D -- C:\Program Files\CCleaner =>.Piriform Ltd
O43 - CFD: 30/08/2017 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 11/10/2016 - [] D -- C:\Program Files\DVD Maker =>.Aone Software
O43 - CFD: 23/01/2015 - [0] SHD -- C:\Program Files\Fichiers communs =>.Microsoft Corporation
O43 - CFD: 08/10/2016 - [] D -- C:\Program Files\Google =>.Google
O43 - CFD: 27/07/2017 - [] D -- C:\Program Files\Helm
O43 - CFD: 13/07/2017 - [] D -- C:\Program Files\Image-Line =>.Image-Line
O43 - CFD: 13/12/2016 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 29/06/2017 - [] D -- C:\Program Files\iPod =>.Apple Inc.®
O43 - CFD: 29/06/2017 - [] D -- C:\Program Files\iTunes =>.Apple Inc.
O43 - CFD: 31/08/2017 - [] D -- C:\Program Files\Malwarebytes =>.Malwarebytes
O43 - CFD: 23/01/2015 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 04/10/2016 - [] D -- C:\Program Files\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 19/08/2017 - [] D -- C:\Program Files\PostgreSQL =>.PostgreSQL
O43 - CFD: 23/01/2015 - [] D -- C:\Program Files\Realtek =>.Realtek
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 19/08/2017 - [] D -- C:\Program Files\Shotcut
O43 - CFD: 30/08/2017 - [] D -- C:\Program Files\Steinberg =>.Steinberg
O43 - CFD: 10/10/2016 - [0] D -- C:\Program Files\Symantec =>.Symantec
O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 11/10/2016 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 11/10/2016 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 13/10/2016 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 23/01/2015 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 11/10/2016 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 21/11/2010 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 11/10/2016 - [] D -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 05/12/2016 - [] D -- C:\Program Files (x86)\Actoll =>.ACTOLL®
O43 - CFD: 05/12/2016 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Systems Incorporated®
O43 - CFD: 29/06/2017 - [] D -- C:\Program Files (x86)\Apple Software Update =>.Apple Inc.
O43 - CFD: 13/07/2017 - [] D -- C:\Program Files (x86)\ASIO4ALL v2 =>.Michael Tippach
O43 - CFD: 05/02/2017 - [] D -- C:\Program Files (x86)\Avira =>.Avira Software
O43 - CFD: 27/03/2017 - [] D -- C:\Program Files (x86)\Blizzard App =>.Blizzard Entertainment, Inc.®
O43 - CFD: 29/06/2017 - [] D -- C:\Program Files (x86)\Bonjour =>.Apple Inc.
O43 - CFD: 31/08/2017 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 10/10/2016 - [] D -- C:\Program Files (x86)\Elaborate Bytes =>.Elaborate Bytes
O43 - CFD: 31/08/2017 - [] D -- C:\Program Files (x86)\Google =>.Google Inc®
O43 - CFD: 27/03/2017 - [] D -- C:\Program Files (x86)\Hearthstone =>.Blizzard Entertainment
O43 - CFD: 31/08/2017 - [] D -- C:\Program Files (x86)\Hi-Rez Studios =>.Hi-Rez Studios
O43 - CFD: 30/08/2017 - [] D -- C:\Program Files (x86)\Image-Line =>.Image-Line
O43 - CFD: 13/05/2017 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield
O43 - CFD: 13/12/2016 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 23/01/2015 - [] D -- C:\Program Files (x86)\Microsoft Application Virtualization Client =>.Microsoft Corporation
O43 - CFD: 23/01/2015 - [] D -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 23/01/2015 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 31/08/2017 - [] D -- C:\Program Files (x86)\Mozilla Firefox =>.Mozilla
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 08/10/2016 - [] D -- C:\Program Files (x86)\Norton Internet Security =>.Symantec
O43 - CFD: 08/10/2016 - [] D -- C:\Program Files (x86)\Norton PC Checkup =>.Symantec Corporation
O43 - CFD: 20/12/2016 - [] D -- C:\Program Files (x86)\NortonInstaller =>.Symantec
O43 - CFD: 12/10/2015 - [] D -- C:\Program Files (x86)\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 10/10/2016 - [] D -- C:\Program Files (x86)\Ori and the Blind Forest
O43 - CFD: 23/01/2015 - [] D -- C:\Program Files (x86)\Realtek =>.Realtek
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 24/07/2017 - [] D -- C:\Program Files (x86)\Resource Hacker =>.Angus Johnson
O43 - CFD: 13/05/2017 - [] RD -- C:\Program Files (x86)\Skype =>.Skype
O43 - CFD: 17/08/2017 - [] D -- C:\Program Files (x86)\Steam =>.Steam Games
O43 - CFD: 23/01/2015 - [0] HD -- C:\Program Files (x86)\Temp =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files (x86)\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 30/08/2017 - [] D -- C:\Program Files (x86)\VST =>.Acoustica, Inc®
O43 - CFD: 30/08/2017 - [] D -- C:\Program Files (x86)\VstPlugins =>.VTS
O43 - CFD: 11/10/2016 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 11/10/2016 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 13/10/2016 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 11/10/2016 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 11/10/2016 - [] D -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 23/07/2017 - [] D -- C:\Program Files (x86)\WinRAR =>.win.rar GmbH®
O43 - CFD: 23/01/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 23/01/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 27/03/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Application Blizzard
O43 - CFD: 21/08/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira =>.Avira Software
O43 - CFD: 22/03/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd
O43 - CFD: 10/10/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes =>.Elaborate Bytes
O43 - CFD: 21/11/2010 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 09/10/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome =>.Google Inc.
O43 - CFD: 27/03/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone =>.Blizzard Entertainment
O43 - CFD: 27/07/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Helm
O43 - CFD: 13/05/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios =>.Hi-Rez Studios
O43 - CFD: 30/08/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line =>.Image-Line
O43 - CFD: 29/06/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes =>.Apple Inc.
O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 06/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mephisto =>.Mephisto Games
O43 - CFD: 23/01/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (Français) =>.Microsoft Corporation
O43 - CFD: 11/10/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security =>.Symantec
O43 - CFD: 08/10/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton PC Checkup =>.Symantec Corporation
O43 - CFD: 04/10/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 10/10/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ori and the Blind Forest
O43 - CFD: 24/07/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Resource Hacker =>.Angus Johnson
O43 - CFD: 02/04/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype =>.Skype
O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 09/10/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam =>.Steam Games
O43 - CFD: 24/07/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tone2 Firebird
O43 - CFD: 27/03/2017 - [] D -- C:\ProgramData\.mono =>.Legitimate
O43 - CFD: 05/12/2016 - [] D -- C:\ProgramData\Adobe =>.Adobe
O43 - CFD: 29/06/2017 - [] D -- C:\ProgramData\Apple =>.Apple Inc.
O43 - CFD: 29/06/2017 - [] D -- C:\ProgramData\Apple Computer =>.Apple Inc.
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 12/06/2017 - [] D -- C:\ProgramData\Avira =>.Avira Software
O43 - CFD: 27/03/2017 - [] D -- C:\ProgramData\Battle.net =>.Games Software
O43 - CFD: 19/08/2017 - [] D -- C:\ProgramData\Blackmagic Design =>.Blackmagic Design
O43 - CFD: 27/03/2017 - [] D -- C:\ProgramData\Blizzard Entertainment =>.Blizzard Entertainment
O43 - CFD: 23/01/2015 - [0] SHD -- C:\ProgramData\Bureau =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 23/01/2015 - [0] SHD -- C:\ProgramData\Favoris =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Favorites =>.Microsoft Corporation
O43 - CFD: 08/10/2016 - [] D -- C:\ProgramData\Google =>.Google
O43 - CFD: 15/05/2017 - [] D -- C:\ProgramData\Hi-Rez Studios =>.Hi-Rez Studios
O43 - CFD: 31/08/2017 - [] D -- C:\ProgramData\Malwarebytes =>.Malwarebytes
O43 - CFD: 23/01/2015 - [0] SHD -- C:\ProgramData\Menu Démarrer =>.Microsoft Corporation
O43 - CFD: 30/08/2017 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 09/03/2017 - [] D -- C:\ProgramData\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 23/01/2015 - [0] SHD -- C:\ProgramData\Modèles =>.Microsoft Corporation
O43 - CFD: 04/08/2017 - [] D -- C:\ProgramData\Norton =>.Symantec Corporation
O43 - CFD: 08/10/2016 - [] D -- C:\ProgramData\NortonInstaller =>.Symantec
O43 - CFD: 31/08/2017 - [] D -- C:\ProgramData\NVIDIA =>.nVidia Corporation
O43 - CFD: 19/12/2016 - [] D -- C:\ProgramData\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 21/08/2017 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 09/10/2016 - [] D -- C:\ProgramData\Riot Games =>.Riot Games
O43 - CFD: 13/05/2017 - [] D -- C:\ProgramData\Skype =>.Skype
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation
O43 - CFD: 20/11/2016 - [] D -- C:\ProgramData\VirtualizedApplications =>.Microsoft Corporation
O43 - CFD: 20/08/2017 - [] D -- C:\ProgramData\Wondershare =>.Wondershare
O43 - CFD: 05/12/2016 - [] D -- C:\Program Files (x86)\Common Files\Adobe AIR =>.Adobe Inc.
O43 - CFD: 29/06/2017 - [] D -- C:\Program Files (x86)\Common Files\Apple =>.Apple Inc.
O43 - CFD: 24/07/2017 - [] D -- C:\Program Files (x86)\Common Files\Avid =>.Avid
O43 - CFD: 18/06/2017 - [] D -- C:\Program Files (x86)\Common Files\BattlEye =>.BattlEye
O43 - CFD: 23/01/2015 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER =>.Designer
O43 - CFD: 23/01/2015 - [] D -- C:\Program Files (x86)\Common Files\InstallShield =>.InstallShield
O43 - CFD: 04/12/2016 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared =>.Microsoft Corporation
O43 - CFD: 13/07/2017 - [] D -- C:\Program Files (x86)\Common Files\Propellerhead Software =>.Propellerhead Software AB
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 13/05/2017 - [] D -- C:\Program Files (x86)\Common Files\Skype =>.Skype
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines =>.Microsoft Corporation
O43 - CFD: 14/06/2017 - [] D -- C:\Program Files (x86)\Common Files\Steam =>.Steam Games
O43 - CFD: 10/10/2016 - [] D -- C:\Program Files (x86)\Common Files\Symantec Shared =>.Symantec Corporation
O43 - CFD: 11/10/2016 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 24/07/2017 - [] D -- C:\Program Files (x86)\Common Files\VST3
O43 - CFD: 19/08/2017 - [] D -- C:\Program Files (x86)\Common Files\Wondershare =>.Wondershare
O43 - CFD: 27/03/2017 - [] D -- C:\Users\Admin\AppData\Roaming\.mono =>.Legitimate
O43 - CFD: 31/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\242e4ff17822412495e329f646ec4776
O43 - CFD: 05/12/2016 - [] D -- C:\Users\Admin\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 27/03/2017 - [0] D -- C:\Users\Admin\AppData\Roaming\Albion
O43 - CFD: 27/03/2017 - [] D -- C:\Users\Admin\AppData\Roaming\AlbionOnline
O43 - CFD: 05/12/2016 - [] D -- C:\Users\Admin\AppData\Roaming\AnkamaCertificates =>.Ankama
O43 - CFD: 05/12/2016 - [] D -- C:\Users\Admin\AppData\Roaming\app =>.Ankama
O43 - CFD: 29/06/2017 - [] D -- C:\Users\Admin\AppData\Roaming\Apple Computer =>.Apple Inc.
O43 - CFD: 30/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\AutoLex
O43 - CFD: 05/02/2017 - [] D -- C:\Users\Admin\AppData\Roaming\Avira =>.Avira Software
O43 - CFD: 27/03/2017 - [] D -- C:\Users\Admin\AppData\Roaming\Battle.net =>.Games Software
O43 - CFD: 27/07/2017 - [] D -- C:\Users\Admin\AppData\Roaming\DigitalSuburban
O43 - CFD: 22/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\Dofus =>.Ankama
O43 - CFD: 05/12/2016 - [] D -- C:\Users\Admin\AppData\Roaming\Dofus-2 =>.Ankama
O43 - CFD: 09/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\Dofus-3 =>.Ankama
O43 - CFD: 31/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\dwm saved files
O43 - CFD: 14/10/2016 - [] D -- C:\Users\Admin\AppData\Roaming\Emjysoft =>.Emjysoft
O43 - CFD: 29/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\helm
O43 - CFD: 23/01/2015 - [] D -- C:\Users\Admin\AppData\Roaming\Identities =>.Microsoft Corporation
O43 - CFD: 13/07/2017 - [] D -- C:\Users\Admin\AppData\Roaming\Image-Line =>.Image-Line
O43 - CFD: 29/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\JetBrains =>.JetBrains Inc
O43 - CFD: 09/10/2016 - [] D -- C:\Users\Admin\AppData\Roaming\LolClient =>.LolClient
O43 - CFD: 30/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\lsm store files
O43 - CFD: 09/10/2016 - [] D -- C:\Users\Admin\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 21/11/2010 - [0] D -- C:\Users\Admin\AppData\Roaming\Media Center Programs =>.Microsoft Corporation
O43 - CFD: 30/08/2017 - [] SD -- C:\Users\Admin\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 31/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 29/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\NuGet =>.Microsoft Corporation
O43 - CFD: 30/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\NVIDIA =>.nVidia Corporation
O43 - CFD: 05/12/2016 - [] D -- C:\Users\Admin\AppData\Roaming\Reg
O43 - CFD: 09/10/2016 - [] D -- C:\Users\Admin\AppData\Roaming\Riot Games =>.Riot Games
O43 - CFD: 27/06/2017 - [] D -- C:\Users\Admin\AppData\Roaming\Skype =>.Skype
O43 - CFD: 23/07/2017 - [] D -- C:\Users\Admin\AppData\Roaming\SoftGrid Client =>.Microsoft Corporation
O43 - CFD: 31/08/2017 - [0] D -- C:\Users\Admin\AppData\Roaming\Splice =>.Splice
O43 - CFD: 31/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\taskeng saved files
O43 - CFD: 23/01/2015 - [0] D -- C:\Users\Admin\AppData\Roaming\TP =>.TP
O43 - CFD: 31/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\uTorrent
O43 - CFD: 23/07/2017 - [] D -- C:\Users\Admin\AppData\Roaming\WinRAR =>.WinRAR
O43 - CFD: 31/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 18/01/2017 - [] D -- C:\Users\Admin\AppData\Local\Adobe =>.Adobe
O43 - CFD: 04/12/2016 - [] D -- C:\Users\Admin\AppData\Local\Ankama =>.Ankama
O43 - CFD: 29/06/2017 - [] D -- C:\Users\Admin\AppData\Local\Apple =>.Apple Inc.
O43 - CFD: 29/06/2017 - [] D -- C:\Users\Admin\AppData\Local\Apple Computer =>.Apple Inc.
O43 - CFD: 23/01/2015 - [0] SHD -- C:\Users\Admin\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 27/03/2017 - [] D -- C:\Users\Admin\AppData\Local\Battle.net =>.Games Software
O43 - CFD: 27/03/2017 - [] D -- C:\Users\Admin\AppData\Local\Blizzard =>.Blizzard
O43 - CFD: 27/03/2017 - [] D -- C:\Users\Admin\AppData\Local\Blizzard Entertainment =>.Blizzard Entertainment
O43 - CFD: 09/10/2016 - [] D -- C:\Users\Admin\AppData\Local\CEF =>.CEF
O43 - CFD: 30/08/2017 - [0] D -- C:\Users\Admin\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 21/08/2017 - [] D -- C:\Users\Admin\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 30/08/2017 - [] D -- C:\Users\Admin\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation
O43 - CFD: 23/01/2015 - [] SHD -- C:\Users\Admin\AppData\Local\EmieBrowserModeList =>.Enterprise mode Site List Mgr
O43 - CFD: 19/08/2017 - [0] SHD -- C:\Users\Admin\AppData\Local\EmieSiteList =>.Enterprise mode Site List Mgr
O43 - CFD: 19/08/2017 - [0] SHD -- C:\Users\Admin\AppData\Local\EmieUserList =>.Enterprise mode Site List Mgr
O43 - CFD: 30/08/2017 - [] D -- C:\Users\Admin\AppData\Local\Google =>.Google
O43 - CFD: 13/05/2017 - [] D -- C:\Users\Admin\AppData\Local\HirezLauncherUI =>.Hi-Rez Studios
O43 - CFD: 23/01/2015 - [0] SHD -- C:\Users\Admin\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 31/08/2017 - [] D -- C:\Users\Admin\AppData\Local\InetInfoTools
O43 - CFD: 17/08/2017 - [] D -- C:\Users\Admin\AppData\Local\IsolatedStorage =>.id Software
O43 - CFD: 29/08/2017 - [] D -- C:\Users\Admin\AppData\Local\JetBrains =>.JetBrains Inc
O43 - CFD: 22/10/2016 - [] D -- C:\Users\Admin\AppData\Local\Macromedia =>.Macromedia
O43 - CFD: 19/08/2017 - [] D -- C:\Users\Admin\AppData\Local\Meltytech
O43 - CFD: 30/08/2017 - [] D -- C:\Users\Admin\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 09/03/2017 - [0] D -- C:\Users\Admin\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 31/08/2017 - [] D -- C:\Users\Admin\AppData\Local\Mozilla =>.Mozilla Corporation
O43 - CFD: 08/10/2016 - [] D -- C:\Users\Admin\AppData\Local\NVIDIA =>.nVidia Corporation
O43 - CFD: 08/10/2016 - [] D -- C:\Users\Admin\AppData\Local\NVIDIA Corporation =>.nVidia Corporation
O43 - CFD: 10/10/2016 - [] D -- C:\Users\Admin\AppData\Local\Ori and the Blind Forest
O43 - CFD: 06/02/2017 - [] D -- C:\Users\Admin\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 29/08/2017 - [0] D -- C:\Users\Admin\AppData\Local\RefSrcSymbols
O43 - CFD: 27/03/2017 - [] D -- C:\Users\Admin\AppData\Local\Sandbox Interactive GmbH =>.Sandbox Interactive GmbH
O43 - CFD: 08/10/2016 - [] D -- C:\Users\Admin\AppData\Local\SoftGrid Client =>.Microsoft Corporation
O43 - CFD: 17/08/2017 - [] D -- C:\Users\Admin\AppData\Local\splice =>.Splice
O43 - CFD: 18/08/2017 - [] D -- C:\Users\Admin\AppData\Local\SpliceSettings
O43 - CFD: 17/08/2017 - [] D -- C:\Users\Admin\AppData\Local\SquirrelTemp =>.Squirrels
O43 - CFD: 05/02/2017 - [] D -- C:\Users\Admin\AppData\Local\Steam =>.Steam Games
O43 - CFD: 29/08/2017 - [0] D -- C:\Users\Admin\AppData\Local\SymbolSourceSymbols
O43 - CFD: 31/08/2017 - [] D -- C:\Users\Admin\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 23/01/2015 - [0] SHD -- C:\Users\Admin\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 17/07/2017 - [] D -- C:\Users\Admin\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 19/08/2017 - [] D -- C:\Users\Admin\AppData\Local\Wondershare =>.Wondershare
O43 - CFD: 24/07/2017 - [] D -- C:\Users\Admin\AppData\Local\Xenocode =>.Legitimate
O43 - CFD: 31/08/2017 - [] D -- C:\Users\Admin\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 06/02/2017 - [0] D -- C:\Users\Admin\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 13/10/2016 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 13/07/2017 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2 =>.Michael Tippach
O43 - CFD: 30/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line =>.Image-Line
O43 - CFD: 30/08/2017 - [0] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JetBrains =>.JetBrains Inc
O43 - CFD: 14/07/2009 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 12/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nightlife
O43 - CFD: 17/08/2017 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Splice =>.Splice
O43 - CFD: 30/08/2017 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 23/01/2015 - [0] SHD -- C:\Users\Default\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 23/01/2015 - [0] SHD -- C:\Users\Default User\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 10/10/2016 - [0] -- C:\Windows\System32\Config\systemprofile\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 08/10/2016 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Google =>.Google
O43 - CFD: 14/07/2009 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 23/01/2015 - [0] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\SoftGrid Client =>.Microsoft Corporation
O43 - CFD: 30/08/2017 - [] SD -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 31/08/2017 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\SoftGrid Client =>.Microsoft Corporation
O43 - CFD: 23/01/2015 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\{90140011-0066-040C-0000-0000000FF1CE} =>.Microsoft Corporation

---\\ ShellIconOverlayIdentifiers (SIOI) (2) - 0s
O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - DLL d’extension d’environnement de stockage.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation

---\\ Image File Execution Options (4) - 0s
O50 - IFEO:C:\Windows\System32\ie4uinit.exe - (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - Outil d’installation sans assistance d’IE 7.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Hôte des applications HTML de Microsoft(R).) [MitigationOptions\\256] =>.Microsoft Corporation

---\\ Liste des pilotes du système (68) - 3s
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [491088] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [339536] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\drivers\adpu320.sys [182864] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [15440] =>.Microsoft Windows®
O58 - SDL:2011/03/11 08:41:12 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [107904] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [194128] =>.Microsoft Windows®
O58 - SDL:2011/03/11 08:41:12 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [27008] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [87632] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [97856] =>.Microsoft Windows®
O58 - SDL:2009/07/19 13:38:40 A . (. - ATK0110 ACPI Utility.) -- C:\Windows\System32\drivers\ASACPI.sys [15416] =>.ASUSTeK Computer Inc.®
O58 - SDL:2010/05/22 17:30:58 A . (.Advanced Micro Devices Inc. - AMD PCIE Filter Driver for ATI PCIE chipset.) -- C:\Windows\System32\drivers\AtiPcie.sys [16440] =>.Advanced Micro Devices, Inc.®
O58 - SDL:2017/06/20 12:34:05 A . (.Avira Operations GmbH & Co. KG - Avira USB Feature Driver.) -- C:\Windows\System32\drivers\avdevprot.sys [64504] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2017/08/09 10:44:35 A . (.Avira Operations GmbH & Co. KG - Avira Minifilter Driver.) -- C:\Windows\System32\drivers\avgntflt.sys [189256] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2017/08/09 10:44:35 A . (.Avira Operations GmbH & Co. KG - Avira Driver for Security Enhancement.) -- C:\Windows\System32\drivers\avipbb.sys [151128] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2017/03/02 19:45:04 A . (.Avira Operations GmbH & Co. KG - Avira Manager Driver.) -- C:\Windows\System32\drivers\avkmgr.sys [35328] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2017/03/02 19:45:04 A . (.Avira Operations GmbH & Co. KG - Avira WFP Network Driver.) -- C:\Windows\System32\drivers\avnetflt.sys [78600] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2017/06/20 12:34:05 A . (.Avira Operations GmbH & Co. KG - Avira USB Filter Driver.) -- C:\Windows\System32\drivers\avusbflt.sys [34128] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2009/06/10 22:34:23 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60a.sys [270848] =>.Broadcom Corporation
O58 - SDL:2009/06/10 22:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [18432] =>.Brother Industries, Ltd.
O58 - SDL:2009/06/10 22:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [8704] =>.Brother Industries, Ltd.
O58 - SDL:2009/07/14 03:19:07 A . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [286720] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [47104] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [14976] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [14720] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 22:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [468480] =>.Broadcom Corporation
O58 - SDL:2017/08/30 11:09:44 A . (.MTQ0HV - .) -- C:\Windows\System32\drivers\c4b281505d32a05e773aac2683ea5365.sys [78744] =>PUP.Optional.Wajam
O58 - SDL:2009/07/14 03:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [17488] =>.Microsoft Windows®
O58 - SDL:2014/12/21 00:31:04 A . (.Elaborate Bytes AG - ElbyCD Windows x64 I/O driver.) -- C:\Windows\System32\drivers\ElbyCDIO.sys [40344] =>.Elaborate Bytes AG®
O58 - SDL:2009/07/14 03:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [530496] =>.Microsoft Windows®
O58 - SDL:2006/12/13 16:42:08 A . (.USB Smart Card Reader - USB Smart Card Reader.) -- C:\Windows\System32\drivers\EMVSCARD.sys [28544] =>.USB Smart Card Reader
O58 - SDL:2009/06/10 22:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3286016] =>.Broadcom Corporation
O58 - SDL:2009/06/10 22:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [31232] =>.Hauppauge Computer Works, Inc.
O58 - SDL:2010/11/21 05:23:47 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [78720] =>.Microsoft Windows®
O58 - SDL:2011/03/11 08:41:26 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [410496] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [44112] =>.Microsoft Windows®
O58 - SDL:2012/11/19 11:27:27 A . (.Qualcomm Atheros Co., Ltd. - Qualcomm Atheros Ar81xx series PCI-E Gigabi.) -- C:\Windows\System32\drivers\L1C62x64.sys [117912] =>.Atheros Communications Inc.®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [114752] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [106560] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [65600] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [115776] =>.Microsoft Windows®
O58 - SDL:2017/08/21 07:20:18 A . (...) -- C:\Windows\System32\drivers\mbae64.sys [77440] =>.Malwarebytes Corporation®
O58 - SDL:2017/08/31 12:20:30 A . (.Malwarebytes - Malwarebytes Real-Time Protection.) -- C:\Windows\System32\drivers\mbam.sys [45472] =>.Malwarebytes Corporation®
O58 - SDL:2017/08/31 12:20:57 A . (.Malwarebytes - Malwarebytes Chameleon.) -- C:\Windows\System32\drivers\MBAMChameleon.sys [192960] =>.Malwarebytes Corporation®
O58 - SDL:2017/08/31 12:20:24 A . (.Malwarebytes - Malwarebytes SwissArmy.) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys [253888] =>.Malwarebytes Corporation®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [35392] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [284736] =>.Microsoft Windows®
O58 - SDL:2017/08/31 12:20:35 A . (.Malwarebytes - Malwarebytes Web Protection.) -- C:\Windows\System32\drivers\mwac.sys [84256] =>.Malwarebytes Corporation®
O58 - SDL:2009/07/14 03:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [51264] =>.Microsoft Windows®
O58 - SDL:2010/09/30 21:00:06 A . (.Renesas Electronics Corporation - USB 3.0 Hub Driver.) -- C:\Windows\System32\drivers\nusb3hub.sys [80384] =>.Renesas Electronics Corporation
O58 - SDL:2010/09/30 21:00:06 A . (.Renesas Electronics Corporation - USB 3.0 Host Controller Driver.) -- C:\Windows\System32\drivers\nusb3xhc.sys [180736] =>.Renesas Electronics Corporation
O58 - SDL:2015/11/25 01:10:29 A . (.NVIDIA Corporation - NVIDIA HDMI Audio Driver.) -- C:\Windows\System32\drivers\nvhda64v.sys [205456] =>.NVIDIA Corporation®
O58 - SDL:2015/01/10 10:07:47 A . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) -- C:\Windows\System32\drivers\nvlddmkm.sys [10274448] =>.NVIDIA Corporation®
O58 - SDL:2011/03/11 08:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [148352] =>.Microsoft Windows®
O58 - SDL:2011/03/11 08:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [166272] =>.Microsoft Windows®
O58 - SDL:2016/04/14 07:38:19 A . (.NVIDIA Corporation - NVIDIA Virtual Audio Driver.) -- C:\Windows\System32\drivers\nvvad64v.sys [56384] =>.NVIDIA Corporation®
O58 - SDL:2009/07/14 03:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1524816] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [128592] =>.Microsoft Windows®
O58 - SDL:2012/06/13 04:10:44 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\drivers\RTKVHD64.sys [4060560] =>.Realtek Semiconductor Corp®
O58 - SDL:2009/06/10 22:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] =>.Macrovision Corporation, Macrovision Europe Limited,
O58 - SDL:2009/07/14 02:00:40 A . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\drivers\serial.sys [94208] =>.Brother Industries Ltd.
O58 - SDL:2009/07/14 03:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [43584] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [80464] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [24656] =>.Microsoft Windows®
O58 - SDL:2016/10/10 10:36:17 A . (.Symantec Corporation - Symantec Event Library.) -- C:\Windows\System32\drivers\SYMEVENT64x86.SYS [175736] =>.Symantec Corporation®
O58 - SDL:2016/12/21 13:20:26 A . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\drivers\usbaapl64.sys [54784] =>.Apple, Inc.
O58 - SDL:2013/07/24 17:02:46 A . (.Elaborate Bytes AG - Virtual CloneDrive SCSI miniport.) -- C:\Windows\System32\drivers\VClone.sys [36864] =>.Elaborate Bytes AG
O58 - SDL:2009/07/14 03:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [17488] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [161872] =>.Microsoft Windows®

---\\ Derniers fichiers modifiés ou crées (Utilisateur) (17) - 6s
O61 - LFC: 2017/08/30 22:03:45 A . (..) -- C:\Users\Admin\AppData\Local\InetInfoTools\unins000.exe [1199825]
O61 - LFC: 2017/08/29 13:32:44 A . (..) -- C:\Users\Admin\AppData\Local\JetBrains\Transient\dotPeek\v09\SolutionCaches\_Default.110592184.00\SymbolCache.bin [8]
O61 - LFC: 2017/08/31 00:43:27 A . (..) -- C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\0qhv6vfk.default\startupCache\scriptCache-child-current.bin [486120]
O61 - LFC: 2017/08/31 11:46:32 A . (..) -- C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\0qhv6vfk.default\startupCache\scriptCache-current.bin [5340989]
O61 - LFC: 2017/08/30 23:53:47 A . (..) -- C:\Users\Admin\AppData\Local\s64prt.dll [14848]
O61 - LFC: 2017/08/30 21:51:20 A . (..) -- C:\Users\Admin\AppData\LocalLow\Mozilla\Temp-{4c6c92e2-8e61-4883-b4f1-f1ba75a5d1f6}\NVIDIA Corporation\NV_Cache\34695c6d2b31fc244f5d19ac1c563b07_fce8395c8fd8a989_15f74c7777689be5_0_0.bin [16384]
O61 - LFC: 2017/08/30 21:51:24 A . (..) -- C:\Users\Admin\AppData\LocalLow\Mozilla\Temp-{4c6c92e2-8e61-4883-b4f1-f1ba75a5d1f6}\NVIDIA Corporation\NV_Cache\34695c6d2b31fc244f5d19ac1c563b07_fce8395c8fd8a989_15f74c7777689be5_0_1.bin [1048576]
O61 - LFC: 2017/08/31 00:29:08 A . (..) -- C:\Users\Admin\AppData\LocalLow\Mozilla\Temp-{9a220a82-61f8-46c4-8b95-d66fb14a75a7}\NVIDIA Corporation\NV_Cache\34695c6d2b31fc244f5d19ac1c563b07_fce8395c8fd8a989_15f74c7777689be5_0_0.bin [16384]
O61 - LFC: 2017/08/30 22:07:05 A . (.lisa.) -- C:\Users\Admin\AppData\Roaming\AutoLex\madox.exe [432640]
O61 - LFC: 2017/08/30 22:17:46 A . (.System.) -- C:\Users\Admin\AppData\Roaming\dwm saved files\dwm.exe [7260672]
O61 - LFC: 2017/08/30 22:17:46 A . (.System.) -- C:\Users\Admin\AppData\Roaming\lsm store files\data.exe [7260672]
O61 - LFC: 2017/08/30 22:17:44 A . (..) -- C:\Users\Admin\AppData\Roaming\lsm store files\lsm.exe [1963572]
O61 - LFC: 2017/08/30 22:17:46 A . (.System.) -- C:\Users\Admin\AppData\Roaming\taskeng saved files\taskeng.exe [7260672]
O61 - LFC: 2017/08/30 15:19:42 A . (..) -- C:\Users\Admin\Downloads\dblue_Glitch\dblue_Glitch_v1_3.dll [7375360]
O61 - LFC: 2017/08/30 15:36:41 A . (..) -- C:\Users\Admin\Downloads\grossbeat_install.exe [5593790]
O61 - LFC: 2017/08/30 18:19:31 RA . (..) -- C:\Users\Admin\Downloads\Image-Line Gross Beat 1.0.5\Image-Line Gross Beat 1.0.5.exe [5943546]
O61 - LFC: 2017/08/30 21:07:56 A . (..) -- C:\Users\Admin\Downloads\ReFX Nexus v2.2 VSTi RTAS DVDR - AiRISO [deepstatus]\air-nexus2.iso [3442802688]

---\\ Associations Shell Spawning (9) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S

---\\ Menu de démarrage Internet (13) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O68 - StartMenuInternet: <>[HKLM\..\Shell\open\Command] (...) -- firefox.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- Chrome.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- iexplore.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

---\\ Recherche d'infection sur les navigateurs (1) - 9s
O69 - SBI: SearchScopes [HKCU] {96BBC430-9900-4299-9F5D-7951AB36EFDF} [DefaultScope] - (Google) - http://www.google.com/ =>.Google Inc.

---\\ Enumère les services démarrés par Svchost (33) - 0s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [72192] =>.Microsoft Corporation
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [80384] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [80384] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\system32\srvsvc.dll [236032] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [794624] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [859648] =>.Microsoft Corporation
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [680448] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [99328] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [344064] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [97792] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [64512] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [359424] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [316928] =>.Microsoft Corporation
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du se.) -- C:\Windows\System32\termsrv.dll [683520] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\system32\wuaueng.dll [2607104] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [849920] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [370688] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [569344] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\system32\seclogon.dll [30720] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [70144] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\system32\iscsiexe.dll [156672] =>.Microsoft Corporation
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\system32\mmcss.dll [67584] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [242688] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [121856] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [136704] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [111104] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\system32\schedsvc.dll [1110016] =>.Microsoft Corporation
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\system32\kmsvc.dll [90624] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84480] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [210432] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\system32\themeservice.dll [44544] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [100864] =>.Microsoft Corporation
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [193536] =>.Microsoft Corporation

---\\ Scan Additionnel (1) - 0s
C:\Windows\System32\drivers\c4b281505d32a05e773aac2683ea5365.sys =>PUP.Optional.Wajam

---\\ Récapitulatif des éléments trouvés sur votre station (3) - 0s
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Adware.Wizzcaster
https://nicolascoolman.eu/2017/03/12/adware-installcore-2/ =>Adware.InstallCore
https://nicolascoolman.eu/2017/02/24/pup-optional-wajam/ =>PUP.Optional.Wajam

~ Unselected Options: O82,
~ End of the scan, 26871 items in 02mn09s (1000)(0)

Publicité


Signaler le contenu de ce document

Publicité