cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2017.10.1.172 By Nicolas Coolman (2017/10/01)
~ Run by Isaie (Administrator) (2017/10/01 13:41:11)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Legal
~ State version: Version OK
~ Mode: Scan
~ Report: D:\Users\Isaie\Desktop\ZHPDiag.txt
~ Report: D:\Users\Isaie\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ System startup: Normal (Normal boot)
Windows 7 Ultimate, 64-bit Service Pack 1 (Build 7601) =>.Microsoft Corporation

---\\ Internet Browsers (3) - 0s
~ MFIE: Mozilla Firefox 56.0 (x64 fr)
~ MFIE: Mozilla Firefox 53.0.3 (x86 fr)
~ MSIE: Internet Explorer v11.0.9600.18349

---\\ Windows Product Information (4) - 0s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ System protection software (3) - 0s
Malwarebytes version 3.1.2.1733 v3.1.2.1733 (Protection)
Microsoft Security Client v4.10.0209.0 (Protection)
Microsoft Security Essentials v4.10.209.0 (Protection)

---\\ System optimization software (1) - 0s
~ CCleaner v5.35 (Optimize)

---\\ Surveillance software (2) - 0s
~ Adobe Flash Player 27 NPAPI (Surveillance)
~ Adobe Reader 9 - Français (Surveillance)

---\\ Information on the system (6) - 0s
~ Operating System: Intel64 Family 6 Model 37 Stepping 2, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 3920.368 MB (47% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive D: has 488 GB (%) free of 610 GB : OK =>.Disk Space

---\\ Connection to the system mode (3) - 0s
~ Computer Name: ISAIE-PC
~ User Name: Isaie
~ Logged in as Administrator

---\\ Enumeration of the disk units (2) - 0s
~ Drive C: has 506 GB free of 592 GB
~ Drive D: has 488 GB free of 610 GB (System)

---\\ State of the Windows Security Center (11) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Search Generic System Files (25) - 3s
[MD5.9DA3B83F80E205B6C601EEE1312FD0A0] - 09/04/2016 - (.Microsoft Corporation - Windows Explorer.) -- D:\Windows\Explorer.exe [3231232] =>.Microsoft Corporation
[MD5.DD81D91FF3B0763C392422865C9AC12E] - 14/07/2009 - (.Microsoft Corporation - Windows host process (Rundll32).) -- D:\Windows\System32\rundll32.exe [45568] =>.Microsoft Corporation
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - 14/07/2009 - (.Microsoft Corporation - Windows Start-Up Application.) -- D:\Windows\System32\Wininit.exe [129024] =>.Microsoft Corporation
[MD5.EA1B9D3C7D11CA407AA89CBB266139CF] - 20/05/2016 - (.Microsoft Corporation - Internet Extensions for Win32.) -- D:\Windows\System32\wininet.dll [2597888] =>.Microsoft Corporation
[MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - 17/07/2014 - (.Microsoft Corporation - Windows Logon Application.) -- D:\Windows\System32\Winlogon.exe [455168] =>.Microsoft Corporation
[MD5.067FA52BFB59A56110A12312EF9AF243] - 21/11/2010 - (.Microsoft Corporation - Software Licensing Library.) -- D:\Windows\System32\sppcomapi.dll [232448] =>.Microsoft Corporation
[MD5.492D07D79E7024CA310867B526D9636D] - 03/03/2011 - (.Microsoft Corporation - DNS Client API DLL.) -- D:\Windows\System32\dnsapi.dll [357888] =>.Microsoft Corporation
[MD5.B40420876B9288E0A1C8CCA8A84E5DC9] - 03/03/2011 - (.Microsoft Corporation - DNS Client API DLL.) -- D:\Windows\Syswow64\dnsapi.dll [270336] =>.Microsoft Corporation
[MD5.9A4A1EEE802BF2F878EE8EAB407B21B7] - 13/10/2015 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- D:\Windows\System32\drivers\AFD.sys [497664] =>.Microsoft Corporation
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - 14/07/2009 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- D:\Windows\System32\drivers\atapi.sys [24128] =>.Microsoft Windows®
[MD5.B8BD2BB284668C84865658C77574381A] - 14/07/2009 - (.Microsoft Corporation - CD-ROM File System Driver.) -- D:\Windows\System32\drivers\Cdfs.sys [92160] =>.Microsoft Corporation
[MD5.F036CE71586E93D94DAB220D7BDF4416] - 21/11/2010 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- D:\Windows\System32\drivers\Cdrom.sys [147456] =>.Microsoft Corporation
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - 21/11/2010 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- D:\Windows\System32\drivers\DfsC.sys [102400] =>.Microsoft Corporation
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - 21/11/2010 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- D:\Windows\System32\drivers\HDAudBus.sys [122368] =>.Microsoft Corporation
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - 14/07/2009 - (.Microsoft Corporation - i8042 Port Driver.) -- D:\Windows\System32\drivers\i8042prt.sys [105472] =>.Microsoft Corporation
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - 14/07/2009 - (.Microsoft Corporation - IP Network Address Translator.) -- D:\Windows\System32\drivers\IpNat.sys [116224] =>.Microsoft Corporation
[MD5.10112D850C844606419C79EE24EE6016] - 12/05/2016 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- D:\Windows\System32\drivers\MRxSmb.sys [159744] =>.Microsoft Corporation
[MD5.E47D571FEC2C76E867935109AB2A770C] - 11/05/2016 - (.Microsoft Corporation - MBT Transport driver.) -- D:\Windows\System32\drivers\netBT.sys [262144] =>.Microsoft Corporation
[MD5.47B2D0B31BDC3EBE6090228E2BA3764D] - 11/01/2016 - (.Microsoft Corporation - NT File System Driver.) -- D:\Windows\System32\drivers\ntfs.sys [1684416] =>.Microsoft Windows®
[MD5.0086431C29C35BE1DBC43F52CC273887] - 14/07/2009 - (.Microsoft Corporation - Parallel Port Driver.) -- D:\Windows\System32\drivers\Parport.sys [97280] =>.Microsoft Corporation
[MD5.471815800AE33E6F1C32FB1B97C490CA] - 21/11/2010 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- D:\Windows\System32\drivers\Rasl2tp.sys [129536] =>.Microsoft Corporation
[MD5.1B6163C503398B23FF8B939C67747683] - 21/11/2010 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- D:\Windows\System32\drivers\rdpdr.sys [165888] =>.Microsoft Corporation
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - 14/07/2009 - (.Microsoft Corporation - SMB Transport driver.) -- D:\Windows\System32\drivers\smb.sys [93184] =>.Microsoft Corporation
[MD5.AA77EB517D2F07A947294F260E3ACA83] - 13/10/2015 - (.Microsoft Corporation - TDI Translation Driver.) -- D:\Windows\System32\drivers\tdx.sys [118272] =>.Microsoft Corporation
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - 21/11/2010 - (.Microsoft Corporation - Volume Shadow Copy Driver.) -- D:\Windows\System32\drivers\volsnap.sys [295808] =>.Microsoft Windows®

---\\ Non Microsoft non disabled Windows Services (2) - 2s
O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - D:\Windows\System32\atiesrxx.exe =>.AMD
O23 - Service: Malwarebytes Service (MBAMService) . (.Malwarebytes - Malwarebytes Service.) - D:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation®

---\\ Services not Microsoft (SR=Run, SS=Stop) (4) - 26s
SS - Demand [30/09/2017] [ 272384] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - D:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated®
SR - Auto [16/07/2015] [ 246784] (AMD External Events Utility) . (.AMD.) - D:\Windows\System32\atiesrxx.exe =>.AMD
SR - Auto [09/05/2017] [ 4470736] Malwarebytes Service (MBAMService) . (.Malwarebytes.) - D:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation®
SS - Demand [27/09/2017] [ 194000] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - D:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation®

---\\ Task Planned Automatically (Register) (65) - 7s
O38 - TASK: {01D1FAA1-43EA-43C2-B62F-D4B177E43171} [64Bits][\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver] - (.Microsoft Corporation - Windows Disk Diagnostic User Resolver.) -- D:\Windows\system32\DFDWiz.exe [79360] =>.Microsoft Corporation
O38 - TASK: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} [64Bits][\Microsoft\Windows\Time Synchronization\SynchronizeTime] - (.Microsoft Corporation - A tool to aid in developing services for Wi.) -- D:\Windows\system32\sc.exe [45056] =>.Microsoft Corporation
O38 - TASK: {088482FA-65B8-4E17-9ABF-1DCD48E8D373} [64Bits][\Microsoft\Windows\Tcpip\IpAddressConflict1] - (.Microsoft Corporation - Network Diagnostic Framework Client API.) -- D:\Windows\System32\ndfapi.dll [238592] =>.Microsoft Corporation
O38 - TASK: {088870B0-DC8A-477D-85F7-B2F5120E6B94} [64Bits][\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent] - (.Microsoft Corporation - GWX Detector.) -- D:\Windows\system32\GWX\GWXDetector.exe [358400] =>.Microsoft Corporation
O38 - TASK: {09F06BFE-A3C8-40E3-846A-6E6F4000C238} [64Bits][\Microsoft\Windows\Tcpip\IpAddressConflict2] - (.Microsoft Corporation - Network Diagnostic Framework Client API.) -- D:\Windows\System32\ndfapi.dll [238592] =>.Microsoft Corporation
O38 - TASK: {0A3BB8CE-CB69-4AC8-A9EF-6F656D3B72F6} [64Bits][\Microsoft\Windows\Media Center\ActivateWindowsSearch] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- D:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {1512EAED-1F4F-4A74-8919-34A607B25C5A} [64Bits][\Microsoft\Windows\Media Center\SqlLiteRecoveryTask] - (.Microsoft Corporation - Windows Media Center Store Update Manager.) -- D:\Windows\ehome\mcupdate.exe [198656] =>.Microsoft Corporation
O38 - TASK: {1CE7BF1A-D864-4AED-91DA-FC1D109884C8} [64Bits][\Microsoft\Windows\Media Center\ReindexSearchRoot] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- D:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {1DC84304-2992-49D0-AC5A-9AD968E6C7D4} [64Bits][\Microsoft\Windows\Media Center\DispatchRecoveryTasks] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- D:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {22A60A74-3B46-4422-9A7D-D455D7167FCB} [64Bits][\Microsoft\Windows\Setup\gwx\launchtrayprocess] - (.Microsoft Corporation - GWX.) -- D:\Windows\system32\GWX\GWX.exe [534016] =>.Microsoft Corporation
O38 - TASK: {23343390-0B22-4173-B387-7DD1A8621DBF} [64Bits][\Microsoft\Windows\Media Center\PBDADiscoveryW2] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- D:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} [64Bits][\Microsoft\Windows\WindowsBackup\ConfigNotification] - (.Microsoft Corporation - Microsoft® Windows Backup.) -- D:\Windows\System32\sdclt.exe [1264640] =>.Microsoft Corporation
O38 - TASK: {32693F3B-E367-498F-B5B3-191CB5F44DC2} [64Bits][\Microsoft\Windows\Media Center\UpdateRecordPath] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- D:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {32E74192-9045-4324-A22A-449E31CEB216} [64Bits][\{AE603147-48AC-4865-B85A-4BCAF785205E}] - (...) -- D:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {37736B62-24A5-494C-8B2E-BBE41BF78721} [64Bits][\Microsoft\Windows\Media Center\PBDADiscoveryW1] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- D:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {457ECED6-E618-4EDB-93ED-05FC92903F4F} [64Bits][\Microsoft\Windows\Media Center\OCURActivate] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- D:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {5A40E926-9E86-4B89-9CFD-B12311724371} [64Bits][\Microsoft\Windows\UPnP\UPnPHostConfig] - (.Microsoft Corporation - A tool to aid in developing services for Wi.) -- D:\Windows\System32\sc.exe [45056] =>.Microsoft Corporation
O38 - TASK: {5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6} [64Bits][\Microsoft\Windows\Defrag\ScheduledDefrag] - (.Microsoft Corp. - Disk Defragmenter Module.) -- D:\Windows\system32\defrag.exe [183296] =>.Microsoft Corp.
O38 - TASK: {63A0ECC7-9519-4D33-AAA0-1712F10F805D} [64Bits][\Microsoft\Windows\Media Center\RecordingRestart] - (...) -- D:\Windows\ehome\ehrec (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {682607DB-7D81-469A-9244-3CCAEFC7E8E6} [64Bits][\Microsoft\Windows\Windows Activation Technologies\ValidationTask] - (.Microsoft Corporation - Windows Activation Technologies Service.) -- D:\Windows\System32\Wat\WatAdminSvc.exe [1255736] =>.Microsoft Corporation®
O38 - TASK: {6AF6F94B-C943-4EEC-8E7A-71CEA0A1D27C} [64Bits][\Microsoft\Windows\Media Center\mcupdate] - (...) -- D:\Windows\ehome\mcupdate (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {72DB7465-BC54-491B-A92A-4637A28C9BBF} [64Bits][\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck] - (.Microsoft Corporation - AppID Certificate Store Verification Task.) -- D:\Windows\system32\appidcertstorecheck.exe [17920] =>.Microsoft Corporation
O38 - TASK: {753C47AE-EC5E-44B3-95A9-2C8E553F0E39} [64Bits][\Microsoft\Windows\Windows Media Sharing\UpdateLibrary] - (.Microsoft Corporation - Windows Media Player Network Sharing Servic.) -- D:\Program Files\Windows Media Player\wmpnscfg.exe [70656] =>.Microsoft Corporation
O38 - TASK: {81540B9F-B5BF-47EB-9C95-BE195BF2C664} [64Bits][\Microsoft\Windows\NetTrace\GatherNetworkInfo] - (...) -- D:\Windows\system32\gatherNetworkInfo.vbs [40552]
O38 - TASK: {88185AF8-5806-4068-BD9A-C944639DA3C0} [64Bits][\Microsoft\Windows\Setup\gwx\rundetector] - (.Microsoft Corporation - GWX Detector.) -- D:\Windows\system32\GWX\GWXDetector.exe [358400] =>.Microsoft Corporation
O38 - TASK: {889878F3-6DB9-45C3-BC76-9649AB3F771F} [64Bits][\Microsoft\Windows\Setup\gwx\refreshgwxcontent] - (.Microsoft Corporation - GWX ConfigManager.) -- D:\Windows\system32\GWX\GWXConfigManager.exe [755200] =>.Microsoft Corporation
O38 - TASK: {8BF9FF44-4CE0-4F4D-B2C5-1B00A8CFED4C} [64Bits][\Microsoft\Windows\Media Center\PvrScheduleTask] - (.Microsoft Corporation - Windows Media Center Store Update Manager.) -- D:\Windows\ehome\mcupdate.exe [198656] =>.Microsoft Corporation
O38 - TASK: {90F0B8A3-F809-4741-9CF9-304BA04F407E} [64Bits][\Microsoft\Windows\Media Center\MediaCenterRecoveryTask] - (.Microsoft Corporation - Windows Media Center Store Update Manager.) -- D:\Windows\ehome\mcupdate.exe [198656] =>.Microsoft Corporation
O38 - TASK: {961EF684-331A-4088-BC58-80E50199F497} [64Bits][\Microsoft\Microsoft Antimalware\MpIdleTask] - (.Microsoft Corporation - Microsoft Malware Protection Command Line U.) -- D:\Program Files\Microsoft Security Client\MpCmdRun.exe [410784] =>.Microsoft Corporation®
O38 - TASK: {994C86AD-A929-4B2C-88A0-4E25A107A029} [64Bits][\Microsoft\Windows\SystemRestore\SR] - (.Microsoft Corporation - Microsoft® Windows System Protection Config.) -- D:\Windows\System32\srrstr.dll [270848] =>.Microsoft Corporation
O38 - TASK: {99E5D64E-F8CC-4D9F-BC70-7A8ECA0E36F8} [64Bits][\Microsoft\Windows\Application Experience\ProgramDataUpdater] - (.Microsoft Corporation - Microsoft Compatibility Telemetry.) -- D:\Windows\system32\compattelrunner.exe [41704] =>.Microsoft Windows®
O38 - TASK: {9DA3B0C4-4708-48DC-979A-D93373354174} [64Bits][\Microsoft\Windows\Media Center\InstallPlayReady] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- D:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {9FE7B586-F7D8-4826-919B-2CA101330EC4} [64Bits][\CCleanerSkipUAC] - (.Piriform Ltd - CCleaner.) -- D:\Program Files\CCleaner\CCleaner.exe [7685808] =>.Piriform Ltd®
O38 - TASK: {A2D3C46D-0821-4DCD-B2F2-4FD7F7CB7616} [64Bits][\Microsoft\Windows\Media Center\PvrRecoveryTask] - (.Microsoft Corporation - Windows Media Center Store Update Manager.) -- D:\Windows\ehome\mcupdate.exe [198656] =>.Microsoft Corporation
O38 - TASK: {A48CABBF-24C8-4B87-B00F-9261807C3B43} [64Bits][\Microsoft\Windows\AppID\PolicyConverter] - (.Microsoft Corporation - AppID Policy Converter Task.) -- D:\Windows\system32\appidpolicyconverter.exe [148480] =>.Microsoft Corporation
O38 - TASK: {A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D} [64Bits][\Microsoft\Windows\Location\Notifications] - (.Microsoft Corporation - Location Activity.) -- D:\Windows\System32\LocationNotifications.exe [90112] =>.Microsoft Corporation
O38 - TASK: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} [64Bits][\Microsoft\Windows\Application Experience\AitAgent] - (...) -- aitagent [0]
O38 - TASK: {AE2B6720-C7B2-4FA9-8BB7-A33441922478} [64Bits][\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime] - (.Microsoft Corporation - GWX Detector.) -- D:\Windows\system32\GWX\GWXDetector.exe [358400] =>.Microsoft Corporation
O38 - TASK: {B1CD63FB-0715-449F-8367-F49BCEEC0A9B} [64Bits][\Microsoft\Windows\Media Center\ehDRMInit] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- D:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {B2A1954C-CA07-4B42-8A93-4CC9A3CD80F2} [64Bits][\WPD\SqmUpload_S-1-5-21-1864223786-918788249-3770300545-1000] - (.Microsoft Corporation - Windows Portable Device API Components.) -- D:\Windows\System32\portabledeviceapi.dll [758272] =>.Microsoft Corporation
O38 - TASK: {B8F491CA-F958-4F23-B8ED-BCDD8DC71365} [64Bits][\Microsoft\Windows\Media Center\OCURDiscovery] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- D:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {C016366B-7126-46CA-B36B-592A3D95A60B} [64Bits][\Microsoft\Windows\Customer Experience Improvement Program\Consolidator] - (.Microsoft Corporation - Windows SQM Consolidator.) -- D:\Windows\System32\wsqmcons.exe [293888] =>.Microsoft Corporation
O38 - TASK: {C45FFC57-FA2F-4B1C-83B2-CDC73A3436E1} [64Bits][\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask] - (.Microsoft Corporation - Windows Media Center Store Update Manager.) -- D:\Windows\ehome\mcupdate.exe [198656] =>.Microsoft Corporation
O38 - TASK: {C80A6519-586F-4192-9CBA-29EE2FBC901C} [64Bits][\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan] - (.Microsoft Corporation - Microsoft Malware Protection Command Line U.) -- D:\Program Files\Microsoft Security Client\MpCmdRun.exe [410784] =>.Microsoft Corporation®
O38 - TASK: {CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186} [64Bits][\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask] - (.Microsoft Corporation - Windows Remote Assistance COM Server.) -- D:\Windows\System32\raserver.exe [125952] =>.Microsoft Corporation
O38 - TASK: {CB8562BB-6490-425C-B9D2-8AED5509C9BF} [64Bits][\Microsoft\Windows\Media Center\PeriodicScanRetry] - (.Microsoft Corporation - Windows Media Center Store Update Manager.) -- D:\Windows\ehome\MCUpdate.exe [198656] =>.Microsoft Corporation
O38 - TASK: {CBEF0A91-1C58-4284-B627-88A3FF5C018E} [64Bits][\Microsoft\Windows\Setup\gwx\refreshgwxconfig] - (.Microsoft Corporation - GWX Detector.) -- D:\Windows\system32\GWX\GWXDetector.exe [358400] =>.Microsoft Corporation
O38 - TASK: {CE0E03D8-A95E-4D40-A2A5-8F905DDEAB49} [64Bits][\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime] - (.Microsoft Corporation - Get Windows 10.) -- D:\Windows\system32\GWX\GWXUXWorker.exe [421488] =>.Microsoft Windows®
O38 - TASK: {D0250F3F-6480-484F-B719-42F659AC64D5} [64Bits][\Microsoft\Windows\Windows Error Reporting\QueueReporting] - (.Microsoft Corporation - Windows Problem Reporting.) -- D:\Windows\system32\wermgr.exe [50688] =>.Microsoft Corporation
O38 - TASK: {D07D0C24-8A6C-4BBD-83F1-F274922D03AA} [64Bits][\Microsoft\Windows\WindowsBackup\AutomaticBackup] - (.Microsoft Corporation - Microsoft® Windows Backup Engine.) -- D:\Windows\System32\sdengin2.dll [1120768] =>.Microsoft Corporation
O38 - TASK: {D7B6E81D-3CF4-432C-84D2-24213F4316E6} [64Bits][\Microsoft\Windows\Autochk\Proxy] - (.Microsoft Corporation - Autochk Proxy DLL.) -- D:\Windows\System32\acproxy.dll [11264] =>.Microsoft Corporation
O38 - TASK: {DAB56C46-0483-4B46-8646-F10A7A913016} [64Bits][\Microsoft\Windows\Media Center\PBDADiscovery] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- D:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {DBCD58E4-350D-44CB-8D0C-9DCEB650ACCE} [64Bits][\Microsoft\Windows\Media Center\RegisterSearch] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- D:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {DD9F510C-95F4-499A-90C8-BAC5BC372FF4} [64Bits][\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask] - (.Microsoft Corporation - A tool to aid in developing services for Wi.) -- D:\Windows\System32\sc.exe [45056] =>.Microsoft Corporation
O38 - TASK: {E22A8667-F75B-4BA9-BA46-067ED4429DE8} [64Bits][\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange] - (.Microsoft Corporation - Base Filtering Engine.) -- D:\Windows\System32\bfe.dll [705024] =>.Microsoft Corporation
O38 - TASK: {E3163C33-301D-4730-A266-5518C5ED3967} [64Bits][\Microsoft\Windows\Bluetooth\UninstallDeviceTask] - (.Microsoft Corporation - Bluetooth Uninstall Device Task.) -- D:\Windows\System32\BthUdTask.exe [36864] =>.Microsoft Corporation
O38 - TASK: {E742A07E-2966-4FEC-9116-87B7FFD62D25} [64Bits][\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector] - (.Microsoft Corporation - Windows Disk Failure Diagnostic Module.) -- D:\Windows\System32\dfdts.dll [45568] =>.Microsoft Corporation
O38 - TASK: {EAF75439-FDD5-4488-93E4-FF108B6A3FCF} [64Bits][\Microsoft\Windows\Media Center\ConfigureInternetTimeService] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- D:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {EB02381F-D652-4B1C-894A-712498C62C51} [64Bits][\Microsoft\Windows\MUI\LPRemove] - (.Microsoft Corporation - MUI Language pack cleanup.) -- D:\Windows\system32\lpremove.exe [71168] =>.Microsoft Corporation
O38 - TASK: {EC48E8FA-FAAF-41CF-8D94-5A6816F4A652} [64Bits][\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline] - (.Microsoft Corporation - Manages scheduled tasks.) -- D:\Windows\System32\schtasks.exe [285696] =>.Microsoft Corporation
O38 - TASK: {EE548C19-0562-4080-83BC-646FAAD90DBE} [64Bits][\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B] - (.Microsoft Corporation - GWX Detector.) -- D:\Windows\system32\GWX\GWXDetector.exe [358400] =>.Microsoft Corporation
O38 - TASK: {EFE7A304-2B65-47AB-A612-7B7F6E821445} [64Bits][\Microsoft\Windows\WindowsBackup\Windows Backup Monitor] - (.Microsoft Corporation - Microsoft® Windows Backup.) -- D:\Windows\System32\sdclt.exe [1264640] =>.Microsoft Corporation
O38 - TASK: {F81DA66E-3495-443D-90A5-6FDCC9643B04} [64Bits][\Adobe Flash Player Updater] - (.Adobe Systems Incorporated - Adobe® Flash® Player Update Service 27.0 r0.) -- D:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [272384] =>.Adobe Systems Incorporated®
O38 - TASK: {FB3C354D-297A-4EB2-9B58-090F6361906B} [64Bits][\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem] - (.Microsoft Corporation - Power Settings Command-Line Tool.) -- D:\Windows\System32\powercfg.exe [71168] =>.Microsoft Corporation
O38 - TASK: {FD4F2CB4-479A-4BF8-AF7F-CCED297DF8F5} [64Bits][\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser] - (.Microsoft Corporation - Microsoft Compatibility Telemetry.) -- D:\Windows\system32\CompatTelRunner.exe [41704] =>.Microsoft Windows®

---\\ Auto loading programs from Registry and folders (15) - 3s
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- D:\Program Files\Microsoft Security Client\msseces.exe =>.Microsoft Corporation®
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- D:\Windows\system32\igfxtray.exe =>.Intel Corporation
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- D:\Windows\system32\hkcmd.exe =>.Intel Corporation
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- D:\Windows\system32\igfxpers.exe =>.Intel Corporation
O4 - HKLM\..\Run: [CanonMyPrinter] . (.CANON INC. - Canon My Printer.) -- D:\Program Files\Canon\MyPrinter\BJMyPrt.exe =>.Canon Inc.®
O4 - HKLM\..\Run: [Malwarebytes TrayApp] . (.Malwarebytes - Malwarebytes Tray Application.) -- D:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe =>.Malwarebytes Corporation®
O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- D:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - HKLM\..\Wow6432Node\Run: [CanonSolutionMenuEx] . (.CANON INC. - Canon Solution Menu EX.) -- D:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE =>.Canon Inc.®
O4 - HKLM\..\Wow6432Node\Run: [Ultralingua 7 Hotkey] . (.Copyright © 2008 - ULHotkey.) -- D:\Program Files (x86)\Ultralingua\Ultralingua 7\ULHotkey.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- D:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe =>.Adobe Systems, Incorporated®
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Desktop Gadgets.) -- D:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Desktop Gadgets.) -- D:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- D:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- D:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-1864223786-918788249-3770300545-1000\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- D:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®

---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (2) - 4s
P2 - EXT FILE: (.HTTPS Everywhere - Encrypt the Web! Automatically use HTT.) -- D:\Users\Isaie\AppData\Roaming\Mozilla\Firefox\Profiles\twui6w8i.default\extensions\https-everywhere-eff@eff.org.xpi =>.HTTPS Everywhere
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- D:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll =>.Adobe Systems Incorporated

---\\ Internet Explorer Extensions, Start, Search (15) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Browser.) (11.00.9600.18347 (winblue_ltsb.160520-1047)) -- D:\Windows\SysWOW64\ieframe.dll =>.Microsoft Corporation

---\\ Internet Explorer, Proxy Management (5) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=D:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=D:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation

---\\ Hosts file redirection (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)

---\\ Global shortcuts Startup (81) - 10s
O4 - GS\Desktop [Administrator]: My Printer.lnk . (.CANON INC. - Canon My Printer.) D:\Program Files\Canon\MyPrinter\BJMYPRT.EXE /mn =>.Canon Inc.®
O4 - GS\Desktop [Administrator]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) D:\Users\Isaie\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) D:\Users\Isaie\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Administrator]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) D:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\sendTo [Administrator]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) D:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) D:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) D:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Administrator]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) D:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Administrator]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) D:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrator]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) D:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Programs [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) D:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Guest]: My Printer.lnk . (.CANON INC. - Canon My Printer.) D:\Program Files\Canon\MyPrinter\BJMYPRT.EXE /mn =>.Canon Inc.®
O4 - GS\Desktop [Guest]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) D:\Users\Isaie\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) D:\Users\Isaie\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Guest]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) D:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\sendTo [Guest]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) D:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) D:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) D:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Guest]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) D:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Guest]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) D:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Guest]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) D:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Programs [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) D:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Isaie]: My Printer.lnk . (.CANON INC. - Canon My Printer.) D:\Program Files\Canon\MyPrinter\BJMYPRT.EXE /mn =>.Canon Inc.®
O4 - GS\Desktop [Isaie]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) D:\Users\Isaie\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
O4 - GS\Desktop [Isaie]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) D:\Users\Isaie\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Isaie]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) D:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\sendTo [Isaie]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) D:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\sendTo [Isaie]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) D:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\TaskBar [Isaie]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) D:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\TaskBar [Isaie]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) D:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Isaie]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) D:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Isaie]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) D:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Programs [Isaie]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) D:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\CommonDesktop [Public]: Adobe Reader 9.lnk . (.Adobe Systems Incorporated - Adobe Reader 9.0.) D:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe =>.Adobe Systems, Incorporated®
O4 - GS\CommonDesktop [Public]: Canon MX880 series Manuel en ligne.lnk . (.CANON INC. - Easy Guide Viewer.) D:\Program Files (x86)\Canon\IJ Manual\Easy Guide Viewer\cmview.exe "D:\PROGRAM FILES (X86)\Canon\IJ Manual\CANON MX880 SERIES\French\Info.egv" =>.Canon Inc.®
O4 - GS\CommonDesktop [Public]: Canon Solution Menu EX.lnk . (.CANON INC. - Canon Solution Menu EX.) D:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE =>.Canon Inc.®
O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Ltd - CCleaner.) D:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd®
O4 - GS\CommonDesktop [Public]: e-Sword.lnk . (.Rick Meyers - e-Sword.exe.) D:\Program Files (x86)\e-Sword\e-Sword.exe
O4 - GS\CommonDesktop [Public]: Freelang.lnk . (.Copyright © 2014 - Freelang.) D:\Program Files (x86)\Freelang\Freelang.exe
O4 - GS\CommonDesktop [Public]: LibreOffice 5.3.lnk . (.The Document Foundation - LibreOffice.) D:\Program Files (x86)\LibreOffice 5\program\soffice.exe =>.The Document Foundation®
O4 - GS\CommonDesktop [Public]: Malwarebytes.lnk . (.Malwarebytes - Malwarebytes.) D:\Program Files\Malwarebytes\Anti-Malware\mbam.exe =>.Malwarebytes Corporation®
O4 - GS\CommonDesktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) D:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\CommonDesktop [Public]: OpenOffice 4.1.2.lnk . (.Apache Software Foundation - OpenOffice 4.1.2.) D:\Program Files (x86)\OpenOffice 4\program\soffice.exe =>.Apache Software Foundation
O4 - GS\Programs [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) D:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Accessories [Public]: Command Prompt.lnk . (.Microsoft Corporation - Windows Command Processor.) D:\Windows\system32\cmd.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) D:\Windows\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) D:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) D:\Program Files (x86)\Internet Explorer\iexplore.exe -extoff =>.Microsoft Corporation®
O4 - GS\SystemTools [Public]: Private Character Editor.lnk . (.Microsoft Corporation - Private Character Editor.) D:\Windows\system32\eudcedit.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Bluetooth File Transfer Wizard.lnk . (.Microsoft Corporation - .) D:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Windows Calculator.) D:\Windows\system32\calc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - Display Switch.) D:\Windows\system32\displayswitch.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Math Input Panel Accessory.) D:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - Windows Mobility Center.) D:\Windows\system32\mblctr.exe /open =>.Microsoft Corporation
O4 - GS\Accessories [Public]: NetworkProjection.lnk . (.Microsoft Corporation - Connect to a Network Projector.) D:\Windows\system32\NetProj.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) D:\Windows\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) D:\Windows\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) D:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Windows Sound Recorder.) D:\Windows\system32\SoundRecorder.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - Sticky Notes.) D:\Windows\system32\StikyNot.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) D:\Windows\System32\mobsync.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Welcome Center.lnk . (.Microsoft Corporation - Windows host process (Rundll32).) D:\Windows\system32\rundll32.exe %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut =>..Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) D:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) D:\Windows\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - Microsoft® Disk Defragmenter.) D:\Windows\system32\dfrgui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - Disk Space Cleanup Manager for Windows.) D:\Windows\system32\cleanmgr.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - Resource and Performance Monitor.) D:\Windows\system32\perfmon.exe /res =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - System Information.) D:\Windows\system32\msinfo32.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - Microsoft® Windows System Restore.) D:\Windows\system32\rstrui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) D:\Windows\system32\taskschd.msc /s =>..Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - Windows Easy Transfer Post Migration Applic.) D:\Windows\system32\migwiz\postmig.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - Windows Easy Transfer Application.) D:\Windows\system32\migwiz\migwiz.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Adobe Reader 9.lnk . (...) D:\Windows\Installer\{AC76BA86-7AD7-1036-7B44-A90000000001}\SC_Reader.exe
O4 - GS\ProgramsCommon [Public]: Media Center.lnk . (.Microsoft Corporation - Windows Media Center.) D:\Windows\ehome\ehshell.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Microsoft Security Essentials.lnk . (.Microsoft Corporation - .) D:\Program Files (x86)\Microsoft Security Client\msseces.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) D:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\ProgramsCommon [Public]: Sidebar.lnk . (.Microsoft Corporation - Windows Desktop Gadgets.) D:\Program Files (x86)\Windows Sidebar\sidebar.exe /showgadgets =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows DVD Maker.lnk . (.Microsoft Corporation - .) D:\Program Files (x86)\DVD Maker\DVDMaker.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) D:\Windows\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) D:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: XPS Viewer.lnk . (.Microsoft Corporation - XPS Viewer.) D:\Windows\system32\xpsrchvw.exe =>.Microsoft Corporation

---\\ Lop.com/Domain Hijackers (2) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240 =>.France 9 Telecom, Free
O17 - HKLM\System\CCS\Services\Tcpip\..\{1EFA76EA-9FB1-4625-9017-4ACC40319BF4}: DhcpNameServer = 212.27.40.241 212.27.40.240 =>.France 9 Telecom, Free

---\\ Extra protocols (20) - 1s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- D:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- D:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- D:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- D:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- D:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- D:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- D:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- D:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- D:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- D:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- D:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- D:\Windows\System32\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- D:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- D:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- D:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- D:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- D:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- D:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- D:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- D:\Windows\System32\mscoree.dll =>.Microsoft Corporation®

---\\ ASIC (ActiveSetup Installed Components) (11) - 1s
O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Microsoft Windows Media Player Setup Utilit.) -- D:\Windows\System32\unregmp2.exe =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- D:\Windows\SysWOW64\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - Microsoft(C) Register Server.) -- D:\Windows\System32\regsvr32.exe =>.Microsoft Corporation
O40 - ASIC: Internet Explorer [64Bits] - {2D46B6DC-2207-486B-B523-A557E6D54B47} . (...) -- /D /C start D:\Windows\system32\ie4uinit.exe (.not file.) =>.SUP.Various
O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- D:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Enable TLS1.1 and 1.2 [64Bits] - {66C64F22-FC60-4E6C-A6B5-F0D580E680CE} . (.Microsoft Corporation - IE Per-User Initialization Utility.) -- D:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Microsoft Windows Media Player Setup Utilit.) -- D:\Windows\System32\unregmp2.exe =>.Microsoft Corporation
O40 - ASIC: Disable SSL3 [64Bits] - {7D715857-A67C-4C2F-A929-038448584D63} . (.Microsoft Corporation - IE Per-User Initialization Utility.) -- D:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - IE Per-User Initialization Utility.) -- D:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- D:\Windows\System32\mscories.dll =>.Microsoft Corporation®
O40 - ASIC: Google Chrome [64Bits] - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (...) -- D:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\chrmstp.exe (.not file.) =>.SUP.Various

---\\ Software installed (24) - 8s
O42 - Logiciel: Adobe Flash Player 27 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Reader 9 - Français - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1036-7B44-A90000000001} =>.Adobe Systems Incorporated
O42 - Logiciel: Canon Easy-PhotoPrint EX - (..) [HKLM][64Bits] -- Easy-PhotoPrint EX =>.Canon Inc.®
O42 - Logiciel: Canon MP Navigator EX 4.1 - (.Canon Inc..) [HKLM][64Bits] -- MP Navigator EX 4.1 =>.Canon Inc.®
O42 - Logiciel: Canon MX880 series MP Drivers - (..) [HKLM][64Bits] -- {1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX880_series
O42 - Logiciel: Canon My Printer - (..) [HKLM][64Bits] -- CanonMyPrinter =>.Canon Inc.®
O42 - Logiciel: Canon Solution Menu EX - (..) [HKLM][64Bits] -- CanonSolutionMenuEX =>.Canon Inc.®
O42 - Logiciel: Canon Utilitaire de numérotation rapide - (..) [HKLM][64Bits] -- Speed Dial Utility =>.Canon Inc.®
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>.Piriform Ltd®
O42 - Logiciel: Enregistrement utilisateur de Canon MX880 series - (..) [HKLM][64Bits] -- Enregistrement utilisateur de Canon MX880 series =>.Canon Inc.®
O42 - Logiciel: e-Sword - (.Rick Meyers.) [HKLM][64Bits] -- {463178C4-E707-41EE-BE8A-080C62BF526D}
O42 - Logiciel: Freelang - (.Freelang.) [HKLM][64Bits] -- {A09E2D66-B931-415C-A9DE-FF030AB5AD77}_is1 =>.Freelang
O42 - Logiciel: Freelang - (.Freelang.net.) [HKLM][64Bits] -- {0F44DC3F-6E62-4AB1-A14B-56223C512F9B}_is1
O42 - Logiciel: LibreOffice 5.3.0.3 - (.The Document Foundation.) [HKLM][64Bits] -- {BB258465-D7F3-474E-8754-3436A75956D8} =>.The Document Foundation
O42 - Logiciel: Malwarebytes version 3.1.2.1733 - (.Malwarebytes.) [HKLM][64Bits] -- {35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1 =>.Malwarebytes Corporation®
O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM][64Bits] -- {2AA3C13E-0531-41B8-AE48-AE28C940A809} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Security Client =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation
O42 - Logiciel: Mozilla Firefox 53.0.3 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 53.0.3 (x86 fr) =>.Mozilla Corporation®
O42 - Logiciel: Mozilla Firefox 56.0 (x64 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 56.0 (x64 fr) =>.Mozilla Corporation®
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService =>.Mozilla
O42 - Logiciel: Nuvoton CIR Device Drivers - (.Nuvoton Technology Corporation.) [HKLM][64Bits] -- {FBC79D04-051E-4367-8051-1DB0C893FBE0} =>.Nuvoton Technology Corporation
O42 - Logiciel: OpenOffice 4.1.2 - (.Apache Software Foundation.) [HKLM][64Bits] -- {DCB1B348-C94E-4D6D-8CE0-7D9DA5CF663E} =>.Apache Software Foundation
O42 - Logiciel: OpenOffice 4.1.2 Language Pack (French) - (.Apache Software Foundation.) [HKLM][64Bits] -- {A726FCAB-2F2A-465A-A686-B2F9E9CD3D83} =>.Apache Software Foundation

---\\ HKCU & HKLM Software Keys (46) - 8s
HKLM\SOFTWARE\Wow6432Node\Adobe =>.Adobe
HKLM\SOFTWARE\Wow6432Node\AMD =>.AMD
HKLM\SOFTWARE\Wow6432Node\Apple Inc. =>.Apple Inc.
HKLM\SOFTWARE\Wow6432Node\ATI =>.ATI
HKLM\SOFTWARE\Wow6432Node\ATI Technologies =>.ATI Technologies
HKLM\SOFTWARE\Wow6432Node\Canon =>.Canon
HKLM\SOFTWARE\Wow6432Node\Google =>.Google
HKLM\SOFTWARE\Wow6432Node\Intel =>.Intel
HKLM\SOFTWARE\Wow6432Node\Khronos =>.Khronos
HKLM\SOFTWARE\Wow6432Node\LibreOffice =>.LibreOffice
HKLM\SOFTWARE\Wow6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware =>.Malwarebytes' Anti-Malware
HKLM\SOFTWARE\Wow6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\Wow6432Node\OpenOffice =>.SourceForge
HKLM\SOFTWARE\Wow6432Node\Piriform =>.Piriform
HKLM\SOFTWARE\Wow6432Node\TeamViewer =>.TeamViewer
HKLM\SOFTWARE\Wow6432Node\The Document Foundation =>.The Document Foundation
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\Adobe =>.Adobe
HKCU\SOFTWARE\AMD =>.AMD
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\ATI =>.ATI
HKCU\SOFTWARE\Canon =>.Canon
HKCU\SOFTWARE\CanonBJ =>.Canon Inc.
HKCU\SOFTWARE\ESET =>.ESET
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\Intel =>.Intel
HKCU\SOFTWARE\Macromedia =>.Macromedia
HKCU\SOFTWARE\Malwarebytes =>.Malwarebytes
HKCU\SOFTWARE\Memodata
HKCU\SOFTWARE\Mozilla =>.Mozilla
HKCU\SOFTWARE\Netscape =>.Netscape
HKCU\SOFTWARE\OpenOffice =>.SourceForge
HKCU\SOFTWARE\Piriform =>.Piriform
HKCU\SOFTWARE\Raptr =>.Raptr
HKCU\SOFTWARE\The Document Foundation =>.The Document Foundation
HKCU\SOFTWARE\Trolltech =>.Trolltech
HKCU\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation
HKCU\SOFTWARE\WinRAR SFX =>.RarLab
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\ZebHelpProcess Helper =>.Nicolas Coolman
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation

---\\ Contents of the Common Files folders (183) - 19s
O43 - CFD: 13/09/2016 - [] D -- D:\Program Files\AMD =>.AMD
O43 - CFD: 16/02/2017 - [] D -- D:\Program Files\Canon =>.Canon Inc.®
O43 - CFD: 16/02/2017 - [] HD -- D:\Program Files\CanonBJ =>.Canon Inc.
O43 - CFD: 30/09/2017 - [] D -- D:\Program Files\CCleaner =>.Piriform Ltd
O43 - CFD: 16/02/2017 - [] D -- D:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 15/04/2015 - [] D -- D:\Program Files\DVD Maker =>.Aone Software
O43 - CFD: 07/08/2017 - [] D -- D:\Program Files\GIMP 2
O43 - CFD: 16/02/2017 - [] D -- D:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 17/01/2017 - [] D -- D:\Program Files\LibreOffice 5 =>.LibreOffice
O43 - CFD: 30/09/2017 - [] D -- D:\Program Files\Malwarebytes =>.Malwarebytes
O43 - CFD: 12/04/2011 - [] D -- D:\Program Files\Microsoft Games =>.Microsoft Corporation
O43 - CFD: 24/02/2017 - [] D -- D:\Program Files\Microsoft Security Client =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- D:\Program Files\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- D:\Program Files\Mozilla Firefox =>.Mozilla
O43 - CFD: 14/07/2009 - [] D -- D:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 16/08/2017 - [0] D -- D:\Program Files\paint.net =>.Rick Brewster
O43 - CFD: 14/07/2009 - [] D -- D:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] HD -- D:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 21/06/2016 - [] D -- D:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 16/02/2017 - [] D -- D:\Program Files\Windows Journal =>.Microsoft Corporation
O43 - CFD: 17/06/2016 - [] D -- D:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 16/02/2017 - [] D -- D:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- D:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 15/04/2015 - [] D -- D:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 21/11/2010 - [] D -- D:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 15/04/2015 - [] D -- D:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- D:\Program Files (x86)\Adobe =>.Adobe Systems, Incorporated®
O43 - CFD: 25/10/2016 - [0] D -- D:\Program Files (x86)\AnonymizerGadget =>.SUP.AnonymizerGadget
O43 - CFD: 16/02/2017 - [] D -- D:\Program Files (x86)\Canon =>.Canon Inc.®
O43 - CFD: 16/01/2017 - [] D -- D:\Program Files (x86)\Chiavetta Internet
O43 - CFD: 16/02/2017 - [] D -- D:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 20/06/2016 - [] D -- D:\Program Files (x86)\e-Sword
O43 - CFD: 05/03/2017 - [] D -- D:\Program Files (x86)\Freelang =>.Freelang
O43 - CFD: 30/09/2017 - [] D -- D:\Program Files (x86)\Google =>.Google
O43 - CFD: 25/10/2016 - [] D -- D:\Program Files (x86)\Grepkvunerck
O43 - CFD: 16/01/2017 - [] D -- D:\Program Files (x86)\GUM9780.tmp
O43 - CFD: 21/06/2016 - [] D -- D:\Program Files (x86)\Intel =>.Intel Corporation
O43 - CFD: 16/02/2017 - [] D -- D:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 25/10/2016 - [] D -- D:\Program Files (x86)\Java =>.Oracle
O43 - CFD: 12/03/2017 - [] D -- D:\Program Files (x86)\LibreOffice 5 =>.LibreOffice
O43 - CFD: 30/09/2017 - [] D -- D:\Program Files (x86)\Malwarebytes Anti-Malware =>.Malwarebytes
O43 - CFD: 24/02/2017 - [] D -- D:\Program Files (x86)\Microsoft Security Client =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- D:\Program Files (x86)\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 25/10/2016 - [] D -- D:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- D:\Program Files (x86)\Mozilla Firefox =>.Mozilla
O43 - CFD: 30/09/2017 - [] D -- D:\Program Files (x86)\Mozilla Maintenance Service =>.Mozilla
O43 - CFD: 14/07/2009 - [] D -- D:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 16/02/2017 - [] D -- D:\Program Files (x86)\Nuvoton Technology Corporation =>.Nuvoton Technology Corporation
O43 - CFD: 18/06/2016 - [] D -- D:\Program Files (x86)\OpenOffice 4 =>.OpenOffice.org
O43 - CFD: 16/02/2017 - [] D -- D:\Program Files (x86)\Raptr Inc =>.Raptr Inc.
O43 - CFD: 14/07/2009 - [] D -- D:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- D:\Program Files (x86)\SafeIP =>.SafeIP
O43 - CFD: 25/10/2016 - [] D -- D:\Program Files (x86)\TeamViewer =>.TeamViewer GmbH
O43 - CFD: 06/03/2017 - [] D -- D:\Program Files (x86)\Ultralingua =>.Ultralingua
O43 - CFD: 25/10/2016 - [0] HD -- D:\Program Files (x86)\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 21/06/2016 - [] D -- D:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 17/06/2016 - [] D -- D:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 16/02/2017 - [] D -- D:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- D:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 15/04/2015 - [] D -- D:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 21/11/2010 - [] D -- D:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 15/04/2015 - [] D -- D:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] RD -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 17/06/2016 - [] RD -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 25/10/2016 - [0] D -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnonymizerGadget =>.SUP.AnonymizerGadget
O43 - CFD: 26/09/2017 - [0] D -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX880 series
O43 - CFD: 16/02/2017 - [] D -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX880 series Manual
O43 - CFD: 07/08/2017 - [] D -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities =>.Canon Inc.
O43 - CFD: 30/09/2017 - [] D -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner =>.Piriform Ltd
O43 - CFD: 20/06/2016 - [] D -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\e-Sword
O43 - CFD: 16/02/2017 - [] D -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Enregistrement utilisateur de Canon MX880 series
O43 - CFD: 05/03/2017 - [] D -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freelang =>.Freelang
O43 - CFD: 17/06/2016 - [] RD -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.3 =>.LibreOffice
O43 - CFD: 17/06/2016 - [] RD -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] D -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes =>.Malwarebytes
O43 - CFD: 30/09/2017 - [] D -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 18/06/2016 - [] SD -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2 =>.SourceForge
O43 - CFD: 16/02/2017 - [] RD -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 12/04/2011 - [0] RHD -- D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC =>.Wacom Technology
O43 - CFD: 08/08/2017 - [] D -- D:\ProgramData\Adobe =>.Adobe
O43 - CFD: 14/07/2009 - [0] SHD -- D:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 25/10/2016 - [] D -- D:\ProgramData\AVAST Software =>.AVAST Software
O43 - CFD: 25/10/2016 - [] D -- D:\ProgramData\Avg =>.AVG Software
O43 - CFD: 25/10/2016 - [] D -- D:\ProgramData\Avira =>.Avira Software
O43 - CFD: 04/06/2016 - [] D -- D:\ProgramData\CanonBJ =>.Canon Inc.
O43 - CFD: 04/06/2016 - [0] HD -- D:\ProgramData\CanonEPP =>.Canon Inc.
O43 - CFD: 30/09/2017 - [] HD -- D:\ProgramData\CanonIJEGV =>.Canon Inc.
O43 - CFD: 04/06/2016 - [0] HD -- D:\ProgramData\CanonIJEPPEX2 =>.Canon Inc.
O43 - CFD: 16/02/2017 - [] D -- D:\ProgramData\CanonIJFAX =>.Canon Inc.
O43 - CFD: 30/09/2017 - [] HD -- D:\ProgramData\CanonIJScan =>.Canon Inc.
O43 - CFD: 30/09/2017 - [] HD -- D:\ProgramData\CanonIJSDU
O43 - CFD: 07/07/2016 - [] D -- D:\ProgramData\CanonIJWSpt =>.Canon Inc.
O43 - CFD: 01/01/2017 - [] D -- D:\ProgramData\Chiavetta Internet
O43 - CFD: 01/01/2017 - [] D -- D:\ProgramData\DatacardService =>.Entriq, Inc.
O43 - CFD: 14/07/2009 - [0] SHD -- D:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- D:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- D:\ProgramData\Favorites =>.Microsoft Corporation
O43 - CFD: 28/07/2016 - [] D -- D:\ProgramData\Freelang =>.Freelang
O43 - CFD: 30/09/2017 - [] D -- D:\ProgramData\Malwarebytes =>.Malwarebytes
O43 - CFD: 16/02/2017 - [] SD -- D:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 17/06/2016 - [] D -- D:\ProgramData\Oracle =>.Oracle
O43 - CFD: 30/09/2017 - [] D -- D:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- D:\ProgramData\Start Menu =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- D:\ProgramData\Templates =>.Microsoft Corporation
O43 - CFD: 06/03/2017 - [] D -- D:\ProgramData\Ultralingua7
O43 - CFD: 15/01/2017 - [] D -- D:\ProgramData\UniqueId =>.Microsoft Corporation
O43 - CFD: 15/01/2017 - [] D -- D:\ProgramData\WinZip =>.WinZip
O43 - CFD: 30/09/2017 - [] D -- D:\Program Files (x86)\Common Files\Adobe =>.Adobe
O43 - CFD: 20/06/2016 - [] D -- D:\Program Files (x86)\Common Files\EzTools =>.EZTools
O43 - CFD: 16/02/2017 - [] D -- D:\Program Files (x86)\Common Files\microsoft shared =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- D:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- D:\Program Files (x86)\Common Files\SpeechEngines =>.Microsoft Corporation
O43 - CFD: 21/06/2016 - [] D -- D:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 23/12/2016 - [] D -- D:\Users\Isaie\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 26/09/2017 - [0] D -- D:\Users\Isaie\AppData\Roaming\Avanquest Software =>.Avanquest Software
O43 - CFD: 23/12/2016 - [] D -- D:\Users\Isaie\AppData\Roaming\Canon =>.Canon
O43 - CFD: 05/06/2016 - [] D -- D:\Users\Isaie\AppData\Roaming\eTeks =>.eTeks
O43 - CFD: 25/10/2016 - [0] D -- D:\Users\Isaie\AppData\Roaming\Ferqerentploziry
O43 - CFD: 03/06/2016 - [] D -- D:\Users\Isaie\AppData\Roaming\Identities =>.Microsoft Corporation
O43 - CFD: 03/06/2016 - [] D -- D:\Users\Isaie\AppData\Roaming\library_dir =>.library_dir
O43 - CFD: 18/06/2016 - [] D -- D:\Users\Isaie\AppData\Roaming\LibreOffice =>.LibreOffice
O43 - CFD: 03/06/2016 - [] D -- D:\Users\Isaie\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 12/04/2011 - [0] D -- D:\Users\Isaie\AppData\Roaming\Media Center Programs =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] SD -- D:\Users\Isaie\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 03/06/2016 - [] D -- D:\Users\Isaie\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 05/06/2016 - [] D -- D:\Users\Isaie\AppData\Roaming\OpenOffice =>.SourceForge
O43 - CFD: 17/06/2016 - [] D -- D:\Users\Isaie\AppData\Roaming\Oracle =>.Oracle
O43 - CFD: 25/10/2016 - [] D -- D:\Users\Isaie\AppData\Roaming\Profiles =>.Microsoft Corporation
O43 - CFD: 16/02/2017 - [] D -- D:\Users\Isaie\AppData\Roaming\Raptr =>.Raptr
O43 - CFD: 17/06/2016 - [] D -- D:\Users\Isaie\AppData\Roaming\Sun =>.Oracle
O43 - CFD: 03/06/2016 - [] D -- D:\Users\Isaie\AppData\Roaming\TeamViewer =>.TeamViewer GmbH
O43 - CFD: 03/06/2016 - [] D -- D:\Users\Isaie\AppData\Roaming\WinRAR =>.WinRAR
O43 - CFD: 01/10/2017 - [] D -- D:\Users\Isaie\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 18/08/2017 - [] D -- D:\Users\Isaie\AppData\Local\Adobe =>.Adobe
O43 - CFD: 03/06/2016 - [0] SHD -- D:\Users\Isaie\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 17/06/2016 - [] D -- D:\Users\Isaie\AppData\Local\Apps =>.Microsoft Corporation
O43 - CFD: 16/08/2017 - [0] D -- D:\Users\Isaie\AppData\Local\Avanquest =>.Avanquest
O43 - CFD: 22/09/2017 - [] D -- D:\Users\Isaie\AppData\Local\Canon Easy-PhotoPrint EX =>.Canon Inc.
O43 - CFD: 23/08/2016 - [] D -- D:\Users\Isaie\AppData\Local\CEF =>.CEF
O43 - CFD: 22/05/2017 - [] D -- D:\Users\Isaie\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 25/10/2016 - [0] D -- D:\Users\Isaie\AppData\Local\Djerkgragoch
O43 - CFD: 20/06/2016 - [] D -- D:\Users\Isaie\AppData\Local\Downloaded Installations =>.Microsoft Corporation
O43 - CFD: 03/06/2016 - [] D -- D:\Users\Isaie\AppData\Local\ESET =>.ESET
O43 - CFD: 02/08/2017 - [] D -- D:\Users\Isaie\AppData\Local\fontconfig =>.Portable Apps
O43 - CFD: 02/08/2017 - [] D -- D:\Users\Isaie\AppData\Local\gegl-0.2 =>.Portable Apps
O43 - CFD: 30/09/2017 - [] D -- D:\Users\Isaie\AppData\Local\Google =>.Google
O43 - CFD: 07/06/2016 - [] D -- D:\Users\Isaie\AppData\Local\GWX =>.GWX
O43 - CFD: 03/06/2016 - [0] SHD -- D:\Users\Isaie\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 16/08/2017 - [0] D -- D:\Users\Isaie\AppData\Local\InPixio =>.InPixio
O43 - CFD: 03/06/2016 - [] D -- D:\Users\Isaie\AppData\Local\Macromedia =>.Macromedia
O43 - CFD: 16/02/2017 - [] D -- D:\Users\Isaie\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 11/11/2016 - [] D -- D:\Users\Isaie\AppData\Local\Microsoft Games =>.Microsoft Corporation
O43 - CFD: 18/11/2016 - [0] DC -- D:\Users\Isaie\AppData\Local\MigWiz =>.MigWiz
O43 - CFD: 30/09/2017 - [] D -- D:\Users\Isaie\AppData\Local\Mozilla =>.Mozilla Corporation
O43 - CFD: 10/08/2017 - [] D -- D:\Users\Isaie\AppData\Local\paint.net =>.Rick Brewster
O43 - CFD: 05/06/2016 - [] D -- D:\Users\Isaie\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 01/10/2017 - [] D -- D:\Users\Isaie\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 03/06/2016 - [0] SHD -- D:\Users\Isaie\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 06/03/2017 - [] D -- D:\Users\Isaie\AppData\Local\Ultralingua7
O43 - CFD: 19/07/2017 - [] D -- D:\Users\Isaie\AppData\Local\vghd =>.SUP.VirtualGirl
O43 - CFD: 30/09/2017 - [] D -- D:\Users\Isaie\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 01/10/2017 - [] D -- D:\Users\Isaie\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 05/06/2016 - [0] D -- D:\Users\Isaie\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 16/02/2017 - [] RD -- D:\Users\Isaie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 16/02/2017 - [] RD -- D:\Users\Isaie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 17/06/2016 - [] RD -- D:\Users\Isaie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 16/02/2017 - [] RD -- D:\Users\Isaie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 15/01/2017 - [0] D -- D:\Users\Isaie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinZip 21.0
O43 - CFD: 14/07/2009 - [0] SHD -- D:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- D:\Users\Default\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- D:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] D -- D:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- D:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- D:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- D:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- D:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] D -- D:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- D:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- D:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 30/09/2017 - [] -- D:\Windows\System32\Config\systemprofile\AppData\Local\SafeIPS =>.Safe IPS
O43 - CFD: 14/07/2009 - [] SD -- D:\Windows\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 14/07/2016 - [] -- D:\Windows\System32\Config\systemprofile\AppData\Roaming\PlaysTV =>.PlaysTV

---\\ ShellIconOverlayIdentifiers (SIOI) (2) - 0s
O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) -- D:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - Shell extensions for sharing.) -- D:\Windows\System32\ntshrui.dll =>.Microsoft Corporation

---\\ Image File Execution Options (4) - 0s
O50 - IFEO:D:\Windows\System32\ie4uinit.exe - (.Microsoft Corporation - IE Per-User Initialization Utility.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:D:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - IE 7.0 Unattended Install Utility.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:D:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:D:\Windows\System32\mshta.exe - (.Microsoft Corporation - Microsoft (R) HTML Application host.) [MitigationOptions\\256] =>.Microsoft Corporation

---\\ System Drivers List (56) - 38s
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- D:\Windows\System32\drivers\adp94xx.sys [491088] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- D:\Windows\System32\drivers\adpahci.sys [339536] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- D:\Windows\System32\drivers\adpu320.sys [182864] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- D:\Windows\System32\drivers\aliide.sys [15440] =>.Microsoft Windows®
O58 - SDL:2015/07/16 04:09:00 A . (.Advanced Micro Devices - AMD ACP Binaries.) -- D:\Windows\System32\drivers\amdacpksd.sys [297672] =>.Advanced Micro Devices, Inc.®
O58 - SDL:2015/04/23 20:19:10 A . (.Advanced Micro Devices, Inc. - AMD PCI Root Bus Lower Filter.) -- D:\Windows\System32\drivers\amdkmpfd.sys [65248] =>.Advanced Micro Devices, Inc.®
O58 - SDL:2011/03/11 08:41:12 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- D:\Windows\System32\drivers\amdsata.sys [107904] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- D:\Windows\System32\drivers\amdsbs.sys [194128] =>.Microsoft Windows®
O58 - SDL:2011/03/11 08:41:12 A . (.Advanced Micro Devices - Storage Filter Driver.) -- D:\Windows\System32\drivers\amdxata.sys [27008] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- D:\Windows\System32\drivers\arc.sys [87632] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- D:\Windows\System32\drivers\arcsas.sys [97856] =>.Microsoft Windows®
O58 - SDL:2009/06/20 04:09:57 A . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driv.) -- D:\Windows\System32\drivers\athrx.sys [1394688] =>.Atheros Communications, Inc.
O58 - SDL:2015/07/16 04:06:36 A . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) -- D:\Windows\System32\drivers\atikmdag.sys [21622272] =>.Advanced Micro Devices, Inc.
O58 - SDL:2015/07/16 03:13:26 A . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- D:\Windows\System32\drivers\atikmpag.sys [665088] =>.Advanced Micro Devices, Inc.
O58 - SDL:2009/06/10 22:34:23 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- D:\Windows\System32\drivers\b57nd60a.sys [270848] =>.Broadcom Corporation
O58 - SDL:2009/06/10 22:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- D:\Windows\System32\drivers\BrFiltLo.sys [18432] =>.Brother Industries, Ltd.
O58 - SDL:2009/06/10 22:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- D:\Windows\System32\drivers\BrFiltUp.sys [8704] =>.Brother Industries, Ltd.
O58 - SDL:2009/07/14 03:19:07 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) -- D:\Windows\System32\drivers\BrSerId.sys [286720] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- D:\Windows\System32\drivers\BrSerWdm.sys [47104] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- D:\Windows\System32\drivers\BrUsbMdm.sys [14976] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- D:\Windows\System32\drivers\BrUsbSer.sys [14720] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 22:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- D:\Windows\System32\drivers\bxvbda.sys [468480] =>.Broadcom Corporation
O58 - SDL:2009/07/14 03:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- D:\Windows\System32\drivers\cmdide.sys [17488] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- D:\Windows\System32\drivers\elxstor.sys [530496] =>.Microsoft Windows®
O58 - SDL:2015/07/30 12:41:36 A . (.ESET - Epfw NDIS LightWeight Filter.) -- D:\Windows\System32\drivers\EpfwLWF.sys [52872] =>.ESET, spol. s r.o.®
O58 - SDL:2009/06/10 22:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- D:\Windows\System32\drivers\evbda.sys [3286016] =>.Broadcom Corporation
O58 - SDL:2009/06/10 22:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- D:\Windows\System32\drivers\hcw85cir.sys [31232] =>.Hauppauge Computer Works, Inc.
O58 - SDL:2009/09/17 19:54:54 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- D:\Windows\System32\drivers\HECIx64.sys [56344] =>.Intel Corporation®
O58 - SDL:2009/08/31 15:36:18 A . (.Windows (R) Win 7 DDK provider - SHIM filter for KMDF HIDMINI driver.) -- D:\Windows\System32\drivers\hidshim.sys [6656] =>.Windows (R) Win 7 DDK provider
O58 - SDL:2010/11/21 05:23:47 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- D:\Windows\System32\drivers\HpSAMD.sys [78720] =>.Microsoft Windows®
O58 - SDL:2011/03/11 08:41:26 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- D:\Windows\System32\drivers\iaStorV.sys [410496] =>.Microsoft Windows®
O58 - SDL:2012/01/10 22:28:18 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- D:\Windows\System32\drivers\igdkmd64.sys [12311904] =>.Intel Corporation
O58 - SDL:2009/07/14 03:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- D:\Windows\System32\drivers\iirsp.sys [44112] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- D:\Windows\System32\drivers\lsi_fc.sys [114752] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- D:\Windows\System32\drivers\lsi_sas.sys [106560] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- D:\Windows\System32\drivers\lsi_sas2.sys [65600] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- D:\Windows\System32\drivers\lsi_scsi.sys [115776] =>.Microsoft Windows®
O58 - SDL:2017/05/09 16:37:58 A . (...) -- D:\Windows\System32\drivers\mbae64.sys [77440] =>.Malwarebytes Corporation®
O58 - SDL:2017/10/01 13:16:03 A . (.Malwarebytes - Malwarebytes SwissArmy.) -- D:\Windows\System32\drivers\MBAMSwissArmy.sys [251832] =>.Malwarebytes Corporation®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- D:\Windows\System32\drivers\megasas.sys [35392] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- D:\Windows\System32\drivers\MegaSR.sys [284736] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- D:\Windows\System32\drivers\nfrd960.sys [51264] =>.Microsoft Windows®
O58 - SDL:2009/08/31 15:36:16 A . (.Nuvoton Technology Corporation - Nuvoton HID CIR Receiver.) -- D:\Windows\System32\drivers\nuvotonhidcir.sys [26624] =>.Nuvoton Technology Corporation
O58 - SDL:2011/03/11 08:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- D:\Windows\System32\drivers\nvraid.sys [148352] =>.Microsoft Windows®
O58 - SDL:2011/03/11 08:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- D:\Windows\System32\drivers\nvstor.sys [166272] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- D:\Windows\System32\drivers\ql2300.sys [1524816] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- D:\Windows\System32\drivers\ql40xx.sys [128592] =>.Microsoft Windows®
O58 - SDL:2009/06/10 22:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- D:\Windows\System32\drivers\secdrv.sys [23040] =>.Macrovision Corporation, Macrovision Europe Limited,
O58 - SDL:2009/07/14 02:00:40 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) -- D:\Windows\System32\drivers\serial.sys [94208] =>.Brother Industries Ltd.
O58 - SDL:2009/07/14 03:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- D:\Windows\System32\drivers\sisraid2.sys [43584] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- D:\Windows\System32\drivers\sisraid4.sys [80464] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- D:\Windows\System32\drivers\stexstor.sys [24656] =>.Microsoft Windows®
O58 - SDL:2017/05/16 15:42:02 A . (.Anchorfree Inc. - Anchorfree HSS VPN Adapter.) -- D:\Windows\System32\drivers\taphss6.sys [42064] =>.AnchorFree Inc®
O58 - SDL:2009/07/14 03:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- D:\Windows\System32\drivers\viaide.sys [17488] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- D:\Windows\System32\drivers\vsmraid.sys [161872] =>.Microsoft Windows®
O58 - SDL:2008/06/03 13:38:30 A . (.Winbond Electronics Corporation - Winbond HID CIR Receiver.) -- D:\Windows\System32\drivers\winbondhidcir.sys [26112] =>.Winbond Electronics Corporation

---\\ File Associations Shell Spawning (11) - 1s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- D:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- D:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (...) -- D:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (...) -- %1" %*
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- D:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- D:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®

---\\ Start Menu Internet (16) - 0s
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- D:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Mozilla Corporation - .) -- D:\Program Files (x86)\Mozilla Firefox\firefox.exe (.not file.) =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (...) -- D:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- D:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- D:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- D:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (...) -- D:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- D:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- D:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- D:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (...) -- D:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- D:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- D:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- D:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (...) -- D:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- D:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

---\\ Search Browser Infection (2) - 23s
O69 - SBI: SearchScopes [HKCU] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com

---\\ Search Svchost Services (33) - 0s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- D:\Windows\System32\aelupsvc.dll [72192] =>.Microsoft Corporation
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- D:\Windows\System32\certprop.dll [80384] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- D:\Windows\System32\certprop.dll [80384] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- D:\Windows\System32\srvsvc.dll [236032] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- D:\Windows\System32\gpsvc.dll [794624] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- D:\Windows\System32\ikeext.dll [859648] =>.Microsoft Corporation
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- D:\Windows\System32\Audiosrv.dll [680960] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- D:\Windows\System32\rasauto.dll [99328] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- D:\Windows\System32\rasmans.dll [344064] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- D:\Windows\System32\mprdim.dll [97792] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- D:\Windows\System32\sens.dll [64512] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- D:\Windows\System32\ipnathlp.dll [359424] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- D:\Windows\System32\tapisrv.dll [316928] =>.Microsoft Corporation
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remote Desktop Session Host Server Remote C.) -- D:\Windows\System32\termsrv.dll [683520] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- D:\Windows\System32\wuaueng.dll [2610688] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- D:\Windows\System32\qmgr.dll [849920] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- D:\Windows\System32\shsvcs.dll [370688] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- D:\Windows\System32\iphlpsvc.dll [569344] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- D:\Windows\system32\seclogon.dll [30720] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- D:\Windows\System32\appinfo.dll [70144] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- D:\Windows\System32\iscsiexe.dll [156672] =>.Microsoft Corporation
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) -- D:\Windows\System32\mmcss.dll [67584] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- D:\Windows\System32\wbem\WMIsvc.dll [242688] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- D:\Windows\System32\sessenv.dll [121856] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- D:\Windows\System32\browser.dll [136704] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- D:\Windows\System32\eapsvc.dll [111104] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- D:\Windows\System32\schedsvc.dll [1110016] =>.Microsoft Corporation
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- D:\Windows\System32\kmsvc.dll [90624] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- D:\Windows\System32\wercplsupport.dll [84480] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- D:\Windows\System32\profsvc.dll [210432] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- D:\Windows\System32\themeservice.dll [44544] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- D:\Windows\System32\bdesvc.dll [100864] =>.Microsoft Corporation
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Software installation Service.) -- D:\Windows\System32\appmgmts.dll [193536] =>.Microsoft Corporation

---\\ Firewall Active Exception List (8) - 2s
O87 - FAEL: "{15AE90A5-8E3E-4754-8CCB-AF931959704C}" [In-None-P6-TRUE] .(...) -- D:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe (.not file.)
O87 - FAEL: "{9596F1C1-877C-4C60-B436-86C323EEF153}" [In-None-P17-TRUE] .(...) -- D:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe (.not file.)
O87 - FAEL: "{CCD96429-2078-44DB-BF8F-A3281D78B992}" [In-None-P6-TRUE] .(...) -- D:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe (.not file.)
O87 - FAEL: "{4CCA0FEF-E8D5-40C5-A7C7-B04306991EA1}" [In-None-P17-TRUE] .(...) -- D:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe (.not file.)
O87 - FAEL: "{CAA6A358-025B-4201-A296-66CD86F6320A}" [In-None-P6-TRUE] .(...) -- D:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe (.not file.)
O87 - FAEL: "{6DEE01E6-F1B1-46E7-9ACE-36CC844F1E52}" [In-None-P17-TRUE] .(...) -- D:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe (.not file.)
O87 - FAEL: "{07F3D87D-C239-4C29-8B06-79741D30DCEF}" [In-None-P17-TRUE] .(...) -- D:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.not file.)
O87 - FAEL: "{97F3B4E3-2292-4B1B-86AC-83C81FEE3DD1}" [In-None-P17-TRUE] .(...) -- D:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.not file.)

---\\ Additional Scan (O88) (32) - 0s
HKLM\Software\WOW6432Node\Microsoft\Active Setup\Installed Components\{2D46B6DC-2207-486B-B523-A557E6D54B47} =>.SUP.Various
HKLM\Software\WOW6432Node\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96} =>.SUP.Various
D:\Program Files (x86)\AnonymizerGadget =>.SUP.AnonymizerGadget
D:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnonymizerGadget =>.SUP.AnonymizerGadget
D:\Users\Isaie\AppData\Local\vghd =>.SUP.VirtualGirl
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\1916A2AF346D399F50313C393200F14140456616 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\2A83E9020591A55FC6DDAD3FB102794C52B24E70 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\2B84BFBB34EE2EF949FE1CBE30AA026416EB2216 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\305F8BD17AA2CBC483A4C41B19A39A0C75DA39D6 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\367D4B3B4FCBBC0B767B2EC0CDB2A36EAB71A4EB =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\3A850044D8A195CD401A680C012CB0A3B5F8DC08 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\40AA38731BD189F9CDB5B9DC35E2136F38777AF4 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\43D9BCB568E039D073A74A71D8511F7476089CC3 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\471C949A8143DB5AD5CDF1C972864A2504FA23C9 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\51C3247D60F356C7CA3BAF4C3F429DAC93EE7B74 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\5DE83EE82AC5090AEA9D6AC4E7A6E213F946E179 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\61793FCBFA4F9008309BBA5FF12D2CB29CD4151A =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\63FEAE960BAA91E343CE2BD8B71798C76BDB77D0 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\6431723036FD26DEA502792FA595922493030F97 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\80962AE4D6C5B442894E95A13E4A699E07D694CF =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\86E817C81A5CA672FE000F36F878C19518D6F844 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\8E5BD50D6AE686D65252F843A9D4B96D197730AB =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9845A431D51959CAF225322B4A4FE9F223CE6D15 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\B533345D06F64516403C00DA03187D3BFEF59156 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\B86E791620F759F17B8D25E38CA8BE32E7D5EAC2 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\C060ED44CBD881BD0EF86C0BA287DDCF8167478C =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\CEA586B2CE593EC7D939898337C57814708AB2BE =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\D018B62DC518907247DF50925BB09ACF4A5CB3AD =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\F8A54E03AADC5692B850496A4C4630FFEAA29D83 =>PUM.Misplaced.Certificate [Avast Software]
HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\FA6660A94AB45F6A88C0D7874D89A863D74DEE97 =>PUM.Misplaced.Certificate [Avast Software]

---\\ Summary of the elements found (5) - 0s
https://nicolascoolman.eu/2017/09/12/origine-lignes-orphelines/ =>.SUP.Orphan
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Various
https://www.anti-malware.top/2016/06/10/superfluous-anonymizergadget/ =>.SUP.AnonymizerGadget
https://www.nicolascoolman.com/fr/superfluous-virtualgirl =>.SUP.VirtualGirl
https://nicolascoolman.eu/2017/06/26/trojan-certlock/ =>PUM.Misplaced.Certificate

~ Unselected Options: O82,
~ End of the scan, 18087 items in 03mn19s (796)(0)

Publicité


Signaler le contenu de ce document

Publicité