cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2018.4.19.74 Par Nicolas Coolman (2018/04/19)
~ Démarré par administrateur (Administrator) (2018/04/19 15:03:34)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Legal
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Users\Administrateur\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\Administrateur\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Démarrage du système: Normal (Normal boot)
Windows 2012R2, 64-bit (Build 9600) =>.Microsoft Corporation

---\\ NAVIGATEURS INTERNET (1) - 0s
~ MSIE: Internet Explorer v11.0.9600.18978

---\\ INFORMATIONS SUR LES PRODUITS WINDOWS (8) - 0s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
~ Windows(R) Operating System, OEM_COA_NSLP channel
Windows ID Activation : OK
~ Windows Partial Key : 6MRWG
Windows License : OK
~ Windows Remaining Initializations Number : 1000
Windows Automatic Updates : OK

---\\ SURVEILLANCE LOGICIEL (1) - 1s
~ Adobe Reader XI (Surveillance)

---\\ INFORMATIONS SUR LE SYSTÈME (6) - 0s
~ Operating System: Intel64 Family 6 Model 79 Stepping 1, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 16644.212 MB (69% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 771 GB (80%) free of 953 GB : OK =>.Disk Space

---\\ MODE DE CONNEXION AU SYSTÈME (3) - 0s
~ Computer Name: AUMAREX-SRV
~ User Name: administrateur
~ Logged in as Administrator

---\\ ÉNUMÉRATION DES UNITÉS DE STOCKAGE (2) - 0s
~ Drive C: has 771 GB free of 953 GB (System)
~ Drive E: has 71 GB free of 953 GB

---\\ ÉTAT DU CENTRE DE SÉCURITÉ WINDOWS (8) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ RECHERCHE PARTICULIÈRE DE FICHIERS GÉNÉRIQUES (25) - 1s
[MD5.B3541A5A20C6264781909B1B7FE54836] - 09/02/2016 - (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\Explorer.exe [2757616] =>.Microsoft Windows®
[MD5.6C308D32AFA41D26CE2A0EA8F7B79565] - 21/11/2014 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe [54784] =>.Microsoft Corporation
[MD5.D9516405E05F24EDCD90B1988FAF3948] - 14/01/2017 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\System32\Wininit.exe [146944] =>.Microsoft Corporation
[MD5.287CB9A57C8BA180DDE548A4BB531D50] - 22/03/2018 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [3241472] =>.Microsoft Corporation
[MD5.4294D7AD504EA206A4A03DB29311B6C2] - 02/01/2018 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\Windows\System32\Winlogon.exe [571392] =>.Microsoft Corporation
[MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - 21/11/2014 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [447488] =>.Microsoft Corporation
[MD5.764E397D1664C3CE690AC35D3DD7085A] - 07/09/2017 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\System32\dnsapi.dll [656896] =>.Microsoft Corporation
[MD5.19992FFEC28B2CE8BDFCE1E7F51C4FAF] - 07/09/2017 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\Syswow64\dnsapi.dll [499200] =>.Microsoft Corporation
[MD5.E37F897ED7B5AFF79B1398258DB96BD9] - 24/12/2014 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [19456] =>.Microsoft Corporation
[MD5.B246BEE99740A2A357E21D863A18774D] - 10/01/2018 - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\Windows\System32\drivers\AFD.sys [559616] =>.Microsoft Corporation
[MD5.74B14192CF79A72F7536B27CB8814FBD] - 22/08/2013 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [26464] =>.Microsoft Windows®
[MD5.2FA6510E33F7DEFEC03658B74101A9B9] - 22/08/2013 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [88576] =>.Microsoft Corporation
[MD5.D61EDE3D49B04E703AEC3B111C763F42] - 05/12/2017 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [165376] =>.Microsoft Corporation
[MD5.D1049D4D1311D43F6FCF180CAA5BF78B] - 02/01/2018 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [138752] =>.Microsoft Corporation
[MD5.D4B7ED39C7900384D9E5C1283F1E7926] - 21/11/2014 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [76800] =>.Microsoft Corporation
[MD5.49EE0AE9E5B64FFBBD06D55C4984B598] - 04/11/2014 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [108544] =>.Microsoft Corporation
[MD5.B7342B3C58E91107F6E946A93D9D4EFD] - 21/11/2014 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [142848] =>.Microsoft Corporation
[MD5.CF49856813FFDF2EB251762BB8B675C8] - 10/02/2018 - (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\Windows\System32\drivers\MRxSmb.sys [401408] =>.Microsoft Corporation
[MD5.0FE750800DEEE91D22399D081371BA79] - 11/08/2017 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [281600] =>.Microsoft Corporation
[MD5.EE9B628D84DE372953A6D30AAB02DBD6] - 02/01/2018 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [2013016] =>.Microsoft Windows®
[MD5.57DCE4FB0467986AE78E1C6FC5240D32] - 11/08/2016 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\Parport.sys [96256] =>.Microsoft Corporation
[MD5.235624C147E3CB4C288D5D3D8E8D64A2] - 02/02/2016 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [112640] =>.Microsoft Corporation
[MD5.680C1DAE268B6FB67FA21B389A8B79EF] - 22/08/2013 - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) -- C:\Windows\System32\drivers\rdpdr.sys [195584] =>.Microsoft Corporation
[MD5.576FA545FAB846B06E79B324160DE25C] - 02/08/2017 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [107520] =>.Microsoft Corporation
[MD5.17F7B0F2298D97F4B6C7A69511033D3D] - 14/03/2016 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [316760] =>.Microsoft Windows®

---\\ LISTE DES SERVICES (Non Microsoft et non désactivés) (8) - 1s
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
O23 - Service: devolo Network Service (DevoloNetworkService) . (.devolo AG - devolo Network Service.) - C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe =>.devolo AG®
O23 - Service: Dr.Web Server (DrWebES) . (.Doctor Web, Ltd. - Dr.Web Enterprise Suite Server.) - C:\Program Files\DrWeb Server\bin\drwcsd.exe =>.Doctor Web Ltd.®
O23 - Service: HP AMS Storage Service (HpAmsStor) . (.Hewlett-Packard Company - HP Insight Storage Agents Service.) - C:\Program Files\Hewlett-Packard\AMS\service\HpAmsStor.exe {00AA57E2B6D40F26E072AF2BD65E2816FA} =>.Hewlett-Packard Company
O23 - Service: HP ProLiant Agentless Management Service (hpqams) . (.Hewlett Packard Enterprise Development LP - HPE ProLiant Agentless Management Service.) - C:\Program Files\Hewlett-Packard\AMS\service\hpqams.exe {00AA57E2B6D40F26E072AF2BD65E2816FA}
O23 - Service: ProLiant Monitor Service (ProLiantMonitor) . (.Hewlett Packard Enterprise - ProLiant Monitor Service.) - C:\Program Files\Hewlett-Packard\iLO 3\service\ProLiantMonitor.exe {3CF170877E235036200BECF49A6312AA}
O23 - Service: SyncoveryVSSService (SyncoveryVSSService) . (...) - C:\Program Files\Syncovery\SyncoveryVSS.exe =>.Super Flexible Software Ltd. & Co. KG®
O23 - Service: TeamViewer 10 (TeamViewer) . (.TeamViewer GmbH - TeamViewer 10.) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe =>.TeamViewer GmbH®

---\\ SERVICES NON MICROSOFT (SR=Démarré,SS=Stoppé) (8) - 2s
SR - Auto [18/12/2012] [ 65192] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
SR - Auto [03/03/2017] [ 3885592] devolo Network Service (DevoloNetworkService) . (.devolo AG.) - C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe =>.devolo AG®
SR - Auto [04/07/2015] [ 519944] Dr.Web Server (DrWebES) . (.Doctor Web, Ltd..) - C:\Program Files\DrWeb Server\bin\drwcsd.exe =>.Doctor Web Ltd.®
SR - Auto [14/09/2016] [ 16736] HP AMS Storage Service (HpAmsStor) . (.Hewlett-Packard Company.) - C:\Program Files\Hewlett-Packard\AMS\service\HpAmsStor.exe {00AA57E2B6D40F26E072AF2BD65E2816FA} =>.Hewlett-Packard Company
SR - Auto [14/09/2016] [ 640352] HP ProLiant Agentless Management Service (hpqams) . (.Hewlett Packard Enterprise Development LP.) - C:\Program Files\Hewlett-Packard\AMS\service\hpqams.exe {00AA57E2B6D40F26E072AF2BD65E2816FA}
SR - Auto [29/07/2016] [ 265360] ProLiant Monitor Service (ProLiantMonitor) . (.Hewlett Packard Enterprise.) - C:\Program Files\Hewlett-Packard\iLO 3\service\ProLiantMonitor.exe {3CF170877E235036200BECF49A6312AA}
SR - Auto [10/06/2016] [ 6186792] SyncoveryVSSService (SyncoveryVSSService) . (...) - C:\Program Files\Syncovery\SyncoveryVSS.exe =>.Super Flexible Software Ltd. & Co. KG®
SR - Auto [02/02/2018] [ 6630128] TeamViewer 10 (TeamViewer) . (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe =>.TeamViewer GmbH®

---\\ TÂCHES PLANIFIÉES EN AUTOMATIQUE (Registre) (76) - 0s
O38 - TASK: {0CB3FF1C-DB4D-4C0D-B1B3-59A29E45E352} [64Bits][\Microsoft\Windows\Time Synchronization\SynchronizeTime] - (.Microsoft Corporation - Outil de configuration du Gestionnaire de c.) -- C:\Windows\System32\sc.exe [68608] =>.Microsoft Corporation
O38 - TASK: {0DFCC7C7-6552-4E21-9D6E-DF15C7878179} [64Bits][\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization] - (.Microsoft Corp. - Module de défragmenteur de disque.) -- C:\Windows\system32\defrag.exe [184832] =>.Microsoft Corp.
O38 - TASK: {0F5BED64-647C-4BD2-83FC-9100D8F69B2D} [64Bits][\Microsoft\Windows\termsrv\licensing\TlsWarning] - (.Microsoft Corporation - Rappel info-bulle des services Bureau à dis.) -- C:\Windows\system32\tlsbln.exe [45568] =>.Microsoft Corporation
O38 - TASK: {1A4415FD-C991-443E-9B98-388878091B1D} [64Bits][\ShadowCopyVolume{5f811a67-6291-49d4-b9dc-e28960f6241d}] - (.Microsoft Corporation - Interface en ligne de commande du service d.) -- C:\Windows\System32\vssadmin.exe [146432] =>.Microsoft Corporation
O38 - TASK: {22F8933B-6077-471D-A4C3-56C7647164AD} [64Bits][\Microsoft\Windows\Server Manager\CleanupOldPerfLogs] - (.Microsoft Corporation - Microsoft ® Console Based Script Host.) -- C:\Windows\System32\cscript.exe [158720] =>.Microsoft Corporation
O38 - TASK: {24211666-53D8-4C75-8E64-B1D035C0ED48} [64Bits][\Microsoft\Windows\WindowsUpdate\Scheduled Start] - (.Microsoft Corporation - Outil de configuration du Gestionnaire de c.) -- C:\Windows\System32\sc.exe [68608] =>.Microsoft Corporation
O38 - TASK: {2C91952C-E506-4218-A8AC-124F53A976AB} [64Bits][\Microsoft\Windows\Customer Experience Improvement Program\Uploader] - (.Microsoft Corporation - Consolidateur SQM Windows.) -- C:\Windows\system32\WSqmCons.exe [382976] =>.Microsoft Corporation
O38 - TASK: {356E6350-133F-4D40-B8B2-E18D647068D5} [64Bits][\Microsoft\Windows\MUI\Lpksetup] - (.Microsoft Corporation - Programme d’installation des packs de langu.) -- C:\Windows\System32\lpksetup.exe [784384] =>.Microsoft Corporation
O38 - TASK: {42FE6C1F-4F0D-41B5-8FC4-C99D15C86FA2} [64Bits][\Microsoft\Windows\Software Inventory Logging\Configuration] - (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\cmd.exe [357376] =>.Microsoft Corporation
O38 - TASK: {519D6FFC-0DC4-4C63-96EE-4792A9CA9BA6} [64Bits][\Microsoft\Windows\Software Inventory Logging\Collection] - (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\cmd.exe [357376] =>.Microsoft Corporation
O38 - TASK: {63993849-B6EA-4EDA-B40A-CB162D15F12C} [64Bits][\Microsoft\Windows\Windows Server Essentials\Macintosh Status Report] - (.Microsoft Corporation - Windows Server RunTask.) -- C:\Windows\System32\Essentials\RunTask.exe [11264] =>.Microsoft Corporation
O38 - TASK: {651FF2A7-84D4-4AE6-9231-BB0411D3A64F} [64Bits][\Microsoft\Windows\Customer Experience Improvement Program\Server\ServerCeipAssistant] - (.Microsoft Corporation - Programme d’amélioration de l’expérience ut.) -- C:\Windows\system32\ceipdata.exe [235520] =>.Microsoft Corporation
O38 - TASK: {70030469-0BE0-4915-9AE0-1F46FF7CDCC8} [64Bits][\Microsoft\Windows\Windows Server Essentials\Consistency Check] - (.Microsoft Corporation - Windows Server RunTask.) -- C:\Windows\System32\Essentials\RunTask.exe [11264] =>.Microsoft Corporation
O38 - TASK: {7413B569-8BD6-4D45-AE89-D983968361DD} [64Bits][\Microsoft\Windows\Windows Error Reporting\QueueReporting] - (.Microsoft Corporation - Windows Problem Reporting.) -- C:\Windows\System32\wermgr.exe [140016] =>.Microsoft Corporation
O38 - TASK: {7457D1F9-7782-42BA-B928-02E8FF94F7F8} [64Bits][\Microsoft\Windows\MUI\LPRemove] - (.Microsoft Corporation - MUI Language pack cleanup.) -- C:\Windows\system32\lpremove.exe [67072] =>.Microsoft Corporation
O38 - TASK: {787E2442-1350-4D4B-B3DF-F73EDF626879} [64Bits][\Microsoft\Windows\PLA\Server Manager Performance Monitor] - (.Microsoft Corporation - Journaux & alertes de performance.) -- C:\Windows\System32\pla.dll [1526784] =>.Microsoft Corporation
O38 - TASK: {88E2FD92-1E16-4994-AFC8-289E75376D17} [64Bits][\Microsoft\Windows\UPnP\UPnPHostConfig] - (.Microsoft Corporation - Outil de configuration du Gestionnaire de c.) -- C:\Windows\System32\sc.exe [68608] =>.Microsoft Corporation
O38 - TASK: {8C52712C-6891-4718-AB16-6C8BF4631F26} [64Bits][\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network] - (.Microsoft Corporation - Outil de configuration du Gestionnaire de c.) -- C:\Windows\System32\sc.exe [68608] =>.Microsoft Corporation
O38 - TASK: {8CCEE9FB-20E3-4E78-B4B4-E812FAEA847D} [64Bits][\Microsoft\Windows\ApplicationData\CleanupTemporaryState] - (.Microsoft Corporation - Windows Application Data API Server.) -- C:\Windows\System32\Windows.Storage.ApplicationData.dll [214392] =>.Microsoft Corporation
O38 - TASK: {94A2F226-78C8-46B8-8527-0F902542A370} [64Bits][\Microsoft\Windows\Windows Server Essentials\Save Customer Experience Improvement Program Data] - (.Microsoft Corporation - Windows Server RunTask.) -- C:\Windows\System32\Essentials\RunTask.exe [11264] =>.Microsoft Corporation
O38 - TASK: {9536335E-476B-42F7-8624-2308CA0F222B} [64Bits][\Microsoft\Windows\Server Manager\ServerManager] - (.Microsoft Corporation - Server Manager Launcher.) -- C:\Windows\system32\ServerManagerLauncher.exe [94208] =>.Microsoft Corporation
O38 - TASK: {96D75494-96A0-4ED4-A1B7-4E4171C92866} [64Bits][\Microsoft\Windows\Defrag\ScheduledDefrag] - (.Microsoft Corp. - Module de défragmenteur de disque.) -- C:\Windows\system32\defrag.exe [184832] =>.Microsoft Corp.
O38 - TASK: {997514A9-18E8-4C71-A9CD-1D360C83A600} [64Bits][\Microsoft\Windows\Time Zone\SynchronizeTimeZone] - (.Microsoft Corporation - TimeZone Sync Task.) -- C:\Windows\system32\tzsync.exe [63488] =>.Microsoft Corporation
O38 - TASK: {9F708456-2B50-4442-B20A-C3B3F4EBA733} [64Bits][\Microsoft\Windows\SpacePort\SpaceAgentTask] - (.Microsoft Corporation - Paramètres des espaces de stockage.) -- C:\Windows\system32\SpaceAgent.exe [104960] =>.Microsoft Corporation
O38 - TASK: {A528142F-413E-4BF1-85C6-38BD737BDEDF} [64Bits][\Microsoft\Windows\Autochk\Proxy] - (.Microsoft Corporation - DLL de proxy Autochk.) -- C:\Windows\System32\acproxy.dll [12288] =>.Microsoft Corporation
O38 - TASK: {A845B103-DC90-4A70-863B-1BCB23FDD357} [64Bits][\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers] - (.Microsoft Corporation - Module d’installation de pilotes.) -- C:\Windows\System32\drvinst.exe [112640] =>.Microsoft Corporation
O38 - TASK: {ACFDA1A0-FFB6-4E34-92A9-F4331BEFB4C5} [64Bits][\Microsoft\Windows\Windows Server Essentials\BPA Scheduled Scan] - (.Microsoft Corporation - Windows PowerShell.) -- C:\Windows\System32\windowspowershell\v1.0\powershell.exe [478720] =>.Microsoft Corporation
O38 - TASK: {B08DEEC9-2178-4D5C-A075-F451733A694E} [64Bits][\Microsoft\Windows\Windows Server Essentials\Alert Evaluations] - (.Microsoft Corporation - Windows Server RunTask.) -- C:\Windows\System32\Essentials\RunTask.exe [11264] =>.Microsoft Corporation
O38 - TASK: {B2492D58-95FB-40DF-AB17-5F1915B3D7E5} [64Bits][\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange] - (.Microsoft Corporation - Moteur de filtrage de base.) -- C:\Windows\System32\bfe.dll [845312] =>.Microsoft Corporation
O38 - TASK: {BB5F850D-91BE-42A2-A0B7-D5274CB74FA8} [64Bits][\Microsoft\Windows\Windows Server Essentials\Backup Cleanup] - (.Microsoft Corporation - Windows Server RunTask.) -- C:\Windows\System32\Essentials\RunTask.exe [11264] =>.Microsoft Corporation
O38 - TASK: {C65A1E30-25AB-4B05-9F28-A654E3B5CD10} [64Bits][\Microsoft\Windows\MUI\Mcbuilder] - (.Microsoft Corporation - Resource cache builder tool.) -- C:\Windows\System32\mcbuilder.exe [281088] =>.Microsoft Corporation
O38 - TASK: {C7B721B2-E18E-45EC-87B6-8EBFAA63D852} [64Bits][\Microsoft\Windows\AppID\PolicyConverter] - (.Microsoft Corporation - AppID Policy Converter Task.) -- C:\Windows\system32\appidpolicyconverter.exe [197632] =>.Microsoft Corporation
O38 - TASK: {CB1A8D23-F86B-412D-9283-C424235300FB} [64Bits][\Microsoft\Windows\Application Experience\ProgramDataUpdater] - (.Microsoft Corporation - Mise à jour des données de compatibilité de.) -- C:\Windows\system32\invagent.dll [705024] =>.Microsoft Corporation
O38 - TASK: {D807998D-DBD2-44B2-8468-02A6CF33E431} [64Bits][\OfficeSoftwareProtectionPlatform\SvcRestartTask] - (.Microsoft Corporation - Outil de configuration du Gestionnaire de c.) -- C:\Windows\System32\sc.exe [68608] =>.Microsoft Corporation
O38 - TASK: {D913775E-E6E6-4E00-BC89-BDAF543BB03E} [64Bits][\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck] - (.Microsoft Corporation - AppID Certificate Store Verification Task.) -- C:\Windows\system32\appidcertstorecheck.exe [17920] =>.Microsoft Corporation
O38 - TASK: {DA23AE6C-A0E8-496C-9401-25B38C8BD4B2} [64Bits][\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup] - (.Microsoft Corporation - DLL du client de déploiement d’AppX.) -- C:\Windows\System32\AppxDeploymentClient.dll [268800] =>.Microsoft Corporation
O38 - TASK: {F00FD1E5-E940-487A-BADE-23E9C5C4D9C7} [64Bits][\Microsoft\Windows\WS\License Validation] - (.Microsoft Corporation - Client de gestion de licences du Windows St.) -- C:\Windows\System32\WSClient.dll [206336] =>.Microsoft Corporation
O38 - TASK: {FBCC008D-BA20-477D-BD4F-1B6962E60989} [64Bits][\Microsoft\Windows\Customer Experience Improvement Program\Consolidator] - (.Microsoft Corporation - Consolidateur SQM Windows.) -- C:\Windows\System32\wsqmcons.exe [382976] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - (.Microsoft Corporation.) -- C:\Windows\System32\sc.exe [w32time task_ed] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization - (.Microsoft Corp..) -- C:\Windows\system32\defrag.exe [-c -h -g -#] =>.Microsoft Corp.
C:\Windows\System32\Tasks\Microsoft\Windows\termsrv\licensing\TlsWarning - (.Microsoft Corporation.) -- C:\Windows\system32\tlsbln.exe [] =>.Microsoft Corporation
C:\Windows\System32\Tasks\ShadowCopyVolume{5f811a67-6291-49d4-b9dc-e28960f6241d} - (.Microsoft Corporation.) -- C:\Windows\System32\vssadmin.exe [Create Shadow] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Server Manager\CleanupOldPerfLogs - (.Microsoft Corporation.) -- C:\Windows\System32\cscript.exe [/B] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - (.Microsoft Corporation.) -- C:\Windows\System32\sc.exe [wuauserv] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader - (.Microsoft Corporation.) -- C:\Windows\system32\WSqmCons.exe [-u] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\MUI\Lpksetup - (.Microsoft Corporation.) -- C:\Windows\System32\lpksetup.exe [-v] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Software Inventory Logging\Configuration - (.Microsoft Corporation.) -- C:\Windows\System32\cmd.exe [/c %systemroot%\system32\silcollector.cmd] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Software Inventory Logging\Collection - (.Microsoft Corporation.) -- C:\Windows\System32\cmd.exe [/c %systemroot%\system32\silcollector.cmd] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Server Essentials\Macintosh Status Report - (.Microsoft Corporation.) -- C:\Windows\System32\Essentials\RunTask.exe [/asm:"C:\Program Files\Windows Server\Bin\WebApps\MacWebService\bin\Microsoft.WindowsServerSolutions] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Server\ServerCeipAssistant - (.Microsoft Corporation.) -- C:\Windows\system32\ceipdata.exe [-id 3] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Server Essentials\Consistency Check - (.Microsoft Corporation.) -- C:\Windows\System32\Essentials\RunTask.exe [/asm:"C:\Windows\System32\Essentials\BackupServerProvider.dll] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - (.Microsoft Corporation.) -- C:\Windows\System32\wermgr.exe [-queuereporting] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\MUI\LPRemove - (.Microsoft Corporation.) -- C:\Windows\system32\lpremove.exe [] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\PLA\Server Manager Performance Monitor - (.Microsoft Corporation.) -- C:\Windows\System32\pla.dll [C:\Windows\System32\pla.dll] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig - (.Microsoft Corporation.) -- C:\Windows\System32\sc.exe [config upnphost start= auto] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network - (.Microsoft Corporation.) -- C:\Windows\System32\sc.exe [wuauserv] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - (.Microsoft Corporation.) -- C:\Windows\System32\Windows.Storage.ApplicationData.dll [Windows.Storage.ApplicationData.dll] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Server Essentials\Save Customer Experience Improvement Program Data - (.Microsoft Corporation.) -- C:\Windows\System32\Essentials\RunTask.exe [/asm:"C:\Windows\Microsoft.Net\assembly\GAC_MSIL\SqmProviderUtilities\v4.0_6.3.0.0__31bf3856ad364e35] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Server Manager\ServerManager - (.Microsoft Corporation.) -- C:\Windows\system32\ServerManagerLauncher.exe [] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Defrag\ScheduledDefrag - (.Microsoft Corp..) -- C:\Windows\system32\defrag.exe [-c -h -k -g -$] =>.Microsoft Corp.
C:\Windows\System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - (.Microsoft Corporation.) -- C:\Windows\system32\tzsync.exe [] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - (.Microsoft Corporation.) -- C:\Windows\system32\SpaceAgent.exe [] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Autochk\Proxy - (.Microsoft Corporation.) -- C:\Windows\System32\acproxy.dll [acproxy.dll] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - (.Microsoft Corporation.) -- C:\Windows\System32\drvinst.exe [6] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Server Essentials\BPA Scheduled Scan - (.Microsoft Corporation.) -- C:\Windows\System32\windowspowershell\v1.0\powershell.exe [-EncodedCommand SQBuAHYAbwBrAGUALQBXAHMAcwBCAHAAYQ] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Server Essentials\Alert Evaluations - (.Microsoft Corporation.) -- C:\Windows\System32\Essentials\RunTask.exe [/asm:"C:\Windows\Microsoft.Net\assembly\GAC_MSIL\AlertFramework\v4.0_6.3.0.0__31bf3856ad364e35\Alert] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - (.Microsoft Corporation.) -- C:\Windows\System32\bfe.dll [bfe.dll] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Server Essentials\Backup Cleanup - (.Microsoft Corporation.) -- C:\Windows\System32\Essentials\RunTask.exe [/asm:"C:\Windows\System32\Essentials\BackupServerProvider.dll] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\MUI\Mcbuilder - (.Microsoft Corporation.) -- C:\Windows\System32\mcbuilder.exe [] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\AppID\PolicyConverter - (.Microsoft Corporation.) -- C:\Windows\system32\appidpolicyconverter.exe [] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - (.Microsoft Corporation.) -- C:\Windows\system32\invagent.dll [C:\Windows\system32\invagent.dll] =>.Microsoft Corporation
C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask - (.Microsoft Corporation.) -- C:\Windows\System32\sc.exe [osppsvc] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - (.Microsoft Corporation.) -- C:\Windows\system32\appidcertstorecheck.exe [] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - (.Microsoft Corporation.) -- C:\Windows\System32\AppxDeploymentClient.dll [C:\Windows\System32\AppxDeploymentClient.dll] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\WS\License Validation - (.Microsoft Corporation.) -- C:\Windows\System32\WSClient.dll [WSClient.dll] =>.Microsoft Corporation
C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - (.Microsoft Corporation.) -- C:\Windows\System32\wsqmcons.exe [] =>.Microsoft Corporation

---\\ APPLICATIONS LANCÉES AU DÉMARRAGE DU SYSTÈME (2) - 1s
O4 - HKCU\..\Run: [Syncovery Background Scheduler] . (...) -- C:\Program Files\Syncovery\SyncoveryService.exe =>.Super Flexible Software Ltd. & Co. KG®
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems, Incorporated®

---\\ PROCESSUS LANCÉS (18) - 3s
[MD5.3927397AC60D943DAF8808AFFED582B7] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65192] [PID.1612] =>.Adobe Systems, Incorporated®
[MD5.8761D5A2C223B4D1AB6B474196EA969C] - (.devolo AG - devolo Network Service.) -- C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3885592] [PID.1764] =>.devolo AG®
[MD5.B0428CD892DF804E99DFB4212F965EC1] - (.Doctor Web, Ltd. - Dr.Web Enterprise Suite Server.) -- C:\Program Files\DrWeb Server\bin\drwcsd.exe [519944] [PID.1856] =>.Doctor Web Ltd.®
[MD5.606616D575B5F6FF5D866645AF24BF1A] - (.Hewlett-Packard Company - HP Insight Storage Agents Service.) -- C:\Program Files\Hewlett-Packard\AMS\service\HpAmsStor.exe [16736] [PID.1072] {00AA57E2B6D40F26E072AF2BD65E2816FA} =>.Hewlett-Packard Company
[MD5.49FB3FF78B00C12B29BD29B2BE53C544] - (.Hewlett Packard Enterprise - ProLiant Monitor Service.) -- C:\Program Files\Hewlett-Packard\iLO 3\service\ProLiantMonitor.exe [265360] [PID.2108] {3CF170877E235036200BECF49A6312AA}
[MD5.08D08222F1B2F20018E3C16258AB8A90] - (...) -- C:\Program Files\Syncovery\SyncoveryVSS.exe [6186792] [PID.2316] =>.Super Flexible Software Ltd. & Co. KG®
[MD5.8370081A7DEC79C48EFC1FE412442461] - (.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6630128] [PID.2600] =>.TeamViewer GmbH®
[MD5.14A5DCFABBBE8900229939F7F216F27F] - (.Hewlett Packard Enterprise Development LP - HPE ProLiant Agentless Management Service.) -- C:\Program Files\Hewlett-Packard\AMS\service\hpqams.exe [640352] [PID.2232] {00AA57E2B6D40F26E072AF2BD65E2816FA}
[MD5.2FD1EC27A63FCE33C8B63DF148B6B600] - (.TeamViewer GmbH - TeamViewer 10.) -- c:\program files (x86)\teamviewer\TeamViewer.exe [16878320] [PID.5976] =>.TeamViewer GmbH®
[MD5.A53B258DEA51AD8E4B2E0FC13C4AD8A3] - (.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\tv_w32.exe [231152] [PID.964] =>.TeamViewer GmbH®
[MD5.D56F70A14D29445B5CFFF6268627F832] - (.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\tv_x64.exe [264432] [PID.4232] =>.TeamViewer GmbH®
[MD5.D2CC1C6B75E95E076BD76482EBB59700] - (...) -- C:\Program Files\Syncovery\SyncoveryService.exe [31220520] [PID.7160] =>.Super Flexible Software Ltd. & Co. KG®
[MD5.2FD1EC27A63FCE33C8B63DF148B6B600] - (.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\TeamViewer.exe [16878320] [PID.8748] =>.TeamViewer GmbH®
[MD5.A53B258DEA51AD8E4B2E0FC13C4AD8A3] - (.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\tv_w32.exe [231152] [PID.7352] =>.TeamViewer GmbH®
[MD5.D56F70A14D29445B5CFFF6268627F832] - (.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\tv_x64.exe [264432] [PID.5720] =>.TeamViewer GmbH®
[MD5.3CB07566302BCEEB898DE270A0BEC175] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352] [PID.7532] =>.Adobe Systems, Incorporated®
[MD5.D300DA738864046F41A5BF5103903BD3] - (.TeamViewer GmbH - TeamViewer 10.) -- c:\program files (x86)\teamviewer\TeamViewer_Desktop.exe [5509360] [PID.8076] =>.TeamViewer GmbH®
[MD5.2C34866C62C0C0B3C65672090A5BEDFB] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Administrateur\AppData\Roaming\ZHP\ZHPDiag3.exe [3070848] [PID.1968] =>.Nicolas Coolman

---\\ INTERNET EXPLORER,Démarrage,Recherche,URLSearchHook (17) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com =>.Bing.com
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = res://iesetup.dll/softadmin.htm
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.9600.18817 (winblue_ltsb.170907-0600)) -- C:\Windows\System32\ieframe.dll =>.Microsoft Corporation
R4 - HKLM\Software\WOW6432Node\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 0

---\\ INTERNET EXPLORER, Site de confiance et site sensible (2) - 0s
~ Microsoft Internet Explorer Restricted Site(s) Domains: 0(Good) / 0(Bad)
~ Microsoft Internet Explorer Restricted Site(s) EscDomains: 0(Good) / 0(Bad)

---\\ INTERNET EXPLORER,Proxy Management (5) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\\ INTERNET EXPLORER,IniFiles, Autoloading Programs (3) - 0s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation

---\\ ÉTUDE DU FICHIER HOSTS (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)

---\\ BROWSER HELPER OBJECT DE NAVIGATEUR (BHO) (2) - 0s
O2 - BHO: Groove GFS Browser Helper [64Bits] - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL =>.Microsoft Corporation®

---\\ RACCOURCIS GLOBAL STARTUP (77) - 3s
O4 - GS\Desktop [Admin-31aumarex]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Administrateur\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Admin-31aumarex]: Control Panel.lnk . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) C:\Windows\system32\rundll32.exe shell32.dll,Control_RunDLL =>..Microsoft Corporation
O4 - GS\Quicklaunch [Admin-31aumarex]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Admin-31aumarex]: Server Manager.lnk . (.Microsoft Corporation - Server Manager.) C:\Windows\system32\ServerManager.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Admin-31aumarex]: Dashboard.lnk . (.Microsoft Corporation - Dashboard.) C:\Windows\system32\Essentials\Dashboard.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Admin-31aumarex]: Windows PowerShell.lnk . (.Microsoft Corporation - Windows PowerShell.) C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe =>.Microsoft Corporation
O4 - GS\Programs [Admin-31aumarex]: Documents.lnk . (...) C:\Users\Administrateur\Documents
O4 - GS\Programs [Admin-31aumarex]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [Admin-31aumarex]: Pictures.lnk . (...) C:\Users\Administrateur\Pictures =>.Microsoft Corporation
O4 - GS\Desktop [Administrateur]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Administrateur\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Administrateur]: Control Panel.lnk . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) C:\Windows\system32\rundll32.exe shell32.dll,Control_RunDLL =>..Microsoft Corporation
O4 - GS\Quicklaunch [Administrateur]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Administrateur]: Server Manager.lnk . (.Microsoft Corporation - Server Manager.) C:\Windows\system32\ServerManager.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrateur]: Dashboard.lnk . (.Microsoft Corporation - Dashboard.) C:\Windows\system32\Essentials\Dashboard.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrateur]: Windows PowerShell.lnk . (.Microsoft Corporation - Windows PowerShell.) C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe =>.Microsoft Corporation
O4 - GS\Programs [Administrateur]: Documents.lnk . (...) C:\Users\Administrateur\Documents
O4 - GS\Programs [Administrateur]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [Administrateur]: Pictures.lnk . (...) C:\Users\Administrateur\Pictures =>.Microsoft Corporation
O4 - GS\Desktop [ChristopheAuger]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Administrateur\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [ChristopheAuger]: Control Panel.lnk . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) C:\Windows\system32\rundll32.exe shell32.dll,Control_RunDLL =>..Microsoft Corporation
O4 - GS\Quicklaunch [ChristopheAuger]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [ChristopheAuger]: Server Manager.lnk . (.Microsoft Corporation - Server Manager.) C:\Windows\system32\ServerManager.exe =>.Microsoft Corporation
O4 - GS\TaskBar [ChristopheAuger]: Dashboard.lnk . (.Microsoft Corporation - Dashboard.) C:\Windows\system32\Essentials\Dashboard.exe =>.Microsoft Corporation
O4 - GS\TaskBar [ChristopheAuger]: Windows PowerShell.lnk . (.Microsoft Corporation - Windows PowerShell.) C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe =>.Microsoft Corporation
O4 - GS\Programs [ChristopheAuger]: Documents.lnk . (...) C:\Users\Administrateur\Documents
O4 - GS\Programs [ChristopheAuger]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [ChristopheAuger]: Pictures.lnk . (...) C:\Users\Administrateur\Pictures =>.Microsoft Corporation
O4 - GS\Desktop [JeanJacquesDeschamps]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Administrateur\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [JeanJacquesDeschamps]: Control Panel.lnk . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) C:\Windows\system32\rundll32.exe shell32.dll,Control_RunDLL =>..Microsoft Corporation
O4 - GS\Quicklaunch [JeanJacquesDeschamps]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [JeanJacquesDeschamps]: Server Manager.lnk . (.Microsoft Corporation - Server Manager.) C:\Windows\system32\ServerManager.exe =>.Microsoft Corporation
O4 - GS\TaskBar [JeanJacquesDeschamps]: Dashboard.lnk . (.Microsoft Corporation - Dashboard.) C:\Windows\system32\Essentials\Dashboard.exe =>.Microsoft Corporation
O4 - GS\TaskBar [JeanJacquesDeschamps]: Windows PowerShell.lnk . (.Microsoft Corporation - Windows PowerShell.) C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe =>.Microsoft Corporation
O4 - GS\Programs [JeanJacquesDeschamps]: Documents.lnk . (...) C:\Users\Administrateur\Documents
O4 - GS\Programs [JeanJacquesDeschamps]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [JeanJacquesDeschamps]: Pictures.lnk . (...) C:\Users\Administrateur\Pictures =>.Microsoft Corporation
O4 - GS\Desktop [krbtgt]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Administrateur\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [krbtgt]: Control Panel.lnk . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) C:\Windows\system32\rundll32.exe shell32.dll,Control_RunDLL =>..Microsoft Corporation
O4 - GS\Quicklaunch [krbtgt]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [krbtgt]: Server Manager.lnk . (.Microsoft Corporation - Server Manager.) C:\Windows\system32\ServerManager.exe =>.Microsoft Corporation
O4 - GS\TaskBar [krbtgt]: Dashboard.lnk . (.Microsoft Corporation - Dashboard.) C:\Windows\system32\Essentials\Dashboard.exe =>.Microsoft Corporation
O4 - GS\TaskBar [krbtgt]: Windows PowerShell.lnk . (.Microsoft Corporation - Windows PowerShell.) C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe =>.Microsoft Corporation
O4 - GS\Programs [krbtgt]: Documents.lnk . (...) C:\Users\Administrateur\Documents
O4 - GS\Programs [krbtgt]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [krbtgt]: Pictures.lnk . (...) C:\Users\Administrateur\Pictures =>.Microsoft Corporation
O4 - GS\Desktop [Mickael Tevenot]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Administrateur\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Mickael Tevenot]: Control Panel.lnk . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) C:\Windows\system32\rundll32.exe shell32.dll,Control_RunDLL =>..Microsoft Corporation
O4 - GS\Quicklaunch [Mickael Tevenot]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Mickael Tevenot]: Server Manager.lnk . (.Microsoft Corporation - Server Manager.) C:\Windows\system32\ServerManager.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Mickael Tevenot]: Dashboard.lnk . (.Microsoft Corporation - Dashboard.) C:\Windows\system32\Essentials\Dashboard.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Mickael Tevenot]: Windows PowerShell.lnk . (.Microsoft Corporation - Windows PowerShell.) C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe =>.Microsoft Corporation
O4 - GS\Programs [Mickael Tevenot]: Documents.lnk . (...) C:\Users\Administrateur\Documents
O4 - GS\Programs [Mickael Tevenot]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [Mickael Tevenot]: Pictures.lnk . (...) C:\Users\Administrateur\Pictures =>.Microsoft Corporation
O4 - GS\Desktop [Valerie]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Administrateur\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Valerie]: Control Panel.lnk . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) C:\Windows\system32\rundll32.exe shell32.dll,Control_RunDLL =>..Microsoft Corporation
O4 - GS\Quicklaunch [Valerie]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Valerie]: Server Manager.lnk . (.Microsoft Corporation - Server Manager.) C:\Windows\system32\ServerManager.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Valerie]: Dashboard.lnk . (.Microsoft Corporation - Dashboard.) C:\Windows\system32\Essentials\Dashboard.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Valerie]: Windows PowerShell.lnk . (.Microsoft Corporation - Windows PowerShell.) C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe =>.Microsoft Corporation
O4 - GS\Programs [Valerie]: Documents.lnk . (...) C:\Users\Administrateur\Documents
O4 - GS\Programs [Valerie]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [Valerie]: Pictures.lnk . (...) C:\Users\Administrateur\Pictures =>.Microsoft Corporation
O4 - GS\CommonDesktop [Public]: Adobe Reader XI.lnk . (.Adobe Systems Incorporated - Adobe Reader.) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe =>.Adobe Systems, Incorporated®
O4 - GS\Programs [Public]: Documents.lnk . (...) C:\Users\Administrateur\Documents
O4 - GS\Programs [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [Public]: Pictures.lnk . (...) C:\Users\Administrateur\Pictures =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Bloc-notes.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Calculatrice de Windows.) C:\Windows\system32\calc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\Windows\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Connexion Bureau à distance.) C:\Windows\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Enregistreur d’actions.) C:\Windows\system32\psr.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Application Windows Wordpad.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Server Backup.lnk . (...) C:\Windows\system32\wbadmin.msc
O4 - GS\ProgramsCommon [Public]: Adobe Reader XI.lnk . (...) C:\Windows\Installer\{AC76BA86-7AD7-1036-7B44-AB0000000001}\SC_Reader.ico =>.Adobe Inc.
O4 - GS\ProgramsCommon [Public]: Search.lnk . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) C:\Windows\system32\rundll32.exe -sta {C90FB8CA-3295-4462-A721-2935E83694BA} =>..Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: TeamViewer 10 Host.lnk . (.TeamViewer GmbH - TeamViewer 10.) C:\Program Files (x86)\TeamViewer\TeamViewer.exe =>.TeamViewer GmbH®

---\\ MODIFICATION DOMAINE/ADRESSES (DNS) (3) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = AUMAREX.local =>.Local Domain
O17 - HKLM\System\CCS\Services\Tcpip\..\{4A7D0D4B-4800-4AB2-8295-30280C577471}: NameServer = 194.2.0.20,194.2.0.50 =>.Oleane DNS
O17 - HKLM\System\CCS\Services\Tcpip\..\{E251933F-23B6-4269-B4B6-B08C008A2EBB}: NameServer = 192.168.1.80,86.10.246.2 =>.Private IP

---\\ PROTOCOLE ADDITIONNEL (16) - 0s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Filter: text/xml [64Bits] - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL =>.Microsoft Corporation®

---\\ REGISTRE AppInit_DLLs et Winlogon Notify (1) - 0s
O20 - Winlogon : UserInit . (.Microsoft Corporation - Application d’ouverture de session Userinit.) - C:\Windows\system32\userinit.exe =>.Microsoft Corporation

---\\ COMPOSANTS ACTIVESETUP INSTALLÉS (ASIC) (7) - 1s
O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (...) -- C:\Program Files\Windows Mail\WinMail.exe (.not file.) =>.SUP.Various
O40 - ASIC: Enable TLS1.1 and 1.2 [64Bits] - {66C64F22-FC60-4E6C-A6B5-F0D580E680CE} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: Disable SSL3 [64Bits] - {7D715857-A67C-4C2F-A929-038448584D63} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll =>.Microsoft Corporation®
O40 - ASIC: Applying Enhanced Security Configuration [64Bits] - {A509B1A7-37EF-4b3f-8CFC-4F3A74704073} . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe =>.Microsoft Corporation
O40 - ASIC: Applying Enhanced Security Configuration [64Bits] - {A509B1A8-37EF-4b3f-8CFC-4F3A74704073} . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe =>.Microsoft Corporation

---\\ LOGICIELS INSTALLÉS (14) - 8s
O42 - Logiciel: Adobe Reader XI (11.0.02) - Français - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1036-7B44-AB0000000001} =>.Adobe Systems Incorporated
O42 - Logiciel: devolo Cockpit - (.devolo AG.) [HKLM][64Bits] -- dlancockpit =>.devolo AG®
O42 - Logiciel: Dr.Web Enterprise Browser Plugins x64 - (.Doctor Web, Ltd.) [HKLM][64Bits] -- {75C601D2-187C-4A9E-98C4-5726B29B897E}
O42 - Logiciel: Dr.Web Enterprise Browser Plugins x86 - (.Doctor Web, Ltd.) [HKLM][64Bits] -- {42953C00-6310-42CC-8343-81394C12009F}
O42 - Logiciel: Dr.Web Server (x64) - (..) [HKLM][64Bits] -- {1EA1A3BD-F1A6-4A2A-B2B8-55731579969C}
O42 - Logiciel: HPE ProLiant Agentless Management Service - (.Hewlett Packard Enterprise Development LP.) [HKLM][64Bits] -- {E9B2359A-D58A-45BE-B5E3-7BF537984B96}
O42 - Logiciel: HPE ProLiant Agentless Management Service - (.Hewlett Packard Enterprise Development LP.) [HKLM][64Bits] -- HP-{EDE88CBB-3384-4DDA-B23B-7E54A3F4344F}
O42 - Logiciel: iLO 3/4 Core Driver (X64) - (.Hewlett Packard Enterprise.) [HKLM][64Bits] -- {1765AAA8-F827-4350-AA97-F788DF14EC5E}
O42 - Logiciel: iLO 3/4 Management Controller Driver Package - (.Hewlett Packard Enterprise.) [HKLM][64Bits] -- HP-{15EC9FFF-3B11-4F2A-92F8-F63F33F64B31}
O42 - Logiciel: Matrox Graphics Software (remove only) - (.Matrox Graphics Inc..) [HKLM][64Bits] -- Matrox Vista Driver Uninstaller {05260217E8775D6983CB65D2F8312AB8} =>.Matrox Graphics Inc.
O42 - Logiciel: MergeModule2012 - (.Microsoft.) [HKLM][64Bits] -- {3E0D2B4B-CA5F-40D6-B0AE-648008897125} =>.Microsoft
O42 - Logiciel: ProLiant Monitor Service (X64) - (.Hewlett Packard Enterprise.) [HKLM][64Bits] -- {24852FC1-8C73-4066-AB2C-88EBEBAF9309}
O42 - Logiciel: Syncovery 7.89a - (.Super Flexible Software.) [HKLM][64Bits] -- Syncovery x64_is1 =>.Super Flexible Software
O42 - Logiciel: TeamViewer 10 Host - (.TeamViewer.) [HKLM][64Bits] -- TeamViewer =>.TeamViewer GmbH®

---\\ CLÉ DE REGISTRE SOFTWARE HKCU & HKLM (29) - 8s
HKLM\SOFTWARE\Adobe =>.Adobe
HKLM\SOFTWARE\Apple Inc. =>.Apple Inc.
HKLM\SOFTWARE\devolo =>.devolo AG
HKLM\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\SNIA
HKLM\SOFTWARE\Syncovery
HKLM\SOFTWARE\TeamViewer =>.TeamViewer
HKLM\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\Adobe =>.Adobe
HKLM\SOFTWARE\WOW6432Node\Apple Inc. =>.Apple Inc.
HKLM\SOFTWARE\WOW6432Node\devolo =>.devolo AG
HKLM\SOFTWARE\WOW6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\WOW6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\WOW6432Node\SNIA
HKLM\SOFTWARE\WOW6432Node\Syncovery
HKLM\SOFTWARE\WOW6432Node\TeamViewer =>.TeamViewer
HKLM\SOFTWARE\WOW6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\Adobe =>.Adobe
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\cks =>.Legitimate
HKCU\SOFTWARE\Local AppWizard-Generated Applications =>.ZWCAD
HKCU\SOFTWARE\Mine =>.Microsoft Corporation
HKCU\SOFTWARE\Syncovery
HKCU\SOFTWARE\SysInternals =>.Sysinternals
HKCU\SOFTWARE\TeamViewer =>.TeamViewer
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation

---\\ CONTENU DES DOSSIERS PROGRAMMES (104) - 4s
O43 - CFD: 22/08/2013 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files\DrWeb Enterprise Browser Plugins
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files\DrWeb Server =>.Doctor Web Ltd.®
O43 - CFD: 18/10/2017 - [0] SHD -- C:\Program Files\Fichiers communs =>.Microsoft Corporation
O43 - CFD: 18/10/2017 - [] D -- C:\Program Files\Hewlett-Packard =>.Hewlett-Packard
O43 - CFD: 15/04/2018 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\Program Files\Syncovery =>.Super Flexible Software Ltd. & Co. KG®
O43 - CFD: 22/08/2013 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] D -- C:\Program Files\Update Services
O43 - CFD: 21/11/2014 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 21/11/2014 - [] D -- C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 18/10/2017 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 21/11/2014 - [] D -- C:\Program Files\Windows Server =>.Microsoft Corporation®
O43 - CFD: 22/08/2013 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation
O43 - CFD: 21/11/2014 - [] D -- C:\Program Files\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Systems, Incorporated®
O43 - CFD: 22/10/2017 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\Program Files (x86)\devolo =>.Devolo AG
O43 - CFD: 28/02/2018 - [] D -- C:\Program Files (x86)\DrWeb Enterprise Browser Plugins
O43 - CFD: 15/04/2018 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\Program Files (x86)\Microsoft Sync Framework =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\Program Files (x86)\Microsoft Visual Studio 8 =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 15/04/2018 - [] D -- C:\Program Files (x86)\TeamViewer =>.TeamViewer GmbH
O43 - CFD: 21/11/2014 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 21/11/2014 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 21/11/2014 - [] D -- C:\Program Files (x86)\Windows Server =>.Microsoft Corporation®
O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 20/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\devolo =>.Devolo AG
O43 - CFD: 20/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dr.Web Server
O43 - CFD: 18/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Documentation
O43 - CFD: 22/08/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Syncovery x64
O43 - CFD: 21/11/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 21/11/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Server Essentials
O43 - CFD: 26/10/2017 - [] D -- C:\ProgramData\Adobe =>.Adobe
O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 18/10/2017 - [0] SHD -- C:\ProgramData\Bureau =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [] D -- C:\ProgramData\Doctor Web =>.Doctor Web Ltd
O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 24/12/2014 - [] D -- C:\ProgramData\LSI =>.LSI
O43 - CFD: 18/10/2017 - [0] SHD -- C:\ProgramData\Menu Démarrer =>.Microsoft Corporation
O43 - CFD: 21/10/2017 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 12/04/2018 - [] D -- C:\ProgramData\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 18/10/2017 - [0] SHD -- C:\ProgramData\Modèles =>.Microsoft Corporation
O43 - CFD: 21/11/2014 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation
O43 - CFD: 18/04/2018 - [] D -- C:\ProgramData\Syncovery
O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation
O43 - CFD: 19/10/2017 - [] D -- C:\Program Files (x86)\Common Files\Adobe =>.Adobe
O43 - CFD: 22/10/2017 - [] D -- C:\Program Files (x86)\Common Files\DESIGNER =>.Designer
O43 - CFD: 22/10/2017 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 22/10/2017 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 18/10/2017 - [] D -- C:\Users\Administrateur\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 26/02/2018 - [] D -- C:\Users\Administrateur\AppData\Roaming\de.devolo.dLAN.Cockpit =>.Devolo AG
O43 - CFD: 26/02/2018 - [] D -- C:\Users\Administrateur\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 28/02/2018 - [] SD -- C:\Users\Administrateur\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 19/04/2018 - [] D -- C:\Users\Administrateur\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 18/10/2017 - [0] SHD -- C:\Users\Administrateur\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 18/10/2017 - [] SHD -- C:\Users\Administrateur\AppData\Local\EmieBrowserModeList =>.Enterprise mode Site List Mgr
O43 - CFD: 08/01/2018 - [0] SHD -- C:\Users\Administrateur\AppData\Local\EmieSiteList =>.Enterprise mode Site List Mgr
O43 - CFD: 08/01/2018 - [0] SHD -- C:\Users\Administrateur\AppData\Local\EmieUserList =>.Enterprise mode Site List Mgr
O43 - CFD: 18/10/2017 - [0] SHD -- C:\Users\Administrateur\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 19/04/2018 - [] D -- C:\Users\Administrateur\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 08/01/2018 - [] D -- C:\Users\Administrateur\AppData\Local\Microsoft_Corporation =>.Microsoft Corporation
O43 - CFD: 18/10/2017 - [] D -- C:\Users\Administrateur\AppData\Local\Packages =>.Microsoft Corporation
O43 - CFD: 19/04/2018 - [] D -- C:\Users\Administrateur\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 18/10/2017 - [0] SHD -- C:\Users\Administrateur\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 19/04/2018 - [] D -- C:\Users\Administrateur\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 18/10/2017 - [] D -- C:\Users\Administrateur\AppData\LocalLow\Microsoft =>.Microsoft Corporation
O43 - CFD: 21/11/2014 - [] RD -- C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 21/11/2014 - [] RD -- C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 15/04/2018 - [] RD -- C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 22/08/2013 - [] D -- C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 15/04/2018 - [] RD -- C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 21/11/2014 - [] RD -- C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 18/10/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [0] D -- C:\Users\Default\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 18/10/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 20/10/2017 - [0] D -- C:\Users\Default User\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 09/02/2018 - [] SD -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation

---\\ ShellIconOverlayIdentifiers (SIOI) (5) - 1s
O106 - SIOI: Groove Explorer Icon Overlay 1 (GFS Unread Stub) [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] - {99FD978C-D287-4F50-827F-B2C658EDA8E7}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Groove Explorer Icon Overlay 2 (GFS Stub) [Groove Explorer Icon Overlay 2 (GFS Stub)] - {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] - {920E6DB1-9907-4370-B3A0-BAFC03D81399}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Groove Explorer Icon Overlay 3 (GFS Folder) [Groove Explorer Icon Overlay 3 (GFS Folder)] - {16F3DD56-1AF5-4347-846D-7C10C4192619}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O106 - SIOI: Groove Explorer Icon Overlay 4 (GFS Unread Mark) [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] - {2916C86E-86A6-43FE-8112-43ABE6BF8DCC}. (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®

---\\ RACCOURCIS DES MENUS CONCEPTUELS (SCMH) (18) - 4s
O108 - CMH1: Open With [64Bits] - {09799AFB-AD67-11d1-ABCD-00C04FC30936} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH1: Open With EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH1: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH1: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O108 - CMH2: OpenContainingFolderMenu [64Bits] - {37ea3a21-7493-4208-a011-7f9ea79ce9f5} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH3: CopyAsPathMenu [64Bits] - {f3d06e7c-1e45-4a26-847e-f9fcdee59be0} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH3: SendTo [64Bits] - {7BA4C740-9E81-11CF-99D3-00AA004AE837} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH3: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O108 - CMH4: EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH4: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH4: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O108 - CMH5: New [64Bits] - {D969A300-E7FF-11d0-A93B-00A0C90F2719} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH5: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH5: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O108 - CMH6: Library Location [64Bits] - {3dad6c5d-2167-4cae-9914-f99e41c12cfa} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH6: PintoStartScreen [64Bits] - {470C0EBD-5D73-4d58-9CED-E91E22E23282} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH6: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation®
O108 - CMH7: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation

---\\ IMAGE FILE EXECUTION OPTIONS (IFEO) (14) - 0s
O50 - IFEO:C:\Windows\System32\cscript.exe - (.Microsoft Corporation - Microsoft ® Console Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\dllhost.exe - (.Microsoft Corporation - COM Surrogate.) [DisableExceptionChainValidation\\3] =>.Microsoft Windows®
O50 - IFEO:C:\Windows\System32\drvinst.exe - (.Microsoft Corporation - Module d’installation de pilotes.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ie4uinit.exe - (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - Outil d’installation sans assistance d’IE 7.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mmc.exe - (.Microsoft Corporation - Microsoft Management Console.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Hôte des applications HTML de Microsoft(R).) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Windows Presentation Foundation Host.) [MitigationOptions\\1118481] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\rundll32.exe - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\\4294967296] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\searchprotocolhost.exe - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\spoolsv.exe - (.Microsoft Corporation - Application sous-système spouleur.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\wscript.exe - (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation

---\\ LISTE DES PILOTES DU SYSTÈME (49) - 5s
O58 - SDL:2013/08/22 14:43:41 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\drivers\3ware.sys [108896] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:41 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\Windows\System32\drivers\adp80xx.sys [782176] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:41 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [79200] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:41 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [259424] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:40 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [25952] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:41 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [114016] =>.Microsoft Windows®
O58 - SDL:2016/09/21 10:44:06 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60a.sys [476472] =>.Broadcom Corporation®
O58 - SDL:2013/08/22 14:43:41 A . (.Brocade Communications Systems, Inc. - Brocade FC/FCoE HBA Stor Miniport Driver.) -- C:\Windows\System32\drivers\bfadfcoei.sys [2265440] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:41 A . (.Brocade Communications Systems, Inc. - Brocade FC/FCoE HBA Stor Miniport Driver.) -- C:\Windows\System32\drivers\bfadi.sys [2265440] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:41 A . (.Broadcom Corporation - Broadcom NetXtreme Unified Crash Dump (x64).) -- C:\Windows\System32\drivers\bnxcd.sys [207712] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:39 A . (.Broadcom Corporation - Broadcom NetXtreme FCoE Crash Dump (x64).) -- C:\Windows\System32\drivers\bnxfcd.sys [90976] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:41 A . (.Broadcom Corporation - FCoE offload x64 FREE.) -- C:\Windows\System32\drivers\bxfcoe.sys [187744] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:41 A . (.Broadcom Corporation - iSCSI offload x64 FREE.) -- C:\Windows\System32\drivers\bxois.sys [560480] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:41 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [531296] =>.Microsoft Windows®
O58 - SDL:2013/06/18 16:45:17 A . (.Chelsio Communications - Virtual Bus Driver for Chelsio ® T4 Chipset.) -- C:\Windows\System32\drivers\cht4vx64.sys [605672] =>.Chelsio Communications
O58 - SDL:2013/08/22 14:43:45 A . (.Emulex - Emulex Storport Miniport Driver.) -- C:\Windows\System32\drivers\elxfcoe.sys [712032] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:45 A . (.Emulex - Emulex Storport Miniport Driver.) -- C:\Windows\System32\drivers\elxstor.sys [712032] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:45 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3357024] =>.Microsoft Windows®
O58 - SDL:2017/03/30 08:41:46 A . (.Microsemi Coporation - Smart Array SAS/SATA Controller Storport Dr.) -- C:\Windows\System32\drivers\HpCISSs3.sys [188400] {48322B4D92F9FF9F290C968FACABD25D}
O58 - SDL:2016/07/30 04:21:20 A . (.Hewlett Packard Enterprise - iLO 3/4 Channel Interface Driver.) -- C:\Windows\System32\drivers\hpqilo3chif.sys [53064] {3CF170877E235036200BECF49A6312AA}
O58 - SDL:2016/07/29 21:19:12 A . (.Hewlett Packard Enterprise - iLO 3/4 Core Driver.) -- C:\Windows\System32\drivers\hpqilo3core.sys [53408] {3CF170877E235036200BECF49A6312AA}
O58 - SDL:2013/08/22 14:43:45 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [64352] =>.Microsoft Windows®
O58 - SDL:2013/08/10 02:39:30 A . (.Intel Corporation - Intel Rapid Storage Technology driver (inbo.) -- C:\Windows\System32\drivers\iaStorAV.sys [651248] =>.Intel Corporation - Intel® Rapid Storage Technology®
O58 - SDL:2013/08/22 14:43:45 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [412000] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:45 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\Windows\System32\drivers\ibbus.sys [463712] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:44 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [109408] =>.Microsoft Windows®
O58 - SDL:2014/05/29 11:14:20 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [101552] =>.LSI Corporation®
O58 - SDL:2013/08/22 14:43:44 A . (.LSI Corporation - LSI SAS Gen3 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas3.sys [81760] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sss.sys [82784] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [56672] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\megasr.sys [575840] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:45 A . (.Mellanox - MLX4 Bus Driver.) -- C:\Windows\System32\drivers\mlx4_bus.sys [426336] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:49 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\Windows\System32\drivers\mvumis.sys [63840] =>.Microsoft Windows®
O58 - SDL:2016/08/29 20:58:52 A . (.Matrox Graphics Inc. - MxG2hDO64.sys.) -- C:\Windows\System32\drivers\MxG2hDO64.sys [580272] {05260217E8775D6983CB65D2F8312AB8} =>.Matrox Graphics Inc.
O58 - SDL:2013/08/22 14:43:49 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\Windows\System32\drivers\ndfltr.sys [66400] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:31 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [150368] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:32 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [168288] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:32 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Inbox Dr.) -- C:\Windows\System32\drivers\ql2300i.sys [1508704] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:31 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Inbox Driver.) -- C:\Windows\System32\drivers\ql40xx2i.sys [475488] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:32 A . (.QLogic Corporation - QLogic FCoE Stor Miniport Inbox Driver.) -- C:\Windows\System32\drivers\qlfcoei.sys [1300320] =>.Microsoft Windows®
O58 - SDL:2013/08/22 17:38:13 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] =>.Rovi Corporation
O58 - SDL:2013/08/22 14:43:31 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [44896] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:32 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [81760] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:32 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\Windows\System32\drivers\stexstor.sys [31072] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:34 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [19808] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:34 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [168800] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:34 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\Windows\System32\drivers\VSTXRAID.SYS [305504] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:35 A . (.Mellanox - Kernel WinMad.) -- C:\Windows\System32\drivers\winmad.sys [28000] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:35 A . (.Mellanox - Kernel WinVerbs.) -- C:\Windows\System32\drivers\winverbs.sys [59744] =>.Microsoft Windows®

---\\ ASSOCIATION Shell Spawning (10) - 1s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (...) -- C:\Windows\System32\WScript.exe "%1" %* =>.Default.Value
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S =>.Default.Value

---\\ MENU DE DÉMARRAGE INTERNET (4) - 0s
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

---\\ RECHERCHE D'INFECTION SUR LES NAVIGATEURS (2) - 0s
O69 - SBI: SearchScopes [HKCU] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com

---\\ ÉNUMÈRE LES SERVICES DÉMARRÉS PAR Svchost (34) - 0s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [214528] =>.Microsoft Corporation
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [158720] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [158720] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [329216] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [1362432] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\IKEEXT.DLL [1080320] =>.Microsoft Corporation
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [187904] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [927744] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\System32\seclogon.dll [31744] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [110080] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [151040] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [110592] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1265664] =>.Microsoft Corporation
O83 - Search Svchost Services: sacsvr (sacsvr) . (.Microsoft Corporation - Microsoft EMS SAC Service.) -- C:\Windows\System32\sacsvr.dll [15872] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [230400] =>.Microsoft Corporation
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\System32\mmcss.dll [71168] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [135168] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [228864] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [346112] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84992] =>.Microsoft Corporation
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\KMSVC.DLL [101376] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [59392] =>.Microsoft Corporation
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\Windows\System32\DeviceSetupManager.dll [206848] =>.Microsoft Corporation
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\Windows\System32\NcaSvc.dll [166400] =>.Microsoft Corporation
O83 - Search Svchost Services: Ias (Ias) . (.Microsoft Corporation - Network Policy Server.) -- C:\Windows\System32\ias.dll [31232] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [102912] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\Windows\System32\rasmans.dll [542720] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [233472] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [73728] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [452608] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [313344] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\System32\wuaueng.dll [3717632] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [933376] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [640000] =>.Microsoft Corporation

---\\ LISTE DES EXCEPTIONS DU PAREFEU WINDOWS (8) - 1s
O87 - FAEL: "{834F4769-C333-4CDA-9E08-7438039DB0B3}" [In-None-P6-TRUE] .(.devolo AG - devolo Network Service.) -- C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe =>.devolo AG®
O87 - FAEL: "{7332F09D-7FC1-497A-BD99-ABFAD262556B}" [In-None-P17-TRUE] .(.devolo AG - devolo Network Service.) -- C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe =>.devolo AG®
O87 - FAEL: "{CF7C47AA-6DB5-4CC0-A09F-C393DD1C18BA}" [In-None-P17-TRUE] .(.Doctor Web, Ltd. - Dr.Web Enterprise Suite Server.) -- C:\Program Files\DrWeb Server\bin\drwcsd.exe =>.Doctor Web Ltd.®
O87 - FAEL: "{FFFE7ADA-AF1E-4C6E-93B9-4E40AE74B760}" [Out-None-P17-TRUE] .(.Doctor Web, Ltd. - Dr.Web Enterprise Suite Server.) -- C:\Program Files\DrWeb Server\bin\drwcsd.exe =>.Doctor Web Ltd.®
O87 - FAEL: "{3849D722-2DA6-4593-9A37-8880BF9331F4}" [In-None-P6-TRUE] .(.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\TeamViewer.exe =>.TeamViewer GmbH®
O87 - FAEL: "{41FADAF4-5F51-4547-ABE0-C3A17D3BC91C}" [In-None-P17-TRUE] .(.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\TeamViewer.exe =>.TeamViewer GmbH®
O87 - FAEL: "{D2E83A4A-86F9-4222-950F-422250D48BF3}" [In-None-P6-TRUE] .(.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe =>.TeamViewer GmbH®
O87 - FAEL: "{E4960247-D247-4FE3-BA54-146EB42E30FF}" [In-None-P17-TRUE] .(.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe =>.TeamViewer GmbH®

---\\ CODES PRODUITS LOGICIELS (30) - 0s
O90 - PUC: "00004109110000000000000000F01FEC" [HKLM] . (.Microsoft Office Professional Plus 2010.) =>Microsoft Corporation
O90 - PUC: "000041091A00C0400000000000F01FEC" [HKLM] . (.Microsoft Office OneNote MUI (French) 2010.) =>Microsoft Corporation
O90 - PUC: "000041094400C0400000000000F01FEC" [HKLM] . (.Microsoft Office InfoPath MUI (French) 2010.) =>Microsoft Corporation
O90 - PUC: "000041095100C0400000000000F01FEC" [HKLM] . (.Microsoft Office Access MUI (French) 2010.) =>Microsoft Corporation
O90 - PUC: "000041096100C0400000000000F01FEC" [HKLM] . (.Microsoft Office Excel MUI (French) 2010.) =>Microsoft Corporation
O90 - PUC: "000041098100C0400000000000F01FEC" [HKLM] . (.Microsoft Office PowerPoint MUI (French) 2010.) =>Microsoft Corporation
O90 - PUC: "000041099100C0400000000000F01FEC" [HKLM] . (.Microsoft Office Publisher MUI (French) 2010.) =>Microsoft Corporation
O90 - PUC: "00004109A100C0400000000000F01FEC" [HKLM] . (.Microsoft Office Outlook MUI (French) 2010.) =>Microsoft Corporation
O90 - PUC: "00004109A20000000100000000F01FEC" [HKLM] . (.Microsoft Office Office 64-bit Components 2010.) =>Microsoft Corporation
O90 - PUC: "00004109A200C0400100000000F01FEC" [HKLM] . (.Microsoft Office Shared 64-bit MUI (French) 2010.) =>Microsoft Corporation
O90 - PUC: "00004109AB00C0400000000000F01FEC" [HKLM] . (.Microsoft Office Groove MUI (French) 2010.) =>Microsoft Corporation
O90 - PUC: "00004109B100C0400000000000F01FEC" [HKLM] . (.Microsoft Office Word MUI (French) 2010.) =>Microsoft Corporation
O90 - PUC: "00004109C200C0400000000000F01FEC" [HKLM] . (.Microsoft Office Proofing (French) 2010.) =>Microsoft Corporation
O90 - PUC: "00004109E600C0400000000000F01FEC" [HKLM] . (.Microsoft Office Shared MUI (French) 2010.) =>Microsoft Corporation
O90 - PUC: "00004109F10010400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (Arabic) 2010.) =>Microsoft Corporation
O90 - PUC: "00004109F10031400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (Dutch) 2010.) =>Microsoft Corporation
O90 - PUC: "00004109F10070400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (German) 2010.) =>Microsoft Corporation
O90 - PUC: "00004109F10090400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (English) 2010.) =>Microsoft Corporation
O90 - PUC: "00004109F100A0C00000000000F01FEC" [HKLM] . (.Microsoft Office Proof (Spanish) 2010.) =>Microsoft Corporation
O90 - PUC: "00004109F100C0400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (French) 2010.) =>Microsoft Corporation
O90 - PUC: "1926E8D15D0BCE53481466615F760A7F" [HKLM] . (.Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219.) =>Microsoft Corporation
O90 - PUC: "1CF2584237C86604BAC288BEBEFA3990" [HKLM] . (.ProLiant Monitor Service (X64).)
O90 - PUC: "1D5E3C0FEDA1E123187686FED06E995A" [HKLM] . (.Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219.) =>Microsoft Corporation
O90 - PUC: "4BEA594979BAED93C82408E6FE57CE7A" [HKLM] . (.Microsoft Visual Studio 2010 Tools for Office Runtime (x64).) =>Microsoft Corporation
O90 - PUC: "68AB67CA7DA76301B744BA0000000010" [HKLM] . (.Adobe Reader XI (11.0.02) - Français.) -- C:\Windows\Installer\{AC76BA86-7AD7-1036-7B44-AB0000000001}\SC_Reader.ico
O90 - PUC: "6CE0A0D8C3A9F453B9CF6AE169EB8164" [HKLM] . (.Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - FRA.) =>Microsoft Corporation
O90 - PUC: "8AAA5671728F0534AA797F88FD41CEE5" [HKLM] . (.iLO 3/4 Core Driver (X64).)
O90 - PUC: "A9532B9EA85DEB545B3EB75F7389B469" [HKLM] . (.HPE ProLiant Agentless Management Service.) =>Hewlett-Packard
O90 - PUC: "B4B2D0E3F5AC6D040BEA460880981752" [HKLM] . (.MergeModule2012.)
O90 - PUC: "DB3A1AE16A1FA2A42B8B5537519769C9" [HKLM] . (.Dr.Web Server (x64).) -- C:\Windows\Installer\{1EA1A3BD-F1A6-4A2A-B2B8-55731579969C}\ARPPRODUCTICON.exe

---\\ PACKAGES WINDOWS INSTALLER (9) - 6s
[MD5.F08C943C61DD94A7B7F84573821999B3] [WIS][2016/08/16 21:38:26] (.Hewlett Packard Enterprise - iLO 3/4 Core Driver (X64).) -- C:\Windows\Installer\18ceb8.msi [995328]
[MD5.69B924186699ADD5F7A7C8B2C597E206] [WIS][2016/07/31 01:44:30] (.Hewlett Packard Enterprise - ProLiant Monitor Service (X64).) -- C:\Windows\Installer\18cebc.msi [110592]
[MD5.E1017A609B06C12248EF759471FEF6D1] [WIS][2016/09/14 17:35:34] (.Hewlett Packard Enterprise Development LP - HPE ProLiant Agentless Management Service (.) -- C:\Windows\Installer\18cec4.msi [270336]
[MD5.A71AB0FC96A786C7B39FE5D8A3930F6D] [WIS][2018/02/28 17:32:43] (.Doctor Web, Ltd - Dr.Web Enterprise Browser Plugins.) -- C:\Windows\Installer\19f6dcc.msi [3424256]
[MD5.C96D0C7B22E237090566B3046070202F] [WIS][2017/10/20 12:46:33] (.Doctor Web - DrWeb Server (x64).) -- C:\Windows\Installer\32275a5.msi [670485504]
[MD5.9349ADED1DCF5B07193441C82454DAE4] [WIS][2017/10/20 13:03:35] (.Doctor Web, Ltd - Dr.Web Enterprise Browser Plugins.) -- C:\Windows\Installer\32275a9.msi [3754496]
[MD5.E398BDE08879A89EA7AD414157BAD086] [WIS][2012/09/24 05:48:11] (.Adobe Systems Incorporated.) -- C:\Windows\Installer\5ae40c.msi [2398208] =>.Adobe Systems Incorporated
[MD5.A04C16EE0D8296F749952B4ED72DC565] [WIS][2013/02/16 00:35:46] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\5ae40d.msp [1519616] =>.SUP.Obsolete.Adobe
[MD5.E9692A6AD6C62525DF8611D1B084D950] [WIS][2013/02/16 00:35:46] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\5ae40e.msp [17502208] =>.SUP.Obsolete.Adobe

---\\ FEATURE CONTROLE. (1) - 0s
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:dashboard.exe

---\\ SCAN ADDITIONNEL (3) - 2s
HKLM\Software\WOW6432Node\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C} =>.SUP.Various
C:\Windows\Installer\5ae40d.msp =>.SUP.Obsolete.Adobe
C:\Windows\Installer\5ae40e.msp =>.SUP.Obsolete.Adobe

---\\ RÉCAPITULATIF DES ÉLÉMENTS TROUVÉS SUR VOTRE STATION (2) - 0s
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Various
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Obsolete.Adobe

~ Unselected Options:
~ End of the scan, 5428 items in 00mn48s (734)(0)

Publicité


Signaler le contenu de ce document

Publicité