cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2018.6.19.139 Par Nicolas Coolman (2018/06/19)
~ Démarré par Florian (Administrator) (2018/06/21 05:53:56)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Legal
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Users\Florian\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\Florian\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Démarrage du système: Normal (Normal boot)
Windows 8.1, 64-bit (Build 9600) =>.Microsoft Corporation

---\\ NAVIGATEURS INTERNET (2) - 0s
~ GCIE: Google Chrome v67.0.3396.87
~ MSIE: Internet Explorer v11.0.9600.17031

---\\ INFORMATIONS SUR LES PRODUITS WINDOWS (8) - 0s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
~ Windows(R) Operating System, RETAIL channel
Windows ID Activation : OK
~ Windows Partial Key : X2C6G
Windows License : OK
~ Windows Remaining Initializations Number : 1000
Windows Automatic Updates : OK

---\\ LOGICIELS DE PROTECTION (1) - 1s
Windows Defender (Activate) (Protection)

---\\ LOGICIELS DE PARTAGE P2P (1) - 1s
~ µTorrent v3.5.3.44428 (P2P)

---\\ INFORMATIONS SUR LE SYSTÈME (6) - 0s
~ Operating System: Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 8387.832 MB (68% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 585 GB (95%) free of 610 GB : OK =>.Disk Space

---\\ MODE DE CONNEXION AU SYSTÈME (3) - 0s
~ Computer Name: Phanteck57350
~ User Name: Florian
~ Logged in as Administrator

---\\ ÉNUMÉRATION DES UNITÉS DE STOCKAGE (2) - 0s
~ Drive C: has 585 GB free of 610 GB (System)
~ Drive J: has 1616 GB free of 1907 GB

---\\ ÉTAT DU CENTRE DE SÉCURITÉ WINDOWS (10) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ RECHERCHE PARTICULIÈRE DE FICHIERS GÉNÉRIQUES (25) - 1s
[MD5.4CE0C733CDCF1D2F78532BBD9CE3441D] - 18/03/2014 - (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\Explorer.exe [2373784] =>.Microsoft Windows®
[MD5.6E0BDFBEEED65B017F2E4C2C910B0520] - 22/08/2013 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe [52736] =>.Microsoft Corporation
[MD5.48CFA7BE561A7BE144C29BB912055016] - 22/08/2013 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\System32\Wininit.exe [144384] =>.Microsoft Corporation
[MD5.65C36A29A131A3A5D64B29FAC4EF6DD6] - 18/03/2014 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [2262016] =>.Microsoft Corporation
[MD5.306EB21E5B480AE9065EA55AC8C35936] - 18/03/2014 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\Windows\System32\Winlogon.exe [562176] =>.Microsoft Corporation
[MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - 18/03/2014 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [447488] =>.Microsoft Corporation
[MD5.5A2020DDCCBB0ED08BAC2355A075F303] - 18/03/2014 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\System32\dnsapi.dll [656384] =>.Microsoft Corporation
[MD5.2B9EED6835D269F35B310DC03D0F5768] - 18/03/2014 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\Syswow64\dnsapi.dll [492544] =>.Microsoft Corporation
[MD5.E37F897ED7B5AFF79B1398258DB96BD9] - 18/03/2014 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [19456] =>.Microsoft Corporation
[MD5.239268BAB58EAE9A3FF4E08334C00451] - 22/08/2013 - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\Windows\System32\drivers\AFD.sys [567296] =>.Microsoft Corporation
[MD5.74B14192CF79A72F7536B27CB8814FBD] - 22/08/2013 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [26464] =>.Microsoft Corporation
[MD5.2FA6510E33F7DEFEC03658B74101A9B9] - 22/08/2013 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [88576] =>.Microsoft Corporation
[MD5.C6796EA22B513E3457514D92DCDB1A3D] - 22/08/2013 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [164352] =>.Microsoft Corporation
[MD5.414686EF104910BA41DF66E83BDCD495] - 18/03/2014 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [134656] =>.Microsoft Corporation
[MD5.03909BDBFF0DCACCABF2B2D4ADEE44DC] - 22/08/2013 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [78336] =>.Microsoft Corporation
[MD5.84CFC5EFA97D0C965EDE1D56F116A541] - 22/08/2013 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [107520] =>.Microsoft Corporation
[MD5.B7342B3C58E91107F6E946A93D9D4EFD] - 18/03/2014 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [142848] =>.Microsoft Corporation
[MD5.16FFC07D36FD83ACA189A641385168B3] - 18/03/2014 - (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\Windows\System32\drivers\MRxSmb.sys [402944] =>.Microsoft Corporation
[MD5.0217532E19A748F0E5D569307363D5FD] - 22/08/2013 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [282624] =>.Microsoft Corporation
[MD5.9AEB38B451A7B84ACB7CD3D664F87BF0] - 18/03/2014 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [2013016] =>.Microsoft Corporation
[MD5.764B1121867B2D9B31C491668AC72B2B] - 22/08/2013 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\Parport.sys [94208] =>.Microsoft Corporation
[MD5.BBB6272B7F46C4640A8CDB8A70C3450F] - 22/08/2013 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [120832] =>.Microsoft Corporation
[MD5.680C1DAE268B6FB67FA21B389A8B79EF] - 18/03/2014 - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) -- C:\Windows\System32\drivers\rdpdr.sys [195584] =>.Microsoft Corporation
[MD5.FFF28F9F6823EB1756C60F1649560BBF] - 22/08/2013 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [107520] =>.Microsoft Corporation
[MD5.3595FBDF25F8BA6256072D103937D7D6] - 18/03/2014 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [311640] =>.Microsoft Corporation

---\\ LISTE DES SERVICES (Non désactivés) (53) - 4s
O23 - Service: AppkohcatiP (AppkohcatiP) . (. - TODO: .) - C:\ProgramData\AppkohcatiP\AppkohcatiP.exe =>PUP.Optional.Salus
O23 - Service: C:\Windows\System32\AudioEndpointBuilder.dll (AudioEndpointBuilder) . (.Microsoft Corporation - Générateur de points de terminaison du serv.) - C:\Windows\System32\AudioEndpointBuilder.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\audiosrv.dll (Audiosrv) . (.Microsoft Corporation - Service Audio Windows.) - C:\Windows\System32\Audiosrv.dll =>.Microsoft Corporation
O23 - Service: Background Logic Handler (backlh) . (. - ExtManager.) - C:\ProgramData\Logic Cramble\set.exe =>PUP.Optional.LogicHandler
O23 - Service: C:\Windows\System32\bfe.dll (BFE) . (.Microsoft Corporation - Moteur de filtrage de base.) - C:\Windows\System32\bfe.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\system32\bisrv.dll (BrokerInfrastructure) . (.Microsoft Corporation - Service d’infrastructure des tâches en arri.) - C:\Windows\System32\bisrv.dll =>.Microsoft Corporation
O23 - Service: Service Bluetooth Switcher (BtSwitcherService) . (.Cambridge Silicon Radio Limited - BtSwitcherService.) - C:\Program Files\CSR\CSR Harmony Wireless Software Stack\BtSwitcherService.exe =>.Cambridge Silicon Radio Ltd.®
O23 - Service: C:\Windows\System32\cryptsvc.dll (CryptSvc) . (.Microsoft Corporation - Services de chiffrement.) - C:\Windows\System32\cryptsvc.dll =>.Microsoft Corporation
O23 - Service: Service audio Bluetooth CSR (CSRBtAudioService) . (.Cambridge Silicon Radio Limited - CSR Bluetooth Audio Service.) - C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtAudioService.exe =>.Cambridge Silicon Radio Ltd.®
O23 - Service: CSR OBEX Service (CsrBtOBEXService) . (.Cambridge Silicon Radio Limited - Bluetooth OBEX Service.) - C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtOBEXService.exe =>.Cambridge Silicon Radio Ltd.®
O23 - Service: Service Bluetooth CSR (CsrBtService) . (.Cambridge Silicon Radio Limited - Csr Bluetooth Service.) - C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtService.exe =>.Cambridge Silicon Radio Ltd.®
O23 - Service: C:\Windows\System32\dhcpcore.dll (Dhcp) . (.Microsoft Corporation - Service client DHCP.) - C:\Windows\System32\dhcpcore.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\dnsapi.dll (Dnscache) . (.Microsoft Corporation - Service de résolution du cache DNS.) - C:\Windows\System32\dnsrslvr.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wevtsvc.dll (EventLog) . (.Microsoft Corporation - Processus hôte pour les services Windows.) - C:\Windows\System32\svchost.exe {330000000AD7212BEC936743EB00000000000A} =>.Microsoft Corporation
O23 - Service: @comres.dll,-2450 (EventSystem) . (.Microsoft Corporation - COM+.) - C:\Windows\System32\es.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\FntCache.dll (FontCache) . (.Microsoft Corporation - Service de cache de police Windows.) - C:\Windows\System32\FntCache.dll =>.Microsoft Corporation
O23 - Service: @gpapi.dll,-112 (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) - C:\Windows\System32\gpsvc.dll =>.Microsoft Corporation
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
O23 - Service: HuaweiHiSuiteService64.exe (HuaweiHiSuiteService64.exe) . (. - HuaweiHiSuiteService.) - C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe =>.Huawei Technologies Co.,Ltd
O23 - Service: netdrvrsvc (INetDriverSvc) . (...) - C:\Program Files\WinVPN\inetdrv.exe
O23 - Service: C:\Windows\System32\iphlpsvc.dll (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) - C:\Windows\System32\iphlpsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\srvsvc.dll (LanmanServer) . (.Microsoft Corporation - DLL du service Serveur.) - C:\Windows\System32\srvsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wkssvc.dll (LanmanWorkstation) . (.Microsoft Corporation - DLL du service Station de travail.) - C:\Windows\System32\wkssvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\lmhsvc.dll (lmhosts) . (.Microsoft Corporation - DLL des services de transport NetBIOS sur T.) - C:\Windows\System32\lmhsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\system32\lsm.dll (LSM) . (.Microsoft Corporation - Service du gestionnaire de session locale.) - C:\Windows\System32\lsm.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\mmcss.dll (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) - C:\Windows\System32\mmcss.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\FirewallAPI.dll (MpsSvc) . (.Microsoft Corporation - Service de protection Microsoft.) - C:\Windows\System32\mpssvc.dll =>.Microsoft Corporation
O23 - Service: Prefs Secure (Nettrans) . (. - Network Packet Monitor.) - C:\ProgramData\PrefsSecure\Nettrans.exe =>PUP.Optional.LogicHandler
O23 - Service: C:\Windows\System32\nlasvc.dll (NlaSvc) . (.Microsoft Corporation - Connaissance des emplacements réseau 2.) - C:\Windows\System32\nlasvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\nsisvc.dll (nsi) . (.Microsoft Corporation - Serveur RPC de l’interface du magasin résea.) - C:\Windows\System32\nsisvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\pcasvc.dll (PcaSvc) . (.Microsoft Corporation - Service de l’Assistant Compatibilité des pr.) - C:\Windows\System32\pcasvc.dll =>.Microsoft Corporation
O23 - Service: PG Manager (pgt_svc) . (.Gold Click Ltd - PG Control Center.) - C:\Program Files (x86)\ProxyGate\MainService.exe =>.SUP.ProxyGate
O23 - Service: C:\Windows\System32\umpo.dll (Power) . (.Microsoft Corporation - Service d’alimentation en mode utilisateur.) - C:\Windows\System32\umpo.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\profsvc.dll (ProfSvc) . (.Microsoft Corporation - ProfSvc.) - C:\Windows\System32\profsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\system32\RpcEpMap.dll (RpcEptMapper) . (.Microsoft Corporation - Mappeur de point de terminaison RPC.) - C:\Windows\System32\RpcEpMap.dll =>.Microsoft Corporation
O23 - Service: @combase.dll,-5010 (RpcSs) . (.Microsoft Corporation - Distributed COM Services.) - C:\Windows\System32\rpcss.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\schedsvc.dll (Schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) - C:\Windows\System32\schedsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\Sens.dll (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) - C:\Windows\System32\sens.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\shsvcs.dll (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) - C:\Windows\System32\shsvcs.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\spoolsv.exe,-1 (Spooler) . (.Microsoft Corporation - Application sous-système spouleur.) - C:\Windows\System32\spoolsv.exe =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\sppsvc.exe,-101 (sppsvc) . (.Microsoft Corporation - Service de la plateforme de protection logi.) - C:\Windows\System32\sppsvc.exe =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\sysmain.dll (SysMain) . (.Microsoft Corporation - Hôte de service Superfetch.) - C:\Windows\System32\sysmain.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\system32\SystemEventsBrokerServer.dll (SystemEventsBroker) . (.Microsoft Corporation - Service Broker pour les événements système.) - C:\Windows\System32\SystemEventsBrokerServer.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\themeservice.dll (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) - C:\Windows\System32\themeservice.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wcmsvc.dll (Wcmsvc) . (.Microsoft Corporation - DLL du service de gestion des connexions Wi.) - C:\Windows\System32\wcmsvc.dll =>.Microsoft Corporation
O23 - Service: Windows Audio Manager (winamgr) . (.Microsoft Corporation - Windows Audio Manager.) - C:\ProgramData\Microsoft\Windows\Audio\winamgr.exe =>.Microsoft Corporation
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) . (.Microsoft Corporation - Antimalware Service Executable.) - C:\Program Files\Windows Defender\MsMpEng.exe =>.Microsoft Corporation®
O23 - Service: C:\Windows\System32\wbem\wmisvc.dll (Winmgmt) . (.Microsoft Corporation - WMI.) - C:\Windows\System32\wbem\WMIsvc.dll =>.Microsoft Corporation
O23 - Service: WinPing Service (WinPing) . (...) - C:\Program Files\WinVPN\wpsvc.exe
O23 - Service: C:\Windows\System32\wlansvc.dll (WlanSvc) . (.Microsoft Corporation - DLL du service de configuration automatique.) - C:\Windows\System32\wlansvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wscsvc.dll (wscsvc) . (.Microsoft Corporation - Service Centre de sécurité de Windows.) - C:\Windows\System32\wscsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\SearchIndexer.exe,-103 (WSearch) . (.Microsoft Corporation - Indexeur Microsoft Windows Search.) - C:\Windows\System32\SearchIndexer.exe =>.Microsoft Corporation
O23 - Service: (Y2Y5MmQ1MDVkOGZjY) . (...) - C:\Windows\yfinuhhrbpfnqlij.yfi

---\\ SERVICES NON MICROSOFT (SR=Démarré,SS=Stoppé) (14) - 4s
SR - Auto [20/06/2018] [ 1810944] AppkohcatiP (AppkohcatiP) . (...) - C:\ProgramData\AppkohcatiP\AppkohcatiP.exe =>PUP.Optional.Salus
SR - Auto [20/06/2018] [ 3780096] Background Logic Handler (backlh) . (...) - C:\ProgramData\Logic Cramble\set.exe =>PUP.Optional.LogicHandler
SR - Auto [22/03/2012] [ 64216] Service Bluetooth Switcher (BtSwitcherService) . (.Cambridge Silicon Radio Limited.) - C:\Program Files\CSR\CSR Harmony Wireless Software Stack\BtSwitcherService.exe =>.Cambridge Silicon Radio Ltd.®
SR - Auto [22/03/2012] [ 465624] Service audio Bluetooth CSR (CSRBtAudioService) . (.Cambridge Silicon Radio Limited.) - C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtAudioService.exe =>.Cambridge Silicon Radio Ltd.®
SR - Auto [22/03/2012] [ 1041616] CSR OBEX Service (CsrBtOBEXService) . (.Cambridge Silicon Radio Limited.) - C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtOBEXService.exe =>.Cambridge Silicon Radio Ltd.®
SR - Auto [22/03/2012] [ 825032] Service Bluetooth CSR (CsrBtService) . (.Cambridge Silicon Radio Limited.) - C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtService.exe =>.Cambridge Silicon Radio Ltd.®
SS - Auto [20/06/2018] [ 153168] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [20/06/2018] [ 153168] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SR - Auto [26/07/2017] [ 192200] HuaweiHiSuiteService64.exe (HuaweiHiSuiteService64.exe) . (...) - C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe =>.Huawei Technologies Co.,Ltd
SR - Auto [10/06/2018] [ 1180160] netdrvrsvc (INetDriverSvc) . (...) - C:\Program Files\WinVPN\inetdrv.exe
SR - Auto [20/06/2018] [ 43520] Prefs Secure (Nettrans) . (...) - C:\ProgramData\PrefsSecure\Nettrans.exe =>PUP.Optional.LogicHandler
SS - Auto [22/02/2017] [ 2285664] PG Manager (pgt_svc) . (.Gold Click Ltd.) - C:\Program Files (x86)\ProxyGate\MainService.exe =>.SUP.ProxyGate
SR - Auto [08/06/2018] [ 12288] WinPing Service (WinPing) . (...) - C:\Program Files\WinVPN\wpsvc.exe
SR - Auto [20/06/2018] [ 1185792] (Y2Y5MmQ1MDVkOGZjY) . (...) - C:\Windows\yfinuhhrbpfnqlij.yfi

---\\ TÂCHES PLANIFIÉES EN AUTOMATIQUE (Registre) (4) - 1s
O38 - TASK: {E19CA369-9116-410E-8F98-CFE1F6CF7B69} [64Bits][\GoogleUpdateTaskMachineUA] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168] =>.Google Inc.
O38 - TASK: {EED370FC-23E1-4963-9D89-3DD0EDC34F18} [64Bits][\GoogleUpdateTaskMachineCore] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168] =>.Google Inc.
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [/ua ./ua] =>.Google Inc.
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [/c] =>.Google Inc.

---\\ APPLICATIONS LANCÉES AU DÉMARRAGE DU SYSTÈME (14) - 2s
O4 - HKLM\..\Run: [CsrHCRPServer] . (.Cambridge Silicon Radio Limited - Csr HCRP Server.) -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrHCRPServer.exe =>.Cambridge Silicon Radio Ltd.®
O4 - HKLM\..\Run: [CsrAudioguiCtrl] . (.Cambridge Silicon Radio Limited - CSR Headset Control.) -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrAudioguiCtrl.exe =>.Cambridge Silicon Radio Ltd.®
O4 - HKLM\..\Run: [CsrSyncMLServer] . (...) -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrSyncMLServer.exe =>.Cambridge Silicon Radio Ltd.®
O4 - HKLM\..\Run: [vksts] . (.Cambridge Silicon Radio Limited - Csr Bluetooth OSD Settings.) -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\vksts.exe =>.Cambridge Silicon Radio Ltd.®
O4 - HKLM\..\Run: [HarmonyUserStartup] . (.Cambridge Silicon Radio Limited - Csr Harmony User Startup Application.) -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\HarmonyUserStartup.exe =>.Cambridge Silicon Radio Ltd.®
O4 - HKLM\..\Run: [CSRHarmonySkypePlugin] . (.Cambridge Silicon Radio Limited - HFP Skype Application.) -- C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe =>.Cambridge Silicon Radio Ltd.®
O4 - HKLM\..\Run: [TrayApplication] . (.Cambridge Silicon Radio Limited - Csr Bluetooth TrayApplication.) -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\TrayApplication.exe =>.Cambridge Silicon Radio Ltd.®
O4 - HKLM\..\RunOnce: [tryki4t5lig] . (. - SanOo.) -- C:\Program Files (x86)\Photomaker\154816.exe
O4 - HKCU\..\Run: [Skype for Desktop] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe =>.Skype Software Sarl®
O4 - HKCU\..\Run: [UX3LkAWonV.exe] . (. - PackageProvider.) -- C:\Program Files\Windows Defender\GC0CWWNC8EP\UX3LkAWonV.exe
O4 - HKCU\..\Run: [EUIPTVIHZU.exe] . (.Copyright - .) -- C:\Users\Florian\AppData\Roaming\b5bad02b55ff4beeb700f1889496acfa\EUIPTVIHZU.exe
O4 - HKUS\S-1-5-21-2852345370-3227221742-3801130228-1001\..\Run: [Skype for Desktop] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe =>.Skype Software Sarl®
O4 - HKUS\S-1-5-21-2852345370-3227221742-3801130228-1001\..\Run: [UX3LkAWonV.exe] . (. - PackageProvider.) -- C:\Program Files\Windows Defender\GC0CWWNC8EP\UX3LkAWonV.exe
O4 - HKUS\S-1-5-21-2852345370-3227221742-3801130228-1001\..\Run: [EUIPTVIHZU.exe] . (.Copyright - .) -- C:\Users\Florian\AppData\Roaming\b5bad02b55ff4beeb700f1889496acfa\EUIPTVIHZU.exe

---\\ PROCESSUS LANCÉS (45) - 8s
[MD5.E548929868BDFD3FC13B46D99605B764] - (. - HuaweiHiSuiteService.) -- C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [192200] [PID.4644] =>.Huawei Technologies Co.,Ltd
[MD5.7A67AEB4C77D30787B3BAC516A81F2B1] - (.Gold Click Ltd - PG Network Component.) -- C:\Program Files (x86)\ProxyGate\Cloud.exe [1503328] [PID.1752] =>.SUP.ProxyGate
[MD5.96C36729FFEEEE3B7BA7ADD80C4418F6] - (.Gold Click Ltd - PG Helper Process.) -- C:\Program Files (x86)\ProxyGate\PGChk.exe [1007200] [PID.15636] =>.SUP.ProxyGate
[MD5.17FB3CD8D63A676B76CD2EF2A8F5BA74] - (. - Network Packet Monitor.) -- C:\ProgramData\PrefsSecure\Nettrans.exe [43520] [PID.31656]
[MD5.DCF1FA8AD58C6264E1CF7605BE14E73E] - (. - TODO: .) -- C:\ProgramData\AppkohcatiP\AppkohcatiP.exe [1810944] [PID.19440] =>PUP.Optional.Salus
[MD5.E3964AC26BB069073100EABBD61D0DE6] - (. - ExtManager.) -- C:\ProgramData\Logic Cramble\set.exe [3780096] [PID.5160]
[MD5.6FF259D19E446CE736D2D9C1DA74C14E] - (.Cambridge Silicon Radio Limited - BtSwitcherService.) -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\BtSwitcherService.exe [64216] [PID.11804] =>.Cambridge Silicon Radio Ltd.®
[MD5.56CD42AC0A286A29804D5E938B76BC75] - (.Cambridge Silicon Radio Limited - Csr Bluetooth Service.) -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtService.exe [825032] [PID.9328] =>.Cambridge Silicon Radio Ltd.®
[MD5.21249D1C893CDA49C296727242109AD2] - (.Cambridge Silicon Radio Limited - Bluetooth OBEX Service.) -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtOBEXService.exe [1041616] [PID.11016] =>.Cambridge Silicon Radio Ltd.®
[MD5.F36B14E5DD31BC45028556768615BDCA] - (.Cambridge Silicon Radio Limited - CSR Bluetooth Audio Service.) -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtAudioService.exe [465624] [PID.4360] =>.Cambridge Silicon Radio Ltd.®
[MD5.25686DAED0DECA2A18A5A0F15A3FCF62] - (. - SanOo.) -- C:\Program Files (x86)\Photomaker\154816.exe [671232] [PID.28236]
[MD5.20839D696727CA2F1DA6F255D0A15BAC] - (.Cambridge Silicon Radio Limited - Csr HCRP Server.) -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrHCRPServer.exe [1134288] [PID.12704] =>.Cambridge Silicon Radio Ltd.®
[MD5.0AED0AB3A735655DCF804E9D2166E341] - (.Cambridge Silicon Radio Limited - CSR Headset Control.) -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrAudioguiCtrl.exe [511696] [PID.29832] =>.Cambridge Silicon Radio Ltd.®
[MD5.1676BD24F1C43E77487845D7EDE8E174] - (...) -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrSyncMLServer.exe [244944] [PID.27720] =>.Cambridge Silicon Radio Ltd.®
[MD5.B65CD168E1FD0A5D287F9297204CA209] - (.Cambridge Silicon Radio Limited - Csr Bluetooth OSD Settings.) -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\vksts.exe [25792] [PID.15852] =>.Cambridge Silicon Radio Ltd.®
[MD5.B701D1004DB34D8FB1DD1490E281CFBF] - (.Cambridge Silicon Radio Limited - Csr Harmony User Startup Application.) -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\HarmonyUserStartup.exe [39128] [PID.12116] =>.Cambridge Silicon Radio Ltd.®
[MD5.969BB83D34E0F15201576212C6938F6F] - (.Cambridge Silicon Radio Limited - Csr Bluetooth TrayApplication.) -- C:\Program Files\CSR\CSR Harmony Wireless Software Stack\TrayApplication.exe [529616] [PID.24140] =>.Cambridge Silicon Radio Ltd.®
[MD5.6C718849D436A7CCEBED72538F8BD04B] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe [288848] [PID.8588] =>.Google Inc®
[MD5.D2F56E366F1CB26866A6F43BD53B46C3] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe [366160] [PID.8624] =>.Google Inc®
[MD5.3C4C4F1AC7F4740271C1823C990B45E0] - (.Python Software Foundation - Python.) -- C:\Users\Florian\AppData\Roaming\LookupPro\python\python.exe [97440] [PID.27840] =>.Python Software Foundation®
[MD5.17DF9D26F1050D8AB309791990E136C0] - (...) -- C:\Users\Florian\AppData\Local\Temp\is-75Q43.tmp\pm_cgo.exe [84480] [PID.25092]
[MD5.7F76D8C32991E898AA95059EAF72345D] - (...) -- C:\Program Files\WinVPN\wpsvc.exe [12288] [PID.2776]
[MD5.17DF9D26F1050D8AB309791990E136C0] - (...) -- C:\Users\Florian\AppData\Local\Temp\is-BLB6N.tmp\pm_cgo.exe [84480] [PID.5660]
[MD5.4F2741CA11AA36FC3AA6EAC71167D1A9] - (...) -- C:\Program Files\WinVPN\inetdrv.exe [1180160] [PID.4888]
[MD5.BBF865B2B40FF6251425916A680FCDDC] - (.BitTorrent Inc. - µTorrent.) -- C:\Users\Florian\AppData\Roaming\uTorrent\uTorrent.exe [1987512] [PID.32040] =>.BitTorrent Inc®
[MD5.91C950BF8892F1B8C1E57DF0BD0FEADF] - (.BitTorrent Inc. - WebHelper.) -- C:\Users\Florian\AppData\Roaming\uTorrent\updates\3.5.3_44428\utorrentie.exe [398008] [PID.4560] =>.BitTorrent Inc®
[MD5.91C950BF8892F1B8C1E57DF0BD0FEADF] - (.BitTorrent Inc. - WebHelper.) -- C:\Users\Florian\AppData\Roaming\uTorrent\updates\3.5.3_44428\utorrentie.exe [398008] [PID.14824] =>.BitTorrent Inc®
[MD5.3C4C4F1AC7F4740271C1823C990B45E0] - (.Python Software Foundation - Python.) -- C:\Users\Florian\AppData\Roaming\LookupPro\python\python.exe [97440] [PID.20840] =>.Python Software Foundation®
[MD5.E1342CCC77FB35E21DD3E7CFE7BE0EEB] - (.Gold Click Ltd - PG Network Component.) -- C:\Program Files (x86)\ProxyGate\PGNet.exe [239712] [PID.31388] =>.SUP.ProxyGate
[MD5.77A89E5330F3432BA9E426E13EE78066] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1588568] [PID.11740] =>.Google Inc®
[MD5.77A89E5330F3432BA9E426E13EE78066] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1588568] [PID.29364] =>.Google Inc®
[MD5.77A89E5330F3432BA9E426E13EE78066] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1588568] [PID.13304] =>.Google Inc®
[MD5.77A89E5330F3432BA9E426E13EE78066] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1588568] [PID.336] =>.Google Inc®
[MD5.77A89E5330F3432BA9E426E13EE78066] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1588568] [PID.2748] =>.Google Inc®
[MD5.77A89E5330F3432BA9E426E13EE78066] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1588568] [PID.26100] =>.Google Inc®
[MD5.77A89E5330F3432BA9E426E13EE78066] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1588568] [PID.26804] =>.Google Inc®
[MD5.77A89E5330F3432BA9E426E13EE78066] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1588568] [PID.27952] =>.Google Inc®
[MD5.18F9ACFF3A6AF6F75D3C06773709A1DC] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Florian\AppData\Roaming\ZHP\ZHPDiag3.exe [3140480] [PID.29956] =>.Nicolas Coolman
[MD5.77A89E5330F3432BA9E426E13EE78066] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1588568] [PID.13904] =>.Google Inc®
[MD5.77A89E5330F3432BA9E426E13EE78066] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1588568] [PID.16916] =>.Google Inc®
[MD5.77A89E5330F3432BA9E426E13EE78066] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1588568] [PID.7092] =>.Google Inc®
[MD5.77A89E5330F3432BA9E426E13EE78066] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1588568] [PID.15056] =>.Google Inc®
[MD5.77A89E5330F3432BA9E426E13EE78066] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1588568] [PID.3344] =>.Google Inc®
[MD5.77A89E5330F3432BA9E426E13EE78066] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1588568] [PID.19840] =>.Google Inc®
[MD5.77A89E5330F3432BA9E426E13EE78066] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1588568] [PID.30620] =>.Google Inc®

---\\ CHROME, Démarrage, Recherche, Extensions (26) - 1s
G0 - GCSP: Preferences [User Data\Default][HomePage] http://185.148.147.134
G0 - GCSP: Preferences [User Data\Default][HomePage] http://apis.google.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://consent.google.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://fonts.googleapis.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://fonts.gstatic.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.gstatic.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google-analytics.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.fr =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.gstatic.com =>.Google Inc.
G2 - GCE: Preference [Florian][User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] =>.Google Inc. {Slides}
G2 - GCE: Preference [Florian][User Data\Default] [aohghmighlieiainnegkcijnfilokake] =>.Google Inc. {Docs}
G2 - GCE: Preference [Florian][User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] http://drive.google.com/ =>.Google Inc. {Drive}
G2 - GCE: Preference [Florian][User Data\Default] [bbfneagfdkkcpjojiigmahjplnbppkff] =>.profiappsplus {Deadpool}
G2 - GCE: Preference [Florian][User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] http://www.youtube.com =>.Youtube {Youtube}
G2 - GCE: Preference [Florian][User Data\Default] [cfhdojbkjhnklbpkdaibdccddilifddb] eyeo GmbH =>.eyeo GmbH {AdBlock Plus}
G2 - GCE: Preference [Florian][User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] =>.Google Inc. {Sheets}
G2 - GCE: Preference [Florian][User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] =>.Google Inc. {Docs hors connexion}
G2 - GCE: Preference [Florian][User Data\Default] [ghdonojphkbfhdccpohfhckojkpfanlg] Lookup Pro
G2 - GCE: Preference [Florian][User Data\Default] [hflefjhkfeiaignkclmphmokmmbhbhik] Adblock for Youtube =>.Better Adblock
G2 - GCE: Preference [Florian][User Data\Default] [iflggecoejbkaiaddimmikppllbhcmpo] Personal Browser
G2 - GCE: Preference [Florian][User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] =>.Google Inc. {Wallet}
G2 - GCE: Preference [Florian][User Data\Default] [ocinjdjondmhheihhgkbmjkofmomnppd] Wonderful Weather
G2 - GCE: Preference [Florian][User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] http://mail.google.com/ =>.Google Inc. {Gmail}
G2 - GCE: Preference [Florian][User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.
C:\Users\Florian\AppData\Local\Google\Chrome\User Data\Default\SystemTable =>.SUP.BrowserExtension

---\\ INTERNET EXPLORER,Démarrage,Recherche,URLSearchHook (20) - 1s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbrhojyn9_5edl73pvoaovybs0wallivdlfdiazfchib3p1jyqkwwagync6shhs1ii5iu7lxkv1q-_btslfrnwxxifrur5k2dw7fvf6b-u1nhcrcegpylexqv1ptczbo2ckqnvt1pxgp292dkedw2dsaw_40czto-4bp3hflhvb8zbzjiwvg9089vq8rzcc_g,,&q={searchterms} =>.SUP.Linkury
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbrhojyn9_5edl73pvoaovybs0wallivdlfdiazfchib3p1jyqkwwagync6shhs1ii5iu7lxkv1q-_btslfrnwxxifrur5k2dw7fvf6b-u1nhcrcegpylexqv1ptczbo2ckqnvt1pxgp292dkedw2dsaw_40czto-4bp3hflhvb8zbzjiwvg9089vq8rzcc_g,,&q={searchterms} =>.SUP.Linkury
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbrhojyn9_5edl73pvoaovybs0wallivdlfdiazfchib3p1jyqkwwagync6shhs1ii5iu7lxkv1q-_btslfrnwxxifrur5k2dw7fvf6b-u1nhcrcegpylexqv1ptczbo2ckqnvt1pxgp292dkedw2dsaw_40czto-4bp3hflhvb8zbzjiwvg9089vq8rzcc_g,,&q={searchterms} =>.SUP.Linkury
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbrhojyn9_5edl73pvoaovybs0wallivdlfdiazfchib3p1jyqkwwagync6shhs1ii5iu7lxkv1q-_btslfrnwxxifrur5k2dw7fvf6b-u1nhcrcegpylexqv1ptczbo2ckqnvt1pxgp292dkedw2dsaw_40czto-4bp3hflhvb8zbzjiwvg9089vq8rzcc_g,,&q={searchterms} =>.SUP.Linkury
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKEY_USERS\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbrhojyn9_5edl73pvoaovybs0wallivdlfdiazfchib3p1jyqkwwagync6shhs1ii5iu7lxkv1q-_btslfrnwxxifrur5k2dw7fvf6b-u1nhcrcegpylexqv1ptczbo2ckqnvt1pxgp292dkedw2dsaw_40czto-4bp3hflhvb8zbzjiwvg9089vq8rzcc_g,,&q={searchterms} =>.SUP.Linkury
R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.9600.17031 (winblue_gdr.140221-1952)) -- C:\Windows\System32\ieframe.dll =>.Microsoft Corporation
R4 - HKLM\Software\WOW6432Node\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 =>Default.Value

---\\ INTERNET EXPLORER, Site de confiance et site sensible (2) - 0s
~ Microsoft Internet Explorer Restricted Site(s) Domains: 0(Good) / 0(Bad)
~ Microsoft Internet Explorer Restricted Site(s) EscDomains: 0(Good) / 0(Bad)

---\\ INTERNET EXPLORER,Proxy Management (5) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\\ INTERNET EXPLORER,IniFiles, Autoloading Programs (3) - 0s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation

---\\ ÉTUDE DU FICHIER HOSTS (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (57)

---\\ BROWSER HELPER OBJECT DE NAVIGATEUR (BHO) (1) - 0s
O2 - BHO: YoutubeAdBlock [64Bits] - {C0D38E5A-7CF8-4105-8FE8-31B81443A114} . (...) -- C:\Program Files (x86)\lJFUJMGEHIE\tFH1Gsq.dll (.not file.) =>PUP.Optional.YouTubeAdBlock

---\\ RACCOURCIS GLOBAL STARTUP (58) - 3s
O4 - GS\Desktop [Administrateur]: Florian Laura.lnk . (...) C:\Users\Florian
O4 - GS\Desktop [Administrateur]: Recover My Files.lnk . (.GetData Pty Ltd - Undelete and recover lost files.) C:\Program Files (x86)\GetData\Recover My Files\RecoverMyFiles.exe =>.GetData Pty Ltd®
O4 - GS\Desktop [Administrateur]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Florian\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Administrateur]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Florian\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\Quicklaunch [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Administrateur]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Administrateur]: Recover My Files.lnk . (.GetData Pty Ltd - Undelete and recover lost files.) C:\Program Files (x86)\GetData\Recover My Files\RecoverMyFiles.exe =>.GetData Pty Ltd®
O4 - GS\Quicklaunch [Administrateur]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Florian\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [Administrateur]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrateur]: Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Programs [Administrateur]: Documents.lnk . (...) C:\Users\Florian\Documents
O4 - GS\Programs [Administrateur]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [Administrateur]: Pictures.lnk . (...) C:\Users\Florian\Pictures =>.Microsoft Corporation
O4 - GS\Desktop [Florian]: Florian Laura.lnk . (...) C:\Users\Florian
O4 - GS\Desktop [Florian]: Recover My Files.lnk . (.GetData Pty Ltd - Undelete and recover lost files.) C:\Program Files (x86)\GetData\Recover My Files\RecoverMyFiles.exe =>.GetData Pty Ltd®
O4 - GS\Desktop [Florian]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Florian\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Desktop [Florian]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Florian\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\Quicklaunch [Florian]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Florian]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Florian]: Recover My Files.lnk . (.GetData Pty Ltd - Undelete and recover lost files.) C:\Program Files (x86)\GetData\Recover My Files\RecoverMyFiles.exe =>.GetData Pty Ltd®
O4 - GS\Quicklaunch [Florian]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) C:\Users\Florian\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O4 - GS\sendTo [Florian]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Florian]: Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation
O4 - GS\TaskBar [Florian]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Programs [Florian]: Documents.lnk . (...) C:\Users\Florian\Documents
O4 - GS\Programs [Florian]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [Florian]: Pictures.lnk . (...) C:\Users\Florian\Pictures =>.Microsoft Corporation
O4 - GS\CommonDesktop [Public]: Betternet.lnk . (.Betternet Technologies Inc. - Betternet for Windows.) C:\Program Files (x86)\Betternet\4.1.1\Betternet.exe =>.BetterNet LLC®
O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --disable-quic =>.Google Inc®
O4 - GS\CommonDesktop [Public]: HiSuite.lnk . (.Huawei - Huawei PC suite.) C:\Program Files (x86)\HiSuite\HiSuite.exe =>.Huawei
O4 - GS\CommonDesktop [Public]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe =>.Skype Software Sarl®
O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe =>.VideoLAN®
O4 - GS\CommonDesktop [Public]: WinZip.lnk . (.WinZip Computing, S.L. - WinZip.) C:\Program Files (x86)\WinZip\WINZIP32.EXE =>.WinZip Computing®
O4 - GS\Programs [Public]: Documents.lnk . (...) C:\Users\Florian\Documents
O4 - GS\Programs [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [Public]: Pictures.lnk . (...) C:\Users\Florian\Pictures =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Bloc-notes.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Calculatrice de Windows.) C:\Windows\system32\calc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\Windows\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Connexion Bureau à distance.) C:\Windows\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Outil Capture d’écran.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Magnétophone Windows.) C:\Windows\system32\SoundRecorder.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Enregistreur d’actions.) C:\Windows\system32\psr.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - Pense-bête.) C:\Windows\system32\StikyNot.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Application Windows Wordpad.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: XPS Viewer.lnk . (.Microsoft Corporation - Visionneuse XPS.) C:\Windows\system32\xpsrchvw.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Table des caractères.) C:\Windows\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Camera.lnk . (.Microsoft Corporation - Camera.) C:\Windows\Camera\Camera.exe =>.Microsoft Windows®
O4 - GS\ProgramsCommon [Public]: FileManager.lnk . (.Microsoft Corporation - OneDrive.) C:\Windows\FileManager\FileManager.exe =>.Microsoft Windows®
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --disable-quic =>.Google Inc®
O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\Windows\System32\Control.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: PhotosApp.lnk . (.Microsoft Corporation - Photos.) C:\Windows\FileManager\PhotosApp.exe =>.Microsoft Windows®
O4 - GS\ProgramsCommon [Public]: Search.lnk . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) C:\Windows\system32\rundll32.exe -sta {C90FB8CA-3295-4462-A721-2935E83694BA} =>..Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Store.lnk . (...) C:\Windows\WinStore\WinStore.htm =>.Microsoft Corporation

---\\ MODIFICATION DOMAINE/ADRESSES (DNS) (4) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 8.8.8.8 =>.France Google Cloud
O17 - HKLM\System\CCS\Services\Tcpip\..\{6277B36A-90C3-497D-84AE-B016BEC68B3E}: DhcpNameServer = 8.8.8.8 =>.France Google Cloud
O17 - HKLM\System\CCS\Services\Tcpip\..\{A269EB54-833B-49E6-9179-34A6C21B6DF5}: DhcpNameServer = 192.168.1.254 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{A269EB54-833B-49E6-9179-34A6C21B6DF5}: DhcpDomain = lan =>.Local Domain

---\\ PROTOCOLE ADDITIONNEL (20) - 0s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation

---\\ REGISTRE AppInit_DLLs et Winlogon Notify (1) - 0s
O20 - Winlogon : UserInit . (.Microsoft Corporation - Application d’ouverture de session Userinit.) - C:\Windows\system32\userinit.exe =>.Microsoft Corporation

---\\ COMPOSANTS ACTIVESETUP INSTALLÉS (ASIC) (6) - 1s
O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Utilitaire d’installation du Lecteur Window.) -- C:\Windows\System32\unregmp2.exe =>.Microsoft Corporation
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll =>.Microsoft Corporation®
O40 - ASIC: Google Chrome [64Bits] - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (.Google Inc. - Google Chrome Installer.) -- C:\Program Files (x86)\Google\Chrome\Application\67.0.3396.87\Installer\chrmstp.exe =>.Google Inc®

---\\ LOGICIELS INSTALLÉS (14) - 8s
O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU][64Bits] -- uTorrent =>.BitTorrent Inc®
O42 - Logiciel: Betternet for Windows 4.1.1 - (.Betternet Technologies Inc..) [HKLM][64Bits] -- {2E77104D-96E1-4A9C-86F2-C7CF8C805999} =>.Betternet Technologies Inc.
O42 - Logiciel: CSR Harmony Wireless Software Stack - (.CSR Plc..) [HKLM][64Bits] -- {17DEA095-8EE1-49A2-AC5A-9663DB098FA9} =>.CSR Plc.
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome =>.Google Inc®
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: HiSuite - (.Huawei Technologies Co.,Ltd.) [HKLM][64Bits] -- Hi Suite =>.Huawei Technologies Co.,Ltd
O42 - Logiciel: Impaq Speed - (.Melasys LLC.) [HKCU][64Bits] -- {5b0c3e0d-0e9b-4ebd-a5de-222a48f16015} =>Adware.InstallCore
O42 - Logiciel: Recover My Files - (.GetData Pty Ltd.) [HKLM][64Bits] -- Recover My Files_is1 =>.GetData Pty Ltd
O42 - Logiciel: Skype version 8.23 - (.Skype Technologies S.A..) [HKLM][64Bits] -- Skype_is1 =>.Skype Software Sarl®
O42 - Logiciel: TAP-Windows 9.21.2 - (.OpenVPN Technologie.) [HKLM][64Bits] -- TAP-Windows =>.OpenVPN Technologie
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
O42 - Logiciel: WinVPN - (.WinSoft.) [HKLM][64Bits] -- {4BB9D57D-4603-4C82-B314-B7A7254F2AEE}
O42 - Logiciel: WinZip 15.0 - (.WinZip Computing, S.L..) [HKLM][64Bits] -- {CD95F661-A5C4-44F5-A6AA-ECDD91C240BE} =>.WinZip Computing, S.L.
O42 - Logiciel: YoutubeAdBlock - (.Company Inc..) [HKLM][64Bits] -- 1655C0CA-7AE7-4012-8502-970C8675E5F8 =>PUP.Optional.YouTubeAdBlock

---\\ CLÉ DE REGISTRE SOFTWARE HKCU & HKLM (81) - 8s
HKLM\SOFTWARE\Betternet =>.Betternet
HKLM\SOFTWARE\Google =>.Google
HKLM\SOFTWARE\Intel =>.Intel
HKLM\SOFTWARE\Licenses =>.Microsoft Corporation
HKLM\SOFTWARE\Macromedia =>.Macromedia
HKLM\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\mtAppkohcatiP =>PUP.Optional.Salus
HKLM\SOFTWARE\mtPitachok
HKLM\SOFTWARE\Nico Mak Computing =>.Nico Mak Computing
HKLM\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\ShmAddon =>PUP.Optional.ShopMania
HKLM\SOFTWARE\VideoLAN =>.VideoLAN
HKLM\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\Betternet =>.Betternet
HKLM\SOFTWARE\WOW6432Node\Google =>.Google
HKLM\SOFTWARE\WOW6432Node\Intel =>.Intel
HKLM\SOFTWARE\WOW6432Node\Licenses =>.Microsoft Corporation
HKLM\SOFTWARE\WOW6432Node\Macromedia =>.Macromedia
HKLM\SOFTWARE\WOW6432Node\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\WOW6432Node\mtAppkohcatiP =>PUP.Optional.Salus
HKLM\SOFTWARE\WOW6432Node\mtPitachok
HKLM\SOFTWARE\WOW6432Node\Nico Mak Computing =>.Nico Mak Computing
HKLM\SOFTWARE\WOW6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\WOW6432Node\ShmAddon =>PUP.Optional.ShopMania
HKLM\SOFTWARE\WOW6432Node\VideoLAN =>.VideoLAN
HKLM\SOFTWARE\WOW6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\Betternet =>.Betternet
HKCU\SOFTWARE\BitTorrent =>.BitTorrent (P2P)
HKCU\SOFTWARE\Cambridge Silicon Radio =>.Cambridge Silicon Radio
HKCU\SOFTWARE\Chrome
HKCU\SOFTWARE\FastDataX =>Adware.FastDataX
HKCU\SOFTWARE\GetData =>.GetData
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\Mine =>.Microsoft Corporation
HKCU\SOFTWARE\mtAppkohcatiP =>PUP.Optional.Salus
HKCU\SOFTWARE\NeoSoftTools
HKCU\SOFTWARE\Nico Mak Computing =>.Nico Mak Computing
HKCU\SOFTWARE\One System Care =>PUP.Optional.OneSystemCare
HKCU\SOFTWARE\Opera Stable Offer
HKCU\SOFTWARE\ProtectedStorage =>.Microsoft Corporation
HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\Rtp =>.RTP Software
HKCU\SOFTWARE\skype =>.Skype
HKCU\SOFTWARE\skypeapp-abae9a316370 =>.Skype Technologies
HKCU\SOFTWARE\System Healer =>.SUP.SystemHealer
HKCU\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation
HKCU\SOFTWARE\WinZip Computing =>.WinZip Computing
HKCU\SOFTWARE\WixSharp =>.Legitimate
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKU\.DEFAULT\SOFTWARE\Google =>.Google
HKU\.DEFAULT\SOFTWARE\Nico Mak Computing =>.Nico Mak Computing
HKU\.DEFAULT\SOFTWARE\WinZip Computing =>.WinZip Computing
HKU\.DEFAULT\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\Betternet =>.Betternet
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\BitTorrent =>.BitTorrent (P2P)
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\Cambridge Silicon Radio =>.Cambridge Silicon Radio
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\Chrome
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\FastDataX =>Adware.FastDataX
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\GetData =>.GetData
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\Google =>.Google
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\Mine =>.Microsoft Corporation
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\mtAppkohcatiP =>PUP.Optional.Salus
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\NeoSoftTools
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\Nico Mak Computing =>.Nico Mak Computing
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\One System Care =>PUP.Optional.OneSystemCare
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\Opera Stable Offer
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\ProtectedStorage =>.Microsoft Corporation
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\Rtp =>.RTP Software
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\skype =>.Skype
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\skypeapp-abae9a316370 =>.Skype Technologies
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\System Healer =>.SUP.SystemHealer
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\WinZip Computing =>.WinZip Computing
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\WixSharp =>.Legitimate
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKU\S-1-5-21-2852345370-3227221742-3801130228-1001\SOFTWARE\ZHP =>.Nicolas Coolman

---\\ CONTENU DES DOSSIERS PROGRAMMES (174) - 7s
O43 - CFD: 21/06/2018 - [] D -- C:\Program Files\A68YVP641U
O43 - CFD: 21/06/2018 - [] D -- C:\Program Files\BS36BF6LYR
O43 - CFD: 21/06/2018 - [] D -- C:\Program Files\CJLKC1WA87
O43 - CFD: 22/08/2013 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files\CSR =>.Cambridge Silicon Radio Ltd.®
O43 - CFD: 20/06/2018 - [0] SHD -- C:\Program Files\Fichiers communs =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 21/06/2018 - [] D -- C:\Program Files\K5EK4K02SU
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 21/06/2018 - [] D -- C:\Program Files\Q76PQ295XE
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files\TAP-Windows =>.OpenVPN Technologie
O43 - CFD: 21/06/2018 - [] D -- C:\Program Files\UBFVVBE537
O43 - CFD: 21/06/2018 - [] D -- C:\Program Files\UCQLE7BQPT
O43 - CFD: 21/06/2018 - [] D -- C:\Program Files\UMZ58KBNT0
O43 - CFD: 22/08/2013 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 21/06/2018 - [] D -- C:\Program Files\VJF9WPZ6QH
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] D -- C:\Program Files\Windows Journal =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] D -- C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [] SHD -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [] D -- C:\Program Files\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 21/06/2018 - [] D -- C:\Program Files\WinVPN
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files (x86)\Betternet =>.Betternet
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files (x86)\CSR =>.Cambridge Silicon Radio Ltd.®
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files (x86)\GetData =>.GetData Pty Ltd®
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files (x86)\Google =>.Google Inc®
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files (x86)\HiSuite =>.Huawei Technologies Co.,Ltd
O43 - CFD: 18/03/2014 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files (x86)\Microsoft =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files (x86)\Photomaker
O43 - CFD: 21/06/2018 - [] D -- C:\Program Files (x86)\ProxyGate =>.SUP.ProxyGate
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files (x86)\VideoLAN =>.VideoLan Team
O43 - CFD: 18/03/2014 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [] SHD -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\WindowsPowerShell =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files (x86)\WinZip =>.WinZip Computing®
O43 - CFD: 22/08/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 20/06/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Betternet Technologies Inc =>.Betternet
O43 - CFD: 20/06/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HiSuite =>.Huawei Technologies Co.,Ltd
O43 - CFD: 21/06/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lookup Pro
O43 - CFD: 22/08/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype =>.Skype
O43 - CFD: 22/08/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC =>.Wacom Technology
O43 - CFD: 20/06/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team
O43 - CFD: 20/06/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip =>.WinZip
O43 - CFD: 21/06/2018 - [] D -- C:\ProgramData\90c4947b00d946f49849e78cf1dcc0ea =>Adware.Suspect
O43 - CFD: 21/06/2018 - [] D -- C:\ProgramData\AppkohcatiP =>PUP.Optional.Salus
O43 - CFD: 20/06/2018 - [] D -- C:\ProgramData\AppkohcatiPs =>PUP.Optional.Salus
O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 21/06/2018 - [] D -- C:\ProgramData\b0e9e8f65cf94fc1a22d56c1f164b4a8 =>Adware.Suspect
O43 - CFD: 21/06/2018 - [] D -- C:\ProgramData\Betternet =>.Betternet
O43 - CFD: 20/06/2018 - [0] SHD -- C:\ProgramData\Bureau =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\ProgramData\Logic Cramble =>PUP.Optional.LogicHandler
O43 - CFD: 20/06/2018 - [0] SHD -- C:\ProgramData\Menu Démarrer =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [0] SHD -- C:\ProgramData\Modèles =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\ProgramData\Pitachoks
O43 - CFD: 20/06/2018 - [] D -- C:\ProgramData\PrefsSecure =>PUP.Optional.LogicHandler
O43 - CFD: 18/03/2014 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [0] AD -- C:\ProgramData\TEMP =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\ProgramData\WinZip =>.WinZip
O43 - CFD: 21/06/2018 - [] D -- C:\ProgramData\XjOPTLXDzAynQaVB
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files (x86)\Common Files\FaseRon
O43 - CFD: 18/03/2014 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Program Files (x86)\Common Files\Skype =>.Skype
O43 - CFD: 18/03/2014 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 21/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\0hokcdgtzqg
O43 - CFD: 20/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\0nu0kr3c3vl
O43 - CFD: 21/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\13fvplpqi0t
O43 - CFD: 21/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\1foqcrtwcnb
O43 - CFD: 21/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\1hvzmz3vlnw
O43 - CFD: 20/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\1jwl0hd0g0e
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 21/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\b5bad02b55ff4beeb700f1889496acfa
O43 - CFD: 20/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\cgozarsdnxn
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\FastDataX =>Adware.FastDataX
O43 - CFD: 21/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\fyfv4mbjtp3
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\Google =>.Google
O43 - CFD: 21/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\iox5mtnv3om
O43 - CFD: 21/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\LookupPro =>Adware.LookupPro
O43 - CFD: 21/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\lyv54h5pvuj
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 21/06/2018 - [] SD -- C:\Users\Florian\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 20/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\nex5fht4zpv
O43 - CFD: 20/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\o215f4jxcte
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\OneSystemCare =>PUP.Optional.OneSystemCare
O43 - CFD: 21/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\p0aonvjwycv
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\Python =>.Python
O43 - CFD: 20/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\qbgtdmmjflm
O43 - CFD: 21/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\qnc01x3l0ok
O43 - CFD: 20/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\sethmt5t1ah
O43 - CFD: 20/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\ShopMore
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\Skype =>.Skype
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\SystemHealer =>.SUP.SystemHealer
O43 - CFD: 20/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\uba1trtnqlu
O43 - CFD: 21/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\uTorrent
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\vlc =>.VideoLan Team
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\WidModule
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\ww.fm
O43 - CFD: 21/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\xyiryyf5q4f
O43 - CFD: 21/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 20/06/2018 - [0] D -- C:\Users\Florian\AppData\Roaming\ztkozkh2uno
O43 - CFD: 20/06/2018 - [0] SHD -- C:\Users\Florian\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Local\Apps =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Local\betterworld =>Adware.ExtenBro
O43 - CFD: 20/06/2018 - [0] D -- C:\Users\Florian\AppData\Local\Deployment =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] SHD -- C:\Users\Florian\AppData\Local\EmieSiteList =>.Enterprise mode Site List Mgr
O43 - CFD: 20/06/2018 - [] SHD -- C:\Users\Florian\AppData\Local\EmieUserList =>.Enterprise mode Site List Mgr
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Local\Google =>.Google
O43 - CFD: 20/06/2018 - [0] SHD -- C:\Users\Florian\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Local\Hisuite =>.Huawei Technologies Co.,Ltd
O43 - CFD: 21/06/2018 - [] D -- C:\Users\Florian\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Local\Package Cache =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Local\Packages =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 21/06/2018 - [] D -- C:\Users\Florian\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [0] SHD -- C:\Users\Florian\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [0] D -- C:\Users\Florian\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Local\Windows
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Local\WinZip =>.WinZip
O43 - CFD: 21/06/2018 - [] D -- C:\Users\Florian\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 20/06/2018 - [0] D -- C:\Users\Florian\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [0] D -- C:\Users\Florian\AppData\LocalLow\BitTorrent
O43 - CFD: 20/06/2018 - [] SHD -- C:\Users\Florian\AppData\LocalLow\EmieSiteList =>.Enterprise mode Site List Mgr
O43 - CFD: 20/06/2018 - [] SHD -- C:\Users\Florian\AppData\LocalLow\EmieUserList =>.Enterprise mode Site List Mgr
O43 - CFD: 20/06/2018 - [] SD -- C:\Users\Florian\AppData\LocalLow\Microsoft =>.Microsoft Corporation
O43 - CFD: 21/06/2018 - [] D -- C:\Users\Florian\AppData\LocalLow\uTorrent
O43 - CFD: 18/03/2014 - [] RD -- C:\Users\Florian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [] RD -- C:\Users\Florian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] RD -- C:\Users\Florian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 22/08/2013 - [] D -- C:\Users\Florian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Users\Florian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recover My Files =>.GetData
O43 - CFD: 20/06/2018 - [] RD -- C:\Users\Florian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] RD -- C:\Users\Florian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [0] SHD -- C:\Users\Default\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [0] SHD -- C:\Users\Default User\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 18/03/2014 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 20/06/2018 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation

---\\ DERNIERS FICHIERS CRÉÉS DANS WINDOWS Prefetcher (28) - 12s
O45 - LFCP:[MD5.10D0A2C44D8A5594AFE25B44BAC5B0B5] 21/06/2018 A -- C:\Windows\Prefetch\IMPAQSPEED_1.0.2.0.EXE-CA53DA51.pf =>Adware.InstallCore
O45 - LFCP:[MD5.9DC349540C2BE1F323C533BD835B8B7F] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.EXE-4BF9FF7C.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.3E54ADAF057B86FC4F400ED19F9B0FAF] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.EXE-550CDBA4.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.8D9A0C15E6D1A0395D9B9EE1AEC6B80C] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.EXE-69FA0A90.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.1DE3DFD085EBAAC0E81851AD2A270660] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.EXE-83299098.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.E1BFE74BE524CCD1806EBE70950D05FC] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.EXE-A66C6072.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.FA950699D5A63219DB47871A34F863D9] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.EXE-AAC4780F.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.37EB4B0D3F1D411F8D35238D8057EA34] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.EXE-B74ED833.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.835920DB6BF90030F73140277F6D4099] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.EXE-F49357A0.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.3477D486C1523759284CFCD11BBA17D3] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.EXE-F6D575F7.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.F2BDDA15007BB5BD6A23F5CCAF7F44DB] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-118D8BB3.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.24A3DD21BB96036435D15DE3B20B530D] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-18D36BB8.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.9E71E200181659335938258DA6E97077] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-4A58E216.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.C4B36FF3D22F22FCF15683EDC340B9E9] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-510751CB.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.2D3BABB0063A7222C928258FB98D6212] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-643884EE.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.24813C78C232A70BCEF47D572C666174] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-6DF70715.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.FC6616CA5706084D85DAE0757EEC58E4] 20/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-8CFB8DA5.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.8C1F0B273937E5F99AEC94F568866FFB] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-8E5B1348.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.F8BEBC1E5E7E371F333B4F622E69622D] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-9BF9353C.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.95A4A6ECBF06C0F9C494907FB2D95908] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-A1E128A3.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.70902040F00DA08EFA2F5C3675794468] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-AC3CEDDA.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.4982EA0CF3B3F4A8522F4E889BFA1BC3] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-AFE5A855.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.05780084EAA74059DDA6FE5B8B20BC05] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-CCBB7FDC.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.221D93E137F3B18D89EAC6850DC62F1C] 20/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-D5FFCD01.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.56D2E61AEB19BE2EB56F26F6BC80A11B] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-DA3790F6.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.27FA54E1F633C59241EA77CC760440F8] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-E30F2A26.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.39E3DFCE1153C68970F256B9EF846026] 21/06/2018 A -- C:\Windows\Prefetch\ONESYSTEMCARE.TMP-EA931F32.pf =>PUP.Optional.OneSystemCare
O45 - LFCP:[MD5.CF32BBF028500B6481E57E509912B465] 21/06/2018 A -- C:\Windows\Prefetch\SOCIAL2SEARCH.EXE-91BF8AAC.pf =>PUP.Optional.Wajam

---\\ ShellIconOverlayIdentifiers (SIOI) (1) - 1s
O106 - SIOI: [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - DLL d’extension d’environnement de stockage.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation

---\\ RACCOURCIS DES MENUS CONCEPTUELS (SCMH) (22) - 2s
O108 - CMH1: BriefcaseMenu [64Bits] - {85BBD920-42A0-1069-A2E4-08002B30309D} . (.Microsoft Corporation - Porte-documents Windows.) -- C:\Windows\System32\syncui.dll =>.Microsoft Corporation
O108 - CMH1: Open With [64Bits] - {09799AFB-AD67-11d1-ABCD-00C04FC30936} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH1: Open With EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH1: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH1: WinZip [64Bits] - {E0D79304-84BE-11CE-9641-444553540000} . (.WinZip Computing, S.L. - WinZip Shell Extension DLL.) -- C:\Program Files (x86)\WinZip\WZSHLS64.DLL =>.WinZip Computing®
O108 - CMH1: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extension d’environnement de Dossiers de tr.) -- C:\Windows\System32\WorkfoldersShell.dll =>.Microsoft Corporation
O108 - CMH2: OpenContainingFolderMenu [64Bits] - {37ea3a21-7493-4208-a011-7f9ea79ce9f5} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH3: CopyAsPathMenu [64Bits] - {f3d06e7c-1e45-4a26-847e-f9fcdee59be0} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH3: SendTo [64Bits] - {7BA4C740-9E81-11CF-99D3-00AA004AE837} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH4: EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH4: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH4: WinZip [64Bits] - {E0D79304-84BE-11CE-9641-444553540000} . (.WinZip Computing, S.L. - WinZip Shell Extension DLL.) -- C:\Program Files (x86)\WinZip\WZSHLS64.DLL =>.WinZip Computing®
O108 - CMH4: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extension d’environnement de Dossiers de tr.) -- C:\Windows\System32\WorkfoldersShell.dll =>.Microsoft Corporation
O108 - CMH5: New [64Bits] - {D969A300-E7FF-11d0-A93B-00A0C90F2719} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH5: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH5: WorkFolders [64Bits] - {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} . (.Microsoft Corporation - Extension d’environnement de Dossiers de tr.) -- C:\Windows\System32\WorkfoldersShell.dll =>.Microsoft Corporation
O108 - CMH6: BriefcaseMenu [64Bits] - {85BBD920-42A0-1069-A2E4-08002B30309D} . (.Microsoft Corporation - Porte-documents Windows.) -- C:\Windows\System32\syncui.dll =>.Microsoft Corporation
O108 - CMH6: Library Location [64Bits] - {3dad6c5d-2167-4cae-9914-f99e41c12cfa} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH6: PintoStartScreen [64Bits] - {470C0EBD-5D73-4d58-9CED-E91E22E23282} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Windows®
O108 - CMH6: WinZip [64Bits] - {E0D79304-84BE-11CE-9641-444553540000} . (.WinZip Computing, S.L. - WinZip Shell Extension DLL.) -- C:\Program Files (x86)\WinZip\WZSHLS64.DLL =>.WinZip Computing®
O108 - CMH7: EnhancedStorageShell [64Bits] - {2854F705-3548-414C-A113-93E27C808C85} . (.Microsoft Corporation - DLL d’extension d’environnement de stockage.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O108 - CMH7: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation

---\\ IMAGE FILE EXECUTION OPTIONS (IFEO) (16) - 0s
O50 - IFEO:C:\Windows\System32\cscript.exe - (.Microsoft Corporation - Microsoft ® Console Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\dllhost.exe - (.Microsoft Corporation - COM Surrogate.) [DisableExceptionChainValidation\\3] =>.Microsoft Windows®
O50 - IFEO:C:\Windows\System32\drvinst.exe - (.Microsoft Corporation - Module d’installation de pilotes.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ie4uinit.exe - (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - Outil d’installation sans assistance d’IE 7.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mmc.exe - (.Microsoft Corporation - Microsoft Management Console.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Hôte des applications HTML de Microsoft(R).) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\PresentationHost.exe - (.Microsoft Corporation - Windows Presentation Foundation Host.) [MitigationOptions\\1118481] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\PrintIsolationHost.exe - (.Microsoft Corporation - PrintIsolationHost.) [MitigationOptions\\2097152] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\rundll32.exe - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\runtimebroker.exe - (.Microsoft Corporation - Runtime Broker.) [MitigationOptions\\4294967296] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\searchprotocolhost.exe - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\spoolsv.exe - (.Microsoft Corporation - Application sous-système spouleur.) [MitigationOptions\\2097152] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\spoolsv.exe - (.Microsoft Corporation - Application sous-système spouleur.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\wscript.exe - (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) [DisableExceptionChainValidation\\3] =>.Microsoft Corporation

---\\ LISTE DES PILOTES DU SYSTÈME (44) - 6s
O58 - SDL:2013/08/22 14:43:41 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\drivers\3ware.sys [108896] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:41 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\Windows\System32\drivers\adp80xx.sys [782176] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:41 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [79200] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:41 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [259424] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:40 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [25952] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:41 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [114016] =>.Microsoft Windows®
O58 - SDL:2013/08/13 01:25:46 A . (. - BCM Function 2 Device Driver.) -- C:\Windows\System32\drivers\bcmfn2.sys [17624] =>.Broadcom Corporation®
O58 - SDL:2013/08/22 14:43:41 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [531296] =>.Microsoft Windows®
O58 - SDL:2012/03/22 21:08:22 A . (.Cambridge Silicon Radio Limited - Csr Bluetooth Port Driver.) -- C:\Windows\System32\drivers\CsrBtPort.sys [2784968] =>.Cambridge Silicon Radio Ltd.®
O58 - SDL:2012/03/22 21:08:30 A . (.Cambridge Silicon Radio Limited - Csr Bluetooth PANU Driver.) -- C:\Windows\System32\drivers\csrpan.sys [39616] =>.Cambridge Silicon Radio Ltd.®
O58 - SDL:2012/03/22 21:08:32 A . (.Cambridge Silicon Radio Limited - Csr Bluetooth Serial Port Driver.) -- C:\Windows\System32\drivers\csrserial.sys [61128] =>.Cambridge Silicon Radio Ltd.®
O58 - SDL:2012/03/22 21:08:34 A . (.Cambridge Silicon Radio Limited - Csr Bluetooth USB Driver.) -- C:\Windows\System32\drivers\csrusb.sys [47296] =>.Cambridge Silicon Radio Ltd.®
O58 - SDL:2012/03/22 21:08:36 A . (.Cambridge Silicon Radio Limited - Csr Bluetooth USB Driver filter.) -- C:\Windows\System32\drivers\csrusbfilter.sys [23752] =>.Cambridge Silicon Radio Ltd.®
O58 - SDL:2013/08/22 14:43:45 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3357024] =>.Microsoft Windows®
O58 - SDL:2017/07/26 09:58:28 A . (.Huawei Technologies Co., Ltd. - Filter Driver.) -- C:\Windows\System32\drivers\ew_usbccgpfilter.sys [18944] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2013/08/22 14:43:45 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [64352] =>.Microsoft Windows®
O58 - SDL:2017/07/26 09:58:28 A . (.Huawei Technologies Co., Ltd. - ew_cdcacm Driver.) -- C:\Windows\System32\drivers\hw_cdcacm.sys [127360] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2017/07/26 09:58:28 A . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\Windows\System32\drivers\hw_quusbmdm.sys [226560] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2017/07/26 09:58:28 A . (.Huawei Technologies Co., Ltd. - USB NDIS Miniport Driver.) -- C:\Windows\System32\drivers\hw_quusbnet.sys [287232] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2017/07/26 09:58:28 A . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\Windows\System32\drivers\hw_usbdev.sys [116864] =>.Huawei Technologies Co., Ltd.
O58 - SDL:2013/07/30 20:47:35 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568] =>.Intel Corporation - Software and Firmware Products®
O58 - SDL:2013/07/25 21:05:39 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320] =>.Intel Corporation - Software and Firmware Products®
O58 - SDL:2013/08/10 02:39:30 A . (.Intel Corporation - Intel Rapid Storage Technology driver (inbo.) -- C:\Windows\System32\drivers\iaStorAV.sys [651248] =>.Intel Corporation - Intel® Rapid Storage Technology®
O58 - SDL:2013/08/22 14:43:45 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [412000] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:44 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [109408] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [93536] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:44 A . (.LSI Corporation - LSI SAS Gen3 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas3.sys [81760] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sss.sys [82784] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [56672] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:45 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\megasr.sys [575840] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:49 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\Windows\System32\drivers\mvumis.sys [63840] =>.Microsoft Windows®
O58 - SDL:2013/06/18 20:30:32 A . (.Ralink Technology Corp. - Ralink 802.11n Wireless Adapter Driver.) -- C:\Windows\System32\drivers\netr28ux.sys [2408208] =>.Mediatek Inc.®
O58 - SDL:2013/08/22 14:43:31 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [150368] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:32 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [168288] =>.Microsoft Windows®
O58 - SDL:2018/06/11 08:16:40 A . (...) -- C:\Windows\System32\drivers\prisafe.sys [120944] =>PUP.Optional.FAssistant
O58 - SDL:2013/06/18 16:46:17 A . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.30 64-bit Dr.) -- C:\Windows\System32\drivers\Rt630x64.sys [591360] =>.Realtek
O58 - SDL:2013/08/22 17:35:09 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] =>.Rovi Corporation
O58 - SDL:2013/08/22 14:43:31 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [44896] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:32 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [81760] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:32 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\Windows\System32\drivers\stexstor.sys [31072] =>.Microsoft Windows®
O58 - SDL:2016/04/21 11:10:04 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\Windows\System32\drivers\tap0901.sys [27136] =>.The OpenVPN Project
O58 - SDL:2013/08/22 14:43:34 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [19808] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:34 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [168800] =>.Microsoft Windows®
O58 - SDL:2013/08/22 14:43:34 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\Windows\System32\drivers\VSTXRAID.SYS [305504] =>.Microsoft Windows®

---\\ DERNIERS FICHIERS MODIFIÉS OU CRÉÉS (Utilisateur) (15) - 132s
O61 - LFC: 2018/06/20 19:17:23 A . (..) -- C:\ProgramData\AppkohcatiP\Alphawarm.dll [460800] =>PUP.Optional.Salus
O61 - LFC: 2018/06/20 19:04:09 A . (..) -- C:\ProgramData\AppkohcatiP\AppkohcatiP.exe [1810944] =>PUP.Optional.Salus
O61 - LFC: 2018/06/20 19:17:23 A . (..) -- C:\ProgramData\AppkohcatiP\Bamfax.exe [149504] =>PUP.Optional.Salus
O61 - LFC: 2018/06/20 19:17:23 A . (..) -- C:\ProgramData\AppkohcatiP\Toucheco.exe [114688] =>PUP.Optional.Salus
O61 - LFC: 2018/06/20 19:17:23 A . (..) -- C:\ProgramData\AppkohcatiP\Zoting.dll [342528] =>PUP.Optional.Salus
O61 - LFC: 2018/06/20 19:08:44 A . (..) -- C:\ProgramData\Logic Cramble\set.exe [3780096]
O61 - LFC: 2018/06/20 19:16:57 A . (..) -- C:\ProgramData\PrefsSecure\crambo.exe [3872331]
O61 - LFC: 2018/06/20 18:37:14 A . (..) -- C:\ProgramData\PrefsSecure\Nettrans.exe [43520]
O61 - LFC: 2018/06/20 19:29:57 N . (.Melasys LLC.) -- C:\Users\Florian\AppData\Local\Package Cache\{5b0c3e0d-0e9b-4ebd-a5de-222a48f16015}\qtspeedtest.exe [569456] =>Adware.InstallCore
O61 - LFC: 2018/06/21 00:08:00 A . (.Melasys LLC.) -- C:\Users\Florian\AppData\Local\Temp\a3xbi3ebnm2\impaqspeed_1.0.2.0.exe [6490224] =>Adware.InstallCore
O61 - LFC: 2018/06/21 00:37:38 A . (.Melasys LLC.) -- C:\Users\Florian\AppData\Local\Temp\fqlwexkty2d\impaqspeed_1.0.2.0.exe [6490224] =>Adware.InstallCore
O61 - LFC: 2018/06/20 19:29:57 A . (.Melasys LLC.) -- C:\Users\Florian\AppData\Local\Temp\sdq03vdtblx\impaqspeed_1.0.2.0.exe [6490224] =>Adware.InstallCore
O61 - LFC: 2018/06/20 19:05:00 A . (..) -- C:\Users\Florian\AppData\Local\Villa-Tam.exe [1810944]
O61 - LFC: 2018/06/20 19:49:09 A . (.Copyright.) -- C:\Users\Florian\AppData\Roaming\b5bad02b55ff4beeb700f1889496acfa\EUIPTVIHZU.exe [576512]
O61 - LFC: 2018/06/15 13:05:34 A . (..) -- C:\Users\Florian\AppData\Roaming\ww.fm\ww.exe [1369075]

---\\ ASSOCIATION Shell Spawning (10) - 0s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (...) -- C:\Windows\System32\WScript.exe "%1" %* =>.Default.Value
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S =>.Default.Value

---\\ MENU DE DÉMARRAGE INTERNET (8) - 0s
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O68 - StartMenuInternet: [64Bits][HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

---\\ RECHERCHE D'INFECTION SUR LES NAVIGATEURS (3) - 0s
O69 - SBI: SearchScopes [HKCU] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKCU] [64Bits]{ielnksrch} - (Search the web) - http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRHOjYN9_5EdL73pVoaOVYBS0WaLlIVdlfDIAZFCHIB3p1JYQKwwAGyNC6SHHs1iI5IU7lXKv1q-_btsLFrnWXXifRur5K2DW7FvF6b-U1nhCRcEgpYLexQV1pTcZBo2Ckqnvt1pxGp292DkEDw2dsaW_40CZto-4BP3HfLhVb8zBZjiwVG9089VQ8rzcc_g,,&q={searchTerms} =>.SUP.Linkury
O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com

---\\ ÉNUMÈRE LES SERVICES DÉMARRÉS PAR Svchost (34) - 1s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [208896] =>.Microsoft Corporation
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [155136] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [155136] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [324608] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [1311744] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\IKEEXT.DLL [1104384] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [903168] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\System32\seclogon.dll [30720] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [109568] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [150528] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [107008] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1214976] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [220672] =>.Microsoft Corporation
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\System32\mmcss.dll [70656] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [134144] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [220160] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [326656] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [81408] =>.Microsoft Corporation
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\KMSVC.DLL [97792] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [339456] =>.Microsoft Corporation
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service d’infrastructure de localisation Wi.) -- C:\Windows\System32\GeofenceMonitorService.dll [491520] =>.Microsoft Corporation
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\Windows\System32\wlidsvc.dll [1576960] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [50688] =>.Microsoft Corporation
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\Windows\System32\DeviceSetupManager.dll [201728] =>.Microsoft Corporation
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\Windows\System32\NcaSvc.dll [164352] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [101376] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\Windows\System32\rasmans.dll [534528] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [223744] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [71680] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [433664] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [306688] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\System32\wuaueng.dll [3408384] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [1017856] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [629760] =>.Microsoft Corporation

---\\ LISTE DES EXCEPTIONS DU PAREFEU WINDOWS (6) - 2s
O87 - FAEL: "{E774D172-BCC9-4E18-B180-462559A52227}" [In-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Florian\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O87 - FAEL: "{8F8E0ACA-4B2C-4910-9DDA-15A9E72EF8F7}" [Out-None-P6-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Florian\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O87 - FAEL: "{2EAB633E-7693-4242-A36E-51313D57B7AB}" [In-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Florian\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O87 - FAEL: "{C481174C-D705-42CB-9440-A2B7B4E5B2AF}" [Out-None-P17-TRUE] .(.BitTorrent Inc. - µTorrent.) -- C:\Users\Florian\AppData\Roaming\uTorrent\uTorrent.exe =>.BitTorrent Inc®
O87 - FAEL: "{48E87236-77AA-4889-987C-C04633A46243}" [In-None-P6-TRUE] .(...) -- C:\Users\Florian\AppData\Roaming\BitTorrent\BitTorrent.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{FABDE273-AA25-4E0B-A13F-5F34327165CA}" [In-None-P17-TRUE] .(...) -- C:\Users\Florian\AppData\Roaming\BitTorrent\BitTorrent.exe (.not file.) =>.SUP.Orphan

---\\ CODES PRODUITS LOGICIELS (5) - 0s
O90 - PUC: "166F59DC4C5A5F446AAACEDD192C04EB" [HKLM] . (.WinZip 15.0.)
O90 - PUC: "590AED711EE82A94CAA56936BD90F89A" [HKLM] . (.CSR Harmony Wireless Software Stack.) -- C:\Windows\Installer\{17DEA095-8EE1-49A2-AC5A-9663DB098FA9}\ARPPRODUCTICON.exe
O90 - PUC: "A089CE062ADB6BC44A720BA745894BAC" [HKLM] . (.Google Update Helper.) =>.Google Inc.
O90 - PUC: "D40177E21E69C9A4682F7CFCC8089599" [HKLM] . (.Betternet for Windows 4.1.1.) -- C:\Windows\Installer\{2E77104D-96E1-4A9C-86F2-C7CF8C805999}\app_icon.ico =>.Betternet
O90 - PUC: "D75D9BB4306428C43B417B7A52F4A2EE" [HKLM] . (.WinVPN.)

---\\ PACKAGES WINDOWS INSTALLER (5) - 2s
[MD5.9E6E9CDD3853578BEEDDCCB10F174911] [WIS][2018/06/21 00:06:52] (.WinSoft - WinVPN 2.0 Installer.) -- C:\Windows\Installer\1b9c591.msi [2162688]
[MD5.20FCA470F5D11797F3EC9AF5584A8D9F] [WIS][2010/10/29 15:00:00] (.Copyright (c) 1991-2010 WinZip International LLC - All Rights Reserved - WinZip Compression Utility.) -- C:\Windows\Installer\3e7851.msi [13153280]
[MD5.7E57B1876A57979197D23A22CECED5E5] [WIS][2018/06/20 17:33:00] (.Betternet Technologies Inc. - Betternet for Windows 4.1.1.) -- C:\Windows\Installer\52adc7.msi [12636160] =>.Betternet Technologies Inc.
[MD5.50EA7A4D9481B12A97070942F474D918] [WIS][2018/06/20 17:53:59] (.Google Inc. - Google Update Helper.) -- C:\Windows\Installer\6a94ff.msi [40960] =>.Google Inc.
[MD5.4EFFB94BBC6324D72ADA023104DCA829] [WIS][2018/06/20 19:57:25] (.Cambridge Silicon Radio Limited. - CSR Bluetooth Stack.) -- C:\Windows\Installer\d726ce.msi [176445952] =>.Cambridge Silicon Radio Limited.

---\\ FEATURE CONTROLE. (128) - 0s
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL]:WindowsAnytimeUpgradeUI.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:infopath.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLOGON.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLgPad.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGuiIT.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPfewgsrv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:Scale_for_R3.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGUI.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:ieuser.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK]:YahooMusicEngine.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOCUMENT_COMPATIBLE_MODE]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:helppane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:devenv.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:dexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS]:msfeedssync.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PROLOG]:msiexec.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:wm.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:cs.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:waol.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPARAMS]:helppane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS]:wlmail.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:sidebar.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:outlook.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING]:communicator.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:winmail.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msimn.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:winmail.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:msimn.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:outlook.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:infopath.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:winword.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:excel.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:powerpnt.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VIEWLINKEDWEBOC_IS_UNSAFE]:HelpPane.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD]:msn.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:PresentationHost.exe =>.Legitimate

---\\ SCAN ADDITIONNEL (56) - 7s
HKLM\SYSTEM\CurrentControlSet\Services\AppkohcatiP =>PUP.Optional.Salus
C:\ProgramData\AppkohcatiP\AppkohcatiP.exe =>PUP.Optional.Salus
HKLM\SYSTEM\CurrentControlSet\Services\backlh =>PUP.Optional.LogicHandler
C:\ProgramData\Logic Cramble\set.exe =>PUP.Optional.LogicHandler
HKLM\SYSTEM\CurrentControlSet\Services\Nettrans =>PUP.Optional.LogicHandler
C:\ProgramData\PrefsSecure\Nettrans.exe =>PUP.Optional.LogicHandler
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0D38E5A-7CF8-4105-8FE8-31B81443A114} =>PUP.Optional.YouTubeAdBlock
HKLM\Software\WOW6432Node\Classes\CLSID\{C0D38E5A-7CF8-4105-8FE8-31B81443A114} =>PUP.Optional.YouTubeAdBlock
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C0D38E5A-7CF8-4105-8FE8-31B81443A114} =>PUP.Optional.YouTubeAdBlock
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1655C0CA-7AE7-4012-8502-970C8675E5F8 =>PUP.Optional.YouTubeAdBlock
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\1655C0CA-7AE7-4012-8502-970C8675E5F8 =>PUP.Optional.YouTubeAdBlock
C:\ProgramData\90c4947b00d946f49849e78cf1dcc0ea =>Adware.Suspect
C:\ProgramData\AppkohcatiP =>PUP.Optional.Salus
C:\ProgramData\AppkohcatiPs =>PUP.Optional.Salus
C:\ProgramData\b0e9e8f65cf94fc1a22d56c1f164b4a8 =>Adware.Suspect
C:\ProgramData\Logic Cramble =>PUP.Optional.LogicHandler
C:\ProgramData\PrefsSecure =>PUP.Optional.LogicHandler
C:\Users\Florian\AppData\Roaming\FastDataX =>Adware.FastDataX
C:\Users\Florian\AppData\Roaming\LookupPro =>Adware.LookupPro
C:\Users\Florian\AppData\Roaming\OneSystemCare =>PUP.Optional.OneSystemCare
C:\Users\Florian\AppData\Roaming\SystemHealer =>.SUP.SystemHealer
C:\Users\Florian\AppData\Local\betterworld =>Adware.ExtenBro
C:\Windows\Prefetch\IMPAQSPEED_1.0.2.0.EXE-CA53DA51.pf =>Adware.InstallCore
C:\Windows\Prefetch\ONESYSTEMCARE.EXE-4BF9FF7C.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.EXE-550CDBA4.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.EXE-69FA0A90.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.EXE-83299098.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.EXE-A66C6072.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.EXE-AAC4780F.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.EXE-B74ED833.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.EXE-F49357A0.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.EXE-F6D575F7.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-118D8BB3.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-18D36BB8.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-4A58E216.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-510751CB.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-643884EE.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-6DF70715.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-8CFB8DA5.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-8E5B1348.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-9BF9353C.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-A1E128A3.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-AC3CEDDA.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-AFE5A855.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-CCBB7FDC.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-D5FFCD01.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-DA3790F6.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-E30F2A26.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\ONESYSTEMCARE.TMP-EA931F32.pf =>PUP.Optional.OneSystemCare
C:\Windows\Prefetch\SOCIAL2SEARCH.EXE-91BF8AAC.pf =>PUP.Optional.Wajam
C:\Windows\System32\drivers\prisafe.sys =>PUP.Optional.FAssistant
C:\ProgramData\AppkohcatiP\Alphawarm.dll =>PUP.Optional.Salus
C:\ProgramData\AppkohcatiP\Bamfax.exe =>PUP.Optional.Salus
C:\ProgramData\AppkohcatiP\Toucheco.exe =>PUP.Optional.Salus
C:\ProgramData\AppkohcatiP\Zoting.dll =>PUP.Optional.Salus
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{ielnksrch} =>.SUP.Linkury

---\\ RÉCAPITULATIF DES ÉLÉMENTS TROUVÉS SUR VOTRE STATION (18) - 0s
https://nicolascoolman.eu/2017/09/07/pup-optional-salus/ =>PUP.Optional.Salus
https://nicolascoolman.eu/2017/01/04/pup-optional-logichandler/ =>PUP.Optional.LogicHandler
https://nicolascoolman.eu/2017/11/10/hijacker-browser-3/ =>Hijacker.Browser
https://nicolascoolman.eu/2017/10/05/sup-browserextension/ =>.SUP.BrowserExtension
https://nicolascoolman.eu/2017/09/07/pup-optional-salus/ =>.SUP.Linkury
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.YouTubeAdBlock
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>BitTorrent (P2P)
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.ShopMania
https://nicolascoolman.eu/2017/06/21/adware-fastdatax/ =>Adware.FastDataX
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.OneSystemCare
https://nicolascoolman.eu/2017/10/03/sup-systemhealer/ =>.SUP.SystemHealer
https://nicolascoolman.eu/2017/03/02/adware-suspect/ =>Adware.Suspect
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Adware.LookupPro
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Adware.ExtenBro
https://nicolascoolman.eu/2017/09/19/adware-installcore-3/ =>Adware.InstallCore
https://nicolascoolman.eu/2017/02/24/pup-optional-wajam/ =>PUP.Optional.Wajam
https://nicolascoolman.eu/2018/06/11/pup-optional-fassistant/ =>PUP.Optional.FAssistant
https://nicolascoolman.eu/2017/09/12/origine-lignes-orphelines/ =>.SUP.Orphan

~ Unselected Options: O82,
~ End of the scan, 5443 items in 03mn31s (1109)(0)

Publicité


Signaler le contenu de ce document

Publicité