cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2018.11.11.194 Par Nicolas Coolman (2018/11/11)
~ Démarré par Utilisateur (Administrator) (2018/11/13 20:31:47)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Certificate ZHPDiag: Legal
~ Etat de la version: Version OK
~ Mode: Scanner
~ Rapport: C:\Users\Utilisateur\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\Utilisateur\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Deactivate
~ Démarrage du système: Normal (Normal boot)
Windows 7 Starter, 32-bit Service Pack 1 (Build 7601) =>.Microsoft Corporation

---\\ NAVIGATEURS INTERNET (3) - 0s
~ GCIE: Google Chrome v70.0.3538.77
~ MFIE: Mozilla Firefox 63.0.1 (x86 fr)
~ MSIE: Internet Explorer v11.0.9600.17126

---\\ INFORMATIONS SUR LES PRODUITS WINDOWS (9) - 0s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
~ Windows Operating System - Windows(R) 7, OEM_COA_NSLP channel
~ Windows Partial Key : RJH6H
Windows License : OK
~ Windows Remaining Initializations Number : 4
Key Management Service client information : KO
Windows Automatic Updates : OK
Windows Activation Technologies : KO

---\\ LOGICIELS DE PROTECTION (1) - 1s
Avira Antivirus v15.0.42.11 (Protection)

---\\ SURVEILLANCE LOGICIEL (3) - 1s
~ Adobe Flash Player 31 ActiveX (Surveillance)
~ Adobe Flash Player 31 NPAPI (Surveillance)
~ Adobe Acrobat Reader DC - Français (Surveillance)

---\\ LOGICIELS D'OPTIMISATION (1) - 1s
~ CCleaner v4.11 (Optimisation)

---\\ INFORMATIONS SUR LE SYSTÈME (6) - 0s
~ Operating System: x86 Family 6 Model 15 Stepping 13, GenuineIntel
~ Operating System: 32-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 2088.248 MB (21% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive C: has 84 GB (52%) free of 159 GB : OK =>.Disk Space

---\\ MODE DE CONNEXION AU SYSTÈME (3) - 0s
~ Computer Name: UTILISATEUR-PC
~ User Name: Utilisateur
~ Logged in as Administrator

---\\ ÉNUMÉRATION DES UNITÉS DE STOCKAGE (3) - 0s
~ Drive C: has 84 GB free of 159 GB (System)
~ Drive D: has 116 GB free of 139 GB
~ Drive E: has 4 GB free of 5 GB

---\\ ÉTAT DU CENTRE DE SÉCURITÉ WINDOWS (9) - 0s
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ RECHERCHE PARTICULIÈRE DE FICHIERS GÉNÉRIQUES (24) - 2s
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - 25/02/2011 - (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\Explorer.exe [2616320] =>.Microsoft Corporation
[MD5.51138BEEA3E2C21EC44D0932C71762A8] - 14/07/2009 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe [44544] =>.Microsoft Corporation
[MD5.B5C5DCAD3899512020D135600129D665] - 14/07/2009 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\System32\Wininit.exe [96256] =>.Microsoft Corporation
[MD5.771CDBC3D62437D6DB070820BB1EDCCF] - 30/05/2014 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [1790976] =>.Microsoft Corporation
[MD5.52449FD429D6053B78AE564DEF303870] - 17/07/2014 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\Windows\System32\Winlogon.exe [304128] =>.Microsoft Corporation
[MD5.E3AE23569749DE12D45BA3B489A036AE] - 20/11/2010 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [193536] =>.Microsoft Corporation
[MD5.B40420876B9288E0A1C8CCA8A84E5DC9] - 03/03/2011 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\System32\dnsapi.dll [270336] =>.Microsoft Corporation
[MD5.129F80D7868E30DF3E3DE33A1D3132B4] - 20/11/2010 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [20480] =>.Microsoft Corporation
[MD5.D0B388DA1D111A34366E04EB4A5DD156] - 30/05/2014 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [338944] =>.Microsoft Corporation
[MD5.338C86357871C167A96AB976519BF59E] - 14/07/2009 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [21584] =>.Microsoft Windows®
[MD5.77EA11B065E0A8AB902D78145CA51E10] - 14/07/2009 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [70656] =>.Microsoft Corporation
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - 20/11/2010 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [108544] =>.Microsoft Corporation
[MD5.F024449C97EC1E464AAFFDA18593DB88] - 20/11/2010 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [78336] =>.Microsoft Corporation
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - 20/11/2010 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [108544] =>.Microsoft Corporation
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - 14/07/2009 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [80896] =>.Microsoft Corporation
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - 14/07/2009 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [101888] =>.Microsoft Corporation
[MD5.01C5B803F6E1FDF8F16F0763DA9B997D] - 01/07/2015 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [124416] =>.Microsoft Corporation
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - 20/11/2010 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [187904] =>.Microsoft Corporation
[MD5.C8DFF8D07755A66C7A4A738930F0FEAC] - 24/01/2014 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [1212352] =>.Microsoft Corporation®
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - 14/07/2009 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\Parport.sys [79360] =>.Microsoft Corporation
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - 14/07/2009 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [78848] =>.Microsoft Corporation
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - 14/07/2009 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [71168] =>.Microsoft Corporation
[MD5.7FE680A3DFA421C4A8E4879AE4C5AAB0] - 11/11/2014 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [74752] =>.Microsoft Corporation
[MD5.F497F67932C6FA693D7DE2780631CFE7] - 20/11/2010 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [245632] =>.Microsoft Windows®

---\\ LISTE DES SERVICES (Non désactivés) (59) - 3s
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
O23 - Service: Avira Protection e-mail (AntiVirMailService) . (.Avira Operations GmbH & Co. KG - Antivirus MailScanner WFP Service.) - C:\Program Files\Avira\Antivirus\avmailc7.exe =>.Avira Operations GmbH & Co. KG®
O23 - Service: Avira Planificateur (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - C:\Program Files\Avira\Antivirus\sched.exe =>.Avira Operations GmbH & Co. KG®
O23 - Service: Avira Protection temps réel (AntiVirService) . (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - C:\Program Files\Avira\Antivirus\avguard.exe =>.Avira Operations GmbH & Co. KG®
O23 - Service: Avira Protection Web (AntiVirWebService) . (.Avira Operations GmbH & Co. KG - AntiVir WebGuard WFP Service.) - C:\Program Files\Avira\Antivirus\avwebg7.exe =>.Avira Operations GmbH & Co. KG®
O23 - Service: C:\Windows\System32\inetsrv\iisres.dll (AppHostSvc) . (.Microsoft Corporation - IIS Application Host Helper Service.) - C:\Windows\System32\inetsrv\apphostsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\audiosrv.dll (AudioEndpointBuilder) . (.Microsoft Corporation - Service Audio Windows.) - C:\Windows\System32\audiosrv.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\audiosrv.dll (Audiosrv) . (.Microsoft Corporation - Service Audio Windows.) - C:\Windows\System32\audiosrv.dll =>.Microsoft Corporation
O23 - Service: Avira Service Host (Avira.ServiceHost) . (.Avira Operations GmbH & Co. KG - Avira Service Host.) - C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe =>.Avira Operations GmbH & Co. KG®
O23 - Service: C:\Windows\System32\BFE.DLL (BFE) . (.Microsoft Corporation - Moteur de filtrage de base.) - C:\Windows\System32\BFE.DLL =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\qmgr.dll (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) - C:\Windows\System32\qmgr.dll =>.Microsoft Corporation
O23 - Service: Bluetooth Service (btwdins) . (.Broadcom Corporation. - Bluetooth Support Server.) - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe =>.Broadcom Corporation®
O23 - Service: Microsoft .NET Framework NGEN v4.0.30319_X86 (clr_optimization_v4.0.30319_32) . (.Microsoft Corporation - .NET Runtime Optimization Service.) - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe =>.Microsoft Corporation®
O23 - Service: C:\Windows\System32\cryptsvc.dll (CryptSvc) . (.Microsoft Corporation - Services de chiffrement.) - C:\Windows\System32\cryptsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\dhcpcore.dll (Dhcp) . (.Microsoft Corporation - Service client DHCP.) - C:\Windows\System32\dhcpcore.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\UtcResources.dll (DiagTrack) . (.Microsoft Corporation - Microsoft Windows Diagnostics Tracking.) - C:\Windows\System32\diagtrack.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\dnsapi.dll (Dnscache) . (.Microsoft Corporation - Service de résolution du cache DNS.) - C:\Windows\System32\dnsrslvr.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wevtsvc.dll (eventlog) . (.Microsoft Corporation - Processus hôte pour les services Windows.) - C:\Windows\System32\svchost.exe =>.Microsoft Corporation
O23 - Service: @comres.dll,-2450 (EventSystem) . (.Microsoft Corporation - COM+.) - C:\Windows\System32\es.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\FDResPub.dll (FDResPub) . (.Microsoft Corporation - Service de publication des ressources de dé.) - C:\Windows\System32\FDResPub.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\FntCache.dll (FontCache) . (.Microsoft Corporation - Service de cache de police Windows.) - C:\Windows\System32\FntCache.dll =>.Microsoft Corporation
O23 - Service: (FreemakeVideoCapture) . (.Ellora Assets Corp. - CaptureLibService.) - C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe =>.Ellora Assets Corp.
O23 - Service: @gpapi.dll,-112 (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) - C:\Windows\System32\gpsvc.dll =>.Microsoft Corporation
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc®
O23 - Service: C:\Windows\System32\IPBusEnum.dll (IPBusEnum) . (.Microsoft Corporation - DLL du service énumérateur de bus IP PnP-X.) - C:\Windows\System32\ipbusenum.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\iphlpsvc.dll (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) - C:\Windows\System32\iphlpsvc.dll =>.Microsoft Corporation
O23 - Service: KMService (KMService) . (...) - C:\Windows\System32\srvany.exe
O23 - Service: C:\Windows\System32\srvsvc.dll (LanmanServer) . (.Microsoft Corporation - DLL du service Serveur.) - C:\Windows\System32\srvsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wkssvc.dll (LanmanWorkstation) . (.Microsoft Corporation - DLL du service Station de travail.) - C:\Windows\System32\wkssvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\lmhsvc.dll (lmhosts) . (.Microsoft Corporation - DLL des services de transport NetBIOS sur T.) - C:\Windows\System32\lmhsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\mmcss.dll (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) - C:\Windows\System32\mmcss.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\FirewallAPI.dll (MpsSvc) . (.Microsoft Corporation - Service de protection Microsoft.) - C:\Windows\System32\MPSSVC.dll =>.Microsoft Corporation
O23 - Service: @C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceMode (NetPipeActivator) . (.Microsoft Corporation - SMSvcHost.exe.) - C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe =>.Microsoft Corporation®
O23 - Service: @C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceMode (NetTcpActivator) . (.Microsoft Corporation - SMSvcHost.exe.) - C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe =>.Microsoft Corporation®
O23 - Service: C:\Windows\System32\nlasvc.dll (NlaSvc) . (.Microsoft Corporation - Connaissance des emplacements réseau 2.) - C:\Windows\System32\nlasvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\nsisvc.dll (nsi) . (.Microsoft Corporation - Serveur RPC de l’interface du magasin résea.) - C:\Windows\System32\nsisvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\umpnpmgr.dll (PlugPlay) . (.Microsoft Corporation - Service mode utilisateur de Plug-and-Play.) - C:\Windows\System32\umpnpmgr.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\umpo.dll (Power) . (.Microsoft Corporation - Service d’alimentation en mode utilisateur.) - C:\Windows\System32\umpo.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\profsvc.dll (ProfSvc) . (.Microsoft Corporation - ProfSvc.) - C:\Windows\System32\profsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\RpcEpMap.dll (RpcEptMapper) . (.Microsoft Corporation - Mappeur de point de terminaison RPC.) - C:\Windows\System32\RpcEpMap.dll =>.Microsoft Corporation
O23 - Service: @oleres.dll,-5010 (RpcSs) . (.Microsoft Corporation - Distributed COM Services.) - C:\Windows\System32\rpcss.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\schedsvc.dll (Schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) - C:\Windows\System32\schedsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\Sens.dll (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) - C:\Windows\System32\Sens.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\shsvcs.dll (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) - C:\Windows\System32\shsvcs.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\spoolsv.exe,-1 (Spooler) . (.Microsoft Corporation - Application sous-système spouleur.) - C:\Windows\System32\spoolsv.exe =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\sppsvc.exe,-101 (sppsvc) . (.Microsoft Corporation - Service de la plateforme de protection logi.) - C:\Windows\System32\sppsvc.exe =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wiaservc.dll (StiSvc) . (.Microsoft Corporation - Service de périphériques d’images fixes.) - C:\Windows\System32\wiaservc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\sysmain.dll (SysMain) . (.Microsoft Corporation - Hôte de service Superfetch.) - C:\Windows\System32\sysmain.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\themeservice.dll (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) - C:\Windows\System32\themeservice.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\dwm.exe,-2000 (UxSms) . (.Microsoft Corporation - Microsoft User Experience Session Managemen.) - C:\Windows\System32\uxsms.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\inetsrv\iisres.dll (W3SVC) . (.Microsoft Corporation - IIS Web Admin Service.) - C:\Windows\System32\inetsrv\iisw3adm.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wbem\WMIsvc.dll (Winmgmt) . (.Microsoft Corporation - WMI.) - C:\Windows\System32\wbem\WMIsvc.dll =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wlansvc.dll (Wlansvc) . (.Microsoft Corporation - DLL du service de configuration automatique.) - C:\Windows\System32\wlansvc.dll =>.Microsoft Corporation
O23 - Service: Windows Live ID Sign-in Assistant (wlidsvc) . (.Microsoft Corp. - Microsoft® Windows Live ID Service.) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE =>.Microsoft Corporation®
O23 - Service: Wondershare Application Framework Service (WsAppService) . (...) - C:\Program Files\Wondershare\WAF\2.4.3.227\WsAppService.exe (.not file.) =>.Wondershare
O23 - Service: C:\Windows\System32\wscsvc.dll (wscsvc) . (.Microsoft Corporation - Service Centre de sécurité de Windows.) - C:\Windows\System32\wscsvc.dll =>.Microsoft Corporation
O23 - Service: Wondershare Driver Install Service (WsDrvInst) . (...) - C:\Program Files\Wondershare\dr.fone toolkit pour Android\Library\DriverInstaller\DriverInstall.exe (.not file.) =>.Wondershare
O23 - Service: C:\Windows\System32\SearchIndexer.exe,-103 (WSearch) . (.Microsoft Corporation - Indexeur Microsoft Windows Search.) - C:\Windows\System32\SearchIndexer.exe =>.Microsoft Corporation
O23 - Service: C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) - C:\Windows\System32\wuaueng.dll =>.Microsoft Corporation

---\\ SERVICES NON MICROSOFT (SR=Démarré,SS=Stoppé) (22) - 7s
SR - Auto [14/08/2018] [ 83984] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated®
SS - Demand [13/11/2018] [ 336008] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated®
SR - Disabl [27/03/2009] [ 14336] Agere Modem Call Progress Audio (AgereModemAudio) . (.LSI Corporation.) - C:\Program Files\LSI SoftModem\agrsmsvc.exe =>.LSI Corporation
SR - Auto [29/10/2018] [ 891472] Avira Protection e-mail (AntiVirMailService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files\Avira\Antivirus\avmailc7.exe =>.Avira Operations GmbH & Co. KG®
SR - Auto [29/10/2018] [ 248312] Avira Planificateur (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files\Avira\Antivirus\sched.exe =>.Avira Operations GmbH & Co. KG®
SR - Auto [29/10/2018] [ 248312] Avira Protection temps réel (AntiVirService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files\Avira\Antivirus\avguard.exe =>.Avira Operations GmbH & Co. KG®
SR - Auto [29/10/2018] [ 1162120] Avira Protection Web (AntiVirWebService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files\Avira\Antivirus\avwebg7.exe =>.Avira Operations GmbH & Co. KG®
SR - Auto [09/10/2018] [ 431688] Avira Service Host (Avira.ServiceHost) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe =>.Avira Operations GmbH & Co. KG®
SR - Disabl [23/05/2008] [ 98304] Backup Scheduler (Backup Scheduler) . (...) - C:\Program Files\FarStone\DriveClone Pro\CBP\DCSchdlerSRVC.exe
SR - Auto [30/07/2009] [ 582944] Bluetooth Service (btwdins) . (.Broadcom Corporation..) - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe =>.Broadcom Corporation®
SR - Disabl [05/05/2009] [ 228408] Com4QLBEx (Com4QLBEx) . (.Hewlett-Packard Development Company, L.P..) - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe =>.Hewlett-Packard Company®
SR - Disabl [30/04/2008] [ 28672] Backup File Event Manager (efbfs) . (.FarStone Technology, Inc..) - C:\Program Files\FarStone\DriveClone Pro\EFB\efbfs.exe
SR - Auto [31/10/2014] [ 9216] (FreemakeVideoCapture) . (.Ellora Assets Corp..) - C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe =>.Ellora Assets Corp.
SR - Auto [02/09/2015] [ 144200] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Demand [02/09/2015] [ 144200] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe =>.Google Inc®
SR - Disabl [21/06/2011] [ 85560] HP Support Assistant Service (HP Support Assistant Service) . (.Hewlett-Packard Company.) - C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe =>.Hewlett-Packard Company®
SR - Disabl [02/11/2011] [ 227896] HP Quick Synchronization Service (HPDrvMntSvc.exe) . (.Hewlett-Packard Company.) - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe =>.Hewlett-Packard Company®
SR - Disabl [02/11/2011] [ 991288] HP Software Framework Service (hpqwmiex) . (.Hewlett-Packard Company.) - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe =>.Hewlett-Packard Company®
SR - Auto [18/04/2003] [ 8192] KMService (KMService) . (...) - C:\Windows\System32\srvany.exe
SR - Disabl [17/06/2009] [ 73728] LightScribeService Direct Disc Labeling Service (LightScribeService) . (.Hewlett-Packard Company.) - C:\Program Files\Common Files\LightScribe\LSSrvc.exe =>.Hewlett-Packard Company
SS - Demand [02/11/2018] [ 201168] Mozilla Maintenance Service (MozillaMaintenance) . (...) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SR - Disabl [26/03/2008] [ 90112] Real time Backup Loader (Real time Backup Loader) . (...) - C:\Program Files\FarStone\DriveClone Pro\fsloader.exe

---\\ TÂCHES PLANIFIÉES EN AUTOMATIQUE (Registre) (32) - 4s
O38 - TASK: {256D2795-7A66-4B8C-8573-ED35BCA66A30}[\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start] - (.Hewlett-Packard Company - HP Support Assistant.) -- C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe [727608] =>.Hewlett-Packard Company
O38 - TASK: {266E6F5E-AC1D-4CA2-A3D9-AFE071FD3C48}[\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up] - (.Hewlett-Packard Company - HPTuneUp.) -- C:\Program Files\Hewlett-Packard\HP Support Framework\HPTuneUp.exe [17976] =>.Hewlett-Packard Company
O38 - TASK: {2E20EECD-E44B-4586-940F-125865C6966B}[\GoogleUpdateTaskMachineUA] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc.
O38 - TASK: {3B6F5613-0502-4E5B-B346-6A2EF1DF36B5}[\Adobe Acrobat Update Task] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1190424] =>.Adobe Systems Incorporated
O38 - TASK: {52AA1735-6283-4A9E-9A05-D92DA02ABB73}[\Adobe Flash Player NPAPI Notifier] - (.Adobe Systems Incorporated - Adobe® Flash® Player Installer/Uninstaller.) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_31_0_0_148_Plugin.exe [1455752] =>.Adobe Systems Incorporated
O38 - TASK: {63762C9D-38CE-44B8-B37C-825F7A7FD5CE}[\AutoKMSCustom] - (.CODYQX4 - AutoKMS.) -- C:\Windows\AutoKMS\AutoKMS.exe [3153408] =>HackTool.AutoKMS
O38 - TASK: {68BAEC95-065E-46BF-A50B-9BBC015828B6}[\Avira_Antivirus_Systray] - (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Program Files\Avira\Antivirus\avgnt.exe [694544] =>.Avira Operations GmbH & Co. KG
O38 - TASK: {6BC0F337-BA22-4C19-9D5F-3D379BB4328B}[\Adobe Flash Player Updater] - (.Adobe Systems Incorporated - Adobe® Flash® Player Update Service 31.0 r0.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [336008] =>.Adobe Systems Incorporated
O38 - TASK: {730EBC16-6978-4138-B701-AEA14C91E9F2}[\CCleanerSkipUAC] - (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe [4505368] =>.Piriform Ltd
O38 - TASK: {7BED76D2-DF7D-4CAA-8D83-C597781D09F7}[\Hewlett-Packard\HP Support Assistant\PC Tuneup] - (.Hewlett-Packard Company - HP Support Assistant.) -- C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe [7120952] =>.Hewlett-Packard Company
O38 - TASK: {B42C1E26-9340-4A7E-BA7E-DC48BF49AD7F}[\RealUpgradeScheduledTaskS-1-5-21-3306339443-3704132785-2724747589-1000] - (.RealNetworks, Inc. - RealUpgrade Launcher.) -- C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [170624] =>.RealNetworks, Inc.
O38 - TASK: {BC0DCFED-1E43-4D1B-983F-F5A7EE83760F}[\GoogleUpdateTaskMachineCore] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files\Google\Update\GoogleUpdate.exe [144200] =>.Google Inc.
O38 - TASK: {D28E304D-2E27-43D4-9C69-D3ECC55418AF}[\{65F80DA0-131C-44BC-AFE2-5201143EEB0D}] - (.InstallShield Software Corporation - InstallShield® unInstaller.) -- C:\Windows\IsUninst.exe [306688] =>.InstallShield Software Corporation
O38 - TASK: {DA82F3F2-9F09-4D8F-A4B0-3B39FC8BBE6B}[\Hewlett-Packard\HP Support Assistant\PC Health Analysis] - (.Hewlett-Packard Company - HP Support Assistant.) -- C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe [7120952] =>.Hewlett-Packard Company
O38 - TASK: {F34F77E0-9FC9-44BC-B0F1-50DDAE0ED837}[\RealUpgradeLogonTaskS-1-5-21-3306339443-3704132785-2724747589-1000] - (.RealNetworks, Inc. - RealUpgrade Launcher.) -- C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [170624] =>.RealNetworks, Inc.
O38 - TASK: {FF682370-1951-40CF-9E2E-E8FE5BA4E6BD}[\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B] - (...) -- schtasks [0]
C:\Windows\System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start - (.Hewlett-Packard Company.) -- C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe [/taskrestart] =>.Hewlett-Packard Company
C:\Windows\System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up - (.Hewlett-Packard Company.) -- C:\Program Files\Hewlett-Packard\HP Support Framework\HPTuneUp.exe [] =>.Hewlett-Packard Company
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [/ua ./ua] =>.Google Inc.
C:\Windows\System32\Tasks\Adobe Acrobat Update Task - (.Adobe Systems Incorporated.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [] =>.Adobe Systems Incorporated
C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_31_0_0_148_Plugin.exe [-check plugin.-check] =>.Adobe Systems Incorporated
C:\Windows\System32\Tasks\AutoKMSCustom - (.CODYQX4.) -- C:\Windows\AutoKMS\AutoKMS.exe [] =>HackTool.AutoKMS
C:\Windows\System32\Tasks\Avira_Antivirus_Systray - (.Avira Operations GmbH & Co. KG.) -- C:\Program Files\Avira\Antivirus\avgnt.exe [/min] =>.Avira Operations GmbH & Co. KG
C:\Windows\System32\Tasks\Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [] =>.Adobe Systems Incorporated
C:\Windows\System32\Tasks\CCleanerSkipUAC - (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [$(Arg0)] =>.Piriform Ltd
C:\Windows\System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup - (.Hewlett-Packard Company.) -- C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe [/L TuneupTimer./L] =>.Hewlett-Packard Company
C:\Windows\System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3306339443-3704132785-2724747589-1000 - (.RealNetworks, Inc..) -- C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [/scheduledcheck] =>.RealNetworks, Inc.
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [/c] =>.Google Inc.
C:\Windows\System32\Tasks\{65F80DA0-131C-44BC-AFE2-5201143EEB0D} - (.InstallShield Software Corporation.) -- C:\Windows\IsUninst.exe [C:\Windows\IsUninst.exe] =>.InstallShield Software Corporation
C:\Windows\System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis - (.Hewlett-Packard Company.) -- C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe [/L Analysis./L] =>.Hewlett-Packard Company
C:\Windows\System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3306339443-3704132785-2724747589-1000 - (.RealNetworks, Inc..) -- C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [/logoncheck] =>.RealNetworks, Inc.
C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B - (...) -- schtasks [/run ./run]

---\\ APPLICATIONS LANCÉES AU DÉMARRAGE DU SYSTÈME (3) - 0s
O4 - HKLM\..\Run: [Avira SystrayStartTrigger] . (.Avira Operations GmbH & Co. KG - Avira.) -- C:\Program Files\Avira\Launcher\Avira.SystrayStartTrigger.exe =>.Avira Operations GmbH & Co. KG®
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation

---\\ PROCESSUS LANCÉS (24) - 5s
[MD5.49778ECE6A622FF108A47841A38A14F3] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) -- C:\Program Files\Avira\Antivirus\sched.exe [248312] [PID.1508] =>.Avira Operations GmbH & Co. KG®
[MD5.F59BEA8794FD4C8472E3F35848945319] - (.Broadcom Corporation. - Bluetooth Tray Application.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [795936] [PID.1272] =>.Broadcom Corporation®
[MD5.1CA48BA85A5393A779615377C56CA6A5] - (.DiMXSoft - Brightness Quick Tuner.) -- C:\Program Files\Desktop Lighter\DLighter.exe [227328] [PID.1376] =>.DiMXSoft
[MD5.696A8431DD22EDE385D7AB84E0EAF4C9] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [83984] [PID.2176] =>.Adobe Systems, Incorporated®
[MD5.49778ECE6A622FF108A47841A38A14F3] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) -- C:\Program Files\Avira\Antivirus\avguard.exe [248312] [PID.2196] =>.Avira Operations GmbH & Co. KG®
[MD5.7D2DD14E60CE4FF3308D66FDA7990546] - (.Broadcom Corporation. - Bluetooth Support Server.) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [582944] [PID.2260] =>.Broadcom Corporation®
[MD5.76884494002C29B71D924500A1B3F973] - (.Ellora Assets Corp. - CaptureLibService.) -- C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe [9216] [PID.2388] =>.Ellora Assets Corp.
[MD5.4635935FC972C582632BF45C26BFCB0E] - (...) -- C:\Windows\System32\srvany.exe [8192] [PID.2572]
[MD5.82865FF17BC664C711EFA674759F9991] - (...) -- C:\Windows\KMService.exe [77824] [PID.2604]
[MD5.FB01D4AE207B9EFDBABFC55DC95C7E31] - (.Microsoft Corp. - Microsoft® Windows Live ID Service.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [1713536] [PID.2796] =>.Microsoft Corporation®
[MD5.F31BAAB32FEE9BF8FB0674D992901FC6] - (.Avira Operations GmbH & Co. KG - Avira Service Host.) -- C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [431688] [PID.2876] =>.Avira Operations GmbH & Co. KG®
[MD5.C649F293B8B047A2694F3C615D09BF17] - (.Microsoft Corp. - Microsoft® Windows Live ID Service Monitor.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE [193920] [PID.3008] =>.Microsoft Corporation®
[MD5.00D0B14B33CA2B614E7CE8FC0B7CF747] - (.Avira Operations GmbH & Co. KG - AntiVir shadow copy service.) -- C:\Program Files\Avira\Antivirus\avshadow.exe [186488] [PID.3356] =>.Avira Operations GmbH & Co. KG®
[MD5.43DEA4C9A58CED1054794AAD727A43D9] - (.Broadcom Corporation. - Bluetooth Stack COM Server.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe [2352416] [PID.3512] =>.Broadcom Corporation®
[MD5.097E03356512A58A058D01B884949F6F] - (.Avira Operations GmbH & Co. KG - Avira.) -- C:\Program Files\Avira\Launcher\Avira.Systray.exe [307184] [PID.4672] =>.Avira Operations GmbH & Co. KG®
[MD5.BE685862479A4AB6F322A3253B696D64] - (.Avira Operations GmbH & Co. KG - Avira system tray application.) -- C:\Program Files\Avira\Antivirus\avgnt.exe [694544] [PID.4716] =>.Avira Operations GmbH & Co. KG®
[MD5.C6F7B11B79D2DE4B4952CC4D45CCC0BB] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [450512] [PID.112] =>.Mozilla Corporation®
[MD5.C6F7B11B79D2DE4B4952CC4D45CCC0BB] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [450512] [PID.4332] =>.Mozilla Corporation®
[MD5.C6F7B11B79D2DE4B4952CC4D45CCC0BB] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [450512] [PID.5572] =>.Mozilla Corporation®
[MD5.C6F7B11B79D2DE4B4952CC4D45CCC0BB] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [450512] [PID.4412] =>.Mozilla Corporation®
[MD5.C6F7B11B79D2DE4B4952CC4D45CCC0BB] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [450512] [PID.1088] =>.Mozilla Corporation®
[MD5.C6F7B11B79D2DE4B4952CC4D45CCC0BB] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [450512] [PID.6136] =>.Mozilla Corporation®
[MD5.0E2A1261615D3235D4E21F231F2EDAE2] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Utilisateur\AppData\Roaming\ZHP\ZHPDiag3.exe [3176832] [PID.2160] =>.Nicolas Coolman
[MD5.C6F7B11B79D2DE4B4952CC4D45CCC0BB] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [450512] [PID.1572] =>.Mozilla Corporation®

---\\ CHROME, Démarrage, Recherche, Extensions (19) - 2s
G2 - GCE: Preference [Utilisateur][User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] =>.Google Inc. {Slides}
G2 - GCE: Preference [Utilisateur][User Data\Default] [aohghmighlieiainnegkcijnfilokake] =>.Google Inc. {Docs}
G2 - GCE: Preference [Utilisateur][User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] http://drive.google.com/ =>.Google Inc. {Drive}
G2 - GCE: Preference [Utilisateur][User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] http://www.youtube.com =>.Youtube {Youtube}
G2 - GCE: Preference [Utilisateur][User Data\Default] [bpegkgagfojjbcpkihigfmkojdmmimdf] Download & Convert with Freemake Video Downloader
G2 - GCE: Preference [Utilisateur][User Data\Default] [cfhdojbkjhnklbpkdaibdccddilifddb] eyeo GmbH =>.eyeo GmbH {AdBlock Plus}
G2 - GCE: Preference [Utilisateur][User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] http://www.google.com/ =>.Google Inc. {Hidden Chrome extensions}
G2 - GCE: Preference [Utilisateur][User Data\Default] [efaidnbmnnnibpcajpcglclefindmkaj] =>.Adobe Inc. {Acrobat}
G2 - GCE: Preference [Utilisateur][User Data\Default] [ehgldbbpchgpcfagfpfjgoomddhccfgh] Freemake Youtube Download Button
G2 - GCE: Preference [Utilisateur][User Data\Default] [emakkfldeggiinnfcdjkakdfcppbfhdg] emakkfldeggiinnfcdjkakdfcppbfhdg =>.clockforchrome {Horloge}
G2 - GCE: Preference [Utilisateur][User Data\Default] [fcfenmboojpjinhpgggodefccipikbpd] Bing =>.Microsoft Corporation
G2 - GCE: Preference [Utilisateur][User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] =>.Google Inc. {Sheets}
G2 - GCE: Preference [Utilisateur][User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] =>.Google Inc. {Docs hors connexion}
G2 - GCE: Preference [Utilisateur][User Data\Default] [jfmjfhklogoienhpfnppmbcbjfjnkonk] RealPlayer HTML5Video Downloader Extension
G2 - GCE: Preference [Utilisateur][User Data\Default] [lmjegmlicamnimmfhcmpkclmigmmcbeh] Application Launcher for Drive (by Google) =>.Google Inc.
G2 - GCE: Preference [Utilisateur][User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] =>.Google Inc. {Wallet}
G2 - GCE: Preference [Utilisateur][User Data\Default] [pdnkcidphdcakpkheohlhocaicfamjie] Bitdefender QuickScan
G2 - GCE: Preference [Utilisateur][User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] http://mail.google.com/ =>.Google Inc. {Gmail}
G2 - GCE: Preference [Utilisateur][User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc.

---\\ COMODO DRAGON, Démarrage, Recherche, Extensions (3) - 0s
C2 - CDE: Preference [User Data\Default] [fnlmalfcdndbebdknocgjhpeenhlcbjf] SNT
C2 - CDE: Preference [Utilisateur][User Data\Default] [hdhmofnopkgkpgnpggloijpbnaonhplc]
C2 - CDE: Preference [User Data\Default] [nhfjefnfnmmnkcckbjjcganphignempo] Win by Browsing

---\\ FIREFOX, Plugins,Démarrage,Recherche,Extensions (19) - 4s
P2 - EXT FILE: (.Microsoft Corporation - Bing Search.) -- C:\Users\Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\91446hj1.default-1409260246158\extensions\bingsearch.full@microsoft.com.xpi =>.Microsoft Corporation
P2 - EXT FILE: (.SmileysWeLove: Smileys for use with Fa - Smileys and Emoticons for Gmail, Faceb.) -- C:\Users\Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\91446hj1.default-1409260246158\extensions\jid1-FB1bBgFMk5H6Wg@jetpack.xpi
P2 - EXT FILE: (.Google Inc. - .) -- C:\Users\Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\91446hj1.default-1409260246158\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi =>.Google Inc.
P2 - EXT FILE: (.Bing - Bing. Search by Microsoft..) -- C:\Users\Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\91446hj1.default-1409260246158\searchplugins\bing-.xml =>.Bing
P2 - EXT FILE: (.Microsoft Corporation - np-mswmp.) -- C:\Program Files\Mozilla Firefox\Plugins\np-mswmp.dll =>.Microsoft Corporation®
P2 - EXT FILE: (.Microsoft Corporation - The plugin allows you to have a better expe.) -- C:\Program Files\Mozilla Firefox\Plugins\npMeetingJoinPluginOC.dll =>.Microsoft Corporation®
P2 - EXT FILE: (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll =>.Adobe Systems, Incorporated®
P2 - EXT FILE: (.Adobe Inc. - Acrobate Reader.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.FRA =>.Adobe Inc.
P2 - EXT FILE: (.Microsoft Corporation.) -- C:\Program Files\Mozilla Firefox\Plugins\WMP Firefox Plugin License.rtf =>.Microsoft Corporation
P2 - EXT FILE: (.Microsoft Corporation.) -- C:\Program Files\Mozilla Firefox\Plugins\WMP Firefox Plugin RelNotes.txt =>.Microsoft Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\browser\features\aushelper@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\browser\features\formautofill@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\browser\features\onboarding@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi =>.Mozilla Corporation
P2 - EXT FILE: (.webcompat.com.) -- C:\Program Files\Mozilla Firefox\browser\features\webcompat-reporter@mozilla.org.xpi =>.webcompat.com
P2 - EXT FILE: (.webcompat.com.) -- C:\Program Files\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi =>.webcompat.com
P2 - FPN: [HKCU] [@movenetworks.com/Quantum Media Player] - (.Move Networks.) -- C:\Users\Utilisateur\AppData\Roaming\Move Networks\plugins\npqmp071700000016.dll
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Macromed\Flash\NPSWF32_31_0_0_148.dll =>.Adobe Systems Incorporated

---\\ INTERNET EXPLORER,Démarrage,Recherche,URLSearchHook (16) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com =>.Google Inc.
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/ =>.Bing.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com =>.Google Inc.
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com =>.Google Inc.
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = www.bing.com =>.Bing.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = about:blank =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com =>.Google Inc.
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R3 - URLSearchHook: {CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D}[HKLM] - Orphan =>.SUP.Orphan
R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.9600.17041 (winblue_gdr.140305-1710)) -- C:\Windows\System32\ieframe.dll =>.Microsoft Corporation
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 0

---\\ INTERNET EXPLORER, Site de confiance et site sensible (2) - 0s
~ Microsoft Internet Explorer Restricted Site(s) Domains: 0(Good) / 0(Bad)
~ Microsoft Internet Explorer Restricted Site(s) EscDomains: 0(Good) / 0(Bad)

---\\ INTERNET EXPLORER,Proxy Management (7) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 =>.Default.Value
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 =>.Default.Value
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\\ INTERNET EXPLORER,IniFiles, Autoloading Programs (3) - 0s
F2 - REG:system.ini: UserInit=C:\Windows\System32\Userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=C:\Windows\system32\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation

---\\ ÉTUDE DU FICHIER HOSTS (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (21)

---\\ BROWSER HELPER OBJECT DE NAVIGATEUR (BHO) (7) - 1s
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} . (.RealPlayer - RealPlayer Download and Record Plugin.) -- C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll =>.RealNetworks, Inc.®
O2 - BHO: (no name) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} (.Orphan.)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll =>.Oracle America, Inc.®
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll =>.Microsoft Corporation®
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL =>.Microsoft Corporation®
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll =>.Oracle America, Inc.®
O2 - BHO: (no name) - {e9e8eb35-ff77-455d-b677-91e5e4fc06c2} (.Orphan.)

---\\ INTERNET EXPLORER, Barre d'outil (Toolbar) (2) - 0s
O3 - Toolbar: 0xB1C218236549D4119B18009027A5CD4F - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} . (...) -- (.not file.)
O3 - Toolbar: 0x524956412D41375643007A786E7484D7 - [HKCU]{41564952-412D-5637-4300-7A786E7484D7} . (...) -- (.not file.)

---\\ RACCOURCIS GLOBAL STARTUP (94) - 6s
O4 - GS\Desktop [Administrateur]: BankPerfect.lnk . (.Fabio Chelly - Programme de gestion bancaire.) C:\Program Files\BankPerfect\bankperfect.exe =>.Fabio Chelly
O4 - GS\Desktop [Administrateur]: Desktop Lighter.lnk . (.DiMXSoft - Brightness Quick Tuner.) C:\Program Files\Desktop Lighter\DLighter.exe =>.DiMXSoft
O4 - GS\Desktop [Administrateur]: Disk Cleanup.lnk . (.Microsoft Corporation - Gestionnaire de nettoyage de disque pour Wi.) C:\Windows\system32\cleanmgr.exe =>.Microsoft Corporation
O4 - GS\Desktop [Administrateur]: Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe http://www.bahaty.com/ =>.Mozilla Corporation
O4 - GS\Desktop [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe http://www.bahaty.com/ =>.Google Inc.
O4 - GS\Desktop [Administrateur]: HP Webcam.lnk . (.Sonic Solutions - WebcamApp.) C:\Program Files\Hewlett-Packard\HP Webcam App\WebcamApp.exe =>.Sonic Solutions®
O4 - GS\Desktop [Administrateur]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe http://www.bahaty.com/ =>.Microsoft Corporation
O4 - GS\Desktop [Administrateur]: Jodix Free WMA to MP3 Converter.lnk . (.Jodix.com - Free WMA to MP3 Converter.) C:\Program Files\Free WMA to MP3 Converter\wma_mp3_converter.exe =>.Jodix.com
O4 - GS\Desktop [Administrateur]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe http://www.bahaty.com/ =>.Mozilla Corporation
O4 - GS\Desktop [Administrateur]: On-Screen Keyboard.lnk . (.Microsoft Corporation - Accessibilité au Clavier visuel.) C:\Windows\system32\osk.exe =>.Microsoft Corporation
O4 - GS\Desktop [Administrateur]: PhotoFiltre 7.lnk . (.PhotoFiltre - PhotoFiltre 7.) C:\Program Files\PhotoFiltre 7\PhotoFiltre7.exe =>.PhotoFiltre
O4 - GS\Desktop [Administrateur]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Utilisateur\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Administrateur]: chrome.LNK . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe http://www.bahaty.com/ =>.Google Inc.
O4 - GS\Quicklaunch [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Administrateur]: Internet Explorer.LNK . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe http://www.bahaty.com/ =>.Microsoft Corporation
O4 - GS\Quicklaunch [Administrateur]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Administrateur]: Mozilla Firefox.LNK . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe http://www.bahaty.com/ =>.Mozilla Corporation
O4 - GS\Quicklaunch [Administrateur]: Opera.LNK . (...) C:\Program Files\Opera\opera.exe http://www.bahaty.com/
O4 - GS\Quicklaunch [Administrateur]: Registry Reviver.lnk . (...) C:\Program Files\ReviverSoft\Registry Reviver\RegistryReviver.exe =>PUP.Optional.RegistryReviver
O4 - GS\Quicklaunch [Administrateur]: Safari.LNK . (...) C:\Program Files\Safari\Safari.exe http://www.bahaty.com/
O4 - GS\sendTo [Administrateur]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\TaskBar [Administrateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Administrateur]: shutdown.lnk . (.Microsoft Corporation - Outil d’arrêt et d’annotation Windows.) C:\Windows\System32\shutdown.exe -s -t 00 =>.Microsoft Corporation
O4 - GS\TaskBar [Administrateur]: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\Startup [Administrateur]: Desktop Lighter.lnk . (.DiMXSoft - Brightness Quick Tuner.) C:\Program Files\Desktop Lighter\DLighter.exe =>.DiMXSoft
O4 - GS\Startup [Administrateur]: Start.lnk . (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) C:\Windows\system32\wscript.exe /e:VBScript.Encode D:\bin.doc =>.Microsoft Corporation
O4 - GS\Programs [Administrateur]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Desktop [Utilisateur]: BankPerfect.lnk . (.Fabio Chelly - Programme de gestion bancaire.) C:\Program Files\BankPerfect\bankperfect.exe =>.Fabio Chelly
O4 - GS\Desktop [Utilisateur]: Desktop Lighter.lnk . (.DiMXSoft - Brightness Quick Tuner.) C:\Program Files\Desktop Lighter\DLighter.exe =>.DiMXSoft
O4 - GS\Desktop [Utilisateur]: Disk Cleanup.lnk . (.Microsoft Corporation - Gestionnaire de nettoyage de disque pour Wi.) C:\Windows\system32\cleanmgr.exe =>.Microsoft Corporation
O4 - GS\Desktop [Utilisateur]: Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe http://www.bahaty.com/ =>.Mozilla Corporation
O4 - GS\Desktop [Utilisateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe http://www.bahaty.com/ =>.Google Inc.
O4 - GS\Desktop [Utilisateur]: HP Webcam.lnk . (.Sonic Solutions - WebcamApp.) C:\Program Files\Hewlett-Packard\HP Webcam App\WebcamApp.exe =>.Sonic Solutions®
O4 - GS\Desktop [Utilisateur]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe http://www.bahaty.com/ =>.Microsoft Corporation
O4 - GS\Desktop [Utilisateur]: Jodix Free WMA to MP3 Converter.lnk . (.Jodix.com - Free WMA to MP3 Converter.) C:\Program Files\Free WMA to MP3 Converter\wma_mp3_converter.exe =>.Jodix.com
O4 - GS\Desktop [Utilisateur]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe http://www.bahaty.com/ =>.Mozilla Corporation
O4 - GS\Desktop [Utilisateur]: On-Screen Keyboard.lnk . (.Microsoft Corporation - Accessibilité au Clavier visuel.) C:\Windows\system32\osk.exe =>.Microsoft Corporation
O4 - GS\Desktop [Utilisateur]: PhotoFiltre 7.lnk . (.PhotoFiltre - PhotoFiltre 7.) C:\Program Files\PhotoFiltre 7\PhotoFiltre7.exe =>.PhotoFiltre
O4 - GS\Desktop [Utilisateur]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Utilisateur\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Utilisateur]: chrome.LNK . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe http://www.bahaty.com/ =>.Google Inc.
O4 - GS\Quicklaunch [Utilisateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Utilisateur]: Internet Explorer.LNK . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe http://www.bahaty.com/ =>.Microsoft Corporation
O4 - GS\Quicklaunch [Utilisateur]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Quicklaunch [Utilisateur]: Mozilla Firefox.LNK . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe http://www.bahaty.com/ =>.Mozilla Corporation
O4 - GS\Quicklaunch [Utilisateur]: Opera.LNK . (...) C:\Program Files\Opera\opera.exe http://www.bahaty.com/
O4 - GS\Quicklaunch [Utilisateur]: Registry Reviver.lnk . (...) C:\Program Files\ReviverSoft\Registry Reviver\RegistryReviver.exe =>PUP.Optional.RegistryReviver
O4 - GS\Quicklaunch [Utilisateur]: Safari.LNK . (...) C:\Program Files\Safari\Safari.exe http://www.bahaty.com/
O4 - GS\sendTo [Utilisateur]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\TaskBar [Utilisateur]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\TaskBar [Utilisateur]: shutdown.lnk . (.Microsoft Corporation - Outil d’arrêt et d’annotation Windows.) C:\Windows\System32\shutdown.exe -s -t 00 =>.Microsoft Corporation
O4 - GS\TaskBar [Utilisateur]: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\Startup [Utilisateur]: Desktop Lighter.lnk . (.DiMXSoft - Brightness Quick Tuner.) C:\Program Files\Desktop Lighter\DLighter.exe =>.DiMXSoft
O4 - GS\Startup [Utilisateur]: Start.lnk . (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) C:\Windows\system32\wscript.exe /e:VBScript.Encode D:\bin.doc =>.Microsoft Corporation
O4 - GS\Programs [Utilisateur]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Ltd - CCleaner.) C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd®
O4 - GS\CommonDesktop [Public]: CyberLink YouCam 5.lnk . (.CyberLink Corp. - YouCam.) C:\Program Files\CyberLink\YouCam\YouCam.exe =>.CyberLink®
O4 - GS\CommonDesktop [Public]: Freemake Video Downloader.lnk . (.Freemake - Freemake Video Downloader.) C:\Program Files\Freemake\Freemake Video Downloader\FreemakeVideoDownloader.exe =>.Ellora Assets Corporation®
O4 - GS\CommonDesktop [Public]: LightScribe.lnk . (.Hewlett-Packard Company - .) C:\Program Files\Common Files\LightScribe\LSLauncher.exe =>.Hewlett-Packard Company
O4 - GS\CommonDesktop [Public]: القرآن الكريم.lnk . (.AutoPlay Media Studio is a Trademark of Indigo Rose C - AutoPlay Application.) C:\Program Files\القرآن الكريم\autorun.exe
O4 - GS\Programs [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Accessories [Public]: Command Prompt.lnk . (.Microsoft Corporation - Interpréteur de commandes Windows.) C:\Windows\system32\cmd.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Bloc-notes.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\SystemTools [Public]: Private Character Editor.lnk . (.Microsoft Corporation - Éditeur de caractères privés.) C:\Windows\system32\eudcedit.exe =>.Microsoft Corporation
O4 - GS\Startup [Public]: Bluetooth.lnk . (.Broadcom Corporation. - Bluetooth Tray Application.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe =>.Broadcom Corporation®
O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Calculatrice de Windows.) C:\Windows\system32\calc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - Afficher le commutateur.) C:\Windows\system32\displayswitch.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\Windows\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Connexion Bureau à distance.) C:\Windows\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Magnétophone Windows.) C:\Windows\system32\SoundRecorder.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) C:\Windows\System32\mobsync.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Welcome Center.lnk . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) C:\Windows\system32\rundll32.exe %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut =>..Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Application Windows Wordpad.) C:\Program Files\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Table des caractères.) C:\Windows\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - Défragmenteur de disque Microsoft®.) C:\Windows\system32\dfrgui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - Gestionnaire de nettoyage de disque pour Wi.) C:\Windows\system32\cleanmgr.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - Moniteur de ressources et de performances.) C:\Windows\system32\perfmon.exe /res =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - Informations système.) C:\Windows\system32\msinfo32.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - Restauration du système de Microsoft® Windo.) C:\Windows\system32\rstrui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) C:\Windows\system32\taskschd.msc /s =>..Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - Application post-migration de transfert de.) C:\Windows\system32\migwiz\postmig.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - Application Transfert de fichiers et paramè.) C:\Windows\system32\migwiz\migwiz.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Acrobat Reader DC.lnk . (.Flexera Software LLC - InstallShield.) C:\Windows\Installer\{AC76BA86-7AD7-1036-7B44-AC0F074E4100}\SC_Reader.ico =>.Flexera Software LLC
O4 - GS\ProgramsCommon [Public]: Acrobat Reader DC.lnk . (.Flexera Software LLC - InstallShield.) C:\Windows\Installer\{AC76BA86-7AD7-1036-7B44-AC0F074E4100}\SC_Reader.ico =>.Flexera Software LLC
O4 - GS\ProgramsCommon [Public]: Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\ProgramsCommon [Public]: Sidebar.lnk . (.Microsoft Corporation - Gadgets du Bureau Windows.) C:\Program Files\Windows Sidebar\sidebar.exe /showgadgets =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Anytime Upgrade.lnk . (.Microsoft Corporation - Interface utilisateur de Mise à niveau expr.) C:\Windows\system32\WindowsAnytimeUpgradeUI.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Live Movie Maker.lnk . (.Microsoft Corporation - Windows Live Movie Maker.) C:\Program Files\Windows Live\Photo Gallery\MovieMaker.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Windows Live Photo Gallery.lnk . (.Microsoft Corporation - Windows Live Photo Gallery.) C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe =>.Microsoft Corporation®
O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: XPS Viewer.lnk . (.Microsoft Corporation - Visionneuse XPS.) C:\Windows\system32\xpsrchvw.exe =>.Microsoft Corporation

---\\ MODIFICATION DOMAINE/ADRESSES (DNS) (3) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{3D463A56-BB6E-4B92-AA0F-2DA4273F9F34}: DhcpNameServer = 192.168.1.1 192.168.1.1 =>.Local IP Adress
O17 - HKLM\System\CCS\Services\Tcpip\..\{DE600022-C6D2-471A-8CC8-989D19B2E621}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress

---\\ PROTOCOLE ADDITIONNEL (24) - 0s
O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll =>.Microsoft Corporation®
O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} . (.Microsoft Corporation - Microsoft Office 2013 component.) -- C:\Program Files\Microsoft Office\Office15\MSOSB.DLL =>.Microsoft Corporation®
O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll =>.Microsoft Corporation®
O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL =>.Microsoft Corporation®

---\\ REGISTRE AppInit_DLLs et Winlogon Notify (1) - 0s
O20 - Winlogon : UserInit . (.Microsoft Corporation - Application d’ouverture de session Userinit.) - C:\Windows\System32\Userinit.exe =>.Microsoft Corporation

---\\ COMPOSANTS ACTIVESETUP INSTALLÉS (ASIC) (11) - 2s
O40 - ASIC: LightScribe Control Panel - {10880D85-AAD9-4558-ABDC-2AB1552D831F} . (.Hewlett-Packard Company - .) -- C:\Program Files\Common Files\LightScribe\LSRunOnce.exe =>.Hewlett-Packard Company®
O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - Microsoft(C) Register Server.) -- C:\Windows\System32\regsvr32.exe =>.Microsoft Corporation
O40 - ASIC: Internet Explorer - {2D46B6DC-2207-486B-B523-A557E6D54B47} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Utilitaire d’installation du Lecteur Window.) -- C:\Windows\System32\unregmp2.exe =>.Microsoft Corporation
O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll =>.Microsoft Corporation®
O40 - ASIC: Google Chrome - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (.Google Inc. - Google Chrome Installer.) -- C:\Program Files\Google\Chrome\Application\70.0.3538.77\Installer\chrmstp.exe =>.Google Inc®
O40 - ASIC: Adobe Reader User Settings - {A6EADE66-0000-0000-484E-7E8A45000000} . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe =>.Microsoft Corporation
O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11CF-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 31.0 r0.) -- C:\Windows\System32\Macromed\Flash\Flash32_31_0_0_148.ocx =>.Adobe Systems Incorporated®

---\\ LOGICIELS INSTALLÉS (148) - 41s
O42 - Logiciel: Adobe Acrobat Reader DC - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AC0F074E4100} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- {77D28FF5-242F-488A-8215-937D6A4D69E0} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- Adobe AIR =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Flash Player 31 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Flash Player 31 NPAPI - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player NPAPI =>.Adobe Systems Incorporated®
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-0804-1033-1959-001824298644} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Shockwave Player 11.5 - (.Adobe Systems, Inc..) [HKLM] -- Adobe Shockwave Player =>.Adobe Systems, Inc.
O42 - Logiciel: ATI Catalyst Install Manager - (.ATI Technologies, Inc..) [HKLM] -- {8F0EDF80-31C2-FA10-DEE8-BD435A5F7D61} =>.ATI Technologies, Inc.
O42 - Logiciel: Avira Antivirus v15.0.42.11 - (.Avira Operations GmbH & Co. KG.) [HKLM] -- Avira Antivirus =>.Avira Operations GmbH & Co. KG®
O42 - Logiciel: Avira v1.2.121.24663 - (.Avira Operations GmbH & Co. KG.) [HKLM] -- {18787388-9263-47A6-B954-41BDE0B90959} =>.Avira Operations GmbH & Co. KG
O42 - Logiciel: Avira v1.2.121.24663 - (.Avira Operations GmbH & Co. KG.) [HKLM] -- {2884d9b5-2fed-48df-b0e0-fe229e7eb781} =>.Avira Operations GmbH & Co. KG®
O42 - Logiciel: BankPerfect 7.3 - (.Fabio Chelly.) [HKLM] -- BankPerfect =>.Fabio Chelly
O42 - Logiciel: Broadcom 802.11 Wireless LAN Adapter - (.Broadcom Corporation.) [HKLM] -- Broadcom 802.11 Wireless LAN Adapter =>.Broadcom Corporation
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner =>.Piriform Ltd®
O42 - Logiciel: Crystal Reports for .NET Framework 2.0 (x86) - (.Business Objects.) [HKLM] -- {7C05EEDD-E565-4E2B-ADE4-0C784C17311C} =>.Business Objects
O42 - Logiciel: CyberLink YouCam 5 - (.CyberLink Corp..) [HKLM] -- {01FB4998-33C4-4431-85ED-079E3EEFE75D} =>.CyberLink®
O42 - Logiciel: CyberLink YouCam 5 - (.CyberLink Corp..) [HKLM] -- InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D} =>.CyberLink®
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF} =>.Microsoft
O42 - Logiciel: Desktop Lighter - (.DiMXSoft.) [HKCU] -- {CFA2CFAB-4B51-47D5-8ECF-5C007F37DB94} =>.DiMXSoft
O42 - Logiciel: DriveClone Pro - (..) [HKLM] -- RestoreIT! {29B013F8F4A37F6B5A3F4991868B9484}
O42 - Logiciel: Free WMA to MP3 Converter 1.16 - (.Jodix Technologies Ltd..) [HKLM] -- Free WMA to MP3 Converter_is1 =>.Jodix Technologies Ltd.
O42 - Logiciel: Galerie de photos Windows Live - (.Microsoft Corporation.) [HKLM] -- {488F0347-C4A7-4374-91A7-30818BEDA710} =>.Microsoft Corporation
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome =>.Google Inc®
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: Hewlett-Packard ACLM.NET v1.1.1.0 - (.Hewlett-Packard.) [HKLM] -- {6F340107-F9AA-47C6-B54C-C3A19F11553F} =>.Hewlett-Packard
O42 - Logiciel: HP Customer Experience Enhancements - (.Hewlett-Packard.) [HKLM] -- {5B295588-59C1-4386-9F85-BB4BEDCB0D22} =>.Hewlett-Packard
O42 - Logiciel: HP Integrated Module with Bluetooth wireless technology - (.Broadcom Corporation.) [HKLM] -- {9E9D49A4-1DF4-4138-B7DB-5D87A893088E} =>.Broadcom Corporation
O42 - Logiciel: HP Quick Launch Buttons - (.Hewlett-Packard.) [HKLM] -- {34D2AB40-150D-475D-AE32-BD23FB5EE355} =>.Hewlett-Packard Company®
O42 - Logiciel: HP SoftPaq Download Manager - (.Hewlett-Packard Company.) [HKLM] -- {223AE3E8-4445-410F-8EDA-13EC137E3BDB} =>.Hewlett-Packard Company
O42 - Logiciel: HP Web Camera - (.Hewlett-Packard.) [HKLM] -- {C7AE4EC3-9C13-4213-8457-74D16B353F91} =>.Hewlett-Packard
O42 - Logiciel: HP Webcam - (.Roxio.) [HKLM] -- {1D61E881-43CD-447B-9E6B-D2C6138B2862} =>.Sonic Solutions®
O42 - Logiciel: HP Webcam Driver - (.Sonix.) [HKLM] -- {399C37FB-08AF-493B-BFED-20FBD85EDF7F} =>.Macrovision Corporation®
O42 - Logiciel: HP Wireless Assistant - (.Hewlett-Packard.) [HKLM] -- {54CC7901-804D-4155-B353-21F0CC9112AB} =>.Hewlett-Packard
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- HDMI =>.Intel Corporation®
O42 - Logiciel: Java 8 Update 73 - (.Oracle Corporation.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83218073F0} =>.Oracle Corporation
O42 - Logiciel: Java Auto Updater - (.Oracle Corporation.) [HKLM] -- {4A03706F-666A-4037-7777-5F2748764D10} =>.Oracle Corporation
O42 - Logiciel: Langue des info-bulles Microsoft Office 2010 - Français - (.Microsoft Corporation.) [HKLM] -- {90140000-00BD-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: LG Connection Manager - (.LGE.) [HKLM] -- {F8597A83-E1BE-4B7D-BD77-5C8CF5A304EA} =>.LGE
O42 - Logiciel: LightScribe System Software - (.LightScribe.) [HKLM] -- {82EF29B1-9B60-4142-A155-0599216DD053} =>.LightScribe
O42 - Logiciel: LSI HDA Modem - (.LSI Corporation.) [HKLM] -- LSI Soft Modem =>.LSI Corporation
O42 - Logiciel: Microsoft .NET Framework 4.5.2 - (.Microsoft Corporation.) [HKLM] -- {3911CF56-9EF2-39BA-846A-C27BD3CD0685} =>.Microsoft Corporation
O42 - Logiciel: Microsoft .NET Framework 4.5.2 - (.Microsoft Corporation.) [HKLM] -- {92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033 =>.Microsoft Corporation®
O42 - Logiciel: Microsoft .NET Framework 4.5.2 (FRA) - (.Microsoft Corporation.) [HKLM] -- {AE119B2F-0A12-3FD3-935F-A96D62205681} =>.Microsoft Corporation
O42 - Logiciel: Microsoft .NET Framework 4.5.2 (Français) - (.Microsoft Corporation.) [HKLM] -- {92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1036 =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Access MUI (French) 2013 - (.Microsoft Corporation.) [HKLM] -- {90150000-0015-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Application Error Reporting - (.Microsoft Corporation.) [HKLM] -- {95120000-00B9-0409-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft DCF MUI (French) 2013 - (.Microsoft Corporation.) [HKLM] -- {90150000-0090-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Excel MUI (French) 2013 - (.Microsoft Corporation.) [HKLM] -- {90150000-0016-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Groove MUI (French) 2013 - (.Microsoft Corporation.) [HKLM] -- {90150000-00BA-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft InfoPath MUI (French) 2013 - (.Microsoft Corporation.) [HKLM] -- {90150000-0044-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Lync MUI (French) 2013 - (.Microsoft Corporation.) [HKLM] -- {90150000-012B-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Access MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0015-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Excel MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0016-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Groove MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-00BA-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office InfoPath MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0044-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Korrekturhilfen 2013 - Deutsch - (.Microsoft Corporation.) [HKLM] -- {90150000-001F-0407-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Language Pack 2010 - Arabic العربية - (.Microsoft Corporation.) [HKLM] -- Office14.OMUI.ar-sa =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Office O MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0100-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office OneNote MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-00A1-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office OSM MUI (French) 2013 - (.Microsoft Corporation.) [HKLM] -- {90150000-00E1-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office OSM UX MUI (French) 2013 - (.Microsoft Corporation.) [HKLM] -- {90150000-00E2-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Outlook MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001A-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office PowerPoint MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0018-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Professional Plus 2013 - (.Microsoft Corporation.) [HKLM] -- {91150000-0011-0000-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Professionnel Plus 2013 - (.Microsoft Corporation.) [HKLM] -- Office15.PROPLUSR =>.Microsoft Corporation®
O42 - Logiciel: Microsoft Office Proof (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proof (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0409-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proof (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proofing (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-002C-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proofing (French) 2013 - (.Microsoft Corporation.) [HKLM] -- {90150000-002C-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proofing Tools 2013 - English - (.Microsoft Corporation.) [HKLM] -- {90150000-001F-0409-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proofing Tools 2013 - Español - (.Microsoft Corporation.) [HKLM] -- {90150000-001F-0C0A-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proofing Tools 2013 - Nederlands - (.Microsoft Corporation.) [HKLM] -- {90150000-001F-0413-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Proofing Tools 2013 - اللغة العربية - (.Microsoft Corporation.) [HKLM] -- {90150000-001F-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Publisher MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0019-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Shared MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-006E-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Shared MUI (French) 2013 - (.Microsoft Corporation.) [HKLM] -- {90150000-006E-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office SharePoint Designer MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0017-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office Word MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001B-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Office X MUI (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0101-0401-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft OneNote MUI (French) 2013 - (.Microsoft Corporation.) [HKLM] -- {90150000-00A1-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Outlook MUI (French) 2013 - (.Microsoft Corporation.) [HKLM] -- {90150000-001A-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft PowerPoint MUI (French) 2013 - (.Microsoft Corporation.) [HKLM] -- {90150000-0018-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Publisher MUI (French) 2013 - (.Microsoft Corporation.) [HKLM] -- {90150000-0019-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} =>.Microsoft Corporation
O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM] -- {F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8} =>.Microsoft Corporation
O42 - Logiciel: Microsoft SQL Server Compact 3.5 SP2 FRA - (.Microsoft Corporation.) [HKLM] -- {AF6919D0-5691-4F35-9D65-54F981013514} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM] -- {770657D0-A123-3C07-8E44-1C83EC895118} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {710f4c1c-cc18-4c49-8cbf-51240c89a1a2} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {837b34e3-7c30-493c-8f6a-2b0f04e2912c} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 - (.Microsoft Corporation.) [HKLM] -- {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Word MUI (French) 2013 - (.Microsoft Corporation.) [HKLM] -- {90150000-001B-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: Move Media Player - (.Move Networks.) [HKCU] -- Move Media Player
O42 - Logiciel: Mozilla Firefox 63.0.1 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 63.0.1 (x86 fr) =>.Mozilla Corporation®
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService =>.Mozilla
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} =>.Microsoft
O42 - Logiciel: MSXML 4.0 SP2 (KB927978) - (.Microsoft Corporation.) [HKLM] -- {37477865-A3F1-4772-AD43-AAFC6BCFF99F} =>.Microsoft Corporation
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71} =>.Microsoft Corporation
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC} =>.Microsoft Corporation
O42 - Logiciel: Open XML SDK 2.0 for Microsoft Office - (.Microsoft Corporation.) [HKLM] -- {171D8D76-3F05-455A-A8AF-C561C2679905} =>.Microsoft Corporation
O42 - Logiciel: Outils de vérification linguistique 2013 de Microsoft Office - Français - (.Microsoft Corporation.) [HKLM] -- {90150000-001F-040C-0000-0000000FF1CE} =>.Microsoft Corporation
O42 - Logiciel: PhotoFiltre 7 - (.Antonio Da Cruz.) [HKCU] -- PhotoFiltre 7 =>.Antonio Da Cruz
O42 - Logiciel: QLBCASL - (.Hewlett-Packard.) [HKLM] -- {F1D7AC58-554A-4A58-B784-B61558B1449A} =>.Hewlett-Packard
O42 - Logiciel: RealUpgrade 1.1 - (.RealNetworks, Inc..) [HKLM] -- {28C2DED6-325B-4CC7-983A-1777C8F7FBAB} =>.RealNetworks, Inc.
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2553284) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-006E-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{C08B8959-0DE4-4E90-B96A-499D70ABCC8D} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0015-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0016-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0017-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{FA070347-1670-4742-A178-EFA8FA7B5F0E} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0018-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0019-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-001A-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-001B-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-001F-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{00694B53-36C7-472D-9CB1-37BAE02F0E78} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-001F-0401-0000-0000000FF1CE}_Office14.PROPLUS_{00694B53-36C7-472D-9CB1-37BAE02F0E78} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-002C-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{ED827D4A-C39C-4B80-8209-3519EFDC7754} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0044-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-006E-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{29A7BE00-F052-4298-A37C-0AB095772ABC} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-00A1-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-00BA-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{33A03A99-A23F-4EA8-BC72-1C80FF6A1A04} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit E - (.Microsoft.) [HKLM] -- {90140000-0100-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{165AF944-A4D1-4489-B99C-1B87C24C994C} =>.Microsoft Corporation®
O42 - Logiciel: Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit E - (.Microsoft.) [HKLM] -- {90140000-0101-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{28C1C197-5AE9-47D8-8D9D-D665C55A0487} =>.Microsoft Corporation®
O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey =>.Synaptics Incorporated
O42 - Logiciel: System Requirements Lab for Intel - (.Husdawg, LLC.) [HKLM] -- {C7CA731B-BF9A-46D9-92CF-8A8737AE9240} =>.Husdawg, LLC
O42 - Logiciel: Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-001F-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{F63A5E34-3E66-4E59-8314-1CAA9D7B12C6} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-001F-0401-0000-0000000FF1CE}_Office14.PROPLUS_{F63A5E34-3E66-4E59-8314-1CAA9D7B12C6} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-001A-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{3795CAEC-FC75-4CBD-B621-ED6703BF418A} =>.Microsoft Corporation®
O42 - Logiciel: Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0018-0401-0000-0000000FF1CE}_Office14.OMUI.ar-sa_{97F45165-5AE1-4CCE-9143-9897E1BCC04E} =>.Microsoft Corporation®
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM] -- VLC media player =>.VideoLAN
O42 - Logiciel: Windows Live - (.Microsoft Corporation.) [HKLM] -- {34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5} =>.Microsoft Corporation
O42 - Logiciel: Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite =>.Microsoft Corporation®
O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {D45240D3-B6B3-4FF9-B243-54ECE3E10066} =>.Microsoft Corporation
O42 - Logiciel: Windows Live FolderShare - (.Microsoft Corporation.) [HKLM] -- {76810709-A7D3-468D-9167-A1780C1E766C} =>.Microsoft Corporation
O42 - Logiciel: Windows Live ID Sign-in Assistant - (.Microsoft Corporation.) [HKLM] -- {C6150D8A-86ED-41D3-87BB-F3BB51B0B77F} =>.Microsoft Corporation
O42 - Logiciel: Windows Live Installer - (.Microsoft Corporation.) [HKLM] -- {0B0F231F-CE6A-483D-AA23-77B364F75917} =>.Microsoft Corporation
O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {AB61A2E9-37D3-485D-9085-19FBDF8CEF4A} =>.Microsoft Corporation
O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {E5B21F11-6933-4E0B-A25C-7963E3C07D11} =>.Microsoft Corporation
O42 - Logiciel: Windows Live Movie Maker - (.Microsoft Corporation.) [HKLM] -- {6DEC8BD5-7574-47FA-B080-492BBBE2FEA3} =>.Microsoft Corporation
O42 - Logiciel: Windows Live Movie Maker - (.Microsoft Corporation.) [HKLM] -- {92EA4134-10D1-418A-91E1-5A0453131A38} =>.Microsoft Corporation
O42 - Logiciel: Windows Live Photo Common - (.Microsoft Corporation.) [HKLM] -- {A9BDCA6B-3653-467B-AC83-94367DA3BFE3} =>.Microsoft Corporation
O42 - Logiciel: Windows Live Photo Common - (.Microsoft Corporation.) [HKLM] -- {C893D8C0-1BA0-4517-B11C-E89B65E72F70} =>.Microsoft Corporation
O42 - Logiciel: Windows Live Photo Gallery - (.Microsoft Corporation.) [HKLM] -- {3336F667-9049-4D46-98B6-4C743EEBC5B1} =>.Microsoft Corporation
O42 - Logiciel: Windows Live PIMT Platform - (.Microsoft Corporation.) [HKLM] -- {83C292B7-38A5-440B-A731-07070E81A64F} =>.Microsoft Corporation
O42 - Logiciel: Windows Live SOXE - (.Microsoft Corporation.) [HKLM] -- {682B3E4F-696A-42DE-A41C-4C07EA1678B4} =>.Microsoft Corporation
O42 - Logiciel: Windows Live SOXE Definitions - (.Microsoft Corporation.) [HKLM] -- {200FEC62-3C34-4D60-9CE8-EC372E01C08F} =>.Microsoft Corporation
O42 - Logiciel: Windows Live UX Platform - (.Microsoft Corporation.) [HKLM] -- {CE95A79E-E4FC-4FFF-8A75-29F04B942FF2} =>.Microsoft Corporation
O42 - Logiciel: Windows Live UX Platform Language Pack - (.Microsoft Corporation.) [HKLM] -- {05E379CC-F626-4E7D-8354-463865B303BF} =>.Microsoft Corporation
O42 - Logiciel: Windows Media Player Firefox Plugin - (.Microsoft Corp.) [HKLM] -- {69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4} =>.Microsoft Corp
O42 - Logiciel: WinRAR 4.00 beta 1 (32-bit) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver =>.win.rar GmbH

---\\ CLÉ DE REGISTRE SOFTWARE HKCU & HKLM (296) - 42s
HKCU\Software\TeleCharger =>.SUP.Downloader
HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3306339443-3704132785-2724747589-1000\Software\SweetIM =>.SUP.SweetIM
HKLM\SOFTWARE\Adobe =>.Adobe
HKLM\SOFTWARE\AdwCleaner =>.Malwarebytes
HKLM\SOFTWARE\Agere =>.Agere Systems
HKLM\SOFTWARE\Ahead =>.Ahead
HKLM\SOFTWARE\ALWIL Software =>.ALWIL Software
HKLM\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKLM\SOFTWARE\Ashampoo =>.Ashampoo
HKLM\SOFTWARE\ATI Technologies =>.ATI Technologies
HKLM\SOFTWARE\Autodesk =>.Autodesk
HKLM\SOFTWARE\Avira =>.Avira
HKLM\SOFTWARE\AVS4YOU =>.AVS4YOU
HKLM\SOFTWARE\BcmSetup =>.BCM
HKLM\SOFTWARE\BrowserChoice =>.Microsoft Corporation
HKLM\SOFTWARE\Bunndle =>.Unknown
HKLM\SOFTWARE\CDDB =>.Cddb Software
HKLM\SOFTWARE\Crystal Decisions =>.Crystal Decisions
HKLM\SOFTWARE\CyberLink =>.CyberLink Corporation
HKLM\SOFTWARE\Daniusoft
HKLM\SOFTWARE\Dell Computer Corporation =>.Dell Inc.
HKLM\SOFTWARE\Disc Soft =>.Disc Soft
HKLM\SOFTWARE\DT Soft =>.DT Soft Ltd
HKLM\SOFTWARE\ExtendOffice =>.ExtendOffice
HKLM\SOFTWARE\FarStone =>.FarStone
HKLM\SOFTWARE\Foxit Software =>.Foxit Software
HKLM\SOFTWARE\Freemake =>.Freemake
HKLM\SOFTWARE\GHSOF
HKLM\SOFTWARE\Google =>.Google
HKLM\SOFTWARE\HalfBaked =>.HalfBaked
HKLM\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard
HKLM\SOFTWARE\Hewlett-Packard Company =>.Hewlett-Packard Company
HKLM\SOFTWARE\HP =>.HP
HKLM\SOFTWARE\HPQ =>.HPQ
HKLM\SOFTWARE\HPQLOG
HKLM\SOFTWARE\IGC =>.IGC
HKLM\SOFTWARE\IM Providers =>.IM Providers
HKLM\SOFTWARE\InstalledOptions =>.Installed Options
HKLM\SOFTWARE\instinno
HKLM\SOFTWARE\Intel =>.Intel
HKLM\SOFTWARE\Internet Download Manager =>.Tonec Inc
HKLM\SOFTWARE\JavaSoft =>.JavaSoft
HKLM\SOFTWARE\JGsoft =>.JGsoft
HKLM\SOFTWARE\Jodix
HKLM\SOFTWARE\JreMetrics =>.JreMetrics
HKLM\SOFTWARE\Kaydara =>.Kaydara
HKLM\SOFTWARE\Licenses =>.Microsoft Corporation
HKLM\SOFTWARE\LightScribe =>.LightScribe
HKLM\SOFTWARE\LSI =>.LSI
HKLM\SOFTWARE\Macromedia =>.Macromedia
HKLM\SOFTWARE\Mail.Ru =>.Mail.Ru
HKLM\SOFTWARE\mamverifier =>Toolbar.Mamverifier
HKLM\SOFTWARE\Mozilla =>.Mozilla
HKLM\SOFTWARE\mozilla.org =>.mozilla.org
HKLM\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKLM\SOFTWARE\Netscape =>.Netscape
HKLM\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\Opera Software =>.Opera Software
HKLM\SOFTWARE\Panicware =>.Panicware
HKLM\SOFTWARE\PhotoBrush
HKLM\SOFTWARE\Piriform =>.Piriform
HKLM\SOFTWARE\PJ
HKLM\SOFTWARE\RealNetworks =>.RealNetworks
HKLM\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKLM\SOFTWARE\RegistryReviver =>PUP.Optional.RegistryReviver
HKLM\SOFTWARE\Roxio =>.Roxio
HKLM\SOFTWARE\SAKHR
HKLM\SOFTWARE\sharegamescom
HKLM\SOFTWARE\SharingMax
HKLM\SOFTWARE\SiteFinder =>PUP.Optional.ShoppingReport
HKLM\SOFTWARE\Skype =>.Skype
HKLM\SOFTWARE\Sonix =>.Sonix
HKLM\SOFTWARE\StarterBackgroundChanger =>.Renaud Gerson
HKLM\SOFTWARE\Symantec =>.Symantec
HKLM\SOFTWARE\Synaptics =>.Synaptics
HKLM\SOFTWARE\synfigstudio
HKLM\SOFTWARE\VideoLAN =>.VideoLAN
HKLM\SOFTWARE\Volatile =>.Microsoft Corporation
HKLM\SOFTWARE\WafCX =>.WafCX
HKLM\SOFTWARE\Widcomm =>.Widcomm
HKLM\SOFTWARE\WidCommUpdate
HKLM\SOFTWARE\WinPj
HKLM\SOFTWARE\WinRAR =>.WinRAR
HKLM\SOFTWARE\Wise Solutions =>.Wise Solutions
HKLM\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKLM\SOFTWARE\X-AVCSD =>.Avira Software
HKLM\SOFTWARE\Xing Technology Corp. =>.Xing Technology Corp.
HKLM\SOFTWARE\YoutubeDownloader
HKLM\SOFTWARE\WOW6432Node\Google =>.Google
HKCU\SOFTWARE\4shared =>.4shared
HKCU\SOFTWARE\7AndroidRecovery
HKCU\SOFTWARE\Adobe =>.Adobe
HKCU\SOFTWARE\ALWIL Software =>.ALWIL Software
HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKCU\SOFTWARE\Applications WinDev =>.WinDev
HKCU\SOFTWARE\Ashampoo =>.Ashampoo
HKCU\SOFTWARE\Authorsoft =>.Authorsoft
HKCU\SOFTWARE\Autodesk =>.Autodesk
HKCU\SOFTWARE\AVAST Software =>.AVAST Software
HKCU\SOFTWARE\Avira =>.Avira
HKCU\SOFTWARE\AVS4YOU =>.AVS4YOU
HKCU\SOFTWARE\BackgroundChanger
HKCU\SOFTWARE\BankPerfect =>.Fabio Chelly
HKCU\SOFTWARE\BrowserTemp =>.Legitimate
HKCU\SOFTWARE\BugSplat =>.Bugsplat Game
HKCU\SOFTWARE\CDDB =>.Cddb Software
HKCU\SOFTWARE\Chromium =>.Chromium
HKCU\SOFTWARE\Citrix =>.Citrix
HKCU\SOFTWARE\Crystal Decisions =>.Crystal Decisions
HKCU\SOFTWARE\CyberLink =>.CyberLink Corporation
HKCU\SOFTWARE\Digital River =>.Digital River Entreprise
HKCU\SOFTWARE\DigitByteStudio =>.DigitByte Studio
HKCU\SOFTWARE\DiMXSoft =>.DiMXSoft
HKCU\SOFTWARE\Disc Soft =>.Disc Soft
HKCU\SOFTWARE\DsAudioDevice_310
HKCU\SOFTWARE\DT Soft =>.DT Soft Ltd
HKCU\SOFTWARE\e-dico
HKCU\SOFTWARE\ExtendOffice =>.ExtendOffice
HKCU\SOFTWARE\Facebook =>.Facebook
HKCU\SOFTWARE\fet
HKCU\SOFTWARE\Foxit Software =>.Foxit Software
HKCU\SOFTWARE\Freemake =>.Freemake
HKCU\SOFTWARE\GNU =>.GNU
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\GotClip Downloader
HKCU\SOFTWARE\GSettings =>.Legitimate
HKCU\SOFTWARE\HalfBaked =>.HalfBaked
HKCU\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard
HKCU\SOFTWARE\ICQ =>.ICQ
HKCU\SOFTWARE\IM Providers =>.IM Providers
HKCU\SOFTWARE\Intel =>.Intel
HKCU\SOFTWARE\Intelore
HKCU\SOFTWARE\JavaSoft =>.JavaSoft
HKCU\SOFTWARE\Kroll OnTrack =>.Kroll OnTrack
HKCU\SOFTWARE\LANGAGENT =>.LangAgent
HKCU\SOFTWARE\LBSU
HKCU\SOFTWARE\Licenses =>.Microsoft Corporation
HKCU\SOFTWARE\LightScribe =>.LightScribe
HKCU\SOFTWARE\Local AppWizard-Generated Applications =>.ZWCAD
HKCU\SOFTWARE\LowRegistry =>.Unknown
HKCU\SOFTWARE\Macromedia =>.Macromedia
HKCU\SOFTWARE\Magnet =>.Magnet
HKCU\SOFTWARE\Mail.Ru =>.Mail.Ru
HKCU\SOFTWARE\MatchWare =>.MatchWare
HKCU\SOFTWARE\Mobile Action =>.Mobile Action
HKCU\SOFTWARE\Move Media Player
HKCU\SOFTWARE\MoveNetworks
HKCU\SOFTWARE\Mozilla =>.Mozilla
HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKCU\SOFTWARE\Netscape =>.Netscape
HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKCU\SOFTWARE\Odboso
HKCU\SOFTWARE\Opera Software =>.Opera Software
HKCU\SOFTWARE\Panicware =>.Panicware
HKCU\SOFTWARE\PasswordTools
HKCU\SOFTWARE\PC SOFT =>.PC SOFT
HKCU\SOFTWARE\PDF Architect =>.pdfforge GmbH
HKCU\SOFTWARE\PhotoFiltre 7 =>.Antonio Da Cruz
HKCU\SOFTWARE\PhotoTouch
HKCU\SOFTWARE\Piriform =>.Piriform
HKCU\SOFTWARE\QtProject =>.QtProject
HKCU\SOFTWARE\RealNetworks =>.RealNetworks
HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\SAKHR
HKCU\SOFTWARE\SecureMedia
HKCU\SOFTWARE\Skype =>.Skype
HKCU\SOFTWARE\SkypeRS =>.Skype Technologies
HKCU\SOFTWARE\Smart Soft =>.Smart Soft
HKCU\SOFTWARE\SoundTaxi Media Suite
HKCU\SOFTWARE\StarterBackgroundChanger =>.Renaud Gerson
HKCU\SOFTWARE\SubSystems =>.Sub Systems Inc
HKCU\SOFTWARE\SuperSoftwarePackage
HKCU\SOFTWARE\Synaptics =>.Synaptics
HKCU\SOFTWARE\System Requirements Lab =>.System Requirements Lab
HKCU\SOFTWARE\The Silicon Realms Toolworks =>.The Silicon Realms Toolworks
HKCU\SOFTWARE\V-Book
HKCU\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation
HKCU\SOFTWARE\Widcomm =>.Widcomm
HKCU\SOFTWARE\WinRAR =>.WinRAR
HKCU\SOFTWARE\WinRAR SFX =>.RarLab
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman
HKCU\SOFTWARE\AppDataLow\Google =>.Google
HKCU\SOFTWARE\AppDataLow\RealNetworks =>.RealNetworks
HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation
HKCU\SOFTWARE\AppDataLow\Software\Adobe =>.Adobe
HKCU\SOFTWARE\AppDataLow\Software\Google =>.Google
HKCU\SOFTWARE\AppDataLow\Software\JavaSoft =>.JavaSoft
HKCU\SOFTWARE\AppDataLow\Software\Mail.Ru =>.Mail.Ru
HKU\.DEFAULT\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKU\.DEFAULT\SOFTWARE\Avast Software =>.AVAST Software
HKU\.DEFAULT\SOFTWARE\Avira =>.Avira
HKU\.DEFAULT\SOFTWARE\DownloadManager =>.DownloadManager
HKU\.DEFAULT\SOFTWARE\Farstone =>.FarStone
HKU\.DEFAULT\SOFTWARE\Foxit Software =>.Foxit Software
HKU\.DEFAULT\SOFTWARE\Google =>.Google
HKU\.DEFAULT\SOFTWARE\HalfBaked =>.HalfBaked
HKU\.DEFAULT\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard
HKU\.DEFAULT\SOFTWARE\Lexmark =>.Lexmark
HKU\.DEFAULT\SOFTWARE\Macromedia =>.Macromedia
HKU\.DEFAULT\SOFTWARE\Netscape =>.Netscape
HKU\.DEFAULT\SOFTWARE\Piriform =>.Piriform
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\4shared =>.4shared
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\7AndroidRecovery
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Adobe =>.Adobe
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\ALWIL Software =>.ALWIL Software
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\AppDataLow =>.Microsoft Corporation
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Applications WinDev =>.WinDev
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Ashampoo =>.Ashampoo
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Authorsoft =>.Authorsoft
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Autodesk =>.Autodesk
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\AVAST Software =>.AVAST Software
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Avira =>.Avira
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\AVS4YOU =>.AVS4YOU
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\BackgroundChanger
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\BankPerfect =>.Fabio Chelly
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\BrowserTemp =>.Legitimate
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\BugSplat =>.Bugsplat Game
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\CDDB =>.Cddb Software
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Chromium =>.Chromium
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Citrix =>.Citrix
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Crystal Decisions =>.Crystal Decisions
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\CyberLink =>.CyberLink Corporation
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Digital River =>.Digital River Entreprise
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\DigitByteStudio =>.DigitByte Studio
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\DiMXSoft =>.DiMXSoft
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Disc Soft =>.Disc Soft
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\DsAudioDevice_310
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\DT Soft =>.DT Soft Ltd
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\e-dico
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\ExtendOffice =>.ExtendOffice
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Facebook =>.Facebook
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\fet
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Foxit Software =>.Foxit Software
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Freemake =>.Freemake
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\GNU =>.GNU
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Google =>.Google
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\GotClip Downloader
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\GSettings =>.Legitimate
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\HalfBaked =>.HalfBaked
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\ICQ =>.ICQ
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\IM Providers =>.IM Providers
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Intel =>.Intel
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Intelore
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\JavaSoft =>.JavaSoft
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Kroll OnTrack =>.Kroll OnTrack
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\LANGAGENT =>.LangAgent
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\LBSU
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Licenses =>.Microsoft Corporation
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\LightScribe =>.LightScribe
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Local AppWizard-Generated Applications =>.ZWCAD
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\LowRegistry =>.Unknown
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Macromedia =>.Macromedia
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Magnet =>.Magnet
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Mail.Ru =>.Mail.Ru
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\MatchWare =>.MatchWare
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Mobile Action =>.Mobile Action
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Move Media Player
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\MoveNetworks
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Mozilla =>.Mozilla
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\MozillaPlugins =>.MozillaPlugins
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Netscape =>.Netscape
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\ODBC =>.DB Connectivity Solutions
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Odboso
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Opera Software =>.Opera Software
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Panicware =>.Panicware
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\PasswordTools
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\PC SOFT =>.PC SOFT
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\PDF Architect =>.pdfforge GmbH
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\PhotoFiltre 7 =>.Antonio Da Cruz
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\PhotoTouch
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Piriform =>.Piriform
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\QtProject =>.QtProject
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\RealNetworks =>.RealNetworks
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\RegisteredApplications =>.Microsoft Corporation
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\SAKHR
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\SecureMedia
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Skype =>.Skype
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\SkypeRS =>.Skype Technologies
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Smart Soft =>.Smart Soft
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\SoundTaxi Media Suite
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\StarterBackgroundChanger =>.Renaud Gerson
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\SubSystems =>.Sub Systems Inc
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\SuperSoftwarePackage
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Synaptics =>.Synaptics
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\System Requirements Lab =>.System Requirements Lab
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\TeleCharger
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\The Silicon Realms Toolworks =>.The Silicon Realms Toolworks
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\V-Book
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Widcomm =>.Widcomm
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\WinRAR =>.WinRAR
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\WinRAR SFX =>.RarLab
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKU\S-1-5-21-3306339443-3704132785-2724747589-1000\SOFTWARE\ZHP =>.Nicolas Coolman

---\\ CONTENU DES DOSSIERS PROGRAMMES (321) - 126s
O43 - CFD: 29/03/2017 - [] D -- C:\Program Files\Adobe =>.Adobe Systems Incorporated®
O43 - CFD: 16/04/2015 - [] D -- C:\Program Files\Ashampoo =>.Ashampoo GmbH
O43 - CFD: 30/10/2009 - [] D -- C:\Program Files\ATI =>.ATI Technologies, Inc®
O43 - CFD: 30/10/2009 - [0] D -- C:\Program Files\ATI Technologies =>.ATI Technologies
O43 - CFD: 01/01/2011 - [] D -- C:\Program Files\Autodesk =>.Autodesk
O43 - CFD: 07/07/2015 - [] D -- C:\Program Files\Avira =>.Avira Software
O43 - CFD: 02/11/2011 - [] D -- C:\Program Files\BankPerfect =>.Fabio Chelly
O43 - CFD: 30/10/2009 - [] D -- C:\Program Files\Broadcom =>.Broadcom Corporation®
O43 - CFD: 10/03/2014 - [] D -- C:\Program Files\CCleaner =>.Piriform Ltd
O43 - CFD: 15/10/2017 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 24/05/2013 - [] D -- C:\Program Files\CyberLink =>.CyberLink Corporation
O43 - CFD: 18/05/2012 - [] D -- C:\Program Files\denouvel
O43 - CFD: 01/04/2016 - [] D -- C:\Program Files\Desktop Lighter
O43 - CFD: 20/10/2011 - [] D -- C:\Program Files\DVD Maker =>.Aone Software
O43 - CFD: 30/10/2009 - [] D -- C:\Program Files\FarStone =>.FarStone
O43 - CFD: 30/10/2009 - [0] SHD -- C:\Program Files\Fichiers communs =>.Microsoft Corporation
O43 - CFD: 16/10/2018 - [] D -- C:\Program Files\Free WMA to MP3 Converter
O43 - CFD: 08/03/2013 - [] D -- C:\Program Files\Freemake =>.Freemake
O43 - CFD: 10/09/2013 - [] D -- C:\Program Files\Ghostgum
O43 - CFD: 29/10/2018 - [] D -- C:\Program Files\Google =>.Google Inc®
O43 - CFD: 03/10/2015 - [] D -- C:\Program Files\GUM5456.tmp
O43 - CFD: 18/05/2018 - [] D -- C:\Program Files\GUMF066.tmp =>.Google Inc®
O43 - CFD: 23/09/2011 - [] D -- C:\Program Files\Hewlett-Packard =>.Hewlett-Packard
O43 - CFD: 24/05/2013 - [] HD -- C:\Program Files\InstallShield Installation Information =>.InstallShield
O43 - CFD: 27/01/2013 - [] D -- C:\Program Files\Intel =>.Intel Corporation
O43 - CFD: 27/06/2014 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 09/03/2016 - [] D -- C:\Program Files\Java =>.Oracle
O43 - CFD: 12/10/2015 - [] D -- C:\Program Files\KMSpico =>HackTool.KMSpico
O43 - CFD: 30/10/2009 - [] D -- C:\Program Files\LSI SoftModem =>.LSI Corporation
O43 - CFD: 06/12/2011 - [] D -- C:\Program Files\Microsoft Analysis Services =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Microsoft Games =>.Microsoft Corporation
O43 - CFD: 25/03/2018 - [] D -- C:\Program Files\Microsoft Office =>.Microsoft Corporation
O43 - CFD: 17/08/2015 - [] D -- C:\Program Files\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 22/04/2016 - [] D -- C:\Program Files\Microsoft SQL Server =>.Microsoft Corporation
O43 - CFD: 06/12/2011 - [] D -- C:\Program Files\Microsoft SQL Server Compact Edition =>.Microsoft Corporation
O43 - CFD: 06/12/2011 - [] D -- C:\Program Files\Microsoft Synchronization Services =>.Microsoft Corporation
O43 - CFD: 03/10/2015 - [] D -- C:\Program Files\Microsoft Visual Studio 8 =>.Microsoft Corporation
O43 - CFD: 22/04/2016 - [] D -- C:\Program Files\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 29/02/2012 - [] D -- C:\Program Files\MotdePasse
O43 - CFD: 03/11/2018 - [] D -- C:\Program Files\Mozilla Firefox =>.Mozilla
O43 - CFD: 02/11/2018 - [] D -- C:\Program Files\Mozilla Maintenance Service =>.Mozilla
O43 - CFD: 09/10/2015 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 29/04/2014 - [] D -- C:\Program Files\MSECache =>.Microsoft Corporation
O43 - CFD: 07/01/2011 - [0] D -- C:\Program Files\MSXML 4.0 =>.Microsoft Corporation
O43 - CFD: 06/05/2013 - [] D -- C:\Program Files\Open XML SDK =>.Microsoft Corporation
O43 - CFD: 22/06/2015 - [] D -- C:\Program Files\Opera =>.Opera Software
O43 - CFD: 07/02/2015 - [] D -- C:\Program Files\Panicware
O43 - CFD: 22/12/2013 - [] D -- C:\Program Files\PhotoFiltre 7 =>.Antonio Da Cruz
O43 - CFD: 21/01/2011 - [] D -- C:\Program Files\Real =>.RealNetworks Inc.
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 30/10/2009 - [] D -- C:\Program Files\Synaptics =>.Synaptics Incorporated®
O43 - CFD: 01/02/2013 - [] D -- C:\Program Files\SystemRequirementsLab =>.System Requirements Lab
O43 - CFD: 09/11/2017 - [] D -- C:\Program Files\TrackView
O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation
O43 - CFD: 30/10/2009 - [] D -- C:\Program Files\VideoLAN =>.VideoLan Team
O43 - CFD: 30/10/2009 - [] D -- C:\Program Files\WIDCOMM =>.Broadcom Corporation®
O43 - CFD: 11/08/2013 - [] D -- C:\Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 25/04/2013 - [] D -- C:\Program Files\Windows Live =>.Microsoft Corporation
O43 - CFD: 20/10/2011 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 26/07/2015 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 30/10/2009 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 20/10/2011 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 20/10/2011 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 20/10/2011 - [] D -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 15/11/2010 - [] D -- C:\Program Files\WinRAR =>.WinRAR
O43 - CFD: 21/02/2017 - [] D -- C:\Program Files\القرآن الكريم
O43 - CFD: 21/11/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 24/01/2010 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo =>.Ashampoo GmbH
O43 - CFD: 29/10/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira =>.Avira Software
O43 - CFD: 24/05/2013 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam 5 =>.CyberLink Corporation
O43 - CFD: 01/04/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desktop Lighter
O43 - CFD: 30/10/2009 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriveClone Pro
O43 - CFD: 06/11/2014 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake =>.Freemake
O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 23/03/2012 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP =>.Hewlett-Packard
O43 - CFD: 11/03/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java =>.Oracle
O43 - CFD: 16/10/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jodix =>.Jodix Technologies
O43 - CFD: 30/10/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling =>.LightScribe
O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 25/03/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 =>.Microsoft Corporation
O43 - CFD: 17/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight =>.Microsoft Corporation
O43 - CFD: 15/05/2011 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils PC SOFT
O43 - CFD: 07/02/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panicware
O43 - CFD: 22/12/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre 7 =>.Antonio Da Cruz
O43 - CFD: 31/01/2013 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real =>.RealNetworks Inc.
O43 - CFD: 21/11/2014 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 26/07/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team
O43 - CFD: 26/06/2011 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live =>.Microsoft Corporation
O43 - CFD: 15/11/2010 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 21/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\القرآن الكريم
O43 - CFD: 29/03/2017 - [] D -- C:\ProgramData\Adobe =>.Adobe
O43 - CFD: 30/05/2015 - [] D -- C:\ProgramData\Apple =>.Apple Inc.
O43 - CFD: 30/05/2015 - [] D -- C:\ProgramData\Apple Computer =>.Apple Inc.
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 24/01/2010 - [] D -- C:\ProgramData\ashampoo =>.Ashampoo GmbH
O43 - CFD: 02/06/2015 - [] D -- C:\ProgramData\Avira =>.Avira Software
O43 - CFD: 07/06/2017 - [] D -- C:\ProgramData\BatteryOptimizer.exe
O43 - CFD: 30/10/2009 - [0] SHD -- C:\ProgramData\Bureau =>.Microsoft Corporation
O43 - CFD: 08/05/2013 - [] D -- C:\ProgramData\CyberLink =>.CyberLink Corporation
O43 - CFD: 08/02/2014 - [] D -- C:\ProgramData\DAEMON Tools Lite =>.DAEMON Tools
O43 - CFD: 30/11/2012 - [] D -- C:\ProgramData\DAEMON Tools Pro =>.The DAEMON Team
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 30/10/2009 - [] D -- C:\ProgramData\FarStone =>.FarStone
O43 - CFD: 30/10/2009 - [0] SHD -- C:\ProgramData\Favoris =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Favorites =>.Microsoft Corporation
O43 - CFD: 06/11/2014 - [] D -- C:\ProgramData\Freemake =>.Freemake
O43 - CFD: 04/07/2013 - [] D -- C:\ProgramData\Google =>.Google
O43 - CFD: 16/12/2010 - [] D -- C:\ProgramData\Hewlett-Packard =>.Hewlett-Packard
O43 - CFD: 23/03/2012 - [] D -- C:\ProgramData\HP =>.Hewlett-Packard
O43 - CFD: 11/01/2013 - [] D -- C:\ProgramData\Installations =>.Unknown
O43 - CFD: 30/01/2014 - [] D -- C:\ProgramData\InstallMate =>Adware.Tarma
O43 - CFD: 08/05/2013 - [] D -- C:\ProgramData\install_clap =>.Microsoft Corporation
O43 - CFD: 23/03/2016 - [] D -- C:\ProgramData\IsolatedStorage =>.id Software
O43 - CFD: 03/10/2015 - [] D -- C:\ProgramData\Licenses =>.Microsoft Corporation
O43 - CFD: 26/02/2012 - [] D -- C:\ProgramData\McAfee =>.McAfee
O43 - CFD: 30/10/2009 - [0] SHD -- C:\ProgramData\Menu Démarrer =>.Microsoft Corporation
O43 - CFD: 25/03/2018 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 25/03/2018 - [] D -- C:\ProgramData\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 12/10/2015 - [] D -- C:\ProgramData\Microsoft Toolkit =>.Microsoft Corporation
O43 - CFD: 30/10/2009 - [0] SHD -- C:\ProgramData\Modèles =>.Microsoft Corporation
O43 - CFD: 30/04/2012 - [] D -- C:\ProgramData\Mozilla =>.Mozilla Corporation
O43 - CFD: 21/02/2011 - [] D -- C:\ProgramData\Norton =>.Symantec Corporation
O43 - CFD: 21/02/2011 - [] D -- C:\ProgramData\NortonInstaller =>.Symantec
O43 - CFD: 09/03/2016 - [] D -- C:\ProgramData\Oracle =>.Oracle
O43 - CFD: 16/10/2018 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation
O43 - CFD: 27/01/2017 - [] D -- C:\ProgramData\pdf-watermark-remover-wm
O43 - CFD: 26/07/2013 - [] D -- C:\ProgramData\Real =>.RealNetworks Inc.
O43 - CFD: 25/03/2018 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation
O43 - CFD: 21/02/2011 - [] D -- C:\ProgramData\Symantec =>.Symantec
O43 - CFD: 03/10/2015 - [] AD -- C:\ProgramData\TEMP =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation
O43 - CFD: 29/04/2011 - [] D -- C:\ProgramData\Uninstall =>.Unknown
O43 - CFD: 19/05/2012 - [0] D -- C:\ProgramData\widdit-toolbar
O43 - CFD: 15/10/2017 - [] D -- C:\ProgramData\wsr
O43 - CFD: 16/12/2010 - [] D -- C:\ProgramData\{23D58E70-3B83-4B83-A227-68770F84F5EC} =>.RarLab
O43 - CFD: 23/09/2011 - [] D -- C:\ProgramData\{D3B41B92-9BC2-43EB-916A-4FA9E8191837}
O43 - CFD: 06/07/2011 - [] D -- C:\ProgramData\{E91883C8-8CDC-46A4-A45F-CB40EB82ED60}
O43 - CFD: 29/03/2017 - [] D -- C:\Program Files\Common Files\Adobe =>.Adobe
O43 - CFD: 12/07/2014 - [] D -- C:\Program Files\Common Files\Adobe AIR =>.Adobe Inc.
O43 - CFD: 09/01/2011 - [0] D -- C:\Program Files\Common Files\Autodesk Shared =>.Autodesk
O43 - CFD: 13/02/2015 - [] D -- C:\Program Files\Common Files\AVSMedia =>.AVSMedia
O43 - CFD: 22/09/2013 - [] D -- C:\Program Files\Common Files\Business Objects =>.Business Objects
O43 - CFD: 22/04/2016 - [] D -- C:\Program Files\Common Files\DESIGNER =>.Designer
O43 - CFD: 09/10/2011 - [] D -- C:\Program Files\Common Files\InstallShield =>.InstallShield
O43 - CFD: 11/03/2016 - [] D -- C:\Program Files\Common Files\Java =>.Oracle
O43 - CFD: 30/10/2009 - [] D -- C:\Program Files\Common Files\LightScribe =>.LightScribe
O43 - CFD: 25/03/2018 - [] D -- C:\Program Files\Common Files\microsoft shared =>.Microsoft Corporation
O43 - CFD: 15/05/2011 - [] D -- C:\Program Files\Common Files\PC SOFT =>.PC Soft
O43 - CFD: 14/05/2013 - [0] D -- C:\Program Files\Common Files\PDF Architect =>.pdfforge GmbH
O43 - CFD: 21/01/2011 - [] D -- C:\Program Files\Common Files\Real =>.RealNetworks Inc.
O43 - CFD: 29/04/2011 - [] D -- C:\Program Files\Common Files\Roxio Shared =>.Roxio
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 30/10/2009 - [] D -- C:\Program Files\Common Files\SNP2UVC =>.Sonix
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files\Common Files\SpeechEngines =>.Microsoft Corporation
O43 - CFD: 03/01/2012 - [] D -- C:\Program Files\Common Files\System =>.Microsoft Corporation
O43 - CFD: 25/11/2009 - [] D -- C:\Program Files\Common Files\Windows Live =>.Microsoft Corporation
O43 - CFD: 29/12/2010 - [] D -- C:\Program Files\Common Files\xing shared =>.Xing
O43 - CFD: 04/07/2013 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 30/05/2015 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Apple Computer =>.Apple Inc.
O43 - CFD: 24/01/2010 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Ashampoo =>.Ashampoo GmbH
O43 - CFD: 01/01/2011 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Autodesk =>.Autodesk
O43 - CFD: 21/04/2015 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Avira =>.Avira Software
O43 - CFD: 02/02/2014 - [] D -- C:\Users\Utilisateur\AppData\Roaming\AVS4YOU =>.AVS4YOU
O43 - CFD: 25/03/2018 - [] D -- C:\Users\Utilisateur\AppData\Roaming\BankPerfect =>.Fabio Chelly
O43 - CFD: 15/04/2010 - [0] D -- C:\Users\Utilisateur\AppData\Roaming\COWON =>.COWON
O43 - CFD: 08/05/2013 - [] D -- C:\Users\Utilisateur\AppData\Roaming\CyberLink =>.CyberLink Corporation
O43 - CFD: 10/03/2014 - [] D -- C:\Users\Utilisateur\AppData\Roaming\DAEMON Tools Lite =>.DAEMON Tools
O43 - CFD: 30/11/2012 - [] D -- C:\Users\Utilisateur\AppData\Roaming\DAEMON Tools Pro =>.The DAEMON Team
O43 - CFD: 28/06/2016 - [0] D -- C:\Users\Utilisateur\AppData\Roaming\DMCache =>.DMCache
O43 - CFD: 20/05/2013 - [] D -- C:\Users\Utilisateur\AppData\Roaming\dvdcss =>.VideoLan Team
O43 - CFD: 04/07/2013 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Foxit Software =>.Foxit Software
O43 - CFD: 16/07/2014 - [] D -- C:\Users\Utilisateur\AppData\Roaming\fr.edumedia.genie.ao3.primaire-a3
O43 - CFD: 16/07/2014 - [] D -- C:\Users\Utilisateur\AppData\Roaming\fr.edumedia.genie.lot-1.a4
O43 - CFD: 17/06/2014 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Free PDF to Word Converter =>.Smart Soft
O43 - CFD: 29/12/2010 - [] D -- C:\Users\Utilisateur\AppData\Roaming\FreeAudioPack =>.FreeAudioPack
O43 - CFD: 04/10/2010 - [] D -- C:\Users\Utilisateur\AppData\Roaming\FreeFLVConverter =>.Koyote Soft
O43 - CFD: 08/03/2013 - [] D -- C:\Users\Utilisateur\AppData\Roaming\FreemakeVideoDownloader =>.Ellora Assets Corporation
O43 - CFD: 09/03/2016 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Freeplane
O43 - CFD: 28/06/2012 - [] D -- C:\Users\Utilisateur\AppData\Roaming\GetRightToGo =>.Headlight Software
O43 - CFD: 30/10/2009 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Google =>.Google
O43 - CFD: 16/12/2010 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Hewlett-Packard =>.Hewlett-Packard
O43 - CFD: 23/03/2012 - [] D -- C:\Users\Utilisateur\AppData\Roaming\hpqLog =>.Hewlett-Packard
O43 - CFD: 23/04/2014 - [] D -- C:\Users\Utilisateur\AppData\Roaming\ICQM
O43 - CFD: 30/10/2009 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Identities =>.Microsoft Corporation
O43 - CFD: 01/01/2011 - [] D -- C:\Users\Utilisateur\AppData\Roaming\IGC =>.IGC
O43 - CFD: 30/10/2009 - [] D -- C:\Users\Utilisateur\AppData\Roaming\InstallShield =>.InstallShield
O43 - CFD: 29/04/2014 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Intelore =>.Intelore
O43 - CFD: 23/03/2016 - [] D -- C:\Users\Utilisateur\AppData\Roaming\IsolatedStorage =>.id Software
O43 - CFD: 07/01/2011 - [] D -- C:\Users\Utilisateur\AppData\Roaming\LG Electronics =>.LG Electronics
O43 - CFD: 30/10/2009 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 28/06/2016 - [] SD -- C:\Users\Utilisateur\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 11/02/2013 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Mobile Action =>.Mobile Action
O43 - CFD: 20/05/2011 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Move Networks
O43 - CFD: 15/11/2017 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 04/07/2012 - [] D -- C:\Users\Utilisateur\AppData\Roaming\OfficeRecovery
O43 - CFD: 03/10/2015 - [] D -- C:\Users\Utilisateur\AppData\Roaming\OfficeTab =>.Extendoffice.com
O43 - CFD: 22/06/2015 - [0] D -- C:\Users\Utilisateur\AppData\Roaming\Opera =>.Opera Software
O43 - CFD: 19/11/2014 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Orion =>.Synapse Audio Software
O43 - CFD: 14/05/2013 - [] D -- C:\Users\Utilisateur\AppData\Roaming\PDF Architect =>.pdfforge GmbH
O43 - CFD: 26/07/2013 - [] D -- C:\Users\Utilisateur\AppData\Roaming\PhotoFiltre =>.Antonio Da Cruz
O43 - CFD: 11/03/2016 - [] D -- C:\Users\Utilisateur\AppData\Roaming\PhotoFiltre 7 =>.Antonio Da Cruz
O43 - CFD: 27/05/2015 - [] D -- C:\Users\Utilisateur\AppData\Roaming\QuickScan =>.Bitdefender
O43 - CFD: 31/01/2013 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Real =>.RealNetworks Inc.
O43 - CFD: 16/11/2010 - [] D -- C:\Users\Utilisateur\AppData\Roaming\RGE
O43 - CFD: 30/10/2009 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Roxio Log Files =>.Roxio
O43 - CFD: 21/03/2010 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Shareaza =>.Shareaza (P2P)
O43 - CFD: 02/02/2015 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Skype =>.Skype
O43 - CFD: 30/04/2011 - [] D -- C:\Users\Utilisateur\AppData\Roaming\skypePM =>.Skype Technologies
O43 - CFD: 09/03/2016 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Sun =>.Oracle
O43 - CFD: 18/06/2011 - [] D -- C:\Users\Utilisateur\AppData\Roaming\U3 =>.U3
O43 - CFD: 14/05/2018 - [] D -- C:\Users\Utilisateur\AppData\Roaming\vlc =>.VideoLan Team
O43 - CFD: 19/11/2014 - [0] D -- C:\Users\Utilisateur\AppData\Roaming\WebTest =>.Python
O43 - CFD: 08/12/2009 - [] D -- C:\Users\Utilisateur\AppData\Roaming\WinRAR =>.WinRAR
O43 - CFD: 11/03/2014 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Youtube Downloader HD =>.Regensoft
O43 - CFD: 13/11/2018 - [] D -- C:\Users\Utilisateur\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 30/10/2009 - [] D -- C:\Users\Utilisateur\AppData\Roaming\{8126D2ED-1984-4573-9D57-97637E10C716}
O43 - CFD: 30/03/2017 - [] D -- C:\Users\Utilisateur\AppData\Local\Adobe =>.Adobe
O43 - CFD: 30/05/2015 - [] D -- C:\Users\Utilisateur\AppData\Local\Apple =>.Apple Inc.
O43 - CFD: 30/05/2015 - [] D -- C:\Users\Utilisateur\AppData\Local\Apple Computer =>.Apple Inc.
O43 - CFD: 30/10/2009 - [0] SHD -- C:\Users\Utilisateur\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 06/05/2013 - [] D -- C:\Users\Utilisateur\AppData\Local\Apps =>.Microsoft Corporation
O43 - CFD: 08/01/2010 - [] D -- C:\Users\Utilisateur\AppData\Local\Ares
O43 - CFD: 24/01/2010 - [] D -- C:\Users\Utilisateur\AppData\Local\ashampoo =>.Ashampoo GmbH
O43 - CFD: 01/01/2011 - [] D -- C:\Users\Utilisateur\AppData\Local\Autodesk =>.Autodesk
O43 - CFD: 30/10/2009 - [] D -- C:\Users\Utilisateur\AppData\Local\Broadcom =>.Broadcom
O43 - CFD: 30/03/2017 - [] D -- C:\Users\Utilisateur\AppData\Local\CEF =>.CEF
O43 - CFD: 28/06/2016 - [] D -- C:\Users\Utilisateur\AppData\Local\Citrix =>.Citrix
O43 - CFD: 30/01/2014 - [] D -- C:\Users\Utilisateur\AppData\Local\Comodo =>.Comodo Group.
O43 - CFD: 16/04/2015 - [] D -- C:\Users\Utilisateur\AppData\Local\CrashRpt
O43 - CFD: 08/05/2013 - [] D -- C:\Users\Utilisateur\AppData\Local\CyberLink =>.CyberLink Corporation
O43 - CFD: 20/08/2013 - [0] D -- C:\Users\Utilisateur\AppData\Local\Deployment =>.Microsoft Corporation
O43 - CFD: 26/04/2018 - [0] D -- C:\Users\Utilisateur\AppData\Local\Diagnostics =>.Microsoft Corporation
O43 - CFD: 12/01/2018 - [0] D -- C:\Users\Utilisateur\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation
O43 - CFD: 28/06/2014 - [] SHD -- C:\Users\Utilisateur\AppData\Local\EmieSiteList =>.Enterprise mode Site List Mgr
O43 - CFD: 28/06/2014 - [] SHD -- C:\Users\Utilisateur\AppData\Local\EmieUserList =>.Enterprise mode Site List Mgr
O43 - CFD: 13/02/2015 - [] D -- C:\Users\Utilisateur\AppData\Local\Facebook =>.Facebook
O43 - CFD: 20/03/2016 - [] D -- C:\Users\Utilisateur\AppData\Local\fontconfig =>.Portable Apps
O43 - CFD: 29/10/2017 - [] D -- C:\Users\Utilisateur\AppData\Local\Google =>.Google
O43 - CFD: 01/06/2015 - [] D -- C:\Users\Utilisateur\AppData\Local\GWX =>.GWX
O43 - CFD: 01/02/2013 - [] D -- C:\Users\Utilisateur\AppData\Local\Hewlett-Packard =>.Hewlett-Packard
O43 - CFD: 30/10/2009 - [0] SHD -- C:\Users\Utilisateur\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 16/04/2015 - [] D -- C:\Users\Utilisateur\AppData\Local\Installer
O43 - CFD: 08/07/2012 - [] D -- C:\Users\Utilisateur\AppData\Local\Macromedia =>.Macromedia
O43 - CFD: 09/11/2018 - [] D -- C:\Users\Utilisateur\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 16/01/2010 - [] D -- C:\Users\Utilisateur\AppData\Local\Microsoft Games =>.Microsoft Corporation
O43 - CFD: 21/06/2018 - [] D -- C:\Users\Utilisateur\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 01/10/2013 - [] D -- C:\Users\Utilisateur\AppData\Local\Mozilla =>.Mozilla Corporation
O43 - CFD: 22/06/2015 - [0] D -- C:\Users\Utilisateur\AppData\Local\Opera =>.Opera Software
O43 - CFD: 13/05/2013 - [] D -- C:\Users\Utilisateur\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 30/10/2009 - [] D -- C:\Users\Utilisateur\AppData\Local\Roxio =>.Roxio
O43 - CFD: 19/12/2009 - [] D -- C:\Users\Utilisateur\AppData\Local\Shareaza =>.Shareaza (P2P)
O43 - CFD: 29/04/2014 - [] D -- C:\Users\Utilisateur\AppData\Local\Skype =>.Skype
O43 - CFD: 13/11/2018 - [] D -- C:\Users\Utilisateur\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 30/10/2009 - [0] SHD -- C:\Users\Utilisateur\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 09/02/2010 - [] D -- C:\Users\Utilisateur\AppData\Local\VirtualStore =>.Microsoft Corporation
O43 - CFD: 20/08/2016 - [] D -- C:\Users\Utilisateur\AppData\Local\Windows Live =>.Microsoft Corporation
O43 - CFD: 15/10/2017 - [] D -- C:\Users\Utilisateur\AppData\Local\Wondershare =>.Wondershare
O43 - CFD: 13/11/2018 - [] D -- C:\Users\Utilisateur\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 13/05/2013 - [0] D -- C:\Users\Utilisateur\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 01/10/2018 - [] D -- C:\Users\Utilisateur\AppData\LocalLow\Adobe =>.Adobe
O43 - CFD: 06/07/2012 - [] D -- C:\Users\Utilisateur\AppData\LocalLow\DataMngr =>Adware.Searchqu
O43 - CFD: 28/06/2014 - [] SHD -- C:\Users\Utilisateur\AppData\LocalLow\EmieSiteList =>.Enterprise mode Site List Mgr
O43 - CFD: 28/06/2014 - [] SHD -- C:\Users\Utilisateur\AppData\LocalLow\EmieUserList =>.Enterprise mode Site List Mgr
O43 - CFD: 29/10/2010 - [0] D -- C:\Users\Utilisateur\AppData\LocalLow\ge2132
O43 - CFD: 29/10/2010 - [0] D -- C:\Users\Utilisateur\AppData\LocalLow\ge4092
O43 - CFD: 14/05/2011 - [] D -- C:\Users\Utilisateur\AppData\LocalLow\Google =>.Google
O43 - CFD: 17/03/2013 - [] D -- C:\Users\Utilisateur\AppData\LocalLow\Microsoft =>.Microsoft Corporation
O43 - CFD: 02/04/2012 - [] D -- C:\Users\Utilisateur\AppData\LocalLow\Move Networks
O43 - CFD: 13/11/2018 - [] D -- C:\Users\Utilisateur\AppData\LocalLow\Mozilla =>.Mozilla Corporation
O43 - CFD: 07/09/2011 - [0] D -- C:\Users\Utilisateur\AppData\LocalLow\Netopsystems
O43 - CFD: 11/03/2016 - [] D -- C:\Users\Utilisateur\AppData\LocalLow\Oracle =>.Oracle
O43 - CFD: 09/03/2016 - [] D -- C:\Users\Utilisateur\AppData\LocalLow\Sun =>.Oracle
O43 - CFD: 06/04/2014 - [] D -- C:\Users\Utilisateur\AppData\LocalLow\Temp =>.Microsoft Corporation
O43 - CFD: 16/10/2018 - [] D -- C:\Users\Utilisateur\Desktop\1
O43 - CFD: 13/11/2018 - [] D -- C:\Users\Utilisateur\Desktop\11 09 2017
O43 - CFD: 16/10/2018 - [] D -- C:\Users\Utilisateur\Desktop\2
O43 - CFD: 16/10/2018 - [] D -- C:\Users\Utilisateur\Desktop\3
O43 - CFD: 06/09/2018 - [] D -- C:\Users\Utilisateur\Desktop\5 6
O43 - CFD: 11/01/2018 - [] D -- C:\Users\Utilisateur\Desktop\hiba@2013
O43 - CFD: 13/11/2018 - [] D -- C:\Users\Utilisateur\Desktop\N dossier
O43 - CFD: 09/03/2017 - [] RD -- C:\Users\Utilisateur\Desktop\Services Windows Live
O43 - CFD: 08/10/2018 - [] D -- C:\Users\Utilisateur\Desktop\الثاني
O43 - CFD: 14/07/2009 - [] RD -- C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 01/04/2015 - [] RD -- C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 16/05/2011 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BankPerfect =>.Fabio Chelly
O43 - CFD: 08/03/2013 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake =>.Freemake
O43 - CFD: 14/07/2009 - [] RD -- C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 21/04/2015 - [0] D -- C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Panicware
O43 - CFD: 22/12/2013 - [0] D -- C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoFiltre 7 =>.Antonio Da Cruz
O43 - CFD: 25/11/2009 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RaLink Wireless =>.Rarink
O43 - CFD: 05/10/2018 - [] RD -- C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 15/11/2010 - [] D -- C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 17/04/2016 - [] D -- C:\Users\Default\AppData\Local\Google =>.Google
O43 - CFD: 30/10/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 26/11/2009 - [0] D -- C:\Users\Default\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 17/04/2016 - [] D -- C:\Users\Default User\AppData\Local\Google =>.Google
O43 - CFD: 30/10/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Historique =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 26/11/2009 - [0] D -- C:\Users\Default User\AppData\Local\Microsoft Help =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 14/07/2009 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 06/05/2013 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Apps =>.Microsoft Corporation
O43 - CFD: 28/04/2011 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Google =>.Google
O43 - CFD: 27/09/2017 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 20/10/2013 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Adobe =>.Adobe
O43 - CFD: 21/04/2015 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Avira =>.Avira Software
O43 - CFD: 04/07/2013 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Foxit Software =>.Foxit Software
O43 - CFD: 30/10/2009 - [0] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\hpqLog =>.Hewlett-Packard
O43 - CFD: 11/10/2017 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Macromedia =>.Macromedia
O43 - CFD: 15/08/2014 - [] SD -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation
User empty folders CLSID founds (677). Clean with ZHPFix 'EmptyCLSID' command =>.SUP.Empty.CLSID

---\\ ShellIconOverlayIdentifiers (SIOI) (2) - 0s
O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - DLL d’extension d’environnement de stockage.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation

---\\ RACCOURCIS DES MENUS CONCEPTUELS (SCMH) (24) - 1s
O108 - CMH1: BriefcaseMenu - {85BBD920-42A0-1069-A2E4-08002B30309D} . (.Microsoft Corporation - Porte-documents Windows.) -- C:\Windows\System32\syncui.dll =>.Microsoft Corporation
O108 - CMH1: MRAICQCMenu - {7C9E7B90-88EC-4852-AC7A-C938268A5D04} . (...) -- C:\Users\Utilisateur\AppData\Roaming\ICQM\ICQ\dll\mramenu.dll {7A8F6F2F463DD8A8CE5B5C3A4E5B5726}
O108 - CMH1: Open With - {09799AFB-AD67-11d1-ABCD-00C04FC30936} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH1: Open With EncryptionMenu - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH1: Sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH1: Shell Extension for Malware scanning - {45AC2688-0253-4ED8-97DE-B5370FA7D48A} . (.Avira Operations GmbH & Co. KG - AntiVirus context menu.) -- C:\Program Files\Avira\Antivirus\shlext.dll =>.Avira Operations GmbH & Co. KG®
O108 - CMH1: WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (...) -- C:\Program Files\WinRAR\RarExt.dll
O108 - CMH2: Compatibility - {1d27f844-3a1f-4410-85ac-14651078412d} . (.Microsoft Corporation - Bibliothèque d’extension de l’onglet Compat.) -- C:\Windows\System32\acppage.dll =>.Microsoft Corporation
O108 - CMH2: OpenContainingFolderMenu - {37ea3a21-7493-4208-a011-7f9ea79ce9f5} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH3: 00avast - {472083B0-C522-11CF-8763-00608CC02F24} . (.Orphan.)
O108 - CMH3: CopyAsPathMenu - {f3d06e7c-1e45-4a26-847e-f9fcdee59be0} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH3: SendTo - {7BA4C740-9E81-11CF-99D3-00AA004AE837} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH4: EncryptionMenu - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH4: Sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH4: WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (...) -- C:\Program Files\WinRAR\RarExt.dll
O108 - CMH5: Gadgets - {6B9228DA-9C15-419e-856C-19E768A13BDC} . (.Microsoft Corporation - Zone de déposé du Volet Windows.) -- C:\Program Files\Windows Sidebar\sbdrop.dll =>.Microsoft Corporation
O108 - CMH5: New - {D969A300-E7FF-11d0-A93B-00A0C90F2719} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH5: Sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH6: BriefcaseMenu - {85BBD920-42A0-1069-A2E4-08002B30309D} . (.Microsoft Corporation - Porte-documents Windows.) -- C:\Windows\System32\syncui.dll =>.Microsoft Corporation
O108 - CMH6: Library Location - {3dad6c5d-2167-4cae-9914-f99e41c12cfa} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH6: Shell Extension for Malware scanning - {45AC2688-0253-4ED8-97DE-B5370FA7D48A} . (.Avira Operations GmbH & Co. KG - AntiVirus context menu.) -- C:\Program Files\Avira\Antivirus\shlext.dll =>.Avira Operations GmbH & Co. KG®
O108 - CMH6: WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (...) -- C:\Program Files\WinRAR\RarExt.dll
O108 - CMH7: EnhancedStorageShell - {2854F705-3548-414C-A113-93E27C808C85} . (.Microsoft Corporation - DLL d’extension d’environnement de stockage.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O108 - CMH7: Sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation

---\\ IMAGE FILE EXECUTION OPTIONS (IFEO) (5) - 0s
O50 - IFEO:C:\Windows\System32\FlashPlayerApp.exe - (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) [DisableExceptionChainValidation\\0] =>.Adobe Systems Incorporated®
O50 - IFEO:C:\Windows\System32\ie4uinit.exe - (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\ieUnatt.exe - (.Microsoft Corporation - Outil d’installation sans assistance d’IE 7.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\msfeedssync.exe - (.Microsoft Corporation - Microsoft Feeds Synchronization.) [MitigationOptions\\256] =>.Microsoft Corporation
O50 - IFEO:C:\Windows\System32\mshta.exe - (.Microsoft Corporation - Hôte des applications HTML de Microsoft(R).) [MitigationOptions\\256] =>.Microsoft Corporation

---\\ ÉNUMÉRATION DES CLÉS StartupReg (16) - 1s
O53 - SMSR:HKLM\...\startupreg\Adobe ARM [Key] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated
O53 - SMSR:HKLM\...\startupreg\Adobe Reader Speed Launcher [Key] . (...) -- C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\BCSSync [Key] . (...) -- C:\Program Files\Microsoft Office\Office14\BCSSync.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\eType Setup403515.exe [Key] . (...) -- C:\Users\UTILIS~1\AppData\Local\Temp\eType Setup403515.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\Facebook Update [Key] . (...) -- C:\Users\Utilisateur\AppData\Local\Facebook\Update\FacebookUpdate.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\HotKeysCmds [Key] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\System32\hkcmd.exe =>.Intel Corporation
O53 - SMSR:HKLM\...\startupreg\IDMan [Key] . (...) -- C:\Program Files\Internet Download Manager\IDMan.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\IgfxTray [Key] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\System32\igfxtray.exe =>.Intel Corporation
O53 - SMSR:HKLM\...\startupreg\LightScribe Control Panel [Key] . (.Hewlett-Packard Company - .) -- C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe =>.Hewlett-Packard Company
O53 - SMSR:HKLM\...\startupreg\OfficeSyncProcess [Key] . (...) -- C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (.not file.)
O53 - SMSR:HKLM\...\startupreg\Persistence [Key] . (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe =>.Intel Corporation
O53 - SMSR:HKLM\...\startupreg\QlbCtrl.exe [Key] . (.Hewlett-Packard Development Company, L.P. - Quick Launch Buttons.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe =>.Hewlett-Packard Development Company, L.P.
O53 - SMSR:HKLM\...\startupreg\StarterBackgroundChanger [Key] . (...) -- C:\Program Files\StarterBackgroundChanger\StarterBackgroundChangerTask.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\SynTPEnh [Key] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe =>.Synaptics Incorporated
O53 - SMSR:HKLM\...\startupreg\WirelessAssistant [Key] . (.Hewlett-Packard - HP Wireless Assistant Main Program.) -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe =>.Hewlett-Packard
O53 - SMSR:HKLM\...\startupreg\YouCam Service [Key] . (.CyberLink Corp. - CyberLink YouCam Service.) -- C:\Program Files\CyberLink\YouCam\YouCamService.exe =>.CyberLink Corp.

---\\ LISTE DES PILOTES DU SYSTÈME (337) - 12s
O58 - SDL:2009/07/14 00:51:21 A . (.Microsoft Corporation - 1394 Bus Device Driver.) -- C:\Windows\System32\drivers\1394bus.sys [54784] =>.Microsoft Corporation
O58 - SDL:2010/11/20 11:01:12 A . (.Microsoft Corporation - 1394 OpenHCI Driver.) -- C:\Windows\System32\drivers\1394ohci.sys [164864] =>.Microsoft Corporation
O58 - SDL:2010/11/20 13:29:15 A . (.Microsoft Corporation - Pilote ACPI pour NT.) -- C:\Windows\System32\drivers\acpi.sys [274304] =>.Microsoft Windows®
O58 - SDL:2010/11/20 09:47:55 A . (.Microsoft Corporation - ACPI Power Metering Driver.) -- C:\Windows\System32\drivers\acpipmi.sys [10240] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:26:15 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [422976] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:26:17 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [297552] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:26:15 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\drivers\adpu320.sys [146512] =>.Microsoft Windows®
O58 - SDL:2014/05/30 07:36:07 A . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\afd.sys [338944] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:55:00 A . (.Microsoft Corporation - RAS Agile Vpn Miniport Call Manager.) -- C:\Windows\System32\drivers\agilevpn.sys [49152] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:26:15 A . (.Microsoft Corporation - Filtre AGP 440 NT.) -- C:\Windows\System32\drivers\AGP440.sys [53312] =>.Microsoft Windows®
O58 - SDL:2009/04/06 18:12:44 A . (.LSI Corporation - SoftModem Device Driver.) -- C:\Windows\System32\drivers\AGRSM.sys [1161664] =>.LSI Corporation
O58 - SDL:2009/07/14 02:26:15 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [14400] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:26:15 A . (.Microsoft Corporation - Filtre AGP AMD NT.) -- C:\Windows\System32\drivers\AMDAGP.SYS [53312] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:26:15 A . (.Microsoft Corporation - Pilote IDE AMD.) -- C:\Windows\System32\drivers\amdide.sys [14912] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:11:04 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\amdk8.sys [55296] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:11:04 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\amdppm.sys [52736] =>.Microsoft Corporation
O58 - SDL:2011/03/11 06:38:37 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [80256] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:26:15 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [159312] =>.Microsoft Windows®
O58 - SDL:2011/03/11 06:38:37 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [22400] =>.Microsoft Windows®
O58 - SDL:2015/02/03 03:26:42 A . (.Microsoft Corporation - AppID Driver.) -- C:\Windows\System32\drivers\appid.sys [50176] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:26:15 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [76368] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:26:15 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [86608] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:54:46 A . (.Microsoft Corporation - MS Remote Access serial network driver.) -- C:\Windows\System32\drivers\asyncmac.sys [17920] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:26:15 A . (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [21584] =>.Microsoft Windows®
O58 - SDL:2013/08/05 02:56:47 A . (.Microsoft Corporation - ATAPI Driver Extension.) -- C:\Windows\System32\drivers\ataport.sys [133056] =>.Microsoft Corporation®
O58 - SDL:2017/06/20 12:28:58 A . (.Avira Operations GmbH & Co. KG - Avira USB Feature Driver.) -- C:\Windows\System32\drivers\avdevprot.sys [46440] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2018/08/18 17:12:24 A . (.Avira Operations GmbH & Co. KG - Avira Minifilter Driver.) -- C:\Windows\System32\drivers\avgntflt.sys [132448] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2018/08/18 17:12:24 A . (.Avira Operations GmbH & Co. KG - Avira Driver for Security Enhancement.) -- C:\Windows\System32\drivers\avipbb.sys [147880] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2017/03/28 19:00:10 A . (.Avira Operations GmbH & Co. KG - Avira Manager Driver.) -- C:\Windows\System32\drivers\avkmgr.sys [35840] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2017/03/28 19:00:10 A . (.Avira Operations GmbH & Co. KG - Avira WFP Network Driver.) -- C:\Windows\System32\drivers\avnetflt.sys [59000] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2017/06/20 12:28:58 A . (.Avira Operations GmbH & Co. KG - Avira USB Filter Driver.) -- C:\Windows\System32\drivers\avusbflt.sys [23304] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2009/07/13 23:02:49 A . (.Broadcom Corporation - Pilote unifié NDIS6.x Broadcom NetXtreme Gi.) -- C:\Windows\System32\drivers\b57nd60x.sys [229888] =>.Broadcom Corporation
O58 - SDL:2009/07/14 02:26:15 A . (.Microsoft Corporation - Battery Class Driver.) -- C:\Windows\System32\drivers\battc.sys [25168] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:45:01 A . (.Microsoft Corporation - BEEP Driver.) -- C:\Windows\System32\drivers\beep.sys [6144] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:23:04 A . (.Microsoft Corporation - BLB Drive Driver.) -- C:\Windows\System32\drivers\blbdrive.sys [35328] =>.Microsoft Corporation
O58 - SDL:2011/02/23 05:47:33 A . (.Microsoft Corporation - NT Lan Manager Datagram Receiver Driver.) -- C:\Windows\System32\drivers\bowser.sys [69632] =>.Microsoft Corporation
O58 - SDL:2009/07/13 23:53:28 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [13568] =>.Brother Industries, Ltd.
O58 - SDL:2009/07/13 23:53:28 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [5248] =>.Brother Industries, Ltd.
O58 - SDL:2009/07/14 01:41:26 A . (.Microsoft Corporation - MAC Bridge Driver.) -- C:\Windows\System32\drivers\bridge.sys [78336] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:57:25 A . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [272128] =>.Brother Industries Ltd.
O58 - SDL:2009/07/13 23:53:32 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [62336] =>.Brother Industries Ltd.
O58 - SDL:2009/07/13 23:53:33 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [12160] =>.Brother Industries Ltd.
O58 - SDL:2009/07/13 23:53:33 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [11904] =>.Brother Industries Ltd.
O58 - SDL:2009/07/14 00:51:36 A . (.Microsoft Corporation - Extension de bus Bluetooth.) -- C:\Windows\System32\drivers\bthenum.sys [34816] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:51:34 A . (.Microsoft Corporation - Bluetooth Communications Driver.) -- C:\Windows\System32\drivers\bthmodem.sys [56320] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:06:49 A . (.Microsoft Corporation - Microsoft Bluetooth MTP Bus Enumerator.) -- C:\Windows\System32\drivers\BthMtpEnum.sys [51200] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:51:43 A . (.Microsoft Corporation - Bluetooth Personal Area Networking.) -- C:\Windows\System32\drivers\bthpan.sys [93696] =>.Microsoft Corporation
O58 - SDL:2012/07/06 20:23:23 A . (.Microsoft Corporation - Pilote de bus Bluetooth.) -- C:\Windows\System32\drivers\bthport.sys [393728] =>.Microsoft Corporation
O58 - SDL:2011/04/28 04:15:03 A . (.Microsoft Corporation - Pilote de Miniport Bluetooth.) -- C:\Windows\System32\drivers\BTHUSB.SYS [60416] =>.Microsoft Corporation
O58 - SDL:2009/07/01 13:46:14 A . (.Broadcom Corporation. - Bluetooth Audio Device.) -- C:\Windows\System32\drivers\btwaudio.sys [86056] =>.Broadcom Corporation®
O58 - SDL:2009/07/01 13:46:12 A . (.Broadcom Corporation. - Broadcom Bluetooth AVDT Service.) -- C:\Windows\System32\drivers\btwavdt.sys [108072] =>.Broadcom Corporation®
O58 - SDL:2009/04/07 16:32:50 A . (.Broadcom Corporation. - Broadcom Bluetooth L2CAP Service.) -- C:\Windows\System32\drivers\btwl2cap.sys [29472] =>.Broadcom Corporation®
O58 - SDL:2009/07/01 13:46:04 A . (.Broadcom Corporation. - Bluetooth Remote Control HID Minidriver.) -- C:\Windows\System32\drivers\btwrchid.sys [18344] =>.Broadcom Corporation®
O58 - SDL:2009/07/13 23:02:48 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbdx.sys [430080] =>.Broadcom Corporation
O58 - SDL:2009/07/14 00:11:15 A . (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\cdfs.sys [70656] =>.Microsoft Corporation
O58 - SDL:2010/11/20 09:38:10 A . (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\cdrom.sys [108544] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:51:17 A . (.Microsoft Corporation - Consumer IR Class Driver for eHome.) -- C:\Windows\System32\drivers\circlass.sys [37888] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:26:15 A . (.Microsoft Corporation - SCSI Class System Dll.) -- C:\Windows\System32\drivers\Classpnp.sys [140864] =>.Microsoft Windows®
O58 - SDL:2011/04/14 04:47:40 A . (.CyberLink Corporation - CyberLink WebCam Virtual Driver.) -- C:\Windows\System32\drivers\clwvd.sys [27760] =>.CyberLink®
O58 - SDL:2009/07/14 00:19:18 A . (.Microsoft Corporation - Control Method Battery Driver.) -- C:\Windows\System32\drivers\CmBatt.sys [14080] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:26:21 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [15952] =>.Microsoft Windows®
O58 - SDL:2015/01/31 00:56:12 A . (.Microsoft Corporation - Kernel Cryptography, Next Generation.) -- C:\Windows\System32\drivers\cng.sys [370488] =>.Microsoft Corporation®
O58 - SDL:2009/07/14 02:26:21 A . (.Microsoft Corporation - Composite Battery Driver.) -- C:\Windows\System32\drivers\compbatt.sys [19024] =>.Microsoft Windows®
O58 - SDL:2010/11/20 10:50:21 A . (.Microsoft Corporation - Multi-Transport Composite Bus Enumerator.) -- C:\Windows\System32\drivers\CompositeBus.sys [31232] =>.Microsoft Corporation
O58 - SDL:2009/04/20 10:38:54 A . (.Hewlett-Packard Development Company, L.P. - HP Tablet PC Key Button HID Driver.) -- C:\Windows\System32\drivers\CPQBttn.sys [9344] =>.Hewlett-Packard Development Company, L.P.
O58 - SDL:2009/07/14 02:20:28 A . (.Microsoft Corporation - Crash Dump Driver.) -- C:\Windows\System32\drivers\crashdmp.sys [35408] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:20:28 A . (.Microsoft Corporation - Disk Block Verification Filter Driver.) -- C:\Windows\System32\drivers\crcdisk.sys [22096] =>.Microsoft Windows®
O58 - SDL:2008/05/29 17:33:46 A . (...) -- C:\Windows\System32\drivers\DCDisk.sys [156160]
O58 - SDL:2008/04/16 17:23:20 A . (...) -- C:\Windows\System32\drivers\dcsnap.sys [84320] {29B013F8F4A37F6B5A3F4991868B9484}
O58 - SDL:2010/11/20 09:42:32 A . (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\dfsc.sys [78336] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:24:05 A . (.Microsoft Corporation - System Indexer/Cache Driver.) -- C:\Windows\System32\drivers\discache.sys [32256] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:20:27 A . (.Microsoft Corporation - PnP Disk Driver.) -- C:\Windows\System32\drivers\disk.sys [57424] =>.Microsoft Windows®
O58 - SDL:2014/02/04 03:07:41 A . (.Microsoft Corporation - Crash Dump Disk Driver.) -- C:\Windows\System32\drivers\Diskdump.sys [27072] =>.Microsoft Corporation®
O58 - SDL:2009/07/14 02:20:28 A . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\drivers\djsvs.sys [70720] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:45:05 A . (.Microsoft Corporation - IEEE-1284.4-1999 Driver.) -- C:\Windows\System32\drivers\Dot4.sys [131072] =>.Microsoft Corporation
O58 - SDL:2010/11/20 10:50:05 A . (.Microsoft Corporation - IEEE-1284.4 Print Class Driver.) -- C:\Windows\System32\drivers\Dot4Prt.sys [16384] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:45:02 A . (.Microsoft Corporation - DOT4 Scan driver.) -- C:\Windows\System32\drivers\Dot4Scan.sys [10752] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:45:03 A . (.Microsoft Corporation - Pilote de filtre DOT4USB.) -- C:\Windows\System32\drivers\Dot4usb.sys [36864] =>.Microsoft Corporation
O58 - SDL:2013/10/04 02:49:41 A . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\Windows\System32\drivers\drmk.sys [81408] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:50:57 A . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\Windows\System32\drivers\drmkaud.sys [5120] =>.Microsoft Corporation
O58 - SDL:2009/01/08 19:00:54 A . (.Wondershare - Wondershare Virtual Audio Device.) -- C:\Windows\System32\drivers\DsAudioDevice_310.sys [16640] =>.Wondershare
O58 - SDL:2009/07/14 02:20:28 A . (.Microsoft Corporation - ATAPI Dump Driver.) -- C:\Windows\System32\drivers\Dumpata.sys [26704] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:17:54 A . (.Microsoft Corporation - Bitlocker Drive Encryption Crashdump Filter.) -- C:\Windows\System32\drivers\dumpfve.sys [55584] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:25:26 A . (.Microsoft Corporation - DirectX API Driver.) -- C:\Windows\System32\drivers\dxapi.sys [13312] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:25:25 A . (.Microsoft Corporation - DirectX Graphics Driver.) -- C:\Windows\System32\drivers\dxg.sys [76288] =>.Microsoft Corporation
O58 - SDL:2014/06/16 02:44:49 A . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\Windows\System32\drivers\dxgkrnl.sys [730048] =>.Microsoft Corporation®
O58 - SDL:2014/06/16 02:44:49 A . (.Microsoft Corporation - DirectX Graphics MMS.) -- C:\Windows\System32\drivers\dxgmms1.sys [219072] =>.Microsoft Corporation®
O58 - SDL:2009/07/14 02:20:28 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [453712] =>.Microsoft Windows®
O58 - SDL:1999/11/11 18:39:56 A . (.EPPSCSI Miniport Driver - EPPSCSI Miniport Driver.) -- C:\Windows\System32\drivers\EPPSCSI.SYS [49628]
O58 - SDL:2009/07/14 00:19:19 A . (.Microsoft Corporation - Error Device Driver.) -- C:\Windows\System32\drivers\errdev.sys [7168] =>.Microsoft Corporation
O58 - SDL:2009/07/13 23:02:48 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbdx.sys [3100160] =>.Broadcom Corporation
O58 - SDL:2009/07/14 00:14:03 A . (.Microsoft Corporation - Microsoft Extended FAT File System.) -- C:\Windows\System32\drivers\exfat.sys [142336] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:14:02 A . (.Microsoft Corporation - Fast FAT File System Driver.) -- C:\Windows\System32\drivers\fastfat.sys [148480] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:45:45 A . (.Microsoft Corporation - Floppy Disk Controller Driver.) -- C:\Windows\System32\drivers\fdc.sys [25088] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:20:28 A . (.Microsoft Corporation - FileInfo Filter Driver.) -- C:\Windows\System32\drivers\fileinfo.sys [58448] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:15:29 A . (.Microsoft Corporation - File Trace Filter Driver.) -- C:\Windows\System32\drivers\filetrace.sys [28160] =>.Microsoft Corporation
O58 - SDL:2008/04/07 16:00:14 A . (. - FileDisk Virtual Disk Driver.) -- C:\Windows\System32\drivers\flbdisk.sys [16896]
O58 - SDL:2008/04/14 10:03:42 A . (...) -- C:\Windows\System32\drivers\flbrc.sys [22528]
O58 - SDL:2008/03/26 14:51:54 A . (.Farstone - FileDisk Virtual Disk Driver.) -- C:\Windows\System32\drivers\FLBRITDISK.sys [19200] =>.FarStone
O58 - SDL:2009/07/14 00:45:45 A . (.Microsoft Corporation - Floppy Driver.) -- C:\Windows\System32\drivers\flpydisk.sys [19968] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:20:28 A . (.Microsoft Corporation - Gestionnaire de filtres de système de fichi.) -- C:\Windows\System32\drivers\fltMgr.sys [198208] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:20:28 A . (.Microsoft Corporation - File System Dependency Manager Mini Filter.) -- C:\Windows\System32\drivers\fsdepends.sys [46160] =>.Microsoft Windows®
O58 - SDL:2012/03/01 06:46:57 A . (.Microsoft Corporation - File System Recognizer Driver.) -- C:\Windows\System32\drivers\fs_rec.sys [19824] =>.Microsoft Windows®
O58 - SDL:2013/01/24 05:47:07 A . (.Microsoft Corporation - BitLocker Drive Encryption Driver.) -- C:\Windows\System32\drivers\fvevol.sys [196328] =>.Microsoft Corporation®
O58 - SDL:2014/04/05 03:24:55 A . (.Microsoft Corporation - FWP/IPsec Kernel-Mode API.) -- C:\Windows\System32\drivers\FWPKCLNT.SYS [187840] =>.Microsoft Corporation®
O58 - SDL:2009/07/14 02:20:28 A . (.Microsoft Corporation - Filtre AGPv3.0 générique Microsoft pour pla.) -- C:\Windows\System32\drivers\GAGP30KX.SYS [57936] =>.Microsoft Windows®
O58 - SDL:2008/03/26 14:51:56 A . (...) -- C:\Windows\System32\drivers\HCDisk.sys [47713]
O58 - SDL:2009/07/13 23:54:14 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [26624] =>.Hauppauge Computer Works, Inc.
O58 - SDL:2010/11/20 10:59:29 A . (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\hdaudbus.sys [108544] =>.Microsoft Corporation
O58 - SDL:2010/11/20 11:00:21 A . (.Microsoft Corporation - High Definition Audio Function Driver.) -- C:\Windows\System32\drivers\HdAudio.sys [304128] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:19:21 A . (.Microsoft Corporation - Hid Battery Driver.) -- C:\Windows\System32\drivers\hidbatt.sys [21504] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:51:33 A . (.Microsoft Corporation - Pilote de miniport Bluetooth pour les périp.) -- C:\Windows\System32\drivers\hidbth.sys [91136] =>.Microsoft Corporation
O58 - SDL:2013/07/03 04:36:24 A . (.Microsoft Corporation - Hid Class Library.) -- C:\Windows\System32\drivers\hidclass.sys [55808] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:51:05 A . (.Microsoft Corporation - Infrared Miniport Driver for Input Devices.) -- C:\Windows\System32\drivers\hidir.sys [37888] =>.Microsoft Corporation
O58 - SDL:2013/07/03 04:36:22 A . (.Microsoft Corporation - Hid Parsing Library.) -- C:\Windows\System32\drivers\hidparse.sys [25728] =>.Microsoft Corporation
O58 - SDL:2010/11/20 10:59:38 A . (.Microsoft Corporation - USB Miniport Driver for Input Devices.) -- C:\Windows\System32\drivers\hidusb.sys [24064] =>.Microsoft Corporation
O58 - SDL:2009/04/29 09:46:54 A . (.Hewlett-Packard Development Company, L.P. - HpqKbFiltr Keyboard Filter Driver.) -- C:\Windows\System32\drivers\HpqKbFiltr.sys [15872] =>.Hewlett-Packard Development Company, L.P.
O58 - SDL:2009/07/14 02:20:28 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [67152] =>.Microsoft Windows®
O58 - SDL:2015/02/25 04:03:14 A . (.Microsoft Corporation - HTTP Pile du protocole.) -- C:\Windows\System32\drivers\http.sys [514560] =>.Microsoft Corporation
O58 - SDL:2010/11/20 13:29:53 A . (.Microsoft Corporation - Hardware Policy Driver.) -- C:\Windows\System32\drivers\hwpolicy.sys [14208] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:11:24 A . (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [80896] =>.Microsoft Corporation
O58 - SDL:2011/03/11 06:38:51 A . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\drivers\iaStorV.sys [332160] =>.Microsoft Windows®
O58 - SDL:2009/09/23 20:18:14 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd32.sys [4808192] =>.Intel Corporation
O58 - SDL:2009/07/14 02:20:36 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [41040] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:20:36 A . (.Microsoft Corporation - Intel PCI IDE Driver.) -- C:\Windows\System32\drivers\intelide.sys [15424] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:11:04 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\intelppm.sys [53760] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:54:29 A . (.Microsoft Corporation - IP FILTER DRIVER.) -- C:\Windows\System32\drivers\ipfltdrv.sys [58880] =>.Microsoft Corporation
O58 - SDL:2010/11/20 10:19:15 A . (.Microsoft Corporation - PILOT IPMI WMI.) -- C:\Windows\System32\drivers\IPMIDrv.sys [65536] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:54:29 A . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\ipnat.sys [101888] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:53:32 A . (.Microsoft Corporation - IRDA Protocol Driver.) -- C:\Windows\System32\drivers\irda.sys [96768] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:53:27 A . (.Microsoft Corporation - Infra-Red Bus Enumerator.) -- C:\Windows\System32\drivers\irenum.sys [13824] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:20:36 A . (.Microsoft Corporation - Pilote de bus PNP ISA.) -- C:\Windows\System32\drivers\isapnp.sys [46656] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:20:36 A . (.Microsoft Corporation - Pilote de la classe Clavier.) -- C:\Windows\System32\drivers\kbdclass.sys [42576] =>.Microsoft Windows®
O58 - SDL:2010/11/20 10:50:10 A . (.Microsoft Corporation - Pilote de filtre clavier HID.) -- C:\Windows\System32\drivers\kbdhid.sys [28160] =>.Microsoft Corporation
O58 - SDL:2010/11/20 10:50:19 A . (.Microsoft Corporation - Kernel CSA Library.) -- C:\Windows\System32\drivers\ks.sys [190976] =>.Microsoft Corporation
O58 - SDL:2015/07/01 21:46:02 A . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\drivers\ksecdd.sys [67520] =>.Microsoft Corporation®
O58 - SDL:2015/07/01 21:46:02 A . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\drivers\ksecpkg.sys [137664] =>.Microsoft Corporation®
O58 - SDL:2009/07/14 00:53:19 A . (.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) -- C:\Windows\System32\drivers\lltdio.sys [48128] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:20:36 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [95824] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:20:37 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [89168] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:20:36 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [54864] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:20:36 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [96848] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:15:45 A . (.Microsoft Corporation - Pilote de filtre de virtualisation de fichi.) -- C:\Windows\System32\drivers\luafv.sys [86528] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:45:57 A . (.Microsoft Corporation - Medium changer class driver.) -- C:\Windows\System32\drivers\mcd.sys [18432] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:20:36 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [30800] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:20:36 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [235584] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:55:24 A . (.Microsoft Corporation - Pilote de périphérique modem.) -- C:\Windows\System32\drivers\modem.sys [31744] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:25:59 A . (.Microsoft Corporation - Monitor Driver.) -- C:\Windows\System32\drivers\monitor.sys [23552] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:20:44 A . (.Microsoft Corporation - Pilote de la classe Souris.) -- C:\Windows\System32\drivers\mouclass.sys [41552] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:45:08 A . (.Microsoft Corporation - Pilote de filtre souris HID.) -- C:\Windows\System32\drivers\mouhid.sys [26112] =>.Microsoft Corporation
O58 - SDL:2015/02/03 04:16:30 A . (.Microsoft Corporation - Gestionnaire des points de montage.) -- C:\Windows\System32\drivers\mountmgr.sys [78784] =>.Microsoft Corporation®
O58 - SDL:2010/11/20 13:30:01 A . (.Microsoft Corporation - Pilote du bus de prise en charge des chemin.) -- C:\Windows\System32\drivers\mpio.sys [130432] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:52:53 A . (.Microsoft Corporation - Microsoft Protection Service Driver.) -- C:\Windows\System32\drivers\mpsdrv.sys [60416] =>.Microsoft Corporation
O58 - SDL:2014/12/19 02:34:44 A . (.Microsoft Corporation - Windows NT WebDav Minirdr.) -- C:\Windows\System32\drivers\mrxdav.sys [116224] =>.Microsoft Corporation
O58 - SDL:2015/07/01 20:18:29 A . (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\mrxsmb.sys [124416] =>.Microsoft Corporation
O58 - SDL:2015/07/01 20:18:39 A . (.Microsoft Corporation - Longhorn SMB Downlevel SubRdr.) -- C:\Windows\System32\drivers\mrxsmb10.sys [225792] =>.Microsoft Corporation
O58 - SDL:2015/07/01 20:18:35 A . (.Microsoft Corporation - Longhorn SMB 2.0 Redirector.) -- C:\Windows\System32\drivers\mrxsmb20.sys [98304] =>.Microsoft Corporation
O58 - SDL:2010/11/20 13:30:01 A . (.Microsoft Corporation - MS AHCI 1.0 Standard Driver.) -- C:\Windows\System32\drivers\msahci.sys [28032] =>.Microsoft Windows®
O58 - SDL:2010/11/20 13:30:04 A . (.Microsoft Corporation - Module spécifique de périphériques Microsof.) -- C:\Windows\System32\drivers\msdsm.sys [116096] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:11:26 A . (.Microsoft Corporation - Mailslot driver.) -- C:\Windows\System32\drivers\msfs.sys [22528] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:51:08 A . (.Microsoft Corporation - Pass-through HID to KMDF Filter Driver.) -- C:\Windows\System32\drivers\mshidkmdf.sys [4096] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:20:43 A . (.Microsoft Corporation - ISA Driver.) -- C:\Windows\System32\drivers\msisadrv.sys [13888] =>.Microsoft Windows®
O58 - SDL:2014/02/04 03:07:50 A . (.Microsoft Corporation - Microsoft iSCSI Initiator Driver.) -- C:\Windows\System32\drivers\msiscsi.sys [234432] =>.Microsoft Corporation®
O58 - SDL:2009/07/14 00:45:08 A . (.Microsoft Corporation - MS KS Server.) -- C:\Windows\System32\drivers\mskssrv.sys [8320] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:45:08 A . (.Microsoft Corporation - MS Proxy Clock.) -- C:\Windows\System32\drivers\mspclock.sys [5888] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:45:07 A . (.Microsoft Corporation - MS Proxy Quality Manager.) -- C:\Windows\System32\drivers\mspqm.sys [5504] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:20:44 A . (.Microsoft Corporation - Kernel Remote Procedure Call Provider.) -- C:\Windows\System32\drivers\msrpc.sys [162896] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:20:44 A . (.Microsoft Corporation - System Management BIOS Driver.) -- C:\Windows\System32\drivers\mssmbios.sys [28240] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:45:08 A . (.Microsoft Corporation - WDM Tee/Communication Transform Filter.) -- C:\Windows\System32\drivers\mstee.sys [6144] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:46:55 A . (.Microsoft Corporation - Pilote HID multipoint Microsoft.) -- C:\Windows\System32\drivers\MTConfig.sys [12288] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:20:44 A . (.Microsoft Corporation - Multiple UNC Provider Driver.) -- C:\Windows\System32\drivers\mup.sys [49728] =>.Microsoft Windows®
O58 - SDL:2012/08/22 18:16:46 A . (.Microsoft Corporation - Pilote NDIS 6.20.) -- C:\Windows\System32\drivers\ndis.sys [712048] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:52:44 A . (.Microsoft Corporation - NDIS Packet Capture Filter Driver.) -- C:\Windows\System32\drivers\ndiscap.sys [27136] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:54:24 A . (.Microsoft Corporation - NDIS 3.0 connection wrapper driver.) -- C:\Windows\System32\drivers\ndistapi.sys [20992] =>.Microsoft Corporation
O58 - SDL:2010/11/20 11:06:36 A . (.Microsoft Corporation - Pilote d’E/S du mode utilisateur NDIS.) -- C:\Windows\System32\drivers\ndisuio.sys [46080] =>.Microsoft Corporation
O58 - SDL:2010/11/20 11:07:50 A . (.Microsoft Corporation - MS PPP Framing Driver (Strong Encryption).) -- C:\Windows\System32\drivers\ndiswan.sys [118784] =>.Microsoft Corporation
O58 - SDL:2010/11/20 11:07:39 A . (.Microsoft Corporation - NDIS Proxy.) -- C:\Windows\System32\drivers\ndproxy.sys [48640] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:53:54 A . (.Microsoft Corporation - NetBIOS interface driver.) -- C:\Windows\System32\drivers\netbios.sys [36352] =>.Microsoft Corporation
O58 - SDL:2010/11/20 09:39:44 A . (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netbt.sys [187904] =>.Microsoft Corporation
O58 - SDL:2013/11/26 12:11:29 A . (.Microsoft Corporation - Network I/O Subsystem.) -- C:\Windows\System32\drivers\netio.sys [240576] =>.Microsoft Corporation®
O58 - SDL:2010/01/13 16:36:40 A . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\Windows\System32\drivers\NETw5s32.sys [6755840] =>.Intel Corporation
O58 - SDL:2009/07/13 23:02:51 A . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\Windows\System32\drivers\netw5v32.sys [4231168] =>.Intel Corporation
O58 - SDL:2009/07/14 02:20:44 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [44624] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:11:32 A . (.Microsoft Corporation - NPFS Driver.) -- C:\Windows\System32\drivers\npfs.sys [35328] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:12:08 A . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\drivers\nsiproxy.sys [16896] =>.Microsoft Corporation
O58 - SDL:2014/01/24 03:18:22 A . (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [1212352] =>.Microsoft Corporation®
O58 - SDL:2009/07/14 00:11:12 A . (.Microsoft Corporation - NULL Driver.) -- C:\Windows\System32\drivers\null.sys [4608] =>.Microsoft Corporation
O58 - SDL:2011/03/11 06:39:00 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [117120] =>.Microsoft Windows®
O58 - SDL:2011/03/11 06:39:00 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [143744] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:20:44 A . (.Microsoft Corporation - Filtre AGP NForce NT.) -- C:\Windows\System32\drivers\NV_AGP.SYS [105024] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:52:03 A . (.Microsoft Corporation - Pilote de miniport WiFi natif.) -- C:\Windows\System32\drivers\nwifi.sys [267264] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:51:29 A . (.Microsoft Corporation - 1394 OpenHCI Port Driver.) -- C:\Windows\System32\drivers\ohci1394.sys [62464] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:53:58 A . (.Microsoft Corporation - Planificateur de paquets QoS.) -- C:\Windows\System32\drivers\pacer.sys [104448] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:45:35 A . (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\parport.sys [79360] =>.Microsoft Corporation
O58 - SDL:2012/03/17 08:27:18 A . (.Microsoft Corporation - Partition Management Driver.) -- C:\Windows\System32\drivers\partmgr.sys [56176] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:45:29 A . (.Microsoft Corporation - Pilote parallèle VDM.) -- C:\Windows\System32\drivers\parvdm.sys [8704] =>.Microsoft Corporation
O58 - SDL:2010/11/20 13:30:06 A . (.Microsoft Corporation - Énumérateur Plug-and-Play PCI pour NT.) -- C:\Windows\System32\drivers\pci.sys [153984] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:20:45 A . (.Microsoft Corporation - Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\pciide.sys [12368] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:19:03 A . (.Microsoft Corporation - PCI IDE Bus Driver Extension.) -- C:\Windows\System32\drivers\pciidex.sys [42560] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:19:03 A . (.Microsoft Corporation - Pilote de bus PCMCIA.) -- C:\Windows\System32\drivers\pcmcia.sys [180288] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:19:04 A . (.Microsoft Corporation - Performance Counters for Windows Driver.) -- C:\Windows\System32\drivers\pcw.sys [43088] =>.Microsoft Windows®
O58 - SDL:2015/02/03 04:00:23 A . (.Microsoft Corporation - Protected Environment Authentication and Au.) -- C:\Windows\System32\drivers\PEAuth.sys [593920] =>.Microsoft Corporation
O58 - SDL:2013/10/04 02:17:08 A . (.Microsoft Corporation - Port Class (Class Driver for Port/Miniport.) -- C:\Windows\System32\drivers\portcls.sys [177152] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:11:04 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\processr.sys [52224] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:19:04 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1383488] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:19:04 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [106064] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:54:13 A . (.Microsoft Corporation - Pilote du support de Microsoft Quality Wind.) -- C:\Windows\System32\drivers\qwavedrv.sys [31744] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:54:40 A . (.Microsoft Corporation - RAS Automatic Connection Driver.) -- C:\Windows\System32\drivers\rasacd.sys [11776] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:54:34 A . (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\rasl2tp.sys [78848] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:54:53 A . (.Microsoft Corporation - RAS PPPoE mini-port/call-manager driver.) -- C:\Windows\System32\drivers\raspppoe.sys [77824] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:54:48 A . (.Microsoft Corporation - Peer-to-Peer Tunneling Protocol.) -- C:\Windows\System32\drivers\raspptp.sys [73728] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:54:58 A . (.Microsoft Corporation - RAS SSTP Miniport Call Manager.) -- C:\Windows\System32\drivers\rassstp.sys [75264] =>.Microsoft Corporation
O58 - SDL:2010/11/20 09:44:05 A . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) -- C:\Windows\System32\drivers\rdbss.sys [242688] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:02:41 A . (.Microsoft Corporation - Microsoft RDP Bus Device driver.) -- C:\Windows\System32\drivers\rdpbus.sys [18944] =>.Microsoft Corporation
O58 - SDL:2010/11/20 11:22:19 A . (.Microsoft Corporation - RDP Miniport.) -- C:\Windows\System32\drivers\RDPCDD.sys [6656] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:01:39 A . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\drivers\RDPENCDD.sys [6656] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:01:41 A . (.Microsoft Corporation - RDP Reflector Driver Miniport.) -- C:\Windows\System32\drivers\RDPREFMP.sys [7168] =>.Microsoft Corporation
O58 - SDL:2014/07/17 02:03:11 A . (.Microsoft Corporation - Pilote de pile RDP Terminal.) -- C:\Windows\System32\drivers\rdpwd.sys [184320] =>.Microsoft Corporation
O58 - SDL:2010/11/20 13:30:10 A . (.Microsoft Corporation - ReadyBoost Driver.) -- C:\Windows\System32\drivers\rdyboost.sys [173440] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:51:41 A . (.Microsoft Corporation - Bluetooth RFCOMM Driver.) -- C:\Windows\System32\drivers\rfcomm.sys [129536] =>.Microsoft Corporation
O58 - SDL:2010/11/20 11:06:36 A . (.Microsoft Corporation - Reliable Multicast Transport.) -- C:\Windows\System32\drivers\rmcast.sys [117760] =>.Microsoft Corporation
O58 - SDL:2012/07/04 20:45:31 A . (.Microsoft Corporation - Remote NDIS Miniport.) -- C:\Windows\System32\drivers\RNDISMP.sys [33280] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:55:21 A . (.Microsoft Corporation - Legacy Non-Pnp Modem Device Driver.) -- C:\Windows\System32\drivers\rootmdm.sys [8192] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:53:20 A . (.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) -- C:\Windows\System32\drivers\rspndr.sys [60928] =>.Microsoft Corporation
O58 - SDL:2010/11/20 13:30:10 A . (.Microsoft Corporation - SBP-2 Protocol Driver.) -- C:\Windows\System32\drivers\sbp2port.sys [85376] =>.Microsoft Windows®
O58 - SDL:2010/11/20 10:24:56 A . (.Microsoft Corporation - Pilote de filtre de lecteur de carte à puce.) -- C:\Windows\System32\drivers\scfilter.sys [26624] =>.Microsoft Corporation
O58 - SDL:2010/11/20 13:30:10 A . (.Microsoft Corporation - SCSI Port Driver.) -- C:\Windows\System32\drivers\scsiport.sys [140160] =>.Microsoft Windows®
O58 - SDL:2009/07/13 21:50:20 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [20480] =>.Rovi Corporation
O58 - SDL:2009/07/14 00:45:28 A . (.Microsoft Corporation - Serial Port Enumerator.) -- C:\Windows\System32\drivers\serenum.sys [17920] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:45:33 A . (.Microsoft Corporation - Pilote de périphérique série.) -- C:\Windows\System32\drivers\serial.sys [83456] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:45:08 A . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\drivers\sermouse.sys [19968] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:45:52 A . (.Microsoft Corporation - Small Form Factor Disk Driver.) -- C:\Windows\System32\drivers\sffdisk.sys [11264] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:45:52 A . (.Microsoft Corporation - Small Form Factor MMC Protocol Driver.) -- C:\Windows\System32\drivers\sffp_mmc.sys [12288] =>.Microsoft Corporation
O58 - SDL:2010/11/20 10:50:49 A . (.Microsoft Corporation - Small Form Factor SD Protocol Driver.) -- C:\Windows\System32\drivers\sffp_sd.sys [12800] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:45:52 A . (.Microsoft Corporation - SCSI Floppy Driver.) -- C:\Windows\System32\drivers\sfloppy.sys [13824] =>.Microsoft Corporation
O58 - SDL:2008/04/25 18:04:28 A . (...) -- C:\Windows\System32\drivers\sioctl.sys [6144]
O58 - SDL:2009/07/14 02:19:03 A . (.Microsoft Corporation - Filtre SIS NT AGP.) -- C:\Windows\System32\drivers\SISAGP.SYS [52304] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:19:04 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [40016] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:19:04 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [77888] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:53:41 A . (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [71168] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:45:28 A . (.Microsoft Corporation - Smart Card Driver Library.) -- C:\Windows\System32\drivers\smclib.sys [17408] =>.Microsoft Corporation
O58 - SDL:2009/07/02 11:39:48 A . (. - USBCAMD for Sonix UVC.) -- C:\Windows\System32\drivers\sncduvc.sys [34480] =>.Chicony Electronics Co., Ltd.®
O58 - SDL:2010/09/11 09:21:26 A . (.Windows (R) Codename Longhorn DDK provider - Support Device.) -- C:\Windows\System32\drivers\SndTAudio.sys [23608] =>.Windows (R) Codename Longhorn DDK provider
O58 - SDL:2009/07/02 11:40:34 A . (. - UVC Camera Streaming Driver.) -- C:\Windows\System32\drivers\snp2uvc.sys [1765168] =>.Chicony Electronics Co., Ltd.®
O58 - SDL:2009/07/14 02:19:03 A . (.Microsoft Corporation - loader for security processor.) -- C:\Windows\System32\drivers\spldr.sys [17472] =>.Microsoft Windows®
O58 - SDL:2009/07/13 21:34:43 A . (.Microsoft Corporation - security processor.) -- C:\Windows\System32\drivers\spsys.sys [405504] =>.Microsoft Corporation
O58 - SDL:2011/04/29 03:46:33 A . (.Microsoft Corporation - Server driver.) -- C:\Windows\System32\drivers\srv.sys [311808] =>.Microsoft Corporation
O58 - SDL:2011/04/29 03:46:15 A . (.Microsoft Corporation - Smb 2.0 Server driver.) -- C:\Windows\System32\drivers\srv2.sys [310272] =>.Microsoft Corporation
O58 - SDL:2011/04/29 03:46:10 A . (.Microsoft Corporation - Server Network driver.) -- C:\Windows\System32\drivers\srvnet.sys [114688] =>.Microsoft Corporation
O58 - SDL:2016/09/01 14:40:51 A . (.Avira Operations GmbH & Co. KG - ssmdrv.) -- C:\Windows\System32\drivers\ssmdrv.sys [18760] =>.Avira Operations GmbH & Co. KG®
O58 - SDL:2009/07/14 02:19:04 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [21072] =>.Microsoft Windows®
O58 - SDL:2014/02/04 03:07:53 A . (.Microsoft Corporation - Microsoft Storage Port Driver.) -- C:\Windows\System32\drivers\storport.sys [149440] =>.Microsoft Corporation®
O58 - SDL:2015/04/11 04:07:47 A . (.Microsoft Corporation - WDM CODEC Class Device Driver 2.0.) -- C:\Windows\System32\drivers\stream.sys [54656] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:19:10 A . (.Microsoft Corporation - Plug and Play Software Device Enumerator.) -- C:\Windows\System32\drivers\swenum.sys [12240] =>.Microsoft Windows®
O58 - SDL:2009/07/29 17:33:04 A . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\Windows\System32\drivers\SynTP.sys [213680] =>.Synaptics Incorporated®
O58 - SDL:2009/07/14 00:45:53 A . (.Microsoft Corporation - SCSI Tape Class Driver.) -- C:\Windows\System32\drivers\tape.sys [24576] =>.Microsoft Corporation
O58 - SDL:2014/04/05 03:25:01 A . (.Microsoft Corporation - Pilote TCP/IP.) -- C:\Windows\System32\drivers\tcpip.sys [1294272] =>.Microsoft Corporation®
O58 - SDL:2012/10/03 16:21:38 A . (.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) -- C:\Windows\System32\drivers\tcpipreg.sys [35328] =>.Microsoft Corporation
O58 - SDL:2010/11/20 09:39:18 A . (.Microsoft Corporation - TDI Wrapper.) -- C:\Windows\System32\drivers\tdi.sys [21504] =>.Microsoft Corporation
O58 - SDL:2010/11/20 11:21:10 A . (.Microsoft Corporation - Named Pipe Transport Driver.) -- C:\Windows\System32\drivers\tdpipe.sys [18432] =>.Microsoft Corporation
O58 - SDL:2012/02/17 05:13:22 A . (.Microsoft Corporation - TCP Transport Driver.) -- C:\Windows\System32\drivers\tdtcp.sys [24576] =>.Microsoft Corporation
O58 - SDL:2014/11/11 02:32:14 A . (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [74752] =>.Microsoft Corporation
O58 - SDL:2010/11/20 13:30:12 A . (.Microsoft Corporation - Remote Desktop Server Driver.) -- C:\Windows\System32\drivers\termdd.sys [53120] =>.Microsoft Windows®
O58 - SDL:2014/07/17 02:02:33 A . (.Microsoft Corporation - TS Security Filter Driver.) -- C:\Windows\System32\drivers\tssecsrv.sys [31232] =>.Microsoft Corporation
O58 - SDL:2010/11/20 11:24:41 A . (.Microsoft Corporation - Pilote de filtre pour concentrateur USB du.) -- C:\Windows\System32\drivers\TsUsbFlt.sys [52224] =>.Microsoft Corporation
O58 - SDL:2010/11/20 11:06:41 A . (.Microsoft Corporation - Pilote d’interface de tunnel Microsoft.) -- C:\Windows\System32\drivers\tunnel.sys [108544] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:19:10 A . (.Microsoft Corporation - Filtre MS AGPv3.5.) -- C:\Windows\System32\drivers\UAGP35.SYS [55888] =>.Microsoft Windows®
O58 - SDL:2010/11/20 09:42:28 A . (.Microsoft Corporation - UDF File System Driver.) -- C:\Windows\System32\drivers\udfs.sys [246784] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:19:11 A . (.Microsoft Corporation - Filtre ULi AGPv3.0 pour plateformes à proce.) -- C:\Windows\System32\drivers\ULIAGPKX.SYS [57424] =>.Microsoft Windows®
O58 - SDL:2010/11/20 11:00:24 A . (.Microsoft Corporation - User-Mode Bus Enumerator.) -- C:\Windows\System32\drivers\umbus.sys [39936] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:51:35 A . (.Microsoft Corporation - Generic pass-through driver.) -- C:\Windows\System32\drivers\umpass.sys [8192] =>.Microsoft Corporation
O58 - SDL:2013/02/12 04:32:45 A . (.Microsoft Corporation - Remote NDIS USB Driver.) -- C:\Windows\System32\drivers\usb8023.sys [15872] =>.Microsoft Corporation
O58 - SDL:2010/11/20 11:00:05 A . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) -- C:\Windows\System32\drivers\USBCAMD.sys [25856] =>.Microsoft Corporation
O58 - SDL:2010/11/20 11:00:05 A . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) -- C:\Windows\System32\drivers\USBCAMD2.sys [25856] =>.Microsoft Corporation
O58 - SDL:2013/11/27 02:13:44 A . (.Microsoft Corporation - USB Common Class Generic Parent Driver.) -- C:\Windows\System32\drivers\usbccgp.sys [76288] =>.Microsoft Corporation
O58 - SDL:2013/07/12 11:07:54 A . (.Microsoft Corporation - USB Consumer IR Driver for eHome.) -- C:\Windows\System32\drivers\usbcir.sys [86016] =>.Microsoft Corporation
O58 - SDL:2013/11/27 02:13:33 A . (.Microsoft Corporation - Universal Serial Bus Driver.) -- C:\Windows\System32\drivers\usbd.sys [6016] =>.Microsoft Corporation
O58 - SDL:2013/11/27 02:13:41 A . (.Microsoft Corporation - EHCI eUSB Miniport Driver.) -- C:\Windows\System32\drivers\usbehci.sys [43520] =>.Microsoft Corporation
O58 - SDL:2013/11/27 02:14:25 A . (.Microsoft Corporation - Default Hub Driver for USB.) -- C:\Windows\System32\drivers\usbhub.sys [258560] =>.Microsoft Corporation
O58 - SDL:2013/11/27 02:13:38 A . (.Microsoft Corporation - OHCI USB Miniport Driver.) -- C:\Windows\System32\drivers\usbohci.sys [20480] =>.Microsoft Corporation
O58 - SDL:2013/11/27 02:13:46 A . (.Microsoft Corporation - Pilote de port USB 1.1 & 2.0.) -- C:\Windows\System32\drivers\usbport.sys [284672] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:17:06 A . (.Microsoft Corporation - USB Printer driver.) -- C:\Windows\System32\drivers\usbprint.sys [19968] =>.Microsoft Corporation
O58 - SDL:2010/11/20 11:52:01 A . (.Microsoft Corporation - Gestionnaire de stratégie de redirection US.) -- C:\Windows\System32\drivers\usbrpm.sys [26112] =>.Microsoft Corporation
O58 - SDL:2009/07/14 01:14:44 A . (.Microsoft Corporation - USB Scanner Driver.) -- C:\Windows\System32\drivers\usbscan.sys [35840] =>.Microsoft Corporation
O58 - SDL:2010/11/20 10:59:46 A . (.Microsoft Corporation - USB Modem Driver.) -- C:\Windows\System32\drivers\usbser.sys [27648] =>.Microsoft Corporation
O58 - SDL:2011/03/11 05:01:12 A . (.Microsoft Corporation - USB Mass Storage Class Driver.) -- C:\Windows\System32\drivers\USBSTOR.SYS [76288] =>.Microsoft Corporation
O58 - SDL:2013/11/27 02:13:36 A . (.Microsoft Corporation - UHCI USB Miniport Driver.) -- C:\Windows\System32\drivers\usbuhci.sys [24064] =>.Microsoft Corporation
O58 - SDL:2013/07/12 11:08:19 A . (.Microsoft Corporation - USB Video Class Driver.) -- C:\Windows\System32\drivers\usbvideo.sys [146816] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:19:10 A . (.Microsoft Corporation - Énumérateur racine de lecteur virtuel.) -- C:\Windows\System32\drivers\vdrvroot.sys [32832] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:25:51 A . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\drivers\vga.sys [25088] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:25:49 A . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\drivers\vgapnp.sys [26112] =>.Microsoft Corporation
O58 - SDL:2010/11/20 13:30:14 A . (.Microsoft Corporation - VHD Miniport Driver.) -- C:\Windows\System32\drivers\vhdmp.sys [160128] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:19:10 A . (.Microsoft Corporation - Filtre VIA NT AGP.) -- C:\Windows\System32\drivers\VIAAGP.SYS [53328] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:11:04 A . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\drivers\viac7.sys [52736] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:19:10 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [16976] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:25:51 A . (.Microsoft Corporation - Video Port Driver.) -- C:\Windows\System32\drivers\videoprt.sys [111616] =>.Microsoft Corporation
O58 - SDL:2010/11/20 13:30:16 A . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\drivers\volmgr.sys [53120] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:19:11 A . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volum.) -- C:\Windows\System32\drivers\volmgrx.sys [297040] =>.Microsoft Windows®
O58 - SDL:2010/11/20 13:30:16 A . (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [245632] =>.Microsoft Windows®
O58 - SDL:2009/07/14 02:19:11 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [141904] =>.Microsoft Windows®
O58 - SDL:2008/05/08 12:17:30 A . (...) -- C:\Windows\System32\drivers\VVBackd5.sys [148827]
O58 - SDL:2009/07/14 00:52:02 A . (.Microsoft Corporation - Pilote de bus WiFi virtuel.) -- C:\Windows\System32\drivers\vwifibus.sys [19968] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:52:04 A . (.Microsoft Corporation - Virtual WiFi Filter Driver.) -- C:\Windows\System32\drivers\vwififlt.sys [48128] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:52:10 A . (.Microsoft Corporation - Virtual WiFi Miniport Driver.) -- C:\Windows\System32\drivers\vwifimp.sys [14336] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:46:53 A . (.Microsoft Corporation - Wacom Serial Pen Tablet HID Driver.) -- C:\Windows\System32\drivers\wacompen.sys [21632] =>.Microsoft Corporation
O58 - SDL:2010/11/20 11:07:45 A . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) -- C:\Windows\System32\drivers\wanarp.sys [63488] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:24:11 A . (.Microsoft Corporation - Watchdog Driver.) -- C:\Windows\System32\drivers\watchdog.sys [35328] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:19:11 A . (.Microsoft Corporation - Microsoft Watchdog Timer Driver.) -- C:\Windows\System32\drivers\wd.sys [19024] =>.Microsoft Windows®
O58 - SDL:2013/06/25 23:56:40 A . (.Microsoft Corporation - Runtime de l’infrastructure de pilotes en m.) -- C:\Windows\System32\drivers\Wdf01000.sys [527064] =>.Microsoft Corporation®
O58 - SDL:2012/07/26 04:39:21 A . (.Microsoft Corporation - Kernel Mode Driver Framework Loader.) -- C:\Windows\System32\drivers\WdfLdr.sys [47720] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:53:51 A . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) -- C:\Windows\System32\drivers\wfplwf.sys [9728] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:19:10 A . (.Microsoft Corporation - Wim file system Driver.) -- C:\Windows\System32\drivers\wimmount.sys [19008] =>.Microsoft Windows®
O58 - SDL:2010/11/20 10:59:44 A . (.Microsoft Corporation - Windows USB Class Driver BETA.) -- C:\Windows\System32\drivers\winusb.sys [35968] =>.Microsoft Corporation
O58 - SDL:2009/07/14 00:19:17 A . (.Microsoft Corporation - Windows Management Interface for ACPI.) -- C:\Windows\System32\drivers\wmiacpi.sys [11264] =>.Microsoft Corporation
O58 - SDL:2009/07/14 02:19:10 A . (.Microsoft Corporation - WMILIB WMI support library Dll.) -- C:\Windows\System32\drivers\wmilib.sys [14912] =>.Microsoft Windows®
O58 - SDL:2009/07/14 00:55:02 A . (.Microsoft Corporation - Couche IFS Winsock2.) -- C:\Windows\System32\drivers\ws2ifsl.sys [16384] =>.Microsoft Corporation
O58 - SDL:2012/07/26 03:33:43 A . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\drivers\WUDFPf.sys [66560] =>.Microsoft Corporation
O58 - SDL:2012/07/26 03:32:51 A . (.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) -- C:\Windows\System32\drivers\WUDFRd.sys [155136] =>.Microsoft Corporation
O58 - SDL:2009/09/28 10:22:00 A . (.©Copyright 2002-2009 Marvell®. All rights reserved. - .) -- C:\Windows\System32\drivers\yk62x86.sys [315392] =>.©Copyright 2002-2009 Marvell®. All rights reserved.
O58 - SDL:2009/07/13 22:40:41 A . (...) -- C:\Windows\System32\ANSI.SYS [9029] =>.Microsoft Corporation
O58 - SDL:2015/03/04 05:16:14 A . (.Microsoft Corporation - Common Log File System Driver.) -- C:\Windows\System32\clfs.sys [249784] =>.Microsoft Corporation®
O58 - SDL:2009/07/13 22:40:44 A . (...) -- C:\Windows\System32\country.sys [27097] =>.Microsoft Corporation
O58 - SDL:2010/11/20 10:50:05 A . (.Microsoft Corporation - IEEE-1284.4 Print Class Driver.) -- C:\Windows\System32\Dot4Prt.sys [16384] =>.Microsoft Corporation
O58 - SDL:2009/07/13 22:40:40 A . (...) -- C:\Windows\System32\HIMEM.SYS [4768] =>.Microsoft Corporation
O58 - SDL:2009/07/13 22:40:43 A . (...) -- C:\Windows\System32\KEY01.SYS [42809] =>.Microsoft Corporation
O58 - SDL:2009/07/13 22:40:43 A . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537] =>.Microsoft Corporation
O58 - SDL:2009/07/13 22:40:23 A . (...) -- C:\Windows\System32\NTDOS.SYS [27866] =>.Microsoft Corporation
O58 - SDL:2009/07/13 22:40:31 A . (...) -- C:\Windows\System32\NTDOS404.SYS [29146] =>.Microsoft Corporation
O58 - SDL:2009/07/13 22:40:35 A . (...) -- C:\Windows\System32\NTDOS411.SYS [29370] =>.Microsoft Corporation
O58 - SDL:2009/07/13 22:40:39 A . (...) -- C:\Windows\System32\NTDOS412.SYS [29274] =>.Microsoft Corporation
O58 - SDL:2009/07/13 22:40:27 A . (...) -- C:\Windows\System32\NTDOS804.SYS [29146] =>.Microsoft Corporation
O58 - SDL:2009/07/13 22:40:11 A . (...) -- C:\Windows\System32\NTIO.SYS [33952] =>.Microsoft Corporation
O58 - SDL:2009/07/13 22:40:15 A . (...) -- C:\Windows\System32\NTIO404.SYS [34672] =>.Microsoft Corporation
O58 - SDL:2009/07/13 22:40:17 A . (...) -- C:\Windows\System32\NTIO411.SYS [35776] =>.Microsoft Corporation
O58 - SDL:2009/07/13 22:40:19 A . (...) -- C:\Windows\System32\NTIO412.SYS [35536] =>.Microsoft Corporation
O58 - SDL:2009/07/13 22:40:13 A . (...) -- C:\Windows\System32\NTIO804.SYS [34672] =>.Microsoft Corporation
O58 - SDL:2015/06/25 09:46:17 A . (.Microsoft Corporation - Pilote Win32 multi-utilisateurs.) -- C:\Windows\System32\win32k.sys [2383872] =>.Microsoft Corporation

---\\ ASSOCIATION Shell Spawning (11) - 1s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* =>.Default.Value
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc®
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (...) -- C:\Windows\System32\WScript.exe "%1" %* =>.Default.Value
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S =>.Default.Value
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®

---\\ MENU DE DÉMARRAGE INTERNET (16) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc®
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Opera\Opera.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Program Files\Opera\Opera.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Program Files\Opera\Opera.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Program Files\Opera\Opera.exe (.not file.)

---\\ RECHERCHE D'INFECTION SUR LES NAVIGATEURS (2) - 32s
O69 - SBI: SearchScopes [HKCU]{2D952FDF-B45F-4F26-B04D-F2A57A1171C5} - (Bing) - http://www.bing.com/ =>.Bing.com
O69 - SBI: SearchScopes [HKCU]{6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - http://www.google.com/ =>.Google Inc.

---\\ ÉNUMÈRE LES SERVICES DÉMARRÉS PAR Svchost (32) - 1s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [62464] =>.Microsoft Corporation
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [67584] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [67584] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\IKEEXT.DLL [679424] =>.Microsoft Corporation
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\audiosrv.dll [475136] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [90624] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [286208] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [49664] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [300544] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [242176] =>.Microsoft Corporation
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du se.) -- C:\Windows\System32\termsrv.dll [523776] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\System32\wuaueng.dll [2057216] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [585728] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [499712] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\System32\seclogon.dll [21504] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [47104] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688] =>.Microsoft Corporation
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\System32\mmcss.dll [49664] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [61440] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164864] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [750592] =>.Microsoft Corporation
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\KMSVC.DLL [71168] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [113664] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [102912] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800] =>.Microsoft Corporation

---\\ LISTE DES EXCEPTIONS DU PAREFEU WINDOWS (58) - 7s
O87 - FAEL: "TCP Query User{8CC6092E-3283-435B-B709-4B090BE2795D}C:\program files\shareaza\shareaza.exe" [In-None-P6-TRUE] .(...) -- C:\program files\shareaza\shareaza.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "UDP Query User{3A5A1463-89D9-4B94-89E9-77D8B2071854}C:\program files\shareaza\shareaza.exe" [In-None-P17-TRUE] .(...) -- C:\program files\shareaza\shareaza.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "TCP Query User{63B7D1D0-BBED-4D36-ADED-881C0F19D9D0}C:\program files\ares\ares.exe" [In-None-P6-TRUE] .(...) -- C:\program files\ares\ares.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "UDP Query User{18CE230C-ED0F-4CD2-8EB1-09933D890971}C:\program files\ares\ares.exe" [In-None-P17-TRUE] .(...) -- C:\program files\ares\ares.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "TCP Query User{5EECBDCB-7A9B-4FC3-8BE2-D1B717102237}C:\program files\ares\chatserver.exe" [In-None-P6-TRUE] .(...) -- C:\program files\ares\chatserver.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "UDP Query User{CFF55174-1C23-4B64-8485-BB69FE5A0527}C:\program files\ares\chatserver.exe" [In-None-P17-TRUE] .(...) -- C:\program files\ares\chatserver.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "TCP Query User{B561B381-AA59-422E-9623-73B7F5AEE134}C:\program files\ares\ares.exe" [In-None-P6-TRUE] .(...) -- C:\program files\ares\ares.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "UDP Query User{16760277-94A5-4128-8F2F-1BA9DAFE8584}C:\program files\ares\ares.exe" [In-None-P17-TRUE] .(...) -- C:\program files\ares\ares.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "TCP Query User{3F9320FE-289D-44C9-B80C-CC364D196819}C:\program files\real\realplayer\realplay.exe" [In-None-P6-TRUE] .(...) -- C:\program files\real\realplayer\realplay.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "UDP Query User{15E1D41A-5CC7-42D1-8822-3B4573655CC6}C:\program files\real\realplayer\realplay.exe" [In-None-P17-TRUE] .(...) -- C:\program files\real\realplayer\realplay.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "TCP Query User{1ADEC4CD-F180-43ED-91B5-BA908A1EC633}C:\program files\google\google earth\client\googleearth.exe" [In-None-P6-TRUE] .(...) -- C:\program files\google\google earth\client\googleearth.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "UDP Query User{8B123EDD-1044-4562-A087-0117A89AAFC8}C:\program files\google\google earth\client\googleearth.exe" [In-None-P17-TRUE] .(...) -- C:\program files\google\google earth\client\googleearth.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "TCP Query User{987E0754-BECF-481F-B91A-2AE06D3A3427}C:\program files\google\google earth\plugin\geplugin.exe" [In-None-P6-TRUE] .(...) -- C:\program files\google\google earth\plugin\geplugin.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "UDP Query User{588B7661-F4BE-4517-82FD-D9F45B9F5AC0}C:\program files\google\google earth\plugin\geplugin.exe" [In-None-P17-TRUE] .(...) -- C:\program files\google\google earth\plugin\geplugin.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{1B1B1F30-5B2D-4683-B84C-02B4DCEB2EB2}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "TCP Query User{323941F6-3B11-4476-89E1-FD830907B856}C:\program files\internet download manager\idman.exe" [In-None-P6-TRUE] .(...) -- C:\program files\internet download manager\idman.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "UDP Query User{C7149CDA-065E-4883-956B-9E44D3F1F173}C:\program files\internet download manager\idman.exe" [In-None-P17-TRUE] .(...) -- C:\program files\internet download manager\idman.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "TCP Query User{F3601C7E-4940-4B8D-A25F-570EBD58F738}C:\program files\mozilla firefox\plugin-container.exe" [In-None-P6-TRUE] .(.Mozilla Corporation - Plugin Container for Firefox.) -- C:\program files\mozilla firefox\plugin-container.exe =>.Mozilla Corporation®
O87 - FAEL: "UDP Query User{8DDB12CF-4AA2-462A-B9A0-C9F83EDAB1AB}C:\program files\mozilla firefox\plugin-container.exe" [In-None-P17-TRUE] .(.Mozilla Corporation - Plugin Container for Firefox.) -- C:\program files\mozilla firefox\plugin-container.exe =>.Mozilla Corporation®
O87 - FAEL: "TCP Query User{0FA03182-6D98-4E7A-AB0A-C3C025D6022A}C:\program files\ifreetv\ifreetv.exe" [In-None-P6-TRUE] .(...) -- C:\program files\ifreetv\ifreetv.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "UDP Query User{9E5DEAA3-EA81-4C7E-9CF3-E949C8D9779B}C:\program files\ifreetv\ifreetv.exe" [In-None-P17-TRUE] .(...) -- C:\program files\ifreetv\ifreetv.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "TCP Query User{31DADC15-8C75-43C3-8389-094377E5E3C9}C:\program files\google\chrome\application\chrome.exe" [In-None-P6-TRUE] .(.Google Inc. - Google Chrome.) -- C:\program files\google\chrome\application\chrome.exe =>.Google Inc®
O87 - FAEL: "UDP Query User{9F2AA91A-EE54-4E5B-82E1-85E118397F11}C:\program files\google\chrome\application\chrome.exe" [In-None-P17-TRUE] .(.Google Inc. - Google Chrome.) -- C:\program files\google\chrome\application\chrome.exe =>.Google Inc®
O87 - FAEL: "TCP Query User{543CBBA9-7715-45C2-86B6-9AF63E546FD5}C:\program files\sopcast\sopcast.exe" [In-None-P6-TRUE] .(...) -- C:\program files\sopcast\sopcast.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "UDP Query User{264C3C37-C4CD-45E7-8622-495903121BAB}C:\program files\sopcast\sopcast.exe" [In-None-P17-TRUE] .(...) -- C:\program files\sopcast\sopcast.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "TCP Query User{C832A466-D6D7-449C-8EB5-D0E6B7AFB7BA}C:\program files\sopcast\adv\sopadver.exe" [In-None-P6-TRUE] .(...) -- C:\program files\sopcast\adv\sopadver.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "UDP Query User{41709B83-3A3D-44C3-A8B7-9323E59BA8F8}C:\program files\sopcast\adv\sopadver.exe" [In-None-P17-TRUE] .(...) -- C:\program files\sopcast\adv\sopadver.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "TCP Query User{D14F3301-D626-4718-A2EC-6F786D910F83}C:\program files\videolan\vlc\vlc.exe" [In-None-P6-TRUE] .(.VideoLAN - VLC media player.) -- C:\program files\videolan\vlc\vlc.exe =>.VideoLAN®
O87 - FAEL: "UDP Query User{2E709323-6062-4DD1-A377-6013A45D469F}C:\program files\videolan\vlc\vlc.exe" [In-None-P17-TRUE] .(.VideoLAN - VLC media player.) -- C:\program files\videolan\vlc\vlc.exe =>.VideoLAN®
O87 - FAEL: "TCP Query User{F8D57BF6-F78A-4AF2-8090-5B8CFBD1DE46}C:\program files\1clickdownload\1clickdownloader.exe" [In-None-P6-TRUE] .(...) -- C:\program files\1clickdownload\1clickdownloader.exe (.not file.) =>PUP.Optional.1ClickDownloader
O87 - FAEL: "UDP Query User{44C9C7C6-7866-423C-9CC2-A0774C27314C}C:\program files\1clickdownload\1clickdownloader.exe" [In-None-P17-TRUE] .(...) -- C:\program files\1clickdownload\1clickdownloader.exe (.not file.) =>PUP.Optional.1ClickDownloader
O87 - FAEL: "{43F9402D-565B-4A25-B069-16A1D91F8977}" [In-None-P17-TRUE] .(...) -- D:\temp internet\Fichiers Internet temporaires\Content.IE5\OVVIICKP\eTypeSetup.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{AC8B572B-22B2-4363-9429-16A81F38F4F2}" [Out-None-P17-TRUE] .(...) -- D:\temp internet\Fichiers Internet temporaires\Content.IE5\OVVIICKP\eTypeSetup.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{C4908E89-348C-49A4-B8C1-2464607ABB39}" [In-None-P17-TRUE] .(...) -- C:\Users\Utilisateur\Documents\Downloads\Programs\eTypeSetup.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{6CFCEEAE-664B-4FA8-911E-B5353305FC44}" [Out-None-P17-TRUE] .(...) -- C:\Users\Utilisateur\Documents\Downloads\Programs\eTypeSetup.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{E0788411-5885-48E5-84B4-78E96D62B7F0}" [In-None-P17-TRUE] .(...) -- C:\Users\Utilisateur\AppData\Local\Temp\eType Setup403515.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{4C3AD66D-91B2-43E1-A7D3-A8D4A9ECA3BB}" [Out-None-P17-TRUE] .(...) -- C:\Users\Utilisateur\AppData\Local\Temp\eType Setup403515.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{8E128646-873C-4AA7-A87D-A7E3E0A39D67}" [In-None-P6-TRUE] .(...) -- C:\Program Files\YourFileDownloader\Downloader.exe (.not file.) =>PUP.Optional.YourFileDownloader
O87 - FAEL: "{B04F6416-D548-4C89-AB42-A1348E3A7AE6}" [In-None-P17-TRUE] .(...) -- C:\Program Files\YourFileDownloader\Downloader.exe (.not file.) =>PUP.Optional.YourFileDownloader
O87 - FAEL: "{33F14628-5AE5-4133-88C9-935E170CB4B2}" [In-None-P6-TRUE] .(...) -- C:\Program Files\YourFileDownloader\YourFile.exe (.not file.) =>PUP.Optional.YourFileDownloader
O87 - FAEL: "{45617A58-C5E6-4089-9B33-CF3CB9F9DA0A}" [In-None-P17-TRUE] .(...) -- C:\Program Files\YourFileDownloader\YourFile.exe (.not file.) =>PUP.Optional.YourFileDownloader
O87 - FAEL: "{16793FDE-5711-4F42-9C2D-F536741B52A4}" [In-None-P6-TRUE] .(...) -- C:\Program Files\ma-config.com\maconfservice.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{72EF0240-CB45-4E43-97C7-C56689C06B6A}" [In-None-P17-TRUE] .(...) -- C:\Program Files\ma-config.com\maconfservice.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{6A44F1FC-6D3F-48C9-9646-318A7C51A08E}" [In-None-P6-TRUE] .(...) -- C:\Program Files\RelevantKnowledge\rlvknlg.exe (.not file.) =>PUP.Optional.RelevantKnowledge
O87 - FAEL: "{AEF7D1D1-5458-46B0-9A3E-0C1A7F6BB407}" [In-None-P17-TRUE] .(...) -- C:\Program Files\RelevantKnowledge\rlvknlg.exe (.not file.) =>PUP.Optional.RelevantKnowledge
O87 - FAEL: "{B366C41F-D030-4EAA-A48A-22CC144108DA}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Maxthon\Bin\Maxthon.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{AC0F8E3C-6DF9-4D2C-9DA0-06DA1CD83FF2}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Maxthon\Bin\MxUp.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{468D75FC-157B-4EC3-93E4-59B35C6ACF22}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Maxthon\Bin\MxUp.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{FD18533F-571B-4211-A91A-2C2E9F1DA3A6}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Maxthon\Bin\Maxthon.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{19495D44-D2A9-4083-B05C-4F2EC02DC391}" [In-None-P6-TRUE] .(...) -- C:\Program Files\Opera\opera.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{FA0DBBA1-C988-46ED-BC47-D61988100693}" [In-None-P17-TRUE] .(...) -- C:\Program Files\Opera\opera.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "TCP Query User{FEC34762-FC22-4560-9A44-72032A3C0C84}C:\program files\jerome laban\remote control\btremoteserver.exe" [In-None-P6-TRUE] .(...) -- C:\program files\jerome laban\remote control\btremoteserver.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "UDP Query User{899F5E2A-E400-4C35-8FA5-25D2A673E710}C:\program files\jerome laban\remote control\btremoteserver.exe" [In-None-P17-TRUE] .(...) -- C:\program files\jerome laban\remote control\btremoteserver.exe (.not file.) =>.SUP.Orphan
O87 - FAEL: "{D6BC724D-8859-4D83-86CF-92D4C33F4773}" [In-None-P6-TRUE] .(.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O87 - FAEL: "{66234B6B-AAD4-441F-98B9-709E6A1FB74F}" [In-None-P17-TRUE] .(.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O87 - FAEL: "TCP Query User{3E790D11-9B0C-40AE-9536-999654296F85}C:\program files\mozilla firefox\firefox.exe" [In-None-P6-TRUE] .(.Mozilla Corporation - Firefox.) -- C:\program files\mozilla firefox\firefox.exe =>.Mozilla Corporation®
O87 - FAEL: "UDP Query User{3A02422E-CA40-4A67-AC94-1B143301D263}C:\program files\mozilla firefox\firefox.exe" [In-None-P17-TRUE] .(.Mozilla Corporation - Firefox.) -- C:\program files\mozilla firefox\firefox.exe =>.Mozilla Corporation®
O87 - FAEL: "{F86597B2-41F9-4648-B210-BB90A6A0420E}" [In-None-P17-TRUE] .(.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe =>.Google Inc®

---\\ CODES PRODUITS LOGICIELS (99) - 7s
O90 - PUC: "000021599B0090400000000000F01FEC" [HKLM] . (.Microsoft Application Error Reporting.) =>.Microsoft Corporation
O90 - PUC: "00004109001010400000000000F01FEC" [HKLM] . (.Microsoft Office O MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109101010400000000000F01FEC" [HKLM] . (.Microsoft Office X MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "000041091A0010400000000000F01FEC" [HKLM] . (.Microsoft Office OneNote MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109440010400000000000F01FEC" [HKLM] . (.Microsoft Office InfoPath MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109510010400000000000F01FEC" [HKLM] . (.Microsoft Office Access MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109610010400000000000F01FEC" [HKLM] . (.Microsoft Office Excel MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109710010400000000000F01FEC" [HKLM] . (.Microsoft Office SharePoint Designer MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109810010400000000000F01FEC" [HKLM] . (.Microsoft Office PowerPoint MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109910010400000000000F01FEC" [HKLM] . (.Microsoft Office Publisher MUI (Arabic) 2010.) =>.bl.org
O90 - PUC: "00004109A10010400000000000F01FEC" [HKLM] . (.Microsoft Office Outlook MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109AB0010400000000000F01FEC" [HKLM] . (.Microsoft Office Groove MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109B10010400000000000F01FEC" [HKLM] . (.Microsoft Office Word MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109C20010400000000000F01FEC" [HKLM] . (.Microsoft Office Proofing (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109DB00C0400000000000F01FEC" [HKLM] . (.Langue des info-bulles Microsoft Office 2010 - Français.) -- C:\Windows\Installer\{90140000-00BD-040C-0000-0000000FF1CE}\UICaptionsIcon =>.Microsoft Corporation
O90 - PUC: "00004109E60010400000000000F01FEC" [HKLM] . (.Microsoft Office Shared MUI (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109F10010400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (Arabic) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109F10090400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (English) 2010.) =>.Microsoft Corporation
O90 - PUC: "00004109F100C0400000000000F01FEC" [HKLM] . (.Microsoft Office Proof (French) 2010.) =>.Microsoft Corporation
O90 - PUC: "000051090900C0400000000000F01FEC" [HKLM] . (.Microsoft DCF MUI (French) 2013.) =>.Microsoft Corporation
O90 - PUC: "000051091A00C0400000000000F01FEC" [HKLM] . (.Microsoft OneNote MUI (French) 2013.) =>.Microsoft Corporation
O90 - PUC: "000051091E00C0400000000000F01FEC" [HKLM] . (.Microsoft Office OSM MUI (French) 2013.) =>.Microsoft Corporation
O90 - PUC: "000051092E00C0400000000000F01FEC" [HKLM] . (.Microsoft Office OSM UX MUI (French) 2013.) =>.Microsoft Corporation
O90 - PUC: "000051094400C0400000000000F01FEC" [HKLM] . (.Microsoft InfoPath MUI (French) 2013.) =>.Microsoft Corporation
O90 - PUC: "000051095100C0400000000000F01FEC" [HKLM] . (.Microsoft Access MUI (French) 2013.) =>.Microsoft Corporation
O90 - PUC: "000051096100C0400000000000F01FEC" [HKLM] . (.Microsoft Excel MUI (French) 2013.) =>.Microsoft Corporation
O90 - PUC: "000051098100C0400000000000F01FEC" [HKLM] . (.Microsoft PowerPoint MUI (French) 2013.) =>.Microsoft Corporation
O90 - PUC: "000051099100C0400000000000F01FEC" [HKLM] . (.Microsoft Publisher MUI (French) 2013.) =>.bl.org
O90 - PUC: "00005109A100C0400000000000F01FEC" [HKLM] . (.Microsoft Outlook MUI (French) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109AB00C0400000000000F01FEC" [HKLM] . (.Microsoft Groove MUI (French) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109B100C0400000000000F01FEC" [HKLM] . (.Microsoft Word MUI (French) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109B210C0400000000000F01FEC" [HKLM] . (.Microsoft Lync MUI (French) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109C200C0400000000000F01FEC" [HKLM] . (.Microsoft Office Proofing (French) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109E600C0400000000000F01FEC" [HKLM] . (.Microsoft Office Shared MUI (French) 2013.) =>.Microsoft Corporation
O90 - PUC: "00005109F10010400000000000F01FEC" [HKLM] . (.Microsoft Office Proofing Tools 2013 - اللغة العربية.) -- C:\Windows\Installer\{90150000-001F-0401-0000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "00005109F10031400000000000F01FEC" [HKLM] . (.Microsoft Office Proofing Tools 2013 - Nederlands.) -- C:\Windows\Installer\{90150000-001F-0413-0000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "00005109F10070400000000000F01FEC" [HKLM] . (.Microsoft Office Korrekturhilfen 2013 - Deutsch.) -- C:\Windows\Installer\{90150000-001F-0407-0000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "00005109F10090400000000000F01FEC" [HKLM] . (.Microsoft Office Proofing Tools 2013 - English.) -- C:\Windows\Installer\{90150000-001F-0409-0000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "00005109F100A0C00000000000F01FEC" [HKLM] . (.Microsoft Office Proofing Tools 2013 - Español.) -- C:\Windows\Installer\{90150000-001F-0C0A-0000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "00005109F100C0400000000000F01FEC" [HKLM] . (.Outils de vérification linguistique 2013 de Microsoft Office - Français.) -- C:\Windows\Installer\{90150000-001F-040C-0000-0000000FF1CE}\misc.exe,6 =>.Microsoft Corporation
O90 - PUC: "00005119110000000000000000F01FEC" [HKLM] . (.Microsoft Office Professional Plus 2013.) =>.Microsoft Corporation
O90 - PUC: "08FDE0F82C1301AFED8EDB34A5F5D716" [HKLM] . (.ATI Catalyst Install Manager.) -- C:\Windows\Installer\{8F0EDF80-31C2-FA10-DEE8-BD435A5F7D61}\ARPPRODUCTICON.exe =>.Western Digital Technologies
O90 - PUC: "0C8D398C0AB171541BC18EB9567EF207" [HKLM] . (.Windows Live Photo Common.) =>.CyberLink Corporation
O90 - PUC: "0D756077321A70C3E844C138CE981581" [HKLM] . (.Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053.) =>.Microsoft Corporation
O90 - PUC: "0D9196FA196553F4D956459F18105341" [HKLM] . (.Microsoft SQL Server Compact 3.5 SP2 FRA.) -- C:\Windows\Installer\{AF6919D0-5691-4F35-9D65-54F981013514}\ProductIcon =>.Microsoft Corporation
O90 - PUC: "1097CC45D40855143B35120FCC1921BA" [HKLM] . (.HP Wireless Assistant.) -- C:\Windows\Installer\{54CC7901-804D-4155-B353-21F0CC9112AB}\controlPanelIcon.exe =>.Hewlett-Packard
O90 - PUC: "11F12B5E3396B0E42AC597363E0CD711" [HKLM] . (.Windows Live Messenger.) -- C:\Windows\Installer\{E5B21F11-6933-4E0B-A25C-7963E3C07D11}\MsblIco.Exe =>.Microsoft Corporation
O90 - PUC: "1B92FE2806B924141A55509912D60D35" [HKLM] . (.LightScribe System Software.) -- C:\Windows\Installer\{82EF29B1-9B60-4142-A155-0599216DD053}\ARPPRODUCTICON.exe =>.Hewlett-Packard
O90 - PUC: "1D034B0FAA6BD374B960AAD30DF10D8B" [HKLM] . (.Microsoft SQL Server 2005 Compact Edition [ENU].) -- C:\Windows\Installer\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}\ProductIcon =>.Microsoft Corporation
O90 - PUC: "1D5E3C0FEDA1E123187686FED06E995A" [HKLM] . (.Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219.) =>.bl.org
O90 - PUC: "26CEF00243C306D4C98ECE73E2100CF8" [HKLM] . (.Windows Live SOXE Definitions.) =>.Microsoft Corporation
O90 - PUC: "38A7958FEB1ED7B4DB77C5C85F3A40AE" [HKLM] . (.LG Connection Manager.) =>.Western Digital Technologies
O90 - PUC: "3CE4EA7C31C931244875471DB653F319" [HKLM] . (.HP Web Camera.) =>.Hewlett-Packard
O90 - PUC: "3D04254D3B6B9FF42B3445CE3E1E0066" [HKLM] . (.Windows Live Communications Platform.) =>.Legitimate
O90 - PUC: "3e43b73803c7c394f8a6b2f0402e19c2" [HKLM] . (.Microsoft Visual C++ 2005 Redistributable.) =>.bl.org
O90 - PUC: "4314AE291D01A814191EA5403531A183" [HKLM] . (.Windows Live Movie Maker.) =>.CyberLink Corporation
O90 - PUC: "4A94D9E94FD183147BBDD5788A3980E8" [HKLM] . (.HP Integrated Module with Bluetooth wireless technology.) -- C:\Windows\Installer\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}\ARPPRODUCTICON.exe =>.bl.org
O90 - PUC: "4EA42A62D9304AC4784BF2381208370F" [HKLM] . (.Java 8 Update 73.) -- C:\Program Files\Java\jre1.8.0_73\\bin\javaws.exe =>.Sun Microsystems
O90 - PUC: "568774731F3A2774DA34AACFB6FC9FF9" [HKLM] . (.MSXML 4.0 SP2 (KB927978).) =>.Microsoft Corporation
O90 - PUC: "5DB8CED64757AF740B0894B2BB2EEF3A" [HKLM] . (.Windows Live Movie Maker.) =>.CyberLink Corporation
O90 - PUC: "5FF82D77F242A884285139D7A6D4960E" [HKLM] . (.Adobe AIR.) =>.Adobe Inc.
O90 - PUC: "65FC11932FE9AB9348A62CB73DDC6058" [HKLM] . (.Microsoft .NET Framework 4.5.2.) =>.Microsoft Corporation
O90 - PUC: "67D8D17150F3A5548AFA5C162C769950" [HKLM] . (.Open XML SDK 2.0 for Microsoft Office.) =>.Microsoft Corporation
O90 - PUC: "68AB67CA408033019195008142926844" [HKLM] . (.Adobe Refresh Manager.) -- C:\Windows\Installer\{AC76BA86-0804-1033-1959-001824298644}\ARPPRODUCTICON.exe =>.Western Digital Technologies
O90 - PUC: "68AB67CA7DA76301B744CAF070E41400" [HKLM] . (.Adobe Acrobat Reader DC - Français.) -- C:\Windows\Installer\{AC76BA86-7AD7-1036-7B44-AC0F074E4100}\SC_Reader.ico =>.Adobe Inc.
O90 - PUC: "6E8A266FCD4F2A1409E1C8110F44DBCE" [HKLM] . (.MSXML 4.0 SP2 (KB973688).) =>.Microsoft Corporation
O90 - PUC: "701043F6AA9F6C745BC43C1AF91155F3" [HKLM] . (.Hewlett-Packard ACLM.NET v1.1.1.0.) -- C:\Windows\Installer\{6F340107-F9AA-47C6-B54C-C3A19F11553F}\ARPPRODUCTICON.exe =>.Microsoft Corporation
O90 - PUC: "7430F8847A4C4734197A0318B8DE7A01" [HKLM] . (.Galerie de photos Windows Live.) =>.CyberLink Corporation
O90 - PUC: "766F6333940964D4896BC447E3BE5C1B" [HKLM] . (.Windows Live Photo Gallery.) =>.CyberLink Corporation
O90 - PUC: "7B292C385A83B0447A137070E0186AF4" [HKLM] . (.Windows Live PIMT Platform.) =>.Legitimate
O90 - PUC: "7BD4C90EC03660F46A13E87A329932FA" [HKLM] . (.D3DX10.) =>.Microsoft Corporation
O90 - PUC: "85CA7D1FA45585A47B486B51851B44A9" [HKLM] . (.QLBCASL.) =>.Hewlett-Packard
O90 - PUC: "8837878136296A749B4514DB0E9B9095" [HKLM] . (.Avira.) =>.Avira Software
O90 - PUC: "8994BF104C33134458DE70E9E3FE7ED5" [HKLM] . (.YouCam.) -- C:\Windows\Installer\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\ARPPRODUCTICON.exe =>.CyberLink Corporation
O90 - PUC: "8E3EA3225444F014E8AD31CE31E7B3BD" [HKLM] . (.HP SoftPaq Download Manager.) -- C:\Windows\Installer\{223AE3E8-4445-410F-8EDA-13EC137E3BDB}\ARPPRODUCTICON.exe =>.Western Digital Technologies
O90 - PUC: "907018673D7AD86419761A87C0E167C6" [HKLM] . (.Windows Live FolderShare.) -- C:\Windows\Installer\{76810709-A7D3-468D-9167-A1780C1E766C}\FolderShare48x48.ico =>.Microsoft Corporation
O90 - PUC: "93BAD29AC2E44034A96BCB446EB8552E" [HKLM] . (.Google Update Helper.) =>.Google Inc.
O90 - PUC: "9E2A16BA3D73D584095891BFFDC8FEA4" [HKLM] . (.Windows Live Messenger.) =>.Microsoft Corporation
O90 - PUC: "A089CE062ADB6BC44A720BA745894BAC" [HKLM] . (.Google Update Helper.) =>.Google Inc.
O90 - PUC: "A6C64DD86500CEF47BA082BB611A1FF1" [HKLM] . (.MSVCRT.) =>.Advanced Micro Devices Inc
O90 - PUC: "A8D0516CDE683D1478BB3FBB150B7BF7" [HKLM] . (.Windows Live ID Sign-in Assistant.) =>.Microsoft Corporation
O90 - PUC: "B137AC7CA9FB9D6429FCA87873EA2904" [HKLM] . (.System Requirements Lab for Intel.)
O90 - PUC: "B6ACDB9A3563B764CA384963D73AFB3E" [HKLM] . (.Windows Live Photo Common.) =>.CyberLink Corporation
O90 - PUC: "c1c4f01781cc94c4c8fb1542c0981a2a" [HKLM] . (.Microsoft Visual C++ 2005 Redistributable.) =>.bl.org
O90 - PUC: "CC973E50626FD7E438456483563B30FB" [HKLM] . (.Windows Live UX Platform Language Pack.) =>.Legitimate
O90 - PUC: "D7314F9862C648A4DB8BE2A5B47BE100" [HKLM] . (.Microsoft Silverlight.) -- C:\Windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ARPIcon =>.Microsoft Corporation
O90 - PUC: "DDA39468D428E8B4DB27C8D5DC5CA217" [HKLM] . (.MSXML 4.0 SP2 (KB954430).) =>.Microsoft Corporation
O90 - PUC: "DDEE50C7565EB2E4DA4EC087C47113C1" [HKLM] . (.Crystal Reports for .NET Framework 2.0 (x86).) =>.Microsoft Corporation
O90 - PUC: "E97A59ECCF4EFFF4A857920FB449F22F" [HKLM] . (.Windows Live UX Platform.) =>.Legitimate
O90 - PUC: "F132F0B0A6ECD384AA32773B467F9571" [HKLM] . (.Windows Live Installer.) =>.Microsoft Corporation
O90 - PUC: "F1F913432FC79CC43B75A17E2DFFA35C" [HKLM] . (.Windows Live.) =>.Microsoft Corporation
O90 - PUC: "F2B911EA21A03DF339F59AD626026518" [HKLM] . (.Microsoft .NET Framework 4.5.2 (FRA).) =>.Microsoft Corporation
O90 - PUC: "F4E3B286A696ED244AC1C470AE61874B" [HKLM] . (.Windows Live SOXE.) =>.Microsoft Corporation
O90 - PUC: "F4EF34AC2FF97DA4880FCCB3CA712B62" [HKLM] . (.HP Support Assistant.) -- C:\Windows\Installer\{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226}\ARPPRODUCTICON.exe =>.Hewlett-Packard
O90 - PUC: "F60730A4A66673047777F5728467D401" [HKLM] . (.Java Auto Updater.) =>.Sun Microsystems
O90 - PUC: "6BBFDF96D153C8B4988D68D79C0D2A4A" [HKCU] . (.Windows Media Player Firefox Plugin.) =>.Microsoft Corporation
O90 - PUC: "6DED2C82B5237CC489A371778C7FBFBA" [HKCU] . (.RealUpgrade 1.1.) =>.RealNetworks Inc.
O90 - PUC: "6BBFDF96D153C8B4988D68D79C0D2A4A" [HKU] . (.Windows Media Player Firefox Plugin.) =>.Microsoft Corporation
O90 - PUC: "6DED2C82B5237CC489A371778C7FBFBA" [HKU] . (.RealUpgrade 1.1.) =>.RealNetworks Inc.

---\\ PACKAGES WINDOWS INSTALLER (37) - 61s
[MD5.0B719046677EF7DD0DE522BDF6CBA1F1] [WIS][2009/10/30 15:11:49] (.Hewlett-Packard Company - LS_HSI.) -- C:\Windows\Installer\1366c.msi [9291776] =>.Hewlett-Packard Company
[MD5.E27484A1A6A19F3D350E725FFDE59D39] [WIS][2009/07/17 08:35:36] (.Hewlett-Packard - QLBCASL.) -- C:\Windows\Installer\13675.msi [1302016] =>.Hewlett-Packard
[MD5.0C7D1280611103A2C2A1A4E1E578A012] [WIS][2009/07/23 12:11:32] (.Hewlett-Packard - HP Wireless Assistant.) -- C:\Windows\Installer\1367a.msi [5855744] =>.Hewlett-Packard
[MD5.817276131DE124CEFB8239DD7A920017] [WIS][2011/07/15 22:46:17] (.RealNetworks, Inc. - RealNetworks Upgrade 1.1.0 Component Instal.) -- C:\Windows\Installer\19d20.msi [386497] =>.RealNetworks, Inc.
[MD5.CE55602609C18D0D86303C2C4E2D5DBB] [WIS][2009/08/07 18:02:00] (.ATI Technologies, Inc. - ATI Catalyst Install Manager Installer (32 .) -- C:\Windows\Installer\1b2c35.msi [4576768] =>.ATI Technologies, Inc.
[MD5.22B66C41AE0AD62F19C77F398C30EBA4] [WIS][2011/09/23 19:49:58] (.Hewlett-Packard Company - HP Support Assistant.) -- C:\Windows\Installer\1ba5c7.msi [47443456] =>.Hewlett-Packard Company
[MD5.B91DFFFDCA369A30F8F1351661E5C8A5] [WIS][2011/06/14 10:05:40] (.Hewlett-Packard - Active Check Local Mode .NET.) -- C:\Windows\Installer\1ba5d5.msi [3427328] =>.Hewlett-Packard
[MD5.50EA7A4D9481B12A97070942F474D918] [WIS][2018/05/19 17:44:06] (.Google Inc. - Google Update Helper.) -- C:\Windows\Installer\1ebec4.msi [40960] =>.Google Inc.
[MD5.56AF22BF29DD10829FCCC0018EE92C9B] [WIS][2012/02/27 17:07:16] (.Hewlett-Packard Company - InstallShield® 2010 - Premier Edition with .) -- C:\Windows\Installer\40597d.msi [12388352] =>.Hewlett-Packard Company
[MD5.130830A3BDA660A60A48619480C5F684] [WIS][2010/03/02 13:58:28] (.LGE.) -- C:\Windows\Installer\45d9f.msi [1380864] =>.LGE
[MD5.225B4D0AE11F1DB498A47AE62355209F] [WIS][2011/09/27 19:07:16] (.Macrovision Corporation - InstallShield® 12 - Premier Edition 12.0.) -- C:\Windows\Installer\48f37e.msi [399664] =>.Macrovision Corporation
[MD5.17FF11563916957BD832FEB5ABC93DE5] [WIS][2018/10/09 15:19:42] (.Avira Operations GmbH & Co. KG - Avira.) -- C:\Windows\Installer\5704f.msi [4353491] =>.Avira Operations GmbH & Co. KG
[MD5.51160E3CEB7430C735C5156C998397DD] [WIS][2011/04/29 21:07:20] (.Hewlett-Packard - HP Web Camera.) -- C:\Windows\Installer\6e5d05.msi [5489152] =>.Hewlett-Packard
[MD5.1504667BA3C10D841C0B76B6412FAFB5] [WIS][2015/03/17 09:41:29] (.Adobe Systems Incorporated.) -- C:\Windows\Installer\7630a.msi [2805760] =>.Adobe Systems Incorporated
[MD5.F5D5F870FBFFEA5CF42164C8B95F0B40] [WIS][2005/09/23 07:56:32] (.Business Objects.) -- C:\Windows\Installer\78d9b3.msi [16971776] =>.Business Objects
[MD5.19E37C40D69674BC66986F6DD37DE5A4] [WIS][2014/07/12 12:13:53] (.Adobe Systems Incorporated - Adobe AIR Installer.) -- C:\Windows\Installer\a88e7.msi [49152] =>.Adobe Systems Incorporated
[MD5.973448AF011FD33D2114C5F625DDAFC2] [WIS][2009/07/30 18:57:24] (.Broadcom Corp. - WIDCOMM Bluetooth Profile Pack.) -- C:\Windows\Installer\b229c1.msi [3608724] =>.Broadcom Corp.
[MD5.BE8246652CFA0F8ACD36A065E098F787] [WIS][2013/01/04 12:40:08] (.Husdawg, LLC - System Requirements Lab for Intel.) -- C:\Windows\Installer\cb59e.msi [405504] =>.Husdawg, LLC
[MD5.2CEA2A0B1480AED6BA0056FAE3883963] [WIS][2016/03/09 00:05:55] (.Oracle Corporation - Java SE Runtime Environment 8 Update 73.) -- C:\Windows\Installer\dbaa2d.msi [49258496] =>.Oracle Corporation
[MD5.38EF3B7E6E1279E5623ECA8383FE1D92] [WIS][2016/03/09 00:05:40] (.Oracle Corporation - Java Auto Updater.) -- C:\Windows\Installer\dbaa34.msi [765952] =>.Oracle Corporation
[MD5.D5E51C3A1D7979665B6B7E1AD2A653B4] [WIS][2018/09/18 14:32:32] (.Adobe Systems Incorporated - Adobe ARM Installer.) -- C:\Windows\Installer\df0e1.msi [887296] =>.Adobe Systems Incorporated
[MD5.72888A4512084F0DF9B4D02EA508679F] [WIS][2014/11/12 10:26:38] (.Google Inc. - Google Update Helper.) -- C:\Windows\Installer\f1185.msi [26112] =>.Google Inc.
[MD5.BE12C27B769F766B80F398F7F6066644] [WIS][2018/08/13 07:20:00] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\120145.msp [103403520] =>.Adobe Systems, Incorporated
[MD5.77AB51250501ADDD4D491DECDB6121FD] [WIS][2017/08/28 17:40:46] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\121f12.msp [2424832] =>.Adobe Systems, Incorporated
[MD5.B02CDF597655C7CAD392D0404975E9AB] [WIS][2018/10/01 10:41:46] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\1b045b.msp [194531328] =>.Adobe Systems, Incorporated
[MD5.82F476D2A7125BB7EBF5A2A657BAB293] [WIS][2017/11/13 05:26:16] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\1d6fe0.msp [23506944] =>.Adobe Systems, Incorporated
[MD5.3617A09ABC822D955214EBE86A991CF3] [WIS][2017/11/29 11:42:28] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\1f212e.msp [1355776] =>.Adobe Systems, Incorporated
[MD5.AEEED5F2BB5ED9A586D1FC293387AF32] [WIS][2017/02/21 13:33:42] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\216434.msp [77639680] =>.Adobe Systems, Incorporated
[MD5.04B537B3AB3D8FD3121C2F07CB853532] [WIS][2018/02/23 14:25:32] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\25c7f9.msp [103350272] =>.Adobe Systems, Incorporated
[MD5.CF478CA41BB57CA934019B65FCD35FB2] [WIS][2017/08/11 11:05:31] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\34bb8.msp [100052992] =>.Adobe Systems, Incorporated
[MD5.9A90F75504F5C7736959925773C5F4B7] [WIS][2016/10/01 02:09:50] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\7630b.msp [75145216] =>.SUP.Obsolete.Adobe
[MD5.E7BD518BB2F9A3A86C8AD97881120EBB] [WIS][2018/10/08 12:11:44] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\76bdc.msp [2174976] =>.Adobe Systems, Incorporated
[MD5.87BDB58F9E5B4EFC3B72EB9AD83EDE24] [WIS][2018/11/13 05:24:12] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\ac6af.msp [3485696] =>.Adobe Systems, Incorporated
[MD5.CECF2A7991F74C858965EA972A43CE3F] [WIS][2017/04/10 06:34:32] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\c0048.msp [57815040] =>.Adobe Systems, Incorporated
[MD5.7DF2196737D027C989EEE176078B4E7F] [WIS][2018/10/22 14:33:19] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\ca151.msp [2584576] =>.Adobe Systems, Incorporated
[MD5.894F8CA42DB45DFDB94D579984B5B89A] [WIS][2018/09/18 09:10:59] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\cfd63.msp [4706304] =>.Adobe Systems, Incorporated
[MD5.E05CA6506E1D5ECE25152018D3FF00CE] [WIS][2018/05/12 07:05:37] (.Adobe Systems, Incorporated.) -- C:\Windows\Installer\dcee7.msp [7094272] =>.Adobe Systems, Incorporated

---\\ FEATURE CONTROLE. (877) - 3s
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL]:WindowsAnytimeUpgradeUI.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Common.DBConnection.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Common.DBConnection64.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:filecompare.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SPREADSHEETCOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:DATABASECOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:POWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:PPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:PDFREFLOW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:WINWORD.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:WORDICON.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT]:VPREVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:infopath.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_IMG]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]:ValueApps.exe =>.SUP.Conduit
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_Cross_Domain_Redirect_Mitigation]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_ISO_2022_JP_SNIFFING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPfewgsrv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGuiIT.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPGUI.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLgPad.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:SAPLOGON.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:Scale_for_R3.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:ieuser.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK]:YahooMusicEngine.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:devenv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:dexplore.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:helppane.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS]:msfeedssync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HIGH_CONTRAST_BACKGROUND_IMAGES]:sidebar.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Common.DBConnection.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Common.DBConnection64.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:filecompare.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SPREADSHEETCOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:DATABASECOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:POWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:PPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:PDFREFLOW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:WINWORD.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:WORDICON.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]:VPREVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_XML_PROLOG]:msiexec.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:wm.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:cs.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]:waol.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DISPPARAMS]:helppane.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS]:wlmail.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Common.DBConnection.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Common.DBConnection64.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:filecompare.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SPREADSHEETCOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:DATABASECOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:POWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:PPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]:msnmsgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Common.DBConnection.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Common.DBConnection64.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:filecompare.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SPREADSHEETCOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:DATABASECOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:POWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:PPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:PDFREFLOW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]:WINWORD.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Common.DBConnection.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Common.DBConnection64.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:filecompare.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SPREADSHEETCOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:DATABASECOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:POWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:PPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:PDFREFLOW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:WINWORD.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]:WORDICON.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:mshta.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:outlook.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]:sidebar.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Common.DBConnection.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Common.DBConnection64.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:filecompare.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SPREADSHEETCOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:DATABASECOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:POWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:PPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:PDFREFLOW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:WINWORD.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]:WORDICON.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Common.DBConnection.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Common.DBConnection64.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:filecompare.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SPREADSHEETCOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:DATABASECOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:POWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:PPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:PDFREFLOW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:WINWORD.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]:WORDICON.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING]:communicator.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Common.DBConnection.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Common.DBConnection64.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:filecompare.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SPREADSHEETCOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:DATABASECOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:POWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:PPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:PDFREFLOW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:WINWORD.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:WORDICON.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]:VPREVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:msimn.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:winmail.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Common.DBConnection.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Common.DBConnection64.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:filecompare.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SPREADSHEETCOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:DATABASECOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:POWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:PPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:PDFREFLOW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]:WINWORD.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Common.DBConnection.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Common.DBConnection64.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:filecompare.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SPREADSHEETCOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:DATABASECOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:PPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:PDFREFLOW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:WORDICON.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]:VPREVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SCRIPTURL_MITIGATION]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Common.DBConnection.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Common.DBConnection64.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:filecompare.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SPREADSHEETCOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:DATABASECOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:POWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:PPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:PDFREFLOW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:WINWORD.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:WORDICON.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND]:VPREVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:winmail.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:msimn.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]:outlook.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Common.DBConnection.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Common.DBConnection64.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:filecompare.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SPREADSHEETCOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:DATABASECOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:POWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:PPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:PDFREFLOW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:WINWORD.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:WORDICON.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]:VPREVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:infopath.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:winword.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:excel.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]:powerpnt.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Common.DBConnection.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Common.DBConnection64.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:filecompare.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SPREADSHEETCOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:DATABASECOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:POWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:PPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:PDFREFLOW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:WINWORD.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:WORDICON.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]:VPREVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VIEWLINKEDWEBOC_IS_UNSAFE]:sllauncher.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD]:msn.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Common.DBConnection.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Common.DBConnection64.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:filecompare.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SPREADSHEETCOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:DATABASECOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:POWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:PPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:PDFREFLOW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:WINWORD.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]:WORDICON.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Common.DBConnection.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Common.DBConnection64.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:filecompare.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SPREADSHEETCOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:DATABASECOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:POWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:PPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:PDFREFLOW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:WINWORD.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]:WORDICON.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:explorer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:iexplore.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:prevhost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:wmplayer.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:PresentationHost.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OSE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:EQNEDT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OSPPSVC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:DW20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:DWTRIG20.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Setup.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:ODeploy.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Oarpmany.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:FLTLDR.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOSQM.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:CMigrate.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:protocolhandler.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:CSISYNCCLIENT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:CLVIEW.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:NAMECONTROLSERVER.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOHTMED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOXMLED.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOSYNC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:MSOUC.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OLicenseHeartbeat.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:FIRSTRUN.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SmartTagInstall.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SQLDumper.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:EXCEL.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:XLICONS.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:AppSharingHookController.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:lync.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OcPubMgr.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:UcMapi.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:lynchtmlconv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Common.DBConnection.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Common.DBConnection64.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:Common.ShowHelp.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:filecompare.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SPREADSHEETCOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:DATABASECOMPARE.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:OUTLOOK.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:SCANPST.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:CNFNOT32.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:excelcnv.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:POWERPNT.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:PPTICO.EXE =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:misc.exe =>.Legitimate
[HKLM\SOFTWARE\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]:PDFREFLOW.EXE =>.Legitimate

---\\ SCAN ADDITIONNEL (48) - 14s
C:\Windows\AutoKMS\AutoKMS.exe =>HackTool.AutoKMS
C:\Windows\System32\Tasks\AutoKMSCustom =>HackTool.AutoKMS
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} =>.SUP.Orphan
HKLM\Software\Classes\CLSID\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} =>.SUP.Orphan
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} =>.SUP.Orphan
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} =>.SUP.Orphan
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e9e8eb35-ff77-455d-b677-91e5e4fc06c2} =>.SUP.Orphan
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{e9e8eb35-ff77-455d-b677-91e5e4fc06c2} =>.SUP.Orphan
C:\Program Files\KMSpico =>HackTool.KMSpico
C:\ProgramData\InstallMate =>Adware.Tarma
C:\Users\Utilisateur\AppData\LocalLow\DataMngr =>Adware.Searchqu
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\00avast =>.SUP.Orphan
[HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:TCP Query User{F8D57BF6-F78A-4AF2-8090-5B8CFBD1DE46}C:\program files\1clickdownload\1clickdownloader.exe =>PUP.Optional.1ClickDownloader
[HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:UDP Query User{44C9C7C6-7866-423C-9CC2-A0774C27314C}C:\program files\1clickdownload\1clickdownloader.exe =>PUP.Optional.1ClickDownloader
[HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{8E128646-873C-4AA7-A87D-A7E3E0A39D67} =>PUP.Optional.YourFileDownloader
[HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{B04F6416-D548-4C89-AB42-A1348E3A7AE6} =>PUP.Optional.YourFileDownloader
[HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{33F14628-5AE5-4133-88C9-935E170CB4B2} =>PUP.Optional.YourFileDownloader
[HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{45617A58-C5E6-4089-9B33-CF3CB9F9DA0A} =>PUP.Optional.YourFileDownloader
[HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{6A44F1FC-6D3F-48C9-9646-318A7C51A08E} =>PUP.Optional.RelevantKnowledge
[HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]:{AEF7D1D1-5458-46B0-9A3E-0C1A7F6BB407} =>PUP.Optional.RelevantKnowledge
C:\Windows\Installer\7630b.msp =>.SUP.Obsolete.Adobe
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\001 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\003 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\004 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\005 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\006 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\007 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\008 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\009 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\010 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\011 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\012 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\013 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\014 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\015 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\016 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\017 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\018 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\019 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\020 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\021 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\022 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\023 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\024 =>.SUP.Temporary.Chrome
C:\Users\Utilisateur\AppData\Local\Google\Chrome\User Data\Default\File System\025 =>.SUP.Temporary.Chrome
C:\Windows\Installer\MSI3FFD.tmp =>Toolbar.Ask
HKCU\Software\TeleCharger =>.SUP.Downloader
HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3306339443-3704132785-2724747589-1000\Software\SweetIM =>.SUP.SweetIM

---\\ RÉCAPITULATIF DES ÉLÉMENTS TROUVÉS SUR VOTRE STATION (18) - 0s
https://nicolascoolman.eu/2017/02/02/hacktool-autokms/ =>HackTool.AutoKMS
https://nicolascoolman.eu/2017/09/12/origine-lignes-orphelines/ =>.SUP.Orphan
https://nicolascoolman.eu/2017/12/22/sup-downloader/ =>.SUP.Downloader
https://nicolascoolman.eu/2017/09/08/sup-sweetim/ =>.SUP.SweetIM
https://nicolascoolman.eu/2017/09/23/barres-doutils-de-navigateur-toolbars/ =>Toolbar.Mamverifier
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.RegistryReviver
https://www.nicolascoolman.com/fr/adware-shoppingreport/ =>PUP.Optional.ShoppingReport
https://nicolascoolman.eu/2017/02/16/hacktool-kmspico/ =>HackTool.KMSpico
https://nicolascoolman.eu/2017/09/09/adware-tarma/ =>Adware.Tarma
https://nicolascoolman.eu/2017/10/15/adware-searchqu/ =>Adware.Searchqu
https://nicolascoolman.eu/2017/11/29/le-format-clsid-registre-windows/ =>.SUP.Empty.CLSID
https://www.nicolascoolman.com/fr/pup-1clickdownloader/ =>PUP.Optional.1ClickDownloader
https://nicolascoolman.eu/2017/09/13/pup-optional-yourfiledownloader/ =>PUP.Optional.YourFileDownloader
https://nicolascoolman.eu/2017/10/27/adware-relevantknowledge/ =>PUP.Optional.RelevantKnowledge
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Obsolete.Adobe
https://nicolascoolman.eu/2017/02/06/superfluous-conduit/ =>.SUP.Conduit
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Temporary.Chrome
https://nicolascoolman.eu/2017/02/28/toolbar-ask/ =>Toolbar.Ask

~ Unselected Options: O82,
~ End of the scan, 11300 items in 06mn33s (2873)(0)

Publicité


Signaler le contenu de ce document

Publicité