cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPDiag v2016.1.31.23 Par Nicolas Coolman (2016/01/30)
~ Démarré par Admin (Administrator) (2020/08/01 07:42:32)
~ Site: http://www.nicolascoolman.fr
~ Facebook: https://www.facebook.com/nicolascoolman1
~ Etat de la version: Pas de fichier réseau
~ Mode: Scanner
~ Rapport: C:\Users\Admin\Desktop\ZHPDiag.txt
~ Rapport: C:\Users\Admin\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ Démarrage du système: Normal (Normal boot)
Windows 7 Professional, 64-bit Service Pack 1 (Build 7601)

---\\ Navigateurs Internet (1) - 1s
MSIE: Internet Explorer v11.0.9600.19596

---\\ Informations sur les produits Windows (4) - 3s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : KO
Windows Activation Technologies : OK

---\\ Logiciels de protection (1) - 164s
Windows Defender W7 (Deactivate)

---\\ Logiciels d'optimisation (1) - 168s
CCleaner v5.69

---\\ Surveillance de Logiciels (2) - 168s
Adobe Flash Player 32 ActiveX
Adobe Acrobat Reader DC - Français

---\\ Logiciels de partage P2P (1) - 168s
eMule

---\\ Informations sur le système (6) - 0s
~ Operating System: Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 3135.672 MB (27% free)
System Restore: Activé (Enable)
System drive C: has 380 GB () free of 476 GB

---\\ Mode de connexion au système (3) - 0s
~ Computer Name: ADMIN-PC
~ User Name: Admin
~ Logged in as Administrator

---\\ Enumération des unités disques (1) - 5s
~ Drive C: has 380 GB free of 476 GB (System)

---\\ Etat du Centre de Sécurité Windows (11) - 1s
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Recherche particulière de fichiers génériques (26) - 7s
[MD5.38AE1B3C38FAEF56FE4907922F0385BA] - 29/08/2016 - (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\Explorer.exe [3229696] =>.Microsoft Corporation
[MD5.C36BB659F08F046B139C8D1B980BF1AC] - 30/03/2017 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe [46080] =>.Microsoft Corporation
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - 14/07/2009 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\System32\Wininit.exe [129024] =>.Microsoft Corporation
[MD5.05B14D2A76DD045041963CF0B50E3B91] - 17/12/2019 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [4859392] =>.Microsoft Corporation
[MD5.CA0E2DF49879C57652531331EF5AE632] - 14/08/2019 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\Windows\System32\Winlogon.exe [455680] =>.Microsoft Corporation
[MD5.067FA52BFB59A56110A12312EF9AF243] - 21/11/2010 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [232448] =>.Microsoft Corporation
[MD5.9B86DF86D1EFF32893BC3FB49BFAA993] - 08/06/2018 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\System32\dnsapi.dll [357888] =>.Microsoft Corporation
[MD5.4A35D7B172AFF9C6B362D7297568836A] - 08/06/2018 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\Syswow64\dnsapi.dll [269824] =>.Microsoft Corporation
[MD5.978DB06958B3F10B36C306D141E010FA] - 21/09/2015 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [20480] =>.Microsoft Corporation
[MD5.0DC2A9882540DEA4A55B08785E09D8FC] - 04/04/2017 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [496128] =>.Microsoft Corporation
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - 14/07/2009 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [24128] =>.Microsoft Windows®
[MD5.B861DF1DC9CA9259934DBAC5E069681B] - 10/02/2019 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [92672] =>.Microsoft Corporation
[MD5.19D46F7541942E5FC7D99199C53C3689] - 21/09/2015 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [150016] =>.Microsoft Corporation
[MD5.63705A08981F7EDD376241D6E0A9C2AC] - 25/04/2018 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [115200] =>.Microsoft Corporation
[MD5.04EC89E18FBA1F3F0E0C55DBF6F45E86] - 21/09/2015 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [122368] =>.Microsoft Corporation
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - 14/07/2009 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [105472] =>.Microsoft Corporation
[MD5.C9A829B22D1F2613E7A3A3E5C0E43EA2] - 21/09/2015 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [116224] =>.Microsoft Corporation
[MD5.360F7406B9CEA63F9FA61335233C451A] - 03/01/2020 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [161280] =>.Microsoft Corporation
[MD5.0805034EA6F5273D4CB130D726AA5450] - 21/02/2019 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [262656] =>.Microsoft Corporation
[MD5.1D728E2DA93EE1F7766DE97D0BEEFC57] - 10/02/2019 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [1680104] {330000005D47BB9D781CF7910C00010000005D} =>.Microsoft Corporation
[MD5.0086431C29C35BE1DBC43F52CC273887] - 14/07/2009 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\Parport.sys [97280] =>.Microsoft Corporation
[MD5.471815800AE33E6F1C32FB1B97C490CA] - 21/11/2010 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [129536] =>.Microsoft Corporation
[MD5.5A5849E58B81C1853D48DF7516CB9AA2] - 21/09/2015 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [166400] =>.Microsoft Corporation
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - 14/07/2009 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [93184] =>.Microsoft Corporation
[MD5.4DD986720F7CB7A8A5D1226793097B9A] - 29/07/2017 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [117248] =>.Microsoft Corporation
[MD5.DAF3D11D0F0FCCBA822F2D558C103CB5] - 21/09/2015 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [297408] {330000002D31F64FB7A2F9756B00000000002D} =>.Microsoft Corporation

---\\ Liste des services NT non Microsoft et non désactivés (10) - 4s
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) . (.ABBYY - ABBYY network license server.) - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe =>.ABBYY SOLUTIONS LIMITED®
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Inc. - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe {0EE3F1C8F451CBF21203341A53F23E71}
O23 - Service: Background Logic Handler (backlh) . (.Copyright © 2016 - ExtManager.) - C:\ProgramData\Logic Cramble\set.exe
O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.®
O23 - Service: CloudPrinter (CloudPrinter) . (...) - C:\ProgramData\CloudPrinter\CloudPrinter.exe
O23 - Service: Main Service (Main Service) . (.Adobe Systems, Incorporated - ExtendScript Toolkit and Debugger.) - C:\Program Files (x86)\MachinerData\emomail.exe =>.Adobe Systems, Incorporated
O23 - Service: PG Manager (pgt_svc) . (.Gold Click Ltd - PG Control Center.) - C:\Program Files (x86)\ProxyGate\MainService.exe {1121E1CE57747D3AA0E2D8A055EE1FA5696D}
O23 - Service: TrustedLogos (TrustedLogos) . (.Copyright © 2018 - TrustedLogos.) - C:\Windows\trustedlogos\TrustedLogos.exe {43EEDB8EFEE79DAAC712F0EA88ECAF99}
O23 - Service: Windows Defender Helper Service (WinDefender) . (...) - C:\Windows\windefender.exe
O23 - Service: Wondershare Application Framework Service (WsAppService) . (.Wondershare - Wondershare Passport.) - C:\Program Files (x86)\Wondershare\WAF\2.4.3.227\WsAppService.exe {5CCAA82369A26AEE30D017616B1CEB69} =>.Wondershare

---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (12) - 19s

SR - Auto [14/05/2009] [ 759048] ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) . (.ABBYY.) - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe =>.ABBYY SOLUTIONS LIMITED®
SR - Auto [07/05/2020] [ 169032] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Inc..) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe {0EE3F1C8F451CBF21203341A53F23E71}
SS - Demand [14/07/2020] [ 335416] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe {0D2CACCD3E9EEC06738410BA31BF6595} =>.Adobe
SR - Auto [05/04/2020] [ 3780096] Background Logic Handler (backlh) . (.Copyright © 2016.) - C:\ProgramData\Logic Cramble\set.exe
SR - Auto [12/08/2015] [ 462096] Service Bonjour (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.®
SR - Auto [05/04/2020] [ 4538880] CloudPrinter (CloudPrinter) . (...) - C:\ProgramData\CloudPrinter\CloudPrinter.exe
SR - Auto [05/04/2020] [ 2372608] Main Service (Main Service) . (.Adobe Systems, Incorporated.) - C:\Program Files (x86)\MachinerData\emomail.exe =>.Adobe Systems, Incorporated
SS - Auto [22/02/2017] [ 2285664] PG Manager (pgt_svc) . (.Gold Click Ltd.) - C:\Program Files (x86)\ProxyGate\MainService.exe {1121E1CE57747D3AA0E2D8A055EE1FA5696D}
SR - Auto [19/09/2019] [ 11328] TrustedLogos (TrustedLogos) . (.Copyright © 2018.) - C:\Windows\trustedlogos\TrustedLogos.exe {43EEDB8EFEE79DAAC712F0EA88ECAF99}
SR - Auto [ 0] [ 0] Windows Defender Helper Service (WinDefender) . (...) - C:\Windows\windefender.exe
SR - Auto [21/06/2017] [ 492768] Wondershare Application Framework Service (WsAppService) . (.Wondershare.) - C:\Program Files (x86)\Wondershare\WAF\2.4.3.227\WsAppService.exe {5CCAA82369A26AEE30D017616B1CEB69} =>.Wondershare

---\\ Processus lancés (51) - 83s
[MD5.B33CF4DE909A5B30F526D82053A63C8E] - (.ABBYY - ABBYY network license server.) -- C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048] [PID.1580] =>.ABBYY SOLUTIONS LIMITED®
[MD5.8BF1E479EF039D92ACB50B1FE2F2FD23] - (.Adobe Inc. - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169032] [PID.1648] {0EE3F1C8F451CBF21203341A53F23E71}
[MD5.D441765B31968FDAFB40A392247194F6] - (.Copyright © 2016 - ExtManager.) -- C:\ProgramData\Logic Cramble\set.exe [3780096] [PID.1668]
[MD5.B5C2F92EE1106DFE7BB1CCE4D35B6037] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [462096] [PID.1792] =>.Apple Inc.®
[MD5.A630DCDA5FF6DEF89A833F186F067277] - (...) -- C:\ProgramData\CloudPrinter\CloudPrinter.exe [4538880] [PID.1824]
[MD5.EF928DB6C330311A9A2359E6CFB40614] - (.Adobe Systems, Incorporated - ExtendScript Toolkit and Debugger.) -- C:\Program Files (x86)\MachinerData\emomail.exe [2372608] [PID.2156] =>.Adobe Systems, Incorporated
[MD5.8CC8039DAA421DBA629D010B28807015] - (...) -- C:\Program Files (x86)\Rebekah\jalisco.exe [61102] [PID.2564]
[MD5.EF928DB6C330311A9A2359E6CFB40614] - (.Adobe Systems, Incorporated - ExtendScript Toolkit and Debugger.) -- C:\Program Files (x86)\MachinerData\main.exe [2372608] [PID.2724] =>.Adobe Systems, Incorporated
[MD5.4DB7A8F72D052BBD0BE4B701BDF98A90] - (.Copyright © 2018 - TrustedLogos.) -- C:\Windows\trustedlogos\TrustedLogos.exe [11328] [PID.2844] {43EEDB8EFEE79DAAC712F0EA88ECAF99}
[MD5.7A67AEB4C77D30787B3BAC516A81F2B1] - (.Gold Click Ltd - PG Network Component.) -- C:\Program Files (x86)\ProxyGate\Cloud.exe [1503328] [PID.3060] {1121E1CE57747D3AA0E2D8A055EE1FA5696D}
[MD5.103CCD4D3CE1FF6AF01F0FABA6B290AB] - (.Wondershare - Wondershare Passport.) -- C:\Program Files (x86)\Wondershare\WAF\2.4.3.227\WsAppService.exe [492768] [PID.3052] {5CCAA82369A26AEE30D017616B1CEB69} =>.Wondershare
[MD5.96C36729FFEEEE3B7BA7ADD80C4418F6] - (.Gold Click Ltd - PG Helper Process.) -- C:\Program Files (x86)\ProxyGate\PGChk.exe [1007200] [PID.2072] {1121E1CE57747D3AA0E2D8A055EE1FA5696D}
[MD5.DC432CDD792556B52D1EB414C40D9A56] - (.Nonomarta - .) -- C:\Program Files (x86)\CNis\583383823.exe [484352] [PID.3764]
[MD5.DD9D606D37338E04EBB4B744998F7E37] - (.Copyright © 7911 - QX8@.) -- C:\Program Files\5XR3URII0F\5XR3URII0.exe [5182464] [PID.3944]
[MD5.50ACEA3147D7E079578BD74BDAF75954] - (. - Slim Setup.) -- C:\Users\Admin\AppData\Roaming\4po5p45s2xv\elgvl5eyrsu.exe [714887] [PID.2676]
[MD5.DD9D606D37338E04EBB4B744998F7E37] - (.Copyright © 7911 - QX8@.) -- C:\Program Files\6ZGUHMH0RO\6ZGUHMH0R.exe [5182464] [PID.2656]
[MD5.EA43016F14A8719A035112F2383DF397] - (. - Setup/Uninstall.) -- C:\Users\Admin\AppData\Local\Temp\is-MHF2C.tmp\elgvl5eyrsu.tmp [897536] [PID.3492]
[MD5.50ACEA3147D7E079578BD74BDAF75954] - (. - Slim Setup.) -- C:\Users\Admin\AppData\Roaming\yas4wlabe1b\dwiukvplxao.exe [714887] [PID.1500]
[MD5.DD9D606D37338E04EBB4B744998F7E37] - (.Copyright © 7911 - QX8@.) -- C:\Program Files\X0P5EQHLF4\X0P5EQHLF.exe [5182464] [PID.1840]
[MD5.EA43016F14A8719A035112F2383DF397] - (. - Setup/Uninstall.) -- C:\Users\Admin\AppData\Local\Temp\is-RNGRT.tmp\dwiukvplxao.tmp [897536] [PID.2920]
[MD5.BE836AA792B2DCA757B8C14E54AC0663] - (. - AOI Setup.) -- C:\Users\Admin\AppData\Roaming\ifdktu15ujb\r1mr40xettg.exe [537056] [PID.1812]
[MD5.5ED68C2D50F4232A83D39C41722BC908] - (. - Setup/Uninstall.) -- C:\Users\Admin\AppData\Local\Temp\is-8N8FJ.tmp\r1mr40xettg.tmp [718848] [PID.1156]
[MD5.C35F8DB6E626B1105D84E0B3D28C9078] - (.CT27IZC7R - C.) -- C:\Program Files\M0LI5PB42P\KZSRCZ5SK.exe [5181952] [PID.628]
[MD5.ADABCD98CAE05031A6EB7E57433C5BAD] - (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe [29262520] [PID.4176] {02FA994D660DE659EE9037ECB437D766}
[MD5.BE836AA792B2DCA757B8C14E54AC0663] - (. - AOI Setup.) -- C:\Users\Admin\AppData\Roaming\vbg4swbczdr\3bto2yc3zvr.exe [537056] [PID.4240]
[MD5.5ED68C2D50F4232A83D39C41722BC908] - (. - Setup/Uninstall.) -- C:\Users\Admin\AppData\Local\Temp\is-721OG.tmp\3bto2yc3zvr.tmp [718848] [PID.4568]
[MD5.C35F8DB6E626B1105D84E0B3D28C9078] - (.CT27IZC7R - C.) -- C:\Program Files\1NPPF7NZXS\LGJQN9PKQ.exe [5181952] [PID.4584]
[MD5.BE836AA792B2DCA757B8C14E54AC0663] - (. - AOI Setup.) -- C:\Users\Admin\AppData\Roaming\qmwauwtforl\rzj4db15zcg.exe [537056] [PID.4752]
[MD5.C35F8DB6E626B1105D84E0B3D28C9078] - (.CT27IZC7R - C.) -- C:\Program Files\KASZ8A3QXK\XZZEGA9RW.exe [5181952] [PID.2368]
[MD5.5ED68C2D50F4232A83D39C41722BC908] - (. - Setup/Uninstall.) -- C:\Users\Admin\AppData\Local\Temp\is-FTARH.tmp\rzj4db15zcg.tmp [718848] [PID.2440]
[MD5.8AEEA4BAA0F43BAE1E0278A203F72206] - (. - CHs Setup.) -- C:\Users\Admin\AppData\Roaming\hj00t500qut\eqwsujztnrf.exe [1568351] [PID.2488]
[MD5.5ED68C2D50F4232A83D39C41722BC908] - (. - Setup/Uninstall.) -- C:\Users\Admin\AppData\Local\Temp\is-4L798.tmp\eqwsujztnrf.tmp [718848] [PID.4924]
[MD5.BE836AA792B2DCA757B8C14E54AC0663] - (. - AOI Setup.) -- C:\Users\Admin\AppData\Roaming\wle3eswu5dm\xa14d0czhqo.exe [537056] [PID.4692]
[MD5.C35F8DB6E626B1105D84E0B3D28C9078] - (.CT27IZC7R - C.) -- C:\Program Files\N5NPETSJ5L\N5NPETSJ5.exe [5181952] [PID.5172]
[MD5.B04B2D466D9B8FFD75B4CD3F1953163F] - (.Copyright © 4820 - PN.) -- C:\Program Files\PZQD4O9OXS\PZQD4O9OX.exe [5378560] [PID.5260]
[MD5.5ED68C2D50F4232A83D39C41722BC908] - (. - Setup/Uninstall.) -- C:\Users\Admin\AppData\Local\Temp\is-ITHLN.tmp\xa14d0czhqo.tmp [718848] [PID.5308]
[MD5.B04B2D466D9B8FFD75B4CD3F1953163F] - (.Copyright © 4820 - PN.) -- C:\Program Files\2XIOELN26W\2XIOELN26.exe [5378560] [PID.5396]
[MD5.117B725CA67D80E90D6CEB131E05E220] - (.Adobe - Adobe® Flash® Player Installer/Uninstaller.) -- C:\Windows\System32\Macromed\Flash\FlashUtil64_32_0_0_403_ActiveX.exe [1029176] [PID.4212] {0D2CACCD3E9EEC06738410BA31BF6595} =>.Adobe
[MD5.51B52BCDF1B286A3EE5A5E803FD181EF] - (...) -- C:\Users\Admin\AppData\Local\Bunkhouse.exe [12288] [PID.1332]
[MD5.141E10C9D17634EA4B44D63F3AC3E330] - (...) -- C:\Program Files (x86)\Soused\Crocodile.exe [12288] [PID.3544]
[MD5.FF9CE0FC9E3B4BC22001764A9EFE4741] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Admin\Downloads\ZHPDiag3.exe [2105344] [PID.4060] =>.Nicolas Coolman
[MD5.8AEEA4BAA0F43BAE1E0278A203F72206] - (. - CHs Setup.) -- C:\Users\Admin\AppData\Roaming\ovlbmp52ez1\cuvdvf42aos.exe [1568351] [PID.8164]
[MD5.5ED68C2D50F4232A83D39C41722BC908] - (. - Setup/Uninstall.) -- C:\Users\Admin\AppData\Local\Temp\is-OCO7P.tmp\cuvdvf42aos.tmp [718848] [PID.8980]
[MD5.B04B2D466D9B8FFD75B4CD3F1953163F] - (.Copyright © 4820 - PN.) -- C:\Program Files\AVLPLIXWB6\AVLPLIXWB.exe [5378560] [PID.8572]
[MD5.51B52BCDF1B286A3EE5A5E803FD181EF] - (...) -- C:\Program Files (x86)\warfarin\Bunkhouse.exe [12288] [PID.7600]
[MD5.141E10C9D17634EA4B44D63F3AC3E330] - (...) -- C:\Users\Admin\AppData\Local\Crocodile.exe [12288] [PID.8508]
[MD5.5A2ED7202FA368191998FB5601812A79] - (...) -- C:\Program Files (x86)\krzysztof\krzysztof.exe [9216] [PID.8076]
[MD5.51B52BCDF1B286A3EE5A5E803FD181EF] - (...) -- C:\Program Files (x86)\Lameness\Bunkhouse.exe [12288] [PID.4784]
[MD5.141E10C9D17634EA4B44D63F3AC3E330] - (...) -- C:\Program Files (x86)\Lameness\Crocodile.exe [12288] [PID.7816]
[MD5.5D76B5CC36079ACE42B4D52EB9C6495B] - (.ILG CRP ver 31 LLC - ILG_BROWSERINC31 Setup.) -- C:\Users\Admin\AppData\Local\Temp\is-OG5E8.tmp\Setup.exe [2095681] [PID.5196]
[MD5.257AAA4C55D5648F7E4CE5A5A869B11C] - (.sasadfsadas - sasadfsadas.) -- C:\ProgramData\525123.exe [357376] [PID.4100]

---\\ Google Chrome, Démarrage,Recherche,Extensions (11) - 0s
G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [eimadpbcbfnmbkopoojfekhnkhdbieeh] Dark Reader
G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [inafjghmmkmiobijhbgkfekenbfbklhb] Bazz Search SafeFinder =>PUP.Optional.SmartBar
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc.
G2 - GCE: Preference [User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router

---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (2) - 1s
P2 - EXT FILE: (...) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\n5ow9kf8.default\searchplugins\findit.xml =>PUP.Optional.SmartBar
P2 - EXT FILE: (...) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\apehwayj.default-release-1591705974589\extensions\{39790485-930b-40a5-8268-69222363ff80}.xpi

---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (19) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.fr
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbacdbtt-ogb_ztugwdvug9uujovv68avecdemeloac1z2vexqfu5tc1m7z9q7w7sgr8la83g_p2zppx_z3rmxi2dyhnubwddcrwpbroklmvop24pnuxg2f5asmrkkljhghprnhg6h50a8p04hjmdgqy4zv0kqv6ystgzf8q-gg0biacna6w-3s&q={searchterms} =>PUP.Optional.Linkury
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbacdbtt-ogb_ztugwdvug9uujovv68avecdemeloac1z2vexqfu5tc1m7z9q7w7sgr8la83g_p2zppx_z3rmxi2dyhnubwddcrwpbroklmvop24pnuxg2f5asmrkkljhghprnhg6h50a8p04hjmdgqy4zv0kqv6ystgzf8q-gg0biacna6w-3s&q={searchterms} =>PUP.Optional.Linkury
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbacdbtt-ogb_ztugwdvug9uujovv68avecdemeloac1z2vexqfu5tc1m7z9q7w7sgr8la83g_p2zppx_z3rmxi2dyhnubwddcrwpbroklmvop24pnuxg2f5asmrkkljhghprnhg6h50a8p04hjmdgqy4zv0kqv6ystgzf8q-gg0biacna6w-3s&q={searchterms} =>PUP.Optional.Linkury
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbacdbtt-ogb_ztugwdvug9uujovv68avecdemeloac1z2vexqfu5tc1m7z9q7w7sgr8la83g_p2zppx_z3rmxi2dyhnubwddcrwpbroklmvop24pnuxg2f5asmrkkljhghprnhg6h50a8p04hjmdgqy4zv0kqv6ystgzf8q-gg0biacna6w-3s&q={searchterms} =>PUP.Optional.Linkury
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKEY_USERS\S-1-5-21-239632087-1797327919-1825595720-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6f%6e%69%63-%73%65%61%72%63%68.%63%6f%6d/?p=mko_awfzxipyrahdgkbacdbtt-ogb_ztugwdvug9uujovv68avecdemeloac1z2vexqfu5tc1m7z9q7w7sgr8la83g_p2zppx_z3rmxi2dyhnubwddcrwpbroklmvop24pnuxg2f5asmrkkljhghprnhg6h50a8p04hjmdgqy4zv0kqv6ystgzf8q-gg0biacna6w-3s&q={searchterms} =>PUP.Optional.Linkury
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer

---\\ Internet Explorer,Proxy Management (6) - 1s
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.a*.*;*.b*.*;*.d*.*;*.e*.*;*.f*.*;*.h*.*;*.i*.*;*.j*.*;*.k*.*;*.l*.*;*.m*.*;*.n*.*;*.o*.*;*.p*.*;*.q*.*;*.r*.*;*.s*.*;*.u*.*;*.v*.*;*.w*.*;*.x*.*;*.y*.*;*.z*.*;*.0*.*;*.1*.*;*.2*.*;*.3*.*;*.4*.*;*.5*.*;*.6*.*;*.7*.*;*.8*.*;*.9*.*;*.*a.*;*.*b.*;*.*d.*;*.*f.*;*.*g.*;*.*h.*;*.*i.*;*.*j.*;*.*k.*;*.*l.*;*.*n.*;*.*p.*;*.*q.*;*.*r.*;*.*t.*;*.*u.*;*.*v.*;*.*w.*;*.*x.*;*.*y.*;*.*z.*;*.*0.*;*.*1.*;*.*2.*;*.*3.*;*.*4.*;*.*5.*;*.*6.*;*.*7.*;*.*8.*;*.*9.*;*.g0*.*;*.g1*.*;*.g2*.*;*.g3*.*;*.g4*.*;*.g5*.*;*.g6*.*;*.g7*.*;*.g8*.*;*.g9*.*;*.t0*.*;*.t1*.*;*.t2*.*;*.t3*.*;*.t4*.*;*.t5*.*;*.t6*.*;*.t7*.*;*.t8*.*;*.t9*.*;*.ga*.*;*.gb*.*;*.gc*.*;*.gd*.*;*.ge*.*;*.gf*.*;*.gg*.*;*.gh*.*;*.gi*.*;*.gj*.*;*.gk*.*;*.gl*.*;*.gm*.*;*.gn*.*;*.gp*.*;*.gq*.*;*.gr*.*;*.gs*.*;*.gt*.*;*.gu*.*;*.gv*.*;*.gw*.*;*.gx*.*;*.gy*.*;*.gz*.*;*.ta*.*;*.tc*.*;*.td*.*;*.te*.*;*.tf*.*;*.tg*.*;*.th*.*;*.ti*.*;*.tj*.*;*.tk*.*;*.tl*.*;*.tm*.*;*.tn*.*;*.to*.*;*.tp*.*;*.tq*.*;*.tr*.*;*.ts*.*;*.tt*.*;*.tu*.*;*.tv*.*;*.tw*.*;*.tx*.*;*.ty*.*;*.tz*.*;*ae.*;*be.*;*ce.*;*de.*;*ee.*;*fe.*;*ge.*;*he.*;*ie.*;*je.*;*ke.*;*me.*;*ne.*;*oe.*;*pe.*;*qe.*;*re.*;*se.*;*te.*;*ue.*;*ve.*;*we.*;*xe.*;*ye.*;*ze.*;*as.*;*bs.*;*cs.*;*ds.*;*fs.*;*gs.*;*hs.*;*js.*;*ks.*;*ls.*;*ms.*;*ns.*;*os.*;*ps.*;*qs.*;*rs.*;*ss.*;*ts.*;*us.*;*vs.*;*ws.*;*xs.*;*ys.*;*zs.*;*ac.*;*bc.*;*cc.*;*dc.*;*ec.*;*fc.*;*gc.*;*hc.*;*jc.*;*kc.*;*lc.*;*mc.*;*nc.*;*oc.*;*pc.*;*qc.*;*rc.*;*sc.*;*tc.*;*uc.*;*vc.*;*wc.*;*xc.*;*yc.*;*zc.*;*.*0e.*;*.*1e.*;*.*2e.*;*.*3e.*;*.*4e.*;*.*5e.*;*.*6e.*;*.*7e.*;*.*8e.*;*.*9e.*;*.*0s.*;*.*1s.*;*.*2s.*;*.*3s.*;*.*4s.*;*.*5s.*;*.*6s.*;*.*7s.*;*.*8s.*;*.*9s.*;*.*0c.*;*.*1c.*;*.*2c.*;*.*3c.*;*.*4c.*;*.*5c.*;*.*6c.*;*.*7c.*;*.*8c.*;*.*9c.*;0*;1*;2*;3*;4*;5*;6*;7*;8*;9*;*0;*1;*2;*3;*4;*5;*6;*7;*8;*9;b*.*;c*.*;d*.*;f*.*;h*.*;i*.*;j*.*;k*.*;l*.*;n*.*;m*.*;o*.*;p*.*;q*.*;r*.*;s*.*;t*.*;u*.*;v*.*;x*.*;y*.*;z*.*
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation

---\\ Etude du fichier hosts (1) - 0s
~ Le fichier hôte est sain (The hosts file is clean) (29)

---\\ Browser Helper Object de navigateur (BHO) (3) - 1s
O2 - BHO: Shareaza Web Download Hook [64Bits] - {0EEDB912-C5FA-486F-8334-57288578C627} . (.Shareaza Development Team - Shareaza Web Download Hook.) -- C:\Program Files (x86)\Shareaza\RazaWebHook32.dll
O2 - BHO: IEToEdge BHO [64Bits] - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} . (.Microsoft Corporation - IEToEdge BHO.) -- C:\Program Files (x86)\Microsoft\Edge\Application\84.0.522.50\BHO\ie_to_edge_bho.dll {330000018B4CB8EB9D8F8AC0E900000000018B} =>.Microsoft Corporation
O2 - BHO: Easy Photo Print [64Bits] - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} (Orphean)

---\\ Applications lancées au démarrage du système (49) - 3s
O4 - HKLM\..\RunOnce: [1chjuve1qnj] . (.Nonomarta - .) -- C:\Program Files (x86)\CNis\583383823.exe
O4 - HKCU\..\Run: [mrthlo] . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe =>.Microsoft Corporation
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] . (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe {02FA994D660DE659EE9037ECB437D766}
O4 - HKCU\..\Run: [JL4BG4ZT1IT1MNQ] . (.Copyright © 7911 - QX8@.) -- C:\Program Files\5XR3URII0F\5XR3URII0.exe
O4 - HKCU\..\Run: [AutumnSky] . (...) -- C:\Windows\rss\csrss.exe
O4 - HKCU\..\Run: [5447316] . (. - Slim Setup.) -- C:\Users\Admin\AppData\Roaming\4po5p45s2xv\elgvl5eyrsu.exe
O4 - HKCU\..\Run: [3QQWSBX7Y1Z7MPV] . (.Copyright © 7911 - QX8@.) -- C:\Program Files\6ZGUHMH0RO\6ZGUHMH0R.exe
O4 - HKCU\..\Run: [CloudNet] . (.Copyright © 2020 - .) -- C:\Users\Admin\AppData\Roaming\261e21d9bddc\261e21d9bddc.exe
O4 - HKCU\..\Run: [8967845] . (. - Slim Setup.) -- C:\Users\Admin\AppData\Roaming\yas4wlabe1b\dwiukvplxao.exe
O4 - HKCU\..\Run: [SDF9IO41WTT5CZX] . (.Copyright © 7911 - QX8@.) -- C:\Program Files\X0P5EQHLF4\X0P5EQHLF.exe
O4 - HKCU\..\Run: [7084438] . (. - AOI Setup.) -- C:\Users\Admin\AppData\Roaming\ifdktu15ujb\r1mr40xettg.exe
O4 - HKCU\..\Run: [O85GVZPUHG4ZJB6] . (.CT27IZC7R - C.) -- C:\Program Files\M0LI5PB42P\KZSRCZ5SK.exe
O4 - HKCU\..\Run: [8163035] . (. - AOI Setup.) -- C:\Users\Admin\AppData\Roaming\vbg4swbczdr\3bto2yc3zvr.exe
O4 - HKCU\..\Run: [3YVMKFHMSZ8GHV6] . (.CT27IZC7R - C.) -- C:\Program Files\1NPPF7NZXS\LGJQN9PKQ.exe
O4 - HKCU\..\Run: [4709412] . (. - AOI Setup.) -- C:\Users\Admin\AppData\Roaming\qmwauwtforl\rzj4db15zcg.exe
O4 - HKCU\..\Run: [XPDJEC1EM8ALLWP] . (.CT27IZC7R - C.) -- C:\Program Files\KASZ8A3QXK\XZZEGA9RW.exe
O4 - HKCU\..\Run: [3989712] . (. - AOI Setup.) -- C:\Users\Admin\AppData\Roaming\wle3eswu5dm\xa14d0czhqo.exe
O4 - HKCU\..\Run: [8HAJS1W33B23P3T] . (.CT27IZC7R - C.) -- C:\Program Files\N5NPETSJ5L\N5NPETSJ5.exe
O4 - HKCU\..\Run: [MI5O1MKL8RLBR82] . (.Copyright © 4820 - PN.) -- C:\Program Files\PZQD4O9OXS\PZQD4O9OX.exe
O4 - HKCU\..\Run: [2307802] . (. - CHs Setup.) -- C:\Users\Admin\AppData\Roaming\hj00t500qut\eqwsujztnrf.exe
O4 - HKCU\..\Run: [D11NBZS6N4HLHUV] . (.Copyright © 4820 - PN.) -- C:\Program Files\2XIOELN26W\2XIOELN26.exe
O4 - HKCU\..\Run: [9451] . (. - CHs Setup.) -- C:\Users\Admin\AppData\Roaming\ovlbmp52ez1\cuvdvf42aos.exe
O4 - HKCU\..\Run: [8RUOEA3G8GMYWYQ] . (.Copyright © 4820 - PN.) -- C:\Program Files\AVLPLIXWB6\AVLPLIXWB.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [mrthlo] . (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [CCleaner Smart Cleaning] . (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe {02FA994D660DE659EE9037ECB437D766}
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [JL4BG4ZT1IT1MNQ] . (.Copyright © 7911 - QX8@.) -- C:\Program Files\5XR3URII0F\5XR3URII0.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [AutumnSky] . (...) -- C:\Windows\rss\csrss.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [5447316] . (. - Slim Setup.) -- C:\Users\Admin\AppData\Roaming\4po5p45s2xv\elgvl5eyrsu.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [3QQWSBX7Y1Z7MPV] . (.Copyright © 7911 - QX8@.) -- C:\Program Files\6ZGUHMH0RO\6ZGUHMH0R.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [CloudNet] . (.Copyright © 2020 - .) -- C:\Users\Admin\AppData\Roaming\261e21d9bddc\261e21d9bddc.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [8967845] . (. - Slim Setup.) -- C:\Users\Admin\AppData\Roaming\yas4wlabe1b\dwiukvplxao.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [SDF9IO41WTT5CZX] . (.Copyright © 7911 - QX8@.) -- C:\Program Files\X0P5EQHLF4\X0P5EQHLF.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [7084438] . (. - AOI Setup.) -- C:\Users\Admin\AppData\Roaming\ifdktu15ujb\r1mr40xettg.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [O85GVZPUHG4ZJB6] . (.CT27IZC7R - C.) -- C:\Program Files\M0LI5PB42P\KZSRCZ5SK.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [8163035] . (. - AOI Setup.) -- C:\Users\Admin\AppData\Roaming\vbg4swbczdr\3bto2yc3zvr.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [3YVMKFHMSZ8GHV6] . (.CT27IZC7R - C.) -- C:\Program Files\1NPPF7NZXS\LGJQN9PKQ.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [4709412] . (. - AOI Setup.) -- C:\Users\Admin\AppData\Roaming\qmwauwtforl\rzj4db15zcg.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [XPDJEC1EM8ALLWP] . (.CT27IZC7R - C.) -- C:\Program Files\KASZ8A3QXK\XZZEGA9RW.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [3989712] . (. - AOI Setup.) -- C:\Users\Admin\AppData\Roaming\wle3eswu5dm\xa14d0czhqo.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [8HAJS1W33B23P3T] . (.CT27IZC7R - C.) -- C:\Program Files\N5NPETSJ5L\N5NPETSJ5.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [MI5O1MKL8RLBR82] . (.Copyright © 4820 - PN.) -- C:\Program Files\PZQD4O9OXS\PZQD4O9OX.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [2307802] . (. - CHs Setup.) -- C:\Users\Admin\AppData\Roaming\hj00t500qut\eqwsujztnrf.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [D11NBZS6N4HLHUV] . (.Copyright © 4820 - PN.) -- C:\Program Files\2XIOELN26W\2XIOELN26.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [9451] . (. - CHs Setup.) -- C:\Users\Admin\AppData\Roaming\ovlbmp52ez1\cuvdvf42aos.exe
O4 - HKUS\S-1-5-21-239632087-1797327919-1825595720-1001\..\Run: [8RUOEA3G8GMYWYQ] . (.Copyright © 4820 - PN.) -- C:\Program Files\AVLPLIXWB6\AVLPLIXWB.exe

---\\ Raccourcis Global Startup (46) - 9s
O4 - GS\Desktop [Admin]: Audacity -.lnk . (...) C:\Users\Admin\Documents\Audacity
O4 - GS\Desktop [Admin]: Documents.lnk . (...) C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms
O4 - GS\Desktop [Admin]: Images.lnk . (...) C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms
O4 - GS\Desktop [Admin]: Incoming.lnk . (...) C:\Users\Admin\Downloads\Nouveau dossier (2)\eMule\Incoming
O4 - GS\Desktop [Admin]: MediaCoder.lnk . (.Mediatronic Pty Ltd - MediaCoder.) C:\Program Files (x86)\MediaCoder\MediaCoder.exe =>.Mediatronic Pty Ltd
O4 - GS\Desktop [Admin]: MOT DE PASSE - Raccourci.lnk . (...) C:\Users\Admin\Documents\MOT DE PASSE.rtf
O4 - GS\Desktop [Admin]: Musiques.lnk . (...) C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Libraries\Music.library-ms
O4 - GS\Desktop [Admin]: PeerBlock.lnk . (.PeerBlock, LLC - .) C:\Program Files (x86)\PeerBlock\peerblock.exe =>.PeerBlock, LLC
O4 - GS\Desktop [Admin]: Téléchargements.lnk . (...) C:\Users\Admin\Downloads
O4 - GS\Desktop [Admin]: Vidéos.lnk . (...) C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms
O4 - GS\Desktop [Admin]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Admin\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Admin]: CCleaner Browser.lnk . (...) C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe
O4 - GS\Quicklaunch [Admin]: IncrediMail 2.0.lnk . (.IncrediMail, Ltd. - IncrediMail Application.) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe =>.Perion Network Ltd.®
O4 - GS\Quicklaunch [Admin]: IZArc.lnk . (.Copyright (c) 2017 Ivan Zahariev - IZArc Archiver.) C:\Program Files (x86)\IZArc\IZArc.exe
O4 - GS\Quicklaunch [Admin]: Shareaza Turbo Accelerator.lnk . (.DownloadBoosters LLC - Shareaza Turbo Accelerator.) C:\Program Files (x86)\Shareaza Turbo Accelerator\Shareaza Turbo Accelerator.exe
O4 - GS\Quicklaunch [Admin]: Shareaza.lnk . (.Shareaza Development Team - Shareaza Ultimate File Sharing.) C:\Program Files (x86)\Shareaza\Shareaza.exe
O4 - GS\TaskBar [Admin]: IncrediMail.lnk . (.IncrediMail, Ltd. - IncrediMail Application.) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe =>.Perion Network Ltd.®
O4 - GS\Desktop [Administrateur]: Audacity -.lnk . (...) C:\Users\Admin\Documents\Audacity
O4 - GS\Desktop [Administrateur]: Documents.lnk . (...) C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms
O4 - GS\Desktop [Administrateur]: Images.lnk . (...) C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms
O4 - GS\Desktop [Administrateur]: Incoming.lnk . (...) C:\Users\Admin\Downloads\Nouveau dossier (2)\eMule\Incoming
O4 - GS\Desktop [Administrateur]: MediaCoder.lnk . (.Mediatronic Pty Ltd - MediaCoder.) C:\Program Files (x86)\MediaCoder\MediaCoder.exe =>.Mediatronic Pty Ltd
O4 - GS\Desktop [Administrateur]: MOT DE PASSE - Raccourci.lnk . (...) C:\Users\Admin\Documents\MOT DE PASSE.rtf
O4 - GS\Desktop [Administrateur]: Musiques.lnk . (...) C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Libraries\Music.library-ms
O4 - GS\Desktop [Administrateur]: PeerBlock.lnk . (.PeerBlock, LLC - .) C:\Program Files (x86)\PeerBlock\peerblock.exe =>.PeerBlock, LLC
O4 - GS\Desktop [Administrateur]: Téléchargements.lnk . (...) C:\Users\Admin\Downloads
O4 - GS\Desktop [Administrateur]: Vidéos.lnk . (...) C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms
O4 - GS\Desktop [Administrateur]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Admin\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Administrateur]: CCleaner Browser.lnk . (...) C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe
O4 - GS\Quicklaunch [Administrateur]: IncrediMail 2.0.lnk . (.IncrediMail, Ltd. - IncrediMail Application.) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe =>.Perion Network Ltd.®
O4 - GS\Quicklaunch [Administrateur]: IZArc.lnk . (.Copyright (c) 2017 Ivan Zahariev - IZArc Archiver.) C:\Program Files (x86)\IZArc\IZArc.exe
O4 - GS\Quicklaunch [Administrateur]: Shareaza Turbo Accelerator.lnk . (.DownloadBoosters LLC - Shareaza Turbo Accelerator.) C:\Program Files (x86)\Shareaza Turbo Accelerator\Shareaza Turbo Accelerator.exe
O4 - GS\Quicklaunch [Administrateur]: Shareaza.lnk . (.Shareaza Development Team - Shareaza Ultimate File Sharing.) C:\Program Files (x86)\Shareaza\Shareaza.exe
O4 - GS\TaskBar [Administrateur]: IncrediMail.lnk . (.IncrediMail, Ltd. - IncrediMail Application.) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe =>.Perion Network Ltd.®
O4 - GS\CommonDesktop [Public]: Audacity.lnk . (.Audacity Team - Audacity® Cross-Platform Sound Editor.) C:\Program Files (x86)\Audacity\audacity.exe =>.Audacity Team
O4 - GS\CommonDesktop [Public]: CCleaner.lnk . (.Piriform Software Ltd - CCleaner.) C:\Program Files\CCleaner\CCleaner64.exe {02FA994D660DE659EE9037ECB437D766}
O4 - GS\CommonDesktop [Public]: CDBurnerXP.lnk . (.Canneverbe Limited - CDBurnerXP.) C:\Program Files\CDBurnerXP\cdbxpp.exe {0847C0D333578DAFA9934DA5A3788807}
O4 - GS\CommonDesktop [Public]: eMule.lnk . (.http://www.emule-project.net - eMule.) C:\Program Files (x86)\eMule\emule.exe
O4 - GS\CommonDesktop [Public]: EPSON Scan.lnk . (.SEIKO EPSON CORP. - EPSON Scan.) C:\Windows\twain_32\escndv\escndv.exe =>.SEIKO EPSON CORP.
O4 - GS\CommonDesktop [Public]: IncrediMail.lnk . (.IncrediMail, Ltd. - IncrediMail Application.) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe =>.Perion Network Ltd.®
O4 - GS\CommonDesktop [Public]: OpenOffice 4.1.5.lnk . (.Apache Software Foundation - OpenOffice 4.1.5.) C:\Program Files (x86)\OpenOffice 4\program\soffice.exe =>.Apache Software Foundation
O4 - GS\CommonDesktop [Public]: Shareaza Turbo Accelerator.lnk . (.DownloadBoosters LLC - Shareaza Turbo Accelerator.) C:\Program Files (x86)\Shareaza Turbo Accelerator\Shareaza Turbo Accelerator.exe
O4 - GS\CommonDesktop [Public]: Shareaza.lnk . (.Shareaza Development Team - Shareaza Ultimate File Sharing.) C:\Program Files (x86)\Shareaza\Shareaza.exe
O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files\VideoLAN\VLC\vlc.exe {0FA5B80428F4624CF9672211E1956FBE} =>.VideoLAN
O4 - GS\Programs [Public]: Flvto Youtube Downloader.lnk . (.Hotger © 2019 - FlvtoYoutubeDownloader.Redesign.) C:\Users\Admin\AppData\Local\Flvto Youtube Downloader\FlvtoYoutubeDownloader.Redesign.exe
O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) C:\Windows\system32\taskschd.msc

---\\ Modification Domaine/Adresses DNS (8) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = lan
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3907D7C3-6123-479D-B78D-DA7ECB6F8ED1}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{69DACBD9-44FF-4AD2-A423-8ACFA4BE0DF2}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9A234BD5-DF1C-43B7-9140-AA956593009E}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C63DF4E0-9107-4152-ABD5-EC894FDFBCA3}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CF2B1DF9-8CEB-4F53-8D7C-98C70F764ED3}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CF2B1DF9-8CEB-4F53-8D7C-98C70F764ED3}: DhcpDomain = lan

---\\ Protocole additionnel (20) - 0s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®

---\\ Logiciels installés (36) - 13s
O42 - Logiciel: 1a379834-6135-41e7-9cf7-e79a9f705fbc - (.A.C. company.) [HKCU][64Bits] -- 1a379834-6135-41e7-9cf7-e79a9f705fbc
O42 - Logiciel: ABBYY FineReader 9.0 Sprint - (.ABBYY.) [HKLM][64Bits] -- {F9000000-0018-0000-0000-074957833700} =>.ABBYY
O42 - Logiciel: ABBYY FineReader 9.0 Sprint - (.ABBYY.) [HKLM][64Bits] -- ABBYY FineReader 9.0 Sprint =>.ABBYY
O42 - Logiciel: Adobe Acrobat Reader DC - Français - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1036-7B44-AC0F074E4100} =>.Adobe Systems Incorporated
O42 - Logiciel: Adobe Flash Player 32 ActiveX - (.Adobe.) [HKLM][64Bits] -- Adobe Flash Player ActiveX {0D2CACCD3E9EEC06738410BA31BF6595} =>.Adobe
O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-0804-1033-1959-001824382551} =>.Adobe Systems Incorporated
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM][64Bits] -- {C1BBFD2A-BCDD-45B3-8C0B-66BD434970A8} =>.Apple Inc.
O42 - Logiciel: ASIO4ALL - (.Michael Tippach.) [HKLM][64Bits] -- ASIO4ALL =>.Michael Tippach
O42 - Logiciel: Audacity 2.3.0 - (.Audacity Team.) [HKLM][64Bits] -- Audacity_is1 =>.Audacity Team
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM][64Bits] -- {56DDDFB8-7F79-4480-89D5-25E1F52AB28F} =>.Apple Inc.
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner {02FA994D660DE659EE9037ECB437D766} =>.Piriform
O42 - Logiciel: CDBurnerXP - (.CDBurnerXP.) [HKLM][64Bits] -- {7E265513-8CDA-4631-B696-F40D983F3B07}_is1 =>.CDBurnerXP
O42 - Logiciel: Comptes - (...) [HKLM][64Bits] -- ST6UNST #1
O42 - Logiciel: D-Link DWA-131 - V5.04b03 - (.D-Link.) [HKLM][64Bits] -- {B7C11488-750D-4E48-A9A4-7207A335984D} =>.Macrovision Corporation®
O42 - Logiciel: EasyPDFCombine Internet Explorer Homepage and New Tab - (.Mindspark Interactive Network, Inc..) [HKCU][64Bits] -- EasyPDFCombineTooltab Uninstall Internet Explorer
O42 - Logiciel: eMule - (...) [HKLM][64Bits] -- eMule
O42 - Logiciel: Epson Easy Photo Print 2 - (.SEIKO EPSON CORPORATION.) [HKLM][64Bits] -- {39F58DDB-B2B8-4B86-AF20-4706A80EB30D} =>.Macrovision Corporation®
O42 - Logiciel: Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) - (.SEIKO EPSON CORPORATION.) [HKLM][64Bits] -- {B2D55EB8-32C5-4B43-9006-9E97DECBA178} =>.Macrovision Corporation®
O42 - Logiciel: Epson Event Manager - (.SEIKO EPSON CORPORATION.) [HKLM][64Bits] -- {03B8AA32-F23C-4178-B8E6-09ECD07EAA47} =>.Seiko Epson Corporation
O42 - Logiciel: EPSON Scan - (.Seiko Epson Corporation.) [HKLM][64Bits] -- EPSON Scanner =>.SEIKO EPSON Corporation®
O42 - Logiciel: EPSON SX125 Series Manuel - (...) [HKLM][64Bits] -- EPSON SX125 Series Manual =>.SEIKO EPSON Corporation®
O42 - Logiciel: EPSON SX125 Series Printer Uninstall - (.SEIKO EPSON Corporation.) [HKLM][64Bits] -- EPSON SX125 Series =>.SEIKO EPSON Corporation®
O42 - Logiciel: HD Video Player - (.AmazingSofts.) [HKCU][64Bits] -- {EF084A47-B742-44AA-A119-B2BAA23B6D4A} NGMediaPlayer_is1
O42 - Logiciel: ILG_BROWSERINC31 version 3.1 - (.ILG CRP ver 31 LLC.) [HKLM][64Bits] -- ILG_BROWSERINC31_is1
O42 - Logiciel: IncrediMail - (.IncrediMail.) [HKLM][64Bits] -- {2CF22C94-1369-4C04-9A5F-A4BC6D91B508} =>.IncrediMail
O42 - Logiciel: IncrediMail 2.0 - (.IncrediMail Ltd..) [HKLM][64Bits] -- IncrediMail =>.Perion Network Ltd.®
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM][64Bits] -- HDMI =>.Intel Corporation®
O42 - Logiciel: IZArc 4.3 - (.Ivan Zahariev.) [HKLM][64Bits] -- {97C82B44-D408-4F14-9252-47FC1636D23E}_is1 =>.Ivan Zahariev
O42 - Logiciel: MediaCoder 0.8.55.5938 - (.Mediatronic.) [HKLM][64Bits] -- MediaCoder =>.Mediatronic
O42 - Logiciel: Microsoft Edge - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Edge {330000018A073733CF2048893C00000000018A} =>.Microsoft Corporation
O42 - Logiciel: Microsoft Edge Update - (...) [HKLM][64Bits] -- Microsoft Edge Update
O42 - Logiciel: OpenOffice 4.1.5 - (.Apache Software Foundation.) [HKLM][64Bits] -- {155C4F2E-7381-4B80-B258-FD0600C9C46B} =>.Apache Software Foundation
O42 - Logiciel: PeerBlock 1.2 (r693) - (.PeerBlock, LLC.) [HKLM][64Bits] -- {015C5B35-B678-451C-9AEE-821E8D69621C}_is1 =>.PeerBlock, LLC
O42 - Logiciel: Shareaza 2.7.10.2 - (.Shareaza Development Team.) [HKLM][64Bits] -- Shareaza_is1
O42 - Logiciel: Shareaza Turbo Accelerator - (.DownloadBoosters LLC.) [HKLM][64Bits] -- Shareaza Turbo Accelerator
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN

---\\ HKCU & HKLM Software Keys (115) - 13s
HKLM\SOFTWARE\Wow6432Node\ABBYY
HKLM\SOFTWARE\Wow6432Node\Adobe
HKLM\SOFTWARE\Wow6432Node\ANI
HKLM\SOFTWARE\Wow6432Node\Apple Inc.
HKLM\SOFTWARE\Wow6432Node\ASIO
HKLM\SOFTWARE\Wow6432Node\ASIO4ALL
HKLM\SOFTWARE\Wow6432Node\Canneverbe Limited
HKLM\SOFTWARE\Wow6432Node\D-Link
HKLM\SOFTWARE\Wow6432Node\DigitalWave
HKLM\SOFTWARE\Wow6432Node\EASEUS
HKLM\SOFTWARE\Wow6432Node\EaseUS Todo Backup
HKLM\SOFTWARE\Wow6432Node\EPSON
HKLM\SOFTWARE\Wow6432Node\Flvto Youtube Downloader
HKLM\SOFTWARE\Wow6432Node\Freemake
HKLM\SOFTWARE\Wow6432Node\Google
HKLM\SOFTWARE\Wow6432Node\GuidGuid13
HKLM\SOFTWARE\Wow6432Node\HaaliMkx
HKLM\SOFTWARE\Wow6432Node\Image-Line
HKLM\SOFTWARE\Wow6432Node\IncrediMail
HKLM\SOFTWARE\Wow6432Node\Intel
HKLM\SOFTWARE\Wow6432Node\JavaSoft
HKLM\SOFTWARE\Wow6432Node\JreMetrics
HKLM\SOFTWARE\Wow6432Node\Licenses
HKLM\SOFTWARE\Wow6432Node\Machiner
HKLM\SOFTWARE\Wow6432Node\Macromedia
HKLM\SOFTWARE\Wow6432Node\MediaCoder
HKLM\SOFTWARE\Wow6432Node\Mozilla
HKLM\SOFTWARE\Wow6432Node\mozilla.org
HKLM\SOFTWARE\Wow6432Node\MozillaPlugins
HKLM\SOFTWARE\Wow6432Node\Nero
HKLM\SOFTWARE\Wow6432Node\ODBC
HKLM\SOFTWARE\Wow6432Node\OpenOffice
HKLM\SOFTWARE\Wow6432Node\Piriform
HKLM\SOFTWARE\Wow6432Node\Propellerhead Software
HKLM\SOFTWARE\Wow6432Node\Proxy
HKLM\SOFTWARE\Wow6432Node\SEIKO EPSON CORPORATION
HKLM\SOFTWARE\Wow6432Node\Shareaza
HKLM\SOFTWARE\Wow6432Node\Shareaza Turbo Accelerator
HKLM\SOFTWARE\Wow6432Node\Softgogo
HKLM\SOFTWARE\Wow6432Node\Sony Corporation
HKLM\SOFTWARE\Wow6432Node\TrustedLogos
HKLM\SOFTWARE\Wow6432Node\WafCX
HKLM\SOFTWARE\Wow6432Node\Windows
HKLM\SOFTWARE\Wow6432Node\Wise Solutions
HKLM\SOFTWARE\Wow6432Node\Wondershare
HKLM\SOFTWARE\Wow6432Node\Wow6432Node
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications
HKCU\SOFTWARE\ABBYY
HKCU\SOFTWARE\Adobe
HKCU\SOFTWARE\Aiseesoft Studio
HKCU\SOFTWARE\AppDataLow
HKCU\SOFTWARE\Apple Computer, Inc.
HKCU\SOFTWARE\Apple Inc.
HKCU\SOFTWARE\Arobas Music
HKCU\SOFTWARE\AvastAdSDK
HKCU\SOFTWARE\BitComet
HKCU\SOFTWARE\BitTorrentPersist
HKCU\SOFTWARE\Bookshop
HKCU\SOFTWARE\BraveSoftware
HKCU\SOFTWARE\BugSplat
HKCU\SOFTWARE\Canneverbe Limited
HKCU\SOFTWARE\Chromium
HKCU\SOFTWARE\CocCoc
HKCU\SOFTWARE\Cocoon Software
HKCU\SOFTWARE\Code Sector
HKCU\SOFTWARE\EaseUS
HKCU\SOFTWARE\EasyPDFCombine
HKCU\SOFTWARE\ej-technologies
HKCU\SOFTWARE\eMule
HKCU\SOFTWARE\EPSON
HKCU\SOFTWARE\FlvtoConverter
HKCU\SOFTWARE\FonePaw
HKCU\SOFTWARE\Freemake
HKCU\SOFTWARE\Google
HKCU\SOFTWARE\Haali
HKCU\SOFTWARE\hotger
HKCU\SOFTWARE\IM
HKCU\SOFTWARE\Image-Line
HKCU\SOFTWARE\IncrediMail
HKCU\SOFTWARE\Intel
HKCU\SOFTWARE\Inter VPN
HKCU\SOFTWARE\IZSoftware
HKCU\SOFTWARE\JavaSoft
HKCU\SOFTWARE\LAV
HKCU\SOFTWARE\Magnet
HKCU\SOFTWARE\ManageTrade
HKCU\SOFTWARE\MediaChance
HKCU\SOFTWARE\Movavi
HKCU\SOFTWARE\Mozilla
HKCU\SOFTWARE\MozillaPlugins
HKCU\SOFTWARE\MPC-HC
HKCU\SOFTWARE\Netscape
HKCU\SOFTWARE\Obsidium
HKCU\SOFTWARE\OpenOffice
HKCU\SOFTWARE\OperaRejectTime
HKCU\SOFTWARE\PC SOFT
HKCU\SOFTWARE\Picture
HKCU\SOFTWARE\Piriform
HKCU\SOFTWARE\Privacy Tools NL
HKCU\SOFTWARE\QtProject
HKCU\SOFTWARE\Rtp
HKCU\SOFTWARE\Shareaza
HKCU\SOFTWARE\Shareaza Turbo Accelerator
HKCU\SOFTWARE\SoftVoice
HKCU\SOFTWARE\SSProtect
HKCU\SOFTWARE\Trolltech
HKCU\SOFTWARE\undefined =>.Superfluous.Downloader
HKCU\SOFTWARE\VB and VBA Program Settings
HKCU\SOFTWARE\VirtualDub.org
HKCU\SOFTWARE\Wondershare
HKCU\SOFTWARE\Wow6432Node
HKCU\SOFTWARE\ZebHelpProcess Helper
HKCU\SOFTWARE\Zyrax Software
HKCU\SOFTWARE\AppDataLow\Software
HKCU\SOFTWARE\AppDataLow\Software\MessengerTime

---\\ Contenu des dossiers Programmes (252) - 64s
O43 - CFD: 20/12/2018 - [] D -- C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint =>.ABBYY SOLUTIONS LIMITED®
O43 - CFD: 03/10/2018 - [] D -- C:\Program Files (x86)\Adobe {0EE3F1C8F451CBF21203341A53F23E71}
O43 - CFD: 05/04/2020 - [] D -- C:\Program Files (x86)\aozfilk
O43 - CFD: 11/05/2019 - [] D -- C:\Program Files (x86)\Apple Software Update {0EBC1935D5294A594B4F32707B0A0AB9}
O43 - CFD: 25/11/2018 - [] D -- C:\Program Files (x86)\ASIO4ALL v2
O43 - CFD: 08/12/2018 - [] D -- C:\Program Files (x86)\Audacity
O43 - CFD: 11/05/2019 - [] D -- C:\Program Files (x86)\Bonjour =>.Apple Inc.®
O43 - CFD: 05/04/2020 - [] D -- C:\Program Files (x86)\Borot
O43 - CFD: 29/07/2020 - [] D -- C:\Program Files (x86)\CNis
O43 - CFD: 03/05/2020 - [] D -- C:\Program Files (x86)\Common Files
O43 - CFD: 29/09/2018 - [] D -- C:\Program Files (x86)\D-Link =>.Microsoft Corporation®
O43 - CFD: 23/09/2019 - [] D -- C:\Program Files (x86)\EaseUS {73CCB86B36F6C0236FEA22D15300AD19}
O43 - CFD: 06/04/2020 - [] D -- C:\Program Files (x86)\Emoticons Mail
O43 - CFD: 29/09/2018 - [] D -- C:\Program Files (x86)\eMule
O43 - CFD: 29/09/2018 - [] D -- C:\Program Files (x86)\epson =>.SEIKO EPSON Corporation®
O43 - CFD: 29/09/2018 - [] D -- C:\Program Files (x86)\Epson Software =>.SEIKO EPSON Corporation®
O43 - CFD: 13/09/2019 - [] D -- C:\Program Files (x86)\FormatFactory
O43 - CFD: 21/04/2020 - [] D -- C:\Program Files (x86)\Free YouTube Downloader Converter
O43 - CFD: 21/04/2020 - [] D -- C:\Program Files (x86)\FreeCodecPack
O43 - CFD: 03/05/2020 - [] D -- C:\Program Files (x86)\Freemake {3A64E7CC688E12D035464BE3}
O43 - CFD: 31/07/2020 - [] D -- C:\Program Files (x86)\Google
O43 - CFD: 01/08/2020 - [] D -- C:\Program Files (x86)\ILG_BROWSERINC31
O43 - CFD: 25/11/2018 - [] D -- C:\Program Files (x86)\Image-Line {4E148D90AF6C2CA02C42A8DE75D1606E}
O43 - CFD: 29/09/2018 - [] D -- C:\Program Files (x86)\IncrediMail =>.Perion Network Ltd.®
O43 - CFD: 29/09/2018 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.Macrovision Corporation®
O43 - CFD: 16/01/2020 - [] D -- C:\Program Files (x86)\Internet Explorer
O43 - CFD: 06/04/2020 - [] D -- C:\Program Files (x86)\InterVpn {274396EE3346CEA0ED5278A0}
O43 - CFD: 29/09/2018 - [] D -- C:\Program Files (x86)\IZArc
O43 - CFD: 05/04/2020 - [] D -- C:\Program Files (x86)\krzysztof
O43 - CFD: 05/04/2020 - [] HD -- C:\Program Files (x86)\Lameness
O43 - CFD: 17/03/2020 - [] D -- C:\Program Files (x86)\LimeWire
O43 - CFD: 06/04/2020 - [] D -- C:\Program Files (x86)\MachinerData
O43 - CFD: 15/09/2019 - [] D -- C:\Program Files (x86)\MediaCoder
O43 - CFD: 01/04/2020 - [0] D -- C:\Program Files (x86)\Megaupload Downloader
O43 - CFD: 31/07/2020 - [] D -- C:\Program Files (x86)\Microsoft {330000018A073733CF2048893C00000000018A}
O43 - CFD: 19/05/2018 - [] D -- C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 12/07/2020 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\MSBuild
O43 - CFD: 06/04/2020 - [0] D -- C:\Program Files (x86)\Multitimer
O43 - CFD: 27/10/2018 - [] D -- C:\Program Files (x86)\OpenOffice 4
O43 - CFD: 05/04/2020 - [] D -- C:\Program Files (x86)\ProxyGate {1121E1CE57747D3AA0E2D8A055EE1FA5696D}
O43 - CFD: 05/04/2020 - [] D -- C:\Program Files (x86)\Rebekah
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 05/04/2020 - [] HD -- C:\Program Files (x86)\scissors
O43 - CFD: 18/04/2020 - [] D -- C:\Program Files (x86)\Shareaza
O43 - CFD: 21/04/2020 - [] D -- C:\Program Files (x86)\Shareaza Turbo Accelerator
O43 - CFD: 05/04/2020 - [] D -- C:\Program Files (x86)\Soused
O43 - CFD: 05/06/2019 - [] D -- C:\Program Files (x86)\Tenorshare ReiBoot
O43 - CFD: 14/07/2009 - [0] HD -- C:\Program Files (x86)\Uninstall Information
O43 - CFD: 05/04/2020 - [] D -- C:\Program Files (x86)\warfarin
O43 - CFD: 20/05/2018 - [] D -- C:\Program Files (x86)\Windows Defender
O43 - CFD: 20/05/2018 - [] D -- C:\Program Files (x86)\Windows Mail
O43 - CFD: 11/07/2019 - [] D -- C:\Program Files (x86)\Windows Media Player
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Windows NT
O43 - CFD: 20/05/2018 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation®
O43 - CFD: 21/11/2010 - [] D -- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 20/05/2018 - [] D -- C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 17/12/2018 - [] D -- C:\Program Files (x86)\Wondershare
O43 - CFD: 29/09/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 9.0 Sprint
O43 - CFD: 22/05/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 19/05/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 29/09/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
O43 - CFD: 26/06/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\comptes
O43 - CFD: 29/09/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\D-Link
O43 - CFD: 29/09/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eMule
O43 - CFD: 29/09/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
O43 - CFD: 29/09/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epson Software
O43 - CFD: 21/04/2020 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free YouTube Downloader Converter
O43 - CFD: 29/09/2018 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 25/11/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
O43 - CFD: 29/09/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IncrediMail
O43 - CFD: 29/09/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IZArc
O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 27/10/2018 - [] SD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.5
O43 - CFD: 29/09/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeerBlock
O43 - CFD: 18/04/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shareaza
O43 - CFD: 21/04/2020 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shareaza Turbo Accelerator
O43 - CFD: 14/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 29/09/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
O43 - CFD: 23/09/2019 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
O43 - CFD: 01/08/2020 - [] RHD -- C:\ProgramData\1DF7DC64
O43 - CFD: 01/08/2020 - [] D -- C:\ProgramData\59
O43 - CFD: 29/09/2018 - [] D -- C:\ProgramData\ABBYY
O43 - CFD: 23/11/2018 - [0] D -- C:\ProgramData\Ableton
O43 - CFD: 04/10/2018 - [] D -- C:\ProgramData\Adobe
O43 - CFD: 05/06/2019 - [] D -- C:\ProgramData\Apple
O43 - CFD: 11/05/2019 - [] D -- C:\ProgramData\Apple Computer
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Application Data
O43 - CFD: 01/05/2020 - [] D -- C:\ProgramData\Ashampoo
O43 - CFD: 19/05/2018 - [0] SHD -- C:\ProgramData\Bureau
O43 - CFD: 19/10/2018 - [] D -- C:\ProgramData\Canneverbe Limited
O43 - CFD: 05/04/2020 - [] D -- C:\ProgramData\CloudPrinter
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Desktop
O43 - CFD: 21/04/2020 - [0] D -- C:\ProgramData\DigitalWave.ApplicationUpdater_files
O43 - CFD: 27/04/2020 - [] D -- C:\ProgramData\DivX
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Documents
O43 - CFD: 11/05/2019 - [] D -- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
O43 - CFD: 29/09/2018 - [] D -- C:\ProgramData\eMule
O43 - CFD: 29/09/2018 - [] D -- C:\ProgramData\EPSON
O43 - CFD: 19/05/2018 - [0] SHD -- C:\ProgramData\Favoris
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Favorites
O43 - CFD: 03/05/2020 - [] D -- C:\ProgramData\Freemake
O43 - CFD: 08/12/2018 - [0] D -- C:\ProgramData\Guitar Pro 6
O43 - CFD: 29/09/2018 - [] D -- C:\ProgramData\IM
O43 - CFD: 29/09/2018 - [] D -- C:\ProgramData\IncrediMail
O43 - CFD: 11/12/2018 - [] D -- C:\ProgramData\IsolatedStorage
O43 - CFD: 05/04/2020 - [] D -- C:\ProgramData\Logic Cramble
O43 - CFD: 19/05/2018 - [0] SHD -- C:\ProgramData\Menu Démarrer
O43 - CFD: 20/06/2020 - [] SD -- C:\ProgramData\Microsoft
O43 - CFD: 19/05/2018 - [0] SHD -- C:\ProgramData\Modèles
O43 - CFD: 03/06/2020 - [] D -- C:\ProgramData\movavi
O43 - CFD: 01/03/2020 - [] D -- C:\ProgramData\Mozilla
O43 - CFD: 09/05/2020 - [] D -- C:\ProgramData\NCH Software
O43 - CFD: 01/05/2020 - [] D -- C:\ProgramData\Nero
O43 - CFD: 05/04/2020 - [0] D -- C:\ProgramData\Newf
O43 - CFD: 10/05/2020 - [0] D -- C:\ProgramData\OEM Links
O43 - CFD: 01/05/2020 - [] D -- C:\ProgramData\Package Cache
O43 - CFD: 15/01/2019 - [] D -- C:\ProgramData\QUICKMEDIACONVERTER
O43 - CFD: 19/11/2018 - [] D -- C:\ProgramData\SecuritySuite
O43 - CFD: 05/04/2020 - [] D -- C:\ProgramData\Snorlers
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Start Menu
O43 - CFD: 17/03/2020 - [] D -- C:\ProgramData\Sun
O43 - CFD: 21/02/2019 - [] D -- C:\ProgramData\SystemAcCrux
O43 - CFD: 22/09/2019 - [0] AD -- C:\ProgramData\TEMP
O43 - CFD: 14/07/2009 - [0] SHD -- C:\ProgramData\Templates
O43 - CFD: 29/09/2018 - [] D -- C:\ProgramData\UDL
O43 - CFD: 23/09/2019 - [] D -- C:\ProgramData\Wondershare
O43 - CFD: 11/12/2018 - [] D -- C:\ProgramData\wsr
O43 - CFD: 29/09/2018 - [] D -- C:\Program Files (x86)\Common Files\ABBYY
O43 - CFD: 17/03/2020 - [] D -- C:\Program Files (x86)\Common Files\Adobe
O43 - CFD: 05/06/2019 - [] D -- C:\Program Files (x86)\Common Files\Apple
O43 - CFD: 29/09/2018 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared
O43 - CFD: 23/11/2018 - [] D -- C:\Program Files (x86)\Common Files\Propellerhead Software
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Common Files\Services
O43 - CFD: 14/07/2009 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines
O43 - CFD: 20/05/2018 - [] D -- C:\Program Files (x86)\Common Files\System
O43 - CFD: 06/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\0awe21ivolo
O43 - CFD: 06/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\0fzbldf3scm
O43 - CFD: 05/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\13qmjogagew
O43 - CFD: 29/07/2020 - [] D -- C:\Users\Admin\AppData\Roaming\261e21d9bddc
O43 - CFD: 05/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\2b5p2oqxn2i
O43 - CFD: 06/04/2020 - [0] D -- C:\Users\Admin\AppData\Roaming\3g4vg3z3ijs
O43 - CFD: 06/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\3qgy0muscgl
O43 - CFD: 29/07/2020 - [] D -- C:\Users\Admin\AppData\Roaming\4po5p45s2xv
O43 - CFD: 23/11/2018 - [] D -- C:\Users\Admin\AppData\Roaming\Ableton
O43 - CFD: 03/10/2018 - [] D -- C:\Users\Admin\AppData\Roaming\Adobe
O43 - CFD: 11/05/2019 - [] D -- C:\Users\Admin\AppData\Roaming\Apple Computer
O43 - CFD: 01/05/2020 - [] D -- C:\Users\Admin\AppData\Roaming\Ashampoo
O43 - CFD: 02/05/2020 - [] D -- C:\Users\Admin\AppData\Roaming\audacity
O43 - CFD: 01/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\BitComet
O43 - CFD: 11/03/2020 - [] D -- C:\Users\Admin\AppData\Roaming\Burnaware
O43 - CFD: 19/10/2018 - [] D -- C:\Users\Admin\AppData\Roaming\Canneverbe Limited
O43 - CFD: 15/01/2019 - [] D -- C:\Users\Admin\AppData\Roaming\Cocoon Software
O43 - CFD: 21/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\DVDVideoSoft
O43 - CFD: 05/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\eanp5doa43n
O43 - CFD: 29/09/2018 - [] D -- C:\Users\Admin\AppData\Roaming\Epson
O43 - CFD: 21/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\Eusing
O43 - CFD: 04/05/2020 - [] D -- C:\Users\Admin\AppData\Roaming\FlvtoConverter
O43 - CFD: 08/12/2018 - [0] D -- C:\Users\Admin\AppData\Roaming\Guitar Pro 6
O43 - CFD: 05/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\h33nphfukig
O43 - CFD: 03/10/2018 - [] D -- C:\Users\Admin\AppData\Roaming\HD Video Player
O43 - CFD: 01/08/2020 - [] D -- C:\Users\Admin\AppData\Roaming\hj00t500qut
O43 - CFD: 31/07/2020 - [] D -- C:\Users\Admin\AppData\Roaming\hpikh1wemgk
O43 - CFD: 06/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\hpskqnzmkpd
O43 - CFD: 06/04/2020 - [0] D -- C:\Users\Admin\AppData\Roaming\hvgrgqzppme
O43 - CFD: 19/05/2018 - [] D -- C:\Users\Admin\AppData\Roaming\Identities
O43 - CFD: 31/07/2020 - [] D -- C:\Users\Admin\AppData\Roaming\ifdktu15ujb
O43 - CFD: 29/09/2018 - [] D -- C:\Users\Admin\AppData\Roaming\InstallShield
O43 - CFD: 06/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\ioe2xuhc1ue
O43 - CFD: 11/12/2018 - [] D -- C:\Users\Admin\AppData\Roaming\IsolatedStorage
O43 - CFD: 29/09/2018 - [] D -- C:\Users\Admin\AppData\Roaming\Macromedia
O43 - CFD: 06/04/2020 - [0] D -- C:\Users\Admin\AppData\Roaming\MagicSearch
O43 - CFD: 12/04/2011 - [0] D -- C:\Users\Admin\AppData\Roaming\Media Center Programs
O43 - CFD: 15/09/2019 - [] D -- C:\Users\Admin\AppData\Roaming\Mediatronic
O43 - CFD: 01/04/2020 - [] SD -- C:\Users\Admin\AppData\Roaming\Microsoft
O43 - CFD: 01/03/2020 - [] D -- C:\Users\Admin\AppData\Roaming\Mozilla
O43 - CFD: 06/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\mvto0rqhhaz
O43 - CFD: 13/08/2019 - [] D -- C:\Users\Admin\AppData\Roaming\NCH Software
O43 - CFD: 01/05/2020 - [] D -- C:\Users\Admin\AppData\Roaming\Nero
O43 - CFD: 20/12/2018 - [] HD -- C:\Users\Admin\AppData\Roaming\Obsidium
O43 - CFD: 27/10/2018 - [] D -- C:\Users\Admin\AppData\Roaming\OpenOffice
O43 - CFD: 06/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\otmwmcrkjjr
O43 - CFD: 01/08/2020 - [] D -- C:\Users\Admin\AppData\Roaming\ovlbmp52ez1
O43 - CFD: 06/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\pal01sbl3ae
O43 - CFD: 05/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\Python
O43 - CFD: 21/02/2019 - [] D -- C:\Users\Admin\AppData\Roaming\Python-Eggs
O43 - CFD: 31/07/2020 - [] D -- C:\Users\Admin\AppData\Roaming\qmwauwtforl
O43 - CFD: 06/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\s4alg0xl2q0
O43 - CFD: 05/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\sanv5cfhfxz
O43 - CFD: 02/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\Shareaza
O43 - CFD: 01/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\Shareaza Turbo Accelerator
O43 - CFD: 29/07/2020 - [] D -- C:\Users\Admin\AppData\Roaming\t14d5f2n3ny
O43 - CFD: 29/05/2019 - [] D -- C:\Users\Admin\AppData\Roaming\TeraCopy
O43 - CFD: 05/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\TimerUtc
O43 - CFD: 05/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\tzza2gb0qjs
O43 - CFD: 31/07/2020 - [] D -- C:\Users\Admin\AppData\Roaming\vbg4swbczdr
O43 - CFD: 28/07/2020 - [] D -- C:\Users\Admin\AppData\Roaming\vlc
O43 - CFD: 31/07/2020 - [] D -- C:\Users\Admin\AppData\Roaming\wle3eswu5dm
O43 - CFD: 11/12/2018 - [] D -- C:\Users\Admin\AppData\Roaming\Wondershare
O43 - CFD: 29/07/2020 - [] D -- C:\Users\Admin\AppData\Roaming\yas4wlabe1b
O43 - CFD: 09/06/2020 - [0] D -- C:\Users\Admin\AppData\Roaming\YoutubeDownloader_upd
O43 - CFD: 06/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\z4j3osm2ypb
O43 - CFD: 01/08/2020 - [] D -- C:\Users\Admin\AppData\Roaming\ZHP
O43 - CFD: 01/04/2020 - [] D -- C:\Users\Admin\AppData\Roaming\{4916c8ce-b9e7-4e25-9a23-25493e41e04c}
O43 - CFD: 29/09/2018 - [] D -- C:\Users\Admin\AppData\Local\ABBYY
O43 - CFD: 17/10/2019 - [] D -- C:\Users\Admin\AppData\Local\Adobe
O43 - CFD: 15/09/2019 - [] D -- C:\Users\Admin\AppData\Local\Aiseesoft Studio
O43 - CFD: 11/05/2019 - [] D -- C:\Users\Admin\AppData\Local\Apple
O43 - CFD: 11/05/2019 - [] D -- C:\Users\Admin\AppData\Local\Apple Computer
O43 - CFD: 19/05/2018 - [0] SHD -- C:\Users\Admin\AppData\Local\Application Data
O43 - CFD: 01/05/2020 - [] D -- C:\Users\Admin\AppData\Local\ashampoo
O43 - CFD: 08/12/2018 - [] D -- C:\Users\Admin\AppData\Local\Audacity
O43 - CFD: 01/04/2020 - [] D -- C:\Users\Admin\AppData\Local\BitTorrentHelper
O43 - CFD: 11/05/2019 - [] D -- C:\Users\Admin\AppData\Local\BraveSoftware
O43 - CFD: 03/10/2018 - [] D -- C:\Users\Admin\AppData\Local\CEF
O43 - CFD: 02/09/2019 - [] D -- C:\Users\Admin\AppData\Local\converter
O43 - CFD: 02/09/2019 - [] D -- C:\Users\Admin\AppData\Local\ConverterAgent
O43 - CFD: 02/09/2019 - [] D -- C:\Users\Admin\AppData\Local\CrashRpt =>.Superfluous.CrashReports
O43 - CFD: 26/07/2020 - [0] D -- C:\Users\Admin\AppData\Local\Diagnostics
O43 - CFD: 28/11/2018 - [] D -- C:\Users\Admin\AppData\Local\EasyPDFCombineTooltab
O43 - CFD: 29/09/2018 - [] D -- C:\Users\Admin\AppData\Local\eMule
O43 - CFD: 02/03/2019 - [] D -- C:\Users\Admin\AppData\Local\Flvto Youtube Downloader
O43 - CFD: 03/10/2018 - [] D -- C:\Users\Admin\AppData\Local\FlvtoYoutubeDownloader
O43 - CFD: 11/12/2018 - [] D -- C:\Users\Admin\AppData\Local\FonePaw
O43 - CFD: 10/01/2019 - [] D -- C:\Users\Admin\AppData\Local\FreemakeVideoConverter
O43 - CFD: 13/04/2020 - [] D -- C:\Users\Admin\AppData\Local\Google
O43 - CFD: 19/05/2018 - [0] SHD -- C:\Users\Admin\AppData\Local\Historique
O43 - CFD: 15/08/2019 - [] D -- C:\Users\Admin\AppData\Local\IM
O43 - CFD: 29/07/2020 - [] D -- C:\Users\Admin\AppData\Local\inetinfoservice
O43 - CFD: 01/04/2020 - [] D -- C:\Users\Admin\AppData\Local\JDownloader v2.0
O43 - CFD: 08/03/2019 - [] D -- C:\Users\Admin\AppData\Local\MessengerTime
O43 - CFD: 31/07/2020 - [] D -- C:\Users\Admin\AppData\Local\Microsoft
O43 - CFD: 02/09/2019 - [] D -- C:\Users\Admin\AppData\Local\Movavi
O43 - CFD: 01/03/2020 - [] D -- C:\Users\Admin\AppData\Local\Mozilla
O43 - CFD: 01/04/2020 - [] D -- C:\Users\Admin\AppData\Local\Programming_by_marco6,_gr
O43 - CFD: 29/09/2018 - [] D -- C:\Users\Admin\AppData\Local\Programs
O43 - CFD: 01/04/2020 - [] D -- C:\Users\Admin\AppData\Local\Shareaza
O43 - CFD: 11/12/2018 - [] D -- C:\Users\Admin\AppData\Local\Solvusoft_Corporation
O43 - CFD: 01/08/2020 - [] D -- C:\Users\Admin\AppData\Local\Temp
O43 - CFD: 19/05/2018 - [0] SHD -- C:\Users\Admin\AppData\Local\Temporary Internet Files
O43 - CFD: 19/05/2018 - [0] D -- C:\Users\Admin\AppData\Local\VirtualStore
O43 - CFD: 15/01/2019 - [] D -- C:\Users\Admin\AppData\Local\WDSetup
O43 - CFD: 14/07/2009 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 13/06/2019 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 25/11/2018 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
O43 - CFD: 01/03/2019 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flvto Youtube Downloader
O43 - CFD: 03/10/2018 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD Video Player
O43 - CFD: 21/08/2019 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
O43 - CFD: 14/07/2009 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 15/09/2019 - [] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaCoder
O43 - CFD: 01/04/2020 - [0] D -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Megaupload Downloader
O43 - CFD: 26/06/2020 - [] RD -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

---\\ ShellIconOverlayIdentifiers (SIOI) (2) - 0s
O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - DLL d’extension d’environnement de stockage.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - Extensions de l’interpréteur de commandes p.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation

---\\ Enumération des clés StartupReg (30) - 3s
O53 - SMSR:HKLM\...\startupreg\1GWV4N934RGKDOM [Key] . (.H - HD.) -- C:\Program Files\Y7AHWLK5AK\Y7AHWLK5A.exe
O53 - SMSR:HKLM\...\startupreg\2309132 [Key] . (. - Beta Setup.) -- C:\Users\Admin\AppData\Roaming\z4j3osm2ypb\r2tzrjutz5b.exe
O53 - SMSR:HKLM\...\startupreg\2455069 [Key] . (. - Beta Setup.) -- C:\Users\Admin\AppData\Roaming\s4alg0xl2q0\pmitytsxdou.exe
O53 - SMSR:HKLM\...\startupreg\3306985 [Key] . (. - COnfi Setup.) -- C:\Users\Admin\AppData\Roaming\13qmjogagew\zq3ybd3pfim.exe
O53 - SMSR:HKLM\...\startupreg\3485896 [Key] . (. - Beta Setup.) -- C:\Users\Admin\AppData\Roaming\0fzbldf3scm\is2vp1rfelq.exe
O53 - SMSR:HKLM\...\startupreg\398581 [Key] . (. - Beta Setup.) -- C:\Users\Admin\AppData\Roaming\hpskqnzmkpd\mwrz0x4gy1p.exe
O53 - SMSR:HKLM\...\startupreg\3ltobraaqb0 [Key] . (.Copyright - CaseClose.) -- C:\Program Files (x86)\aozfilk\718619703.exe
O53 - SMSR:HKLM\...\startupreg\4742875 [Key] . (. - Beta Setup.) -- C:\Users\Admin\AppData\Roaming\0awe21ivolo\kfq4xubhbji.exe
O53 - SMSR:HKLM\...\startupreg\4859346 [Key] . (. - Beta Setup.) -- C:\Users\Admin\AppData\Roaming\otmwmcrkjjr\2xxs3ms1kfs.exe
O53 - SMSR:HKLM\...\startupreg\5565551 [Key] . (. - COnfi Setup.) -- C:\Users\Admin\AppData\Roaming\h33nphfukig\p2srn5nevbu.exe
O53 - SMSR:HKLM\...\startupreg\5797245 [Key] . (. - Beta Setup.) -- C:\Users\Admin\AppData\Roaming\mvto0rqhhaz\1nnvzyeslq5.exe
O53 - SMSR:HKLM\...\startupreg\58K1T5JL9JGYPLX [Key] . (.H - HD.) -- C:\Program Files\FH2E3HYHXP\FH2E3HYHX.exe
O53 - SMSR:HKLM\...\startupreg\6342812 [Key] . (...) -- C:\Users\Admin\AppData\Local\Temp\is-EQNHK.tmp\Driiazji.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\656694 [Key] . (. - COnfi Setup.) -- C:\Users\Admin\AppData\Roaming\sanv5cfhfxz\hsc1xgvhjdy.exe
O53 - SMSR:HKLM\...\startupreg\6657665 [Key] . (. - Beta Setup.) -- C:\Users\Admin\AppData\Roaming\3qgy0muscgl\qk3503v1aoh.exe
O53 - SMSR:HKLM\...\startupreg\7997985 [Key] . (. - COnfi Setup.) -- C:\Users\Admin\AppData\Roaming\tzza2gb0qjs\rlevpqoss3x.exe
O53 - SMSR:HKLM\...\startupreg\8069190 [Key] . (. - COnfi Setup.) -- C:\Users\Admin\AppData\Roaming\2b5p2oqxn2i\h4uu4jrwh5s.exe
O53 - SMSR:HKLM\...\startupreg\8172165 [Key] . (. - Beta Setup.) -- C:\Users\Admin\AppData\Roaming\ioe2xuhc1ue\ivwkiiems2y.exe
O53 - SMSR:HKLM\...\startupreg\8527398 [Key] . (. - Beta Setup.) -- C:\Users\Admin\AppData\Roaming\pal01sbl3ae\g0pgnrbv5tb.exe
O53 - SMSR:HKLM\...\startupreg\9191097 [Key] . (. - COnfi Setup.) -- C:\Users\Admin\AppData\Roaming\eanp5doa43n\q0amolswdul.exe
O53 - SMSR:HKLM\...\startupreg\9375KTFCCLFONMS [Key] . (.H - HD.) -- C:\Program Files\2JVT4TVD11\Y0W9KV3ZU.exe
O53 - SMSR:HKLM\...\startupreg\aptitudes [Key] . (...) -- C:\Program Files (x86)\scissors\aptitudes.exe
O53 - SMSR:HKLM\...\startupreg\Assen [Key] . (...) -- C:\Program Files (x86)\Soused\Crocodile.exe
O53 - SMSR:HKLM\...\startupreg\CCleaner Smart Cleaning [Key] . (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe
O53 - SMSR:HKLM\...\startupreg\Climb [Key] . (...) -- C:\Program Files (x86)\Soused\Crocodile.exe
O53 - SMSR:HKLM\...\startupreg\EEventManager [Key] . (.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe =>.Seiko Epson Corporation
O53 - SMSR:HKLM\...\startupreg\EPSON SX125 Series [Key] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\System32\spool\drivers\x64\3\E_IATIGGE.EXE =>.Seiko Epson Corporation
O53 - SMSR:HKLM\...\startupreg\Flvto Youtube Downloader [Key] . (.Hotger © 2019 - FlvtoYoutubeDownloader.Redesign.) -- C:\Users\Admin\AppData\Local\Flvto Youtube Downloader\FlvtoYoutubeDownloader.Redesign.exe
O53 - SMSR:HKLM\...\startupreg\FP7723DBT3UWNRQ [Key] . (.H - HD.) -- C:\Program Files\AXOG7NRJV1\AXOG7NRJV.exe
O53 - SMSR:HKLM\...\startupreg\Herne [Key] . (...) -- C:\Program Files (x86)\warfarin\Bunkhouse.exe

---\\ Liste des pilotes du système (55) - 11s
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [491088] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [339536] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\drivers\adpu320.sys [182864] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [15440] =>.Microsoft Windows®
O58 - SDL:2015/09/21 12:15:00 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [107904] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [194128] =>.Microsoft Windows®
O58 - SDL:2015/09/21 12:15:00 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [27008] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [87632] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [97856] =>.Microsoft Windows®
O58 - SDL:2005/03/29 01:30:38 A . (. - ATK0110 ACPI Utility.) -- C:\Windows\System32\drivers\ASACPI.sys [8192]
O58 - SDL:2009/06/10 22:34:23 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60a.sys [270848] =>.Broadcom Corporation
O58 - SDL:2009/06/10 22:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [18432] =>.Brother Industries, Ltd.
O58 - SDL:2009/06/10 22:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [8704] =>.Brother Industries, Ltd.
O58 - SDL:2009/07/14 03:19:07 A . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [286720] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [47104] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [14976] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 22:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [14720] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 22:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [468480] =>.Broadcom Corporation
O58 - SDL:2009/07/14 03:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [17488] =>.Microsoft Windows®
O58 - SDL:2016/11/11 01:02:36 A . (.Realtek Semiconductor Corporation - Realtek WLAN USB NDIS Driver 48186.) -- C:\Windows\System32\drivers\DSoftAPrtwlanu.sys [5608960] {0320BE3EB866526927F999B97B04346E} =>.Realtek Semiconductor Corporation
O58 - SDL:2009/07/14 03:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [530496] =>.Microsoft Windows®
O58 - SDL:2018/12/25 17:26:52 A . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Backup Driver.) -- C:\Windows\System32\drivers\eubakup.sys [74120] {73CCB86B36F6C0236FEA22D15300AD19} =>.CHENGDU YIWO Tech Development Co., Ltd
O58 - SDL:2018/12/25 17:26:52 A . (...) -- C:\Windows\System32\drivers\EUBKMON.sys [54152] {73CCB86B36F6C0236FEA22D15300AD19}
O58 - SDL:2018/12/25 17:26:54 A . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Access Driver.) -- C:\Windows\System32\drivers\eudskacs.sys [23432] {73CCB86B36F6C0236FEA22D15300AD19} =>.CHENGDU YIWO Tech Development Co., Ltd
O58 - SDL:2018/12/25 17:26:54 A . (.CHENGDU YIWO Tech Development Co., Ltd - Disk Backup Image Preview Driver.) -- C:\Windows\System32\drivers\EuFdDisk.sys [342408] {73CCB86B36F6C0236FEA22D15300AD19} =>.CHENGDU YIWO Tech Development Co., Ltd
O58 - SDL:2009/06/10 22:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3286016] =>.Broadcom Corporation
O58 - SDL:2012/10/03 16:14:56 A . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\System32\drivers\GEARAspiWDM.sys [33240] =>.GEAR Software Inc.®
O58 - SDL:2009/06/10 22:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [31232] =>.Hauppauge Computer Works, Inc.
O58 - SDL:2010/11/21 05:23:47 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [78720] =>.Microsoft Windows®
O58 - SDL:2015/09/21 12:15:00 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [410496] =>.Microsoft Windows®
O58 - SDL:2009/09/23 19:23:02 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd64.sys [6180832] =>.Intel Corporation
O58 - SDL:2009/07/14 03:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [44112] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [114752] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [106560] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [65600] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [115776] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [35392] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [284736] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [51264] =>.Microsoft Windows®
O58 - SDL:2015/09/21 12:15:00 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [148352] =>.Microsoft Windows®
O58 - SDL:2015/09/21 12:15:00 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [166272] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1524816] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [128592] =>.Microsoft Windows®
O58 - SDL:2011/06/10 06:34:52 A . (.Realtek - Realtek 8136/8168/8169 NDIS 6.20 64-bit Dri.) -- C:\Windows\System32\drivers\Rt64win7.sys [539240] =>.Realtek Semiconductor Corp®
O58 - SDL:2009/06/10 22:35:48 A . (.Realtek - Realtek 8180/8185 Wireless Device.) -- C:\Windows\System32\drivers\RTL85n64.sys [378368] =>.Realtek
O58 - SDL:2009/06/10 22:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] =>.Macrovision Corporation, Macrovision Europe Limited,
O58 - SDL:2009/07/14 03:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [43584] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [80464] =>.Microsoft Windows®
O58 - SDL:2019/07/09 02:29:44 A . (.Samsung Electronics Co., Ltd. - SAMSUNG USB Composite Device Driver.) -- C:\Windows\System32\drivers\ssudbus.sys [135520] {75B5499C96D676A5FAE2656B351E1FD6} =>.Samsung Electronics Co., Ltd.
O58 - SDL:2019/07/09 02:29:48 A . (.Samsung Electronics Co., Ltd. - SAMSUNG Android Modem Device Driver.) -- C:\Windows\System32\drivers\ssudmdm.sys [166752] {75B5499C96D676A5FAE2656B351E1FD6} =>.Samsung Electronics Co., Ltd.
O58 - SDL:2009/07/14 03:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [24656] =>.Microsoft Windows®
O58 - SDL:2016/08/16 04:18:34 A . (.MBB - USB Modem/Serial Device Driver.) -- C:\Windows\System32\drivers\usb2ser.sys [159936] {7FE63AB8AB9D36964BC29EAD7641180A} =>.MBB
O58 - SDL:2009/07/14 03:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [17488] =>.Microsoft Windows®
O58 - SDL:2009/07/14 03:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [161872] =>.Microsoft Windows®
O58 - SDL:2020/07/29 21:20:48 A . (...) -- C:\Windows\System32\drivers\WinmonProcessMonitor.sys [36096]

---\\ Derniers fichiers modifiés ou crées (Utilisateur) (14) - 44s
O61 - LFC: 2020/07/26 10:43:05 A . (.Piriform Software Ltd.) -- C:\Users\Admin\Downloads\ccsetup569.exe [28064096] {02FA994D660DE659EE9037ECB437D766}
O61 - LFC: 2020/07/29 21:57:53 A . (..) -- C:\Users\Admin\AppData\Roaming\yas4wlabe1b\dwiukvplxao.exe [714887]
O61 - LFC: 2020/07/31 14:05:17 A . (..) -- C:\Users\Admin\AppData\Roaming\wle3eswu5dm\xa14d0czhqo.exe [537056]
O61 - LFC: 2020/07/31 13:25:13 A . (..) -- C:\Users\Admin\AppData\Roaming\vbg4swbczdr\3bto2yc3zvr.exe [537056]
O61 - LFC: 2020/07/29 21:17:54 A . (..) -- C:\Users\Admin\AppData\Roaming\t14d5f2n3ny\l3dcmjxj0wg.exe [16363]
O61 - LFC: 2020/07/31 13:45:13 A . (..) -- C:\Users\Admin\AppData\Roaming\qmwauwtforl\rzj4db15zcg.exe [537056]
O61 - LFC: 2020/08/01 07:42:20 A . (..) -- C:\Users\Admin\AppData\Roaming\ovlbmp52ez1\cuvdvf42aos.exe [1568351]
O61 - LFC: 2020/07/31 13:18:28 A . (..) -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\OdingEU1.exe [21504]
O61 - LFC: 2020/07/31 13:18:12 A . (..) -- C:\Users\Admin\AppData\Roaming\ifdktu15ujb\r1mr40xettg.exe [537056]
O61 - LFC: 2020/07/31 23:11:34 A . (..) -- C:\Users\Admin\AppData\Roaming\hpikh1wemgk\huwakxwn2x0.exe [381479]
O61 - LFC: 2020/08/01 07:22:16 A . (..) -- C:\Users\Admin\AppData\Roaming\hj00t500qut\eqwsujztnrf.exe [1568351]
O61 - LFC: 2020/07/29 21:37:58 A . (..) -- C:\Users\Admin\AppData\Roaming\4po5p45s2xv\elgvl5eyrsu.exe [714887]
O61 - LFC: 2020/07/29 21:39:44 A . (.Copyright © 2020.) -- C:\Users\Admin\AppData\Roaming\261e21d9bddc\261e21d9bddc.exe [549376]
O61 - LFC: 2020/07/31 13:41:53 A . (..) -- C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\Nigori.bin [733]

---\\ Associations Shell Spawning (10) - 1s
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe {33000002CF6D2CC57CAA65A6D80000000002CF} =>.Microsoft Corporation
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S

---\\ Menu de démarrage Internet (8) - 0s
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe {33000002CF6D2CC57CAA65A6D80000000002CF} =>.Microsoft Corporation
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe {330000018A073733CF2048893C00000000018A} =>.Microsoft Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Microsoft Edge.) -- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe =>.Microsoft Corporation

---\\ Recherche d'infection sur les navigateurs (5) - 5s
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/
O69 - SBI: SearchScopes [HKCU] {34E336DC-8EA6-45E4-8A0F-A57FA9FDBF0F} - (Google) - http://www.google.com/
O69 - SBI: SearchScopes [HKCU] {ielnksrch} - (Search the web) - http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBAcdbTT-oGb_ZTugWdVuG9UUjovV68aVEcDeMEloac1Z2vEXQFU5tC1M7z9Q7w7Sgr8LA83G_P2ZPpX_Z3rMXi2dyhnubwDDCRWPBrokLMvop24pnUXg2F5asMRkklJhGHPrNhg6h50A8P04hJmDGQy4ZV0Kqv6YsTgZf8q-gg0biACNa6w-3S&q={searchTerms} =>PUP.Optional.Linkury
O69 - SBI: SearchScopes [HKLM] ielnksrch - (Search the web) - http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBAcdbTT-oGb_ZTugWdVuG9UUjovV68aVEcDeMEloac1Z2vEXQFU5tC1M7z9Q7w7Sgr8LA83G_P2ZPpX_Z3rMXi2dyhnubwDDCRWPBrokLMvop24pnUXg2F5asMRkklJhGHPrNhg6h50A8P04hJmDGQy4ZV0Kqv6YsTgZf8q-gg0biACNa6w-3S&q={searchTerms} =>PUP.Optional.Linkury
O69 - SBI: SearchScopes [HKLM] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (@ieframe.dll,-12512) - http://www.bing.com/

---\\ Enumère les services démarrés par Svchost (32) - 1s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [72192] =>.Microsoft Corporation
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [80384] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [80384] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\system32\srvsvc.dll [236032] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [794624] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [863232] =>.Microsoft Corporation
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [680960] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [99328] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [345088] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [97792] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [64512] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [358912] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [316416] =>.Microsoft Corporation
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du se.) -- C:\Windows\System32\termsrv.dll [688128] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [850944] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [371712] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [572416] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\system32\seclogon.dll [30720] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [70144] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\system32\iscsiexe.dll [156672] =>.Microsoft Corporation
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédia.) -- C:\Windows\system32\mmcss.dll [67584] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [242688] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [128000] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [136704] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [111104] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\system32\schedsvc.dll [1110528] =>.Microsoft Corporation
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\system32\kmsvc.dll [90624] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [86016] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [225792] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\system32\themeservice.dll [44544] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [100864] =>.Microsoft Corporation
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [193536] =>.Microsoft Corporation

---\\ Liste des exceptions du parefeu Windows (18) - 2s
O87 - FAEL: "{F834FE57-4383-486F-AF3A-2E777F6FEE3F}" [In-None-P17-TRUE] .(.D-Link Corp. - D-Link Portable WiFi Application.) -- C:\Program Files (x86)\D-Link\DWA-131 revE\IHV\PortableWiFi.exe {130303E4570C272909E265DDB859DEEF}
O87 - FAEL: "TCP Query User{88983483-ECE2-4E56-996B-5B6CA496AB50}C:\program files (x86)\emule\emule.exe" [In-None-P6-TRUE] .(.http://www.emule-project.net - eMule.) -- C:\program files (x86)\emule\emule.exe
O87 - FAEL: "UDP Query User{853F5C9E-C9AF-4962-89C5-B3908C52224C}C:\program files (x86)\emule\emule.exe" [In-None-P17-TRUE] .(.http://www.emule-project.net - eMule.) -- C:\program files (x86)\emule\emule.exe
O87 - FAEL: "{E4546134-923A-4B23-808D-319837C12E62}" [In-None-P6-TRUE] .(.Piriform Software Ltd - CCleaner emergency updater.) -- C:\Program Files\CCleaner\CCUpdate.exe {02FA994D660DE659EE9037ECB437D766}
O87 - FAEL: "{7747C95F-2ED3-4B41-89E6-E3B5F69FA0E7}" [In-None-P17-TRUE] .(.Piriform Software Ltd - CCleaner emergency updater.) -- C:\Program Files\CCleaner\CCUpdate.exe {02FA994D660DE659EE9037ECB437D766}
O87 - FAEL: "{1A0BCB20-7A97-4C0F-80ED-301462DF4967}" [Out-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Soused\Crocodile.exe
O87 - FAEL: "{51C98D79-FF75-452D-9C7B-1CB643F1CB69}" [Out-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Lameness\Crocodile.exe
O87 - FAEL: "{2BC847D7-CB19-41DC-98A8-DE2FB63A3877}" [Out-None-P17-TRUE] .(...) -- C:\Program Files (x86)\warfarin\Bunkhouse.exe
O87 - FAEL: "{BAD7A103-9C1F-4C96-82DE-2D8D8DC7C6A7}" [Out-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Lameness\Bunkhouse.exe
O87 - FAEL: "{1B3BAF38-AFDA-4FF2-BC6A-34C969357E97}" [In-None-P6-TRUE] .(.Shareaza Development Team - Shareaza Ultimate File Sharing.) -- C:\Program Files (x86)\Shareaza\Shareaza.exe
O87 - FAEL: "{FEF27207-5416-4C9C-BE44-F0723B61743A}" [In-None-P17-TRUE] .(.Shareaza Development Team - Shareaza Ultimate File Sharing.) -- C:\Program Files (x86)\Shareaza\Shareaza.exe
O87 - FAEL: "{DB0F6467-DDC5-4438-B047-1D77FBC66C6A}" [In-None-P17-TRUE] .(...) -- C:\Windows\rss\csrss.exe
O87 - FAEL: "{017BFE6D-5947-4BE5-957E-3569E65680F5}" [In-None-P17-TRUE] .(...) -- C:\Windows\rss\csrss.exe
O87 - FAEL: "{7E2A7E4C-BFC9-4DA7-9C90-7807377EF0B2}" [In-None-P17-TRUE] .(...) -- C:\Windows\rss\csrss.exe
O87 - FAEL: "{AF889D3B-70E6-4823-89C4-FC19A7E20EF0}" [In-None-P17-TRUE] .(...) -- C:\Windows\rss\csrss.exe
O87 - FAEL: "{95B58ADD-E9CD-4F1D-A1D3-234A35ACA46D}" [In-None-P17-TRUE] .(...) -- C:\Windows\rss\csrss.exe
O87 - FAEL: "{60D54AD0-E81B-4452-99C5-69AF39C285C3}" [In-None-P17-TRUE] .(...) -- C:\Windows\rss\csrss.exe
O87 - FAEL: "{4C9A0454-22DC-4126-9B37-E2825F0CE07C}" [In-None-P17-TRUE] .(...) -- C:\Users\Admin\AppData\Roaming\261e21d9bddc\261e21d9bddc\261e21d9bddc.exe (.not file.)

---\\ Scan Additionnel (6) - 0s
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\inafjghmmkmiobijhbgkfekenbfbklhb =>PUP.Optional.SmartBar
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\n5ow9kf8.default\searchplugins\findit.xml =>PUP.Optional.SmartBar
HKCU\SOFTWARE\undefined =>.Superfluous.Downloader
C:\Users\Admin\AppData\Local\CrashRpt =>.Superfluous.CrashReports
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{ielnksrch} =>PUP.Optional.Linkury
HKLM\Software\Microsoft\Internet Explorer\SearchScopes\ielnksrch =>PUP.Optional.Linkury

---\\ Récapitulatif des éléments trouvés sur votre station (4) - 0s
http://www.nicolascoolman.fr/?p=308 =>PUP.Optional.SmartBar
http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.Linkury
http://www.nicolascoolman.fr/?p=5145 =>.Superfluous.Downloader
http://www.nicolascoolman.fr/?p=5145 =>.Superfluous.CrashReports

~ End of the scan, 15411 items in 00h08mn16s (924)(0)

Publicité


Signaler le contenu de ce document

Publicité